HomeLegal
Growth Partners Consultancy W.L.L

Privacy and Data Protection Policy

Growth Digital Store for Courses and Templates

Document Information
Document Number
GPC-POL-02
Version
1.2
Last Updated
August 30, 2026.
Effective Date
August 23, 2026.
Data Controller
Growth Partners Consultancy W.L.L, Commercial Registration No. 197615-1, Kingdom of Bahrain
Privacy and Data Protection Email
support@growth-gcc.com

Acknowledgement and Acceptance

By purchasing through the Platform, you agree to these policies.

This Policy explains the Personal Data we collect, why we collect it, how we protect it, your rights, and how to exercise them.

1. Scope of the policy.

This policy applies to all personal data collected by Growth Partners Consultancy W.L.L. or processed through its online store and associated communication channels. This policy is formulated in accordance with the provisions of Personal Data Protection Law in the Kingdom of Bahrain promulgated by Act No. 30 of 2018 and its implementing resolutions, and with the best practices recognized in the GCC States.

Company is the Data Controller for the data referred to in this policy, and the entity that determines and assumes responsibility for the purposes and means of processing.

2. The data we collect.

We follow the principle of data minimisation and collect only the Personal Data reasonably necessary to provide the service.

Identification data.

Examples: Full name.

Collection source: Directly from you when you’re registering or purchasing.

Is it required?: Yes, to complete the order and issue the Licence.

Communication data.

Examples: E-mail, phone number.

Collection source: Directly from you.

Is it required?: Yes, to deliver the product and communicate about the order.

Licensing data.

Examples: Company name or project to be licensed.

Collection source: Directly from you when you buy.

Is it required?: Yes, for Digital Templates, because they’re the basis for determining the scope of the Licence.

Order and transaction data.

Examples: Order number, product name, transaction amount, date and time, payment status, last four digits of the card and type when supplied from Payment Gateway.

Collection source: From Payment Gateway and the store system.

Is it required?: Yes. It is generated automatically when the transaction is completed.

Technical use data.

Examples: IP address, browser type and device, access times, download log and attempts, course viewing activity.

Collection source: Automatically when you use the platform.

Is it required?: Automatically collected for security and proof of delivery.

Correspondence data.

Examples: The content of your letters to us and attachments you send with Refund requests or complaints.

Collection source: Directly from you.

Is it required?: Optional generally, but required when necessary to process your request.

Payment Data

We don’t collect or store on our servers any complete data on payment cards, such as the full card number, expiry date or verification code.

Payment Data is processed entirely by the Approved Payment Service Provider in an environment that complies with applicable payment-card security standards, including PCI DSS where applicable. We receive only the transaction result and limited identifying data that cannot be used to make a payment.

We don’t collect data of a sensitive nature, such as health, belief, race or criminal record data, and we don’t ask you to provide it, and we ask you not to include any such data in your correspondence with us.

3. Processing purposes and legal bases.

We process your data only for a specific and legitimate purpose, with a clear legal basis, as follows:

Order fulfilment and delivery of and access to Digital Product.

Data used: Definition, communication, order.

Legal basis for processing: Performance of the contract between you and Company.

Issuance of Licence and registration of Company or Authorized Project.

Data used: Definition, authorization.

Legal basis for processing: Performance of the contract and protection of legitimate interest in controlling the scope of use.

Order fulfilment and processing of payments and Refund.

Data used: Request, transaction data.

Legal basis for processing: Contract implementation and adherence to payment system rules.

Order verification, anti-fraud and protection of Platform.

Data used: Technical use, request.

Legal basis for processing: The legitimate interest of the company in the protection of its systems and rights.

Proof of delivery and defence of company against disputes and bank objections.

Data used: Request, technical use.

Legal basis for processing: Legitimate interest and exercise of the right to defence.

Answer your questions, complaints, and Refund requests.

Data used: Communication, correspondence.

Legal basis for processing: Performance of the contract and respond to your request.

Maintenance of accounting, tax and system records.

Data used: Request, transaction data.

Legal basis for processing: Obligation under law.

Sending marketing letters and offers about our products.

Data used: Communication.

Legal basis for processing: Your express, separate and optional consent, which is not a condition for the completion of the purchase, and you withdraw it at any time through a clear means of unsubscribing.

We will not process your data for any new purpose that is fundamentally different from those mentioned above until you have been notified and given your consent when necessary.

