📍

Tbseem

Legal الشؤون القانونية
Privacy Policy سياسة الخصوصية Terms of Service شروط الخدمة Data Processing Agreement اتفاقية معالجة البيانات

Data Processing Agreement

Policy version 2026-07-25 · effective from the date above.

1. Parties and roles

This Data Processing Agreement (DPA) is between the company subscribed to Tbseem ("the Customer," acting as data controller for its employees' personal data) and Tbseem ("the Processor"). It supplements the Terms of Service and describes how the Processor handles personal data on the Customer's behalf, consistent with Saudi Arabia's Personal Data Protection Law (PDPL).

2. Subject matter and duration

The Processor processes the personal data described in the Privacy Policy (employee name, contact details, invite codes, attendance timestamps, check-in and location data, device push tokens, and task records) for the duration of the Customer's subscription, plus the retention periods described in that Privacy Policy.

3. Processing only on instructions

The Processor will process personal data only on the Customer's documented instructions, which are given by configuring and using the app as intended (for example, turning on live location tracking, assigning tasks, or inviting employees). The Processor will not use the data for any purpose of its own, including marketing, profiling, or resale, and will inform the Customer if it believes an instruction would violate the PDPL or other applicable law.

4. Confidentiality

The Processor ensures that anyone authorized to process the data (employees or contractors of Tbseem) is bound by an obligation of confidentiality, whether contractual or statutory.

5. Security measures

The Processor maintains reasonable technical and organizational measures appropriate to the risk, including:

  • Per-tenant data isolation enforced at the database layer, so one company's data is never visible to another
  • Role-based access control (employee, supervisor, admin, superadmin), enforced server-side
  • Encryption in transit for all data sent to and from the app
  • Automatic deletion of location data after the two-year retention period described in the Privacy Policy
  • When an individual user's account is deleted, access is removed immediately; their personal data (profile, push token, live-location cache, location-ping history) is permanently erased 90 days later; their attendance and check-in records are retained for the Customer's own payroll and audit purposes, with personal identifiers stripped from those records 90 days after deletion (see Privacy Policy Section 5)
  • The database (Firestore) holding attendance, check-in, and location records runs on Google Cloud infrastructure in the Dammam region (me-central2), inside Saudi Arabia
  • Reliance on Google Firebase's infrastructure-level security (access controls, encryption at rest, and Google's own compliance program) for authentication, file storage, and app hosting, which are operated by Google globally rather than pinned to the Dammam region

6. Sub-processors

The Customer authorizes the Processor to engage the following sub-processors:

Sub-processorFunctionLocation
Google FirebaseDatabase (Firestore): attendance, check-in, and location recordsDammam, Saudi Arabia (me-central2)
Google FirebaseAuthentication (sign-in)Global Google service, not pinned to a single region
Google FirebaseFile storage and app/dashboard hostingGoogle-managed infrastructure
Google Cloud FunctionsInvite-code verification at sign-upUnited States (us-central1)
SentryCrash and error reportingOutside Saudi Arabia
ExpoPush notification deliveryOutside Saudi Arabia

The Processor remains responsible for each sub-processor's compliance with obligations equivalent to this DPA. If the Processor intends to add or replace a sub-processor, it will update the Privacy Policy's sub-processor list and, where the change is material, make a reasonable effort to notify the Customer in advance.

7. Assisting with data subject requests

Since the Customer is the controller, most data subject requests (access, correction, deletion) should go to the Customer first. Where a request reaches the Processor directly, the Processor will forward it to the Customer promptly and provide reasonable technical assistance to fulfill it, including the account-deletion and data-export functionality already built into the app.

8. Breach notification

If the Processor becomes aware of a personal data breach affecting the Customer's data, it will notify the Customer without undue delay after becoming aware, with the information reasonably available at that time (nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed), so the Customer can meet its own notification obligations to SDAIA and to affected employees under the PDPL.

9. Deletion or return of data on termination

On termination of the subscription, the Processor will, at the Customer's choice, delete or return the Customer's personal data, except where retention is required by applicable law. Location data in particular is deleted automatically after two years regardless of subscription status, per the Privacy Policy.

