Data Processing Terms
Who is the controller, who is the processor, and on what terms we handle personal data.
Who is the controller, who is the processor, and on what terms we handle personal data.
Which law this follows
These terms are written to comply with Egyptian Personal Data Protection Law 151 of 2018 and its executive regulation, and with any other legislation in force that applies to the processing.
They form part of the agreement between Inno Source and every subscribing company, and they apply to all personal data processed through the system and its related applications and tools.
Where a signed subscription contract addresses a matter differently, that contract prevails.
Controller and processor
The customer is the CONTROLLER of the personal data it enters or collects about its own employees, customers and suppliers. It decides why and how that data is processed.
Inno Source is the PROCESSOR of that data. It processes it on the customer's documented instructions and only so far as performing this agreement requires.
This split decides who answers to the regulator and to the data subject. In practice it means: a request from an employee about their own record goes to their employer, and we cannot and do not act on it directly.
For the limited data we hold about the customer as our own client — contact details, invoices, correspondence — we are the controller.
The scope of our processing
We process personal data only to provide, operate, secure and support the service, and to comply with a legal obligation.
We do not sell personal data, we do not use it for advertising, and we do not process it for any purpose of our own beyond the one stated next.
The one additional purpose: we may use data in AGGREGATED and ANONYMISED form to analyse and improve the service. Aggregated and anonymised means the result cannot be traced back to the customer, to any individual, or to the customer's figures or trade secrets. This is stated openly rather than buried, because a purpose a customer discovers later is a purpose they did not agree to.
For the camera-counting unit, images and derived metadata from operation may be used to improve the detection models, subject to the same non-disclosure condition, and the customer may object to this in writing.
Biometric and special-category data
The system can process biometric data. Specifically: fingerprint attendance from attendance devices; face matching on an attendance photograph, where the employer has enabled it; and face recognition for attendance in the vision module, where the employer has enabled it.
Biometric data is special-category personal data under Egyptian Personal Data Protection Law 151 of 2018.
THE CUSTOMER ALONE IS RESPONSIBLE for obtaining explicit consent from the individuals concerned before enabling any of these features, for notifying them of the purpose and the retention, and for the lawfulness of the processing generally. We supply the tool; the decision to point it at a person is the employer's.
The customer indemnifies Inno Source against any claim, fine or proceeding arising from a failure to obtain those consents or to give those notices.
Every one of these features is off unless the customer switches it on. None of them is on by default, and a company that never enables them processes no biometric data through this system at all.
Security measures
We apply appropriate technical and organisational measures to protect personal data against unauthorised access or disclosure. Those measures include, and are not limited to:
tenant isolation — each customer's data is held in a separate database schema, logically isolated from every other customer;
permission-based access — each user reaches only what their role and their accessible branches allow, enforced at the server and not merely in the interface;
server-side masking of financial figures from users who lack the financial-data permission, so a withheld figure is returned as absent rather than as zero;
encryption in transit, and sealed storage of device credentials on the machines that hold them;
regular backups, and an audit record of sensitive actions including refused attempts.
These are described as they are implemented. A measure we do not operate is not listed here.
Sub-processors
We engage sub-processors to run the service. By category:
hosting and infrastructure providers — always engaged;
messaging platforms, where the customer has configured one;
artificial-intelligence providers, where the customer has enabled AI or vision features;
payment gateways, where the customer has configured one.
Only the first is unavoidable. A customer that configures no messaging platform, no AI provider and no payment gateway sends personal data to none of them.
We remain responsible to the customer for our sub-processors within the limits of liability set out in our terms, and we bind them to confidentiality obligations no weaker than our own.
The identity of the sub-processors engaged for a particular customer is given on written request.
Breach notification
Each party shall notify the other, without undue delay, of any breach or leak that comes to its knowledge and affects personal data covered by this agreement.