4. What we don’t do with your data.

  • We don’t sell your personal data to anyone, in any way, for any purpose.
  • We don’t rent your data, we don’t trade it, we don’t share it with data intermediaries.
  • We don’t share your data with third parties for their own marketing purposes.
  • We don’t make solely automated decisions about you that produce legal effect on you without human intervention.
  • We don’t use your data to create behavioural profiles that are directed to external advertising without your consent.

5. Those with whom data may be shared.

We may share a minimum of your data with the following, and to the extent necessary only for the purpose:

Approved Payment Service Provider.

Data shared: Request and payment data required for the operation.

Purpose: Payment processing, Refund, dispute resolution and bank objections.

Hosting providers and technical structure of the platform.

Data shared: Data stored on the Platform.

Purpose: Operation of the store, data storage and security.

E-mail service provider and system messages.

Data shared: Name and e-mail.

Purpose: Order notifications and access for Buyers via My Purchases and Responses.

Our legal advisers and our auditors.

Data shared: Request and correspondence statements as required.

Purpose: Defending the rights of the company or fulfilling a professional obligation, and a subject to strict confidentiality obligations.

Competent judicial and oversight bodies.

Data shared: Only what is officially requested.

Purpose: Response to an lawful official order or request.

We commit each service provider with whom we deal, under a written agreement, to maintain confidentiality of data, not to use it for the agreed purpose, and to apply appropriate protective measures.

6. Data transfer outside Kingdom of Bahrain.

Some of your data may be stored or processed on servers located outside the Kingdom of Bahrain by the nature of cloud services. In this case, we are obliged to transfer only to a State that provides adequate protection of personal data, or after obtaining the necessary authorization from the competent authority, or based on one of the legally prescribed exceptions such as the need for the transfer to perform the contract with you or to obtain your express consent.

7. Duration of data retention.

Account, identification and contact data.

Retention period: For as long as the account, access or Licence remains active, and thereafter only for any period required by law or reasonably necessary to protect legitimate rights.

Action after the retention period: Delete or anonymise after need and statutory duration, unless some need to be retained to establish rights.

Requests, transactions, delivery records and disputes.

Retention period: Delivery and dispute records are retained for at least two (2) years. Accounting and tax records are retained for the statutory period applicable to the Company’s registration status and the requirements in force from time to time.

Action after the retention period: Delete or anonymise after expiry of the period, unless there is a legal obligation or a dispute to retain.

Licensing data and name of company or project licensed.

Retention period: For as long as the relevant Licence remains active, and thereafter for any period required by law or necessary to establish rights connected with that Licence.

Action after the retention period: Deleted or anonymised, with the Licence record maintained where necessary to establish rights.

Correspondence, Refund requests and complaints.

Retention period: At least 2 years from the date of closure of the application, or a longer period if a dispute or statutory obligation arises.

Action after the retention period: Permanently delete.

Marketing list data.

Retention period: Until your consent is withdrawn, or five years after the last interaction, whichever is closer.

Action after the retention period: Deleted from the list immediately.

If a dispute, legal claim or official investigation arises, we shall keep the relevant data until the end of the dispute and a final decision thereon, even if it exceeds the above-mentioned periods.

8. Your rights to your data.

Subject to applicable law and identity verification, you may request access to the Personal Data we process about you and receive it in a readable format; request correction, blocking or erasure where the legal conditions are met; object to certain processing and direct marketing; withdraw consent; request data portability where applicable and technically feasible; and lodge a complaint with the competent authority.

Requests are submitted through support@growth-gcc.com, and we will respond to them during the applicable statutory periods, including ten (10) working days for requests for correction, blocking or erasure when the conditions are met. We may request proof of your identity and explain the reasons for any total or partial rejection.

9. Security measures.

Depending on the nature of the data, the level of risks, possibilities and characteristics available in the systems we use, we shall apply appropriate technical and regulatory measures to protect your data from unauthorized loss, destruction, access or disclosure, including, where appropriate and available:

  • The connection encryption of Platform through a secure protocol, and the encryption of sensitive data during preservation wherever possible.
  • Restricting access to data to the minimum number of workers who need it to perform their functions.
  • Use strong passwords and activate verification by two steps on administrative systems where the feature is available.
  • Periodic data backups and refund testing, to the extent appropriate to the nature of the system.
  • Periodic updating of systems, software, firewalls and malware control programs.
  • Reliance on a certified payment service provider that applies the security standards of the card industry, so that we do not store full card data on our servers.

