Privacy Policy
Jaber Connect - published by MOHAMMAD GAZE NAYEF JABER on behalf of Jaber Group
Last Updated: August 19, 2026
Effective Date: August 19, 2026
1. Introduction
Welcome to Jaber Connect ("we," "us," "our"), a mobile application published by MOHAMMAD GAZE NAYEF JABER ("Publisher") under the Google Play developer name Jaber Group on behalf of Jaber Group ("Company"). This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our mobile application ("App"), available on Apple App Store and Google Play Store.
This Privacy Policy is drafted in compliance with:
- The Jordanian Personal Data Protection Law No. 24 of 2023 (PDPL), which came into force on March 17, 2024, with full compliance required since March 16, 2025. This is Jordan's first comprehensive data protection legislation.
- The Jordanian Cybercrime Law No. 17 of 2023, effective September 13, 2023, which replaced the 2015 cybercrime law and governs data security offenses.
- The Jordanian Electronic Transactions Law No. 15 of 2015, governing electronic records and communications.
- The Jordanian Labor Law No. 8 of 1996 and its amendments, as applicable to employment data.
- Apple App Store Review Guidelines (including Guideline 5.1 on Privacy and Guideline 5.1.2 on data sharing with third parties including AI systems, updated November 2025).
- Google Play Developer Program Policies, including the Data Safety section requirements and account deletion requirements.
By using the App, you provide your explicit consent to the collection and processing of your data as described in this Privacy Policy, in accordance with Article 5 of the PDPL. If you do not agree, please do not use the App.
2. Data Controller Information
- Data Controller: Jaber Group
- Publisher / Data Processor: MOHAMMAD GAZE NAYEF JABER
- Google Play Developer Name: Jaber Group
- Account Owner / Contact Person: Saleh Barjakly
- Contact Email: ai.dev.jabergrp@gmail.com
- Website: https://www.jaber-grp.com/
- Address: Jaba al hussain, 1, Amman - 11121, Jordan (JO)
- Phone: +962770369440
Under Article 8 of the PDPL, Jaber Group acts as the Data Controller and is responsible for protecting all data in our custody. The Publisher acts as a Data Processor facilitating the publication and technical operation of the App on behalf of Jaber Group.
3. Information We Collect
3.1 Personal Data You Provide (Registration & Profile)
| Data Type | Required/Optional | Purpose |
|---|---|---|
| Full name | Required | Account identification |
| Email address | Required | Account identification and authentication |
| Password | Required (stored only as bcrypt hash, never in plain text) | Authentication |
| Employee ID | Assigned by manager after approval | Employer identification |
| Phone number | Required | Account verification and workplace contact |
| Nationality | Required | Employer identification and compliance |
| National ID number | Required | Employer identification (this is sensitive personal data under Article 2 of the PDPL) |
| Job title | Required | Organizational assignment and access control |
| Preferred language | Required | Localized app experience and privacy notice presentation |
| Country, brand, branch | Required | Organizational assignment |
| Profile picture | Optional (uploaded by you) | Personalization |
3.2 Security and Audit Data
To protect accounts and provide an accountable administrative service, we record security and activity events. Depending on the event and your organization's settings, these records may include the event time, authenticated user, action and affected resource, request method and path, result/status, duration, request and correlation identifiers, IP address (full, masked, or disabled by policy), approximate country, device/browser user agent, referrer, and strictly redacted technical metadata. Passwords, authentication tokens, national identifiers, exam codes, and comparable secrets are excluded or redacted from audit metadata.
The database may also retain dormant historical employment/compliance records created by older versions of the App. Those records are no longer exposed as an active App module and are retained only where deletion would conflict with legal, compliance, or referential-integrity obligations.
3.3 Data Collected Automatically
| Data Type | When Collected | Purpose |
|---|---|---|
| Mobile activity timestamps | While App is active (synced periodically) | Inactivity policy enforcement |
| App usage patterns | During App use | Service delivery |
3.4 Data Collected With Your Permission
| Data Type | When Collected | Permission Required | Purpose |
|---|---|---|---|
| Camera images (front and back) | Only during proctored exam sessions, at configurable intervals | Camera permission (iOS: NSCameraUsageDescription; Android: CAMERA) | Exam integrity verification via AI analysis |
| GPS location (precise) | Only during exam start when geofencing is enabled for your role | Location permission (iOS: NSLocationWhenInUseUsageDescription; Android: ACCESS_FINE_LOCATION) | Verifying you are at an authorized exam location |
| WiFi network name (SSID) | Only during exam start when WiFi validation is enabled for your role | Network state permission | Verifying you are on an authorized network |
Important: Camera, location, and network data are collected only during specific exam-related actions, not continuously. You will be clearly informed before any such collection occurs.
