سياسة الخصوصية وحماية البيانات

منصة مُلِمّ التعليمية | آخر تحديث: 28 يونيو 2026

تُطبق هذه السياسة وفق قانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020 ولائحته التنفيذية الصادرة بقرار رقم 816 لسنة 2025، وأي متطلبات أو قرارات واجبة التطبيق تصدر عن مركز حماية البيانات الشخصية.

تُشغِّل منصة "مُلِمّ" شركة Mollim for Electronic Marketing Service، وتُعد الشركة المتحكم في البيانات الشخصية التي تحدد أغراض ووسائل معالجتها من خلال التطبيق والموقع والخدمات المرتبطة بهما.

توضح هذه السياسة البيانات التي نجمعها عن الطلاب والمدرسين والزوار، ومصادرها، وأغراض استخدامها، والجهات التي قد تتلقاها، ومدة الاحتفاظ بها، والحقوق المتاحة لأصحاب البيانات.

باستخدام المنصة أو إنشاء حساب، تقر بأنك اطلعت على هذه السياسة. وعندما تكون الموافقة هي الأساس القانوني للمعالجة، سنطلبها بصورة منفصلة وواضحة ويمكنك سحبها وفقًا لما توضحه هذه السياسة.

1. نطاق السياسة ومصادر البيانات

تسري هذه السياسة على استخدام تطبيق وموقع "مُلِمّ"، وعمليات إنشاء الحساب والحجز والدفع والدعم والتقييم والإشعارات وأي خدمات مرتبطة بالمنصة.

نحصل على البيانات من:

  • المستخدم مباشرة عند التسجيل أو استكمال الملف الشخصي أو رفع المستندات أو التواصل مع الدعم.
  • استخدام المنصة، مثل سجلات الدخول والحجز والدفع والتفاعل والأخطاء التقنية.
  • مدرس أو طالب آخر عندما يكون ذلك لازمًا لتنفيذ حجز أو شكوى أو نزاع.
  • مزودي تسجيل الدخول والدفع والإشعارات والتحليلات وغيرهم من مقدمي الخدمات، في الحدود اللازمة لتقديم الخدمة.

2. البيانات التي نجمعها

أ. بيانات الحساب والتحقق

  • الاسم، البريد الإلكتروني، رقم الهاتف، نوع الحساب، اللغة المفضلة، وصورة الملف الشخصي.
  • بيانات تسجيل الدخول والتحقق والأمان، بما في ذلك كلمة المرور المحفوظة بصيغة مجزأة، وحالة التحقق، ومحاولات الدخول، ومعرفات تسجيل الدخول عبر Google أو Facebook أو Apple عند استخدام هذه الخيارات.

ب. بيانات المدرسين

  • تاريخ الميلاد، النوع، المحافظة والمدينة، السيرة الذاتية، الخبرة، التخصصات، المستويات التعليمية، الجداول والأسعار والروابط المهنية أو الاجتماعية.
  • مستندات التحقق، مثل صورة بطاقة الهوية، صورة شخصية مع البطاقة، الشهادات والمؤهلات، وحالة ونتيجة مراجعة الاعتماد.

ج. بيانات الطلاب

  • تاريخ الميلاد، النوع، المحافظة والمدينة، المرحلة والسنة التعليمية، المواد المفضلة، وبيانات الملف التعليمي.

د. بيانات الحجز والدفع والمحفظة

  • تفاصيل الحصص والباقات والمواعيد والحضور والإلغاء والاسترداد والتقييمات والشكاوى.
  • قيمة المعاملة، العملة، وسيلة الدفع، حالة الدفع، معرف العملية لدى مزود الدفع، وسجلات التسوية والتحويل.
  • بيانات الحساب البنكي أو المحفظة الإلكترونية اللازمة لتحويل مستحقات المدرسين.
تُعالج بيانات بطاقات الدفع الكاملة بواسطة مزود الدفع المعتمد. لا تخزن "مُلِمّ" رقم البطاقة الكامل أو رمز الأمان الخاص بها على خوادمها.

هـ. المحتوى والدعم

  • التقييمات، الشكاوى، طلبات الدعم، المراسلات، المرفقات، والسبب الاختياري لطلب حذف الحساب.

