The template is not the legal standing
A picture of a signature or a scanned bit of handwriting inside a PDF does not make evidence. What makes evidence is being able to prove who signed, when, and that the document has not changed since.
Wthaiq is a documentation and evidence authority for transactions and contracts. This page explains in practical language what “legal recognition” of the electronic signature means in Egypt. It sets out when your signature counts as admissible evidence, what your rights are as a data subject under Law No. 151 of 2020, and which documents we advise having authenticated traditionally.
The phrase “electronic signatures are legally recognised” is repeated a great deal in marketing without explanation. The practical meaning is simpler and more precise. The Egyptian legislator did not require a signature to be handwritten on paper for it to take effect. Instead it conferred on the electronic signature and the electronic instrument evidentiary weight in proof whenever certain technical and procedural conditions are met, in Law No. 15 of 2004 and its executive regulations. So the right question is not “is the electronic signature recognised?” but “is this particular signature capable of being proven?”.
A picture of a signature or a scanned bit of handwriting inside a PDF does not make evidence. What makes evidence is being able to prove who signed, when, and that the document has not changed since.
The law and its regulations tie legal effect to conditions: the signature must be linked to its owner, the owner must have sole control of the signing means, and any later change to the document or the signature must be detectable.
In a dispute, the party relying on the contract is the one who has to produce what supports its validity. That is why the platform's real value is not the “look” of the signature but The proof file that you keep with it.
Some transactions are required by law to take an official form or to be authenticated before a competent authority. In these cases an electronic signature is no substitute for the official procedure. See The traditional notary office.
A valid contract paired with unlawful data processing is still a source of risk. That is why we treat Law No. 151 of 2020 as a layer running parallel to the signature, not as an appendix.
When the other party is a consumer, consumer protection law imposes extra care: comprehensible terms, clear disclosure, and giving the consumer a copy of the contract they signed.
Wthaiq is a documentation and evidence authority for transactions and contracts. We prove who signed and when, we reveal any change made after signing, and we keep the complete evidence file. The strongest thing we offer is signing with identity verification: an official document and a live face match, both tied to the signature itself. We are not an issuer of electronic certification certificates, and we claim no accreditation we have not obtained. And for anyone who signs with us using their own token, we embed their signature in the file and preserve it — the certificate comes from their licensed authority, not from us.
The legal effect of an electronic signature rests on three ideas in Law No. 15 of 2004 and its executive regulations. The first is the attribution of the signature to its owner, the second is that owner's sole control over the means of signing, and the third is the detection of any subsequent alteration. Here is how each is implemented on the platform, step by step.
Every signature must be attributed to a specific person, not to a “device” or a “shared account”. So we build every signature on a traceable identity: a verified email or phone number, and a one-time verification code at the moment of signing. And you can raise the level to identity verification with an official document and a live face match.
A signature means nothing if another party — including the sender of the contract — can sign on the signer's behalf. So each party's authority is separated from the others, and the verification code goes to the signer's own channel.
This is the condition that separates a “signed” document from a “provable” one. We compute a digital fingerprint for the final document using SHA-256. A change to a single character produces a completely different fingerprint, so it is detected immediately on comparison.
Proof needs a sequence: who it was sent to, when the document was opened, when it was signed, and from which IP address and which browser. This log is what answers the questions of an investigator, an arbitrator or a lawyer a year after the event.
If you need the document years from now, it has to be readable and verifiable with ordinary tools. That is why we produce the final document as a PDF with a human-readable completion certificate. And anyone who signs with their token gets a signature embedded inside the file in PAdES format.
The Egyptian Personal Data Protection Law does not merely oblige organisations to protect data; it grants the data subject rights they can exercise themselves. These are those rights as we apply them on the platform, and the practical route for exercising them.
To know that your data is being collected, what it is, why, and to whom it may be disclosed.
Applied in the privacy policy and on the data collection pageTo request a copy of the data we hold about you in a readable form.
