ننصيح legal@naseeh.io

NASEEH · LEGAL POLICY

سياسة خصوصية نصيح

كيف نجمع البيانات ونستخدمها ونشاركها ونحتفظ بها، وما الخيارات والحقوق المتاحة.

سارية من 31 يوليو 2026Version 2026-07-31.2

مهم: هذه الوثيقة توزع المخاطر وتحمي مقدم خدمة صغير يعتمد على مزودي ذكاء اصطناعي وسحابة خارجيين. Important: this document allocates risk for a small provider dependent on external AI and cloud vendors.

01

الجهة المسؤولة والنطاق

شركة 10881252 Canada Corporation، تورونتو، أونتاريو، كندا، هي المسؤولة عن بيانات خدمات نصيح الاستهلاكية. عندما يقدم عميل تجاري الخدمة لمستخدميه قد يكون العميل هو المتحكم ونكون معالجاً وفق تعليماته. تغطي السياسة الموقع والتطبيقات والخدمات والدعم، وقد يكملها إشعار ميزة أو اتفاقية أو إضافة معالجة بيانات.

02

بيانات الحساب والاتصال

قد نجمع الاسم والبريد والهاتف وبلد الإقامة واللغة والمؤسسة والدور ومعرفات الحساب وصورة الملف وإعداداته ووسائل المصادقة وسجل القبول والتواصل. إذا أنشأ مسؤول حساباً لك فقد يقدم هذه البيانات. لا ترسل معلومات غير لازمة.

03

المحتوى وبيانات العمل

نجمع ما تختار إدخاله أو رفعه أو إنشاؤه، مثل الأسئلة والتعليمات والمستندات والصور والتسجيلات والملفات وبيانات القضية والعملاء والمخرجات والتعليقات. قد يحتوي المحتوى بيانات شخصية أو مهنية حساسة تخصك أو تخص آخرين، وأنت أو مؤسستك مسؤولان عن الصلاحية والإشعار والتقليل.

04

بيانات الدفع والاشتراك

نجمع الخطة وحالة الفوترة والفواتير والضرائب والعملة وسجل المعاملات ومعرفات مزود الدفع. يعالج مزود الدفع أو متجر التطبيق رقم البطاقة أو الحساب البنكي عادةً وفق سياسته، وقد لا نحتفظ بالبيانات الكاملة. نتلقى معلومات عن نجاح الدفع أو فشله أو النزاع أو الاسترداد.

05

بيانات الاستخدام والجهاز

قد نجمع عناوين IP ونوع الجهاز والنظام والمتصفح وإصدار التطبيق واللغة والمنطقة الزمنية والصفحات والميزات والنقرات والطلبات والأخطاء والأداء ووقت الاستخدام ومعرفات الجلسة والسجل الفني. نستخدمها لتشغيل الخدمة وفهمها وحمايتها وفرض الحدود وحساب التكلفة.

06

بيانات الأمان ومكافحة الإساءة

قد نجمع محاولات الدخول وإشارات الاحتيال وسمعة الشبكة ونتائج التحقق وسجل الأذونات والتنبيهات وعينات لازمة للتحقيق في إساءة أو اختراق أو مخالفة. قد نربط الإشارات عبر الحسابات والأجهزة لحماية المستخدمين والخدمة، مع مراعاة القانون.

07

التحقق من الهوية أو العمر

إذا تطلبت ميزة أو قانون أو مزود التحقق من الهوية أو العمر أو الموقع، فقد نجمع وثيقة أو صورة أو نتيجة تحقق أو دولة أو تاريخ ميلاد بالقدر اللازم. قد يعالج مزود متخصص الصورة أو القياسات الحيوية إن وُجدت، وسنقدم إشعاراً أو موافقة عندما يفرض القانون. لا نجمعها في كل حساب.

08

مصادر البيانات

نحصل على البيانات منك ومن استخدامك، ومن مؤسستك ومسؤوليها، ومن مزودي تسجيل الدخول والدفع والمتاجر والتكاملات، ومن شركاء الدعم والأمان، ومن مصادر عامة أو مرخصة عند استخدام بحث قانوني، ومن جهات حكومية أو أطراف تبلغ عن إساءة أو نزاع.

