اتفاق معالجة البيانات (DPA)
1 تمهيد ونطاق الاتفاق
يُبرم هذا الاتفاق ("اتفاق معالجة البيانات" أو "DPA") بين العيادة أو المنشأة الصحية المشتركة في خدمة Do Pro ("المتحكم")، وبين Do Pro ("المعالج")، ويُعد جزءاً لا يتجزأ من شروط الاستخدام وسياسة الخصوصية الخاصة بالخدمة، ويحكم معالجة Do Pro لبيانات المرضى وأي بيانات شخصية أخرى يُدخلها المتحكم أو مستخدموه في الخدمة نيابةً عن المتحكم.
يُبرم هذا الاتفاق تنفيذاً لأحكام قانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020 ولائحته التنفيذية، وبالقدر الذي تنطبق فيه هذه الأحكام على العلاقة بين الطرفين.
2 التعريفات
- "البيانات الشخصية": أي بيانات تتعلق بشخص طبيعي محدد أو قابل للتحديد، بما في ذلك بيانات المرضى.
- "بيانات المرضى": البيانات الصحية والشخصية للمرضى التي يدخلها المتحكم أو مستخدموه في الخدمة، وتُعد من البيانات الشخصية الحساسة.
- "المتحكم": العيادة أو المنشأة الصحية التي تحدد أغراض ووسائل معالجة بيانات المرضى.
- "المعالج": Do Pro، بصفتها الجهة التي تعالج بيانات المرضى نيابةً عن المتحكم ووفق تعليماته.
- "المعالج من الباطن": أي طرف ثالث يستعين به Do Pro لمعالجة بيانات المرضى ضمن تشغيل الخدمة.
- "صاحب البيانات": الشخص الطبيعي الذي تخصه البيانات الشخصية محل المعالجة (المريض أو المستخدم).
- "حادث الاختراق الأمني": أي واقعة تؤدي إلى إتلاف أو فقدان أو تعديل أو إفشاء غير مصرح به لبيانات شخصية، سواء عرضياً أو غير مشروع.
3 أدوار الأطراف
فيما يتعلق ببيانات المرضى، يكون المتحكم هو "متحكم البيانات" المسؤول عن تحديد أغراض ووسائل المعالجة والتأكد من وجود الأساس القانوني والموافقات اللازمة، ويعمل Do Pro بصفته "معالج بيانات" يعالج بيانات المرضى فقط نيابةً عن المتحكم وبالقدر اللازم لتقديم الخدمة.
فيما يتعلق ببيانات حساب المشترك والفوترة والبيانات اللازمة لإدارة العلاقة التعاقدية مع Do Pro، قد يعمل Do Pro بصفته متحكماً بالقدر اللازم لهذه الأغراض، وذلك دون إخلال بالتزاماته كمعالج لبيانات المرضى.
4 موضوع المعالجة ومدتها وطبيعتها وغرضها
| البند | التفاصيل |
|---|---|
| موضوع المعالجة | تشغيل خدمة إدارة العيادات (ملفات المرضى، المواعيد، الجلسات، الخطط الغذائية والعلاجية، التقارير، المتابعات) |
| مدة المعالجة | طوال فترة سريان اشتراك المتحكم، وحتى انتهاء فترة الاحتفاظ بعد الإنهاء وفق سياسة الخصوصية |
| طبيعة المعالجة | التخزين، الاسترجاع، التنظيم، التحليل الآلي المساعد (حاسبات، خطط، تنبيهات)، النسخ الاحتياطي، النقل التقني اللازم لتشغيل الخدمة |
| فئات البيانات | بيانات هوية المريض، بيانات صحية (تاريخ مرضي، قياسات، تشخيصات مدخلة، خطط علاجية وغذائية)، بيانات تواصل |
| فئات أصحاب البيانات | مرضى العيادة المشتركة |
| الغرض | تمكين المتحكم من إدارة عيادته وتقديم الخدمة الصحية لمرضاه من خلال منصة Do Pro |
5 المعالجة وفق تعليمات المتحكم
- يلتزم Do Pro بمعالجة بيانات المرضى فقط بناءً على تعليمات المتحكم الموثقة، والتي تشمل التعليمات المضمنة في هذا الاتفاق وفي إعدادات واستخدام الخدمة نفسها.