3.5 Data Generated Through App Use
- Exam data: Scores, pass/fail status, attempt counts, session timestamps, answers submitted
- Cheat detection logs: Records of suspicious behavior during exams (app switching, screen capture attempts)
- AI analysis results: Cheat scores and verdicts generated from proctoring image analysis
- Learning progress: Video watch position and duration, course completion status
- Gamification data: Points balance, coins balance, spin wheel history, leaderboard rankings
- Shop data: Redemption codes, redemption history, transaction records
- Support data: Technical tickets, inquiries, and communications
- Notification history: Notifications received and read status
- Administrative audit history: Security, authentication, authorization, configuration, and data-change events
4. Legal Basis for Processing
Under Article 5 of the PDPL, we process your data based on the following lawful bases:
- Explicit Consent: You provide consent when you register for the App and when you grant camera, location, or network permissions for exam proctoring. Your consent is documented electronically as required by the PDPL.
- Contractual Necessity: Processing necessary to provide the services you have requested (educational content delivery, exam management, rewards, support, and account administration).
- Legitimate Interest of Your Organization: Your organization uses this App as a workplace learning and assessment tool. Exam integrity monitoring, security auditing, access control, and performance reporting serve legitimate operational and security interests.
- Legal Obligation: Retention of records where required by applicable law, including legacy employment records created before retirement of the former employment-management features.
You may withdraw your consent at any time (see Section 9), though this may affect your ability to use certain features of the App.
5. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation and authentication | Name, email, password hash | Consent, Contract |
| Delivering educational content | User ID, category permissions, video progress | Contract |
| AI learning assistant and source indexing (Rafiq) | Eligible training content processed in the background; the question you submit, app language, and authorized training metadata, FAQ text, or indexed passages evaluated during learner search | Contract, Employer interest |
| Exam administration and scoring | User ID, exam answers, scores, timestamps | Contract, Employer interest |
| Exam proctoring and integrity | Camera images, location, WiFi SSID, cheat logs | Explicit consent |
| AI-powered cheat detection | Proctoring images, exam behavior data | Explicit consent |
| Points/coins reward system | User ID, transaction history | Contract |
| Shop redemptions | User ID, coin balance, redemption codes | Contract |
| Security, fraud prevention, and accountability | Authentication events, administrative actions, request and device/network context | Contract, Employer interest, Legal obligation |
| Notifications | User ID, notification content | Contract |
| Inactivity monitoring | Mobile activity timestamps | Employer interest |
| Company analytics and reporting | Aggregated exam and performance data | Employer interest |
| Technical support | Ticket content, user details | Contract |
6. AI-Powered Processing and Third-Party Data Sharing
6.1 AI Features
In compliance with Apple App Store Guideline 5.1.2 (updated November 2025), we explicitly disclose that your personal data is shared with the following AI system:
Google Gemini AI (provided by Google LLC) is used for:
- Exam proctoring image analysis: Your camera images captured during proctored exams are sent to Google Gemini for AI analysis to detect potential cheating. The AI generates a cheat score (0-100) and a verdict.
- Question generation: Administrators use AI to generate exam questions from educational content. This does not involve your personal data.
- Question voice generation: Administrators may send question or answer text, plus voice-delivery settings, to Google Gemini to create AI narration. This feature is for administrator-authored learning content and is not intended to include your personal data.
- Rafiq source indexing: If your organization enables Rafiq indexing, a background process sends eligible course content to Google Gemini without waiting for a learner question. A video file may be uploaded and analyzed in bounded time ranges; only requested PDF page ranges and normalized article text ranges are sent for each analysis call. Gemini returns routing notes and page, time, or text locators that Jaber Connect checks for valid structure and source bounds and stores with the training source. Generated video and PDF statements are used only to improve material routing and are not treated as proof of a factual answer. Only exact article extracts that Jaber Connect independently matches to the current normalized source text may be shown as learner-facing evidence. Exam question banks are not part of this indexing process.
- Rafiq learner questions: When you choose to ask Rafiq a question, your question, app language, and the titles, descriptions, FAQ excerpts, or indexed passages that Rafiq evaluates from training material you are currently authorized to access are sent to Google Gemini. This is used to locate and explain your assigned training material. Hidden or unassigned material and exam question banks are not included in learner search.
Your explicit consent is obtained before AI analysis of proctoring images. By starting a proctored exam, you consent to that analysis. Rafiq question processing starts only when you submit a question, but organization-enabled source indexing may run independently in the background. Do not include personal or sensitive information that is not needed for your learning request.
For uploaded Rafiq source files, Jaber Connect requests deletion from Gemini promptly after the relevant processing completes. This deletion is best effort: a client interruption or provider deletion failure can prevent immediate deletion, and Google controls its own processing and retention under the applicable service terms.