09

ملفات الارتباط والتقنيات المماثلة

قد تستخدم الخدمة ملفات ارتباط أو تخزيناً محلياً أو معرفات لازمة لتسجيل الدخول والأمان والتفضيلات والقياس. القياس المقيّد بالمحتوى مفعّل افتراضياً لجميع المستخدمين، ولا توفر الخدمة حالياً إعداداً داخل المنتج لإيقافه، ولا تستجيب لإشارات الخصوصية في المتصفح مثل «عدم التتبع» (Do Not Track) أو «التحكم العالمي بالخصوصية» (Global Privacy Control).

10

تقديم الخدمة

نستخدم البيانات لإنشاء الحساب والمصادقة وحفظ العمل وتنفيذ التعليمات وتشغيل البحث والتحليل والتوليد والتكاملات وإدارة الملفات والصلاحيات والفوترة والدعم والتواصل التشغيلي. يعتمد نطاق المعالجة على الميزة التي تختارها وإعدادات الحساب.

11

الأمان والإنفاذ

نستخدم البيانات لاكتشاف ومنع والتحقيق في الاحتيال والاختراق والبرامج الضارة والاستخدام المحظور وتجاوز الحدود، وحماية الحقوق والأشخاص والبنية، وفرض الشروط، واختبار الاعتمادية. قد تتضمن العملية تصنيفاً آلياً ومراجعة بشرية محدودة عند الضرورة.

12

التحسين والبحث

قد نستخدم ملاحظاتك الاختيارية وبيانات الأداء والأعطال والأمان ومقاييس مجمعة أو منزوعة الهوية لتحسين المنتج والمصنفات والنماذج والعمليات. قد نستخدم محتوى خاصاً لتقييم أو تحسين خدمة عندما يسمح إعداد أو اتفاقية أو إشعار أو موافقة أو مصلحة مشروعة أو قانون. تعالج بيانات العميل التجاري وفق شروطه وإضافة المعالجة.

13

الاتصالات والتسويق

نرسل إشعارات الخدمة والأمان والفوترة والتغييرات القانونية التي قد لا يمكن إلغاء الاشتراك منها أثناء بقاء الحساب. قد نرسل تحديثات أو عروضاً وفق القانون واختياراتك، ويمكن إلغاء الرسائل التسويقية عبر رابط الإلغاء الواضح في الرسالة أو عبر privacy@naseeh.io. قد نبقى نتواصل لأسباب غير تسويقية لازمة.

14

التحكم وإلغاء الاشتراك

يمكنك أن تطلب منا عدم استخدام بيانات اتصالك للتسويق، وأن نقتصر على تقديم الخدمة أو المعلومة التي طلبتها. تتضمن أي رسالة تسويقية تجارية نرسلها تعريف المرسل ورابطاً واضحاً لإلغاء الاشتراك. لا نستخدم بيانات Google Ads API لبناء جمهور إعلاني أو لإعادة الاستهداف. لا يوفر Naseeh حالياً إعداداً داخل المنتج لإيقاف القياس المقيّد بالمحتوى ولا يستجيب لإشارات عدم التتبع في المتصفح؛ وحيث يمنحك القانون المنطبق حقاً في إلغاء مشاركة معرفات التحليلات أو الإعلانات يمكنك ممارسته عبر privacy@naseeh.io. ويمكنك أيضاً إدارة تفضيلات الإعلانات أو ملفات الارتباط لدى المزود أو المتصفح عندما ينطبق ذلك.

15

الأسس القانونية

بحسب مكانك والسياق، نعالج لتنفيذ عقد أو اتخاذ خطوات بطلبك، وبموافقة، ولمصالح مشروعة متوازنة مثل تقديم الخدمة والأمان ومنع الاحتيال والتحسين، وللوفاء بالقانون، ولحماية مصالح حيوية، ولإقامة مطالبة أو الدفاع عنها. عندما نعتمد الموافقة يمكنك سحبها للمستقبل، وقد تتوقف الميزة.

