سياسة الخصوصية
1 مقدمة ونطاق السياسة
تحترم Do Pro خصوصية المستخدمين والمرضى وتتعامل مع البيانات الشخصية وفق قانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020 ولائحته التنفيذية، وبقدر ما ينطبق على الخدمة والعمليات التي ننفذها فعلياً.
بالنسبة إلى بيانات المرضى التي تُدخلها العيادة أو مستخدموها في الخدمة، تكون العيادة أو المنشأة الصحية هي متحكم البيانات (Controller)، وتعمل Do Pro كـمعالج بيانات (Processor) لمعالجة تلك البيانات نيابةً عن المتحكم ووفق تعليماته وفي حدود تقديم الخدمة. أما بيانات حساب المشترك وبيانات الفوترة والبيانات اللازمة لإدارة العلاقة التعاقدية مع Do Pro، فقد تكون Do Pro متحكماً فيها بالقدر اللازم لهذه الأغراض.
لا تمنح هذه السياسة Do Pro حقاً أوسع من الحقوق والسلطات اللازمة لتشغيل الخدمة، ولا تنشئ التزامات تقنية أو تشغيلية تتجاوز ما يتم تنفيذه فعلياً في الخدمة.
2 البيانات التي نجمعها
- بيانات الحساب: الاسم، البريد الإلكتروني، رقم الهاتف، اسم العيادة، معرف العيادة، وبيانات المصادقة. لا نحتفظ بكلمة المرور بصورتها النصية؛ ويعالج مزود المصادقة كلمة المرور باستخدام تجزئة تشفيرية آمنة.
- بيانات المرضى: الاسم، التاريخ والبيانات الصحية، القياسات، الخطط الغذائية والعلاجية، سجل الجلسات والمتابعات، والتقارير — وتُدخلها العيادات بحسب صلاحياتها.
- بيانات الدفع: خطة الاشتراك، فترة الفوترة، وبيانات التواصل اللازمة للفوترة. لا نحتفظ ببيانات بطاقات الدفع مباشرة عندما تتم المدفوعات من خلال مزود دفع خارجي.
- بيانات تقنية وتشغيلية: نوع المتصفح والجهاز، معرّفات تقنية، سجلات الأخطاء والنشاط اللازمة للأمن وتشغيل الخدمة، وقد تُعالج بيانات الشبكة مثل عنوان IP عند الحاجة التقنية أو الأمنية.
- بيانات الاستخدام والتحليلات: قد تُستخدم أدوات تحليلات على صفحات الموقع العامة أو الواجهات التي يتم تفعيلها فيها، وفق إعداداتها الفعلية. ولا يجوز إرسال بيانات المرضى أو البيانات الصحية إلى أدوات التحليلات.
3 كيف نجمع البيانات
- تُقدَّم مباشرة بواسطة المستخدمين عند التسجيل أو إدخال البيانات.
- تُجمع تلقائياً (بيانات تقنية) أثناء استخدام الخدمة.
- عبر خدمات الدخول الموحد (مثل تسجيل الدخول عبر Google) حيث يسمح بها، وفق البيانات التي يتيحها مزود تسجيل الدخول.
4 أغراض المعالجة
- تشغيل الخدمة وتقديمها وصيانتها وتحسينها.
- إدارة الحسابات والاشتراكات والفوترة وطلبات الترقية.
- تقديم الدعم الفني والتواصل التشغيلي.
- الالتزام بالالتزامات القانونية، حماية الخدمة، ومنع إساءة الاستخدام والاحتيال والاختراق.
- إجراء التحليلات التشغيلية أو الإحصائية على بيانات غير صحية وبالقدر اللازم لتحسين الخدمة، دون استخدام بيانات المرضى أو البيانات الصحية لأغراض تحليلية خارج الخدمة.
5 الأساس القانوني للمعالجة
- تنفيذ العقد (شروط الاستخدام) الذي أبرمته معنا.
- موافقتك الصريحة حيث يلزمها القانون.
- الالتزام بالتزام قانوني.