However, no electronic system can guarantee absolute safety, so we would advise you to keep your access data confidential and not share it with anyone.

10. Dealing with data breach.

In the event of a breach affecting your personal data, we commit ourselves to the following actions:

  • Contain the breach immediately and assess its scope and potential impact on data holders.
  • Notify the competent regulatory authority of the Kingdom of Bahrain without undue delay and within the period of time prescribed by law and executive decisions in force, when the notification is due.
  • Notify you directly and without undue delay if the breach carries a high risk to your rights, indicating the nature of the breach, the affected data, the actions taken and the preventive recommendations.
  • Document the incident, its causes and corrective actions, and review controls to prevent recurrence.

11. Cookies.

The Platform uses necessary Cookies to maintain login sessions, preserve shopping-cart contents and remember language preferences. These Cookies cannot be disabled without affecting the service. We may also use analytics Cookies to measure Platform performance and improve user experience; where consent is required, such Cookies are activated only with your consent.

12. The privacy of minors.

If we find out that we have collected data on a minor, we should immediately delete it and cancel the associated account. If you are a parent or guardian and believe that a minor has provided us with his data, please write to us to take the necessary action.

13. External links and websites.

Platform or its materials may contain links to sites or services managed by others. These sites are not subject to this policy, and the company has no responsibility for its data collection or use practices.

14. Policy Amendment.

We may update this policy from time to time to keep abreast of changes in our services or in statutory requirements. The amended text is posted on the Platform with an update of the date of the last update of this document. If the amendment is material and affects the scope of your data processing, we have notified you of it via your registered e-mails well in advance of its entry into force.

15. Governing Law and Jurisdiction.

This policy and any disputes arising therefrom are governed by the laws of the Kingdom of Bahrain and the jurisdiction of the competent courts of the Kingdom of Bahrain have exclusive jurisdiction without prejudice to your right to appeal to the supervisory body competent to protect the personal data.

Final Notes

  • To exercise any of your rights or to enquire about this policy, email us at support@growth-gcc.com with a clear statement of your request and the order number if any.
  • The Arabic text of this Policy is the authoritative version and prevails in the event of any inconsistency with a translation.
  • If any of these policy items are declared invalid, the remaining provisions remain valid and enforceable.
  • By purchasing through the Platform, you agree to these policies.
الرئيسيةالسياسات
Growth Partners Consultancy W.L.L

سياسة الخصوصية وحماية البيانات

متجر Growth الرقمي للدورات والقوالب

بيانات الوثيقة
رقم المستند
GPC-POL-02
الإصدار
1.2
تاريخ آخر تحديث
30 أغسطس 2026
تاريخ النفاذ
23 أغسطس 2026
المتحكم في البيانات
شركة جروث بارتنرز للاستشارات ذ.م.م (Growth Partners Consultancy W.L.L)، سجل تجاري رقم 197615-1، مملكة البحرين
البريد الإلكتروني للخصوصية وحماية البيانات
support@growth-gcc.com

إقرار وموافقة

بالشراء من المنصة، أنت توافق على هذه السياسات.

تُوضّح هذه السياسة أي بيانات نجمعها عنك، ولماذا نجمعها، وكيف نحميها، وما هي حقوقك تجاهها، وكيف تمارسها.

أولًا: نطاق السياسة

تسري هذه السياسة على كل بيانات شخصية تجمعها شركة جروث بارتنرز للاستشارات ذ.م.م (Growth Partners Consultancy W.L.L) أو تعالجها من خلال متجرها الإلكتروني وقنوات التواصل المرتبطة به. وتُصاغ هذه السياسة استرشادًا بأحكام قانون حماية البيانات الشخصية في مملكة البحرين الصادر بالقانون رقم (30) لسنة 2018 وقراراته التنفيذية، وبأفضل الممارسات المتعارف عليها في دول مجلس التعاون لدول الخليج العربية.

الشركة هي «المتحكم في البيانات» بالنسبة للبيانات المشار إليها في هذه السياسة، وهي الجهة التي تحدد أغراض المعالجة ووسائلها وتتحمل المسؤولية عنها.

