Privacy Policy
This Privacy Policy describes how SoReel ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you use soreel.ae and related services (the "Service"). It also explains your rights and how to exercise them.
We process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL") and applicable implementing regulations.
1. Who we are
SoReel is operated from the United Arab Emirates. For data protection matters, contact us at privacy@soreel.ae. We are the Controller of personal data described in this policy unless otherwise stated.
2. What we collect
Account data - full name, email address, password hash (we never store plaintext passwords), account type (Creator or Business), date of account creation, language and locale preferences.
Profile data - Instagram, TikTok, YouTube handle(s); follower and engagement counts obtained from social platforms via OAuth or scheduled refresh; bio text; profile picture URL; city or area.
Business and venue data - venue name, category, location, description, cover image, trade licence documents (where uploaded for verification), business representative details.
Contact data - phone or WhatsApp number where you choose to provide one (used to facilitate post-approval contact between matched Creators and Businesses; never displayed publicly).
OAuth access tokens - when you connect Instagram, YouTube, or TikTok, we store access tokens (and refresh tokens where issued) to fetch metrics on your behalf. Tokens are encrypted at rest.
Usage data - Collab applications, approvals, redemptions, post submissions, ratings, in-app messages with support, notification preferences.
Follower snapshots - periodic snapshots of your public follower count from connected platforms, used to report growth attributable to a Collab.
Payment data - for paid plans, our payment processor (Ziina) handles card details directly; we receive only a token, the last four digits, the card brand, and transaction status. We do not store full card numbers.
Technical data - IP address, browser type and version, device OS, pages visited, timestamps, error logs. Collected automatically for security, debugging, and platform integrity.
Communications - emails you send us, support chat messages, transactional email delivery receipts.
2A. Business prospect data (B2B outreach)
Separately from data we collect from registered Users (Section 2), we collect limited business contact information about businesses we may want to introduce to SoReel.
What we collect: venue name and address; publicly displayed business email address and phone number; publicly displayed social media handles (Instagram, TikTok, YouTube); publicly displayed business performance signals such as Google review counts and social media follower counts; notes about the business derived from public sources.
Sources: editorial publications (Time Out Dubai/AD, What's On, Caterer ME, Gulf News, Khaleej Times), public directories (Google Maps, Tabby and Tamara merchant directories, Letswork, Tripadvisor), creator blogs, and our own warm professional network.
Legal basis: legitimate interest (UAE PDPL Article 5(7)). We limit collection to publicly available business information necessary for B2B outreach and prospect qualification. We do not collect personal data of individuals beyond the publicly displayed business owner or representative contact.
Use: to assess whether the business is a potential fit for the SoReel platform, and to send introductory outreach communications.
Retention: until the business either signs up as a User OR requests removal (see Opt-out below) OR a maximum of 24 months from collection, whichever comes first.
Opt-out: any business owner or representative who does not wish to receive SoReel outreach may reply "unsubscribe" to any email we send, or write to privacy@soreel.ae. We add the contact to our permanent exclusion list within 24 hours and do not contact the business again.
2B. Meeting bookings via Microsoft Bookings
If you book a meeting with SoReel through our public Bookings page (bookings.soreel.ae), Microsoft Corporation collects and processes:
- Your name (required)
- Your email address (required)
- Any details you choose to provide in the "Special requests" field
- Your timezone (auto-detected from your browser)
- The service and time slot you select
This data is processed by Microsoft Corporation under Microsoft's privacy terms (https://privacy.microsoft.com). SoReel receives notification of the booking and uses the data only to:
- Confirm and conduct the scheduled meeting
- Send reminder and follow-up communications related to the meeting
- Follow up on the conversation after the meeting
Retention of booking records: SoReel retains meeting records (including any notes from the meeting) for 24 months from the date of the meeting, after which they are deleted unless required for legal or audit reasons.
Cancellation: you can cancel a scheduled meeting using the link in your confirmation email at any time before the start time.
No User account required: booking a meeting does not create a SoReel User account and does not bind you to the Terms of Service. The Terms of Service apply only if and when you separately sign up as a User on soreel.ae. Booking is governed by this Privacy Policy and Microsoft's own privacy terms.
3. Legal basis for processing (UAE PDPL Article 5)
We process personal data on the following legal bases:
- Performance of a contract - to operate the Service for which you signed up (Article 5(2)).
