CODEFY HUB PRIVACY POLICY
Version: 1.0
Effective Date: 1st August 2025
Last Updated: 1st August 2026
This Privacy Policy explains how Codefy Hub For IT Solutions, trading as Codefy Hub, collects, uses, stores, discloses and otherwise processes personal data in connection with Codefy Hub websites, Codefy ERP, portals, applications, services and business operations.
In this Privacy Policy, “Codefy,” “Codefy Hub,” “we,” “us,” and “our” refer to Codefy Hub For IT Solutions
This Privacy Policy should be read together with, where applicable, the Codefy Hub Terms of Service, Codefy ERP Service Terms, Mobile Application Privacy Notice, Data Processing Addendum, and Subprocessors and Technology Providers list.
1. Scope
This Privacy Policy applies to personal data processed by Codefy in connection with:
the Codefy Hub website;
Codefy ERP;
Codefy accounts;
business and sales enquiries;
customer administration;
support;
Codefy portals;
mobile applications;
Codefy AI functionality;
transportation technology;
tracking functionality;
and other Codefy services.
Certain processing performed through Codefy ERP is conducted on behalf of Codefy Customers. In those situations, the Customer may be the organization primarily responsible for determining why and how the personal data is processed.
2. Codefy's Privacy Roles
Codefy may process personal data in different legal capacities depending on the circumstances.
Codefy as Controller
Codefy may determine the purposes and means of processing for information relating to its own business operations.
Examples may include:
website enquiries;
prospective customer information;
business contacts;
Customer account administration;
billing contacts;
Codefy security operations;
legal compliance;
service communications;
and permitted marketing activities.
For these activities, Codefy may act as a controller.
Codefy as Processor
Customers may use Codefy ERP to process information concerning their own employees, students, parents, guardians, Drivers, Riders, customers, suppliers, contractors and other individuals.
Where a Customer determines why and how such information is processed and Codefy processes it on the Customer's instructions, Codefy generally acts as processor.
The Customer is responsible for its obligations as controller, including establishing the appropriate lawful basis for processing.
Codefy's processor obligations are further described in the Data Processing Addendum.
3. Who May Be Covered by This Policy
Depending on the Services used, personal data may relate to:
website visitors;
prospective customers;
Customer representatives;
Authorized Users;
employees;
job applicants;
contractors;
Drivers;
Riders;
students;
parents;
guardians;
school personnel;
transportation supervisors;
Transport Provider personnel;
suppliers;
Customer customers;
and other individuals whose information is processed through Codefy.
4. Personal Data We May Process
The categories of information processed depend on the Services and functionality used.
Identity Information
This may include:
name;
username;
employee identifier;
student identifier;
Driver identifier;
Customer or supplier identifier;
profile information;
and other identifiers.
Contact Information
This may include:
email address;
telephone number;
business contact information;
address;
emergency contact information;
and guardian contact information.
Account Information
This may include:
account identifier;
organization;
role;
permissions;
authentication information;
login activity;
account status;
and security related information.
Codefy does not need or intend to store plaintext account passwords.
Authentication credentials should be processed using appropriate authentication and security mechanisms.
5. Organizational and Employment Information
Where enabled by a Customer, Codefy ERP may process information concerning:
employment;
department;
job title;
manager;
attendance;
leave;
work schedule;
compensation related records;
HR documents;
organizational assignments;
and other employment related information.
The Customer determines which HR information it chooses to process through the Services.
6. Financial and Commercial Information
Codefy ERP may process financial or commercial records supplied by Customers.
These may include:
invoices;
expenses;
payments;
purchase orders;
supplier information;
pricing;
accounting records;
financial transactions;
and related business information.
Where a third party payment processor handles payment credentials directly, Codefy may receive transaction status, reference information or limited payment metadata rather than full card information.
The applicable payment provider will be identified in the Subprocessors and Technology Providers list where appropriate.
7. Transportation Information
Where transportation functionality is enabled, Codefy may process information relating to:
Drivers;
vehicles;
Transport Providers;
Riders;
routes;
stops;
schedules;
trips;
projects;
pickup locations;
drop off locations;
attendance;
boarding;
transportation status;
vehicle assignment;
Driver assignment;
and transportation related operational records.
