Privacy Policy

How Brand Makers Advertising handles personal data in Nazzam. Written to describe what the system actually does, not what a template says.

In effect from 8 August 2026.

1. Who is responsible for your data

Nazzam is operated by Brand Makers Advertising, a company established in the Arab Republic of Egypt, at 16A Anwar Al-Mofti, Nasr City, Cairo, Egypt. Brand Makers Advertising is the controller of the personal data described in this policy.

For anything in this policy, including a request to see, correct or delete your data, write to hello@nazzam.org.

2. Two different kinds of data

The distinction matters, because our obligations differ.

  • Your account data. The name, email address and password you register with, the workspace you belong to, and your role in it. We are the controller of this.
  • The data you put into your workspace. Your customers, contacts, deals, notes, files. This is yours. You decide what goes in it, what it is used for and when it is deleted; we hold and process it on your instructions. In GDPR terms you are the controller and we are the processor. If the records you upload describe people in the EU, the responsibility for having a lawful basis to hold them is yours, not ours.

3. What we collect, and why

  • Account details — to create your login, identify you to your colleagues, and let you recover access.
  • Workspace content — because storing and organising it is the service you are asking for.
  • Security and audit records — every change to a record is logged with who made it, when, from which IP address and which browser. This exists because our customers need to know who changed what, and it also protects us both if an account is misused. It is kept for as long as the workspace exists.
  • Operational logs — request timings and errors, so we can find faults. These may include your IP address.
  • Email delivery records — that a message was sent to you, when, and whether it was accepted, so we can tell whether an invitation or a password reset actually arrived.

We do not use advertising or analytics trackers. There is no Google Analytics, no advertising pixel and no third-party tracking script anywhere in this product or this website. We do not sell personal data, and we do not share it for marketing.

4. Our lawful basis

Under the GDPR, where it applies, we rely on:

  • Performance of a contract — for your account and for hosting your workspace. Without this data there is no service.
  • Legitimate interests — for security logging, audit records and fault diagnosis, balanced against your rights and limited to what those purposes need.
  • Legal obligation — where Egyptian law requires us to retain records.

Under Egypt’s Personal Data Protection Law (Law No. 151 of 2018), we process your data on the basis of your consent given at registration and the necessity of processing to deliver the service you signed up for.

5. Cookies

We use cookies only to make the product work. Specifically: a session cookie that keeps you signed in, and a stored preference for whether you want the light or dark appearance.

There are no advertising cookies and no third-party cookies, which is why you are not being asked to dismiss a consent banner.

6. Where your data is, and who else touches it

Brand Makers Advertising is in Egypt, but the infrastructure it runs on is not. We think you should know exactly where your data physically sits:

  • Database — Neon, Frankfurt, Germany (EU). Your workspace content and account records live here.
  • Hosting — Vercel. Serves the application and processes requests.
  • Email — Resend. Delivers invitations, password resets and notifications. Receives the recipient address and the message content.

This means personal data is transferred outside Egypt. Under the PDPL such transfers are restricted, and under the GDPR they are covered by the standard contractual clauses in our agreements with these providers. Each of them acts as our processor: they may only handle your data to provide their service to us, and may not use it for their own purposes.

We do not use any other third-party processor. If that changes, this list changes with it.

7. How long we keep it

  • While your workspace is active — your content is kept until you delete it.
  • Deleted records go to a recycle bin and can be restored by you. They are removed permanently when purged from there.
  • Backups — database backups are retained on a rolling basis, so a record you delete may persist in a backup for a short period before ageing out. This is a limitation of having backups at all, and we would rather tell you than pretend deletion is instantaneous everywhere.
  • After you close your account — your workspace content is deleted. Records we must keep for legal or accounting reasons are retained for as long as the law requires.

8. Your rights

Under the PDPL and, where it applies, the GDPR, you may ask us to:

  • tell you what personal data we hold about you;
  • give you a copy of it in a portable format;
  • correct anything inaccurate;
  • delete it, where we are not required to keep it;
  • restrict or object to how we process it;
  • withdraw consent you previously gave.

Write to hello@nazzam.org. We will respond within 30 days. You will not be charged, and you will not be treated any differently for asking.

You can also export your entire workspace yourself at any time, from inside the product, without asking us — to Excel, JSON or PDF.

If you think we have handled your data badly, tell us first and we will try to fix it. You also have the right to complain to the Egyptian Data Protection Centre, or to your national supervisory authority if you are in the EU or the UK.

9. Security

Passwords are stored hashed, never in readable form. Access between workspaces is separated at the data layer, and every request is checked against your permissions on the server rather than in the browser. Traffic is encrypted in transit. Every write is recorded in an audit trail.

No system is perfect, and we will not claim otherwise. If a breach affects your data, we will notify you and the relevant authority as the law requires, and tell you what we know rather than the least we can get away with.

10. Children

This is a business product and is not intended for anyone under 18. We do not knowingly collect data about children.

11. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you — by email or in the product — before the change takes effect, not after. The date at the top always reflects the version you are reading.

12. A note on this document

This policy was written to describe this system accurately rather than to be as broad as possible. It has not yet been reviewed by a lawyer qualified in Egyptian data protection law. If you are relying on it for a procurement or compliance decision, ask us — we would rather have that conversation than have you assume.