ننصيح legal@naseeh.io

NASEEH · LEGAL POLICY

إضافة معالجة بيانات نصيح

شروط معالجة بيانات العميل التجاري عندما تدمج هذه الإضافة في اتفاق ملزم.

سارية من 27 يوليو 2026Version 2026-07-30.6

مهم: هذه الوثيقة توزع المخاطر وتحمي مقدم خدمة صغير يعتمد على مزودي ذكاء اصطناعي وسحابة خارجيين. Important: this document allocates risk for a small provider dependent on external AI and cloud vendors.

01

التطبيق وعدم الانفصال

تطبق هذه الإضافة فقط إذا دمجتها الشروط التجارية أو طلب شراء أو اتفاق موقع وكان نصيح يعالج بيانات شخصية نيابةً عن العميل. لا يؤدي فتح الصفحة أو استخدامها وحده إلى تكليف معالجة أو ضمان أو اتفاق مستقل. تسود الاتفاقية الموقعة عند التعارض.

02

التعاريف والأدوار

يقصد ببيانات العميل الشخصية البيانات الشخصية داخل بيانات العميل، وبالقانون قوانين حماية البيانات المطبقة على المعالجة. العميل هو المتحكم أو المعالج المفوض من متحكم، ونصيح هو المعالج أو المعالج الفرعي لذلك النطاق. لا يشمل ذلك معالجة نصيح كمتحكم مستقل للفوترة والأمان والامتثال.

03

تفاصيل المعالجة

الموضوع هو تقديم خدمة الذكاء الاصطناعي والبحث وإدارة العمل والدعم خلال مدة الاتفاق وما يلزم للحذف أو الامتثال. الطبيعة تشمل الاستضافة والتنظيم والاسترجاع والتحليل والتوليد والنقل والحذف. الفئات وأصحاب البيانات يحددهم العميل بحسب ما يرسله، وقد تشمل مستخدمين وموظفين وعملاء وموكلين وأطراف قضايا.

04

تعليمات العميل

نعالج وفق التعليمات الموثقة في الاتفاق واستخدام العميل المشروع والإعدادات، بما في ذلك النقل للمزودين اللازمين، ما لم يفرض القانون معالجة أخرى. يبلغنا العميل بالتعليمات غير المشروعة، ويجوز لنا رفض أو تعليق تعليمات نعتقد أنها مخالفة أو غير قابلة تقنياً أو توسع النطاق أو التكلفة دون اتفاق.

05

التزامات العميل

يضمن العميل قانونية التعليمات والبيانات والأساس والإشعارات والموافقات والتقليل والدقة والاحتفاظ، وأن لديه سلطة تعيين نصيح والمعالجين الفرعيين. يحدد العميل ما إذا كانت الخدمة مناسبة لفئات حساسة أو منظمة ويجري تقييمات الأثر المطلوبة. لا يرسل بيانات محظورة في طلب أو سياسة.

06

السرية والأفراد

نقصر الوصول إلى الأفراد الذين يحتاجونه لتقديم الخدمة أو حمايتها أو دعمها، ونلزمهم بسرية مناسبة. قد يتم الوصول الآلي أو البشري المحدود للتحقيق في أمان أو دعم أو إساءة أو وفق تعليمات العميل والقانون.

07

التدابير الأمنية

نحافظ على تدابير تقنية وتنظيمية معقولة ومتناسبة مع المخاطر وطبيعة الخدمة، مثل ضوابط الوصول والتشفير أثناء النقل والتسجيل والمراقبة وإدارة الثغرات والنسخ الاحتياطي والاستجابة للحوادث. التدابير تتطور ولا تضمن أمناً مطلقاً، ويظل العميل مسؤولاً عن الإعداد والجهاز والمستخدمين والنسخ.

08

المعالجون الفرعيون

يفوض العميل استخدام الشركات التابعة ومزودي النماذج والسحابة والتخزين والبحث والمراقبة والدعم وغيرهم كمعالجين فرعيين. نفرض حماية مناسبة لطبيعة الخدمة، ونبقى مسؤولين عن التزاماتنا التعاقدية لا عن ضمان كل فعل خارجي. يجوز تغيير المزود عند الحاجة التشغيلية أو الأمنية أو القانونية.

09

الاعتراض على معالج فرعي

إذا كان اتفاق العميل يمنحه حق إشعار، يجوز الاعتراض كتابةً لسبب حماية بيانات موثق خلال المهلة المحددة أو 10 أيام من الإشعار. لا يوقف الاعتراض التغيير أو يؤخره. العلاج الوحيد هو إيقاف الميزة المتأثرة أو إنهاء الجزء المتأثر دون رد رسوم.

