ASMH Africa
- Document code:
- ASMH-AFRIQUE-POL-23
- Version:
- 2.0
- Effective date:
- August 27, 2026
- Intended audiences:
- Candidate, trainee, graduate, and authorized employees
Preamble
تنظم هذه السياسة إنشاء الحساب والهوية الأكاديمية الداخلية وحمايتهما واستردادهما وتعليقهما والإبلاغ عن الحوادث، دون تقديمهما كاعتماد أو هوية حكومية أو ترخيص مهني.
Article 1: Create the account
One account is created per person after appropriate verification. Its data must reflect the real situation. It is prohibited to create multiple accounts to cheat or impersonate others.
Article 2: Internal academic identity
The account may include an academic number, mail, or digital card. These are internal tools for managing studies, and do not alone prove government accreditation, student status with another party, professional right, or external privilege.
Article 3: Login data
The account holder is obligated to create a unique and strong password, not to share it or send it by mail, to update the recovery methods, and to close the session on the shared device.
Article 4: Multi-factor verification
It may be requested upon sensitive entry, changing the means of recovery, or issuing a document or administrative account. It provides, as much as possible, a recovery method that does not depend on a single channel.
Article 5: Sessions and devices
The system may terminate an inactive session, request new verification upon unusual behavior, and limit reasonably concurrent sessions. Changing geographical location alone is not evidence of abuse.
Article 6: Activity Record
Login, attempts, password changes, deliverables, results, documents, permissions and necessary financial operations can be accessed. The register is not used for unannounced or disproportionate surveillance.
Article 7: Recovery
When access is lost, support verifies the identity with minimal appropriate information. A password or active verification code is not required. Restoration may include closing sessions, changing the password, and activating an additional agent.
Article 8: Urgent communications
You must report immediately:
- Changing the mail or phone without the knowledge of its owner;
- The appearance of data or result of another person;
- Password or code leak;
- Message impersonating the academy;
- Amending a result or document without support;
- Loss of a device with an active session;
- Validity should not be available.
Article 9: Security Comment
An account may be temporarily suspended upon reasonable suspicion of hacking, spoofing, malware, or data risk. The suspension shall be limited to the necessary duration and scope, and the holder shall be notified whenever notification would not prejudice the investigation or protection.
Article 10: Administrative or financial suspension
Subject to POL-04 and POL-16, it does not automatically delete works, change results, erase history, prevent complaints, or access to underlying personal data within legitimate limits.
Article 11: Reactivation
It takes place after the reason and verification have disappeared, and may require changing the password, closing sessions, and correcting data. No fees are charged after a hack that was not intentionally caused by the account holder.
Article 12: Academic mail
If it is temporary, its expiration date will be announced. Notice will be given prior to closing and a reasonable opportunity to save what is permitted to be transmitted and change mail associated with personal services.
Article 13: Graduate account and account closure
May be converted to limited powers of documentation and verification. Closing an entry does not mean deleting the necessary academic or accounting record, and POL-20 applies to deletion and retention.
Article 14: Harmful content and abusive use
It is prohibited to upload malware, unwanted identity documents, third party health data, cheating materials or content that violates rights. The file can be isolated in case of clear danger, with notification whenever possible.
Article 15: Automated decisions
No final penalty is issued that affects exclusively a technical warning. An authorized person reviews the data and context and allows the account holder to clarify.
Article 16: Academy responsibilities
It implements separation of powers, verification for administrative accounts, periodic auditing, revoking access when changing roles, logging of sensitive operations, and incident response.
Article 17: Review
You may request a review of an incorrect comment or merge, or a refund may be denied according to POL-18. The right to report to the competent authority is reserved.
Article 18: Communication
Urgent security report to [email protected] titled “Urgent — Account Security”, with no passwords or codes sent.

All policies
Privacy and security

