Data Request Guidance
Effective date: 2026-08-20 · v1.0.0
1. What you can request
Depending on the data and applicable law, you may ask to know whether personal data is processed, receive a copy, correct inaccurate data, erase identity data, or object to or restrict particular processing. A merchant may also request an export of its tenant data.
[EGYPTIAN LAWYER REVIEW REQUIRED] Confirm the rights, exceptions, legal bases, complaint route, and whether portability applies under Egypt's Personal Data Protection Law.
2. Where to send a request
For diner or order data, contact the restaurant or merchant first. The merchant controls that data and can identify the order and decide the request. Ramlyon is generally its processor and will assist it.
For a Ramlyon account, platform-security data, billing data, or when the merchant cannot be reached, send the request to [email protected]. Include your name, the relevant account or restaurant, the right you wish to exercise, and a safe way to reply.
3. Identity proof
Ramlyon or the merchant must be able to match the requester to the relevant data without exposing it to another person. A diner will normally need to identify the restaurant, the phone number used, and relevant order details. A merchant should write from its registered account email where possible.
Only the minimum proof reasonably needed for the request should be sought. Do not send a password, one-time code, full payment credential, or unnecessary government-identity copy. Additional proof may be requested when the risk of disclosure or erasure requires it.
4. How the request is handled
Ramlyon first determines whether it is the controller or a processor for the data in question. When it is a processor for diner data, it routes the request to the merchant and assists that merchant with the customer-erasure or tenant-export tools. When Ramlyon is the controller, it reviews the request against applicable identity, security, billing-retention, and legal-record requirements.
Customer erasure removes the diner-directory record and identity from linked orders and guest sessions, while financial order rows and amounts remain. An export excludes password hashes, session secrets, verification tokens, and other authentication material.
5. Response time
Ramlyon records the intake date and responds in writing within [EGYPTIAN LAWYER REVIEW REQUIRED — PDPL response deadline]. If another controller must act, Ramlyon will explain the routing rather than representing that it can decide the request itself.
6. Questions or complaints
Send follow-up questions to [email protected] and quote the request reference supplied in the written response. The legally required regulator and complaint details remain [EGYPTIAN LAWYER REVIEW REQUIRED].