CODEFY DATA PROCESSING ADDENDUM
Version: 1.0
Effective Date: 1st August 2025
This Data Processing Addendum, the “DPA”, forms part of the agreement between Codefy Hub For IT Solutions, trading as Codefy Hub, and the Customer governing Customer's use of the Services.
This DPA applies where Codefy processes Customer Personal Data on behalf of Customer in connection with Codefy Hub or Codefy ERP.
The DPA supplements the Codefy Hub Terms of Service, applicable Codefy ERP Service Terms, Order Form and other applicable written agreements between the parties.
If this DPA conflicts with the General Terms concerning processing of Customer Personal Data, this DPA shall control with respect to that processing.
1. Definitions
For purposes of this DPA:
Applicable Data Protection Law means laws and regulations applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, Egyptian Personal Data Protection Law No. 151 of 2020 and its Executive Regulations.
Controller means the person or organization that determines the purposes and means of processing Personal Data.
Customer Personal Data means Personal Data processed by Codefy on behalf of Customer through the Services.
Data Subject means an identified or identifiable natural person to whom Personal Data relates.
Personal Data means information relating to an identified or identifiable natural person and includes equivalent concepts under Applicable Data Protection Law.
Processing includes any operation performed on Personal Data, including collection, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, combination, restriction, deletion or destruction.
Processor means a person or organization processing Personal Data on behalf of a Controller.
Security Incident means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Codefy.
Subprocessor means a third party appointed by Codefy to process Customer Personal Data on behalf of Customer in connection with the Services.
2. Roles of the Parties
Where Customer determines the purposes and means of processing Customer Personal Data through the Services:
Customer acts as Controller.
Codefy acts as Processor.
Where Customer itself acts as processor for another controller, Customer may act as Processor and Codefy as Subprocessor.
Nothing in this DPA prevents Codefy from acting separately as Controller for limited processing performed for Codefy's own lawful purposes as described in the Codefy Hub Privacy Policy.
3. Customer Instructions
Codefy shall process Customer Personal Data only:
to provide the Services;
according to Customer's documented instructions;
as necessary to perform the Agreement;
or as required by applicable law.
The Agreement, Customer's use and configuration of the Services, Order Forms, support requests and other documented directions constitute Customer instructions.
If Codefy is legally required to process Customer Personal Data contrary to Customer's instructions, Codefy will notify Customer before processing unless prohibited by law.
4. Lawfulness of Customer Instructions
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.
Customer represents that it has an appropriate legal basis and authority for Customer Personal Data submitted to the Services.
Customer shall not instruct Codefy to process Personal Data unlawfully.
If Codefy reasonably believes that an instruction violates applicable data protection law, Codefy may suspend the affected processing and inform Customer, where legally permitted, until the parties resolve the issue.
5. Categories of Data Subjects
Depending on the Services and Customer configuration, Customer Personal Data may relate to:
Customer personnel;
employees;
workers;
job applicants;
contractors;
Drivers;
Riders;
students;
parents;
guardians;
school personnel;
supervisors;
Transport Provider personnel;
customers;
suppliers;
Customer business contacts;
and other individuals whose information Customer processes through the Services.
6. Categories of Customer Personal Data
Depending on Customer configuration, Customer Personal Data may include:
identity information;
contact information;
account information;
employment information;
HR records;
attendance;
financial and commercial information;
supplier information;
Customer records;
student transportation information;
guardian relationships;
Driver information;
vehicle related information associated with individuals;
trip information;
route information;
pickup and drop off information;
location data;
telematics information;
device information;
application activity;
documents;
communications;
and other Customer configured Personal Data.
7. Sensitive Personal Data
Certain Customer Personal Data may constitute sensitive personal data under Applicable Data Protection Law.
Depending on Customer use, this may include children's information, financial information, biometric related information, health information or other legally protected categories.
Customer is responsible for determining whether processing sensitive Personal Data is appropriate and for obtaining any required authorization, consent or regulatory permission applicable to Customer.
Codefy shall apply safeguards appropriate to the nature of the processing and its legal obligations as Processor.
8. Children and Student Data
Codefy ERP may process student information where Customer uses student transportation functionality.
Customer is responsible for establishing its lawful authority to process student information.
Where guardian authorization or consent is required, Customer is responsible for obtaining and maintaining that authorization unless Codefy expressly agrees in writing to operate a consent mechanism on Customer's behalf.
Codefy shall process student information according to Customer's documented instructions and Applicable Data Protection Law.
9. Data Minimization
Customer should configure the Services to process only Personal Data reasonably necessary for Customer's intended purposes.
Codefy will design and operate the Services with appropriate consideration for data minimization.
Where reasonably practicable, Codefy will avoid transmitting identifiable student information to telematics providers when vehicle, Driver, device or trip identifiers are sufficient to provide the tracking functionality.
10. Processing Details
The subject matter of processing is the provision of the Services purchased by Customer.
The duration of processing is generally the term of the Agreement plus applicable retention, export, backup and deletion periods.
The nature and purpose of processing may include:
hosting;
storage;
retrieval;
organization;
transmission;
display;
calculation;
workflow processing;
reporting;
authentication;
security;
support;
transportation management;
tracking;
telematics;
AI assisted functionality;
and other processing necessary to provide Customer configured Services.
11. Confidentiality
Codefy shall ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access shall be limited to personnel who require access for legitimate purposes relating to provision, support, security or administration of the Services.
12. Access Controls
Codefy shall implement access controls appropriate to the Services and risks involved.
Such controls may include:
authentication;
role based access;
administrative controls;
tenant restrictions;
service account controls;
logging;
and authorization mechanisms.
Customer remains responsible for configuring its own Authorized Users and organizational permissions appropriately.
13. Security Measures
Codefy shall maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, alteration or disclosure.
Measures may include, where appropriate:
encryption in transit;
encryption at rest;
authentication;
role based authorization;
tenant isolation;
secure software development practices;
logging and monitoring;
backup controls;
vulnerability management;
incident response;
access restriction;
and infrastructure security.