- المصلحة المشروعة، حيث تكون منطبقة قانوناً، في أمن الخدمة وتحسينها وتشغيلها، مع مراعاة عدم تعارضها مع حقوق أصحاب البيانات.
- وبالنسبة للبيانات الصحية الحساسة، لا يُفهم من هذا الأساس العام أنه يجيز معالجتها دون استيفاء المتطلبات الخاصة بها من موافقات أو تراخيص أو تصاريح أو استثناءات قانونية، بحسب الأحوال.
6 البيانات الصحية الحساسة
تُعد البيانات الصحية من البيانات الشخصية الحساسة بموجب القانون المصري. وبالنسبة إلى بيانات المرضى التي تدخلها العيادة، تكون العيادة هي متحكم البيانات وتعمل Do Pro كـمعالج لمعالجتها نيابةً عنها وفي حدود تعليماتها وتقديم الخدمة.
تتحمل العيادة مسؤولية التأكد من وجود الأساس القانوني والموافقات والتراخيص أو التصاريح المطلوبة قبل جمع البيانات الصحية أو إدخالها إلى الخدمة. وتلتزم Do Pro بعدم استخدام بيانات المرضى لأغراض تسويقية أو بيعها أو استخدامها لتحليل إعلاني أو لأغراض ثانوية خارج نطاق الخدمة، إلا إذا كان ذلك مطلوباً أو مسموحاً به قانوناً وبالقدر اللازم لذلك.
7 مشاركة البيانات
- لا نبيع بياناتك أو بيانات مرضاك.
- قد نعتمد على مزودي خدمات تقنية لمعالجة البيانات بالنيابة عنا، مثل خدمات قاعدة البيانات والمصادقة والتخزين والاستضافة والإشعارات والتحليلات أو الدفع، بحسب الخدمات المفعلة فعلياً. يتم اختيارهم وإدارتهم بما يتناسب مع متطلبات الأمن وحماية البيانات، وتكون معالجة بيانات المرضى في حدود أغراض الخدمة وتعليمات المتحكم وبموجب الترتيبات التعاقدية المناسبة حيث يلزم.
- نكشف البيانات إذا تطلب القانون ذلك أو بأمر قضائي أو تنظيمي، أو بالقدر اللازم لحماية حقوقنا أو أمن الخدمة أو مستخدمينا، مع مراعاة القيود القانونية الواجبة.
- لا نمنح مزودي الخدمات المستقلين حقاً مستقلاً في استخدام بيانات المرضى لأغراضهم التسويقية أو الإعلانية لمجرد تقديمهم خدمة تقنية لـDo Pro.
8 أمن البيانات
- استخدام وسائل حماية مناسبة للبيانات أثناء النقل وعند التخزين، بما في ذلك التشفير حيث تدعمه البنية التقنية ومزودو الخدمة.
- ضبط صلاحيات الوصول بنظام أدوار صارم (superadmin / admin / secretary / user).
- نسخ احتياطية وآليات استعادة وفق البنية التشغيلية المتاحة للخدمة، مع مراجعات أمنية وإجراءات للحد من مخاطر الوصول غير المصرح به.
- حدود وصول صارمة للفريق التقني وفحوص خلفية بحسب ما يسمح به القانون.
9 الاحتفاظ بالبيانات
نحتفظ بالبيانات للمدة اللازمة لتقديم الخدمة وإدارة الحساب والعلاقة التعاقدية والامتثال للالتزامات القانونية. بعد إنهاء الاشتراك، قد نتيح للمشترك فترة معقولة لتصدير بياناته وفق إمكانات الخطة والخدمة، ثم تُحذف أو تُتلف بيانات الخدمة الخاضعة لسيطرتنا عندما لا يعود الاحتفاظ بها لازماً، مع استثناء النسخ الاحتياطية أو السجلات التي يلزم الاحتفاظ بها قانوناً أو لأغراض أمنية أو إثبات الحقوق، وتُدار هذه الاستثناءات وفق دورة الاحتفاظ التشغيلية.
