الشروط والخصوصية

سياسة الخصوصية

كيف يجمع سارب بيانات المكاتب التي تستخدمه وبيانات عملائها، وكيف يستخدمها ويحميها، وفق نظام حماية البيانات الشخصية السعودي.

آخر تحديث: 2026-09-10

النص العربي والإنجليزي متساويان في الحجية. يمكنك عرض النص الإنجليزي لكل قسم من الرابط أسفله. وفي حال تعارض التفسير، يرجّح النص العربي وفقاً للعرف القضائي السعودي.

01المقدمة والنطاق

توضّح سياسة الخصوصية هذه ("السياسة") كيف تُجمع البيانات الشخصية التي تُعالَج عبر منصة سارب ("الخدمة")، وكيف تُستخدم وتُشارك وتُحمى. ويقدّم الخدمة خالد ظافر بن سعد القرني، المرخّص بموجب وثيقة العمل الحر رقم FL-002881762 تحت الاسم التجاري "سارب" ("المزوّد")، وهو الطرف المسؤول عن هذه السياسة. وتنطبق هذه السياسة على المكتب العقاري السعودي المرخّص المشترك في الخدمة ("العميل")، وعلى المستخدمين المفوّضين التابعين له، وعلى عملاء العميل الذين يسجّل العميل بياناتهم على المنصة، وعلى زوّار الصفحات العامة. وقد صدرت هذه السياسة وفقاً لنظام حماية البيانات الشخصية ("النظام") ولائحته التنفيذية ولائحة نقل البيانات الشخصية إلى خارج المملكة (ويُشار إليهما معاً بـ"اللائحة").
النص الإنجليزي: Introduction & Scope
This Privacy Policy (the "Policy") explains how personal data processed through the SARP platform (the "Service") is collected, used, shared and protected. The Service is provided by Khalid Dhafer Saad Alqarni, licensed under Freelance Certificate No. FL-002881762, trading as "SARP" (the "Provider"), who is the party responsible for this Policy. The Policy applies to the licensed Saudi real estate office that subscribes to the Service (the "Customer"), to the Customer's Authorized Users, to the Customer's own clients whose data the Customer records on the Platform, and to visitors of the public pages. It is issued in accordance with the Personal Data Protection Law ("PDPL"), its Implementing Regulations and the Regulation on Personal Data Transfer Outside the Kingdom (together, the "Regulations").

02التعريفات

"البيانات الشخصية" تعني كل بيان، مهما كان مصدره أو شكله، من شأنه أن يؤدي إلى معرفة الفرد على وجه التحديد، أو يجعل التعرّف عليه ممكناً بصفة مباشرة أو غير مباشرة. "جهة التحكم" تعني الجهة التي تحدّد الغرض من معالجة البيانات الشخصية وكيفيتها. وفيما يخص بيانات عملاء العميل (المشترين والبائعين والمستأجرين وملاك العقارات) يُعدّ العميل جهة التحكم. "جهة المعالجة" تعني أي جهة تُعالج البيانات الشخصية لصالح جهة التحكم ونيابةً عنها. ويعمل المزوّد بصفة جهة معالجة لبيانات عملاء العميل التي يحفظها العميل على المنصة، وبصفة جهة تحكم فيما يخص بيانات حسابات المستخدمين المفوّضين وبيانات الفوترة وزوّار الصفحات العامة. "المعالج الفرعي" يعني طرفاً ثالثاً يستعين به المزوّد لمعالجة البيانات نيابةً عنه. "صاحب البيانات" يعني الشخص الذي تخصّه البيانات الشخصية. "سدايا" تشير إلى الهيئة السعودية للبيانات والذكاء الاصطناعي، وهي الجهة المختصّة بتطبيق النظام في المملكة.
النص الإنجليزي: Definitions
"Personal Data" means any data, regardless of source or form - that would lead to identifying an individual specifically, or that makes it possible to identify an individual directly or indirectly. "Controller" means the party that determines the purpose and manner of processing Personal Data. For the Customer's client data (buyers, sellers, tenants, property owners), the Customer is the Controller. "Processor" means any party that processes Personal Data for and on behalf of a Controller. The Provider acts as Processor for the client data the Customer stores on the Platform, and as Controller for the account data of Authorized Users, billing data, and visitors of the public pages. "Sub-processor" means a third party the Provider engages to process data on its behalf. "Data Subject" means the individual to whom the Personal Data relates. "SDAIA" refers to the Saudi Data & AI Authority, the competent authority for the PDPL in the Kingdom.

