Legal

Privacy policy

Last updated 13 September 2026 · Applies to Dawamee version 1.4.0 for Android

At a glance

  • Choose Company or Personal mode at first launch. In Company mode, your employer keeps attendance records through the Digital Pages service. Personal mode keeps your own time record encrypted on your device and makes no API or network requests.
  • Precise location is recorded only at the moment you check in or out, start or end a break, or submit or cancel a leave request. There is no background or continuous location.
  • No advertising, no advertising identifier, no third-party analytics or tracking, and no sale or sharing of your data with advertisers or data brokers.
  • The app never receives your salary or bank details, and your fingerprint or face never leaves your device.
  • Questions, access or deletion: app@digital-pages.dev

1. Who is responsible for your data

Dawamee (“the app”) is published and operated by Digital Pages (“we”, “us”).

In Company mode, you reach the service through your employer. Your employer decides that attendance will be recorded, who is invited, and what happens to the records afterwards, so your employer is the controller of that information. We provide and run the app and the service behind it on your employer's behalf. Where Digital Pages is itself the employer, we are both.

If you want to know why your company records attendance or reviews a particular entry, ask your employer first. If you want to know what the app technically stores, this page answers that, and you can always write to app@digital-pages.dev.

Personal mode: your device, your record

Other / Personal mode does not connect to payroll or create a server account. You keep your own attendance, breaks and leave on your device; neither Digital Pages nor an employer receives those records from the app. Personal leave is Recorded or Cancelled, without management review. You control any CSV files you export, which may contain precise location and personal notes.

There is no online backup. If Android cannot use the encryption key, the app reports a storage error and does not automatically erase the existing encrypted records. We cannot recover the key or restore those records from a server. Clearing app storage or uninstalling removes local records; exported files must be managed separately.

2. How a Company account comes to exist

There is no public sign-up for Company mode. An administrator at your company grants your work email address mobile access from the payroll system and sends you an invitation. Sign-in then uses that email address and a six-digit one-time code; there is no password to create. An invitation is required for Company access. Other / Personal mode requires no account, email, invitation or code.

3. What the app collects

3.1 Company identity, from your employer's payroll system

When you sign in, the service reads a narrow, read-only view of your employer's payroll records: your name, work email address, employee identifier, company identifier and the status fields that decide whether you are eligible to use the app. That view cannot be written to and contains no salary, bank, contract or other payroll detail. The service also stores your email in code and session records, and an employee-name snapshot in leave requests; those identity fields are not kept solely in payroll.

3.2 Company sign-in and session data

  • Your email address, so that a code can be sent to it.
  • The one-time code, stored only as a keyed hash, valid for ten minutes, with a limit of five attempts. Codes are limited to one per minute and five per hour per address.
  • A session token, stored on the server only as a hash and valid for seven days. On your device it is held in Android's encrypted storage.
  • Short-lived rate-limiting counters keyed to a hash of the network address a request came from, used to slow down abuse.

3.3 Attendance and breaks

Check-in and check-out times, the working day they belong to, break start and end times, total break time, the reason you chose for each break and any note you added.

3.4 Leave requests

Both modes record leave type, dates or times, reason and status. Company requests additionally include your payroll name and, after review, the reviewer, review time and review note. Personal leave is Recorded or Cancelled locally and is not submitted for management approval.

3.5 Location, at the moment of an action

Latitude, longitude, accuracy in metres, the original time of the fix and whether it is fresh or last-known, attached to each attendance action and each leave submission or cancellation. Section 4 describes this in full.

3.6 Company device and connection details

The network address the request came from, the agent string the app sends, whether your device reported Wi-Fi or mobile data, and a short device description reported by your device. These accompany the attendance entry so that your employer's administrators can see the circumstances in which it was made. They are reported by the device itself and are not treated as proof of identity.

Company actions additionally use Android hardware key attestation. The service checks the app package, signing certificate, app version and verified boot state, then keeps a session-bound public key that is valid for up to six hours and short-lived request nonces to prevent replay. The private signing key stays in Android Keystore. The server checks Google’s public certificate revocation list; no attendance or location is sent to Google by this service. Personal mode does not enroll keys or make attestation requests.

