هذه السياسة توضح كيفية قيام مؤسسة زياد ناصر الوشمي للتجارة، سجل تجاري رقم 7053851809، بصفتها الجهة المشغلة لتطبيق Provatto، بجمع البيانات الشخصية ومعالجتها وحفظها والإفصاح عنها وحمايتها عند استخدام التطبيق أو الخدمات المرتبطة به، وذلك وفقًا لنظام حماية البيانات الشخصية في المملكة العربية السعودية والأنظمة ذات الصلة.
1) من نحن
Provatto تطبيق يتيح للمستخدمين إنشاء سجل رقمي للساعات والمقتنيات ذات الصلة، وإدارة البيانات المرتبطة بها، وتوثيق بعض الوقائع والأحداث المتعلقة بها داخل التطبيق، بما في ذلك تسجيل انتقال السجل الرقمي بين الحسابات عند طلب المستخدم وموافقة الطرف الآخر.
2) نطاق هذه السياسة
تنطبق هذه السياسة على البيانات الشخصية التي نجمعها من المستخدمين عند إنشاء الحساب أو استخدام التطبيق أو التواصل معنا أو استخدام وظائف التطبيق المختلفة. كما تنطبق على البيانات التي نجمعها من الغير في الحدود التي يجيزها النظام وعند وجود مسوغ نظامي لذلك.
3) البيانات التي نجمعها
قد نجمع الفئات الآتية من البيانات الشخصية بحسب طبيعة الاستخدام:
- بيانات الحساب والتواصل: الاسم، البريد الإلكتروني، رقم الجوال، المدينة، اسم المستخدم، وبيانات التحقق من الحساب.
- بيانات السجل الرقمي للمقتنيات: العلامة، الموديل، الرقم المرجعي، الرقم التسلسلي، سعر الشراء، تاريخ الشراء، الصور، الملاحظات، وسجل الأحداث المرتبط بالمقتنى.
- بيانات المعاملات داخل التطبيق: بيانات طلبات تسجيل انتقال السجل الرقمي، وحالة القبول أو الرفض، والوقت والتاريخ، وهوية الحسابات المعنية بالعملية.
- البيانات التقنية: عنوان بروتوكول الإنترنت، معرف الجهاز أو التطبيق، نوع الجهاز، نظام التشغيل، سجلات الدخول، أوقات الوصول، بيانات الأعطال، وسجلات الاستخدام التقنية بالقدر اللازم لتشغيل التطبيق وأمنه.
- بيانات التواصل والدعم: أي معلومات يزودنا بها المستخدم عند التواصل معنا للاستفسار أو طلب الدعم أو تقديم شكوى أو ممارسة حقوقه النظامية.
4) طريقة جمع البيانات
- مباشرة من المستخدم عند إنشاء الحساب أو تعبئة الحقول أو رفع الصور أو تحديث السجل الرقمي أو التواصل معنا.
- تلقائيًا عبر التطبيق والأنظمة التقنية المرتبطة به عند الاستخدام، مثل السجلات التقنية وبيانات الأعطال.
- من مستخدم آخر في نطاق محدود عند استخدام وظيفة تسجيل انتقال السجل الرقمي، في الحدود اللازمة لتنفيذ الوظيفة ووفق المسوغ النظامي المناسب.
5) الأغراض التي نعالج البيانات من أجلها
- إنشاء الحساب وتسجيل الدخول وإدارة هوية المستخدم.
- تشغيل التطبيق وتمكين المستخدم من إنشاء وإدارة السجل الرقمي للمقتنيات.
- تنفيذ الوظائف التي يطلبها المستخدم، بما في ذلك تسجيل الأحداث وطلبات تسجيل انتقال السجل الرقمي.
- التحقق من أمن الحسابات ومنع إساءة الاستخدام أو الاحتيال أو الوصول غير المشروع.
- تقديم الدعم الفني وخدمة العملاء ومعالجة الشكاوى والطلبات.
- تطوير التطبيق وتحسين الأداء وتجربة المستخدم.