و. البيانات التقنية وبيانات الجهاز

  • عنوان بروتوكول الإنترنت، نوع الجهاز ونظام التشغيل وإصدار التطبيق، معرفات الجلسة والطلب، أوقات الاستخدام، وسجلات الأخطاء والأداء والأمان.
  • رمز الإشعارات، نوع الجهاز واسمه، والموضوعات المشترك بها عند تفعيل الإشعارات.
  • ملفات تعريف الارتباط أو المعرفات المشابهة المستخدمة لتشغيل الموقع وتأمين الجلسات وقياس الأداء.

3. أغراض استخدام البيانات

  • إنشاء الحساب وتسجيل الدخول والتحقق من الهوية وإدارة الملف الشخصي.
  • عرض المدرسين وإدارة الحجز والجداول والحضور والتقييمات والشكاوى.
  • تنفيذ المدفوعات والاستردادات والتسويات وتحويل مستحقات المدرسين ومكافحة الاحتيال.
  • إرسال رسائل التحقق والأمان والحجز والدعم والإشعارات التشغيلية.
  • تخصيص تجربة الاستخدام، مثل اللغة والمستوى والمواد ذات الصلة.
  • قياس أداء المنصة، وتشخيص الأعطال، وتحسين الجودة والاعتمادية والأمان.
  • إنفاذ شروط الاستخدام، والتحقيق في المخالفات، وتسوية النزاعات، وحماية حقوق المنصة والمستخدمين.
  • الامتثال للالتزامات القانونية والتنظيمية والمحاسبية والضريبية وأوامر الجهات المختصة.

4. الأسس القانونية للمعالجة

نعالج البيانات فقط عند توافر أساس قانوني مناسب، وقد يشمل ذلك:

  • تنفيذ العقد: عندما تكون المعالجة ضرورية لإنشاء الحساب أو تنفيذ الحجز أو الدفع أو تقديم الدعم.
  • الموافقة: للمعالجة الاختيارية أو التسويق المباشر أو الإشعارات الاختيارية أو معالجة البيانات الحساسة حيث يلزم ذلك.
  • الالتزام القانوني: للاحتفاظ بالسجلات أو الإفصاح للجهات المختصة أو تنفيذ حكم أو أمر قانوني.
  • المصلحة المشروعة: لتأمين المنصة، ومنع الاحتيال، وتحسين الخدمة، وإدارة المطالبات، بشرط ألا تتغلب هذه المصالح على حقوق وحريات صاحب البيانات.
  • إثبات الحقوق أو الدفاع عنها: عند إدارة شكوى أو نزاع أو مطالبة قانونية.

إذا سحبت موافقتك، فلا يؤثر ذلك على مشروعية المعالجة التي تمت قبل السحب، وقد نستمر في معالجة بعض البيانات إذا وجد أساس قانوني آخر.

5. التحليلات وتشخيص الأعطال والإشعارات

قد نستخدم الخدمات التالية عند تفعيلها:

  • Google Analytics for Firebase / GA4: لقياس أحداث الاستخدام والحجز والدفع والاسترداد. تُرسل معرفات حساب تقنية وبيانات معاملة محدودة، وتُعطل الإعلانات المخصصة في القياسات المرسلة من الخادم.
  • Firebase Cloud Messaging: لإرسال الإشعارات باستخدام رمز الجهاز وتفضيلات الاشتراك.
  • Sentry: لتسجيل الأعطال والأخطاء ومؤشرات الأداء مع تعطيل إرسال البيانات الشخصية الافتراضية، وقد يتضمن السجل معرفًا تقنيًا للمستخدم ومسار الطلب بعد تنقيته.
  • Microsoft Clarity: لفهم تجربة الواجهة من خلال تسجيلات جلسات أو خرائط تفاعل عندما تكون هذه الخدمة مفعلة على واجهة تستخدمها.
لا نرسل عمدًا كلمات المرور، رموز التحقق، رموز المصادقة، أرقام بطاقات الدفع، روابط الدفع، نصوص المحادثات أو المستندات الشخصية إلى أدوات التحليل أو تشخيص الأعطال.

