These documents has been translated into English ​​for informational purposes only. The original, authoritative text (in Arabic) can be found at:
https://client.nashirnet.net/index.php?m=agreements&language=arabic

Last Update: 27/08/2026

Information Security Policy

This document forms an integral part of NashirNet's approved Terms and Conditions and must be interpreted and applied together with them. Together, they form the legal and regulatory framework governing the relationship between the Company and the Customer.

Using the website, creating an Account, requesting or using any Service, or continuing to use it constitutes an acknowledgment that you have read and understood this document and expressly and bindingly agree to all of its provisions.

If there is any conflict between the provisions of this document and the Terms and Conditions, the general Terms and Conditions shall prevail, unless the conflict relates to a matter specifically governed by this document. In that case, the provisions of this document shall prevail only in relation to that matter.


Purpose of the Policy:

This Policy establishes the general framework for protecting the security of NashirNet's information, systems, and technical infrastructure, ensuring the confidentiality, integrity, and availability of information, and reducing potential security risks in accordance with applicable laws and regulations.


Scope of Application:

This Policy applies to:

  • All NashirNet systems, networks, and infrastructure.
  • All employees, contractors, and authorized representatives.
  • All Customers and Users, to the extent related to their use of the Services.
  • Any Third Parties authorized to access or technically interact with NashirNet's systems.

Information Security Principles:

NashirNet manages information security in accordance with the following fundamental principles:

  • Confidentiality: Protecting information against unauthorized access.
  • Integrity: Maintaining the accuracy and completeness of information and preventing unauthorized modification.
  • Availability: Ensuring that systems and Services remain available within the approved operational limits.

Access and Permission Management:

  • Access permissions to systems and information are granted in accordance with the principle of least privilege.
  • Access permissions are reviewed periodically and revoked immediately when they are no longer required.
  • The User is responsible for protecting their login credentials and must not share them with any other party.

Protection of Systems and Infrastructure:

NashirNet is committed to applying appropriate technical and organizational measures to protect its systems, which may include:

  • Firewalls and intrusion detection and prevention systems.
  • Periodic security updates.
  • Continuous technical monitoring of the infrastructure.
  • Logical separation between operational environments whenever possible.

This shall not be interpreted as providing any absolute guarantee that security incidents will not occur.


Data and Information Security:

  • Customer data is treated with strict confidentiality and in accordance with the approved Privacy Policy.
  • Customer data is accessed only to the extent technically necessary to provide the Service, perform maintenance, or comply with legal requirements.
  • NashirNet is not responsible for any breach or leakage resulting from the Customer's negligence, inadequate configurations, actions, or the actions of its Users.

Backup and Business Continuity:

  • Backup procedures are applied in accordance with the approved technical policies and the applicable Service Plan.
  • Backup or business continuity procedures do not constitute an absolute guarantee against data loss or Service interruption.
  • The Customer remains responsible for maintaining additional independent backups whenever necessary.

Security Incident Management:

In the event of a security incident:

  • NashirNet takes appropriate measures to contain the incident and minimize its effects.
  • The incident is investigated within the available technical and organizational limits.
  • Affected parties, if any, are notified where legally required or operationally appropriate.

Customer Responsibilities:

Customers must:

  • Secure their Accounts and login credentials.
  • Monitor the activities, Services, and applications they operate or use within their Services.
  • Refrain from any use that may threaten the security of systems or networks.
  • Comply with the Acceptable Use Policy (AUP) and all related policies.

Third Parties:

Some Services may depend on a Third Party. Such Third Party is subject to its own policies and procedures, and NashirNet is not responsible for any security failure resulting from systems or Services that are not directly managed by NashirNet.


Compliance and Legal Obligations:

NashirNet applies this Policy in accordance with applicable laws and regulations and any regulatory requirements, court orders, or official instructions issued by competent authorities.


Amendments to the Policy:

NashirNet reserves the right to amend or update this Policy at any time. Any amendments become effective from the date they are published on the website. Continued use of the Services after publication constitutes implied acceptance of the amendments.