Legal

Privacy Policy

Last updated: 5 September 2026

This policy explains what personal data ClinHelm collects, why, and how it is handled. ClinHelm plays two different roles depending on who you are — the first section below explains which one applies to you.

1Controller and processor — which one applies to you

If you are a patient of a clinic that uses ClinHelm, your clinic is the data controller: it decides what patient data to collect and why, and it is the right place to send a request about your own records. ClinHelm acts as a data processor for that patient data — we process it only on the clinic's instructions, inside that clinic's own isolated workspace.

If you signed up for a ClinHelm account yourself — as a clinic owner creating a workspace, or as a visitor submitting our contact form — ClinHelm is the data controller for that account and contact information.

2What we collect

Depending on how you use ClinHelm, we process:

  • Patient records entered by clinic staff: name, national ID, date of birth, gender, phone number, email, and address.
  • Clinical documentation entered by clinicians: medical history, assessments, session notes, treatment plans, discharge summaries, outcome measures, and clinical photos or media.
  • Files uploaded to a patient's record (e.g. lab results, referral letters).
  • Audit log entries for every change made in the system: which user made it, what action, before/after values, the time, the IP address, and the browser/device (user-agent string) used — kept for accountability and security investigation.
  • Session and sign-in metadata: the IP address and user-agent recorded when you sign in, so an account holder can review and revoke their own active sessions.
  • Notification delivery records: which reminder or confirmation template was sent, in which language, and to which phone number or email — not a saved copy of the exact wording, since messages are composed from a template at the moment they are sent.
  • If you sign up for ClinHelm yourself: your name, email, phone number, clinic name, and the plan you select.
  • Staff personal data entered when the clinic sets up an account: name, contact details, role and permissions, employment/compensation details used for payroll, and the two-factor authentication secret used to secure sign-in.

3Why we process it

For patient data, we process it strictly to provide the clinic's workspace to the clinic that operates it — scheduling, clinical documentation, billing, and patient reminders — as instructed by that clinic. For account data, we process it to create and run your ClinHelm account, respond to your enquiries, and improve the product.

We also process audit-log and session data for security: detecting suspicious sign-ins, investigating incidents, and meeting the clinic's own record-keeping obligations.

4Who else processes this data (sub-processors)

ClinHelm uses a small number of specialist providers to deliver the service. Each is instructed to process data only for the purpose listed and only to the extent needed.

  • Meta (WhatsApp Cloud API) — delivers WhatsApp appointment reminders and confirmations.
  • An SMS gateway (SMS Misr for Egypt; Twilio is available for other regions) — delivers SMS reminders and one-time codes.
  • An email provider (SMTP) — delivers account and notification emails.
  • An S3-compatible object storage provider — stores uploaded patient files and documents.
  • Oracle Cloud Infrastructure — hosts the virtual machine that runs the application and its database, in a data centre operated by Oracle Cloud Infrastructure. (The specific region is stated by the operator of a given deployment.)
  • Google Maps — loads the map staff use to set the clinic's location; only shown to clinic staff, never to a patient.
  • GitHub — if you submit in-app feedback, your message, browser/device information, and your clinic's workspace identifier are filed as a GitHub issue so our team can act on it.

5How long we keep data

These are the retention periods ClinHelm is built around today. They are the clinic's proposed operating parameters, pending final sign-off from legal counsel, and are not yet a guaranteed contractual commitment:

  • Medical records — 10 years after a patient's last visit.
  • Audit logs — 7 years.
  • Notification delivery records — settled messages (sent, suppressed, or voided) for 180 days; a staff in-app alert, once read, for 90 days. A failed delivery still awaiting manual follow-up, or an unread staff alert, is kept until it is resolved.
  • Contact-form and signup lead information that never converts to a clinic — anonymized after 24 months of inactivity.

Where a retention period requires data to be removed, ClinHelm's approach is to anonymize the record while keeping a minimal audit skeleton — the fact that an event happened — so the clinic's own audit trail and legal obligations stay intact.

6Your rights, and how to request them

If your data was entered by a clinic (patient records), start with that clinic — they control the data and are best placed to act on an access, correction, or deletion request. ClinHelm supports the clinic in fulfilling that request.

If you are contacting us about your own ClinHelm account or a contact-form submission, use the contact form below and we will act on the request ourselves.

There is no automated self-service deletion in ClinHelm today. Every deletion or erasure request is handled manually: we verify the requester, then anonymize the record while retaining the minimal audit trail required for security and legal record-keeping.

7Security measures

Each clinic's data lives in its own isolated workspace. Role-based access keeps clinical notes away from staff who don't need them. Every change is recorded in an audit trail, and audit rows cannot be edited or deleted. Sign-in supports two-factor codes, and an account holder can review and revoke their own active sessions. Automated off-site backups are not currently enabled for this deployment, and no restore procedure exists today — contact us using the form below for the current data-protection posture.

8Cookies

ClinHelm uses a small number of functional cookies to keep you signed in and to remember your workspace — never a third-party advertising or analytics cookie, and never one that tracks you across other sites.

  • carehelm_refresh — keeps you signed in. Deleted when your session ends or you sign out; not readable by page scripts.
  • ch_access — a short-lived copy of your access token, used only so the first page you load already has your data on it; not readable by page scripts.
  • ch_branch — remembers which branch you last viewed, for a clinic with more than one location. Kept for 1 year; readable by the page so every request it makes is scoped to that branch (it is a hint, never a permission — the server checks your membership on every request).
  • carehelm.theme — remembers whether you chose light or dark mode. Kept for 1 year, and readable by the page so it can apply your choice before it loads.

Your language (Arabic or English) is part of the page address, not a cookie, so it is never stored on your device.

9Egypt's Personal Data Protection Law (PDPL)

ClinHelm is designed with Egypt's Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations in mind. A full legal compliance review, including any cross-border data transfer question, is in progress and not yet complete — see the pending-review notice at the top of this page. In particular:

  • We treat health data as a special category of data and rely on your explicit, informed consent — captured on the clinic's own consent form — as the basis for processing it.
  • You have the rights described in "Your rights, and how to request them" above: access, rectification, erasure, restriction, objection, and data portability, as well as the right to lodge a complaint with Egypt's Personal Data Protection Centre.
  • If a personal data breach occurs, we are committed to notifying the Personal Data Protection Centre within 72 hours, and any affected individuals within 3 working days where the breach is likely to pose a high risk to their rights.
  • ClinHelm will appoint a Data Protection Officer as the law requires; until then, data-protection questions can be raised through the contact form below.
  • We do not transfer personal data outside Egypt today. Any future cross-border transfer will only take place under a licence from the Personal Data Protection Centre, or under an applicable explicit-consent exception (for example, medical necessity).

10Children's data

ClinHelm is used by clinic staff to record patient information, including for pediatric patients. Where a patient is a minor, the treating clinic is responsible for obtaining the appropriate consent from a parent or guardian before entering their data — the same as for any other patient record.

11Changes to this policy

We may update this policy as the product or our providers change. Material changes will be reflected here with a new "last updated" date.

12Contact us

Questions about this policy can be sent to the address below.

Questions? Reach us at our contact form