Warsha

Data Processing Policy

Version 1.0 · effective 2026-08-06

The rules Warsha follows when it processes personal data, and how a new processing activity gets approved.

العربية

1. Relationship to other documents

The Privacy Policy tells a person what happens to their data. This policy is the internal standard that makes that true: it governs how Warsha decides to process anything at all.

The Data Processing Register is the inventory produced by applying this policy. Every activity in the register was approved under these rules.

2. Principles

Every processing activity must satisfy all of these before it exists:

  • A stated purpose. Not "analytics" — what decision does this let someone make.
  • Minimisation. The narrowest data that serves the purpose, and no field collected because it might be useful later.
  • A recorded basis, and where the basis is consent, a real choice with a real off switch that does not degrade anything else.
  • A retention trigger and period, or an explicit statement that neither has been settled and the item is under manual review.
  • A named access rule: which capability may read it, and whether that read is logged.
  • An entry in the Data Processing Register before processing begins, not after.

3. Special categories

Identity documents and criminal-record certificates are treated as the most sensitive data Warsha holds, and carry additional rules: private storage only, capability-gated access, every access logged, never exported, never used for training, and offence detail confined to a private reviewer record no client can read.

Warsha does not process health data, biometric data, religious affiliation, political opinion, or a sex marker. Where such a value appears on a document it is not extracted, not inferred and not stored.

4. Lawful basis

Egyptian data protection law and its executive regulations continue to develop. Warsha records the basis it proposes for each activity and marks it as pending legal review where it has not been confirmed.

This is deliberate. Asserting a settled legal characterisation that has not been obtained would be a claim about compliance rather than a description of practice, and a person reading it could not tell the difference.

5. Subprocessors

A supplier that processes personal data on Warsha's behalf is a subprocessor and must be in the Subprocessor Register before it processes anything.

Engaging one requires: a purpose, a data-category list, a location, a written agreement, a check that the supplier's terms prohibit using Warsha data to improve the supplier's own models, and a governance decision.

Adding a subprocessor is always a material change to the Privacy Policy. Users are told who, for what and where, before it takes effect.

6. Staff access

Access follows capability, not seniority or job title. Holding a senior role does not by itself grant sight of an identity document.

The most sensitive capabilities require re-authentication, and the most consequential decisions require a second person.

Access to sensitive records is logged whether or not anything was found, because a log that only records discoveries cannot show that a lookup was improper.

7. Changing this policy

A change to what may be processed, on what basis, by whom, or with which supplier requires a governance decision and a new version of this policy, and where it affects a person, a material update to the Privacy Policy with renewed acceptance.