ATHAR
Back to dashboard

Privacy Policy

Last updated: September 17, 2026

This policy describes what data the ATHAR system collects from its users, why it collects it, and how it is protected and used — matching what the system actually does today. Any legal or organizational point that has not yet been decided is explicitly marked "TODO" below rather than assumed.

1. Scope of this policy

ATHAR is an internal platform for documenting employee achievements and preparing institutional excellence award files. It is used only by employees authorized to create an account in it, and this policy applies to all such users' data stored in the system.

2. Data the system collects

Account data: email address, full name (Arabic and/or English), and preferred language. Passwords are never stored as plain text — only as an irreversible hashed value.

Profile and job data: job information, educational qualifications, and languages, which may include a national ID number if the user enters it as part of their personal data.

Achievement and criteria data: everything the user enters across the excellence criteria (performance and achievement, learning and knowledge, innovation, community work, leadership), including indicators and reported numeric results.

Attachments: files, documents, certificates, and award logos the user uploads as supporting evidence for their achievements — these files are stored privately per user (protection and access details in section 5 below), and are never reused or shared outside their owner's own account.

Operational security data: sign-in/sign-out records, IP address, and timestamps — used purely for security purposes (detecting unauthorized access attempts), never for marketing.

3. Why this data is collected

This data is collected for one specific purpose: letting an employee document their achievements, measure readiness against the excellence criteria, and prepare an award file built on their real, entered data. It is never used for marketing or advertising.

4. AI use in draft generation

The system uses an external AI service provider (currently configured as OpenAI or Anthropic) to generate narrative drafts for the professional write-up in the award file, based only on the achievement/criteria data the user has entered themselves. Sensitive account data (such as passwords) and the attached files themselves are never sent to the AI provider — only the text needed to generate the draft.

TODO: confirming the contractual terms with the AI provider(s) regarding whether submitted data is used to train their models is a legal/contractual point that needs confirmation from the responsible party — this policy does not assume an answer.

5. How your data is protected

Access to the system requires signing in with an account and a hashed password (your actual password is never stored), and no user can access another user's data — the system verifies who is asking every time before showing any data.

Files and attachments you upload (certificates, documents, logos) are stored privately outside any public path, and are only ever served to their owner after an identity check on every view or download request — there is no public link anyone else could open.

The system keeps an internal audit log for specific, sensitive operations only — such as signing in and out, creating/editing/deleting excellence-criteria records, and uploading or deleting evidence — for internal security and accountability purposes when needed. This log stores only the type of action, which user performed it, and when — never a password, the text content, or the files themselves.

TODO: encryption at rest for sensitive fields (such as the national ID number) is not currently enabled in the database used today. This is planned for a later phase when moving to the production database architecture, and is not yet in place — this policy does not assume otherwise.

6. Data retention

TODO: there is currently no operational policy for automatically deleting data after a set period — data remains stored for as long as the account is active. Setting a formal retention period is an organizational decision for the party responsible for the system.

7. Sharing data with other parties

Your data is never shared with any third party for marketing or commercial purposes. The one exception is the AI service provider described in section 4, solely for generating text drafts.

TODO: details of the email (SMTP) provider used for system notifications, where enabled, depend on the operating organization's own configuration and have not yet been specified in this policy.

8. Cookies and local storage

The system uses one cookie for your sign-in session (to keep you signed in and verify your identity while using it), and a separate cookie that only stores your language preference (Arabic/English).

The system also uses local storage in your browser (localStorage) — this stays on your own device and is never sent to ATHAR's servers — to remember display preferences (dark mode, text size, background color), the state of some interface elements (such as expanded/collapsed sections), and occasionally an unsaved draft of a form you're filling in, to protect it from being lost if the browser closes before you save.

None of this (cookies or local storage) is used for analytics, advertising, or external tracking.

9. Data backup

Backups of the system's database are taken for business-continuity and data-recovery purposes.

TODO: a recurring automated backup schedule and long-term off-machine storage location have not yet been decided operationally — backups are currently run manually.

10. Your rights over your data

You can view and edit your stored data at any time directly through the system's screens (Profile, Achievements, Criteria).

TODO: there is currently no self-service tool to fully delete an account from within the system. Any request to delete an account or its data is currently handled manually through the "Support" page in the dashboard, not automatically.

11. Changes to this policy

This policy may be updated when new features are added that genuinely change how data is collected or used. The "last updated" date at the top of this page reflects the latest revision.

12. Contact about privacy

For any privacy question, or to request access to or deletion of your data, please reach out through the "Support" page in the dashboard.

TODO: a dedicated privacy-request email address has not yet been designated by the party responsible for the system.