Legal centre

All the agreements and policies governing your use of the Wthaiq platform, in one organised place.

All documents are governed by the laws of the Arab Republic of Egypt · Effective date: 1 June 2026

Compliance with the European Regulation (GDPR)

Print / PDF
Note: This English text is provided for convenience only. The Arabic version is the authoritative and binding text; in the event of any discrepancy or conflict of interpretation, the Arabic text prevails.
Issue date: 1 June 2026Date of entry into force and effect: 1 June 2026Last updated: 1 June 2026

Last updated: 1 June 2026

Effective date: 1 June 2026

Chapter One: Introduction

1. Purpose

This document explains how Wthaiq ("the Platform", "we") complies, to the extent that the European Union General Data Protection Regulation (GDPR) applies, with the requirements relating to the processing of personal data.

This document does not constitute an undertaking that the Regulation applies to all Users or to all processing activities; rather, it sets out the framework that Wthaiq follows where the Regulation applies as a matter of law.

2. Scope of application

This document applies to the processing of personal data that is subject to the GDPR, in accordance with the territorial scope criteria set out in the Regulation.

The use of Wthaiq's services does not, in itself, mean that the European Regulation applies to all Users or to all processing operations.

3. Relationship with other documents

This document is to be read together with:

  • The Privacy Policy.
  • The Data Processing Agreement (DPA).
  • The Data Subject Requests Policy.
  • The Data Retention Policy.
  • The Data Deletion Policy.
  • The Terms and Conditions of Use.
  • In the event of any conflict, the mandatory provisions set out in the GDPR shall apply to the extent of their applicability.

4. Definitions

The following terms shall have the meanings given to them in the GDPR, unless the context requires otherwise, including:

  • Personal data.
  • Data subject.
  • Processing.
  • Data controller.
  • Data processor.
  • Personal data breach.
  • Supervisory authority.
  • International data transfer.

Chapter Two: Principles of Data Processing

5. Processing principles

Where the GDPR applies, Wthaiq undertakes to observe the fundamental principles of data processing, including:

  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Data accuracy.
  • Storage limitation.
  • Integrity and confidentiality.
  • Accountability.

6. Lawful basis for processing

Depending on the nature of each processing operation, Wthaiq relies on one of the lawful bases recognised by the GDPR, such as:

  • Performance of a contract.
  • Compliance with a legal obligation.
  • Legitimate interests.
  • Consent of the data subject.
  • Protection of vital interests.
  • Performance of a task carried out in the public interest, where applicable.
  • Wthaiq does not rely on a particular lawful basis unless it is appropriate to the nature of the processing.

7. Data minimisation

Wthaiq seeks to collect and process only the personal data necessary to achieve the legitimate purposes for which it was collected.

8. Data accuracy

Wthaiq adopts reasonable procedures to maintain the accuracy of personal data, and the data subject may request the rectification of inaccurate data in accordance with the applicable laws.


Chapter Three: Data Subject Rights

9. Respect for rights

If the GDPR applies to a particular processing operation, Wthaiq undertakes to respect the rights of data subjects to the extent required by the Regulation and the relevant laws.

10. Rights that may be available

These rights may include, as the case may be:

  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restriction of processing.
  • The right to data portability.
  • The right to object.
  • The right to withdraw consent.
  • The right not to be subject to a decision based solely on automated processing, where applicable.

11. Exercise of rights

The data subject may exercise their rights through Wthaiq's official channels of communication.

All requests are subject to identity verification procedures, to internal policies and procedures, and to the exemptions permitted by law.

12. Responding to requests

Wthaiq handles data subject requests within the periods imposed by the GDPR or any applicable law, and the period may be extended in the cases permitted by the Regulation, with notification to the applicant where appropriate.

Chapter Four: Data Security and Breach Notification

13. Security measures

Wthaiq adopts appropriate technical and organisational measures to protect personal data, commensurate with the nature of the data, the purposes of the processing and the level of risk, and in a manner consistent with the requirements of Article 32 of the GDPR, where applicable.

These measures may include, as the case may be:

  • Encryption.
  • Access permission controls.
  • Multi-factor authentication, where appropriate.
  • Backups.
  • Logging of security events.
  • Periodic security reviews.
  • Business continuity and disaster recovery plans.

14. Personal data breaches

If Wthaiq becomes aware of a personal data breach subject to the requirements of the GDPR, it shall handle it in accordance with its internal procedures and the applicable law.

Where Wthaiq acts as a data processor, it shall make reasonable efforts to notify the controller without undue delay, to the extent permitted by law.

15. Cooperation during incidents

Wthaiq may cooperate with clients and the competent authorities, as the case may be, in order to assist in:

  • Assessing the effects of the incident.
  • Mitigating its effects.
  • Implementing corrective actions.
  • Meeting statutory notification requirements.

