Skip to main content
Corevia Software Solutions
  • Products
  • Solutions
  • Pricing
  • About
  • Support
Sign in
Legal · V1

سياسة الخصوصية

English | العربية

Privacy Policy — Corevia Software
Effective Date: 13 July 2026
Last Updated: 13 July 2026

1. Who We Are

Corevia Software ("Corevia", "we", "us") develops and sells digital products, Excel-based business systems, and software services through coreviasoftware.com (the "Website"). For the purposes of Qatar's Law No. 13 of 2016 Concerning Personal Data Protection (the "PDPPL"), Corevia is the controller of personal data collected through the Website.

Controller details: Corevia for Software Solutions (trading as "Corevia Software"), License No. 331584, Doha, State of Qatar. Privacy contact: info@coreviasoftware.com.

2. Scope of This Policy

This Policy applies to personal data we process when you visit the Website, create an account, purchase or download products, subscribe to services, or contact support. It does not apply to third-party websites or services linked from the Website (including payment gateways), which have their own privacy policies.

3. Information We Collect

(a) Registration information. Name, email address, password (stored only as a one-way cryptographic hash — we cannot read your password), and optional profile details such as company name and country.

(b) Customer profile and account activity. Account settings, email verification status, support correspondence, and preferences you set.

(c) Orders. Products ordered, order dates, amounts, currency, order status, and billing details you provide (e.g., billing name and country). We do not collect or store payment card numbers (see Section 7).

(d) Payments. Payment status and transaction references returned to us by the payment gateway (e.g., confirmation codes, masked identifiers). The gateway — not Corevia — collects your card or bank details.

(e) Downloads and entitlements. Records of which products you are entitled to, download events, timestamps, and technical logs used to protect products against unauthorized access. IP addresses in our audit and download logs are stored in a pseudonymized (HMAC-hashed) form.

(f) Device and technical information. Browser type, operating system, referring pages, approximate region, and similar technical data generated when you use the Website, collected through server logs and essential cookies.

(g) Cookies. See Section 6 and our separate Cookie Policy (COR-LEG-004).

(h) Communications. Emails and support messages you send us.

We do not intentionally collect data of "special nature" under the PDPPL (such as data relating to ethnic origin, health, religious beliefs, or criminal records), and we ask that you do not submit such data to us.

4. How We Use Your Information

We use personal data to:

(a) create and administer your account, including email verification and login security;
(b) process orders, deliver digital products, create entitlements, and enable protected downloads;
(c) provide customer support and respond to your requests;
(d) send service communications (order confirmations, receipts, license and security notices, material changes to terms or policies);
(e) secure the Website — including fraud prevention, abuse detection, rate limiting, and audit logging;
(f) comply with legal obligations, including accounting, tax, and lawful requests by competent authorities;
(g) analyze aggregate, non-identifying usage to improve products and the Website;
(h) with your consent where required, send marketing communications (see Section 15).

We do not sell personal data. We do not use personal data for automated decision-making that produces legal effects concerning you.

5. Legal Basis for Processing

Under the PDPPL, we process personal data:

(a) with your consent — for example, when you create an account or opt in to marketing;
(b) where processing is necessary to perform a contract with you — such as delivering products you have purchased;
(c) where processing is necessary for our legitimate purposes as permitted by the PDPPL — such as securing the Website and preventing fraud — balanced against your rights;
(d) where processing is necessary to comply with a legal obligation.

6. Cookies and Analytics

The Website currently uses essential cookies only — session, authentication, and security (CSRF) cookies necessary for the Website to function. We do not currently operate third-party analytics or advertising cookies.

If we enable analytics tools in the future (such as Google Analytics or Microsoft Clarity), we will update this Policy and the Cookie Policy first, and where required we will request your consent before activating non-essential cookies. Full details, including retention periods and browser controls, are in the Cookie Policy (COR-LEG-004).

7. Payments

Payments are processed by licensed third-party payment gateways through hosted payment pages (which may include Qatar-licensed providers such as Sadad or other gateways identified at checkout). Corevia never receives or stores your full card number, CVV, or banking credentials. The gateway processes your payment data under its own privacy policy and applicable financial regulations. We receive only the transaction outcome and reference data needed to fulfil your order and maintain accounting records.