يمكنك إدارة الإشعارات من إعدادات التطبيق أو الجهاز، وإدارة ملفات الارتباط من إعدادات المتصفح. قد تكون بعض الملفات أو المعرفات ضرورية لتسجيل الدخول وتأمين الخدمة ولا يمكن تعطيلها دون التأثير على عملها.

6. مشاركة البيانات ومقدمو الخدمات

لا نبيع بياناتك: لا نبيع أو نؤجر البيانات الشخصية لأطراف ثالثة لاستخدامها في التسويق المستقل.

قد نشارك الحد الأدنى اللازم من البيانات مع:

  • الطلاب والمدرسين: لتنفيذ الحجز وإدارة الموعد والتواصل اللازم لتقديم الخدمة، دون مشاركة بيانات مالية أو مستندات تحقق.
  • مزودي الدفع والتحويل: مثل Fawaterak، لتنفيذ التحصيل والاسترداد والتحويل والتحقق من حالة المعاملة.
  • مزودي الاستضافة والتخزين: بما في ذلك خدمات قواعد البيانات وCloudinary لحفظ الصور والمرفقات والمستندات المرفوعة.
  • مزودي الاتصالات: مثل Firebase للإشعارات وResend للبريد الإلكتروني.
  • مزودي التحليل والأمان: مثل Google Analytics وSentry وMicrosoft Clarity عند تفعيلها.
  • المستشارين ومقدمي الدعم: في حدود ما يلزم للمحاسبة أو الدعم الفني أو القانوني وتحت التزامات مناسبة بالسرية.
  • الجهات الحكومية والقضائية: عندما يوجب القانون ذلك أو استجابة لأمر صحيح أو لحماية الحقوق ومنع الاحتيال والجرائم.
  • صفقة مؤسسية: عند الاندماج أو إعادة الهيكلة أو نقل النشاط، مع مراعاة استمرار حماية البيانات وإخطار المستخدمين عند اللزوم.

7. نقل البيانات خارج مصر

قد يعالج بعض مقدمي الخدمات بيانات في دول أخرى أو من خلال بنية سحابية موزعة. عند حدوث نقل دولي للبيانات، نلتزم بالمتطلبات والضمانات والتصاريح أو الموافقات الواجبة وفق القانون واللائحة التنفيذية وقرارات مركز حماية البيانات الشخصية، ونقصر النقل على البيانات اللازمة للغرض المحدد.

8. الاحتفاظ بالبيانات وحذف الحساب

  • نحتفظ ببيانات الحساب طوال مدة نشاطه، ثم للمدة اللازمة لإتمام التسويات والرد على الشكاوى والوفاء بالالتزامات القانونية وحماية الحقوق.
  • عند قبول طلب حذف الحساب، يتم تعطيل الحساب وإلغاء جلساته وحذف رموز الإشعارات المرتبطة به، ثم تُجدول إجراءات الحذف بعد انتهاء المراجعة والتسويات اللازمة.
  • قد نحتفظ بسجلات المعاملات والمدفوعات والاستردادات والشكاوى والأمان للمدد التي تفرضها القوانين أو تتطلبها المطالبات ومكافحة الاحتيال، حتى بعد حذف الحساب.
  • قد تبقى نسخ محدودة في النسخ الاحتياطية إلى أن تُستبدل وفق دورة النسخ المعتادة، مع تقييد استخدامها لأغراض الاستعادة والأمان.
  • يجوز الاحتفاظ بالبيانات المجمعة أو مجهولة الهوية التي لا تحدد شخصًا بعينه لأغراض الإحصاء والتحسين.

9. الأمان وحوادث البيانات

  • نطبق تدابير تقنية وتنظيمية مناسبة بحسب طبيعة البيانات، مثل التحكم في الصلاحيات، وتجزئة كلمات المرور، وتأمين الاتصالات، والتسجيل والمراقبة، والنسخ الاحتياطي، وتقليل البيانات.
  • يُقصر الوصول إلى البيانات الشخصية على من يحتاجها لأداء مهامه، مع مراجعة الوصول واتخاذ إجراءات عند الاشتباه في إساءة الاستخدام.
  • لا توجد وسيلة إلكترونية آمنة بنسبة مطلقة؛ لذلك نراجع تدابير الحماية ونحدثها وفق المخاطر والتطورات التقنية.
  • عند وقوع خرق للبيانات، نتخذ إجراءات الاحتواء والتحقيق والمعالجة، ونُخطر مركز حماية البيانات الشخصية وأصحاب البيانات المتأثرين وفق الحالات والمواعيد التي يحددها القانون.

