01 — Legal · Privacy

Your data,
plainly explained

// Effective 21 July 2026 · 10 sections

/ 01

Scope and responsibility

This policy applies to c01.dev, the C01 client application, and the private client workspace operated by C01 Developments in Cairo, Egypt. C01 is responsible for the personal data described here. A client organisation may also control information it asks its team members to place in the workspace.

The client application is invitation-only and is intended for C01 clients and their authorised teammates.

/ 02

Data we collect

We collect identity and account data such as name, business email, organisation, workspace role, account status, and last activity time. We process project, deliverable, document, invoice, notification, rating, and support information needed to provide the workspace.

For security and signing, we may process session identifiers, device and app version, push token, approximate network information, user agent, signature name and email, typed attestation, timestamp, document hash, and a one-way source identifier. We do not store raw sign-in codes or raw document-access tokens.

/ 03

How data reaches us

Data comes from you, your organisation's primary contact, C01 project operations, and the systems that operate the service. The public contact form also collects the information a prospective client chooses to submit.

We do not obtain data brokers' profiles, contact lists, precise location, health data, or advertising identifiers for the client application.

/ 04

Why we use it

We use personal data to authenticate users, provide the private workspace, display project and commercial records, support electronic signatures, deliver optional notifications, answer support requests, secure and troubleshoot the service, comply with law, and establish or defend legal claims.

Our grounds include performing our contract, taking requested pre-contract steps, complying with legal obligations, and legitimate interests in operating and securing a business service. Where consent is required, such as the device-level push permission, it can be declined or withdrawn.

/ 05

Sharing and processors

We share data only with vendors needed to run C01, such as infrastructure, database and authentication, hosting, email, push-delivery, monitoring, and document-generation providers. They process data under their service terms and security commitments. We may also disclose information when required by law, to protect rights and safety, or as part of a business reorganisation with appropriate safeguards.

We do not sell personal data, share it for cross-context behavioural advertising, or use client-workspace data to build advertising profiles.

/ 06

Notifications and analytics

Push notifications are optional. The application sends only a title, short operational summary, and routing identifiers through the push service, not document, invoice, payment, or signature contents. Revoking permission does not disable any core feature.

The native application has no advertising SDK. The public website may use privacy-oriented aggregate web analytics to understand page performance. Client-workspace business data is not sent to website analytics.

/ 07

Security and international processing

We use transport encryption, access controls, row-level tenant isolation, private storage, short-lived access credentials, encrypted device session storage, audit records, and administrative procedures appropriate to the service. No internet service can promise absolute security.

Service providers may process data outside Egypt. Where this happens, we use the provider's contractual and organisational safeguards and limit transfers to what operating the service requires.

/ 08

Retention and account deletion

Account and routine workspace-personal data are kept while access is active and only as long as needed afterward. Security and support records are kept for a limited period appropriate to their purpose.

You can initiate deletion directly in the application: open Account → Delete my account and confirm. Access and push delivery stop immediately. We complete the request within 30 days. Signed agreements, signatures, invoices, payment records, and limited audit evidence may be retained when required for accounting, contractual, fraud-prevention, or legal-claims purposes. They are restricted to those purposes and deleted when the applicable obligation ends.

If you cannot access the application, contact [email protected] for account-access help.

/ 09

Your choices and rights

Depending on applicable law, you may ask to access, correct, delete, restrict, or receive a copy of your personal data, and may object to certain processing. You may change push permission in device settings and correct workspace contact information through C01 support.

We may need to verify identity and authority before fulfilling a request. You may also complain to the competent data-protection authority.

/ 10

Children, changes, and contact

The service is a business workspace and is not intended for anyone under 18. We do not knowingly create accounts for children.

We may update this policy when the service or legal requirements change. Material changes will be communicated through the application, website, or account email before they take effect when appropriate.

Privacy questions: [email protected] · C01 Developments, Cairo, Egypt.

See also our Terms of Service and Support page.