Compliance

Electronic signature Built on Egyptian law
and data processed under clear controls

Wthaiq is a documentation and evidence authority for transactions and contracts. This page explains in practical language what “legal recognition” of the electronic signature means in Egypt. It sets out when your signature counts as admissible evidence, what your rights are as a data subject under Law No. 151 of 2020, and which documents we advise having authenticated traditionally.

Electronic Signature Law No. 15 of 2004 Personal Data Protection Law No. 151 of 2020 Consumer Protection Law SHA-256 fingerprint and audit trail

What “legal recognition” means in practice in Egypt

The phrase “electronic signatures are legally recognised” is repeated a great deal in marketing without explanation. The practical meaning is simpler and more precise. The Egyptian legislator did not require a signature to be handwritten on paper for it to take effect. Instead it conferred on the electronic signature and the electronic instrument evidentiary weight in proof whenever certain technical and procedural conditions are met, in Law No. 15 of 2004 and its executive regulations. So the right question is not “is the electronic signature recognised?” but “is this particular signature capable of being proven?”.

The template is not the legal standing

A picture of a signature or a scanned bit of handwriting inside a PDF does not make evidence. What makes evidence is being able to prove who signed, when, and that the document has not changed since.

Legal standing is conditional, not absolute

The law and its regulations tie legal effect to conditions: the signature must be linked to its owner, the owner must have sole control of the signing means, and any later change to the document or the signature must be detectable.

The burden falls on whoever relies on the document

In a dispute, the party relying on the contract is the one who has to produce what supports its validity. That is why the platform's real value is not the “look” of the signature but The proof file that you keep with it.

Official form wherever the law requires it

Some transactions are required by law to take an official form or to be authenticated before a competent authority. In these cases an electronic signature is no substitute for the official procedure. See The traditional notary office.

Data protection is part of compliance

A valid contract paired with unlawful data processing is still a source of risk. That is why we treat Law No. 151 of 2020 as a layer running parallel to the signature, not as an appendix.

Clarity towards the consumer

When the other party is a consumer, consumer protection law imposes extra care: comprehensible terms, clear disclosure, and giving the consumer a copy of the contract they signed.

An important, plainly stated clarification

Wthaiq is a documentation and evidence authority for transactions and contracts. We prove who signed and when, we reveal any change made after signing, and we keep the complete evidence file. The strongest thing we offer is signing with identity verification: an official document and a live face match, both tied to the signature itself. We are not an issuer of electronic certification certificates, and we claim no accreditation we have not obtained. And for anyone who signs with us using their own token, we embed their signature in the file and preserve it — the certificate comes from their licensed authority, not from us.

When is an electronic signature legally valid? The conditions in practice

The legal effect of an electronic signature rests on three ideas in Law No. 15 of 2004 and its executive regulations. The first is the attribution of the signature to its owner, the second is that owner's sole control over the means of signing, and the third is the detection of any subsequent alteration. Here is how each is implemented on the platform, step by step.

The signature is tied to the signer alone

Every signature must be attributed to a specific person, not to a “device” or a “shared account”. So we build every signature on a traceable identity: a verified email or phone number, and a one-time verification code at the moment of signing. And you can raise the level to identity verification with an official document and a live face match.

On the platform: Every signer has their own invitation that cannot be forwarded, and their identity check is recorded independently of the other parties.

The signer's sole control over the signature method

A signature means nothing if another party — including the sender of the contract — can sign on the signer's behalf. So each party's authority is separated from the others, and the verification code goes to the signer's own channel.

On the platform: The document's creator can send, track and send reminders, but cannot sign on another party's behalf.

Any change after signing can be detected

This is the condition that separates a “signed” document from a “provable” one. We compute a digital fingerprint for the final document using SHA-256. A change to a single character produces a completely different fingerprint, so it is detected immediately on comparison.

On the platform: The fingerprint is included in the completion certificate, and any party can match it through The document verification page with no account required.

A full time record that does not rely on the parties' memory

Proof needs a sequence: who it was sent to, when the document was opened, when it was signed, and from which IP address and which browser. This log is what answers the questions of an investigator, an arbitrator or a lawyer a year after the event.

On the platform: An audit trail that cannot be edited from the interface, delivered attached to the document within the E-signature certificate.

A self-contained file that does not depend on the platform continuing to exist

If you need the document years from now, it has to be readable and verifiable with ordinary tools. That is why we produce the final document as a PDF with a human-readable completion certificate. And anyone who signs with their token gets a signature embedded inside the file in PAdES format.

On the platform: Download a full copy and keep it in your archive — you will not need to sign in to read it later.