- Legitimate interests - fraud prevention, security, service improvement, where these are not overridden by your rights (Article 5(7)).
- Consent - for marketing communications, optional integrations, and any processing you have explicitly opted into (Article 5(1)). You may withdraw consent at any time.
- Legal obligation - to comply with UAE tax, anti-money-laundering, court order, or other regulatory requirements (Article 5(3)).
- Vital interests / public interest - only where required by law (Articles 5(4), 5(5)).
4. How we use your data
- To operate the Service: matching Creators with Businesses, processing applications, generating redemption codes, tracking post submissions.
- To verify identity, trade licences, and social media ownership.
- To calculate Creator reach metrics and AED-equivalent value for Business reporting.
- To send transactional emails (signup confirmation, application status, payment receipts, post reminders, security alerts).
- To send service announcements (planned downtime, terms updates).
- To send marketing communications (tips, new features) - only with your explicit opt-in; you can unsubscribe at any time.
- To detect and prevent fraud, abuse, and Acceptable Use violations.
- To respond to support requests and resolve User disputes.
- To comply with legal obligations and respond to lawful requests from UAE authorities.
- To improve the Service through aggregated, anonymised analytics. This includes anonymous funnel tracking (a random ID stored in your browser to measure where signups drop off) - the ID has no personal data attached unless you complete signup, at which point it links to your account so we can review your own journey.
We do not sell, rent, or trade your personal data. We do not show third-party advertising in the Service. We do not use your data to train third-party AI models.
5. Who we share your data with
Other Users on the Service. When you apply for a Collab, the Business sees your handle, follower count, rating, and any details displayed on your public profile. After a Collab is approved, both parties may see each other's WhatsApp contact number (once it has been verified via our planned WhatsApp verification flow) to coordinate the visit. Email addresses are never exchanged between Users.
Sub-processors. We use the following service providers to operate the Service. They process personal data on our instructions and under written data-processing terms:
- C2P Consultants (United Arab Emirates) - registered Tech Provider for the SoReel Meta app; holds the Meta app credentials on SoReel's behalf and facilitates Instagram API access. C2P processes Platform Data only at SoReel's direction and may not use it for its own purposes.
- Supabase (United States / European Union infrastructure) - database, authentication, file storage, edge functions.
- Resend (United States) - transactional email delivery.
- Ziina (United Arab Emirates) - subscription payment processing.
- Meta Platforms (United States / Ireland) - Instagram OAuth and metrics retrieval (via C2P Consultants as registered Tech Provider); WhatsApp Business API for contact verification and notifications (planned).
- Google (United States / Ireland) - YouTube OAuth and metrics retrieval.
- TikTok / ByteDance (Singapore / Ireland) - TikTok OAuth and metrics retrieval.
- Bluehost (United States) - web hosting for static assets.
- Anthropic (United States) - support-chat assistant model inference for the in-app help bot; data minimised to the support message content.
- Microsoft Corporation (United States / European Union infrastructure) - Microsoft 365 services including Outlook, Microsoft Bookings (meeting scheduling), Calendar, and Teams meetings. Used to host operational mailboxes, receive prospect meeting bookings, and conduct video meetings.
Legal disclosures. We may share data with UAE authorities, courts, or law enforcement where required by law, court order, or to protect the rights, property, or safety of SoReel, our Users, or the public.
Business transfers. If we are involved in a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to this Privacy Policy or an equivalent successor.
6. Cross-border data transfers
Some of our sub-processors are based outside the UAE (notably United States and European Union). When we transfer your personal data outside the UAE, we rely on:
- The recipient country being deemed by UAE authorities to have an adequate level of data protection, or
- Standard contractual clauses, processor binding rules, or equivalent safeguards required by UAE PDPL Article 22, or
- Your explicit consent for the transfer (Article 23).
7. Data retention periods
We retain your personal data only as long as necessary for the purposes set out in this policy or as required by law. Specific retention periods:
- Account profile and activity: while your account is active.
- After account deletion: personal identifiers wiped within 30 days. Anonymised aggregate statistics may be retained indefinitely.
- Payment and transaction records: 7 years from the transaction date, as required by UAE tax and commercial law.
- OAuth tokens: until you disconnect the integration, plus up to 7 days for safe revocation processing.
