Zain ERP Logo

Legal

PRIVACY POLICY

Issued by
WKS For Digital Media
Applies to
Zain ERP platform and website
Sections
19

Zain ERP (also branded as Daftar Zain ERP)

Effective Date: [Current Date] Last Updated: [Current Date]

INTRODUCTION AND SCOPE#

This Privacy Policy ("Policy") describes how Zain ERP ("we," "us," "our," or "Company") collects, uses, processes, stores, and protects personal data and sensitive business information when you access or use:

  • Our website at www.zainerp.com
  • Our cloud application at app.zainerp.com
  • Our mobile applications (if applicable)
  • All related services, features, and content (collectively, the "Service")

This Policy applies to:

  • Business users and administrators who register and subscribe to Zain ERP
  • Employees or team members of subscribing businesses who are granted access to the platform
  • Visitors to our website who do not create an account
  • Employees and contractors of businesses who process payroll data through our Service

Important: Zain ERP is a B2B (business-to-business) service designed exclusively for commercial use by organizations and businesses. We do not knowingly collect or process personal data from or about individuals in a personal, non-commercial context. If you are an individual user, you should not use this Service.

For more information on how we use cookies and similar tracking technologies, please refer to our separate Cookie Policy available at www.zainerp.com/cookie-policy.

For terms governing your use of the Service, please refer to our Terms of Service available at www.zainerp.com/terms.

DATA CONTROLLER AND CONTACT INFORMATION#

2.1 Data Controller

Zain ERP is the data controller responsible for the processing of personal data under this Policy. As a freelance/small business team, we operate as:

Legal Entity: Zain ERP (Operating Name: Daftar Zain ERP) Country of Operation: Egypt (MENA Region) Business Type: Cloud-based SaaS Platform for Accounting & ERP

2.2 How to Contact Us

For Privacy Inquiries, Data Requests, or Concerns:

📧 Email: info@daftarzain.com 📱 Phone: +20 100 0566328 📍 Location: Cairo, Egypt

Response Time: We aim to respond to all privacy inquiries within 7-15 business days. Given our small team size, response times may extend beyond this during peak periods, but we will acknowledge receipt of your request within 48 hours.

2.3 Data Protection Authority

If you have concerns about our privacy practices or believe we have violated your data protection rights, you may file a complaint with:

  • Egyptian Personal Data Protection Authority (if applicable based on Egyptian law requirements)
  • Your local data protection authority (if you are located outside Egypt)
  • In the EU, your national Data Protection Authority under GDPR

CATEGORIES OF PERSONAL DATA COLLECTED#

Zain ERP collects different categories of data depending on how you interact with our Service:

3.1 Account Registration and Profile Data

What We Collect:

  • Full name and job title
  • Business name and industry
  • Business email address and phone number
  • Business address and location
  • Business registration/tax ID (if provided)
  • Payment and billing address
  • Subscription tier selected
  • Account preferences and settings

How We Collect It:

  • Directly from you during account registration
  • Updated by you in your account profile
  • Provided during the subscription checkout process

Why We Collect It:

  • To create and manage your account
  • To provide access to the Service
  • To communicate with you about your subscription and account
  • To send billing invoices and subscription confirmations
  • To comply with tax and accounting obligations

3.2 Business Financial, Accounting, and Inventory Data

What We Collect: When you use Zain ERP, you voluntarily input and store sensitive business data within the platform, including:

  • Financial Records: Income transactions, expenses, receipts, invoices, journal entries, bank reconciliations
  • Accounting Data: Account charts, cost centers, ledger entries, financial reports, balance sheets
  • Customer Information: Customer names, contact details, purchase history, credit terms
  • Vendor/Supplier Information: Vendor names, contact details, payment terms, purchase history
  • Inventory Data: Product descriptions, quantities, costs, warehouse locations, SKUs
  • Sales Data: Sales orders, quotations, shipping information, customer interactions
  • Purchasing Data: Purchase orders, supplier quotes, payment records
  • Fixed Asset Records: Asset descriptions, acquisition costs, depreciation schedules, disposal records
  • Cost Accounting Data: Cost allocations, cost center details, project costs

How We Collect It:

  • Directly uploaded by you or your team members
  • Imported from accounting software, bank feeds, or other sources you connect
  • Entered manually into the platform

Why We Collect It:

  • To provide core accounting and ERP functionality
  • To generate financial reports and dashboards specific to your business
  • To store your business records securely in the cloud
  • To enable multi-user collaboration and access control within your organization

Sensitivity and Security: We recognize this data is highly sensitive. We implement technical and organizational safeguards appropriate to the sensitivity of financial and accounting data (see Section 9 for details on security measures).

