النص العربي والإنجليزي متساويان في الحجية. يمكنك عرض النص الإنجليزي لكل قسم من الرابط أسفله. وفي حال تعارض التفسير، يرجّح النص العربي وفقاً للعرف القضائي السعودي.
01قبول الشروط وهوية المزوّد
النص الإنجليزي: Acceptance of Terms & Identity of the Provider
02التعريفات
النص الإنجليزي: Definitions
03الأهلية والترخيص وضمانات العميل
- أنه مكتب عقاري مرخّص رسمياً من الهيئة العامة للعقار بموجب رخصة وساطة سارية، وأن كل رخصة فال ينسبها إلى نفسه أو إلى أي من مستخدميه المفوّضين صحيحة وسارية، وأن جميع البيانات المقدّمة أثناء التسجيل، بما فيها رقم رخصة الهيئة والسجل التجاري والرقم الضريبي، صحيحة وحديثة.
- أن لديه، بصفته جهة التحكم، أساساً نظامياً صحيحاً وفق النظام واللائحة لكل بيان شخصي يسجّله على المنصة من البيانات الشخصية لعملائه، وأنه أخطر أصحاب تلك البيانات بما يوجبه النظام من إخطار، وحصل على موافقتهم حيثما كانت الموافقة هي الأساس المعتمد.
- أنه لن يرفع إلى المنصة أو يُدخل فيها أي بيانات لا يملك حق معالجتها، ولا صوراً لوثائق هوية أو صكوك أو وكالات تخصّ أشخاصاً لا تربطه بهم علاقة تعاقدية أو تكليف مشروع.
- أنه سيُشعر المزوّد فوراً بأي تغيير في وضعه النظامي، كإلغاء رخصته أو تعليقها، يؤثر على أحقيته في استخدام الخدمة.
النص الإنجليزي: Eligibility, Licensing & Customer Warranties
- it is a real estate office duly licensed by REGA under a valid brokerage licence; every FAL licence it attributes to itself or to any of its Authorized Users is genuine and current; and all information provided during onboarding, including REGA licence number, Commercial Registration and VAT number, is accurate and current;
- as Controller it has a valid lawful basis under the PDPL and the Regulations for every item of Client Personal Data it records on the Platform, has given the Data Subjects the notice the PDPL requires, and has obtained their consent wherever consent is the basis relied on;
- it will not upload to or enter into the Platform any data it has no right to process, including copies of identity documents, title deeds or powers of attorney of persons with whom it has no contractual relationship or lawful engagement; and
- it will promptly notify the Provider of any change in its regulatory status, such as cancellation or suspension of its licence, that affects its entitlement to use the Service.
04منح حق الاستخدام
النص الإنجليزي: Grant of Use
05التزامات العميل
- استخدام المنصة فقط لأغراض مشروعة تتوافق مع الأنظمة السعودية ولوائح الهيئة العامة للعقار.
- المحافظة على سرّية بيانات تسجيل الدخول وإشعار المزوّد فور اكتشاف أي وصول غير مصرّح به.
- التأكد من أن المستخدمين المفوّضين مدرّبون على حماية البيانات والاستخدام المقبول.
- عدم محاولة الهندسة العكسية للمنصة أو استخراج شفرتها المصدرية.
- عدم استخدام المنصة لنقل برامج ضارة أو فيروسات أو محتوى مؤذٍ.
- عدم إعادة بيع المنصة أو الترخيص من الباطن لأي طرف ثالث.
- معالجة البيانات الشخصية لعملائه وفق الأسس النظامية المقرّرة في النظام واللائحة، وضبط صلاحيات مستخدميه المفوّضين بما لا يتجاوز حاجة العمل.
النص الإنجليزي: Customer Obligations
- Use the Platform only for lawful purposes consistent with Saudi laws and REGA regulations.
- Maintain the confidentiality of user credentials and notify the Provider of any unauthorized access.
- Ensure that Authorized Users are trained on data protection and acceptable use.
- Not attempt to reverse engineer, decompile, or extract source code from the Platform.
- Not use the Platform to transmit malware, viruses, or harmful content.
- Not resell, sublicense, or offer the Platform as a service to any third party.
- Process Client Personal Data only on a lawful basis under the PDPL and the Regulations, and set its Authorized Users' permissions no wider than the work requires.
