Data Protection Policy
Marvel Technology’s organisational commitments for protecting personal data across Sukna.
Purpose
Marvel Technology and Information Systems WLL, operator of Sukna (Marvel, Sukna, we, us or our), is committed to protecting personal data across the Sukna website, mobile application, web dashboard, support operations and corporate activities.
This Policy states the governance and minimum controls we apply throughout the data lifecycle. It supports compliance with Bahrain's Law No. 30 of 2018 Promulgating the Personal Data Protection Law (PDPL) and its executive orders. It is supplemented by the Sukna Privacy Policy, customer and vendor data-processing agreements, security standards, retention schedule, incident-response plan and internal procedures.
1. Scope
This Policy applies to:
- all Marvel directors, officers, employees, temporary workers and contractors;
- all personal data for which Marvel is a data controller;
- all personal data processed by Marvel for a Community Customer;
- all environments, devices, databases, backups, logs and paper records used for Sukna; and
- all vendors and subprocessors with access to personal data.
A Community Customer is an owners association, developer, property manager or other subscribing organisation responsible for a property or community. A data subject is an identifiable individual, including a resident, owner, tenant, family member, authorised representative, visitor, prospect, staff member or supplier contact.
2. Accountability and legal roles
2.1 Marvel as controller
Marvel is a data controller for purposes it determines, including Sukna account administration, platform security, direct support, website enquiries, cookie choices, optional marketing, product administration and its own legal/business records.
2.2 Marvel as processor
A Community Customer is normally the controller of community records, including resident/unit relationships, identity verification required for access, service requests, notices, documents, invoices, violations, visitor/access records and owners-association governance. Marvel processes those records only on documented instructions and under a written data-processing agreement.
Marvel will notify the Community Customer if an instruction appears to violate applicable data-protection law and may suspend the affected processing while the issue is resolved. Marvel will not sell, independently advertise against or otherwise reuse identifiable Community Customer data for its own unrelated purposes.
2.3 Responsibility
- Management approves this Policy, provides adequate resources and accepts residual high risks.
- Privacy lead maintains the processing register, advice, rights-request process, DPIAs, transfer and vendor records, incident privacy assessment and regulatory coordination. Appointment of a statutory Data Protection Guardian will be notified where required.
- Security and engineering leads implement privacy by design, secure development, access control, logging, testing, resilience and deletion.
- Product owners document the purpose, fields, legal basis, notices, roles, recipients, retention and user controls before a feature is approved.
- Customer/support teams follow verified identity, minimum-access and escalation procedures.
- All personnel protect confidentiality, use data only for authorised work and report incidents immediately. Confidentiality continues after employment or engagement ends.
3. Data-protection principles
Sukna applies the following principles:
- Lawfulness and fairness: every activity must have a documented legal basis and must not use data in an unexpected or unjustifiably harmful way.
- Purpose limitation: personal data is collected for specific, explicit and legitimate purposes and is not reused incompatibly.
- Data minimisation: each field, attachment and permission must be necessary and proportionate.
- Accuracy: reasonable processes allow users and authorised Community Customers to correct records.
- Storage limitation: each record category has a documented period and deletion/anonymisation action.
- Security and confidentiality: safeguards reflect data sensitivity, volume, context, available technology and potential harm.
- Transparency and choice: notices are concise, accessible and delivered when data is collected or first recorded.
- Accountability: decisions, assessments, contracts, consent, access and incidents are documented so compliance can be demonstrated.
4. Lawful processing and consent
Before collection begins, the responsible owner must document the purpose, controller, data categories, individuals, legal basis, mandatory/optional status, recipients, transfer mechanism and retention period.
Depending on the purpose, processing may rely on explicit consent, contract or pre-contract steps, legal obligation, recognised legal proceedings, vital interests or a legitimate interest that does not override individual rights.
Consent must be:
- an affirmative, written or electronic action;
- specific to a clear purpose;
- informed, unambiguous and recorded;
- freely given, without making an optional use a condition of an unrelated service; and
- as easy to withdraw as to give, without fee or liability.
Terms acceptance, operational communications and marketing consent are separate choices. Non-essential cookies, SDKs and third-party embeds are not loaded before valid consent. A person who rejects them can continue to use unrelated content and core functions.
Sensitive personal data may be processed only under an applicable statutory exception and enhanced controls. Criminal-record data, if ever required, is not processed without specific legal review.
5. Data classification and handling
Sukna uses the following minimum classification.
Data is classified according to the highest-risk element in a record. Downloading Restricted or Confidential data to unmanaged devices, personal email, personal messaging accounts or unapproved storage is prohibited.
6. Collection and privacy by design
6.1 Product approval
A new or materially changed feature cannot process personal data until its data-design record is approved. The record must cover:
- user and business purpose;
- fields and permissions, including why each is necessary;
- controller/processor roles and customer configuration;
- lawful basis and point-of-collection notice;
- access roles and audit events;
- vendors, SDKs, countries and contracts;
- retention, deletion and backup behaviour;
- rights-request support; and
- security and abuse cases.
Default settings must be privacy protective. Optional fields and sharing are off by default unless the user or authorised Community Customer chooses them.
