سياسة خصوصية كومبلاي
تاريخ النفاذ: ٢٥ أغسطس ٢٠٢٦م
تاريخ آخر تحديث: ٢٤ أغسطس ٢٠٢٦م
الإصدار: ١٫٩
١. التمهيد
١/١ تشغل شركة الطموح الجريء ("كومبلاي" أو "نحن") خدمة كومبلاي لمتابعة الالتزام. ونتعامل مع البيانات الشخصية وفقا لـنظام حماية البيانات الشخصية في المملكة العربية السعودية الصادر بالمرسوم الملكي رقم (م/١٩) وتاريخ ٩/٢/١٤٤٣هـ، المعدل بالمرسوم الملكي رقم (م/١٤٨) وتاريخ ٥/٩/١٤٤٤هـ ("النظام")، ولائحته التنفيذية، ولائحة نقل البيانات الشخصية خارج المملكة، والأدلة الصادرة عن الهيئة السعودية للبيانات والذكاء الاصطناعي ("سدايا").
١/٢ توضح هذه السياسة ما نجمعه من بيانات شخصية، وأغراض ذلك، وأسسه النظامية، ومن نشاركها معه، وأين تخزن، ومدد الاحتفاظ بها، وحقوقك.
١/٣ يقصد بـ"البيانات الشخصية" كل بيان، مهما كان مصدره أو شكله، من شأنه أن يؤدي إلى معرفة الفرد على وجه التحديد، أو يجعل التعرف عليه ممكنا بصفة مباشرة أو غير مباشرة.
١/٤ تعد هذه السياسة جزءا من شروط استخدام كومبلاي.
٢. من نحن
| البند | التفاصيل |
|---|
| جهة التحكم | شركة الطموح الجريء، شركة ذات مسؤولية محدودة (شخص واحد) |
| الرقم الوطني الموحد | ٧٠٣٨٥٠٢٨٧٣ |
| تاريخ التسجيل | ٢٨/٠٢/٢٠٢٤م |
| المقر المسجل | الرياض، المملكة العربية السعودية |
| التواصل في جميع مسائل الخصوصية | info@komplyapp.com |
| مسؤول حماية البيانات الشخصية | لم يعين بتاريخ النفاذ، وتعالج استفسارات الخصوصية عبر العنوان أعلاه. |
٣. جهة التحكم وجهة المعالجة
٣/١ حين نكون جهة التحكم. نحدد أغراض المعالجة ووسائلها، وتسري هذه السياسة مباشرة، على:
- بيانات حسابك (البريد الإلكتروني، وكلمة المرور، واسم العرض)؛
- ملف منشأتك وإجابات الاستبيان؛
- نشاط المتابعة والملاحظات؛
- المراسلات التي ترسلها إلينا؛
- البيانات التقنية الناتجة عن استخدامك الخدمات.
٣/٢ حين نكون جهة المعالجة. قد تتضمن المستندات التي ترفعها، كالسجلات التجارية والتراخيص والشهادات، بيانات شخصية عن أفراد غيرك، كالملاك أو المديرين أو المفوضين. وبالنسبة لتلك البيانات، أنت جهة التحكم ونحن جهة المعالجة، ونعمل بناء على تعليماتك. وأنت مسؤول عن توافر أساس نظامي لرفعها وعن أي إشعارات أو موافقات لازمة. وتحدد التزاماتنا في البند (٨) من شروط الاستخدام المتاحة على www.komplyapp.com/terms.
٣/٣ إذا تواصل معنا فرد بشأن بيانات لا نحوزها إلا بصفتنا جهة معالجة، أحلناه إليك وقدمنا لك المساعدة في الاستجابة.
٤. ما نجمعه
٤/١ البيانات التي تقدمها لنا
| الفئة | المحتوى |
|---|
| بيانات الحساب | البريد الإلكتروني، وكلمة المرور (تحفظ مجزأة تشفيريا ولا تحفظ بصيغة مقروءة إطلاقا)، واسم العرض |
| بيانات المنشأة | اسم المنشأة، ورقم السجل التجاري |
| إجابات الاستبيان | الشكل النظامي، والقطاع، وشريحة الإيرادات، وعدد الموظفين، والملكية الأجنبية، ووجود مقر فعلي، وما إذا كانت المنشأة تعالج بيانات شخصية |
| بيانات المتابعة | الالتزامات التي تضع عليها علامة الإنجاز أو الإخفاء، والتواريخ التي تدخلها، والالتزامات التي تضيفها |
| دورك | ما تخبرنا به عن كونك صاحب منشأة أو محاسبا أو محاميا أو مسؤول التزام أو غير ذلك مما تصفه بكلماتك. ومن بين الإجابات أفضل عدم الإفصاح |
| إقرارات الامتثال | سجل بكل مرة تعلم فيها التزاما مستمرا بوصفه مطبقا لدى منشأة أو تتراجع عن ذلك، مع التاريخ والحساب الذي قام به |
| المستندات المرفوعة | ملفات PDF أو JPEG أو PNG بحجم حتى ١٠ ميغابايت، وقد تتضمن بيانات شخصية ومعرفات تخصك أو تخص غيرك |
| الملاحظات | بلاغات عدم دقة الالتزامات، والتقييمات والتعليقات التي ترسلها |
| المراسلات | الرسائل التي ترسلها إلى info@komplyapp.com |
لا نجمع أرقام الهوية الوطنية أو الإقامة كبيانات منظمة، وقد تتضمنها المستندات التي تختار رفعها.
لا نجمع بيانات بطاقات الدفع ولا نخزنها. وتعالج بيانات البطاقة مباشرة لدى ميسر (Moyasar).
٤/٢ البيانات المتولدة تلقائيا
| الفئة | المحتوى |
|---|
| البيانات التقنية | عنوان بروتوكول الإنترنت، ونوع المتصفح والجهاز، وما يماثلها مما يتولد عند اتصال متصفحك ببنيتنا التحتية وبشبكة Cloudflare |
| سجلات الخادم والمصادقة | أحداث تسجيل الدخول، والطوابع الزمنية، والأخطاء التي تسجلها خوادمنا |
| بيانات الجلسة | معرف جلسة يحفظ في التخزين المحلي لمتصفحك لإبقائك مسجل الدخول |
| تحليلات الاستخدام | بيانات مجمعة عن الصفحات والخصائص المستخدمة، يجمعها برنامج Umami المستضاف على خادمنا في الرياض، ولا يضع ملفات ارتباط، ولا يسند معرفا دائما، ولا يبني ملفا عنك |
٤/٣ ملفات الارتباط
لا نستخدم ملفات ارتباط. تحفظ جلسة دخولك عبر التخزين المحلي في متصفحك، وهو لازم لعمل الخدمات ويمسح عند تسجيل الخروج. ولأننا لا نضع أي ملفات ارتباط للتحليلات أو الإعلانات أو التتبع، فلا يعرض إشعار موافقة.