3.3 Employee and Payroll Data

What We Collect (via Payroll Module):

When you use the payroll processing features, we process the following employee-related personal data on your behalf:

  • Employee Personal Information: Full names, employee IDs, dates of birth, national ID numbers
  • Contact Information: Personal phone numbers, home addresses (if required for payroll)
  • Employment Details: Job titles, departments, employment dates, employment status (full-time, part-time, contract)
  • Salary and Compensation: Salaries, wages, hourly rates, bonuses, allowances, deductions
  • Tax Information: Tax identification numbers, tax status, withholding information
  • Banking Information: Bank account numbers for salary deposits
  • Leave and Attendance: Leave balances, absences, attendance records
  • Compliance Records: Government mandatory information for payroll reporting, social insurance contributions

How We Collect It:

  • Uploaded by you (the business administrator/payroll manager)
  • Imported from existing payroll systems
  • Entered directly into the payroll module

Legal Basis for Processing: Zain ERP acts as a data processor on behalf of your business (the data controller and employer). We process employee data solely as instructed by you and under your control. You, as the employer, are responsible for:

  • Obtaining employee consent to process their personal data (as required by local law)
  • Ensuring payroll data processing complies with labor laws, tax regulations, and employment contracts
  • Determining retention periods for payroll records
  • Informing employees about this Privacy Policy and data processing

Zain ERP does not use employee data for its own purposes (except as required for system maintenance, security, and fraud prevention).

Data Retention for Payroll Data: Payroll records are retained for the period specified in your subscription or until you delete them. After subscription cancellation, payroll data is retained for an additional 30 days (grace period), then permanently deleted within 60 days of cancellation, unless:

  • Local labor or tax law requires longer retention (e.g., Egypt may require 7-year retention for tax/labor compliance)
  • You request export and have saved your own copy

3.4 Payment and Billing Data

What We Collect:

  • Payment method type (credit card, debit card, bank account)
  • Billing name and address
  • Transaction history and receipts
  • Invoice details and payment dates
  • Billing email and communication preferences

What We Do NOT Collect: Zain ERP does not directly collect or store your credit card numbers, expiration dates, or CVV codes. This sensitive payment data is managed exclusively by our third-party payment processor, Paymob (see Section 6 for details).

Why We Collect It:

  • To process your subscription charges
  • To generate invoices and billing records
  • To communicate about billing and payment issues
  • To comply with accounting and tax obligations

3.5 Usage, Technical, and Log Data

What We Collect:

  • Login and Access Information: Login times, IP addresses, browser type and version, device information
  • Feature Usage: Features accessed, modules used, actions performed, time spent on features
  • System Logs: Error messages, performance metrics, system performance data
  • Communication Logs: Support messages, in-app notifications, feedback submitted
  • Analytics Data: Aggregate usage patterns, feature adoption rates, user behavior trends
  • Cookies and Tracking Data: See our separate Cookie Policy for details

How We Collect It:

  • Automatically logged by our servers and application infrastructure
  • Through cookies and similar tracking technologies (see Cookie Policy)
  • Through analytics tools integrated into the Service

Why We Collect It:

  • To provide, maintain, and improve the Service
  • To troubleshoot technical issues and support users
  • To monitor system performance and security
  • To understand how features are being used to guide product development
  • To detect and prevent fraudulent or abusive activity
  • To comply with security and audit requirements

3.6 Cookies and Similar Tracking Technologies

Zain ERP uses cookies, pixels, and similar tracking technologies to collect data about your interactions with our website and application. Please refer to our separate Cookie Policy for detailed information on:

  • Types of cookies used (session, persistent, third-party)
  • Cookie purposes (functionality, analytics, marketing)
  • How to manage or opt out of cookies
  • Third-party services that may set cookies

We reference rather than duplicate this information to avoid confusion.

3.7 Marketing and Newsletter Data

What We Collect:

  • Email address for newsletter subscriptions
  • Preferences for communication frequency and content types
  • Engagement data (email opens, link clicks)
  • Marketing consent status and opt-in/opt-out preferences

How We Collect It:

  • From the newsletter subscription form on our website
  • From marketing preference settings in your account
  • Automatically tracked through email engagement analytics

Why We Collect It:

  • To send you marketing emails, product updates, and promotional offers
  • To communicate about new features, webinars, and industry insights
  • To conduct marketing analytics and improve our email campaigns
  • To maintain a contact list of interested prospects and customers

Your Rights: You can unsubscribe from marketing emails at any time by clicking the "Unsubscribe" link in any marketing email or by adjusting your preferences in your account settings. Unsubscribing from marketing emails will not affect your ability to receive transactional or service-related emails (e.g., billing, password resets, support responses).

Zain ERP processes personal data for specific, legitimate purposes. Under data protection laws (Egypt's Personal Data Protection Law and, where applicable, GDPR), we must provide a legal basis for each processing activity.

4.1 Processing Based on Contract Performance

Purpose: To provide the Service and fulfill your subscription

Data Processed:

  • Account registration and profile data
  • Financial and accounting data you enter
  • Employee/payroll data (as processor on your behalf)
  • Payment and billing data
  • Usage and technical data

Legal Basis: Processing is necessary to perform the contract between you and Zain ERP (your subscription agreement).