6.2 Data protection impact assessment
A DPIA must be completed before high-risk processing, including:
- systematic or large-scale sensitive-data processing;
- central facial recognition or other biometric identification;
- large-scale monitoring of publicly accessible areas;
- extensive automated evaluation or profiling with significant effects;
- linking identifiable files from unrelated controllers for different purposes;
- identity-document processing at material scale;
- resident scoring, violations or other processing likely to cause material harm; or
- a new technology or use that materially changes reasonable expectations.
The DPIA describes necessity, proportionality, risks, safeguards, consultation, residual risk and approvals. Processing that needs PDPA notification or prior authorisation will not begin until that step is complete.
7. Special Sukna controls
7.1 Identity documents
- The Community Customer must document why identity verification is necessary and what evidence is proportionate.
- Where a lower-risk method is sufficient, Sukna will avoid collecting a full document image.
- The image is separated from ordinary profile views and made accessible only to authorised verification roles.
- Every view, change, export and deletion of an identity document is logged.
- By default, the image is deleted once verification is final and no later than 30 days afterwards. A longer period requires documented customer instruction, lawful basis and expiry date.
- Verified attributes are limited to those needed for account/community eligibility.
- Demo, training and public documentation must use synthetic identity data.
7.2 Device biometrics
Sukna's approved architecture uses the device operating system for Face ID/fingerprint matching and receives only an authentication result. Sukna does not receive a raw face/fingerprint or template. Any proposal to change this architecture requires a DPIA, explicit privacy review, enhanced security and any required prior authorisation before development data is collected.
7.3 Owners-association meetings and voting
- The Community Customer configures eligibility, entitlement, notice, quorum, proxy and ballot rules and remains responsible for their legality.
- Sukna records the system events needed to evidence participation and result integrity.
- Administrative access to ballots and audit events is restricted and logged.
- Secret-ballot choices are not exposed to the Community Customer or other users unless the configured legal process requires and authorises access.
- Test ballots and production ballots are separated.
- A correction never silently overwrites the original governance event; the audit trail records the authorised change and reason.
- Sukna does not certify that a meeting, vote or resolution is legally valid.
7.4 Invoices and payments
- The Community Customer is responsible for the invoice, amount and entitlement to collect it.
- Complete card number and CVV collection is handled by an approved payment provider, not stored by Sukna.
- Sukna retains limited transaction, status and reconciliation data and restricts access by finance role.
- Payment pages identify the collecting entity/provider, amount, currency and confirmation route.
- Refunds, chargebacks and disputes follow documented customer/provider procedures.
7.5 Violations, complaints and service content
Violations and complaints may affect a person's reputation or community rights. They are visible only to roles with an operational need, must identify the source/status where appropriate, and must support correction, response and escalation. Service-request attachments are not reused for demonstrations, training or marketing without separate authority.
8. Access management
Access is based on least privilege, community boundary, job role and current need.
- Unique user IDs are mandatory; shared administrative accounts are prohibited except for controlled technical accounts.
- Privileged access requires strong authentication and is reviewed at least quarterly.
- Joiner, mover and leaver events trigger prompt access changes.
- Community Customer administrators may grant only documented roles within their community.
- Production access by support/engineering requires an approved support or incident purpose and is logged.
- Access to identity images, violations, invoices, voting records and exports receives enhanced monitoring.
- Inactive accounts and credentials are disabled under the applicable access standard.
9. Security and resilience
Sukna maintains a risk-based information-security programme that includes:
- secure configuration and change management;
- encryption in transit and appropriate encryption at rest with controlled keys;
- strong authentication, password protection and secret management;
- application, network, endpoint and malware protections;
- input validation, dependency management and secure development review;
- central security/audit logging protected against unauthorised alteration;
- vulnerability scanning and independent penetration testing at least annually and after material high-risk changes;
- encrypted, access-controlled backups and tested restoration;
- business-continuity and disaster-recovery plans;
- vendor security due diligence and contractual controls; and
- secure deletion or irreversible anonymisation at end of retention.
Security testing and monitoring are performed in a way that minimises live personal data. Production data is not copied to development or test environments unless strictly necessary, approved and protected to an equivalent standard; synthetic data is the default.
10. Vendors and Community Customers
Before a vendor processes personal data, Sukna assesses its capability, security, countries, subprocessors and breach/rights support. The written contract must cover:
- documented instructions and purpose limits;
- confidentiality and personnel controls;
- technical and organisational safeguards;
- subprocessor approval and equivalent obligations;
- overseas-transfer requirements;
- prompt incident notice and cooperation;
- assistance with rights, DPIAs and regulators;
- return/deletion at end of service; and
- evidence, audit and remediation rights proportionate to risk.
The Community Customer DPA contains equivalent terms and clearly allocates the controller's legal duties and Marvel's processor assistance. Sukna maintains an approved vendor and subprocessor register.
11. Disclosures and international transfers
Personal data is disclosed only to authorised recipients for a documented purpose and minimum scope. Requests from authorities are verified, recorded and reviewed for legal basis and proportionality unless law prohibits notice or review.