03البيانات التي نجمعها

نجمع الفئات التالية من البيانات:
  • بيانات المكتب - الاسم النظامي، والاسم بالعربية، ورقم رخصة الهيئة العامة للعقار، والسجل التجاري، والرقم الضريبي، والعنوان.
  • بيانات المستخدمين - الاسم الكامل، والبريد الإلكتروني، ورقم الجوال، والدور (مالك/مدير/وسيط)، وكلمة المرور المشفّرة، وبيانات التحقق بخطوتين.
  • بيانات الطلبات - طلبات الشراء والبيع والإيجار التي يُدخلها المستخدمون، بما في ذلك معلومات التواصل والميزانية وتفضيلات الموقع وحالة التمويل.
  • بيانات العقارات - العناوين والصور والإحداثيات ورموز العنوان الوطني وأرقام الصكوك وبيانات التواصل مع الملاك.
  • خزانة الوثائق - الملفات المرفوعة مثل السجل التجاري ورخصة الهيئة وهوية المفوّض بالتوقيع والصكوك والعقود.
  • سجلات الاستخدام - سجلات الدخول، وعنوان IP، ونوع المتصفح، والطوابع الزمنية، وسجل التدقيق للإجراءات المنفّذة على المنصة.
  • إحصاءات الاستخدام الإجمالية - لكل مكتب، أعداد ومجاميع فقط: عدد العروض، وعدد الطلبات حسب النوع والمرحلة، وعدد الصفقات المسجّلة والمغلقة، وعدد المستخدمين النشطين، وحجم التخزين المستهلك. تُجمع لتشغيل المنصة وتأمينها وتحسينها فقط. ولا نجمع لهذا الغرض سجلات عملاء المكتب على مستوى الأفراد ولا قيم صفقاته ولا عمولاته، ولا يطّلع موظفو المنصة على هذه الإحصاءات إلا في صورتها الإجمالية.
  • نموذج التواصل العام - عند مراسلتنا من صفحة التواصل على sarp-sa.net، نسجّل الاسم واسم المكتب والبريد الإلكتروني ورقم الجوال والرسالة التي تكتبها، إضافةً إلى عنوان IP الذي وردنا منه الطلب لتقييد معدل الإرسال والتحقيق في إساءة الاستخدام فقط، ويُمحى تلقائياً بعد تسعين (90) يوماً (البند الثامن). ويُحمى هذا النموذج بخدمة Cloudflare Turnstile للتحقق من أن المرسل ليس روبوتاً (البند السادس). والمزوّد هو جهة التحكم في هذه البيانات.
  • مشاركة العقارات مع العملاء - قد يرسل إليك مكتب عقاري ملف PDF أو رسالة واتساب بتفاصيل عقار واحد. الملف والرسالة ينشآن في متصفح الوسيط ويصلانك منه مباشرة، ولا يمر أي منهما على خوادم سارب ولا يسجل سارب عنك شيئا عند فتحهما. ولا توجد على سارب صفحات عامة للمكاتب أو العقارات، ولا روابط مشاركة، ولا نماذج طلبات عامة.
  • قناة الدعم عبر واتساب - إذا راسلت رقم دعم سارب على واتساب، نسجّل رقم جوالك واسم ملفك الشخصي ورسائلك وحالة التسليم، لغرض الردّ عليك وتحويلك إلى فريقنا عند طلبك. وهذه القناة مخصّصة للتواصل مع سارب ولا علاقة لها بمساحات عمل المكاتب.
النص الإنجليزي: Data We Collect
We collect the following categories of data:
  • Agency information - legal name, Arabic name, REGA license number, Commercial Registration, VAT number, address.
  • User credentials - full name, email, phone, role (owner / manager / agent), hashed password, multi-factor authentication data.
  • Request data - buyer, seller, and rental requests entered by Authorized Users, including contact details, budget, location preferences, and financing status.
  • Property listings - addresses, photos, coordinates, Saudi National Address codes, title-deed numbers, and owner contact details.
  • Document vault - uploaded files such as CR, REGA license, authorized-signatory ID, title deeds, and contracts.
  • Usage logs - sign-in records, IP address, browser type, timestamps, and audit trail of actions taken on the Platform.
  • Aggregate usage statistics - per agency, counts and totals only: number of listings, number of requests by type and stage, number of deals recorded and closed, number of active users, and storage consumed. Collected solely to operate, secure and improve the Platform. We do not collect the agency's client-level records, transaction values or commission earnings for this purpose, and Platform staff see these statistics in aggregate form only.
  • Public contact form - when you write to us from the contact page on sarp-sa.net, we record the name, agency name, email, phone number and message you type, together with the IP address the submission came from, used only for rate limiting and abuse investigation and erased automatically after ninety (90) days (section 8). The form is protected by Cloudflare Turnstile, which checks that the sender is not a bot (section 6). The Provider is the Controller of this data.
  • Property sharing with clients - an agency may send you a PDF brochure or a WhatsApp message describing a single listing. Both are generated in the agent's browser and reach you directly from the agent; neither passes through SARP's servers and SARP records nothing about you when you open them. SARP has no public agency or listing pages, no share links and no public request forms.
  • WhatsApp support channel - if you message SARP's support number on WhatsApp, we record your phone number, profile name, messages and delivery status, in order to answer you and hand you to our team when you ask. This channel is for contacting SARP and is not connected to any agency's workspace.