16

مزودو الخدمة والمعالجون

نشارك القدر اللازم مع مزودي النماذج والسحابة والاستضافة والتخزين والبحث والمراقبة والأمان والدفع والمتاجر والتحليلات والاتصال والدعم والاستشارات. يعملون وفق عقودهم والقانون، وقد يعالج بعضهم البيانات كمتحكم مستقل لوظائفه. تتغير قائمة المزودين مع تغير الخدمة.

17

التكاملات والإجراءات التي تختارها

عند ربط حساب أو طلب إرسال محتوى أو تنفيذ إجراء، نشارك البيانات مع الطرف الذي اخترته وفق تعليماتك، وقد يستقبل ذلك الطرف معلومات حسابك ومحتواك. تخضع معالجته لسياسته لا لسياسة نصيح. افصل التكامل عندما لا تعود تحتاجه، وقد لا يؤدي الفصل إلى حذف ما أُرسل سابقاً. يلتزم استخدام نصيح ونقله إلى أي تطبيق آخر للمعلومات الواردة من واجهات Google بسياسة بيانات مستخدم خدمات Google API، بما في ذلك متطلبات الاستخدام المحدود.

18

المؤسسة ومسؤولو مساحة العمل

إذا كان الحساب تابعاً لمؤسسة، فقد يصل مسؤولوها إلى ملفك ومحتواك ومخرجاتك وسجل النشاط والتدقيق والفوترة، ويضبطون الصلاحيات والتكاملات والاحتفاظ ويصدرون أو يحذفون البيانات. قد تنقل المؤسسة الحساب أو تعيد تعيينه. راجع سياساتها لأننا لا نتحكم في استخدام المسؤول لبيانات المؤسسة.

19

الإفصاح القانوني والحماية

يجوز حفظ البيانات أو الإفصاح عنها لحكومة أو محكمة أو إنفاذ قانون أو منظم أو طرف آخر عندما نعتقد بحسن نية أن ذلك مطلوب أو مناسب بصورة معقولة للامتثال للقانون أو الإجراء، أو حماية الحقوق والأمان، أو منع ضرر أو احتيال أو جريمة، أو إنفاذ اتفاق، أو التحقيق في مخالفة. قد نمنع الإشعار إذا حظره القانون أو كان خطراً.

20

المعاملات المؤسسية

يجوز مشاركة البيانات مع مستشارين وممولين ومشترين أو خلفاء فعليين أو محتملين في تمويل أو إعادة تنظيم أو اندماج أو بيع أصول أو إفلاس أو نقل للخدمة، مع ضوابط مناسبة للسياق. قد تنتقل البيانات والالتزامات إلى الجهة الخلف.

21

التحويلات الدولية

قد تعالج البيانات في كندا والولايات المتحدة وأي دولة يعمل فيها مزود لازم، وقد تخضع لقوانين ووصول حكومي مختلف. عندما يفرض القانون نستخدم آلية نقل أو شروطاً أو تقييماً مناسباً، لكن لا نضمن بقاء البيانات في دولة بعينها ما لم ينص اتفاق موقع.

22

الاحتفاظ

نحتفظ بالبيانات بقدر الحاجة للغرض والحساب والعقد، وللأمان والنسخ الاحتياطي والتدقيق والفوترة والضرائب والنزاعات والحقوق والامتثال. تختلف المدة حسب النوع والإعداد والقانون، وقد تبقى نسخ محدودة في السجلات والنسخ الاحتياطية والمزودين حتى دورة الحذف. قد نحتفظ ببيانات منزوعة الهوية دون مدة محددة.

23

الحذف وإغلاق الحساب

قد يؤدي طلب الحذف أو إغلاق الحساب إلى فقد الوصول ولا يلغي فوراً كل نسخة. يجوز الاحتفاظ بما يلزم للقانون أو الأمان أو النزاع أو منع الاحتيال أو إثبات المعاملة، وبما يخص المؤسسة وفق تعليماتها، وبالبيانات المجمعة أو المنزوعة الهوية. لا يمكن استرجاع محتوى حُذف نهائياً، ولا نضمن أداة تصدير دائماً.