06ملكية البيانات وعزلها
النص الإنجليزي: Data Ownership & Isolation
07إحصاءات الاستخدام الإجمالية
ولا يجمع المزوّد لهذا الغرض، ولا يستخرج، ولا يستنتج بيانات عملاء العميل على مستوى الأفراد (بما في ذلك هوية أي مشترٍ أو بائع أو مستأجر أو مالك سجّله العميل أو بيانات التواصل معه أو متطلباته)، ولا قيم صفقات العميل، ولا العمولات أو غيرها من الإيرادات التي يحصّلها العميل من عملائه. وتبقى تلك البيانات بيانات عميل بالمعنى الوارد في البند السادس ولا يُصار إلى الوصول إليها إلا وفق ما يجيزه ذلك البند. ولا يطّلع موظفو المزوّد على هذه الإحصاءات إلا في صورتها الإجمالية؛ ولا يُعرض عليهم من خلالها أي سجل فردي من سجلات العميل.
النص الإنجليزي: Aggregate Usage Statistics
For this purpose the Provider does not collect, extract, or derive the Customer's client-level data (including the identity, contact details, or requirements of any buyer, seller, tenant, or owner recorded by the Customer), nor the values of the Customer's transactions, nor the commission or other earnings the Customer receives from its clients. Such data remains Customer Data within the meaning of Clause 6 and is accessed only as that Clause permits. The Provider's staff see these statistics in aggregate form only; no individual record of the Customer is presented to them through the statistics.
08أحكام معالجة البيانات (جهة التحكم، جهة المعالجة)
٨-١ الأدوار والتعليمات. العميل هو جهة التحكم في البيانات الشخصية لعملائه: فهو الذي يقرّر الغرض من معالجتها ووسيلتها. والمزوّد جهة معالجة، لا يعالج تلك البيانات إلا بناءً على تعليمات العميل الموثّقة، وهي: هذه الاتفاقية، وما يُجريه العميل ومستخدموه المفوّضون من إعدادات وإجراءات داخل المنصة (كإنشاء السجلات ورفع الوثائق وضبط الصلاحيات والتصدير والحذف). وإذا رأى المزوّد أن تعليماً ما يخالف النظام أو اللائحة، أخطر العميل بذلك دون تأخير وامتنع عن تنفيذه إلى أن يُصحَّح.
٨-٢ تقييد الغرض. لا يستخدم المزوّد البيانات الشخصية لعملاء العميل لأي غرض من أغراضه الخاصة؛ فلا يبيعها، ولا يؤجّرها، ولا يُنمّط أصحابها، ولا يستخدمها في التسويق، ولا في تدريب أي نموذج أو منتج، ولا يجمعها مع بيانات عميل آخر. ويقتصر ما يطّلع عليه موظفو المزوّد على الإحصاءات الإجمالية المبيّنة في البند السابع.
٨-٣ السرية. يلتزم المزوّد بألا يتيح الوصول إلى بيانات العميل إلا لمن تقتضي مهامه ذلك ممن التزم كتابياً بالمحافظة على سرّيتها، وبمبدأ أقل صلاحية ممكنة. ولا يطّلع موظفو المزوّد على سجل بعينه من سجلات العميل إلا لمعالجة طلب دعم قدّمه العميل أو لمعالجة حادثة أمنية، ويُقيَّد كل اطلاع من هذا النوع في سجل التدقيق مع هوية من أجراه ووقته.
٨-٤ التدابير الأمنية. يطبّق المزوّد ويُبقي سارية التدابير التقنية والتنظيمية التالية على الأقل:
- التشفير أثناء النقل (TLS) وعند التخزين لقواعد البيانات والملفات المرفوعة.
- ضبط الصلاحيات حسب الدور (مالك، مدير، وسيط، طاقم المنصة) مع مبدأ أقل صلاحية ممكنة.
- عزل بيانات كل مكتب في مساحة عمل مستقلة بحيث لا يصل أي مكتب إلى بيانات مكتب آخر.
- سجل تدقيق لعمليات الإنشاء والتعديل والحذف والتصدير والاطلاع على الوثائق، غير قابل للتعديل من المستخدمين.
