Last updated · May 2, 2026
Privacy Policy
This policy describes how egimpex.com collects, uses, retains and protects your personal data, in strict compliance with the European Union's General Data Protection Regulation (GDPR).
1. Data controller
The data controller is egimpex.com, operated by Bryan Hadadzak, headquartered in Alexandria, Egypt. For any question relating to the processing of your data or to exercise your rights, contact our Data Protection Officer (DPO) at support@egimpex.com.
2. Data collected
We collect and process the following data categories: (a) account data (email, hashed password, preferred language, time zone), (b) company profile data (legal name, country, city, business sector, production capacities, logo), (c) KYB documents (commercial registry, ISO/HACCP/BIO certifications, identification of legal representative), (d) published content (product listings, photos, descriptions), (e) communication data (messages exchanged on the internal messaging, RFQs sent and received), (f) transactional data (orders, statuses, Stripe subscription references), (g) technical data (IP address, user-agent, access logs, product analytics data).
3. Legal bases for processing
In accordance with Article 6 of the GDPR, we process your data on the following legal bases: (1.b) performance of the service contract between you and egimpex for providing the Platform, B2B matchmaking and billing; (1.c) legal obligation for anti-money-laundering KYB verifications and accounting record retention; (1.f) legitimate interest for B2B outreach to professional company contacts (verified registry of 40,000 Egyptian producers), Platform security, fraud prevention and service improvement; (1.a) explicit consent for analytics cookies and marketing newsletter sending.
4. Processing purposes
Your data is processed for the following purposes: (a) creation and management of your account, (b) matching buyers and suppliers (profile display, search, messaging, RFQ), (c) KYB verification and fraud prevention, (d) billing and management of SaaS subscriptions, (e) transactional communication (order notifications, received messages), (f) marketing communication with explicit consent and the ability to unsubscribe at any time, (g) product improvement (anonymized, aggregated analytics), (h) compliance with our legal and tax obligations.
5. Subprocessors and recipients
To provide our services, we use technical subprocessors selected for their GDPR guarantees: Supabase (database, authentication, file storage — EU region hosting); Resend (transactional email sending — EU headquarters); Vercel (web application hosting — EU regions prioritized); Cloudflare (CDN, DNS, attack protection — global network with EU routing prioritized); PostHog (anonymized product analytics — EU instance); Sentry (application error monitoring — EU instance); Stripe (billing of SaaS Pro and Premium subscriptions — EU headquarters for European users). No subprocessor is authorized to use your data for its own purposes; each is bound by a subprocessing contract compliant with Article 28 of the GDPR.
6. Retention periods
Your account and profile data is retained for the entire duration of your contractual relationship with egimpex. After termination of your account, it is retained for 3 years to comply with our legal obligations (accounting, KYB justifications, commercial limitation period). KYB documents are retained for 5 years after the last transaction in accordance with anti-money-laundering obligations. Technical logs are retained for a maximum of 12 months. Published content (product listings) is deleted upon termination, unless you explicitly request archiving.
7. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have the following rights: right of access to your data, right of rectification, right to erasure ("right to be forgotten"), right to restriction of processing, right to data portability in a structured, machine-readable format, right to object to processing (in particular for marketing communications), and right to withdraw your consent at any time for processing based on consent.
8. How to exercise your rights
To exercise any of these rights, send your request by email to support@egimpex.com specifying the nature of your request and attaching proof of identity. We will reply within a maximum of 30 days, free of charge, except for manifestly unfounded or excessive requests. You can also export your data or delete your account directly from your settings.
9. Cookies
We use a limited number of cookies, classified into two categories: strictly necessary (authentication session, language preference) and analytics (anonymized audience measurement, subject to your consent). No third-party marketing cookies are set (no Facebook Pixel, no Google Ads, no retargeting). For details and to manage your consent, see our dedicated GDPR notice.
10. Security
We apply appropriate technical and organizational measures to protect your data: HTTPS/TLS encryption across the entire site, encryption-at-rest of Supabase databases, Postgres Row Level Security (RLS) to compartmentalize data access per user, bcrypt password hashing, administrative access logging, daily encrypted backups, regular security audits.
11. Transfers outside the European Union
By default, all our data is hosted in data centers located in the European Union (EU regions of Supabase and Vercel). Cloudflare operates a global network but our configurations prioritize European nodes for EU users. No structural transfer outside the EU takes place. If an exceptional situation required a transfer outside the EU, it would be governed by the European Commission Standard Contractual Clauses or a validated transfer mechanism.
12. Complaint to a supervisory authority
If you consider that the processing of your data does not comply with the GDPR, you have the right to lodge a complaint with the supervisory authority of your country of residence. For France, this is the Commission nationale de l'informatique et des libertés (CNIL — www.cnil.fr).