- لن ننظر إلى فواتيرك، أرصدتك، رواتب فريقك، أرقام عملائك، أو أي بيانات مالية خاصة بك — لا للفضول، لا للتحليل، لا للتسويق.
- لن نقرأ محادثاتك مع المساعد الذكي ولا الرسائل التي ترسلها لزبائنك من خلال المنصة.
- لن نُسرّب أي بيان من بياناتك لأي طرف خارجي، لا تجارياً، ولا للأبحاث، ولا بأي صفة كانت.
- لن ندخل إلى حسابك لأي سبب — حتى للدعم الفني — إلا بعد إذن صريح ومسبق منك، يُسجَّل في سجل التدقيق الذي تستطيع مراجعته في أي وقت.
- لن نبيع بياناتك أبداً، لا الآن ولا في المستقبل. لو غُيِّر هيكل الشركة أو بيعت، يبقى هذا التعهد ملزماً للخلف.
1. البيانات التي نجمعها
لتقديم الخدمة، نحفظ على خوادمنا الفئات التالية فقط:
أ. بيانات تشغيلية تُدخلها أنت أو فريقك:
- اسم الشركة، عنوانها، عملتها، لغة الواجهة، شعارها (اختياري).
- جهات الاتصال (عملاء وموردين): الأسماء، الأرقام، البريد الإلكتروني، الرصيد.
- المعاملات المحاسبية: الفواتير، المصاريف، الدفعات، القيود، الذمم.
- المخزون، المستودعات، المشاريع، الفريق، الأهداف، البايبلاين.
- الملفات المرفقة (إيصالات، صور، PDF)، يتم تخزينها مشفّرة على القرص.
ب. بيانات تقنية يلزم جمعها تلقائياً:
- أرقام هواتف المستخدمين الذين سجّلوا الدخول (للمصادقة عبر واتساب).
- عناوين IP وأوقات الدخول (لاكتشاف السلوك المشبوه). لا نخزّن عنوان IP الفعلي — فقط بصمة مُلحَّمة (sha256 مع ملح خاص، 16 خانة فقط) لا يمكن رجوعها لعنوان أصلي.
- سجلات أخطاء التطبيق (تقتصر على معرفات تقنية — لا تشمل محتوى ماليّ).
- تحليلات استخدام مجهولة الهوية: زيارات الصفحات في موقع sejel.app والـdashboard، المتصفح ونظام التشغيل، مصدر الزيارة (referrer + UTM). معرّف الجلسة مُخزَّن في localStorage فقط (لا cookies من طرف ثالث). لا تتبّع Google Analytics ولا Facebook Pixel ولا أي طرف خارجي. ينحفظ كل شيء داخل قاعدة بياناتنا فقط. نحترم متصفح Do-Not-Track — إذا كان مُفعَّلاً عندك، نتجاهل البيكون كلياً.
2. لماذا نُعالج هذه البيانات
الاستخدام الوحيد المسموح هو:
- تشغيل الخدمة التي اشتركت فيها (حساب الأرصدة، إصدار التقارير، إرسال الفواتير، إلخ).
- مصادقة دخولك وحماية الحساب من اختراق.
- إصدار فواتير الاشتراك (الفوترة المتعلقة بسِجِلّ ذاتها).
- الالتزام بأي مطلب قانوني سارٍ في الدولة المستضيفة (مثل الاحتفاظ بسجلات لأغراض ضريبية).
لن نستخدم بياناتك لأي غرض آخر دون إذنك الصريح.
3. من يستطيع الوصول إلى بياناتك
الوصول إلى بياناتك مُقيَّد بحسب الأدوار التالية:
- أنت ومن تختاره من فريقك: وفق الصلاحيات التي تمنحها من إعدادات الفريق.
- أدوات الخدمة الآلية (السيرفر): قراءة البيانات لتقديم الوظائف (تقارير، تنبيهات، نسخ احتياطي). هذه القراءات لا يراها أحد من البشر.
- طاقم سِجِلّ: لا يحق لأحد من فريقنا الدخول إلى بياناتك إلا بعد الحصول على إذن خطي صريح منك، عبر بريد إلكتروني أو طلب رسمي عبر المنصة. كل دخول يُسجَّل تلقائياً في سجل التدقيق.
4. الدعم الفني — الإذن المسبق شرط لازم
الإجراء العملي عند طلبك للدعم:
- تُرسل لنا وصف المشكلة (دون تفاصيل مالية حساسة).
- نُحدّد لك ما إذا كنا نحتاج للوصول الفعلي إلى بياناتك أو يكفينا التعليمات.
- إذا لزم الوصول، نطلب موافقتك الصريحة على نطاق ومدة محددين.
- بعد إنجاز المهمة، يُغلَق الوصول تلقائياً ويُسجَّل في سجل التدقيق.
- تستطيع في أي وقت سحب الإذن.
5. معالجة الذكاء الاصطناعي
عندما تستخدم المساعد الذكي للمحاسبة أو المدير المالي أو المستشار التنفيذي:
- تُرسَل النصوص والأرقام اللازمة إلى مزوّدي الذكاء الاصطناعي (مثل Anthropic أو OpenAI) عبر قنوات مشفّرة لتوليد الإجابة.
