هذه السياسة مكتوبة وفق قانون حماية البيانات الشخصية الاردني رقم 24 لسنة 2023.
تشرح ما نجمعه، واين نخزنه، ومن يصل اليه، وما هي حقوقك وكيف تمارسها.
1. صفتنا تختلف باختلاف البيانات
نحن متحكم ببيانات حسابك: بريدك واسمك واسم مؤسستك وسجلات الدخول. ونحن
معالج بمحتوى نموذجك التشغيلي، وهو ما تدخله انت وقد يتضمن اسماء موظفيك ومسمياتهم
الوظيفية وتوقيعات المعتمدين. في هذا الجزء المؤسسة هي المتحكم وتحدد الغرض والوسيلة، ونحن نعالج
بناء على تعليماتها وحدها.
2. ما نجمعه
- بيانات الحساب: البريد الالكتروني، الاسم، اسم المؤسسة بالعربية والانجليزية،
كلمة المرور مخزنة كبصمة مشفرة (bcrypt) لا كنص.
- محتوى نموذجك التشغيلي: الوحدات التنظيمية والوظائف والاجراءات والسياسات
والمؤشرات والمخاطر والخدمات، وما يرد فيها من اسماء ومسميات وظيفية.
- سجلات تقنية: عنوان الشبكة ووقت الطلب وصفحته، تحفظ لاغراض الامن وتشخيص
الاعطال.
- احداث استخدام: وقائع مثل «انشئ سجل» او «ولدت وثيقة»، مربوطة بالمؤسسة
لا بالشخص، ولا تحمل اسما ولا بريدا ولا نص محتوى. نستخدمها لمعرفة اين يتعثر المستخدمون
وكم يستغرق الوصول الى اول وثيقة. هذه الاحداث تسجل عندنا فقط، ولا نستعين باي خدمة تحليلات
خارجية.
لا نجمع بيانات حساسة بمفهوم المادة الرابعة من القانون، ولا نطلب رقما وطنيا ولا بيانات صحية ولا
بيانات بنكية داخل المنصة.
3. لماذا نعالجها
لتنفيذ العقد معك وتشغيل الخدمة، ولحماية المنصة من اساءة الاستخدام، وللتواصل معك بشان حسابك.
لا نبيع البيانات ولا نؤجرها ولا نستخدمها في اعلانات.
4. اين تخزن، وهل تغادر الاردن
نعم، تغادر. تعمل الخوادم وقاعدة البيانات والنسخ الاحتياطية في مركز بيانات
Hetzner في مدينة Falkenstein في المانيا. ونذكرها صراحة لان المادة المتعلقة بالنقل خارج الحدود في
القانون الاردني تشترط ان يوفر الطرف المستقبل حماية كافية، والمانيا خاضعة للنظام الاوروبي العام
لحماية البيانات (GDPR)، وهو من اعلى انظمة الحماية المعمول بها.
وللجهات التي لا يجوز لبياناتها ان تغادر المملكة، تتوفر خطة الاستضافة الذاتية (السيادية) التي
تعمل بالكامل على خوادم الجهة نفسها. تواصل معنا قبل التسجيل.
5. من يصل الى البيانات غيرنا
| الجهة | مكان المعالجة | الغرض |
|---|
| Hetzner Online GmbH | المانيا (Falkenstein) | استضافة الخوادم وقاعدة البيانات والنسخ الاحتياطية |
| Cloudflare, Inc. | الولايات المتحدة، بشبكة عالمية | نطاق الموقع وتوجيه الطلبات والحماية من الهجمات، وفحص Turnstile عند التسجيل، وتمرير البريد الوارد |
| Resend (Amazon SES) | الولايات المتحدة | رسائل الخدمة: رمز التحقق، واستعادة كلمة المرور، والاشعارات |
| Anthropic PBC | الولايات المتحدة | ميزات الذكاء الاصطناعي، ولا تعمل الا اذا ادخلت المؤسسة مفتاحها الخاص |
لا نضيف جهة معالجة جديدة دون تحديث هذه الصفحة، ونشعر المشتركين قبل ثلاثين يوما من اي اضافة
تمس بياناتهم، ليتاح لهم الاعتراض.
