Privacy Policy
Last updated: 6 October 2026
Nexacare is a clinic management platform for clinics in Egypt and the MENA region. This policy explains what data we handle, in which roles, where it is stored, and the choices available to clinics and their patients.
1. Who we are
Nexacare ("we") provides software that clinics use to manage appointments, patient records, prescriptions, messaging and billing. You can reach us at support@nexacare.care.
2. Our role: processor for patient data, controller for account data
For patient data entered or collected through the platform, the clinic is the data controller and Nexacare acts as a processor on the clinic's instructions. For the account data of clinic staff (name, email, sign-in records) and for demo or contact requests, Nexacare is the controller.
3. Data we process for clinics
Patient identifiers and contact details, appointment and queue history, clinical documentation (visits, diagnoses, prescriptions, vitals, allergies, attached documents), messaging consent and delivery logs, and billing records — all scoped to the clinic that created them.
4. Health data under Egypt's data protection law
Patient health data is sensitive personal data under Egypt's Personal Data Protection Law No. 151 of 2020. The duties of obtaining patient consent and establishing the lawful grounds for care sit with the clinic as controller; for patients who are children, that includes obtaining a parent's or guardian's consent where the law requires it. Nexacare supports this with per-patient, per-channel consent records and audit logs, and processes health data only to provide the service.
5. Where data is stored
The cloud service runs on Vercel, with the database on Neon and attached documents in Cloudflare R2 object storage, in data centers outside Egypt. The database provider keeps managed, encrypted point-in-time backups, and we keep our own encrypted backups, taken several times a day and stored separately from the database provider. A clinic that needs its data to stay on its own premises can run Nexacare self-hosted, on a server it controls.
6. How we protect it
Every record is scoped to its clinic and kept apart at two layers: in the application and, independently, by PostgreSQL row-level security. Connections are encrypted in transit, staff access is role- and scope-gated, and sensitive actions are recorded in an audit log that the clinic's administrators can read.
7. Messaging and consent
Appointment reminders, confirmations and recall messages are sent by email or WhatsApp only where the clinic has recorded the patient's consent for that channel. Delivery attempts are logged. A patient can withdraw consent at their clinic at any time. A message that staff send by hand, for example with one tap in WhatsApp, is sent by the clinic from its own device.
8. Retention and deletion
Clinic data is retained while the clinic's account is active. Medical and financial records may have to be kept for periods set by Egyptian law, so we do not delete them automatically. When a clinic closes its account, a complete export is available to it, and we delete the clinic's data on its written request, except for records the law requires us to keep. Copies held in backups age out as the backups are replaced: the provider's on its own schedule, and ours within about twelve months.
9. Rights of patients and staff
Patients exercise access, correction and deletion rights through their clinic, and we assist the clinic in fulfilling them. Clinic staff can access and correct their account data in the app and may request deletion of their account.
10. Requests you send us
If you ask for a demo, we process the details you give us (your name, your clinic, how to reach you and, if you choose, your specialty, number of doctors and current system) only to respond to you. We keep them while we are in contact with you and delete them if you ask.
11. Cookies
We use only the cookies the service needs to work: a session cookie that keeps a signed-in staff member signed in, and cookies that remember the language and theme a person chose. Visitors to our public pages receive no cookies, and we use no advertising, analytics or tracking cookies, so there is no cookie banner. The bot challenge on the demo and booking forms is provided by Cloudflare and may use its own browser storage to do its job.
12. Sub-processors
We rely on a small set of providers to run the hosted service: Vercel (hosting), Neon (database), Cloudflare (storage for attached documents and for our encrypted backups, and a bot challenge on the public booking and demo forms), Resend (transactional email), GitHub (runs the scheduled job that takes our backups, which are encrypted before they are stored), and WhatsApp where a clinic uses it: staff can open a message in WhatsApp on their own device with one tap, and a clinic can connect its own number for automatic sending. We will notify clinics of material changes to this list.
13. Breach notification
If we become aware of a personal data breach affecting a clinic's data, we will notify the affected clinic without undue delay, including what we know, the likely impact, and the measures taken.
14. Changes to this policy
We will announce material changes to this policy to clinic owners by email or in the app before they take effect.
Questions? Contact us at support@nexacare.care.