Chapter Five: International Data Transfers

16. Data transfers

Personal data may be processed or stored outside the country in which the data subject resides where this is necessary for the provision of the services.

Where the GDPR applies, any international transfer shall be carried out in accordance with Chapter V of the Regulation and using the appropriate legal mechanisms.

17. Transfer safeguards

Wthaiq may rely, as the case may be, on:

  • Adequacy decisions.
  • Standard contractual clauses (SCCs).
  • Any other mechanism approved under the GDPR.

18. Service providers

Wthaiq may engage service providers or sub-processors located in various countries.

Wthaiq undertakes, where appropriate, to enter into suitable contractual arrangements with such providers in order to protect personal data in accordance with the law.


Chapter Six: Accountability and Compliance

19. Records

Wthaiq maintains, where appropriate, the records necessary to demonstrate compliance with its legal obligations relating to the processing of personal data.

20. Impact assessments

Where the law requires a Data Protection Impact Assessment (DPIA) to be carried out, Wthaiq shall cooperate with the client, within the limits of its role as a data processor and to the extent permitted by the nature of the services.

21. Privacy by design

In developing its services, Wthaiq seeks to observe the principles of privacy by design and privacy by default, to the extent appropriate to the nature of the services.

22. Training and governance

Wthaiq works to strengthen compliance through internal policies, governance procedures and appropriate awareness measures for the personnel authorised to process personal data, commensurate with the size of its business and the nature of its services.

Chapter Seven: Shared Responsibilities

23. Client responsibilities

Where the client is the data controller, the client is responsible for:

  • Determining the lawful basis for the processing.
  • Providing data subjects with the required notices.
  • Obtaining consents where appropriate.
  • Issuing lawful instructions to Wthaiq.
  • Complying with the obligations imposed upon it under the GDPR.

24. Wthaiq's responsibilities

Where Wthaiq acts in the capacity of a data processor, it undertakes to perform the obligations imposed upon it under the GDPR, within the limits of the role it performs and the nature of the services provided.

25. Limits of liability

Wthaiq shall not be liable for any infringement of the GDPR arising from:

  • Unlawful instructions issued by the client.
  • Processing carried out by the client outside Wthaiq's services.
  • The client's breach of its legal obligations.
  • Data provided by the client without a lawful basis for its processing.
  • This is without prejudice to any liability that may not be excluded or limited under the law.

Chapter Eight: Transparency and Communication

26. Communication

Data subjects or clients may contact Wthaiq through the official channels of communication published on the website in relation to data protection enquiries or requests.

27. Identity verification

Wthaiq may take reasonable steps to verify the identity of the applicant before disclosing any data or giving effect to any of the rights established under the GDPR.

28. Fees

Wthaiq handles requests free of charge wherever this is required under the GDPR.

However, if a request is manifestly unfounded, excessive or repetitive, Wthaiq may, to the extent permitted by the Regulation, charge a reasonable fee or refuse the request.


Chapter Nine: General Provisions

29. Amendment of the document

Wthaiq may amend this compliance document where this is necessary to keep pace with legislative or regulatory amendments or to improve compliance procedures.

30. No creation of additional rights

This document is intended to explain how Wthaiq complies with the GDPR where it applies.

This document does not, in itself, create any rights or obligations beyond those imposed by law or by the agreements concluded between the parties.

31. Severability

If any provision of this document becomes ineffective or unenforceable under the law, this shall not affect the validity or effectiveness of the remaining provisions.

32. Integration with the legal documents

This document shall be construed together with the Privacy Policy, the Data Processing Agreement (DPA), the Data Subject Requests Policy, the Data Retention Policy, the Data Deletion Policy and the Terms and Conditions of Use, as an integrated framework for data governance.

33. Precedence of the law

In the event of a conflict between any provision of this document and a mandatory provision contained in the GDPR or any applicable European legislation, that mandatory provision shall prevail to the extent of the conflict.

34. No waiver

Wthaiq's failure to exercise any right relating to compliance with the GDPR shall not be deemed a waiver of that right, unless the waiver is made in writing and issued by an authorised representative.

35. Entry into force

This document enters into force as of the date stated at its beginning and remains in effect until it is amended or replaced.

36. Final acknowledgement

The User or client acknowledges that they have reviewed this General Data Protection Regulation (GDPR) compliance document, and understands that it sets out the framework followed by Wthaiq where the Regulation applies, and that the application of certain provisions depends on the nature of the service, Wthaiq's role in the processing and the applicable law.


Governing Law and Jurisdiction

This document shall be governed by and construed in accordance with the laws of the Arab Republic of Egypt, and the competent Egyptian courts shall have jurisdiction to determine any dispute arising out of or in connection with it, and any arbitration — if agreed upon by the two parties — shall be conducted within the Arab Republic of Egypt and in accordance with its laws, without prejudice to any mandatory rights afforded to the User under the applicable laws of their country of residence.