1. Introduction
AHG ("the App") is a business accounting application developed by AYAN Codex for Alushibe Holding Group and its authorized staff. It provides mobile access to the organization's ERP system (accounts, balances, statements, and financial transactions). This policy explains what information the App handles, why, and the choices you have. The App is intended for authorized business users only — it is not a consumer service.
2. Information We Collect
Account & sign-in information
- Google Sign-In: if you sign in with Google, we receive your name and email address from Google to authenticate you against your organization's authorized user list.
- Email verification (OTP): if you sign in with a one-time code, we process your email address to deliver the code.
Device & licensing information
- A hashed device identifier — a one-way SHA-256 fingerprint computed on your device from a hardware-backed device identifier (the Widevine DRM provisioning ID, or the Android ID / an app-generated install ID when unavailable) together with coarse device properties (manufacturer and model). Only the resulting hash is transmitted — the underlying identifiers never leave your device. The App cannot access, and never collects, your IMEI, phone serial number, or MAC address.
- Device platform, app version, and device name — used to activate and validate the software license.
- Server-side security logs of licensing requests may include IP address and user agent, used solely for fraud prevention and abuse protection.
Business data
- The accounting records shown in the App (accounts, balances, transactions, statements) belong to your organization and are retrieved from your organization's own database. The App displays and records this data on behalf of your employer; it is not collected by AYAN Codex for its own purposes.
3. Device Permissions
- Camera: used only to scan the QR code of your license serial number during activation. No photos or videos are captured, stored, or uploaded.
- Biometrics (fingerprint / face unlock): used only to unlock the App on your device. Biometric data is processed entirely by your device's operating system and never leaves your device — we cannot access it.
- Internet: required to connect to your organization's ERP server and the license server over encrypted connections (HTTPS/TLS).
4. How We Use Information
- Authenticate you and keep your session secure.
- Activate, validate, and protect the software license (anti-fraud).
- Provide the App's accounting features (viewing and recording your organization's financial data).
- Respond to support requests.
The App contains no advertising and no third-party analytics or tracking SDKs. We do not sell, rent, or trade any personal information.
5. Data Sharing
- Google: only when you choose Google Sign-In, per Google's Privacy Policy.
- Your organization: the financial data you enter is stored in your organization's ERP database and is governed by its internal policies.
- We may disclose information if required by law.
- No other third parties receive your data.
6. Data Security
- All network traffic uses encrypted HTTPS/TLS connections.
- Credentials and license material are stored only in the device's secure storage (Android Keystore / iOS Keychain).
- License-server responses are cryptographically signed (Ed25519) and verified by the App.
- Access to business data requires both a valid organizational account and a valid software license.
7. Data Retention & Deletion
- Sign-in and licensing records are kept while your organization's subscription is active and for a reasonable period afterwards as required for security auditing and legal compliance.
- Business/accounting records are retained by your organization under its own policies.
- To request deletion of your personal data (name, email, device activation), contact us at support@ayancodex.com. Requests are honored within 30 days unless retention is legally required.
- Uninstalling the App removes all locally stored credentials and cached data from your device.
8. Children's Privacy
The App is a business tool for authorized adult staff. It is not directed at children under 13, and we do not knowingly collect information from children.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated effective date.
10. Contact Us
For any privacy questions or requests:
- Email: support@ayancodex.com
- Developer: AYAN Codex
١. مقدمة
تطبيق AHG ("التطبيق") هو تطبيق محاسبة للأعمال طورته AYAN Codex لمجموعة العشيبي القابضة وموظفيها المصرح لهم. يتيح التطبيق الوصول عبر الهاتف إلى نظام ERP الخاص بالمؤسسة (الحسابات والأرصدة وكشوف الحساب والمعاملات المالية). توضح هذه السياسة البيانات التي يتعامل معها التطبيق وأسباب ذلك وخياراتكم. التطبيق مخصص للمستخدمين المصرح لهم فقط وليس خدمة استهلاكية عامة.
٢. البيانات التي نجمعها
بيانات الحساب وتسجيل الدخول
- تسجيل الدخول عبر Google: عند اختياره نستلم الاسم والبريد الإلكتروني من Google للتحقق من هويتكم ضمن قائمة المستخدمين المصرح لهم.
- رمز التحقق عبر البريد (OTP): نعالج بريدكم الإلكتروني لإرسال رمز الدخول.
