Skip to content

Privacy Policy

1. Who we are

The Five HR is operated by [[ LEGAL ENTITY NAME ]] ("The Five", "we"), [[ registered in the Arab Republic of Egypt, CR No. XXXX ]], at [[ FULL ADDRESS, EGYPT ]]. For privacy questions, contact our data protection contact at privacy@thefive.space.

2. Controller vs processor

We act in two capacities:

  • As a data controller for the personal data of our own account holders and website visitors (e.g. the person who signs up, billing contacts, marketing subscribers).
  • As a data processor for the personal data that you, our Customer, upload about your candidates and employees. For that data, you are the controller, you determine the purposes, and we process it only on your documented instructions to provide the Service.

3. Personal data we collect

  • Account & contact data — name, work email, phone, company, role.
  • Customer Content (as processor) — candidate and employee records you enter: names, contact details, CVs, salaries, national ID / insurance numbers, bank details, payroll figures.
  • Usage & technical data — log data, device/browser type, IP address, pages viewed, and actions taken, used to operate and secure the Service.
  • Communications — messages you send us and support requests.

4. Why we process data & legal basis

We process personal data to: provide, secure and improve the Service; authenticate users; calculate payroll and generate documents at your instruction; communicate with you; handle billing; comply with legal obligations; and prevent fraud and abuse. Our legal bases under the PDPL include your explicit consent, performance of our contract with you, compliance with a legal obligation, and our legitimate business interests where not overridden by your rights.

Where we rely on consent, it is explicit, informed and specific, and you may withdraw it at any time without affecting processing carried out before withdrawal. As our Customer, you are responsible for obtaining any consent required from your candidates and employees before entering their personal data into the Service.

6. Cookies & similar technologies

We use strictly necessary cookies to keep you signed in and to remember preferences (e.g. light/dark theme). We use limited analytics to understand usage. We currently use only strictly necessary cookies and basic, privacy-respecting analytics. If we introduce non-essential or marketing cookies, we will ask for your consent first in line with the PDPL.

7. How we share data & sub-processors

We do not sell personal data. We share it only with service providers who help us run the Service, under contracts that require appropriate protection:

  • Hosting & database — Supabase (managed database & storage, EU region).
  • Application hosting — Vercel (application hosting & delivery).
  • Transactional email — Resend (transactional email).
  • Payments — a payment processor (added when paid plans begin).

We may also disclose data where required by law or to protect rights, safety and security.

8. Cross-border transfers

Some providers process data outside Egypt (for example, in the European Union). Where the PDPL requires, we will obtain the necessary permit from the Personal Data Protection Center and apply appropriate safeguards for transfers of personal data abroad. Our primary database is hosted in the European Union; where the PDPL requires, we apply an appropriate transfer mechanism and obtain the necessary permit from the Personal Data Protection Center.

9. Data retention

We keep personal data only as long as needed for the purposes above, for the life of your account, and as required to meet legal, tax and accounting obligations. Customer Content is retained while your account is active and deleted or returned after termination as described in our Terms, subject to legal retention requirements.

10. How we protect data

We apply technical and organisational measures appropriate to the sensitivity of payroll data, including encryption in transit and at rest, strict role-based access controls, database-level tenant isolation so no customer can access another's data, and an immutable audit log of sensitive actions. No system is perfectly secure, but we work continuously to protect your data.

11. Your rights

Subject to the PDPL, you have the right to: be informed about processing; access your personal data; correct inaccurate or incomplete data; request erasure; restrict or object to processing (including for marketing); withdraw consent; and request portability where technically feasible. To exercise these rights, contact privacy@thefive.space; we will respond within the period required by law. Where we process employee/candidate data as a processor, please direct requests to the relevant Customer (controller); we will assist them.

12. Personal data breach

If a personal data breach occurs, we will take prompt action and, where required by the PDPL, notify the Personal Data Protection Center within seventy-two (72) hours of becoming aware of it and inform affected data subjects and/or the relevant controller within the legally required timeframe.

13. Children

The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect data from children.

14. Changes to this policy

We may update this Privacy Policy. We will post the new version here with an updated date and, for material changes, provide reasonable notice.

15. Contact us

Controller: [[ LEGAL ENTITY NAME ]]
Privacy contact: privacy@thefive.space
Address: [[ FULL ADDRESS, EGYPT ]]
Supervisory authority: Personal Data Protection Center (Egypt)