- عدم حفظ أي رابط دائم للوثائق؛ فلا يُنشأ رابط تنزيل الوثيقة إلا عند الطلب وبعد التحقق من صلاحية الطالب، وتنتهي صلاحيته خلال 15 دقيقة.
- التحقق بخطوتين (2FA): إلزامي لطاقم المنصة، ومتاح لجميع المستخدمين المفوّضين، ويمكن للعميل فرضه على جميع مستخدميه.
- نسخ احتياطية منتظمة، وحفظ مفاتيح الخدمة في مدير أسرار مُدار، وتحديث المكوّنات البرمجية لسدّ نقاط الضعف الأمنية أولاً بأول.
٨-٥ المعالجون الفرعيون وموقع الاستضافة. يأذن العميل للمزوّد بالاستعانة بالمعالجين الفرعيين المبيّنين أدناه، ولا غيرهم. وتُخزَّن بيانات العميل لدى Google Cloud في منطقة واحدة مسمّاة هي europe-west4 (هولندا)، ويعمل خادم التطبيق الذي يعالجها ويعرض الصفحات في منطقة europe-west4 (هولندا). ويعتزم المزوّد نقل تخزين البيانات إلى منطقة me-central2 (الدمام، المملكة العربية السعودية) داخل المملكة؛ ويبقى خادم التطبيق بعد ذلك النقل في منطقته الحالية لأن هذه الخدمة غير متاحة في منطقة الدمام، وتنتقل البيانات بينهما مشفّرةً عبر شبكة Google الخاصة عند كل طلب. ويلتزم المزوّد بإشعار العميل كتابياً قبل 30 يوماً على الأقل من أي تغيير في منطقة الاستضافة أو من إضافة معالج فرعي أو استبداله؛ وللعميل خلال مدة الإشعار أن يعترض كتابياً، وإذا تعذّر تلافي سبب اعتراضه جاز له إنهاء الاتفاقية دون غرامة مع استرداد الرسوم عن المدة غير المستفاد منها وتصدير بياناته وفق البند ٨-٩. ويُلزم المزوّد كل معالج فرعي كتابياً بالتزامات في حماية البيانات لا تقلّ عمّا التزم به في هذا البند، ويبقى مسؤولاً أمام العميل عن أداء معالجيه الفرعيين.
| المعالج الفرعي | الخدمة والغرض | البيانات التي تصل إليه | موقع المعالجة |
|---|---|---|---|
| Google Cloud (Google LLC / Google Ireland Ltd) | Firebase Authentication وCloud Firestore وCloud Storage وFirebase App Hosting (Cloud Run) وSecret Manager استضافة المنصة وتشغيلها؛ وحفظ جميع بيانات العميل وحسابات المستخدمين. | جميع بيانات العميل، بما فيها البيانات الشخصية لعملاء العميل، وبيانات دخول المستخدمين، والوثائق المرفوعة. | البيانات المخزّنة (Cloud Firestore وCloud Storage): منطقة europe-west4 (هولندا). خادم التطبيق (App Hosting): منطقة europe-west4 (هولندا). أما سجلات حسابات Firebase Authentication (البريد الإلكتروني، والجوال، وتجزئة كلمة المرور) فتحفظ في خدمة المصادقة العالمية لدى Google، وهي غير مقيّدة بمنطقة واحدة. |
| Cloudflare, Inc. | Turnstile الحماية من الروبوتات في نموذج التواصل العام (sarp-sa.net/contact) فقط. ولا تحمّل في أي صفحة مصادق عليها. | عنوان IP وإشارات المتصفح للزائر الذي يرسل نموذج التواصل. ولا يصل إليها أي شيء من داخل مساحة عمل أي عميل. | شبكة Cloudflare العالمية |
| Meta Platforms, Inc. | WhatsApp Cloud API الردّ على من يراسل رقم دعم سارب الخاص. وغير متصلة بأي مساحة عمل لعميل. | رقم الجوال واسم الملف الشخصي ورسائل الشخص الذي يتواصل مع رقم الدعم. ولا تمرّ عبرها أي بيانات شخصية لعملاء العميل. | بنية Meta التحتية (خارج المملكة) |