10. حقوق صاحب البيانات

وفقًا للقانون، ومع مراعاة الاستثناءات والاحتفاظ الإلزامي، يمكنك طلب:

  • معرفة البيانات التي نعالجها وأغراض المعالجة والجهات التي قد تتلقاها.
  • الوصول إلى بياناتك والحصول على نسخة منها.
  • تصحيح البيانات غير الدقيقة أو استكمال البيانات الناقصة.
  • محو البيانات أو تقييد معالجتها عندما تتوافر الشروط القانونية.
  • سحب الموافقة أو الاعتراض على معالجة تقوم على الموافقة أو المصلحة المشروعة، والاعتراض على التسويق المباشر في أي وقت.
  • تقديم شكوى إلينا أو إلى مركز حماية البيانات الشخصية.

قد نطلب معلومات للتحقق من الهوية قبل تنفيذ الطلب، وسنرد خلال المدة القانونية. إذا تعذر تنفيذ الطلب كليًا أو جزئيًا، سنوضح السبب متى كان القانون يسمح بذلك.

12. التسويق المباشر وتفضيلات التواصل

  • نرسل الرسائل التشغيلية الضرورية، مثل التحقق من الحساب وتأكيد الحجز والدفع والأمان والدعم، لأنها لازمة لتقديم الخدمة.
  • لا نرسل رسائل تسويقية إلكترونية إلا وفق الموافقة والمتطلبات القانونية الواجبة، وتوضح الرسالة هوية المرسل والغرض منها ووسيلة مجانية وسهلة لإلغاء الاشتراك.
  • يمكنك سحب الموافقة على التسويق أو تعديل تفضيلات الإشعارات في أي وقت، دون أن يؤثر ذلك على الرسائل التشغيلية الضرورية.

13. خدمات وروابط الأطراف الثالثة

قد تتضمن المنصة روابط أو صفحات دفع أو خدمات مستقلة تديرها أطراف ثالثة. تخضع البيانات التي تقدمها مباشرة إلى تلك الجهات لسياسات الخصوصية الخاصة بها. نشجعك على مراجعة تلك السياسات، ولا تغطي هذه السياسة ممارسات المواقع أو الخدمات التي لا نتحكم فيها.

14. تحديثات هذه السياسة

قد نحدث هذه السياسة لتعكس تغييرات الخدمة أو المتطلبات القانونية أو ممارسات المعالجة. سننشر النسخة المحدثة مع تاريخ السريان، وسنرسل إشعارًا مناسبًا داخل التطبيق أو عبر البريد الإلكتروني عند وجود تغيير جوهري. إذا كان التغيير يتطلب موافقة جديدة، فلن نعتمد على الموافقة السابقة وحدها.

15. التواصل والشكاوى

لممارسة حقوقك أو للاستفسار عن الخصوصية أو الإبلاغ عن واقعة متعلقة بالبيانات، تواصل مع جهة الخصوصية في "مُلِمّ":

support@mail.mollim.cloud

© 2026 منصة مُلِمّ التعليمية (Mollim for Electronic Marketing Service). جميع الحقوق محفوظة.

خاضع للقوانين المصرية | محاكم القاهرة المختصة

Privacy and Data Protection Policy

Mollim Educational Platform | Last updated: 28 June 2026

This policy applies under Egyptian Personal Data Protection Law No. 151 of 2020, its Executive Regulations issued by Decision No. 816 of 2025, and any applicable requirements or decisions issued by the Personal Data Protection Center.

Mollim for Electronic Marketing Service operates the Mollim platform and acts as the data controller that determines the purposes and means of processing personal data through the app, website, and related services.

This policy explains the data we collect about students, teachers, and visitors; where it comes from; why we use it; who may receive it; how long we retain it; and the rights available to data subjects.