04الأساس النظامي للمعالجة

فيما يخص بيانات عملاء العميل، فإن العميل هو جهة التحكم وهو الذي يحدّد الأساس النظامي لمعالجتها وفق النظام، ويعالجها المزوّد نيابةً عنه بناءً على تعليماته الموثّقة تنفيذاً لعقد الخدمة (البند الثامن من شروط الخدمة). أما البيانات التي يكون المزوّد جهة التحكم فيها، فلا نعالجها إلا استناداً إلى أحد الأسس التالية:
  • تنفيذ العقد - لتقديم الخدمة التي اشترك فيها العميل وإدارة حسابات مستخدميه.
  • الالتزام النظامي - للامتثال للأنظمة السعودية، بما فيها لوائح الهيئة العامة للعقار، والأنظمة الضريبية والمحاسبية، ونظام مكافحة غسل الأموال، وأوامر الجهات المختصّة.
  • المصلحة المشروعة - لحماية المنصة، واكتشاف الاحتيال وإساءة الاستخدام، والاحتفاظ بسجل التدقيق، وتطوير المنتج، بما لا يمسّ حقوق أصحاب البيانات.
  • الموافقة - للأنشطة الاختيارية مثل الرسائل التسويقية، ويمكن سحب هذه الموافقة في أي وقت دون أن يؤثر ذلك على مشروعية المعالجة السابقة.
النص الإنجليزي: Lawful Basis for Processing
For the Customer's client data, the Customer is the Controller and determines the lawful basis under the PDPL; the Provider processes that data on the Customer's behalf and documented instructions in performance of the service contract (Clause 8 of the Terms of Service). For data of which the Provider is the Controller, we process only where one of the following bases applies:
  • Performance of a contract - to deliver the Service the Customer has subscribed to and manage its users' accounts.
  • Legal obligation - to comply with Saudi law, including REGA regulations, tax and accounting rules, Anti-Money Laundering rules, and orders from competent authorities.
  • Legitimate interest - to secure the Platform, detect fraud and abuse, maintain audit logs, and improve the product, in a way that does not override Data Subject rights.
  • Consent - for optional activities such as marketing emails, where consent can be withdrawn at any time without affecting the lawfulness of prior processing.

05كيف نستخدم بياناتك

نستخدم البيانات الشخصية للأغراض التالية:
  • تجهيز مساحة العمل الخاصة بالعميل ونطاقه الفرعي، والتحقّق من هوية المستخدمين المفوّضين.
  • تشغيل مسار الطلبات، ومحرك المطابقة الذكي، ونظام المتابعات، ووحدة المزادات، وخزانة الوثائق.
  • إرسال الإشعارات التشغيلية (إعادة تعيين كلمة المرور، والموافقات، وتنبيهات الإسناد، وإشعارات الفواتير).
  • إصدار الفواتير، وحيثما كان المزوّد مسجَّلاً في ضريبة القيمة المضافة، إصدار فواتير ضريبية وفق نظام الفوترة الإلكترونية.
  • مراقبة جاهزية الخدمة، ومعالجة الحوادث، وصدّ أي إساءة استخدام.
  • الاستجابة لطلبات أصحاب البيانات ومساعدة العميل في الاستجابة لها، والالتزام بمتطلبات النظام.
  • تطوير المنصة، باستخدام الإحصاءات الإجمالية المبيّنة في البند الثالث دون غيرها.
ولا نستخدم بيانات عملاء العميل لأي غرض من أغراضنا الخاصة، ولا نبيعها، ولا نُنمّط أصحابها، ولا نستخدمها في التسويق أو في تدريب أي نموذج.
النص الإنجليزي: How We Use Your Data
We use Personal Data to:
  • Provision the Customer's tenant workspace and subdomain, and authenticate Authorized Users.
  • Run the request pipeline, smart-matching engine, follow-up CRM, auctions module, and document vault.
  • Send transactional notifications (password reset, approvals, assignment alerts, billing notices).
  • Issue invoices and, where the Provider is VAT-registered, tax invoices under the e-invoicing regulations.
  • Monitor Service health, investigate incidents, and block abuse.
  • Respond to Data Subject requests, assist the Customer in responding to them, and comply with PDPL obligations.
  • Improve the Platform, using only the aggregate statistics described in section 3.
We never use the Customer's client data for purposes of our own: we do not sell it, profile the individuals, use it for marketing, or use it to train any model.

06المعالجون الفرعيون ومشاركة البيانات

لا نبيع البيانات الشخصية. ونستعين بالمعالجين الفرعيين التالين، ولا غيرهم، لتشغيل الخدمة؛ وكلٌّ منهم ملزَم بالتزامات تعاقدية لحماية البيانات وسرّيتها:
  • Google Cloud (Google LLC / Google Ireland Ltd) - Firebase Authentication وCloud Firestore وCloud Storage وFirebase App Hosting (Cloud Run) وSecret Manager. استضافة المنصة وتشغيلها؛ وحفظ جميع بيانات العميل وحسابات المستخدمين. جميع بيانات العميل، بما فيها البيانات الشخصية لعملاء العميل، وبيانات دخول المستخدمين، والوثائق المرفوعة. (الموقع: البيانات المخزّنة (Cloud Firestore وCloud Storage): منطقة europe-west4 (هولندا). خادم التطبيق (App Hosting): منطقة europe-west4 (هولندا). أما سجلات حسابات Firebase Authentication (البريد الإلكتروني، والجوال، وتجزئة كلمة المرور) فتحفظ في خدمة المصادقة العالمية لدى Google، وهي غير مقيّدة بمنطقة واحدة.)
  • Cloudflare, Inc. - Turnstile. الحماية من الروبوتات في نموذج التواصل العام (sarp-sa.net/contact) فقط. ولا تحمّل في أي صفحة مصادق عليها. عنوان IP وإشارات المتصفح للزائر الذي يرسل نموذج التواصل. ولا يصل إليها أي شيء من داخل مساحة عمل أي عميل. (الموقع: شبكة Cloudflare العالمية)
  • Meta Platforms, Inc. - WhatsApp Cloud API. الردّ على من يراسل رقم دعم سارب الخاص. وغير متصلة بأي مساحة عمل لعميل. رقم الجوال واسم الملف الشخصي ورسائل الشخص الذي يتواصل مع رقم الدعم. ولا تمرّ عبرها أي بيانات شخصية لعملاء العميل. (الموقع: بنية Meta التحتية (خارج المملكة))
  • Resend, Inc. - البريد الإلكتروني التشغيلي. إرسال رسائل الحساب والفوترة إلى المستخدمين المفوّضين: الدعوات، وإعادة تعيين كلمة المرور، والفواتير، وإشعارات التجربة والسداد، والتنبيهات. اسم المستلم وبريده الإلكتروني ومحتوى الرسالة. ترسل إلى المستخدمين المفوّضين لدى العميل فقط، ولا ترسل إلى عملاء العميل. (الموقع: الولايات المتحدة الأمريكية)
  • يونيفونك (Unifonic) - الرسائل النصية القصيرة. رسائل نصية متعلقة بدورة الاشتراك إلى جوال مالك المكتب (مثل قرب انتهاء الفترة التجريبية). رقم جوال المالك ونص الرسالة. ولا ترسل إلى عملاء العميل. (الموقع: المملكة العربية السعودية)

