MSAMM

Privacy Notice

2 August 2026

This notice explains what personal data MSAMM collects, why, who we share it with, and what you can do about it. It covers https://msamm.co and everything you do through an account on it.

We have tried to write it in plain language and to be specific. Where we hold something sensitive — an identity document, a bank account number — we say so rather than hiding it inside a general phrase.

1. Who is responsible for your data

MSAMM, operating https://msamm.co, decides why and how your personal data is processed and is the controller of it.

You can reach us about anything in this notice — including a request to see, correct or delete your data — at info@msamm.co.

2. What we collect

Everyone with an account.

  • Your name and email address, which are required to register.
  • Your password, stored only as a cryptographic hash — we cannot read it and cannot tell you what it is.
  • Your phone number, if you choose to give one, and whether it has been verified. These are stored separately, so we never say "verified" about a number that was not the one verified.
  • Your language and your region, which decide what you see and which currency you are charged in.
  • Sign-in sessions, and a record of significant actions on your account.

If you buy something.

  • What you bought, when, the amount and the currency, and a reference from the payment provider.
  • For hour packages: your balance, every deduction, and when the hours expire.
  • We do not receive or store your card number, expiry date or security code. Those go directly to the payment provider.

If you take a course.

  • Which courses you are enrolled in and which lessons you have completed.
  • Your assessment attempts and scores.
  • Any certificate issued to you, and its serial number.

If you raise support tickets.

  • The content of your tickets, including anything you write or attach.
  • Proposals made to you and which you accepted.
  • Meeting records — who attended and when. We do not record video or audio unless we tell you first and you agree.

If you apply as a consultant or an intern. This is the most sensitive data we hold, and we hold it because we cannot let an unverified person near a client's systems.

  • A government photo identity document — a national ID, an Iqama or a passport. The file itself is stored inside our database, not on a public file service, and is readable only by administrators reviewing it.
  • Any certificates or qualifications you claim, in the same way.
  • A record that you accepted our confidentiality agreement, and which version.
  • For consultants: your bank account name, bank name, IBAN, SWIFT code and country, so that we can pay you.
  • Your hourly rate, which is confidential and never shown to clients.

Technical data. Standard web server information such as your IP address and browser, used to keep the service running and secure.

3. Why we use it, and on what basis

  • To provide what you bought — running your account, giving you course access, tracking your hour balance, routing your tickets. This is necessary to perform our contract with you.
  • To take payment and keep financial records — necessary for the contract, and required by tax and commercial law.
  • To verify consultants and interns — necessary for our contract with them, and necessary for the legitimate interest of protecting clients from unverified people handling their systems.
  • To issue and verify certificates — necessary for the contract, since a certificate that cannot be checked is worthless.
  • To keep the platform secure and to investigate abuse — our legitimate interest, and yours.
  • To send you service messages — account confirmations, payment receipts, ticket updates. These are part of the service and are not marketing.
  • To comply with the law where we are required to.

We do not sell your personal data. We do not use it to build advertising profiles, and we do not use your content to train machine learning models.

4. What is visible to other people

Most of your data is visible only to you and to the administrators who need it. Three things are more visible than that, and you should know before you use those features.

Certificate verification is public. Anyone holding a certificate code can look it up without an account. The page shows the holder's name, the course, the score, the serial number, the issue date, and whether it has been revoked. It does not show your email address or any contact detail. If you would rather your name were not on a publicly checkable page, do not sit the assessment.

The consultant directory is public. It shows a consultant's first name and a reference code, their track, product and experience. It deliberately does not show a consultant's full name, contact details or rate.

Questions and answers are visible to signed-in users. If you post a question, other users can read it. Do not put confidential information in one.

When you join a meeting, the other participants — which may include up to two interns as observers — see your name, and your image and voice if you enable them.

5. Who we share it with

We use a small number of service providers to run the platform. They process data on our instructions and for no other purpose.

  • Payment providers — Paymob, Tap, Fawry and Moyasar, depending on your region. They receive what they need to take the payment and are the ones who handle your card details, not us.
  • Our video meeting provider — receives the data needed to place you in a meeting room.
  • Our email provider — receives your email address and the content of the service messages we send you.
  • Our hosting provider — operates the servers on which the platform and its database run.

We will also disclose data where the law requires it, or to establish or defend a legal claim.

If a consultant works on your ticket, they see what you put in that ticket. Tell them what they need and no more — in particular, do not put system credentials or another organisation's confidential data into a ticket.

6. Where your data goes

Our servers are in Europe, and some of our service providers operate outside Egypt and Saudi Arabia. That means your personal data may be transferred out of the country you are in.

Where we make such a transfer we take reasonable steps to see that the data remains protected to an equivalent standard, and we only use providers who commit to that.

7. How long we keep it

We keep personal data for as long as we need it for the purpose we collected it, and then no longer. In practice that means:

  • Account and learning data — while your account is open. If you close it, we delete or anonymise what we are not required to keep.
  • Financial records — for as long as tax and commercial law in the relevant country requires us to keep them, which is longer than your account may last.
  • Certificates — kept while the certificate is valid, because a certificate has to remain checkable to mean anything.
  • Identity documents — kept while you work through the platform and for a period afterwards to evidence that we verified you. Tell us if you stop working with us and we will review whether we still need them.
  • Bank details — kept while we may still owe you a payment, then removed.
  • Our audit log — which records who did what and when, kept as our record of how the platform was administered. This is deliberately not deleted with an account, because a log you can erase is not a log.

We are reviewing these periods with legal advice and will state them precisely once we have.

8. Your rights

Depending on where you are, data protection law gives you rights over your personal data. Customers in Egypt have rights under the Personal Data Protection Law (Law 151 of 2020); customers in Saudi Arabia have rights under the Personal Data Protection Law of the Kingdom.

In general terms, you can ask us to:

  • tell you what data we hold about you, and give you a copy;
  • correct it if it is wrong;
  • delete it, where we do not have a good reason to keep it;
  • stop or limit a particular use of it;
  • withdraw a consent you gave us, where we relied on consent.

Email info@msamm.co and tell us what you want. We will answer within the time the applicable law allows, and we may ask you to confirm your identity first — we are not going to hand your data to somebody who says they are you.

Some requests we cannot fully grant. We cannot delete a financial record we are required to keep, and we cannot delete our audit log. Where we refuse, we will tell you why.

If you are not satisfied with how we handled your request, you can complain to the data protection authority in your country.

9. How we protect it

  • The site is served only over an encrypted connection.
  • Passwords are stored as hashes and never in a form we can read.
  • The database and its supporting services are not reachable from the internet.
  • Access to administrative functions is restricted by role, and significant actions are logged.
  • Server access is by cryptographic key only; password sign-in is disabled.
  • Backups are taken daily.

No system is perfectly secure. If we suffer a breach that affects your personal data, we will tell you and the relevant authority as the law requires.

10. Cookies

We use a small number of cookies, and all of them are necessary for the site to work: keeping you signed in, remembering your language, and protecting forms against cross-site request forgery.

We do not use advertising cookies, and we do not use third-party analytics or tracking. That is why you are not being asked to accept a cookie banner.

11. Children

This service is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we will remove it.

12. Changes to this notice

We may update this notice. The date at the top shows when it last changed. If we change it in a way that materially affects you, we will tell account holders by email.