Skip to content
Terminal العربية

Privacy Policy

This document is an English draft pending legal review; the authoritative Arabic version will be published after counsel approval.All legal documents

DRAFT — REQUIRES REVIEW BY QUALIFIED EGYPTIAN LEGAL COUNSEL BEFORE USE

Non-final draft for counsel review. Not legal advice; no legal effect. Do not publish or rely upon until reviewed and approved by a lawyer admitted in the Arab Republic of Egypt, and confirmed against the current Executive Regulations and guidance of Egypt's Personal Data Protection Centre. Complete all [bracketed] placeholders before use.

Terminal — Privacy & Data-Use Policy

Effective date: [EFFECTIVE DATE PLACEHOLDER]

Last updated: [LAST UPDATED PLACEHOLDER]

This Policy explains how Terminal collects, uses, shares, and protects personal data, and your rights, under Egypt's Personal Data Protection Law No. 151 of 2020 ("PDPL").

1. Who is the controller

The data controller is [OPERATOR LEGAL ENTITY NAME], [REGISTERED ADDRESS], Arab Republic of Egypt ("Terminal", "we"). Data-protection contact / Data Protection Officer: [DPO NAME / EMAIL / PHONE]. *(PDPL Art. 4 requires a controller to safeguard data and, per Art. 8, to designate a person responsible for data protection registered with the Personal Data Protection Centre.)*

2. Scope

This Policy covers personal data of individuals we deal with through the Platform — for example, the named users, representatives, and contacts of member organizations (Buyers and Providers) and website visitors. Terminal is a B2B platform; most information exchanged concerns organizations, but individuals' personal data (such as names, business emails, and phone numbers) is included and is protected under the PDPL.

3. What data we collect

  • Account and profile data — names, business email, phone, job title, organization details, credentials, seat/role assignments.
  • Provider/Buyer listing and verification data — company profile fields, category, capacity information, and documents you upload (e.g. commercial registration, tax card, certificates, licences), which may contain personal data of your representatives.
  • RFQ, quote, and messaging data — the content of RFQs, quotes, attachments, and messages you exchange with other Members.
  • Usage and technical data — log data, device/browser information, IP address, and interactions with the Platform, used for security, operation, and improvement.

4. Lawful basis and consent

We process personal data on the basis of your explicit consent and/or another lawful basis permitted under the PDPL (such as processing necessary to perform our contract with you and to operate the service you request). *(PDPL Art. 2, Art. 6, and Art. 12 require the data subject's explicit — and, in the cases specified, written — consent, unless another legal basis applies; Art. 3 requires that data be collected for legitimate, specific, and transparent purposes.)* Where we rely on consent, you may withdraw it at any time through the mechanisms described in Section 9 *(PDPL Art. 17 requires clear, uncomplicated opt-out/withdrawal mechanisms)*; withdrawal does not affect processing already carried out.

5. How we use data

We use personal data to:

  • create and administer accounts, organizations, and seats;
  • operate the directory and the RFQ/quote workflow, and route your content to the Members you interact with;
  • carry out the limited verification review described in the Verification Boundary Statement;
  • provide support, security, fraud prevention, and service communications;
  • comply with legal obligations; and
  • improve and maintain the Platform.

We process data only for specified, legitimate purposes and do not keep it longer than necessary for those purposes *(PDPL Art. 3)*.

6. Consented aggregation and no sale of identifiable data

Terminal may produce aggregated and anonymized market insights or reports (for example, category-level demand or pricing trends). We will include an organization's data in such reports only in aggregated, anonymized form that does not identify the organization or any individual, and only where the organization has given explicit consent to that use. We do not sell identifiable commercial or personal data, and we do not disclose your identifiable RFQ, quote, or commercial data to third parties for their own marketing without your explicit consent, except as required by law or as necessary to operate the service you request (e.g. delivering your quote to the Buyer you responded to).

7. Documents and attachments

Files you upload (verification documents, RFQ/quote attachments) are stored and made available only as needed to operate the service — for example, to complete verification review or to deliver an attachment to the intended recipient Member. Do not upload personal data you are not entitled to share. You are responsible for the lawfulness of the content you upload.

8. Retention

We retain personal data only for as long as necessary for the purposes described here, or as required by Egyptian law (for example, tax and commercial record-keeping), after which we delete or anonymize it *(PDPL Art. 3 and Art. 4 — retention limitation and deletion/anonymization after the purpose is fulfilled)*. [COUNSEL/OPERATOR: insert specific retention periods per data category once determined.]

9. Your rights and how to exercise them

Under the PDPL, you have the right to:

  • know about, access, and obtain a copy of your personal data we hold;
  • withdraw consent to the retention or processing of your personal data;
  • correct, update, add to, or erase your personal data;
  • restrict processing to a specified purpose;
  • be notified of any breach affecting your personal data; and
  • object to processing (or its results) where it conflicts with your fundamental rights and freedoms.

*(These rights are set out in the PDPL's data-subject rights provisions.)* To exercise any right, contact [DPO / DATA-REQUEST EMAIL]. We will respond within the period required by the PDPL and its Executive Regulations. You may also lodge a complaint with Egypt's Personal Data Protection Centre.

10. Sharing and processors

We share personal data with: (a) other Members, only as inherent in the service (e.g. showing your listing, delivering your RFQ/quote/message to the counterparty you chose); (b) service providers/processors who host and support the Platform under contract and on our instructions; and (c) authorities where required by law. Processors are bound to process data only on our instructions and to protect it *(PDPL Art. 5)*.

11. Cross-border transfer and hosting (Cloudflare)

The Platform is hosted on Cloudflare infrastructure, and some processing (e.g. storage, content delivery, and compute) may occur on servers located outside the Arab Republic of Egypt. Under the PDPL, transferring, storing, or sharing personal data abroad is permitted only where the destination country offers a level of protection at least equivalent to the PDPL and subject to obtaining the relevant licence or permit from the Personal Data Protection Centre *(PDPL Art. 14)*, and, in general, with the data subject's consent. [COUNSEL: confirm the transfer mechanism, any required Centre licence/permit, and whether data-residency configuration is needed; complete before use.]

12. Security

We apply technical and organizational safeguards appropriate to the risk to protect personal data against loss, misuse, and unauthorized access *(PDPL Art. 4)*. No system is completely secure. In the event of a personal-data breach, we will notify the Personal Data Protection Centre and, where required, affected data subjects, within the timeframes set by the PDPL *(Art. 7 — notify the Centre within 72 hours of becoming aware, and notify affected data subjects within 3 days of notifying the Centre; immediate notification where national security is involved)*.

13. Changes to this Policy

We may update this Policy. We will post the updated version with a new "last updated" date and, where changes are material, provide reasonable notice.

14. Contact

Data-protection queries and requests: [DPO / DATA-REQUEST EMAIL][OPERATOR LEGAL ENTITY NAME], [REGISTERED ADDRESS], Arab Republic of Egypt. Supervisory authority: Personal Data Protection Centre (Egypt).