Legal

Privacy Policy

Last updated: July 2026

Draft for product integration — pending review by legal counsel before launch.

This policy explains how AwjPass ([registered legal name], Cairo, Egypt) handles your personal data, in line with Egypt's Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations (Prime Ministerial Decree No. 816 of 2025).

1. Who we are

This app and website are operated by [AwjPass registered legal name], a company registered in Egypt (Commercial Registration No. [CR], Tax Registration No. [TRN]), Cairo, Egypt. For your account and platform data, AwjPass is the data controller.

AwjPass connects you with independent wellness venues. For the data a venue collects about its own clients through AwjPass, the venue is also a controller and AwjPass acts partly as its processor.

Data Protection Officer / privacy contact: privacy@awjpass.com.

2. Data we collect

Identity & contact: name, email, phone, and (optionally) gender and date of birth.

Account & security: hashed credentials, device/session and log data, IP address.

Booking data: the venues, services, staff, dates, check-in and payment status of your bookings.

Payment data: online payments are processed by Paymob. AwjPass receives a payment reference, amount and status — never your full card number.

3. Why we use it (and our lawful basis)

To create and secure your account, and to take and manage bookings — performance of our contract with you.

To process payments, refunds and settlements, and to issue receipts and meet tax and accounting duties — contract and legal obligation.

To prevent fraud and keep the service secure — our legitimate interest.

Promotional messages are sent only if you separately opt in (consent), and you can withdraw that consent at any time. Booking confirmations and reminders for bookings you made are transactional, not marketing.

4. Who we share it with

The venue you book with, to deliver your service.

Our processors, acting on our instructions: Supabase (database/auth/hosting), Cloudflare R2 (file storage), Paymob (payments), and push/email delivery providers.

Authorities or our advisors where required by law. We do not sell your personal data.

5. International transfers

Some processors operate outside Egypt. Where personal data is transferred abroad, we rely on the safeguards permitted by the PDPL and its Executive Regulations, and — where required — on a cross-border transfer licence from the Personal Data Protection Centre (PDPC).

6. Retention & security

We keep data only as long as needed for the purposes above or as required by tax/accounting law, then delete or anonymise it. Records tied to a receipt/invoice are kept for the statutory period.

Data is encrypted in transit and at rest, and access is restricted by role. If a personal-data breach is likely to cause harm, we notify the PDPC within 72 hours and affected individuals within 3 working days.

7. Your rights

You can request access to, correction of, export of, or deletion of your personal data, and object to or restrict certain processing, from the app (Profile → Legal & Privacy) or by emailing privacy@awjpass.com. We respond within the period required by the PDPL.

You can withdraw marketing consent at any time. If you believe we have not handled your data lawfully, you may complain to the Personal Data Protection Centre (PDPC).

8. Cookies & children

Our website uses cookies as described in our Cookie Policy. AwjPass is not directed at children; a parent/guardian with concerns should contact privacy@awjpass.com.

9. Contact

For any privacy request or question, contact privacy@awjpass.com.

Questions? Contact support@awjpass.com.