ونستخدم Umami مستضافا ذاتيا على خادمنا في الرياض لفهم الصفحات والخصائص الأكثر استخداما. وهو لا يستخدم ملفات ارتباط، ولا يجمع بيانات شخصية، ولا تغادر بياناته المملكة ولا تصل إلى أي طرف آخر.
وإذا أضيفت أي أداة تحليلات أو رصد أعطال تابعة لطرف آخر، حدث هذا البند والبند (٦)، وأخذت الموافقة متى لزمت قبل تفعيلها.
٥. أثر عدم تقديم البيانات
بيانات الحساب وبيانات المنشأة وإجابات الاستبيان إلزامية، إذ لا تستطيع الخدمات إنتاج قائمة التزامات بدونها.
ودورك إلزامي كذلك، لكن لسبب مختلف نفضل ذكره صراحة بدل تركه تحت الجملة السابقة. فهو لا يؤثر في قائمة التزاماتك إطلاقا. ونسأل عنه لأن صاحب المنشأة والمحاسب والمحامي ومسؤول الالتزام يحتاجون أمورا مختلفة من القائمة نفسها، ولا نحسن البناء لمن لا نعرفهم. ولأنه ليس لازما لتقديم الخدمات، فمن بين الإجابات أفضل عدم الإفصاح، وهي إجابة كاملة لا يترتب عليها شيء.
أما رفع المستندات وإرسال الملاحظات فـاختياري.
٦. أغراض المعالجة وأسسها النظامية
| الغرض | الأساس النظامي |
|---|
| إنشاء حسابك وتشغيله وتقديم الخدمات | تنفيذ عقد أنت طرف فيه |
| مطابقة الالتزامات بملف منشأتك | تنفيذ عقد |
| تخزين المستندات التي ترفعها مقابل الالتزامات | تنفيذ عقد |
| حفظ سجل قابل للمراجعة لأوضاع الامتثال التي تسجلها على منشأة | تنفيذ عقد؛ ومصلحتنا المشروعة في حفظ سجل امتثال دقيق للمنشأة |
| إرسال رسائل المصادقة وتنبيهات المواعيد المجدولة | تنفيذ عقد |
| الرد على استفساراتك وشكاواك | تنفيذ عقد؛ مصلحتنا المشروعة في دعم المستخدمين |
| حفظ سجلات الخادم والمصادقة لتأمين الخدمات والتحقق من إساءة الاستخدام | مصلحتنا المشروعة في حماية أنظمتنا ومستخدمينا |
| قياس الاستخدام المجمع للخدمات عبر أداة التحليلات المستضافة ذاتيا | مصلحتنا المشروعة في فهم كيفية استخدام الخدمات وتحسينها |
| مراجعة بلاغات الدقة والملاحظات لتصحيح قاعدة الالتزامات وتحسينها | مصلحتنا المشروعة في تطوير الخدمات |
| معرفة من يستخدم الخدمات لنبني لهم | مصلحتنا المشروعة في تطوير الخدمات لمن يستخدمونها فعلا |
| الفوترة والسداد | تنفيذ عقد؛ الامتثال لالتزام نظامي |
| الامتثال للالتزامات النظامية والاستجابة للطلبات المشروعة من الجهات المختصة | الامتثال لالتزام نظامي |
| إثبات الحقوق النظامية أو ممارستها أو الدفاع عنها | مصلحتنا المشروعة في حماية حقوقنا |
٦/١ المصلحة المشروعة. حين نستند إليها، نتحقق من أن المعالجة ضرورية وأنها لا تمس حقوقك. ولا نستند إليها في معالجة البيانات الشخصية الحساسة.
٦/٢ لا نرسل رسائل تسويقية. الرسائل التي نرسلها هي رسائل مصادقة، وتنبيهات مواعيد، وردود على استفساراتك، وإشعارات خدمية كتعديل هذه الوثائق. وإذا استحدثنا التسويق مستقبلا، حصلنا على موافقتك أولا، ووفرنا وسيلة مجانية لإلغاء الاشتراك في كل رسالة، وفق ما يوجبه النظام.
٦/٣ لن نعالج بياناتك لغرض يتعارض مع الغرض الذي جمعت من أجله. وإذا نشأ غرض جديد، حدثنا هذه السياسة وحصلنا على الموافقة متى لزمت.
٦/٤ سحب الموافقة. متى استندنا إلى الموافقة، جاز لك سحبها في أي وقت دون مقابل بمراسلتنا على info@komplyapp.com. ولا يؤثر السحب في المعالجة السابقة عليه ولا في المعالجة القائمة على أساس آخر.
٧. البيانات الشخصية الحساسة
٧/١ تشمل البيانات الشخصية الحساسة بموجب النظام: ما يدل على الأصل العرقي أو القبلي، أو المعتقد الديني أو الفكري أو السياسي، والبيانات الأمنية والجنائية، وبيانات السمات الحيوية أو الوراثية المعرفة للفرد، والبيانات الصحية، وما يدل على أن أحد الوالدين أو كليهما مجهول.
٧/٢ لا نطلب بيانات شخصية حساسة، والخدمات غير مصممة لحفظها. فلا ترفعها.
٧/٣ وإذا رفعت مستندا يتضمن بيانات شخصية حساسة، فأنت مسؤول عن الموافقة الصريحة أو الأساس النظامي الآخر الذي يشترطه النظام.
٧/٤ لا نستخدم أي بيانات شخصية في التنميط أو الإعلان أو حملات التوعية.