- المزوّدون يعملون بموجب اتفاقيات تجارية تمنع تدريب نماذجهم على بياناتك (zero-retention / no-training).
- لا يرى أي بشري لدى المزوّد ما يُرسَل من حسابك.
- نحن لا نخزن نسخاً إضافية من البيانات المرسلة للذكاء الاصطناعي خارج قاعدة بياناتك الأصلية لدينا.
6. المشاركة مع أطراف ثالثة
نشارك جزءاً محدوداً ومحدداً من البيانات مع مزوّدي خدمات أساسيين، فقط بقدر ما يلزم لتشغيل المنصة:
- مزوّدو واتساب الرسميون (360dialog أو Meta Cloud API): محتوى الرسائل التي ترسلها أنت بنفسك أو يرسلها المساعد الذكي نيابة عنك. هؤلاء يخضعون لشروط واتساب.
- مزوّدو الذكاء الاصطناعي (Anthropic, OpenAI): كما ذُكر في القسم 5.
- مزوّد الاستضافة: يحفظ ملفات قاعدة البيانات على خوادم آمنة. لا يطّلع على المحتوى.
- هيئة الزكاة والضريبة والجمارك (ZATCA): نُرسل لها الفواتير الإلكترونية التي تخضع لمتطلبات المرحلة الثانية، إذا اخترت تفعيل تلك الميزة (السعودية فقط).
لا نشارك بياناتك مع جهات تسويقية، شركات إعلانات، شركاء أعمال، أو أي طرف خارج هذه القائمة.
7. أمن البيانات والتشفير
- التشفير أثناء النقل: كل اتصال بين متصفحك وخوادمنا، وبين خوادمنا وأي طرف ثالث، يمرّ عبر TLS/HTTPS.
- التشفير في حالة السكون: قواعد البيانات والملفات تُخزَّن مشفّرة على القرص.
- المصادقة: لا كلمات سر — الدخول عبر رمز يُرسَل لواتساب المسجَّل. لا يمكن لأحد الدخول لحسابك بدون الوصول الفيزيائي لرقمك.
- سجل التدقيق: كل عملية حسّاسة (دخول، تعديل، حذف، سحب بيانات) تُسجَّل بختم زمني ومعرّف للمستخدم. السجل غير قابل للتعديل.
- النسخ الاحتياطي: نُجري نُسخاً احتياطية يومية مشفّرة، تُحفظ لمدة 30 يوماً.
8. مدة الاحتفاظ والحذف
- طالما حسابك نشط، نحتفظ بكل بياناتك ليتسنّى لك الوصول إليها واستخراج التقارير.
- عند إلغاء الاشتراك أو إغلاق الحساب، تظل بياناتك متاحة للتصدير لمدة 90 يوماً.
- بعد 90 يوماً، تُحذف نهائياً من قواعد البيانات النشطة، ثم من النسخ الاحتياطية خلال 30 يوماً إضافياً.
- يمكنك في أي وقت طلب حذف فوري عبر info@cmslevant.com — نُنفّذ الحذف خلال 7 أيام عمل.
9. حقوقك على بياناتك
في أي وقت يحق لك:
- الاطلاع: عرض أي بيان نحتفظ به عنك من لوحة التحكم.
- التصدير: تنزيل بياناتك بصيغة Excel أو JSON.
- التعديل: تصحيح أي معلومة خاطئة مباشرة من المنصة.
- الحذف: حذف حسابك وكل ما يتعلق به نهائياً.
- الاعتراض: على أي معالجة لا تقبلها — راسلنا وسنُجيب خلال 14 يوماً.
- مراجعة سجل التدقيق: لرؤية كل من دخل إلى بياناتك ومتى.
10. في حال وقع اختراق
إذا — لا قدّر الله — وقع اختراق يؤثر على بياناتك:
- سنُبلغك خلال 72 ساعة من اكتشافه.
- سنُوضّح: ماذا تأثر، كيف وقع، ما الإجراءات التي اتخذناها لاحتوائه.
- سنُقدّم لك التوصيات اللازمة لحماية حسابك (تغيير رقم، مراجعة فريق، إلخ).
- سنتعاون مع السلطات المختصة إذا تطلّب الأمر.
11. تواصل معنا
لأي استفسار، طلب، أو شكوى تخصّ خصوصيتك:
- البريد الإلكتروني: info@cmslevant.com
- الموقع: sejel.app
- نرد على كل طلبات الخصوصية خلال 14 يوماً.
- We will not look at your invoices, balances, payroll, customer numbers, or any of your financial data — not for curiosity, not for analysis, not for marketing.
- We will not read your conversations with the AI assistant or the messages you send your customers through the Platform.
- We will not leak any of your data to any external party — commercially, for research, or in any capacity.
- We will not enter your account for any reason — even for technical support — without your explicit, prior consent, which is recorded in the audit log you can inspect at any time.