| Resend, Inc. | البريد الإلكتروني التشغيلي إرسال رسائل الحساب والفوترة إلى المستخدمين المفوّضين: الدعوات، وإعادة تعيين كلمة المرور، والفواتير، وإشعارات التجربة والسداد، والتنبيهات. | اسم المستلم وبريده الإلكتروني ومحتوى الرسالة. ترسل إلى المستخدمين المفوّضين لدى العميل فقط، ولا ترسل إلى عملاء العميل. | الولايات المتحدة الأمريكية |
| يونيفونك (Unifonic) | الرسائل النصية القصيرة رسائل نصية متعلقة بدورة الاشتراك إلى جوال مالك المكتب (مثل قرب انتهاء الفترة التجريبية). | رقم جوال المالك ونص الرسالة. ولا ترسل إلى عملاء العميل. | المملكة العربية السعودية |
٨-٦ نقل البيانات إلى خارج المملكة. ما دامت منطقة تخزين البيانات الحالية خارج المملكة، فإن بيانات العميل، بما فيها البيانات الشخصية لعملائه، تُخزَّن وتُعالَج خارج المملكة العربية السعودية. وبعد اكتمال نقل التخزين إلى منطقة داخل المملكة، تبقى البيانات مخزّنةً داخل المملكة، لكنها تُعالَج عند كل طلب في خادم التطبيق خارجها وتُنقل إليه مشفّرةً، كما تبقى سجلات حسابات المستخدمين في خدمة المصادقة العالمية لدى Google. ويستند المزوّد في هذا النقل إلى الضمانات المناسبة المقرّرة في لائحة نقل البيانات الشخصية إلى خارج المملكة، وهي: الالتزامات التعاقدية لحماية البيانات التي يُلزم بها Google Cloud بموجب ملحق معالجة البيانات الخاص به، والتدابير التقنية الواردة في البند ٨-٤، وقصر النقل على القدر اللازم لتشغيل الخدمة. ولا يدّعي المزوّد أن لدولة الاستضافة قراراً بتوفر مستوى حماية ملائم صادراً عن الجهة المختصّة، ولا يضمن ذلك. ويُقرّ العميل، بصفته جهة التحكم، بأنه أُخطر بهذا الوضع قبل الاشتراك، وبأن مسؤولية استيفاء أي شرط إضافي يفرضه النظام أو اللائحة على جهة التحكم بخصوص هذا النقل تقع عليه. ويُخطَر العميل عند اكتمال نقل التخزين إلى داخل المملكة، ويُحدَّث هذا البند تبعاً لذلك.
٨-٧ الإشعار بحوادث تسرّب البيانات. يلتزم المزوّد بإشعار العميل كتابياً خلال 72 ساعة من علمه بأي حادثة تسرّب أو إتلاف أو وصول غير مصرّح به يمسّ بيانات العميل. ويتضمّن الإشعار، بقدر ما يكون معلوماً حينه ويُستكمل تباعاً: طبيعة الحادثة ووقت وقوعها ووقت اكتشافها، وفئات البيانات وأصحابها وعددهم التقريبي، والآثار المحتملة عليهم، والتدابير التي اتُّخذت أو يُقترح اتخاذها لاحتواء الحادثة والحدّ من آثارها، وجهة الاتصال لدى المزوّد. ويتعاون المزوّد مع العميل فيما يلزم لتمكينه من الوفاء بالتزامه، بصفته جهة التحكم، بإبلاغ سدايا وأصحاب البيانات في المدد المقرّرة نظاماً.
٨-٨ المساعدة في طلبات أصحاب البيانات. إذا ورد إلى المزوّد مباشرةً طلب من صاحب بيانات يخصّ بيانات يحتفظ بها العميل، أحاله المزوّد إلى العميل خلال ثلاثة (3) أيام عمل ولم يبتّ فيه بنفسه. ويمكّن المزوّد العميل من الاستجابة لطلبات الاطلاع والتصحيح والإتلاف والحصول على نسخة عبر أدوات المنصة ذاتها؛ وفيما يتعذّر تنفيذه بتلك الأدوات، يقدّم المزوّد المساعدة اللازمة بناءً على طلب كتابي خلال عشرة (10) أيام عمل.
