فكر تك — نظام كاشير للمطاعم السعوديةفكر تك

سياسة الخصوصية — كلينيكو

آخر تحديث: ٢ أغسطس ٢٠٢٦

تنبيه بشأن مرحلة الاختبار: تطبيق كلينيكو في مرحلة اختبار مغلق ومحدود، ولم يُطرح للعموم بعد. خلال هذه المرحلة قد تعمل الخدمة على بنية تحتية مؤقتة لأغراض الاختبار، والبيانات المُدخَلة بيانات تجريبية تُحذف عند انتهاء الاختبار. لا تُدخِل بيانات صحية حقيقية أو أرقام هوية حقيقية في هذه المرحلة.

١. من نحن

كلينيكو منصة سعودية لحجز المواعيد الطبية، تُشغّلها شركة فكر تك. لأغراض نظام حماية البيانات الشخصية السعودي، تُعدّ فكر تك جهة التحكّم في البيانات الشخصية التي تُعالَج عبر التطبيق. للتواصل بشأن الخصوصية: adnan@fekirtech.com.

إصدار هذه الوثيقة: privacy-v1.0.0. يظهر الإصدار نفسه داخل التطبيق عند منحك الموافقة، ويُسجَّل مع كل موافقة.

٢. البيانات التي نجمعها

نجمع فقط ما تحتاجه الخدمة فعلياً، وهذه هي القائمة الكاملة:

  • بيانات الحساب: البريد الإلكتروني، والاسم بالعربية والإنجليزية، وكلمة المرور (تُخزَّن كبصمة مشفّرة bcrypt ولا يمكن استرجاعها كنص)، ولغة الواجهة المفضّلة.
  • بيانات تعريف حسّاسة: رقم الجوال ورقم الهوية الوطنية أو الإقامة. يُخزَّن كلاهما مشفّراً في قاعدة البيانات، ويُستخدم بجانبه مُلخّص تشفيري للبحث دون كشف النص الأصلي.
  • بيانات المواعيد: المستشفى أو المجمع والعيادة والطبيب والخدمة والوقت، وملاحظة نصّية اختيارية عن الأعراض تكتبها أنت. تُعامَل هذه البيانات كبيانات صحية حسّاسة.
  • بيانات الدفع: المبلغ وحالة العملية ومُعرّفها لدى مزوّد الدفع. لا نستقبل بيانات بطاقتك ولا نخزّنها إطلاقاً، إذ تُدخَل مباشرة لدى مزوّد الدفع المرخّص.
  • بيانات الاستخدام: التقييمات التي تكتبها، وقائمة المفضّلة، وتاريخ آخر تسجيل دخول.
  • بيانات تقنية: عنوان IP ومُعرّف التطبيق، ويُسجَّلان في سجلّ التدقيق ومع كل موافقة تمنحها، كدليل نظامي على المعالجة المشروعة.
  • رمز الإشعارات: مُعرّف الجهاز الخاص بالإشعارات ونوع نظام التشغيل، لإرسال تذكيرات المواعيد.

٣. ما لا نجمعه

  • موقعك الجغرافي لا يغادر جهازك. يطلب التطبيق إذن الموقع لعرض العيادات القريبة على الخريطة فقط، ويُستخدم الموقع داخل الجهاز لتوسيط الخريطة. لا يُرسَل إلى خوادمنا ولا يُخزَّن لدينا. يمكنك رفض الإذن وستعمل بقية أجزاء التطبيق كالمعتاد.
  • لا نستخدم مُعرّف الإعلانات ولا أي أدوات تتبّع إعلاني أو تحليلات طرف ثالث. الإعلانات المعروضة داخل التطبيق ثابتة ويختارها فريقنا يدوياً، وهي غير موجَّهة ولا تعتمد على بياناتك.
  • لا نبيع بياناتك الشخصية ولا نؤجّرها ولا نشاركها لأغراض تسويقية لأي طرف ثالث.

٤. الأساس النظامي والموافقة

تُعالَج البيانات الصحية بموجب موافقتك الصريحة حصراً. عند إنشاء الحساب تُطلَب منك موافقات منفصلة لكل غرض، وتُسجَّل كل موافقة مع إصدار هذه السياسة ووقتها. الأغراض هي:

  • الحساب وتقديم الخدمة (مطلوب)
  • معالجة البيانات الصحية (مطلوب للحجز)
  • حجز المواعيد ومشاركة بياناتك مع المنشأة التي اخترتها (مطلوب للحجز)
  • معالجة المدفوعات ومشاركة ما يلزم مع مزوّد الدفع (مطلوب للدفع)
  • التسويق (اختياري، ومعطّل افتراضياً، ولا يُستخدم مع البيانات الصحية إطلاقاً)
  • التحليلات (اختياري ومعطّل افتراضياً)

يمكنك سحب أي موافقة اختيارية في أي وقت من داخل التطبيق، وتتوقف المعالجة لذلك الغرض فوراً. سحب الموافقات المطلوبة يعني إيقاف الخدمة نفسها.

