8 800 332 65-66

Support 24/7

0 Your Cart 0.00 ج.س

Cart (0)

No products in the cart.

Privacy and Data Protection Policy – Kush One Platform

Effective Date: __ / __ / 20__
Last Updated: __ / __ / 20__

1. Introduction

Kush Integrated Solutions Co. Ltd., owner of the Kush One platform, is committed to protecting users’ privacy and personal data, and to processing such data lawfully, securely, and for the purposes set out in this Policy.

This Policy applies to the website, applications, services, and systems of the Platform, and forms an integral supplement to the General Terms of Use.

2. Scope of Application

This Policy applies to data of:

  1. Platform visitors.
  2. Buyers, Sellers, and Service Providers.
  3. Representatives of companies and institutions.
  4. Applicants for registration or verification.
  5. Users of shipping, payment, and support services.
  6. Persons who contact the Platform or submit complaints.

3. Data Collected by the Platform

Depending on the nature of use, the Platform may collect the following data:

Identity and contact data

  • Name and date of birth when needed.
  • Phone number and email address.
  • Address and delivery location.
  • Identity document image and details.
  • Personal photo, when verification is required.

Company and seller data

  • Trade name and legal form.
  • Registration certificate and licenses.
  • Commercial and tax numbers.
  • Authorized representative details.
  • Bank account or collection method details.
  • Agency, distribution, or product-ownership documents.

Transaction data

  • Orders, purchases, and quotations.
  • Product details, quantities, and values.
  • Invoices, payments, and refunds.
  • Shipping, delivery, installation, and maintenance data.
  • Complaints, correspondence, and ratings.

Technical data

  • IP address.
  • Device, browser, and operating system type.
  • Login and in-platform activity data.
  • Cookies and similar technologies.
  • Failure, security, and login-attempt logs.

Location data

Approximate or precise location may be collected after obtaining the required permission, for delivery purposes or to display services and products available in the user’s area.

4. Sources of Data

The Platform obtains data from:

  1. The user directly.
  2. The user’s activity and use of the Platform.
  3. Sellers or Buyers who are parties to a transaction.
  4. Banks and payment service providers.
  5. Shipping companies and service providers.
  6. Official authorities or lawful databases.
  7. Verification and anti-fraud service providers.
  8. Public sources whose use is permitted by law.

5. Purposes of Processing

The Platform uses data for the following purposes:

  1. Creating, managing, and securing accounts.
  2. Verifying identity, legal capacity, and licenses.
  3. Fulfilling orders, payments, shipping, and delivery.
  4. Enabling communication between transaction parties.
  5. Managing stores, advertisements, and quotations.
  6. Providing support and handling complaints and refunds.
  7. Preventing fraud, misuse, and unlawful activities.
  8. Protecting the Platform, users, and technical systems.
  9. Improving services and user experience.
  10. Preparing statistics and analytics after reducing the ability to identify individuals.
  11. Sending operational and legal notices.
  12. Sending marketing offers where consent or a lawful basis exists.
  13. Complying with legal, regulatory, and judicial requirements.

Data is not used for purposes incompatible with the purpose for which it was collected, except with the user’s consent or as permitted by law.

6. Legal Basis for Processing

The Platform processes data where necessary:

  1. To perform a contract or take pre-contractual steps.
  2. To comply with a legal or regulatory obligation.
  3. To protect the legitimate interests of the Platform or users.
  4. To prevent fraud and secure services.
  5. Based on the user’s consent, where required.
  6. To protect vital interests in exceptional cases.

The user may withdraw consent at any time, without affecting the lawfulness of prior processing or processing based on another legal ground.

7. Sharing Data Between Seller and Buyer

Data necessary to complete a transaction may be shared between Seller and Buyer, including name, contact, delivery, and order details.

Each party must use the data solely to perform the transaction and after-sales services, and may not:

  • Use it for unlawful purposes.
  • Sell or share it without a legal basis.
  • Use it for marketing without consent.
  • Retain it longer than the legal or contractual need.

The user is responsible for any independent processing carried out outside Platform systems.

8. Sharing Data with Third Parties

The Platform may share data to the extent necessary with:

  1. Licensed banks and payment service providers.
  2. Shipping, storage, and delivery companies.
  3. Hosting and cloud computing providers.
  4. Messaging, communications, and support providers.
  5. Cybersecurity, verification, and anti-fraud companies.
  6. Accountants, auditors, and legal advisors.
  7. Competent governmental, judicial, and regulatory authorities.
  8. Any party that succeeds the Company through a lawful merger, acquisition, or reorganization.

The Platform requires service providers to use data only within the contracted service, maintain confidentiality, and apply appropriate security measures.

9. Payment Data

Payments are processed, according to available methods, through licensed banks or payment service providers.

The Platform does not retain full card details where payment is processed directly by an independent provider. Payment data is also subject to the policy and terms of the relevant financial institution.

The Platform may retain the transaction reference, amount, status, and necessary accounting data.

10. Transfer of Data Outside Sudan

Data may be stored or processed outside the Republic of Sudan when using international technical or cloud services or when executing cross-border transactions.

Subject to capabilities and legal requirements, the Platform takes appropriate safeguards to protect data, including:

  1. Contracting with parties that follow suitable security and privacy standards.
  2. Defining processing purposes and use limits.
  3. Imposing confidentiality and protection obligations.
  4. Restricting access to data.
  5. Complying with any applicable consents or legal requirements.

