◆ LEGAL · COMPLIANCE
Compliance & Data Protection
Global overview covering Bahrain PDPL, GCC frameworks, EU/UK GDPR, California CCPA/CPRA, and our worldwide baseline.
01 · Overview
ZOMBIEREX is a social platform for motorcycle and automotive enthusiasts. This page describes how we handle personal data across jurisdictions and the platform policies that govern rider content, marketplace listings, and safety features.
This is app-owner editable content maintained by ZOMBIEREX. It is a plain-language summary of controls we operate today; it is not a certification, legal opinion, or regulatory filing.
02 · Bahrain — Personal Data Protection Law (PDPL)
We align our handling of personal data with the Kingdom of Bahrain's Personal Data Protection Law, Law No. (30) of 2018 and its implementing regulations issued by the Personal Data Protection Authority (PDPA).
- Lawful basis: consent, contract, or legitimate interest.
- Right to access, rectify, object, and erase your data.
- Notification of a data breach affecting Bahraini residents.
- Cross-border transfer safeguards where the destination country is not listed as adequate by the PDPA.
- Data-subject requests: privacy@zombierex.com.
03 · GCC — Regional Data Protection
Where residents of other GCC states use ZOMBIEREX we also align with:
- UAE — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and DIFC/ADGM data-protection regulations.
- Saudi Arabia — Personal Data Protection Law (PDPL) issued by Royal Decree M/19 of 1443H, as amended, and SDAIA implementing regulations.
- Qatar — Law No. 13 of 2016 on the Protection of Personal Data.
- Oman — Personal Data Protection Law, Royal Decree No. 6/2022.
- Kuwait — CITRA Data Privacy Protection Regulation.
Where a stricter GCC requirement applies (for example, explicit consent for sensitive data or in-country hosting), we honour it for residents of that state.
04 · EU & UK — GDPR
For users in the European Economic Area, United Kingdom, and Switzerland we process personal data under the EU General Data Protection Regulation (2016/679) and the UK GDPR / Data Protection Act 2018.
- Rights: access, rectification, erasure, restriction, portability, objection, and to withdraw consent.
- Legal bases documented per processing activity.
- Standard Contractual Clauses for transfers outside the EEA/UK.
- Data-protection incidents notified to the lead supervisory authority within 72 hours where required.
05 · California — CCPA / CPRA
California residents have rights under the California Consumer Privacy Act (as amended by the CPRA): to know, delete, correct, limit use of sensitive personal information, and to opt out of the sale or sharing of personal information. ZOMBIEREX does not sell personal information. Requests: privacy@zombierex.com.
06 · Worldwide baseline
Regardless of location we apply this baseline:
- Encryption in transit (TLS) and at rest for stored personal data.
- Role-based access control with least-privilege database policies (Row-Level Security).
- Audit logging of privileged actions (role changes, moderation, payments, SOS).
- Retention limits and account deletion within 30 days of a verified request.
- Vulnerability reporting channel: security@zombierex.com.
07 · Safety, telemetry & SOS
Route recording, group-ride tracking, crash detection, and the SOS share-link only run while you enable them. Location data is bound to your account and is not sold. SOS share links use unguessable tokens and can be revoked at any time from the Atlas SOS screen.
08 · Marketplace conduct
Sellers must describe vehicles and parts accurately and comply with local import, tax, and roadworthiness rules. ZOMBIEREX is not a party to the sale. Prohibited: stolen goods, counterfeit safety gear, weapons, and any items restricted by the buyer's or seller's jurisdiction.
09 · Contact
Data-protection officer: privacy@zombierex.com
Security disclosures: security@zombierex.com
Trust & safety: trust@zombierex.com
Last reviewed: July 2026.
Related: this page · privacy@zombierex.com