سياسة الخصوصية — بلسم
آخر تحديث: ٢٤ آب ٢٠٢٦
نحن في بلسم نأخذ خصوصيتك على محمل
الجد. هذه السياسة توضّح ما نجمعه من بيانات، كيف نستعملها، ومتى
نتشاركها — للمستخدمين كمرضى، كادر طبي، أطباء، صيدليات، أو إداريين.
١. البيانات التي نجمعها
نجمع — حسب نوع المستخدم — ما يلي:
-
للمرضى: الاسم الكامل، رقم الهاتف،
العنوان (عند طلب خدمة منزلية)، صورة الملف الشخصي
(اختياري)، تاريخ الميلاد، الحساسيات والأمراض
المزمنة (اختيارية، لبطاقة الطوارئ).
-
الموقع الجغرافي: نستعمل موقعك الدقيق
(إحداثيات GPS) عند البحث عن كادر/صيدلية قريبة أو طلب خدمة
منزلية. وإذا فعّلت «مشاركة الموقع» أثناء تنفيذ خدمة، يُحدَّث
موقعك دورياً (كل بضع دقائق) ليتابعه مزوّد الخدمة المرتبط بطلبك
فقط. ولا يُقرأ موقعك إلا والتطبيق مفتوحٌ أمامك:
لا نطلب إذن الموقع في الخلفية ولا نتتبّعك والتطبيق مغلق،
ويتوقّف التحديث فور انتهاء الخدمة أو إيقافك للميزة أو إغلاقك التطبيق.
-
العائلة والمعالون: إذا أضفت أفراد عائلتك أو من
تعولهم، نعالج بياناتهم التي تزوّدنا بها (الاسم، صلة القرابة،
الحساسيات، الملاحظات الطبية) تحت مسؤوليتك وبتفويض
منك، ولغرض تقديم الرعاية لهم.
-
محتوى المحادثات داخل التطبيق: الرسائل المتبادلة
بينك وبين مزوّد الخدمة المرتبط بطلبك (نصوص وصور مرفقة)، تُحفَظ
لتقديم الخدمة وحلّ النزاعات، وتُحذَف مع حسابك.
-
للكادر الطبي والأطباء والصيادلة: الاسم، رقم الهاتف،
الجنس، التخصص (للأطباء)، اسم الصيدلية (للصيادلة)، صورة شخصية،
المؤهلات العلمية، إثبات الهوية، الموقع أثناء العمل.
-
الإداريون: الاسم، رقم الهاتف، نطاق الصلاحيات.
-
تلقائياً: Firebase Cloud Messaging token (لإشعارات
push)، نظام التشغيل، إصدار التطبيق، تقارير الأعطال (crash reports)
عبر Sentry (مجهَّلة قدر الإمكان).
ما لا نجمعه: أرقام البطاقات الائتمانية، الحسابات
البنكية، أرقام جوازات السفر، ولا البريد الإلكتروني ولا كلمات
المرور — فالدخول إلى بلسم برقم الهاتف وحدَه عبر رمزٍ لمرّةٍ
واحدة، ولا يُطلب منك بريدٌ ولا كلمةُ مرورٍ ولا يُخزَّن أيٌّ منهما.
١ب. السجلات الطبية والصحية
لتقديم الخدمة، تُخزَّن البيانات الطبية التالية على خوادمنا
(Supabase، محمية بـ Row Level Security ومتاحة لك ولمزوّدي الرعاية
الذين تمنحهم إذن الوصول فقط):
-
سجل الزيارات: التشخيص ورموز ICD-10،
نتائج الفحوصات المخبرية وصورها، العلامات الحيوية، والملاحظات
السريرية التي يُدخلها الطبيب.
-
متعقّبات الصحة (اختيارية): بيانات متابعة الحمل
(تاريخ آخر دورة، الموعد المتوقّع، الوزن، حركات الجنين، نتيجة
الولادة)، جدول لقاحات الأطفال (اسم الطفل، تاريخ الميلاد،
الحساسيات، مواعيد اللقاحات).