This is distinct from an individual user's own account deletion (e.g. an employee who leaves and deletes their account while the Customer's subscription continues): that follows the schedule in Privacy Policy Section 5 — access removed immediately, personal data erased 90 days later, and attendance/check-in records retained for the Customer's own recordkeeping with personal identifiers stripped at the same 90-day mark.

10. Governing law

This DPA is governed by the laws of the Kingdom of Saudi Arabia, consistent with the Terms of Service.

11. Contact

Questions about this DPA: support@tbseem.com.

اتفاقية معالجة البيانات

إصدار السياسة 2026-07-25 · سارية اعتباراً من التاريخ أعلاه.

١. الأطراف والأدوار

اتفاقية معالجة البيانات هذه (DPA) مبرمة بين الشركة المشتركة في تبصيم ("العميل"، بصفته المتحكم بالبيانات لبيانات موظفيه الشخصية) وتبصيم ("المعالج"). تكمّل هذه الاتفاقية شروط الخدمة وتصف كيفية تعامل المعالج مع البيانات الشخصية نيابةً عن العميل، بما يتوافق مع نظام حماية البيانات الشخصية السعودي (PDPL).

٢. موضوع الاتفاقية ومدتها

يعالج المعالج البيانات الشخصية الموصوفة في سياسة الخصوصية (اسم الموظف، بيانات التواصل، رموز الدعوة، أوقات الحضور، بيانات الزيارات والموقع، رموز الإشعارات الفورية، وسجلات المهام) طوال مدة اشتراك العميل، بالإضافة إلى فترات الاحتفاظ الموصوفة في تلك السياسة.

٣. المعالجة وفق التعليمات فقط

يعالج المعالج البيانات الشخصية فقط وفق التعليمات الموثقة من العميل، والتي تُمنح من خلال إعداد واستخدام التطبيق كما هو مقصود (مثل تفعيل تتبع الموقع المباشر، إسناد المهام، أو دعوة الموظفين). لن يستخدم المعالج البيانات لأي غرض خاص به، بما في ذلك التسويق أو التنميط أو إعادة البيع، وسيُبلغ العميل إن اعتقد أن أحد التعليمات يخالف نظام حماية البيانات الشخصية أو أي نظام آخر معمول به.

٤. السرية

يضمن المعالج أن كل من يُصرَّح له بمعالجة البيانات (موظفو أو متعاقدو تبصيم) ملزم بالتزام سرية، سواء تعاقدياً أو نظامياً.

٥. تدابير الأمان

يحافظ المعالج على تدابير تقنية وتنظيمية معقولة تتناسب مع المخاطر، منها:

  • عزل البيانات لكل شركة على مستوى قاعدة البيانات، بحيث لا تظهر بيانات شركة لأخرى أبداً
  • التحكم بالوصول حسب الدور (موظف، مشرف، مدير، مسؤول عام)، مفروض من جانب الخادم
  • تشفير البيانات أثناء النقل لكل البيانات المرسلة من وإلى التطبيق
  • حذف تلقائي لبيانات الموقع بعد فترة الاحتفاظ البالغة سنتين الموصوفة في سياسة الخصوصية
  • عند حذف حساب مستخدم فردي، يُلغى وصوله فوراً؛ تُحذف بياناته الشخصية (الملف الشخصي، رمز الإشعارات، ذاكرة الموقع اللحظي، سجل بيانات التتبع) نهائياً بعد ٩٠ يوماً؛ وتُحفظ سجلات حضوره وزياراته لأغراض الرواتب والتدقيق الخاصة بالعميل، مع إزالة المُعرِّفات الشخصية من تلك السجلات بعد ٩٠ يوماً من الحذف (انظر البند ٥ من سياسة الخصوصية)
  • قاعدة البيانات (Firestore) التي تحتفظ بسجلات الحضور والزيارات والموقع تعمل على بنية تحتية من Google Cloud في منطقة الدمام (me-central2)، داخل المملكة العربية السعودية
  • الاعتماد على أمان البنية التحتية لدى Google Firebase (ضوابط الوصول، التشفير أثناء التخزين، وبرنامج الامتثال الخاص بجوجل) للمصادقة وتخزين الملفات والاستضافة، وهي خدمات تُشغّلها Google عالمياً وليست مرتبطة بمنطقة الدمام

