Effective 16 September 2026. Ameen is business software; this page is not legal, tax, or accounting advice.
Privacy Policy
This policy explains what Ameen does with personal data. Ameen is operated by Ahmad Abu Rabee, an individual rather than a registered company, reachable at sales@ameen-erp.com.
What we hold
Account data: your name, email address, preferred language and number format, whether two-factor authentication is on, and when you were last active. Your password is stored only as an Argon2 hash and is never held in readable form.
Business records you enter: customers and suppliers (name, contact person, email, phone, tax number, address, notes), employees (name, job title, email, phone, hire date, salary, notes), and your invoices, payments, stock movements, and journal entries.
Security logs: sign-in attempts and administrative actions. In these logs your email address and IP address are stored only as one-way hashes, so a pattern of attempts can be investigated without keeping the identifiers in readable form.
Files: PDFs generated from your own documents, and any data export you request.
Access requests: if you send us an access request from the public website, we keep what you typed into the form, the domain name of the site that referred you, and any campaign tags (utm_source, utm_medium, utm_campaign) in the link you followed. We keep the domain name only, never the full referring address, and we record nothing else about your visit.
We set no advertising or analytics cookies, run no third-party trackers, and the application makes no requests from your browser to any third-party server.
Why we process it
To give you and your colleagues access to the workspace; to produce the documents and reports you ask for; to keep the service secure and investigate abuse; to email you about invitations, password resets, and subscription reminders; and to meet obligations the law places on us.
Much of what you enter is personal data about other people, typically your employees, customers, and suppliers. For that data you decide what is collected and why, and we act only on your behalf. The Data Processing Addendum sets out that relationship.
Who else is involved
- Contabo, which provides the server. Your data is stored in the European Union (France).
- Resend, which delivers transactional email such as invitations, password resets, and reminders. It receives the recipient's address and the message.
- Let's Encrypt, which issues the HTTPS certificate for ameen-erp.com and receives no personal data.
We do not sell personal data and we share it with nobody else unless the law compels us to.
Where it is stored
Everything, including the database, uploaded files, and backups, sits on one server in the European Union (France). It is not replicated to other regions. If that ever changes we will say so here first.
How long we keep it
- Active records: for as long as your organisation exists.
- After a confirmed deletion request: 30 days, then removed.
- Workspace sign-in sessions: 30 days. Administrator sessions: 12 hours.
- Password reset links: 30 minutes. Invitations: 7 days. Two-factor challenges: 5 minutes.
- Data export downloads: 7 days, after which the link stops working.
- Security logs: retained for audit, with email and IP held only as hashes.
- Access requests from the public website: kept while we are following them up.
Backups are taken regularly, and copies of deleted data may remain in them until they are rotated out.
How we protect it
Passwords are hashed with Argon2. Two-factor authentication is available to every account. Every organisation's rows are separated by database-level row security, so one organisation cannot read another's data even if the application itself has a bug. All traffic runs over HTTPS.
Administrative access to the platform is separate from customer accounts, expires after 12 hours, and is written to an audit log. If an administrator ever needs to act inside your workspace to support you, that access is limited to one hour and is recorded.
Your rights
You can see and correct most of your data directly in the workspace. You can also ask us to:
- give you a copy of your organisation's data as a downloadable export
- correct anything inaccurate
- delete your organisation and its records
- stop processing where we have no overriding reason to continue
Owners can start an export or a deletion request from workspace settings. For anything else, write to sales@ameen-erp.com. We aim to respond within 30 days. If you think we have mishandled your data, you may complain to the data protection authority where you live.
Children
Ameen is business software and is not intended for anyone under 18.
Changes
If this policy changes in a way that matters, we will email organisation owners before the change takes effect.