← Back

Privacy Policy

Effective Date: 2025-01-01  |  Last Updated: 2025-01-01

1. Introduction

This Privacy Policy explains how Amalah ("we", "us"), accessible at amalah.app, collects, uses, stores, and protects personal information. Amalah is a SaaS platform for licensed domestic worker recruitment offices in Kuwait.

We are committed to protecting the privacy of all individuals whose data is processed through our Platform — including Office owners, employees, domestic workers, and clients — in compliance with applicable laws in the State of Kuwait.

2. Data Roles

Amalah acts as a data processor — we store and manage data on behalf of Offices. Each Office is the data controller for the worker and client data it enters into the Platform.

Offices decide what data to collect and for what purpose. Amalah provides the technical infrastructure only. We do not verify, approve, or control the data entered by Offices.

3. Data We Collect

We collect and process the following categories of personal data:

CategoryData TypesPurpose
Office RegistrationOffice name, license number, phone, email, password (hashed), logoAccount creation and verification
Employee AccountsName, email, role, permissionsMulti-user access management
Worker ProfilesNationality, age, skills, photos, documents (stored internally, not shown publicly)Profile management and recruitment operations
Reservation DataClient name, phone, reservation date, documentsTracking placements and reservations
Technical DataIP address, browser type, device info, timestampsSecurity and service optimization

4. Public vs. Private Data

We distinguish clearly between data shown publicly and data kept private:

  1. Public office pages display ONLY: nationality, age, skills, and a profile image. No full names, passport numbers, ID numbers, or dates of birth are ever shown publicly.
  2. Full worker profiles (including documents and identity details) are accessible only to the Office that created them and authorized Amalah administrators.
  3. Offices are fully responsible for ensuring they have valid consent before uploading any worker data.
  4. We never sell, rent, or trade personal data to third parties.

5. How We Use Data

Personal data is processed for the following purposes only:

  1. Service Delivery: Providing core Platform features — profiles, reservations, employee management, public pages.
  2. Account Management: Authentication, subscriptions, and account-related communications.
  3. Security: Detecting and preventing unauthorized access, fraud, and abuse.
  4. Legal Compliance: Retaining records as required by applicable laws.
  5. Improvement: Analyzing anonymized usage patterns to improve the Platform.

We do NOT use personal data for advertising, profiling, automated decision-making, or any unrelated purpose.

6. Data Storage & Security

All data is stored on Google Firebase (Google Cloud Platform), which provides:

  1. Encryption in transit (TLS/SSL) and at rest (AES-256).
  2. SOC 1, SOC 2, and ISO 27001 certified data centers.
  3. Automated backups and disaster recovery.
  4. Access controls and audit logging.

We also implement application-level security:

  1. Role-based access rules — users can only access their own Office's data.
  2. Secure authentication with hashed passwords.
  3. File type validation and upload size limits.
  4. Passwords are never stored in plain text.

7. Data Sharing

We do not sell or trade personal data. We may share data only when:

  1. Required by our service provider (Google Firebase) for hosting, storage, and authentication.
  2. An Office makes limited worker data visible on its public page (nationality, age, skills, image only).
  3. Required by valid court orders or lawful requests from Kuwaiti authorities.
  4. Necessary to protect the rights, safety, or property of Amalah or the public.

8. Data Retention

We retain personal data as necessary for service provision and compliance with applicable legal requirements:

  1. Active Accounts: Data is kept while your subscription is active.
  2. Archived Records: Retained as necessary for legal compliance and business records.
  3. Terminated Accounts: Data may be retained as required by applicable law, then permanently deleted.
  4. Technical Logs: Retained for up to 12 months for security purposes.

9. Your Rights

We adopt international best practices to provide you with the following rights:

  1. Access: Request a copy of the personal data we hold about you.
  2. Correction: Update or fix inaccurate data via the Platform or by contacting us.
  3. Export: Download your data in CSV format using built-in export features.
  4. Deletion: Request account and data deletion, subject to legal retention requirements.
  5. Objection: Object to specific processing activities by contacting us.

Workers should first contact the Office managing their data. Amalah may assist in facilitating requests where appropriate.

To exercise any right, email us. We will respond within 30 days. support@amalah.app

10. International Data

Our Platform processes data of workers from multiple countries. Offices are responsible for understanding applicable data protection requirements for their workers' nationalities.

  1. Data is stored on Google Cloud infrastructure with adequate protections for international data transfers.

11. Cookies & Local Storage

Amalah uses only essential cookies and local storage for:

  1. Authentication: Keeping you logged in.
  2. Preferences: Saving your language choice (Arabic/English).
  3. Performance: Caching for faster loads and offline support.

We do NOT use tracking, analytics, or advertising cookies.

12. Children's Privacy

Amalah is a business platform for licensed offices. It is not for individuals under 18. We do not knowingly collect data from minors. All workers on the Platform must be of legal working age.

13. Data Breach Notification

If a data breach occurs that may affect your rights:

  1. We will notify affected Offices via email as soon as reasonably possible.
  2. We will cooperate with authorities as required by law.
  3. We will take immediate steps to contain the breach.
  4. We will inform affected parties about the breach and recommended actions.

14. Changes to This Policy

We may update this policy. Material changes will be communicated at least 15 days before taking effect via email or in-platform notification.

15. Contact Us

For questions about this Privacy Policy or your data:

Email: support@amalah.app
Platform: amalah.app

We aim to respond within 30 days.

Terms of ServiceSupport