Before data leaves Bahrain, Sukna records the data, exporter, importer, countries, purpose, onward transfers and legal mechanism. Direct transfer may be made to a destination recognised by the Bahrain PDPA as adequate. Other transfers require applicable prior authorisation or a statutory exception plus the necessary contract and safeguards. Transfer status is reassessed when a vendor, country or law changes.
12. Accuracy, retention and deletion
Product owners and Community Customers must provide a way to correct data and define the authoritative source for key identity, unit, invoice and voting fields. Material corrections are logged.
Sukna maintains a record-level retention schedule aligned with the public Privacy Policy. Every period has a trigger, owner, legal/business justification, disposal action and exception process. Indefinite retention is prohibited.
Legal holds are documented, limited to relevant records and reviewed at least every six months. When a hold ends, the ordinary schedule resumes. Deletion must cover active copies, search indexes and exports under Sukna's control; protected backups expire on the documented overwrite cycle and are not restored to ordinary use.
Aggregated information may be kept longer only if it has been tested so that an individual cannot reasonably be re-identified. Pseudonymisation alone is not anonymisation.
13. Individual rights
Sukna provides a monitored electronic route for access, correction, blocking, erasure, objection, consent withdrawal, marketing opt-out and automated-decision requests.
The privacy team will:
- log the request and identify the relevant controller;
- verify identity using proportionate information and avoid requesting a new ID image where a safer method works;
- acknowledge and route Community Customer requests promptly;
- search all relevant systems and vendors;
- apply legal exceptions narrowly and record the reason;
- respond within the applicable Bahrain period-normally 15 working days for access and 10 working days for valid correction, blocking, erasure or direct-marketing objection; and
- propagate an accepted correction, blocking or erasure to relevant recipients as required.
No person is penalised for making a privacy request. Ordinary requests are handled free of charge unless Bahrain law permits otherwise.
14. Direct marketing and operational messages
Operational notices necessary for security, invoices, service requests, meetings or community administration are distinguished from promotions. Sukna marketing requires the appropriate consent and always includes a simple opt-out. An opt-out is applied across the relevant channel without unnecessary delay and within the legal deadline. Suppression data is retained only to honour the choice.
Community Customers may not use Sukna data for unrelated marketing unless they independently establish and document a lawful basis and provide the required notice and choice.
15. Personal-data incidents
Anyone who suspects loss, unauthorised access, disclosure, alteration, unavailability or improper processing must immediately report it through Sukna's incident channel. Personnel must preserve evidence and must not investigate by copying or circulating data beyond the response team.
The incident team will:
- contain the event and protect affected individuals;
- establish what happened, when, systems, countries, data categories and approximate people/records affected;
- identify the controller and notify affected Community Customers without undue delay, with an internal target of no later than 24 hours after awareness;
- assess likely harm and document the decision;
- support notice to the Bahrain PDPA within 72 hours where required, explaining any delay;
- notify affected individuals without undue delay where the breach is likely to create high risk, unless a legal exception applies;
- document mitigation, recovery and recurrence-prevention measures; and
- retain the incident record and evidence under restricted access.
No public statement about an incident may be misleading or delay a legally required notice.
16. Training, assurance and improvement
- Personnel complete privacy and security training at onboarding and at least annually.
- Higher-risk roles receive role-specific training for identity documents, support, production access, payments, governance and incident handling.
- Compliance with this Policy, rights timelines, privileged access, vendor status, deletion jobs and consent controls is reviewed periodically.
- Material findings have a named owner, due date and management escalation.
- This Policy and related risks are reviewed at least annually and after material product, vendor, law or incident changes.
Violation of this Policy may lead to access removal, disciplinary or contractual action and, where appropriate, reporting to a Community Customer, regulator or law-enforcement authority.
17. Governing law and courts
These Terms and any non-contractual dispute connected with them are governed by the laws of the Kingdom of Bahrain, without limiting mandatory rights you have under applicable law.
The competent courts of the Kingdom of Bahrain have jurisdiction, subject to any mandatory consumer forum or dispute right that cannot lawfully be excluded.
18. Questions and complaints
Questions, rights requests or complaints may be submitted to:
Marvel Technology and Information Systems WLL (Sukna)
Arcapita, Office 2
Bahrain Bay, Manama 346
Kingdom of Bahrain
Privacy: info@marvel-technology.com
Support: hello@sukna.co
Individuals may also complain to the Bahrain Personal Data Protection Authority.
الغرض
تلتزم شركة مارفل تكنولوجي وأنظمة المعلومات ذ.م.م، مشغّلة سُكنى («مارفل» أو «سُكنى» أو «نحن» أو «لنا»)، بحماية البيانات الشخصية عبر موقع سُكنى الإلكتروني وتطبيق الهاتف المحمول ولوحة التحكم عبر الويب وعمليات الدعم والأنشطة المؤسسية.
تبيّن هذه السياسة الحوكمة والحد الأدنى من الضوابط التي نطبّقها طوال دورة حياة البيانات. وهي تدعم الامتثال لقانون البحرين رقم 30 لسنة 2018 بإصدار قانون حماية البيانات الشخصية وأوامره التنفيذية. وتُستكمَل بسياسة خصوصية سُكنى واتفاقيات معالجة بيانات العملاء والموردين ومعايير الأمن وجدول الاحتفاظ وخطة الاستجابة للحوادث والإجراءات الداخلية.