3.7 Deletion requests

The verified deletion form collects your email and language and sends a separate code valid for ten minutes. We store a purpose-bound hash of that code and security counters, not the code itself. After you confirm, we retain the request reference, email, relevant company and employee identifiers, timestamps and the deletion or retention decision. A keyed fingerprint of the email prevents closed access from being reopened automatically. Request and decision records are restricted to authorised company administrators and service operators; this release has no automatic purge for them.

3.8 Kept only on your device

Your language and appearance choice, biometric-lock settings and, in Company mode, the encrypted session token. Personal attendance, breaks, leave, GPS stamps and notes are kept in encrypted on-device storage and are not uploaded. There is no online backup. A Personal CSV export contains records, GPS and notes in the file destination you choose; that file is outside the app’s encrypted storage and remains under your control. Release builds of the app disable debugging, disable system backups of app data, and block screenshots and app-preview capture.

4. Location, in detail

Location is the most sensitive thing the app records, so here is exactly how it behaves.

  • A fix is captured only when you check in, check out, start or end a break, or submit or cancel a leave request. Nothing is captured while you browse other screens, while the app is in the background, or when the app is closed.
  • The app requests a new fix after confirmation. If that attempt fails while GPS remains enabled, it uses the latest known real location. The original timestamp and accuracy are preserved and the source is marked LAST_KNOWN in records and exports. Mock locations are refused. Without any usable real fix, the action cannot be recorded.
  • Fresh fixes require valid coordinates, accuracy of 250 metres or better and age of no more than 120 seconds. A LAST_KNOWN fallback may be older or less accurate; its actual time and accuracy remain visible in the record. It is not proof of the user’s current position.
  • Precise location permission and enabled location services are required to reach the employee screens. If either is missing, the app says so and offers to open Android settings. Without them you cannot record attendance from the app.
  • The app holds no “allow all the time” background location permission, defines no office geofence, and does not judge whether a position is inside or outside a permitted area. It produces a stamp attached to your action. Company stamps are sent for employer review; Personal stamps stay on your device unless you export them.

5. What the app does not collect

No advertising identifier and no advertising or marketing profiling. No third-party analytics, crash-reporting or tracking SDK. No contacts, photos, messages, call history or microphone access. A Personal CSV export writes only the file you choose through Android’s file picker; it does not scan other files. No continuous or background location. No salary or bank information. No biometric data: biometric unlocking is performed by Android, and the app only learns whether it succeeded. We do not sell your data and we do not share it with advertisers or data brokers.

6. Why Company data is used

DataPurpose
Identity and eligibilityConfirming that you are an employee entitled to use the app, and attaching records to the right person and company
Email and one-time codeSigning you in without a password, and preventing abuse of the code system
Attendance, breaks and leaveProducing the attendance record your employer uses for time-keeping, leave management and payroll
Location, device and connection detailsShowing your employer's authorised administrators the circumstances in which each entry was made
Security counters and service logsProtecting the service against abuse and keeping it running

Where data-protection law applies, this processing rests on your employment relationship, your employer's legitimate interest in accurate attendance records, and any legal obligation your employer has to keep employment records. Your data is not processed for advertising or for any purpose unrelated to attendance.

7. Who can see Company data

  • Your employer. Authorised payroll administrators at your company review your attendance, its location stamps and your leave requests from the payroll application. That is the purpose of the app.
  • Digital Pages staff who operate the service, strictly where needed to run, support, back up or repair it.
  • The infrastructure used to run the service: the provider hosting the server, and the mail service that delivers your one-time codes and invitations.
  • Authorities, only where we or your employer are legally required to disclose.

There is no third-party SDK inside the app that receives your data.

8. Where data is kept

Company attendance data is stored in a dedicated database on a server operated by Digital Pages, separate from the main payroll database and reachable only through this service's own restricted account. Traffic between the app and the service uses HTTPS; connections between the service and the database use TLS.

