قائد نظامُ تشغيلِ طوارئ للمنشآت الصحّيّة، ويعالج بياناتٍ شخصيّةً وصحّيّةً حسّاسة. هذه الصفحة تصف ما يُجمَع، ولماذا، وأين يُخزَّن، ومن يصل إليه.
البياناتُ التي تُدخَل في قائد مملوكةٌ للمنشأة الصحّيّة التي تستعمله، وهي «مالك البيانات» المسؤول عن مشروعيّة جمعها والاحتفاظ بها. ويعمل مشغّلُ النظام حسن فقيهي (فرد) «معالِجاً» نيابةً عنها، فلا يستعمل البيانات لغرضٍ من عنده.
للتواصل في شأن الخصوصيّة: privacy@qaed.app
| الحقل | الغرض |
|---|---|
| الاسم · البريد · الجوّال · الرقم الوظيفيّ · المسمّى · القسم · رقم تصنيف الهيئة السعوديّة للتخصّصات الصحّيّة | إنشاء الحساب، ونسبةُ كلِّ إجراءٍ إلى فاعله في سجلّ الحادثة |
| كلمة المرور — مجزّأةً بـbcrypt ولا تُخزَّن نصّاً | الدخول |
| سرُّ العامل الثاني ورموزُ الاستعادة (مجزّأة) | التحقّق بخطوتين |
عند تفعيل حدثٍ يستدعي فرزاً، يُدخِل المنسوبُ في ملفّ المصاب:
| الحقل | |
|---|---|
| رقم الملفّ الطبّيّ (MRN) · الاسم · رقم الهويّة أو الإقامة · العمر · الجنس · الوزن · الطول · الجنسيّة · الجوّال | هويّة المصاب |
| اسم أقرب الأقارب وجوّاله | الإبلاغ والتواصل |
| لون الفرز · وقت الوصول · وسيلة الوصول · العلامات الحيويّة وملاحظات الحالة | إدارة الفرز والاستجابة |
هذه البيانات تُرفَع إلى خادم النظام لتتزامن بين أجهزة الفريق الواحد في الحدث نفسه. ولا تُشارَك خارج المنشأة.
يُسجَّل لكلِّ إجراءٍ حسّاس: وقتُه، والحسابُ الذي نفّذه ودورُه، وعنوانُ الشبكة (IP) ووكيلُ المستعرض ورمزُ الدولة، وصورةُ السجلّ قبل التعديل وبعده. وهذا مطلبُ ضوابطٍ أمنيّةٍ ورقابيّة، ولا يُستعمل لتتبّع سلوك المستخدم.
وسجلُّ التدقيق غيرُ قابلٍ للتعديل أو الحذف بالتصميم — حارسٌ في قاعدة البيانات يمنع ذلك. فما دخله بقي.
رمزُ إشعارات الجهاز (Apple على iOS، وGoogle على أندرويد)، ونوعُ المنصّة، وتفضيلاتُ الصوت. تُستعمل لإيصال إنذارات الأكواد.
رسائلُ محادثة الحدث، والملاحظات، ونصوصُ البلاغات، وطلباتُ الدعم، وتقاريرُ التعافي.
لا يقرأ قائد موقعَ جهازك. لا يطلب إذنَ الموقع ولا يستعمل خدماتِ تحديد الموقع البتّة. وإحداثيّاتُ الحدث — إن وُجدت — يكتبها المستخدم بيده أو يختارها من خريطة.
الكاميرا: تُستعمل لمسح رمز سوار الفرز وفتح ملفّ المصاب فقط. لا تُحفَظ صورٌ ولا تُرفَع.
Face ID / Touch ID / بصمة أندرويد: للتحقّق محلّيّاً عند فتح التطبيق. تُجرى المطابقةُ داخل الجهاز عبر نظام التشغيل، ولا يصل قائداً أيُّ قياسٍ حيويّ — يصله «نجح» أو «فشل» وحسب.
داخل المملكة العربيّة السعوديّة: على خادمٍ في منطقة الرياض لدى الشركة السعوديّة للحوسبة السحابيّة (SCCC)، بقاعدة بيانات PostgreSQL يشغّلها المشغّلُ بنفسه. والنسخُ الاحتياطيّةُ كلَّ ساعةٍ مشفَّرةً في المنطقة نفسها. ولا تُنقَل البياناتُ المخزَّنة خارج المملكة؛ والاستثناءُ الوحيد نصُّ الإشعار الذي يمرُّ بخوادم آبل أو Google (البند ٦).
| الطرف | ما يصله |
|---|---|
| الشركة السعوديّة للحوسبة السحابيّة (SCCC) — البنية التحتيّة في الرياض | الخادمُ والنسخُ الاحتياطيّة، بوصفها مزوّدَ بنيةٍ لا يطّلع على المحتوى |
| Apple Push Notification service | نصُّ الإشعار ورمزُ الجهاز. وقد يتضمّن نصُّ الإنذار اسمَ الكود وموقعَه داخل المبنى واسمَ المُفعِّل — فهو يمرُّ بخوادم آبل بحكم آليّة الإشعارات. |
| Google Firebase Cloud Messaging | مثلُ ما سبق، لأجهزة أندرويد. |
| Cloudflare — توجيه البريد | الرسائلُ التي ترسلها إلى عناوين qaed.app تمرُّ به إلى بريد المشغّل. |
تبقى بياناتُ المنشأة ما دام حسابُها قائماً. ويجوز لمدير المنشأة حذفُ السجلّات التشغيليّة من داخل النظام. أمّا سجلُّ التدقيق فلا يُحذَف لأنّه ضمانةُ المساءلة، ويبقى للمدّة النظاميّة.
