Privacy Policy
We are committed to protecting your privacy and being transparent about the personal data we collect and how we use it.
Introduction
Thank you for using MiPal. MiPal is provided by Misr Italia Properties ("we", "us", "the Company") for use by our employees and authorised personnel. Your trust is important to us, and we are committed to protecting the privacy and security of your personal information.
This policy explains what data the app collects, how we use it, who we share it with, how long we keep it, and the rights available to you. It is issued in accordance with applicable data protection laws.
MiPal requires an active Company account and is not available for general public use. Accounts are created for you by our IT department — you cannot register yourself. Please do not share your account with anyone; doing so puts Company and personal data at risk and may result in your access being suspended.
Information We Collect
Your account and identity. Your name, work email address, work phone number, employee identifier, job title, department and reporting line. This comes from your Company employment records and your Company work account, not from anything you type into the app.
Your activity in the app. The attendance records, leave requests and service desk requests you create, and the approval decisions recorded against them.
Your location. Your coordinates are recorded only at the moment you check in or out, to confirm the attendance event happened at an authorised work location. The app does not follow your location at any other time and cannot see where you are while it is closed or idle.
Content you submit. The messages, voice recordings and files you send to the Zio AI assistant, and any photos or documents you attach to a leave or service request.
Device and technical data. Your device's push notification token, its model, operating system version and app version, crash reports and performance measurements, and network connectivity status.
Data we receive automatically. As with any app that communicates over the internet, our systems and service providers receive your IP address and server access logs, an authentication cookie is set in the sign-in window, and map imagery is requested by your device directly from our map providers. We use this to operate, secure and troubleshoot the service — never to build a profile of you or monitor your behaviour.
What we do not collect. We do not collect your biometric data — Face ID and fingerprint checks are performed entirely by your device, and the app receives only a pass or fail result. We also do not collect advertising identifiers, your contacts, your location in the background, payment or bank account details, health data, or your browsing activity outside the app.
How We Use and Share Your Data
We use your data only to run the app and deliver its features — to sign you in and keep your account secure, to record and validate your attendance, to process and approve your leave requests, to create and track service desk requests, to answer your questions through the Zio assistant, to notify you about your requests and approvals, to diagnose crashes and improve stability, and to meet the Company's legal, contractual and record-keeping obligations as your employer.
We do not use your data for advertising, marketing, profiling, or automated decisions that produce legal effects, or for any purpose unrelated to your employment.
We do not sell, trade or rent your personal data. We share it only with the service providers that help us operate the app — for sign-in, HR record-keeping, service desk ticketing, the assistant, crash reporting, notifications, app updates and map imagery. Each of them acts on our instructions, under contract, and receives only what it needs for that purpose. We require every provider to protect your data to the same standard set out in this policy.
Content you send to the Zio assistant is processed by a third-party AI service outside the Company, so please do not send the assistant information you would not want handled externally.
Some providers store or process data in other countries, including the United States and the European Union, so using the app involves transferring your data across borders. We do this in line with applicable data protection laws, relying on contractual data protection terms, requiring that data is encrypted in transit, and limiting each transfer to what that provider needs.
We may also disclose your data where the law requires it, or where it is necessary to protect our rights, property or safety, or those of others.
Tracking and Cookies
We do not track you. MiPal contains no advertising and no advertising or analytics SDKs, does not access your device's advertising identifier, and does not link your activity with data from other apps or websites. We do not measure feature usage or session length, and we never sell, rent or disclose your personal data to data brokers. Because we do not track you, the app does not show Apple's App Tracking Transparency prompt.
Cookies. The app itself does not set cookies. An authentication cookie is set inside the secure browser window that opens when you sign in, purely to keep your session active.
Crash reporting. We use a crash reporting service to record crashes and performance data. These reports contain your device model, operating system version, app version and technical traces, and are not linked to your identity. Your push notification token identifies your device installation rather than you personally, and is used only to deliver notifications.
Security and Data Retention
We protect your information using recognised security standards. All traffic between the app and our systems travels over encrypted connections (TLS), and your authentication tokens are held in your device's hardware-backed secure storage — the iOS Keychain or the Android Keystore. Access to your data on our systems is limited to authorised staff with a genuine business need, and that access is logged. If a breach ever affects your personal data, we will notify you and the competent authority as required by applicable law.
We keep your data only as long as we need it for the purpose it was collected, or as long as the law requires:
- Attendance and leave records — for the duration of your employment, plus the period required by applicable labour and tax law
- Service desk requests — for as long as we need the record for operational purposes, which may continue after your employment ends
- Assistant conversations — 60 days
- Crash and performance data — 30 days
- Server and access logs, including IP addresses — 30 days
Where we keep data longer for security, fraud prevention or legal compliance, we do so only for as long as that purpose requires. Data we no longer need is deleted or permanently anonymised.
Your Rights
Subject to applicable data protection laws, you have the right to be told what personal data we hold about you and why, to obtain a copy of it, to have it corrected or completed if it is wrong, to ask us to erase data we are not legally required to keep, to withdraw your consent, to object to or restrict processing in the circumstances the law allows, to be told if a breach affects your rights, and to lodge a complaint with the competent data protection authority.
To exercise any of these rights, contact us using the details in Section 9, and we will respond within the period required by law. Some rights are limited where the data forms part of the Company's statutory employment records — where we cannot meet a request in full, we will tell you why.
Account Deletion
MiPal does not offer self-registration. Your account is created, provisioned and deactivated by the Company's IT department as part of your employment, using your Company work account — so there is no account for you to delete from inside the app.
When you leave the Company, IT revokes your access and deactivates your account. Some data is kept after that: your attendance and leave records, because they are statutory employment records we are required to keep, and your service desk requests and security logs, for audit and security purposes.
You can ask us to delete any personal data we are not legally required to keep — including your assistant conversation history, your uploaded attachments and your device push token. You can also withdraw your consent to processing at any time. To do either, email App.support@misritaliaproperties.com with the subject line "Account data deletion request". We will confirm what can be deleted, what has to be kept, and why.
Children and Policy Changes
MiPal is intended solely for Company employees and is not directed at, or intended for use by, anyone under the age of 18. We do not knowingly collect data from children.
We may update this policy from time to time to reflect changes in the app or in legal requirements. Material changes will be communicated through the app or by email, and the "last updated" date at the top of this page always shows the most recent revision. By continuing to use MiPal, you accept the current version of this policy.
Contact Us
If you have any questions about this policy, or you want to exercise any of your rights, you can reach us at:
Misr Italia Properties