٥. مع من نشارك بياناتك

  • المنشأة الصحية التي تحجز لديها: تصل إدارتها إلى بيانات موعدك وبيانات التواصل معك، وذلك فقط لتقديم الخدمة. لا تصل أي منشأة إلى بيانات مرضى منشأة أخرى.
  • مزوّد الدفع: نستخدم مزوّد دفع مرخّصاً داخل المملكة لتنفيذ عمليات الدفع وتحويل مستحقات المنشأة. تُشارَك البيانات اللازمة لإتمام العملية فقط.
  • الجهات المختصة عند وجود التزام نظامي يوجب ذلك.

٦. مدد الاحتفاظ

«إخفاء الهوية» يعني إزالة ما يدلّ عليك مع الإبقاء على السجل المالي أو الإحصائي غير المُعرِّف، وذلك حيث يوجب النظام الاحتفاظ به.

  • بيانات التعريف الشخصية: ٥ سنوات من آخر نشاط، ثم إخفاء الهوية
  • المواعيد: ٧ سنوات، ثم إخفاء الهوية
  • المدفوعات: ١٠ سنوات، ثم إخفاء الهوية
  • الموافقات: ١٠ سنوات، ثم إخفاء الهوية
  • سجلّات التدقيق: ١٠ سنوات، ثم الحذف
  • طلبات ممارسة الحقوق: ١٠ سنوات، ثم إخفاء الهوية
  • جلسات الدخول: تُحذف عند انتهائها أو إلغائها

٧. حقوقك

بموجب نظام حماية البيانات الشخصية السعودي، لك الحق في:

  • الاطّلاع على بياناتك والحصول على نسخة منها بصيغة قابلة للقراءة آلياً
  • تصحيح أي بيانات غير دقيقة
  • طلب حذف بياناتك
  • نقل بياناتك إلى جهة أخرى
  • الاعتراض على المعالجة أو تقييدها
  • سحب موافقتك في أي وقت

تُقدَّم الطلبات من داخل التطبيق عبر «حسابي» ثم «حقوقك في بياناتك»، أو بمراسلتنا على adnan@fekirtech.com. نردّ خلال ٣٠ يوماً، وقد تُمدَّد المدة ٣٠ يوماً إضافية مرة واحدة مع إشعارك بذلك. لحذف الحساب راجع صفحة حذف الحساب.

٨. كيف نحمي بياناتك

  • تشفير الاتصال بالكامل عبر TLS، ويرفض التطبيق أي اتصال غير مشفّر
  • تشفير رقم الجوال ورقم الهوية داخل قاعدة البيانات
  • تخزين كلمات المرور كبصمات bcrypt لا يمكن عكسها
  • فصل صلاحيات صارم، بحيث ترى كل منشأة بيانات مرضاها فقط
  • سجلّ تدقيق غير قابل للتعديل لكل وصول إلى البيانات الشخصية
  • حدّ لمحاولات تسجيل الدخول للحماية من هجمات التخمين

٩. مكان حفظ البيانات

عند التشغيل الفعلي للخدمة تُحفظ البيانات داخل المملكة العربية السعودية. وكما هو موضّح في أعلى الصفحة، فإن الخدمة حالياً في مرحلة اختبار مغلق وقد تعمل على بنية تحتية مؤقتة، ولا تُستخدم فيها بيانات حقيقية. سنحدّث هذه الصفحة قبل استقبال أي بيانات حقيقية.

١٠. الأطفال

التطبيق مخصّص لمن أتمّ الثامنة عشرة. لا نجمع بيانات الأطفال عن قصد، وإذا علمنا بذلك نحذفها.

١١. تحديثات هذه السياسة

عند أي تغيير جوهري نصدر إصداراً جديداً من هذه الوثيقة ونطلب موافقتك من جديد داخل التطبيق.


Testing phase notice: Cliniqo is in limited closed testing and has not been released publicly. During this phase the service may run on temporary infrastructure for testing purposes, and any data entered is test data that will be deleted when testing ends. Do not enter real health information or real national ID numbers during this phase.