ثانيًا: البيانات التي نجمعها

نلتزم بمبدأ الحد الأدنى، فلا نجمع إلا ما نحتاجه فعلًا لتنفيذ الخدمة. والبيانات التي نجمعها هي:

بيانات التعريف

الأمثلة: الاسم الكامل

مصدر الجمع: منك مباشرة عند التسجيل أو الشراء

هل تقديمها إلزامي؟: نعم، لإتمام الطلب وإصدار الرخصة

بيانات التواصل

الأمثلة: البريد الإلكتروني، رقم الهاتف

مصدر الجمع: منك مباشرة

هل تقديمها إلزامي؟: نعم، لتسليم المنتج والتواصل بشأن الطلب

بيانات الترخيص

الأمثلة: اسم الشركة أو المشروع المراد ترخيص القالب له

مصدر الجمع: منك مباشرة عند الشراء

هل تقديمها إلزامي؟: نعم بالنسبة للقوالب، لأنها أساس تحديد نطاق الرخصة

بيانات الطلب والمعاملة

الأمثلة: رقم الطلب، اسم المنتج، قيمة العملية، تاريخها ووقتها، حالة الدفع، آخر أربعة أرقام من البطاقة ونوعها متى زُوّدنا بها من بوابة الدفع

مصدر الجمع: من بوابة الدفع ومن نظام المتجر

هل تقديمها إلزامي؟: تُنشأ تلقائيًا بإتمام العملية

بيانات الاستخدام التقنية

الأمثلة: عنوان بروتوكول الإنترنت، نوع المتصفح والجهاز، أوقات الدخول، سجل التحميلات ومحاولاتها، سجل مشاهدة الدورة

مصدر الجمع: تلقائيًا عند استخدامك للمنصة

هل تقديمها إلزامي؟: تُجمع تلقائيًا لأغراض الأمن وإثبات التسليم

بيانات المراسلات

الأمثلة: محتوى رسائلك إلينا والمرفقات التي ترسلها مع طلبات الاسترداد أو الشكاوى

مصدر الجمع: منك مباشرة

هل تقديمها إلزامي؟: اختياري، ويلزم لمعالجة طلبك

بيانات الدفع

لا نجمع ولا نخزّن على خوادمنا أي بيانات كاملة لبطاقات الدفع، مثل رقم البطاقة الكامل أو تاريخ انتهائها أو رمز التحقق.

تُعالَج بيانات الدفع بالكامل لدى مزوّد خدمة الدفع المعتمد في بيئة تلتزم بمعايير أمن بيانات صناعة بطاقات الدفع المعمول بها، بما في ذلك معيار أمن بيانات صناعة بطاقات الدفع (PCI DSS) متى كان منطبقًا، ولا يصلنا منها سوى نتيجة العملية وبيانات تعريفية محدودة لا تكفي لإجراء عملية دفع.

لا نجمع بيانات ذات طبيعة حساسة، كالبيانات الصحية أو العقائدية أو العرقية أو المتعلقة بالسجل الجنائي، ولا نطلب منك تزويدنا بها. ونرجو منك عدم إدراج أي بيانات من هذا النوع في مراسلاتك معنا.

ثالثًا: أغراض المعالجة وأسسها المشروعة

لا نعالج بياناتك إلا لغرض محدد ومشروع، ووفق أساس قانوني واضح، على النحو التالي:

تنفيذ الطلب وتسليم المنتج الرقمي وإتاحة الوصول إليه

البيانات المستخدمة: التعريف، التواصل، الطلب

الأساس المشروع للمعالجة: تنفيذ العقد المبرم بينك وبين الشركة

إصدار الرخصة وتسجيل الشركة أو المشروع المرخص له

البيانات المستخدمة: التعريف، الترخيص

الأساس المشروع للمعالجة: تنفيذ العقد وحماية المصلحة المشروعة في ضبط نطاق الاستخدام