٨-٩ التصدير والإعادة والحذف. للعميل في أي وقت أثناء سريان الاتفاقية أن يصدّر نسخة كاملة من بياناته بصيغة منظّمة مقروءة آلياً من خلال المنصة (الإعدادات ← الخصوصية ← تصدير البيانات). وعند انتهاء الاتفاقية لأي سبب، يُبقي المزوّد إمكانية التصدير متاحة، ثم يحذف جميع بيانات العميل من أنظمته التشغيلية خلال 30 يوماً من تاريخ الانتهاء، وتُمحى النسخ الاحتياطية بدورتها المعتادة ولا تُستعاد إلا لاستعادة المنصة بكاملها. ويزوّد المزوّد العميل، بناءً على طلبه، بشهادة كتابية تُثبت إتمام الحذف. ويُستثنى من الحذف ما توجب الأنظمة السعودية الاحتفاظ به لدى المزوّد كسجلاته المحاسبية وفواتيره الصادرة للعميل، وهي لا تتضمّن البيانات الشخصية لعملاء العميل.
٨-١٠ الإثبات والتحقق. يقدّم المزوّد للعميل، بناءً على طلب كتابي لا يتكرّر أكثر من مرة في السنة، ما يلزم بصورة معقولة لإثبات الوفاء بهذا البند، بما في ذلك وصف التدابير الأمنية السارية، وقائمة المعالجين الفرعيين المحدّثة، وما يخصّ العميل من سجلات التدقيق. ويُتاح للعميل، بناءً على طلبه، نسخة مستقلة من هذه الأحكام بصيغة اتفاقية معالجة بيانات قابلة للتوقيع، مطابقة لهذا البند في مضمونها؛ وعند التوقيع عليها تُقدَّم أحكامها على هذا البند فيما يتعارضان فيه.
النص الإنجليزي: Data Processing Terms (Controller, Processor)
8.1 Roles and instructions. The Customer is the Controller of Client Personal Data: it decides why and how that data is processed. The Provider is a Processor and processes Client Personal Data solely on the Customer's documented instructions, which are this Agreement and the configuration and actions the Customer and its Authorized Users perform within the Platform (creating records, uploading documents, setting permissions, exporting and deleting). If the Provider considers that an instruction contravenes the PDPL or the Regulations, it shall inform the Customer without delay and refrain from carrying it out until it is corrected.
8.2 Purpose limitation. The Provider shall not use Client Personal Data for any purpose of its own. It shall not sell or rent it, profile the Data Subjects, use it for marketing, use it to train any model or product, or combine it with another Customer's data. What the Provider's staff see is confined to the aggregate statistics described in Clause 7.
8.3 Confidentiality. The Provider shall make Customer Data accessible only to persons whose duties require it and who are bound in writing to keep it confidential, on a least-privilege basis. The Provider's staff open an individual record of the Customer only to handle a support request the Customer has raised or to handle a security incident, and every such access is recorded in the audit log with the identity of the person and the time.
8.4 Security measures. The Provider shall implement and maintain at least the following technical and organisational measures:
- Encryption in transit (TLS) and at rest for databases and uploaded files.
- Role-based access control (owner, manager, agent, platform staff) with least-privilege defaults.
- Per-office isolation: each office's data sits in its own workspace and no office can reach another's data.
- An audit log of create, update, delete, export and document-view actions that users cannot alter.
- No persistent document links: a download link for a document is generated only on request, after the requester's authorisation has been checked, and expires within 15 minutes.
- Two-factor authentication (2FA): mandatory for platform staff, available to every Authorized User, and enforceable by the Customer for all of its users.
- Regular backups, service keys held in a managed secret store, and software components updated to close security weaknesses as they are disclosed.
8.5 Sub-processors and hosting region. The Customer authorises the Provider to engage the Sub-processors listed below, and no others. Customer Data is stored with Google Cloud in one named region, europe-west4 (the Netherlands), and the application server that processes it and renders pages runs in region europe-west4 (the Netherlands). The Provider intends to migrate data storage to region me-central2 (Dammam, Kingdom of Saudi Arabia) inside the Kingdom; after that migration the application server remains in its current region, because that service is not offered in the Dammam region, and data travels between the two encrypted over Google's private network on every request. The Provider shall give the Customer not less than 30 days' written notice of any change of hosting region and of the addition or replacement of any Sub-processor. The Customer may object in writing within the notice period; if the ground of objection cannot be resolved, the Customer may terminate this Agreement without penalty, with a refund of fees for the unused period, and export its data under Clause 8.9. The Provider shall bind each Sub-processor in writing to data-protection obligations no less protective than those in this Clause and remains liable to the Customer for its Sub-processors' performance.
