سياسة الخصوصية
1 مقدمة
تحترم Do Pro خصوصية المستخدمين والمرضى وتلتزم بحماية البيانات الشخصية وفق قانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020 ولائحته التنفيذية. توضح هذه السياسة أنواع البيانات التي نجمعها، وكيف نستخدمها، وكيف نحميها، وحقوقك.
2 البيانات التي نجمعها
- بيانات الحساب: الاسم، البريد الإلكتروني، رقم الهاتف، اسم العيادة، معرف العيادة، وكلمة المرور (مشفرة).
- بيانات المرضى: الاسم، التاريخ والبيانات الصحية، القياسات، الخطط الغذائية والعلاجية، سجل الجلسات والمتابعات، والتقارير — وتُدخلها العيادات بحسب صلاحياتها.
- بيانات الدفع: خطة الاشتراك، فترة الفوترة، وبيانات التواصل للفوترة (لا نخزن بيانات بطاقات الدفع مباشرة).
- بيانات تقنية: عنوان IP، نوع المتصفح والجهاز، وسجلات النشاط في حدود الغرض التشغيلي.
3 كيف نجمع البيانات
- تُقدَّم مباشرة بواسطة المستخدمين عند التسجيل أو إدخال البيانات.
- تُجمع تلقائياً (بيانات تقنية) أثناء استخدام الخدمة.
- عبر خدمات الدخول الموحد (مثل تسجيل الدخول عبر Google) حيث يسمح بها.
4 أغراض المعالجة
- تشغيل الخدمة وتقديمها وصيانتها وتحسينها.
- إدارة الحسابات والاشتراكات والفوترة وطلبات الترقية.
- تقديم الدعم الفني والتواصل التشغيلي.
- الالتزام بالالتزامات القانونية وفرض الشروط.
5 الأساس القانوني للمعالجة
- تنفيذ العقد (شروط الاستخدام) الذي أبرمته معنا.
- موافقتك الصريحة حيث يلزمها القانون.
- الالتزام بالتزام قانوني.
- مصلحتنا المشروعة في تحسين الخدمة وأمنها.
6 البيانات الصحية الحساسة
تُعد بيانات المرضى الصحية بيانات حساسة بموجب القانون المصري. تُعالج هذه البيانات حصرياً بتوجيه من مسؤول المعالجة (العيادة) وحصرياً لأغراض إدارة الحالة الصحية. نحن لا نستخدم بيانات المرضى لأي أغراض تسويقية أو تحليلية خارج إطار الخدمة، ولا نشاركها إلا بموجب القانون أو بتعليمات مسؤول المعالجة.
7 مشاركة البيانات
- لا نبيع بياناتك أو بيانات مرضاك.
- نتشارك البيانات مع مزودي خدمات تقنية لدعم الخدمة (استضافة، تخزين، مصادقة، إشعارات) ضمن اتفاقات حماية بيانات ملزمة.
- نكشف البيانات إذا تطلب القانون ذلك أو بأمر قضائي أو تنظيمي، أو لحماية حقوقنا ومستخدمينا.
8 أمن البيانات
- تشفير البيانات أثناء النقل (TLS) وعند التخزين.
- ضبط صلاحيات الوصول بنظام أدوار صارم (superadmin / admin / secretary / user).
- نسخ احتياطية منتظمة ومراجعات أمنية دورية.
- حدود وصول صارمة للفريق التقني وفحوص خلفية بحسب ما يسمح به القانون.
9 الاحتفاظ بالبيانات
نحتفظ بالبيانات طوال فترة الاشتراك، ولمدة معقولة بعد إنهائه بما يسمح بالتصدير والالتزامات القانونية. عند انتهاء المدة، تُحذف البيانات أو تُتلف بشكل آمن. سجلات النشاط التدقيقية تُنظف دورياً وفق السياسة التشغيلية.
10 حقوق أصحاب البيانات
- حق الوصول إلى بياناتك الشخصية.
- حق طلب التصحيح أو التحديث.
- حق طلب الحذف (وفق القيود القانونية).
- حق طلب تقييد المعالجة أو الاعتراض عليها في الحالات المنصوص عليها.
- حق نقل البيانات (المصادرة) حيث ينطبق ذلك.
تتم ممارسة هذه الحقوق عبر التواصل معنا، أو عبر العيادة بصفتها مسؤول المعالجة لبيانات المرضى. نرد على الطلبات خلال المدة القانونية.
11 بيانات الأطفال
لا نجمع بيانات الأطفال دون موافقة ولي الأمر. عند معالجة بيانات قاصريين (أقل من 15 عاماً وفق القانون المصري) تتطلب الموافقة من ولي الأمر، وتتحمل العيادة مسؤولية التحقق من ذلك.
12 ملفات تعريف الارتباط (Cookies)
نستخدم ملفات تعريف ارتباط وتخزين محلي (localStorage / IndexedDB) لأغراض الجلسات، تفضيلات اللغة، تخزين الرموز (tokens)، والتخزين المؤقت للبيانات لعمل الخدمة دون اتصال. لا نستخدمها لتتبعك لأغراض إعلانية.
13 الخدمات الخارجية
تعتمد الخدمة على مزودي خدمات خارجيين منهم: Supabase (قاعدة البيانات والمصادقة والاستضافة)، ومنصات الإشعارات، وخدمات الدخول عبر Google، وروابط واتساب. تخضع بياناتك في هذه الخدمات لسياساتهم، ونلتزم باختيار مزودين يتوافقون مع معايير أمنية معقولة.