24

الأمان وحدوده

نستخدم ضوابط تقنية وتنظيمية معقولة بحسب طبيعة الخدمة، مثل إدارة الوصول والتشفير أثناء النقل والمراقبة والنسخ الاحتياطي والحماية على الحافة والتطبيق. لا توجد وسيلة أو مزود أو نموذج آمن تماماً، ولا نضمن منع كل اختراق أو فقد أو خطأ أو إفصاح. أنت مسؤول عن الجهاز وكلمة المرور والنسخ المستقلة وإعداد الصلاحيات.

25

حقوق الخصوصية

بحسب القانون ودورنا، قد يحق لك معرفة المعالجة والوصول إلى البيانات أو نسخة منها وتصحيحها أو حذفها أو تقييدها أو الاعتراض أو نقلها وسحب الموافقة والشكوى. قد توجه طلب بيانات مؤسسة إلى مؤسستك. يمكننا طلب التحقق وتحديد الطلب ورفض أو تقييد ما يسمح القانون برفضه لحماية الحقوق أو السرية أو الأمان أو الالتزامات.

26

القرارات الآلية

نستخدم الأتمتة للكشف عن الإساءة والأمان وتوجيه الميزات وقد تؤدي إلى حجب أو طلب تحقق. لا نقصد اتخاذ قرار قانوني أو ائتماني أو توظيفي أو طبي نهائي عنك دون مراجعة حيث يفرض القانون. يمكنك طلب مراجعة قرار حساب مؤثر عبر الدعم، لكن لا نضمن إعادة التفعيل إذا استمر الخطر أو الحظر.

27

الأطفال

الخدمة ليست موجهة لمن لا يملك السن القانونية المطلوبة للحساب، ولا نجمع بيانات طفل عن علم دون تفويض أو أساس مناسب. إذا اعتقدت أن طفلاً قدم بيانات على نحو غير مصرح فأبلغ privacy@naseeh.io. قد نغلق الحساب ونحذف أو نعزل البيانات مع مراعاة القانون والالتزامات.

28

كندا والشكاوى

للمستخدمين في كندا نعالج وفق المبادئ والمتطلبات المنطبقة، وقد تكون البيانات متاحة قانوناً لسلطات أجنبية عند معالجتها خارج كندا. يمكنك تقديم سؤال أو شكوى لمسؤول الخصوصية عبر privacy@naseeh.io. سنراجعها وفق القانون، ولا يمنع ذلك حقك في التواصل مع مكتب مفوض الخصوصية الكندي أو جهة مختصة.

29

عدم البيع والإعلانات الموجهة

لا نبيع البيانات الشخصية مقابل المال. قد تعتبر بعض القوانين مشاركة معرفات للتحليلات أو الإعلانات «بيعاً» أو «مشاركة» وتمنح حق الإلغاء؛ وحيثما يمنحك قانون منطبق هذا الحق يمكنك ممارسته عبر privacy@naseeh.io، إذ لا يوجد حالياً إعداد لذلك داخل المنتج. لا نحول الوصف القانوني إلى وعد يتجاوز ما يفرضه القانون.

30

التغييرات

قد نحدّث السياسة عند تغير الخدمة أو المزودين أو القانون أو الممارسة. ننشر الإصدار وتاريخ السريان، وقد نقدم إشعاراً إضافياً للتغيير الجوهري عندما يفرض القانون. إذا تطلب التغيير موافقة فسنطلبها؛ وإلا تسري السياسة المنشورة على المعالجة المستقبلية في التاريخ المحدد.

31

التواصل

للطلبات والأسئلة والشكاوى اكتب إلى privacy@naseeh.io. للدعم support@naseeh.io وللشؤون القانونية legal@naseeh.io. الجهة: 10881252 Canada Corporation، 231 Broadview Ave، تورونتو، أونتاريو M4M 2G3، كندا. قد نطلب معلومات معقولة للتحقق من الهوية والاختصاص والحساب قبل تنفيذ الطلب.

Naseeh Privacy Policy

How we collect, use, share, retain, and protect data, and the choices and rights available. Effective July 31, 2026. Version 2026-07-31.2.

01

Controller and Scope

10881252 Canada Corporation of Toronto, Ontario, Canada controls data for Naseeh consumer services. Where a commercial customer provides the service to users, that customer may be controller and we may process under its instructions. This Policy covers the website, apps, service, and support and may be supplemented by a feature notice, agreement, or DPA.