10

التحويلات الدولية

يفوض العميل المعالجة في كندا والولايات المتحدة ودول المزودين. نستخدم آلية نقل يفرضها القانون عندما تنطبق، مثل شروط تعاقدية أو قرار كفاية، وقد نتخذ تدابير إضافية حسب المخاطر. إذا أصبحت آلية غير صالحة يجوز استبدالها أو تقييد المعالجة دون التزام باستضافة محلية ما لم يذكر طلب موقع.

11

طلبات أصحاب البيانات

يرد العميل على الطلبات بصفته المتحكم. إذا وصلنا طلب يتعلق ببيانات العميل نوجهه إلى العميل حيث يسمح القانون. نقدم مساعدة معقولة عبر وظائف الخدمة أو بمقابل للجهد الإضافي، مع مراعاة طبيعة المعالجة والمعلومات المتاحة، ولا نلتزم ببناء وظيفة جديدة.

12

الحوادث الأمنية

نبلغ نقطة اتصال العميل دون تأخير غير مبرر بعد تأكيد حادث أمني يتعلق ببيانات العميل عندما يفرض القانون أو الاتفاق ذلك، ونقدم المعلومات المتاحة بصورة معقولة. لا يعد الإبلاغ إقراراً بالخطأ أو المسؤولية. العميل مسؤول عن تقييم وإشعار الجهات والأشخاص، ولا نتحمل تأخراً سببه تحقيق أو مزود أو أمر قانوني.

13

التقييمات والسلطات

نقدم معلومات معقولة متاحة للعميل لإثبات الامتثال، مع حماية سرية وأمان ومعلومات العملاء الآخرين. إذا لم تكف المستندات وكان القانون يفرض تدقيقاً، يتفق الطرفان على نطاق ووقت ومدقق مستقل، مرة سنوياً عادةً، وعلى نفقة العميل ودون اختبار اختراق أو وصول إلى أنظمة مشتركة.

14

طلبات الحكومة

نراجع الطلبات الحكومية المتعلقة ببيانات العميل ونقاوم الطلب غير الصالح حيث نرى أساساً معقولاً، ونقصر الإفصاح بصورة مناسبة. قد نبلغ العميل إذا سمح القانون وكان ذلك عملياً. لا نضمن نجاح الاعتراض ولا نتحمل مسؤولية إفصاح مطلوب قانوناً أو إجراء مزود وفق قانون منطبق.

15

الحذف والإرجاع

عند انتهاء الخدمة نحذف أو نعيد بيانات العميل وفق وظائف الخدمة والاتفاق والتعليمات القانونية، مع استثناء النسخ الاحتياطية والسجلات والاحتفاظ القانوني والأمني إلى انتهاء دوراتها. العميل مسؤول عن التصدير قبل الانتهاء. لا نضمن تنسيقاً خاصاً أو استعادة بعد الحذف إلا بمقابل واتفاق.

16

بيانات عالية الحساسية

لا يجوز إرسال بيانات صحية منظمة أو بطاقات كاملة أو أسرار حكومية مصنفة أو بيانات بيومترية أو فئات أخرى شديدة التنظيم ما لم يسمح طلب موقع ويحدد الضوابط. لا يؤدي قبول تقني لملف إلى موافقة على فئته، ويجوز عزله أو حذفه أو تعليق الحساب.

17

المسؤولية

تخضع هذه الإضافة لإخلاءات الضمان وحدود المسؤولية والاستثناءات والتعويض في الاتفاق، ولا تنشئ حداً إضافياً أو مستقلاً ولا توسع العلاج. يتحمل العميل التكاليف الناتجة عن تعليمات أو بيانات أو عدم امتثال من جانبه.

18

التغييرات والتواصل

يجوز تحديث هذه الإضافة لمعالجة قانون أو آلية نقل أو مزود جديد، ويعد نشر النسخة المحدثة إشعاراً كافياً، دون التزام بإشعار إضافي. لا يخفض التحديث الحماية الجوهرية خلال مدة طلب إلا للامتثال أو استبدال آلية أو بموافقة. تواصل عبر privacy@naseeh.io، ولا يعد الرد اتفاقاً مخصصاً ما لم يوقعه ممثل مخول.

Naseeh Data Processing Addendum

Processor terms for Commercial Customer Data when this DPA is incorporated into a binding agreement. Effective July 27, 2026. Version 2026-07-30.6.

01

Application; No Standalone Engagement

This DPA applies only if incorporated by the Commercial Terms, an order, or a signed agreement and Naseeh processes Personal Data for Customer. Viewing or using this page alone creates no processing engagement, warranty, or standalone agreement. A signed agreement controls conflicts.