| Sub-processor | Service and purpose | Data that reaches it | Where it processes |
|---|---|---|---|
| Google Cloud (Google LLC / Google Ireland Ltd) | Firebase Authentication, Cloud Firestore, Cloud Storage, Firebase App Hosting (Cloud Run), Secret Manager Hosting and running the Platform; storing all Customer Data and user accounts. | All Customer Data, including Client Personal Data, user credentials and uploaded documents. | Data at rest (Cloud Firestore and Cloud Storage): region europe-west4 (the Netherlands). Application server (App Hosting): region europe-west4 (the Netherlands). Firebase Authentication account records (email, phone, password hash): Google's global authentication service, which is not pinned to a single region. |
| Cloudflare, Inc. | Turnstile Bot protection on the public contact form (sarp-sa.net/contact) only. Not loaded on any authenticated page. | IP address and browser signals of the visitor submitting the contact form. Nothing from inside any Customer workspace. | Cloudflare global network |
| Meta Platforms, Inc. | WhatsApp Cloud API Answering people who message SARP's own support number. Not connected to any Customer workspace. | Phone number, profile name and messages of the person who contacts the support number. No Client Personal Data passes through it. | Meta infrastructure (outside the Kingdom) |
| Resend, Inc. | Transactional email Sending account and billing email to Authorized Users: invitations, password resets, invoices, trial and payment notices, alerts. | Recipient's name and email address and the content of the message. Sent only to the Customer's Authorized Users, never to the Customer's clients. | United States |
| Unifonic | SMS Subscription-lifecycle text messages to the office owner's phone (for example, trial ending). | Owner's phone number and the message text. Never sent to the Customer's clients. | Kingdom of Saudi Arabia |
8.6 Transfer outside the Kingdom. For as long as the current storage region is outside the Kingdom, Customer Data, including Client Personal Data, is stored and processed outside the Kingdom of Saudi Arabia. Once the migration of storage to a region inside the Kingdom is complete, the data remains stored inside the Kingdom but is processed on every request by the application server outside it and is transmitted to that server encrypted; user account records likewise remain in Google's global authentication service. The Provider relies for this transfer on the appropriate safeguards provided for in the Regulation on Personal Data Transfer Outside the Kingdom, namely: the contractual data-protection commitments that bind Google Cloud under its Data Processing Addendum, the technical measures in Clause 8.4, and limiting the transfer to what is necessary to run the Service. The Provider does not claim, and does not warrant, that the competent authority has issued a decision recognising the hosting country as providing an adequate level of protection. The Customer, as Controller, acknowledges that it was informed of this position before subscribing and that it is responsible for meeting any additional condition the PDPL or the Regulations impose on a Controller in respect of this transfer. The Customer shall be notified when the migration of storage into the Kingdom is complete, and this Clause shall be updated accordingly.
8.7 Breach notification. The Provider shall notify the Customer in writing within 72 hours of becoming aware of any breach, destruction or unauthorised access affecting Customer Data. The notice shall state, so far as then known and supplemented as it becomes known: the nature of the incident, when it occurred and when it was discovered; the categories of data and of Data Subjects affected and their approximate number; the likely consequences for them; the measures taken or proposed to contain the incident and mitigate its effects; and a contact at the Provider. The Provider shall cooperate with the Customer so that the Customer, as Controller, can notify SDAIA and the Data Subjects within the periods the law prescribes.
8.8 Assistance with Data Subject requests. If a request from a Data Subject concerning data held by the Customer reaches the Provider directly, the Provider shall forward it to the Customer within three (3) business days and shall not decide it itself. The Provider enables the Customer to answer requests for access, correction, destruction and a copy of the data through the Platform's own tools; where a request cannot be met with those tools, the Provider shall give the necessary assistance on written request within ten (10) business days.