8. Location and Telematics Information
Certain transportation functionality may process location and telematics information.
Depending on the application and enabled functionality, this may include:
GPS coordinates;
timestamps;
speed;
heading;
location accuracy;
motion information;
device identifiers;
trip information;
Driver or vehicle association;
and related operational information.
The actual data processed depends on the application and tracking implementation.
The Mobile Application Privacy Notice provides application specific details.
9. Driver Tracking
Where tracking is enabled, the Driver App may collect or process precise location and related information during transportation operations.
Tracking may continue in the background where the user has granted the necessary permissions and tracking functionality is enabled.
Codefy's current Driver application includes functionality requiring precise and background location, activity recognition and persistent location services.
This information may be used to provide:
trip detection;
live vehicle location;
fleet visibility;
trip recording;
route progress;
transportation monitoring;
and related operational functionality.
10. Rider Location
Rider location is conceptually different from persistent Driver tracking.
The Rider App may provide optional features that use the location of the user's own device.
For example, a Rider, employee, student, parent or guardian may choose to use location to:
identify their current position;
find a pickup point;
view relevant nearby transportation information;
or use another location based feature.
Where location access is optional, the user may choose whether to grant the required device permission.
Unless separately disclosed and enabled, installation of the Rider App does not mean Codefy continuously tracks the Rider's device.
11. Supervisor Location and Device Permissions
The Supervisor App may process location where required for enabled field or transportation functionality.
It may also request access to camera or images where features such as QR scanning or image uploads are used.
The current Android Supervisor application declares background and foreground location functionality, camera access and media access.
Detailed permission information will be provided in the Mobile Application Privacy Notice.
12. Camera and Images
Certain Codefy applications may request camera or image access.
Depending on the application, these permissions may be used for:
QR code scanning;
document capture;
profile or operational images;
uploading evidence;
or other user initiated functionality.
Codefy will not describe camera access as being used for purposes that are not actually implemented.
Users may deny optional permissions, although associated functionality may then be unavailable.
13. Device and Technical Information
Codefy may process technical information necessary to operate and secure the Services.
This may include:
device type;
operating system;
application version;
browser information;
IP address;
session information;
device or application identifiers;
push notification tokens;
error information;
security logs;
and diagnostic information.
14. Student Information
Where Codefy ERP is used for student transportation, the Customer may process student information through the platform.
Depending on configuration, this may include:
student name;
student identifier;
school;
class or grade where required;
route;
pickup and drop off information;
trip information;
attendance;
transportation status;
authorized guardian relationships;
and related transportation information.
Customers should configure Codefy ERP to process only information necessary for their legitimate student transportation purposes.
15. Parent and Guardian Information
Student transportation functionality may process information relating to authorized parents and guardians.
This may include:
name;
contact information;
relationship to the student;
account information;
authorization information;
and transportation related communications.
Schools and other Customers are responsible for accurately establishing and maintaining guardian relationships where they act as controller.
16. Children's Personal Data
Student information may constitute children's personal data and may receive enhanced protection under applicable law.
Where a school or other Customer determines the purposes of processing student information through Codefy ERP, the Customer is generally responsible for establishing an appropriate lawful basis and obtaining guardian authorization or consent where required.
Codefy will process such information according to the Customer's documented instructions where Codefy acts as processor, subject to applicable law and the DPA.
Where Codefy itself is legally required to obtain or record a particular authorization, Codefy will implement appropriate mechanisms.
17. Data Minimization for Student Tracking
Codefy seeks to avoid unnecessary disclosure of identifiable student information to third party tracking providers.
Where technically practicable, telematics information should be associated with a Driver, vehicle, device or trip identifier rather than transmitted to a tracking provider together with unnecessary student identity information.
Codefy may associate the tracked trip with authorized student information internally where necessary to provide student transportation functionality.
18. Information Provided Directly to Us
We may receive personal data when an individual:
creates an account;
contacts Codefy;
requests a demonstration;
submits a support request;
communicates with sales;
uses the website;
uses a Codefy application;
provides information through a form;
or otherwise interacts directly with Codefy.
19. Information Provided by Customers
A substantial amount of information processed through Codefy ERP may be provided by Customer organizations rather than directly by the individual.
For example, an employer may provide employee information, a Transport Provider may provide Driver information, or a School may provide authorized student transportation information.