لا يعني الحذف من واجهة الخدمة بالضرورة الحذف الفوري من جميع النسخ الاحتياطية؛ ويتم التخلص منها وفق دورة النسخ الاحتياطي المعمول بها.
10 حقوق أصحاب البيانات
- حق الوصول إلى بياناتك الشخصية.
- حق طلب التصحيح أو التحديث.
- حق طلب الحذف (وفق القيود القانونية).
- حق طلب تقييد المعالجة أو الاعتراض عليها في الحالات المنصوص عليها.
- حق نقل البيانات أو الحصول عليها في صورة قابلة للاستخدام حيث ينطبق ذلك وبالقدر الذي يسمح به القانون والخدمة.
تُمارس حقوق أصحاب البيانات المتعلقة ببيانات المرضى من خلال العيادة بصفتها متحكم البيانات، ويمكن لـDo Pro دعم العيادة في تنفيذ الطلبات ضمن قدرات الخدمة. أما حقوق المستخدم المتعلقة بحسابه وبياناته التي تعالجها Do Pro بصفتها متحكماً، فيمكن ممارستها بالتواصل معنا. تخضع الاستجابة للهوية والاختصاص والقيود والمواعيد التي يقررها القانون.
11 بيانات الأطفال
تُعامل بيانات الأطفال باعتبارها بيانات شخصية حساسة وفق القانون المصري. وبالنسبة للأطفال الأقل من 15 عاماً، يجب الحصول قبل جمع البيانات على موافقة كتابية صريحة من ولي الأمر وفق المتطلبات القانونية والتنظيمية المعمول بها. وبالنسبة للفئات العمرية الأخرى، تُطبق متطلبات الموافقة والتمثيل القانوني بحسب الأحوال. وتتحمل العيادة بصفتها متحكم البيانات مسؤولية التحقق من استيفاء هذه المتطلبات قبل إدخال بيانات الطفل إلى الخدمة.
12 ملفات تعريف الارتباط (Cookies)
نستخدم ملفات تعريف الارتباط والتخزين المحلي (localStorage / IndexedDB) بالقدر اللازم للجلسات، وتفضيلات اللغة، والمصادقة، والتخزين المؤقت أو العمل دون اتصال حيث تدعم الخدمة ذلك. وقد تستخدم صفحات الموقع العامة أدوات تحليلات مثل Google Analytics 4 إذا كانت مفعلة، لجمع مؤشرات استخدام مجمعة مثل الزيارات والتفاعل ونوع الجهاز والموقع الجغرافي التقريبي. لا ينبغي إرسال بيانات المرضى أو البيانات الصحية إلى أدوات التحليلات، ولا نستخدم بيانات المرضى لأغراض إعلانية.
تخضع أدوات الطرف الثالث لإعداداتها وسياساتها الخاصة. نراجع إعدادات التحليلات لتقليل جمع البيانات غير الضرورية وتجنب تمرير بيانات شخصية حساسة أو بيانات مرضى إليها.
13 الخدمات الخارجية
تعتمد الخدمة على مزودي خدمات خارجيين بحسب المكونات المفعلة فعلياً، ومنهم خدمات Supabase لقاعدة البيانات والمصادقة والتخزين أو المكونات ذات الصلة، وخدمات Firebase لاستضافة صفحات الموقع حيث تكون مفعلة، وخدمات Google لتسجيل الدخول أو التحليلات حيث تكون مفعلة، وخدمات الإشعارات، وروابط WhatsApp، وأي مزود دفع يتم تفعيله مستقبلاً. لا يُفهم من ذكر أي مزود أن جميع أنواع البيانات تُرسل إليه؛ ويقتصر الإرسال على ما يلزم لتشغيل الميزة المعنية.
تخضع معالجة البيانات لدى هذه الخدمات لشروط وسياسات مزوديها بالإضافة إلى التزامات Do Pro التعاقدية والقانونية. وتبقى العيادة مسؤولة عن تعليمات معالجة بيانات المرضى، بينما تلتزم Do Pro باستخدام مزودي المعالجة في حدود تشغيل الخدمة وبما يتناسب مع متطلبات حماية البيانات.