Based on Codefy's current product architecture, these measures may include use of hosted database, authentication, storage and realtime infrastructure; web application and API hosting; separate live tracking gateway infrastructure; server side service credentials for authorized system operations; Customer user authentication through session cookies or bearer tokens; tenant scoping; Row Level Security where configured; application level permission checks; restricted storage access; and limited data transfer to approved technology providers.
Privileged service credentials are intended to remain server side and must not be intentionally exposed to browser or mobile clients.
Specific measures may evolve as technology and risks change, provided Codefy does not materially reduce the overall level of protection during the applicable Service term without appropriate justification.
14. Customer Security Responsibilities
Customer remains responsible for security matters within its control.
These include:
protecting Customer credentials;
selecting appropriate administrators;
configuring permissions;
securing Customer devices;
protecting Customer networks;
removing former users;
reviewing administrative access;
and using available security functionality appropriately.
15. Multi Tenant Architecture
Codefy ERP may operate as a multi tenant service.
Codefy shall maintain logical and technical controls designed to prevent one Customer from accessing another Customer's Customer Personal Data without authorization.
Customer access remains subject to tenant, application, role and permission controls.
16. Subprocessors
Customer generally authorizes Codefy to appoint Subprocessors necessary to provide the Services, subject to this DPA and Applicable Data Protection Law.
Codefy shall maintain a current Subprocessors and Technology Providers List identifying material Subprocessors where appropriate.
Codefy shall require Subprocessors processing Customer Personal Data on Codefy's behalf to undertake data protection obligations appropriate to the processing and consistent with Codefy's obligations under this DPA to the extent required by law.
17. Damoov
Where Customer uses transportation tracking functionality supported by Damoov, Codefy may engage Damoov Pte. Ltd. in the processing chain for telematics services.
The Codefy implementation may transmit or receive information associated with pseudonymous device identifiers, GPS coordinates, timestamps, speed, heading, accuracy, motion information and related telematics data.
Codefy's current implementation provisions tenant specific Damoov integrations and associates Damoov device tokens with relevant transportation records.
Codefy's fleet gateway can receive provider location information and associate it with authorized trip, Driver and vehicle context.
Damoov describes itself as processor in relation to institutional customers for applicable telematics processing. Damoov Privacy Policy
18. Tracking Provider Changes
Customer authorizes Codefy to replace or supplement tracking providers where reasonably necessary, subject to Codefy's obligations under this DPA and Applicable Data Protection Law.
Codefy shall not use replacement of a provider to materially reduce the protection afforded to Customer Personal Data.
19. Other Subprocessors
Depending on enabled Services, Codefy may use Subprocessors providing:
cloud infrastructure;
database services;
authentication;
web application and API hosting;
fleet tracking gateway hosting;
communications;
SMS delivery;
mobile push notifications;
maps;
AI processing;
tracking and telematics;
payment related services;
support infrastructure;
and other technology necessary to operate the Services.
The current provider list shall be maintained separately so that operational provider changes do not require amendment of the entire DPA.
20. Subprocessor Changes
Where required by Applicable Data Protection Law or Customer's applicable commercial terms, Codefy will provide reasonable notice of material new Subprocessors processing Customer Personal Data.
Where Customer has a legally required right to object, Customer may object on reasonable data protection grounds.
The parties shall work in good faith to resolve a legitimate objection.
If no commercially reasonable resolution exists, Codefy may permit termination of the affected Service subject to the applicable Agreement and legal requirements.
21. Third Party Integrations Selected by Customer
A service independently selected and enabled by Customer is not necessarily a Codefy Subprocessor.
Where Customer instructs Codefy to transmit Customer Personal Data to a Customer selected integration, Customer is responsible for determining that the recipient is appropriate and lawful.
Codefy remains responsible for third parties that Codefy itself appoints as Subprocessors according to this DPA.
22. International Processing
Customer acknowledges that Codefy and authorized Subprocessors may process Customer Personal Data outside Egypt where necessary to provide the Services.
Such processing remains subject to Applicable Data Protection Law.
Where cross border transfers require authorization, contractual safeguards, permits or other mechanisms under Egyptian law, Codefy shall implement applicable requirements for transfers within its responsibility.
23. Processing Locations
Codefy shall maintain reasonable information regarding material Subprocessor processing locations through its Subprocessor documentation or other Customer facing compliance materials.
Processing locations may change where Codefy or its providers modify infrastructure.
Codefy will manage such changes according to applicable legal and contractual requirements.
24. Data Subject Requests
Where Codefy receives a request from a Data Subject relating to Customer Personal Data for which Customer acts as Controller, Codefy may refer the requester to Customer.
Unless legally required to respond directly, Codefy shall not independently determine the substantive response to such request.
Codefy will provide Customer with reasonable assistance necessary to respond to requests concerning:
access;
correction;
deletion;
restriction;
objection;
consent withdrawal;
or other applicable rights,
taking into account the nature of the processing and functionality available through the Services.
25. Verification and Customer Responsibility
Customer is responsible for determining whether a person requesting access, deletion or modification is entitled to exercise the requested right.
Codefy may provide technical functionality assisting Customer with such requests.
Customer remains responsible for the legal decision concerning the request where Customer acts as Controller.
26. Student and Guardian Requests
Requests concerning student information may require verification of guardian authority or another lawful relationship.
Customer is responsible for determining who is authorized to exercise rights relating to student records where Customer acts as Controller.
Codefy shall not knowingly disclose student information to an unauthorized person merely because that person claims to be a guardian.
27. Security Incidents
Codefy shall maintain procedures for identifying, investigating, containing and responding to Security Incidents.
Where Codefy becomes aware of a Security Incident affecting Customer Personal Data, Codefy shall notify Customer without undue delay and within any period necessary for Codefy to satisfy its applicable processor obligations.
The notification shall contain information reasonably available to Codefy concerning the incident.
28. Security Incident Information
To the extent reasonably available, Codefy's notification may include:
the nature of the incident;
date or estimated period;
categories of affected Personal Data;
categories or approximate number of affected Data Subjects;
likely consequences;
containment measures;
remediation measures;
and relevant contact information.
Information may be provided in phases where all details are not immediately available.