6. كم نحتفظ بها
بيانات الحساب ومحتوى النموذج تبقى ما بقي الحساب قائما. بعد الانهاء: ثلاثون يوما للتصدير، ثم
الحذف من الانظمة العاملة خلال ثلاثين يوما، ثم من النسخ الاحتياطية بانتهاء دورتها. السجلات التقنية
تحفظ تسعين يوما.
7. كيف نحميها
نذكر هنا ما هو قائم فعلا، لا ما ننوي عمله:
- الاتصال مشفر بالكامل عبر HTTPS.
- كلمات المرور مخزنة كبصمة bcrypt، ولا يمكن استرجاع النص الاصلي منها.
- عزل المؤسسات مطبق على مستوى التطبيق: كل استعلام مقيد بمعرف المؤسسة.
- مفتاح الذكاء الاصطناعي الذي تدخله مخزن مشفرا (Fernet) لا كنص ظاهر.
- نسخ احتياطية يومية الى تخزين منفصل.
- الوصول التشغيلي مقصور على مشغل المنصة، وبقدر ما يلزم للتشغيل او لاصلاح عطل.
وللشفافية: لا تتوفر حاليا مصادقة ثنائية للحسابات، ولا تشفير على مستوى التطبيق للبيانات المخزنة
عدا مفتاح الذكاء الاصطناعي. من يشترط اي منهما فليذكره قبل التعاقد.
8. حقوقك
يمنحك القانون الحق في: الاطلاع على بياناتك والحصول على نسخة منها، وتصحيح ما هو خاطئ او ناقص،
وحذفها او اخفاء هويتها، وتقييد معالجتها على غرض محدد، ونقلها الى متحكم اخر، وسحب موافقتك في اي
وقت، والاشعار عند وقوع اختراق يمسها.
لممارسة اي منها راسلنا على [email protected]. نرد خلال ثلاثين يوما.
واذا كنت موظفا لدى جهة مشتركة وطلبك يخص بيانات ادخلتها جهتك، فالجهة هي المتحكم، ونحيل طلبك اليها
ونعينها على الرد.
9. عند وقوع اختراق
اذا وقع اختراق يمس سلامة البيانات وقد يلحق ضررا جسيما بصاحبها، نشعر اصحاب البيانات خلال
اربع وعشرين ساعة من اكتشافه، ونشعر وحدة حماية البيانات الشخصية خلال اثنتين وسبعين ساعة، بمصدر
الاختراق والبيانات المتاثرة والاجراءات المتخذة، وفق ما يوجبه القانون.
10. ملفات الارتباط
نستخدم ما يلزم للتشغيل فقط: ملف جلسة الدخول (hk_session)، وتفضيل اللغة المحفوظ في متصفحك، وملف
فحص Cloudflare Turnstile عند التسجيل لمنع التسجيل الالي. لا نستخدم ملفات تتبع اعلانية.
11. الاطفال
المنصة موجهة للاستخدام المؤسسي، ولا تخصص حسابات لمن هم دون الثامنة عشرة.
12. تعديل السياسة
عند تعديلها نحدث تاريخ السريان اعلاه، ونشعر المشتركين بالبريد قبل ثلاثين يوما من اي تعديل
جوهري.
13. الشكاوى
راسلنا اولا على [email protected]. ولك في كل الاحوال الحق في التقدم
بشكوى الى مجلس حماية البيانات الشخصية في المملكة الأردنية الهاشمية.
This policy is written against Jordan's Personal Data Protection Law
No. 24 of 2023. It explains what we collect, where it is stored, who can reach it, and what
your rights are.
1. Our role depends on which data
We are the controller of your account data: your email, your name, your
organization's name, and sign-in logs. We are a processor of your operating
model content, which you enter and which may contain your staff's names, job titles and the
names of document approvers. For that part your organization is the controller and decides
the purpose and the means, and we process only on its instructions.