- إذا رأى Do Pro أن تعليمة معينة من المتحكم تخالف قانون حماية البيانات المصري أو أي قانون آمر آخر، يُخطر المتحكم فوراً قبل تنفيذها، دون إخلال بحق Do Pro في تعليق التنفيذ إلى حين التوضيح.
- لا يستخدم Do Pro بيانات المرضى لأي غرض خارج نطاق تقديم الخدمة، بما في ذلك عدم استخدامها للتسويق أو التحليل الإعلاني أو تدريب نماذج أو أدوات لغرض غير مرتبط بتقديم الخدمة للمتحكم نفسه، دون موافقة كتابية صريحة منفصلة.
6 سرية الأفراد المصرح لهم
يلتزم Do Pro بأن يقتصر الوصول إلى بيانات المرضى على الموظفين والمتعاقدين الذين تستلزم طبيعة عملهم ذلك، وأن يكونوا ملتزمين بالتزامات سرية تعاقدية أو قانونية مكتوبة قبل منحهم أي صلاحية وصول، وأن يتلقوا توعية أساسية بمتطلبات حماية البيانات الصحية.
7 التدابير الأمنية
يطبق Do Pro تدابير تقنية وتنظيمية مناسبة لطبيعة البيانات والمخاطر المرتبطة بها، وتشمل على الأقل:
- التشفير أثناء النقل وعند التخزين، حيث تدعمه البنية التقنية ومزودو الخدمة.
- نظام صلاحيات وصول قائم على الأدوار (superadmin / admin / secretary / user).
- نسخ احتياطية دورية وآليات استعادة موثقة.
- سجلات نشاط وأمان (logs) لرصد الوصول غير المعتاد.
- مراجعات أمنية دورية وإجراءات للحد من مخاطر الوصول غير المصرح به.
يجوز لـ Do Pro تحديث هذه التدابير من وقت لآخر بما يحافظ على مستوى حماية مكافئ أو أعلى.
8 المعالجون من الباطن
يوافق المتحكم بموجب هذا الاتفاق موافقة عامة على استعانة Do Pro بمعالجين من الباطن لتشغيل الخدمة، ومنهم حالياً (بحسب المكونات المفعلة فعلياً):
- Supabase — لخدمات قاعدة البيانات، المصادقة، والتخزين.
- Firebase (Google) — لاستضافة صفحات الموقع وبعض المكونات التقنية حيث تكون مفعلة.
- Google — لخدمات تسجيل الدخول الموحد أو التحليلات حيث تكون مفعلة (على مستوى الموقع العام فقط، دون بيانات المرضى).
- مزودو خدمات الإشعارات وروابط WhatsApp للتواصل التشغيلي.
- أي مزود دفع يتم تفعيله مستقبلاً لمعالجة بيانات الفوترة.
يلتزم Do Pro بفرض التزامات حماية بيانات مكافئة لالتزاماته بموجب هذا الاتفاق على أي معالج من الباطن، وبإخطار المتحكم بأي تغيير جوهري في قائمة المعالجين من الباطن (إضافة أو استبدال) قبل التفعيل بفترة معقولة، مع منح المتحكم فرصة الاعتراض لأسباب حماية بيانات معقولة؛ وفي حال عدم التوصل لحل، يجوز لأي من الطرفين إنهاء الاشتراك وفق بند الإنهاء في شروط الاستخدام.
9 المساعدة في طلبات أصحاب البيانات
يقدم Do Pro للمتحكم الدعم التقني المعقول ضمن إمكانات الخدمة للاستجابة لطلبات أصحاب البيانات (المرضى) المتعلقة بالوصول أو التصحيح أو الحذف أو تقييد المعالجة، وذلك خلال مدة معقولة من إخطار المتحكم بالطلب، مع مراعاة القيود التقنية والقانونية المعمول بها.
10 المساعدة في تقييم أثر حماية البيانات
يقدم Do Pro للمتحكم، عند الطلب المعقول وبالقدر المتاح لديه، المعلومات اللازمة لمساعدته في إجراء تقييم أثر حماية البيانات أو التشاور المسبق مع الجهة التنظيمية المختصة، إذا تطلب القانون ذلك.
11 الإخطار بالاختراق الأمني
- عند اكتشاف Do Pro لحادث اختراق أمني مؤكد أو محتمل قد يؤثر على بيانات المرضى، يُخطر المتحكم دون تأخير غير مبرر، وفي حدود 72 ساعة من العلم بالحادث حيثما أمكن عملياً.