29. Egyptian Breach Requirements
Where Egyptian Personal Data Protection Law applies, the parties shall cooperate to satisfy applicable breach notification requirements according to their respective legal roles.
The 2025 Executive Regulations establish detailed incident notification requirements for controllers and processors, including regulatory reporting mechanisms and information concerning the nature and effects of the incident.
Codefy's notification to Customer does not relieve Customer from Customer's own regulatory notification obligations as Controller.
30. Incident Cooperation
Codefy shall reasonably cooperate with Customer's investigation of a Security Incident affecting Customer Personal Data.
Such cooperation may include reasonably available technical information necessary for Customer's legal assessment and notifications.
Codefy is not required to disclose information that would compromise another Customer's security, Codefy's protected security architecture, privileged information or another person's legal rights.
31. Security Incident Remediation
Codefy shall take reasonable steps to contain and remediate a Security Incident within systems under Codefy's control.
Customer remains responsible for remediation required within Customer controlled devices, accounts, networks, configurations and systems.
32. Regulatory Cooperation
Taking into account the nature of processing, Codefy shall provide reasonable assistance where Customer is required to communicate with a competent data protection authority regarding Codefy's processing of Customer Personal Data.
Customer remains responsible for its regulatory relationship as Controller.
33. Data Protection Impact Assessments
Where Customer is legally required to perform a data protection impact assessment relating to Customer's use of the Services, Codefy shall provide reasonable information concerning Codefy's processing that Customer cannot reasonably obtain itself.
Any assistance beyond standard compliance documentation that requires substantial bespoke professional effort may be subject to mutually agreed fees unless required otherwise by law.
34. Prior Consultation
Where applicable law requires prior consultation with a supervisory authority concerning processing performed through the Services, Codefy will provide reasonable assistance concerning the Codefy controlled aspects of processing.
Customer remains responsible for determining whether consultation is required.
35. Audit Information
Codefy shall make available information reasonably necessary to demonstrate compliance with its processor obligations under this DPA.
Codefy may satisfy this obligation through appropriate documentation, security summaries, certifications, audit reports, questionnaires or other reasonable compliance materials where available.
36. Customer Audits
Where Applicable Data Protection Law gives Customer a right to conduct an audit that cannot reasonably be satisfied through Codefy's standard compliance materials, Customer may request an additional audit.
Such audits shall:
be subject to reasonable advance notice;
occur during normal business hours;
avoid unnecessary disruption;
protect Codefy and other Customers' confidential information;
not expose information that could compromise Service security;
and be limited to matters relevant to Customer Personal Data.
The parties may agree reasonable costs for audits requiring substantial Codefy resources unless prohibited by law.
37. Government Inspections
Codefy shall cooperate with competent authorities to the extent legally required concerning processing for which Codefy is responsible.
Where legally permitted, Codefy may notify Customer of an authority request specifically concerning Customer Personal Data.
38. Data Retention
Codefy shall retain Customer Personal Data according to:
Customer instructions;
the Agreement;
applicable Service configuration;
legal requirements;
security requirements;
and documented retention procedures.
Different data categories may have different retention periods.
39. Customer Configurable Retention
Where Codefy provides Customer configurable retention functionality, Customer is responsible for selecting settings appropriate to its legal and operational requirements.
Codefy does not determine Customer's statutory record retention obligations merely by providing configurable software.
40. Tracking Data Retention
Transportation tracking data may be subject to specific retention periods based on Customer requirements, Codefy configuration and the applicable tracking provider.
Where a Subprocessor maintains separate telematics retention periods, Codefy shall manage that provider according to Codefy's applicable contractual rights and this DPA.
41. Damoov Retention
Codefy will not represent that one universal Damoov retention period applies where Damoov's applicable service configuration permits or applies different retention periods.
Codefy shall document its applicable Damoov processing arrangement and manage retention according to Codefy's actual contractual and technical configuration.
42. Return and Export of Customer Data
During the Agreement and for any applicable post termination export period, Customer may retrieve Customer Data using available export functionality or another agreed mechanism.
Available export formats may vary according to the relevant module and data structure.
Customer is responsible for completing required exports before the applicable deletion deadline.
43. Deletion Following Termination
Following termination or expiration, Codefy shall delete or return Customer Personal Data according to the Agreement, Customer instructions and Applicable Data Protection Law, unless continued retention is legally required.
Codefy may maintain Customer Personal Data for a limited post termination period to allow export where provided by the Agreement.
44. Backup Deletion
Customer Personal Data may remain in protected backups after deletion from active systems until the applicable backup is overwritten according to Codefy's backup cycle.
Codefy shall not intentionally restore deleted Customer Personal Data into active processing except where necessary for legitimate disaster recovery or continuity purposes.
If restored, applicable deletion instructions should be reapplied where technically appropriate.
45. Legal Retention
Codefy may retain limited Customer Personal Data where required by applicable law or reasonably necessary for:
legal claims;
security;
fraud prevention;
regulatory obligations;
or enforcement of contractual rights.
Any retained information shall remain protected under applicable confidentiality and security obligations.
46. AI Processing
Where Customer enables AI functionality that processes Customer Personal Data, Codefy shall process such information according to Customer's instructions and this DPA.
Codefy may engage authorized AI technology providers as Subprocessors where applicable.
Such providers shall be addressed through Codefy's Subprocessor framework.
47. AI Data Minimization
Codefy shall seek to transmit only information reasonably necessary to perform the applicable AI functionality.
Customer is responsible for determining whether the Customer Personal Data it instructs Codefy to process through an AI enabled feature is appropriate for that purpose.
Customer should avoid submitting sensitive Personal Data to general purpose AI functionality unless the applicable feature is intended and appropriately configured for such processing.
Where reasonably practicable, Codefy may apply measures such as data selection, filtering, pseudonymization, access restrictions or other controls to reduce unnecessary disclosure to AI Subprocessors.
48. AI Providers and Model Training
Where Codefy engages a third party AI provider as a Subprocessor, Codefy shall use the provider under terms and configurations reasonably appropriate for processing Customer Personal Data.
Codefy shall not represent that Customer Personal Data is excluded from provider model training unless that representation is accurate for the applicable provider, service tier and contractual configuration.