-
بطاقة الطوارئ (SOS): الحساسيات، الأمراض
المزمنة، وجهة اتصال الطوارئ — لعرضها عند الحاجة.
-
التحكم بالوصول (Consents): نحتفظ بسجلّ
بالأطباء الذين منحتهم إذن الاطلاع على سجلّك الطبي وتواريخ المنح
والإلغاء؛ يمكنك سحب الإذن في أي وقت من التطبيق.
هذه البيانات تُحذَف عند حذف حسابك وفق القسم
٤. مدة الاحتفاظ (باستثناء ما يفرض
القانون الاحتفاظ به، مثل سجل المواد الخاضعة للرقابة لدى الصيدليات).
١أ. بيانات الصيدليات (Pharmacy Data)
إذا كنت تستعمل بلسم كحساب صيدلية، نعالج بيانات إضافية مرتبطة
بنشاط الصيدلية، وفق ما يلي:
-
بيانات العملاء: اسم العميل، رقم الهاتف، تاريخ
الشراء، تاريخ التسليم. تُحفَظ في جداول الصيدلية الخاصة
بحسابك (RLS-isolated) ولا تتم مشاركتها مع صيدليات أخرى.
-
تاريخ المشتريات: الأصناف المُسلَّمة لكل عميل،
الكميات، الأسعار. مرتبطة بـ pharmacy_id الخاص بحسابك فقط.
-
سجل المواد الخاضعة للرقابة (Controlled Substance Log):
مطلوب قانونياً، يُحتفَظ به لمدة تحدّدها الجهة التنظيمية المحلية
(عادة ٧ سنوات). لا يُحذَف عند حذف الحساب الشخصي للصيدلاني.
-
الأرصدة والديون (Credit Balance): الرصيد
المُستحَق على عملاء الصيدلية بالدينار العراقي (IQD). تُحفَظ
محلياً على خوادمنا فقط لخدمة عمليات الصيدلية.
-
الفواتير وسجل المبيعات: تُخزَّن بـ IQD،
مرتبطة بـ pharmacy_id ولا يطّلع عليها سوى المالك والصيدلانيين
المخوّلين.
-
وثائق الترخيص: صور الترخيص، الهوية، شهادات
المؤهل تُستعمل لأغراض التحقق فقط، ولا تُشارَك مع أي طرف.
مدد الاحتفاظ التفصيلية موضّحة في القسم
٤. مدة الاحتفاظ وفي
صفحة حذف الحساب.
٢. كيف نستعمل بياناتك
-
تشغيل الخدمة: ربط المرضى بالأطباء/الصيادلة/الكادر،
إرسال إشعارات الطلبات، عرض الحركات في لوحة الإدارة.
-
السلامة: اكتشاف الاستخدام المسيء، منع spam، تنبيهات
SOS.
-
التحسين: تحليل crashes (Sentry) لإصلاح الأعطال
بدون تتبّع شخصي.
لا نستعمل بياناتك للإعلانات. بلسم لا يحوي أي
طبقة إعلانية، ولا يبيع بياناتك لأي طرف ثالث.
٣. متى نشارك بياناتك
-
مع المستخدمين الآخرين في النظام فقط بقدر ما يلزم
لأداء الخدمة (مثلاً عرض اسم المريض على الطبيب الحاجز).
-
مزوّدو البنية التحتية: Supabase (DB)، Firebase
(FCM)، Sentry (crash reporting). جميعهم ملتزمون بضمانات حماية
تعاقدية بمعايير الصناعة (Data Processing Agreements).
-
السلطات القضائية فقط عند طلب رسمي وفقاً للقانون
المحلي.
لا نبيع بياناتك ولا نؤجّرها ولا نتاجر بها. ولا
تُشارَك بياناتك الصحّية مع أيّ طرفٍ لأغراض الإعلان أو التسويق أو
بناء ملفّاتٍ إعلانيّة — لا الآن ولا مستقبلاً.
٣أ. مزوّدو خدمة معالجة البيانات
-
Supabase — قاعدة البيانات الرئيسية وتخزين
الملفات (RLS-protected).
-
Firebase Cloud Messaging (FCM) — لإرسال
إشعارات push.
