By Yousef Shaiban · Last updated August 2026
Every reply the agent sends is also a record.
PDPL-aware means the decisions a regulator would ask about are made and written down before go-live rather than after: what personal data the deployment touches, where it sits, who can reach it, and when a person takes over. It is a posture rather than a certificate, and no third-party attestation has been issued for ChatSheba.
Key takeaways
- Data protection is built into each deployment from the start, not added afterward.
- Each deployment runs inside its own data boundary — no cross-tenant mixing.
- On-prem and regulated-residency paths are available where data location is required.
- Human escalation is a compliance control — sensitive cases go to a person.
- Every conversation is recorded in the CRM for an auditable record.
What does PDPL-aware by design actually mean here?
The difference between aware and compliant is not a wording preference. The first describes deployment decisions that are made before launch and can be shown; the second describes a certificate somebody else issues, and no such certificate exists for ChatSheba. In practice: personal data handling, residency, retention and access are settled before the first conversation runs, so a compliance team can see how customer data moves before it moves. Where your industry imposes specific obligations, those become part of the deployment configuration rather than assumptions.
How is one client's data kept separate from another's?
Every deployment sits in its own data boundary. One client's conversations, contacts, and CRM records do not share a boundary with another client's, so there is no cross-tenant mixing of personal data by default. This matters most for regulated buyers who must demonstrate that customer records stay contained: the boundary is the unit of isolation, and it is defined per deployment rather than shared across a single multi-tenant pool you cannot point to.
Can the data stay in our environment or a specific region?
For banks, healthcare providers and other regulated buyers, Sheba supports on-prem and regulated-residency paths, scoped per deployment during the engagement rather than switched on from a standing configuration. If your obligations require personal data to stay inside a specific jurisdiction or inside your own infrastructure, that requirement is fixed in the deployment configuration rather than worked around afterwards.
How does human escalation work as a compliance control?
Human escalation is treated as a control, not just a convenience. When a conversation touches a case that needs a person — a sensitive request, an edge case, or anything outside the agent's defined scope — ChatSheba hands off to your team instead of improvising. The escalation path means a human stays accountable for decisions that carry regulatory weight. You set where the line sits; the system routes accordingly.
Can we audit what the AI said and did?
Every conversation is logged in the CRM underneath ChatSheba, against the customer record: what was asked, what the agent answered, and when a human took over. Because the CRM sits under all four channels, the record stays consistent regardless of where the customer started. When an internal review asks what happened in a specific interaction, the history is read from the record rather than reconstructed.
Does Arabic-native handling change the compliance picture?
It strengthens it. Arabic is authored natively rather than translated, across every dialect, so the agent understands and logs what a customer actually said in their own language — which keeps the audit record accurate rather than a lossy translation. The same per-deployment boundaries, residency paths, and escalation controls apply whether the conversation runs in Arabic, English, or one of 10+ supported UI languages. Compliance does not weaken because the buyer's customers write in Arabic.
Frequently asked questions
Bring AI support into a regulated environment
Walk through your PDPL obligations with us and we will map the data boundary, residency, and escalation controls for your deployment.
Discuss your use case