النسخة العربية أدناه هي النسخة المعتمدة؛ الإنجليزية ترجمة للتيسير. The Arabic version below is the controlling version; the English is a convenience translation.
تطبيق «كيتو عربي (KetoArab)» أداة عافية وتغذية. هذه السياسة توضّح ما نجمعه من بيانات، وكيف نعالجها ونحميها، وما حقوقك بموجب المرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية ولائحته التنفيذية، والقوانين المعمول بها لحماية البيانات في بلد إقامة المستخدم. المدخلات الصحية في التطبيق اختيارية تقدّمها أنت طواعيةً، وتحت تحكّمك، ويمكنك حذفها في أي وقت.
الجزء (أ) — سياسة الخصوصية (النسخة العربية — هي النسخة المعتمدة)
١. مَن نحن ومسؤول التحكم بالبيانات
تطبيق «كيتو عربي (KetoArab)» («التطبيق»)، الذي تُشغّله «حلول زاد لإمداد مواقع الشبكة المعلوماتية (الإنترنت) بالمحتويات»، المسجّلة في دبي، الإمارات العربية المتحدة، بالسجل التجاري رقم ١٢١٦٢٦٠، هي جهة التحكم في البيانات (Data Controller) المسؤولة عن معالجة بياناتك الشخصية وفق المرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية ولائحته التنفيذية، والقوانين المعمول بها لحماية البيانات في بلد إقامة المستخدم.
للتواصل بشأن الخصوصية أو ممارسة حقوقك: [email protected].
٢. ما البيانات التي نجمعها
نجمع الفئات التالية. المدخلات الصحية المعلَّمة (اختيارية) هي مدخلات صحية اختيارية تقدّمها أنت بنفسك، وتُصنَّف نظاماً كبيانات حساسة تتطلب موافقتك الصريحة المنفصلة قبل جمعها، ويمكنك حجبها أو حذفها دون أن يمنعك ذلك من استخدام الميزات الأساسية.
أ) بيانات الحساب والهوية (عادية):
- الاسم الأول واسم العائلة.
- البريد الإلكتروني ورقم الجوال.
- تاريخ الميلاد (يُشتق العمر منه ولا يُخزَّن منفصلاً) والجنس والدولة والحالة الاجتماعية ومصدر الإحالة واللغة والمنطقة الزمنية.
ب) مدخلات صحية اختيارية تقدّمها أنت (تُصنَّف نظاماً كبيانات حساسة):
- الوزن والطول ونسبة الدهون ومستوى النشاط والتمارين.
- حالة الحمل/الرضاعة/النفاس.
- استخدام الأدوية، والأدوية المسجّلة، والحالات الصحية (مثل السكري، تكيّس المبايض، الغدة الدرقية).
- بيانات الدورة الشهرية (الإعدادات، تواريخ الدورة، الأعراض).
- سجلات الوزن وقياسات الجسم (محيطات).
- صور التقدّم (صور للجسم).
- سجلات الطعام/الوجبات وصور الطعام والقيم الغذائية.
- العادات، والمزاج/الطاقة، والصيام، وشرب الماء، والأهداف الغذائية.
ج) بيانات الاستخدام والجهاز:
- نوع المنصة ومعرّف الجهاز، و«رمز الجهاز» (Registration Token) اللازم لإرسال الإشعارات الفورية عبر Firebase Cloud Messaging، و«معرّف الإعلان» (Advertising ID) عند عرض إعلانات غير مخصّصة.
- سجلات الوصول والتدقيق اللازمة للأمان والامتثال.
د) بيانات الدفع (عند تفعيل الاشتراكات المدفوعة):
- معرّف العميل لدى مزود الدفع وبيانات الاشتراك (لا نخزّن بيانات البطاقة؛ تتم لدى مزود الدفع).