4.2 Processing Based on Legitimate Interest

Purpose: To improve the Service, provide support, and ensure business continuity

Data Processed:

  • Usage, technical, and log data
  • Aggregate analytics data
  • Support communications
  • Security and fraud prevention data

Legal Basis: Processing is necessary for our legitimate interests in:

  • Improving and optimizing the Service
  • Providing customer support and resolving issues
  • Preventing fraud, abuse, and unauthorized access
  • Ensuring platform security and data integrity
  • Understanding product performance and user needs
  • Conducting business analytics and product development

Purpose: To comply with laws and regulations

Data Processed:

  • Account information for verification purposes
  • Financial transaction records
  • Employee/payroll data (for tax and labor compliance)
  • Billing and invoicing data

Legal Basis: Processing is necessary to comply with:

  • Tax and accounting regulations in Egypt and other jurisdictions
  • Employment and payroll laws
  • Anti-money laundering (AML) and know-your-customer (KYC) requirements
  • Court orders or legal requests
  • Data protection laws themselves (e.g., to fulfill data subject rights requests)

Purpose: To comply with laws and regulations

Data Processed:

  • Account information for verification purposes
  • Financial transaction records
  • Employee/payroll data (for tax and labor compliance)
  • Billing and invoicing data

Legal Basis: Processing is necessary to comply with:

  • Tax and accounting regulations in Egypt and other jurisdictions
  • Employment and payroll laws
  • Anti-money laundering (AML) and know-your-customer (KYC) requirements
  • Court orders or legal requests
  • Data protection laws themselves (e.g., to fulfill data subject rights requests)
  • Payment industry security standards (PCI DSS)

4.6 Payment Gateway Compliance Processing

Purpose: To maintain compliance with payment processing regulations and security standards

Data Processed:

  • Transaction records and payment history
  • Billing information and invoice details
  • Account verification and fraud prevention data
  • Regulatory compliance documentation

Legal Basis: Necessity for contract performance and legal compliance

  • PCI DSS (Payment Card Industry Data Security Standard) compliance
  • AML (Anti-Money Laundering) verification
  • KYC (Know-Your-Customer) requirements
  • Financial regulations in Egypt and internationally
  • Payment processor requirements (Paymob)

Purpose: To send marketing communications and non-essential communications

Data Processed:

  • Email address for newsletters and marketing
  • Marketing engagement data
  • Communication preferences

Legal Basis: Processing is based on your explicit opt-in consent. You may withdraw this consent at any time by unsubscribing from emails or updating your preferences.

8 Payment Gateway and Regulatory Compliance Commitment#

Zain ERP is committed to maintaining the highest standards of data protection and security for payment processing:

PCI DSS Compliance:

  • All payment processing strictly adheres to PCI DSS (Payment Card Industry Data Security Standard) Level 1
  • Zain ERP itself is PCI DSS compliant via our payment processor Paymob
  • Raw payment card data is never stored by Zain ERP; all sensitive payment information is handled exclusively by Paymob

AML/KYC Compliance:

  • Zain ERP implements anti-money laundering (AML) procedures
  • Know-your-customer (KYC) verification is conducted for account creation
  • Enhanced due diligence for high-risk transactions or accounts
  • Compliance with Egyptian financial regulations and international standards

Data Protection Compliance:

  • GDPR compliance for EU users
  • Egypt's Personal Data Protection Law compliance
  • UK GDPR compliance for UK users
  • Regular compliance audits and assessments

Incident Response and Breach Notification:

  • 72-hour breach notification to affected users (or as required by law)
  • Immediate containment and evidence preservation procedures
  • Cooperation with law enforcement and regulatory authorities
  • Comprehensive incident response plan documented and tested

DATA PROCESSING ACROSS SUBSCRIPTION TIERS#

5.1 Software Only Tier

Data Scope:

  • You input financial, accounting, inventory, and business data
  • Data remains within the platform and your account
  • No additional third-party processing (except Paymob for payments and standard service providers)

Who Accesses Your Data:

  • Only you and team members you grant access to
  • Zain ERP team (only for technical support, security, or system maintenance)
  • Automated systems (for backup, monitoring, analytics)

Processing Characteristics:

  • Self-service; you manage all data entry and reconciliation
  • No white-glove bookkeeping services
  • No AI processing of your financial data

5.2 Full Accounting Service Tier

Data Scope:

  • Includes all data from the Software Only tier
  • Additionally, your full financial records are accessed by Zain ERP's accounting team

Who Accesses Your Data:

  • You and your team members (as above)
  • Zain ERP's accounting staff (as a small team, typically 1-3 accountants or bookkeepers)
  • Zain ERP team for support and system maintenance

Processing Characteristics:

  • Zain ERP acts as a service provider (data processor) on your behalf
  • Our accounting team performs:
  • Day-to-day transaction recording
  • Bank reconciliation
  • Accounts receivable/payable management
  • Journal entry preparation
  • Monthly/quarterly financial reporting
  • Compliance and audit support

Data Handling:

  • Accounting staff access your data securely through the platform (no data export to local computers)
  • Work is performed in the platform using your account
  • All accounting operations are logged and auditable
  • Staff are bound by confidentiality agreements
  • Data is processed only as instructed by you

Important: The Full Accounting Service provides bookkeeping and administrative support, not professional accounting advice, tax planning, or audit services. You remain responsible for tax compliance and strategic financial decisions. See our Terms of Service for full disclaimers.

5.3 AI-Powered Finance Tier

Data Scope:

  • Includes all data from Software Only and Full Accounting Service tiers
  • Additionally, financial data is processed by AI/machine learning systems for analysis and forecasting

Who Accesses Your Data:

  • You, your team, Zain ERP accounting staff (if applicable), and support team (as above)
  • AI/Machine Learning Systems (as described below)

AI Processing: Zain ERP uses artificial intelligence and machine learning to provide:

  • Financial Forecasting: Predictive models of revenue, expenses, and cash flow
  • Anomaly Detection: Identification of unusual transactions or patterns
  • Financial Insights: Analysis and recommendations based on your financial trends
  • AI Finance Assistant: A conversational AI tool to answer questions about your finances

Data Handling for AI Processing:

1. On-Platform Processing: As a small team, we currently process AI analysis within our secured infrastructure using your data. Financial data is not automatically shared with third-party AI providers (e.g., OpenAI, Google Cloud AI) without your explicit consent.

2. Third-Party AI Services (Future Consideration): As we scale, we may use third-party AI model providers to improve analysis and forecasting accuracy. If and when this occurs, we will:

  • Notify you in advance
  • Obtain your explicit consent before processing your data with external AI providers
  • Use data processing agreements with such providers
  • Ensure appropriate data protection safeguards

3. Data De-identification: Where possible, we anonymize or aggregate your data before AI processing to reduce privacy risk.

4. Retention: AI-generated insights and models are retained to improve forecasting accuracy and service quality. Raw customer data used for AI processing is not retained longer than the standard data retention period (see Section 8).

Important Disclaimers:

  • AI-generated outputs (forecasts, anomalies, insights) are not professional financial advice
  • You should not rely solely on AI recommendations for major financial decisions
  • AI models may contain errors or biases; always validate outputs with traditional accounting methods
  • See our Terms of Service for full disclaimers regarding AI-generated content

THIRD-PARTY DATA SHARING AND SUB-PROCESSORS#

Zain ERP does not sell, rent, or trade your personal data to third parties for their marketing purposes. However, we share data with carefully selected service providers who help us operate the Service.

6.1 Payment Processing – Paymob

Service: Payment processing and billing Data Shared: Payment method information, billing name and address, transaction amounts and dates

Paymob's Role: Paymob is a third-party payment processor and acts as a data processor on our behalf. Paymob does not act as a data controller.

Data Protection: Paymob is PCI DSS compliant and handles payment data according to industry security standards. Zain ERP does not receive or store raw credit card data; Paymob manages this securely.

Contact: For questions about Paymob's privacy practices, visit paymob.com or contact their support.

6.2 Cloud Hosting and Infrastructure

Service: Server hosting, data storage, backup, and disaster recovery Data Shared: All customer data is stored on our hosting provider's servers

Hosting Provider: [We use regional cloud infrastructure providers based in Egypt/MENA for data residency compliance]

Data Protection: Our hosting provider is contractually bound to maintain security standards and confidentiality.

6.3 Analytics and Monitoring Tools

Service: Website analytics, application performance monitoring, error tracking Data Shared: Aggregate usage data, technical logs, performance metrics (not personal customer data)

Tools Used: Standard web analytics and application performance monitoring tools (details available upon request)

Data Protection: Analytics data is processed in accordance with this Privacy Policy and our Cookie Policy.

6.4 Customer Support and Communication

Service: Support ticket management, email communication, chat support Data Shared: Email address, support messages, account information relevant to the support issue

Providers: Third-party ticketing systems and communication platforms help us manage support efficiently

Data Protection: Support providers are contractually obligated to maintain confidentiality.

6.5 Accounting Staff (Full Accounting Service and AI-Powered Finance Tiers)

Service: Bookkeeping and accounting operations Data Shared: Full financial, accounting, and business data as necessary to perform accounting services

Staff Status: Zain ERP's small team of accountants/bookkeepers Data Protection:

  • All staff sign confidentiality agreements
  • Access is role-based and restricted to data necessary for assigned tasks
  • All activity is logged for audit purposes
  • Staff are trained on data security and privacy

6.6 Other Third-Party Services (if applicable)

We may use other third-party services for:

  • Email delivery and transactional communications
  • Document signing and contract management
  • Accounting integrations (if you connect external accounting systems)
  • Payment gateway integrations
  • Security and fraud prevention services

Each third-party service is evaluated for data protection compliance before use.