Where Codefy contractually commits that Customer Personal Data will not be used to train third party models, Codefy shall configure and select applicable AI services consistently with that commitment.
The applicable AI Subprocessors shall be identified through the Subprocessors and Technology Providers List.
49. AI Output and Personal Data
AI generated output may reproduce, infer, summarize or otherwise relate to Customer Personal Data supplied to an AI enabled feature.
Customer remains responsible for determining who within its organization may access such functionality and whether generated output should be retained in Customer records.
Where AI output constitutes Personal Data, it remains subject to the applicable protections of this DPA.
50. Automated Processing
Codefy ERP may enable Customer configured automated workflows or AI assisted processing.
Where Customer determines the purpose and configuration of such processing, Customer remains responsible for determining whether applicable laws permit the processing and whether human review, notice, consent or another safeguard is required.
Codefy shall provide reasonable information concerning relevant Codefy functionality where necessary for Customer to assess its compliance obligations.
51. Location and Telematics Processing
Where Customer enables transportation tracking, Codefy may process location and telematics information on Customer's behalf.
Depending on the implementation, this may include:
GPS coordinates;
timestamps;
speed;
heading;
accuracy information;
motion or activity information;
device identifiers;
Driver association;
vehicle association;
trip association;
route information;
and related transportation metadata.
The purposes may include active trip tracking, fleet visibility, trip recording, transportation monitoring, route progress and related Customer configured transportation operations.
52. Background Driver Tracking
Where enabled, Driver location and telematics processing may continue while the Driver application operates in the background.
Customer is responsible for ensuring that its use of Driver monitoring has an appropriate lawful basis and complies with applicable employment, transportation and privacy requirements.
Customer is also responsible for providing any notices or obtaining any consents required from Drivers, except where Codefy expressly agrees to perform a particular notice or consent mechanism on Customer's behalf.
Codefy shall provide reasonable information concerning the tracking functionality to enable Customer to provide appropriate transparency.
53. Rider Location
Where the Rider App provides optional location functionality, Codefy may process the location of an employee, student, parent, guardian or other Rider on Customer's behalf when the user enables or invokes that functionality.
Such processing should be limited to the disclosed purpose associated with the feature.
Unless separately configured, disclosed and lawfully enabled, optional Rider location shall not be treated as authorization for continuous Driver style background tracking.
54. Student Location
Where a student uses an optional Rider location feature, Customer is responsible for determining the lawful basis for that processing and obtaining guardian authorization or consent where required.
Codefy shall seek to minimize the collection, retention and disclosure of student device location consistent with the applicable feature.
Student device location should not be disclosed to a telematics provider where such disclosure is unnecessary for providing the relevant functionality.
55. Parent and Guardian Location
Where a parent or guardian voluntarily uses an optional location feature, the location of that person's device shall be treated as Personal Data relating to that parent or guardian.
Such location should not automatically become part of the student's permanent transportation record unless required for the disclosed functionality, Customer configuration or applicable law.
56. Separation of Identity and Telematics
Where reasonably practicable, Codefy shall structure transportation tracking so that third party telematics providers receive pseudonymous device, vehicle, Driver or trip identifiers rather than unnecessary identifying information concerning Riders or students.
Codefy may maintain the necessary association between telematics identifiers and Customer transportation records within Codefy controlled systems.
This provision does not prohibit disclosure of identifying information where it is genuinely necessary to provide the applicable Service and permitted under this DPA.
57. Mobile Application Processing
Customer Personal Data may be processed through Codefy mobile applications.
The categories of processing and permissions differ according to application and user role.
The applicable Mobile Application Privacy Notice provides more detailed information concerning the Driver, Supervisor and Rider applications.
The DPA governs Codefy's processor obligations for Customer Personal Data processed through those applications.
58. Customer Responsibility for Mobile Users
Customer is responsible for determining which individuals may access Customer controlled mobile functionality.
Customer shall maintain appropriate processes for:
creating users;
assigning roles;
associating students and guardians;
authorizing Drivers;
removing former users;
and correcting unauthorized access.
Codefy shall provide available technical controls according to the applicable Service.
59. Employee Monitoring
Where Customer uses Codefy ERP or Codefy mobile applications to monitor employee or contractor attendance, location, activity, transportation or performance, Customer remains responsible for determining whether such monitoring is lawful and proportionate.
Customer is responsible for applicable workplace notices, policies, consultation requirements, consents and other legal requirements.
Codefy's provision of monitoring functionality does not constitute legal approval of Customer's particular monitoring practice.
60. Transportation Operational Data
Customer acknowledges that certain transportation information may combine Personal Data with operational records.
Examples include:
Driver plus vehicle assignment;
Driver plus location;
Rider plus trip;
student plus route;
guardian plus student;
attendance plus trip;
and Driver performance plus telematics.
Such combined information remains Customer Personal Data where it relates to an identifiable individual.
61. Public and Limited Tracking Sharing
Where Customer enables a limited trip sharing feature, Customer instructs Codefy to make the authorized tracking information available to the intended recipient.
Codefy may implement technical measures such as:
limited fields;
expiring access;
tokenized links;
restricted trip scope;
and other controls designed to reduce unnecessary disclosure.
Customer remains responsible for determining whether the sharing itself is appropriate and for distributing access only to intended recipients.
62. Customer Data Disclosure Within the Organization
Codefy ERP may make Customer Personal Data available to Customer's Authorized Users according to configured roles and permissions.
Such disclosure is performed according to Customer's instructions.
Customer is responsible for ensuring that its role and permission configuration reflects its own legal and organizational requirements.
63. Customer Data Disclosure to Transport Providers
Where Customer configures Codefy ERP to share information with a Transport Provider, Customer instructs Codefy to make the relevant information available according to the configured workflow.
Customer is responsible for determining whether the Transport Provider is authorized to receive the information.
Where the Transport Provider independently determines its own purposes for subsequent processing, it may have separate obligations under Applicable Data Protection Law.
64. Customer Data Disclosure to Schools, Enterprises and Portals
Codefy may provide Customer configured portal access to enterprises, Schools or other authorized organizations.
