In short
- Inside the service, the firm controls its data and we process it on the firm's behalf under the data processing agreement. For website forms and accounts we are the controller, as this policy explains.
- We collect only what is needed: what you write in our forms, account details, and limited technical and usage data.
- No advertising and no third-party analytics. One cookie of our own remembers where you first came from, for 90 days.
- Data is hosted outside Egypt: our servers are in the European Union (Finland) and the AI model provider is in the United States, with the safeguards described below.
- Firm data is never used to train AI models, and we do not sell personal data.
- You have the rights to know, access, correct, erase, withdraw consent and object, under Law No. 151 of 2020.
This summary is for convenience; the full text below is what applies.
Contents
1. Scope and who we are
This policy applies to the FahmQanon website and service. It explains how we process personal data under the Personal Data Protection Law issued by Law No. 151 of 2020 (the “Law”). Terms such as controller, processor and sensitive personal data have the meaning given in Article 1 of the Law.
The service is provided by the company that operates FahmQanon (“we” or “us”):
- Operating company
- Intrazero
- Commercial registration no.
- 19035
- Address
- B Square, Nasr Road, Cairo, Egypt
- Email for privacy and legal requests
- [email protected]
2. When we are the controller and when the processor
We are the controller of the data we collect for ourselves: website form data; members' accounts, as far as needed to run, secure and bill them; your correspondence with us; and technical logs.
We are a processor on behalf of the firm for everything the firm and its members enter in the service: cases and their parties, documents and attachments, chats with the assistant, drafts, deadlines, firm memory and imported past cases. The firm is the controller of this data; we process it on its instructions and under the data processing agreement, and use it for no purpose of our own.
If your data is in a law firm's files (for example as a client, an opponent or a witness in a case), the firm is responsible for it and any request about it should go to the firm. If your request reaches us, we pass it to the firm and help it respond.
3. What we collect
Website forms. A demo request: your name, firm or organisation, role, country, phone, email, number of lawyers, practice areas, message and the plan you are interested in. A request to add a law or a country: the subject, the message, and your email if you give it. With each request we keep a value derived from the IP address by one-way hashing (not the address itself), used to limit abuse.
Member accounts. Name, email address, firm and role in it, password (kept only as a one-way hash), phone number if one is added, and the time of the last sign-in. When an account is created we may also record the country the connection came from, as our network provider identifies it; values derived by one-way hashing from the IP address and the device, for security; and the first-visit source kept in the cookie described below.
Usage and technical data. The firm log records what happens to cases and members (opens, exports, downloads, shares, removals, role changes, walls and support access) with the member's name, the time and the IP address. We count answers and pages read against the plan's limits, and record citation-check results, lawyers' ratings of answers and the amount of text processed (tokens) for costs, without reading the content. Our web servers keep request logs (IP address, browser and page requested) for 14 days.
Payments and invoices. Subscription, invoice and payment status details. Card payment is not open yet; when it opens, card details will be entered with the payment provider, and we will neither receive nor keep full card numbers.
Your correspondence with us. The messages and support requests you send us.
5. Why we use data, and on what basis
We process data for the following purposes, each resting on one of the grounds for lawful processing in Article 6 of the Law:
- Answering website requests and arranging demos
- Your consent, given by sending the request, and the steps needed to conclude a contract at your request.
- Creating accounts, running the service and support
- Performing our contract with the firm, and enabling us to meet our obligations to it.
- Service emails: invitations, password resets, deadline reminders and notices
- Performing our contract with the firm.
- Security, preventing abuse and the firm log
- Enabling us and the firm to meet our obligations and exercise our legitimate rights, without conflicting with your fundamental rights and freedoms.
- Billing, accounting and tax
- Performing the contract, and meeting an obligation set by law.
- Learning how people find us, and improving quality from counts and ratings
- Our legitimate rights, without conflicting with your fundamental rights and freedoms. We read no case or chat content for this.
