Privacy Policy

Operator

This Privacy Policy (the "Policy") explains how MODREG Regulatory Digital Solutions LLC, an Egyptian limited liability company registered in the commercial register under No. [●], headquartered at District 5, Sokhna Road, New Cairo, Egypt (the "Company", "MODREG", "we", "our", or "us"), collects, processes, stores, uses, discloses, and protects personal data in connection with the access to and use of:

  • the MODREG regulatory-management platform and all related modules, dashboards, workflows, alerts, interfaces, and digital services available through the secure MODREG web application (the "Platform"); and
  • the public website located at modreg.app, including all subdomains, directories, microsites, landing pages, associated pages, and any other website, domain, URL, digital platform, or online presence that the Company owns, operates, controls, or designates now or in the future for MODREG-related services (the "Website").

The Platform and Website are collectively referred to as the "Services".

This Policy applies to individuals whose personal data may be processed through the Services, including:

  • representatives of a subscribing organization (the "Client");
  • employees or personnel authorised by a Client to access the Platform (the "Authorized Users");
  • visitors to the Website;
  • suppliers or individuals submitting information for publication through Supplier Listings or the Supplier Hub (as applicable); and
  • any other person whose personal data is provided to the Company in connection with the operation of the Services.

This Policy forms an integral part of the MODREG Platform Terms & Conditions and should be read together with any policies incorporated by reference therein, including the Security Policy, Cookies Policy (if published), and any applicable data processing terms or Order Form provisions.

Definitions

Unless otherwise defined in this Policy, capitalised terms have the meanings given to them in the MODREG Platform Terms & Conditions:

Term Definition
"Authorized User(s)"means any employees, officers, representatives, personnel, consultants, or other individuals authorised by a Client to access and use the Platform under that Client's Subscription.
"Client"means the company, organization, or legal entity that accesses or purchases the Platform under a Subscription for regulatory tracking, workflow management, assignments, or related business purposes.
"Client Data"means all data, documents, regulatory files, product information, submissions, attachments, materials, and other content uploaded, entered, stored, processed, or transmitted by or on behalf of a Client through the Platform.
"Cookies"means small text files or similar technologies placed on a user's device when visiting the Website or using the Services for purposes such as functionality, security, analytics, and user experience enhancement.
"Order Form"means any written or electronic document issued, approved, or accepted by the Company that sets out the Client's subscription details, including the selected plan, pricing, billing frequency, number of Authorized Users, product limits, optional modules, and any agreed commercial terms.
"Personal Data"means any information relating to an identified or identifiable natural person, including, without limitation, name, contact details, job title, login credentials, identification numbers, online identifiers, location data, usage data, or any other information that may directly or indirectly identify such person.
"Processing" or "Process"means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transfer, dissemination, alignment, restriction, deletion, destruction, anonymisation, or any other form of handling.
"Services"means all functionality provided through the Platform under the Client's Subscription.
"Subscription"means the paid plan selected by the Client (Monthly, Annual, Enterprise, or any successor plan).
"Supplier"means any local or international supplier, manufacturer, distributor, or business entity that submits information, product details, or related materials to the Company for visibility, publication, or listing through the Website or Supplier Hub.
"Supplier Content"means any information, product data, descriptions, specifications, certificates, regulatory approvals, images, documents, contact information, marketing materials, or other content submitted by or on behalf of a Supplier for publication, display, or processing through the Services.
"Supplier Hub"means the supplier-related section, functionality, listing environment, or digital space made available by the Company through the Website or Services for showcasing Supplier Content and increasing market visibility.
"Supplier Listing"means the publicly accessible publication, display, or presentation of Supplier Content on the Website, Supplier Hub, or any other digital channel operated, controlled, or designated by the Company.
"User"means any person who accesses, visits, browses, interacts with, or uses the Website or the Services, including Clients, Authorized Users, Suppliers, and website visitors.
"Website"means the public-facing website located at modreg.app, including all subdomains, directories, microsites, landing pages, associated web pages, as well as any other website, domain, URL, digital platform, or online presence that the Company owns, operates, controls, or designates now or in the future for hosting information, Supplier Listings, marketing materials, or access to MODREG-related services.

Scope and Roles

The Platform and Services are provided on a business-to-business (B2B) basis. The Client is responsible for controlling which Authorized Users are granted access and what Client Data is uploaded or processed.

For Personal Data contained within Client Data uploaded to the Platform, the Client typically determines the purposes and means of processing and is therefore responsible for ensuring it has the lawful basis and authority to provide such data to the Company.

The Company processes Personal Data as required to:

  • operate, maintain, and secure the Platform and Website;
  • provide the Services requested under a Subscription and any applicable Order Form;
  • manage accounts, billing, renewals, and support; and
  • comply with legal obligations and enforce the Terms.

Personal Data We Collect

Account and Subscription Data

Where a Client subscribes to the Platform, we may collect and process:

  • organization name, address, industry, and contact details;
  • name, email address, phone number, job title, and role of Client representatives and Authorized Users;
  • subscription plan, billing frequency, payment status, invoice details, and Order Form information.

Platform Usage Data

We may collect technical and usage information relating to access and use of the Platform, including:

  • login events, timestamps, user roles, and audit logs;
  • feature usage and system interactions;
  • device, browser, operating system, IP address, and approximate location derived from IP.

