Legal centre

All the agreements and policies governing your use of the Wthaiq platform, in one organised place.

All documents are governed by the laws of the Arab Republic of Egypt · Effective date: 1 June 2026

Privacy policy

Print / PDF
Note: This English text is provided for convenience only. The Arabic version is the authoritative and binding text; in the event of any discrepancy or conflict of interpretation, the Arabic text prevails.
Date of issue: 1 June 2026Date of entry into force and effect: 1 June 2026Last updated: 1 June 2026

Last updated: 1 June 2026

Date of entry into force: 1 June 2026


Chapter One: General Provisions

1. Introduction

The Wthaiq platform ("the Platform", "we", "us", "our") welcomes you.

This Privacy Policy explains how Wthaiq collects, processes, uses, stores, discloses and protects personal data and technical data when you use the website, the applications, the electronic signature services or any other service provided by the Platform.

This Policy forms an integral part of the Terms and Conditions of Use, and your use of the Platform constitutes acceptance of the practices described in it, to the extent permitted by the applicable law.

We undertake to handle personal data in accordance with the principles of lawfulness, transparency, data minimisation and information security, and in a manner consistent with the regulations and rules in force that apply to the services we provide.


2. Scope of the Policy

This Policy applies to all personal data and other data processed by Wthaiq upon the use of:

  • The website.
  • The control panel.
  • The document creation services.
  • The electronic signature services.
  • The artificial intelligence services.
  • The applications.
  • The programming interfaces (API) upon their launch.
  • All services associated with the Platform.

This Policy does not apply to websites, applications or services owned by third parties, even if they are linked to the Platform.


3. Acceptance of the Policy

By using the Platform, the User acknowledges that he:

  1. Has read the Privacy Policy.
  2. Has understood how his data is processed.
  3. Has agreed to the practices described in it to the extent that the law requires his consent.
  4. Bears responsibility for providing the Platform with correct and up-to-date data.

In cases where the law requires obtaining express consent for the processing of certain data, such processing shall not take place except after obtaining the required consent or where another legal basis permitting it exists.


4. Definitions

For the purposes of this Policy, the following terms shall have the meanings set out against each of them:

Personal Data: any information relating to an identified natural person or a natural person who can be identified, directly or indirectly.

Processing: any operation performed on data, including collection, recording, organisation, storage, use, modification, transfer, sharing, deletion or destruction.

The User: any person who uses the services of Wthaiq.

The Platform: all websites, applications and systems of Wthaiq.

The Document: any contract, file, agreement or instrument created, uploaded, signed or stored using the Platform.

Electronic Signature: any signature effected through the electronic services provided by the Platform.

Service Provider: any external entity that provides a service assisting the Platform in operating its services.

Technical Data: the data collected automatically upon the use of the services, such as the IP address, the type of browser and device, and usage logs.


Chapter Two: The Data We Collect

5. Data Provided by the User

We may collect the data that the User provides directly upon using the Platform, including:

  1. The name.
  2. The email address.
  3. The telephone number.
  4. The encrypted password.
  5. The company name.
  6. The job title.
  7. The address.
  8. Invoicing data.
  9. Subscription data.
  10. Any information the User chooses to add to his account.

The User is not obliged to provide any data that is not required for the provision of the service, unless it is necessary under the law or by the nature of the service requested.


6. Document Data

The Platform may process the data contained in the documents that the User creates, uploads, modifies or signs, including:

  • The names of the parties.
  • Contact details.
  • The contractual clauses.
  • The attachments.
  • The electronic signatures.
  • Any other data the User inserts within the document.

Such data is processed to the extent necessary to provide the service and to carry out the User's instructions.


7. Account Data

Account data may include:

  1. The date of creation of the account.
  2. The status of the subscription.
  3. The account settings.
  4. The login log.
  5. The log of devices used.
  6. The preferred language.
  7. The time zone.
  8. The User's preferences.

8. Data Collected Automatically

Upon the use of the Platform, certain data may be collected automatically, such as:

  1. The IP address.
  2. The type of browser.
  3. The operating system.
  4. The type of device.
  5. The device identifier.
  6. The language.
  7. The pages visited.
  8. The duration of the session.
  9. Access times.
  10. Performance data.
  11. Technical errors.
  12. Security data.

