سياسة الخصوصية
آخر تحديث: 9 أكتوبر 2026 (بيانات الشركة المشغّلة)
Replyeye علامة تجارية تابعة لشركة ريبلاي اي للبرمجيات ذ.م.م (شخص واحد)، سجل تجاري رقم 253812، الدوحة، قطر.
١. مقدمة
توضح هذه السياسة كيف تجمع Replyeye ("نحن") وتستخدم وتحمي البيانات عند استخدامك لمنصتنا لخدمة العملاء بالذكاء الاصطناعي، سواء كنت شركة مشتركة في المنصة أو عميلًا يتواصل مع إحدى الشركات المشتركة عبر المنصة. تلتزم Replyeye بقانون حماية خصوصية البيانات الشخصية القطري (PDPPL). بالنسبة لبيانات عملاء الشركة المشتركة نحن "معالج بيانات" نعالجها نيابةً عنها ولتشغيل مساعدها فقط، وتبقى الشركة المشتركة "متحكم البيانات" المسؤول عنها. وبالنسبة لبيانات حسابات الشركات وموظفيها وزوار موقعنا نحن "متحكم البيانات".
٢. البيانات التي نجمعها
- بيانات حساب الشركة وفريقها: الأسماء، البريد الإلكتروني، الجوال، الأدوار، معلومات الاشتراك والفواتير والمدفوعات وإيصالات التحويل.
- محتوى المحادثات: رسائل عملاء الشركة (نص، وتفريغ نصي للرسائل الصوتية، ووصف نصي للصور)، وردود المساعد، وردود موظفي الشركة من لوحة التحكم.
- الملاحظات الداخلية التي يكتبها موظفو الشركة على المحادثات (لا تصل للعميل ولا يستخدمها المساعد).
- ملفات المعرفة وتعليمات المساعد التي تضيفها الشركة.
- بيانات الاستخدام التقنية: عدد الرسائل واستهلاك النماذج، لأغراض الفوترة ومراقبة الأداء.
- سجل النشاط والتدقيق: من نفّذ أي إجراء على الحساب ومتى، لأغراض الأمان والمساءلة.
- طلبات التواصل من موقعنا (الاسم، الشركة، الجوال، البريد، الرسالة)، لغرض الرد عليها فقط.
٣. كيف نستخدم البيانات
نستخدم البيانات لتشغيل المساعد والرد على عملاء الشركة، ولتمكين موظفي الشركة من الرد والمراجعة من لوحة التحكم، ولحساب الاستخدام والفوترة، ولحماية المنصة. لا نبيع أي بيانات، ولا نستخدم محتوى المحادثات لتدريب نماذج ذكاء اصطناعي عامة؛ تُستخدم بيانات كل شركة حصرًا لتشغيل مساعدها. نفحص ملفات المعرفة والتعليمات وردود المساعد آليًا لرصد المحتوى المخالف لسياسة الاستخدام المقبول (بما في ذلك عبر خدمة الإشراف لدى OpenAI)، ولا يرى فريقنا في هذه التنبيهات إلا مقتطفًا مخفي البيانات. لا يطلب المساعد بيانات حساسة للغاية (مثل أرقام بطاقات الدفع أو كلمات المرور أو رموز التحقق أو أرقام الهوية)، ونطلب منك عدم مشاركتها عبر المحادثة.
٤. عزل البيانات بين الشركات
بيانات كل شركة مشتركة (محادثاتها، ملفاتها، عملاؤها، فريقها) معزولة عن باقي الشركات على مستوى قاعدة البيانات، ولا يمكن لأي شركة الوصول لبيانات شركة أخرى.
٥. وصول فريقنا إلى المحتوى
لا يطّلع فريق Replyeye على محادثات الشركات المشتركة أو ملفات معرفتها أو تعليمات مساعدها في التشغيل العادي. يُفتح وصول مؤقت ومسجَّل في حالتين فقط: (١) عندما تمنح الشركة فريق الدعم وصولًا لمدة 30 أو 60 دقيقة من لوحة التحكم، ويمكنها إنهاؤه في أي وقت؛ (٢) عندما يراجع فريق الثقة والأمان تنبيه امتثال، لمدة 30 دقيقة، ويقتصر على الملف أو المحادثة المعنية، بسبب مكتوب، مع إشعار الشركة فور فتحه. كل اطلاع مسجَّل، وتتلقى الشركة ملخصًا بما اطُّلع عليه عند انتهاء الوصول، وتجد سجل النشاط في لوحة التحكم.
٦. مشاركة البيانات مع أطراف ثالثة
نستعين بمزودي خدمات تقنية لتشغيل المنصة، بعضهم خارج قطر: مزودو نماذج الذكاء الاصطناعي (OpenAI وAnthropic وGoogle عبر OpenRouter، وOpenAI للبحث في المعرفة وتفريغ الصوت ووصف الصور والإشراف على المحتوى)، وقاعدة البيانات والتخزين (Supabase)، والأتمتة واستضافة الموقع والبريد (Hostinger)، وقنوات التواصل التي تربطها الشركة (مثل Telegram). يلتزم هؤلاء المزودون بحماية البيانات واستخدامها لتقديم الخدمة فقط. عند اشتراك شركتك نوفر اتفاقية معالجة بيانات (DPA) توضح التزاماتنا.
