PRIN-006 — المبادئ الحاكمة
مبدأ حماية البيانات والخصوصية
Principle of Data Protection & Privacy
رقم الإصدار: v1.0
تاريخ النفاذ: 2026-08-20
02 — مبدأ الامتثال
الحالة: مبدأ حاكم أساسي
النطاق: منظومة بال لانسر، ومشغلها، والأنشطة والعلاقات والإجراءات التي تتم أو تُدار من خلالها، كلٌ في حدود ما ينطبق عليه قانونًا وتعاقديًا.
أولًا: نص المبدأ
تلتزم منظومة بال لانسر ومشغلها بإدارة وتشغيل الخدمات والوظائف الواقعة ضمن نطاق مسؤوليتهما وفق القوانين والأنظمة والتعليمات والمتطلبات التنظيمية والقواعد الملزمة واجبة التطبيق، بما في ذلك ما ينطبق منها على المعاملات العابرة للحدود.
ويُعد الامتثال عنصرًا أصيلًا في تصميم وتشغيل المنظومة، ويجب مراعاته عند إنشاء أو تعديل العقود والسياسات والإجراءات والوظائف التقنية والتكاملات الخارجية، بما يتناسب مع طبيعة النشاط والدور الذي تؤديه بال لانسر.
ولا يجوز تصميم أو تشغيل أي وظيفة أو إجراء داخل المنظومة بقصد تجاوز متطلب قانوني أو تنظيمي واجب التطبيق، أو تمكين نشاط يتطلب ترخيصًا أو تصريحًا أو أهلية قانونية خاصة دون استيفاء المتطلبات اللازمة له.
ثانيًا: الامتثال في حدود الدور والمسؤولية
تتحمل بال لانسر مسؤولية الامتثال للمتطلبات القانونية والتنظيمية التي تنطبق عليها وعلى الأنشطة والوظائف التي تقوم بها فعليًا.
ولا يؤدي ارتباط المنظومة أو تكاملها تقنيًا أو تشغيليًا مع بنك أو مزود خدمات دفع أو أي جهة مالية مرخصة إلى انتقال المسؤوليات التنظيمية أو الترخيصية الخاصة بتلك الجهة إلى بال لانسر.
وبالمقابل، لا يعفي وجود جهة خارجية أو شريك مرخص بال لانسر من الالتزامات التي تقع عليها هي بموجب القانون أو الاتفاق أو طبيعة الدور الذي تؤديه.
ويجب المحافظة على فصل واضح بين المسؤوليات التشغيلية والتقنية للمنظومة وبين المسؤوليات المالية أو التنظيمية أو المهنية التي تقع قانونًا على الجهات المرخصة أو المختصة.
ثالثًا: الأنشطة الخاضعة للترخيص
لا يجوز لبال لانسر ممارسة أو تقديم نفسها على أنها تمارس نشاطًا ماليًا أو مصرفيًا أو مهنيًا أو تنظيميًا يتطلب ترخيصًا خاصًا، ما لم يكن ذلك النشاط مشمولًا بترخيص قانوني نافذ يجيز لها ممارسته.
وعندما تعتمد معاملة أو خدمة على نشاط مالي خاضع للترخيص، يجب تنفيذ ذلك النشاط من خلال الجهة المالية المرخصة والمختصة، وفقًا للقانون والترخيص والترتيبات التعاقدية ذات الصلة.
ولا تُعد الوظائف التقنية التي تقوم بها بال لانسر — بما في ذلك إنشاء العقد، أو تسجيل حالة المعاملة، أو تسجيل استحقاق تشغيلي، أو إرسال تعليمات أو بيانات تكاملية إلى الجهة المالية المرخصة — بذاتها ممارسةً للخدمة المالية التي تنفذها الجهة المرخصة.