If an individual has questions about information that their employer, school or another Customer has placed into Codefy ERP, the Customer may be the appropriate first point of contact where it acts as controller.
20. Information Generated Through Use
Codefy may generate operational information as users interact with the Services.
This may include:
audit records;
workflow history;
login events;
trip records;
system activity;
status changes;
notifications;
tracking events;
security events;
and diagnostic information.
21. Information From Third Party Services
Where enabled, Codefy may receive information from integrated services.
These may include:
tracking providers;
map providers;
payment processors;
AI providers;
authentication providers;
communications services;
Customer selected integrations;
and other technology providers.
The information received depends on the integration.
22. Why We Process Personal Data
Depending on Codefy's legal role and the applicable Service, personal data may be processed to:
provide the Services;
authenticate users;
manage accounts;
operate ERP functionality;
perform Customer configured workflows;
provide transportation functionality;
provide tracking;
send notifications;
provide support;
maintain security;
prevent fraud or abuse;
process billing;
improve reliability;
comply with law;
respond to legal requests;
and protect Codefy, Customers and users.
23. Customer Directed Processing
Where Codefy acts as processor, Codefy processes Customer Personal Data according to the Customer's documented instructions, including instructions inherent in the Customer's use and configuration of the Services.
Codefy does not independently determine the Customer's underlying business purpose for such processing except where required to operate, secure or legally administer the Services.
24. Legal Bases
Where Codefy acts as controller and applicable law requires a legal basis, processing may be based on:
performance of a contract;
steps requested before entering a contract;
compliance with legal obligations;
legitimate interests where permitted;
consent where required;
and other lawful grounds recognized by applicable law.
The appropriate basis depends on the processing activity.
25. Consent
Where processing requires consent, Codefy or the applicable Customer should provide appropriate information before obtaining consent.
Where Codefy relies on consent for processing under its control, individuals may withdraw consent as permitted by applicable law.
Withdrawal does not affect processing lawfully conducted before withdrawal.
Certain Services may be unavailable where information or permissions necessary to provide them are not supplied.
26. Mobile Permissions
Mobile operating systems require users to authorize certain categories of device access.
Depending on the application, Codefy may request permissions relating to:
location;
background location;
activity recognition;
camera;
images;
notifications;
biometric authentication;
and other device functionality.
Not every application requests every permission.
The Mobile Application Privacy Notice describes the applicable permission set for each Codefy application.
27. Damoov and Telematics Processing
Codefy currently uses Damoov technology in certain transportation tracking functionality.
Codefy's implementation provisions tenant specific Damoov integrations and may associate Damoov device tokens with Drivers or active trips.
The tracking gateway may receive coordinates, speed, heading, accuracy and timestamps and associate them with authorized Codefy transportation information.
Damoov describes its telematics technology as processing information such as GPS, motion and trip related information and describes institutional customers as controllers in applicable processing contexts. Damoov Privacy Policy
Codefy will identify Damoov in its Subprocessors and Technology Providers list while Damoov is used as a relevant provider.
28. Artificial Intelligence Processing
Certain Codefy functionality may use artificial intelligence.
Where a user invokes an AI feature, information necessary to fulfill that request may be processed by Codefy and, where applicable, an authorized AI technology provider.
The categories of information depend on the AI feature and Customer configuration.
Codefy will seek to limit information transmitted to AI providers to what is reasonably necessary for the relevant functionality.
Where AI providers process Customer Personal Data on Codefy's behalf, they should be addressed through the applicable processor and subprocessor framework.
29. AI and Sensitive Information
Customers should not intentionally submit unnecessary sensitive personal data to AI functionality.
Where an AI feature is designed to process particular Customer Data, Customer remains responsible for determining that such processing is appropriate and lawful.
Codefy may implement technical or contractual safeguards concerning AI processing.
30. How We Share Personal Data
Codefy does not disclose personal data indiscriminately.
Information may be disclosed:
to Customer Authorized Users according to configured permissions;
to service providers and subprocessors;
to Customer selected integrations;
where directed by the Customer;
where required by law;
to protect legal rights or security;
in connection with a corporate transaction subject to appropriate safeguards;
or with the individual's authorization where appropriate.