INTERNATIONAL DATA TRANSFERS AND CROSS-BORDER PROCESSING#

7.1 Primary Data Location

Zain ERP operates primarily in Egypt and stores customer data in servers located in the Egypt/MENA region to support regional compliance and data residency requirements.

7.2 International Users

If you are located outside Egypt or use Zain ERP from outside the region:

  • Your data may be transferred to and processed in Egypt/MENA
  • By accepting this Privacy Policy, you consent to such transfers
  • We ensure appropriate safeguards for international transfers

7.3 GDPR Compliance (for EU Users)

If you are located in the European Union, UK, or other jurisdictions with GDPR or similar strong data protection laws:

  • Transfer Mechanism: We rely on Standard Contractual Clauses (SCCs) or similar adequacy mechanisms for lawful data transfers
  • Your Rights: You retain GDPR rights including access, correction, erasure, and portability
  • Data Protection Authority: You may file complaints with your national data protection authority
  • Additional Safeguards: We implement additional technical safeguards for EU user data

7.4 Data Localization and Sovereignty

We recognize that some jurisdictions (including Egypt) may have data residency or sovereignty requirements. We design our infrastructure to:

  • Keep financial and operational data within the MENA region
  • Ensure backup and disaster recovery systems comply with local requirements
  • Provide data localization options where legally or contractually required

DATA RETENTION AND DELETION#

8.1 Retention During Active Subscription

While your subscription is active, Zain ERP retains all data you input or generate within the Service. This includes:

  • Financial and accounting records
  • Employee and payroll data
  • Customer and vendor information
  • Inventory records
  • Usage logs and analytics data
  • Backup copies for disaster recovery

8.2 Retention After Subscription Cancellation

Upon cancellation of your subscription:

Grace Period (30 days):

  • Your account remains accessible for 30 days after cancellation
  • You may download, export, or retrieve your data
  • We retain all data during this period for account recovery purposes

Permanent Deletion (60 days after grace period ends):

  • After the 30-day grace period expires, Zain ERP will delete or destroy all customer data within an additional 60 days
  • This includes:
  • Financial and accounting records
  • Employee/payroll data
  • Customer information
  • Usage logs (where not aggregated/anonymized)
  • All backup copies containing customer data are also deleted
  • Deletion is permanent and irreversible

No Data Recovery:

  • After the 60-day deletion period, Zain ERP cannot recover or restore your data
  • You are responsible for maintaining your own backups before cancellation

Notwithstanding the above, Zain ERP may retain customer data for longer periods if required by law:

Tax and Accounting Compliance:

  • Financial records may be retained for 7 years (standard retention period in Egypt for tax/audit purposes)
  • Payroll records may be retained for 7 years (to comply with employment and tax law)
  • Retention is limited to data required for tax, audit, and legal compliance

Legal Holds and Litigation:

  • Data may be retained if subject to a court order, legal claim, or government request
  • We will notify you of such retention unless prohibited by law

Security and Fraud Prevention:

  • Aggregated security logs and fraud prevention data may be retained longer for system security

8.4 Anonymization and Aggregation

After deletion, Zain ERP may retain anonymized or aggregated data that cannot identify your business or individuals, including:

  • Aggregate usage statistics and trends
  • Anonymized analytics for product improvement
  • De-identified security and performance data

DATA SECURITY MEASURES#

Zain ERP implements technical and organizational security measures appropriate to the sensitivity of financial, accounting, payroll, and personal data processed on the platform.

9.1 Technical Safeguards

Encryption:

  • Data in transit is encrypted using TLS/SSL (HTTPS) protocols
  • Data at rest is encrypted using industry-standard encryption algorithms
  • Sensitive fields (e.g., social security numbers, bank account numbers) may be encrypted with additional layers

Access Controls:

  • Role-based access control (RBAC) restricts who can access specific data
  • Multi-factor authentication (MFA) is available and recommended for accounts
  • Admin accounts require strong passwords and periodic security reviews
  • Automated logging tracks all data access and modifications

Network Security:

  • Firewalls protect against unauthorized network access
  • Regular security scans and vulnerability assessments
  • DDoS protection to prevent service disruption

Backup and Disaster Recovery:

  • Automated daily backups of all customer data
  • Geographically distributed backup locations (within MENA region)
  • Tested disaster recovery procedures to restore service in case of data loss

9.2 Organizational Safeguards

Staff Training and Access Control:

  • All staff who handle customer data receive privacy and security training
  • Access to customer data is restricted to employees with a legitimate business need
  • Confidentiality agreements bind all staff
  • Staff are screened during hiring and monitored for security compliance

