Skip to content

The platform

In-Kingdom data residency, governed at the data layer

For rights holders in the region, where fan data lives is not a detail, it's the deal. Sfere is Saudi-founded and built in-region: it runs in-Kingdom, keeps data under your control, and enforces PDPL consent at the data layer.

Cooling fans in a data-center server hall

Fan data that stays where it belongs

In-region processing, no data leaving your control, and consent enforced with the data: the foundation for trusting a platform with your fan base.

In-Kingdom by default

Deploy and process fan data inside the Kingdom. Residency isn't a region toggle added later, it's where the platform actually runs.

PDPL from the ground up

Built around Saudi Arabia's Personal Data Protection Law, consent, purpose, and data-subject rights modeled into the data layer, not bolted on.

Your data stays yours

Self-host in your own cloud or on-prem with no data egress; Sfere never becomes an offshore copy of your fan base.

Consent travels with the data

Every profile carries its consent and purpose and enforces them wherever it moves, so residency and consent never drift out of sync.

Sovereign, not siloed

Keep data in-region without giving up real-time activation and analytics, sovereignty without the usual capability trade-off.

Arabic-native at the core

Arabic-first identity and data handling, built for the region you operate in rather than translated on top of it.

Aligned with Saudi data protection from the ground up

Saudi Arabia's Personal Data Protection Law, in force with regulator oversight since September 2024, sets clear expectations for where fan data lives and how consent is handled. Sfere is designed to meet them at the data layer rather than through after-the-fact process.

Data stays in the Kingdom

PDPL tightly restricts moving personal data of individuals in Saudi Arabia outside the Kingdom. Deploy Sfere in-region, on your cloud, private network, or on-premise, and the cross-border question never has to arise. Confirm the specifics with your counsel.

Consent and purpose logged

Every profile carries the lawful basis it was collected under. Consent and purpose are stored with the data and enforced when it moves, so you can show a regulator not just what you hold but why you may hold it.

Data-subject rights, built in

Access, correction, and deletion requests act on the profile itself. When a fan withdraws consent, that change propagates through the data layer rather than lingering in a downstream copy.

Your operator never sees the data

Self-host and no external operator holds a standing view of your fan base. Whether data ever crosses a border is a decision you make under your own controls, not a vendor default. Specific control mappings are worked through with your counsel.

Consent and residency, enforced together

Residency isn't a storage location bolted on at the end. It's a property of the deployment, and consent rides with every profile, so the two never drift out of sync.

Deploy in-region

The platform runs where you place it, an in-Kingdom cloud region, your private network, or your own data centre. Residency is decided at deployment, so data is processed in-region from the first event rather than exported and pulled back.

Attach consent to the profile

As signals resolve into one fan profile, the consent and purpose behind each signal travel with it. The record of what a fan agreed to lives next to the data it governs, not in a separate compliance spreadsheet.

Enforce as data moves

When a profile is activated into a segment or a journey, its consent and residency rules are checked at the data layer. A withdrawn permission or a region restriction is honoured everywhere the profile goes.

Prove it on demand

Audit logs and consent history give your legal and security teams a clear record of where data lives, who touched it, and on what basis, the evidence a PDPL review asks for.

Prove residency to a regulator without going batch

Keeping fan data in-Kingdom usually means falling back to nightly pipelines and losing real-time activation. Sfere resolves, governs, and activates in-region as events arrive, so you can show a regulator exactly where data lives and still act on it live.

  • Choose where fan data lives, in-Kingdom, or any region you require.
  • Residency and PDPL compliance governed at the data layer, not patched on top.
  • Self-hosted with your own keys means no third-party egress and no offshore copies.
  • Consent, purpose, and residency enforced together: the record regulators expect.
See security & compliance

Where fans become players.

See how Sfere turns your live audience into active, returning, monetizable fans. Book a walkthrough with our team.