٣. الأساس النظامي للمعالجة
- موافقة صريحة منفصلة لكل فئة من المدخلات الصحية الاختيارية، تُجمع منفصلةً قبل أي جمع للبيانات الصحية. وهذه الموافقات قابلة للسحب بشكل مستقل لكل فئة: مؤشرات الصحة الأساسية (health_metrics) لازمة لتشغيل الميزات الصحية، أمّا الصحة الإنجابية والدورة الشهرية وصور التقدّم وبيانات التدريب فهي موافقات اختيارية منفصلة يمكنك منحها أو سحبها كلٌّ على حدة دون أن يؤثّر ذلك على بقيتها.
- تنفيذ العقد/تقديم الخدمة لتشغيل حسابك وتقديم الميزات الأساسية.
- موافقة عادية منفصلة للتسويق (اختيارية، ولا تُستخدم البيانات الحساسة للتسويق أبداً).
٤. كيف نجمع موافقتك ونسجّلها
نعرض شاشة موافقة قبل جمع أي بيانات صحية، وفيها اختيارات منفصلة لكل فئة (لا تجميع/لا حزم). ونسجّل في سجل موافقات غير قابل للتعديل: الفئة، والحالة (مُنحت/سُحبت)، والأساس النظامي، ونسخة السياسة، وبصمة SHA-256 لنص الموافقة المعروض، واللغة، والوقت. ويمكنك سحب الموافقة بنفس سهولة منحها، ولكل فئة على حدة.
٥. أغراض المعالجة
- التغذية بالذكاء الاصطناعي: نُحلّل سياقك الصحي وصور طعامك لاقتراح خطط ووجبات. تتم المعالجة على خادم داخلي (Ollama) داخل بنيتنا التحتية، ولا تُرسَل بياناتك إلى أي مزود ذكاء اصطناعي سحابي خارجي.
- المدرّب البشري: عند تعيين مدرّب، قد يطّلع على سياقك الصحي المصرّح به لمساعدتك. وفي التدريب بين جنسين مختلفين، تُمنع مشاركة الصور منعاً تاماً ويُكتفى بالقياسات الرقمية.
- التحفيز (Gamification): نقاط وإنجازات لتشجيع المتابعة.
٦. كيف تُستخدم مدخلاتك الصحية (وما لا نفعله بها)
المدخلات الصحية التي تقدّمها تُستخدم فقط لتخصيص تجربتك أنت (اقتراحات وجبات، تذكيرات)؛ يعمل الذكاء الاصطناعي على خوادمنا؛ ولا تُباع بياناتك الصحية ولا تُستخدم للإعلانات إطلاقًا.
ولا نستخدم أدوات تحليلات لطرف ثالث؛ وأي إعلانات نعرضها تكون غير مخصّصة، وبياناتك الصحية لا تُستخدم أبدًا لاستهدافك بالإعلانات ولا تُشارَك لأغراض إعلانية.
٧. الأطراف الخارجية ومعالِجو البيانات الفرعيون
نعتمد على بنيتنا التحتية الخاصة، ولا نستعين بمزوّدين خارجيين إلا في حدود ضيقة كما هو موضّح أدناه:
١) بنيتنا التحتية الخاصة — مستضافة ذاتيًا على خوادمنا، ولا تُشارَك البيانات مع أطراف خارجية: تبقى بياناتك على بنيتنا التحتية الخاصة، وهذا في حدّ ذاته وضع أقوى لحماية الخصوصية.
