Privacy policy
Last updated: 29 September 2026
This policy explains how processes personal data in Clinicato, including patients' health data, in line with Egypt's Personal Data Protection Law 151 of 2020 and its executive regulations.
1. Our role and the clinic's
- Patients' data, including their health data, is controlled by the clinic that entered it: the clinic decides why and how it is processed, and we process it on its behalf and only on its instructions, as a processor.
- Your account, the clinic's users' accounts, and subscription and billing data are controlled by us and processed under this policy.
2. Data we process for ourselves
- Registration details: your name, the clinic's name, mobile, email, governorate, number of doctors and specialties.
- Usage and security data: sign-ins, IP address, device type and the security log, to protect accounts.
- Billing data: plan, invoices and payments; card details go straight to the payment provider and are never stored by us.
3. Data we process for the clinic
- Patients' basic and contact details, appointments, invoices and payments.
- Health data: history, allergies, medications, visits, diagnoses, prescriptions, images and medical files, and the record of the patient's consent to processing.
- We use this data only to provide the service to the clinic, and access it only as far as that requires and on its instructions.
4. Data processing agreement summary
- We process patients' data only on the clinic's documented instructions, including these terms and what it chooses in the system's settings.
- Everyone on our team who may access it is bound to confidentiality, and access is given only to those whose work needs it.
- We apply technical and organisational security measures suited to the sensitivity of health data, described under «Security» below.
- We use only the sub-processors this policy names or that we tell the clinic about before adding, and bind them to protection duties no weaker than ours.
- We help the clinic answer its patients' requests and meet its duties towards the Personal Data Protection Centre.
- We notify the clinic of any breach affecting its patients' data without delay and within 24 hours of becoming aware of it, with the information we have to help it notify the Centre and the patients affected.
- When the contract ends we let the clinic download its data, then delete it at its request or after the periods under «Retention».
- On reasonable request we give the clinic the information needed to show we comply with this agreement.
5. Hosting and transfers
- Databases and files are hosted with trusted cloud providers, every clinic has its own database, and private files are kept in private storage opened only through short-lived signed links.
- A clinic's database may be hosted on a server in a given region where that is available for its country, and the database is never moved without telling the clinic.
- When personal data is transferred outside the Arab Republic of Egypt we follow the controls and licences set by the law and the Personal Data Protection Centre.
6. Who can see the data
- Inside the clinic: each user within their permissions; reception never sees medical content, and every look at or change to the medical record is logged with who and when, for the clinic manager to review.
- Sub-processors that help us run the service, each within its role: hosting and database providers, Cloudflare (storage and protection), Meta (WhatsApp messages), online payment providers (such as Paymob), the email provider, the AI provider for features that use it with no model training on the data, and the Tax Authority for e-invoice and e-receipt data if the clinic turns it on.
- Our support team: enters a clinic's account only with its manager's consent and for a limited time, every entry is logged, and support accounts cannot see patients' medical content.
- Authorities: where the law or a court order requires it, telling the clinic unless the law forbids us.
7. What we never do
- We never sell or rent personal or health data, or share it for advertising.
- We never use patients' data for marketing or to train AI models, and never contact a clinic's patients for our own purposes.
8. Security
- All connections are encrypted (HTTPS), every clinic's integration keys are stored encrypted, and every clinic has a separate database.
- Private files open only through short-lived signed links, two-step verification is available for every account and can be required for key roles, and accounts lock temporarily after repeated failed sign-ins.
- Role-based permissions, medical data kept apart from reception's, an access log for every medical record, and daily backups.
9. Retention
- We keep the clinic's data for as long as it subscribes, and backups for 14 days.
- After cancelling, the clinic can download a complete copy of its data, and when it asks for permanent deletion we delete its database and files, and the remaining backups expire within 30 days.
- Retention periods for medical records are set by the clinic under the professional laws it is subject to, and we keep billing data for as long as tax law requires.
10. Patients' rights
- Patients have the right to know what data is held about them, to get a copy, to correct it, to ask for it to be deleted or its processing restricted, to object, and to withdraw consent, as far as the law allows.
- Patients exercise these rights through the clinic they deal with, which controls their data; if a patient writes to us we pass the request to the clinic and help it carry it out.
- Patients can stop reminder messages any time from the stop link in the message.
- Minors' data is recorded by or with the consent of their guardian, whom the system contacts about appointments and reminders.
11. Your rights as a user
- Know what data we hold about you and get a copy, correct it, ask for it to be deleted or its processing restricted, and object to marketing.
- You can complain to the Personal Data Protection Centre if you believe your rights were not respected.
12. Breach notification
- If a breach affects clinic data we notify the clinic without delay and within 24 hours of becoming aware of it, and help it notify the Personal Data Protection Centre within the period the law sets and inform the patients affected where needed.
- If a breach affects data we control, we notify the Centre and those affected ourselves as the law requires.
13. Cookies
- On clinicato.com we use only the cookies needed for signing in and security, and if we turn on ad measurement tools we say so here.