- يتضمن الإخطار، بالقدر المتاح وقت الإخطار: طبيعة الحادث، الفئات وأعداد سجلات البيانات المتأثرة تقريباً، الإجراءات المتخذة أو المقترحة للاحتواء والحد من الأثر، وجهة التواصل لمزيد من المعلومات.
- يتعاون Do Pro مع المتحكم في التحقيق والاحتواء، ويزوده بالمعلومات المعقولة اللازمة لوفاء المتحكم بالتزاماته تجاه الجهات التنظيمية وأصحاب البيانات المتأثرين خلال المواعيد القانونية.
12 حق التدقيق والمراجعة
يجوز للمتحكم، بإخطار كتابي مسبق لا تقل مدته عن 15 يوم عمل ولمرة واحدة كل 12 شهراً (ما لم يكن هناك حادث أمني يستدعي خلاف ذلك)، أن يطلب من Do Pro استبيان أمني أو تقرير امتثال يوضح التدابير الفنية والتنظيمية المطبقة. يجوز لـ Do Pro تلبية هذا الطلب من خلال تقديم شهادات أو تقارير امتثال معتمدة (إن وجدت) بدلاً من تدقيق ميداني مباشر، حفاظاً على أمن وسرية بيانات العيادات الأخرى المستضافة على نفس البنية التحتية.
13 النقل الدولي للبيانات
قد تُعالج أو تُخزن بعض بيانات المرضى لدى معالجين من الباطن خارج جمهورية مصر العربية بحسب مواقع البنية التحتية المستخدمة. يقر المتحكم بذلك ويوافق عليه بموجب هذا الاتفاق، وذلك دون إخلال بالتزام Do Pro باستيفاء أي متطلبات ترخيص أو تصريح أو موافقة أو مستوى حماية مناسب يفرضه القانون المصري على هذا النقل.
14 إرجاع أو حذف البيانات عند الإنهاء
- عند انتهاء أو إنهاء اشتراك المتحكم، يتيح Do Pro له فترة تصدير بيانات المرضى وفق ما هو منصوص عليه في شروط الاستخدام وإمكانات خطته.
- بعد انتهاء فترة الإتاحة، يحذف Do Pro بيانات المرضى من أنظمته التشغيلية النشطة، مع جواز الاحتفاظ بنسخ احتياطية لفترة محدودة لأغراض أمنية أو قانونية وفق دورة الاحتفاظ المعتمدة، ثم التخلص منها بعد ذلك.
- يجوز لـ Do Pro الاحتفاظ ببيانات يلزم الاحتفاظ بها بموجب القانون المصري أو لإثبات حقوقه القانونية، وذلك بالقدر اللازم فقط.
15 المسؤولية
تخضع مسؤولية كل طرف بموجب هذا الاتفاق لسقف وشروط المسؤولية المنصوص عليها في شروط الاستخدام، بما في ذلك سقف المسؤولية الإجمالية المحدد فيها، وذلك دون إخلال بأي مسؤولية لا يجوز قانوناً استبعادها أو الحد منها.
16 المدة والإنهاء
يسري هذا الاتفاق طوال مدة سريان اشتراك المتحكم في الخدمة، وينتهي تلقائياً بانتهاء أو إنهاء ذلك الاشتراك، مع استمرار سريان الالتزامات المتعلقة بالسرية وحذف البيانات والمسؤولية بعد الإنهاء بالقدر اللازم لتحقيق الغرض منها.
17 العلاقة بشروط الاستخدام وسياسة الخصوصية
يُشكل هذا الاتفاق جزءاً مكملاً لشروط الاستخدام وسياسة الخصوصية الخاصة بـ Do Pro. في حال وجود تعارض بين هذا الاتفاق وبينهما فيما يخص معالجة بيانات المرضى تحديداً، يُطبق هذا الاتفاق بالقدر الذي لا يخالف القانون؛ وفيما عدا ذلك تظل شروط الاستخدام وسياسة الخصوصية سارية.
18 القانون الحاكم والاختصاص القضائي
يخضع هذا الاتفاق ويُفسَّر وفقاً لقوانين جمهورية مصر العربية. أي نزاع ينشأ عنه يُسعى أولاً إلى حله بالتفاوض بحسن نية، وإذا تعذر ذلك يكون الاختصاص للمحاكم المصرية المختصة نوعياً ومكانياً.