This data is collected for operational, security and analytical purposes.


9. Log Files

The Platform may create electronic logs containing technical information, such as:

  • The time of login.
  • The time of logout.
  • The IP address.
  • The type of browser.
  • The operating system.
  • The operations carried out within the account.
  • Technical errors.
  • Security events.

These logs are used for the purposes of:

  1. Operating the services.
  2. Protecting the security of the Platform.
  3. Detecting fraud.
  4. Investigating security incidents.
  5. Complying with legal obligations.

10. IP Address

The Platform may collect the Internet Protocol address (IP Address) upon the use of its services.

The IP address is used for the following purposes:

  1. Protecting the security of the account.
  2. Preventing fraud.
  3. Detecting intrusion attempts.
  4. Creating electronic signature records.
  5. Improving the performance of the services.
  6. Complying with legal and regulatory requirements.

The IP address is not used on its own to identify the User conclusively, and it may differ according to the internet service provider or the network used.


11. Cookies

The Platform uses cookies and similar technologies to improve the User experience, operate the services and analyse performance.

Cookies may be used in order to:

  1. Log in.
  2. Remember preferences.
  3. Improve performance.
  4. Analyse usage.
  5. Protect accounts.
  6. Detect misuse.

The use of cookies is regulated in greater detail in the Platform's Cookies Policy.


12. Device and Browser Data

We may collect information about the device used to access the Platform, such as:

  1. The type of device.
  2. The manufacturer.
  3. The operating system.
  4. The version of the system.
  5. The type of browser.
  6. The screen resolution.
  7. The time zone.
  8. The language.
  9. Other technical identifiers necessary for operating and improving the services.

This data is not used to identify the User directly unless that is necessary for security or legal purposes.

Chapter Three: The Specialised Data Processed by the Platform

13. Electronic Signature Data

Upon the use of the electronic signature services, the Platform may process certain data necessary to provide the service and to evidence the electronic operations, which may include:

  1. The name of the signatory.
  2. The email address of the signatory.
  3. The telephone number, if used in verification.
  4. The IP address.
  5. The time of sending the signature request.
  6. The time of opening the document.
  7. The time of signature.
  8. The time of completion of the signature process.
  9. Device and browser data.
  10. The log of events relating to the signature process.
  11. The means of verification used.
  12. The Timestamp.
  13. The status of the signature process.

This data is processed in order to operate the electronic signature service, improve its security, and create technical records associated with the process.

The retention of this data does not mean that the Platform guarantees the legal validity of the signature in all countries or before all authorities.


14. Artificial Intelligence Data

If the User uses the artificial intelligence services provided by the Platform, the following may be processed:

  1. The Prompts.
  2. The questions.
  3. The texts entered.
  4. The documents sent to the service.
  5. The outputs generated by the artificial intelligence.
  6. The usage data associated with the service.

This data is used to provide the requested service, improve the quality of performance, detect malfunctions, and comply with legal obligations, in accordance with the appropriate legal basis.

The Platform does not use the User's data to train its own artificial intelligence models unless this is expressly stipulated, or it has obtained the necessary consent, or this is permissible under the law.


15. Technical Support Data

Upon contacting the support team, we may collect:

  1. The name.
  2. The email address.
  3. The telephone number.
  4. The account number.
  5. The content of the messages.
  6. The attachments.
  7. The conversation logs.
  8. Technical information relating to the problem.

This data is used to provide technical support, verify requests, and improve the quality of the services.


16. Subscription and Payment Data

If the User subscribes to a paid service, the following data may be processed:

  1. The type of subscription.
  2. The date of subscription.
  3. The date of renewal.
  4. The value of the subscription.
  5. The currency.
  6. The status of payment.
  7. The invoice number.
  8. The payment record.

As a general rule, the Platform does not retain full payment card data where it is processed by approved external payment providers.


