نحن في Aram Academy («المنصّة»، «نحن») نُولي خصوصيتك أهمية قصوى. توضِّح هذه السياسة البيانات التي نجمعها، وكيف نستعملها ونحميها ونشاركها، وحقوقك تجاهها. باستخدامك المنصّة فأنت توافق على هذه السياسة.
١. البيانات التي نجمعها
١.١ بيانات تُقدِّمها مباشرةً
- الاسم الكامل والبريد الإلكتروني ورقم الهاتف (عند التسجيل).
- كلمة المرور (مُخزَّنة بشكل مُجزَّأ/مُشفَّر بـ bcrypt — لا نحفظها كنصّ واضح أبداً).
- للمعلّم/المركز: السيرة، الصورة، المؤهّلات والخبرات، روابط التواصل، وتفاصيل الحساب البنكي لتحويل الأرباح.
- للطالب: الصفّ الدراسي (اختياري)، والاشتراكات والكورسات.
- الرسائل والتقييمات والمرفقات التي تكتبها أو ترفعها.
١.٢ بيانات تُجمَع تلقائياً
- عنوان IP، نوع المتصفّح ونظام التشغيل، والصفحات التي تزورها داخل المنصّة.
- تقدُّمك في الكورسات (نسبة الإكمال، الدروس المُشاهَدة).
- ملفّات تعريف ارتباط ضرورية للجلسة وحماية النماذج (CSRF) وتفضيلاتك (اللغة).
١.٣ بيانات من أطراف ثالثة
- تأكيد المدفوعات من بوّابة الدفع CyberSource (لا نستلم ولا نخزّن أرقام البطاقات إطلاقاً).
- رموز ربط Zoom (OAuth) للمعلّمين الذين يربطون حساب Zoom لاستضافة الحصص — انظر القسم ٤.
٢. كيف نستعمل بياناتك
- تقديم الخدمة: توصيل الكورسات والحصص، معالجة المدفوعات، إصدار الشهادات.
- التواصل: إشعارات الحصص والتذكيرات والتحديثات المهمّة.
- التحسين: تحليل الاستخدام بشكل مُجمَّع لتطوير الميزات.
- الأمان: كشف الاحتيال ومنع البوتات والتحقّق من الهوية.
- الالتزام القانوني: الاستجابة للمتطلّبات القانونية عند لزومها.
٣. ما لا نفعله أبداً
- لا نبيع بياناتك الشخصية لأيّ طرف.
- لا نشاركها مع مُعلِنين ولا نستعملها لإعلانات خارجية.
- لا نقرأ رسائلك الخاصّة إلّا للضرورة الأمنية أو بأمر قانوني.
- لا نخزّن بيانات بطاقتك البنكية.
٤. تكامل Zoom (الحصص المباشرة)
تتكامل Aram Academy مع Zoom لتمكين المعلّمين من عقد حصص مباشرة. نصل ونعالج الحدّ الأدنى الضروري فقط من بيانات Zoom:
- إدارة الاجتماعات: إنشاء/تعديل/جدولة/حذف اجتماع، وجلب معرّف الاجتماع وروابط الانضمام والبدء ورمز الدخول، والبيانات الوصفية الأساسية (الموضوع، الوقت، المدّة، المُضيف).
- المشاركون: نستعمل الاسم الظاهر للطالب لإدخاله إلى الحصّة.
- رموز OAuth: تُخزَّن مُشفَّرة وتُستعمل حصراً لإدارة اجتماعات ذلك المعلّم.
ما لا نصل إليه: لا نطّلع على تسجيلاتك السحابية في Zoom، ولا جهات الاتصال، ولا سجلّ الدردشة، ولا أيّ بيانات تتجاوز ما يلزم لجدولة الحصّة وتشغيلها. ولا نُسجّل اجتماعاتك عبر سحابة Zoom نيابةً عنك.
المشاركة مع Zoom: موضوع الاجتماع ووقته وهويّة المُضيف، واسم الطالب الظاهر عند الانضمام. تخضع معالجة Zoom لبياناتك لـ سياسة خصوصية Zoom.