14 النقل عبر الحدود
قد تُعالج أو تُخزن بعض البيانات لدى مزودي خدمات خارج جمهورية مصر العربية بحسب البنية التحتية ومواقع مراكز البيانات التي تستخدمها الخدمة. ويخضع نقل أو تخزين أو إتاحة البيانات الشخصية عبر الحدود للمتطلبات القانونية والتنظيمية المصرية، بما في ذلك متطلبات الترخيص أو التصريح أو الموافقة أو مستوى الحماية المناسب، بحسب الحالة. لا تُفسر هذه السياسة على أنها تصريح مستقل لإجراء نقل دولي متى كان القانون يتطلب ترخيصاً أو تصريحاً أو استيفاء شروط إضافية.
15 إخطار الاختراق
- عند اكتشاف خرق أمني مؤكد أو محتمل يؤثر مادياً على بيانات شخصية تحت معالجة Do Pro، نتخذ إجراءات الاحتواء والتحقيق والتقييم، ونُخطر المتحكم المتأثر دون تأخير غير مبرر وبالقدر والمعلومات المتاحة لدينا.
- نتعاون مع المتحكم ونوفر له المعلومات ذات الصلة التي تكون متاحة لدينا بالقدر المعقول لتمكينه من الوفاء بالتزاماته النظامية تجاه الجهة التنظيمية أو أصحاب البيانات، بحسب الأحوال.
- توزيع مسؤوليات الإخطار والمهل النظامية يتحدد وفق القانون وصفة كل طرف. ولا تُنشئ هذه السياسة التزاماً على Do Pro بإخطار جهة حكومية أو فرد نيابةً عن العيادة إلا إذا كان ذلك مطلوباً قانوناً أو متفقاً عليه صراحةً.
16 التعديلات على السياسة
قد نحدّث هذه السياسة من وقت لآخر لتعكس تغييرات الخدمة أو المتطلبات القانونية أو التنظيمية. يُنشر أي تحديث جوهري عبر إشعار مناسب، ويُحدد تاريخ السريان في النسخة المنشورة. ولا يُفهم من استمرار استخدام الخدمة وحده أنه يُسقط أي حقوق أو متطلبات موافقة أو إخطار يفرضها القانون.
17 التواصل
لأي استفسار أو ممارسة حقوقك، تواصل معنا عبر:
البريد الإلكتروني: info@doproclinics.com
واتساب: 0110 248 7975
18 تاريخ السريان
تسري هذه السياسة اعتباراً من تاريخ الإصدار الموضح أعلاه. ويجب قراءة هذه السياسة مع شروط الاستخدام v2.0 وأي اتفاق معالجة بيانات (DPA) أو شروط خاصة بالخطة يتم الاتفاق عليها مع المشترك، وفي حال وجود تعارض فيما يتعلق بمعالجة بيانات المرضى، تُطبق الوثيقة التعاقدية الخاصة بمعالجة البيانات بالقدر الذي لا يخالف القانون.
19 لغة الوثيقة وأولوية النصوص
هذه السياسة مُعدّة باللغتين العربية والإنجليزية. عند وجود أي تعارض أو تباين بين النسختين، تكون النسخة العربية هي النسخة المعتمدة والملزمة قانوناً، وتُعتبر النسخة الإنجليزية مقدَّمة للتيسير فقط.
1 Introduction and Scope
Do Pro respects the privacy of users and patients and processes personal data in accordance with Egyptian Personal Data Protection Law No. 151 of 2020 and its implementing regulations, to the extent applicable to the Service and to the processing activities we actually perform.
For Patient Data entered by a clinic or its Users, the clinic or healthcare facility is the data controller, and Do Pro acts as a data processor processing such data on the controller's behalf, in accordance with its instructions and solely to provide the Service. For account, billing and relationship-management data processed for Do Pro's own contractual purposes, Do Pro may act as a controller to the extent necessary for those purposes.