31. Subprocessors and Technology Providers
Codefy uses technology providers to operate portions of its Services.
Depending on enabled functionality, these may include providers of:
cloud infrastructure;
database services;
authentication;
communications;
maps;
tracking and telematics;
AI;
payments;
and other infrastructure.
Codefy will maintain a Subprocessors and Technology Providers page identifying material providers where appropriate.
32. Third Party Integrations Selected by Customers
Customers may independently connect Codefy ERP to third party services.
Where a Customer chooses such an integration, information may be transmitted according to the Customer's instructions.
Those third parties may process information under their own terms and privacy practices.
Customer should evaluate such providers before enabling them.
33. International Processing and Transfers
Codefy and its technology providers may process information in countries other than the country in which an individual is located.
Where Egyptian personal data is transferred or processed outside Egypt, Codefy will address applicable cross border transfer requirements under Egyptian data protection law and its Executive Regulations.
The applicable DPA and Subprocessor List will provide additional information for Customer controlled data.
34. Data Retention
Codefy retains personal data only for periods reasonably necessary for the purposes for which it is processed, contractual requirements, legitimate security and operational needs, dispute resolution and applicable legal obligations.
Retention periods vary according to the type of information and Codefy's role.
Where Codefy acts as processor, Customer Data retention is governed by the Customer's instructions, applicable subscription, DPA, technical backup cycle and legal requirements.
35. Tracking Data Retention
Tracking data may have different retention periods from ordinary ERP records.
Retention may depend on:
Customer configuration;
operational requirements;
applicable law;
Codefy configuration;
and the applicable tracking provider.
Codefy will not state a third party provider retention period that is inconsistent with Codefy's actual contractual or configured arrangement.
36. Damoov Retention
Damoov's public documentation describes different retention periods for different telematics data types and service configurations.
Accordingly, Codefy will maintain retention based on its applicable Damoov service configuration rather than representing that one universal Damoov retention period applies to every Customer.
Damoov's applicable privacy and service documentation can be reviewed through its official legal materials. Damoov legal privacy information
37. Deletion
Personal data may be deleted when:
it is no longer required;
the applicable Customer instructs deletion where Codefy acts as processor;
an applicable retention period expires;
an account or subscription is terminated;
or deletion is required under applicable law.
Certain information may be retained where necessary for legal compliance, fraud prevention, security, dispute resolution or establishment, exercise or defense of legal claims.
38. Backups
Deleted information may remain temporarily in protected backups until those backups are overwritten according to Codefy's backup cycle.
Backup information is not intended to be restored into active production systems except for legitimate disaster recovery or continuity purposes.
39. Security
Codefy implements technical and organizational measures intended to protect personal data against unauthorized access, loss, alteration, disclosure or destruction.
Measures may include, as appropriate:
access controls;
authentication;
role based permissions;
encryption;
secure communications;
logging;
monitoring;
tenant isolation;
backup controls;
software security practices;
and incident response procedures.
No information system can guarantee absolute security.
40. Tenant Isolation
Codefy ERP is designed as a multi tenant platform.
Codefy implements technical controls intended to restrict Customers to information associated with their authorized tenant, applications and permissions.
Customers remain responsible for properly configuring their own users and roles.
41. Security Incidents
Codefy maintains procedures intended to identify, investigate, contain and respond to suspected or confirmed security incidents involving personal data.
A personal data breach may include unauthorized access to, acquisition of, disclosure of, alteration of, loss of, destruction of or inability to access personal data where the event affects the confidentiality, integrity or availability of that information.
Where Codefy acts as controller, Codefy will evaluate the incident and take the actions required under applicable data protection law.
Where Codefy acts as processor for a Customer, Codefy will notify the affected Customer in accordance with the applicable Data Processing Addendum and applicable law and will provide reasonably available information necessary for the Customer to satisfy its own legal obligations.
Under Egypt's current Personal Data Protection framework, qualifying breaches or violations may require notification to the Personal Data Protection Center within 72 hours from awareness. The required notification can include the nature and time of the incident, affected records, potential consequences, corrective measures and relevant data protection contact information.
Where notification to affected individuals is legally required, Codefy or the applicable Customer will provide notification according to the parties' respective legal roles and obligations.