٨. مع من نشارك البيانات
لا نبيع البيانات الشخصية ولا نؤجرها ولا نتاجر بها، ولا نشاركها إلا وفق ما يأتي.
| الجهة | ما تتولاه | الموقع |
|---|
| Oracle Cloud Infrastructure | استضافة قاعدة البيانات والتطبيق والملفات المرفوعة والنسخ الاحتياطية المشفرة | الرياض، السعودية (`me-riyadh-1`) |
| Oracle Email Delivery | إرسال رسائل المصادقة وتنبيهات المواعيد | الرياض، السعودية |
| Umami (مستضاف ذاتيا) | تحليلات الاستخدام المجمعة، وليست طرفا آخر إذ تعمل على خادمنا | الرياض، السعودية |
| Cloudflare | تسليم الواجهة الأمامية الثابتة، ولا تحوز بيانات حسابات، لكنها تعالج عناوين الإنترنت أثناء النقل | خارج المملكة |
| Google Workspace | صندوق مراسلاتنا (info@komplyapp.com)، فتخزن الرسائل التي ترسلها إلينا وتعالج لدى Google | خارج المملكة |
| ميسر (Moyasar) | مدفوعات البطاقات، وترسل بيانات البطاقة إليها مباشرة ولا نطلع عليها. وتعمل ميسر بوصفها جهة تحكم مستقلة في تلك البيانات، لا معالجا لدينا. انظر البند ٨/٣ | انظر البند ٩/٢(ج) |
| الجهات المختصة | الإفصاح الذي يوجبه النظام أو أمر قضائي أو طلب مشروع، ومنها سدايا ووزارة التجارة وهيئة الزكاة والضريبة والجمارك وجهات إنفاذ النظام | المملكة |
| الجهة المستحوذة | في حال بيع النشاط أو إعادة هيكلته، بشرط توفير حماية مماثلة | لا ينطبق |
٨/١ نلزم المزودين بمعالجة البيانات الشخصية بالقدر اللازم لتقديم خدمتهم لنا فقط.
٨/٢ تتوفر قائمة محدثة بالمزودين عند الطلب من info@komplyapp.com.
٨/٣ ميسر (Moyasar) جهة تحكم مستقلة، لا معالج لدينا. عند إدخال بيانات بطاقتك فإنك تقدمها إلى ميسر مباشرة، ولا نستلم رقم البطاقة ولا نخزنه إطلاقا. وميسر هي من يقرر كيفية معالجة تلك البيانات وهي المسؤولة عنها بصفتها المستقلة. وتسري عليها سياسة خصوصية ميسر المتاحة على moyasar.com/ar/resources/privacy-policy. ولا نحتفظ إلا بما تعيده إلينا ميسر: نوع البطاقة، وآخر أربعة أرقام، وتاريخ الانتهاء، ومعرفات تربط عملية السداد بحسابك. ولك أن تطلب حذف البطاقة المحفوظة في أي وقت، فنحذفها لدى ميسر أولا ثم نزيلها من سجلاتنا، وتبقى مدتك المدفوعة كما هي.
٨/٤ مزود المدفوعات السابق. حتى ٢٣ أغسطس ٢٠٢٦ كانت المدفوعات تعالج لدى Tap Payments. فإن كنت قد سددت عبرها فقد عولجت بيانات بطاقتك لديها بصفتها جهة تحكم مستقلة، وتسري عليها سياستها المتاحة على www.tap.company/en-sa/privacy. ونحتفظ بسجلات تلك المدفوعات ضمن سجلاتنا المحاسبية للمدة الموضحة في جدول مدد الاحتفاظ.
٨/٤ الوصول بحساب واحد. يتم الوصول إلى الخدمات من خلال حساب واحد، ولا تتوفر حاليا إمكانية دعوة مستخدمين إضافيين إلى المنشأة.
٩. أين تخزن بياناتك
٩/١ تخزن بيانات حسابك وملف منشأتك وإجابات الاستبيان وبيانات المتابعة والمستندات المرفوعة على بنية تحتية في مدينة الرياض بالمملكة العربية السعودية، لدى Oracle Cloud Infrastructure في نطاق `me-riyadh-1`. وترسل رسائل المصادقة والتنبيهات من النطاق ذاته.
٩/٢ وتقع معالجة محدودة خارج المملكة، ونبينها صراحة بدلا من الادعاء بخلاف ذلك:
(أ) Cloudflare تتولى تسليم الواجهة الأمامية الثابتة، ولا تحوز بيانات حسابات، لكن عنوان الإنترنت الخاص بك وبيانات الاتصال تمر عبر شبكتها خارج المملكة.
(ب) Google Workspace تستضيف صندوق مراسلاتنا، فإذا راسلتنا بالبريد الإلكتروني، خزن محتوى رسالتك، بما فيه أي بيانات شخصية، وعولج لدى Google خارج المملكة.
(ج) ميسر (Moyasar) تعالج بيانات بطاقة الدفع، وتعمل تحت رقابة البنك المركزي السعودي وإشرافه. وتفيد سياسة الخصوصية المنشورة لديها بأنها لا تنقل البيانات الشخصية خارج المملكة العربية السعودية. ولأن ميسر تجمع تلك البيانات منك مباشرة بوصفها جهة تحكم مستقلة، ولا تمر عبر أنظمتنا، فإن ترتيبات تلك البيانات تحكمها سياستها وجهتها الرقابية لا نحن.
٩/٣ ومتى نقلت بيانات شخصية خارج المملكة، استندنا إلى الحالات التي تجيزها المادة (التاسعة والعشرون) من النظام، وقصرنا النقل على الحد الأدنى اللازم، وتحققنا من ألا يمس بالأمن الوطني أو بالمصالح الحيوية للمملكة.
٩/٤ يرجى عدم إرسال بيانات شخصية حساسة أو سرية إلينا عبر البريد الإلكتروني، واستخدام الخدمات نفسها المستضافة داخل المملكة.
