This Privacy Policy explains how DocuMed handles personal data. DocuMed is operated by Mustafa El Mahdy, a sole proprietor based in Egypt ("DocuMed", "we", "us"), and is accessible at documed.health.
This policy is written in compliance with Egyptian Personal Data Protection Law No. 151 of 2020 ("PDPL") and follows international best practice. The Arabic version of this policy is the controlling version for any dispute arising in Egypt; the English version is provided for convenience.
1. Who Controls What Data
DocuMed handles two categories of personal data, and the roles are different for each.
Account Data — DocuMed is the controller. This includes the name, email, phone number, role, and login credentials of the Clinic's Admin and Users. We collect this directly when they sign up or are added to a Clinic account, and we control how it is used.
Patient Data — the Clinic is the controller, DocuMed is the processor. This includes everything the Clinic enters about its patients: names, contact details, national ID, date of birth, sex, address, clinical notes, diagnoses, treatment plans, and attached files such as labs and X-rays. The Clinic decides what to collect and what to do with it; DocuMed only stores and processes this data on the Clinic's behalf, following the Clinic's instructions and these terms.
If you are a patient of a DocuMed-using clinic, your relationship is with that clinic, not with DocuMed. DocuMed will support clinics in responding to patient data requests but does not deal with patients directly.
2. What Data We Collect
From the Admin and Users (Account Data):
- Name
- Email address
- Phone number (optional)
- Role within the Clinic
- Password (stored as a one-way hash; we cannot read it)
- IP address and approximate location at login
- Browser and device information
About the Clinic:
- Clinic name, phone, and address
- Subscription status and billing-related information
Patient Data the Clinic enters:
- Patient identifiers (name, phone, national ID, date of birth, sex, address)
- Visit records (chief complaint, clinical notes, diagnosis, treatment plan, follow-up date)
- Attached files (lab results, X-rays, documents)
- Any other clinical information the Clinic chooses to record
Automatically collected technical data:
- Server logs (IP address, time, requested page, response code)
- Audit log entries (which User performed which action, on which record, when)
- Error reports captured by our monitoring system (Sentry)
3. How We Use the Data
We use Account Data to provide the service, authenticate logins and protect accounts, send transactional emails (such as password resets and trial or renewal notices), detect and prevent fraud and abuse, communicate with the Admin about service matters, and improve the service based on aggregated usage.
We process Patient Data only to store and display it to authorized Users of the Clinic, enable features such as search and export, maintain audit trails for the Clinic, and recover from technical failures (backups).
We do not use Patient Data for advertising, analytics, model training, or any purpose other than providing the service to the Clinic.
4. Legal Basis for Processing
Under Egyptian PDPL and applicable international principles, we process Account Data based on the contractual necessity of providing the service and, where applicable, our legitimate interests in running and securing it. We process Patient Data based on the contractual relationship between DocuMed and the Clinic, where the Clinic has its own legal basis (typically patient consent or a healthcare-related legal basis) for collecting and using that data.
5. How We Share Data
DocuMed does not sell personal data. We share data only as follows.
With service providers ("sub-processors") who help us run the service:
| Sub-processor | Purpose | Where data is processed |
|---|---|---|
| Supabase | Database hosting (PostgreSQL) | Outside Egypt (typically EU or US) |
| Render | Application hosting | Outside Egypt (typically EU or US) |
| Cloudflare R2 | File and attachment storage (labs, X-rays, documents) | Outside Egypt (global object storage) |
| Resend | Transactional email delivery | Outside Egypt (typically US) |
| Sentry | Error monitoring | Outside Egypt (typically US) |
Each sub-processor is bound by its own terms and security obligations. We choose providers that maintain industry-standard security practices.
With authorities where required by Egyptian law, valid legal process, or to protect the rights and safety of DocuMed, its users, or the public.
In a business transfer if DocuMed is acquired, merged, or sells substantially all of its assets. The Clinic will be notified in advance and may cancel and export its data.
We do not share Patient Data with third parties for any other purpose without the Clinic's explicit instruction.
6. International Data Transfers
Because some of our infrastructure providers are based outside Egypt, personal data is transferred internationally. We rely on these providers' standard contractual protections and security certifications. If you are uncomfortable with international processing, contact us before signing up.
7. Security
We protect data through:
- Encryption in transit — all connections use HTTPS.
- Encryption at rest — the database, file storage, and backups are encrypted.
- Tenant isolation — every database query is scoped to a single Clinic, so one Clinic cannot access another's data.
- Role-based access — Users can only access data appropriate to their role.
- Password hashing — passwords are stored as one-way hashes, never in plain text.
- Audit logging — significant actions are recorded with user, timestamp, and IP.
- Backups — automated backups with retention to allow recovery from failures.
- Error monitoring — operational issues are tracked through Sentry without exposing sensitive data.
No system is perfectly secure. The Clinic is responsible for protecting its own credentials, training its Users, and using strong passwords.
8. Data Retention
| Data | How long we keep it |
|---|---|
| Account Data for active Clinics | For the duration of the subscription |
| Patient Data for active Clinics | For the duration of the subscription |
| Data after cancellation | 90 days, then permanent deletion |
| Backups containing deleted data | Up to 30 additional days before rotated out |
| Audit logs | For the duration of the subscription, plus 90 days |
| Server logs | 30 days |
| Error reports (Sentry) | 90 days |
After permanent deletion, data cannot be recovered.
9. Your Rights
Under Egyptian PDPL, individuals have rights regarding their personal data, including the rights to access, correct, delete (subject to legal and contractual exceptions), object to certain processing, restrict processing, data portability, withdraw consent, and complain to the Egyptian Personal Data Protection Center.
If you are an Admin or User: contact us at the address in Section 12 to exercise these rights regarding your Account Data.
If you are a patient: these rights apply to your Patient Data, but the Clinic is the controller. Contact the Clinic directly; we will assist the Clinic in fulfilling your request.
We aim to respond to verified requests within 30 days.
10. Cookies and Tracking
DocuMed uses essential cookies required for the service to work — primarily session cookies for keeping Users logged in and CSRF tokens for security.
We do not use advertising cookies, cross-site tracking, analytics cookies that profile individual users, or third-party social media trackers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to Admins and posted on documed.health at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent version.
12. Contact
For privacy questions, requests, or complaints, contact:
Mustafa El Mahdy
Privacy contact for DocuMed
Email: mustafaelmahdy52@gmail.com
Website: documed.health
You also have the right to lodge a complaint with the Egyptian Personal Data Protection Center if you believe your rights under PDPL have been violated.