This Policy does not grant Do Pro rights broader than those necessary to operate the Service and does not create technical or operational obligations beyond what the Service actually implements.
2 Data We Collect
- Account data: name, email, phone number, clinic name, clinic identifier, and authentication data. We do not retain passwords in plaintext; the authentication provider processes passwords using secure cryptographic hashing.
- Patient data: name, health history and data, measurements, dietary and therapeutic plans, session and follow-up records, and reports — entered by clinics under their own authority.
- Payment data: subscription plan, billing period and billing contact details. We do not directly retain payment-card details when payments are handled by an external payment provider.
- Technical and operational data: browser and device type, technical identifiers, error/security logs and activity records needed to operate and secure the Service, and network data such as IP address where technically or security necessary.
- Usage and analytics data: analytics tools may be used on public website pages or interfaces where enabled, according to their actual configuration. Patient Data and health data must not be sent to analytics tools.
3 How We Collect Data
- Provided directly by users during registration or data entry.
- Collected automatically (technical data) during use of the Service.
- Via single sign-on services (such as Google sign-in) where enabled, limited to the information made available by the identity provider.
4 Purposes of Processing
- Operating, providing, maintaining and improving the Service.
- Managing accounts, subscriptions, billing and upgrade requests.
- Providing technical support and operational communications.
- Complying with legal obligations, protecting the Service, and preventing misuse, fraud and unauthorized access.
- Performing operational or statistical analysis on non-health data where necessary to improve the Service, without using Patient Data or health data for analytics outside the Service.
5 Legal Basis for Processing
- Performance of the contract (Terms of Service) concluded with us.
- Your explicit consent where required by law.
- Compliance with a legal obligation.
- Our legitimate interests, where legally applicable, in securing, operating and improving the Service, subject to the rights of data subjects.
- For sensitive health data, this general basis does not by itself authorize processing without any required consent, license, permit or statutory exception applicable to the processing.
6 Sensitive Health Data
Patient health data is sensitive personal data under Egyptian law. For Patient Data entered by a clinic, the clinic is the data controller and Do Pro acts as a processor processing such data on the clinic's behalf and within its instructions and the scope of the Service.
The clinic is responsible for ensuring that the required legal basis, consents, licenses, permits or statutory exceptions have been satisfied before collecting or entering health data. Do Pro does not sell Patient Data or use it for marketing, advertising analytics, or unrelated secondary purposes, except where required or expressly permitted by law and only to the necessary extent.
7 Data Sharing
- We do not sell your data or your patients' data.
- We may use technical service providers to process data on our behalf, including database, authentication, storage, hosting, notifications, analytics or payment services, depending on the features actually enabled. Providers are selected and managed with appropriate security and data-protection considerations, and Patient Data is processed only for Service purposes and controller instructions, subject to appropriate contractual arrangements where required.
- We disclose data where required by law or by judicial or regulatory order, or where reasonably necessary to protect our rights, the security of the Service or our users, subject to applicable legal restrictions.
- Technical service providers do not receive an independent right to use Patient Data for their own marketing or advertising merely because they provide a technical service to Do Pro.
8 Data Security
- Appropriate technical safeguards for data in transit and at rest, including encryption where supported by the relevant technical architecture and service providers.
- Access control through a strict role system (superadmin / admin / secretary / user).
- Backups and recovery mechanisms according to the Service's operational architecture, together with security reviews and measures designed to reduce unauthorized-access risks.
- Strict access limits for the technical team and background checks where permitted by law.
9 Data Retention
We retain data for as long as necessary to provide the Service, manage accounts and contractual relationships, and comply with legal obligations. After termination, we may provide the Subscriber with a reasonable export period according to the applicable plan and Service capabilities. We then delete or securely destroy Service data under our control when retention is no longer necessary, except for backups or records that must be retained by law, for security purposes, or to establish or defend legal rights; such exceptions are managed according to the applicable retention cycle.
Deletion from the Service interface does not necessarily mean immediate deletion from all backups; backup copies are removed according to the applicable backup lifecycle.