Incident Response Plan:

  • Zain ERP maintains an incident response plan for data breaches
  • In case of unauthorized access or data loss, we will:
  • Immediately contain the breach and preserve evidence
  • Notify affected customers within 5 business days (or as required by law)
  • Cooperate with law enforcement and data protection authorities as required
  • Provide guidance on remediation steps

Third-Party Security:

  • All sub-processors and service providers are contractually required to maintain security standards
  • We periodically audit third-party services for compliance

9.3 Compliance with International Standards

Zain ERP is committed to:

  • Compliance with GDPR (where applicable to EU users)
  • Compliance with Egypt's data protection regulations
  • PCI DSS compliance for payment processing (via Paymob)
  • ISO 27001 security standards (where applicable)
  • Regular security audits and vulnerability assessments
  • Mandatory staff training on data protection and security

9.4 Breach Notification

In the event of an unauthorized access to or loss of Customer Data:

  • We will notify affected users within 72 hours (or as required by law)
  • We will provide:
  • Description of the breach
  • Types of data affected
  • Likely consequences
  • Measures taken to mitigate damage
  • Contact information for follow-up questions
  • We will cooperate with authorities as required
  • We will not delay notification to conduct investigations

DATA SUBJECT AND USER RIGHTS#

Under data protection laws (Egypt's Personal Data Protection Law and, where applicable, GDPR), you have rights regarding your personal data. Zain ERP respects these rights and provides mechanisms for you to exercise them.

10.1 Right to Access (Data Subject Access Request)

Your Right: You have the right to request access to all personal data Zain ERP holds about you.

How to Exercise:

  • Submit a written request to info@daftarzain.com
  • Include your name, account email, and date of the request
  • Specify the scope (e.g., "all data," "specific data category")

Our Response:

  • We will provide a copy of your data in a structured, commonly-used format (e.g., CSV, PDF)
  • Response timeframe: 15-30 days (may extend to 60 days for complex requests)
  • No fee will be charged for reasonable requests

10.2 Right to Correction (Data Rectification)

Your Right: If you believe your personal data is inaccurate or incomplete, you can request correction.

How to Exercise:

  • Contact info@daftarzain.com with details of the inaccuracy
  • Specify what data should be corrected and why

Our Response:

  • We will correct inaccurate data promptly
  • We will confirm the correction in writing
  • Response timeframe: 15-30 days

Note: For account and profile data, you can often correct information directly through your account settings.

10.3 Right to Erasure ("Right to Be Forgotten")

Your Right: You can request deletion of your personal data in certain circumstances.

How to Exercise:

  • Contact info@daftarzain.com with a request to delete your data
  • Specify which data categories (e.g., contact information, profile data)

Important Limitations:

  • We cannot delete data if required to retain it by law (e.g., tax records must be retained for 7 years)
  • We cannot delete financial transaction records if they are necessary for audit or compliance
  • If you request deletion of your entire account and data, see the account cancellation process in our Terms of Service
  • Deletion requests will be processed according to our data retention policy (Section 8)

Our Response:

  • We will confirm receipt and status of your deletion request
  • Response timeframe: 15-30 days

10.4 Right to Data Portability

Your Right: You can request your data in a structured, machine-readable format to transfer to another service.

How to Exercise:

  • Contact info@daftarzain.com requesting data portability
  • Specify the format you need (e.g., CSV, JSON, XML)
  • Specify data categories (e.g., accounting records, contact information)

Our Response:

  • We will provide your data in the requested format
  • Data will be provided in a format compatible with common tools
  • Response timeframe: 15-30 days
  • Small processing fee may apply for large or complex requests

Note: Some data may not be portable (e.g., AI-generated analysis created from your data).

10.5 Right to Object

Your Right: You can object to processing of your data in certain circumstances, particularly for:

  • Marketing and promotional communications
  • Profiling or analytics based on legitimate interest
  • Automated decision-making

How to Exercise:

  • For marketing emails: Click "Unsubscribe" in any email or contact info@daftarzain.com
  • For other objections: Contact info@daftarzain.com with details

Our Response:

  • We will stop processing for the stated purpose (unless we have a compelling legal reason to continue)
  • Response timeframe: 15-30 days

Your Right: If we process your data based on consent (e.g., for marketing), you can withdraw consent at any time.

How to Exercise:

  • Contact info@daftarzain.com to withdraw consent
  • Specify what consent you are withdrawing (e.g., "marketing emails," "newsletter subscription")

Our Response:

  • We will stop processing based on that consent
  • Withdrawal is effective immediately upon receipt
  • Prior processing based on valid consent is not retroactively invalid

10.7 Right to Lodge a Complaint

Your Right: If you believe Zain ERP has violated your data protection rights, you can lodge a formal complaint.

