Skip to main content
Legal

Privacy policy

What personal data we process and why, where it is kept, and how to use your rights under Egypt's Personal Data Protection Law.

Last updated: 4 October 2026

In short

  • Inside the service, the firm controls its data and we process it on the firm's behalf under the data processing agreement. For website forms and accounts we are the controller, as this policy explains.
  • We collect only what is needed: what you write in our forms, account details, and limited technical and usage data.
  • No advertising and no third-party analytics. One cookie of our own remembers where you first came from, for 90 days.
  • Data is hosted outside Egypt: our servers are in the European Union (Finland) and the AI model provider is in the United States, with the safeguards described below.
  • Firm data is never used to train AI models, and we do not sell personal data.
  • You have the rights to know, access, correct, erase, withdraw consent and object, under Law No. 151 of 2020.

This summary is for convenience; the full text below is what applies.

Contents

1. Scope and who we are

This policy applies to the FahmQanon website and service. It explains how we process personal data under the Personal Data Protection Law issued by Law No. 151 of 2020 (the “Law”). Terms such as controller, processor and sensitive personal data have the meaning given in Article 1 of the Law.

The service is provided by the company that operates FahmQanon (“we” or “us”):

Operating company
Intrazero
Commercial registration no.
19035
Address
B Square, Nasr Road, Cairo, Egypt
Email for privacy and legal requests
[email protected]

2. When we are the controller and when the processor

We are the controller of the data we collect for ourselves: website form data; members' accounts, as far as needed to run, secure and bill them; your correspondence with us; and technical logs.

We are a processor on behalf of the firm for everything the firm and its members enter in the service: cases and their parties, documents and attachments, chats with the assistant, drafts, deadlines, firm memory and imported past cases. The firm is the controller of this data; we process it on its instructions and under the data processing agreement, and use it for no purpose of our own.

If your data is in a law firm's files (for example as a client, an opponent or a witness in a case), the firm is responsible for it and any request about it should go to the firm. If your request reaches us, we pass it to the firm and help it respond.

3. What we collect

Website forms. A demo request: your name, firm or organisation, role, country, phone, email, number of lawyers, practice areas, message and the plan you are interested in. A request to add a law or a country: the subject, the message, and your email if you give it. With each request we keep a value derived from the IP address by one-way hashing (not the address itself), used to limit abuse.

Member accounts. Name, email address, firm and role in it, password (kept only as a one-way hash), phone number if one is added, and the time of the last sign-in. When an account is created we may also record the country the connection came from, as our network provider identifies it; values derived by one-way hashing from the IP address and the device, for security; and the first-visit source kept in the cookie described below.

Usage and technical data. The firm log records what happens to cases and members (opens, exports, downloads, shares, removals, role changes, walls and support access) with the member's name, the time and the IP address. We count answers and pages read against the plan's limits, and record citation-check results, lawyers' ratings of answers and the amount of text processed (tokens) for costs, without reading the content. Our web servers keep request logs (IP address, browser and page requested) for 14 days.

Payments and invoices. Subscription, invoice and payment status details. Card payment is not open yet; when it opens, card details will be entered with the payment provider, and we will neither receive nor keep full card numbers.

Your correspondence with us. The messages and support requests you send us.

4. Cookies and browser storage

We use no advertising or cross-site tracking cookies and no third-party analytics. This is what we use:

fq_first_touch
A cookie of our own, written on your first visit and kept for 90 days. It holds the campaign tags in the link, if any (utm_source, utm_medium, utm_campaign), the page you came from, the first page you visited and the time of the visit. It is read only when an account is created, so that we know how people find us.
NEXT_LOCALE
On the sign-in and application pages only: remembers the interface language, and is deleted when the browser is closed.
Browser local storage
After you sign in, keeps your sign-in token, interface preferences such as the theme and the sidebar, and small technical flags. The sign-in token is removed when you sign out.

You can delete cookies and local storage in your browser's settings. Browsing the site is not affected, though you will need to sign in again.

5. Why we use data, and on what basis

We process data for the following purposes, each resting on one of the grounds for lawful processing in Article 6 of the Law:

Answering website requests and arranging demos
Your consent, given by sending the request, and the steps needed to conclude a contract at your request.
Creating accounts, running the service and support
Performing our contract with the firm, and enabling us to meet our obligations to it.
Service emails: invitations, password resets, deadline reminders and notices
Performing our contract with the firm.
Security, preventing abuse and the firm log
Enabling us and the firm to meet our obligations and exercise our legitimate rights, without conflicting with your fundamental rights and freedoms.
Billing, accounting and tax
Performing the contract, and meeting an obligation set by law.
Learning how people find us, and improving quality from counts and ratings
Our legitimate rights, without conflicting with your fundamental rights and freedoms. We read no case or chat content for this.
Complying with the law and with orders, and protecting our rights
Meeting an obligation set by law, an order of the competent investigating authorities or a court judgment, and exercising our legitimate rights.