| الجهة | الغرض | البيانات المتدفّقة | الموقع |
|---|---|---|---|
| PostgreSQL | قاعدة البيانات الرئيسية | بيانات الحساب والمدخلات الصحية | داخلي/خوادمنا |
| Redis | التخزين المؤقت والجلسات | بيانات مؤقتة | داخلي/خوادمنا |
| MinIO | تخزين الصور (طعام/تقدّم/مرفقات) | الصور | داخلي/خوادمنا |
| Ollama (ذكاؤنا الاصطناعي الداخلي المستضاف ذاتيًا — وليس مزوّد ذكاء اصطناعي سحابي) | التغذية بالذكاء الاصطناعي | السياق الصحي وصور الطعام | داخلي/خوادمنا |
| Keycloak | المصادقة/تسجيل الدخول | بيانات الدخول/الرموز | داخلي/خوادمنا |
٢) مزوّدون خارجيون نستخدمهم فعليًا: (أ) واتساب/Meta لإيصال رمز الدخول لمرة واحدة (OTP) إلى رقم جوالك، و(ب) Google Firebase Cloud Messaging لإرسال الإشعارات الفورية إلى جهازك؛ وقد يُعرَض في التطبيق إعلانات غير مخصّصة خلال المرحلة الأولى (انظر «الإعلانات» أدناه).
| الجهة | الغرض | البيانات المتدفّقة | الموقع |
|---|---|---|---|
| WhatsApp / Meta | إيصال رمز الدخول لمرة واحدة (OTP) | رقم الجوال ورمز التحقق | خارجي — Meta |
| Google Firebase (FCM) | إرسال الإشعارات الفورية (Push) | «رمز الجهاز» (Registration Token) ومعرّفات الجهاز | خارجي — Google LLC |
| مزوّد إعلانات (خارجي) | عرض إعلانات غير مخصّصة (سياقية) | معرّف الإعلان ومعلومات الجهاز الأساسية | خارجي |
الإشعارات الفورية (Google Firebase Cloud Messaging): نستخدم خدمة Firebase Cloud Messaging (FCM) المقدَّمة من Google LLC لإرسال الإشعارات الفورية إلى جهازك (مثل التذكيرات وتحديثات التطبيق). لهذا الغرض يُنشئ التطبيق «رمز جهاز» (Registration Token) تستخدمه Google لتوجيه الإشعارات إلى جهازك، وقد تعالج Google معرّفات الجهاز وبيانات تشغيل الخدمة بصفتها «معالِج بيانات» وفق شروط معالجة البيانات الخاصة بـ Firebase. لا نُرسل عبر الإشعارات أي بيانات صحية أو حساسة. يمكنك إيقاف الإشعارات في أي وقت من إعدادات جهازك أو من إعدادات التطبيق.
الإعلانات: قد يكون التطبيق مدعومًا بالإعلانات خلال المرحلة الأولى (إلى حين تفعيل الاشتراكات المدفوعة). تُعرض الإعلانات عبر مزوّد إعلانات خارجي قد يعالج «معرّف الإعلان» (Advertising ID) ومعلومات الجهاز الأساسية لعرض الإعلانات وقياس أدائها ومنع الاحتيال. الإعلانات التي نعرضها غير مخصّصة (سياقية)، ولا نبني عنك ملفًّا إعلانيًّا. لا تُشارَك بياناتك الصحية أو الحسّاسة مع أي مزوّد إعلانات، ولا تُستخدم لاستهدافك بالإعلانات إطلاقًا. ويمكنك إعادة تعيين معرّف الإعلان أو الحدّ من تتبّع الإعلانات من إعدادات جهازك.
الدفع بالبطاقة عبر الإنترنت غير مُفعّل حاليًا (يعتمد الإطلاق على نموذج القسائم/الرموز). إذا فُعِّل الدفع بالبطاقة مستقبلًا، سيُضاف مزوّد دفع متوافق مع PCI-DSS ويُفصح عنه هنا.
لا نستخدم أدوات تحليلات لطرف ثالث (مثل Google Analytics أو Mixpanel)، وأي إعلانات تُعرَض تكون غير مخصّصة ولا تعتمد على بياناتك الصحية.