What strengthens your position in a dispute

  • Independent verification for each signer through their own channel, then identity verification with a document and a face when needed.
  • The SHA-256 fingerprint of the final document is stated in the certificate.
  • A continuous time-stamped audit trail from sending to completion.
  • One final copy received by all parties at the same moment.
  • Clear, unambiguous clauses, and attachments named explicitly inside the contract.

What weakens your position

  • Sending the contract to a shared department inbox rather than a named person.
  • Signing “on behalf of” another person from their device or under their account.
  • Amending a paper copy after electronic signing and circulating it.
  • Relying on a screenshot or a WhatsApp message instead of the proof file.
  • Using an electronic signature for a transaction the law requires to take an official form.

Your rights as a data subject under Law No. 151 of 2020

The Egyptian Personal Data Protection Law does not merely oblige organisations to protect data; it grants the data subject rights they can exercise themselves. These are those rights as we apply them on the platform, and the practical route for exercising them.

The right to be informed

To know that your data is being collected, what it is, why, and to whom it may be disclosed.

Applied in the privacy policy and on the data collection page

The right of access

To request a copy of the data we hold about you in a readable form.

A request from the data centre in your account

The right to rectification

To rectify any inaccurate or out-of-date data relating to you.

Change it instantly from account settings

The right to erasure

To request the erasure of your data, to the extent that this does not conflict with a legal obligation or with preserving evidence of a contract in force.

A documented deletion request with confirmation that it was carried out

Withdrawal of consent

To withdraw your consent to processing that is based on consent, without retroactive effect on anything lawfully carried out before the withdrawal.

Unsubscribe and preferences

Objection and restriction of processing

To object to processing you consider unjustified, or to request that it be restricted to a defined scope.

A request that is examined and answered in writing

How to exercise your right in practice — four steps

1) Send the request from your registered channel

From the data centre in your account, or from the email address registered in your name. Specifying the type of request (access / rectification / erasure / objection) speeds up execution.

2) We verify your identity

A mandatory step, not a formality: carrying out a deletion or access request for someone who is not the data subject is itself a breach. That is why we require verification proportionate to the sensitivity of the request.

3) We act on it, or explain why we decline

Full execution may be prevented by a contract in force whose evidence must be preserved, or by a legal retention obligation. In that case we set out the reason for you, then apply the available alternative, such as restricting processing instead of full erasure.

4) We notify you of the outcome in writing

You receive a confirmation setting out what was carried out and what was not and why, and the request and its outcome are recorded in our internal logs under the accountability principle.

The data we collect and why — no vagueness

The data minimisation principle means we ask only for what the service genuinely needs. And this transparency is not a favour: disclosing the purpose and the basis of processing is the core of what Law No. 151 of 2020 requires. The table below sets out what we collect, why, and on what basis.

The types of data Wthaiq collects, the purpose of each type, and the basis on which it is processed
Type of dataWhy we need itLawful basis for processing
Account details

Name, email, phone number

Account creation, sign-in, and the attribution of every signature to a specific person. Performing the contract concluded with you (the service itself)
Details of the parties to the document

Signers' names and contact details

Sending the invitations, verifying identity and notifying the parties of the document's status. Performance of the contract and a legitimate interest in completing the transaction
Document content

The contracts and files you upload

Completing the signing cycle and saving a copy you can come back to. Performance of the contract — and you are responsible for the content of what you upload
Audit trail data

Timestamps, IP, browser and device type

Proof of who signed and when, and detection of any tampering or unauthorised access. A legitimate interest in proof and in the security of the service
Invoice details

Subscription and payment data

Collecting payment for the service and issuing the necessary financial documents. Performance of the contract and a legal/accounting obligation
Support messages

What you write to us in support requests

Resolving the issue you contacted us about and improving the service. A legitimate interest in providing support

What we do not do with your data

We do not sell your data, we do not use the content of your contracts for marketing, and we do not repurpose data collected for one purpose for a different one without a clear basis. When a piece of data is no longer needed, it is deleted or anonymised rather than kept “just in case”.

Who inside our organisation sees your data

Access is limited to the minimum number of staff and to a defined purpose (technical support or investigation of a security incident), and is recorded in the audit trail. There is no “general” access to document content, and contract content is not available for internal browsing without a documented reason.

Retention periods and deletion — clear logic, not whim

Keeping a piece of data after the need for it has passed is risk with no return, and deleting it too early can cost you evidence you need. So we tie retention periods to the purpose and to what the law requires, not to an arbitrary number.