9. How long Company data is kept

DataRetention
One-time code challengesThe code hash is cleared on successful use; a code becomes invalid after 10 minutes. Later code requests remove other challenge rows whose last send time is over 24 hours old.
Sign-in sessionsInvalid after 7 days. Expired rows are deleted during a later successful sign-in; signing out deletes that session.
Rate-limiting countersEntries older than 2 hours are removed during later code requests.
Attendance, breaks and leave requests, with their location stampsKept as your employer's employment record, for as long as your employer requires and the law allows
Database backupsRetained on a rolling 14-day basis, then destroyed

Authentication cleanup is triggered by these later requests, not by a guaranteed deletion schedule. How long Company attendance records are kept after employment ends is your employer’s decision. Personal records stay on your device until app storage is cleared or the app is uninstalled; exported CSV files remain separately under your control.

10. How data is protected

  • HTTPS with a valid certificate for all traffic between the app and the service.
  • One-time codes and session tokens stored only as hashes, never in readable form.
  • The session token held in Android's encrypted storage on your device.
  • Debugging, system backup of app data, and screenshot or app-preview capture disabled in release builds.
  • Database accounts limited to exactly the tables and columns they need, with no access to salary data.
  • The service running in a hardened container with a read-only filesystem and no extra privileges.
  • Request size limits, rate limits, and your eligibility re-checked on every authenticated request.

No system is perfectly secure, but the app is built so that a problem in one part does not expose payroll data.

11. Your choices

  • Location permission can be withdrawn at any time in Android settings. The app will then be unable to record attendance, because a fix is required for those actions.
  • Biometric lock is optional and can be switched on or off in the app's settings.
  • Language and appearance are your choice and are stored on your device.
  • Signing out in Company mode removes the session from your device and invalidates it on the server.
  • Uninstalling removes the app and its on-device data. Company entries already sent remain in your employer’s record. Personal records are removed, while exported CSV files remain outside app storage.

12. Your rights

Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected or deleted, to restrict or object to its use, and to complain to a data-protection authority.

For Company employment records, the fastest route for most requests is the HR or payroll administrator at your company, who can review your entries and handle a correction request. You can also write to us at app@digital-pages.dev and we will help, working with your employer where the records belong to them. For deletion, use the email-verified form on Delete my data. Confirmation immediately closes Dawamee access and revokes sessions. Company attendance and leave records enter a tracked employer deletion or documented retention review; separate payroll records and files on your device are not erased by this form. We answer requests within 30 days.

13. Children

Dawamee is a time-keeping tool for adults and is not directed at children. Company access is limited to invited, eligible employees.

14. Changes to this policy

If this policy changes, we will update this page and the date at the top. Changes that materially affect Company data use will also be communicated through your employer.

15. Contact

Digital Pages — Dawamee
app@digital-pages.dev

Appendix: Android permissions

PermissionWhy the app asks
Precise and approximate locationThe single fix attached to each attendance action and leave submission or cancellation. Used only while you are using the app; no background location.
Internet and network stateCompany mode: reaching the attendance service and reporting Wi-Fi or mobile data for an action. Personal mode makes no API or network requests.
Biometrics / fingerprintThe optional app lock. Verification is performed by Android; the app only learns the result.
NotificationsIf granted, only for messages the app itself raises on your device. The app does not receive remote push messages.