٨. النقل الدولي للبيانات (Cross-border)
قد يعالج مزوّدونا الخارجيون بعض البيانات خارج دولة الإمارات: واتساب/Meta (رقم جوالك ورمز الدخول لإيصال الرمز)، وGoogle (معرّفات الجهاز و«رمز الجهاز» لإرسال الإشعارات الفورية، بصفتها معالِج بيانات)، ومزوّد الإعلانات (معرّف الإعلان لعرض إعلانات غير مخصّصة). يخضع أي نقل للبيانات إلى خارج الدولة لأحكام المرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية ولائحته التنفيذية، مع توفير ضمانات مناسبة بموجب قانون حماية البيانات الإماراتي.
٩. حقوقك (صاحب البيانات)
لك الحق في: العلم، والوصول، والحصول على نسختك، والتصحيح، والإتلاف/الحذف، وسحب الموافقة، والاعتراض/النقل.
- الوصول/النسخة: نُصدِّر بياناتك من سجل تصدير شامل يغطي عشرات الجداول (الصحة، الطعام، الوزن، القياسات، الدورة، الصور، الموافقات، إلخ).
- الحذف: عند طلب الحذف نحذف بياناتك غير الخاضعة للاحتفاظ النظامي، ونُجهّل المحتوى المشترك، مع استثناء السجلات الخاضعة للاحتفاظ النظامي (انظر §١٠).
- حذف الحساب داخل التطبيق متاح.
- سحب الموافقة بنفس سهولة منحها، ولكل فئة على حدة.
١٠. الاحتفاظ والإتلاف
تُحذف البيانات غير المالية خلال 30 يومًا من الطلب؛ تُحفظ السجلات المالية/الضريبية للمدة التي تتطلبها القوانين المعمول بها في دولة الإمارات؛ تُكنَس سجلات المحادثات تلقائيًا بعد 30 يومًا.
- السجلات المالية/الضريبية: تُحتفظ بها للمدة التي تتطلبها القوانين المعمول بها في دولة الإمارات، ولا تُحذف بطلب الحذف.
- سجلات الموافقة: تُحفظ كدليل امتثال (سجل المعالجة RoPA).
- سجلات المحادثات: تُكنَس تلقائيًا بعد 30 يومًا عبر مهمة مجدولة.
١١. أمن البيانات
نطبّق ضوابط تقنية وتنظيمية (تخزين داخلي للصور، روابط مؤقتة، مصادقة، سجل تدقيق غير قابل للتعديل، عزل على مستوى الصفوف RLS مفعّل). لا يلغي ذلك مسؤوليتك عن حماية بيانات دخولك.
١٢. الإشعار بالاختراق
إذا وقع اختراق قد يضرّ ببياناتك أو بحقوقك، نُشعر الجهة المختصة بحماية البيانات في دولة الإمارات (مكتب البيانات الإماراتي) دون تأخير غير مبرَّر من علمنا به، ونُشعرك عند اللزوم.
١٣. الأطفال
التطبيق غير موجّه لمن هم دون ١٨. لا نجمع بيانات الأطفال عمداً.
١٤. إخلاء طبي مهم
التطبيق أداة عافية/تغذية عامة وليس جهازاً طبياً ولا يقدّم تشخيصاً أو علاجاً ولا ادعاءات طبية. استشر طبيبك قبل أي تغيير غذائي، خصوصاً في الحمل/الرضاعة/النفاس أو وجود حالة مرضية. اقرأ إخلاء المسؤولية الطبي الكامل.
١٥. التواصل والتعديلات
لأي استفسار: [email protected]. قد نحدّث هذه السياسة وننشر نسخةً جديدة برقم نسخة وتاريخ. القانون الواجب التطبيق والاختصاص القضائي: دولة الإمارات العربية المتحدة (إمارة دبي).
PART (B) — PRIVACY POLICY (English — convenience translation)
The KetoArab app is a wellness and nutrition tool. This policy explains what data we collect, how we process and protect it, and your rights under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its Executive Regulations, and the applicable data-protection laws of the user’s country of residence. The health inputs in the app are optional, self-reported, under your control, and deletable at any time.