رابعًا: التحقق والامتثال المرتبط بالمستخدمين والمعاملات
يجوز للمنظومة، ويجب عليها متى كان ذلك مطلوبًا قانونًا أو تنظيميًا أو لازمًا لتشغيل الخدمة بصورة مشروعة وآمنة، طلب المعلومات أو المستندات أو الإقرارات اللازمة للتحقق من هوية المستخدم أو صفته أو أهليته أو صلاحياته أو طبيعة معاملته.
ويجب أن تكون متطلبات التحقق متناسبة مع الغرض المشروع منها وطبيعة العلاقة والمخاطر والمتطلبات واجبة التطبيق، وألا تتجاوز المعلومات اللازمة لتحقيق ذلك الغرض.
ويجوز، وفقًا للقانون والسياسات والإجراءات المعتمدة، تقييد أو تعليق أو رفض خدمة أو معاملة عندما:
- يكون تنفيذها محظورًا قانونًا؛
- يتعذر استيفاء متطلب قانوني أو تنظيمي لازم لإتمامها؛ أو
- توجد مؤشرات أو أسباب معقولة تستدعي التحقق من الامتثال قبل السماح بإنشائها أو استمرارها.
ولا يجوز استخدام إجراءات التحقق بصورة تعسفية أو لغير الأغراض المشروعة التي وضعت من أجلها.
خامسًا: الامتثال المالي وقواعد الحظر
تلتزم بال لانسر، في حدود دورها القانوني والتشغيلي، بالمتطلبات واجبة التطبيق عليها فيما يتعلق بسلامة المعاملات ومكافحة الاستخدام غير المشروع للمنظومة والقيود القانونية والتنظيمية ذات الصلة.
أما إجراءات الامتثال المالي التي تقع بحكم القانون أو الترخيص على البنك أو مزود خدمات الدفع أو الجهة المالية المرخصة — بما في ذلك إجراءات التحقق والمراقبة والرقابة المالية التي تدخل ضمن اختصاصها — فتظل من مسؤولية تلك الجهة.
ويجب أن تسمح ترتيبات التكامل والتعاون، في الحدود المسموح بها قانونًا، بتبادل المعلومات أو الإشعارات اللازمة لتمكين كل جهة من تنفيذ الالتزامات الواقعة عليها، دون الخلط بين أدوار الأطراف أو نقل المسؤولية التنظيمية من جهة إلى أخرى دون أساس قانوني.
وتُنظم التفاصيل المتعلقة بـ مكافحة غسل الأموال وتمويل الإرهاب، والتحقق المالي، والعقوبات والقيود القانونية أو التنظيمية واجبة التطبيق، ضمن السياسات والاتفاقيات المتخصصة وبحسب نطاق مسؤولية كل طرف.
ولا يؤدي ذلك إلى إسناد مسؤوليات الجهة المالية المرخصة إلى بال لانسر أو اعتبار المنظومة جهة مالية لمجرد تكاملها التقني أو التشغيلي مع تلك الجهة.
سادسًا: الامتثال في العقود والمعاملات
يجب ألا يؤدي إنشاء عقد أو قبول عرض سعر أو تعديل معاملة أو تنفيذ إجراء تشغيلي من خلال بال لانسر إلى تجاوز متطلب قانوني أو تنظيمي واجب التطبيق.
ويجوز للمنظومة منع إنشاء المعاملة أو تعليقها أو إيقاف استمرارها عندما يتبين وجود مانع قانوني أو تنظيمي يحول دون إتمامها، وفقًا للقانون والسياسات والعقود المعتمدة.
ولا يؤدي قبول المستخدم إلكترونيًا لأي شرط أو اتفاق أو عقد إلى إضفاء المشروعية على نشاط محظور، أو تصحيح مخالفة قانونية، أو تجاوز متطلب تنظيمي إلزامي.
وتراعى، عند وجود عنصر عابر للحدود، المتطلبات والقيود القانونية والتنظيمية واجبة التطبيق على المعاملة أو الأطراف أو الخدمة بحسب الحالة، دون افتراض خضوع جميع المعاملات الدولية لنظام قانوني واحد.
