1. Our commitment
Our customers handle some of the most sensitive financial information in the region. Their customers — banks and telecom operators — count on them to be discreet, careful, and compliant. Easy Collects is built around the same expectation.
Security is not a feature we add. It is a precondition for the service to exist at all.
2. We do not look at your data
The data inside your tenant belongs to you. Our team does not browse it, mine it, or use it for any purpose other than operating the platform you have subscribed to. Access by our personnel is limited to a small group of authorised staff and is permitted only when you ask us to assist or when strictly required to investigate a legitimate operational incident.
3. Each customer is ringfenced
Every customer’s data lives in its own logically isolated tenant. There is no commingling. Your data is not visible to any other customer, and our staff cannot accidentally route or expose data across tenants.
4. Where the data lives
Customer data is stored in professional, certified cloud data centres operated by reputable providers. By default in the European Union; regulated customers can elect data residency in Egypt or the United Arab Emirates. Encrypted in transit and at rest.
5. Access controls
Access inside your organisation is controlled by you. Permissions are granular per role. SSO via SAML 2.0 / OIDC is supported, so officer onboarding and offboarding mirrors your existing HR processes.
6. A record of every action
Every meaningful action is recorded with the actor, the timestamp, and the affected resource. The audit trail is tamper-resistant and is retained for the period required to support investigations, compliance reviews, and customer reporting.
7. Compliance posture
The platform is operated in alignment with leading international information-security frameworks and is designed to support our customers’ obligations under the Egyptian Personal Data Protection Law and the EU GDPR where relevant. Our security pack — controls, sub-processors, DPA — is available to qualified procurement teams under NDA.
8. Continuity & recovery
We back up customer data on a regular schedule and routinely test our ability to restore the service if an incident occurs. Recovery objectives are designed to keep operational disruption to the smallest possible window.
9. Incident response
We maintain an on-call response capability and a documented incident-response playbook. In the event of a confirmed security incident affecting customer data, we will notify the customer in a timely manner — and within any timeframe required by applicable law.
10. Reporting an issue
Researchers and customers can report security concerns to security@easycollects.com. We acknowledge every report and follow up promptly.