KINDI · A bureau for handling sensitive language.

In-Kingdom PII masking for frontier LLMsRiyadh · Kingdom of Saudi ArabiaPreview
KINDI.me
09 Aug 2026 · 1448-02-26 HRiyadh · --:-- AST
PL. 24 · § 01
§ I.

Current sub-processors

KINDI engages the following sub-processors to provide the service. Each entry lists what the sub-processor receives, where it operates, and what it is not permitted to receive. For the definition of “Sub-processor” and the contractual safeguards KINDI flows down, see the Data Processing Addendum.

Note on the language-model rows. Both language-model providers are engaged only when a Customer routes a request through the KINDI proxy; the direct masking and file-redaction endpoints never contact either of them. In every case the personal-data spans have been replaced with deterministic placeholders before the text is forwarded, and the original values and the placeholder mapping are not sent. A production request is authenticated with the Customer’s own provider key, passed through for that single request and never stored by KINDI. A dashboard demo request is authenticated with KINDI’s own operated account with that provider, under per-account and system-wide caps.

PL. 24 · § 02
§ II.

Notice of changes

KINDI will publish a notice at least 14 days in advance of adding, replacing, or materially changing the role of any sub-processor listed above. Notices are posted on this page, with a corresponding version increment at the head of the document, and emailed to the registered address on file for each account.

PL. 24 · § 03
§ III.

Right of objection

A Customer that objects to a new sub-processor on reasonable data-protection grounds may, within the 14-day notice period, terminate the affected service and receive a pro-rata refund of any unused prepaid balance. The objection must be submitted in writing via the contact form at kindi.me/contact, marked for the attention of the Data Protection Officer, and must state the basis for the objection.

PL. 24 · § 04
§ IV.

Cross-border transfers

Hosting, storage, backups, and operational logs all remain inside the Kingdom of Saudi Arabia. Four sub-processors in the table above operate outside the Kingdom: the DNS and TLS-issuance provider, the transactional-email provider, and the two language-model providers the optional proxy reaches. Each receives the data described in the “What it receives” column and no more. The DNS provider receives no personal data at all; the language-model providers receive masked text only.

A Customer may send the masked text to a frontier language model in one of two ways. In the direct integration, the Customer’s own client makes the call to the model; KINDI is not party to that transfer, and the Customer is the Controller for it. In the optional KINDI proxy, KINDI forwards the masked text to the model on the Customer’s behalf, using the Customer’s own provider key for a production request or KINDI’s operated account for a dashboard demo; the providers reached by the proxy are listed in the table above. In both cases the text that crosses the frontier carries only deterministic placeholders, the original personal data never leaves the Kingdom, and the placeholder mapping is held in the request only and is discarded once the response is returned. The Customer remains the Controller for the cross-border transfer and is responsible for satisfying the requirements of the Transfer Regulation, including any Transfer Risk Assessment expected under Article 7 of the same regulation.