A fully signed document

It is kept with its evidence file for as long as your account exists, because it is proof of a contract you may need later. You are free to download and archive it yourself at any time — and we always recommend doing so.

A draft or an unfinished document

It has no evidential value, so we do not keep it any longer than necessary. Drafts and temporary data are cleared once they are no longer needed.

The audit trail

tied to the lifetime of the document itself — because deleting it on its own strips the document of its value as evidence.

Financial data and invoices

They are kept for as long as accounting and legal obligations require, even if you ask for the rest of your data to be deleted.

When the account is closed

We delete account data and preferences. Excepted is anything that must be retained by law, and anything that constitutes evidence of a contract for another party who shared the document with you. Your right to erasure does not cancel their right to their evidence.

De-identification instead of deletion

When we need statistical operating data, we strip out anything that identifies a person, so it becomes attributable to nobody rather than remaining personal data.

We tell you what usually goes unsaid

Asking to “delete everything” is not always in your interest. If you delete a signed document, you may lose the evidence you need in a future dispute, and the platform will not be able to restore it for you. Download your full copy first, then request deletion.

Data transfer and hosting

Transferring personal data outside the country is not a technical detail; Law No. 151 of 2020 restricts it with controls, which is why we treat it as a compliance decision rather than a setting in a control panel. The principles we adhere to are published here so that you can compare them against your legal team's standards.

Encryption on every connection

Every connection to the platform runs over a channel encrypted with TLS 1.3. Anyone intercepting network traffic between you and us sees encrypted data, not the content of a contract.

Providers with a defined purpose

When we use a service provider (hosting, messaging, payments), their access is limited to what is necessary for their purpose, and is subject to a contractual confidentiality and protection obligation.

Cross-border transfer under controls

No personal data is transferred outside the country except within the limits the law permits, with an equivalent level of protection, and for a stated purpose connected to running the service.

Least-privilege permissions

Every internal access is tied to a defined role and logged, and permissions are granted on a need-to-know basis and withdrawn once the reason for them ends.

Controlled backups

We treat a backup as sensitive data, exactly like the original. And it is not used to bring back data whose deletion has already been decided.

Incident response

Where an incident affecting personal data occurs, we handle it along a defined path: containment, impact assessment, and notification of the authorities and the data subjects in the cases and within the periods prescribed by law.

Security and infrastructure details are on the trust and security page

Documents for which traditional authentication is recommended

This section is here deliberately. Any signing platform that tells you “everything can be signed electronically” is selling you a risk. The practical rule is simple: where the law requires a formal form for a transaction — notarisation, registration or publication before a competent authority — an electronic signature does not replace that procedure. This stays true even if the file was signed with the best technical tools there are.

What the law requires to take an official form

  • Transactions that the law requires to be notarised or registered before a competent authority.
  • Anything requiring registration in an official register for the right to transfer or to take effect against third parties.
  • Instruments that a government body requires to be submitted in an official authenticated form.
  • What a financing body or a regulator stipulates in its written terms.

Practical situations that call for a pause and a question

  • The other party objects to electronic signing in advance and insists on paper.
  • The document will be submitted to a body that insists on an authenticated copy and accepts nothing else.
  • The signer has no personal channel of their own (email or phone) that can be verified.
  • Serious doubt about the signer's capacity, or about their authority to sign on behalf of a legal entity.
  • A cross-border transaction governed by foreign law with different formal requirements.
A comparison between electronic signing on the platform and traditional authentication
The standardElectronic signing on WthaiqTraditional / official notarisation
Best suited toEveryday commercial and administrative contracts: supply, services, confidentiality, employment, operating leases, accepted quotations.Transactions for which the law requires a formal instrument or registration.
Time to completionMinutes, remotely, with no travel and no appointments.Tied to the authority's dates, its procedures and the parties' attendance in person.
What it is proved withAn audit trail, a SHA-256 fingerprint, a completion certificate, and identity verification when requested.An official capacity derived from the notarising authority and its procedures.
Verification laterFingerprint matching via The verification page In seconds.Review of the register or the instrument by the competent authority.
When the law requires a formal instrumentIt is not a substitute for the official procedure.is the right way.
Not legal advice

This page is a practical explanation of the platform's approach, not a legal opinion on any particular matter. Determining the form required for a specific transaction depends on its details, its parties and the body it will be submitted to — so consult your legal adviser when in doubt, and treat that pause as money saved rather than time lost.

Start from solid legal ground

Carefully written contract templates, and a signing cycle that produces a complete evidence file for every document.

This page is a general explanation of the platform’s policies and its approach to compliance, and does not constitute legal advice.