By using the platform or creating an account, you acknowledge that you have read this policy. Where consent is the legal basis for processing, we will request it separately and clearly, and you may withdraw it as described below.

1. Scope and Data Sources

This policy applies to the Mollim app and website and to account registration, booking, payment, support, reviews, notifications, and other platform-related services.

We obtain data from:

  • You directly when you register, complete a profile, upload documents, or contact support.
  • Your use of the platform, including login, booking, payment, interaction, and technical error records.
  • Another teacher or student when needed to fulfil a booking or handle a complaint or dispute.
  • Login, payment, notification, analytics, and other service providers to the extent necessary to provide the service.

2. Data We Collect

A. Account and Verification Data

  • Name, email address, phone number, account type, preferred language, and profile picture.
  • Login, verification, and security data, including hashed passwords, verification status, login attempts, and Google, Facebook, or Apple login identifiers when those options are used.

B. Teacher Data

  • Date of birth, gender, governorate and city, biography, experience, specializations, education levels, schedules, prices, and professional or social links.
  • Verification materials such as a national ID image, a photo holding the ID, certificates and qualifications, and verification review status and outcome.

C. Student Data

  • Date of birth, gender, governorate and city, education level and year, preferred subjects, and educational profile information.

D. Booking, Payment, and Wallet Data

  • Lesson and package details, schedules, attendance, cancellation, refunds, reviews, and complaints.
  • Transaction value, currency, payment method and status, provider transaction identifiers, and settlement and payout records.
  • Bank account or electronic wallet details needed to pay teacher earnings.
Full payment-card details are processed by the approved payment provider. Mollim does not store complete card numbers or card security codes on its servers.

E. Content and Support Data

  • Reviews, complaints, support requests, correspondence, attachments, and the optional reason supplied with an account deletion request.

F. Technical and Device Data

  • IP address, device type, operating system and app version, session and request identifiers, usage times, and error, performance, and security logs.
  • Notification token, device type and name, and subscribed topics when notifications are enabled.
  • Cookies or similar identifiers used to operate the website, secure sessions, and measure performance.

3. How We Use Data

  • Create accounts, authenticate users, verify identity, and manage profiles.
  • Display teachers and manage bookings, schedules, attendance, reviews, and complaints.
  • Process payments, refunds, settlements, and teacher payouts, and prevent fraud.
  • Send verification, security, booking, support, and operational notifications.
  • Personalize the experience, such as language, education level, and relevant subjects.
  • Measure platform performance, diagnose errors, and improve quality, reliability, and security.
  • Enforce the terms, investigate misuse, resolve disputes, and protect the rights of the platform and its users.
  • Comply with legal, regulatory, accounting, tax, and competent-authority requirements.

4. Legal Bases for Processing

We process data only where an appropriate legal basis is available, which may include:

  • Contractual necessity: where processing is needed to create an account, fulfil a booking or payment, or provide support.
  • Consent: for optional processing, direct marketing, optional notifications, or sensitive-data processing where consent is required.
  • Legal obligation: to keep required records, disclose information to competent authorities, or comply with a judgment or lawful order.
  • Legitimate interests: to secure the platform, prevent fraud, improve services, and manage claims, provided those interests do not override your rights and freedoms.
  • Establishing or defending legal rights: when handling a complaint, dispute, or legal claim.

Withdrawing consent does not affect processing lawfully performed before withdrawal. We may continue processing some data where another legal basis applies.

5. Analytics, Diagnostics, and Notifications

We may use the following services when enabled:

  • Google Analytics for Firebase / GA4: to measure usage, booking, payment, and refund events. Limited transaction metadata and technical account identifiers may be sent, and server-side measurements disable personalized advertising.
  • Firebase Cloud Messaging: to deliver notifications using a device token and subscription preferences.
  • Sentry: to record crashes, errors, and performance diagnostics with default personal-data collection disabled. Reports may contain a technical user identifier and a sanitized request path.
  • Microsoft Clarity: to understand interface use through session recordings or interaction heatmaps where enabled on an interface you use.
We do not intentionally send passwords, OTPs, authentication tokens, payment-card numbers, payment URLs, chat text, or personal documents to analytics or diagnostic tools.