الشروط والسياسات

سياسة الخصوصية

آخر تحديث 13 أيلول/سبتمبر 2026 · تنطبق على Dawamee الإصدار 1.4.0 لأندرويد

باختصار

  • اختر وضع الشركة أو الوضع الشخصي عند التشغيل الأول. تحفظ جهة عملك سجلات الحضور عبر خدمة Digital Pages في وضع الشركة. أما الوضع الشخصي فيحفظ سجل وقتك مشفّراً على جهازك ولا يُجري أي طلبات API أو شبكة.
  • يُسجَّل الموقع الدقيق في لحظة الإجراء فقط: الحضور أو الانصراف أو بدء الاستراحة أو إنهاؤها أو إرسال طلب إجازة أو إلغائه. لا يوجد تتبّع مستمر ولا في الخلفية.
  • لا إعلانات ولا معرّف إعلاني ولا تحليلات أو تتبّع من طرف ثالث، ولا بيع لبياناتك أو مشاركتها مع المعلنين أو وسطاء البيانات.
  • لا يصل التطبيق إلى تفاصيل راتبك أو حسابك البنكي، ولا تغادر بصمتك أو صورة وجهك جهازك.
  • للاستفسار أو طلب نسخة من بياناتك أو حذفها: app@digital-pages.dev

1. من المسؤول عن بياناتك

تنشر تطبيق Dawamee («التطبيق») وتشغّله شركة Digital Pages («نحن»).

في وضع الشركة، تصل إلى الخدمة من خلال جهة عملك. شركتك هي التي تقرر تسجيل الحضور ومن تتم دعوته وما يحدث للسجلات بعد ذلك، وهي بذلك الجهة المتحكمة بتلك البيانات. أما نحن فنوفّر التطبيق والخدمة ونشغّلهما نيابة عنها. وحين تكون Digital Pages نفسها جهة العمل، فنحن الطرفان معاً.

إن أردت معرفة سبب تسجيل شركتك للحضور أو مراجعتها لسجل معيّن، فاسأل شركتك أولاً. أما إن أردت معرفة ما يخزّنه التطبيق تقنياً، فهذه الصفحة تجيبك، ويمكنك دائماً مراسلتنا على app@digital-pages.dev.

الوضع الشخصي: جهازك وسجلك

لا يتصل وضع «أخرى / شخصي» بنظام الرواتب ولا ينشئ حساباً على الخادم. تحفظ حضورك واستراحاتك وإجازاتك على جهازك؛ ولا تتلقى Digital Pages أو جهة العمل تلك السجلات من التطبيق. تكون الإجازة الشخصية «مسجّلة» أو «ملغاة» دون مراجعة إدارية. وتتحكم أنت في أي ملفات CSV تصدّرها، وقد تتضمن الموقع الدقيق وملاحظات شخصية.

لا توجد نسخة احتياطية عبر الإنترنت. إذا تعذّر على أندرويد استخدام مفتاح التشفير، يعرض التطبيق خطأ تخزين ولا يمحو السجلات المشفّرة الموجودة تلقائياً. لا يمكننا استعادة المفتاح أو السجلات من خادم. يمحو مسح بيانات التطبيق أو إلغاء تثبيته السجلات المحلية، وتُدار الملفات المصدّرة بشكل منفصل.

2. كيف يُنشأ حساب وضع الشركة

لا يوجد تسجيل عام لوضع الشركة. يمنح مسؤول في شركتك بريدك الإلكتروني الوظيفي صلاحية الاستخدام عبر الهاتف من نظام الرواتب ويرسل لك الدعوة. بعدها يتم الدخول بذلك البريد ورمز من ستة أرقام يُستخدم لمرة واحدة، دون كلمة مرور. تلزم الدعوة للوصول إلى وضع الشركة. أما «أخرى / شخصي» فلا يحتاج إلى حساب أو بريد أو دعوة أو رمز.

3. ما الذي يجمعه التطبيق

3.1 بيانات الهوية من نظام الرواتب لدى شركتك

عند تسجيل الدخول، تقرأ الخدمة عرضاً محدوداً للقراءة فقط من سجلات الرواتب: اسمك وبريدك الوظيفي ومعرّف الموظف ومعرّف الشركة وحقول الحالة التي تحدد أهليتك لاستخدام التطبيق. هذا العرض غير قابل للكتابة ولا يتضمن الراتب أو البيانات البنكية أو العقد أو أي تفصيل آخر من الرواتب. وتحفظ الخدمة أيضاً بريدك في سجلات الرموز والجلسات ونسخة من اسم الموظف في طلبات الإجازة؛ لذا لا تقتصر حقول الهوية هذه على نظام الرواتب.