Who to Contact: 1. First: Contact Zain ERP directly at info@daftarzain.com to resolve the issue 2. Then: If unresolved, file a complaint with your local data protection authority:

  • Egypt: Egyptian Personal Data Protection Authority (or relevant local authority)
  • EU: Your national Data Protection Authority
  • Other: Your country's data protection regulator

10.8 Exercising Your Rights

General Process: 1. Submit a request to info@daftarzain.com 2. Include your full name, account email, and request type 3. Provide any relevant details or supporting information 4. We will acknowledge receipt within 48 hours 5. We will respond with a substantive answer within 15-30 days (may extend to 60 days for complex requests) 6. If we deny a request, we will explain the reason and your right to appeal

Identity Verification:

  • We may ask you to verify your identity before processing requests
  • Verification helps us protect your data from unauthorized access

No Retaliation:

  • We will not penalize or discriminate against you for exercising your rights
  • Your right to use Zain ERP is not conditioned on waiving your data protection rights

SPECIAL HANDLING OF EMPLOYEE DATA#

When Zain ERP processes employee data (via the payroll module or Full Accounting Service), we have special obligations.

11.1 Data Processor Role

Zain ERP's Status: Zain ERP is a data processor when handling employee personal data. Your business (the employer) is the data controller.

What This Means:

  • You determine what employee data is collected, how it is used, and how long it is retained
  • You are responsible for obtaining employee consent and complying with employment laws
  • Zain ERP processes employee data only as instructed by you
  • Zain ERP does not use employee data for its own marketing, analytics, or business purposes

As the data controller, you are responsible for:

  • Informing employees that their data is processed via Zain ERP
  • Providing employees with this Privacy Policy or an employee-specific privacy notice
  • Obtaining any required consent for payroll processing
  • Complying with local labor laws regarding employee data

We recommend including privacy notice language in employee handbooks or employment contracts.

11.3 Data Processor Agreement

For customers using the payroll module or Full Accounting Service tier, we maintain a data processor agreement that specifies:

  • Data processing obligations and limitations
  • Sub-processors (e.g., hosting providers)
  • Data security and confidentiality requirements
  • Audit and compliance rights

You can request a copy of our standard Data Processor Addendum (DPA) at info@daftarzain.com.

11.4 Employee Rights with Respect to Payroll Data

Employees may exercise data rights (access, correction, objection) with respect to their payroll information. If an employee contacts Zain ERP directly, we will:

  • Redirect the employee to contact their employer (you) as the data controller
  • Cooperate with you to fulfill valid employee requests
  • Not share employee data with the employee except through you (the employer)

CHILDREN'S PRIVACY#

12.1 No Service to Minors

Zain ERP is a B2B service designed exclusively for business use by organizations and adult users. We do not knowingly:

  • Collect personal data from individuals under 18 years of age
  • Provide our Service to minors for personal, educational, or non-commercial use
  • Knowingly solicit data from children

12.2 Parental/Guardian Responsibility

If a parent or guardian believes a child has provided personal data to Zain ERP, please contact us immediately at info@daftarzain.com, and we will delete the data.

12.3 Exception: Employee Payroll Data

Payroll records may include minimal information about employees' dependents (e.g., number of dependents for tax purposes), but such data is:

  • Processed solely for payroll and tax compliance
  • Not used for marketing or profiling
  • Treated with the same security as other employee data

POLICY CHANGES AND NOTIFICATION#

13.1 Right to Modify This Policy

Zain ERP reserves the right to modify this Privacy Policy at any time to reflect changes in:

  • Our data processing practices
  • Applicable laws and regulations
  • Our business operations
  • Technology and security standards

13.2 Notice of Changes

When we make material changes to this Privacy Policy, we will:

  • Provide 30 days' advance written notice via email to your registered account email
  • Display a prominent notice on our website (www.zainerp.com)
  • Update the "Last Updated" date at the top of this Policy
  • Describe the changes clearly (summary of key modifications)

13.3 Material vs. Non-Material Changes

Material Changes (requiring advance notice):

  • Changes to your data rights
  • New data categories being collected
  • New third-party data sharing
  • Changes to data retention periods
  • Changes to international data transfers
  • Reduction in security safeguards

Non-Material Changes (effective immediately):

  • Clarifications or corrections
  • Contact information updates
  • Addition of security safeguards
  • Minor wording improvements

13.4 Your Acceptance

Your continued use of Zain ERP after the notice period constitutes acceptance of the modified Policy. If you do not agree with changes, you may cancel your subscription (see our Terms of Service for cancellation procedures).