ونُخطر العميل كتابياً قبل 30 يوماً على الأقل من إضافة معالج فرعي أو استبداله أو تغيير منطقة الاستضافة. كما نشارك البيانات، عند اللزوم، مع:

  • البنوك - تُسدَّد رسوم الاشتراك بحوالة بنكية، فتعالج الحوالةَ في مجراها الطبيعي بنكُ العميل وبنكُنا. ولا نستخدم مزوّد خدمات دفع، ولا نحتفظ ببيانات بطاقات على الإطلاق.
  • هيئة الزكاة والضريبة والجمارك - حيثما كان المزوّد مسجَّلاً في ضريبة القيمة المضافة، بيانات الفواتير التي يوجب نظام الفوترة الإلكترونية إرسالها.
  • الجهات المختصّة - عند ورود أمر نظامي من جهة رقابية أو قضائية، أو عند اشتراط الأنظمة السعودية ذلك.
ولا نستخدم شبكات إعلانات خارجية أو ملفات تتبع سلوكي، ولا أدوات تحليل تتبّع المستخدمين عبر المواقع.
النص الإنجليزي: Sub-processors & Data Sharing
We do not sell Personal Data. We rely on the following Sub-processors, and no others, to run the Service; each is bound by contractual data-protection and confidentiality obligations:
  • Google Cloud (Google LLC / Google Ireland Ltd) - Firebase Authentication, Cloud Firestore, Cloud Storage, Firebase App Hosting (Cloud Run), Secret Manager. Hosting and running the Platform; storing all Customer Data and user accounts. All Customer Data, including Client Personal Data, user credentials and uploaded documents. (Location: Data at rest (Cloud Firestore and Cloud Storage): region europe-west4 (the Netherlands). Application server (App Hosting): region europe-west4 (the Netherlands). Firebase Authentication account records (email, phone, password hash): Google's global authentication service, which is not pinned to a single region.)
  • Cloudflare, Inc. - Turnstile. Bot protection on the public contact form (sarp-sa.net/contact) only. Not loaded on any authenticated page. IP address and browser signals of the visitor submitting the contact form. Nothing from inside any Customer workspace. (Location: Cloudflare global network)
  • Meta Platforms, Inc. - WhatsApp Cloud API. Answering people who message SARP's own support number. Not connected to any Customer workspace. Phone number, profile name and messages of the person who contacts the support number. No Client Personal Data passes through it. (Location: Meta infrastructure (outside the Kingdom))
  • Resend, Inc. - Transactional email. Sending account and billing email to Authorized Users: invitations, password resets, invoices, trial and payment notices, alerts. Recipient's name and email address and the content of the message. Sent only to the Customer's Authorized Users, never to the Customer's clients. (Location: United States)
  • Unifonic - SMS. Subscription-lifecycle text messages to the office owner's phone (for example, trial ending). Owner's phone number and the message text. Never sent to the Customer's clients. (Location: Kingdom of Saudi Arabia)

We give the Customer not less than 30 days' written notice before adding or replacing a Sub-processor or changing the hosting region. Where necessary we also share data with:

  • Banks - subscription fees are paid by bank transfer, so the Customer's own bank and ours process the transfer in the ordinary course. We do not use a payment processor and we never hold card details.
  • Zakat, Tax and Customs Authority - where the Provider is VAT-registered, the invoice data the e-invoicing regulations require to be transmitted.
  • Competent authorities - where disclosure is required by Saudi law or a valid order from a regulatory or judicial body.
We do not use third-party advertising networks, behavioral-ad cookies, or external analytics vendors that track users across sites.