1. Who we are

Cliniqo is a Saudi medical appointment booking platform operated by FekirTech. For the purposes of the Saudi Personal Data Protection Law (PDPL), FekirTech is the data controller for personal data processed through the app. Privacy contact: adnan@fekirtech.com.

Document version: privacy-v1.0.0. The same version is shown in the app when you grant consent, and is recorded against every consent.

2. The data we collect

We collect only what the service actually needs. This is the complete list:

  • Account data: email address, name in Arabic and English, password (stored only as a bcrypt hash and never recoverable as text), and preferred interface language.
  • Sensitive identifiers: mobile number and Saudi national ID or Iqama number. Both are stored encrypted in the database, alongside a cryptographic digest used for lookup without exposing the original value.
  • Appointment data: the hospital or complex, clinic, doctor, service and time, plus an optional free-text symptom note that you write. This is treated as sensitive health data.
  • Payment data: amount, transaction status and the payment provider's reference. We never receive or store your card details, which are entered directly with the licensed payment provider.
  • Usage data: reviews you write, your favourites list, and your last sign-in time.
  • Technical data: IP address and app identifier, recorded in the audit log and against each consent you grant, as the legal record of lawful processing.
  • Push token: your device notification identifier and platform, used to send appointment reminders.

3. What we do not collect

  • Your location never leaves your device. The app requests location permission only to show nearby clinics on the map, and the position is used on-device to centre that map. It is not sent to our servers and we do not store it. You may decline the permission and the rest of the app works normally.
  • We do not use the advertising ID or any advertising tracker or third-party analytics SDK. Ads shown inside the app are static and curated by hand, are not targeted, and do not depend on your data.
  • We do not sell your personal data, rent it, or share it with any third party for marketing purposes.

4. Lawful basis and consent

Health data is processed solely on the basis of your explicit consent. At sign-up you are asked for separate consent per purpose, and each consent is recorded with the version of this policy and its timestamp. The purposes are:

  • Account and service delivery (required)
  • Health data processing (required to book)
  • Appointment booking, including sharing your data with the facility you choose (required to book)
  • Payment processing, including sharing what is necessary with the payment provider (required to pay)
  • Marketing (optional, off by default, and never applied to health data)
  • Analytics (optional, off by default)

You can withdraw any optional consent at any time from inside the app, and processing for that purpose stops immediately. Withdrawing a required consent means the service itself stops.

5. Who we share data with

  • The healthcare facility you book with: its administration can access your appointment and contact details, solely to deliver the service. No facility can access another facility's patients.
  • The payment provider: we use a payment provider licensed inside the Kingdom to process payments and settle the facility's share. Only the data necessary to complete the transaction is shared.
  • Competent authorities where a legal obligation requires it.

6. Retention periods

“Anonymise” means stripping what identifies you while keeping the non-identifying financial or statistical record where the law requires it to be retained.

  • Personal identifiers: 5 years from last activity, then anonymised
  • Appointments: 7 years, then anonymised
  • Payments: 10 years, then anonymised
  • Consents: 10 years, then anonymised
  • Audit logs: 10 years, then deleted
  • Data subject requests: 10 years, then anonymised
  • Sessions: deleted on expiry or revocation

7. Your rights

Under the Saudi Personal Data Protection Law you have the right to:

  • Access your data and receive a machine-readable copy
  • Correct any inaccurate data
  • Request erasure of your data
  • Port your data to another provider
  • Object to or restrict processing
  • Withdraw your consent at any time

Requests can be made from inside the app under “My account” then “Your data rights”, or by writing to adnan@fekirtech.com. We respond within 30 days, extendable once by a further 30 days with notice to you. To delete your account see the account deletion page.

8. How we protect your data

  • Fully encrypted transport over TLS; the app refuses any unencrypted connection
  • Mobile number and national ID encrypted inside the database
  • Passwords stored as irreversible bcrypt hashes
  • Strict role separation, so each facility sees only its own patients
  • An immutable audit log of every access to personal data
  • Rate limiting on sign-in to resist brute-force attacks

9. Where data is stored

In live operation, data is stored inside the Kingdom of Saudi Arabia. As stated at the top of this page, the service is currently in closed testing and may run on temporary infrastructure, with no real data in use. We will update this page before accepting any real data.

10. Children

The app is intended for users aged 18 and over. We do not knowingly collect children's data, and we delete it if we become aware of it.

11. Updates to this policy

For any material change we publish a new version of this document and ask for your consent again inside the app.

سياسة الخصوصية | كلينيكو | فكر تك