3.2 بيانات الدخول والجلسة في وضع الشركة

  • بريدك الإلكتروني لإرسال الرمز إليه.
  • رمز الدخول، ويُخزَّن على شكل بصمة تشفير فقط، وصلاحيته عشر دقائق بحد أقصى خمس محاولات. ويقتصر إرسال الرموز على رمز واحد في الدقيقة وخمسة في الساعة لكل عنوان بريد.
  • رمز الجلسة، ويُخزَّن على الخادم على شكل بصمة تشفير فقط، وصلاحيته سبعة أيام. وعلى جهازك يُحفظ في التخزين المشفَّر في أندرويد.
  • عدّادات قصيرة الأجل للحد من المحاولات، مرتبطة ببصمة تشفير لعنوان الشبكة الذي جاء منه الطلب، للحد من إساءة الاستخدام.

3.3 سجلات الحضور والاستراحات

أوقات الحضور والانصراف، ويوم العمل الذي تنتمي إليه، وأوقات بدء الاستراحات وانتهائها، ومجموع مدة الاستراحة، والسبب الذي اخترته لكل استراحة وأي ملاحظة أضفتها.

3.4 طلبات الإجازة

يسجّل الوضعان نوع الإجازة وتواريخها أو أوقاتها والسبب والحالة. وتتضمن طلبات الشركة أيضاً اسمك في نظام الرواتب، وبعد المراجعة: المسؤول الذي راجعها والوقت والملاحظة. أما الإجازة الشخصية فتكون «مسجّلة» أو «ملغاة» محلياً ولا تُرسل للموافقة الإدارية.

3.5 الموقع لحظة الإجراء

خط العرض وخط الطول ودقة التحديد بالأمتار ووقت التحديد، تُلتقط مرة واحدة مع كل إجراء حضور ومع كل إرسال أو إلغاء لطلب إجازة. ويشرح البند 4 ذلك بالتفصيل.

3.6 تفاصيل الجهاز والاتصال في وضع الشركة

عنوان الشبكة الذي جاء منه الطلب، والمعرّف الذي يرسله التطبيق، وما إذا كان جهازك متصلاً بشبكة Wi-Fi أم ببيانات الهاتف، ووصف مختصر للجهاز يُبلّغ عنه جهازك. ترافق هذه التفاصيل سجل الحضور ليتمكن المسؤولون المخوّلون في شركتك من رؤية ظروف تسجيله. وهي معلومات يبلّغ عنها الجهاز نفسه ولا تُعتبر إثباتاً للهوية.

تستخدم إجراءات الشركة أيضاً إثبات مفتاح أندرويد المدعوم بالعتاد. تتحقق الخدمة من حزمة التطبيق وشهادة توقيعه وإصداره وحالة إقلاع الجهاز، ثم تحفظ مفتاحاً عاماً مرتبطاً بالجلسة وصالحاً حتى ست ساعات وقِيماً مؤقتة لمنع تكرار الطلب. يبقى المفتاح الخاص في Android Keystore. يتحقق الخادم من قائمة إبطال الشهادات العامة لدى Google دون إرسال الحضور أو الموقع إليها. لا يسجّل الوضع الشخصي هذه المفاتيح ولا يطلب إثبات التطبيق.

3.7 طلبات الحذف

يجمع نموذج الحذف الموثّق بريدك ولغتك ويرسل رمزاً منفصلاً صالحاً لعشر دقائق. نخزّن بصمة مرتبطة بغرض الرمز وعدّادات الأمان، ولا نخزّن الرمز نفسه. بعد التأكيد نحتفظ بمرجع الطلب والبريد ومعرّفات الشركة والموظف المعنيين والأوقات وقرار الحذف أو الاحتفاظ. وتمنع بصمة بريد محمية بمفتاح إعادة فتح الوصول المغلق تلقائياً. تقتصر سجلات الطلبات والقرارات على مسؤولي الشركة ومشغّلي الخدمة المخوّلين، ولا يوجد حذف تلقائي لها في هذا الإصدار.