8.9 Export, return and deletion. At any time during the term the Customer may export a complete copy of its data in a structured, machine-readable format through the Platform (Settings → Privacy → Export data). On expiry or termination of this Agreement for any reason, the Provider shall keep export available and shall then delete all Customer Data from its operational systems within 30 days of the termination date; backup copies are overwritten in their ordinary rotation and are restored only to recover the Platform as a whole. On request, the Provider shall give the Customer a written certificate confirming that deletion is complete. Excluded from deletion is what Saudi law requires the Provider to retain of its own records, such as its accounting records and the invoices it issued to the Customer; these do not contain Client Personal Data.
8.10 Demonstration of compliance. On written request made not more than once in any year, the Provider shall give the Customer what is reasonably needed to demonstrate compliance with this Clause, including a description of the security measures in force, the current list of Sub-processors, and the audit-log entries relating to the Customer. On request the Customer may obtain a standalone copy of these terms in the form of a signable Data Processing Agreement identical in substance to this Clause; once signed, that agreement prevails over this Clause where the two conflict.
09الاشتراك والرسوم والفواتير
٩-١ تُستحق رسوم الاشتراك مقدّماً بالريال السعودي. …
٩-٢ للعميل أن يختار مدة دفع مسبق قدرها شهر واحد (1) أو ثلاثة (3) أو ستة (6) أو اثنا عشر (12) شهراً. وتستوجب المدد التي تبلغ ثلاثة أشهر فأكثر خصماً على السعر المعلن بنسبة 5% و10% و17% على التوالي، ولا يستوجب اشتراك الشهر الواحد أي خصم. والحدّ الأقصى للمدة اثنا عشر شهراً. وتكون المدة المختارة ثابتة طوال سريانها، ويُطبّق الخصم المقابل لها على الفاتورة الصادرة عنها.
٩-٣ تُسدَّد الرسوم بحوالة بنكية إلى الحساب المبيّن في الفاتورة مع ذكر رقم الفاتورة. ولا يُعتدّ بالسداد إلا بتأكيد المزوّد استلام المبلغ محصَّلاً في حسابه البنكي وفق كشف الحساب؛ ورفع العميل لإشعار التحويل يُعدّ إخطاراً بالسداد لا سداداً بذاته. ويلتزم المزوّد بمراجعة الإشعار المرفوع دون تأخير غير مبرَّر.
٩-٤ …
٩-٥ تُقدَّم الخدمة عن المدة التي سُدِّدت رسومها فعلاً. وإذا لم تُستلم الرسوم في تاريخ الاستحقاق المبيّن في الفاتورة، جاز للمزوّد إيقاف الخدمة بعد إشعار كتابي؛ وإذا بقي المبلغ غير مسدَّد بعد ثلاثين (30) يوماً من الإيقاف، جاز للمزوّد إنهاء هذه الاتفاقية. ولا يترتّب على الإيقاف تمديد المدة المدفوعة، ويُعاد التمكين من الخدمة عند تأكيد سداد المبلغ المستحق. ويسري البند الخامس عشر (المدة والإنهاء) على الإنهاء بسبب عدم السداد كسريانه على أي إنهاء آخر.
النص الإنجليزي: Subscription, Fees & Billing
9.1 Subscription fees are payable in advance in Saudi Riyals (SAR). …
9.2 The Customer may elect a prepayment term of one (1), three (3), six (6) or twelve (12) months. Terms of three months or longer attract a discount on the list price of 5%, 10% and 17% respectively; a term of one month attracts no discount. Twelve months is the maximum term. The elected term is fixed for its duration and the corresponding discount is applied to the invoice raised for that term.
9.3 Fees are payable by bank transfer to the account stated on the invoice, quoting the invoice number. Payment is recognised only upon the Provider confirming receipt of cleared funds against its bank statement; the submission of a transfer receipt by the Customer constitutes notice of payment and not payment itself. The Provider shall review a submitted receipt without undue delay.
9.4 …
9.5 Service is provided for the period covered by fees actually received. Where fees are not received by the due date stated on the invoice, the Provider may, after written notice, suspend the Service; and where the amount remains unpaid thirty (30) days after suspension, the Provider may terminate this Agreement. Suspension does not extend the paid period, and access is restored upon confirmation of the outstanding amount. Clause 15 (Term & Termination) applies to termination for non-payment as it applies to any other termination.
