Privacy Policy

This policy explains what Ameen does with personal data. Ameen is operated by Ahmad Abu Rabee, an individual rather than a registered company, reachable at sales@ameen-erp.com.

What we hold

Account data: your name, email address, preferred language and number format, whether two-factor authentication is on, and when you were last active. Your password is stored only as an Argon2 hash and is never held in readable form.

Business records you enter: customers and suppliers (name, contact person, email, phone, tax number, address, notes), employees (name, job title, email, phone, hire date, salary, notes), and your invoices, payments, stock movements, and journal entries.

Security logs: sign-in attempts and administrative actions. In these logs your email address and IP address are stored only as one-way hashes, so a pattern of attempts can be investigated without keeping the identifiers in readable form.

Files: PDFs generated from your own documents, and any data export you request.

Access requests: if you send us an access request from the public website, we keep what you typed into the form, the domain name of the site that referred you, and any campaign tags (utm_source, utm_medium, utm_campaign) in the link you followed. We keep the domain name only, never the full referring address, and we record nothing else about your visit.

We set no advertising or analytics cookies, run no third-party trackers, and the application makes no requests from your browser to any third-party server.

Why we process it

To give you and your colleagues access to the workspace; to produce the documents and reports you ask for; to keep the service secure and investigate abuse; to email you about invitations, password resets, and subscription reminders; and to meet obligations the law places on us.

Much of what you enter is personal data about other people, typically your employees, customers, and suppliers. For that data you decide what is collected and why, and we act only on your behalf. The Data Processing Addendum sets out that relationship.

Who else is involved

We do not sell personal data and we share it with nobody else unless the law compels us to.

Where it is stored

Everything, including the database, uploaded files, and backups, sits on one server in the European Union (France). It is not replicated to other regions. If that ever changes we will say so here first.

How long we keep it

Backups are taken regularly, and copies of deleted data may remain in them until they are rotated out.

How we protect it

Passwords are hashed with Argon2. Two-factor authentication is available to every account. Every organisation's rows are separated by database-level row security, so one organisation cannot read another's data even if the application itself has a bug. All traffic runs over HTTPS.

Administrative access to the platform is separate from customer accounts, expires after 12 hours, and is written to an audit log. If an administrator ever needs to act inside your workspace to support you, that access is limited to one hour and is recorded.

Your rights

You can see and correct most of your data directly in the workspace. You can also ask us to:

Owners can start an export or a deletion request from workspace settings. For anything else, write to sales@ameen-erp.com. We aim to respond within 30 days. If you think we have mishandled your data, you may complain to the data protection authority where you live.

Children

Ameen is business software and is not intended for anyone under 18.

Changes

If this policy changes in a way that matters, we will email organisation owners before the change takes effect.