- Server logs (IP, technical): 90 days from collection.
- Support chat transcripts: 24 months from the last message.
- Verification documents (trade licence images): until verification is decided plus 18 months, after which deleted unless required for ongoing legal/dispute reasons.
- Backup snapshots: overwritten on a 30-day rolling cycle.
- Legal holds: data subject to active legal proceedings, tax audits, or regulatory investigations is retained until the matter is resolved.
8. Your rights under UAE PDPL
You have the following rights regarding your personal data:
- Right to be informed - about how we process your data (this policy).
- Right of access (Article 13) - request a copy of the personal data we hold about you.
- Right to rectification (Article 14) - correct inaccurate or incomplete data.
- Right to erasure / deletion (Article 15) - delete your personal data, subject to legal retention requirements.
- Right to restrict processing (Article 16) - limit how we use your data in specific circumstances.
- Right to data portability (Article 17) - receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 18) - to processing based on legitimate interests or for marketing purposes.
- Right to withdraw consent - for processing based on consent, at any time.
- Right not to be subject to solely automated decision-making (Article 19) - that produces legal or similarly significant effects. We do not currently use such automated decision-making.
- Right to lodge a complaint - with the UAE Data Office or other competent authority.
To exercise any of these rights, use our , or email privacy@soreel.ae. We respond within 30 days as required by Article 24 of the PDPL.
9. Security
We implement appropriate technical and organisational measures to protect your personal data:
- HTTPS / TLS for all data in transit.
- Encryption at rest for OAuth tokens, verification documents, and password hashes.
- Row-level security policies in our database so Users can only access their own data.
- Time-limited authentication sessions with secure tokens.
- Access controls and audit logging for administrative actions.
- Regular security review of code and infrastructure.
No system is perfectly secure. We will notify affected Users and the UAE Data Office of any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by UAE PDPL Article 9.
10. Children's data
SoReel is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. Creator accounts for users aged 16-17 require parent or guardian consent and are subject to additional safeguards.
If you believe we may have collected data from a child under 16 without proper consent, contact us at privacy@soreel.ae and we will delete the data promptly.
11. Cookies and similar technologies
We use only essential cookies and local-storage entries required for the Service to function:
- Authentication tokens (Supabase session) - to keep you signed in.
- Wizard draft state (sessionStorage) - to recover unsaved progress in offer or venue setup.
- UI preferences (localStorage) - to remember dismissed notifications and personalisation flags.
We do not use third-party tracking cookies. We do not use advertising cookies. We do not use cross-site behavioural tracking.
If we add product analytics in the future (e.g. PostHog or Google Analytics), we will update this section and obtain consent where required.
12. Marketing communications
We will only send you marketing communications (newsletters, tips, feature announcements) if you have explicitly opted in. You can unsubscribe at any time using the link in any marketing email, or from Settings → Notifications.
Transactional communications (account-critical notices, application status, security alerts, payment receipts) are not marketing and you cannot opt out of them while your account is active.
13. International users
SoReel is operated from the United Arab Emirates and is intended primarily for UAE Users. If you access the Service from outside the UAE, you do so on your own initiative and are responsible for compliance with your local laws. By using the Service from outside the UAE, you consent to your data being transferred to and processed in the UAE.
14. Profile visibility
Some of your data is visible to other Users by design:
- Creator profiles - handle, bio, follower counts, ratings, and any badges are visible to Businesses browsing the Service.
- Venue listings - venue name, category, location, description, cover image, and verification status are visible to Creators browsing the Service.
- WhatsApp contact - visible only after a Collab application is approved, and only between the matched Creator and Business.
- Email addresses - never shared with other Users.
- Verification documents - never shared with other Users.
15. Changes to this policy
We may update this policy. The "Last updated" date at the top will change, and material changes will be notified by email or in-app banner at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
16. Contact and complaints
Data protection enquiries, rights requests, or complaints: privacy@soreel.ae or via .
If you believe we have not adequately addressed your concern, you may lodge a complaint with the UAE Data Office or other competent supervisory authority in your jurisdiction.
SoReel - operated from the United Arab Emirates. Compliant with UAE Federal Decree-Law No. 45 of 2021.
تصف سياسة الخصوصية هذه كيف تجمع صوريل ("نحن"، "لنا") بياناتك الشخصية وتستخدمها وتخزنها وتشاركها وتحميها عند استخدامك soreel.ae والخدمات المرتبطة ("الخدمة"). كما توضح حقوقك وكيفية ممارستها.