A request from the data centre in your accountTo rectify any inaccurate or out-of-date data relating to you.
Change it instantly from account settingsTo request the erasure of your data, to the extent that this does not conflict with a legal obligation or with preserving evidence of a contract in force.
A documented deletion request with confirmation that it was carried outTo withdraw your consent to processing that is based on consent, without retroactive effect on anything lawfully carried out before the withdrawal.
Unsubscribe and preferencesTo object to processing you consider unjustified, or to request that it be restricted to a defined scope.
A request that is examined and answered in writingFrom the data centre in your account, or from the email address registered in your name. Specifying the type of request (access / rectification / erasure / objection) speeds up execution.
A mandatory step, not a formality: carrying out a deletion or access request for someone who is not the data subject is itself a breach. That is why we require verification proportionate to the sensitivity of the request.
Full execution may be prevented by a contract in force whose evidence must be preserved, or by a legal retention obligation. In that case we set out the reason for you, then apply the available alternative, such as restricting processing instead of full erasure.
You receive a confirmation setting out what was carried out and what was not and why, and the request and its outcome are recorded in our internal logs under the accountability principle.
The data minimisation principle means we ask only for what the service genuinely needs. And this transparency is not a favour: disclosing the purpose and the basis of processing is the core of what Law No. 151 of 2020 requires. The table below sets out what we collect, why, and on what basis.
| Type of data | Why we need it | Lawful basis for processing |
|---|---|---|
| Account details Name, email, phone number |
Account creation, sign-in, and the attribution of every signature to a specific person. | Performing the contract concluded with you (the service itself) |
| Details of the parties to the document Signers' names and contact details |
Sending the invitations, verifying identity and notifying the parties of the document's status. | Performance of the contract and a legitimate interest in completing the transaction |
| Document content The contracts and files you upload |
Completing the signing cycle and saving a copy you can come back to. | Performance of the contract — and you are responsible for the content of what you upload |
| Audit trail data Timestamps, IP, browser and device type |
Proof of who signed and when, and detection of any tampering or unauthorised access. | A legitimate interest in proof and in the security of the service |
| Invoice details Subscription and payment data |
Collecting payment for the service and issuing the necessary financial documents. | Performance of the contract and a legal/accounting obligation |
| Support messages What you write to us in support requests |
Resolving the issue you contacted us about and improving the service. | A legitimate interest in providing support |
We do not sell your data, we do not use the content of your contracts for marketing, and we do not repurpose data collected for one purpose for a different one without a clear basis. When a piece of data is no longer needed, it is deleted or anonymised rather than kept “just in case”.
Access is limited to the minimum number of staff and to a defined purpose (technical support or investigation of a security incident), and is recorded in the audit trail. There is no “general” access to document content, and contract content is not available for internal browsing without a documented reason.
Keeping a piece of data after the need for it has passed is risk with no return, and deleting it too early can cost you evidence you need. So we tie retention periods to the purpose and to what the law requires, not to an arbitrary number.
It is kept with its evidence file for as long as your account exists, because it is proof of a contract you may need later. You are free to download and archive it yourself at any time — and we always recommend doing so.
It has no evidential value, so we do not keep it any longer than necessary. Drafts and temporary data are cleared once they are no longer needed.
tied to the lifetime of the document itself — because deleting it on its own strips the document of its value as evidence.
They are kept for as long as accounting and legal obligations require, even if you ask for the rest of your data to be deleted.
We delete account data and preferences. Excepted is anything that must be retained by law, and anything that constitutes evidence of a contract for another party who shared the document with you. Your right to erasure does not cancel their right to their evidence.
When we need statistical operating data, we strip out anything that identifies a person, so it becomes attributable to nobody rather than remaining personal data.
Asking to “delete everything” is not always in your interest. If you delete a signed document, you may lose the evidence you need in a future dispute, and the platform will not be able to restore it for you. Download your full copy first, then request deletion.
