
Trust & Compliance
At ENTEK.AI, we maintain the highest standards of compliance and security in energy trading. Our platform is built on a foundation of trust, transparency, and regulatory adherence.
UN Environment Recognition
ENTEK.AI is proud to be recognized by the United Nations Environment Programme for our innovative approach and commitment to sustainable energy solutions in the MENA region. This recognition validates our dedication to environmental stewardship and our role as pioneers in green energy transformation.

International Standards & Certifications
We are committed to achieving and maintaining the highest industry standards
ISO 27001
Information Security Management
Our marketplace platform handles sensitive energy trading data. ISO 27001 certification will ensure we maintain world-class information security controls to protect your business data and transactions.
- Secure data encryption and storage
- Regular security audits and risk assessments
- Continuous monitoring and incident response
ISO 9001
Quality Management Systems
Ensuring consistent quality in our marketplace operations, supplier verification processes, and customer service delivery through internationally recognized quality management standards.
- Rigorous supplier vetting and quality assurance
- Continuous process improvement and optimization
- Customer satisfaction measurement and feedback
ISO 50001
Energy Management Systems
As an energy marketplace and management platform, ISO 50001 certification will demonstrate our commitment to optimizing energy performance and promoting sustainable energy practices.
- Energy performance monitoring and optimization
- Systematic approach to energy efficiency improvements
- Reduction of energy costs and environmental impact
ISO 14001
Environmental Management Systems
Aligning with our UN recognition, ISO 14001 will formalize our commitment to minimizing environmental impact and promoting sustainable practices across our energy marketplace operations.
- Environmental impact assessment and reduction
- Compliance with environmental regulations
- Sustainable resource management and waste reduction
Our Commitment to Compliance
At ENTEK.AI, we understand that trust is the foundation of successful energy partnerships. Our commitment to achieving these international certifications reflects our dedication to operational excellence, data security, and environmental responsibility.
We are actively working towards obtaining these certifications and will update our compliance status as we progress. For specific questions about our compliance standards, security measures, or certification timeline, please contact our compliance team at [email protected].
Compliance Legal Documentation
The following legal content is included in a terms-like document format.
Compliance Documentation for ENTEK.AI
Last Updated: November 12, 2025
1. Executive Summary
ENTEK.AI is committed to maintaining the highest standards of legal, regulatory, and ethical compliance in all aspects of our operations. As an AI-powered energy marketplace operating in the Kingdom of Saudi Arabia and serving customers across the MENA region, we adhere to comprehensive compliance frameworks covering data protection, energy sector regulations, financial services, cybersecurity, and environmental sustainability.
This Compliance Documentation outlines our commitment to regulatory adherence and describes the frameworks, policies, and procedures we have implemented to ensure ongoing compliance with all applicable laws and regulations.
2. Regulatory Framework Overview
ENTEK.AI operates under a complex regulatory environment that includes:
2.1 Data Protection and Privacy
Saudi Personal Data Protection Law (PDPL)
The PDPL, which came into force on September 14, 2023, governs the collection, processing, storage, and transfer of personal data in Saudi Arabia. ENTEK.AI is fully compliant with all PDPL requirements, including:
Lawful processing of personal data based on consent, contractual necessity, legal obligation, or legitimate interests
Implementation of appropriate technical and organizational security measures
Appointment of a Data Protection Officer (DPO)
Data breach notification procedures (within 72 hours to SDAIA)
Respect for data subject rights (access, rectification, erasure, portability, objection)
Cross-border data transfer safeguards using Standard Contractual Clauses and Transfer Risk Assessments
Maintenance of comprehensive data processing records
Regulatory Authority: Saudi Data and Artificial Intelligence Authority (SDAIA)
Compliance Status: Fully compliant since September 14, 2024
2.2 Energy Sector Regulations
Saudi Electricity Regulatory Authority (SERA)
SERA regulates the electricity and energy sector in Saudi Arabia to ensure reliability, safety, and efficiency of energy supply.
