Privacy Policy
Last updated: August 21, 2026
1. Who We Are
This website is operated by Muhammad Ibrahim Mujahid ("we", "us", "our"), acting as the Data Controller as defined under Egypt's Personal Data Protection Law No. 151 of 2020 ("PDPL"). For any privacy-related inquiries or to exercise your statutory rights, please contact us at: mohamed.mojahead@gmail.com.
2. Our Commitments to You
Your personal data is used strictly and exclusively for the specific purpose for which it was provided. Specifically:
- We do not sell, lease, or commercialize your personal data with any third party.
- We do not add you to marketing mailing lists or send unsolicited newsletters; your email address is used solely to respond to your specific inquiry.
- We do not build advertising profiles about you or target you with proprietary advertisements.
- We do not correlate analytics data with your personal identity obtained from contact or testimonial forms.
- We do not subject your data to automated decision-making processes or profiling that produces legal effects.
- We do not retain your personal data beyond the defined retention periods set forth below.
- Your data is processed exclusively for: responding to your contact inquiries, publishing your submitted testimonials, recording and enforcing your cookie consent preferences, and safeguarding the website against unauthorized use or abuse.
3. Definitions
- Personal Data: Any data relating to an identified natural person, or an identifiable natural person who can be identified, directly or indirectly, including name, email address, telephone number, and online identifiers.
- Sensitive Personal Data: Data revealing psychological, physical, biometric, or genetic information, religious beliefs, or financial data. This website is not intended to collect sensitive data; please refrain from submitting sensitive data via our forms.
- Processing: Any operation or set of operations performed on personal data by automated or non-automated means, such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
- Consent: Any freely given, specific, informed, and unambiguous indication of your agreement to the processing of your personal data.
4. Itemized Data Inventory
This section provides an exhaustive, field-by-field inventory of all data categories stored by this website:
4.1 Contact Form (Stored in our Database)
When submitting the "Contact Me" form, we store:
- Name: Mandatory; maximum 100 characters.
- Email Address: Mandatory; maximum 254 characters (standard validated format).
- Phone Number: Optional; maximum 25 characters.
- Message: Mandatory; between 10 and 5,000 characters.
- Submission Timestamp: Precise date and time of dispatch.
- CAPTCHA Verification Result: A boolean status (Yes/No) confirming successful verification against automated bots (the verification token itself is not retained).
- Email Delivery Status: A boolean indicator (Yes/No) confirming whether the notification email was successfully transmitted to the site owner.
Purpose: Reviewing and responding to your inquiry. Legal Basis: Necessary for taking pre-contractual measures upon your request (Article 10, PDPL). The message content is accessible solely to the site owner.
4.2 Testimonial Submissions (Stored in our Database)
When submitting a testimonial for moderation, we store:
- Quote Text: The statement intended for publication.
- Display Name: As provided by the submitter.
- Job Title: As provided by the submitter.
- Photograph: User-uploaded profile image, displayed alongside the quote upon moderation approval.
- LinkedIn Handle / URL: Optional; displayed only if provided.
- Salted Hash of IP Address: A one-way cryptographic hash used exclusively to prevent duplicate or malicious submissions. Raw IP addresses are never stored alongside testimonials.
- Proof of Consent: Exact timestamp of consent checkbox selection, privacy policy version accepted, and browser user-agent string at the time of submission.
- Moderation Status: Pending, Approved, or Rejected.
Purpose: Displaying moderated testimonials on the website. Legal Basis: Your explicit, affirmative consent obtained prior to submission. Rejected submissions are permanently purged within 90 days.
4.3 Cookie Consent Records (Stored in our Database)
Upon interacting with our cookie consent mechanism, we store:
- Pseudonymous Identifier (UUID): Stored via an
HTTP-onlycookie; contains no personally identifiable information and cannot independently identify you. - Category Preferences: Essential (always active), Analytics (Yes/No), Marketing (Yes/No).
- Consent and Policy Versions: Exact versions of the banner and legal notices presented to you.
- Consent Timestamp: Precise date and time consent was granted.
- Withdrawal Timestamp: Recorded upon subsequent revocation of consent, where applicable.
Purpose: Enforcing your preferences across sessions and evidencing legal compliance. Legal Basis: Compliance with statutory obligations under the PDPL.
4.4 Analytics Events (Opt-In Only)
Subject strictly to your prior affirmative opt-in:
- Page views (URL, page title), interactions with designated UI components, element text labels, page sections, and standard device/browser metadata.