07أمن البيانات

نطبّق الضوابط التقنية والتنظيمية التالية، وهي ذاتها التي التزمنا بها تعاقدياً في البند الثامن من شروط الخدمة:
  • التشفير أثناء النقل (TLS) وعند التخزين لقواعد البيانات والملفات.
  • عزل البيانات لكل مكتب بحيث لا يرى أي مكتب بيانات مكتب آخر.
  • ضبط الصلاحيات حسب الدور (مالك/مدير/وسيط/طاقم المنصة) مع مبدأ أقل صلاحية ممكنة.
  • التحقق بخطوتين: إلزامي لطاقم المنصة، ومتاح لجميع مستخدمي المكاتب، ويمكن للمكتب فرضه على مستخدميه.
  • سجل تدقيق غير قابل للتعديل لعمليات الإنشاء والتعديل والحذف والتصدير والاطلاع على الوثائق.
  • عدم حفظ أي رابط دائم للوثائق؛ يُنشأ رابط التنزيل عند الطلب بعد التحقق من الصلاحية وتنتهي مدته خلال 15 دقيقة.
  • نسخ احتياطية منتظمة، وحفظ مفاتيح الخدمة في مدير أسرار مُدار، وتحديث المكوّنات البرمجية لسدّ نقاط الضعف الأمنية أولاً بأول.
وفي حال وقوع حادثة تسرّب تمسّ بيانات العميل، نُخطر العميل خلال 72 ساعة من علمنا بها بالتفاصيل المبيّنة في البند ٨-٧ من شروط الخدمة. ولا يخلو أي نظام من مخاطر، ويُقرّ العميل بأن النقل عبر الإنترنت ينطوي على مخاطر متأصلة، ويلتزم بإبلاغ المزوّد فوراً بأي حادثة مشتبه بها.
النص الإنجليزي: Data Security
We apply the following technical and organizational measures, the same ones we have committed to contractually in Clause 8 of the Terms of Service:
  • Encryption in transit (TLS) and at rest for databases and file storage.
  • Per-tenant data isolation so one agency cannot see another agency's data.
  • Role-based access control (owner / manager / agent / platform staff) with least-privilege defaults.
  • Two-factor authentication: mandatory for platform staff, available to every agency user, and enforceable by the agency for all of its users.
  • Immutable audit logs for create, update, delete, export and document-view actions.
  • No persistent document links: a download link is generated on request after an authorisation check and expires within 15 minutes.
  • Regular backups, service keys held in a managed secret store, and software components updated to close security weaknesses as they are disclosed.
If a breach affecting Customer data occurs, we notify the Customer within 72 hours of becoming aware of it, with the details set out in Clause 8.7 of the Terms of Service. No system is perfectly secure; the Customer acknowledges that transmission over the internet carries inherent risk and agrees to notify the Provider promptly of any suspected incident.

08مدة الاحتفاظ بالبيانات

نحتفظ بالبيانات الشخصية طوال مدة اشتراك العميل النشط. وبعد انتهاء الاشتراك أو إنهائه، تبقى إمكانية تصدير البيانات متاحة للعميل، ثم نحذف جميع بيانات العميل من أنظمتنا التشغيلية خلال 30 يوماً من تاريخ الانتهاء، ونزوّد العميل بشهادة حذف كتابية عند طلبه. وتُمحى النسخ الاحتياطية بدورتها المعتادة. ويُستثنى من ذلك ما تشترط الأنظمة السعودية احتفاظ المزوّد به من سجلاته الخاصة، كالسجلات المحاسبية والفواتير الصادرة للعميل لمدة ست (6) سنوات، وهي لا تتضمّن بيانات عملاء العميل. أما سجلات التدقيق المرتبطة بإجراءات خاضعة للرقابة، فنحتفظ بها للمدة التي تحدّدها اللائحة ذات العلاقة.

بيانات مكافحة الإساءة. الطلبات التي وردت إلى المكاتب عبر النماذج العامة التي كانت متاحة سابقاً على سارب تبقى في مساحة عمل المكتب المستلم بصفتها بيانات عميل يحتفظ بها المكتب وفق سياسته بصفته جهة التحكم فيها؛ أما عنوان IP ونوع المتصفح المسجَّلان معها فيُمحيان نهائياً بعد تسعين (90) يوماً عبر مهمة تنظيف مجدولة. وعنوان IP المسجَّل مع رسائل نموذج التواصل العام (البند الثالث) يُمحى بالمهمة نفسها بعد تسعين (90) يوماً من إرسال الرسالة، بينما تبقى الرسالة نفسها حتى تُحذف أو تطلب حذفها. وإذا رغبت في حذف طلب أرسلته إلى مكتب، فتواصل مع المكتب مباشرة، أو تواصل معنا عبر البند السابع عشر وسنحيل طلبك.
النص الإنجليزي: Data Retention
We retain Personal Data for as long as the Customer's subscription is active. After expiry or termination, export remains available to the Customer, and we then delete all Customer data from our operational systems within 30 days of the termination date, providing a written deletion certificate on request. Backup copies are overwritten in their ordinary rotation. Excluded is what Saudi law requires the Provider to retain of its own records, such as accounting records and the invoices issued to the Customer, for six (6) years, which do not contain the Customer's client data. Audit logs tied to regulated actions are kept for the period required by the applicable regulation.

Anti-abuse metadata. Enquiries that reached agencies through the public forms SARP previously offered remain in the receiving agency's workspace as Customer data, retained under that agency's own policy as Controller; the IP address and browser user-agent recorded with them are permanently erased after ninety (90) days by a scheduled purge job. The IP address recorded with a message sent through the public contact form (section 3) is erased by the same job ninety (90) days after the message was sent, while the message itself is kept until it is deleted or you ask for its deletion. If you want an enquiry you sent to an agency deleted, contact the agency directly, or contact us using section 17 and we will route the request.