1. النطاق
تنطبق هذه السياسة على:
- جميع أعضاء مجلس إدارة مارفل ومسؤوليها وموظفيها والعاملين المؤقتين والمقاولين؛
- جميع البيانات الشخصية التي تكون مارفل متحكّمًا فيها؛
- جميع البيانات الشخصية التي تعالجها مارفل لصالح عميل مجتمع؛
- جميع البيئات والأجهزة وقواعد البيانات والنسخ الاحتياطية والسجلات والسجلات الورقية المستخدمة لسُكنى؛ و
- جميع الموردين والمعالجين الفرعيين ذوي الوصول إلى البيانات الشخصية.
عميل المجتمع هو اتحاد ملاك أو مطوّر أو مدير عقار أو جهة مشتركة أخرى مسؤولة عن عقار أو مجتمع. وصاحب البيانات هو فرد قابل للتعريف، بما في ذلك مقيم أو مالك أو مستأجر أو فرد أسرة أو ممثل معتمد أو زائر أو عميل محتمل أو موظف أو جهة اتصال لمورّد.
2. المساءلة والأدوار القانونية
2.1 مارفل كمتحكّم
تكون مارفل متحكّمًا في البيانات للأغراض التي تحدّدها، بما في ذلك إدارة حسابات سُكنى وأمن المنصة والدعم المباشر واستفسارات الموقع وخيارات ملفات تعريف الارتباط والتسويق الاختياري وإدارة المنتج وسجلاتها القانونية/التجارية الخاصة.
2.2 مارفل كمعالج
يكون عميل المجتمع عادةً المتحكّم في سجلات المجتمع، بما في ذلك علاقات المقيم/الوحدة والتحقق من الهوية اللازم للوصول وطلبات الخدمة والإشعارات والمستندات والفواتير والمخالفات وسجلات الزوّار/الدخول وحوكمة اتحاد الملاك. وتعالج مارفل تلك السجلات فقط بناءً على تعليمات موثّقة وبموجب اتفاقية معالجة بيانات مكتوبة.
ستُخطر مارفل عميل المجتمع إذا بدا أن تعليمًا يخالف قانون حماية البيانات المعمول به، وقد تعلّق المعالجة المتأثرة إلى حين حلّ المسألة. ولن تبيع مارفل بيانات عميل مجتمع قابلة للتعريف أو تعلن ضدّها بشكل مستقل أو تعيد استخدامها على نحو آخر لأغراضها غير ذات الصلة.
2.3 المسؤولية
- تعتمد الإدارة هذه السياسة وتوفّر الموارد الكافية وتقبل المخاطر المرتفعة المتبقّية.
- يحافظ مسؤول الخصوصية على سجل المعالجة والمشورة وعملية طلبات الحقوق وتقييمات أثر حماية البيانات وسجلات النقل والموردين وتقييم خصوصية الحوادث والتنسيق التنظيمي. وسيُخطَر بتعيين حارس قانوني لحماية البيانات حيثما لزم ذلك.
- ينفّذ مسؤولو الأمن والهندسة الخصوصيةَ حسب التصميم والتطوير الآمن والتحكم في الوصول والتسجيل والاختبار والمرونة والحذف.
- يوثّق مالكو المنتج الغرض والحقول والأساس القانوني والإشعارات والأدوار والمستلمين والاحتفاظ وضوابط المستخدم قبل اعتماد أي ميزة.
- تتّبع فرق العملاء/الدعم إجراءات الهوية المُتحقَّق منها والحد الأدنى من الوصول والتصعيد.
- يحمي جميع الموظفين السرّية ويستخدمون البيانات فقط للعمل المعتمد ويبلغون عن الحوادث فورًا. وتستمر السرّية بعد انتهاء التوظيف أو التعاقد.
3. مبادئ حماية البيانات
تطبّق سُكنى المبادئ التالية:
- المشروعية والإنصاف: يجب أن يكون لكل نشاط أساس قانوني موثّق، وألّا يستخدم البيانات على نحو غير متوقّع أو ضار بلا مبرّر.
- تحديد الغرض: تُجمَع البيانات الشخصية لأغراض محدَّدة وصريحة ومشروعة ولا يُعاد استخدامها على نحو غير متوافق.
- تقليل البيانات: يجب أن يكون كل حقل ومرفق وإذن ضروريًّا ومتناسبًا.
- الدقة: تتيح عمليات معقولة للمستخدمين ولعملاء المجتمع المعتمدين تصحيح السجلات.
- تحديد التخزين: لكل فئة سجل مدة موثّقة وإجراء حذف/إخفاء هوية.
- الأمن والسرّية: تعكس الضمانات حساسية البيانات وحجمها وسياقها والتقنية المتاحة والضرر المحتمل.
- الشفافية والاختيار: الإشعارات موجزة وسهلة الوصول وتُقدَّم عند جمع البيانات أو تسجيلها لأول مرة.
- المساءلة: تُوثَّق القرارات والتقييمات والعقود والموافقات والوصول والحوادث بحيث يمكن إثبات الامتثال.
