What this policy covers
This Privacy Policy explains how Mibsal ERP ("Mibsal", "we", "us") handles personal data across mibsal.com, registration and support, and the Mibsal ERP product. It is written for the organisations that subscribe, their authorised users, the people whose records an organisation enters — customers, clients, patients or guests — and website visitors. It should be read with our Terms of Service and the Jordanian Personal Data Protection Law No. (24) of 2023 and the regulations and instructions issued under it.
Who controls the data in your account
Your organisation decides what information is entered into Mibsal ERP, who on its staff can see it, and how long it must be kept. For the records it enters about the people it serves, your organisation is the controller and Mibsal acts as its processor, operating the software on your organisation's documented instructions. Mibsal is separately responsible as controller for the limited data it determines how to use itself, such as website enquiries, registration details, billing contacts, security logs and its direct customer relationship with your organisation. We do not sell personal data or share it with advertisers.
What we store
Depending on how your organisation uses the platform, Mibsal ERP stores:
- Your staff accounts: names, email addresses, phone numbers, and the role each person holds.
- The records your organisation enters about the people it serves: contact details, appointments and bookings, the work or service delivered, notes, documents, invoices and payments.
- Health data, but only where your organisation uses a module that records it — for example the medical history, allergies and other clinical alerts, charting, treatment plans, clinical notes and lab cases an organisation providing care keeps. Health data is a special category, and it is stored only because that organisation chose to record it.
- An activity log of who did what and when, kept automatically as you use the system.
We do not ask your organisation or the people it serves for anything beyond what the software's own screens collect, and we do not run any tracking or analytics script on the parts of the product your team uses day to day.
Why and how we process data
We process account and organisation data to review registrations, provide and secure the service, authenticate users, deliver support and notifications, administer subscriptions, keep financial records, prevent misuse and meet legal obligations. We process the records an organisation enters only to provide the functions that organisation chooses to use, including records, scheduling, work and treatment workflows, reporting, billing and authorised exports. Where consent is the applicable basis, the organisation is responsible for obtaining it in a clear form for each purpose. A person may withdraw consent subject to legal, contractual and financial obligations and, where the organisation keeps health or other regulated records, to the record-keeping rules that bind it.
How each organisation's data is kept separate
Every organisation's data is isolated at the database level: every record belongs to exactly one organisation, and every request the system serves is scoped to the organisation the logged-in user belongs to. There is no screen, report or export in Mibsal ERP that shows one organisation's records, appointments or invoices to another organisation.
Who at Mibsal can see your data
Day to day, nobody at Mibsal looks at your organisation's data. A small number of people who operate the platform can, when needed for support or maintenance, access it through an administrative account — and every time that happens, it is written to an activity log, both on your organisation's own record and on our separate operator log, noting who did it, when, and from where. We do not have a support process that is invisible to you.
The audit log
Every organisation has its own activity log recording who changed what, and when. It is append-only: there is no screen, in your organisation or in ours, that can edit or delete an entry once it is written. You can read it, filter it, and export it at any time.
Signed clinical notes, where an organisation records them
Where your organisation uses a clinical module, a clinical note becomes a permanent record once it is signed. It cannot be edited or deleted afterwards, by any account, including ours. If a signed note needs correcting, the correction is added as a separate, dated addendum — the original stays exactly as it was signed, and both are kept on file.
Security measures we take
Access to Mibsal ERP requires a login, and what a staff member can see or do is governed by the permissions your organisation assigns them — a receptionist's account is not an accountant's account unless you make it one. Your organisation's data, including any health data it records, is stored on servers we operate, isolated per organisation as described above, and every change of consequence is written to the audit log. We do not hold any external security certification (such as ISO 27001, HIPAA or SOC 2) today, and we do not claim to. If that changes, this page will say so.
What happens if a subscription lapses
If your organisation's trial or subscription lapses, the account moves to a read-only state: authorised users can still open records, run available reports and exports, but cannot create or edit data until the subscription is renewed. Recording payment restores write access. Read-only access is an access-control state, not a promise to retain every category forever. Retention and deletion are explained below.
Getting your data out
Your activity log can be exported from within Mibsal ERP at any time, whether your subscription is active or lapsed. For a full export of your organisation's other records — the people it serves, appointments, invoices and any clinical data — contact us at contact@mibsal.com and we will provide it.
Retention, deletion and backups
We retain each category only while it is needed to provide the service, maintain security and audit evidence, resolve disputes, or satisfy financial, tax, healthcare and other legal obligations. Your organisation determines the retention of the records it controls within those obligations, including any longer period its own regulator imposes — the medical records an organisation providing care must keep, for example. A closure or deletion request is assessed category by category: data that no longer has a lawful or necessary purpose is deleted or anonymised, while records that must be kept remain protected and access-restricted. Deletion from rotating backups follows the backup lifecycle and may not be immediate. An organisation may request the current retention details and a full export before closure.
Who we share data with
We disclose data only where needed to operate the service, follow an organisation's instruction, or meet a legal obligation. This can include infrastructure and backup providers, email delivery providers, and the government e-invoicing service of the market an organisation operates in — in Jordan, the Income and Sales Tax Department through JoFotara — for the invoices that organisation chooses to submit. Providers receive only what their function requires and are expected to protect it under appropriate contractual and confidentiality controls. We do not sell personal data, share it with advertisers, or use the records in an account to train a general-purpose model.
Devices and offline use
When your organisation's staff use Mibsal ERP without a connection, the app can keep working for reading your schedule and your records, and a new record or appointment created offline is held on that device until it reconnects and syncs. Nothing else — no invoice, no e-invoicing submission, no signed clinical note — is ever created or stored on a device while offline. Those actions require a live connection by design.
Children's data
Some of the people an organisation records are minors — a patient, a student, a customer's child. Where your organisation holds a minor's record, the same rules above apply to it as to any other. Obtaining the appropriate parental or guardian consent to serve that person and to record their data is your organisation's responsibility as the controller, not ours.
Website storage and cookies
The public website currently uses local browser storage to remember a visitor's privacy choice and, when changed, appearance preference. It does not currently load advertising or visitor-tracking analytics. The authenticated portals also keep the session credential on the signed-in user's device so requests can be authenticated. If optional analytics or another non-essential category is introduced, it must remain off until the visitor gives the relevant consent.
Your rights and how to exercise them
Subject to the Jordanian Personal Data Protection Law and its exceptions, a person may ask to be informed about processing, access their data, correct or complete it, object to unnecessary, excessive, discriminatory or unlawful processing, withdraw consent where processing relies on consent, and request deletion or transfer where the law permits. An organisation handles requests concerning the records it controls. Mibsal assists it as its processor. Mibsal handles requests about registration, account, website and relationship data it controls directly. Send a request to contact@mibsal.com. We may ask for information needed to verify identity and authority.
Changes to this policy
If we change how we handle your data in a way that matters, we will update this page and change the date at its top. We will not make a change here quietly.
Contact
Questions about this policy, or a request to export or correct data, can be sent to contact@mibsal.com.