09موقع استضافة البيانات

  • تخزين البيانات (Cloud Firestore وCloud Storage): منطقة واحدة مسمّاة هي europe-west4 (هولندا)، وهي خارج المملكة العربية السعودية. ويعتزم المزوّد نقل تخزين البيانات إلى منطقة me-central2 (الدمام، المملكة العربية السعودية) داخل المملكة.
  • خادم التطبيق (Firebase App Hosting): منطقة europe-west4 (هولندا). وهو الذي يعالج البيانات ويعرض الصفحات، ويبقى في هذه المنطقة بعد نقل التخزين لأن الخدمة غير متاحة في منطقة الدمام؛ وتنتقل البيانات بينه وبين التخزين مشفّرةً عبر شبكة Google الخاصة عند كل طلب.
  • حسابات المستخدمين (Firebase Authentication): خدمة مصادقة عالمية لدى Google غير مقيّدة بمنطقة واحدة؛ تُحفظ فيها بيانات الدخول (البريد الإلكتروني والجوال وتجزئة كلمة المرور) ولا تتأثر بنقل التخزين.

ونُخطر العميل كتابياً قبل 30 يوماً على الأقل من أي تغيير في منطقة تخزين البيانات أو منطقة خادم التطبيق، ونحدّث هذه السياسة تبعاً لذلك. ويُخطَر العميل بمواقع الاستضافة الحالية قبل الاشتراك.

النص الإنجليزي: Data Residency & Hosting
  • Data storage (Cloud Firestore and Cloud Storage): one named region, europe-west4 (the Netherlands), which is outside the Kingdom of Saudi Arabia. The Provider intends to migrate data storage to region me-central2 (Dammam, Kingdom of Saudi Arabia) inside the Kingdom.
  • Application server (Firebase App Hosting): region europe-west4 (the Netherlands). This is where data is processed and pages are rendered; it stays in this region after the storage migration because the service is not offered in the Dammam region, and data travels between it and storage encrypted over Google's private network on every request.
  • User accounts (Firebase Authentication): a global Google authentication service not pinned to a single region; it holds sign-in data (email, phone, password hash) and is unaffected by the storage migration.

We give the Customer not less than 30 days' written notice of any change of the data-storage region or the application-server region and update this Policy accordingly. The Customer is informed of the current hosting locations before subscribing.

10حقوقك بموجب نظام حماية البيانات الشخصية

يقرّر النظام لصاحب البيانات الحقوق التالية، بالعبارات التي يستعملها النظام، ونبيّن أمام كل حق كيفية ممارسته:
  • الحق في العلم - أن تعرف الأساس النظامي لجمع بياناتك والغرض منه، وألا تُعالَج لغرض آخر. تؤدّي هذه السياسة هذا الإخطار فيما نكون فيه جهة التحكم؛ ويؤدّيه المكتب فيما يخص بيانات عملائه.
  • الحق في الوصول إلى بياناتك الشخصية - الاطلاع على ما لدينا من بياناتك. للمستخدمين المفوّضين: الإعدادات ← الخصوصية ← تصدير البيانات. ولعملاء المكتب: بالتواصل مع المكتب، أو بمراسلتنا فنحيل طلبك إليه خلال ثلاثة أيام عمل.
  • الحق في طلب الحصول على بياناتك الشخصية بصيغة مقروءة وواضحة (نقل البيانات) - نسخة منظّمة مقروءة آلياً. تُنتَج من الإعدادات ← الخصوصية ← تصدير البيانات، ويحصل عليها عملاء المكتب من المكتب الذي يستطيع تصديرها بالأداة ذاتها.
  • الحق في طلب تصحيح بياناتك أو إكمالها أو تحديثها - يعدّل المستخدم المفوّض بيانات حسابه من إعدادات الملف الشخصي؛ ويصحّح المكتب سجلات عملائه داخل المنصة مباشرةً؛ وفيما عدا ذلك بمراسلتنا.
  • الحق في طلب إتلاف بياناتك الشخصية (الحذف) - إذا لم تعد لازمة للغرض الذي جُمعت له ولم يوجب النظام الاحتفاظ بها. للمستخدمين المفوّضين: الإعدادات ← الخصوصية ← طلب الحذف؛ ولعملاء المكتب: عبر المكتب الذي يحذف السجل من المنصة، أو بمراسلتنا فنحيل الطلب.
  • الحق في سحب الموافقة - في أي وقت، دون أن يؤثر ذلك على المعالجة السابقة؛ من إعدادات الإشعارات أو بمراسلتنا.
  • الاعتراض على المعالجة وطلب تقييدها - لك أن تعترض على معالجة قائمة على المصلحة المشروعة، وأن تطلب إيقاف استعمال بياناتك في التسويق المباشر، وأن تطلب الاكتفاء بحفظ سجل محل نزاع دون استعماله إلى أن يُبتّ فيه. ويُقدَّم الطلب بمراسلتنا أو عبر المكتب.
  • الحق في تقديم شكوى إلى الجهة المختصّة - لك أن تتقدّم بشكوى إلى الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) وفق البند الثاني عشر.
نُقرّ باستلام كل طلب خلال ثلاثة (3) أيام عمل، ونبتّ فيه خلال المدة التي تحدّدها اللائحة وبما لا يتجاوز ثلاثين (30) يوماً، ويجوز تمديدها بالقدر الذي تجيزه اللائحة عند تعقّد الطلب مع إشعارك بذلك. وإذا تعذّر تنفيذ الطلب، مثلاً لأن الفاتورة يجب الاحتفاظ بها نظاماً، فسنوضّح السبب ونحدّد البيانات الخاضعة للحفظ النظامي. وقد نطلب ما يكفي من البيانات للتحقّق من هويتك قبل التنفيذ. وتُقدَّم الطلبات إلى privacy@sarp-sa.net.
النص الإنجليزي: Your Rights Under the PDPL
The PDPL grants Data Subjects the following rights, in the words the Law uses, and next to each we state how to exercise it:
  • The right to be informed - to know the lawful basis and purpose of collecting your data, and that it will not be processed for another purpose. This Policy gives that notice where we are the Controller; the agency gives it for its own clients' data.
  • The right to access your Personal Data - to see what we hold about you. Authorized Users: Settings → Privacy → Export data. Agency clients: contact the agency, or write to us and we forward your request to it within three business days.
  • The right to request your Personal Data in a readable and clear format (portability) - a structured, machine-readable copy. Produced from Settings → Privacy → Export data; agency clients obtain it from the agency, which can export it with the same tool.
  • The right to request correction, completion or updating of your data - an Authorized User edits account data from profile settings; the agency corrects its client records directly in the Platform; otherwise, write to us.
  • The right to request destruction of your Personal Data (deletion) - where it is no longer needed for the purpose it was collected for and no statutory retention applies. Authorized Users: Settings → Privacy → Request deletion; agency clients: through the agency, which deletes the record in the Platform, or write to us and we forward the request.
  • The right to withdraw consent - at any time, without affecting prior processing; from notification settings or by writing to us.
  • Objection to processing and restriction - you may object to processing based on legitimate interest, ask that your data no longer be used for direct marketing, and ask that a disputed record be kept but not used until the dispute is resolved. Make the request by writing to us or through the agency.
  • The right to lodge a complaint with the competent authority - you may complain to the Saudi Data & AI Authority (SDAIA) as described in section 12.
We acknowledge every request within three (3) business days and decide it within the period the Regulations set, and in any case within thirty (30) days, extendable as the Regulations permit for complex requests with notice to you. Where a request cannot be fulfilled, for example, because an invoice must be retained by law, we explain the reason and identify the data held under legal hold. We may ask for enough information to verify your identity before acting. Requests go to privacy@sarp-sa.net.