نعالج البيانات الشخصية وفقا للمرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية ("قانون حماية البيانات الإماراتي") واللوائح التنفيذية المعمول بها.
1. من نحن
صوريل تشغل من دولة الإمارات العربية المتحدة. للأمور المتعلقة بحماية البيانات، تواصل معنا على privacy@soreel.ae. نحن المتحكم في البيانات الشخصية الموصوفة في هذه السياسة ما لم يذكر خلاف ذلك.
2. ما الذي نجمعه
بيانات الحساب - الاسم الكامل، عنوان البريد الإلكتروني، تجزئة كلمة المرور (لا نخزن كلمات المرور الأصلية أبدا)، نوع الحساب (صانع محتوى أو نشاط تجاري)، تاريخ إنشاء الحساب، تفضيلات اللغة والإقليم.
بيانات الملف - معرفات انستقرام وتيك توك ويوتيوب؛ أعداد المتابعين والتفاعل المستحصلة من منصات التواصل عبر OAuth أو التحديث المجدول؛ نص النبذة؛ رابط صورة الملف؛ المدينة أو المنطقة.
بيانات الأعمال والموقع - اسم الموقع، الفئة، الموقع، الوصف، صورة الغلاف، مستندات الرخصة التجارية (حيث رفعت للتحقق)، تفاصيل ممثل النشاط التجاري.
بيانات التواصل - رقم الهاتف أو واتساب حيث تختار تقديمه (يستخدم لتسهيل التواصل بعد الموافقة بين صناع المحتوى والأنشطة التجارية المطابقة؛ لا يعرض علنا أبدا).
رموز وصول OAuth - عند ربطك انستقرام أو يوتيوب أو تيك توك، نخزن رموز الوصول (ورموز التحديث حيث صدرت) لجلب المقاييس نيابة عنك. تشفر الرموز أثناء التخزين.
بيانات الاستخدام - طلبات التعاون، الموافقات، عمليات الاستلام، إرسال المنشورات، التقييمات، الرسائل داخل التطبيق مع الدعم، تفضيلات الإشعارات.
لقطات المتابعين - لقطات دورية لعدد متابعيك العام من المنصات المرتبطة، تستخدم لإعداد تقرير النمو المنسوب إلى التعاون.
بيانات الدفع - للباقات المدفوعة، يعالج معالج الدفع لدينا (زينة) تفاصيل البطاقة مباشرة؛ نتلقى رمزا مميزا فقط، وآخر أربعة أرقام، وعلامة البطاقة، وحالة المعاملة. لا نخزن أرقام البطاقات الكاملة.
البيانات التقنية - عنوان IP، نوع المتصفح وإصداره، نظام تشغيل الجهاز، الصفحات المزارة، الطوابع الزمنية، سجلات الأخطاء. تجمع تلقائيا لأغراض الأمن وتصحيح الأخطاء وسلامة المنصة.
الاتصالات - رسائل البريد الإلكتروني التي ترسلها إلينا، رسائل دعم المحادثة، إيصالات تسليم البريد الإلكتروني للمعاملات.
2 أ. بيانات الأنشطة التجارية المحتملة (التواصل التجاري)
بالإضافة إلى البيانات التي نجمعها من المستخدمين المسجلين (القسم 2)، نجمع معلومات اتصال محدودة عن الأنشطة التجارية التي قد نرغب في تعريفها بصوريل.
ما نجمعه: اسم الموقع وعنوانه؛ عنوان البريد الإلكتروني التجاري ورقم الهاتف المعروضين علنا؛ معرفات وسائل التواصل الاجتماعي المعروضة علنا (انستقرام، تيك توك، يوتيوب)؛ مؤشرات الأداء التجارية المعروضة علنا مثل عدد مراجعات قوقل وعدد متابعي وسائل التواصل الاجتماعي؛ ملاحظات عن النشاط التجاري مستمدة من مصادر عامة.
المصادر: المنشورات التحريرية (تايم أوت دبي/أبوظبي، واتس أون، كاتيرر ميدل إيست، جلف نيوز، الخليج تايمز)، الأدلة العامة (خرائط قوقل، أدلة تجار تابي وتمارا، ليتس وورك، تريب أدفايزر)، مدونات صناع المحتوى، وشبكة علاقاتنا المهنية الدافئة.