4. المعالجة القانونية والموافقة
قبل بدء الجمع، يجب على المالك المسؤول توثيق الغرض والمتحكّم وفئات البيانات والأفراد والأساس القانوني وحالة الإلزام/الاختيار والمستلمين وآلية النقل ومدة الاحتفاظ.
بحسب الغرض، قد تستند المعالجة إلى موافقة صريحة أو عقد أو خطوات ما قبل التعاقد أو التزام قانوني أو إجراءات قانونية معترف بها أو مصالح حيوية أو مصلحة مشروعة لا تتجاوز حقوق الأفراد.
يجب أن تكون الموافقة:
- إجراءً إيجابيًّا مكتوبًا أو إلكترونيًّا؛
- محدَّدة لغرض واضح؛
- مستنيرة وغير ملتبسة ومُسجَّلة؛
- مقدَّمة بحرية، دون جعل استخدام اختياري شرطًا لخدمة غير ذات صلة؛ و
- سهلة السحب سهولة منحها، دون رسم أو مسؤولية.
قبول الشروط والاتصالات التشغيلية وموافقة التسويق خيارات منفصلة. ولا تُحمَّل ملفات تعريف الارتباط وحزم التطوير غير الأساسية وعناصر الأطراف الثالثة المضمّنة قبل موافقة صحيحة. ويمكن لمن يرفضها مواصلة استخدام المحتوى غير ذي الصلة والوظائف الأساسية.
لا تُعالَج البيانات الشخصية الحسّاسة إلا بموجب استثناء قانوني معمول به وضوابط مُعزّزة. ولا تُعالَج بيانات السجل الجنائي، إن لزمت يومًا، دون مراجعة قانونية محدَّدة.
5. تصنيف البيانات والتعامل معها
تستخدم سُكنى الحد الأدنى من التصنيف التالي.
تُصنَّف البيانات وفق أعلى عنصر خطورة في السجل. ويُحظر تنزيل البيانات المقيَّدة أو السرّية إلى أجهزة غير مُدارة أو بريد إلكتروني شخصي أو حسابات مراسلة شخصية أو تخزين غير معتمد.
6. الجمع والخصوصية حسب التصميم
6.1 اعتماد المنتج
لا يمكن لميزة جديدة أو مُعدَّلة جوهريًّا معالجة بيانات شخصية إلى أن يُعتمَد سجل تصميم بياناتها. ويجب أن يغطّي السجل:
- الغرض للمستخدم وللأعمال؛
- الحقول والأذونات، بما في ذلك سبب ضرورة كلٍّ منها؛
- أدوار المتحكّم/المعالج وتهيئة العميل؛
- الأساس القانوني وإشعار نقطة الجمع؛
- أدوار الوصول وأحداث التدقيق؛
- الموردين وحزم التطوير والدول والعقود؛
- سلوك الاحتفاظ والحذف والنسخ الاحتياطي؛
- دعم طلبات الحقوق؛ و
- حالات الأمن وإساءة الاستخدام.
يجب أن تكون الإعدادات الافتراضية حامية للخصوصية. وتكون الحقول الاختيارية والمشاركة معطّلة افتراضيًّا ما لم يخترها المستخدم أو عميل المجتمع المعتمد.
6.2 تقييم أثر حماية البيانات
يجب إكمال تقييم أثر حماية البيانات قبل المعالجة عالية الخطورة، بما في ذلك:
- معالجة بيانات حسّاسة بشكل منهجي أو واسع النطاق؛
- التعرّف المركزي على الوجه أو تحديد الهوية بالقياسات الحيوية؛
- المراقبة واسعة النطاق للأماكن المتاحة للعموم؛
- التقييم الآلي المكثّف أو التصنيف ذي الآثار الجوهرية؛
- ربط ملفات قابلة للتعريف من متحكّمين غير مرتبطين لأغراض مختلفة؛
- معالجة وثائق الهوية على نطاق جوهري؛
- تسجيل درجات المقيمين أو المخالفات أو غيرها من المعالجة التي يُرجَّح أن تُسبّب ضررًا جوهريًّا؛ أو
- تقنية أو استخدام جديد يغيّر جوهريًّا التوقعات المعقولة.
يصف التقييم الضرورة والتناسب والمخاطر والضمانات والتشاور والمخاطر المتبقّية والاعتمادات. ولن تبدأ المعالجة التي تحتاج إلى إخطار هيئة حماية البيانات أو تصريح مسبق إلا بعد إتمام تلك الخطوة.
7. ضوابط سُكنى الخاصة
7.1 وثائق الهوية
- يجب على عميل المجتمع توثيق سبب ضرورة التحقق من الهوية وما هو الدليل المتناسب.
- حيثما تكفي طريقة أقل خطورة، ستتجنّب سُكنى جمع صورة وثيقة كاملة.
- تُفصَل الصورة عن عروض الملف الشخصي الاعتيادية وتُتاح فقط لأدوار التحقق المعتمدة.
- يُسجَّل كل عرض وتغيير وتصدير وحذف لوثيقة هوية.
