Privacy policy

1. Scope

This policy explains how [company legal name] (“we”) processes personal data on the ECMS Pro website (ecms.tadreb.live), when you request a demo, contact us or create an account for a center, and in center owners’ and users’ accounts.

Students’ and guardians’ data that centers enter into the system is controlled by the center itself; we process it on the center’s behalf and on its instructions (see section 9). Ask the center directly about it.

2. What we collect and why

DataWhenPurposeBasis
Name, mobile number, email (optional), center name, governorate, approximate student count and your messageDemo or contact requestAnswering and following up your requestYour request
The center owner’s name and mobile number, the center’s details and addressAccount creationCreating the center and running the trialContract
Your acceptance of the terms and this policy, with their versions and the dateAccount creationProof of acceptanceLegal obligation
Your consent to marketing messages (optional)When you opt inSending product news and offersConsent
Confirmation codes (we never store the code itself, nor the mobile number in readable form in their records)Mobile number verificationPreventing fake signups and abuseLegitimate interest
An encrypted fingerprint of your IP address that changes dailyForm submissions and code requestsPreventing abuse and rate limitingLegitimate interest
Traffic sources (such as utm tags)Account creation or form submissionKnowing which channels bring centersLegitimate interest
Billing details: legal name, tax ID, address, emailPaid subscriptionIssuing and collecting invoicesContract and legal obligation
Site usage events (pages, source) with a random identifierOnly with your “Analytics” consentImproving the siteConsent
Ad measurement identifiersOnly with your “Marketing” consentMeasuring our adsConsent
Page performance measurements (load speed), aggregated with no identifier or cookieA sample of visitsKeeping the site fastLegitimate interest
Sign-in and activity logs of center users and our teamDuring useSecurity and auditLegitimate interest and legal obligation

We never ask for payment card details; payments happen on Fawry’s secure page.

3. How long we keep it

DataPeriod
Demo and contact requests closed without a contract, or found to be spam24 months after closing, then deleted
Signups that failed, were rejected or expired90 days
Confirmation code records7 days
IP fingerprintsCannot be linked across days, because their key changes daily
The analytics identifier (_ecms_cid)180 days, deleted as soon as you withdraw consent
Aggregated performance measurements24 months, with no identifier
Center accounts and their dataFor the subscription, then per section 8 of the terms of service
Invoices and billing detailsAs long as the law requires [—]

4. Who we share it with

We do not sell personal data. We share it only with service providers that process it for us:

  • Hosting: [hosting provider] in [region — to be set by the owner].
  • Confirmation codes: the Company’s Odoo system, through the SMS provider [—] and WhatsApp (Meta). They receive the mobile number and the code at the moment of sending only.
  • Payment and invoicing: Fawry to collect payments, and the Company’s Odoo system to issue invoices.
  • Analytics and ads (only with your consent): Google Analytics and Meta, to which we send events from our servers; no Google or Meta code runs on our pages.
  • Authorities under a binding legal request.

5. Transfers outside Egypt

Some data may be processed outside the Arab Republic of Egypt: [servers in (region)], measurement events at Google and Meta (only with your consent), and WhatsApp messages through Meta. We transfer data only to parties offering an adequate level of protection, as required by Law No. 151 of 2020 and its executive regulations [and any licence required from the Personal Data Protection Center — for review].

6. How we protect it

Encrypted connections (https) on every page, a separate database for every center, passwords stored with irreversible hashing, confirmation codes limited in time and attempts, encrypted secret keys, encrypted daily backups kept off the server, and narrowly scoped access for each member of our team with every administrative action logged. No third-party script runs on ECMS Pro pages.

7. Your rights

Under Law No. 151 of 2020 you may: know and access the data we hold about you, correct it, ask for it to be deleted or its processing restricted, object to its processing, withdraw your consent at any time (through “Cookie settings” or by unsubscribing from marketing messages), and be told of any breach affecting your data. Send your request from your registered mobile number or email to [privacy@…]; we reply within [30] days after verifying your identity. You may also complain to the Personal Data Protection Center.

8. Children

The ECMS Pro website is meant for center owners and their teams, not for children. Students’ data, including children’s, is entered and controlled by the center, and we treat it as sensitive data.

9. Data we process on centers’ behalf

We process the students’, guardians’ and staff data a center enters only to provide the Service to that center, and for no other purpose. Every center has its own database, and students’ data is never shown publicly except through private links the center creates (the receipt link and the results link), which are excluded from search engines.

10. Cookies

See the cookie policy. We use analytics and marketing cookies only with your consent.

11. Changes and contact

We may change this policy; each version is published with its effective date, and we notify you of material changes. Contact: [data protection officer] · [email] · [address].

Choose what you agree to. Optional cookies do not affect how the site works.