Key Regulations:
Law on Dry Gas and Liquified Petroleum Gas (LPG) Distribution (Royal Decree M/112): Governs the licensing, distribution, and safety standards for LPG and dry gas distribution for residential and commercial purposes
Technical Regulation for Tanks – Part 2: LPG Tankers: Establishes safety standards for LPG transport vehicles and equipment
Energy Efficiency Standards: Requirements for monitoring, reporting, and improving energy efficiency
Compliance Measures:
All suppliers on our platform are verified to hold valid energy distribution licenses
Regular audits of supplier compliance with safety and quality standards
Adherence to SASO (Saudi Standards, Metrology and Quality Organization) standards for equipment and vehicles
Implementation of safety training programs for delivery personnel
Emergency response protocols and incident reporting systems
Compliance Status: Fully compliant with all energy sector regulations
2.3 Financial Services and Payment Processing
Saudi Central Bank (SAMA) Regulations
As a platform that facilitates financial transactions, ENTEK.AI complies with SAMA regulations governing payment processing, anti-money laundering (AML), and counter-terrorism financing (CTF).
Key Compliance Areas:
Payment Services Provider Regulations: Compliance with rules governing electronic payment processing
Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF): Implementation of Know Your Customer (KYC) procedures, transaction monitoring, and suspicious activity reporting
Consumer Protection: Fair pricing, transparent terms, and dispute resolution mechanisms
Data Security: PCI-DSS compliance for payment card data handling
Compliance Measures:
Partnership with licensed payment service providers (PSPs)
KYC verification for all corporate clients and suppliers
Automated transaction monitoring for suspicious activities
Regular AML/CTF training for relevant staff
Secure payment processing infrastructure with end-to-end encryption
Compliance Status: Fully compliant with SAMA regulations
2.4 Cybersecurity
National Cybersecurity Authority (NCA) Requirements
The NCA establishes cybersecurity standards for critical infrastructure and essential services in Saudi Arabia.
Key Frameworks:
Essential Cybersecurity Controls (ECC): Mandatory controls for organizations operating critical infrastructure
Cybersecurity Regulatory Framework: Requirements for risk management, incident response, and business continuity
Data Classification and Protection Standards: Guidelines for protecting sensitive information
Compliance Measures:
Implementation of comprehensive cybersecurity controls aligned with NCA ECC framework
Regular vulnerability assessments and penetration testing
24/7 security operations center (SOC) for threat detection and response
Incident response plan with notification procedures to NCA
Employee cybersecurity awareness training
Third-party security assessments for all service providers
Business continuity and disaster recovery plans
Compliance Status: Fully compliant with NCA cybersecurity requirements
2.5 Taxation
General Authority of Zakat and Tax (GAZT)
ENTEK.AI complies with all tax obligations in Saudi Arabia, including:
Value Added Tax (VAT): 15% VAT on applicable transactions
Corporate Income Tax: Compliance with corporate tax filing and payment obligations
Withholding Tax: Proper withholding and remittance for cross-border payments
Compliance Measures:
VAT registration and regular filing of VAT returns
Accurate invoicing with VAT details
Maintenance of comprehensive financial records
Engagement of qualified tax advisors
Regular tax audits and assessments
Compliance Status: Fully compliant with all tax obligations
2.6 Environmental Compliance and Sustainability
Saudi Vision 2030 and ESG Standards
ENTEK.AI is committed to supporting Saudi Vision 2030's sustainability goals and maintaining high Environmental, Social, and Governance (ESG) standards.
