Privacy policy
1. Scope
This policy explains how [company legal name] (“we”) processes personal data on the ECMS Pro website (ecms.tadreb.live), when you request a demo, contact us or create an account for a center, and in center owners’ and users’ accounts.
Students’ and guardians’ data that centers enter into the system is controlled by the center itself; we process it on the center’s behalf and on its instructions (see section 9). Ask the center directly about it.
2. What we collect and why
| Data | When | Purpose | Basis |
|---|---|---|---|
| Name, mobile number, email (optional), center name, governorate, approximate student count and your message | Demo or contact request | Answering and following up your request | Your request |
| The center owner’s name and mobile number, the center’s details and address | Account creation | Creating the center and running the trial | Contract |
| Your acceptance of the terms and this policy, with their versions and the date | Account creation | Proof of acceptance | Legal obligation |
| Your consent to marketing messages (optional) | When you opt in | Sending product news and offers | Consent |
| Confirmation codes (we never store the code itself, nor the mobile number in readable form in their records) | Mobile number verification | Preventing fake signups and abuse | Legitimate interest |
| An encrypted fingerprint of your IP address that changes daily | Form submissions and code requests | Preventing abuse and rate limiting | Legitimate interest |
| Traffic sources (such as utm tags) | Account creation or form submission | Knowing which channels bring centers | Legitimate interest |
| Billing details: legal name, tax ID, address, email | Paid subscription | Issuing and collecting invoices | Contract and legal obligation |
| Site usage events (pages, source) with a random identifier | Only with your “Analytics” consent | Improving the site | Consent |
| Ad measurement identifiers | Only with your “Marketing” consent | Measuring our ads | Consent |
| Page performance measurements (load speed), aggregated with no identifier or cookie | A sample of visits | Keeping the site fast | Legitimate interest |
| Sign-in and activity logs of center users and our team | During use | Security and audit | Legitimate interest and legal obligation |
We never ask for payment card details; payments happen on Fawry’s secure page.
3. How long we keep it
| Data | Period |
|---|---|
| Demo and contact requests closed without a contract, or found to be spam | 24 months after closing, then deleted |
| Signups that failed, were rejected or expired | 90 days |
| Confirmation code records | 7 days |
| IP fingerprints | Cannot be linked across days, because their key changes daily |
The analytics identifier (_ecms_cid) | 180 days, deleted as soon as you withdraw consent |
| Aggregated performance measurements | 24 months, with no identifier |
| Center accounts and their data | For the subscription, then per section 8 of the terms of service |
| Invoices and billing details | As long as the law requires [—] |
4. Who we share it with
We do not sell personal data. We share it only with service providers that process it for us:
- Hosting: [hosting provider] in [region — to be set by the owner].
- Confirmation codes: the Company’s Odoo system, through the SMS provider [—] and WhatsApp (Meta). They receive the mobile number and the code at the moment of sending only.
- Payment and invoicing: Fawry to collect payments, and the Company’s Odoo system to issue invoices.
- Analytics and ads (only with your consent): Google Analytics and Meta, to which we send events from our servers; no Google or Meta code runs on our pages.
- Authorities under a binding legal request.
5. Transfers outside Egypt
Some data may be processed outside the Arab Republic of Egypt: [servers in (region)], measurement events at Google and Meta (only with your consent), and WhatsApp messages through Meta. We transfer data only to parties offering an adequate level of protection, as required by Law No. 151 of 2020 and its executive regulations [and any licence required from the Personal Data Protection Center — for review].
6. How we protect it
Encrypted connections (https) on every page, a separate database for every center, passwords stored with irreversible hashing, confirmation codes limited in time and attempts, encrypted secret keys, encrypted daily backups kept off the server, and narrowly scoped access for each member of our team with every administrative action logged. No third-party script runs on ECMS Pro pages.
7. Your rights
Under Law No. 151 of 2020 you may: know and access the data we hold about you, correct it, ask for it to be deleted or its processing restricted, object to its processing, withdraw your consent at any time (through “Cookie settings” or by unsubscribing from marketing messages), and be told of any breach affecting your data. Send your request from your registered mobile number or email to [privacy@…]; we reply within [30] days after verifying your identity. You may also complain to the Personal Data Protection Center.
8. Children
The ECMS Pro website is meant for center owners and their teams, not for children. Students’ data, including children’s, is entered and controlled by the center, and we treat it as sensitive data.
9. Data we process on centers’ behalf
We process the students’, guardians’ and staff data a center enters only to provide the Service to that center, and for no other purpose. Every center has its own database, and students’ data is never shown publicly except through private links the center creates (the receipt link and the results link), which are excluded from search engines.
10. Cookies
See the cookie policy. We use analytics and marketing cookies only with your consent.
11. Changes and contact
We may change this policy; each version is published with its effective date, and we notify you of material changes. Contact: [data protection officer] · [email] · [address].