42. Incident Cooperation With Customers
Where Codefy processes Customer Personal Data on behalf of a Customer, Codefy will reasonably cooperate with that Customer in investigating a qualifying personal data incident relating to Codefy controlled systems.
Such cooperation may include, where reasonably available:
information regarding the nature of the incident;
categories of information affected;
approximate scope;
known or anticipated consequences;
containment actions;
remediation measures;
and information reasonably necessary for applicable regulatory notifications.
Codefy's cooperation does not transfer the Customer's independent legal responsibilities as controller to Codefy.
43. Data Subject Rights
Individuals may have rights concerning their personal data under applicable law.
Depending on the circumstances and applicable law, these may include rights to:
access personal data;
request correction or completion;
request deletion where legally available;
object to or restrict certain processing;
withdraw consent where processing is based on consent;
request information about processing;
and submit complaints to the competent authority.
Egypt's current regulatory framework requires controllers to maintain procedures and records concerning requests to add, modify or erase personal data and mechanisms for informing the affected person.
Not every right applies in every circumstance.
Certain requests may be limited where retention or continued processing is required by law, necessary for legal claims, necessary to protect another person's rights or otherwise permitted by applicable law.
44. Exercising Rights Where Codefy Is Controller
Where Codefy acts as controller, individuals may submit applicable privacy requests to:
privacy@codefyhub.com
or through any privacy request mechanism made available by Codefy.
Codefy may request information reasonably necessary to verify the identity and authority of the person making the request before disclosing, modifying or deleting personal data.
This verification protects individuals from unauthorized access to their information.
Codefy will respond according to the time periods required by applicable law.
45. Requests Concerning Customer Controlled Data
Where Codefy processes personal data on behalf of a Customer, such as an employer, school, enterprise or Transport Provider, that Customer normally determines how a data subject request should be handled.
Individuals should generally direct such requests to the applicable Customer.
If Codefy receives a request relating to Customer controlled data, Codefy may refer the individual to the relevant Customer and, where appropriate, notify the Customer of the request.
Codefy will provide reasonable assistance to the Customer as required under the Data Processing Addendum and applicable law.
46. Identity Verification
Before responding to a privacy request, Codefy or the applicable Customer may need to verify the requester's identity.
Verification measures should be proportionate to the sensitivity of the information and the nature of the request.
Codefy will not intentionally disclose personal data solely because someone claims to be the person concerned without reasonable verification where verification is appropriate.
For student information, guardian information or information associated with another person's account, additional authorization checks may be required.
47. Correction of Personal Data
Individuals may request correction of inaccurate personal data where applicable.
Where information was provided and controlled by a Customer, such as an employer or school, Codefy may require the Customer to authorize or perform the correction.
Certain historical operational records may need to be preserved where modification would undermine audit integrity, financial records, legal obligations or legitimate dispute records.
In those circumstances, a corrected or supplementary record may be maintained instead of altering historical information.
48. Deletion Requests
Individuals may request deletion of personal data where permitted under applicable law.
A deletion request may not require immediate deletion where the information must be retained for:
legal or regulatory obligations;
financial recordkeeping;
security;
fraud prevention;
legal claims;
audit integrity;
contractual obligations;
or another lawful retention purpose.
Where Codefy acts as processor, deletion is generally performed according to Customer instructions and the Data Processing Addendum.
49. Withdrawal of Consent
Where Codefy relies on consent as the legal basis for processing under Codefy's control, the individual may withdraw consent in accordance with applicable law.
Withdrawal applies prospectively and does not invalidate processing lawfully performed before withdrawal.
If consent is necessary to provide a particular optional feature, withdrawing consent may result in the feature becoming unavailable.
For example, withdrawal of optional Rider location permission may prevent location based Rider functionality from operating.
50. Mobile Permission Controls
Mobile users can generally manage device permissions through their mobile operating system.
Depending on the application, this may include:
location;
background location;
camera;
photos or media;
notifications;
motion or activity recognition;
and biometric functionality.
The effect of disabling a permission depends on the relevant feature.
For example, disabling Driver background location may prevent continuous trip tracking from functioning properly, while declining optional Rider location access should affect only location dependent Rider functionality.
The separate Mobile Application Privacy Notice provides more detail.