الاحتفاظ والإلغاء: نحتفظ بمراجع الاجتماع (المعرّف/الرابط) طوال إتاحة الحصّة للطلاب المشتركين ثمّ نحذفها وفق جدول الاحتفاظ. تبقى رموز OAuth حتى تفصل الربط أو تحذف حسابك. يمكنك فصل Zoom في أيّ وقت من إعدادات لوحة التحكّم، أو إلغاء الإذن من Zoom App Marketplace (Manage ← Installed Apps). عند الفصل أو إزالة التطبيق نحذف الرموز ونتوقّف عن الوصول لحسابك في Zoom.
٥. مشاركة البيانات مع مزوّدي الخدمات
نشارك الحدّ الأدنى من البيانات مع مزوّدين موثوقين لتشغيل المنصّة فقط:
| الخدمة | الغرض | البيانات المُشتركة |
|---|---|---|
| Zoom | الحصص المباشرة | بيانات الاجتماع، اسم المُضيف/المشارك |
| Bunny.net | استضافة وحماية الفيديو | معرّف المستخدم (للعلامة المائية والروابط المُوقَّعة) |
| CyberSource | معالجة المدفوعات | الاسم، البريد، المبلغ |
| Google (Gemini) | ميزات الذكاء الاصطناعي | النصّ الذي تُدخله في الأداة |
| Firebase (FCM) | الإشعارات الفورية (عند تفعيلها) | رمز جهاز الإشعار |
| مزوّد البريد (SMTP) | رسائل البريد | الاسم، البريد، محتوى الإشعار |
٦. حقوقك
- الوصول: طلب نسخة من بياناتك.
- التصحيح: تعديل معلوماتك من صفحة الإعدادات.
- الحذف: طلب حذف حسابك (مع الاحتفاظ بما يلزم قانونياً كالفواتير).
- التصدير والاعتراض: طلب بياناتك أو رفض استعمالها لأغراض تسويقية.
لممارسة هذه الحقوق راسلنا على qeeqmurad@gmail.com.
٧. الأمان
- اتصال HTTPS/TLS على كلّ الصفحات.
- كلمات المرور مُجزَّأة بـ bcrypt، والأسرار الحسّاسة مُشفَّرة.
- عزل بيانات كلّ معلّم/مركز (Tenant Isolation) وتحديد معدّل الطلبات على المسارات الحسّاسة.
- روابط فيديو مُوقَّعة ومؤقّتة لحماية المحتوى.
٨. مدّة الاحتفاظ
- بيانات الحساب: طوال نشاطه + فترة بعد الإلغاء ما لم يُطلَب الحذف.
- سجلّات الفواتير: للمدّة التي يفرضها القانون.
- سجلّات الذكاء الاصطناعي والأمان: لمدد محدودة ثمّ تُحذف.
٩. ملفّات تعريف الارتباط (Cookies)
نستعمل ملفّات ضرورية (الجلسة وحماية CSRF) ووظيفية (تفضيلاتك كاللغة) فقط. لا نستعمل ملفّات تتبّع إعلانية خارجية.
١٠. الأطفال
المنصّة غير موجَّهة للأطفال دون ١٣ سنة. إن اكتشفنا حساباً لطفل دون السنّ حذفناه. إن كنت وليّ أمر وتعتقد أنّ طفلك سجّل، راسلنا.
١١. تحديثات هذه السياسة
قد نُحدِّث هذه السياسة لتعكس تغييرات في خدماتنا أو القانون، ونُخطِر بالتغييرات الجوهرية مسبقاً عبر البريد أو إشعار داخل المنصّة.
١٢. التواصل
لأيّ استفسار حول الخصوصية: qeeqmurad@gmail.com
At Aram Academy (the “Platform”, “we”, “us”) your privacy matters. This Policy explains what data we collect, how we use, protect, and share it, and the rights you have. By using the Platform you agree to this Policy.
1. Information We Collect
1.1 Information you provide
- Full name, email address, and phone number (at sign-up).
- Password (stored hashed with bcrypt — never kept in plain text).
