Privacy Policy
- Version:
- 0.9-beta
- Last updated:
- 2026-10-03
- Effective:
- [set at launch]
Beta (draft) version under legal review before public launch — may change before taking effect. You will be asked to accept again after any material change.
In short
- We collect only the data needed to run the platform; we do not sell your data and do not use advertising trackers.
- Your private project data is not shown to any investor until you accept their intro request.
- Your project's monthly metrics are included in an investor's AI analysis only with your explicit consent, which you can withdraw at any time.
- AI requests are processed by providers outside Egypt (mainly in the USA) under paid accounts, after personal data is automatically removed from them; your account data is not sent to them.
- You can export your data or delete your account directly from Settings.
- Questions: privacy@octasolutions.net.
1. Who We Are (Data Controller)
1.1 Controller identity
- The controller of personal data processed through the platform is "OCTA Solution LLC" (شركة حلول أوكتا ذات المسؤولية المحدودة), an Egyptian limited liability company headquartered in Cairo, Arab Republic of Egypt.
- Commercial Register No.: [Commercial Register No.]. Registered address: [Full registered address]. Website: www.octasolutions.net.
- Data protection officer: [Data Protection Officer], reachable at privacy@octasolutions.net.
1.2 Reference laws
We comply with Egypt's Personal Data Protection Law No. 151 of 2020 and its executive regulations and, to the extent they apply to our users, observe the Saudi Personal Data Protection Law administered by the Saudi Data and Artificial Intelligence Authority (SDAIA) and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, guided by comparable international standards. [For review: applicability of the Saudi and UAE laws to the platform, and licensing or registration requirements with Egypt's Personal Data Protection Centre]
1.3 Roles
- The Company is the controller of account, project and payment data and operational logs.
- When users exchange data after an accepted intro and off the platform, each of them is responsible for their own use of it.
- A sponsor receiving an "Ask a specialist" request becomes an independent controller of the data it receives. [For review: characterisation of sponsors (independent or joint controller) and the agreement needed with them]
2. Data We Collect
2.1 Account data
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, email, country | You |
| Login data | Password stored as an Argon2id hash; we cannot see it | You |
| Account type | Founder, investor, sponsor, administrator | You or the Company |
| Mobile number (optional) | Only for WhatsApp alerts if you opt in | You |
| Preferences | Notification and language preferences | You |
| Verification status | Email verification, KYC level, administrator notes and documents | You and the administrator |
2.2 Project data
- Title, sector and stage: shown in the teaser.
- Problem, solution and business model: private, shown only after an intro is accepted. The teaser excludes the owner's identity, the problem, the solution and exact figures.
- Monthly metrics: shared in an investor's AI report only after intro acceptance and after you enable "Allow AI analysis".
- Idea fingerprint: a SHA-256 value with a timestamp.
2.3 Data rooms and NDAs
- Documents uploaded by the founder.
- The investor's NDA signature (typed name, version of the NDA text, time).
- A view log (who viewed which document and when); the viewer's identity appears as a watermark on PDFs.
2.4 Interaction data
Intro requests and their status, messages and "Ask a specialist" requests (including your name, email and message text), and notifications sent.
2.5 Payment data
Subscription plan, points packs, balance and transactions, invoices, and the transaction reference at the payment gateway. We do not receive or store card data; it is entered directly with the Kashier payment gateway.
2.6 AI data
Inputs and outputs stored with your sessions and reports, usage metadata (provider, model, token counts, cost), and the number of replacements made by the personal-data anonymisation layer in each request, without the replaced values.
2.7 Verified Handover data
The item manifest, uploaded code archives, scan reports, digital fingerprints, e-signature evidence (typed full name, time, IP address, hash) and the handover certificate. See the "Verified Handover Terms".
2.8 Technical and security data
IP address, browser type, login times, the append-only audit log, and policy acceptance records (policy, version, time, IP address). Cookies are explained in the "Cookie Policy".
2.9 Data we do not ask for
We do not ask for sensitive personal data (such as health or religious data). Please do not upload it in projects or data rooms unless necessary and with the required legal basis.