17. Data Received from Third Parties

The Platform may receive certain data from external entities, such as:

  1. Login service providers.
  2. Payment service providers.
  3. Verification service providers.
  4. Email service providers.
  5. Text message service providers.
  6. Analytics service providers.

Such data is handled in accordance with this Policy and the applicable laws.


Chapter Four: Purposes of Data Processing

18. Operation of the Services

Personal data is processed in order to operate the services of the Platform, including:

  1. Creating accounts.
  2. Managing accounts.
  3. Creating documents.
  4. Sharing documents.
  5. Carrying out electronic signature operations.
  6. Storing data.
  7. Managing subscriptions.

19. Improvement of the Services

Data may be used to analyse and improve the performance of the services, including:

  1. Developing new features.
  2. Improving the speed of performance.
  3. Fixing errors.
  4. Improving the User experience.
  5. Developing the user interface.
  6. Measuring the use of the services.

Data is used for this purpose in a manner proportionate to the objective, and having regard to minimising data as far as possible.


20. Protection of Security

Data may be processed in order to:

  1. Detect fraud.
  2. Prevent misuse.
  3. Protect accounts.
  4. Detect intrusions.
  5. Protect the technical infrastructure.
  6. Investigate security incidents.
  7. Prevent unauthorised access.

21. Communication with the User

The Platform may use the User's contact data in order to:

  1. Send account notifications.
  2. Send verification requests.
  3. Send signature requests.
  4. Send security notifications.
  5. Respond to support requests.
  6. Communicate regarding subscriptions and invoices.
  7. Send legal notices relating to the service.

Contact data is not used to send marketing messages where the law requires consent and it has not been obtained.


22. Legal Compliance

Personal data may be processed where this is necessary in order to:

  1. Comply with laws and regulations.
  2. Execute the orders of the competent authorities.
  3. Protect the legal rights of the Platform or the users.
  4. Respond to judicial or regulatory proceedings.
  5. Fulfil tax or accounting obligations.
  6. Prevent crimes or fraud.

23. Analytics and Statistics

The Platform may use technical data or aggregated or anonymised data to carry out analytics and statistics relating to the performance of the services, such as:

  1. The number of users.
  2. The use of features.
  3. Technical performance.
  4. Detection of malfunctions.
  5. Measurement of the quality of service.

These analytics are not intended to identify users whenever anonymous or aggregated data can be used to achieve the purpose.


Chapter Five: The Legal Basis for Data Processing

24. The Legal Basis for Processing

The Platform processes personal data on the basis of one or more of the following legal bases, according to the nature of the processing and the applicable law:

  1. Performance of the contract or taking steps at the User's request prior to entering into the contract.
  2. Compliance with a legal obligation.
  3. Protection of the legitimate interests of the Platform, the User or third parties, where the rights and freedoms of the data subject do not override those interests.
  4. The User's consent, where it is required by law.
  5. Any other legal basis permitted by the applicable regulation.

25. Withdrawal of Consent

If particular processing relies on the User's consent, he may withdraw his consent at any time, to the extent permitted by the law.

The withdrawal of consent does not affect the lawfulness of the processing carried out before its withdrawal, and it may also result in the impossibility of providing certain services which by their nature depend on that processing.


26. Data Minimisation

The Platform undertakes, whenever possible, to collect and process the data that is necessary to achieve the legitimate purposes associated with the provision of the services, and it endeavours not to collect data for which there is no operational or legal need.

Chapter Six: Sharing and Disclosure of Data

27. Sharing of Data

Wthaiq does not sell the personal data of users.

Personal data is not shared except within the limits necessary to provide the services, comply with the law, or protect legitimate rights and interests, and in accordance with what is set out in this Policy.


28. Service Providers

The Platform may share certain data with independent service providers who assist it in operating its services, including by way of example:

  1. Cloud hosting providers.
  2. Database providers.
  3. Email service providers.
  4. Text message service providers.
  5. Electronic signature service providers.
  6. Artificial intelligence service providers.
  7. Analytics service providers.
  8. Payment service providers.
  9. Technical support service providers.
  10. Information security service providers.

These providers are not permitted to process the data except to the extent necessary to provide the contracted services, and in accordance with the applicable contractual and legal obligations.


