الاتفاقية التي تحكم معالجة ستافلي للبيانات الشخصية نيابةً عن مؤسستك، بـالتزاماتٍ ومسؤولياتٍ واضحة وفق نظام حماية البيانات الشخصية السعودي (PDPL).The agreement governing how Staffly processes personal data on your organization's behalf, with clear obligations and accountability under the Saudi Personal Data Protection Law (PDPL).
نموذج أولي للمراجعة القانونية قبل التوقيع. هذه الاتفاقية نموذج استرشادي أُعدّ بصيغةٍ نظامية معتادة لاتفاقيات معالجة البيانات في المملكة العربية السعودية، ولم تتم مراجعتها أو اعتمادها من قِبل مستشارٍ قانوني مرخّص. يجب مراجعتها واعتمادها قانونيًا قبل توقيعها أو الاعتماد عليها كوثيقةٍ ملزمة.Template — review with legal counsel before signing. This agreement is a drafting aid prepared in a standard KSA-appropriate DPA structure. It has not been reviewed or ratified by licensed legal counsel, and must be reviewed and approved by qualified counsel before it is signed or relied upon as a binding document.
تشكّل اتفاقية معالجة البيانات هذه ("الاتفاقية") جزءًا لا يتجزأ من شروط خدمة ستافلي المبرمة بين المؤسسة المشتركة ("المتحكم في البيانات"، "المنشأة"، "أنتم") ومؤسسة ستافلي إي أر بي ("معالج البيانات"، "ستافلي"). تُحدّد المنشأة أغراض ووسائل معالجة البيانات الشخصية لموظفيها وأصحاب البيانات الآخرين، بينما تعالج ستافلي هذه البيانات بصفتها معالجًا فحسب، وبناءً على تعليمات المنشأة الموثّقة.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Staffly Terms of Service between the subscribing organization ("Controller", "Tenant", "you") and Staffly ERP Est. ("Processor", "Staffly"). The Controller determines the purposes and means of processing personal data of its employees and other data subjects; Staffly processes that data solely as a processor, on the Controller's documented instructions.
تقديم منصة ستافلي لتخطيط موارد المنظمة وإدارة القوى العاملة (الحضور، الرواتب، الإجازات، شؤون الموظفين، والوحدات الأخرى التي تُفعّلها المنشأة).
طوال سريان اتفاقية الخدمة، بالإضافة إلى أي فترة احتفاظٍ يفرضها النظام أو المادة ٩ أدناه.
التخزين، والاسترجاع، والتنظيم، والهيكلة، والنقل، والحذف، بالقدر اللازم لتشغيل وحدات المنصة التي فعّلتها المنشأة.
موظفو المنشأة، والمتقدمون للوظائف، والمتعاقدون، وذوو الموظفين حيثما فُعِّلت الوحدات ذات الصلة.
Provision of the Staffly workforce-management and HR ERP platform (attendance, payroll, leave, employee affairs, and any other module the Controller enables).
For as long as the service agreement is in force, plus any retention period required by law or set out in Section 9 below.
Storage, retrieval, organization, structuring, transmission, and deletion of personal data as necessary to deliver the modules the Controller has enabled.
The Controller's employees, job applicants, and contractors, and their dependents where the relevant module is enabled.
تلتزم ستافلي بما يلي:
Staffly will:
تمنح المنشأة ستافلي تصريحًا عامًا بإشراك معالجين فرعيين لتقديم خدمات البنية التحتية والاستضافة والدعم اللازمة لتشغيل المنصة، بشرط التزام كل معالجٍ فرعي بشروط حماية بياناتٍ لا تقل صرامةً عن هذه الاتفاقية. تبقى ستافلي مسؤولةً بالكامل عن أفعال وإغفالات أي معالجٍ فرعي. تحتفظ ستافلي بقائمةٍ محدَّثة بالمعالجين الفرعيين، وتُخطر المنشأة بأي إضافةٍ أو استبدالٍ مُزمَع، مع منحها فرصةً معقولة للاعتراض لأسبابٍ متعلقة بحماية البيانات.
The Controller grants Staffly general authorization to engage sub-processors for the hosting, infrastructure, and support functions necessary to deliver the platform (e.g. cloud infrastructure providers), provided each sub-processor is bound by data-protection terms no less protective than this DPA. Staffly remains fully liable for a sub-processor's acts and omissions. Staffly maintains a current list of sub-processors and will notify the Controller of any intended addition or replacement, giving the Controller a reasonable opportunity to object on data-protection grounds.
مع مراعاة طبيعة المعالجة، تُقدّم ستافلي للمنشأة مساعدةً تقنية وتنظيمية معقولة للوفاء بالتزامها بالاستجابة لطلبات أصحاب البيانات الممارسين لحقوقهم بموجب PDPL (الاطلاع، والتصحيح، والحذف، والاعتراض، والتقييد) — بما في ذلك من خلال ميزاتٍ في المنصة تُتيح لمسؤولي المنشأة الاطلاع على البيانات أو تصحيحها أو تصديرها أو حذفها مباشرةً حيثما أمكن ذلك تقنيًا.
Taking into account the nature of processing, Staffly will provide the Controller with reasonable technical and organizational assistance to fulfil its obligation to respond to data subjects exercising their PDPL rights (access, correction, deletion, objection, and restriction) — including through platform features that let the Controller's administrators view, correct, export, or delete personal data directly wherever technically feasible.