CONTACT US AND FILING COMPLAINTS#

14.1 Privacy Questions and Requests

If you have questions about this Privacy Policy or wish to exercise your data rights:

📧 Email: info@daftarzain.com 📱 Phone: +20 100 0566328 ⏱️ Response Time: We aim to acknowledge your inquiry within 48 hours and provide a substantive response within 7-15 business days

Include in your email:

  • Your name and account email address
  • Type of request (access, correction, deletion, objection, etc.)
  • Detailed description of your inquiry
  • Any relevant dates or transaction information

14.2 General Support Inquiries

For technical support or general questions about the Service (not privacy-specific):

📧 Email: info@daftarzain.com 📱 Phone: +20 100 0566328 ⏱️ Response Time: 24/7 support with responses typically within 24 hours

14.3 Filing a Complaint with a Data Protection Authority

If you believe Zain ERP has violated your privacy rights and we have not resolved the matter, you have the right to lodge a complaint with a data protection authority:

In Egypt:

  • Contact the relevant Egyptian data protection authority (if established) or pursue remedies under Egyptian civil law

In the European Union:

  • Contact your national Data Protection Authority (your country's "Supervisory Authority")
  • You may file complaints with the data protection authority in your member state or where the alleged violation occurred
  • A list of EU DPAs is available at edpb.ec.europa.eu

In Other Countries:

  • Contact your local data protection regulator or relevant government agency

14.4 Dispute Resolution

Before escalating to a data protection authority, we encourage you to: 1. Contact us at info@daftarzain.com with a detailed explanation of your concern 2. Allow 15 business days for us to investigate and respond 3. Work toward a collaborative resolution

We are committed to resolving privacy concerns promptly and fairly.

ADDITIONAL INFORMATION FOR SPECIFIC JURISDICTIONS#

15.1 Egypt

Zain ERP is operated by a small business team based in Egypt and is subject to Egyptian law. This Privacy Policy is designed to comply with Egyptian data protection principles and applicable regulations. Data is primarily stored in Egypt or the MENA region.

15.2 European Union / GDPR

For customers located in or using Zain ERP from the EU:

  • GDPR Applicability: If you are an EU resident or your business processes EU personal data, GDPR applies to your use of Zain ERP
  • Data Transfers: Your data is transferred to Egypt; such transfers are governed by Standard Contractual Clauses or similar mechanisms
  • Your Rights: You retain all rights under GDPR (access, rectification, erasure, portability, objection, profiling rights)
  • Data Protection Authority: You may contact your national data protection authority regarding GDPR compliance
  • DPA: We maintain a Data Processing Agreement for EU customers; request at info@daftarzain.com

15.3 United Kingdom / UK Data Protection Act 2018

UK residents and businesses using Zain ERP are covered under the UK Data Protection Act 2018 and UK GDPR. The same rights and protections as EU GDPR users apply.

DEFINITIONS#

  • "Data" means any information relating to an identified or identifiable natural person (personal data) or business information (business data)
  • "Personal Data" means any information about a natural person (individual) that can identify them, including name, email, phone, address, employment details, financial information
  • "Data Controller" means the entity that determines the purposes and means of data processing (Zain ERP, with respect to general account data; you, with respect to employee data)
  • "Data Processor" means the entity that processes data on behalf of a data controller (Zain ERP, with respect to employee payroll data)
  • "Processing" means any operation performed on data, including collection, use, storage, transfer, analysis, or deletion
  • "Service" means the Zain ERP platform, website, applications, and all related services
  • "We/Us/Our" means Zain ERP
  • "You/Your" means the business, organization, or individual using Zain ERP

FINAL NOTICE#

This Privacy Policy is current as of the Last Updated date shown at the top of this document. Zain ERP reserves all rights to modify this Policy. Please review this Policy periodically for updates.

By using Zain ERP, you acknowledge that you have read and understood this Privacy Policy and agree to our data processing practices.

Questions? Contact us at info@daftarzain.com or call +20 100 0566328.

END OF PRIVACY POLICY

APPENDIX A: DATA PROCESSING SUMMARY TABLE#

This table provides a quick reference for data processing activities:

Data CategoryCollection MethodPurposeLegal BasisRetentionSharing
Account/Registration DataDirect user inputAccount mgmt, billing, service provisionContractDuring subscription + 30 days graceBilling/support providers
Financial/Accounting DataUser input/importProvide accounting service, reportsContractDuring subscription + 30 days graceAccounting staff (Full Service/AI tiers)
Employee/Payroll DataUser input/importPayroll processing, tax complianceContract + LegalDuring subscription + 30 days grace; payroll records 7 years for taxPayroll processors, tax authorities
Payment/Billing DataSubscription checkoutProcess charges, invoicingContractDuring subscription + 30 days grace; 7 years for taxPaymob (processor), tax authorities
Usage/Technical DataAutomatic loggingService improvement, support, securityLegitimate Interest1-3 years (aggregate); longer for securityHosting providers, analytics services
CookiesWebsite trackingFunctionality, analytics, marketingConsentSee Cookie PolicyThird-party services (see Cookie Policy)
Marketing/NewsletterSubscription formMarketing communicationsConsentUntil unsubscribeEmail service provider

End of Document

Questions about this document? Reach us through the contact page.