10 Your Data Rights
- The right to access your personal data.
- The right to request correction or update.
- The right to request deletion (subject to legal limitations).
- The right to request restriction of, or object to, processing where provided by law.
- The right to obtain or port data in a usable form where applicable and to the extent permitted by law and the Service.
Rights concerning Patient Data are exercised through the clinic as data controller, and Do Pro may support the clinic in responding within the Service's capabilities. Rights concerning a user's own account data processed by Do Pro as controller may be exercised by contacting us. Requests are subject to identity verification, legal scope, applicable limitations and statutory timeframes.
11 Children's Data
Children's data is treated as sensitive personal data under Egyptian law. For children under 15, written and explicit parental consent must be obtained before collection in accordance with the applicable legal and regulatory requirements. For other age groups, the applicable consent and legal-representation requirements apply as appropriate. The clinic, as data controller, is responsible for verifying these requirements before entering a child's data into the Service.
12 Cookies
We use cookies and local storage (localStorage / IndexedDB) as necessary for sessions, language preferences, authentication, and caching or offline functionality where supported by the Service. Public website pages may use analytics tools such as Google Analytics 4 if enabled, to collect aggregate usage indicators such as visits, engagement, device type and approximate geographic location. Patient Data and health data must not be sent to analytics tools, and we do not use Patient Data for advertising purposes.
Third-party analytics tools are subject to their own configurations and policies. We review analytics settings to reduce unnecessary collection and prevent sensitive personal data or Patient Data from being passed to them.
13 Third-Party Services
The Service relies on external providers depending on the components actually enabled, including Supabase services for database, authentication, storage or related components, Firebase services for website hosting where enabled, Google services for sign-in or analytics where enabled, notification services, WhatsApp links, and any payment provider activated in the future. Mentioning a provider does not mean that all categories of data are sent to it; data is shared only as needed for the relevant feature.
Processing by these providers is subject to their terms and policies in addition to Do Pro's contractual and legal obligations. The clinic remains responsible for instructions concerning Patient Data, while Do Pro uses processors and subprocessors within the scope necessary to operate the Service and with appropriate data-protection considerations.
14 Cross-Border Transfers
Some data may be processed or stored by service providers outside the Arab Republic of Egypt, depending on the infrastructure and data-center locations used by the Service. Any transfer, storage, sharing, processing or access across borders is subject to applicable Egyptian legal and regulatory requirements, including any required license, permit, consent or adequate level of protection. This Policy is not itself a standalone authorization for an international transfer where the law requires additional approval or conditions.
15 Breach Notification
- When we discover a confirmed or reasonably suspected security breach materially affecting personal data processed by Do Pro, we will take containment, investigation and assessment measures and notify the affected controller without undue delay to the extent and with the information reasonably available to us.
- We cooperate with the controller and provide relevant information reasonably available to us to support its legal obligations toward the regulator or affected data subjects, as applicable.
- The allocation of notification duties and statutory deadlines depends on applicable law and each party's legal role. This Policy does not create an obligation for Do Pro to notify a regulator or individual on behalf of the clinic unless required by law or expressly agreed.
16 Changes to This Policy
We may update this Policy from time to time to reflect changes to the Service or legal and regulatory requirements. Material updates will be published with appropriate notice and an effective date. Continued use of the Service does not by itself waive any consent, notice or other rights required by law.
17 Contact
For any questions or to exercise your rights, contact us at:
Email: info@doproclinics.com
WhatsApp: 0110 248 7975
18 Effective Date
This Policy is effective as of the release date shown above. It should be read together with the Terms of Service v2.0 and any applicable Data Processing Agreement (DPA) or plan-specific terms agreed with the Subscriber. If there is a conflict concerning Patient Data processing, the applicable data-processing agreement will govern to the extent it does not conflict with mandatory law.
19 Governing Language
This Policy is prepared in both Arabic and English. In the event of any conflict or discrepancy between the two versions, the Arabic version shall be the authoritative and legally binding version, and the English version is provided for convenience only.