51. Marketing Communications
Codefy may send commercial communications to business contacts where permitted by applicable law.
Recipients may unsubscribe from optional marketing communications using the unsubscribe mechanism included in the communication or by contacting Codefy.
Unsubscribing from marketing does not prevent Codefy from sending necessary transactional, security, account, billing or Service related communications.
Where electronic marketing consent or authorization is required under Egyptian law, Codefy will implement the applicable requirements.
52. Cookies and Similar Technologies
The Codefy website and web applications may use cookies, browser storage or similar technologies where necessary to:
authenticate users;
maintain sessions;
remember preferences;
protect security;
measure Service operation;
and support permitted analytics.
Where legally required, Codefy will provide appropriate notice or consent mechanisms for non essential cookies or similar tracking technologies.
A separate Cookie Notice may be provided if Codefy's website use of cookies becomes sufficiently extensive to justify one.
53. Analytics
Codefy may use analytics to understand Service performance, usage patterns, errors and product reliability.
Where analytics information relates to an identifiable or identifiable individual, it will be handled according to this Privacy Policy.
Codefy should prefer aggregated or deidentified analytics where personal identification is not required.
Any external analytics provider that processes personal data on Codefy's behalf should be addressed in the applicable Subprocessor and Technology Provider framework.
54. Deidentified and Aggregated Information
Codefy may generate statistical, aggregated or deidentified information from use of the Services where permitted by applicable law and contractual commitments.
Codefy may use information that no longer identifies an individual or Customer for purposes such as:
security analysis;
product performance;
service improvement;
capacity planning;
research;
and business analytics.
Codefy will not represent information as anonymous or deidentified where it remains reasonably capable of being linked back to an identifiable individual.
55. Product Improvement
Codefy may use operational, diagnostic and usage information to maintain and improve the Services where permitted by the Agreement and applicable law.
Where Customer Personal Data is processed on behalf of a Customer, Codefy's use is subject to the Data Processing Addendum and applicable Customer instructions.
Codefy should not use Customer confidential business records for unrelated purposes merely because the records are technically accessible to the platform.
56. Artificial Intelligence and Model Training
Where third party AI services are used, Codefy will seek to configure such services consistently with Codefy's contractual and privacy obligations.
Whether information submitted through an AI feature may be retained or used by an AI provider depends on the applicable provider, service tier and contractual configuration.
Codefy will not state that Customer Data is never used for model training unless that statement is accurate for the specific AI providers and service arrangements actually used.
Material AI technology providers will be identified through the Subprocessors and Technology Providers framework where appropriate.
57. Automated Decisions
Certain Codefy ERP functionality may assist Customers with automated workflows, recommendations or AI generated outputs.
Unless Codefy expressly determines the purpose of an automated decision itself, Customer configured business decisions generally remain under the Customer's control.
Customers are responsible for ensuring that automated decisions affecting employment, students, financial interests, legal rights, transportation safety or other significant interests comply with applicable law and include appropriate human oversight.
Codefy may restrict functionality that it reasonably determines creates unacceptable legal, privacy, security or safety risk.
58. Sensitive Personal Data
Certain information processed through Codefy ERP may constitute sensitive personal data under applicable law.
Depending on Customer configuration, this may include information relating to:
children;
financial information;
biometric information;
health information;
criminal history;
or other categories designated as sensitive by law.
Customers should avoid collecting sensitive information that is unnecessary for the purpose for which Codefy ERP is being used.
Processing sensitive personal data may require enhanced safeguards, explicit consent or regulatory permits under Egyptian law. Egypt's current framework treats children's data and several other categories as sensitive and establishes licensing and permit requirements for certain processing.
59. Biometric Functionality
Some Codefy applications may support biometric authentication provided by the user's device, such as fingerprint or facial authentication.
Where biometric authentication is handled locally by the mobile operating system, Codefy may receive confirmation that authentication succeeded without receiving the underlying biometric template itself.
Codefy should clearly distinguish local device biometric authentication from any future feature that would itself collect or store biometric templates.
If Codefy introduces direct biometric processing, this Privacy Policy and the applicable notices must be updated before such processing occurs.
60. Student and Children's Data Rights
Where a request relates to student or children's personal data, Codefy may need to verify the authority of the parent, guardian, school or other person making the request.