١٠. مدد الاحتفاظ
| البيانات | مدة الاحتفاظ |
|---|
| بيانات الحساب والمنشأة والاستبيان والمتابعة | طوال بقاء حسابك مفتوحا |
| المستندات المرفوعة | طوال بقائها مرفقة، أو حتى تحذفها أو تحذف المنشأة المرتبطة بها |
| البيانات التي تحذفها | تزال من قاعدة البيانات الحية ومن التخزين فورا، سواء حذفت مستندا أو منشأة أو حسابك كله |
| قيود الحذف | كل حذف لحساب أو لمنشأة يترك قيدا واحدا، أيا كان من نفذه: أنت من إعداداتك، أو مسؤول بناء على طلبك، أو إجراء عدم النشاط الموضح أدناه. ويسجل القيد التاريخ والبريد الإلكتروني للحساب وما حذف ومقداره، وسبب الحذف متى تصرف مسؤول. ولا يحفظ سواه. ولا يزيله الحذف الذي يصفه، وهذا مقصود، إذ لن يستطيع قيد حذف يحذف نفسه أن يجيب عن السؤال الذي وجد من أجله، وهو هل حذفنا فعلا ما طلبت حذفه |
| إقرارات الامتثال | تحذف مع المنشأة التي تخصها. وإذا أتيح مستقبلا وصول مشترك إلى المنشأة، فإن الإقرار المتروك على منشأة لا تملكها يبقى مع تلك المنشأة، مع إزالة هويتك منه، فلا يبقى فيه إلا أن الالتزام سجل بوصفه مطبقا وتاريخ ذلك |
| أرشيف تصدير البيانات | يحفظ في مساحة خاصة ٧ أيام بعد جهوزية التصدير ثم يحذف تلقائيا، ولا يستطيع تنزيله سواك |
| النسخ الاحتياطية المشفرة | تحفظ ٣٠ يوما ثم تنقضي تلقائيا، وقد تبقى البيانات المحذوفة في نسخة احتياطية حتى ٣٠ يوما بعد حذفها |
| المراسلات | تحذف الرسالة بعد مرور ٢٤ شهرا على تاريخ إرسالها. ونحذفها ضمن مراجعة مجدولة وليس تلقائيا، لذلك قد تبقى مدة قصيرة بعد ذلك |
| سجلات الخادم والمصادقة | ٩٠ يوما |
| سجلات الفوترة والمحاسبة | تحفظ للمدة الدنيا التي تقتضيها الأنظمة الضريبية وأنظمة الشركات |
| الحسابات غير النشطة | بعد ٢٤ شهرا من عدم النشاط نراسلك على بريدك المسجل، فإن لم تستجب حذف الحساب وبياناته بعد ٣٠ يوما |
١٠/١ نتلف البيانات الشخصية متى انتفت الحاجة إليها لتحقيق غرض الجمع، ما لم يوجب النظام الاحتفاظ بها أو تكن لازمة لإثبات حق أو الدفاع عنه.
١٠/٢ الحذف نهائي، ولا يمكن استرجاع البيانات بعد حذف الحساب وفق إجراء عدم النشاط.
١١. الأمن
١١/١ نبين أدناه التدابير المطبقة فعليا، ولا ندعي شهادات أو ضوابط لا نحوزها.
المطبق حاليا:
- التشفير أثناء النقل عبر بروتوكول TLS، ينهى عند الخادم الوكيل العكسي لدينا؛
- التشفير أثناء التخزين وفق ما توفره Oracle Cloud افتراضيا لتشفير وحدات التخزين؛
- حفظ كلمات المرور مجزأة تشفيريا، ولا تحفظ بصيغة مقروءة إطلاقا؛
- التحكم في الوصول على مستوى السجلات في قاعدة البيانات، بحيث لا يستطيع حساب قراءة منشآت حساب آخر، ولا كتابة أي شيء في منشأة ليس عضوا فيها. والمسؤولون استثناء معلن، موضح في البند ١١/٣. وهذا مختبر لا مجرد مؤكد: قبل نشر كل إصدار من هذه السياسة نشغل اختبارا آليا يسجل الدخول بحسابات حقيقية منفصلة ويحاول تلك القراءات والكتابات بين الحسابات على النظام الحي، ويفشل الاختبار إذا نجحت أي منها؛
- حفظ الملفات المرفوعة في مساحة تخزين خاصة غير قابلة للوصول عبر رابط مباشر، ومقصورة على الحساب المالك للمنشأة المعنية. ولا يمنح المسؤولون أي وصول إلى تلك المساحة، ولا إلى المساحة الخاصة المنفصلة التي يحفظ فيها أرشيف تصدير البيانات، وكلاهما مقصود. ويؤكد الاختبار نفسه أن حساب المسؤول لا يستطيع تنزيل أي من مستنداتك، ولا الحصول على رابط لها، ولا سرد ما هو محفوظ. انظر البند ١١/٣؛
- تقييد أنواع الملفات وأحجامها عند الرفع؛
- نسخ احتياطية يومية مشفرة إلى Object Storage بمدة احتفاظ ٣٠ يوما، مع إجراء استعادة مختبر.
غير المطبق بعد، ويجري العمل عليه:
- خطة موثقة للاستجابة للحوادث؛
- سجل لحالات تسريب البيانات الشخصية؛
- مراجعات دورية للصلاحيات؛
- اختبار اختراق مستقل.
١١/٢ لا يوجد نظام آمن بصورة مطلقة. وأنت مسؤول عن سرية كلمة مرورك وعن تأمين أجهزتك وبريدك الإلكتروني.
١١/٣ اطلاع المسؤولين على حسابك. يستطيع عدد محدود من مسؤولينا فتح سجل حسابك، لدعمك أو لبحث مشكلة أو للرد على استفسار يتعلق بالفوترة. والذي يطلعون عليه هو اسم العرض والبريد الإلكتروني والمنشآت المرتبطة بحسابك والاشتراك والالتزامات المسجلة على تلك المنشآت وسجل قبولك لهذه الوثائق وأسماء المستندات التي رفعتها وتواريخها، دون المستندات نفسها إطلاقا، والدور الذي ذكرته لنا. ويلزم قبل فتح السجل أن يختار المسؤول سببا من قائمة محددة، وأن يكتبه صراحة متى كان السبب خارجها. ويقيد ذلك السبب وهوية المسؤول ووقت الاطلاع في سجل وصول لا يستطيع تعديله ولا حذفه. ولا يستطيع المسؤولون فتح المستندات التي ترفعها، ولا فتح أرشيف تصدير البيانات، فهاتان المساحتان لا تمنحانهم أي وصول. ونحن نفضل إخبارك بهذا صراحة على أن تفترض أن لا أحد يستطيع الاطلاع على حسابك.
١٢. تسريب البيانات الشخصية
١٢/١ عند وقوع تسريب للبيانات الشخصية، نبلغ سدايا خلال اثنتين وسبعين (٧٢) ساعة من علمنا به، وفقا للائحة التنفيذية للنظام.
١٢/٢ ونبلغ الأفراد المتأثرين دون تأخير غير مبرر متى كان من شأن التسريب إلحاق ضرر جسيم بهم أو ببياناتهم، مع بيان ما وقع وآثاره المحتملة وما يمكننا وما يمكنهم فعله.