02

Account and Contact Data

We may collect name, email, phone, country, language, organization, role, account identifiers, profile image and settings, authentication methods, acceptance records, and communications. An administrator may provide this data when creating an account for you. Do not submit unnecessary information.

03

Content and Work Data

We collect what you choose to enter, upload, or create, such as questions, instructions, documents, images, recordings, files, matter and client data, outputs, and comments. Content may contain sensitive personal or professional information about you or others. You or your organization is responsible for authority, notice, and minimization.

04

Payment and Subscription Data

We collect plan, billing status, invoices, taxes, currency, transaction history, and payment-provider identifiers. A payment provider or app store typically processes the full card or bank number under its policy, and we may not hold it. We receive payment success, failure, dispute, and refund information.

05

Usage and Device Data

We may collect IP address, device, operating system, browser, app version, language, time zone, pages, features, clicks, requests, errors, performance, usage time, session identifiers, and technical logs. We use these to operate, understand, secure, meter, and cost the service.

06

Security and Abuse Data

We may collect login attempts, fraud signals, network reputation, verification results, permission history, alerts, and samples needed to investigate abuse, compromise, or violations. We may correlate signals across accounts and devices to protect users and the service, subject to law.

07

Identity or Age Verification

If a feature, law, or provider requires identity, age, or location verification, we may collect a document, image, verification result, country, or date of birth as necessary. A specialist may process an image or biometric measurement if used, with notice or consent where law requires. This is not collected for every account.

08

Data Sources

We receive data from you and your use, your organization and administrators, sign-in, payment, app-store, and integration providers, support and security partners, public or licensed sources used by legal search, and government or other parties reporting abuse or disputes.

09

Cookies and Similar Technologies

The service may use cookies, local storage, or identifiers needed for sign-in, security, preferences, and measurement. Content-blind analytics is enabled by default for all users; the service does not currently offer an in-product setting to turn it off and does not respond to browser privacy signals such as Do Not Track or Global Privacy Control.

10

Providing the Service

We use data to create and authenticate accounts, preserve work, follow instructions, run search, analysis, generation, integrations, files, permissions, billing, support, and operational communications. Processing scope depends on selected features and account settings.

11

Security and Enforcement

We use data to detect, prevent, and investigate fraud, compromise, malware, prohibited use, and limit evasion; protect rights, people, and infrastructure; enforce terms; and test reliability. This may include automated classification and limited human review where necessary.

12

Improvement and Research

We may use optional feedback, performance, failure, and security data, and aggregated or de-identified metrics to improve products, classifiers, models, and operations. We may use private content to evaluate or improve a service where an account setting, agreement, notice, consent, legitimate interest, or law permits. Commercial Customer Data follows its terms and DPA.

13

Communications and Marketing

We send service, security, billing, and legal-change notices that may be non-optional while an account remains open. We may send updates or offers under law and your choices. Marketing messages can be unsubscribed through the clear link in the message or by emailing privacy@naseeh.io. Necessary non-marketing contact may continue.

14

Control and Opt-Out Rights

You may ask us not to use your contact details for marketing and to limit contact to the service or information you requested. Any commercial marketing email we send identifies the sender and includes a clear unsubscribe link. We do not use Google Ads API data to build advertising audiences or retarget people. Naseeh does not currently provide an in-product control to disable content-blind measurement and does not respond to browser Do Not Track signals; where applicable law gives you a right to opt out of analytics or advertising-identifier sharing, you may exercise it through privacy@naseeh.io. You may also manage advertising or cookie preferences through the relevant provider or browser where applicable.

15

Legal Bases

Depending on location and context, we process to perform a contract or take requested steps, with consent, for balanced legitimate interests such as service delivery, security, fraud prevention, and improvement, to comply with law, protect vital interests, and establish or defend claims. Where consent applies, it may be withdrawn prospectively and the feature may stop.

16

Service Providers and Processors

We share what is needed with AI-model, cloud, hosting, storage, search, monitoring, security, payment, app-store, analytics, communications, support, and professional providers. They operate under contracts and law, and some may be independent controllers for their functions. The provider list changes as the service changes.

