This Data Processing Agreement (DPA) is between the company subscribed to Tbseem ("the Customer," acting as data controller for its employees' personal data) and Tbseem ("the Processor"). It supplements the Terms of Service and describes how the Processor handles personal data on the Customer's behalf, consistent with Saudi Arabia's Personal Data Protection Law (PDPL).
The Processor processes the personal data described in the Privacy Policy (employee name, contact details, invite codes, attendance timestamps, check-in and location data, device push tokens, and task records) for the duration of the Customer's subscription, plus the retention periods described in that Privacy Policy.
The Processor will process personal data only on the Customer's documented instructions, which are given by configuring and using the app as intended (for example, turning on live location tracking, assigning tasks, or inviting employees). The Processor will not use the data for any purpose of its own, including marketing, profiling, or resale, and will inform the Customer if it believes an instruction would violate the PDPL or other applicable law.
The Processor ensures that anyone authorized to process the data (employees or contractors of Tbseem) is bound by an obligation of confidentiality, whether contractual or statutory.
The Processor maintains reasonable technical and organizational measures appropriate to the risk, including:
The Customer authorizes the Processor to engage the following sub-processors:
| Sub-processor | Function | Location |
|---|---|---|
| Google Firebase | Database (Firestore): attendance, check-in, and location records | Dammam, Saudi Arabia (me-central2) |
| Google Firebase | Authentication (sign-in) | Global Google service, not pinned to a single region |
| Google Firebase | File storage and app/dashboard hosting | Google-managed infrastructure |
| Google Cloud Functions | Invite-code verification at sign-up | United States (us-central1) |
| Sentry | Crash and error reporting | Outside Saudi Arabia |
| Expo | Push notification delivery | Outside Saudi Arabia |
The Processor remains responsible for each sub-processor's compliance with obligations equivalent to this DPA. If the Processor intends to add or replace a sub-processor, it will update the Privacy Policy's sub-processor list and, where the change is material, make a reasonable effort to notify the Customer in advance.
Since the Customer is the controller, most data subject requests (access, correction, deletion) should go to the Customer first. Where a request reaches the Processor directly, the Processor will forward it to the Customer promptly and provide reasonable technical assistance to fulfill it, including the account-deletion and data-export functionality already built into the app.
If the Processor becomes aware of a personal data breach affecting the Customer's data, it will notify the Customer without undue delay after becoming aware, with the information reasonably available at that time (nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed), so the Customer can meet its own notification obligations to SDAIA and to affected employees under the PDPL.
On termination of the subscription, the Processor will, at the Customer's choice, delete or return the Customer's personal data, except where retention is required by applicable law. Location data in particular is deleted automatically after two years regardless of subscription status, per the Privacy Policy.
This is distinct from an individual user's own account deletion (e.g. an employee who leaves and deletes their account while the Customer's subscription continues): that follows the schedule in Privacy Policy Section 5 — access removed immediately, personal data erased 90 days later, and attendance/check-in records retained for the Customer's own recordkeeping with personal identifiers stripped at the same 90-day mark.
This DPA is governed by the laws of the Kingdom of Saudi Arabia, consistent with the Terms of Service.
Questions about this DPA: support@tbseem.com.
اتفاقية معالجة البيانات هذه (DPA) مبرمة بين الشركة المشتركة في تبصيم ("العميل"، بصفته المتحكم بالبيانات لبيانات موظفيه الشخصية) وتبصيم ("المعالج"). تكمّل هذه الاتفاقية شروط الخدمة وتصف كيفية تعامل المعالج مع البيانات الشخصية نيابةً عن العميل، بما يتوافق مع نظام حماية البيانات الشخصية السعودي (PDPL).
يعالج المعالج البيانات الشخصية الموصوفة في سياسة الخصوصية (اسم الموظف، بيانات التواصل، رموز الدعوة، أوقات الحضور، بيانات الزيارات والموقع، رموز الإشعارات الفورية، وسجلات المهام) طوال مدة اشتراك العميل، بالإضافة إلى فترات الاحتفاظ الموصوفة في تلك السياسة.