- الامتثال للالتزامات النظامية والطلبات الصادرة من الجهات المختصة.
- إرسال الإشعارات التشغيلية المتعلقة بالحساب أو الخدمة أو الأمان أو التحديثات الجوهرية.
- إرسال مواد تسويقية أو ترويجية فقط في الأحوال التي يجيزها النظام وبعد الحصول على الموافقة عندما تكون مطلوبة نظامًا.
6) الأساس النظامي لمعالجة البيانات
- موافقة صاحب البيانات الشخصية، عندما تكون الموافقة مطلوبة وفقًا لنظام حماية البيانات الشخصية.
- تنفيذ اتفاق يكون صاحب البيانات طرفًا فيه، أو اتخاذ خطوات سابقة على التعاقد بناءً على طلبه، وفقًا للمادة السادسة من النظام.
- تحقيق مصلحة مشروعة لجهة التحكم، ما لم يخل ذلك بحقوق صاحب البيانات، وفقًا للمادتين العاشرة والخامسة عشرة من النظام.
- الامتثال لالتزام نظامي أو طلب صادر من جهة مختصة.
7) الحد الأدنى من البيانات
نلتزم بأن يكون محتوى البيانات الشخصية ملائمًا ومقصورًا على الحد الأدنى اللازم لتحقيق الغرض من جمعها ومعالجتها، وفقًا للمادة الحادية عشرة من نظام حماية البيانات الشخصية.
8) دقة البيانات
يجب على المستخدم تزويدنا ببيانات صحيحة ودقيقة ومحدثة. ونقوم باتخاذ الخطوات المعقولة للتحقق من دقة البيانات، وفقًا للمادة الرابعة عشرة من النظام.
9) الإفصاح عن البيانات الشخصية
- لمزودي الخدمات التقنية الذين يعالجون البيانات نيابة عنا لتشغيل التطبيق أو استضافته أو دعمه الفني، وفقًا للمادة الثامنة من النظام.
- للطرف الآخر في عملية تسجيل انتقال السجل الرقمي، بالقدر اللازم لتنفيذ الوظيفة.
- إذا طلبت ذلك أو وافقت عليه وفقًا للنظام.
- إذا كان الإفصاح لازمًا امتثالًا لالتزام نظامي أو طلب صادر من جهة مختصة.
- إذا كان الإفصاح ضروريًا لحماية حقوقنا النظامية أو أمن التطبيق أو المستخدمين أو منع الاحتيال، في الحدود التي يجيزها النظام.
ولا نبيع البيانات الشخصية للغير، ولا نفصح عنها لأغراض غير مصرح بها أو غير مسموح بها نظامًا.
10) نقل البيانات خارج المملكة
قد تتم استضافة بعض البيانات أو معالجتها داخل المملكة أو خارجها من خلال مزودي خدمات تقنيين. وإذا جرى نقل البيانات إلى خارج المملكة، فإن ذلك يتم وفقًا للمادة التاسعة والعشرين من النظام، بما يشمل: أن يكون النقل لغرض مشروع ومحدد؛ وألا يمس الأمن الوطني أو مصالح المملكة الحيوية؛ وأن يتوافر مستوى مناسب للحماية؛ وأن يقتصر على الحد الأدنى اللازم؛ وأن تتخذ التدابير التعاقدية والتنظيمية والتقنية المناسبة.
11) مزودو المعالجة والخدمات التقنية
قد نستعين بجهات معالجة أو مزودي خدمات للاستضافة السحابية أو قواعد البيانات أو دعم البنية التحتية. ونلتزم باختيار الجهات التي توفر الضمانات اللازمة، وفقًا للمادة الثامنة من النظام، دون أن يخل ذلك بمسؤوليتنا تجاه أصحاب البيانات.
12) الاحتفاظ بالبيانات
نحتفظ بالبيانات طوال المدة اللازمة لتحقيق الأغراض المبينة، وعند انتهاء الغرض نقوم بإتلافها دون تأخير غير مبرر وفقًا للمادة الثامنة عشرة من النظام، ما لم يوجد مسوغ نظامي للاحتفاظ. وعند طلب حذف الحساب، نسعى لتنفيذ الحذف خلال مدة لا تتجاوز 30 يومًا، ما لم يكن الاحتفاظ لازمًا نظامًا أو تقنيًا أو بسبب نزاع قائم.