- افتراضيًّا، تُحذف الصورة بمجرد اكتمال التحقق وفي موعد لا يتجاوز 30 يومًا بعده. وتتطلب مدة أطول تعليمات عميل موثّقة وأساسًا قانونيًّا وتاريخ انتهاء.
- تقتصر السمات المُتحقَّق منها على ما يلزم لأهلية الحساب/المجتمع.
- يجب أن تستخدم العروض التوضيحية والتدريب والوثائق العامة بيانات هوية اصطناعية.
7.2 القياسات الحيوية للجهاز
تستخدم بنية سُكنى المعتمدة نظام تشغيل الجهاز لمطابقة معرّف الوجه/البصمة، وتتلقّى نتيجة مصادقة فقط. ولا تتلقّى سُكنى صورة وجه/بصمة خام أو قالبًا. وأي اقتراح لتغيير هذه البنية يتطلب تقييم أثر حماية بيانات ومراجعة خصوصية صريحة وأمنًا مُعزّزًا وأي تصريح مسبق مطلوب قبل جمع بيانات التطوير.
7.3 اجتماعات اتحاد الملاك والتصويت
- يهيّئ عميل المجتمع قواعد الأهلية والاستحقاق والإشعار والنصاب والتوكيل والاقتراع ويبقى مسؤولًا عن قانونيتها.
- تسجّل سُكنى أحداث النظام اللازمة لإثبات المشاركة وسلامة النتيجة.
- يكون الوصول الإداري إلى بطاقات الاقتراع وأحداث التدقيق مقيَّدًا ومُسجَّلًا.
- لا تُكشف اختيارات الاقتراع السرّي لعميل المجتمع أو لمستخدمين آخرين ما لم تقتضِ العملية القانونية المُهيَّأة الوصول وتصرّح به.
- تُفصَل بطاقات الاقتراع التجريبية عن بطاقات الإنتاج.
- لا يستبدل التصحيح أبدًا حدث الحوكمة الأصلي بصمت؛ ويسجّل مسار التدقيق التغيير المعتمد وسببه.
- لا تشهد سُكنى بأن اجتماعًا أو تصويتًا أو قرارًا صحيح قانونًا.
7.4 الفواتير والمدفوعات
- يكون عميل المجتمع مسؤولًا عن الفاتورة والمبلغ والاستحقاق في تحصيله.
- يتولّى مزوّد دفع معتمد جمع رقم البطاقة الكامل وقيمة CVV، ولا تخزّنها سُكنى.
- تحتفظ سُكنى ببيانات معاملات وحالة وتسوية محدودة وتقصر الوصول إليها على الدور المالي.
- تحدّد صفحات الدفع الجهة/المزوّد الذي يجمع المبلغ والعملة ومسار التأكيد.
- تتّبع الاستردادات والمردودات والنزاعات إجراءات عميل/مزوّد موثّقة.
7.5 المخالفات والشكاوى ومحتوى الخدمة
قد تؤثّر المخالفات والشكاوى في سمعة شخص أو حقوقه المجتمعية. وهي مرئية فقط للأدوار ذات الحاجة التشغيلية، ويجب أن تحدّد المصدر/الحالة حيثما كان ملائمًا، وأن تدعم التصحيح والاستجابة والتصعيد. ولا يُعاد استخدام مرفقات طلبات الخدمة في العروض التوضيحية أو التدريب أو التسويق دون صلاحية منفصلة.
8. إدارة الوصول
يستند الوصول إلى مبدأ أقل امتياز وحدود المجتمع والدور الوظيفي والحاجة الحالية.
- معرّفات المستخدمين الفريدة إلزامية؛ وتُحظر الحسابات الإدارية المشتركة باستثناء الحسابات التقنية المضبوطة.
- يتطلب الوصول المميَّز مصادقة قوية ويُراجَع كل ثلاثة أشهر على الأقل.
- تؤدي أحداث الانضمام والانتقال والمغادرة إلى تغييرات وصول فورية.
- لا يجوز لمسؤولي عميل المجتمع منح سوى الأدوار الموثّقة داخل مجتمعهم.
- يتطلب وصول الدعم/الهندسة إلى الإنتاج غرض دعم أو حادث معتمَدًا ويُسجَّل.
- يخضع الوصول إلى صور الهوية والمخالفات والفواتير وسجلات التصويت والتصديرات لمراقبة مُعزّزة.
- تُعطَّل الحسابات وبيانات الاعتماد غير النشطة بموجب معيار الوصول المعمول به.
9. الأمن والمرونة
تحافظ سُكنى على برنامج أمن معلومات قائم على المخاطر يشمل:
- التهيئة الآمنة وإدارة التغيير؛
- التشفير أثناء النقل والتشفير المناسب في حالة السكون بمفاتيح مضبوطة؛
- المصادقة القوية وحماية كلمات المرور وإدارة الأسرار؛
- حماية التطبيقات والشبكات ونقاط النهاية والبرمجيات الخبيثة؛
- التحقق من المدخلات وإدارة التبعيات ومراجعة التطوير الآمن؛
- تسجيل مركزي للأمن/التدقيق محمي من التعديل غير المصرّح به؛
- فحص الثغرات واختبار اختراق مستقل سنويًّا على الأقل وبعد التغييرات الجوهرية عالية الخطورة؛
- نسخ احتياطية مشفّرة ومضبوطة الوصول واستعادة مُختبَرة؛
- خطط استمرارية الأعمال والتعافي من الكوارث؛
- العناية الواجبة الأمنية للموردين والضوابط التعاقدية؛ و
- الحذف الآمن أو إخفاء الهوية غير القابل للعكس عند انتهاء الاحتفاظ.