Customer is responsible for determining the scope of information each portal user may access.
Codefy shall provide reasonable technical access controls consistent with the applicable Service.
65. Confidential Customer Data
Customer Personal Data remains subject to Codefy's confidentiality obligations under the Agreement.
Codefy shall not disclose Customer Personal Data to another Customer except where Customer has expressly instructed such disclosure through an authorized multi party workflow or where disclosure is otherwise legally permitted.
66. Personnel Access
Codefy personnel shall access Customer Personal Data only where reasonably necessary for authorized purposes such as:
Service operation;
support;
security;
incident response;
maintenance;
legal compliance;
or another purpose permitted under the Agreement.
Codefy shall maintain appropriate internal authorization and confidentiality controls.
67. Support Access
Where Customer requests support, Codefy personnel may access relevant Customer configuration, logs or Customer Personal Data where reasonably necessary to investigate the issue.
Codefy shall seek to limit support access to information relevant to the support request.
Customer should avoid unnecessarily submitting sensitive Personal Data in support communications.
68. Diagnostic and Security Logs
Codefy may maintain logs necessary for:
security;
fraud prevention;
authentication;
auditability;
performance;
troubleshooting;
and incident investigation.
Where such logs contain Customer Personal Data, they remain subject to applicable protections under this DPA.
Codefy should design application logging to avoid unnecessary inclusion of credentials, access tokens, device tokens, tenant identifiers, user identifiers, payment secrets and other sensitive values.
Where reasonably practicable, Codefy may use redaction, limited log output, development-only diagnostic logging, risky log checks or similar controls to reduce unnecessary exposure in logs.
Security logs may be retained separately from ordinary Customer Data where a longer retention period is reasonably necessary for security or legal purposes.
69. Data Accuracy
Customer is responsible for the accuracy of Customer Personal Data supplied to Codefy.
Codefy shall provide reasonable functionality for Customer to correct or update information where supported by the relevant Service.
Codefy is not required to independently verify the factual accuracy of Customer Personal Data unless expressly agreed.
70. Privacy by Design and Default
Codefy shall take data protection principles into account when designing and materially modifying Services that process Customer Personal Data.
Where appropriate to the nature and risk of processing, this may include:
data minimization;
access restrictions;
purpose limitation;
secure defaults;
tenant isolation;
pseudonymization;
retention controls;
and transparency mechanisms.
71. Pseudonymization
Where appropriate, Codefy may use pseudonymous identifiers to reduce unnecessary exposure of direct identifiers.
Pseudonymization does not cause information to cease being Personal Data where Codefy or another party can reasonably reconnect the identifier to an individual.
Such information shall therefore continue to receive appropriate protection.
72. Encryption
Codefy shall use appropriate encryption mechanisms for Customer Personal Data where reasonably necessary according to the nature of the processing and associated risks.
This may include encryption of network communications and encryption of stored information where supported by the applicable infrastructure.
Encryption measures may evolve as Codefy's technical architecture changes.
73. Authentication
Codefy shall maintain authentication mechanisms intended to restrict Service access to authorized users.
Depending on the Service, these may include:
password based authentication;
session controls;
biometric assisted device authentication;
multi factor authentication where available;
service credentials;
API credentials;
and other authentication mechanisms.
Customer remains responsible for managing Customer user access appropriately.
74. Biometric Authentication
Where a Codefy mobile application uses biometric authentication provided by the user's operating system, Codefy may receive an authentication result without receiving the underlying fingerprint or facial template.
Such local device authentication shall not be treated as Codefy processing biometric templates unless Codefy actually receives or stores such biometric information.
If Codefy introduces direct biometric template processing, the parties shall address any additional legal requirements before such processing is enabled.
75. Data Portability and Export
Where applicable and technically supported, Codefy shall provide Customer with mechanisms to export Customer Data.
Customer is responsible for securely storing, transmitting and protecting exported data after it leaves Codefy controlled systems.
Exporting data does not remove Customer's obligations under Applicable Data Protection Law.
76. Deidentified and Aggregated Data
Codefy may process information derived from the Services that has been aggregated or deidentified so that it no longer identifies Customer, a Data Subject or another identifiable person, where permitted by Applicable Data Protection Law and the Agreement.
Such information may be used for:
Service reliability;
security;
capacity planning;
product improvement;
analytics;
and research.
Codefy shall not characterize information as anonymous where it remains reasonably capable of being linked to an identifiable person.
77. No Sale of Customer Personal Data
Codefy shall not sell Customer Personal Data to data brokers or advertisers merely because Codefy processes such data in providing the Services.
Codefy shall not use Driver, Rider, student or guardian location data for unrelated behavioral advertising.
Nothing in this section prevents Codefy from using Subprocessors necessary to provide the Services according to this DPA.
78. No Independent Marketing Use of Customer Personal Data
Codefy shall not use Customer controlled employee, student, Driver, Rider, guardian, supplier or similar operational records for unrelated direct marketing to those individuals merely because Codefy processes their information on Customer's behalf.
This does not prevent Codefy from communicating directly with Customer account administrators or business contacts where Codefy independently has a lawful basis to do so.
79. Legal Requests for Customer Personal Data
If Codefy receives a legally binding request from a governmental authority or court seeking Customer Personal Data, Codefy may disclose information to the extent legally required.
Where legally permitted and reasonably practicable, Codefy shall notify Customer before disclosure so that Customer may seek appropriate protection.
Codefy shall seek to limit disclosure to information required by the valid legal request.
80. Conflicting Legal Requirements
If Codefy becomes subject to a legal obligation that Codefy reasonably believes conflicts with Customer's documented instructions, Codefy shall notify Customer where legally permitted.
The parties shall cooperate in good faith to determine an appropriate lawful response.
81. Records of Processing
Codefy shall maintain records concerning its processing activities to the extent required by Applicable Data Protection Law.
Customer remains responsible for maintaining records required of Customer as Controller.
Codefy shall provide reasonable information concerning Codefy's processing to assist Customer with its applicable recordkeeping obligations.