- Each event is associated with a random session identifier and timestamp.
- Form input values are strictly excluded from interaction event trackers.
Purpose: Aggregated website performance measurement and optimization. Legal Basis: Your revocable consent.
4.5 Transient Security Metadata
- IP Addresses: Processed strictly in volatile memory for rate-limiting, denial-of-service mitigation, and CAPTCHA challenge evaluations; IP addresses are never committed to persistent database storage in readable form.
- Cloudflare security cookies may be set for infrastructure defense (see our Cookie Policy).
5. Excluded Data Categories
We deliberately do not process or collect:
- Precise geolocation data.
- Biometric, genetic, medical, religious, or political opinion data.
- Payment or financial details (this website does not maintain checkout functionalities or process transactions).
- Cross-site browsing history.
- Personal data of minors (this website is not intended for individuals under 18 years of age).
6. Cookies and Tracking Technologies
Non-essential analytics and marketing cookies remain strictly disabled and technically blocked from executing until you record an affirmative choice via the consent banner. Detailed schedules, including cookie identifiers, providers, and expiration lifespans, are set forth in our Cookie Policy.
7. Third-Party Data Processors
We never sell your data. We share necessary data strictly with certified data processors under binding contractual safeguards:
- Supabase: Managed PostgreSQL database hosting for form submissions and content storage.
- GitHub Pages / GitHub: Static frontend web hosting infrastructure.
- Cloudflare: Security mitigation, bot protection, and Turnstile CAPTCHA services.
- Resend: Transactional email delivery service for contact form notifications.
- Google (Tag Manager / Analytics), Microsoft Clarity, Meta Pixel: Analytical measurement scripts deployed exclusively upon receipt of prior opt-in consent for the applicable category.
All processors operate solely on our documented instructions and maintain equivalent organizational and technical security measures.
8. Cross-Border Data Transfers
Certain service providers process data on servers located outside the Arab Republic of Egypt. All cross-border transfers are conducted in compliance with Article 16 of the PDPL and its Executive Regulations, based on adequacy decisions, standard contractual clauses imposing PDPL-equivalent protections, or your explicit consent where required.
9. Retention Periods
- Contact Inquiries: Retained for the duration of communication, archived, and permanently erased after 24 months.
- Published Testimonials: Retained until you request removal or withdrawal of consent.
- Rejected Testimonials: Permanently deleted within 90 days from rejection.
- Consent Audit Trails: Retained for 3 years to demonstrate regulatory compliance, then purged.
- Analytics Data: Retained in accordance with respective platform configurations (typically 13–14 months).
10. Your Rights Under the PDPL
You may exercise the following statutory rights free of charge by contacting us via email:
- Right of Access: Obtain confirmation of processing and an accessible copy of your personal data.
- Right to Rectification: Request correction or completion of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of personal data when retention is no longer legally justified.
- Right to Restriction: Request suspension of processing during the pendency of a verified dispute.
- Right to Object: Object to data processing based on legitimate interests.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Withdraw Consent: Revoke cookie or testimonial consent at any time via the "Privacy Settings" control panel, without affecting the lawfulness of processing prior to revocation.
- Post-Mortem Directives: Designate instructions regarding the management of your personal data post-mortem.
We respond to all verified requests within the statutory timeframes established by the Executive Regulations. You also reserve the right to submit a complaint to the Personal Data Protection Center (PDPC) affiliated with the Ministry of Communications and Information Technology.
11. Security Measures
In compliance with Article 12 of the PDPL, we implement robust technical and organizational security controls, including Transport Layer Security (TLS) in transit, HTTP-only cookie attributes, cryptographic hashing of IP logs, API rate limiting, CAPTCHA verification, least-privilege database access policies, and standard security headers.
12. Personal Data Breach Notification
In the event of a security breach likely to compromise personal data, we will formally notify the Personal Data Protection Center without undue delay and within 72 hours of becoming aware of the breach, pursuant to Article 13 of the PDPL, and will notify affected data subjects directly where there is a risk of substantial harm.
13. Protection of Minors
This website is not directed to individuals under 18 years of age, and we do not knowingly process minors' data. If you believe a minor has submitted personal data, please contact us immediately for expeditious deletion.
14. Amendments to this Policy
Material amendments will be indicated via the "Last Updated" timestamp and, where legally warranted, through re-solicited consent. The applicable policy version is recorded alongside your consent audit trail.
This Privacy Policy reflects actual operational controls and supplements—without superseding—the provisions of Law No. 151 of 2020 and its Executive Regulations.