3.8 ما يبقى على جهازك وحده

اختيارك للغة والمظهر وإعدادات القفل البيومتري، ورمز الجلسة المشفّر في وضع الشركة. تُحفظ سجلات الحضور والاستراحات والإجازات الشخصية وأختام الموقع والملاحظات مشفّرة على الجهاز ولا تُرفع للخادم. لا توجد نسخة احتياطية عبر الإنترنت. ويحتوي تصدير CSV الشخصي على السجلات والموقع والملاحظات في الوجهة التي تختارها؛ ويكون الملف خارج تخزين التطبيق المشفّر وتحت سيطرتك. كما تعطّل نسخ الإصدار من التطبيق تصحيح الأخطاء، والنسخ الاحتياطي لبيانات التطبيق، والتقاط الصور أو معاينة التطبيق.

4. الموقع بالتفصيل

الموقع هو أكثر ما يسجّله التطبيق حساسية، وهذه آلية عمله بالضبط.

  • يُلتقط الموقع فقط عند تسجيل الحضور أو الانصراف أو بدء استراحة أو إنهائها أو إرسال طلب إجازة أو إلغائه. ولا يُلتقط شيء أثناء تصفّح بقية الشاشات ولا حين يكون التطبيق في الخلفية أو مغلقاً.
  • يطلب التطبيق تحديداً جديداً بعد التأكيد. إذا تعذّر مع بقاء GPS مفعّلاً، يستخدم آخر موقع حقيقي معروف ويحفظ وقته ودقته الأصليين مع علامة LAST_KNOWN في السجلات والتصدير. تُرفض المواقع الوهمية، ولا يُسجَّل الإجراء إذا لم يتوفر أي موقع حقيقي صالح.
  • يتطلب التحديد الحديث إحداثيات صالحة ودقة 250 متراً أو أفضل وعُمراً لا يتجاوز 120 ثانية. قد يكون بديل LAST_KNOWN أقدم أو أقل دقة، ويبقى وقته ودقته الفعليان في السجل. ولا يُعدّ دليلاً على موقع المستخدم الحالي.
  • يتطلب الوصول إلى شاشات الموظف تفعيل خدمات الموقع ومنح إذن الموقع الدقيق. وإن نقص أحدهما، ينبّهك التطبيق ويعرض فتح إعدادات أندرويد. ومن دونهما لا يمكنك تسجيل الحضور من التطبيق.
  • لا يملك التطبيق إذن الموقع في الخلفية («السماح طوال الوقت»)، ولا يحدد نطاقاً جغرافياً للمكتب، ولا يحكم إن كان الموقع داخل منطقة مسموحة أو خارجها. ينتج ختم موقع مرافقاً للإجراء. تُرسل أختام وضع الشركة لمراجعة جهة العمل، وتبقى أختام الوضع الشخصي على جهازك ما لم تصدّرها.

5. ما لا يجمعه التطبيق

لا معرّف إعلاني ولا أي تصنيف إعلاني أو تسويقي. لا أدوات تحليلات أو تقارير أعطال أو تتبّع من طرف ثالث. لا وصول إلى جهات الاتصال أو الصور أو الرسائل أو سجل المكالمات أو الميكروفون. ويكتب تصدير CSV الشخصي الملف الذي تختاره عبر منتقي ملفات أندرويد فقط ولا يفحص الملفات الأخرى. لا تتبّع مستمر أو في الخلفية. لا بيانات راتب أو حساب بنكي. ولا بيانات بيومترية: فالتحقق البيومتري يجريه نظام أندرويد، ولا يعرف التطبيق سوى نتيجته. نحن لا نبيع بياناتك ولا نشاركها مع المعلنين أو وسطاء البيانات.