Website Data

When you browse the Website, we may process:

  • IP address and device/browser information;
  • website interactions and pages visited;
  • cookie and similar technology data (subject to any Cookies Policy).

Support Communications

If you contact us, we may process:

  • your contact details;
  • ticket content, attachments, screenshots, and correspondence; and
  • resolution records and service history.

Supplier-Related Data

For Supplier Listings / Supplier Hub submissions, we may process:

  • supplier contact details (name, role, email, phone);
  • company identifiers and commercial profile data; and
  • any Personal Data contained in Supplier Content submitted for publication or verification.

Client Data May Include Personal Data

Client Data uploaded to the Platform may include Personal Data depending on Client use (e.g., names of employees responsible for steps, internal approvals, or contact persons). The Client is responsible for ensuring that any such upload is authorised and lawful.

How We Use Personal Data

We process Personal Data for the following purposes:

  • Service Delivery – To create accounts, authenticate access, provide Platform functionality, enable workflows, dashboards, alerts, assignments, and internal operational tools.
  • Administration and Billing – To manage Subscriptions, invoicing, payments, renewals, account status, and communications required to administer the Client relationship.
  • Support and Incident Handling – To respond to support requests, troubleshoot issues, provide updates, and manage security incidents.
  • Security, Integrity, and Abuse Prevention – To protect the Platform and Website, enforce access controls, detect suspicious activity, prevent fraud, and ensure compliance with the Terms.
  • Compliance and Legal Purposes – To comply with applicable laws, respond to lawful requests, protect rights, and enforce contracts and policies.
  • Improvements and Analytics – To analyse service performance, develop improvements, and optimise user experience. Where possible, the Company uses aggregated or anonymised data for analytics and product enhancement.
  • Communications – To send operational communications (e.g., account notifications, security alerts, billing reminders). Marketing communications (if any) will be sent only where lawful and may include an opt-out mechanism.

Legal Bases for Processing

We process Personal Data only where we have a lawful basis, which may include:

  • performance of a contract (including provision of Services under a Subscription / Order Form);
  • legitimate interests (e.g., security, fraud prevention, Platform improvement), provided such interests do not override the rights of individuals;
  • compliance with legal obligations; and/or
  • consent, where required by applicable law (including for certain cookies or marketing communications).

Disclosure of Personal Data

No Sale of Personal Data

The Company does not sell Personal Data.

Service Providers

We may share Personal Data with third-party service providers acting on our behalf (e.g., cloud hosting, email delivery, payment processors, analytics, customer support tools), strictly to the extent necessary to provide and secure the Services.

Legal and Regulatory Disclosure

We may disclose Personal Data where required to comply with applicable law, court orders, or lawful requests by competent authorities.

Business Transfers

If the Company undergoes a merger, acquisition, restructuring, or sale of assets, Personal Data may be transferred as part of that transaction subject to appropriate safeguards.

Client Access and Control

Within the Platform, Client administrators may access Authorized User information and activity logs associated with the Client's Subscription.

International Transfers

Personal Data may be stored or processed in Egypt or in other countries where the Company, its affiliates, or service providers maintain infrastructure.

Where Personal Data is transferred internationally, the Company will implement appropriate safeguards as required by applicable data protection laws.

Data Retention

We retain Personal Data only for as long as necessary to fulfil the purposes described in this Policy, including providing the Services, complying with legal obligations, resolving disputes, and enforcing agreements.

Upon termination of a Subscription, Client Data (including any Personal Data contained therein) may be deleted or anonymised within a reasonable period, subject to:

  • legal retention requirements;
  • security, audit, and incident investigation needs; and
  • backup and continuity systems.

Data Security

The Company implements and maintains reasonable and appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, alteration, or disclosure, in line with the Company's Security Policy.

No system is 100% secure. The Client remains responsible for:

  • controlling Authorized User access;
  • maintaining strong password and authentication practices; and
  • promptly notifying the Company of suspected compromise or misuse.

Data Subject Rights

Subject to applicable law, individuals may have rights to request access to, correction of, deletion of, restriction of, or objection to processing of their Personal Data.

Where Personal Data is processed as part of Client Data within the Platform, requests may need to be directed through the relevant Client (as the primary controller for such data), and the Company may require verification of identity and authority.

The Company may refuse or limit requests where permitted by law, including where requests are unfounded, excessive, or would compromise security, confidentiality, or the rights of others.

Cookies and Similar Technologies

The Website may use cookies or similar technologies to operate, enhance performance, and analyse usage. Where required by law, consent mechanisms may be implemented.

Where a separate Cookies Policy is published, it forms part of this Policy and applies to the Website.

Children

The Services are provided on a B2B basis and are not intended for children. The Company does not knowingly collect Personal Data from minors.

Third-Party Links

The Website may contain links to third-party websites. The Company is not responsible for the privacy practices of third parties, and this Policy does not apply to external sites.

Changes to This Policy

The Company may amend, update, or modify this Policy at any time. Updated versions will be posted on the Website and/or within the Platform with a revised "Last Updated" date.

Continued use of the Services after publication of an updated Policy constitutes acceptance of the revised Policy to the extent permitted by law.

Contact Us

For questions or requests relating to this Policy or Personal Data, please contact:

MODREG Regulatory Digital Solutions LLC
District 5, Sokhna Road, New Cairo, Egypt
Email: [email protected]