8. Downloads and Entitlements

To protect paid products, downloads are tied to your account entitlements. We log download events (product, time, pseudonymized IP) for security, licensing enforcement, and fraud prevention. These logs are retained per Section 12.

9. Third-Party Processors

We share personal data only with service providers who process it on our behalf and under contractual obligations of confidentiality and security, limited to:

  • Hosting and infrastructure providers (application and database hosting);
  • Payment gateways (as independent controllers of the payment data they collect);
  • Email delivery providers (for transactional emails such as verification and receipts);
  • Professional advisers and authorities where legally required.

A current list of material processors can be requested via the privacy contact in Section 19.

10. International Data Transfers

Our hosting and email infrastructure may be located outside the State of Qatar. Where personal data is transferred across borders, we take measures designed to ensure an adequate level of protection consistent with the PDPPL, including contractual safeguards with providers. Under the PDPPL, transfers must not be made where they would breach the law or cause serious harm to data subjects.

11. Data Security

We apply technical and organizational measures appropriate to the risk, including:

  • passwords stored using strong one-way hashing (bcrypt);
  • encrypted connections (HTTPS/TLS) across the Website;
  • HTTP-only, secure session cookies and CSRF protection;
  • role-based access controls and audit logging for administrative actions;
  • pseudonymization (HMAC hashing) of IP addresses in logs;
  • payment card data never touching our systems;
  • download files stored outside the public web directory and gated by entitlements.

No system is perfectly secure. If we become aware of a personal data breach likely to cause serious harm, we will notify the competent authority and affected individuals as required by the PDPPL and NCSA guidance.

12. Data Retention

We keep personal data only as long as needed for the purposes above:

Data Indicative retention Reason
Account data Life of the account + up to 12 months after closure Service delivery; dispute window
Order and payment records Up to 10 years Accounting, tax, and commercial-record obligations
Support correspondence Up to 24 months after resolution Service quality and dispute handling
Security and download logs Up to 12 months Security, licensing enforcement
Marketing preferences Until consent withdrawn Compliance with your choices

When retention ends, data is deleted or irreversibly anonymized.

13. Your Rights

Under the PDPPL, you have the right to:

(a) withdraw consent to processing based on consent;
(b) object to processing that is not necessary for the purposes for which data was collected;
(c) access your personal data and request a copy;
(d) correct inaccurate or incomplete data;
(e) request erasure of data that is no longer necessary for the purposes for which it was collected;
(f) be informed of any breach of your personal data likely to cause you serious harm.

To exercise these rights, contact info@coreviasoftware.com. We will respond within a reasonable period and in any event within any timeframe required by law. If you are dissatisfied, you may complain to the competent authority in Qatar (the National Cyber Security Agency's competent department for personal data protection). Rights under other laws (e.g., GDPR for EU residents, where applicable) are addressed in Section 18.

Exercising your rights is free of charge except where the law permits a reasonable fee for repetitive or manifestly unfounded requests.

14. Children's Privacy

The Services are intended for adults and business users. We do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us and we will delete it. The PDPPL contains specific protections for children's data online; because our Services are not directed at children, we do not operate child-directed features.

15. Marketing Communications

We send marketing emails only with your consent (opt-in) or as otherwise permitted by law. Every marketing email contains an unsubscribe link, and you can also opt out from your account or by contacting us. Opting out does not affect service communications (receipts, security notices), which we must still send.

16. SaaS Business Data

For future hosted SaaS products, data you upload about your own business (which may include personal data of your customers or employees) is processed by Corevia on your behalf and on your instructions. You remain the controller of that data; Corevia acts as a processor. Before launching SaaS products that process third-party personal data at scale, Corevia will make a Data Processing Agreement (DPA) available to business customers.

17. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced on the Website or by email before they take effect, and the "Last Updated" date will be revised. Where a change requires your consent under applicable law, we will seek it.

18. Future Compliance Considerations

Corevia serves customers inside and outside Qatar. As our customer base grows, additional regimes may apply to some processing, including the EU/UK GDPR (for offering goods or services to individuals in the EU/UK), and other national privacy laws. We do not currently claim certification under any privacy framework, and we do not claim GDPR representation arrangements. Before materially targeting such markets, Corevia will assess and implement any required measures (legal bases, representative appointments, transfer mechanisms, notices).