13) كيفية إتلاف البيانات
عند انتهاء الحاجة إلى البيانات، نتخذ الإجراءات المناسبة لإتلافها أو إزالة ما يؤدي إلى معرفة صاحبها، بما يمنع الوصول غير المشروع إليها أو استعادتها.
14) حماية البيانات وأمنها
نتخذ تدابير تنظيمية وإدارية وتقنية مناسبة لحماية البيانات من الفقد أو الإساءة أو الوصول غير المصرح به أو التعديل أو الإفصاح غير المشروع، وفقًا للمادة التاسعة عشرة من النظام، بما في ذلك التحكم في الصلاحيات وحماية الحسابات والتشفير ومراقبة الوصول وإدارة الحوادث الأمنية.
15) الإخطار بالحوادث الأمنية
إذا علمنا بوقوع تسرب أو تلف أو وصول غير مشروع للبيانات بما قد يترتب عليه ضرر، فسنتعامل مع ذلك وفقًا للمادة العشرين من النظام، بما في ذلك الإشعار اللازم للجهة المختصة أو لصاحب البيانات متى وجب ذلك نظامًا.
16) حقوق صاحب البيانات الشخصية
- الحق في العلم بالمسوغ النظامي لجمع بياناته والغرض من جمعها.
- الحق في الوصول إلى بياناته الشخصية المتوافرة لدينا.
- الحق في طلب الحصول على بياناته بصيغة مقروءة وواضحة متى كان ذلك ممكنًا نظامًا.
- الحق في طلب تصحيح البيانات أو إتمامها أو تحديثها.
- الحق في طلب إتلاف البيانات التي انتهت الحاجة إليها، دون إخلال بحالات الاحتفاظ النظامية.
- الحق في الرجوع عن الموافقة، دون أن يؤثر ذلك على مشروعية المعالجة السابقة.
- الحق في التقدم بشكوى إلى الجهة المختصة إذا لم تتم معالجة طلبه وفق النظام.
17) كيفية ممارسة الحقوق
وسنبذل العناية للاستجابة للطلبات خلال المدة النظامية، وفقًا للمادة الحادية والعشرين من النظام، مع مراعاة ما قد يرد على بعض الطلبات من قيود أو استثناءات نظامية.
18) التسويق والرسائل
لا نستخدم بيانات الاتصال الخاصة بك لإرسال مواد تسويقية إلا بعد الحصول على الموافقة عندما تكون مطلوبة نظامًا، وفقًا للمادتين الخامسة والعشرين والسادسة والعشرين من النظام. كما نتيح وسيلة واضحة لطلب التوقف في أي وقت.
19) القُصّر
التطبيق مخصص لمن أتم ثماني عشرة سنة هجرية فأكثر. ولا نقبل عن علم إنشاء حسابات لمن هم دون هذا السن، وإذا تبين خلاف ذلك جاز لنا تعليق الحساب أو إغلاقه واتخاذ ما يلزم وفق النظام.
20) الوثائق الرسمية والبيانات الحساسة
لا نطلب عادة رفع الوثائق الرسمية التي تحدد الهوية، ولا يجوز للمستخدم رفعها إلا إذا طلبنا ذلك صراحة لسبب نظامي مشروع. ولا يُفترض بالتطبيق جمع بيانات حساسة، ويجب على المستخدم الامتناع عن إدخال أي بيانات حساسة أو وثائق رسمية أو بيانات تخص الغير دون مسوغ نظامي.
21) بيانات الغير التي يقدمها المستخدم
إذا زودنا المستخدم ببيانات تخص شخصًا آخر، فيجب أن يكون مخولًا نظامًا بإدخالها وأن يكون استخدامها لازمًا لغرض مشروع ومحدد. ويظل المستخدم مسؤولًا عن صحة هذا الإجراء وعن عدم إساءة استخدام بيانات الغير.
