Privacy Policy
Last updated: [DATE ON PUBLICATION]
1. Who we are
Heritage Egypt (the “Platform”) operates heritage-egypt.info and its subsites, including Old Cairo and E-Cards, with more to follow.
- Data controller: Yasser El-Shayeb / Heritage Egypt — [registered entity name, address].
- Developer / data processor: Rafeek Ghaly, [company name], who builds and operates the technical infrastructure on the controller’s behalf.
- Per-subsite data owners: some datasets are owned by third parties and used under licence or partnership (for example, original postcard and heritage data attributed to [UNESCO / Louvre / Yasser El-Shayeb / other]). Where a subsite is governed by a distinct data owner, an addendum to this policy identifies them.
Privacy contact: [privacy@heritage-egypt.info or other].
2. What data we collect
- Server logs: IP address, browser/user-agent, pages requested, timestamps — recorded automatically by our web server for security and reliability.
- Analytics: aggregate, cookieless usage statistics (page views, referrers, country) that do not identify individuals and do not track you across sites.
- Account data: for registered contributors/staff — name, email, hashed password, and role — used to operate the research dashboard.
- Content you submit: contributions, annotations, and bug reports you send, including any contact details you choose to include.
3. Cookies
The public site uses no advertising or tracking cookies, and our analytics are cookieless — so no consent banner is required for browsing. Registered users who log in receive a single strictly-necessary session cookie to keep them signed in. See our Cookie Notice for details.
4. Why we process your data (legal bases)
- Legitimate interests — operating, securing, and improving the Platform.
- Contract / consent — providing accounts and processing contributions you submit.
- Legal obligation — where we must retain or disclose data by law.
We aim to comply with Egypt’s Personal Data Protection Law (Law No. 151 of 2020) and, for visitors in the EU/EEA and UK, the GDPR/UK GDPR.
5. Sharing & international transfers
We do not sell personal data. We share it only with service providers who help us run the Platform (e.g. hosting and, once enabled, a CDN/security provider) under appropriate safeguards, or where required by law. Some providers may process data outside Egypt/the EEA under recognised transfer mechanisms.
6. Retention & security
We keep personal data only as long as needed for the purposes above (server logs are retained for [N] days/months; account data for the life of the account). Data is encrypted in transit (HTTPS), access is restricted, and databases are backed up daily.
7. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict processing, and withdraw consent. To exercise these rights, contact us at [contact email]. You may also complain to your local data protection authority.
8. Changes
We may update this policy; material changes will be posted here with a new “last updated” date.