الأساس القانوني: المصلحة المشروعة (المادة 5(7) من قانون حماية البيانات الإماراتي). نقصر الجمع على المعلومات التجارية المتاحة للعموم والضرورية للتواصل التجاري وتأهيل الأنشطة المحتملة. لا نجمع البيانات الشخصية للأفراد بما يتجاوز جهة الاتصال التجارية لمالك النشاط أو ممثله المعروضة علنا.
الاستخدام: لتقييم ما إذا كان النشاط التجاري ملائما لمنصة صوريل، ولإرسال اتصالات تعريفية.
الاحتفاظ: حتى يسجل النشاط التجاري كمستخدم أو يطلب الإزالة (انظر إلغاء الاشتراك أدناه) أو لمدة أقصاها 24 شهرا من تاريخ الجمع، أيهما أسبق.
إلغاء الاشتراك: يمكن لأي مالك نشاط تجاري أو ممثل لا يرغب في تلقي اتصالات صوريل الرد بكلمة "unsubscribe" على أي بريد إلكتروني نرسله، أو الكتابة إلى privacy@soreel.ae. نضيف جهة الاتصال إلى قائمة الاستبعاد الدائمة خلال 24 ساعة ولا نتواصل مع النشاط التجاري مرة أخرى.
2 ب. حجوزات الاجتماعات عبر Microsoft Bookings
إذا حجزت اجتماعا مع صوريل عبر صفحة الحجز العامة (bookings.soreel.ae)، تجمع شركة Microsoft Corporation وتعالج:
- اسمك (مطلوب)
- عنوان بريدك الإلكتروني (مطلوب)
- أي تفاصيل تختار تقديمها في حقل "طلبات خاصة"
- المنطقة الزمنية (تكتشف تلقائيا من متصفحك)
- الخدمة وفترة الحجز التي تختارها
تعالج Microsoft Corporation هذه البيانات بموجب شروط خصوصية Microsoft (https://privacy.microsoft.com). تتلقى صوريل إشعارا بالحجز وتستخدم البيانات فقط من أجل:
- تأكيد الاجتماع المجدول وإجرائه
- إرسال اتصالات تذكير ومتابعة متعلقة بالاجتماع
- متابعة المحادثة بعد الاجتماع
الاحتفاظ بسجلات الحجز: تحتفظ صوريل بسجلات الاجتماعات (بما فيها أي ملاحظات من الاجتماع) لمدة 24 شهرا من تاريخ الاجتماع، تحذف بعدها ما لم تكن مطلوبة لأسباب قانونية أو تدقيقية.
الإلغاء: يمكنك إلغاء اجتماع مجدول باستخدام الرابط الموجود في رسالة التأكيد في أي وقت قبل وقت البدء.
لا يلزم حساب مستخدم: حجز اجتماع لا ينشئ حساب مستخدم في صوريل ولا يلزمك بشروط الخدمة. تنطبق شروط الخدمة فقط إذا قمت بالتسجيل لاحقا كمستخدم على soreel.ae بشكل منفصل. يخضع الحجز لسياسة الخصوصية هذه ولشروط الخصوصية الخاصة بـ Microsoft.
3. الأساس القانوني للمعالجة (المادة 5 من قانون حماية البيانات الإماراتي)
نعالج البيانات الشخصية بناء على الأسس القانونية التالية:
- تنفيذ عقد - لتشغيل الخدمة التي اشتركت بها (المادة 5(2)).
- المصالح المشروعة - منع الاحتيال، الأمن، تحسين الخدمة، حيث لا تتجاوزها حقوقك (المادة 5(7)).
- الموافقة - للاتصالات التسويقية، التكاملات الاختيارية، وأي معالجة وافقت عليها صراحة (المادة 5(1)). يمكنك سحب الموافقة في أي وقت.
- الالتزام القانوني - للامتثال للضرائب الإماراتية ومكافحة غسل الأموال وأوامر المحاكم أو متطلبات تنظيمية أخرى (المادة 5(3)).
- المصالح الحيوية / المصلحة العامة - فقط حيث يقتضي القانون (المادتان 5(4) و5(5)).