You can manage notifications through app or device settings and cookies through browser settings. Some cookies or identifiers are necessary for login and security and cannot be disabled without affecting the service.

6. Data Sharing and Service Providers

We do not sell your data: we do not sell or rent personal data to third parties for their independent marketing.

We may share the minimum data necessary with:

  • Students and teachers: to fulfil a booking, manage the schedule, and communicate as needed for the lesson, without sharing financial details or verification documents.
  • Payment and payout providers: such as Fawaterak, to process collections, refunds, payouts, and transaction status checks.
  • Hosting and storage providers: including database services and Cloudinary for uploaded images, attachments, and documents.
  • Communication providers: such as Firebase for notifications and Resend for email.
  • Analytics and security providers: such as Google Analytics, Sentry, and Microsoft Clarity when enabled.
  • Advisers and support providers: where needed for accounting, technical support, or legal services and subject to appropriate confidentiality obligations.
  • Government and judicial authorities: where required by law, in response to a valid order, or to protect rights and prevent fraud or crime.
  • Corporate transactions: in a merger, restructuring, or business transfer, subject to continued data protection and notice where required.

7. International Data Transfers

Some service providers may process data in other countries or through distributed cloud infrastructure. Where an international transfer occurs, we apply the requirements, safeguards, and permits or approvals required by the law, Executive Regulations, and Personal Data Protection Center decisions, and limit the transfer to data necessary for the stated purpose.

8. Data Retention and Account Deletion

  • We retain account data while the account is active and then for as long as needed to complete settlements, respond to complaints, meet legal obligations, and protect legal rights.
  • When an account deletion request is accepted, the account is deactivated, active sessions are revoked, associated notification tokens are deleted, and deletion procedures are scheduled after required reviews and settlements.
  • Transaction, payment, refund, complaint, and security records may be retained for periods required by law or needed for claims and fraud prevention, even after account deletion.
  • Limited copies may remain in backups until replaced through the normal backup cycle, with use restricted to restoration and security.
  • Aggregated or anonymized data that no longer identifies an individual may be retained for statistics and service improvement.

9. Security and Data Incidents

  • We apply technical and organizational measures appropriate to the data, including access controls, password hashing, secure communications, logging and monitoring, backups, and data minimization.
  • Access to personal data is limited to those who need it for their work, with access review and action taken where misuse is suspected.
  • No electronic system is completely secure, so we review and update safeguards according to risk and technical developments.
  • If a personal data breach occurs, we take containment, investigation, and remediation steps and notify the Personal Data Protection Center and affected data subjects where and within the time required by law.

10. Your Data Rights

Subject to legal exceptions and mandatory retention, you may request:

  • Information about the data we process, the processing purposes, and potential recipients.
  • Access to and a copy of your personal data.
  • Correction of inaccurate data or completion of incomplete data.
  • Erasure of data or restriction of processing where legal conditions are met.
  • Withdrawal of consent or objection to processing based on consent or legitimate interests, and objection to direct marketing at any time.
  • Submission of a complaint to us or to the Personal Data Protection Center.

We may request information to verify your identity before fulfilling a request and will respond within the legally required period. If a request cannot be fulfilled in whole or in part, we will explain the reason where the law permits.

12. Direct Marketing and Communication Preferences

  • We send necessary operational messages, such as account verification, booking, payment, security, and support messages, because they are required to provide the service.
  • We send electronic marketing only in accordance with applicable consent and legal requirements. Marketing messages identify the sender and purpose and provide a free and easy opt-out method.
  • You may withdraw marketing consent or change notification preferences at any time without affecting necessary operational messages.

13. Third-Party Services and Links

The platform may contain links, payment pages, or independent services operated by third parties. Data you provide directly to those parties is governed by their privacy policies. We encourage you to review those policies; this policy does not cover websites or services we do not control.

14. Changes to This Policy

We may update this policy to reflect service, legal, or processing changes. We will publish the updated version with its effective date and provide appropriate in-app or email notice of material changes. If a change requires new consent, we will not rely on prior consent alone.

15. Contact and Complaints

To exercise your rights, ask a privacy question, or report a data-related incident, contact Mollim's privacy contact:

support@mail.mollim.cloud