-
Sentry — تقارير الأعطال والأداء (مجهَّلة قدر
الإمكان، لإصلاح الأعطال فقط).
-
Apple App Store / Google Play — توزيع التطبيق
ومعالجة المراجعات؛ لا نتحكم بسياساتهم.
كل هؤلاء يعالجون البيانات نيابة عنّا (data processors)، وليس
لهم صلاحية استعمالها لأغراضهم الخاصة.
٤. مدة الاحتفاظ
- الحساب نشط: نحتفظ بكل البيانات.
-
عند حذف الحساب: نمسح كل البيانات الشخصية خلال ٣٠ يوم
(يبقى نسخ احتياطي مشفَّر لـ ٩٠ يوم لاسترداد الحوادث).
- logs مجهَّلة (بدون PII): تُحفَظ ١٢ شهر لتحليل الأمان.
-
سجلات الفواتير (الصيدليات): تُحفَظ للمدة التي
يفرضها الالتزام الضريبي/المحاسبي المحلي.
-
سجل المواد الخاضعة للرقابة: حسب القانون
المحلي (عادة ٧ سنوات).
٤أ. النقل عبر الحدود
تُخزَّن بياناتك لدى Supabase على بنية AWS في منطقة
مومباي / الهند (ap-south-1). قد تُعالَج إشعارات
الـ push عبر خوادم Firebase/Google Cloud. بما أنك قد تستعمل
التطبيق من خارج هذه المنطقة، فإنك توافق على نقل بياناتك ومعالجتها
هناك. كل عمليات النقل تتم بتشفير TLS 1.2+ مع
ضمانات تعاقدية مع المعالجين.
٥. الأمان
- كل الاتصالات مشفَّرة بـ HTTPS/TLS 1.2+.
-
الـ Supabase API مع Certificate Pinning للحماية من
MITM.
-
الـ session تُخزَّن في Keystore (Android) أو
Keychain (iOS) ولا يُسمَح بـ Auto Backup.
-
النسخ الاحتياطية للصيدلية تُشفَّر قبل كتابتها على القرص بـ
AES-256-GCM ومفتاحٍ مشتقٍّ بـ
PBKDF2 (600,000 دورة) من عبارة مرورٍ تختارها أنت
ولا نحتفظ بها — فمن يفقد العبارة يفقد النسخة، ونحن لا نستطيع فتحها.
-
التحقق على مستوى DB عبر Row Level Security (RLS) —
٦٠ جدول بسياسات صارمة.
-
الإشعارات الحسّاسة تُحقَّق role server-side قبل التوجيه.
٦. حقوقك
أنت تملك الحق في:
-
الوصول لبياناتك — اكتب لـ
support@balsam.online
-
تصحيح البيانات — يمكنك تعديل ملفك من داخل التطبيق
أو طلب تصحيح بريدياً.
-
حذف الحساب نهائياً — متوفر داخل التطبيق
(الإعدادات → حذف الحساب) أو بريدياً.
-
تنزيل نسخة من بياناتك (data portability) — اطلبها
بريدياً.
- الاعتراض على معالجة بياناتك.
٦أ. حذف الحساب
يمكنك حذف حسابك بأي من الطريقتين:
٧. الأطفال
بلسم مخصّص للبالغين ١٨ سنة فأكثر؛ وبتسجيلك تُقِرّ
أنك بالغ ١٨ سنة فأكثر. لا نجمع عمداً أي بيانات من قاصرين كمستخدمين،
ولو علمنا أن مستخدماً قاصر سجّل، نمسح حسابه فوراً.
أما البيانات الصحية للأطفال (مثل جدول لقاحات طفلك
أو متعقّب الحمل) فيُدخلها الوالد أو الوصيّ البالغ على مسؤوليته
ولغرض الرعاية فقط، وتُعامَل بنفس مستوى الحماية في هذه السياسة،
وتُحذَف عند حذف حساب الوالد. أولياء الأمور يمكنهم التواصل معنا
لطلب الوصول أو الحذف في أي وقت.