3. Purposes and Legal Bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and managing the account and verifying email | Account data | Performance of contract (Terms of Use) |
| Showing projects, intro requests and opening contact after acceptance | Project and interaction data | Performance of contract, and the founder's consent on acceptance |
| Data rooms, NDAs, view logs and watermarks | Data room data | Performance of contract, and legitimate interest in protecting confidentiality |
| AI analysis of monthly metrics for an investor | Monthly metrics | The founder's explicit consent, per project |
| AI services you request | Your inputs | Performance of contract |
| Identity verification | Verification data | Legitimate interest in trust and fraud prevention, or legal obligation where applicable |
| Payments and invoicing | Payment data | Performance of contract and legal obligation (accounting and tax) |
| Essential service emails (email verification, password reset) | Performance of contract | |
| WhatsApp alerts | Mobile number | Your consent |
| Sharing your project with sponsors | Project data | Your consent by enabling "visible to sponsors" |
| Sending an "Ask a specialist" request | Name, email, message | Your request and performance of contract |
| Aggregated market report for sponsors | Aggregated, anonymised data | Legitimate interest |
| Security, audit log and abuse prevention | Technical data | Legitimate interest and legal obligation |
| Verified Handover | Handover data | Performance of the contract between the parties and their request |
| Proof of policy acceptance | Acceptance records | Legal obligation and legitimate interest |
[For review: align the legal bases above with those set out in Egyptian Law No. 151 of 2020, which relies on consent as a primary basis]
4. Who We Share Data With
4.1 Other users
- Investors: see only the anonymised teaser, then contact details and project details after your acceptance.
- Sponsors: see your project only if you enable "visible to sponsors", after the early-access delay of their tier, and within a monthly contact quota. A sponsor receives your name, email and message if you send it an "Ask a specialist" request.
- The other party to a Verified Handover: sees the items, reports and signature evidence; the buyer sees the scan report, not the code, before delivery.
- The public handover verification page: shows only the certificate number, dates, hashes and item counts.
4.2 Service providers (processors)
| Processor | Purpose | Location |
|---|---|---|
| Hosting and storage provider | Running the platform, file storage and backups | [For review: hosting location and provider] |
| Kashier | Payment processing | Egypt |
| Email (SMTP) provider | Sending emails | [For review: provider name and location] |
| Meta (WhatsApp Cloud API) | WhatsApp alerts for users who opted in | Outside Egypt |
| Anthropic, OpenAI, Google | AI services; they receive only anonymised content, without account data | Outside Egypt, mainly USA |
- We engage processors under terms that require them to process data on our instructions and only for the service. [For review: conclude data processing agreements with each processor or confirm their standard terms are sufficient]
- Under the AI providers' API terms, data sent to them is not used to train their models. [For review: verify each provider's current terms and data retention periods]
- AI providers receive no account data (name, email address or mobile number). Before each request leaves the platform, the platform applies an automatic anonymisation layer that replaces with placeholders the requesting user's name and parts of it their email address and mobile number, and the identifiers it detects in the text, such as email addresses, phone numbers, ID numbers, payment cards, international bank account numbers (IBANs) and links to personal social media profiles. The "AI Use Policy" sets out the details and limits of this layer.
4.3 Public authorities
We disclose data to competent judicial or regulatory authorities where there is a legal obligation or an order from them, and only to that extent.
4.4 Change of ownership
In a merger, acquisition or restructuring, data may pass to the successor entity with the same safeguards, with notice to you.
4.5 What we do not do
We do not sell, rent or share your personal data for advertising.
5. International Transfers
- AI requests are sent to providers outside Egypt, mainly in the USA, after the automatic anonymisation layer is applied, so that only anonymised content, without personal data and without any account data, is transferred to them. Because automatic detection cannot guarantee the removal of every indirect identifier written in free text, such as names of other people typed by the user, we ask you not to include other people's personal data in AI requests. [For review: confirm that anonymised content sent to AI providers as described falls outside the cross-border personal data transfer rules of Law No. 151 of 2020 and their Saudi and UAE equivalents]
- WhatsApp messages pass through Meta's infrastructure outside Egypt.
