Inno Source

Privacy Policy

What personal data the Inno Source products collect, why, and for how long.

What personal data the Inno Source products collect, why, and for how long.

Who the controller is

For the personal data a subscribing company enters or collects about its own employees, customers and suppliers, that company is the data CONTROLLER. We are the data PROCESSOR, acting on its instructions and only so far as running the service requires.

This split decides who answers to a regulator and who answers to the person the data is about. If you are an employee or a customer of a company that uses Inno Source, your request goes to that company, not to us — we cannot act on it without them, and doing so would itself be a breach.

For the limited data we hold about our own direct customers and about visitors to our website, we are the controller.

What we collect, product by product

The ERP holds what the subscribing company enters: staff records, customer and supplier records, documents, transactions and accounting entries.

The staff mobile app holds the user's account and, where the employer has enabled mobile attendance, the location of a check-in and optionally a check-in photograph.

The van sales app holds route, stock, invoice and collection data for the representative operating it.

Inno Agent holds no personal data. It holds a device token and communicates with hardware on the local network.

Inno Counter holds production images from the camera; what it keeps and for how long is set out in the Inno Counter privacy notice.

Inno Time records working-time measurements from a company PC; what it does and deliberately does not record is set out in its own notice.

Attendance devices produce fingerprint and, where enabled, face data. That is special-category data and is covered separately below.

Camera footage and images

Camera images exist for two distinct purposes and they are not mixed.

Production counting: the camera watches a production line to count units. Images kept for that purpose are of the product, and the cropped images that the model could not recognise are kept so the model can be corrected. What is kept locally, what is uploaded and the limits on both are stated in the Inno Counter privacy notice.

Attendance and recognition: where the subscribing company has enabled face recognition for attendance, images of PEOPLE are processed. That is special-category personal data. The company must obtain explicit consent from the individuals concerned before enabling it. We provide the tool; the company is responsible for the lawfulness of using it.

We do not sell images, and we do not disclose an image that identifies a person to any third party except where a competent judicial or regulatory authority requires it.

Where data is stored and who can reach it

Data is held on secure infrastructure, with each customer in a separate database schema logically isolated from every other customer.

Within a customer, access is governed by that customer's own permission settings: each user sees what their role and their accessible branches allow, and financial figures are withheld at the server from users who lack the financial-data permission — not merely hidden in the interface.

Our own staff reach customer data only where support or operation requires it, and under the confidentiality obligation described in our terms.

Everything sent between our apps and our servers travels over an encrypted HTTPS/TLS connection. Device credentials are held in sealed storage on the machine that holds them, we take regular backups, and sensitive actions are written to an audit log that also records refused attempts.

We may move hosting to other infrastructure or another provider without prejudice to data security, giving prior notice where the move affects the service.

No system is perfectly secure and we do not claim otherwise. Where a breach affects data covered by this policy we notify without undue delay, as set out in our Data Processing Terms.

Third parties that see data

We use sub-processors to run the service. By category they are: hosting providers; messaging platforms, where the customer has enabled them; artificial-intelligence providers, where the customer has enabled AI features; and payment gateways, where the customer has enabled them.

Each of those categories is optional except hosting. A customer that does not configure a messaging platform, an AI provider or a payment gateway sends no data to one.

Where an AI feature is used, the content of that request leaves our infrastructure and reaches the configured provider. That is stated again, more fully, in our AI policy, because it is the point people most need to know before switching the feature on.

We remain responsible towards the customer for our sub-processors within the limits set out in our terms.

How long we keep things

While the subscription is running, we keep the customer's data for as long as the customer keeps it. Deleting a record inside the system is the customer's decision, not ours.

After the relationship ends, the customer has thirty (30) days to export its data, and we may permanently delete it from our infrastructure sixty (60) days after the end date, unless a longer retention has been agreed in writing.

Camera images kept for counting review are subject to their own, much shorter, retention, described in the Inno Counter privacy notice.

Records we must keep for statutory reasons — invoices and accounting records about our own customers — are kept for the period the law requires, regardless of the above.

Rights of the people in the data

A person whose data is in the system has the rights granted by Egyptian Personal Data Protection Law 151 of 2018 — to know, to access, to correct, and to have data erased in the cases the law allows.

Those rights are exercised against the CONTROLLER. In almost every case that is the company that employs you or that you deal with, not Inno Source.

That is not a reason to leave you without a route. To ask for your data to be deleted, corrected, or sent to you, write to the address in the last section of this policy with the subject "Data deletion request" (or "correction" / "copy"), giving your full name, the company you deal with, and the email or phone your record uses — we need those to find your record and to be sure the request is yours.

We acknowledge within seven (7) days and complete within thirty (30) days. Where the controller is that company we forward your request to them, act on their instruction, and tell you we have done so and to whom. Where the data is ours to delete we delete it and confirm.

What cannot be deleted, and why: records the law requires to be kept — payroll, accounting entries, invoices — and anything a court or regulator requires to be retained. We name which of these applied to your request rather than refusing in general terms.

Changes to this policy

We may amend this policy. The amended version is published on this page with its version number and effective date and applies from that date.

Where an amendment materially changes what we collect or who we share it with, we notify subscribing companies through the approved channel before it takes effect.

The law this follows

This policy is written to comply with Egyptian Personal Data Protection Law 151 of 2018 and its executive regulation.

The controller/processor split, our obligations as a processor, our sub-processors, breach notification and the treatment of special-category data are set out in full in our Data Processing Terms, which form part of the agreement with every subscribing company.

Language and the governing text

These terms were drafted in Arabic. The Arabic text is the authentic and governing version. The English version is provided as a convenience translation, and where the two differ in meaning the Arabic text alone applies.

How to reach us

Inno Source

Address: Nasr City, Cairo 11371, EG

Email for notices: privacy@innovationsrc.com

Telephone: +201117330111

A notice sent to the address or email published here is effective from the date it is sent.

All pages