٨. تغييرات السياسة
قد نُحدّث هذه السياسة. أي تغيير جوهري يُعلَن داخل التطبيق قبل
التطبيق بـ ٣٠ يوم. استمرارك في استعمال التطبيق بعد سريان التحديث
يعني قبولك.
للأسئلة عن الخصوصية أو طلبات البيانات:
Privacy Policy — Balsam
Last updated: 24 August 2026
At Balsam we take your privacy seriously.
This policy explains what data we collect, how we use it, and when we
share it — for users as patients, medical staff, doctors, pharmacies, or
administrators.
1. Data We Collect
Depending on the type of user, we collect the following:
-
For patients: full name, phone number,
address (when requesting a home service), profile photo (optional),
date of birth, allergies and chronic conditions (optional,
for the emergency card).
-
Location: we use your precise location (GPS
coordinates) when searching for nearby staff or a pharmacy, or when
requesting a home service. If you enable location sharing during a
service, your location is updated periodically (every few minutes) so
that only the provider attached to your request can follow it. Your
location is only ever read while the app is open in front of you:
we do not request background location permission and we do
not track you while the app is closed. Updates stop as soon
as the service ends, you turn the feature off, or you close the app.
-
Family and dependants: if you add family members or
dependants, we process the data you provide about them (name,
relationship, allergies, medical notes) under your
responsibility and authorisation, for the purpose of providing them
care.
-
In-app chat content: messages exchanged between you
and the provider attached to your request (text and attached images)
are stored to deliver the service and resolve disputes, and are deleted
with your account.
-
For medical staff, doctors, and pharmacists: name,
phone number, gender, specialty (for doctors), pharmacy name (for
pharmacists), profile photo, qualifications, proof of identity, and
location while working.
-
Administrators: name, phone number, and scope of permissions.
-
Automatically: a Firebase Cloud Messaging token (for
push notifications), operating system, app version, and crash reports
via Sentry (anonymised as far as possible).
What we do not collect: credit-card numbers, bank
accounts, passport numbers, and neither email addresses nor
passwords — signing in to Balsam uses your phone number alone
via a one-time code. We never ask for an email address or a password,
and we store neither.
1b. Medical and Health Records
To deliver the service, the following medical data is stored on our
servers (Supabase, protected by Row Level Security and available only to
you and the care providers you grant access to):
-
Visit history: diagnosis and ICD-10 codes,
laboratory results and their images, vital signs, and the clinical
notes entered by the doctor.
-
Health trackers (optional): pregnancy tracking data
(last menstrual period, expected date, weight, fetal movements,
delivery outcome), the childhood vaccination schedule (child's name,
date of birth, allergies, vaccination dates).
-
Emergency card (SOS): allergies, chronic
conditions, and an emergency contact — displayed when needed.
-
Access control (consents): we keep a record of the
doctors you have granted access to your medical file, with the dates of
grant and revocation; you may withdraw access at any time from the app.
This data is deleted when you delete your account, in accordance with
section 4. Retention — except for what the
law requires us to keep, such as the controlled-substance log held by
pharmacies.
1a. Pharmacy Data
If you use Balsam as a pharmacy account, we process additional data
related to the pharmacy's activity, as follows:
-
Customer data: customer name, phone number, purchase
date, and delivery date. Stored in your account's own pharmacy tables
(RLS-isolated) and never shared with other pharmacies.
-
Purchase history: the items delivered to each
customer, quantities, and prices — linked only to your account's
pharmacy_id.
-
Controlled Substance Log: legally required, retained
for the period set by the local regulator (typically 7 years). It is
not deleted when the pharmacist's personal account is deleted.
-
Credit balances: amounts owed by the pharmacy's
customers in Iraqi dinars (IQD). Stored on our servers solely to serve
the pharmacy's operations.
-
Invoices and sales records: stored in IQD, linked to
pharmacy_id and visible only to the owner and authorised pharmacists.
-
Licence documents: images of the licence, identity,
and qualification certificates are used for verification only and are
never shared with any party.
Detailed retention periods are set out in section
4. Retention and on the
account deletion page.