11جهة الاتصال لحماية البيانات

لأي استفسار بخصوص هذه السياسة، أو لممارسة حقوقك بموجب النظام، أو للإبلاغ عن حادثة مشتبه بها، تواصل معنا على privacy@sarp-sa.net. ويُرجى تضمين ما يكفي من التفاصيل حتى نتمكّن من التحقّق من هويتك وتحديد البيانات المعنية. والمسؤول عن حماية البيانات هو مقدّم الخدمة المسمّى في البند الأول.
النص الإنجليزي: Data Protection Contact
For any question about this Policy, to exercise your PDPL rights, or to report a suspected incident, contact us at privacy@sarp-sa.net. Please include enough detail for us to verify your identity and locate the data in question. The person responsible for data protection is the Provider named in section 1.

12الجهة المختصّة

يحق لك تقديم شكوى إلى الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا)، وهي الجهة المختصّة بتطبيق النظام في المملكة. وتتوفّر بيانات التواصل مع سدايا وقنوات تقديم الشكاوى على موقعها sdaia.gov.sa. ونحن نشجّعك على التواصل معنا أولاً حتى نسعى لحلّ المسألة مباشرةً.
النص الإنجليزي: Competent Authority
You have the right to lodge a complaint with the Saudi Data & AI Authority (SDAIA), the competent authority for the PDPL in the Kingdom. SDAIA's contact details and complaint channels are available at sdaia.gov.sa. We encourage you to contact us first so we can try to resolve the issue directly.

13ملفات الارتباط والتتبّع

تستخدم المنصة عدداً محدوداً من ملفات الارتباط الخاصة بها، والضرورية لتشغيل الخدمة:
  • ملف الجلسة - يُبقيك مسجّل الدخول بعد المصادقة.
  • ملف اللغة - يحفظ تفضيلك بين العربية والإنجليزية.
  • ملفات الأمان - تساعد في رصد سرقة الجلسات وتزوير الطلبات بين المواقع.
ولا نستخدم ملفات ارتباط إعلانية من أطراف أخرى، ولا بيكسلات تتبّع بين المواقع، ولا أدوات تحليل خارجية مثل Google Analytics أو Meta Pixel داخل الصفحات المحمية. ويمكنك من متصفحك حظر ملفات الارتباط أو حذفها، لكن بعض الميزات الأساسية (مثل البقاء مسجّل الدخول) لن تعمل إذا حظرت ملفات الجلسة.
النص الإنجليزي: Cookies & Tracking
The Platform uses a small number of first-party cookies strictly necessary to operate the Service:
  • Session cookie - keeps you signed in after authentication.
  • Language cookie - remembers your Arabic/English preference.
  • Security cookies - help detect session hijacking and cross-site forgery.
We do not set third-party advertising cookies, we do not use cross-site tracking pixels, and we do not integrate external analytics vendors such as Google Analytics or Meta Pixel on authenticated pages. Your browser can block or delete cookies; some core features (for example, staying signed in) will not work if you block session cookies.