- We will never sell your data, now or in the future. If the company structure changes or the business is sold, this pledge binds the successor.
1. What data we collect
To provide the Service, we store only the following categories on our servers:
a. Operational data you or your team enter:
- Company name, address, currency, UI language, logo (optional).
- Contacts (customers and suppliers): names, numbers, email, balance.
- Accounting transactions: invoices, expenses, payments, journal entries, receivables.
- Inventory, warehouses, projects, team, targets, pipeline.
- Attached files (receipts, images, PDFs), stored encrypted at rest.
b. Technical data we must collect automatically:
- Phone numbers of users who log in (for WhatsApp authentication).
- IP addresses and login times (to detect suspicious behaviour). We do NOT store the raw IP — only a salted SHA-256 hash truncated to 16 characters, which cannot be reversed to the original address.
- Application error logs (limited to technical identifiers — never financial content).
- Anonymous usage analytics: pageviews on sejel.app and the dashboard, browser + OS, traffic source (referrer + UTM). The session identifier lives in localStorage only (no third-party cookies). No Google Analytics, no Facebook Pixel, no external tracker — everything stays inside our own database. We honour Do-Not-Track: if your browser sends DNT=1, the beacon is dropped server-side.
2. Why we process this data
The only permitted use is:
- Running the Service you subscribed to (computing balances, issuing reports, sending invoices, etc.).
- Authenticating your login and protecting the account from compromise.
- Issuing your subscription invoices (Sejel's own billing).
- Complying with applicable legal obligations in the hosting jurisdiction (e.g. record-keeping for tax).
We will NOT use your data for any other purpose without your explicit consent.
3. Who can access your data
Access to your data is strictly role-restricted:
- You and the team members you choose: per the permissions you grant in team settings.
- Automated service tools (the server): read your data to provide functionality (reports, alerts, backups). These reads are never seen by any human.
- Sejel staff: No one on our team may access your data without your explicit, written prior consent, by email or a formal in-platform request. Every access is automatically recorded in the audit log.
4. Technical support — prior consent is required
The practical procedure when you request support:
- You send us a description of the issue (without sensitive financial details).
- We tell you whether we actually need to access your data or whether guidance will suffice.
- If access is required, we request your explicit consent for a defined scope and duration.
- After the task is complete, access is automatically closed and recorded in the audit log.
- You can revoke consent at any time.
5. AI processing
When you use the AI accounting assistant, the AI CFO, or the CEO Advisor:
- The text and numbers needed are sent to our AI providers (such as Anthropic or OpenAI) over encrypted channels to generate the response.
- The providers operate under commercial agreements that prohibit training their models on your data (zero-retention / no-training).
- No human at the provider sees what is sent from your account.
- We do not store additional copies of the data sent to AI outside your original database with us.
6. Third-party sharing
We share a limited, specific subset of data with essential service providers, only to the extent necessary to operate the Platform:
- Official WhatsApp providers (360dialog or Meta Cloud API): the content of messages you send yourself or the AI assistant sends on your behalf. These are subject to WhatsApp's terms.
- AI providers (Anthropic, OpenAI): as described in section 5.
- Hosting provider: stores the database files on secure servers. Does not view the content.
- ZATCA (Zakat, Tax and Customs Authority): we send it the e-invoices subject to Phase 2 requirements, if you activate that feature (Saudi Arabia only).
We do not share your data with marketers, ad networks, business partners, or any party outside this list.
7. Data security & encryption
- Encryption in transit: every connection between your browser and our servers, and between our servers and any third party, passes over TLS/HTTPS.
- Encryption at rest: databases and files are stored encrypted on disk.
- Authentication: no passwords — login via a code sent to the registered WhatsApp number. No one can access your account without physical access to your phone.
- Audit log: every sensitive operation (login, edit, delete, data pull) is recorded with a timestamp and user identifier. The log is immutable.
- Backups: we take daily encrypted backups, retained for 30 days.
8. Retention & deletion
- While your account is active, we retain all your data so you can access it and extract reports.
- When you cancel or close the account, your data remains exportable for 90 days.
- After 90 days, it is permanently deleted from the live databases, then from backups within an additional 30 days.
- You may at any time request immediate deletion via info@cmslevant.com — we perform the deletion within 7 business days.
9. Your rights over your data
At any time you have the right to:
- Inspect: view any data we hold about you from the dashboard.
- Export: download your data as Excel or JSON.
- Correct: fix any incorrect information directly from the Platform.
- Delete: permanently delete your account and everything related to it.
- Object: to any processing you do not accept — email us and we will respond within 14 days.
- Review audit log: see who accessed your data and when.
10. In case of a breach
If — heaven forbid — a breach occurs that affects your data:
- We will notify you within 72 hours of detection.
- We will explain: what was affected, how it happened, what we have done to contain it.
- We will provide recommendations to protect your account (change number, review team, etc.).
- We will cooperate with the competent authorities where required.
11. Contact us
For any privacy question, request, or complaint:
- Email: info@cmslevant.com
- Website: sejel.app
- We respond to all privacy requests within 14 days.