يُجرى اختبار الأمن والمراقبة بطريقة تقلّل البيانات الشخصية الحية. ولا تُنسخ بيانات الإنتاج إلى بيئات التطوير أو الاختبار ما لم يكن ذلك ضروريًّا للغاية ومعتمدًا ومحميًّا بمعيار معادل؛ والبيانات الاصطناعية هي الوضع الافتراضي.
10. الموردون وعملاء المجتمع
قبل أن يعالج مورّد بيانات شخصية، تقيّم سُكنى قدرته وأمنه ودوله ومعالجيه الفرعيين ودعمه للخرق/الحقوق. ويجب أن يغطّي العقد المكتوب:
- التعليمات الموثّقة وحدود الغرض؛
- السرّية وضوابط الموظفين؛
- الضمانات التقنية والتنظيمية؛
- اعتماد المعالج الفرعي والالتزامات المعادلة؛
- متطلبات النقل إلى الخارج؛
- الإشعار الفوري بالحوادث والتعاون؛
- المساعدة في الحقوق وتقييمات الأثر والجهات التنظيمية؛
- الإعادة/الحذف عند انتهاء الخدمة؛ و
- حقوق الأدلّة والتدقيق والمعالجة بما يتناسب مع المخاطر.
تحتوي اتفاقية معالجة بيانات عميل المجتمع على شروط معادلة وتوزّع بوضوح الواجبات القانونية للمتحكّم ومساعدة مارفل كمعالج. وتحتفظ سُكنى بسجل معتمد للموردين والمعالجين الفرعيين.
11. الإفصاحات وعمليات النقل الدولية
لا تُفصح البيانات الشخصية إلا لمستلمين معتمدين لغرض موثّق وبأدنى نطاق. وتُتحقَّق طلبات الجهات وتُسجَّل وتُراجَع للأساس القانوني والتناسب ما لم يمنع القانون الإشعار أو المراجعة.
قبل خروج البيانات من البحرين، تسجّل سُكنى البيانات والمصدّر والمستورد والدول والغرض وعمليات النقل اللاحقة والآلية القانونية. ويجوز النقل المباشر إلى وجهة تعترف بها هيئة حماية البيانات البحرينية بأنها كافية. وتتطلب عمليات النقل الأخرى تصريحًا مسبقًا معمولًا به أو استثناءً قانونيًّا إضافةً إلى العقد والضمانات اللازمة. ويُعاد تقييم حالة النقل عند تغيّر مورّد أو دولة أو قانون.
12. الدقة والاحتفاظ والحذف
يجب على مالكي المنتج وعملاء المجتمع توفير طريقة لتصحيح البيانات وتحديد المصدر الموثوق لحقول الهوية والوحدة والفاتورة والتصويت الأساسية. وتُسجَّل التصحيحات الجوهرية.
تحافظ سُكنى على جدول احتفاظ على مستوى السجل يتوافق مع سياسة الخصوصية العامة. ولكل مدة مُحفِّز ومالك ومبرّر قانوني/تجاري وإجراء تخلّص وعملية استثناء. ويُحظر الاحتفاظ غير المحدَّد المدة.
تُوثَّق التعليقات القانونية وتُقصَر على السجلات ذات الصلة وتُراجَع كل ستة أشهر على الأقل. وعند انتهاء التعليق، يُستأنف الجدول الاعتيادي. ويجب أن يشمل الحذف النسخ النشطة وفهارس البحث والتصديرات الخاضعة لسيطرة سُكنى؛ وتنتهي النسخ الاحتياطية المحمية وفق دورة الكتابة فوقها الموثّقة ولا تُستعاد إلى الاستخدام الاعتيادي.
يجوز الاحتفاظ بالمعلومات المجمّعة مدة أطول فقط إذا اختُبِرت بحيث لا يمكن إعادة تعريف فرد بشكل معقول. والإخفاء المستعار وحده ليس إخفاءً للهوية.
13. حقوق الأفراد
توفّر سُكنى مسارًا إلكترونيًّا مُراقَبًا لطلبات الوصول والتصحيح والحظر والمحو والاعتراض وسحب الموافقة وإلغاء التسويق والقرارات الآلية.
سيقوم فريق الخصوصية بـ:
- تسجيل الطلب وتحديد المتحكّم المعني؛
- التحقق من الهوية باستخدام معلومات متناسبة وتجنّب طلب صورة هوية جديدة حيثما تنجح طريقة أكثر أمانًا؛
- الإقرار بطلبات عميل المجتمع وتوجيهها فورًا؛
- البحث في جميع الأنظمة والموردين ذوي الصلة؛
- تطبيق الاستثناءات القانونية بشكل ضيّق وتسجيل السبب؛
- الاستجابة خلال المدة البحرينية المعمول بها — عادةً 15 يوم عمل للوصول و10 أيام عمل للتصحيح أو الحظر أو المحو أو اعتراض التسويق المباشر الصحيح؛ و
- نقل التصحيح أو الحظر أو المحو المقبول إلى المستلمين المعنيين حسب المطلوب.
