Legal
GDPR
Last updated: August 1, 2026
1. Overview
The General Data Protection Regulation (GDPR) sets rules for how personal data of individuals in the EU/EEA is collected, used, and protected. While Bosla's primary market is Egypt and MENA, this page explains how our platform is built to support GDPR-aligned practices for any seller or end customer whose data falls under it.
2. Controller and processor roles
Bosla is the data controller for account and billing data about the sellers and team members who use our platform. For the messages, orders, and contact details that sellers route through Bosla to communicate with their own customers, Bosla acts as a data processor, and the seller is the controller. Sellers are responsible for having a lawful basis to process their customers' data.
3. Legal basis for processing
We process personal data under one or more of these bases: performance of our contract with you (providing the Service), our legitimate interests (securing and improving the Service), compliance with legal obligations, and, where applicable, your consent (e.g. marketing communications).
4. Your rights
Individuals whose data is subject to GDPR have the right to:
- Access the personal data we hold about them.
- Correct inaccurate data.
- Request erasure ("right to be forgotten").
- Restrict or object to certain processing.
- Receive their data in a portable format.
- Lodge a complaint with a supervisory authority.
Sellers should direct their own account requests to us. End customers should direct requests about their data to the seller they interacted with, who controls that data; we support sellers in fulfilling these requests.
5. International data transfers
Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards, such as standard contractual clauses with our infrastructure and sub-processors, to protect that data.
6. Sub-processors
We use a limited set of infrastructure and integration providers to operate the Service (cloud hosting, messaging platforms, AI model providers, email/SMS providers). Each is bound by data protection terms consistent with GDPR requirements. A current list is available on request.
7. Contact us
For GDPR-related questions or requests, contact us at [email protected].