Compliance Areas:
Carbon Emissions Tracking: Real-time monitoring and reporting of carbon footprint
Carbon Offset Programs: Verified carbon credit programs for clients
Renewable Energy Promotion: Facilitating access to renewable energy sources
Environmental Impact Assessments: Regular assessments of environmental impact
Sustainable Operations: Energy-efficient infrastructure and green logistics
Recognition:
UN Environment Programme recognition for sustainable energy solutions
Alignment with UN Sustainable Development Goals (SDGs)
Compliance Status: Active ESG program with ongoing improvements
3. Compliance Management System
3.1 Governance Structure
Board of Directors
The Board provides oversight of compliance matters and approves major compliance policies and initiatives.
Chief Compliance Officer (CCO)
The CCO is responsible for developing, implementing, and monitoring the compliance program across all business units.
Compliance Committee
A cross-functional committee that meets quarterly to review compliance matters, assess risks, and recommend policy updates.
Data Protection Officer (DPO)
The DPO oversees all data protection and privacy compliance matters, serves as the point of contact for SDAIA, and manages data subject requests.
Department Compliance Champions
Each department has designated compliance champions who ensure day-to-day adherence to compliance policies and procedures.
3.2 Compliance Policies and Procedures
ENTEK.AI has implemented comprehensive policies covering:
Data Protection and Privacy Policy
Information Security Policy
Anti-Money Laundering and Counter-Terrorism Financing Policy
Code of Conduct and Ethics
Supplier Verification and Due Diligence Procedures
Incident Response and Breach Notification Procedures
Records Retention and Destruction Policy
Third-Party Risk Management Policy
Whistleblower Protection Policy
Conflict of Interest Policy
All policies are reviewed annually and updated as needed to reflect regulatory changes.
3.3 Risk Assessment and Management
Annual Compliance Risk Assessment
We conduct comprehensive annual risk assessments to identify, evaluate, and prioritize compliance risks across all areas of operation.
Risk Mitigation Strategies
For each identified risk, we develop and implement mitigation strategies, including:
Enhanced controls and monitoring
Staff training and awareness programs
Technology solutions and automation
Third-party audits and assessments
Insurance coverage
Ongoing Risk Monitoring
We continuously monitor compliance risks through:
Key risk indicators (KRIs) and metrics
Regular internal audits
Compliance testing and validation
Incident tracking and analysis
Regulatory updates monitoring
3.4 Training and Awareness
Mandatory Compliance Training
All employees complete mandatory compliance training upon joining and annually thereafter, covering:
Data protection and privacy (PDPL compliance)
Information security and cybersecurity
Anti-money laundering and fraud prevention
Code of conduct and ethics
Sector-specific regulations (energy, financial services)
Role-Specific Training
Employees in specific roles receive additional specialized training relevant to their responsibilities.
Awareness Campaigns
Regular communications, newsletters, and campaigns to maintain high levels of compliance awareness throughout the organization.
3.5 Monitoring and Auditing
Internal Audits
Our internal audit function conducts regular audits of compliance with policies, procedures, and regulatory requirements.
External Audits
We engage independent third-party auditors to conduct annual compliance audits and certifications, including:
ISO 27001 (Information Security Management)
ISO 9001 (Quality Management)
PCI-DSS (Payment Card Industry Data Security Standard)
SOC 2 Type II (Service Organization Controls)
Regulatory Inspections
We cooperate fully with regulatory inspections and examinations by SDAIA, SERA, SAMA, NCA, and other authorities.
Continuous Monitoring
Automated monitoring systems track compliance metrics, detect anomalies, and generate alerts for potential compliance issues.