2. What we collect
- Account data: email, name, organization name in Arabic and English, and
your password stored as a bcrypt hash, never as text.
- Operating model content: org units, roles, processes, policies, KPIs,
risks and services, including any names and job titles inside them.
- Technical logs: IP address, request time and path, kept for security and
fault diagnosis.
- Usage events: facts such as "a record was created" or "a document was
generated", keyed to the organization and never to a person, carrying no name, no email
and no content. We use them to see where people get stuck and how long reaching a first
document takes. They are recorded only by us; we use no third-party analytics service.
We do not collect sensitive data as the law defines it. The platform never asks for a
national ID number, health data, or bank details.
3. Why we process it
To perform our contract with you and run the service, to protect the platform from abuse,
and to contact you about your account. We do not sell or rent data, and we do not use it for
advertising.
4. Where it is stored, and does it leave Jordan
Yes, it does. The servers, the database and the backups run in Hetzner's
data centre in Falkenstein, Germany. We state that plainly because Jordan's cross-border
transfer rules require the receiving party to provide adequate protection, and Germany falls
under the EU General Data Protection Regulation, one of the strongest regimes in force.
For entities whose data may not leave the Kingdom, the Sovereign self-hosted plan runs
entirely on the entity's own servers. Talk to us before signing up.
5. Who else can reach the data
| Provider | Where it processes | Purpose |
|---|
| Hetzner Online GmbH | Germany (Falkenstein) | Server, database and backup hosting |
| Cloudflare, Inc. | United States, global network | DNS, request routing and DDoS protection, the Turnstile check at signup, and inbound mail forwarding |
| Resend (Amazon SES) | United States | Service email: verification codes, password resets and notifications |
| Anthropic PBC | United States | AI features, and only if the organization enters its own API key |
We do not add a new processor without updating this page, and subscribers get thirty days'
notice of any addition that touches their data, so they can object.
6. How long we keep it
Account data and model content are kept while the account exists. After termination:
thirty days to export, deletion from live systems within a further thirty days, then from
backups as their cycle expires. Technical logs are kept for ninety days.
7. How we protect it
What follows is what is actually in place, not what is planned:
- All traffic is encrypted with HTTPS.
- Passwords are stored as bcrypt hashes and cannot be reversed to the original text.
- Tenant isolation is enforced at the application layer: every query is scoped to the
organization's identifier.
- Any AI key you enter is stored encrypted (Fernet), not in plain text.
- Daily backups to separate storage.
- Operational access is limited to the platform operator, and only as far as running the
service or fixing a fault requires.
For transparency: there is currently no two-factor authentication on accounts, and no
application-level encryption at rest beyond the AI key. If your organization requires either,
raise it before contracting.
8. Your rights
The law gives you the right to access your data and get a copy, correct what is wrong or
incomplete, have it deleted or anonymised, restrict processing to a specific purpose, move it
to another controller, withdraw consent at any time, and be told about a breach that affects
you.
To exercise any of these, write to [email protected]. We reply within
thirty days. If you work for a subscribing organization and your request concerns data your
employer entered, that organization is the controller: we pass the request to them and help
them answer it.
9. If there is a breach
If a breach of data security and integrity occurs that could cause serious harm to the data
subject, we notify affected data subjects within twenty-four hours of discovering it, and the
Personal Data Protection Unit within seventy-two hours, with the source of the breach, the
data affected and the steps taken, as the law requires.
10. Cookies
Only what running the service requires: the sign-in session cookie (hk_session), your
language preference stored in your browser, and the Cloudflare Turnstile cookie on the signup
page to block automated registrations. We use no advertising or tracking cookies.
11. Children
The platform is for organizational use and we do not provide accounts to anyone under
eighteen.
12. Changes to this policy
When we change it we update the effective date above, and subscribers get thirty days'
email notice of any material change.
13. Complaints
Write to us first at [email protected]. You always retain the right
to complain to the Personal Data Protection Council in the Hashemite Kingdom of Jordan.