بيانات الجهاز والترخيص
- معرّف جهاز مجزأ (Hash) — بصمة SHA-256 أحادية الاتجاه تُحسب على جهازكم من معرّف جهاز مدعوم عتادياً (معرّف Widevine DRM، أو Android ID / معرّف تثبيت يولّده التطبيق عند عدم توفره) مع خصائص عامة للجهاز (الشركة المصنعة والطراز). يُرسل الناتج المجزأ فقط — ولا تغادر المعرّفات الأصلية جهازكم أبداً. لا يمكن للتطبيق الوصول إلى IMEI أو الرقم التسلسلي للهاتف أو عنوان MAC ولا يجمعها إطلاقاً.
- نظام التشغيل وإصدار التطبيق واسم الجهاز — لتفعيل ترخيص البرنامج والتحقق منه.
- قد تتضمن سجلات الأمان على خادم الترخيص عنوان IP ومتصفح الجهاز، وتُستخدم فقط لمنع الاحتيال وإساءة الاستخدام.
بيانات الأعمال
- السجلات المحاسبية المعروضة في التطبيق (الحسابات والأرصدة والمعاملات وكشوف الحساب) مملوكة لمؤسستكم وتُجلب من قاعدة بياناتها. يعرض التطبيق هذه البيانات ويسجلها نيابة عن جهة عملكم، ولا تجمعها AYAN Codex لأغراضها الخاصة.
٣. أذونات الجهاز
- الكاميرا: تُستخدم فقط لمسح رمز QR الخاص بالرقم التسلسلي للترخيص أثناء التفعيل. لا يتم التقاط أو تخزين أو رفع أي صور أو مقاطع.
- البصمة / التعرف على الوجه: تُستخدم فقط لفتح التطبيق على جهازكم. تُعالج بيانات البصمة بالكامل بواسطة نظام تشغيل الجهاز ولا تغادر جهازكم أبداً — ولا يمكننا الوصول إليها.
- الإنترنت: مطلوب للاتصال بخادم ERP الخاص بمؤسستكم وخادم الترخيص عبر اتصالات مشفرة (HTTPS/TLS).
٤. كيف نستخدم البيانات
- التحقق من هويتكم والحفاظ على أمان الجلسة.
- تفعيل ترخيص البرنامج والتحقق منه وحمايته من الاحتيال.
- تقديم ميزات المحاسبة (عرض وتسجيل البيانات المالية لمؤسستكم).
- الرد على طلبات الدعم.
لا يحتوي التطبيق على أي إعلانات ولا أدوات تحليلات أو تتبع من أطراف ثالثة. ولا نبيع أو نؤجر أو نتاجر بأي بيانات شخصية.
٥. مشاركة البيانات
- Google: فقط عند اختياركم تسجيل الدخول عبر Google، وفق سياسة خصوصية Google.
- مؤسستكم: البيانات المالية التي تدخلونها تُخزن في قاعدة بيانات ERP الخاصة بمؤسستكم وتخضع لسياساتها الداخلية.
- قد نفصح عن بيانات إذا ألزمنا القانون بذلك.
- لا يستلم أي طرف ثالث آخر بياناتكم.
٦. أمان البيانات
- جميع الاتصالات مشفرة عبر HTTPS/TLS.
- تُخزن بيانات الاعتماد ومواد الترخيص فقط في التخزين الآمن للجهاز (Android Keystore / iOS Keychain).
- استجابات خادم الترخيص موقعة تشفيرياً (Ed25519) ويتحقق التطبيق منها.
- الوصول إلى بيانات الأعمال يتطلب حساباً مؤسسياً صالحاً وترخيص برنامج صالحاً معاً.
٧. الاحتفاظ بالبيانات وحذفها
- تُحفظ سجلات الدخول والترخيص طوال فترة اشتراك مؤسستكم ولفترة معقولة بعدها لأغراض التدقيق الأمني والالتزام القانوني.
- تحتفظ مؤسستكم بالسجلات المحاسبية وفق سياساتها الخاصة.
- لطلب حذف بياناتكم الشخصية (الاسم والبريد الإلكتروني وتفعيل الجهاز) راسلونا على support@ayancodex.com. تُنفذ الطلبات خلال 30 يوماً ما لم يكن الاحتفاظ مطلوباً قانوناً.
- إلغاء تثبيت التطبيق يزيل جميع بيانات الاعتماد والبيانات المخزنة محلياً من جهازكم.
٨. خصوصية الأطفال
التطبيق أداة عمل للموظفين البالغين المصرح لهم، وليس موجهاً للأطفال دون 13 عاماً، ولا نجمع بيانات منهم عن قصد.
٩. التغييرات على هذه السياسة
قد نحدّث هذه السياسة من وقت لآخر، وستظهر التغييرات الجوهرية في هذه الصفحة مع تاريخ سريان محدث.
١٠. التواصل معنا
لأي استفسارات أو طلبات تتعلق بالخصوصية:
- البريد الإلكتروني: support@ayancodex.com
- المطوّر: AYAN Codex