تطبّق ستافلي تدابير تقنية وتنظيمية تشمل:
Staffly applies technical and organizational measures including:
عند علم ستافلي بحدوث خرقٍ للبيانات الشخصية التي تعالجها نيابةً عن المنشأة، تُخطر المنشأة دون تأخيرٍ لا مبرر له، وفي جميع الأحوال خلال ٧٢ ساعة من العلم، مع وصف طبيعة الخرق، وفئات وأعداد أصحاب البيانات والسجلات المتأثرة تقريبيًا، والآثار المحتملة، والتدابير المُتخذة أو المقترحة لمعالجته — بما يُمكِّن المنشأة من الوفاء بالتزاماتها في الإخطار الخاصة بها تجاه الجهات المختصة وأصحاب البيانات المتأثرين وفق PDPL.
If Staffly becomes aware of a personal data breach affecting data it processes on the Controller's behalf, it will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, describing the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed — so the Controller can meet its own notification obligations to the competent authority and affected data subjects under the PDPL.
الموقف التشغيلي لستافلي هو تخزين ومعالجة البيانات داخل المملكة العربية السعودية حيثما أمكن ذلك تقنيًا. حيثما تطلّبت وظيفةٌ محدودة من المعالجة مكوّنًا خدميًا خارج المملكة، يخضع ذلك النقل للضمانات التي تفرضها المادة ٢٩ من PDPL (أساسٌ قانوني موثّق، ومستوى حماية كافٍ أو ضمانات تعاقدية، وسجل تدقيق) — راجع صفحة الامتثال لنظام PDPL للتفصيل.
Staffly's operating posture is in-Kingdom data residency: personal data is stored and processed within Saudi Arabia wherever technically feasible. Where a limited processing function must use a service component located outside the Kingdom, that transfer is made subject to the safeguards required under PDPL Article 29 (documented legal basis, an adequate level of protection or contractual safeguards, and an audit trail) — see the PDPL Compliance page for detail.
تعالج ستافلي البيانات الشخصية وتحتفظ بها طوال مدة اتفاقية الخدمة فقط، بالإضافة إلى أي مدةٍ يفرضها النظام المعمول به (كمتطلبات الاحتفاظ بسجلات الرواتب والعمل). عند إنهاء اتفاقية الخدمة، وبحسب اختيار المنشأة، تُعيد ستافلي بياناتها بصيغةٍ قابلةٍ للاستخدام و/أو تحذفها (بما في ذلك من النسخ الاحتياطية خلال دورةٍ تشغيلية معقولة) خلال ٣٠ يومًا، إلا في الحالات التي يفرض فيها النظام الاحتفاظ بها.
Staffly processes and retains personal data only for the duration of the service agreement, plus any period required by applicable law (e.g. statutory payroll/labor-record retention). On termination of the service agreement, at the Controller's choice, Staffly will return the Controller's data in a usable exported format and/or delete it (including from backups within a reasonable operational cycle) within 30 days, except where retention is required by law.
بإشعارٍ كتابي مسبق ومعقول، وبحدٍ أقصى مرةً واحدة سنويًا (أو عقب خرقٍ مؤكَّد للبيانات الشخصية)، يجوز للمنشأة طلب معلوماتٍ تُثبت امتثال ستافلي لهذه الاتفاقية، بما يشمل تقارير تدقيقٍ ذات صلة أو شهادات أمنية أو ملخص تدقيق. تُتيح ستافلي هذه المعلومات، أو تتعاون بشكلٍ معقول مع تدقيقٍ ميداني عند الضرورة المعقولة له، وذلك على نحوٍ لا يُخلّ بأمن أو سرية بيانات المنشآت الأخرى.
On reasonable prior written notice, and no more than once per year (or following a confirmed personal data breach), the Controller may request information demonstrating Staffly's compliance with this DPA, including relevant audit reports, security certifications, or a summary audit. Staffly will make such information available, or reasonably cooperate with an on-site audit where reasonably necessary, in a manner that does not compromise the security or confidentiality of other tenants' data.
تسري هذه الاتفاقية من تاريخ بدء المنشأة استخدام المنصة، وتظل سارية طوال معالجة ستافلي للبيانات الشخصية نيابةً عن المنشأة بموجب اتفاقية الخدمة. تنتهي تلقائيًا بانتهاء أو إنهاء اتفاقية الخدمة الأساسية، دون إخلالٍ بالالتزامات التي تستمر بطبيعتها بعد الإنهاء (السرية، وأمن البيانات المُحتفظ بها لحين حذفها، والإخطار بأي خرقٍ ناشئ قبل الإنهاء).
This DPA takes effect on the date the Controller begins using the Platform and remains in effect for as long as Staffly processes personal data on the Controller's behalf under the service agreement. It terminates automatically on expiry or termination of the underlying service agreement, without prejudice to obligations that by their nature survive termination (confidentiality, security of retained data pending deletion, and breach notification for incidents arising before termination).
تخضع هذه الاتفاقية لأنظمة المملكة العربية السعودية، بما في ذلك نظام حماية البيانات الشخصية ولوائحه التنفيذية، وتُحسَم أي منازعاتٍ ناشئة عنها أمام الجهات القضائية المختصة في المملكة.
This DPA is governed by the laws of the Kingdom of Saudi Arabia, including the Personal Data Protection Law and its Implementing Regulations. Any dispute arising from this DPA is subject to the exclusive jurisdiction of the competent courts of Saudi Arabia.