Privacy Policy
This page describes what Kalim does with your data: what we take, why, for how long, and how you get it back or have it erased. Clauses are numbered so you can ask about one by its number.
This is a translation of the Arabic original. Where the two differ, the Arabic version governs.
1.0
Effective 2026-07-31
Entity: PharmaFuture
Governed by Egyptian personal data protection law
1Who processes your data, and in what capacity
Kalim is a business communication and messaging platform. Companies use it to bring their customer conversations into one inbox, route them to staff, send templates and campaigns, and connect them to their own systems.
When you message a company that uses Kalim, that company is the controller of your data: it decided why your data is processed and how. We are the processor; we act on the data on its behalf and on its instructions, and we do not use it for any purpose of our own. That is a clause in the contract signed with them, and it has a practical consequence for you: anything concerning your underlying relationship with the company is directed to them and carried out by us on their behalf, while deletion of your data from our systems can be requested from us directly, as set out in clause 8.
2What we process
- The conversation content you send or receive over the channel, and any images or files attached to it.
- The identifier you message from: a phone number, an email address, or an account ID.
- Data from the company's own systems if it has connected them to Kalim, such as your order number, appointment, or invoice.
- Operational logs about delivery and errors, written with an opaque identifier instead of your address.
3What reaches us from WhatsApp, and what does not
Your conversation with the company travels over the WhatsApp Business Platform, a service operated by Meta. We state this explicitly because part of what we process does not reach us from you directly; it passes through Meta first and then reaches us.
What we receive from it
- The phone number you messaged from.
- The display name on your WhatsApp profile, as you set it.
- Your message text, its identifier, and the time it was sent. Images and files are fetched separately by their identifier.
- Delivery and read receipts and their timestamps, the state of the reply window, and the conversation category Meta uses to price it.
What we do not receive from it
We neither request nor receive your contact list, your conversations with any other party, your profile photo, or your location unless you send it in a message. WhatsApp does not make those available to us in the first place.
What we do with it
We use the above for two purposes: delivering your message to the company and its reply to you, and applying the consent and opt-out rules in clauses 5 and 6. None of it enters advertising, none of it is returned to Meta for an advertising purpose, and none of it is sold.
Meta also processes your data in its own capacity, under the WhatsApp Privacy Policy. That processing has its own separate terms and is outside our control.
4Three things the system cannot do
The three clauses below are enforced in the code and in the build checks. There is no internal policy reviewed by a member of staff behind them.
- No trait about you is inferred from platform metadata. The delivery and read receipts, the reply-window state, and the pricing measurements described in clause 3 remain operational figures; they do not become a description of you in your record. An automated check enforces this and fails the build if it is violated.
- No cross-tenant learning. What is learned from your conversations with one company does not cross to another company in any form, and anonymisation is not a defence nor an accepted justification for crossing.
- No inference of an employee's emotional state. The tone of your own message may be classified to improve service; the member of staff replying to you is not measured or stored, and no code path in the system does so.
5Legal basis and consent
For every contact, every company, and every message category separately (service · marketing · calls) there is an independent consent record. It carries the time of collection, the channel, the method, the evidence of consent, and the trading name disclosed to you at that moment.
- If the consent record for the requested category is absent, sending fails. The message is blocked at the system boundary before it leaves.
- Consent to one category is not used for another. Someone who agreed to order alerts did not agree to a promotional offer.
- Health data requires separate, explicit, written consent.
6Opting out
- An opt-out is a permanent suppression, and neither a contact importer nor a campaign builder overrides it.
- It propagates immediately across all of the company's numbers, so its effect is not limited to the number you messaged.
- It is accepted off-channel too — by phone or in the branch — and recorded with the same effect.
- The time of receipt and the time of enforcement are each recorded separately, and the gap between them is measured and displayed.
7Retention periods
| Type | Period | Why |
|---|---|---|
| Consent evidence | Three years from the date of the last message, not from the date of consent | So the evidence outlives the active relationship rather than expiring inside it |
| Conversation content | Set by the company, within floors it cannot go below | A platform-imposed minimum the customer cannot silently lower |
| Compliance log | Anonymised, not deleted | A record proving a block occurred loses its value if it can be erased — see clause 10 |
| Operational logs | Short, and under an opaque identifier | Diagnosis does not need your identity |
8Your rights, and how to exercise them yourself
You may request: access to your data · correction · erasure · objection to a particular processing · withdrawal of your consent at any time.
Erasure does not have to go through the company
You may request erasure directly from us, without the company you message acting as intermediary, through the data deletion page. It issues you a receipt with a reference number as soon as you submit, it has a published response clock, and it ends with a closure receipt enumerating the stores your data was erased from.
9Hiding your contact details
A company can enable a control that stops your number or email from leaving our servers to its employees' screens; they see an opaque identifier and a shortened form. Where that control is enabled, revealing the address becomes an audited action: it requires a classified reason, it is recorded with who revealed it, when, and why, it expires automatically, and the company itself can see it.
Whatever the state of that control, your address is never written into any operational log, debug output, error trace, or alert. Logs always use the opaque identifier.
10Security and isolation
- Isolation lives in the data layer. Each company is isolated at row level in the database, and the application connects through a role that can neither bypass that isolation nor own the tables. This is checked automatically on every build.
- A hash-chained compliance log per company proves that a block occurred. Editing one line breaks the chain and is detected; a failed attempt is itself recorded as an event.
- Zero standing access for platform operators to customer content. Emergency access requires a classified reason and the approval of an approver the company appoints, carries an automatically expiring grant, and every read is logged and visible to the company.
Where a government authority asks for data, that has a published, written path: what a request must contain, how its legality is reviewed, when we object, what we tell the company, and what we record. It is set out on the government and law enforcement requests page.
11Processing location and cross-border transfer
As of 17 August 2026, your data is stored outside Egypt — on a server we own, in our infrastructure provider's data centre in Germany, and applying from that date. Our provider offers no location inside Egypt, and we do not hide that behind general wording. We name the country rather than a region, because "region" covers more ground than we can actually guarantee.
We must also state that the Egyptian licensing track is under way and not yet complete. Cross-border transfer is subject to prior authorisation from the competent authority, and we are in the process of obtaining it. We say this plainly because concealing the status of a licence is worse than disclosing it — you are entitled to decide on the fact, not on an impression.
Your rights are unchanged wherever the data sits: access, rectification, erasure and objection, through the data deletion page and within the response times published here. Any change to the storage location is communicated to you before it takes effect, not after.
12Sub-processors
We rely on infrastructure and messaging-channel providers, first among them Meta as operator of the WhatsApp channel described in clause 3. The full list and each party's scope is available on request, is shown to the company before activation, and any new external processing is recorded before it happens.
Published list: sub-processors and their roles.
13Minors
The service is directed at communication between businesses and their adult customers, and we do not knowingly collect data about minors.
14Changes to this policy
Every version carries a version number and an effective date. Material changes are notified before they take effect, and previous versions remain available because they are evidence of what was in force at the time of a particular processing.
15Contact
Data Protection Officer: السمان محمد محمد
Email: privacy@kalim-ai.com
Address: شارع قاسم محمد، القاهرة، مصر
You always retain the right to lodge a complaint with the competent personal data protection authority.