١٢/٣ ومتى مس التسريب بيانات نحوزها بصفتنا جهة معالجة لك، أبلغناك دون تأخير غير مبرر لتفي بالتزاماتك.
١٢/٤ خطة الاستجابة للحوادث الموثقة قيد الإعداد، وحتى اكتمالها تتولى إدارة الشركة معالجة الحوادث مباشرة عبر info@komplyapp.com.
١٣. حقوقك
مع مراعاة الضوابط والاستثناءات الواردة في النظام:
| الحق | مضمونه |
|---|
| العلم | معرفة غرض الجمع وأساسه النظامي، وهويتنا، وما إذا كانت البيانات إلزامية أم اختيارية، والجهات التي قد يفصح لها عن بياناتك |
| الوصول | تأكيد ما إذا كنا نحوز بياناتك الشخصية والاطلاع عليها |
| الحصول على نسخة | تسلم بياناتك بصيغة مقروءة وواضحة ودون مقابل |
| التصحيح | تصحيح البيانات غير الصحيحة أو الناقصة أو غير المحدثة أو استكمالها أو تحديثها |
| الإتلاف | إتلاف البيانات متى انتفت الحاجة إليها لتحقيق غرض الجمع |
| سحب الموافقة | متى استندت المعالجة إلى الموافقة |
| التظلم | أمام سدايا، انظر البند (١٥) |
١٣/١ كيفية الممارسة. راسلنا على info@komplyapp.com مبينا الحق الذي ترغب في ممارسته. وحذف الحساب متاح كذلك ذاتيا من إعدادات الحساب، ويزيل بياناتك من قاعدة البيانات الحية ومن التخزين فورا. ولك أيضا حذف منشأة واحدة ومستنداتها دون إغلاق حسابك. وفي الحالتين نحفظ قيد حذف واحدا، ويبين البند ١٠ ما يتضمنه بالضبط وسبب حفظه.
١٣/٢ التصدير. تستطيع تصدير بياناتك بنفسك من إعدادات حسابك دون الرجوع إلينا. ونجهز لك أرشيفا يتضمن سجلات حسابك ومنشآتك، والدور الذي ذكرته لنا، وإجابات الاستبيان، وبيانات المتابعة، وإقرارات الامتثال المسجلة على منشآتك، وملاحظاتك، وسجل قبولك لهذه الوثائق، ونسخا من المستندات التي رفعتها. ويبقى جاهزا للتنزيل ٧ أيام ثم يحذف تلقائيا، ولك أن تطلب غيره. ويتاح طلب تصدير واحد كل ٢٤ ساعة. وإذا فضلت أن ننتج النسخة لك، فاكتب إلى info@komplyapp.com.
١٣/٣ التحقق. نتحقق من هويتك قبل التنفيذ، وقد نطلب معلومات معقولة لهذا الغرض فقط.
١٣/٤ المدة. نستجيب خلال ثلاثين (٣٠) يوما من الطلب المستوفي، وتمدد ثلاثين (٣٠) يوما أخرى للطلبات المعقدة أو المتكررة، مع إشعارك خلال المدة الأولى.
١٣/٥ الحدود. يجوز لنا رفض الطلب أو تقييده حيث يجيز النظام، كتعارضه مع التزام نظامي أو قضائي، أو إضراره بحقوق الغير، أو إخلاله بتحقيق قائم، أو كونه غير مبرر أو مبالغا فيه بصورة ظاهرة. وسنبين الأسباب ونعلمك بحقك في التظلم.
١٣/٦ ممارسة حقوقك مجانية.
١٤. الأطفال
١٤/١ الخدمات معدة للاستخدام التجاري وغير موجهة لمن هم دون الثامنة عشرة (١٨).
١٤/٢ لا نجمع عن علم بيانات عن طفل أو ناقص أهلية دون موافقة وليه. وإذا رأيت خلاف ذلك، فراسلنا على info@komplyapp.com وسنتحقق ونحذفها عند الاقتضاء.
١٥. الشكاوى
١٥/١ يرجى عرض ملاحظاتك علينا أولا على info@komplyapp.com.
١٥/٢ ولك في أي وقت التظلم أمام الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) على https://sdaia.gov.sa، عبر قنواتها الرسمية لشكاوى حماية البيانات الشخصية.
١٥/٣ وفي مسائل المستهلك والتجارة الإلكترونية، يمكنك التواصل مع وزارة التجارة عبر قنواتها الرسمية.
١٦. المعالجة الآلية
١٦/١ تطابق الخدمات الالتزامات بمنشأتك عبر محرك قائم على قواعد يطبق على إجابات الاستبيان، وهو ما يحدد البنود التي تظهر في قائمتك.
١٦/٢ ولا يعد ذلك قرارا يرتب أثرا نظاميا عليك، بل اقتراحا يخضع لمراجعتك، وقد يكون ناقصا أو خاطئا، وانظر شروط الاستخدام.
١٦/٣ لا تستخدم الخدمات الذكاء الاصطناعي، ولا نستخدم بياناتك في تدريب أي نموذج.
١٧. تعديل هذه السياسة
١٧/١ قد نحدث هذه السياسة لمواكبة تغير الأنظمة أو ممارساتنا، بما في ذلك عند استحداث التحليلات أو رصد الأعطال أو الفوترة أو خصائص جديدة.
١٧/٢ تنشر السياسة المحدثة بتاريخ نفاذ جديد، وفي التعديلات الجوهرية نشعرك قبل ثلاثين (٣٠) يوما على الأقل عبر البريد الإلكتروني أو داخل المنصة.
١٧/٣ ومتى تطلب التعديل موافقتك بموجب النظام، حصلنا عليها قبل نفاذه.
١٨. التواصل
info@komplyapp.com
شركة الطموح الجريء
١٩. اللغة
صدرت هذه السياسة باللغتين العربية والإنجليزية. وفي حال وجود أي اختلاف أو تباين في التفسير، تسود النسخة العربية، وهي المعول عليها أمام محاكم المملكة العربية السعودية وجهاتها المختصة.
© ٢٠٢٦ شركة الطموح الجريء. جميع الحقوق محفوظة.