19 لغة الوثيقة وأولوية النصوص
هذا الاتفاق مُعدّ باللغتين العربية والإنجليزية. عند وجود أي تعارض أو تباين بين النسختين، تكون النسخة العربية هي النسخة المعتمدة والملزمة قانوناً، وتُعتبر النسخة الإنجليزية مقدَّمة للتيسير فقط.
20 التواصل
لأي استفسار حول هذا الاتفاق، يمكنك التواصل عبر:
البريد الإلكتروني: info@doproclinics.com
واتساب: 0110 248 7975
1 Introduction and Scope
This Data Processing Agreement ("DPA") is entered into between the clinic or healthcare facility subscribing to the Do Pro service (the "Controller") and Do Pro (the "Processor"). It forms an integral part of the Terms of Service and Privacy Policy of the Service, and governs Do Pro's processing of Patient Data and any other personal data entered by the Controller or its Users into the Service on the Controller's behalf.
This Agreement is entered into pursuant to Egyptian Personal Data Protection Law No. 151 of 2020 and its implementing regulations, to the extent applicable to the relationship between the parties.
2 Definitions
- "Personal Data": any data relating to an identified or identifiable natural person, including Patient Data.
- "Patient Data": the health and personal data of patients entered into the Service by the Controller or its Users, considered sensitive personal data.
- "Controller": the clinic or healthcare facility that determines the purposes and means of processing Patient Data.
- "Processor": Do Pro, processing Patient Data on the Controller's behalf and in accordance with its instructions.
- "Sub-processor": any third party engaged by Do Pro to process Patient Data as part of operating the Service.
- "Data Subject": the natural person to whom the personal data relates (the patient or user).
- "Personal Data Breach": any incident leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data.
3 Roles of the Parties
With respect to Patient Data, the Controller is the "data controller" responsible for determining the purposes and means of processing and ensuring the required legal basis and consents are in place, and Do Pro acts as a "data processor," processing Patient Data solely on the Controller's behalf and to the extent necessary to provide the Service.
With respect to Subscriber account, billing, and contractual-relationship data, Do Pro may act as a controller to the extent necessary for those purposes, without affecting its obligations as processor of Patient Data.
4 Subject Matter, Duration, Nature and Purpose of Processing
| Item | Details |
|---|---|
| Subject matter | Operation of the clinic management Service (patient records, appointments, sessions, diet and therapeutic plans, reports, follow-ups) |
| Duration | For the duration of the Controller's subscription, and until the end of the applicable retention period following termination as set out in the Privacy Policy |
| Nature | Storage, retrieval, organization, assistive automated analysis (calculators, plans, alerts), backup, and technical transmission necessary to operate the Service |
| Categories of data | Patient identity data, health data (medical history, measurements, entered diagnoses, therapeutic and dietary plans), contact data |
| Categories of data subjects | Patients of the subscribing clinic |
| Purpose | Enabling the Controller to manage its clinic and provide healthcare services to its patients through the Do Pro platform |
5 Processing on the Controller's Instructions
- Do Pro shall process Patient Data only on the Controller's documented instructions, including instructions embedded in this Agreement and in the Controller's configuration and use of the Service itself.
- If Do Pro considers that an instruction from the Controller infringes Egyptian data protection law or other mandatory law, it will notify the Controller promptly before carrying it out, without prejudice to Do Pro's right to suspend execution pending clarification.
- Do Pro does not use Patient Data for any purpose outside the scope of providing the Service, including not using it for marketing, advertising analytics, or training models or tools unrelated to providing the Service to the Controller itself, without separate express written consent.
6 Confidentiality of Authorized Personnel
Do Pro ensures that access to Patient Data is limited to employees and contractors whose role requires it, that they are bound by written contractual or statutory confidentiality obligations before being granted access, and that they receive basic awareness of health-data protection requirements.
7 Security Measures
Do Pro implements technical and organizational measures appropriate to the nature of the data and associated risks, including at minimum:
- Encryption in transit and at rest, where supported by the technical architecture and service providers.
- Role-based access control (superadmin / admin / secretary / user).
- Regular backups and documented recovery mechanisms.
- Activity and security logs to detect unusual access.
- Periodic security reviews and measures to reduce unauthorized-access risk.
Do Pro may update these measures from time to time provided an equivalent or higher level of protection is maintained.
8 Sub-processors
The Controller grants Do Pro general authorization under this Agreement to engage sub-processors to operate the Service, currently including (depending on components actually enabled):
- Supabase — database, authentication, and storage services.