02

Definitions and Roles

Customer Personal Data means personal data within Customer Data, and Data Protection Law means law applicable to the processing. Customer is controller or a processor authorized by a controller, and Naseeh is processor or subprocessor for that scope. This excludes Naseeh processing as independent controller for billing, security, and compliance.

03

Processing Details

The subject is delivery of AI, search, work management, and support during the agreement and as needed for deletion or compliance. Operations include hosting, organizing, retrieving, analyzing, generating, transmitting, and deleting. Customer determines categories and data subjects through submissions, potentially including users, employees, customers, clients, and matter participants.

04

Customer Instructions

We process under documented instructions in the agreement, lawful Customer use, and settings, including transfers to necessary providers, unless law requires otherwise. Customer must not issue unlawful instructions. We may reject or suspend instructions we believe unlawful, technically infeasible, or outside agreed scope or cost.

05

Customer Obligations

Customer warrants lawful instructions, data, basis, notices, consent, minimization, accuracy, retention, and authority to appoint Naseeh and subprocessors. Customer determines suitability for sensitive or regulated categories and conducts required impact assessments. Customer must not submit data prohibited by an order or policy.

06

Confidentiality and Personnel

We limit access to personnel needing it to provide, protect, or support the service and bind them to appropriate confidentiality. Automated or limited human access may occur for security, support, abuse investigation, Customer instructions, and law.

07

Security Measures

We maintain reasonable technical and organizational measures proportionate to risk and service nature, such as access controls, encryption in transit, logging, monitoring, vulnerability management, backup, and incident response. Controls evolve and do not guarantee absolute security. Customer remains responsible for configuration, devices, users, and copies.

08

Subprocessors

Customer authorizes affiliates and AI-model, cloud, storage, search, monitoring, support, and other providers as subprocessors. We impose protections appropriate to the service and remain responsible for our contractual obligations, not a guarantee of every external act. Providers may change for operational, security, or legal needs.

09

Subprocessor Objection

If Customer’s agreement provides notice rights, Customer may object in writing for documented data-protection reasons within the stated period or 10 days after notice. An objection does not suspend or delay the change. The sole remedy is disabling the affected feature or terminating the affected part without refund.

10

International Transfers

Customer authorizes processing in Canada, the United States, and provider countries. We use a legally required transfer mechanism where applicable, such as contractual clauses or adequacy, and may add risk-based measures. If a mechanism becomes invalid, we may replace it or restrict processing, without a local-hosting duty unless a signed order states one.

11

Data Subject Requests

Customer responds to requests as controller. If we receive a request for Customer Data, we direct it to Customer where law permits. We provide reasonable help through service functions or at cost for additional effort, considering processing nature and available information. We need not build new functionality.

12

Security Incidents

We notify Customer’s contact without undue delay after confirming a Customer Personal Data security incident where law or agreement requires and provide reasonably available information. Notice is not an admission of fault or liability. Customer assesses and notifies regulators and people. We are not responsible for delay caused by investigation, a provider, or legal restriction.

13

Assessments and Authorities

We provide reasonably available information to demonstrate compliance while protecting security, confidentiality, and other customers. If documents are insufficient and law requires an audit, parties agree scope, timing, and an independent auditor, ordinarily once yearly, at Customer expense, without penetration testing or access to shared systems.

14

Government Requests

We review government requests for Customer Data, challenge invalid requests where we see reasonable grounds, and appropriately limit disclosure. We may notify Customer where lawful and practicable. We do not guarantee a challenge succeeds and are not liable for legally required disclosure or provider action under applicable law.

15

Deletion and Return

At service end, we delete or return Customer Data under service functions, agreement, and law, except backup, log, legal, and security retention until cycles complete. Customer must export before termination. We do not promise a custom format or post-deletion restoration absent a paid agreement.

16

Highly Sensitive Data

Do not submit regulated health data, full payment-card data, classified government secrets, biometric data, or other highly regulated categories unless a signed order permits and defines safeguards. Technical acceptance of a file is not approval of its category, and we may isolate or delete it or suspend the account.

17

Liability

This DPA is subject to the agreement’s disclaimers, liability limits, exclusions, and indemnities and creates no additional or separate cap or expanded remedy. Customer bears costs arising from its instructions, data, or noncompliance.

18

Changes and Contact

We may update this DPA for new law, transfer mechanisms, or providers. Publication of the updated version is sufficient notice, and we have no additional-notice obligation. An update will not materially reduce protection during an order term except for compliance, mechanism replacement, or agreement. Contact privacy@naseeh.io. A response is not a custom agreement unless signed by an authorized representative.