6.2 Third-Party Service Providers
We share data with the following third-party processors, each acting under our instructions in accordance with Article 12 of the PDPL:
| Provider | Location | Data Shared | Purpose |
|---|---|---|---|
| Google Gemini AI (Google LLC) | United States | Proctoring images; administrator-authored learning content and voice-delivery settings; eligible training video files, PDF page ranges, and article text ranges for Rafiq indexing; learner-submitted Rafiq questions and relevant authorized training metadata or excerpts | AI analysis, question generation, voice narration, Rafiq source indexing, and the Rafiq learning assistant (see 6.1) |
| Cloudflare, Inc. | Global CDN | Proctoring images, profile pictures, PDF documents, question and answer voice audio | Image, audio, and file storage |
| Vimeo, Inc. | United States | No personal data | Video content hosting |
| Google Maps Platform (Google LLC) | United States | GPS coordinates (during exam validation only) | Geofencing location verification |
| Railway | United States | All application data | Database and server hosting |
6.3 Cross-Border Data Transfer
Under Article 13 of the PDPL, personal data must not be transferred outside Jordan if the destination provides a lower level of protection, except where the data subject has explicitly consented after being informed.
Disclosure: Your data is stored on and processed by servers located outside Jordan (United States and global CDN locations). By using this App, you explicitly consent to this cross-border transfer, having been informed that these jurisdictions may not provide the same level of data protection as Jordan's PDPL. We ensure our third-party providers maintain appropriate security measures.
6.4 We Do NOT:
- Sell your personal data to any third party
- Share your data with advertisers or marketing companies
- Use your data for purposes unrelated to the App's services
- Share your data with any party not listed in this Privacy Policy
7. Data Shared With Your Employer
Your organization's authorized administrators and managers may access:
- Your exam scores, pass/fail status, and attempt history
- AI cheat detection results and proctoring analysis
- Your learning progress and video completion status
- Your points/coins balance and leaderboard ranking
- Administrative security and audit events associated with your account
- Your account status (active, inactive, verified)
This sharing is necessary for the App's core purpose as a workplace learning, assessment, and administration tool.
8. Data Security
In compliance with Article 8 of the PDPL, we implement the following security measures:
- Password protection: All passwords are hashed using bcrypt (one-way encryption) before storage. We never store or have access to your plain-text password.
- Authentication: JWT (JSON Web Token) based authentication with automatic session expiration.
- Encryption in transit: All data transmitted between the App and our servers uses HTTPS/TLS encryption.
- Role-based access control: Granular permission system ensuring users only access data authorized for their role.
- Screenshot protection: The App includes screen capture protection (react-native-capture-protection) to prevent unauthorized recording of educational content.
- Account verification: New accounts require branch manager approval before activation.
- Automatic deactivation: Accounts are automatically deactivated after configurable periods of inactivity.
- Accountability controls: Administrative and security-sensitive activity is recorded with integrity fingerprints, tenant isolation, configurable retention, and privacy-aware redaction.
8.1 Data Breach Notification
In compliance with the PDPL's breach notification requirements:
- We will notify affected users within 24 hours of discovering a serious data breach that could cause harm.
- We will notify the relevant Jordanian authority (the Personal Data Protection Unit) within 72 hours of discovering such a breach.
- Notifications will include details of the breach and measures you can take to mitigate negative consequences.
9. Your Rights Under the PDPL
Under Articles 9-11 of the Jordanian PDPL, you have the following rights. You are free from any financial or contractual consequences for exercising these rights:
- Right to Access (Article 9): You may request access to and obtain a copy of all personal data we hold about you.
- Right to Withdraw Consent (Article 9): You may withdraw your consent to data processing at any time. This may affect your ability to use certain App features.
- Right to Correction (Article 9): You may request correction, amendment, or update of any inaccurate or outdated personal data.
- Right to Erasure (Article 9): You may request deletion of all personal data collected about you, subject to legal retention requirements.
- Right to Limit Processing (Article 9): You may request that processing of your data be limited to a specific scope.
- Right to Object (Article 9): You may object to processing or profiling that is unnecessary, excessive, discriminatory, or in violation of Jordanian law.
- Right to Data Portability (Article 9): You may request transfer of your data from our possession to another data controller.
- Right to Be Notified (Article 9): You have the right to be notified of any data breaches that may compromise your data's security.
How to Exercise Your Rights
- In-App: Contact your organization's administrator
- Email: Send a request to ai.dev.jabergrp@gmail.com
- Account Deletion: You may request complete account and data deletion by contacting ai.dev.jabergrp@gmail.com or through your organization's administrator. We will process deletion requests within 30 days, subject to legal retention obligations.
