#Legal #Privacy

Effective date: August 1, 2026

2.1 Scope and Data Controller

This Privacy Policy explains how [Legal Entity Name] ("Hirfa," "we") collects, uses, discloses, and protects personal data of Clients, Craftsmen, and visitors to gethirfa.com, in accordance with the Egyptian Personal Data Protection Law No. 151 of 2020 ("PDPL") and its executive regulations. Hirfa acts as the Data Controller for the personal data described below.

2.2 Categories of Data We Collect

Category Examples Purpose
Identity data Full name, national ID number, date of birth, profile photo Identity verification, fraud prevention
Contact data Phone number, email address, service address Communication, service delivery, OTP verification
Location data GPS coordinates, city/district Matching to nearby Craftsmen, ETA calculation
Financial data Payment method tokens, transaction history, payout bank details (Craftsmen) Processing payments, commission settlement, tax compliance
Usage data Booking history, in-app messages, search queries, ratings given/received Service delivery, dispute resolution, quality improvement
Technical data Device type, OS version, IP address, app version, crash logs Security, fraud detection, performance monitoring
Verification documents National ID scans, trade certificates (Craftsmen only) Onboarding compliance, trust & safety

2.3 Legal Basis for Processing (PDPL Art. 5)

We process personal data on the following legal bases: (a) performance of a contract — to deliver the booking and payment service you requested; (b) explicit consent — obtained at registration and for optional marketing communications; (c) legitimate interest — fraud prevention, platform security, and service improvement, balanced against your rights; (d) legal obligation — tax reporting, responding to lawful government requests, and PDPL compliance itself.

2.4 How We Use Your Data

  • Matching Clients with the nearest available, qualified Craftsmen.
  • Processing bookings, payments, commission deductions, and Craftsman payouts.
  • Sending transactional communications: booking confirmations, OTP codes, status updates, receipts.
  • Investigating disputes, safety reports, and suspected fraud (see Sections 9–10 of this suite).
  • Improving matching algorithms, app performance, and (with consent) sending promotional offers.
  • Complying with Egyptian legal, regulatory, and tax obligations.

2.5 Data Sharing with Third Parties

We share limited personal data only with:

  • Licensed payment gateways — to process transactions (Hirfa does not receive or store full card numbers).
  • SMS/OTP service providers — to deliver verification codes.
  • Cloud infrastructure providers — to host the Platform under contractual data-protection commitments.
  • Egyptian government authorities — only when legally compelled by a valid court order, subpoena, or regulatory request under Egyptian law.
  • The other party to a booking — a Client's name, approximate location, and phone-masked contact are shared with the assigned Craftsman, and vice versa, solely to enable the service.

Hirfa does not sell personal data to third parties for marketing purposes, under any circumstances.

2.6 International Data Transfers

Where any data is processed or stored outside Egypt (e.g., via cloud infrastructure), such transfers are made only to jurisdictions or providers offering an adequate level of protection consistent with PDPL requirements, or under appropriate contractual safeguards.

2.7 Data Retention

  • Active account data is retained for as long as the account remains active.
  • Following account deletion, financial/transaction records are retained for 5 years as required by Egyptian tax and commercial law.
  • Other personal data not subject to a legal retention requirement is deleted or irreversibly anonymized within 90 days of a verified deletion request.
  • Security and audit logs are retained per the Audit Logs Policy (Section 12).

2.8 Your Rights Under PDPL

Subject to applicable law, you have the right to: access your data; request correction of inaccurate data; request erasure ("right to be forgotten"); withdraw consent for optional processing (e.g., marketing) at any time; object to processing based on legitimate interest; and request data portability in a structured, commonly used format. To exercise any of these rights, contact privacy@gethirfa.com. We will respond within the timeframe mandated by the PDPL's executive regulations.

2.9 Data Security Measures

We apply encryption in transit (TLS 1.2+) and at rest, role-based access controls, database-level row-level security, mandatory two-factor authentication for internal systems handling sensitive data, and regular security reviews — see the Security Policy (Section 4) and Access Control Policy (Section 8) for full detail.

2.10 Cookies and Tracking (Web)

gethirfa.com uses essential cookies for session management and, with your consent, analytics cookies to understand site usage. You can manage cookie preferences via your browser settings or the site's cookie banner.

2.11 Children's Privacy

The Platform is not directed at, and must not be used by, individuals under 18 years of age. Any account found to belong to a minor will be terminated immediately upon discovery.

2.12 Changes to This Policy

We will notify Users of material changes to this Privacy Policy via in-app notice or email at least 15 days before the change takes effect.

2.13 Contact / Data Protection Queries

privacy@gethirfa.com · Creativa Hub Tanta Office, Gharbia, Egypt