1. Introduction
Restaurants for E-Marketing ("Company", "we", "us"), operating the HotelsVendors platform ("Platform"), is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Services.
This policy is compliant with:
- Egyptian Data Protection Law (Law No. 151 of 2020) — Primary applicable law for all data processing activities.
- EU General Data Protection Regulation (GDPR) — Where applicable to EU-based users or data subjects.
- Egyptian Anti-Money Laundering Law (Law No. 80 of 2002) — KYC data retention requirements.
2. Data Controller
The data controller for your personal data is:
- Company: Restaurants for E-Marketing
- Tax ID: 704226146
- Commercial Registry: 105300900196948
- Email: privacy@hotelsvendors.com
- Address: Cairo, Arab Republic of Egypt
3. Data We Collect
3.1 Account and Identity Data
- Full name, email address, phone number
- Company name, job title, role
- Tax Identification Number (TIN)
- Commercial Registration Number
- Business license documents
3.2 Financial Data
- Bank account numbers (encrypted at rest using AES-256-GCM)
- Bank names
- Transaction history and order data
- Invoice data (ETA-compliant)
- Credit scores and risk assessments
3.3 Usage Data
- IP address, browser type, device information
- Pages visited, features used, time spent on Platform
- Search queries and product interactions
- AI assistant conversation logs (anonymized after 90 days)
3.4 Document Data
- Uploaded business documents (licenses, certificates)
- ETA-submitted invoices and supporting documents
- Dispute evidence and resolution records
4. How We Use Your Data
We process your personal data for the following purposes:
- Service Provision: To operate the Platform, process orders, and facilitate transactions.
- KYC/AML Compliance: To verify your identity as required by Egyptian Anti-Money Laundering Law (Law No. 80 of 2002).
- ETA E-Invoicing: To submit invoices to the Egyptian Tax Authority as required by law.
- Factoring Referral: To refer eligible transactions to licensed factoring partners.
- Platform Improvement: To analyze usage patterns and improve our Services.
- Communication: To send transaction updates, security alerts, and (with consent) marketing communications.
- Legal Obligation: To comply with applicable laws, regulations, and legal processes.
5. Legal Basis for Processing
We process your data based on:
- Contract Performance: Processing necessary to perform our contract with you (Terms of Service).
- Legal Obligation: Processing required by Egyptian law (ETA e-invoicing, AML/KYC, tax record retention).
- Legitimate Interest: Processing necessary for our legitimate business interests (platform security, fraud prevention).
- Consent: Where you have given explicit consent (marketing communications, analytics cookies).
6. Data Sharing
We share your data with the following categories of recipients:
- Factoring Partners (Oliv, EFG Hermes): When you initiate a factoring request, relevant transaction and identity data is shared with the selected licensed factoring partner.
- Payment Processors (Paymob, Fawry): For payment processing. Card data is tokenized and never stored on our servers.
- Egyptian Tax Authority (ETA): Invoice data is submitted as required by Egyptian e-invoicing regulations.
- Law Enforcement: When required by valid legal process or to protect the Platform from fraud.
We do NOT sell your personal data to third parties.
7. Data Security
We implement the following security measures:
- Encryption at Rest: Sensitive fields (tax IDs, bank accounts, phone numbers) are encrypted using AES-256-GCM.
- Encryption in Transit: All data is transmitted over TLS 1.3.
- Access Control: Role-based access control (RBAC) with tenant isolation.
- Audit Logging: Immutable audit trail with SHA-256 hash chain for all data mutations.
- Payment Processing: Card data is handled exclusively by PCI-DSS compliant partners (Paymob, Fawry). We do not store card numbers.
8. Data Retention
We retain your data for the following periods:
- Invoices and Tax Records: 10 years from date of issuance (Egyptian Tax Law requirement).
- Accounting Records: 10 years from date of transaction (Egyptian Commercial Law).
- KYC Documents: 5 years from account closure (Egyptian AML Law).
- Transaction Data: 7 years from date of transaction.
- Account Data: Duration of account relationship plus 7 years.
- Marketing Consent: Until withdrawal of consent.
- AI Conversation Logs: Anonymized after 90 days; deleted after 1 year.
9. Your Rights
Under Egyptian Data Protection Law and GDPR (where applicable), you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data (subject to legal retention requirements).
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent for processing at any time.
To exercise any of these rights, contact us at privacy@hotelsvendors.com. We will respond within 30 days as required by Egyptian Data Protection Law.
10. Cross-Border Data Transfers
Your data is primarily stored and processed in Egypt. If data is transferred outside Egypt, we ensure appropriate safeguards are in place in accordance with Egyptian Data Protection Law (Law No. 151 of 2020), including standard contractual clauses or adequacy decisions.
11. Cookies and Tracking
The Platform uses essential cookies for authentication and session management. Analytics and marketing cookies are used only with your explicit consent. You may manage cookie preferences through the Platform's cookie consent banner.
12. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or Platform notification at least 30 days before taking effect. The "Last updated" date at the top indicates when this policy was last revised.
14. Contact and Complaints
For privacy-related inquiries or complaints, contact us at:
- Email: privacy@hotelsvendors.com
- Company: Restaurants for E-Marketing
- Address: Cairo, Arab Republic of Egypt
If you are not satisfied with our response, you may file a complaint with the Egyptian Data Protection Center (under the Personal Data Protection Agency) or the competent courts of Cairo.