01Article 40 is a better starting point than a template
The Iraqi Constitution of 2005 says, in Article 40, that the confidentiality of communication — postal, telegraphic, electronic and telephonic — is guaranteed, and may not be monitored, wiretapped or disclosed except by judicial decision. Article 17 adds a general right to personal privacy.
That is a stronger and simpler promise than most privacy statutes make. So we built the policy around it: no monitoring, no disclosure without a court order, and encryption that turns the constitutional promise into a technical fact rather than a corporate one.
02What Iraqi law actually covers
Iraq does not yet have a comprehensive data-protection statute. What it has is a set of laws that, together, cover most of what matters:
- The Civil Code No. 40 of 1951 for contracts and liability — including Article 259, which does not let us exclude liability for our own fraud or gross fault.
- The Electronic Signature and Electronic Transactions Law No. 78 of 2012, which makes your tap on "I agree" a real, binding consent and imposes confidentiality duties on electronic service providers.
- The Penal Code No. 111 of 1969, Articles 437–438, which criminalise disclosing secrets and violating private life.
- The Consumer Protection Law No. 1 of 2010 for your rights as a user of a service offered in Iraq.
Where the law is silent, we adopted the strictest international norm we could defend — data minimisation above all.
03Arabic prevails
Our legal documents are written in Modern Standard Arabic first, and the Arabic text prevails over the English if they ever diverge. Arabic is the official language of the state; a policy that binds Iraqis should be authoritative in their language, not in a translation.
The rest of the site stays in Iraqi dialect on purpose. Legal text is where precision beats warmth.
04What it changed in the product
Writing the policy this way forced decisions. We set the minimum age at 13 with guardian consent to 18, because full contractual capacity in Iraq begins at 18. We committed to reviewing the legality of every request before responding. And we wrote down a data-retention table with actual numbers — 30 days for undelivered messages, 12 months for logs — because "as long as necessary" is not a promise.
You can read the result at /en/privacy and /en/terms. Tell us where it can be clearer.