We do not sell personal data or use it for advertising, and we send no marketing messages without your consent. We make no decision about you that rests solely on automated processing and has legal effects.

6. Who we share data with

We share data with providers that process it on our behalf to run the service (“sub-processors”), each only as far as its work requires:

Cloud hosting
Application servers, databases and the search engine. In the European Union (Finland).
Network, protection and file storage
The site's traffic passes through this provider's network to be delivered and protected, and documents, files and the nightly database backups are kept in private storage with it in Western Europe.
AI model provider
In the United States. It receives the question and what is needed to answer it (texts from the library, and excerpts from the firm's files the person asking may open, including files attached to the chat) only to produce the answer, draft or summary. Under its terms for business use it does not use them for training; it may keep them for a limited period for security and abuse monitoring, as those terms allow.
Email delivery
Sending invitations, password resets, reminders and notices: name, email address and the text of the message. Sends from the European Union.
Payments
Once card payment opens: a local payment gateway in Egypt.

The full list naming each sub-processor is given to firms on request, and is attached as Annex 1 of the data processing agreement sent with the contract.

We may also disclose data when the law, a court order or an order of a competent authority requires it, and only as far as required. If the service passes to a successor, the data passes with it under the same commitments as this policy, with notice to you in advance.

7. Transfers outside Egypt

Our servers and providers are outside Egypt, so personal data is transferred out of Egypt: to the European Union (hosting, files and email), to the United States (the AI model), and across our protection provider's network, which spans many countries.

Article 14 of the Law makes transferring personal data to a foreign country subject to a level of protection not lower than the one the Law sets and to a licence or permit from the Personal Data Protection Centre, and leaves the rules to the executive regulations. We undertake that our transfers take place in accordance with these conditions and rules.

Our safeguards include: choosing providers in countries with strict data-protection laws or bound by contractual terms to protect the data; encrypting data in transit; sending the AI model provider only the minimum needed, with no use for training; and the access controls described in this policy and on the confidentiality page.

8. How long we keep data

Website requests
As long as needed to answer and follow them up. You can ask for yours to be deleted at any time.
Member accounts
As long as the account exists. When a firm is deleted, the accounts of its members who belong to no other organisation are deleted; the account of a member the firm has removed is deleted at that person's request.
Firm data
Until the firm asks for it to be deleted. It is then deleted after a 30-day wait, and its copies in the nightly backups are deleted with those backups, within 30 days after that, as set out in the data processing agreement.
Unused past-case import files
Deleted automatically after 7 days.
Firm log
As long as the firm exists; it is deleted with the firm. After a deletion we keep the deletion record, which holds no content.
Backups
Every night, a full backup of the service's databases is kept 7 days on the application server and 30 days in the private object storage (Western Europe), then deleted; the search index is snapshotted nightly and kept 7 days.
Web server logs
14 days.
Billing and payment records
For the period tax and accounting laws require.
The fq_first_touch cookie
90 days, in your browser.

9. How we protect data

We apply technical and organisational measures suited to legal data, among them: access control through roles, case teams, visibility levels and walls; a log of what happens; files kept in private storage that is never public and downloaded through signed links valid for at most 15 minutes; encryption of data in transit; passwords kept as one-way hashes; and databases and the search engine that cannot be reached from the internet. Our team opens case content only through temporary access a firm grants to one case. The details are on the confidentiality page and in the data processing agreement.

No system is perfectly secure. If a personal data breach occurs, we act to contain it, report it to the Personal Data Protection Centre and notify the people affected, as the Law requires.

10. Your rights and how to use them

Article 2 of the Law gives you the following rights over your personal data:

  • to know about the personal data we hold about you, and to see it, access it and obtain it;
  • to withdraw the consent you gave earlier to our keeping or processing your data;
  • to have your data corrected, amended, erased, added to or updated;
  • to have processing limited to a specified scope;
  • to be told of any breach of your personal data;
  • to object to the processing of your data, or to its results, where it conflicts with your fundamental rights and freedoms.

To use any of these rights, write to [email protected], from the email address we hold for you if possible. We may ask for proof of identity before acting, and we reply within the periods set by the Law and its executive regulations.

Firm members can see their account details, and change some of them, in the service. Requests about firm data go to the firm, as the controller of that data.

You may also complain to the Personal Data Protection Centre, which under Article 19 of the Law receives complaints and reports concerning the Law's provisions.

11. Children

The service is for lawyers and law firms, and we do not knowingly collect children's data through the website or accounts. Firms' files may include children's data in their cases, for example in family matters; the Law treats it as sensitive data, the firm is responsible for it as the controller, and we process it under the data processing agreement.

12. Changes to this policy

We may amend this policy. We publish every change on this page with its “last updated” date, and we tell firm admins about any material change by email or in the service before it takes effect.

13. Contact

For any question or request about your personal data: [email protected].