KOMPLY PRIVACY POLICY
Effective Date: 25 August 2026
Last Updated: 24 August 2026
Version: 1.9
1. INTRODUCTION
1.1 Altamuh Aljariy Company ("Komply", "we", "us") operates the Komply compliance-tracking service. We handle personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, Royal Decree No. M/19 dated 09/02/1443H as amended by Royal Decree No. M/148 dated 05/09/1444H (the "PDPL"), its Implementing Regulations, the Regulations on Personal Data Transfer outside the Kingdom, and guidance issued by the Saudi Data & Artificial Intelligence Authority ("SDAIA").
1.2 This Policy explains what personal data we collect, why, on what legal basis, who we share it with, where it is stored, how long we keep it, and what rights you have.
1.3 "Personal data" means any data, whatever its source or form, that may lead to identifying an individual specifically, or make identifying them possible directly or indirectly.
1.4 This Policy forms part of the Komply Terms of Use.
2. WHO WE ARE
| Item | Details |
|---|
| Data Controller | شركة الطموح الجريء (Altamuh Aljariy Company), a single-person LLC |
| Unified National Number | 7038502873 |
| Date of Registration | 28/02/2024 |
| Registered Office | Riyadh, Kingdom of Saudi Arabia |
| Contact for all privacy matters | info@komplyapp.com |
| Data Protection Officer | Not appointed as at the Effective Date. Privacy enquiries are handled at the address above. |
3. CONTROLLER AND PROCESSOR
3.1 Where we are the controller. We decide the purposes and means of processing, and this Policy applies directly, for:
- your account data (email, password, display name);
- your business profile and questionnaire answers;
- your tracker activity and feedback;
- correspondence you send us;
- technical data generated when you use the Services.
3.2 Where we are a processor. Documents you upload, such as commercial registrations, licences and certificates, may contain personal data about individuals other than you, such as owners, managers or signatories. For that data you are the controller and we are the processor, acting on your instructions. You are responsible for having a lawful basis to upload it and for any notices or consents required. Our obligations are set out in Section 8 of the Terms of Use at www.komplyapp.com/terms.
3.3 If an individual contacts us about data we hold only as a processor, we will refer them to you and assist you in responding.
4. WHAT WE COLLECT
4.1 Data you give us
| Category | What it includes |
|---|
| Account data | Email address, password (stored hashed, never in readable form), display name |
| Business data | Business name, commercial registration number |
| Questionnaire answers | Legal structure, sector, revenue band, employee count, foreign ownership, whether the business has physical premises, and whether it processes personal data |
| Tracker data | Which obligations you mark done or hidden, dates you enter, custom obligations you add |
| Your role | Whether you tell us you are a business owner, an accountant, a lawyer, a compliance officer, or something else you describe in your own words. Prefer not to say is one of the answers |
| Compliance acknowledgments | A record of each time you mark a continuing obligation as in place for a Business, or undo that, with the date and the Account that did it |
| Uploaded documents | PDF, JPEG or PNG files up to 10 MB. These may contain personal data and identifiers belonging to you or others |
| Feedback | Obligation accuracy flags, ratings and comments you submit |
| Correspondence | Emails you send to info@komplyapp.com |
We do not collect national ID or Iqama numbers as structured data. Documents you choose to upload may contain them.
We do not collect or store payment card details. Card data is handled directly by Moyasar.
4.2 Data generated automatically
| Category | What it includes |
|---|
| Technical data | IP address, browser and device type, and similar information generated when your browser connects to our infrastructure and to Cloudflare |
| Server and authentication logs | Login events, timestamps, and errors recorded by our servers |
| Session data | A session identifier stored in your browser's local storage to keep you signed in |
| Usage analytics | Aggregated page and feature usage collected by Umami, our own analytics software running on our Riyadh server. It sets no cookies, assigns no persistent identifier, and does not build a profile of you |
4.3 Cookies
We do not use cookies. Your login session is kept using your browser's local storage, which is necessary for the Services to function and is cleared when you sign out. Because we set no analytics, advertising or tracking cookies, no consent banner is shown.
We use Umami, self-hosted on our own server in Riyadh, to understand which pages and features are used. It is cookieless, collects no personal data, and the data never leaves the Kingdom or reaches a third party.
If any third-party analytics or error-monitoring tool is added, this Section and Section 6 will be updated and consent obtained where required before it is enabled.
5. IF YOU DO NOT PROVIDE DATA
Account data, business data and questionnaire answers are required, because the Services cannot generate a compliance checklist without them.
Your role is required too, but for a different reason, and we would rather say so than leave it sitting under the sentence above. It has no effect on your checklist at all. We ask because a business owner, an accountant, a lawyer and a compliance officer need different things from the same list, and we cannot build well for people we cannot see. Because it is not needed to deliver the Services, Prefer not to say is one of the answers. It is a complete answer, and nothing follows from choosing it.
Uploading documents and submitting feedback are optional.
6. WHY WE PROCESS IT, AND ON WHAT BASIS
| Purpose | Legal basis under the PDPL |
|---|
| Creating and running your account, and providing the Services | Performance of a contract to which you are a party |
| Matching obligations to your business profile | Performance of a contract |
| Storing documents you upload against obligations | Performance of a contract |
| Keeping an auditable history of the compliance positions you record against a Business | Performance of a contract; our legitimate interest in keeping an accurate compliance record for the Business |
| Sending authentication emails and scheduled deadline reminders | Performance of a contract |
| Responding to your enquiries and complaints | Performance of a contract; our legitimate interest in supporting users |
| Keeping server and authentication logs to secure the Services and investigate misuse | Our legitimate interest in protecting our systems and users |
| Measuring aggregated usage of the Services through our self-hosted analytics | Our legitimate interest in understanding and improving how the Services are used |
| Reviewing accuracy flags and feedback to correct and improve the Obligations Dataset | Our legitimate interest in improving the Services |
| Understanding who uses the Services, so that we can build for them | Our legitimate interest in developing the Services for the people who actually use them |
| Billing and payment | Performance of a contract; compliance with a legal obligation |
| Complying with legal or regulatory obligations and responding to lawful requests from authorities | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Our legitimate interest in protecting our legal rights |
6.1 Legitimate interest. Where we rely on legitimate interest, we satisfy ourselves that the processing is necessary and does not prejudice your rights. We do not rely on legitimate interest for sensitive personal data.
6.2 We do not send marketing emails. Emails we send are authentication messages, deadline reminders, replies to your enquiries, and service notices such as changes to these documents. If we introduce marketing in future, we will obtain your consent first and give you a free way to opt out in every message, as the PDPL requires.