- Complying with the law and with orders, and protecting our rights
- Meeting an obligation set by law, an order of the competent investigating authorities or a court judgment, and exercising our legitimate rights.
We do not sell personal data or use it for advertising, and we send no marketing messages without your consent. We make no decision about you that rests solely on automated processing and has legal effects.
7. Transfers outside Egypt
Our servers and providers are outside Egypt, so personal data is transferred out of Egypt: to the European Union (hosting, files and email), to the United States (the AI model), and across our protection provider's network, which spans many countries.
Article 14 of the Law makes transferring personal data to a foreign country subject to a level of protection not lower than the one the Law sets and to a licence or permit from the Personal Data Protection Centre, and leaves the rules to the executive regulations. We undertake that our transfers take place in accordance with these conditions and rules.
Our safeguards include: choosing providers in countries with strict data-protection laws or bound by contractual terms to protect the data; encrypting data in transit; sending the AI model provider only the minimum needed, with no use for training; and the access controls described in this policy and on the confidentiality page.
8. How long we keep data
- Website requests
- As long as needed to answer and follow them up. You can ask for yours to be deleted at any time.
- Member accounts
- As long as the account exists. When a firm is deleted, the accounts of its members who belong to no other organisation are deleted; the account of a member the firm has removed is deleted at that person's request.
- Firm data
- Until the firm asks for it to be deleted. It is then deleted after a 30-day wait, and its copies in the nightly backups are deleted with those backups, within 30 days after that, as set out in the data processing agreement.
- Unused past-case import files
- Deleted automatically after 7 days.
- Firm log
- As long as the firm exists; it is deleted with the firm. After a deletion we keep the deletion record, which holds no content.
- Backups
- Every night, a full backup of the service's databases is kept 7 days on the application server and 30 days in the private object storage (Western Europe), then deleted; the search index is snapshotted nightly and kept 7 days.
- Web server logs
- 14 days.
- Billing and payment records
- For the period tax and accounting laws require.
- The
fq_first_touchcookie - 90 days, in your browser.
9. How we protect data
We apply technical and organisational measures suited to legal data, among them: access control through roles, case teams, visibility levels and walls; a log of what happens; files kept in private storage that is never public and downloaded through signed links valid for at most 15 minutes; encryption of data in transit; passwords kept as one-way hashes; and databases and the search engine that cannot be reached from the internet. Our team opens case content only through temporary access a firm grants to one case. The details are on the confidentiality page and in the data processing agreement.
No system is perfectly secure. If a personal data breach occurs, we act to contain it, report it to the Personal Data Protection Centre and notify the people affected, as the Law requires.
10. Your rights and how to use them
Article 2 of the Law gives you the following rights over your personal data:
- to know about the personal data we hold about you, and to see it, access it and obtain it;
- to withdraw the consent you gave earlier to our keeping or processing your data;
- to have your data corrected, amended, erased, added to or updated;
- to have processing limited to a specified scope;
- to be told of any breach of your personal data;
- to object to the processing of your data, or to its results, where it conflicts with your fundamental rights and freedoms.
To use any of these rights, write to [email protected], from the email address we hold for you if possible. We may ask for proof of identity before acting, and we reply within the periods set by the Law and its executive regulations.
Firm members can see their account details, and change some of them, in the service. Requests about firm data go to the firm, as the controller of that data.
You may also complain to the Personal Data Protection Centre, which under Article 19 of the Law receives complaints and reports concerning the Law's provisions.
11. Children
The service is for lawyers and law firms, and we do not knowingly collect children's data through the website or accounts. Firms' files may include children's data in their cases, for example in family matters; the Law treats it as sensitive data, the firm is responsible for it as the controller, and we process it under the data processing agreement.
12. Changes to this policy
We may amend this policy. We publish every change on this page with its “last updated” date, and we tell firm admins about any material change by email or in the service before it takes effect.
13. Contact
For any question or request about your personal data: [email protected].