4. كيف نستخدم بياناتك
- تشغيل ميزات الخدمة الأساسية (الحسابات، الملفات، الخلاصة، الطلبات، المراسلات، التقارير).
- التحقق من ملكية حساب وسائل التواصل والرخصة التجارية والاتصال بواتساب.
- إرسال الإشعارات المتعلقة بالمعاملات (الموافقات على التعاون، عمليات الاستلام، تأكيدات المنشور، إيصالات الدفع).
- إنتاج تقارير الأعمال التي توضح انتشار التعاون والتفاعل ونمو المتابعين.
- منع الاحتيال، اكتشاف إساءة استخدام المنصة، الامتثال للأوامر القانونية.
- تحسين الخدمة عبر التحليلات المجمعة وغير المعرفة.
- التسويق حيث وافقت صراحة (يمكنك إلغاء الاشتراك في أي وقت).
- الرد على رسائل دعمك ومراسلاتك.
5. مع من نشارك بياناتك
أنشطة تجارية مطابقة - عندما تتقدم لتعاون، ترى الأعمال اسمك ومعرفات وسائل التواصل وأعداد المتابعين الموثقة والنبذة وصورة الملف والمدينة. بعد الموافقة، قد يرى أيضا واتساب/الهاتف (إن قدمته) ورمز الاستلام.
مزودو الخدمات (المعالجون) - نستخدم أطرافا ثالثة مختارة لتشغيل الخدمة بموجب اتفاقيات معالجة بيانات: زينة (الدفع)، Resend (تسليم البريد الإلكتروني للمعاملات)، Supabase (استضافة قاعدة البيانات/التخزين)، Bluehost (استضافة الويب)، Microsoft Corporation (خدمات Microsoft 365: Outlook وBookings وCalendar وTeams)، مقدمو OAuth لكل منصة (Meta/Instagram، Google/YouTube، TikTok).
السلطات - قد نفصح عن البيانات عند الطلب بموجب أمر قانوني صالح (محكمة، نائب عام، جهة تنظيمية) أو حيث يقتضي القانون.
عمليات نقل الأعمال - في حال الدمج أو الاستحواذ أو بيع الأصول، قد تنقل البيانات إلى الجهة الخلف، مع إشعار لك ومع الالتزامات نفسها.
6. عمليات نقل البيانات عبر الحدود
تستضاف بعض مكونات المنصة من قبل مزودين خارج دولة الإمارات (على سبيل المثال، تشغيل Supabase في الاتحاد الأوروبي/الولايات المتحدة). تتم عمليات النقل وفقا للقسم الثالث من قانون حماية البيانات الإماراتي ومع ضمانات تعاقدية مناسبة. يمكنك طلب تفاصيل عن الأطراف المرسل إليها وضماناتها عبر التواصل معنا.
7. فترات الاحتفاظ بالبيانات
- بيانات الحساب النشط - تحتفظ طوال نشاط حسابك.
- بعد الحذف - تحذف معظم البيانات الشخصية خلال 30 يوما من حذف الحساب.
- الفواتير وسجلات المعاملات - تحتفظ لمدة 5 سنوات وفقا لمتطلبات الضرائب الاتحادية والمحاسبة الإماراتية.
- سجلات منع الاحتيال - تحتفظ لمدة تصل إلى 3 سنوات من آخر نشاط.
- المراسلات - تحتفظ لمدة سنتين بعد الإغلاق.
- النسخ الاحتياطية - قد تحتفظ في النسخ الاحتياطية المشفرة لمدة تصل إلى 90 يوما بعد الحذف لأغراض التعافي من الكوارث.
8. حقوقك بموجب قانون حماية البيانات الإماراتي
بموجب قانون حماية البيانات الإماراتي، لديك الحقوق التالية:
- الوصول - اطلب نسخة من بياناتك الشخصية (المادة 13).
- التصحيح - اطلب تصحيح البيانات غير الدقيقة أو غير الكاملة (المادة 14).
- الحذف - اطلب الحذف، مع مراعاة فترات الاحتفاظ القانونية (المادة 15).
- تقييد المعالجة - اطلب أن نتوقف عن استخدام بياناتك في ظروف معينة (المادة 16).
- نقل البيانات - اطلب بياناتك بصيغة منظمة وآلية القراءة (المادة 18).
- الاعتراض على المعالجة - لا سيما التسويق المباشر والتحليلات (المادة 17).