لا يُعاقَب أي شخص على تقديم طلب خصوصية. وتُعالَج الطلبات الاعتيادية مجانًا ما لم يسمح القانون البحريني بخلاف ذلك.
14. التسويق المباشر والرسائل التشغيلية
تُميَّز الإشعارات التشغيلية اللازمة للأمن والفواتير وطلبات الخدمة والاجتماعات وإدارة المجتمع عن العروض الترويجية. ويتطلب تسويق سُكنى الموافقة المناسبة ويتضمّن دائمًا إلغاء اشتراك بسيطًا. ويُطبَّق إلغاء الاشتراك عبر القناة المعنية دون تأخير لا مبرّر له وضمن الموعد القانوني. وتُحفظ بيانات الاستبعاد فقط لاحترام الاختيار.
لا يجوز لعملاء المجتمع استخدام بيانات سُكنى لتسويق غير ذي صلة ما لم يثبتوا بشكل مستقل أساسًا قانونيًّا ويوثّقوه ويقدّموا الإشعار والاختيار المطلوبَين.
15. حوادث البيانات الشخصية
على كل من يشتبه في فقدان أو وصول غير مصرّح به أو إفصاح أو تعديل أو عدم توافر أو معالجة غير سليمة أن يبلغ فورًا عبر قناة الحوادث في سُكنى. ويجب على الموظفين حفظ الأدلّة وعدم التحقيق بنسخ البيانات أو تداولها خارج فريق الاستجابة.
سيقوم فريق الحوادث بـ:
- احتواء الحدث وحماية الأفراد المتأثرين؛
- تحديد ما حدث ومتى والأنظمة والدول وفئات البيانات وعدد الأشخاص/السجلات المتأثرة تقريبًا؛
- تحديد المتحكّم وإخطار عملاء المجتمع المتأثرين دون تأخير لا مبرّر له، بهدف داخلي لا يتجاوز 24 ساعة بعد العلم؛
- تقييم الضرر المحتمل وتوثيق القرار؛
- دعم إخطار هيئة حماية البيانات البحرينية خلال 72 ساعة حيثما لزم، مع توضيح أي تأخير؛
- إخطار الأفراد المتأثرين دون تأخير لا مبرّر له حيثما يُرجَّح أن يُنشئ الخرق خطرًا مرتفعًا، ما لم ينطبق استثناء قانوني؛
- توثيق تدابير التخفيف والتعافي ومنع التكرار؛ و
- حفظ سجل الحادث والأدلّة بوصول مقيَّد.
لا يجوز أن يكون أي بيان علني عن حادث مضلِّلًا أو أن يؤخّر إشعارًا مطلوبًا قانونًا.
16. التدريب والتأكيد والتحسين
- يكمل الموظفون تدريب الخصوصية والأمن عند الالتحاق وسنويًّا على الأقل.
- تتلقّى الأدوار عالية الخطورة تدريبًا خاصًّا بالدور لوثائق الهوية والدعم والوصول للإنتاج والمدفوعات والحوكمة ومعالجة الحوادث.
- يُراجَع دوريًّا الامتثالُ لهذه السياسة والجداول الزمنية للحقوق والوصول المميَّز وحالة الموردين ومهام الحذف وضوابط الموافقة.
- للنتائج الجوهرية مالك مُسمّى وتاريخ استحقاق وتصعيد إداري.
- تُراجَع هذه السياسة والمخاطر ذات الصلة سنويًّا على الأقل وبعد تغييرات جوهرية في المنتج أو المورّد أو القانون أو الحوادث.
قد يؤدي انتهاك هذه السياسة إلى إزالة الوصول أو إجراء تأديبي أو تعاقدي، وحيثما كان ملائمًا، إبلاغ عميل مجتمع أو جهة تنظيمية أو جهة إنفاذ قانون.
17. القانون الحاكم والمحاكم
تخضع هذه الشروط وأي نزاع غير تعاقدي مرتبط بها لقوانين مملكة البحرين، دون الحدّ من الحقوق الإلزامية المكفولة لك بموجب القانون المعمول به.
تختصّ محاكم مملكة البحرين المختصة بالنظر في النزاعات، مع مراعاة أي منتدى استهلاكي إلزامي أو حق في النزاع لا يمكن استبعاده قانونًا.
18. الأسئلة والشكاوى
يمكن تقديم الأسئلة أو طلبات الحقوق أو الشكاوى إلى:
شركة مارفل تكنولوجي وأنظمة المعلومات ذ.م.م (سُكنى)
أركابيتا، مكتب 2
خليج البحرين، المنامة 346
مملكة البحرين
الخصوصية: info@marvel-technology.com
الدعم: hello@sukna.co
يجوز للأفراد أيضًا تقديم شكوى إلى هيئة حماية البيانات الشخصية في البحرين.
Questions about this policy? Contact us at hello@sukna.co.