MAAT

Log In

🔒 Privacy Policy & Personal Data Protection

Last updated: April 2026 — Compliant with Egyptian Personal Data Protection Law No. 151 of 2020

1. Data Controller

MAAT Platform (MAAT), Arab Republic of Egypt. Data Protection Officer: [email protected]

2. Data We Collect

Registration data: Full name, national ID (14 digits), phone, email, ID card photo (both sides), biometric video with GPS.

Professional data: Syndicate number, professional card photo, specializations, years of experience, office details, bank account.

Usage data: GPS location, request history, financial transactions, conversations (encrypted at rest — see Clause 5), call logs, ratings.

Device data: Device type, OS, device ID (for notifications).

3. Legal Basis for Processing (Article 5 — PDPL)

Contractual necessity: Processing data required to fulfill the service contract.

Explicit consent: Your consent at registration to the Terms including the data use clause.

Legitimate interest: Improving services, preventing fraud, ensuring security.

4. Use of Data for AI (Clause 7)

By accepting the Terms, the Platform automatically anonymizes your data (removing name, national ID, phone, and email) and uses the anonymized data to train AI models and produce market reports.

Anonymized data is not personal data under Article 2 of Egypt's PDPL.

You may object to this use or request its restriction at any time without affecting your use of the Platform — see Clause 6 (Your Rights) for how to exercise this right.

5. Encryption & Security

Chat messages are encrypted at rest with AES-256-GCM, using a separate derived key per conversation channel — this is server-side encryption, not end-to-end encryption; the Platform can technically access message content when necessary (for example, reviewing content that violates policy, responding to a lawful request, or investigating a dispute), and this access is restricted to the Platform's top-level owner role and logged to a reviewable access log.

Financial data is protected by a hash-chained audit trail.

Local mobile data is encrypted with SQLCipher (AES-256).

6. Your Rights (Articles 3 & 4 — PDPL)

You have the right to: access, correct, delete, and transfer your data, and to object to or restrict any processing — including use of your anonymized data to train AI (Clause 4 above).

To exercise rights: email [email protected] — we respond within 15 business days.

7. Data Sharing

We do not sell your personal data. We share it only with: Stripe (payment processing), Firebase (notifications), cloud storage providers, AI providers (OpenAI and Anthropic — for processing text, voice, and documents, per the consent described in Clause 4 above), and judicial authorities upon legal request.

Some of these providers are located outside Egypt; any international transfer of your data is governed by Article 14 of Personal Data Protection Law 151/2020, which requires an equivalent level of protection or adequate contractual safeguards.

8. Data Retention

We retain data for your active account lifetime + 5 years after closure (legal obligation). Anonymized data is stored permanently.

9. Complaints

You may file a complaint with the Personal Data Protection Centre (PDPC) under Law No. 151 of 2020.