6.3 We will not use your data for a purpose inconsistent with the one it was collected for. If a new purpose arises, we will update this Policy and obtain consent where required.
6.4 Withdrawing consent. Where we rely on consent, you may withdraw it at any time at no cost by writing to info@komplyapp.com. Withdrawal does not affect processing already carried out, or processing resting on another basis.
7. SENSITIVE PERSONAL DATA
7.1 Sensitive personal data under the PDPL includes data revealing racial or ethnic origin, religious, intellectual or political belief, security or criminal-conviction data, biometric or genetic data identifying a person, health data, and data indicating that one or both parents are unknown.
7.2 We do not ask for sensitive personal data and the Services are not designed to hold it. Do not upload it.
7.3 If you upload a document containing sensitive personal data, you are responsible for the explicit consent or other lawful basis required under the PDPL.
7.4 We do not use any personal data for profiling, advertising or awareness campaigns.
8. WHO WE SHARE IT WITH
We do not sell, rent or trade personal data. We share it only as set out below.
| Recipient | What they handle | Where |
|---|
| Oracle Cloud Infrastructure | Hosting of our self-hosted database, application and uploaded files, and encrypted backups | Riyadh, KSA (`me-riyadh-1`) |
| Oracle Email Delivery | Sending authentication emails and deadline reminders | Riyadh, KSA |
| Umami (self-hosted) | Aggregated usage analytics. Not a third party; it runs on our own server | Riyadh, KSA |
| Cloudflare | Serving the static frontend. Holds no account data, but processes visitor IP addresses in transit | Outside KSA |
| Google Workspace | Our correspondence mailbox (info@komplyapp.com), so emails you send us are stored and processed by Google | Outside KSA |
| Moyasar | Card payments. Card details go directly to them and are not seen by us. Moyasar acts as an independent data controller for that information, not as our processor. See Section 8.3 | See Section 9.2(c) |
| Competent authorities | Disclosure required by law, court order or lawful request, including SDAIA, the Ministry of Commerce, ZATCA and law enforcement | KSA |
| An acquirer | In a sale or restructuring of the business, subject to equivalent protection | Not applicable |
8.1 We require providers to process personal data only as needed to deliver their service to us.
8.2 An updated list of providers is available on request from info@komplyapp.com.
8.3 Moyasar is a separate controller, not our processor. When you enter card details, you give them directly to Moyasar. We never receive or store the card number. Moyasar decides how it processes that information and is accountable for it in its own right. Moyasar's privacy policy applies to it and is available at moyasar.com/en/resources/privacy-policy. We hold only what Moyasar returns to us: the card brand, the last four digits, the expiry date, and identifiers linking a payment to your Account. You may ask us to delete a saved card at any time; we delete it at Moyasar first and then remove it from our records, and your paid period is unaffected.
8.4 Our former payment provider. Until 23 August 2026, payments were processed by Tap Payments. If you paid through it, your card details were handled by Tap as an independent controller and its own policy applies, available at www.tap.company/en-sa/privacy. We keep records of those payments within our accounting records for the period set out in the retention table.
8.4 Single account access. The Services are accessed through a single Account, with no facility currently to invite additional users to a Business.
9. WHERE YOUR DATA IS STORED
9.1 Your account data, business profile, questionnaire answers, tracker data and uploaded documents are stored on infrastructure located in Riyadh, Kingdom of Saudi Arabia, on Oracle Cloud Infrastructure in the `me-riyadh-1` region. Authentication and reminder emails are sent from the same region.
9.2 Limited processing does take place outside the Kingdom, and we set it out plainly rather than claim otherwise:
(a) Cloudflare delivers the static frontend of the website. It holds no account data, but your IP address and connection metadata pass through its network outside the Kingdom.
(b) Google Workspace hosts our correspondence mailbox. If you email us, the content of that email, including any personal data in it, is stored and processed by Google outside the Kingdom.
(c) Moyasar processes payment card information and operates under the control and supervision of the Saudi Central Bank. Its published privacy policy states that it does not transfer personal data outside the Kingdom of Saudi Arabia. Because Moyasar collects that data directly from you as an independent controller, and it never passes through our systems, the arrangements for it are governed by its own policy and its regulator rather than by us.
9.3 Where personal data is transferred outside the Kingdom, we rely on the grounds permitted by Article 29 of the PDPL, limit the transfer to the minimum necessary, and satisfy ourselves that the transfer does not prejudice national security or the vital interests of the Kingdom.
9.4 Please do not send sensitive or confidential personal data to us by email. Use the Services themselves, which are hosted in the Kingdom.
10. HOW LONG WE KEEP IT
| Data | Retention |
|---|
| Account, business, questionnaire and tracker data | For as long as your account is open |
| Uploaded documents | For as long as they are attached, or until you delete them or the related Business |
| Data you delete | Removed from the live database and file storage immediately, whether you delete a document, a Business, or your whole Account |
| Deletion records | Every deletion of an Account or of a Business leaves one log entry, whoever carried it out: you from your settings, an administrator at your request, or the inactivity process described below. The entry records the date, the email address of the Account, what was deleted and how much of it, and where an administrator acted, the reason they gave. It holds nothing else. It is deliberately not removed by the deletion it describes, because a deletion record that deleted itself could not answer the question it exists for, which is whether we really did delete what you asked us to delete |
| Compliance acknowledgments | Deleted with the Business they belong to. If shared access to a Business is introduced in future, an acknowledgment left on a Business you do not own would stay with that Business, with your identity removed from it, so that what remains records only that the obligation was marked in place, and when |
| Data export archives | Held in a private area for 7 days after your export is ready, then deleted automatically. Only you can download yours |
| Encrypted backups | Retained 30 days, then aged out automatically. Deleted data may persist in a backup for up to 30 days after deletion |
| Correspondence | Deleted once the message is more than 24 months old, counted from the date you sent it. We do this as a scheduled clear out rather than automatically, so a message may remain for a short period after that point |
| Server and authentication logs | 90 days |
| Billing and accounting records | Retained for the minimum period required by Saudi tax and companies legislation |
| Inactive accounts | After 24 months of inactivity we email you at your registered address. If you do not respond, the account and its data are deleted 30 days later |
10.1 We will destroy personal data once it is no longer necessary for the purpose it was collected for, unless retention is required by law or is necessary to establish or defend a legal claim.