29. Legal Disclosure

The Platform may disclose personal data if this is:

  1. Required under the law.
  2. In execution of a judicial order.
  3. In response to a request issued by a competent authority.
  4. Necessary to protect the legal rights of the Platform.
  5. Necessary to prevent fraud, crimes or security threats.
  6. Necessary to protect users or the public from imminent harm, in accordance with what the law permits.

30. Restructuring and Transfer of Business

In the event of a merger, acquisition, restructuring, sale of assets, or transfer of ownership of the Platform or part of its business, personal data may be transferred to the legal successor or the acquiring entity, provided that its processing continues in a manner consistent with this Policy or any subsequent policy providing a comparable level of protection, having regard to what the applicable law imposes.


31. Aggregated and Anonymised Data

The Platform may use or share data from which personal identifiers have been removed, or aggregated data which does not reasonably permit the identification of the User, for the purposes of:

  1. Analytics.
  2. Statistics.
  3. Improving the services.
  4. Studies.
  5. Product development.
  6. Preparing reports.

Such data is not considered personal data once it has become anonymised in accordance with the applicable law.


Chapter Seven: International Transfer of Data

32. Processing of Data Outside the User's Country

Data may be processed, stored or transferred to countries other than the country in which the User resides, where this is necessary to provide, operate or support the services.

Such processing may be carried out by Wthaiq or by its approved service providers.


33. Safeguards for International Transfer

When transferring personal data outside the country in which it was collected, the Platform endeavours to apply the appropriate safeguards as required by the law, and those safeguards may include:

  1. Entering into appropriate contractual agreements with service providers.
  2. Relying on adequacy decisions, where available.
  3. Applying the appropriate technical and organisational measures.
  4. Any other mechanisms permitted by the applicable law.

34. The User's Consent to Transfer

By using the Platform, the User acknowledges that his data may be transferred, stored or processed in other countries if this is necessary to provide the services, having regard to the applicable legal requirements and the appropriate safeguards.


Chapter Eight: Data Protection

35. Security Measures

The Platform applies reasonable technical, administrative and organisational measures intended to protect personal data from:

  1. Unauthorised access.
  2. Unlawful use.
  3. Unauthorised disclosure.
  4. Modification.
  5. Destruction.
  6. Loss.
  7. Misuse.

Those measures may include, according to the nature of the service:

  • Encryption.
  • Access controls.
  • Backups.
  • Security monitoring.
  • Logging of security events.
  • Review of permissions.
  • Periodic security testing.

36. Limits of Information Security

Notwithstanding the adoption of appropriate security measures, the security of no electronic system or communications network can be absolutely guaranteed.

Accordingly, the Platform does not guarantee that data will be protected from all risks, attacks, intrusions or circumstances beyond reasonable control.


37. The User's Responsibility for the Security of His Account

The User undertakes to maintain the security of his account and his login credentials, and bears responsibility for:

  1. Protecting the password.
  2. Not sharing login credentials.
  3. Using secure devices and networks as far as possible.
  4. Notifying the Platform upon suspicion of any unauthorised use.

The Platform does not bear responsibility for any unauthorised use of the account where it arises from the User's breach of these obligations.


Chapter Nine: Retention and Deletion of Data

38. The Data Retention Period

The Platform retains personal data for a period not exceeding the period necessary to achieve the purposes for which it was collected, or to comply with legal or regulatory obligations, or to protect the legal rights of the Platform or the users.

The retention period may differ according to:

  1. The type of data.
  2. The type of service.
  3. The type of subscription.
  4. Legal requirements.
  5. Accounting or tax requirements.
  6. Cybersecurity requirements.

39. Deletion of Data

The User may request the deletion of his personal data in accordance with what the applicable laws permit.

Nevertheless, the Platform may retain certain data if its retention is necessary in order to:

  1. Comply with the law.
  2. Perform contractual obligations.
  3. Protect legal rights.
  4. Resolve disputes.
  5. Prevent fraud.
  6. Protect the security of the Platform.