تحصيل قيمة الطلب ومعالجة المدفوعات والاسترداد

البيانات المستخدمة: الطلب، بيانات المعاملة

الأساس المشروع للمعالجة: تنفيذ العقد والالتزام بقواعد شبكات الدفع

التحقق من الطلبات ومكافحة الاحتيال وحماية المنصة

البيانات المستخدمة: الاستخدام التقنية، الطلب

الأساس المشروع للمعالجة: المصلحة المشروعة للشركة في حماية أنظمتها وحقوقها

إثبات التسليم والدفاع عن الشركة أمام النزاعات والاعتراضات البنكية

البيانات المستخدمة: الطلب، الاستخدام التقنية

الأساس المشروع للمعالجة: المصلحة المشروعة وممارسة الحق في الدفاع

الرد على استفساراتك وشكاواك وطلبات الاسترداد

البيانات المستخدمة: التواصل، المراسلات

الأساس المشروع للمعالجة: تنفيذ العقد والاستجابة لطلبك

الاحتفاظ بالسجلات المحاسبية والضريبية والنظامية

البيانات المستخدمة: الطلب، بيانات المعاملة

الأساس المشروع للمعالجة: الالتزام بموجب قانوني

إرسال رسائل تسويقية وعروض عن منتجاتنا

البيانات المستخدمة: التواصل

الأساس المشروع للمعالجة: موافقتك الصريحة والمنفصلة والاختيارية، وهي ليست شرطًا لإتمام الشراء، ولك سحبها في أي وقت من خلال وسيلة واضحة لإلغاء الاشتراك

لن نعالج بياناتك لأي غرض جديد يختلف جوهريًا عن الأغراض المذكورة أعلاه إلا بعد إخطارك والحصول على موافقتك متى كانت لازمة.

رابعًا: ما لا نفعله ببياناتك

  • لا نبيع بياناتك الشخصية لأي جهة، بأي صورة، ولأي غرض.
  • لا نؤجّر بياناتك ولا نتاجر بها ولا نشاركها مع وسطاء بيانات.
  • لا نشارك بياناتك مع أطراف ثالثة لأغراضهم التسويقية الخاصة.
  • لا نتخذ بشأنك قرارات آلية بحتة تُنتج أثرًا قانونيًا عليك دون تدخل بشري.
  • لا نستخدم بياناتك لإنشاء ملفات تعريف سلوكية توجَّه إلى جهات إعلانية خارجية دون موافقتك.

خامسًا: الجهات التي قد تُشارَك معها البيانات

قد نشارك حدًا أدنى من بياناتك مع الجهات التالية، وبقدر ما يلزم للغرض فقط:

مزوّد خدمة الدفع المعتمد

البيانات المشارَكة: بيانات الطلب وبيانات الدفع اللازمة لتنفيذ العملية

الغرض: معالجة الدفع والاسترداد وتسوية النزاعات والاعتراضات البنكية

مزوّدو الاستضافة والبنية التقنية للمنصة

البيانات المشارَكة: البيانات المخزّنة على المنصة

الغرض: تشغيل المتجر وحفظ البيانات وتأمينها

مزوّد خدمة البريد الإلكتروني ورسائل النظام

البيانات المشارَكة: الاسم والبريد الإلكتروني

الغرض: إرسال إشعارات الطلب وإتاحة المشتريات والوصول إليها عبر My Purchases والردود

مستشارونا القانونيون ومدققونا

البيانات المشارَكة: ما يلزم من بيانات الطلب والمراسلات

الغرض: الدفاع عن حقوق الشركة أو الوفاء بالتزام مهني، وبالتزام كامل بالسرية

الجهات القضائية والرقابية المختصة

البيانات المشارَكة: ما يُطلب رسميًا فقط

الغرض: الاستجابة لأمر أو طلب رسمي صادر وفق القانون

نلزم كل مزوّد خدمة نتعامل معه، بموجب اتفاق مكتوب، بالمحافظة على سرية البيانات، وبعدم استخدامها لغير الغرض المتفق عليه، وبتطبيق تدابير حماية مناسبة.

سادسًا: نقل البيانات خارج مملكة البحرين

قد تُخزَّن بعض بياناتك أو تُعالَج على خوادم تقع خارج مملكة البحرين بحكم طبيعة الخدمات السحابية. وفي هذه الحالة نلتزم بألا يتم النقل إلا إلى دولة توفر حماية كافية للبيانات الشخصية، أو بعد الحصول على التصريح اللازم من الجهة المختصة، أو استنادًا إلى أحد الاستثناءات المقررة قانونًا مثل ضرورة النقل لتنفيذ العقد المبرم معك أو الحصول على موافقتك الصريحة. ونحرص في كل الأحوال على إبرام ضمانات تعاقدية مناسبة مع الجهة المستقبِلة.

