Skip to main content
Legal

Data processing agreement

The agreement under which FahmQanon processes the personal data a firm enters, as the firm's processor, under Personal Data Protection Law No. 151 of 2020.

Last updated: 4 October 2026

In short

  • The firm is the controller of its data; we process it on the firm's behalf and only on its instructions.
  • Legal files may contain sensitive data; we apply the same protection to all of the firm's data.
  • Our team does not open case content except through temporary, logged access the firm grants to one case.
  • Data is processed in the European Union; the AI model provider in the United States receives only what an answer needs, and does not use it for training.
  • We notify the firm of any breach without undue delay and help it meet its own obligations.
  • At the end: export is always available, and full deletion follows a 30-day wait.

This summary is for convenience; the full text below is what applies.

Contents

1. Parties and scope

This agreement is between the firm that subscribes to FahmQanon (the “Firm”), as controller, and the company that operates FahmQanon (“we” or “us”), as processor. It is part of the terms of use and the Firm accepts it when it subscribes. Where there is a signed contract, a copy of this agreement and its annex is attached to it. Our details:

Operating company
Intrazero
Commercial registration no.
19035
Address
B Square, Nasr Road, Cairo, Egypt
Email for privacy and legal requests
[email protected]

This agreement applies to all personal data we process on the Firm's behalf in providing the service. Terms such as controller, processor, sensitive personal data and breach have the meaning given in Article 1 of the Personal Data Protection Law issued by Law No. 151 of 2020 (the “Law”).

Article 3 of the Law's issuing provisions excludes certain data from the Law, among it data relating to judicial police records, investigations and court cases. Whatever the reach of that exclusion over some of the Firm's data, we apply this agreement to all of it.

Where they conflict on personal data, this agreement prevails over the terms of use, and a contract signed with the Firm, where there is one, prevails over both.

2. Subject matter, nature, purpose and duration

Subject matter
Hosting and processing the Firm's data to provide the service to it.
Nature
Storage, organisation and indexing for search; reading the text of documents on our servers (their text layer, or optical character recognition); retrieving relevant passages; sending a question and what is needed to answer it to the AI model provider; checking references; producing drafts, summaries and exports; sending notices and reminders; backing up the databases and the search index; and deletion.
Purpose
Providing the service to the Firm under the terms of use; support at the Firm's request; the security of the service; and counting usage against the plan's limits.
Duration
The term of the subscription, then until deletion is complete under return and deletion.

3. Categories of data and data subjects

Data subjects: the Firm's members; its clients; its clients' opponents and the other parties to cases; witnesses and experts; the parties' representatives; and anyone else named in the Firm's files and correspondence.

Categories of data: identity and contact details (names, capacities, identification numbers, addresses and phone numbers); case data (claims, facts, events, hearing dates, courts, outcomes, judgments and amounts); the content of documents and attachments; chats with the assistant and drafts; deadlines; firm memory summaries; imported past cases; and members' details and their activity in the firm log.

Sensitive data: legal files may contain data the Law treats as sensitive, such as health or financial data, religious beliefs, political opinions, security status and children's data. For processing it, the Law requires a licence from the Personal Data Protection Centre and the written and explicit consent of the person concerned, except where the law permits otherwise, and a guardian's consent for children's data (Article 12). The Firm decides what of it to enter and is responsible for its basis for doing so, and each party obtains the licence or permit the Law requires of it.

4. Processing on the Firm's instructions

We process the Firm's data only on its documented instructions, as Article 5 of the Law requires. Its instructions are: the terms of use and this agreement; what the Firm and its members do in the service (entering, configuring, sharing and deleting); and what a firm admin sends us in writing.

If we believe an instruction breaches the Law, we tell the Firm, and we may hold off carrying it out until the Firm changes it.

We do not process the Firm's data for any purpose of our own, we do not sell it, and we never use it to train AI models, ours or anyone else's.