6. لماذا تُستخدم بيانات وضع الشركة

البياناتالغرض
الهوية والأهليةالتأكد من أنك موظف يحق له استخدام التطبيق، وربط السجلات بالشخص والشركة الصحيحين
البريد ورمز الدخولتسجيل دخولك دون كلمة مرور، ومنع إساءة استخدام نظام الرموز
الحضور والاستراحات والإجازاتإنتاج سجل الحضور الذي تستخدمه شركتك لضبط الدوام وإدارة الإجازات والرواتب
الموقع وتفاصيل الجهاز والاتصالإظهار ظروف تسجيل كل إجراء للمسؤولين المخوّلين في شركتك
عدّادات الحماية وسجلات الخدمةحماية الخدمة من إساءة الاستخدام والحفاظ على استمرار عملها

حيثما تنطبق قوانين حماية البيانات، تستند هذه المعالجة إلى علاقة العمل، والمصلحة المشروعة لجهة عملك في الحفاظ على سجلات حضور دقيقة، وأي التزام قانوني عليها بحفظ سجلات الموظفين. ولا تُعالَج بياناتك لأغراض إعلانية ولا لأي غرض لا صلة له بالحضور.

7. من يمكنه الاطلاع على بيانات وضع الشركة

  • جهة عملك. يراجع المسؤولون المخوّلون عن الرواتب في شركتك حضورك وأختام الموقع المرافقة له وطلبات إجازتك من تطبيق الرواتب، وهذا هو الغرض من التطبيق.
  • موظفو Digital Pages المشغّلون للخدمة، وبالقدر اللازم فقط لتشغيلها ودعمها ونسخها احتياطياً وإصلاحها.
  • البنية التحتية المستخدمة لتشغيل الخدمة: مزوّد استضافة الخادم، وخدمة البريد التي توصل رموز الدخول والدعوات.
  • الجهات الرسمية، فقط حين يُلزمنا القانون أو يُلزم جهة عملك بالإفصاح.

لا توجد داخل التطبيق أي أداة من طرف ثالث تتلقى بياناتك.

8. أين تُحفظ البيانات

تُحفظ بيانات حضور وضع الشركة في قاعدة بيانات مخصّصة على خادم تشغّله Digital Pages، منفصلة عن قاعدة بيانات الرواتب الرئيسية ولا يمكن الوصول إليها إلا عبر حساب مقيّد خاص بهذه الخدمة. ويجري الاتصال بين التطبيق والخدمة عبر HTTPS، وبين الخدمة وقاعدة البيانات عبر TLS.

9. مدة الاحتفاظ ببيانات وضع الشركة

البياناتمدة الاحتفاظ
طلبات رموز الدخولتُمسح بصمة الرمز عند استخدامه بنجاح، ويبطل الرمز بعد 10 دقائق. تحذف طلبات الرموز اللاحقة سجلات الرموز الأخرى التي مضى على آخر إرسال لها أكثر من 24 ساعة.
جلسات الدخولتبطل بعد 7 أيام. تُحذف السجلات المنتهية عند دخول ناجح لاحق، ويحذف تسجيل الخروج تلك الجلسة.
عدّادات الحد من المحاولاتتُحذف السجلات الأقدم من ساعتين خلال طلبات رموز الدخول اللاحقة.
الحضور والاستراحات وطلبات الإجازة مع أختام الموقعتُحفظ ضمن سجل العمل لدى شركتك، للمدة التي تحتاجها ويسمح بها القانون
النسخ الاحتياطية لقاعدة البياناتتُحفظ لمدة 14 يوماً بالتناوب ثم تُتلف

يُشغَّل تنظيف بيانات الدخول عبر هذه الطلبات اللاحقة، وليس وفق موعد حذف دوري مضمون. وتقرر شركتك مدة حفظ سجلات العمل بعد انتهاء التوظيف. أما السجلات الشخصية فتبقى على جهازك حتى مسح بيانات التطبيق أو إلغاء تثبيته، وتبقى ملفات CSV المصدّرة منفصلة وتحت سيطرتك.