This Policy does not claim any certification (e.g., ISO 27001, SOC 2) that Corevia does not hold.

19. Contact Information

Corevia for Software Solutions (trading as Corevia Software) — Privacy
Website: https://coreviasoftware.com
Privacy contact: info@coreviasoftware.com
Registered address: Doha, Qatar
License Number: 331584

سياسة الخصوصية — كوريفيا لحلول البرمجيات (Corevia for Software Solutions)
تاريخ السريان: 13 يوليو 2026
آخر تحديث: 13 يوليو 2026

1. من نحن

تقوم كوريفيا لحلول البرمجيات ("كوريفيا" أو "نحن") بتطوير وبيع المنتجات الرقمية وأنظمة الأعمال المبنية على إكسل والخدمات البرمجية عبر الموقع coreviasoftware.com ("الموقع"). ولأغراض القانون رقم 13 لسنة 2016 بشأن حماية خصوصية البيانات الشخصية ("قانون حماية البيانات")، تُعدّ كوريفيا المتحكم في البيانات الشخصية التي تُجمع عبر الموقع.

بيانات المتحكم: كوريفيا لحلول البرمجيات (الاسم التجاري: Corevia Software)، رخصة رقم 331584، الدوحة، دولة قطر. جهة الاتصال للخصوصية: info@coreviasoftware.com.

2. نطاق هذه السياسة

تسري هذه السياسة على البيانات الشخصية التي نعالجها عند زيارتكم الموقع أو إنشاء حساب أو شراء المنتجات أو تنزيلها أو الاشتراك في الخدمات أو التواصل مع الدعم. ولا تسري على مواقع أو خدمات الأطراف الثالثة المرتبطة بالموقع (بما فيها بوابات الدفع)، إذ لكل منها سياسة خصوصية خاصة.

3. المعلومات التي نجمعها

(أ) معلومات التسجيل: الاسم، والبريد الإلكتروني، وكلمة المرور (تُخزَّن بصيغة تجزئة تشفيرية أحادية الاتجاه فقط — لا يمكننا قراءة كلمة مروركم)، وبيانات اختيارية مثل اسم الشركة والدولة.

(ب) ملف العميل ونشاط الحساب: إعدادات الحساب، وحالة التحقق من البريد، ومراسلات الدعم، والتفضيلات.

(ج) الطلبات: المنتجات المطلوبة وتواريخ الطلبات والمبالغ والعملة وحالة الطلب وبيانات الفوترة التي تقدمونها. ولا نجمع أرقام بطاقات الدفع ولا نخزّنها (انظر البند 7).

(د) المدفوعات: حالة السداد ومراجع المعاملات التي تعيدها إلينا بوابة الدفع (مثل رموز التأكيد والمعرّفات المقنَّعة). فبوابة الدفع — لا كوريفيا — هي التي تجمع بيانات بطاقتكم أو حسابكم البنكي.

(هـ) التنزيلات والاستحقاقات: سجلات المنتجات المستحَقة لكم، ووقائع التنزيل وأوقاتها، والسجلات التقنية لحماية المنتجات من الوصول غير المصرّح به. وتُخزَّن عناوين IP في سجلات التدقيق والتنزيل بصيغة مموّهة (تجزئة HMAC).

(و) معلومات الجهاز والمعلومات التقنية: نوع المتصفح، ونظام التشغيل، والصفحات المُحيلة، والمنطقة التقريبية، وبيانات تقنية مماثلة تُنشأ عند استخدام الموقع عبر سجلات الخادم وملفات تعريف الارتباط الأساسية.

(ز) ملفات تعريف الارتباط: انظر البند 6 وسياسة ملفات تعريف الارتباط المستقلة (COR-LEG-004).

(ح) المراسلات: رسائل البريد الإلكتروني ورسائل الدعم التي ترسلونها إلينا.

ولا نتعمد جمع البيانات ذات "الطبيعة الخاصة" بمفهوم قانون حماية البيانات (كالبيانات المتعلقة بالأصل العرقي أو الصحة أو المعتقد الديني أو السجل الجنائي)، ونرجو عدم موافاتنا بمثل هذه البيانات.