3.6 Incident Management and Reporting
Incident Response Plan
We maintain a comprehensive incident response plan covering:
Data breaches and privacy incidents
Cybersecurity incidents
Safety incidents (delivery, equipment)
Regulatory violations
Fraud and financial crimes
Reporting Procedures
Internal Reporting:
All compliance incidents must be reported immediately to the Compliance team
Incident tracking and investigation procedures
Root cause analysis and corrective actions
External Reporting:
Data Breaches: Notification to SDAIA within 72 hours; notification to affected individuals without undue delay
Cybersecurity Incidents: Notification to NCA as required
Safety Incidents: Notification to SERA and relevant authorities
Financial Crimes: Reporting to SAMA and law enforcement
Incident Documentation
All incidents are thoroughly documented, including:
Incident details and timeline
Investigation findings
Remediation actions taken
Lessons learned and preventive measures
4. Supplier and Third-Party Compliance
4.1 Supplier Verification Process
All energy suppliers on our platform undergo rigorous verification, including:
Business License Verification: Valid commercial registration and energy distribution licenses
Safety Certifications: SASO certifications for vehicles and equipment
Insurance Verification: Adequate liability and vehicle insurance
Background Checks: Verification of company and key personnel
Financial Due Diligence: Assessment of financial stability
Compliance History: Review of regulatory compliance record
4.2 Ongoing Supplier Monitoring
Performance Monitoring:
Delivery performance and customer satisfaction ratings
Safety incident tracking
Compliance with platform policies and standards
Periodic Re-verification:
Annual renewal of licenses and certifications
Periodic audits of high-volume suppliers
Compliance attestations
Supplier Training:
Onboarding training on platform policies and procedures
Safety and compliance training
Updates on regulatory changes
4.3 Third-Party Service Provider Management
Due Diligence:
All third-party service providers (payment processors, cloud providers, analytics tools) undergo due diligence assessments covering:
Data protection and security practices
Regulatory compliance
Financial stability
Reputation and track record
Contractual Safeguards:
Data Processing Agreements (DPAs) with all processors
Service Level Agreements (SLAs) with performance metrics
Confidentiality and security obligations
Audit rights and compliance reporting requirements
Liability and indemnification provisions
Ongoing Oversight:
Regular review of third-party compliance reports and certifications
Periodic assessments and audits
Incident notification and response coordination
5. Data Protection and Privacy Compliance
5.1 PDPL Compliance Program
Data Mapping and Inventory
We maintain a comprehensive data inventory documenting:
Categories of personal data collected
Sources of personal data
Purposes of processing
Legal basis for processing
Data recipients and transfers
Retention periods
Privacy by Design and Default
We implement privacy considerations into all new systems, products, and services from the design stage, including:
Data minimization principles
Purpose limitation
Default privacy settings
Pseudonymization and anonymization where possible
Data Subject Rights Management
We have established processes to handle data subject requests efficiently:
Online portal for submitting requests
Verification procedures to confirm identity
Response within 30 days
Tracking and documentation of all requests
Cross-Border Transfer Compliance
For all transfers of personal data outside Saudi Arabia, we implement:
Standard Contractual Clauses (SCCs)
Transfer Risk Assessments (TRAs) for sensitive data
Data Processing Agreements with international processors
Documentation of transfer mechanisms
Data Breach Response
Our data breach response plan includes:
Immediate containment and investigation
Assessment of risk to data subjects
Notification to SDAIA within 72 hours
Notification to affected individuals (if high risk)
Documentation and post-incident review
5.2 Data Protection Officer (DPO)
Our DPO is responsible for:
Monitoring compliance with PDPL and other data protection laws
Advising on data protection impact assessments (DPIAs)
Serving as point of contact for SDAIA and data subjects
Conducting privacy training and awareness programs
Reporting to senior management on data protection matters
DPO Contact: [email protected]
6. Cybersecurity Compliance
6.1 Security Controls
We implement comprehensive security controls aligned with NCA Essential Cybersecurity Controls (ECC) and ISO 27001:
Access Controls:
Role-based access control (RBAC)
Multi-factor authentication (MFA) for all user accounts
Privileged access management (PAM)
Regular access reviews and recertification
Network Security:
Firewalls and intrusion detection/prevention systems (IDS/IPS)
Network segmentation and isolation
Virtual private networks (VPNs) for remote access
DDoS protection
Data Security:
Encryption in transit (TLS 1.3)
Encryption at rest (AES-256)
Secure key management
Data loss prevention (DLP) tools
Application Security:
Secure software development lifecycle (SDLC)
Regular code reviews and security testing
Web application firewall (WAF)
API security controls
Endpoint Security:
Antivirus and anti-malware protection
Endpoint detection and response (EDR)
Mobile device management (MDM)
Patch management
Security Monitoring:
24/7 Security Operations Center (SOC)
Security Information and Event Management (SIEM)
Threat intelligence integration
Automated alerting and response
6.2 Vulnerability Management
Regular vulnerability scanning (weekly)
Annual penetration testing by independent third parties
Bug bounty program for responsible disclosure
Patch management with prioritization based on risk
Remediation tracking and verification
6.3 Incident Response
Our cybersecurity incident response plan includes:
Incident detection and triage
Containment and eradication
Recovery and restoration
Post-incident analysis and lessons learned
Notification to NCA and other authorities as required
7. Financial Compliance
7.1 Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF)
Risk-Based Approach:
We apply a risk-based approach to AML/CTF compliance, with enhanced due diligence for higher-risk customers and transactions.