10. كيف تُحمى البيانات

  • ‏HTTPS بشهادة صالحة لكل الاتصال بين التطبيق والخدمة.
  • تخزين رموز الدخول ورموز الجلسة على شكل بصمات تشفير فقط، لا بصيغة مقروءة.
  • حفظ رمز الجلسة في التخزين المشفَّر في أندرويد على جهازك.
  • تعطيل تصحيح الأخطاء والنسخ الاحتياطي لبيانات التطبيق والتقاط الصور أو معاينة التطبيق في نسخ الإصدار.
  • حصر صلاحيات حسابات قاعدة البيانات في الجداول والأعمدة اللازمة فقط، دون أي وصول إلى بيانات الرواتب.
  • تشغيل الخدمة داخل حاوية محصّنة بنظام ملفات للقراءة فقط ودون صلاحيات إضافية.
  • حدود على حجم الطلبات ومعدّلها، وإعادة التحقق من أهليتك مع كل طلب مُصدَّق.

لا يوجد نظام آمن تماماً، لكن التطبيق مبني بحيث لا يؤدي خلل في جزء منه إلى كشف بيانات الرواتب.

11. خياراتك

  • إذن الموقع يمكن سحبه في أي وقت من إعدادات أندرويد، وعندها لن يتمكن التطبيق من تسجيل الحضور لأن تحديد الموقع شرط لتلك الإجراءات.
  • القفل البيومتري اختياري ويمكن تفعيله أو تعطيله من إعدادات التطبيق.
  • اللغة والمظهر من اختيارك ويُحفظان على جهازك.
  • تسجيل الخروج في وضع الشركة يزيل الجلسة من جهازك ويُلغيها على الخادم.
  • إلغاء التثبيت يزيل التطبيق وبياناته على الجهاز، وتبقى سجلات الشركة المرسلة سابقاً لدى جهة عملك. تُحذف السجلات الشخصية، بينما تبقى ملفات CSV المصدّرة خارج تخزين التطبيق.

12. حقوقك

بحسب مكان إقامتك، قد يحق لك طلب نسخة من بياناتك أو تصحيحها أو حذفها أو تقييد استخدامها أو الاعتراض عليه، وتقديم شكوى إلى جهة مختصة بحماية البيانات.

لسجلات العمل في وضع الشركة، فإن أسرع طريق لمعظم الطلبات هو مسؤول الموارد البشرية أو الرواتب في شركتك، إذ يمكنه مراجعة سجلاتك والتعامل مع طلب التصحيح. ويمكنك أيضاً مراسلتنا على app@digital-pages.dev وسنساعدك، بالتنسيق مع شركتك حين تكون السجلات تخصّها. وللحذف تحديداً، راجع صفحة حذف بياناتي. نردّ على الطلبات خلال 30 يوماً.

13. الأطفال

‏Dawamee أداة لضبط أوقات العمل للبالغين، وليست موجّهة للأطفال. ويقتصر الوصول إلى وضع الشركة على الموظفين المدعوّين والمؤهلين.

14. تعديلات هذه السياسة

عند تعديل هذه السياسة سنحدّث هذه الصفحة والتاريخ المذكور في أعلاها. كما تُبلَّغ جهة عملك بالتعديلات الجوهرية التي تمس طريقة استخدام بيانات وضع الشركة.

15. التواصل

‏Digital Pages — Dawamee
app@digital-pages.dev

ملحق: أذونات أندرويد

الإذنسبب طلبه
الموقع الدقيق والتقريبيتحديد الموقع المرافق لكل إجراء حضور ولكل إرسال أو إلغاء لطلب إجازة، أثناء استخدام التطبيق فقط ودون أي تتبّع في الخلفية.
الإنترنت وحالة الشبكةوضع الشركة: الاتصال بخدمة الحضور وبيان استخدام Wi-Fi أو بيانات الهاتف عند الإجراء. لا يُجري الوضع الشخصي أي طلبات API أو شبكة.
التحقق البيومتري / البصمةقفل التطبيق الاختياري. يجري التحقق في نظام أندرويد، ولا يعرف التطبيق سوى النتيجة.
الإشعاراتعند منحه، تُستخدم فقط للرسائل التي ينشئها التطبيق على جهازك. ولا يتلقى التطبيق إشعارات فورية من خادم بعيد.