يعالج المعالج البيانات الشخصية فقط وفق التعليمات الموثقة من العميل، والتي تُمنح من خلال إعداد واستخدام التطبيق كما هو مقصود (مثل تفعيل تتبع الموقع المباشر، إسناد المهام، أو دعوة الموظفين). لن يستخدم المعالج البيانات لأي غرض خاص به، بما في ذلك التسويق أو التنميط أو إعادة البيع، وسيُبلغ العميل إن اعتقد أن أحد التعليمات يخالف نظام حماية البيانات الشخصية أو أي نظام آخر معمول به.
يضمن المعالج أن كل من يُصرَّح له بمعالجة البيانات (موظفو أو متعاقدو تبصيم) ملزم بالتزام سرية، سواء تعاقدياً أو نظامياً.
يحافظ المعالج على تدابير تقنية وتنظيمية معقولة تتناسب مع المخاطر، منها:
يُصرّح العميل للمعالج بالاستعانة بمعالجي البيانات من الباطن التالين:
| معالج من الباطن | الوظيفة | الموقع |
|---|---|---|
| Google Firebase | قاعدة البيانات (Firestore): سجلات الحضور والزيارات والموقع | الدمام، المملكة العربية السعودية (me-central2) |
| Google Firebase | المصادقة (تسجيل الدخول) | خدمة عالمية من Google، غير مرتبطة بمنطقة جغرافية واحدة |
| Google Firebase | تخزين الملفات واستضافة التطبيق/اللوحة | بنية تحتية تديرها Google |
| Google Cloud Functions | التحقق من رمز الدعوة عند التسجيل | الولايات المتحدة الأمريكية (us-central1) |
| Sentry | الإبلاغ عن الأعطال والأخطاء | خارج المملكة العربية السعودية |
| Expo | توصيل الإشعارات الفورية | خارج المملكة العربية السعودية |
يبقى المعالج مسؤولاً عن التزام كل معالج من الباطن بالتزامات مماثلة لهذه الاتفاقية. إذا نوى المعالج إضافة أو استبدال معالج من الباطن، فسيحدّث قائمة معالجي الباطن في سياسة الخصوصية، وسيبذل جهداً معقولاً لإشعار العميل مسبقاً إن كان التغيير جوهرياً.
بما أن العميل هو المتحكم بالبيانات، فإن معظم طلبات أصحاب البيانات (الوصول، التصحيح، الحذف) يجب أن تُوجَّه إلى العميل أولاً. إذا وصل طلب إلى المعالج مباشرة، فسيحيله إلى العميل فوراً ويقدّم مساعدة تقنية معقولة لتنفيذه، بما في ذلك وظيفتَي حذف الحساب وتصدير البيانات المدمجتين بالفعل في التطبيق.
إذا علم المعالج باختراق بيانات شخصية يؤثر على بيانات العميل، فسيُبلغ العميل دون تأخير غير مبرر بعد علمه، مع المعلومات المتاحة بشكل معقول في ذلك الوقت (طبيعة الاختراق، فئات وعدد أصحاب البيانات والسجلات المتأثرة تقريباً، النتائج المحتملة، والتدابير المتخذة أو المقترحة)، حتى يتمكن العميل من الوفاء بالتزاماته الخاصة بالإبلاغ لهيئة SDAIA وللموظفين المتأثرين بموجب نظام حماية البيانات الشخصية.
عند إنهاء الاشتراك، سيقوم المعالج، بحسب اختيار العميل، بحذف أو إعادة بيانات العميل الشخصية، إلا في الحالات التي يتطلب فيها النظام المعمول به الاحتفاظ بها. تُحذف بيانات الموقع تحديداً تلقائياً بعد سنتين بغض النظر عن حالة الاشتراك، وفق سياسة الخصوصية.
يختلف هذا عن حذف مستخدم فردي لحسابه الخاص (مثلاً موظف يغادر الشركة ويحذف حسابه بينما يستمر اشتراك العميل): فذلك يتبع الجدول الموضح في البند ٥ من سياسة الخصوصية — إلغاء الوصول فوراً، وحذف البيانات الشخصية بعد ٩٠ يوماً، مع الاحتفاظ بسجلات الحضور والزيارات لأغراض حفظ سجلات العميل، وإزالة المُعرِّفات الشخصية منها عند نفس علامة ٩٠ يوماً.
تخضع اتفاقية معالجة البيانات هذه لأنظمة المملكة العربية السعودية، بما يتوافق مع شروط الخدمة.
لأي استفسارات حول هذه الاتفاقية: support@tbseem.com.