- سحب الموافقة - حيث كانت الموافقة هي الأساس القانوني.
لممارسة أي حق، تواصل معنا على privacy@soreel.ae. سنرد خلال 30 يوما. قد نطلب تأكيد هويتك قبل التنفيذ. عملية مجانية ما لم يكن الطلب متكررا أو مفرطا بشكل واضح.
9. الأمن
نطبق تدابير تقنية وتنظيمية تشمل:
- تشفير TLS للبيانات أثناء النقل.
- تشفير في حالة السكون لقاعدة البيانات والنسخ الاحتياطية.
- تجزئة كلمة المرور بـ bcrypt (لا تخزين للنص الأصلي).
- سياسات أمن الصف على مستوى الصف (RLS) في قاعدة البيانات.
- الوصول الإداري محصور بالموظفين المخولين فقط، مع تسجيل.
- مراجعات أمنية دورية للتبعيات.
10. بيانات الأطفال
الخدمة غير موجهة للأطفال دون سن 13 عاما ولا نجمع بيانات منهم عن قصد. يجوز للمستخدمين بين 16 و17 عاما إنشاء حسابات صانع محتوى فقط بموافقة الوالد أو الوصي ووفقا لقانون حماية الطفل الإماراتي (المادة 26).
11. ملفات تعريف الارتباط والتقنيات المماثلة
نستخدم الحد الأدنى من ملفات تعريف الارتباط الأساسية للجلسة لإبقائك مسجلا ولحماية CSRF. لا نستخدم ملفات تعريف ارتباط تتبع أطراف ثالثة لأغراض الإعلان. حاليا لا تتم أي تحليلات أطراف ثالثة على الموقع.
12. الاتصالات التسويقية
إن وافقت على التسويق، نرسل تحديثات منتج عرضية فقط. يمكنك إلغاء الاشتراك في أي وقت عبر رابط إلغاء الاشتراك في كل بريد إلكتروني أو من إعدادات الإشعارات. يحترم إلغاء الاشتراك خلال 24 ساعة.
13. المستخدمون الدوليون
إن وصلت إلى الخدمة من خارج دولة الإمارات، قد تخضع البيانات لعمليات نقل عبر الحدود كما هو موصوف في القسم 6. باستخدامك الخدمة، فإنك تقر بهذه التحويلات. حيث ينطبق GDPR (المملكة المتحدة، الاتحاد الأوروبي)، نلتزم بالحد الأدنى من حقوق GDPR إلى جانب قانون حماية البيانات الإماراتي.
14. ظهور الملف
المتغيرات التالية مرئية للأطراف المطابقة:
- الاسم وصورة الملف والنبذة - مرئية للأنشطة التجارية المطابقة.
- معرفات وسائل التواصل وأعداد المتابعين - مرئية للأنشطة التجارية المطابقة.
- سجل التعاون - مرئي للأنشطة التجارية المطابقة (إجمالي، بدون أسماء مواقع سابقة).
- التقييمات - متوسط النجوم مرئي علنا؛ التقييمات الفردية غير مرئية.
- أرقام الهاتف - لا تشارك أبدا مع مستخدمين آخرين.
- عناوين البريد الإلكتروني - لا تشارك أبدا مع مستخدمين آخرين.
- مستندات التحقق - لا تشارك أبدا مع مستخدمين آخرين.
15. التغييرات على هذه السياسة
قد نحدث هذه السياسة. سيتغير تاريخ "آخر تحديث" في الأعلى، وسيتم إشعار التغييرات الجوهرية عبر البريد الإلكتروني أو لافتة داخل التطبيق قبل 14 يوما على الأقل من سريانها. يشكل استمرار استخدام الخدمة بعد التاريخ الفعال قبولا.
16. التواصل والشكاوى
استفسارات حماية البيانات أو طلبات الحقوق أو الشكاوى: privacy@soreel.ae أو عبر .
إن اعتقدت بأننا لم نعالج قلقك بشكل كاف، يمكنك تقديم شكوى إلى مكتب البيانات الإماراتي أو سلطة إشراف مختصة أخرى في نطاق ولايتك القضائية.
صوريل - تشغل من دولة الإمارات العربية المتحدة. متوافقة مع المرسوم بقانون اتحادي رقم 45 لسنة 2021.