40. Backups

Certain data may remain within backups for a limited period after its deletion from the operational systems, for the purposes of business continuity, data recovery or compliance with security requirements.

Such data is deleted or overwritten in accordance with the backup cycles adopted by the Platform, unless the law requires its retention for a longer period.

Chapter Ten: The User's Rights

41. The Rights of Data Subjects

In accordance with the applicable law, the User may enjoy rights relating to his personal data, including:

  1. The right to know what data is being processed.
  2. The right of access to his personal data.
  3. The right to obtain a copy of his data, where this is legally available.
  4. The right to request the rectification of inaccurate or incomplete data.
  5. The right to request the deletion of data in the cases permitted by the law.
  6. The right to request the restriction of processing.
  7. The right to object to certain types of processing.
  8. The right to withdraw consent where the processing relies on it.
  9. The right to data portability, if the law grants this right.

These rights are not absolute, and they may be subject to exceptions or restrictions determined by the applicable law.


42. How to Exercise the Rights

The User may exercise his rights through the official means of communication provided by the Platform.

The Platform may request additional information to verify the identity of the applicant before executing any request relating to personal data, in order to protect the privacy of users and prevent unauthorised access.


43. The Period for Responding to Requests

The Platform endeavours to process requests relating to personal data within a reasonable period and in accordance with the time limits prescribed by the applicable law.

In the event that the request cannot be executed or is delayed, the Platform may notify the User of the reason for the delay or the refusal if the law permits this.


Chapter Eleven: Compliance with Data Protection Regulations

44. Compliance with the General Data Protection Regulation (GDPR)

If the General Data Protection Regulation (GDPR) applies to particular processing carried out by the Platform, Wthaiq undertakes, to the extent required, to apply the requirements set out in that Regulation.

This may include, according to the case:

  1. Respecting the rights of data subjects.
  2. Applying the appropriate security measures.
  3. Using an appropriate legal basis for the processing.
  4. Applying the necessary safeguards upon the international transfer of data.
  5. Performing the other obligations imposed by the Regulation.

45. Compliance with the Saudi Personal Data Protection Law (PDPL)

If the processing of data is subject to the provisions of the Personal Data Protection Law of the Kingdom of Saudi Arabia, the Platform undertakes, to the extent applicable to it, to comply with the relevant statutory requirements, including protecting the rights of data subjects and performing the statutory obligations relating to data processing.


46. Compliance with the Emirati Data Protection Law

If the processing of data is subject to the federal or local laws in force in the United Arab Emirates concerning the protection of personal data, the Platform undertakes to comply with the requirements applicable to it in accordance with the applicable law.


47. Divergence of Legal Requirements

The User's rights and the Platform's obligations may differ according to the country, territory or legal system to which the processing of data is subject.

In the event of a conflict between this Policy and the requirements of a mandatory applicable law, the provisions of that law shall apply to the extent that it imposes.


Chapter Twelve: Children

48. Use of the Service by Children

The services of Wthaiq are not directed at children, and the Platform may not be used by any person who does not have the legal capacity required to use the services, in accordance with the applicable law.


49. Collection of Children's Data

The Platform does not knowingly collect personal data belonging to children where the law requires special consent or prohibits its collection without satisfying the legal requirements.

If it becomes apparent to the Platform that it has collected a child's data in contravention of the law, it will take the appropriate measures to address the matter, including deleting the data where this is required.


Chapter Thirteen: Security Incidents

50. Response to Security Incidents

If a security incident occurs that may affect the confidentiality, integrity or availability of personal data, the Platform shall take the appropriate measures to investigate the incident, limit its effects and restore the services where possible.


51. Notification of Incidents

If the law obliges the Platform to notify the User or the competent authority of the occurrence of a security incident or a data breach, this shall be done within the period and in the manner prescribed by the applicable law.

No notification of the occurrence of a security incident shall be deemed an admission of legal liability for that incident.


Chapter Fourteen: Updating the Privacy Policy

52. Amendment of the Policy

Wthaiq may amend or update this Policy at any time if operational, legal, regulatory or security necessity so requires.

Amendments become effective as from the date of their publication on the Platform or from the date specified in them.