Know Your Customer (KYC):
Identity verification for all corporate clients and suppliers
Beneficial ownership identification
Ongoing monitoring and periodic re-verification
Transaction Monitoring:
Automated monitoring for suspicious transaction patterns
Threshold-based alerts for large transactions
Investigation and documentation of suspicious activities
Suspicious Activity Reporting:
Procedures for identifying and reporting suspicious activities to SAMA and relevant authorities
Confidentiality and non-tipping-off obligations
Staff Training:
Regular AML/CTF training for all relevant staff
Updates on emerging risks and typologies
7.2 Payment Card Industry Data Security Standard (PCI-DSS)
We are PCI-DSS compliant through our partnership with certified payment processors. We do not store, process, or transmit payment card data directly, minimizing PCI scope.
Compliance Measures:
Use of PCI-DSS certified payment gateways
Secure tokenization of payment information
Regular security assessments
Quarterly network scans by Approved Scanning Vendors (ASVs)
8. Certifications and Standards
ENTEK.AI maintains the following certifications and adheres to international standards:
9. Reporting and Transparency
9.1 Regulatory Reporting
We submit regular reports to regulatory authorities, including:
SDAIA: Annual data protection compliance reports
SERA: Quarterly operational and safety reports
SAMA: AML/CTF compliance reports
NCA: Cybersecurity incident reports
GAZT: Monthly VAT returns and annual tax filings
9.2 Transparency Reports
We publish annual transparency reports disclosing:
Data subject requests received and processed
Data breaches and incidents
Government requests for data
Compliance certifications and audit results
9.3 ESG Reporting
We publish annual ESG reports covering:
Carbon emissions data and reduction initiatives
Social impact metrics (jobs created, community programs)
Governance practices and compliance performance
Progress toward Saudi Vision 2030 goals
10. Continuous Improvement
ENTEK.AI is committed to continuous improvement of our compliance program through:
Regular review and update of policies and procedures
Benchmarking against industry best practices
Incorporation of lessons learned from incidents and audits
Investment in compliance technology and automation
Engagement with regulators, industry associations, and stakeholders
Monitoring of regulatory developments and emerging risks
11. Contact Information
For compliance-related inquiries, please contact:
Chief Compliance Officer
Email: [email protected]
Phone: 920005469
Data Protection Officer
Email: [email protected]
General Compliance Inquiries
Email: [email protected]
Whistleblower Hotline (Anonymous Reporting)
Email: [email protected]
Phone: [Hotline Number]
12. Regulatory Authority Contact Information
Acknowledgment: This Compliance Documentation represents ENTEK.AI's commitment to operating with the highest standards of legal, regulatory, and ethical compliance. We continuously monitor and adapt our compliance program to meet evolving regulatory requirements and industry best practices.
Document Version: 1.0
Next Review Date: November 12, 2026
