Privacy Policy
**Al-Rubaiy and Partners Law Firm**
**Last Updated**: May 2026
---
1. Introduction
### System Nature:
This Privacy Policy applies to the "Al-Rubaiy" mobile application and web system, exclusively designed for a **law firm** to organize and manage office operations and cases (financially, administratively, and legally).
### Who Can Use the System:
#### 1. **Mobile App (Android)**:
✅ **For employees and lawyers only** working at Al-Rubaiy Law Firm❌ **Not for clients** - clients cannot use the mobile app❌ **No public registration** - no one can create an account themselves✅ **Accounts created by administration only**#### 2. **Web System (Portal)**:
✅ **For employees**: Full access based on permissions✅ **For clients**: Limited portal to track their cases only❌ **No public registration** - all accounts created by administration#### What Clients Can Do via Web Portal:
✅ Access their own accounts✅ Track stages of their cases only✅ Monitor financial account for each of their cases✅ Text messaging with administration via portal❌ **Cannot**: View others' cases or general data❌ **Cannot**: Use the mobile app (Android)### System Purpose:
Organizing and managing law office operationsManaging cases legally, financially, and administrativelyElectronic archiving of paper documentsFacilitating communication between company branches in different governorates---
2. Data We Collect
The application collects the following data strictly for work purposes:
### Authentication Data:
Username and password for system accessDevice information (for security purposes only)### Work Records:
Legal cases, follow-ups, and documents entered by employeesReports and notes related to casesText and voice communications between employees and clients### Financial Data:
Service fees and commissions related to casesAccounting vouchers (receipts and payments)---
3. Permissions Required
### Camera:
**Capturing photos of legal documents** to attach to cases**Professional document scanning** using OpenCV technology**No access to photo gallery** - camera only### Files and Documents:
**File selection**: We use Android's native Storage Access Framework**No access to your files** except those you manually select**Uploaded files** are used only for legal case management**No storage read permissions required** on Android 13+### Microphone:
**Voice notes** linked to case files**Encrypted voice calls between employees only** for case discussions**Speech-to-text** for reports (processed locally on device)**No call recording** - live calls only### Firebase Cloud Messaging (FCM) — Push Notifications:
**Service**: Firebase by Google for delivering push notifications**What is sent**: Device token to Google servers solely to deliver notifications**Not used to identify you personally** — the token contains no personal information**Background notifications**: Call and message notifications can be received even when the app is **completely closed** via FCM**Call notifications**: Appear as a full-screen call interface on the lock screen**Google Privacy Policy**: https://policies.google.com/privacy### Proximity Sensor:
Used **only during active calls** to turn off the screen when the phone is held to the ear**No data is collected** from this sensor#### Purpose of Calls:
Communication between employees in **different company branches** (the company has branches in many governorates in Yemen)Discussing cases and coordinating between lawyersLegal consultations between employees**Calls are for employees only** - not for clients### Notifications:
Legal deadline alerts and case updatesIncoming call notifications---
4. Data Storage
### Storage Location:
All data stored on **Al-Rubaiy Law Firm's private servers**Servers located in secure, protected data centers**No data sharing** with unauthorized third parties### Retention Period:
**Active cases**: Duration of case + 5 years**Closed cases**: 10 years (legal and professional requirements)**Financial data**: 10 years (tax and legal requirements)**Conversations**: 1 year after case closure**Employee accounts**: Employment duration + 5 years after termination---
5. Security
### Encryption:
✅ **HTTPS/TLS 1.3** encrypted protocol✅ Data encryption at rest (**AES-256**)✅ Password encryption (**bcrypt**)### Access Control:
✅ Password authentication✅ Role-based permissions✅ Complete audit log### Protection:
✅ Advanced firewall✅ Continuous security monitoring✅ Daily backups✅ Disaster recovery plan---
6. Data Sharing
### System Nature:
The application and web system are **internal electronic archiving systems** only. The primary purpose is:
Maintaining electronic copies of paper documents archived at the company headquartersFacilitating information access for authorized employeesTracking case stages electronically### No External Data Sharing Policy:
No data is shared outside the application and web system whatsoever
#### Paper Originals:
✅ All original documents are kept **in paper form at company headquarters**✅ Electronic copies are **backup copies** for archiving only✅ When courts request documents, **original paper copies** are sent#### Data Access:
**Restricted to within the system only**:
✅ Authorized employees and lawyers (based on permissions)✅ No data export or transmission outside the system✅ No connection to external systems or third parties### What We Absolutely Do NOT Do:
❌ **No data sharing** with any external entity❌ **No electronic data transmission** to courts (we send paper copies)❌ **No connection to external systems** or public cloud services❌ **No selling or trading** of data❌ **No use for advertising** or marketing❌ **No sharing with advertising companies** or data brokers### Technical Infrastructure:
Servers are **company-owned** and located at headquarters or local data centers**No connection** to public cloud services (Google, AWS, Azure for external applications)System is **closed and isolated** - for internal use only---
7. Employee Rights
### You have the right to:
1. **Access**: View all data recorded under your name
2. **Correction**: Request correction of inaccurate data
3. **Portability**: Obtain a copy of your data
4. **Objection**: Refuse data processing for certain purposes
### Account Management:
#### Account Creation:
**Administration creates accounts** and maintains employee dataAdministration grants permissions based on each employee's roleEmployees **cannot create accounts** themselves#### What Employees Can Change:
✅ **Username**: Can be changed from account settings✅ **Password**: Can be changed anytime❌ **Permissions**: Set by administration only❌ **Job Role**: Determined by administration#### Working Within Permissions:
Each employee works **within granted permissions** from administrationPermissions determine what can be viewed and modifiedEmployees cannot exceed their permissions#### Upon Employment Termination:
**Administration deactivates the account** (not the employee)Account is **not deleted** - only deactivatedData retained for legal records (5 years)Employees **cannot delete their own accounts**#### For Inquiries:
For data inquiries or modifications, contact IT DepartmentTo request a copy of your data, contact administration---
8. Data Usage
### Primary Purpose: Legal and Financial Case Tracking
We use data **exclusively** for documenting and tracking case progress:
#### 1. **Legal Tracking**:
✅ Recording case stages (from intake to closure)✅ Documenting legal procedures performed by lawyers✅ Maintaining hearing dates and important deadlines✅ Tracking case status (active, pending, closed)#### 2. **Reporting**:
✅ Detailed reports of what happened at each stage✅ Documentation of actions and steps taken✅ Periodic case progress summaries✅ Internal performance statistics#### 3. **Attaching Supporting Documents**:
✅ Attaching photos or files of documents obtained by lawyers✅ Preserving documents that prove lawyer's actions✅ Archiving contracts, judgments, and correspondence✅ Documenting evidence and case-related documents#### 4. **Financial Tracking**:
✅ Recording service fees and commissions✅ Tracking payments and receivables✅ Issuing receipts and payment vouchers✅ Financial reports related to cases#### 5. **Communication and Messaging**:
**Voice Calls**:
✅ Encrypted voice calls **between employees only**✅ For case discussions and coordination between branches✅ Company has branches in many governorates in Yemen - calls facilitate communication❌ **No calls with clients** through the app**Text Messaging**:
✅ Text messages **between employees only**✅ For discussing cases and exchanging information✅ Encrypted and secure❌ **No chats with clients** through the app**Notifications**:
✅ Hearing and important deadline notifications✅ Incoming call alerts from employees✅ Case updates### What We Do NOT Use Data For:
❌ **No selling** data to third parties❌ **No use for advertising** or marketing❌ **No analysis** for commercial purposes outside work scope❌ **No sharing** outside the system whatsoever❌ **No use** for any purpose unrelated to case management---
9. Contact
**Email**: ameen25r@gmail.com
**Phone**: +967 779 266 601
**Address**: Al-Rubaiy Law Firm, Sana'a, Yemen
**Website**: https://rubaiy.com
### Data Protection Officer:
**Name**: mohhash
**Email**: mohhash2012@gmail.com
---
**Last Updated**: May 2026
**Version**: 3.0
**Language**: English
---
© 2026 Al-Rubaiy and Partners Law Firm. All rights reserved.