10.2 Deletion is permanent. Once an account is deleted under the inactivity process, the data cannot be recovered.
11. SECURITY
11.1 We describe below the measures actually in place. We do not claim certifications or controls we do not hold.
In place:
- Encryption in transit using TLS, terminated at our reverse proxy;
- Encryption at rest as provided by default by Oracle Cloud block volume encryption;
- Passwords stored hashed, never in readable form;
- Row level security enforced in the database, so one Account cannot read another Account's Businesses and cannot write anything into a Business it does not belong to. Administrators are a declared exception, described in Section 11.3. This is tested rather than asserted: before each version of this Policy is published, we run an automated test that signs in as separate real accounts and attempts those cross account reads and writes against the live system, and it fails if any of them succeeds;
- Uploaded files stored in a private area, not publicly reachable by direct link, and restricted to the Account that owns the relevant Business. Administrators are granted no access to that area, and none to the separate private area holding data export archives, both of which are deliberate. The same test confirms that an administrator account cannot download one of your documents, obtain a link to one, or list what is stored. See Section 11.3;
- File type and size restrictions on upload;
- Daily encrypted backups to Object Storage with 30-day retention, and a tested restore procedure.
Not yet in place, and being worked on:
- A documented incident response plan;
- A personal data breach register;
- Periodic access reviews;
- Independent penetration testing.
11.2 No system is completely secure. You are responsible for keeping your password confidential and for securing your own devices and email account.
11.3 Administrator access to your Account. A small number of our administrators can open your Account record, to support you, to look into a problem, or to answer a billing question. What they see is your display name, email address, the Businesses on your Account, your subscription, the obligations recorded against those Businesses, your record of accepting these documents, the file names and dates of the documents you have uploaded, though never the documents themselves, and the role you told us you have. Before the record opens, the administrator must choose a reason from a fixed list and, where the reason is anything other than the listed ones, write it out. That reason, their identity and the time are written to an access log that they cannot edit or delete. Administrators cannot open the documents you upload, and cannot open a data export archive; those two areas grant them no access at all. We would rather tell you this plainly than let you assume no one can ever see your Account.
12. PERSONAL DATA BREACH
12.1 If a personal data breach occurs, we will notify SDAIA within seventy-two (72) hours of becoming aware of it, as the PDPL Implementing Regulations require.
12.2 We will notify affected individuals without undue delay where a breach may cause serious harm to them or their data, describing what happened, the likely consequences, and what we and they can do.
12.3 Where a breach affects data we hold as a processor for you, we will notify you without undue delay so you can meet your own obligations.
12.4 A documented incident response process is in development. Until it is complete, breach handling is managed directly by the Company's management at info@komplyapp.com.
13. YOUR RIGHTS
Subject to the conditions and exceptions in the PDPL:
| Right | What it means |
|---|
| To be informed | To know the purpose and legal basis of collection, who we are, whether data is mandatory or optional, and who your data may be disclosed to |
| Access | To confirm whether we hold your personal data and to see it |
| To obtain a copy | To receive your personal data in a readable, clear format, free of charge |
| Correction | To have inaccurate, incomplete or outdated data corrected, completed or updated |
| Destruction | To have data destroyed when it is no longer needed for the purpose it was collected for |
| To withdraw consent | Where processing rests on consent |
| To complain | To SDAIA, see Section 15 |
13.1 How to exercise them. Email info@komplyapp.com, describing the right you want to exercise. Account deletion is also available directly in your Account settings and removes your data from the live database and file storage immediately. You can separately delete a single Business, together with its documents, without closing your Account. In both cases we keep one deletion record, and Section 10 sets out exactly what it contains and why.
13.2 Export. You can export your own data from your Account settings, without asking us. We prepare an archive containing your account and Business records, the role you told us you have, your questionnaire answers, your tracker data, the compliance acknowledgments recorded against your Businesses, your feedback, your record of accepting these documents, and copies of the documents you have uploaded. It is ready to download for 7 days, after which it is deleted automatically and you can request another. One export may be requested every 24 hours. If you would rather we produced a copy for you, write to info@komplyapp.com.
13.3 Verification. We will verify your identity before acting, and may ask for reasonable information for that purpose only.
13.4 Timing. We will respond within thirty (30) days of a valid request, extendable by a further thirty (30) days for complex or repeated requests, with notice to you within the first period.
13.5 Limits. We may decline or restrict a request where the PDPL permits, for example where it conflicts with a legal or judicial obligation, harms another person's rights, prejudices an investigation, or where the request is manifestly unfounded or excessive. We will explain why and tell you about your right to complain.
13.6 Exercising your rights is free.
14. CHILDREN
14.1 The Services are for business use and are not directed to anyone under eighteen (18).
14.2 We do not knowingly collect data about a child or a person lacking legal capacity without a guardian's consent. If you believe we have, contact info@komplyapp.com and we will investigate and delete it where appropriate.
15. COMPLAINTS
15.1 Please raise concerns with us first at info@komplyapp.com.
15.2 You may also complain at any time to the Saudi Data & Artificial Intelligence Authority (SDAIA) at https://sdaia.gov.sa, through its official channels for personal data protection complaints.
15.3 For consumer or e-commerce matters, you may contact the Ministry of Commerce through its official channels.
16. AUTOMATED PROCESSING
16.1 The Services match obligations to your business using a rules-based engine applied to your questionnaire answers. This determines which items appear on your checklist.
16.2 This is not a decision producing legal effects about you. It is a suggestion for your review, and it may be incomplete or wrong. See the Terms of Use.
16.3 The Services do not use artificial intelligence, and we do not use your data to train any model.
17. CHANGES TO THIS POLICY
17.1 We may update this Policy to reflect changes in law or in our practices, including when analytics, error monitoring, billing or new features are introduced.
17.2 The updated Policy will be published with a new Effective Date. For material changes we will give at least thirty (30) days' notice by email or in-product notice.
17.3 Where a change requires your consent under the PDPL, we will obtain it before the change takes effect.
18. CONTACT
info@komplyapp.com
Altamuh Aljariy Company
19. LANGUAGE
This Policy is issued in Arabic and English. In the event of any discrepancy or difference in interpretation, the Arabic version prevails and is the version relied upon before the courts and authorities of the Kingdom of Saudi Arabia.
© 2026 Altamuh Aljariy Company. All rights reserved.