Google Play Account Deletion Requirement: In compliance with Google Play's account deletion policy, we provide both an in-app path and a web-accessible method (email) for requesting account and data deletion.
10. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of active account + 1 year after deletion request | Service delivery, legal compliance |
| Exam scores and results | Duration of employment relationship + as required by employer | Employer compliance, training records |
| Proctoring images | As configured by your organization (default: duration of exam session review period) | Exam integrity verification |
| Cheat detection logs | Duration of employment relationship | Audit and compliance |
| Security and administrative audit events | Organization-configured period (30-3,650 days; default 365 days) | Security, accountability, legal compliance |
| Legacy employment/compliance records | Only as required by applicable law or referential-integrity obligations | Legal obligation |
| Video progress | Duration of active account | Service delivery |
| Points/coins transactions | Duration of active account | Service delivery |
| Shop redemptions | Duration of active account + 1 year | Transaction records |
| Notifications | 90 days or until deleted by user | Service delivery |
| Inactivity logs | 1 year | Audit trail |
| Rafiq indexed routing notes, verified article extracts, and source locators | Retained as immutable source-version history until the applicable material or notes version is deleted under the organization's content-retention practices | Training-material routing and source traceability for independently verified extracts |
| Rafiq training-source embedding vectors | Up to 45 days in a shared tenant-scoped search cache; changed or deleted source text is no longer queried but its prior derived vector expires on this bound | Faster semantic search without reprocessing unchanged training text |
| Rafiq questions and answers | Not retained by Jaber Connect as server-side conversation history; a response replay cache may be kept for up to 5 minutes and a question-derived search vector for up to 15 minutes | Reliable answer delivery and faster search |
Upon account deletion, we will erase your personal data except where retention is required by law (Jordanian Labor Law, PDPL compliance records).
11. Children's Privacy
The App is designed exclusively for use by employees within corporate organizations. It is not intended for children. We do not knowingly collect personal data from anyone under the age of 18. If we discover that we have collected data from a person under 18, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us immediately at ai.dev.jabergrp@gmail.com.
12. Device Permissions
The App may request the following device permissions:
| Permission | Platform | When Requested | Purpose | Required? |
|---|---|---|---|---|
| Camera | iOS, Android | Before proctored exams | Capturing proctoring images | Only for proctored exams |
| Location (When In Use) | iOS, Android | Before geofenced exams | Verifying authorized exam location | Only for geofenced exams |
| Network/WiFi State | Android | Before WiFi-validated exams | Verifying authorized network | Only for WiFi-validated exams |
| Internet | iOS, Android | Always | App functionality | Yes |
| Local Storage | iOS, Android | Always | Caching authentication tokens and preferences | Yes |
You can revoke camera and location permissions at any time through your device settings. Revoking these permissions may prevent you from taking proctored or geofenced exams.
13. Cookies and Local Storage
The App uses local device storage (AsyncStorage) to store:
- Authentication tokens (for keeping you logged in)
- User profile data (for offline display)
- Category permission cache (for content access)
The App does not use browser cookies, advertising identifiers, or tracking pixels. We do not track you across other apps or websites.
14. Push Notifications
The App may send notifications regarding:
- Account status updates (verification, deactivation)
- Administrative announcements from your organization
- Security and administrative notices
You can disable notifications through your device settings at any time.
15. Virtual Currency Disclosure
The App uses an internal virtual currency system (Points and Coins). These have no real-world monetary value, cannot be exchanged for real currency, and are not connected to any payment processing system. No real-money transactions occur within the App. There are no in-app purchases.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make changes:
- We will update the "Last Updated" date at the top
- For material changes, we will notify you through the App
- Your continued use of the App after changes constitutes acceptance
Under the PDPL, if the nature, type, or purposes of processing change, we will obtain fresh consent from you.
17. Complaints
If you believe your data protection rights have been violated, you may:
- Contact us at ai.dev.jabergrp@gmail.com
- File a complaint with the Jordanian Personal Data Protection Unit established under the PDPL
- Seek remedy through the competent courts in Amman, Jordan
18. Governing Law
This Privacy Policy is governed by the laws of the Hashemite Kingdom of Jordan. Any disputes shall be subject to the exclusive jurisdiction of the courts of Amman, Jordan.
19. Contact Us
Jaber Group (Data Controller)
- Email: ai.dev.jabergrp@gmail.com
- Website: https://www.jaber-grp.com/
- Address: Jaba al hussain, 1, Amman - 11121, Jordan (JO)
- Phone: +962770369440
- Contact Person: Saleh Barjakly
Publisher
- Legal Name: MOHAMMAD GAZE NAYEF JABER
- Google Play Developer Name: Jaber Group
*This Privacy Policy was last updated on July 13, 2026.*