- Hosting location: [For review: hosting location and provider]. We plan to host inside Egypt where possible; until decided, data may be hosted outside Egypt with appropriate safeguards.
- We limit transferred data to what the service needs and rely on available contractual and technical safeguards. [For review: cross-border transfer requirements for WhatsApp messages and for hosting if outside Egypt, under Egyptian law (including any licence or permit from the Personal Data Protection Centre) and the Saudi and UAE laws]
6. Retention
| Data | Period |
|---|---|
| Account data | While the account is active |
| Code archives in Verified Handover | Deleted automatically 90 days after the deal is completed or cancelled |
| Handover certificates, hashes and audit records | Retained as evidence [For review: period] |
| Payment and invoice records | [For review: statutory retention period for accounting records] |
| Notification outbox tokens | Scrubbed after sending |
| Daily backups | Deleted after 14 days |
| Policy acceptance records | [For review: period] |
6.1 On account deletion
- Immediate anonymisation: the email is replaced and the name and mobile number are removed.
- All login sessions are revoked.
- Projects are archived and their private fields erased; monthly metrics are deleted.
- Data-room documents are soft-deleted and the files purged from storage.
- Your AI sessions and reports are deleted, and the content of investor reports built on your project data is redacted.
- Pending notifications are cleared.
- Payment, invoice and audit records are retained only for legally required periods.
- Data disappears from backups within 14 days as they roll off.
7. Your Rights
- You have the right to access your data, obtain a copy, rectify it, delete it, withdraw consent, object to or restrict processing, port your data, and complain to the competent authority.
- From Settings you can: export all your data as JSON, delete your account (after entering your password), edit your profile and notification preferences, withdraw AI-analysis consent per project, and view your NDA history.
- "Your Rights and How to Exercise Them" explains these rights, how to exercise them and response times.
8. Security
We apply appropriate technical and organisational measures, including:
- Encrypted connections (HTTPS) and a Content Security Policy (CSP).
- Password hashing with Argon2id.
- A short-lived access token kept in memory only and a rotating httpOnly refresh cookie; tokens are never stored in the browser's local storage.
- Rate limiting to prevent abuse.
- An append-only, tamper-evident audit log using a SHA-256 hash chain.
- Integration keys encrypted with AES-256-GCM.
- Watermarks on data-room documents.
- Daily backups deleted after 14 days, and optional S3-compatible storage with server-side encryption, preferring a provider inside Egypt.
No system is completely secure. We do not claim any security certification or external audit. If a breach is likely to affect your rights, we will notify you and the competent authority in accordance with the legally prescribed periods and procedures. [For review: breach notification periods under the three laws]
9. Automated Decisions
- The platform produces automated results such as thesis-match scores and KPI reports.
- These results are informational only. The platform makes no automated decision producing legal or similarly significant effects on you. Acceptance, rejection and investment decisions are made by people.
- Details are in the "AI Use Policy".
10. Children
The platform is for adults (18 and over) only, and we do not knowingly collect minors' data. If we learn that an account belongs to a minor, we delete it.
11. Marketing
We send marketing messages only according to the notification preferences you choose, and you can turn them off at any time. Essential service emails (email verification and password reset) are always sent.
12. Changes to this Policy
- This policy is versioned.
- We notify you of material changes in-app and by email; you must accept the new version before continuing to use the service, and we record the acceptance (policy, version, time, IP address).
13. Contact and Complaints
- Data protection officer: [Data Protection Officer], at privacy@octasolutions.net.
- You have the right to lodge a complaint with the competent data protection authority in your country, such as Egypt's Personal Data Protection Centre, the Saudi Data and Artificial Intelligence Authority (SDAIA), or the UAE Data Office, in accordance with their procedures.
- We welcome you contacting us first so we can try to resolve the matter, though this is not a condition of your right to complain. See "Complaints, Disputes and Contact".