4. كيفية استخدامنا لمعلوماتكم

نستخدم البيانات الشخصية من أجل:

(أ) إنشاء حسابكم وإدارته، بما في ذلك التحقق من البريد وأمان الدخول؛
(ب) معالجة الطلبات وتسليم المنتجات الرقمية وإنشاء الاستحقاقات وتمكين التنزيلات المحمية؛
(ج) تقديم دعم العملاء والرد على طلباتكم؛
(د) إرسال المراسلات الخدمية (تأكيدات الطلبات، الإيصالات، إشعارات الترخيص والأمان، والتغييرات الجوهرية في الشروط أو السياسات)؛
(هـ) تأمين الموقع — بما يشمل منع الاحتيال وكشف إساءة الاستخدام وتقييد المعدل وسجلات التدقيق؛
(و) الامتثال للالتزامات القانونية، بما فيها المحاسبة والضرائب والطلبات المشروعة من الجهات المختصة؛
(ز) تحليل الاستخدام الإجمالي غير المعرِّف للهوية لتحسين المنتجات والموقع؛
(ح) وبموافقتكم حيثما تلزم، إرسال مراسلات تسويقية (انظر البند 15).

ولا نبيع البيانات الشخصية، ولا نستخدمها في اتخاذ قرارات آلية تُنتج آثاراً قانونية بشأنكم.

5. الأساس القانوني للمعالجة

بموجب قانون حماية البيانات، نعالج البيانات الشخصية:

(أ) بناءً على موافقتكم — كإنشاء الحساب أو الاشتراك في التسويق؛
(ب) حيثما تكون المعالجة ضرورية لتنفيذ عقد معكم — كتسليم المنتجات المشتراة؛
(ج) حيثما تكون المعالجة ضرورية لأغراضنا المشروعة التي يجيزها القانون — كتأمين الموقع ومنع الاحتيال — مع الموازنة مع حقوقكم؛
(د) حيثما تكون المعالجة ضرورية للامتثال لالتزام قانوني.

6. ملفات تعريف الارتباط والتحليلات

يستخدم الموقع حالياً ملفات تعريف ارتباط أساسية فقط — ملفات الجلسة والمصادقة والأمان (حماية CSRF) اللازمة لعمل الموقع. ولا نشغّل حالياً أي ملفات تحليلات أو إعلانات تابعة لأطراف ثالثة.

وإذا فعّلنا مستقبلاً أدوات تحليلات (مثل Google Analytics أو Microsoft Clarity)، فسنحدّث هذه السياسة وسياسة ملفات تعريف الارتباط أولاً، وسنطلب موافقتكم قبل تفعيل الملفات غير الأساسية حيثما يلزم. وترد التفاصيل الكاملة في سياسة ملفات تعريف الارتباط (COR-LEG-004).

7. المدفوعات

تعالج المدفوعات بوابات دفع مرخّصة تابعة لأطراف ثالثة عبر صفحات دفع مستضافة (وقد تشمل مزوّدين مرخّصين في قطر مثل "سداد" أو غيرها مما يُحدَّد عند الدفع). لا تتلقى كوريفيا مطلقاً رقم بطاقتكم الكامل أو رمز CVV أو بيانات اعتمادكم البنكية ولا تخزّنها. وتعالج البوابة بياناتكم وفق سياسة خصوصيتها واللوائح المالية المطبقة، ولا نتلقى نحن سوى نتيجة المعاملة والبيانات المرجعية اللازمة لتنفيذ طلبكم وحفظ السجلات المحاسبية.

8. التنزيلات والاستحقاقات

حمايةً للمنتجات المدفوعة، تُربط التنزيلات باستحقاقات حسابكم. ونسجّل وقائع التنزيل (المنتج، الوقت، عنوان IP المموّه) لأغراض الأمان وإنفاذ الترخيص ومنع الاحتيال، وتُحفظ هذه السجلات وفق البند 12.

9. المعالجون من الأطراف الثالثة

لا نشارك البيانات الشخصية إلا مع مزوّدي خدمات يعالجونها نيابةً عنا وبموجب التزامات تعاقدية بالسرية والأمان، وتنحصر في:

  • مزوّدي الاستضافة والبنية التحتية (استضافة التطبيق وقاعدة البيانات)؛
  • بوابات الدفع (بصفتها متحكمة مستقلة في بيانات الدفع التي تجمعها)؛
  • مزوّدي خدمات البريد الإلكتروني (للرسائل التشغيلية كالتحقق والإيصالات)؛
  • المستشارين المهنيين والجهات المختصة حيثما يقتضي القانون.