14 النقل عبر الحدود
قد تُخزن البيانات على خوادم خارج جمهورية مصر العربية. يتم أي نقل عبر الحدود وفق أحكام القانون (بما فيها أحكام المادة 14 من قانون حماية البيانات الشخصية المصري) وبالضمانات المناسبة، وبموافقة الأطراف المعنية حيث يلزم ذلك.
15 إخطار الاختراق
- في حال وقوع خرق أمني قد يؤثر على البيانات الشخصية، سنُخطِر العيادات المتأثرة دون تأخير غير مبرر.
- نتيح للعيادات ما يلزم لتمكينها من إبلاغ الجهات التنظيمية (المركز القومي لحماية البيانات الشخصية) والأفراد المتأثرين ضمن المواعيد القانونية.
- الالتزام التنظيمي بالإخطار يقع على مسؤول المعالجة (العيادة) وفق القانون؛ ونحن نلتزم بدورنا بتزويدها بالمعلومات الدقيقة المتاحة لدينا.
16 التعديلات على السياسة
قد نحدّث هذه السياسة من وقت لآخر، ويُنشر أي تحديث جوهري عبر إشعار. يُعد استمرارك في استخدام الخدمة بعد التعديل قبولاً بالسياسة المحدّثة.
17 التواصل
لأي استفسار أو ممارسة حقوقك، تواصل معنا عبر:
البريد الإلكتروني: info@doproclinics.com
واتساب: 0110 248 7975
18 تاريخ السريان
تسري هذه السياسة اعتباراً من تاريخ الإصدار الموضح أعلاه وتُحدَّث عند الحاجة وفق أحكام المادة (16).
1 Introduction
Do Pro respects the privacy of users and patients and is committed to protecting personal data in accordance with the Egyptian Personal Data Protection Law No. 151 of 2020 and its implementing regulations. This policy describes the data we collect, how we use and protect it, and your rights.
2 Data We Collect
- Account data: name, email, phone number, clinic name, clinic identifier, and (encrypted) password.
- Patient data: name, health history and data, measurements, dietary and therapeutic plans, session and follow-up records, and reports — entered by clinics under their own authority.
- Payment data: subscription plan, billing period, and billing contact details (we do not directly store card details).
- Technical data: IP address, browser and device type, and activity logs within operational scope.
3 How We Collect Data
- Provided directly by users during registration or data entry.
- Collected automatically (technical data) during use of the Service.
- Via single sign-on services (such as Google sign-in) where enabled.
4 Purposes of Processing
- Operating, providing, maintaining and improving the Service.
- Managing accounts, subscriptions, billing and upgrade requests.
- Providing technical support and operational communications.
- Complying with legal obligations and enforcing the terms.
5 Legal Basis for Processing
- Performance of the contract (Terms of Service) concluded with us.
- Your explicit consent where required by law.
- Compliance with a legal obligation.
- Our legitimate interest in improving the security and quality of the Service.
6 Sensitive Health Data
Patient health data is considered sensitive data under Egyptian law. It is processed exclusively at the direction of the data controller (the clinic) and solely for healthcare management purposes. We do not use patient data for marketing or off-Service analytics, and we do not share it except as required by law or as instructed by the controller.
7 Data Sharing
- We do not sell your data or your patients' data.
- We share data with technical service providers supporting the Service (hosting, storage, authentication, notifications) under binding data protection agreements.
- We disclose data where required by law or by judicial or regulatory order, or to protect our rights and our users.
8 Data Security
- Encryption of data in transit (TLS) and at rest.
- Access control through a strict role system (superadmin / admin / secretary / user).
- Regular backups and periodic security reviews.
- Strict access limits for the technical team and background checks where permitted by law.
9 Data Retention
We retain data for the subscription period and for a reasonable period after termination to allow export and legal compliance. After that period, data is securely deleted or destroyed. Audit activity logs are periodically cleaned in accordance with the operational policy.
10 Your Data Rights
- The right to access your personal data.
- The right to request correction or update.
- The right to request deletion (subject to legal limitations).
- The right to request restriction of, or object to, processing where provided by law.
- The right to data portability where applicable.
These rights are exercised by contacting us, or through the clinic as the data controller for patient data. We respond within the legally required timeframe.
11 Children's Data
We do not collect children's data without guardian consent. When processing data of minors (under 15 years old under Egyptian law), consent from the guardian is required, and the clinic is responsible for verifying this.
12 Cookies
We use cookies and local storage (localStorage / IndexedDB) for sessions, language preferences, token storage, and offline data caching required for the Service to function. We do not use them to track you for advertising purposes.
13 Third-Party Services
The Service relies on external providers including: Supabase (database, authentication and hosting), notification platforms, Google sign-in, and WhatsApp links. Your data within these services is subject to their policies, and we commit to selecting providers that meet reasonable security standards.
14 Cross-Border Transfers
Data may be stored on servers outside the Arab Republic of Egypt. Any cross-border transfer is carried out in accordance with the law (including Article 14 of the Egyptian Personal Data Protection Law) with appropriate safeguards and, where required, the consent of the parties concerned.
15 Breach Notification
- In the event of a security breach affecting personal data, we will notify the affected clinics without undue delay.
- We provide what is needed to enable clinics to inform regulators (the Egyptian Data Protection Center) and affected individuals within the legally required timeframes.
- The regulatory notification obligation lies with the data controller (the clinic) under the law; we commit to providing accurate information available to us.
16 Changes to This Policy
We may update this policy from time to time, and any material update is published with notice. Continued use of the Service after a change constitutes acceptance of the updated policy.
17 Contact
For any questions or to exercise your rights, contact us at:
Email: info@doproclinics.com
WhatsApp: 0110 248 7975
18 Effective Date
This policy is effective as of the release date shown above and is updated when necessary in accordance with Section (16).