- Teacher/center: bio, photo, qualifications and experience, social links, and bank details for payouts.
- Student: grade level (optional), and your subscriptions and courses.
- Messages, reviews, and attachments you write or upload.
1.2 Information collected automatically
- IP address, browser and operating-system type, and pages you visit on the Platform.
- Your course progress (completion %, lessons watched).
- Essential cookies for your session and form protection (CSRF), plus your preferences (language).
1.3 Information from third parties
- Payment confirmation from the CyberSource gateway (we never receive or store card numbers).
- Zoom OAuth tokens for teachers who connect a Zoom account to host live classes — see Section 4.
2. How We Use Your Data
- Provide the service: deliver courses and classes, process payments, issue certificates.
- Communicate: class notifications, reminders, and important updates.
- Improve: analyze usage in aggregate to develop features.
- Security: fraud detection, bot prevention, and identity verification.
- Legal compliance: respond to lawful requirements when required.
3. What We Never Do
- We never sell your personal data to anyone.
- We do not share it with advertisers or use it for external advertising.
- We do not read your private messages except for security necessity or lawful order.
- We do not store your card data.
4. Zoom Integration (Live Classes)
Aram Academy integrates with Zoom so teachers can hold live classes. We access and process only the minimum necessary Zoom data:
- Meeting management: create / update / schedule / delete a meeting, and retrieve the meeting ID, join & start URLs, passcode, and basic metadata (topic, time, duration, host).
- Participants: we use a student’s display name to admit them to the class.
- OAuth tokens: stored encrypted and used solely to manage that teacher’s meetings.
What we do NOT access: we do not access your Zoom cloud recordings, contacts, chat history, or any data beyond what is needed to schedule and run the class. We do not record your meetings via Zoom cloud on your behalf.
Shared with Zoom: the meeting topic and time, the host identity, and a student’s display name when joining. Zoom’s handling of your data is governed by the Zoom Privacy Statement.
Retention & revocation: we keep meeting references (ID/link) while the class remains available to enrolled students, then delete them per our retention schedule. OAuth tokens are kept until you disconnect or delete your account. You can disconnect Zoom at any time from your dashboard settings, or revoke access at the Zoom App Marketplace (Manage → Installed Apps). On disconnect or uninstall we delete the tokens and stop accessing your Zoom account.
5. Sharing With Service Providers
We share the minimum data with trusted providers solely to operate the Platform:
| Service | Purpose | Data shared |
|---|---|---|
| Zoom | Live classes | Meeting data, host/participant name |
| Bunny.net | Video hosting & protection | User ID (watermark & signed URLs) |
| CyberSource | Payment processing | Name, email, amount |
| Google (Gemini) | AI features | The text you enter in the tool |
| Firebase (FCM) | Push notifications (when enabled) | Device push token |
| Email provider (SMTP) | Email delivery | Name, email, notification content |
6. Your Rights
- Access: request a copy of your data.
- Rectification: edit your information from the settings page.
- Deletion: request account deletion (we retain what the law requires, e.g. invoices).
- Portability & objection: request your data or object to marketing use.
To exercise these rights, email qeeqmurad@gmail.com.
7. Security
- HTTPS/TLS on every page.
- Passwords hashed with bcrypt; sensitive secrets encrypted.
- Per-teacher/center data isolation (tenant isolation) and rate-limiting on sensitive routes.
- Signed, time-limited video URLs to protect content.
8. Data Retention
- Account data: for the life of the account + a period after closure, unless deletion is requested.
- Invoice records: for the period required by law.
- AI and security logs: for limited periods, then deleted.
9. Cookies
We use only essential cookies (session and CSRF protection) and functional cookies (your preferences such as language). We do not use third-party advertising trackers.
10. Children
The Platform is not directed to children under 13. If we discover an under-age account we delete it. If you are a guardian and believe your child registered, contact us.
11. Updates to This Policy
We may update this Policy to reflect changes in our services or the law, and we will notify you of material changes in advance by email or an in-platform notice.
12. Contact
For any privacy inquiry: qeeqmurad@gmail.com