1. Who we are / Data Controller
The KetoArab app ("the App"), operated by HLUL ZAD FOR INTERNET CONTENT PROVIDER, registered in Dubai, United Arab Emirates under Commercial Register No. 1216260, is the Data Controller for the processing of your personal data under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its Executive Regulations, and the applicable data-protection laws of the user’s country of residence. Privacy contact / rights requests: [email protected].
2. What data we collect
Items marked (optional) are optional, self-reported health inputs you provide yourself. They are legally classified as sensitive data requiring your separate explicit consent before collection; you may withhold or delete them without losing access to core features.
(a) Account & identity (ordinary): first/last name; email, phone; date of birth (age is derived, not stored separately), gender, country, marital status, referral source, language, timezone.
(b) Optional health inputs you provide (legally classified as sensitive): weight, height, body-fat %, activity/exercise level; pregnancy / breastfeeding / Nifas status; medication use, medications, health conditions (e.g. diabetes, PCOS, thyroid); menstrual-cycle data (settings, cycle dates, symptoms); weight logs and body measurements (circumferences); progress photos (body images); food/meal logs, food photos, and macros; habits, mood/energy, fasting, water intake, nutrition goals.
(c) Usage & device: platform and device identifier, a device registration token for push notifications via Firebase Cloud Messaging, and an advertising identifier (Advertising ID) when non-personalized ads are shown; access/audit logs.
(d) Payment data (once paid subscriptions launch): payment-provider customer ID and subscription data — we do not store card details (handled by the payment provider).
3. Lawful basis
- Separate explicit consent per category of optional health input, collected separately before any health-data collection. These consents are independently withdrawable per category: basic health_metrics are needed to run the health features, while reproductive-health, menstrual-cycle, progress-photos, and coaching-data are optional, separate consents you may grant or withdraw individually without affecting the others.
- Contract / service delivery to run your account and core features.
- Separate ordinary consent for marketing (optional; sensitive data is never used for marketing).
4. How we collect & record consent
A consent screen is shown before any health-data collection, with separate opt-ins per category (no bundling). We record, in an immutable consent ledger: the category, status (granted/withdrawn), lawful basis, policy version, a SHA-256 hash of the exact consent text shown, locale, and timestamp. You can withdraw consent as easily as you gave it, per category.
5. Processing purposes
- AI nutrition: we analyze your health context and food photos to suggest plans/meals. Processing runs on an on-premise server (Ollama) inside our own infrastructure; your data is NOT sent to any external cloud-AI provider.
- Human coach: an assigned coach may view your authorized health context. In cross-gender coaching, photo sharing is hard-blocked and only numeric measurements are exchanged.
- Gamification: points/achievements to encourage adherence.
6. How your health inputs are used (and what we do NOT do)
The health inputs you provide are used only to personalize your own experience (meal suggestions, reminders); the AI runs on our own servers; your health data is never sold and never used for advertising.
We use no third-party analytics tools; any ads we show are non-personalized, and your health data is never used to target you with ads and is never shared for advertising purposes.
7. Third parties / sub-processors
We rely on our own infrastructure, and use external providers only within the narrow limits described below:
1) Our own infrastructure — self-hosted on our own servers; data is NOT shared with external third parties: your data stays on our own infrastructure, which is itself a stronger privacy position.
| Party | Purpose | Data | Location |
|---|---|---|---|
| PostgreSQL | primary database | account data, health inputs | self-hosted / on our servers |
| Redis | caching / sessions | transient data | self-hosted / on our servers |
| MinIO | image storage (food/progress/attachments) | images | self-hosted / on our servers |
| Ollama (our in-house / self-hosted AI — NOT a cloud AI vendor) | AI nutrition | health context, food photos | self-hosted / on our servers |
| Keycloak | auth / sign-in | login data/tokens | self-hosted / on our servers |
2) External providers we genuinely use: (a) WhatsApp / Meta, to deliver the one-time login code (OTP) to your phone number, and (b) Google Firebase Cloud Messaging, to deliver push notifications to your device; the app may also show non-personalized ads during the initial phase (see "Advertising" below).