82. Egyptian Data Protection Compliance
Where Egyptian Personal Data Protection Law applies, Codefy and Customer shall perform their respective Controller and Processor obligations under Law No. 151 of 2020 and its applicable Executive Regulations.
This may include requirements concerning:
processing records;
security;
Data Subject rights;
breach management;
sensitive Personal Data;
children's Personal Data;
Data Protection Officers;
licenses;
permits;
and cross border processing.
Each party remains responsible for obtaining licenses, permits or registrations legally required specifically of that party.
83. Data Protection Officer
Where required by Applicable Data Protection Law, each party shall appoint or designate a Data Protection Officer or other responsible privacy official and satisfy applicable registration requirements.
Codefy's applicable privacy contact information shall be maintained in its Privacy Policy or other Customer facing compliance documentation.
84. Customer Regulatory Authorizations
Customer is responsible for obtaining licenses, permits, approvals or registrations required specifically because of Customer's own processing purposes, industry or use of the Services.
For example, Codefy's provision of a technical capability does not obtain on Customer's behalf a regulatory approval that Customer itself is required to hold.
Codefy will reasonably cooperate by providing information concerning the Services where necessary for Customer's application or compliance assessment.
85. Codefy Regulatory Authorizations
Codefy is responsible for obtaining licenses, permits, approvals or registrations required specifically for Codefy's activities as Processor or Controller under Applicable Data Protection Law.
Codefy shall not shift to Customer an authorization requirement that legally belongs to Codefy.
86. Changes in Applicable Law
If a change in Applicable Data Protection Law requires material changes to this DPA or the Services, the parties shall cooperate in good faith to implement legally necessary modifications.
Codefy may update this DPA where reasonably necessary to maintain compliance, subject to the change provisions of the Agreement and applicable law.
87. Suspension of Unlawful Processing
Codefy may suspend an affected processing activity where continuing the activity would reasonably expose Codefy, Customer, Data Subjects or the Services to material legal or security risk.
Where legally permitted and reasonably practicable, Codefy will notify Customer and work with Customer to restore lawful processing.
88. Term and Survival
This DPA remains effective for as long as Codefy processes Customer Personal Data on Customer's behalf.
Relevant confidentiality, security, deletion and legal compliance obligations survive termination for as long as Codefy retains Customer Personal Data.
89. Liability
The liability provisions of the Agreement apply to this DPA unless Applicable Data Protection Law requires otherwise or the parties expressly agree otherwise in writing.
Nothing in this DPA limits liability to the extent such limitation is prohibited by applicable law.
Any negotiated enterprise Order Form may specify a different liability allocation for data protection claims where expressly agreed by the parties and permitted by applicable law.
90. Indemnification
Any indemnification relating to data protection shall be governed by the applicable indemnification provisions of the Agreement unless expressly modified in an Order Form or other signed agreement.
Nothing in this DPA creates an additional unlimited indemnification obligation unless expressly stated.
91. Relationship With the Agreement
Except as expressly modified by this DPA, the Agreement remains in effect.
If there is a conflict between this DPA and another part of the Agreement concerning Codefy's processing of Customer Personal Data, this DPA shall prevail for that processing unless a later signed agreement expressly states otherwise.
92. Governing Law
This DPA is governed by the governing law specified in the Agreement.
Where the General Terms apply, the intended governing law is the law of the Arab Republic of Egypt.
Mandatory provisions of Applicable Data Protection Law remain applicable notwithstanding the contractual governing law provision.
93. Jurisdiction
Disputes concerning this DPA are subject to the jurisdiction provisions contained in the Agreement, subject to any mandatory jurisdiction of competent data protection or governmental authorities.
Nothing in this section prevents either party from cooperating with or responding to a competent data protection authority as legally required.
94. Electronic Execution
This DPA may be accepted electronically, incorporated through an Order Form or executed separately.
Where permitted by applicable law, electronic acceptance has the same contractual effect as physical execution.
95. Contact Information
Codefy Processor
Codefy Hub For IT Solutions
Trading as Codefy Hub
16 Omar Ibn Al Khattab, Sheraton, Cairo, Egypt
Registration# 773819371
Legal: legal@codefyhub.com
Privacy: privacy@codefyhub.com
Customer Controller
The Customer identified in the applicable Order Form or other governing Agreement.
Privacy contact: as provided by Customer.
96. Processing Schedule
The following schedule forms part of this DPA.
Subject Matter
Provision of Codefy Hub and Codefy ERP Services purchased or enabled by Customer.
Duration
For the term of the Agreement and applicable post termination retention, export and deletion periods.
Nature of Processing
Collection where applicable, receipt, recording, organization, storage, retrieval, consultation, transmission, display, calculation, analysis, workflow processing, tracking, reporting, support, security, deletion and other operations necessary to provide the Services.
Purposes
Providing Customer configured ERP, mobile application, transportation, tracking, AI, portal, reporting, workflow and related functionality.
Categories of Data Subjects
Employees, workers, applicants, contractors, Drivers, Riders, students, parents, guardians, school personnel, Transport Provider personnel, customers, suppliers and other individuals whose information Customer lawfully processes through the Services.
Categories of Personal Data
Identity, contact, account, employment, HR, financial, operational, transportation, student, guardian, Driver, Rider, trip, route, location, telematics, device, document and Customer configured information.
Sensitive Personal Data
May include children's information, financial information and other sensitive categories configured by Customer, subject to Applicable Data Protection Law.
Subprocessors
As maintained in the Codefy Subprocessors and Technology Providers List.
97. Security Schedule
Codefy's technical and organizational measures may include, as appropriate to the applicable Services and processing risks:
access control and authentication;
role based authorization;
tenant isolation;
encryption in transit;
encryption at rest where supported by the relevant infrastructure;
secure credential and secret management;
logging and monitoring;
security event detection;
backup and recovery controls;
software development controls;
vulnerability management;
restricted administrative access;
incident response procedures;
availability and continuity measures;
and periodic review of security controls.
For the current Codefy ERP architecture, the security model is expected to include Supabase-hosted database, authentication, storage and realtime services; server side Supabase service-role use only for authorized system or administrative operations; web application and API hosting through the configured deployment provider; and a separate fleet tracking gateway where live transportation tracking is enabled.