22) ملفات السجل والبيانات التقنية
قد نستخدم السجلات التقنية وبيانات الاستخدام المحدودة لأغراض التشغيل والحماية وتحليل الأعطال وقياس الأداء وتحسين الخدمة، ولا تستخدم لغرض لا يتصل بذلك إلا وفق المسوغ النظامي المناسب.
23) التعديلات على هذه السياسة
يجوز لنا تعديل هذه السياسة من وقت إلى آخر. وعند إجراء تعديلات جوهرية سنقوم بإشعار المستخدمين بالوسيلة المناسبة. ويعد استمرار استخدام التطبيق بعد سريان التحديثات قبولًا بها في حدود ما يجيزه النظام.
24) اللغة المعتمدة
حررت هذه السياسة باللغة العربية، وتكون هي المرجع عند الاختلاف في التفسير، ما لم ننشر نسخة أخرى معتمدة وننص على خلاف ذلك.
25) التواصل معنا
This policy explains how Ziad Nasser Alwashmi Trading Est. (Commercial Registration No. 7053851809), as the operator of the Provatto app, collects, processes, stores, discloses, and protects personal data when you use the app or its related services, in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia and related regulations.
1) Who We Are
Provatto is an app that lets users create a digital record for watches and related collectibles, manage the associated data, and document certain facts and events within the app — including recording the transfer of a digital record between accounts at a user's request and with the other party's consent.
2) Scope of This Policy
This policy applies to the personal data we collect from users when creating an account, using the app, contacting us, or using the app's various functions. It also applies to data we collect from third parties within the limits permitted by law and where a legal basis exists.
3) Data We Collect
- Account and contact data: name, email, mobile number, city, username, and account verification data.
- Collectible digital record data: brand, model, reference number, serial number, purchase price, purchase date, photos, notes, and the event log associated with the item.
- In-app transaction data: digital-record transfer request data, acceptance or rejection status, time and date, and the identity of the accounts involved.
- Technical data: IP address, device or app identifier, device type, operating system, access logs, access times, crash data, and technical usage logs necessary to operate and secure the app.
- Communication and support data: any information the user provides when contacting us for inquiries, support, complaints, or to exercise their statutory rights.
4) How We Collect Data
- Directly from the user when creating an account, filling in fields, uploading photos, updating a digital record, or contacting us.
- Automatically through the app and its related technical systems during use, such as technical logs and crash data.
- From another user, in a limited scope, when using the digital-record transfer function, within the limits necessary to carry out the function and per the appropriate legal basis.
5) Purposes of Processing
- Creating an account, signing in, and managing user identity.
- Operating the app and enabling users to create and manage a digital record of their collectibles.
- Carrying out functions requested by the user, including logging events and digital-record transfer requests.
- Verifying account security and preventing misuse, fraud, or unauthorized access.
- Providing technical support and customer service and handling complaints and requests.
- Developing the app and improving performance and user experience.
- Complying with legal obligations and requests from competent authorities.
- Sending operational notifications related to the account, service, security, or material updates.
- Sending marketing materials only where permitted by law and after obtaining consent where legally required.
6) Legal Basis for Processing
- The consent of the data subject, where required under the Personal Data Protection Law.
- Performance of an agreement to which the data subject is a party, or pre-contractual steps at their request, pursuant to Article 6 of the Law.
- The legitimate interest of the controller, provided it does not prejudice the data subject's rights and the data is not sensitive, pursuant to Articles 10 and 15 of the Law.
- Compliance with a legal obligation or a request from a competent authority.
7) Data Minimization
We ensure that personal data is adequate and limited to the minimum necessary to achieve the purpose of its collection and processing, pursuant to Article 11 of the Personal Data Protection Law.
8) Data Accuracy
The user must provide correct, accurate, and up-to-date data. We take reasonable steps to verify data accuracy, pursuant to Article 14 of the Law.
9) Disclosure of Personal Data
- To technical service providers who process data on our behalf to operate, host, or technically support the app, per Article 8 of the Law.