- Firebase (Google) — website hosting and certain technical components where enabled.
- Google — single sign-on or analytics services where enabled (public website level only, excluding Patient Data).
- Notification and WhatsApp messaging providers for operational communication.
- Any payment provider activated in the future for billing data processing.
Do Pro imposes data-protection obligations on any sub-processor equivalent to its obligations under this Agreement, and will notify the Controller of any material change to the sub-processor list (addition or replacement) with reasonable prior notice, giving the Controller an opportunity to object on reasonable data-protection grounds; if unresolved, either party may terminate the subscription in accordance with the termination provisions of the Terms of Service.
9 Assistance with Data Subject Requests
Do Pro provides the Controller with reasonable technical support, within the capabilities of the Service, to respond to data subject (patient) requests concerning access, correction, deletion, or restriction of processing, within a reasonable period after being notified of the request, subject to applicable technical and legal limitations.
10 Assistance with Data Protection Impact Assessments
Upon reasonable request and to the extent available, Do Pro provides the Controller with information necessary to assist it in carrying out a data protection impact assessment or prior consultation with the competent regulator, where required by law.
11 Personal Data Breach Notification
- Upon discovering a confirmed or reasonably suspected Personal Data Breach that may affect Patient Data, Do Pro will notify the Controller without undue delay, and within 72 hours of becoming aware of the incident where reasonably practicable.
- The notification will include, to the extent available at the time: the nature of the incident, approximate categories and volume of affected records, measures taken or proposed to contain and mitigate the impact, and a contact point for further information.
- Do Pro cooperates with the Controller in investigation and containment, and provides reasonably available information necessary for the Controller to meet its obligations toward regulators and affected data subjects within statutory deadlines.
12 Audit Rights
With at least 15 business days' prior written notice, and no more than once every 12 months (unless a security incident warrants otherwise), the Controller may request that Do Pro provide a security questionnaire or compliance report describing the technical and organizational measures in place. Do Pro may satisfy such a request by providing available compliance certifications or reports in lieu of an on-site audit, to protect the security and confidentiality of other clinics hosted on the same infrastructure.
13 International Data Transfers
Some Patient Data may be processed or stored by sub-processors outside the Arab Republic of Egypt, depending on the infrastructure locations used. The Controller acknowledges and consents to this under this Agreement, without prejudice to Do Pro's obligation to satisfy any licensing, authorization, consent, or adequate-protection requirement imposed by Egyptian law on such transfer.
14 Return or Deletion of Data on Termination
- Upon expiry or termination of the Controller's subscription, Do Pro provides an export period for Patient Data as set out in the Terms of Service and according to the capabilities of the applicable plan.
- After the export period ends, Do Pro deletes Patient Data from its active operational systems, subject to retaining backup copies for a limited period for security or legal purposes under the applicable retention cycle, after which they are disposed of.
- Do Pro may retain data required to be kept under Egyptian law or to establish its legal rights, to the extent necessary only.
15 Liability
Each party's liability under this Agreement is subject to the liability cap and terms set out in the Terms of Service, including the aggregate liability cap specified therein, without prejudice to any liability that cannot lawfully be excluded or limited.
16 Term and Termination
This Agreement remains in effect for the duration of the Controller's subscription to the Service and terminates automatically upon expiry or termination of that subscription, with obligations relating to confidentiality, data deletion, and liability surviving termination to the extent necessary to fulfill their purpose.
17 Relationship with the Terms of Service and Privacy Policy
This Agreement forms an integral supplement to Do Pro's Terms of Service and Privacy Policy. In the event of a conflict between this Agreement and either of them specifically regarding the processing of Patient Data, this Agreement governs to the extent it does not conflict with mandatory law; otherwise, the Terms of Service and Privacy Policy remain in effect.
18 Governing Law and Jurisdiction
This Agreement is governed by and construed in accordance with the laws of the Arab Republic of Egypt. Any dispute arising from it shall first be resolved through good-faith negotiation; if unresolved, the competent Egyptian courts shall have exclusive jurisdiction.
19 Governing Language
This Agreement is prepared in both Arabic and English. In the event of any conflict or discrepancy between the two versions, the Arabic version shall be the authoritative and legally binding version, and the English version is provided for convenience only.
20 Contact
For any questions about this Agreement, contact us at:
Email: info@doproclinics.com
WhatsApp: 0110 248 7975