If the law, a court order or an order of a competent authority requires us to process or disclose the Firm's data, we tell the Firm beforehand unless the law forbids it, and we disclose only what is required.

5. Our personnel and access

Only those of our personnel whose work requires it have access to the Firm's data, and they are bound to confidentiality by contract or by law.

Our team's console shows counts, settings, members and billing, never case files, documents, chats or drafts. The support team opens a case only when a firm admin grants it temporary access to that one case, for 24, 48, 72 or 168 hours. The access ends by itself and the Firm can end it sooner; granting and ending it are written to the Firm's log and to our team's log.

Access to the servers and databases is limited to the few people who operate the service, and is used only to run, maintain and secure it.

6. Security measures

We apply the following measures, and improve them without lowering the overall level of protection during the subscription:

Access control within the firm
Firm roles (firm admin, partner, lawyer, paralegal); a team for each case (lead, members and viewers); visibility levels (the case team and the partners by default, the whole firm, or confidential); and walls for conflicts of interest. One access rule applies to lists, search, similar cases, mentions, notifications, chats and the assistant's answers.
Separation between firms
Every record is tied to its firm; there are no public links and no sharing between firms; and each firm's files sit in a storage folder of its own.
Logs
The firm log records opens, exports, downloads, shares, removals, changes of roles and visibility, requests to join, walls and support access; a firm admin can read and export it. Our team's actions are recorded in a log of their own.
Encryption in transit
Connections between the browser and the service, and between the service and its providers, are encrypted.
Private file storage
Documents are kept in private storage that is never public, and are served only through the service after an access check, or through signed links valid for at most 15 minutes.
Passwords and servers
Passwords are kept only as one-way hashes; the databases and the search engine cannot be reached from the internet; and a firewall protects the servers.
Backups
Every night, a full backup of the service's databases is kept 7 days on the application server and 30 days in the private object storage (Western Europe), then deleted; the search index is snapshotted nightly and kept 7 days.
Quality measured without reading content
We measure the service's quality from counts, the results of the automated reference check and lawyers' ratings, without reading questions, answers or case content.

7. Sub-processors

The Firm gives us general authorisation to use the sub-processors whose categories are set out in Annex 1. We bind each of them by contractual terms to protect the data at a level no lower than this agreement as far as its work is concerned, and we remain responsible to the Firm for their performance.

We notify the firm admin at least 15 days before adding or replacing a sub-processor, unless the security or continuity of the service requires an urgent replacement, in which case we notify them as soon as we can. The Firm may object on reasonable data-protection grounds; if we do not agree on a solution, the Firm may end the subscription before the change takes effect.

The full list of sub-processors, with their names, addresses and processing locations, is given to any firm on request and attached to this agreement when it is sent with the contract.

8. Cross-border transfers

The Firm's data is processed outside Egypt: application servers, databases and the search engine in the European Union (Finland); files and the nightly database backups in private storage in Western Europe; email sent from the European Union; the site's traffic passing through the protection provider's network across many countries; and the AI model provider operating in the United States. The Firm acknowledges this when it subscribes.

Only the question and what is needed to answer it are sent to the AI model provider: texts from the library and excerpts from the Firm's files that the person asking may open, including files attached to the chat; never a whole case file. The provider processes them only to produce the answer, draft or summary, does not use them for training under its terms, and may keep them for a limited period for security and abuse monitoring, as those terms allow.

Article 14 of the Law makes transferring personal data to a foreign country subject to a level of protection not lower than the one the Law sets and to a licence or permit from the Personal Data Protection Centre, as the executive regulations specify. We undertake that transfers take place accordingly, with the safeguards in this agreement: encryption in transit, sending only what is needed, no use for training, and contractual terms with sub-processors.

9. Assisting the Firm

Requests from data subjects: the Firm can carry out most requests with the service's own tools (viewing, editing, exporting and removing), and we help with those it cannot. If a request about the Firm's data reaches us, we pass it to the Firm without undue delay and do not answer it ourselves except on the Firm's instructions.