Our notification states what we know at the time of sending — what happened, which categories of data are affected so far as we can tell, and what we are doing — and is followed up as more becomes known. We do not delay a notification in order to make it complete.
Notification to the regulator and to the individuals concerned is the CONTROLLER's obligation, that is, the customer's. We provide the information the customer needs to make it.
We are not responsible for a leak or loss whose source is the customer, its users, its infrastructure, its devices, its disclosure of login credentials, or its own negligence in managing permissions.
Requests from the people in the data
A data subject exercises their rights against the CONTROLLER.
Where the controller is the customer — which is almost always the case — a request that reaches us is passed to the customer and is not actioned by us. Acting on it without the employer would itself be processing outside the customer's instructions, and therefore a breach.
We assist the customer in answering such a request, within a reasonable time and at no additional charge where the assistance is proportionate.
Where we are the controller, a request is sent to the address published in our privacy policy and we answer it ourselves.
Return and deletion
On the end of the relationship for any reason, and provided all sums due have been paid, we enable the customer to export its data in a standard readable electronic format within thirty (30) days of the end date.
Sixty (60) days after the end date we may permanently delete the customer's data from our infrastructure in accordance with our retention practice, unless a longer retention has been agreed in writing and for consideration.
Preparing data in a special or non-standard format is work outside the scope and is quoted separately.
Records we are required by law to keep are retained for the statutory period regardless of the above.
The customer undertakes to remove the software installed at its premises — the counting program and the hardware agent — and to return or destroy any copies or documents belonging to us.
Confidentiality and non-solicitation
Each party shall keep confidential the information it becomes aware of by reason of this agreement and shall not disclose it to a third party, during the term and for three (3) years after it ends. Disclosure required by a competent judicial or regulatory authority is excepted.
Neither party shall, directly or indirectly, employ or engage any of the other party's personnel who took part in performing this agreement, during its term and for twelve (12) months after it ends, except with written consent. A party in breach shall pay agreed compensation equal to twelve (12) months' wages of the person concerned, without need to prove loss.
Language and the governing text
These terms were drafted in Arabic. The Arabic text is the authentic and governing version. The English version is provided as a convenience translation, and where the two differ in meaning the Arabic text alone applies.
All pages
- المستندات القانونية
- Inno Counter — Camera and Image Policy
- سياسة الكاميرات والصور — عدّاد إنو
- Inno Counter — Terms of Use
- إنو كاونتر — شروط الاستخدام
- شروط استخدام الموقع
- خصائص الذكاء الاصطناعي — إزاي بتشتغل وحدودها
- AI features — How they work and their limits
- Inno Source ERP — Terms of Service
- خصوصية الموقع وملفات الكوكيز
- Website Terms of Use
- About Us – Inno Source Tech Solutions
- Inno Source Mobile Application
- سياسة الخصوصية
- Subscription, Cancellation and Refunds
- الاشتراك والإلغاء والاسترداد
- Service Level and Support
- مستوى الخدمة والدعم الفني
- Inno Agent — Terms and Remote Access
- شروط الوكيل (Inno Agent) والتحكم عن بُعد
- Inno Time — What It Records About an Employee
- إنو تايم — بيسجّل إيه عن الموظف
- Inno Source mobile app — Privacy Policy
- تطبيق إنو سورس — سياسة الخصوصية
- Inno Source mobile app — Terms of Use
- شروط استخدام تطبيق إنو سورس
- Van sales app — Terms of Use
- شروط استخدام تطبيق مبيعات الفان
- Website Privacy and Cookies
- Legal documents
- الضمانات وحدود المسؤولية
- Acceptable Use Policy
- سياسة الاستخدام المقبول
- Data Processing Terms
- شروط معالجة البيانات
- Privacy Policy
- شروط استخدام نظام إنو سورس
- Warranties and Limits of Liability
- Contact Us – Inno Source Tech Solutions
- FAQs – Inno Source Tech Solutions
- Pricing and plans
- Start a subscription
- Blog