53. Notice of Amendments

Upon making material amendments to this Policy, the Platform shall make reasonable efforts to notify users by the appropriate means, such as email, notifications within the Platform, or publishing a notice on the website.

Continued use of the services after the amendments take effect is deemed acceptance of the Policy in its updated form, to the extent permitted by the law.


Chapter Fifteen: Contacting Us

54. Communication Concerning Privacy

If you have any enquiries, requests, complaints or applications relating to personal data or to the Privacy Policy, you may contact Wthaiq through the official means of communication published on the website.

The Platform may request additional information to verify the identity of the applicant before disclosing any data or executing any request relating to personal data.


55. Entry into Force

This Privacy Policy enters into force as from the date set out at its beginning, and remains in effect until it is replaced or updated in accordance with the provisions of this Policy.

Chapter Sixteen: Advanced Data Protection Provisions

56. The Principle of Data Minimisation

Wthaiq undertakes, whenever possible, to collect and process the minimum data necessary to achieve the legitimate purposes relating to the provision of the services, and works to avoid collecting data for the processing of which there is no operational or legal need.


57. Accuracy of Data

Part of the services depends on the data provided by the User.

Therefore, the User undertakes to provide the Platform with correct, accurate and up-to-date data, and is responsible for updating it upon the occurrence of any change.

The Platform does not bear responsibility for any effects resulting from the provision of incorrect, incomplete or outdated data.


58. Confidentiality of Employees

Authorisation to access personal data is restricted to the employees, contractors or service providers whose work by its nature so requires, and they are subject to contractual or statutory obligations relating to the confidentiality of information and the protection of data.


59. Processing of Data on Behalf of the User

Within the limits of the services provided by Wthaiq, the Platform may process the data contained within the documents or accounts on the basis of the User's instructions and for the purposes of operating the services only.

The Platform does not use that data for purposes other than the provision of the service unless this is required under the law, stipulated in this Policy, or with the User's consent.


60. Sensitive Data

As a general rule, the Platform does not require users to enter sensitive personal data unless this is necessary to the nature of the service.

If the User chooses to enter sensitive data within the documents or files, he acknowledges that he has the legal basis necessary for its processing, and bears responsibility for entering and using it.


61. Data Relating to Third Parties

If the User enters personal data belonging to other persons, he acknowledges and warrants that he holds the legal right to share and process that data using the services of the Platform, and that he has obtained any consents that may be required under the law.

The Platform does not bear responsibility for the User's entry of data belonging to third parties without a legal basis.


62. Anonymised Data

The Platform may convert certain data into anonymised or aggregated data such that it does not reasonably permit the identification of any person.

Such data may be used for statistical, analytical, operational or research purposes, or to improve the services.


63. Privacy of Documents

Wthaiq does not claim any ownership of the documents created or uploaded by the User.

Access to those documents is restricted to the limits necessary to operate the services, provide technical support, comply with the law, or on the basis of the User's instructions, or in the other cases permitted under this Policy.


64. Activity Logging

The Platform may log certain activities carried out within the account, including:

  1. Login.
  2. Creation of documents.
  3. Modification of documents.
  4. Sending of signature requests.
  5. Signature operations.
  6. Deletion of files.
  7. Changing of account settings.
  8. Other administrative operations.

The purpose of this is to strengthen the security of accounts, improve the services, and assist in investigating security incidents.


65. Legal Precedence

If any provision of this Privacy Policy conflicts with mandatory requirements imposed by an applicable data protection law, the provisions of that law shall apply to the extent necessary to resolve the conflict, without this affecting the effectiveness of the remaining provisions of this Policy.

Chapter Seventeen: Cookies and Similar Technologies

66. Use of Cookies

Wthaiq uses cookies and similar technologies to improve the performance of the Platform and provide a more efficient and secure user experience.

These technologies may include cookies, browser Local Storage, session identifiers, measurement and analytics tools, and other similar technologies.


67. Types of Cookies

The Platform may use the following types of cookies:

  1. Files necessary for the operation of the Platform.
  2. Security and authentication files.
  3. Files that save the User's preferences.
  4. Performance measurement files.
  5. Analytics and statistics files.
  6. Files that improve the user experience.