لك — بحسب نظام حماية البيانات الشخصيّة في المملكة — حقُّ العلم والوصول والتصحيح والإتلاف والاعتراض. تُمارَس عبر مدير المنشأة، أو بمراسلة privacy@qaed.app. ويُردُّ على الطلب خلال ٣٠ يوماً.
وإن كنتَ مصاباً أو مريضاً أُدخِلت بياناتُك في قائد، فالمنشأةُ الصحّيّةُ التي عالجتك هي وجهةُ طلبك.
قائد أداةُ عملٍ لمنسوبي المنشآت الصحّيّة، ولا يُوجَّه إلى الأطفال ولا تُنشأ فيه حساباتٌ لهم. وقد تتضمّن ملفّاتُ المصابين قاصرين بحكم طبيعة الطوارئ، ومسؤوليّةُ ذلك على المنشأة بوصفها مالكَ البيانات.
يُحدَّث تاريخُ أعلى الصفحة عند كلّ تغيير، ويُبلَّغ مديرو المنشآت بالتغيير الجوهريّ.
Qaed is an emergency operations system for healthcare facilities, and it processes personal and sensitive health data. This page states what is collected, why, where it is stored, and who can reach it.
Data entered into Qaed belongs to the healthcare facility using it; the facility is the data controller. The system operator, Hassan Faqihi (an individual), acts as a processor on the facility's behalf and does not use the data for any purpose of its own.
Privacy contact: privacy@qaed.app
| Field | Purpose |
|---|---|
| Name · email · phone · employee ID · job title · department · SCFHS registration number | Account creation, and attributing every action to its actor in the incident record |
| Password — bcrypt-hashed, never stored in clear text | Sign-in |
| Two-factor secret and recovery codes (hashed) | Two-step verification |
When an event requires triage, staff enter into the casualty record:
| Field | |
|---|---|
| Medical record number (MRN) · name · national ID or Iqama number · age · sex · weight · height · nationality · phone | Casualty identity |
| Next-of-kin name and phone | Notification and contact |
| Triage colour · arrival time · arrival mode · vital signs and condition notes | Triage and response management |
This data is uploaded to the system server so it synchronises across the devices of the team working the same event. It is not shared outside the facility.
Every sensitive action records: its time, the account and role that performed it, the network address (IP), user agent and country code, and a snapshot of the record before and after the change. This is a security and regulatory control requirement; it is not used to profile user behaviour.
The audit log cannot be edited or deleted by design — a database guard prevents it.
Device notification token (Apple on iOS, Google on Android), platform, and sound preferences — used to deliver code alerts.
Incident chat messages, notes, directive texts, support requests, and recovery reports.
Qaed does not read your device location. It requests no location permission and uses no location services at all. Event coordinates, where present, are typed by the user or picked from a map.
Camera: used only to scan a triage wristband code and open the casualty record. No images are stored or uploaded.
Face ID / Touch ID / Android fingerprint: local verification when opening the app. Matching happens on-device through the operating system, and no biometric measurement ever reaches Qaed — it receives only success or failure.
Inside the Kingdom of Saudi Arabia: on a server in the Riyadh region of the Saudi Cloud Computing Company (SCCC), in a PostgreSQL database run by the operator. Hourly backups are encrypted and kept in the same region. Stored data is not transferred outside the Kingdom; the only exception is notification text, which passes through Apple or Google servers (section 6).
| Party | What reaches them |
|---|---|
| Saudi Cloud Computing Company (SCCC) — infrastructure in Riyadh | The server and backups, as an infrastructure provider with no access to content |
| Apple Push Notification service | Notification text and device token. Alert text may include the code name, its location inside the building, and the activating staff member's name, since it passes through Apple's servers by the nature of push delivery. |
| Google Firebase Cloud Messaging | The same, for Android devices. |
| Cloudflare — email routing | Messages you send to qaed.app addresses pass through it to the operator's mailbox. |
Facility data is retained while the facility's account is active. A facility administrator may delete operational records from within the system. The audit log is not deleted, as it is the accountability guarantee, and is retained for the statutory period.
Under the Saudi Personal Data Protection Law you have the rights to be informed, to access, to correct, to destroy, and to object. Exercise them through your facility administrator, or by writing to privacy@qaed.app. Requests are answered within 30 days.
If you are a patient or casualty whose data was entered into Qaed, the healthcare facility that treated you is the correct recipient of your request.
Qaed is a work tool for healthcare staff. It is not directed at children and no accounts are created for them. Casualty records may involve minors by the nature of emergency care; responsibility for that rests with the facility as data controller.
The date at the top is updated on every change, and facility administrators are notified of material changes.