The applicable Customer may remain the appropriate controller for requests concerning student records.
Codefy will not knowingly provide a student's personal information to a person merely claiming to be a guardian without appropriate authorization mechanisms.
Where applicable law gives a child independent rights at a particular age, Codefy and the Customer should implement the relevant legal requirements.
61. Parent and Guardian Location
Where a parent or guardian uses optional Rider App location functionality, any location obtained from the parent's own device should be treated separately from the student's transportation records.
The parent's device location should only be used for the location based purpose disclosed to the user unless another lawful purpose is clearly communicated.
Use of the Rider App by a parent does not authorize continuous background tracking of the parent unless such functionality is separately disclosed, lawfully enabled and consented to where required.
62. Employee Monitoring and Driver Tracking
Codefy provides technology that Customers may use in employment or contractor contexts, including Driver tracking.
Codefy does not determine whether a particular Customer's employee monitoring practice is lawful merely by providing the technology.
Customers using location, attendance, telematics or monitoring functionality are responsible for complying with applicable labor, privacy and workplace requirements, including providing required notices and obtaining consent or authorization where necessary.
Codefy will provide information reasonably necessary for Customers to understand the functionality they enable.
63. Location Data Visibility
Location information may be visible to authorized Customer users according to role based permissions and the particular transportation workflow.
Potential viewers may include, where authorized:
Customer administrators;
transport operations personnel;
supervisors;
Transport Providers;
enterprise personnel;
school personnel;
Riders;
parents;
guardians;
and recipients of authorized trip sharing.
The precise information available to each user type depends on the functionality and permissions configured.
Customer is responsible for ensuring organizational access remains appropriate.
64. Public or Shared Tracking Links
Where Codefy provides limited trip sharing links, the information displayed should be restricted to what is reasonably required for the sharing purpose.
Users must not distribute tracking links beyond intended recipients.
Codefy may apply expiration periods, restricted data views or other controls to reduce the risk of unauthorized access.
Codefy's current tracking implementation already distinguishes limited public share views from broader authenticated fleet visibility.
65. Location Accuracy
Location information should not be assumed to be perfectly accurate or continuously available.
GPS, networks, maps, device settings, provider availability, battery restrictions and environmental conditions can affect accuracy and availability.
Privacy related location records should therefore be understood as technical measurements rather than definitive proof that an individual was at an exact place at an exact moment.
66. Third Party Websites and Services
The Services may contain links to or integrations with third party websites, applications or services.
Where an individual leaves Codefy controlled Services and interacts directly with an independent third party, that party's privacy practices may apply.
Codefy is not responsible for the privacy practices of independent third parties merely because Codefy provides a link to them.
This does not affect Codefy's responsibility for subprocessors appointed by Codefy.
67. Corporate Transactions
If Codefy is involved in a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, personal data may be disclosed to relevant advisers, potential counterparties and successors where reasonably necessary and subject to appropriate confidentiality and legal safeguards.
Where required by law, affected individuals or Customers will be notified of material changes in controller identity or processing.
68. Legal Requests and Compliance
Codefy may disclose personal data where required by applicable law, valid court order, regulatory requirement or lawful governmental request.
Codefy may also process or preserve information where reasonably necessary to:
establish or defend legal rights;
investigate fraud;
protect users;
protect Codefy infrastructure;
respond to security threats;
or comply with legal obligations.
Where legally permitted and appropriate, Codefy may notify the affected Customer of a legal request concerning Customer Data.
69. Government and Regulatory Authorities
Codefy may cooperate with the Egyptian Personal Data Protection Center and other competent authorities as required by applicable law.
The 2025 Executive Regulations establish the Personal Data Protection Center's operational regulatory role, including licensing, compliance oversight and breach reporting mechanisms.
Codefy will maintain records and documentation required by applicable data protection obligations.
70. Data Protection Officer
Where required by applicable Egyptian data protection law, Codefy will appoint or designate a Data Protection Officer or other responsible privacy official and complete applicable registration requirements.
Current commentary on the Egyptian framework identifies DPO appointment and registration with the Personal Data Protection Center among the organizational requirements for covered legal entities.
Privacy enquiries may be sent to privacy@codefyhub.com.
