Legal
Privacy Policy
How FurnViz collects, uses, shares, retains, and protects personal data — including GDPR and Egyptian PDPL rights.
This page is a plain-language summary for general information and is not legal advice.
Last updated: June 29, 2026
1. Who We Are
This Privacy Policy is issued by FurnViz, based in Giza, Egypt. FurnViz acts as the data controller in respect of personal data collected and processed in connection with your use of the FurnViz platform and website. Our designated Data Protection Officer (DPO) can be reached at [email protected].
2. Scope
This Privacy Policy applies to personal data we collect through: (a) the FurnViz SaaS platform; (b) the FurnViz website; (c) email and other communications with us; and (d) customer support interactions. It applies to all individuals whose personal data we process, including Account holders, authorized Users, and website visitors.
3. Data We Collect
Account and Registration Data
- Full name and job title
- Company name, type, and size
- Business email address and phone number
- Billing address and country
- Username and password (stored as a cryptographic hash)
Payment and Transaction Data
- Billing name and address
- Payment method type (card brand, last 4 digits, expiry) — full card numbers are processed exclusively by our PCI-DSS compliant payment processor and never stored on FurnViz servers
- Transaction history, invoice records, and subscription status
Customer Content
- Floor plans, architectural drawings, and spatial data you upload
- Product catalog data, furniture models, and brand assets
- End-client project details and generated 3D visualization files
Usage and Technical Data
- Features accessed, pages viewed, button clicks, and session duration
- Browser type and version, operating system, screen resolution, and device type
- IP address, approximate geographic location (country/city level), and referral URL
- Error logs and performance metrics
4. Legal Bases for Processing
We process your personal data only where we have a valid legal basis:
- Performance of a contract: Processing necessary to provide the Service under our Terms of Service.
- Legitimate interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, product improvement, security monitoring).
- Consent: Where you have given explicit consent (e.g., for marketing cookies or email marketing). You may withdraw consent at any time.
- Legal obligation: Processing required to comply with applicable laws, including the Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL).
5. How We Use Your Data
- To create and manage your Account and deliver the Service
- To process subscription payments, issue invoices, and manage billing
- To authenticate Users and maintain platform security
- To provide customer support and respond to inquiries
- To send transactional communications: account notifications, payment receipts, service updates, and security alerts
- To analyze aggregated and anonymized usage patterns to improve platform features
- To detect, investigate, and prevent fraudulent transactions and security incidents
- To comply with applicable legal obligations, including tax and regulatory reporting requirements
6. Cookies
We use cookies and similar technologies on our website and platform. For full details on the types of cookies we use, their purposes, durations, and how to manage your preferences, please read our Cookie Policy.
7. Data Sharing and Sub-Processors
We do not sell, rent, or trade your personal data to third parties. We share personal data only in the following limited circumstances:
- Sub-processors: Carefully vetted third-party service providers processing data on our behalf, including cloud infrastructure providers, CDN providers, PCI-DSS compliant payment processors, email delivery services, and anonymized analytics platforms. All sub-processors are bound by written data processing agreements.
- Professional advisors: Lawyers, auditors, and accountants, under applicable confidentiality obligations.
- Legal and regulatory authorities: Where required by applicable law, including requests from Egyptian regulatory authorities such as the NTRA.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you.
8. International Data Transfers
FurnViz primarily stores data within Egypt in line with the data localization principles of the Egyptian PDPL (Law No. 151 of 2020). Where we transfer personal data outside Egypt or, for EU-based customers, outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms.
9. Egyptian PDPL Compliance
We comply with the Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL) and its implementing regulations. Under the PDPL, you have the right to: be informed about data processing; access your personal data; correct inaccurate data; request erasure; restrict or object to processing; and data portability. To exercise PDPL rights, contact us at [email protected].
10. GDPR Rights for EU/EEA Users
If you are located in the EU or EEA, you benefit from GDPR rights, including: the right of access (Article 15); the right to rectification (Article 16); the right to erasure (Article 17); the right to restriction of processing (Article 18); the right to data portability (Article 20); the right to object (Article 21); and the right to lodge a complaint with your local supervisory authority. Contact our DPO at [email protected]. We will respond within 30 days of receipt.
11. Data Retention
We retain personal data for as long as your Account is active and for 90 days following the termination or expiration of your Subscription, during which you may request a data export. After this period, we securely delete or anonymize your personal data. Certain data may be retained longer where required by law (e.g., financial records for tax purposes). Usage logs are retained for up to 12 months for security purposes.
12. Data Security
We implement comprehensive technical and organizational security measures including AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access controls, multi-factor authentication, regular penetration testing, and a documented incident response plan.
13. Children’s Privacy
The Service is designed exclusively for business users. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected such data, please contact us immediately at [email protected].
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email at least 14 days before the updated policy takes effect.
15. Contact Us
For privacy inquiries or to exercise your rights: [email protected] | FurnViz, Giza, Egypt | +20 1515356916.