سابعًا: الامتثال في استخدام الذكاء الاصطناعي
يجوز استخدام تقنيات الذكاء الاصطناعي داخل بال لانسر للمساعدة في تحليل المحادثات، واستخراج عناصر الاتفاق، والكشف عن البيانات الناقصة، والمساعدة في إعداد عروض الأسعار أو المستندات التعاقدية وفق القوالب والقواعد المعتمدة.
ولا يجوز اعتبار مخرجات الذكاء الاصطناعي بذاتها موافقة ملزمة من أحد الأطراف، ولا يجوز منحها سلطة مستقلة لاتخاذ قرار قانوني أو مالي أو تنظيمي يتطلب موافقة بشرية أو صلاحية قانونية محددة.
ولا يجوز للذكاء الاصطناعي أن يفرض على الأطراف سعرًا أو نطاق عمل أو التزامًا تعاقديًا لم يعتمدوه.
ويجب أن تخضع الوظائف المعتمدة على الذكاء الاصطناعي للضوابط والسياسات المقررة لها، وأن تظل القرارات الملزمة للأطراف خاضعة للموافقات والصلاحيات المطلوبة.
ثامنًا: الامتثال وحماية البيانات وتقليلها
يجب تنفيذ إجراءات الامتثال والتحقق وجمع المعلومات ومعالجتها بطريقة تراعي القواعد واجبة التطبيق المتعلقة بحماية البيانات والخصوصية والسرية وأمن المعلومات.
ويجب تطبيق مبدأ تقليل البيانات، بحيث يقتصر جمع البيانات ومعالجتها على القدر المشروع والضروري والمتناسب مع الغرض المحدد الذي جُمعت من أجله، وفقًا للمتطلبات واجبة التطبيق.
ولا يجوز استخدام متطلبات الامتثال كمبرر لجمع أو معالجة أو الاحتفاظ ببيانات تتجاوز ما يلزم لتحقيق الغرض المشروع أو ما يفرضه القانون.
وتُنظم الأحكام التفصيلية المتعلقة بجمع البيانات ومعالجتها والاحتفاظ بها والإفصاح عنها وحمايتها وحقوق أصحابها ضمن المبادئ والسياسات والاتفاقيات المتخصصة ذات الصلة.
تاسعًا: التحديث والاستجابة للتغير التنظيمي
تخضع سياسات وإجراءات وضوابط الامتثال للمراجعة والتحديث عند حدوث تغيير قانوني أو تنظيمي مؤثر، أو تغير جوهري في نموذج أعمال المنظومة أو خدماتها أو الأسواق التي تعمل فيها.
ويجوز تعديل أو تعليق أو تقييد أي وظيفة أو خدمة عندما يكون ذلك ضروريًا للامتثال لمتطلب قانوني أو تنظيمي واجب التطبيق، وفق الإجراءات القانونية والتعاقدية ذات الصلة.
ويجب أن تتم التعديلات المؤثرة على حقوق المستخدمين أو التزاماتهم وفق آليات الإشعار والموافقة أو غيرها من المتطلبات التي يفرضها القانون أو العقد بحسب الحالة.
عاشرًا: أثر مبدأ الامتثال
يعد مبدأ الامتثال أحد المبادئ الحاكمة لمنظومة بال لانسر، ويجب مراعاته عند إعداد ومراجعة وتشغيل العقود والسياسات والإجراءات والضوابط التقنية والتكاملات الخارجية والوظائف التي تعتمد عليها المنظومة.
ويُفسر هذا المبدأ بالاقتران مع مبدأ سيادة القانون وبقية المبادئ الحاكمة، دون أن يؤدي تطبيقه إلى توسيع اختصاص بال لانسر أو تحميلها مسؤوليات الجهات المالية أو المهنية أو التنظيمية المرخصة التي تتعامل معها.
وفي حال وجود متطلب امتثال تفصيلي يتعلق بنشاط أو سوق أو دولة أو نوع معاملة معين، يجب تنظيمه في السياسة أو الاتفاقية المختصة، بما يحدد بوضوح نطاق الالتزام والجهة المسؤولة عن تنفيذه.