- To the other party in a digital-record transfer process, to the extent necessary to carry out the function.
- If you request or consent to it in accordance with the law.
- Where necessary to comply with a legal obligation or a request from a competent authority.
- Where necessary to protect our legal rights, the security of the app or users, or to prevent fraud, within legal limits.
We do not sell personal data to third parties, nor disclose it for unauthorized or legally impermissible purposes.
10) Transfer of Data Outside the Kingdom
Some personal data may be hosted or processed inside or outside the Kingdom through technical service providers. If data is transferred outside the Kingdom, this is done in accordance with Article 29 of the Law, including: the transfer being for a legitimate, specific purpose; not prejudicing national security or the Kingdom's vital interests; an adequate level of protection being available; the transfer being limited to the minimum necessary; and appropriate contractual, organizational, and technical measures being taken.
11) Processors and Technical Service Providers
We may engage processors or service providers for cloud hosting, database, or infrastructure support. We select entities that provide the necessary guarantees, pursuant to Article 8 of the Law, without prejudice to our responsibility toward data subjects.
12) Data Retention
We retain personal data for as long as necessary to achieve the stated purposes, and when the purpose ends we destroy it without undue delay pursuant to Article 18 of the Law, unless there is a legal basis for retention. Upon an account deletion request, we generally seek to carry out deletion within 30 days, unless retention is legally or technically necessary or due to an existing dispute.
13) How Data Is Destroyed
When data is no longer needed, we take appropriate measures to destroy it or remove what would specifically identify its owner, in a way that prevents unlawful access or recovery.
14) Data Protection and Security
We take appropriate organizational, administrative, and technical measures to protect data from loss, misuse, unauthorized access, alteration, or unlawful disclosure, pursuant to Article 19 of the Law, including access controls, account protection, encryption, access monitoring, and security incident management.
15) Notification of Security Incidents
If we become aware of a leak, damage, or unlawful access to data that may cause harm, we will handle it in accordance with Article 20 of the Law, including the necessary notification to the competent authority or the data subject where legally required.
16) Rights of the Data Subject
- The right to be informed of the legal basis and purpose for collecting their data.
- The right to access their personal data held by us.
- The right to request their data in a readable, clear format where legally possible.
- The right to request correction, completion, or updating of the data.
- The right to request destruction of data no longer needed, without prejudice to statutory retention cases.
- The right to withdraw consent, without affecting the lawfulness of prior processing.
- The right to file a complaint with the competent authority if their request is not handled per the law.
17) How to Exercise Rights
We will exercise due care to respond within the statutory period, pursuant to Article 21 of the Law, taking into account any legal restrictions or exceptions.
18) Marketing and Messages
We do not use your contact data to send marketing materials except after obtaining consent where legally required, pursuant to Articles 25 and 26 of the Law. We also provide a clear means to stop these messages at any time.
19) Minors
The app is intended for those who are eighteen (Hijri) years or older. We do not knowingly allow accounts for those under this age, and if it becomes clear otherwise we may suspend or close the account and take necessary action per the law.
20) Official Documents and Sensitive Data
We do not normally request the uploading of official identity documents, and the user may not upload them unless we explicitly request so for a legitimate legal reason. The app is not intended to collect sensitive data, and the user must refrain from entering any sensitive data, official documents, or third-party data without a legal basis.
21) Third-Party Data Provided by the User
If the user provides data relating to another person, they must be legally authorized to enter it, and its use must be necessary for a legitimate, specific purpose. The user remains responsible for the correctness of this action and for not misusing third-party data.
22) Log Files and Technical Data
We may use technical logs and limited usage data for operation, protection, crash analysis, performance measurement, and service improvement, and it is not used for any unrelated purpose except under the appropriate legal basis.
23) Amendments to This Policy
We may amend this policy from time to time. When making material amendments, we will notify users by an appropriate means. Continued use of the app after updates take effect constitutes acceptance within the limits permitted by law.
24) Governing Language
This policy was drafted in Arabic, which is the reference in case of any difference in interpretation, unless we publish another approved version and stipulate otherwise.