2. How We Use Your Data
-
Operating the service: connecting patients with
doctors, pharmacists, and staff; sending booking and service
notifications; displaying activity in the admin dashboard.
-
Safety: detecting abusive use, preventing spam, and
SOS alerts.
-
Improvement: analysing crashes (Sentry) to fix
failures, without personal tracking.
We do not use your data for advertising. Balsam contains
no advertising layer and does not sell your data to any third party.
3. When We Share Your Data
-
With other users in the system only to the extent
required to deliver the service (for example, showing the patient's
name to the booked doctor).
-
Infrastructure providers: Supabase (database),
Firebase (FCM), Sentry (crash reporting). All are bound by
industry-standard contractual protections (Data Processing Agreements).
-
Judicial authorities only upon an official request
made in accordance with local law.
We do not sell, rent, or trade your data. Your health
data is never shared with anyone for advertising, marketing, or
ad-profiling purposes — now or in the future.
3a. Data Processors
-
Supabase — the primary database and file storage
(RLS-protected).
-
Firebase Cloud Messaging (FCM) — sending push
notifications.
-
Sentry — crash and performance reports (anonymised as
far as possible, used only to fix failures).
-
Apple App Store / Google Play — distributing the
application and processing reviews; we do not control their policies.
All of these process data on our behalf (data processors) and have no
authority to use it for their own purposes.
4. Retention
- While the account is active: we retain all data.
-
On account deletion: we erase all personal data within
30 days (an encrypted backup remains for 90 days for
incident recovery).
- Anonymised logs (no PII): retained for 12 months for security analysis.
-
Invoice records (pharmacies): retained for the period
required by local tax and accounting obligations.
-
Controlled Substance Log: as required by local
pharmaceutical law (typically 7 years).
4a. Cross-Border Transfer
Your data is stored with Supabase on AWS infrastructure in the
Mumbai / India (ap-south-1) region. Push notifications
may be processed through Firebase / Google Cloud servers. Because you may
use the application from outside this region, you consent to your data
being transferred and processed there. All transfers use
TLS 1.2+ encryption with contractual guarantees from the
processors.
5. Security
- All connections are encrypted with HTTPS/TLS 1.2+.
-
The Supabase API uses certificate pinning to protect
against man-in-the-middle attacks.
-
Sessions are stored in the Keystore (Android) or
Keychain (iOS), with auto-backup disabled.
-
Pharmacy backups are encrypted before they are written to disk with
AES-256-GCM under a key derived via
PBKDF2 (600,000 iterations) from a passphrase you
choose and we never store — lose the passphrase and the backup is
unrecoverable, by us included.
-
Authorisation is enforced at the database level through
Row Level Security (RLS) — 60 tables with strict
policies.
- Sensitive notifications have their role verified server-side before routing.
6. Your Rights
You have the right to:
-
Access your data — write to
support@balsam.online
-
Correct your data — you can edit your profile inside
the app or request a correction by email.
-
Delete your account permanently — available inside the
app (Settings → Delete account) or by email.
-
Download a copy of your data (data portability) —
request it by email.
- Object to the processing of your data.
6a. Account Deletion
You can delete your account in either of two ways:
-
From inside the app:
Settings → My account → Delete account.
-
On the web:
balsamiqone.web.app/account-deletion
(with details of what is deleted and what is retained for legal
reasons).
7. Children (COPPA / GDPR-K)
Balsam is intended for adults aged 18 and over; by
registering you confirm that you are 18 or older. We do not knowingly
collect data from minors as users, and if we learn that a minor has
registered we delete the account immediately.
Children's health data (such as your child's vaccination
schedule or the pregnancy tracker) is entered by the adult parent or
guardian, under their responsibility and for the purpose of care only. It
receives the same level of protection described in this policy and is
deleted when the parent's account is deleted. Parents may contact us to
request access or deletion at any time.
8. Changes to This Policy
We may update this policy. Any material change is announced inside the
app 30 days before it takes effect. Your continued use of the application
after the update takes effect means you accept it.
For privacy questions or data requests:
© ٢٠٢٦ بلسم · Balsam. جميع الحقوق محفوظة.