Transferring personal data outside the country is not a technical detail; Law No. 151 of 2020 restricts it with controls, which is why we treat it as a compliance decision rather than a setting in a control panel. The principles we adhere to are published here so that you can compare them against your legal team's standards.
Every connection to the platform runs over a channel encrypted with TLS 1.3. Anyone intercepting network traffic between you and us sees encrypted data, not the content of a contract.
When we use a service provider (hosting, messaging, payments), their access is limited to what is necessary for their purpose, and is subject to a contractual confidentiality and protection obligation.
No personal data is transferred outside the country except within the limits the law permits, with an equivalent level of protection, and for a stated purpose connected to running the service.
Every internal access is tied to a defined role and logged, and permissions are granted on a need-to-know basis and withdrawn once the reason for them ends.
We treat a backup as sensitive data, exactly like the original. And it is not used to bring back data whose deletion has already been decided.
Where an incident affecting personal data occurs, we handle it along a defined path: containment, impact assessment, and notification of the authorities and the data subjects in the cases and within the periods prescribed by law.
Security and infrastructure details are on the trust and security page
This section is here deliberately. Any signing platform that tells you “everything can be signed electronically” is selling you a risk. The practical rule is simple: where the law requires a formal form for a transaction — notarisation, registration or publication before a competent authority — an electronic signature does not replace that procedure. This stays true even if the file was signed with the best technical tools there are.
| The standard | Electronic signing on Wthaiq | Traditional / official notarisation |
|---|---|---|
| Best suited to | Everyday commercial and administrative contracts: supply, services, confidentiality, employment, operating leases, accepted quotations. | Transactions for which the law requires a formal instrument or registration. |
| Time to completion | Minutes, remotely, with no travel and no appointments. | Tied to the authority's dates, its procedures and the parties' attendance in person. |
| What it is proved with | An audit trail, a SHA-256 fingerprint, a completion certificate, and identity verification when requested. | An official capacity derived from the notarising authority and its procedures. |
| Verification later | Fingerprint matching via The verification page In seconds. | Review of the register or the instrument by the competent authority. |
| When the law requires a formal instrument | It is not a substitute for the official procedure. | is the right way. |
This page is a practical explanation of the platform's approach, not a legal opinion on any particular matter. Determining the form required for a specific transaction depends on its details, its parties and the body it will be submitted to — so consult your legal adviser when in doubt, and treat that pause as money saved rather than time lost.
These questions come up routinely in the review of any signing tool. If you are reviewing Wthaiq as in-house counsel or as a compliance manager, here are our direct answers to them, together with what we need from you in return.
Every completed document carries three elements: the final version as a PDF, a completion certificate bearing a SHA-256 fingerprint, and a timestamped audit trail. This is the pack you attach to any memorandum or claim. To it is added the embedded PAdES signature for anyone who signed with their token.
Standardise the legally approved templates, and decide who has the right to send and who has the right to edit. Most contract risk comes from an unapproved version sent by an employee acting in good faith.
The platform proves who signed and through which verification channel; proving their authority to represent a legal entity is a governance responsibility on your side. Tie every signer to a written authorisation kept in their file.
Set a retention period and a retention reason for each type of contract. Carrying out erasure requests then becomes a decision made in advance rather than a debate every time.
You determine the purpose of processing your parties’ data and the content of your documents; we process it to deliver the service in line with your instructions and our published policies. Clarity on this split is a prerequisite for any serious compliance review.
Data subject requests, requests to extract a proof file for an old document, and compliance questions — all have one documented route, so nothing gets lost in the general support inbox.
Compliance makes far more sense once you see it tied to execution, security and proof.
Carefully written contract templates, and a signing cycle that produces a complete evidence file for every document.
This page is a general explanation of the platform’s policies and its approach to compliance, and does not constitute legal advice.