Where live tracking is used, gateway access may use short-lived encrypted session tokens, origin restrictions, internal service secrets, provider-side WebSocket connections and limited tracking data transfer to the browser. The gateway should not intentionally send Damoov device tokens, provider JWTs, instance keys, tenant identifiers, user identifiers or raw provider payloads to browser clients.
Where payment functionality is enabled through Paymob or another payment provider, complete payment card credentials should be collected and processed by the payment provider rather than intentionally stored by Codefy, while Codefy may store transaction references, payment tokens, card last-four digits, status and billing metadata where needed for subscription billing, reconciliation, fraud prevention or support.
The specific implementation of these measures may evolve over time as Codefy's architecture, infrastructure and threat environment change.
Codefy shall not materially reduce the overall level of protection for Customer Personal Data during the applicable Service term without reasonable justification.
98. Access Management
Codefy shall limit access to Customer Personal Data to personnel and systems that reasonably require such access.
Access rights should be assigned according to job function, operational necessity and least privilege principles.
Codefy may periodically review privileged or administrative access and revoke access that is no longer necessary.
Customer remains responsible for access permissions assigned to its own Authorized Users.
99. Credential Security
Codefy shall use appropriate technical controls to protect credentials used to access production systems and Customer Personal Data.
Privileged credentials, service secrets, API keys and similar authentication materials should not be intentionally exposed in publicly accessible source code or unsecured locations.
Where a credential is suspected to have been compromised, Codefy shall take reasonable steps to rotate, revoke or otherwise secure it.
100. Encryption in Transit
Codefy shall use secure transmission mechanisms appropriate to the Services when transmitting Customer Personal Data across public networks.
This may include current TLS or equivalent encrypted transport mechanisms.
Where third party Subprocessors receive Customer Personal Data, Codefy shall use provider interfaces and configurations reasonably designed to protect data in transit.
101. Encryption at Rest
Where appropriate to the nature of the data, processing risk and available infrastructure, Codefy shall use encryption or equivalent storage protections for Customer Personal Data stored in Codefy controlled or Codefy appointed infrastructure.
Encryption at rest does not replace the need for access controls, authorization and other security measures.
102. Tenant Isolation
Codefy ERP may operate using shared infrastructure for multiple Customers.
Codefy shall maintain logical and technical controls intended to prevent unauthorized cross tenant access to Customer Personal Data.
These may include tenant identifiers, database access rules, Supabase Row Level Security where configured, authorization checks, role and capability controls, application level restrictions, service side validation, limited browser and mobile DTOs, and separation of system user, Driver, Supervisor and Rider access flows.
103. Logging and Auditability
Codefy may maintain logs relating to:
authentication;
administrative activity;
access;
security events;
system operations;
data changes;
API activity;
and other events reasonably necessary for security, auditability and troubleshooting.
Logging should be designed to avoid unnecessary inclusion of sensitive Customer Personal Data where such data is not required for the logging purpose.
Application diagnostic logging should avoid exposing secrets, credentials, authorization headers, API keys, payment secrets, device tokens, Supabase service-role credentials, full personal identifiers and raw provider payloads where such exposure is not necessary for the logging purpose.
Logs containing Customer Personal Data remain subject to this DPA.
104. Secure Development Practices
Codefy shall maintain reasonable software development practices intended to reduce security vulnerabilities.
These may include:
source control;
peer review;
automated testing;
dependency management;
security testing;
access restrictions;
environment separation;
and controlled deployment processes.
The precise development controls may vary according to the relevant component and risk.
105. Vulnerability Management
Codefy shall maintain processes to identify, assess and remediate material security vulnerabilities affecting the Services.
Remediation priority may take into account:
severity;
exploitability;
affected data;
exposure;
likelihood;
availability of mitigation;
and impact on Customer Personal Data.
Codefy is not required to disclose detailed vulnerability information where disclosure would itself create a material security risk.
106. Dependency and Third Party Security
Codefy may rely on third party libraries, cloud platforms and infrastructure.
Codefy shall maintain reasonable processes for evaluating material dependencies and responding to known security issues where such dependencies affect the Services.
Customer acknowledges that no modern software platform can eliminate all dependency risk.
107. Environment Separation
Where reasonably appropriate, Codefy shall maintain separation between production environments and development or testing environments.
Customer Personal Data should not be copied into non production environments unnecessarily.
Where production Customer Personal Data is required for troubleshooting or testing, appropriate safeguards should be applied.
108. Backup and Recovery
Codefy shall maintain backup or recovery mechanisms appropriate to the Services and Customer subscription.
Backup architecture may vary across Services.
Backups may be used for disaster recovery, operational continuity and restoration following material system failure.
Backup availability does not guarantee recovery of every individual record or transaction unless a specific recovery commitment is stated in an applicable Service Level Agreement or Order Form.
109. Business Continuity
Codefy shall maintain reasonable measures intended to support continuity of material Services following significant technical disruption.
Such measures may include redundancy, backups, infrastructure recovery procedures, provider recovery mechanisms and operational response plans.
Customer remains responsible for maintaining its own continuity procedures for critical business and transportation operations.
110. Incident Response Program
Codefy shall maintain an incident response process appropriate to the nature of the Services.
The process may include:
incident identification;
triage;
containment;
investigation;
remediation;
recovery;
documentation;
and post incident review.
Where a Security Incident affects Customer Personal Data, the notification provisions of this DPA apply.
111. Breach Notification Timing
Where Egyptian Personal Data Protection Law applies, Codefy and Customer shall cooperate so that each party can meet its applicable notification obligations.
Egypt's 2025 Executive Regulations require controllers and processors, as applicable, to notify the Personal Data Protection Center within 72 hours after becoming aware of a qualifying breach or violation.
Because the Customer may need information from Codefy to meet its own regulatory deadline, Codefy shall notify the Customer of a Security Incident affecting Customer Personal Data without undue delay after becoming aware of it.
112. Breach Records
Codefy shall maintain internal records of material Security Incidents affecting Personal Data to the extent required by Applicable Data Protection Law.