If Codefy is legally required to publish additional Data Protection Officer details, Codefy will publish those details through this Privacy Policy or another appropriate privacy notice.
71. Regulatory Licenses and Permits
Codefy intends to obtain and maintain licenses, permits, registrations or authorizations required under applicable Egyptian personal data protection law for the processing activities it performs.
The 2025 Executive Regulations introduced a more detailed licensing framework for controllers and processors and for certain categories of processing, including sensitive data and international transfers.
Where Codefy is required to publish specific license, permit or registration information, Codefy will update this Privacy Policy or another appropriate Customer facing privacy notice.
72. Cross Border Transfer Safeguards
Where personal data is transferred outside Egypt, Codefy will implement applicable safeguards and authorization mechanisms required by Egyptian law.
Depending on the circumstances, these may include regulatory authorization, appropriate contractual arrangements, assessment of the destination jurisdiction or other permitted mechanisms.
Codefy's Data Processing Addendum will provide additional contractual treatment for international processing performed on behalf of Customers.
73. Processing Locations
Codefy's Services may use infrastructure or technology providers located in more than one country.
Because the precise processing location can depend on the Service, provider and Customer configuration, Codefy should maintain current provider and processing location information through the Subprocessors and Technology Providers page rather than hard coding every provider location into this Privacy Policy.
74. Changes to Technology Providers
Codefy may add, remove or replace technology providers as its Services evolve.
Where a change materially affects processing of Customer Personal Data, Codefy will comply with applicable notification or contractual obligations under the DPA.
Replacement of a provider does not permit Codefy to disregard applicable data protection requirements.
75. Changes to This Privacy Policy
Codefy may update this Privacy Policy to reflect changes in:
law;
regulation;
Services;
technology;
data processing activities;
technology providers;
or privacy practices.
The updated version will identify its effective date.
Where a change materially affects individuals' rights or the processing of existing Customer Personal Data, Codefy will provide additional notice where required by applicable law or contract.
76. Previous Versions
Codefy should maintain archived versions of this Privacy Policy where reasonably appropriate.
Maintaining historical versions helps Customers and individuals determine which privacy terms applied at an earlier time.
77. Complaints
Individuals may contact Codefy with concerns about how their personal data is processed.
Codefy will review privacy complaints according to its applicable legal obligations and internal procedures.
Where Codefy acts only as processor for a Customer, Codefy may refer a complaint to the applicable Customer.
Individuals may also have the right to submit a complaint to the Egyptian Personal Data Protection Center or another competent supervisory authority as provided by applicable law.
78. Contact Codefy About Privacy
Privacy questions, requests or concerns may be submitted to:
Codefy Hub For IT Solutions
Trading as Codefy Hub
16 Omar Ibn Al Khattab, Sheraton, Cairo, Egypt
Registration# 773819371
Legal: legal@codefyhub.com
Privacy: privacy@codefyhub.com
Website: www.codefyhub.com
79. Customer Privacy Contacts
Where an individual's data was supplied to Codefy by an employer, school, Transport Provider or another Customer, that organization may be the controller and the appropriate first point of contact.
Codefy may assist the Customer with the request according to the Data Processing Addendum.
80. Governing Privacy Framework
Codefy's privacy practices are intended to operate in accordance with applicable privacy and data protection laws, including the Egyptian Personal Data Protection Law No. 151 of 2020 and its Executive Regulations issued pursuant to Ministerial Decision No. 816 of 2025.
The Executive Regulations entered into force on November 2, 2025 and provide detailed requirements regarding controller and processor obligations, security incidents, data subject rights, licensing and international transfers.
Where another mandatory law applies to a particular Customer, individual or processing activity, Codefy will address such requirements as required by applicable law and contract.
81. Relationship With Other Codefy Legal Documents
This Privacy Policy should be read together with the other Codefy legal documents applicable to the relevant Service.
These may include:
the Codefy Hub Terms of Service;
the Codefy ERP Service Terms;
the Mobile Application Privacy Notice;
the Data Processing Addendum;
and the Subprocessors and Technology Providers List.
If Codefy processes personal data on behalf of an enterprise Customer, the DPA governs the processor relationship between Codefy and that Customer.
The Mobile Application Privacy Notice provides more detailed application specific information about Driver, Supervisor and Rider permissions and device processing.