10الملكية الفكرية
النص الإنجليزي: Intellectual Property
11السرية
النص الإنجليزي: Confidentiality
12توفّر الخدمة والدعم الفني
النص الإنجليزي: Service Availability & Support
13الضمانات وإخلاء المسؤولية
النص الإنجليزي: Warranties & Disclaimers
14تحديد المسؤولية
١٤-١ لا يتجاوز مجموع مسؤولية المزوّد تجاه العميل، عن كل ما ينشأ عن هذه الاتفاقية أو يتصل بها أياً كان سببه، عقدياً كان أو تقصيرياً أو غير ذلك، إجمالي رسوم الاشتراك التي سدّدها العميل فعلاً للمزوّد خلال الاثني عشر (12) شهراً السابقة مباشرةً للواقعة التي نشأت عنها المطالبة. ويُحتسب هذا الحدّ لجميع المطالبات مجتمعةً لا لكل مطالبة على حدة.
١٤-٢ لا يكون المزوّد مسؤولاً، في أي حال، عن أي ضرر غير مباشر أو تبعي، ولا عن فوات الربح أو الكسب أو الفرصة، ولا عن توقف الأعمال أو تعطّلها، ولا عن المساس بالسمعة التجارية، ولا عن الفقد الناجم عن انقطاع الخدمة وقتياً، حتى لو أُخطر باحتمال وقوع ذلك الضرر.
١٤-٣ لا يسري ما ورد في الفقرتين ١٤-١ و١٤-٢ على ما لا تجيز أنظمة المملكة العربية السعودية استبعاد المسؤولية عنه أو تحديدها، ومن ذلك المسؤولية الناشئة عن الغش أو التدليس أو التعمّد أو الخطأ الجسيم، أو عن الإضرار بالنفس، أو ما تقضي المحكمة المختصّة بعدم جواز الإعفاء منه.
١٤-٤ لا يخضع لحدّ المسؤولية المقرّر في الفقرة ١٤-١ التزامُ العميل بالتعويض المنصوص عليه في البند الثالث عن الإخلال بضماناته، ولا التزامه بسداد الرسوم المستحقة.
النص الإنجليزي: Limitation of Liability
14.1 The aggregate liability of the Provider to the Customer for everything arising out of or in connection with this Agreement, however caused, whether in contract, tort or otherwise, shall not exceed the total subscription fees actually paid by the Customer to the Provider in the twelve (12) months immediately preceding the event giving rise to the claim. This limit applies to all claims in the aggregate and not to each claim separately.
14.2 The Provider shall in no event be liable for any indirect or consequential loss, for loss of profit, revenue or opportunity, for business interruption or downtime, for damage to commercial reputation, or for loss resulting from temporary unavailability of the Service, even if advised of the possibility of such loss.
14.3 Clauses 14.1 and 14.2 do not apply to liability that the laws of the Kingdom of Saudi Arabia do not permit to be excluded or limited, including liability arising from fraud, misrepresentation, wilful misconduct or gross negligence, or for personal injury, or any liability the competent court holds cannot be excluded.
14.4 The Customer's indemnity in Clause 3 for breach of its warranties, and its obligation to pay the fees due, are not subject to the limit in Clause 14.1.
15المدة والإنهاء
النص الإنجليزي: Term & Termination
16القانون الحاكم وتسوية النزاعات
النص الإنجليزي: Governing Law & Dispute Resolution
17القوة القاهرة
النص الإنجليزي: Force Majeure
18التعديلات
النص الإنجليزي: Amendments
19التواصل
- المزوّد: خالد ظافر بن سعد القرني - وثيقة عمل حر رقم FL-002881762
- الاسم التجاري: سارب
- العنوان: الرياض، المملكة العربية السعودية
النص الإنجليزي: Contact
- Provider: Khalid Dhafer Saad Alqarni - Freelance Certificate No. FL-002881762
- Trading as: SARP
- Address: Riyadh, Kingdom of Saudi Arabia
هذا النص للاطلاع. ننصح العميل بمراجعة الاتفاقية مع مستشار قانوني سعودي مرخّص قبل الالتزام بها للاستخدام التجاري. وتتوفر نسخة مستقلة من أحكام معالجة البيانات (البند الثامن) بصيغة اتفاقية معالجة بيانات عند الطلب.
سياسة الخصوصية ←