14بيانات الأطفال

المنصة منتج موجّه للمنشآت، مخصّص للمكاتب العقارية المرخّصة، وليست موجّهة لمن هم دون الثامنة عشرة (18) من العمر. ولا نجمع عن علم بيانات شخصية من قاصرين. وإذا علمت أن قاصراً قدّم لنا بيانات شخصية، يرجى التواصل مع privacy@sarp-sa.net، وسنقوم بحذفها.
النص الإنجليزي: Children's Data
The Platform is a business-to-business product for licensed real estate agencies and is not intended for individuals under eighteen (18) years of age. We do not knowingly collect Personal Data from minors. If you believe a minor has submitted Personal Data to us, please contact privacy@sarp-sa.net and we will delete it.

15نقل البيانات إلى خارج المملكة

نقولها بوضوح: ما دامت بيانات المنصة مخزّنة في منطقة europe-west4 (هولندا)، فإن بيانات العميل، بما فيها البيانات الشخصية لعملائه، تُخزَّن وتُعالَج خارج المملكة العربية السعودية. وبعد نقل التخزين إلى داخل المملكة ستبقى المعالجة عند كل طلب في خادم التطبيق خارجها (البند التاسع). كما تُنقل إلى خارج المملكة بيانات محدودة لتشغيل قنوات الاتصال المبيّنة في البند السادس (اسم المستخدم المفوّض وبريده الإلكتروني إلى مزوّد البريد التشغيلي في الولايات المتحدة، وبيانات من يراسل رقم الدعم إلى Meta)، ولا تشمل هذه القنوات بيانات عملاء العميل.

ونستند في هذا النقل إلى الضمانات المناسبة المقرّرة في لائحة نقل البيانات الشخصية إلى خارج المملكة، وهي: الالتزامات التعاقدية لحماية البيانات التي يلتزم بها كل معالج فرعي بموجب اتفاقية معالجة البيانات الخاصة به، والتدابير التقنية الواردة في البند السابع، وقصر النقل على القدر اللازم لتشغيل الخدمة. ولا ندّعي أن الجهة المختصّة أصدرت قراراً بتوفر مستوى حماية ملائم في أي من دول الاستضافة. ويُخطَر العميل، بصفته جهة التحكم في بيانات عملائه، بهذا الوضع قبل الاشتراك، ويقع عليه استيفاء أي شرط إضافي يفرضه النظام أو اللائحة على جهة التحكم بخصوص هذا النقل. وللاطلاع على قائمة المعالجين الفرعيين المحدّثة، راجع البند السادس أو راسلنا على privacy@sarp-sa.net.
النص الإنجليزي: Transfer Outside the Kingdom
Plainly: for as long as the Platform's data is stored in region europe-west4 (the Netherlands), Customer data, including the Customer's clients' personal data, is stored and processed outside the Kingdom of Saudi Arabia. After storage moves into the Kingdom, processing on every request will still take place on the application server outside it (section 9). Limited data is also transferred outside the Kingdom to run the communication channels described in section 6 (an Authorized User's name and email address to the transactional email provider in the United States, and the data of people who message the support number to Meta); those channels do not carry the Customer's client data.

We rely for these transfers on the appropriate safeguards provided for in the Regulation on Personal Data Transfer Outside the Kingdom: the contractual data-protection commitments each Sub-processor gives under its data processing agreement, the technical measures in section 7, and limiting the transfer to what is necessary to run the Service. We do not claim that the competent authority has issued a decision recognising any hosting country as providing an adequate level of protection. The Customer, as Controller of its clients' data, is informed of this position before subscribing and is responsible for meeting any additional condition the PDPL or the Regulations impose on a Controller in respect of this transfer. For the current list of Sub-processors see section 6 or write to privacy@sarp-sa.net.

16التعديلات على هذه السياسة

قد نحدّث هذه السياسة من حين لآخر لتعكس التغييرات في الخدمة أو الأنظمة أو ممارساتنا. وعند إجراء تعديلات جوهرية، نخطر العميل بالبريد الإلكتروني قبل بدء سريانها بثلاثين (30) يوماً على الأقل. وتظل النسخة الأحدث متاحة دائماً على هذه الصفحة، مع تاريخ "آخر تحديث" في أعلاها. ويُعدّ استمرار استخدام الخدمة بعد تاريخ السريان قبولاً للسياسة المحدّثة.
النص الإنجليزي: Changes to This Policy
We may update this Policy from time to time to reflect changes in the Service, the law, or our practices. When we make material changes, we will notify the Customer by email at least thirty (30) days before the changes take effect. The latest version is always available on this page, with the "Last updated" date at the top. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

17كيفية التواصل معنا

سارب - الخصوصية والامتثال
  • مقدّم الخدمة: خالد ظافر بن سعد القرني - وثيقة عمل حر رقم FL-002881762
  • البريد الإلكتروني: privacy@sarp-sa.net
  • عام: sales@sarp-sa.net
  • العنوان: الرياض، المملكة العربية السعودية
النص الإنجليزي: How to Contact Us
SARP - Privacy & Compliance

هذا النص للاطلاع. ننصح العميل بمراجعة الاتفاقية مع مستشار قانوني سعودي مرخّص قبل الالتزام بها للاستخدام التجاري.

شروط الخدمة ←