The Platform does not use cookies for purposes that require the User's consent unless that consent has been obtained where the applicable law so requires.


68. Control of Cookies

The User may control or delete cookies through the settings of the browser or the device.

Nevertheless, disabling certain files may result in the cessation of certain features of the Platform or a reduction in the efficiency of certain services.


Chapter Eighteen: Third-Party Services

69. Third-Party Websites and Services

The Platform may contain links to or integrations with websites, applications or services owned by third parties.

Wthaiq does not control the privacy policies or practices of those entities, and does not bear responsibility for them.

The User is advised to review the privacy policies of any external service before using it.


70. Infrastructure Providers

The Platform may rely on external service providers to deliver certain functions, such as:

  1. Cloud hosting.
  2. Databases.
  3. Email services.
  4. Text message services.
  5. Payment services.
  6. Artificial intelligence services.
  7. Analytics services.
  8. Backup services.
  9. Information security services.

These providers are selected according to appropriate commercial and technical criteria, with an endeavour to bind them contractually to protect data to the appropriate extent.


71. Processing of Data by Third Parties

If data is processed by an external service provider on behalf of Wthaiq, that processing shall be within the limits necessary to provide the service or to fulfil legal or contractual obligations, and in a manner consistent with this Policy and the applicable laws.


Chapter Nineteen: Final Provisions

72. Independence of the Privacy Policy

This Policy constitutes a supplementary part of the Terms and Conditions of Use, and is read together with all the other legal policies published on the Platform.

In the event of a conflict, precedence shall be in accordance with the order determined by the Terms and Conditions of Use, unless the law imposes otherwise.


73. No Waiver

Wthaiq's abstention from exercising any right relating to data protection or to the enforcement of this Policy shall not be deemed a waiver of that right.

No waiver shall be effective unless issued in writing by an authorised representative of the Platform.


74. Severability of Clauses

If any provision of this Policy is found to be unlawful or unenforceable under the applicable law, this shall not affect the validity or effectiveness of the remaining provisions, which shall remain in force to the extent permitted by the law.


75. Survival of Certain Provisions

The provisions relating to information security, data retention, ownership rights, dispute resolution, legal compliance, and the other provisions whose purpose requires their continuation, shall remain in force even after the closure of the account or the cessation of use of the services, to the extent necessary.


76. The Authoritative Language

This Policy may be available in more than one language.

In the event of any difference in interpretation between the language versions, the version adopted by Wthaiq as the official version shall be the reference, to the extent permitted by the law.


77. Acknowledgements

The User acknowledges that he:

  1. Has reviewed the Privacy Policy.
  2. Has understood how his data is processed.
  3. Is aware of his rights relating to personal data.
  4. Has provided the data with which he supplies the Platform correctly, to the best of his knowledge.
  5. Bears responsibility for any data belonging to third parties that he enters into the Platform.

78. Details of the Contact Officer

Wthaiq may designate an officer or a team specialised in privacy and data protection enquiries.

The official means of communication for this purpose are published on the website when available.


79. Updating Contact Details

The User undertakes to keep the contact details of his account up to date so that the Platform is able to send notifications relating to privacy, security or the account when needed.


80. Final Entry into Force

This Privacy Policy enters into force as from the date specified at its beginning, and remains in effect until it is amended or replaced in accordance with its provisions; and continued use of the services of Wthaiq after any update takes effect is deemed acceptance of the Policy in its amended form, to the extent permitted by the applicable law.

Chapter Twenty: Advanced Data Governance Provisions

81. The Principle of Privacy by Design

Wthaiq endeavours, whenever this is technically and operationally possible, to have regard to the principles of data protection and privacy in the design and development of its services and its new features, in a manner proportionate to the nature of the service and the potential risks.


82. Privacy by Default

The Platform adopts, where appropriate, default settings intended to limit the processing of personal data to the extent necessary to provide the service, without prejudice to the essential functions of the Platform.