17

Chosen Integrations and Actions

When you connect an account or direct content or an action, we share data with the selected party under your instruction, and it may receive account information and content. Its processing follows its policy, not this Policy. Disconnect when no longer needed; disconnection may not delete data already sent. Naseeh’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

18

Organization and Workspace Administrators

If an organization controls the account, administrators may access profile, content, outputs, activity, audit, and billing records; configure permissions, integrations, and retention; and export or delete data. The organization may transfer or reassign the account. Review its policies because we do not control administrator use of organization data.

19

Legal Disclosure and Protection

We may preserve or disclose data to government, court, law enforcement, regulator, or another party where we believe in good faith it is required or reasonably appropriate to comply with law or process, protect rights and safety, prevent harm, fraud, or crime, enforce an agreement, or investigate a violation. Notice may be withheld where prohibited or risky.

20

Corporate Transactions

Data may be shared with advisers, financiers, and actual or potential purchasers or successors in financing, reorganization, merger, asset sale, insolvency, or service transfer, with context-appropriate safeguards. Data and obligations may transfer to a successor.

21

International Transfers

Data may be processed in Canada, the United States, and any country where a necessary provider operates, under different laws and government access. Where required, we use an appropriate transfer mechanism, terms, or assessment. We do not promise data stays in a particular country unless a signed agreement says so.

22

Retention

We retain data as needed for purpose, account, contract, security, backup, audit, billing, tax, disputes, rights, and compliance. Periods vary by type, setting, and law. Limited copies may remain in logs, backups, and providers until deletion cycles complete. De-identified data may be retained indefinitely.

23

Deletion and Account Closure

Deletion or closure may end access and does not instantly erase every copy. We may retain what is needed for law, security, disputes, fraud prevention, transaction proof, organization instructions, and aggregated or de-identified data. Permanently deleted content may be unrecoverable, and we do not promise an export tool is always available.

24

Security and Its Limits

We use reasonable technical and organizational controls appropriate to the service, such as access management, encryption in transit, monitoring, backups, and edge and application protection. No method, provider, or model is perfectly secure, and we do not guarantee prevention of every breach, loss, error, or disclosure. You are responsible for devices, passwords, independent copies, and permissions.

25

Privacy Rights

Depending on law and our role, you may have rights to know, access, copy, correct, delete, restrict, object, port, withdraw consent, and complain. Organization-data requests may be directed to the organization. We may verify identity, clarify scope, and deny or limit requests where law permits to protect rights, confidentiality, security, or obligations.

26

Automated Decisions

We use automation for abuse detection, security, and feature routing, which may result in blocking or verification. We do not intend to make a final legal, credit, employment, or health decision about you without review where law requires. You may request review of a material account decision through support, but reinstatement is not guaranteed where risk or restriction remains.

27

Children

The service is not directed to anyone below the legal age for an account, and we do not knowingly collect child data without appropriate authority or basis. If you believe a child submitted data without authorization, contact privacy@naseeh.io. We may close the account and delete or isolate data subject to law and obligations.

28

Canada and Complaints

For Canadian users, we process under applicable principles and requirements. Data processed outside Canada may be lawfully accessible to foreign authorities. Questions or complaints may be sent to the Privacy Officer at privacy@naseeh.io. We will review under law, without limiting the right to contact the Office of the Privacy Commissioner of Canada or another competent authority.

29

No Sale and Targeted Advertising

We do not sell personal data for money. Some laws may characterize certain analytics or advertising identifier sharing as a sale or sharing and provide opt-out rights; where an applicable law grants you that right, you may exercise it through privacy@naseeh.io, as no in-product setting currently exists. This legal label is not a promise beyond applicable law.

30

Changes

We may update this Policy as the service, providers, law, or practices change. We publish the version and effective date and may give additional notice of a material change where required. If consent is required, we will request it; otherwise the posted Policy applies prospectively on the stated date.

31

Contact

Send requests, questions, and complaints to privacy@naseeh.io. Contact support@naseeh.io for support and legal@naseeh.io for legal matters. Entity: 10881252 Canada Corporation, 231 Broadview Ave, Toronto, Ontario M4M 2G3, Canada. We may request reasonable information to verify identity, jurisdiction, and account before acting.