سابعًا: مدة الاحتفاظ بالبيانات

بيانات الحساب والتعريف والتواصل

مدة الاحتفاظ: طوال بقاء الحساب أو الوصول إلى المشتريات أو الرخصة قائمًا، وبعد انتهائها للمدة اللازمة نظامًا أو لحماية الحقوق المشروعة

ما يحدث بعد انقضاء المدة: تُحذف أو تُجهَّل بعد انتهاء الحاجة والمدة النظامية، ما لم يلزم الاحتفاظ ببعضها لإثبات الحقوق

بيانات الطلبات والمعاملات وسجلات التسليم والنزاعات

مدة الاحتفاظ: سنتان (2) على الأقل لسجلات التسليم والنزاعات، وتُحفظ السجلات المحاسبية والضريبية للمدة النظامية الواجبة بحسب حالة التسجيل والمتطلبات النافذة من وقت لآخر

ما يحدث بعد انقضاء المدة: تُحذف أو تُجهَّل بعد انقضاء المدة، ما لم يوجد التزام قانوني أو نزاع يوجب الاحتفاظ بها

بيانات الترخيص واسم الشركة أو المشروع المرخص له

مدة الاحتفاظ: طوال سريان الرخصة، وبعد انتهائها للمدة اللازمة نظامًا أو لإثبات الحقوق المرتبطة بها

ما يحدث بعد انقضاء المدة: تُحذف أو تُجهَّل، مع الاحتفاظ بسجل الرخصة عند اللزوم لإثبات الحقوق

المراسلات وطلبات الاسترداد والشكاوى

مدة الاحتفاظ: سنتان (2) على الأقل من تاريخ إغلاق الطلب، أو مدة أطول إذا نشأ نزاع أو التزام نظامي

ما يحدث بعد انقضاء المدة: تُحذف نهائيًا

بيانات القوائم التسويقية

مدة الاحتفاظ: حتى سحب موافقتك، أو انقضاء خمس (5) سنوات من آخر تفاعل، أيهما أقرب

ما يحدث بعد انقضاء المدة: تُحذف من القائمة فورًا

إذا نشأ نزاع أو مطالبة قانونية أو تحقيق رسمي، احتفظنا بالبيانات ذات الصلة إلى حين انتهاء النزاع وصدور قرار نهائي فيه، ولو تجاوز ذلك المدد المذكورة أعلاه.

ثامنًا: حقوقك تجاه بياناتك

لك، وفقًا للقانون وبعد التحقق من هويتك، طلب معرفة البيانات الشخصية التي نعالجها عنك والحصول عليها بصيغة مقروءة، وتصحيحها أو حجبها أو مسحها متى توافرت الشروط القانونية، والاعتراض على بعض أوجه المعالجة والتسويق المباشر، وسحب موافقتك، وطلب نقل بياناتك متى كان ذلك ضروريًا وممكنًا تقنيًا، والتظلم لدى الجهة المختصة.

تُقدَّم الطلبات عبر support@growth-gcc.com، ونستجيب لها خلال المدد النظامية، ومنها عشرة (10) أيام عمل لطلبات التصحيح أو الحجب أو المسح متى توافرت شروطها. وقد نطلب ما يثبت هويتك، ونوضح لك أسباب أي رفض كلي أو جزئي.

تاسعًا: التدابير الأمنية

نطبّق، بحسب طبيعة البيانات ومستوى المخاطر والإمكانات والخصائص المتاحة في الأنظمة التي نستخدمها، تدابير فنية وتنظيمية مناسبة لحماية بياناتك من الفقد أو الإتلاف أو الوصول أو الإفصاح غير المصرح به، ومنها، متى كان ذلك مناسبًا ومتاحًا:

  • تشفير الاتصال بالمنصة عبر بروتوكول آمن، وتشفير البيانات الحساسة أثناء الحفظ حيثما أمكن.
  • تقييد صلاحيات الوصول إلى البيانات على العدد الأدنى من العاملين الذين يحتاجونها لأداء مهامهم.
  • استخدام كلمات مرور قوية وتفعيل التحقق بخطوتين على الأنظمة الإدارية متى كانت الخاصية متاحة.
  • إجراء نسخ احتياطي دوري للبيانات وفحص إمكانية استعادتها بالقدر المناسب لطبيعة النظام.
  • التحديث الدوري للأنظمة والبرمجيات وجدران الحماية وبرامج مكافحة البرمجيات الخبيثة.
  • الاعتماد على مزوّد خدمة دفع معتمد يطبّق معايير أمن صناعة بطاقات الدفع، بحيث لا نخزّن بيانات البطاقات الكاملة على خوادمنا.