Other obligations: we give the Firm the reasonable information it needs to assess the processing, to answer the Personal Data Protection Centre and to meet its breach-reporting obligations.

Record of processing: we keep a record of the processing we carry out on the Firm's behalf, as Article 5 of the Law requires.

10. Breach notification

If we become aware of a breach affecting the Firm's data, we notify the firm admin without undue delay, with the information we have: the nature and causes of the breach, the categories of data and the approximate number of records affected, its likely effects, the measures taken and proposed to limit it, and our contact point. We add information as it becomes available.

Article 7 of the Law requires the controller and the processor, as the case may be, to report a breach to the Personal Data Protection Centre within seventy-two hours of becoming aware of it, and to notify the person concerned within three working days of the report. We coordinate with the Firm so that these deadlines can be met, and we meet what the Law requires of us.

Notifying a breach is not an admission of fault or liability.

11. Return and deletion at the end

Return: the Firm can export its data at any time, as set out in the terms of use, and download its documents from their cases.

Deletion: the account owner asks for the Firm to be deleted, and nothing is deleted for 30 days, during which the request can be cancelled. The Firm is then closed to its members, and the following are deleted from every store: search entries; the Firm's files in its folder; all records of cases, chats, documents, drafts, deadlines, firm memory and the firm log; and the accounts of members who belong to no other organisation. The deletion is not counted as complete while anything remains, and it is run again until it is.

The Firm's data also stays in the nightly backups until those are deleted: within 30 days for the database backups and within 7 days for the search index snapshots. We keep the deletion record (who asked, who confirmed and when, and how many items were deleted, without any content) and the subscription and payment records for the period the law requires. We keep nothing else unless the law obliges us to, in which case we protect it and use it for no other purpose. This follows Article 5 of the Law, under which the processor erases personal data when the processing period ends or hands it to the controller.

We confirm the deletion in writing at the Firm's request.

12. Audits and demonstrating compliance

We give the Firm, on request, what is needed to demonstrate our compliance with this agreement and the Law, and we enable the Personal Data Protection Centre to inspect and supervise, as Article 5 of the Law requires.

We answer reasonable security questionnaires in writing. Once a year, with reasonable advance notice, the Firm may carry out an audit itself or through an independent auditor bound to confidentiality, at a time and with a scope agreed in advance, at its own cost, and without access to other firms' data or disruption of the service. An audit may also take place at other times after a breach affecting the Firm's data, or at the Centre's request.

13. Liability, term and governing law

Each party's liability under this agreement is subject to the limits of liability in the terms of use, without prejudice to what the law does not allow to be limited.

This agreement applies for as long as we process data for the Firm, and its confidentiality and deletion obligations continue after the subscription ends until they are fulfilled. It is amended in the way set out in the terms of use, and the “last updated” date at the top of this page shows the version in force. It is governed by Egyptian law, and the courts of Cairo hear disputes under it.

14. Annex 1: sub-processors

This annex sets out the categories of sub-processors. The full list, with each one's name, address and terms, is given on request and attached to the agreement sent with the contract.

Cloud hosting
Service: application servers, databases, the search engine, and the nightly backups kept on the server
Data: all of the Firm's data
Location: European Union (Finland)
Network, protection and file storage
Service: delivering and protecting the site's traffic; keeping documents, files and the nightly database backups in private storage
Data: everything passing through the site, the Firm's files, and the database backups
Location: a global network; file storage in Western Europe
AI model provider
Service: producing the assistant's answers, drafts and summaries
Data: the question and what is needed to answer it, from the library and from the Firm's files
Location: United States
Safeguards: no use for training; limited retention for security, under its terms
Email delivery
Service: sending invitations, password resets, reminders and notices
Data: name, email address and the text of the message
Location: European Union
Payments (once card payment opens)
Service: collecting subscription payments
Data: billing and payment details
Location: Egypt

Annex 2 (security measures) is the security measures section above.