02 — COMPLIANCE PRINCIPLE
Status: Fundamental Governing Principle
Scope: The PalLancer ecosystem, its operator, and the activities, relationships, and procedures conducted or administered through it, each to the extent legally and contractually applicable.
1. Principle
The PalLancer ecosystem and its operator shall manage and operate the services and functions falling within their respective scope of responsibility in accordance with all applicable laws, regulations, regulatory instructions, requirements, and binding rules, including those applicable to cross-border transactions.
Compliance shall constitute an integral element of the design and operation of the ecosystem and shall be taken into account when creating or modifying contracts, policies, procedures, technical functions, and external integrations, in a manner proportionate to the nature of the relevant activity and the role performed by PalLancer.
No function or procedure within the ecosystem shall be designed or operated for the purpose of circumventing any applicable legal or regulatory requirement, or enabling an activity requiring a license, authorization, permit, or specific legal capacity without satisfying the requirements applicable to such activity.
2. Compliance Within the Scope of Role and Responsibility
PalLancer shall be responsible for complying with the legal and regulatory requirements applicable to PalLancer itself and to the activities and functions that it actually performs.
The technical or operational integration of the ecosystem with a bank, payment service provider, or any other licensed financial entity shall not result in the transfer to PalLancer of the regulatory or licensing responsibilities applicable to such entity.
Conversely, the involvement of an external entity or licensed partner shall not relieve PalLancer of any obligations imposed upon it by applicable law, contractual arrangements, or the nature of the role it performs.
A clear separation shall at all times be maintained between the operational and technical responsibilities of the ecosystem and the financial, regulatory, or professional responsibilities legally assigned to licensed or otherwise competent entities.
3. Activities Subject to Licensing
PalLancer shall not conduct, or represent itself as conducting, any financial, banking, professional, or regulatory activity requiring a specific license unless such activity is covered by a valid legal authorization or license permitting PalLancer to conduct it.
Where a transaction or service depends upon a financial activity subject to licensing, such activity shall be performed by the duly licensed and competent financial entity, in accordance with applicable law, the relevant license, and the applicable contractual arrangements.
Technical functions performed by PalLancer — including creating a contract, recording the status of a transaction, recording an operational entitlement, or transmitting integration instructions or data to a licensed financial entity — shall not, in and of themselves, constitute the provision by PalLancer of the financial service performed by the licensed financial entity.
4. Verification and Compliance Relating to Users and Transactions
PalLancer may, and where legally or regulatorily required or necessary for the lawful and secure operation of the service shall, request such information, documents, or declarations as may be necessary to verify a user's identity, status, legal capacity, authority, or the nature of a transaction.
Verification requirements shall be proportionate to their legitimate purpose, the nature of the relationship, the relevant risks, and the applicable requirements, and shall not extend beyond the information necessary to achieve such purpose.
In accordance with applicable law and approved policies and procedures, PalLancer may restrict, suspend, or refuse a service or transaction where:
- its performance is prohibited by law;
- a legal or regulatory requirement necessary for its completion cannot be satisfied; or
- there are reasonable indicators or grounds requiring compliance verification before the transaction or service may be created or continued.
Verification procedures shall not be applied arbitrarily or for purposes other than the legitimate purposes for which they were established.
5. Financial Compliance and Applicable Restrictions
Within the scope of its legal and operational role, PalLancer shall comply with the requirements applicable to it concerning transaction integrity, prevention of unlawful use of the ecosystem, and relevant legal and regulatory restrictions.
Financial compliance procedures that, by law or by virtue of a license, fall within the responsibility of a bank, payment service provider, or other licensed financial entity — including verification, monitoring, and financial oversight procedures falling within that entity's regulated responsibilities — shall remain the responsibility of such entity.
Integration and cooperation arrangements shall, to the extent permitted by applicable law, enable the exchange of information or notifications necessary for each entity to discharge its respective obligations, without conflating the roles of the parties or transferring regulatory responsibility from one entity to another without a legal basis.