International data transfers are also subject to any foreign law applicable to the user or the transaction.

11. Data Retention

The Platform retains data for the period necessary to achieve processing purposes, perform transactions, settle disputes, and meet legal, accounting, and security obligations.

Some data may be retained after account closure, including:

  • Transaction and payment records.
  • Invoices and accounting records.
  • Verification documents.
  • Complaints and disputes.
  • Security and anti-fraud records.
  • Data required by law.

Data is deleted or de-identified when the legitimate need to retain it ends, where legally and technically possible.

12. Information Security

The Platform applies appropriate technical and organizational measures to protect data, including according to risk:

  1. Encryption of communications and sensitive data.
  2. Access-control settings.
  3. Verification of user and staff identity.
  4. Backup and data recovery.
  5. Monitoring of systems and login attempts.
  6. Software updates and vulnerability remediation.
  7. Staff training and confidentiality obligations.
  8. Review of service providers and security systems.

Absolute protection of any electronic system cannot be guaranteed. The user must keep login credentials confidential and not share them with others.

13. Data Incidents and Breaches

If a security incident affecting data occurs, the Platform takes appropriate steps to contain, investigate, and remediate it.

Competent authorities and affected users are notified where legally required or where the incident poses a material risk to their rights or interests.

14. User Rights

Subject to law and lawful restrictions, the user may request:

  1. Knowledge of the data the Platform processes about them.
  2. A copy of such data.
  3. Correction or completion of inaccurate data.
  4. Deletion of data for which there is no longer a basis for retention.
  5. Restriction of certain processing activities.
  6. Objection to direct marketing.
  7. Withdrawal of consent where consent is the basis for processing.
  8. Account closure.
  9. Submission of a complaint regarding use of their data.

A request may be refused or limited if it conflicts with a legal obligation, third-party rights, Platform security, or investigation of fraud or an existing dispute.

The Platform may request proof of identity before fulfilling the request.

15. Marketing Communications

The Platform may send offers, news, and marketing for its products or services or those of Sellers in accordance with consent and legal requirements.

The user may unsubscribe from marketing messages at any time. This does not cover necessary notices relating to the account, orders, security, or legal obligations.

16. Cookies

The Platform uses cookies and similar technologies for:

  • Operating the Platform and login.
  • Saving user preferences.
  • Protecting accounts and preventing fraud.
  • Measuring performance and analyzing usage.
  • Personalizing content and advertisements, where consented.

The user may control non-essential cookies through consent settings or the browser, with possible impact on some Platform features.

Details are set out in a separate Cookies Policy once actual tracking tools are adopted.

17. Recordings and Correspondence

The Platform may retain correspondence, calls, and support logs to document requests, improve service, settle disputes, and prevent fraud, with notice of recording where required.

18. Publicly Published Data

Certain Seller, store, or product data may be publicly available, including:

  • Store name.
  • Logo and images.
  • Product and service details.
  • City or service coverage.
  • Ratings.
  • Contact details the Seller agrees to publish.
  • Verification or accreditation status.

The user is responsible for content they choose to publish publicly.

19. Children’s Data

The Platform does not target persons below the legal age required to enter into transactions.

A minor may not create a commercial account or complete a transaction except through a guardian or legal representative and in accordance with the law.

If data of a minor is found to have been collected without a lawful basis, the Platform may delete it and suspend the related account.

20. Automated Decisions and Anti-Fraud

Technical systems may be used to analyze transactions and identify risks or unusual activity, which may result in additional verification or temporary suspension of an order or account.

The user may request human review of a decision that has a material effect, unless prohibited by law or unless security and investigation procedures require otherwise.

21. External Links and Services

The Platform may contain links or services provided by independent parties. The Company is not responsible for those parties’ privacy policies or practices.

The user should review their policies before providing data to them.

22. Legal Disclosure

The Platform may disclose data where:

  1. An order is issued by a court or competent authority.
  2. A legal or regulatory obligation exists.
  3. Investigating fraud, crime, or a security threat.
  4. Protecting the rights of the Company, users, or third parties.
  5. Establishing or defending a legal claim.

Disclosure is limited to what is necessary and legally permitted.

23. User Responsibility for Data

The user undertakes that data provided is accurate and lawful, and that the user is authorized to submit any data relating to another person.

The user is responsible for updating their data, keeping the account confidential, and not uploading documents or information beyond what the Platform requests.

24. Amendment of the Policy

The Platform may amend this Policy to meet legal, technical, or operational requirements.

Amendments are published with their effective date, and users are notified of material changes through approved means.

25. Governing Law

This Policy is governed by the laws of the Republic of Sudan.

Where specific processing is subject to an applicable foreign law, the Platform complies with its requirements within the legal scope applying to the Company, the user, or the transaction.

26. Contact and Privacy Requests

Inquiries, complaints, and rights requests should be directed to:

Kush Integrated Solutions Co. Ltd.
Kush One Platform

  • Registered Address: __________________________
  • Privacy Email: ______________
  • Phone: ______________________________
  • Company Registration No.: ________________________
  • Data Protection Officer: ____________________

A request must include the requester’s name, contact details, the nature of the request, and what is needed to verify identity.