83. Review of Access Permissions

The Platform periodically reviews the permissions of access to personal data within its systems, with the aim of limiting access to data and restricting it to the persons whose work by its nature so requires.


84. Maintenance of Processing Records

The Platform may maintain internal records relating to personal data processing operations, for the purposes of compliance, risk management, improving governance, and fulfilling legal obligations where necessary.


85. Risk Assessment

The Platform may carry out periodic assessments of the risks relating to information security and data protection, and take the appropriate measures to address those risks in accordance with the nature of the services and the technologies used.


Chapter Twenty-One: Provisions Specific to Artificial Intelligence

86. Data Used with Artificial Intelligence Services

Upon the use of the artificial intelligence services, the User should avoid entering any personal or confidential data that is not necessary to achieve the intended purpose.

The User remains responsible for assessing the nature of the data he chooses to enter into those services.


87. Review of Outputs

The outputs generated by the artificial intelligence services are not considered part of the data verified or adopted by the Platform.

The responsibility for reviewing those outputs before using, sharing or relying on them rests with the User alone.


88. Improvement of the Services

The Platform may use anonymised or aggregated usage data to analyse and improve the performance of the artificial intelligence features, without using the data in a manner that permits the identification of the User, unless there is a legal basis permitting this.


Chapter Twenty-Two: Additional Final Provisions

89. Portability Between Policies

The Privacy Policy is interpreted together with the remaining legal policies of the Platform as an integrated system, and the invalidity or amendment of any policy does not affect the effectiveness of the remaining policies, unless the law requires otherwise.


90. No Sale of Personal Data

Wthaiq does not sell the personal data of users to third parties for monetary consideration.

Any sharing of data takes place in accordance with this Policy and for the legitimate purposes associated with the provision of the services or compliance with legal obligations.


91. No Creation of Additional Contractual Rights

This Privacy Policy is not intended to create contractual rights or obligations beyond what the law imposes or what is expressly stipulated in the Terms and Conditions of Use.


92. Interpretation

The provisions of this Policy are interpreted so as to achieve the protection of personal data, having regard to the nature of the services provided by Wthaiq and the applicable legal requirements.


93. Survival of Certain Provisions

The provisions relating to data retention, legal obligations, responding to the requests of the competent authorities, dispute resolution, and the other provisions whose purpose requires their continuation, remain in force after the termination of the account or the cessation of use of the services, to the extent necessary.


94. Official Means of Communication

Wthaiq adopts the means of communication published on its website as the official means for receiving requests and enquiries relating to data protection and privacy.


95. Updating the User's Information

The User undertakes to update his personal data whenever a change occurs to it, in order to ensure the accuracy of the information associated with his account and to enable the Platform to provide the services and communicate with him correctly.


96. Repetitive or Unjustified Requests

The Platform may, to the extent permitted by the law, refuse, postpone or impose reasonable fees on requests that are excessively repetitive or unjustified, or that are shown to involve an abuse of the rights relating to data protection.


97. Identity Verification Before Disclosure

The Platform may request additional information or documents to verify the identity of the applicant before executing any request relating to personal data, in order to protect the privacy of data subjects and prevent unauthorised disclosure.


98. Application of the Policy

This Policy applies to all data processing operations carried out by Wthaiq as from its date of entry into force, unless the law requires the application of different provisions to particular processing.


99. The Official Version

Wthaiq maintains the official updated version of the Privacy Policy on its website, and it shall be the authoritative reference in the event of a difference between versions published in other places.


100. Final Acknowledgement

By using the services of Wthaiq, the User acknowledges that he has reviewed this Privacy Policy, has understood how his personal data is collected, used, disclosed and protected, and consents to its processing in accordance with the provisions of this Policy and to the extent permitted by the applicable law.


Governing Law and Jurisdiction

This document shall be governed by and construed in accordance with the laws of the Arab Republic of Egypt, and jurisdiction shall lie with the competent Egyptian courts to determine any dispute arising out of or relating to it; and any arbitration — if agreed upon by the two parties — shall be conducted within the Arab Republic of Egypt and in accordance with its laws, without prejudice to any mandatory rights afforded to the User under the applicable laws of his country of residence.