Such records may include:
the nature of the incident;
when it was identified;
affected systems;
categories of affected data;
containment measures;
remediation actions;
notification decisions;
and relevant follow up actions.
The Egyptian Executive Regulations require secure recording of breach or violation notifications and related information.
113. Physical Security
Where Codefy directly controls physical facilities containing production infrastructure, Codefy shall apply reasonable physical access restrictions.
Where production infrastructure is hosted by a cloud or data center provider, physical security may be provided by that Subprocessor under its applicable security program.
Codefy shall not represent that it directly operates physical controls belonging to its infrastructure providers.
114. Personnel Security
Codefy shall take reasonable steps to ensure that personnel with access to Customer Personal Data understand their confidentiality and security responsibilities.
Depending on role and risk, measures may include:
confidentiality obligations;
security awareness;
access restrictions;
training;
and disciplinary procedures for material misuse.
115. Secure Disposal
Where Codefy disposes of storage media or infrastructure directly under its control, Customer Personal Data shall be deleted or rendered inaccessible using reasonable methods appropriate to the medium and risk.
Where infrastructure is operated by a Subprocessor, Codefy may rely on that provider's secure deletion and media disposal processes where appropriate.
116. Security Testing
Codefy may perform or commission security testing appropriate to the Services.
This may include:
automated scanning;
application testing;
dependency scanning;
configuration review;
penetration testing;
or other security assessment methods.
The extent and frequency of testing may depend on Service maturity, architecture and risk.
117. Customer Security Information
Codefy may provide Customer with reasonable information about its security practices through documentation, questionnaires, audit materials or other compliance resources.
Codefy is not required to disclose information that would materially compromise the security of Codefy, another Customer, or a Subprocessor.
118. Customer Security Notifications
Customer shall notify Codefy without undue delay if Customer becomes aware of:
compromised Customer credentials;
unauthorized Customer accounts;
misconfigured access;
security incidents involving Customer systems that may affect Codefy;
or unlawful access to Customer Personal Data through Customer controlled systems.
The parties shall cooperate where a security issue spans both Codefy and Customer controlled environments.
119. Customer Device Security
Customer is responsible for securing devices used by its Authorized Users, including Driver, Supervisor and Rider devices where applicable.
Customer should maintain appropriate controls regarding:
device access;
screen locks;
account removal;
lost devices;
malware;
operating system updates;
and unauthorized device sharing.
Codefy may provide application security functionality but does not manage every Customer device unless specifically contracted to do so.
120. Mobile Security
Codefy may implement measures intended to reduce mobile application risk, including secure API communication, authentication controls, token expiration, permission management and device specific security features.
The precise controls may differ between Driver, Supervisor and Rider applications according to their functionality and risk profile.
121. Telemetry Security
Where telematics information is transmitted between a Driver device, tracking provider and Codefy systems, Codefy shall use reasonable technical measures intended to protect the transmission and access to such data.
Where Codefy uses a separate fleet tracking gateway, that gateway may validate short-lived access tokens, retrieve only authorized active trip context, filter provider updates to permitted trips and send limited safe tracking information to authorized browser clients.
The security of a third party telematics provider's own systems is subject to that provider's security controls and Codefy's applicable Subprocessor obligations.
122. Location Data Security
Because location information can create elevated privacy risk, access to identifiable or linkable location information should be limited to users and systems reasonably requiring it.
Customer is responsible for restricting location visibility within its organization to appropriate Authorized Users.
Codefy may implement technical scoping, role controls, limited public share views or other safeguards where appropriate.
123. Student Data Security
Codefy shall apply heightened care to Customer Personal Data concerning children where such information is processed through the Services.
Where reasonably practicable, access should be limited according to role and purpose, and unnecessary transmission of identifiable student information to third party tracking systems should be avoided.
Customer remains responsible for defining which of its personnel and guardians should have access to student transportation records.
124. Changes to Security Measures
Codefy may modify its technical and organizational security measures over time to reflect changes in:
technology;
architecture;
risk;
regulatory requirements;
provider capabilities;
or security practices.
Such changes shall not intentionally result in a material reduction in the overall protection of Customer Personal Data during an active subscription without reasonable justification.
125. Compliance Transition Under Egyptian Law
The parties acknowledge that Egypt's Executive Regulations under Ministerial Decision No. 816 of 2025 entered into force in November 2025 and introduced detailed operational requirements for controllers and processors, including licensing, DPO, security, breach management and international transfer requirements. Current legal commentary indicates a statutory transition period running to November 1, 2026 for covered organizations to regularize their processing activities.
Each party shall be responsible for completing regulatory steps legally applicable specifically to that party.
126. No Reduction of Mandatory Rights
Nothing in this DPA limits or excludes rights or obligations that cannot lawfully be limited under Applicable Data Protection Law.
If a provision of this DPA conflicts with a mandatory requirement of Applicable Data Protection Law, the mandatory requirement shall apply to the extent of the conflict.
127. Severability
If any provision of this DPA is found invalid or unenforceable, the remaining provisions shall continue in effect.
The invalid provision shall, where legally permitted, be interpreted or modified to achieve its intended purpose as closely as possible while remaining lawful.
128. Entire Processing Agreement
This DPA, together with the Agreement and documents expressly incorporated into it, constitutes the parties' agreement concerning Codefy's processing of Customer Personal Data on Customer's behalf.
No informal statement or product description modifies this DPA unless incorporated into a written agreement between the parties.
129. Execution
This DPA may be incorporated by reference into the Codefy Hub Terms, an Order Form or another written agreement.
A separately signed copy is not required where the governing commercial agreement validly incorporates this DPA and applicable law permits such incorporation.
Where Customer requires a signed DPA for procurement or regulatory purposes, the parties may execute a counterpart identifying the relevant Customer legal entity.
130. Final Processing Details
For clarity, the parties confirm that the Processing Schedule, Security Schedule, Subprocessor List and applicable Order Form together may provide the operational details necessary to understand the processing performed through the Services.
Where Customer purchases additional modules or enables materially different processing, the processing description may be updated through the applicable Service documentation or Order Form without requiring complete replacement of this DPA, provided the updated processing remains governed by this DPA.