| Party | Purpose | Data | Location |
|---|---|---|---|
| WhatsApp / Meta | deliver OTP login code | phone number, code | external — Meta |
| Google Firebase (FCM) | deliver push notifications | device registration token, device identifiers | external — Google LLC |
| Ad provider (external) | serve non-personalized (contextual) ads | advertising ID, basic device info | external |
Push notifications (Google Firebase Cloud Messaging): We use Firebase Cloud Messaging (FCM), provided by Google LLC, to deliver push notifications to your device (e.g. reminders and app updates). For this purpose the app generates a registration token that Google uses to route notifications to your device; Google may process device identifiers and service-operation data as a data processor under the Firebase Data Processing and Security Terms. We never include health or otherwise sensitive data in notifications. You can disable notifications at any time in your device or app settings.
Advertising: The app may be ad-supported during the initial phase (until paid subscriptions launch). Ads are served by an external ad provider that may process an advertising identifier (Advertising ID) and basic device information to display ads, measure performance, and prevent fraud. The ads we show are non-personalized (contextual), and we do not build an advertising profile about you. Your health or otherwise sensitive data is never shared with any ad provider and is never used to target you with ads. You can reset the advertising ID or limit ad tracking in your device settings.
Online card payment is not currently active (launch uses a voucher/code model). If card payment is enabled in future, a PCI-DSS-compliant payment processor will be added and disclosed here.
We use no third-party analytics SDK (e.g. Google Analytics or Mixpanel); any ads shown are non-personalized (contextual) and do not use your health data.
8. Cross-border transfer
Our external providers may process some data outside the United Arab Emirates: WhatsApp / Meta (your phone number and login code, to deliver the code), Google (device identifiers and the registration token, to deliver push notifications, as a data processor), and the ad provider (advertising ID, to serve non-personalized ads). Any transfer outside the UAE is subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its Executive Regulations, with appropriate safeguards under the UAE PDPL.
9. Your rights
Right to be informed, access, obtain a copy, correct, destroy/delete, withdraw consent, object/portability.
- Access/copy: we export your data via a comprehensive export registry covering dozens of tables (health, food, weight, measurements, cycle, photos, consents, etc.).
- Deletion: on request we delete non-retained data and anonymize shared content, except records under statutory retention (see §10).
- In-app account deletion is offered.
- Withdraw consent as easily as given, per category.
10. Retention & destruction
Non-financial data is deleted within 30 days of the request; financial/tax records are retained for the period required by applicable UAE law; conversation logs are automatically swept after 30 days.
- Financial/tax records: retained for the period required by applicable UAE law and not deleted by a deletion request.
- Consent records: kept as compliance evidence (RoPA).
- Conversation logs: automatically swept after 30 days by a scheduled job.
11. Security
Technical & organizational controls (on-prem image storage, time-limited links, authentication, immutable audit log, Row-Level Security ENABLED). This does not remove your duty to protect your credentials.
12. Breach notification
If a breach occurs that may harm your data or rights, we notify the competent UAE data-protection authority (UAE Data Office) without undue delay of becoming aware, and notify you where required.
13. Children
The App is not directed to anyone under 18. We do not knowingly collect children’s data.
14. Important medical disclaimer
The App is a general wellness/nutrition tool, not a medical device; it provides no diagnosis, treatment, or medical claims. Consult your physician before any dietary change, especially during pregnancy/breastfeeding/Nifas or with a medical condition. Read the full Medical Disclaimer.
15. Contact & changes
Questions: [email protected]. We may update this policy and publish a new version/date. Governing law & venue: United Arab Emirates (Emirate of Dubai).
النسخة 1.1 — آخر تحديث: 4 يوليو 2026 · Version 1.1 — Last updated: 4 July 2026