Detailed requirements concerning Anti-Money Laundering and Countering the Financing of Terrorism, financial verification, and applicable sanctions, legal restrictions, or regulatory restrictions shall be governed by the relevant specialized policies and agreements according to the scope of responsibility of each party.
Nothing in this Principle shall attribute the responsibilities of a licensed financial entity to PalLancer or cause PalLancer to be regarded as a financial institution merely because of its technical or operational integration with such entity.
6. Compliance in Contracts and Transactions
The creation of a contract, acceptance of a quotation, modification of a transaction, or implementation of an operational procedure through PalLancer shall not result in the circumvention of any applicable legal or regulatory requirement.
PalLancer may prevent the creation of a transaction, suspend it, or discontinue its continuation where a legal or regulatory impediment prevents its completion, in accordance with applicable law and the approved policies and contracts.
A user's electronic acceptance of any term, agreement, or contract shall not legalize a prohibited activity, cure a legal violation, or override a mandatory regulatory requirement.
Where a cross-border element exists, the legal and regulatory requirements and restrictions applicable to the transaction, the parties, or the relevant service shall be observed on a case-by-case basis, without assuming that all international transactions are governed by a single legal regime.
7. Compliance in the Use of Artificial Intelligence
Artificial intelligence technologies may be used within PalLancer to assist in analyzing communications between the parties, extracting agreed elements, identifying missing information, and assisting in the preparation of quotations or contractual documents in accordance with approved templates and rules.
Artificial intelligence outputs shall not, in and of themselves, constitute binding consent by either party, nor shall artificial intelligence be granted independent authority to make any legal, financial, or regulatory decision requiring human approval or specific legal authority.
Artificial intelligence shall not impose upon the parties any price, scope of work, or contractual obligation that has not been approved by them.
Functions relying on artificial intelligence shall be subject to the controls and policies established for their use, and decisions binding upon the parties shall remain subject to the required approvals and authorizations.
8. Compliance, Data Protection, and Data Minimization
Compliance, verification, collection of information, and data-processing procedures shall be implemented in a manner that observes applicable requirements relating to data protection, privacy, confidentiality, and information security.
The Data Minimization Principle — مبدأ تقليل البيانات shall apply, whereby the collection and processing of data shall be limited to what is lawful, necessary, and proportionate to the specific purpose for which such data is collected, in accordance with applicable requirements.
Compliance requirements shall not be used as a justification for collecting, processing, or retaining data beyond what is necessary to achieve the legitimate purpose or what is required by law.
Detailed provisions governing the collection, processing, retention, disclosure, and protection of data, as well as the rights of data subjects, shall be addressed in the relevant specialized principles, policies, and agreements.
9. Updates and Response to Regulatory Change
Compliance policies, procedures, and controls shall be reviewed and updated where there is a material change in applicable law or regulation, or a material change in the ecosystem's business model, services, or markets of operation.
Any function or service may be modified, suspended, or restricted where necessary to comply with an applicable legal or regulatory requirement, in accordance with the relevant legal and contractual procedures.
Where modifications materially affect users' rights or obligations, such modifications shall be implemented in accordance with applicable notice, consent, or other requirements imposed by law or contract, as the circumstances require.
10. Effect of the Compliance Principle
The Compliance Principle constitutes one of the governing principles of the PalLancer ecosystem and shall be observed in the preparation, review, and operation of contracts, policies, procedures, technical controls, external integrations, and functions upon which the ecosystem relies.
This Principle shall be interpreted in conjunction with the Rule of Law Principle and the other governing principles, without expanding PalLancer's authority or imposing upon it the responsibilities of the licensed financial, professional, or regulatory entities with which it interacts.
Where a detailed compliance requirement relates to a particular activity, market, jurisdiction, or type of transaction, such requirement shall be addressed in the relevant specialized policy or agreement, which shall clearly identify the scope of the obligation and the entity responsible for its implementation.