ويمكن طلب قائمة المعالجين الجوهريين الحالية عبر جهة الاتصال في البند 19.

10. نقل البيانات عبر الحدود

قد تقع بنيتنا التحتية للاستضافة والبريد خارج دولة قطر. وعند نقل البيانات الشخصية عبر الحدود، نتخذ تدابير تهدف إلى ضمان مستوى حماية ملائم يتفق مع قانون حماية البيانات، بما في ذلك الضمانات التعاقدية مع المزوّدين. وبموجب القانون، لا يجوز النقل متى شكّل مخالفةً للقانون أو ألحق ضرراً جسيماً بأصحاب البيانات.

11. أمن البيانات

نطبّق تدابير تقنية وتنظيمية مناسبة لدرجة المخاطر، ومنها:

  • تخزين كلمات المرور بتجزئة أحادية الاتجاه قوية (bcrypt)؛
  • اتصالات مشفّرة (HTTPS/TLS) عبر الموقع؛
  • ملفات جلسات آمنة بخاصية HTTP-only وحماية CSRF؛
  • ضوابط وصول قائمة على الأدوار وسجلات تدقيق للإجراءات الإدارية؛
  • تمويه عناوين IP في السجلات (تجزئة HMAC)؛
  • عدم مرور بيانات بطاقات الدفع بأنظمتنا مطلقاً؛
  • تخزين ملفات التنزيل خارج الدليل العام للويب وتقييدها بالاستحقاقات.

ولا يوجد نظام آمن تماماً. وإذا علمنا بخرقٍ للبيانات الشخصية يُرجَّح أن يُلحق ضرراً جسيماً، فسنخطر الجهة المختصة والأفراد المتأثرين وفق قانون حماية البيانات وإرشادات الوكالة الوطنية للأمن السيبراني.

12. الاحتفاظ بالبيانات

نحتفظ بالبيانات الشخصية للمدة اللازمة للأغراض المذكورة فقط:

البيانات مدة الاحتفاظ الاسترشادية السبب
بيانات الحساب مدة الحساب + حتى 12 شهراً بعد الإغلاق تقديم الخدمة؛ نافذة المنازعات
سجلات الطلبات والمدفوعات حتى 10 سنوات الالتزامات المحاسبية والضريبية والتجارية
مراسلات الدعم حتى 24 شهراً بعد الحل جودة الخدمة ومعالجة المنازعات
سجلات الأمان والتنزيل حتى 12 شهراً الأمان وإنفاذ الترخيص
تفضيلات التسويق حتى سحب الموافقة الامتثال لاختياراتكم

وعند انتهاء مدة الاحتفاظ، تُحذف البيانات أو تُجعل مجهولة الهوية بلا رجعة.

13. حقوقكم

بموجب قانون حماية البيانات، لكم الحق في:

(أ) سحب الموافقة على المعالجة القائمة على الموافقة؛
(ب) الاعتراض على المعالجة غير الضرورية للأغراض التي جُمعت البيانات من أجلها؛
(ج) الاطلاع على بياناتكم الشخصية وطلب نسخة منها؛
(د) تصحيح البيانات غير الدقيقة أو غير المكتملة؛
(هـ) طلب محو البيانات التي لم تعد ضرورية للأغراض التي جُمعت من أجلها؛
(و) الإخطار بأي خرق لبياناتكم الشخصية يُرجَّح أن يلحق بكم ضرراً جسيماً.

ولممارسة هذه الحقوق، تواصلوا معنا عبر info@coreviasoftware.com. وسنرد خلال مدة معقولة وبما لا يتجاوز أي مهلة يفرضها القانون. وإذا لم ترضوا عن ردنا، يمكنكم التقدم بشكوى إلى الجهة المختصة في دولة قطر (الإدارة المختصة بحماية البيانات الشخصية في الوكالة الوطنية للأمن السيبراني).