٦. معالجو البيانات من الباطن

يُصرّح العميل للمعالج بالاستعانة بمعالجي البيانات من الباطن التالين:

معالج من الباطنالوظيفةالموقع
Google Firebaseقاعدة البيانات (Firestore): سجلات الحضور والزيارات والموقعالدمام، المملكة العربية السعودية (me-central2)
Google Firebaseالمصادقة (تسجيل الدخول)خدمة عالمية من Google، غير مرتبطة بمنطقة جغرافية واحدة
Google Firebaseتخزين الملفات واستضافة التطبيق/اللوحةبنية تحتية تديرها Google
Google Cloud Functionsالتحقق من رمز الدعوة عند التسجيلالولايات المتحدة الأمريكية (us-central1)
Sentryالإبلاغ عن الأعطال والأخطاءخارج المملكة العربية السعودية
Expoتوصيل الإشعارات الفوريةخارج المملكة العربية السعودية

يبقى المعالج مسؤولاً عن التزام كل معالج من الباطن بالتزامات مماثلة لهذه الاتفاقية. إذا نوى المعالج إضافة أو استبدال معالج من الباطن، فسيحدّث قائمة معالجي الباطن في سياسة الخصوصية، وسيبذل جهداً معقولاً لإشعار العميل مسبقاً إن كان التغيير جوهرياً.

٧. المساعدة في طلبات أصحاب البيانات

بما أن العميل هو المتحكم بالبيانات، فإن معظم طلبات أصحاب البيانات (الوصول، التصحيح، الحذف) يجب أن تُوجَّه إلى العميل أولاً. إذا وصل طلب إلى المعالج مباشرة، فسيحيله إلى العميل فوراً ويقدّم مساعدة تقنية معقولة لتنفيذه، بما في ذلك وظيفتَي حذف الحساب وتصدير البيانات المدمجتين بالفعل في التطبيق.

٨. الإبلاغ عن الاختراقات

إذا علم المعالج باختراق بيانات شخصية يؤثر على بيانات العميل، فسيُبلغ العميل دون تأخير غير مبرر بعد علمه، مع المعلومات المتاحة بشكل معقول في ذلك الوقت (طبيعة الاختراق، فئات وعدد أصحاب البيانات والسجلات المتأثرة تقريباً، النتائج المحتملة، والتدابير المتخذة أو المقترحة)، حتى يتمكن العميل من الوفاء بالتزاماته الخاصة بالإبلاغ لهيئة SDAIA وللموظفين المتأثرين بموجب نظام حماية البيانات الشخصية.

٩. حذف أو إعادة البيانات عند الإنهاء

عند إنهاء الاشتراك، سيقوم المعالج، بحسب اختيار العميل، بحذف أو إعادة بيانات العميل الشخصية، إلا في الحالات التي يتطلب فيها النظام المعمول به الاحتفاظ بها. تُحذف بيانات الموقع تحديداً تلقائياً بعد سنتين بغض النظر عن حالة الاشتراك، وفق سياسة الخصوصية.

يختلف هذا عن حذف مستخدم فردي لحسابه الخاص (مثلاً موظف يغادر الشركة ويحذف حسابه بينما يستمر اشتراك العميل): فذلك يتبع الجدول الموضح في البند ٥ من سياسة الخصوصية — إلغاء الوصول فوراً، وحذف البيانات الشخصية بعد ٩٠ يوماً، مع الاحتفاظ بسجلات الحضور والزيارات لأغراض حفظ سجلات العميل، وإزالة المُعرِّفات الشخصية منها عند نفس علامة ٩٠ يوماً.

١٠. النظام الحاكم

تخضع اتفاقية معالجة البيانات هذه لأنظمة المملكة العربية السعودية، بما يتوافق مع شروط الخدمة.

١١. التواصل

لأي استفسارات حول هذه الاتفاقية: support@tbseem.com.