AMA GCC Privacy Policy

Alhayek Medical Academy (AMA) ? NursesMap | Effective July 19, 2026

1. Introduction Alhayek Medical Academy (AMA) is committed to protecting the privacy of NursesMap users and processing personal data lawfully, fairly, transparently, and securely. This Privacy Policy has been prepared with reference to Jordan Personal Data Protection Law No. 24 of 2023 and any mandatory data-protection requirements applicable in the user’s country of residence.

2. Scope of this Policy This Policy applies to the NursesMap website and learning platform, student accounts, courses, question banks, recorded lectures, mock examinations, live sessions, VIP coaching, official support channels, payment and invoicing activities, and Academy-managed student communities. Third-party websites and services operate under their own privacy policies.

3. Data Controller and Contact Details The data controller is Alhayek Medical Academy (AMA), an independent training entity registered in Jordan. Privacy enquiries and data-subject requests may be submitted to Alhayekacademy@gmail.com. The Academy’s current official contact channels are listed in Section 20.

4. Personal Data We Collect Depending on the services used, the Academy may collect the following categories of personal data:

  • Account data, including legal name, email address, telephone number, country of residence, login credentials, purchased courses, and subscription plan.

  • Learning data, including course progress, quiz results, attempts, lecture-viewing activity, booked coaching sessions, and educational enquiries.

  • Technical and security data, including IP address, device and browser information, login timestamps, linked devices, error logs, password-recovery tokens, and suspected unauthorized activity.

  • Payment and invoicing data, including transaction amount, currency, date, reference number, payment status, and information required for payment processing and, where applicable, the issuance of tax invoices in accordance with applicable laws.

  • Support and communication data, including emails, WhatsApp messages, complaints, refund requests, and coaching-related correspondence.

5. Payment Card Information Payment-card information is processed by the relevant payment gateway or financial institution. The Academy does not ordinarily receive or retain complete card numbers or card security codes. Payment providers process such information under their own security and privacy terms.

6. Dynamic Watermark and Anti-Piracy Data Course videos may display a dynamic, non-obstructive watermark containing an internal tracking identifier linked to the user’s account. The watermark is designed not to display the user’s telephone number or email address directly on screen. Tracking identifiers and related access records may be used to investigate unauthorized recording, redistribution, account sharing, or copyright infringement. A tracking identifier will not, by itself, be treated as conclusive proof of intentional misconduct without an appropriate review of the surrounding evidence.

7. Purposes of Processing The Academy processes personal data to create and manage accounts; provide purchased courses and subscriptions; monitor learning progress; administer live sessions and VIP coaching; process payments and issue invoices; provide technical and educational support; prevent fraud, piracy, and account sharing; investigate policy violations; send service notices; improve platform performance and content; comply with legal and tax obligations; and manage refund requests and payment disputes.

8. Legal Bases for Processing Depending on the circumstances, processing is based on performance of the user agreement, compliance with legal obligations, the user’s consent where required, protection of legal rights, and the Academy’s legitimate interests in operating, securing, and improving its services, provided those interests do not override the user’s fundamental rights. Consent may be withdrawn at any time without affecting processing lawfully completed before withdrawal.

9. Cookies and Similar Technologies The platform may use cookies, local storage, and similar technologies to maintain login sessions, remember preferences, operate checkout functions, measure platform performance, and detect unauthorized activity. Consent will be requested for non-essential cookies where required by applicable law.

10. Sharing of Personal Data The Academy does not sell or rent personal data. Data may be shared, only to the extent reasonably necessary, with hosting and learning-platform providers, payment gateways and banks, electronic invoicing providers, where applicable and competent tax authorities, email and messaging providers, virtual-classroom services, technical and security providers, professional advisers, and public or judicial authorities acting under a valid legal requirement. Service providers must process data for authorized purposes and apply appropriate safeguards.

11. WhatsApp, Telegram, and External Platforms When users communicate through WhatsApp, Telegram, or another external platform, that platform may process data under its own privacy policy. Users should not post medical, financial, identification, or other highly sensitive information in public or group community channels.

12. International Data Transfers Some service providers may process or store data outside Jordan. Where personal data is transferred internationally, the Academy will use legally appropriate safeguards and take reasonable steps to ensure an adequate level of protection in accordance with applicable law.

13. Data Retention Personal data is retained only for as long as necessary for the purposes described in this Policy. Account and learning records are retained while the account or subscription remains active and for a reasonable period afterward to handle enquiries and legal claims. Transaction and invoicing records are retained for applicable statutory and tax periods. Security logs are retained for the period reasonably necessary to detect and investigate misuse. Data is deleted or anonymized when there is no continuing legal, contractual, or operational need to retain it.

14. Data Security The Academy applies proportionate administrative, technical, and organizational safeguards, including access controls, account and password protections, monitoring of suspicious activity, secure backups, encrypted communications where available, and restricted staff and service-provider access. No electronic system is completely secure, but reasonable precautions are maintained to reduce foreseeable risks.

15. Automated Monitoring and Account Decisions Automated tools may flag unusual simultaneous logins, suspected account sharing, attempted fraud, or unauthorized recording or downloading. A final decision producing a material adverse effect, such as permanent account termination, will not be based solely on an automated alert without appropriate human review. Affected users may request review through the official support email.

16. User Rights Subject to applicable law, users may request access to their personal data, a copy of their data, correction of inaccurate information, deletion where no lawful retention ground exists, restriction of certain processing, objection to eligible processing, withdrawal of consent, cessation of direct marketing, and data portability where legally and technically applicable. Users may also lodge a complaint with the competent dataprotection authority. The Academy may request reasonable information to verify the requester’s identity.

17. Adults Only The platform is intended for users aged 18 or older. The Academy does not knowingly collect personal data from children without a valid legal basis and any consent required from a parent or guardian. An account created contrary to this requirement may be closed and its data deleted, subject to mandatory retention obligations.

18. Marketing Communications Marketing communications will be sent only where permitted by law and, where required, with the user’s consent. Users may opt out at any time. Opting out of marketing does not prevent necessary account, transaction, security, or service communications.

19. Data Breaches and Policy Updates If a personal-data breach occurs, the Academy will investigate, contain, and document the incident and will notify the competent authority and affected users where required by law. This Policy may be updated to reflect legal, technical, or service changes. Material changes will be communicated through the platform or registered email within an appropriate period before taking effect where required.

20. Official Privacy and Support Contacts Privacy and data requests: Alhayekacademy@gmail.com | GCC WhatsApp Support: +966 56 796 1168 | Jordan WhatsApp Support: +962 7 9080 7575

21. Language and Mandatory Rights This Policy may be provided in Arabic and English. The Academy should identify the controlling version at publication. Nothing in this Policy limits any mandatory privacy or consumer-protection right that cannot lawfully be waived in the user’s country of residence.