٧. الاحتفاظ بالبيانات والحذف
نحتفظ بالمحادثات والمعرفة طالما استمر اشتراك الشركة. يمكن لمالك الحساب تنزيل نسخة من بياناته، وطلب حذف حساب الشركة من لوحة التحكم؛ يراجع فريقنا الطلب خلال 7 أيام ويمكن إلغاؤه قبل التنفيذ. عند التنفيذ تُحذف المحادثات والملفات والعملاء والفريق وتعليمات المساعد نهائيًا، ونحتفظ فقط بالفواتير والمدفوعات وسجل العمليات بالقدر الذي يلزمنا به القانون. يُحتفظ بسجل النشاط والتدقيق 24 شهرًا ثم يُحذف آليًا، وتُحذف مقتطفات تنبيهات المحتوى خلال 90 يومًا أو فور إغلاق التنبيه كإنذار خاطئ.
٨. الأمان
نستخدم التشفير أثناء النقل، والعزل بين الشركات على مستوى قاعدة البيانات، وصلاحيات حسب الدور داخل كل شركة، وأقل صلاحيات ممكنة لموظفينا مع سجل تدقيق لا يمكن تعديله. لا يوجد نظام آمن بالكامل؛ وفي حال وقوع حادث يمس البيانات نُبلغ الشركة المتأثرة وفق ما يقتضيه القانون.
٩. حقوقك
إذا كنت عميلًا لإحدى الشركات المشتركة، فالشركة هي المسؤولة عن بياناتك؛ تواصل معها أولًا لطلب الاطلاع على بياناتك أو تصحيحها أو حذفها، وسنساعدها على تلبية طلبك. وإذا كنت صاحب حساب على المنصة، فيمكنك تعديل بياناتك وتنزيلها وطلب حذف الحساب من لوحة التحكم، أو التواصل معنا.
١٠. التواصل معنا
لأي استفسار متعلق بالخصوصية: info@replyeye.com أو نموذج التواصل.
Privacy Policy
Last updated: 9 October 2026 (the operating company)
Replyeye is a brand of Reply Eye for Software LLC (single-member), Commercial Registration No. 253812, Doha, Qatar.
1. Introduction
This policy explains how Replyeye ("we") collects, uses and protects data when you use our AI customer-service platform, whether you are a subscribing business or a customer contacting one of those businesses through the platform. Replyeye complies with Qatar's Personal Data Privacy Protection Law (PDPPL). For a subscribing business's customer data we are a "data processor" acting on the business's behalf and only to run its assistant; the business remains the "data controller". For business account and staff data and for visitors to our website we are the controller.
2. Data We Collect
- Business account and team data: names, email addresses, mobile numbers, roles, subscription, invoices, payments and transfer receipts.
- Conversation content: customers' messages (text, transcripts of voice messages, text descriptions of images), the assistant's replies, and replies sent by the business's staff from the dashboard.
- Internal notes written by the business's staff on conversations (never sent to the customer, never used by the assistant).
- Knowledge files and assistant instructions added by the business.
- Technical usage data: message counts and model usage, for billing and performance monitoring.
- Activity and audit log: who did what on an account and when, for security and accountability.
- Contact requests from our website (name, company, mobile, email, message), used only to reply.
3. How We Use Data
We use data to run the assistant and answer the business's customers, to let the business's staff reply and review from the dashboard, to meter usage and bill, and to protect the platform. We never sell data and never use conversation content to train general AI models; each business's data is used only to run its own assistant. We automatically check knowledge files, instructions and assistant replies for content that breaks the Acceptable Use Policy (including through OpenAI's moderation service); our team sees only a masked excerpt in these alerts. The assistant never asks for highly sensitive data (such as card numbers, passwords, verification codes or ID numbers), and we ask you not to share it in the chat.
4. Data Isolation Between Companies
Each subscribing business's data (conversations, files, customers, team) is isolated from every other business at the database level; no business can access another business's data.
5. Our Team's Access to Content
In normal operation the Replyeye team does not see a business's conversations, knowledge files or assistant instructions. Temporary, logged access is opened only (1) when the business grants support access for 30 or 60 minutes from its dashboard (it can end it at any time), or (2) when our trust & safety team reviews a compliance alert, for 30 minutes, limited to the file or conversation concerned, with a written reason and immediate notice to the business. Every read is logged; the business receives a summary of what was read when access ends and can see the activity log in its dashboard.
6. Sharing Data with Third Parties
We use technology providers to run the platform, some outside Qatar: AI model providers (OpenAI, Anthropic and Google through OpenRouter, and OpenAI for knowledge search, voice transcription, image description and content moderation), database and storage (Supabase), automation, website hosting and email (Hostinger), and the channels a business connects (such as Telegram). These providers must protect the data and use it only to provide the service. When your business subscribes we provide a Data Processing Agreement (DPA) setting out our commitments.
7. Data Retention and Deletion
We keep conversations and knowledge for as long as the business's subscription continues. The account owner can download a copy of their data and request deletion of the business account from the dashboard; our team reviews the request within 7 days and it can be cancelled before it is carried out. When carried out, conversations, files, customers, team and assistant instructions are permanently deleted; we keep only invoices, payments and the activity log to the extent the law requires. The activity and audit log is kept for 24 months and then deleted automatically; content-alert excerpts are deleted within 90 days, or immediately when an alert is closed as a false positive.
8. Security
We use encryption in transit, database-level isolation between businesses, role-based permissions within each business, and least-privilege access for our staff with an audit log that cannot be altered. No system is completely secure; if an incident affects data we notify the affected business as the law requires.
9. Your Rights
If you are a customer of a subscribing business, that business is responsible for your data: contact it first to access, correct or delete your data, and we will help it respond. If you hold an account on the platform, you can edit and download your data and request account deletion from the dashboard, or contact us.
10. Contact Us
For any privacy question: info@replyeye.com or our contact form.