وتكون ممارسة الحقوق مجانية إلا حيثما يجيز القانون فرض رسم معقول على الطلبات المتكررة أو الظاهرة البطلان.

14. خصوصية الأطفال

الخدمات موجهة للبالغين ومستخدمي الأعمال، ولا نجمع عن علم بيانات شخصية من أطفال دون الثامنة عشرة. فإذا كنتم تعتقدون أن طفلاً قدّم إلينا بيانات شخصية، فتواصلوا معنا وسنحذفها.

15. المراسلات التسويقية

لا نرسل رسائل تسويقية إلا بموافقتكم (الاشتراك الاختياري) أو وفق ما يجيزه القانون. وتتضمن كل رسالة تسويقية رابط إلغاء الاشتراك، كما يمكنكم إلغاء الاشتراك من حسابكم أو بالتواصل معنا. ولا يؤثر إلغاء الاشتراك على المراسلات الخدمية (الإيصالات، إشعارات الأمان) التي يتعين علينا إرسالها.

16. بيانات أعمال SaaS

بالنسبة لمنتجات SaaS المستضافة المستقبلية، تُعالَج البيانات التي ترفعونها عن أعمالكم (وقد تتضمن بيانات شخصية لعملائكم أو موظفيكم) نيابةً عنكم وبناءً على تعليماتكم؛ فتظلون أنتم المتحكم في تلك البيانات وتعمل كوريفيا بصفة معالج. وقبل إطلاق منتجات SaaS تعالج بيانات شخصية لأطراف ثالثة على نطاق واسع، ستوفر كوريفيا اتفاقية معالجة بيانات (DPA) لعملاء الأعمال.

17. تعديل هذه السياسة

قد نحدّث هذه السياسة من وقت لآخر. وتُعلن التغييرات الجوهرية عبر الموقع أو البريد الإلكتروني قبل سريانها، مع تحديث تاريخ "آخر تحديث". وحيثما يستلزم التغيير موافقتكم بموجب القانون، فسنطلبها.

18. اعتبارات الامتثال المستقبلية

تخدم كوريفيا عملاء داخل قطر وخارجها. ومع نمو قاعدة العملاء، قد تسري أنظمة إضافية على بعض المعالجات، ومنها اللائحة العامة لحماية البيانات في الاتحاد الأوروبي/المملكة المتحدة (GDPR) وقوانين خصوصية وطنية أخرى. ولا ندّعي حالياً أي اعتماد بموجب أي إطار خصوصية، ولا ندّعي ترتيبات تمثيل بموجب GDPR. وقبل الاستهداف الجوهري لتلك الأسواق، ستقيّم كوريفيا أي تدابير لازمة وتنفذها.

ولا تدّعي هذه السياسة أي شهادة (مثل ISO 27001 أو SOC 2) لا تحوزها كوريفيا.

19. معلومات الاتصال

كوريفيا لحلول البرمجيات (Corevia for Software Solutions) — الخصوصية
الموقع: https://coreviasoftware.com
جهة الاتصال للخصوصية: info@coreviasoftware.com
العنوان المسجَّل: الدوحة، قطر
رقم الرخصة: 331584

Corevia Software Solutions

Smart software solutions that help businesses manage, grow and transform with confidence.

Platform

ProductsSolutionsPricingCustomer Portal

Company

AboutSupportinfo@coreviasoftware.com

Legal

Terms of ServicePrivacy PolicyRefund PolicyCookie PolicyCookie Settings
© 2026 Corevia. All rights reserved.Smart Software. Stronger Business.

Essential cookies only·ملفات أساسية فقط

Corevia uses essential cookies required for secure login, account sessions, form protection, and website operation. We do not currently use analytics or advertising cookies. Learn more in our Cookie Policy.

تستخدم كوريفيا ملفات تعريف الارتباط الأساسية اللازمة لتسجيل الدخول الآمن والجلسات وحماية النماذج وتشغيل الموقع. ولا نستخدم حالياً ملفات التحليلات أو الإعلانات. لمزيد من المعلومات، يرجى مراجعة سياسة ملفات تعريف الارتباط.

  • Essential / الأساسية: always active / مفعّلة دائماً
  • Analytics / التحليلات: not used / غير مستخدمة
  • Marketing / التسويق: not used / غير مستخدمة