ومع ذلك، لا يمكن لأي نظام إلكتروني أن يضمن أمانًا مطلقًا، ولذلك ننصحك بالمحافظة على سرية بيانات دخولك وعدم مشاركتها مع أحد.

عاشرًا: التعامل مع خرق البيانات

في حال وقوع خرق يمس بياناتك الشخصية، نلتزم باتخاذ الإجراءات التالية:

  • احتواء الخرق فورًا وتقييم نطاقه وأثره المحتمل على أصحاب البيانات.
  • إخطار الجهة الرقابية المختصة في مملكة البحرين دون تأخير غير مبرر وخلال المدة التي يحددها القانون والقرارات التنفيذية النافذة، متى كان الإخطار واجبًا.
  • إخطارك مباشرةً ودون تأخير غير مبرر إذا كان الخرق ينطوي على مخاطر عالية على حقوقك، مع بيان طبيعة الخرق والبيانات المتأثرة والإجراءات المتخذة والتوصيات الوقائية.
  • توثيق الحادثة وأسبابها والإجراءات التصحيحية، ومراجعة الضوابط لمنع تكرارها.

حادي عشر: ملفات الارتباط (Cookies)

تستخدم المنصة ملفات ارتباط ضرورية لتشغيلها، مثل حفظ جلسة الدخول ومحتويات سلة الشراء وضبط تفضيلات اللغة، ولا يمكن تعطيلها دون تعطّل الخدمة. وقد نستخدم ملفات ارتباط تحليلية لقياس أداء المنصة وتحسين تجربة الاستخدام، ولا تُفعّل هذه الملفات إلا بموافقتك متى كانت الموافقة لازمة. ولك في جميع الأحوال التحكم في ملفات الارتباط من إعدادات متصفحك أو حذفها، مع ملاحظة أن تعطيل الملفات الضرورية قد يمنعك من إتمام الشراء أو الوصول إلى مشترياتك.

ثاني عشر: خصوصية القاصرين

المنصة مخصصة لمن أتم ثمانية عشر (18) عامًا من العمر. ولا نجمع عن علم أي بيانات شخصية تخص من هم دون هذه السن. وإذا تبيّن لنا أننا جمعنا بيانات تخص قاصرًا، بادرنا بحذفها فورًا وإلغاء الحساب المرتبط بها. وإذا كنت وليًا أو وصيًا وتعتقد أن قاصرًا زوّدنا ببياناته، فيرجى مراسلتنا لاتخاذ اللازم.

ثالث عشر: الروابط والمواقع الخارجية

قد تحتوي المنصة أو موادها على روابط لمواقع أو خدمات تديرها جهات أخرى. ولا تخضع تلك المواقع لهذه السياسة، ولا تتحمل الشركة أي مسؤولية عن ممارساتها في جمع البيانات أو استخدامها. وننصحك بمراجعة سياسة الخصوصية الخاصة بكل موقع تزوره.

رابع عشر: تعديل السياسة

قد نحدّث هذه السياسة من وقت لآخر لمواكبة التغيرات في خدماتنا أو في المتطلبات النظامية. ويُنشر النص المعدّل على المنصة مع تحديث تاريخ آخر تحديث المدوّن أعلاه. وإذا كان التعديل جوهريًا ويمس نطاق معالجة بياناتك، أخطرناك به عبر البريد الإلكتروني المسجل لديك قبل نفاذه بمدة معقولة.

خامس عشر: القانون الحاكم والاختصاص القضائي

تخضع هذه السياسة وكل ما ينشأ عنها من نزاعات لقوانين مملكة البحرين، وينعقد الاختصاص بنظرها للمحاكم المختصة في مملكة البحرين دون سواها، وذلك دون إخلال بحقك في التظلم أمام الجهة الرقابية المختصة بحماية البيانات الشخصية.

ملاحظات ختامية

  • لممارسة أي من حقوقك أو للاستفسار عن هذه السياسة، راسلنا على support@growth-gcc.com مع بيان طلبك بوضوح ورقم الطلب إن وُجد.
  • النص العربي لهذه السياسة هو النص المعتمد، ويُرجَّح عند الاختلاف مع أي ترجمة.
  • إذا قُضي ببطلان أي بند من بنود هذه السياسة، بقيت بقية البنود صحيحة ونافذة.
  • بالشراء من المنصة، أنت توافق على هذه السياسات.
E-mail
Password
Confirm Password