PraxisRun your clinic with clarity

Privacy Policy

Last updated: 2026-09-04

This Privacy Policy explains how Praxis ("Praxis", "we", "us") handles personal data when a clinic and its staff use the Praxis clinic-management platform, and when a patient interacts with a clinic that uses Praxis (for example, to book an appointment or receive a WhatsApp reminder).

Praxis is built for the Egyptian market and is operated with Egypt's Law No. 151 of 2020 on the Protection of Personal Data in mind. We do not claim certification under any other jurisdiction's privacy framework (for example, the EU's GDPR); if your clinic operates outside Egypt, you are responsible for confirming Praxis meets your local obligations before relying on it.

1. Who processes what — clinics and Praxis

Praxis is multi-tenant software: each clinic that signs up gets its own isolated data space (enforced both in application code and at the database level, via row-level security), and clinic staff log in with a clinic-specific code, username and password.

For patient records, bookings, clinical notes and attachments that a clinic enters into Praxis, the clinic is the data controller and Praxis acts as its data processor — the clinic decides what patient information to collect and is responsible for having a lawful basis (including, where needed, the patient's consent) for collecting it. For account, subscription and billing data tied to the clinic itself, Praxis is the data controller.

Praxis staff do not browse clinic data as a matter of course. Every read and write of patient data is written to an audit log; access outside normal support workflows requires a documented reason.

2. Information we collect

  • Clinic staff account data — name, username, phone, role (admin, doctor, reception), and a securely hashed password (argon2id; we never store passwords in plain text).
  • Patient records entered by the clinic — name, phone number, date of birth, address, medical/clinical notes, diagnosis, vitals, and prescription or document attachments (photos/PDFs) the clinic uploads to a patient's file.
  • Booking and visit data — appointment times, queue numbers, visit status, and, for clinics with public online booking enabled, the booking made directly by a patient through the clinic's page.
  • Payment references — when a clinic or patient pays through Kashier (cash, card, InstaPay, or mobile wallet), Praxis stores the payment status, amount, currency, and a provider transaction reference. Praxis never receives or stores full card numbers, CVV codes, or wallet credentials — those are handled entirely by Kashier's own payment page.
  • Communications data — the phone numbers used to send WhatsApp or SMS confirmations and reminders, the message template used, and delivery status (sent, delivered, failed).
  • Technical data — IP address and basic device/browser information collected for security purposes (rate limiting, abuse prevention) and, where advertising cookies described in Section 4 are active, for measuring ad performance.

3. How we use information

To provide the service: authenticate staff, isolate each clinic's data from every other clinic, run the booking/queue engine, generate appointment reminders, record payments, and produce the reports a clinic sees in its dashboard.

To keep the service secure: rate-limiting public endpoints, detecting abuse, and maintaining the audit log of who accessed or changed patient data.

To operate the business: subscription billing, trial and grace-period reminders, and responding to support requests.

To the extent Meta Pixel or similar advertising tools are active on our marketing pages (see Section 4), aggregate, non-clinical data about visits to those pages to measure and improve advertising performance.

4. Cookies and similar technologies

Praxis itself does not currently set third-party tracking or advertising cookies inside the clinic application. The application uses strictly necessary cookies only: a short-lived signed-in session cookie and a refresh-token cookie (both httpOnly, so they cannot be read by page scripts), plus a local, on-device preference for light/dark theme stored in your browser's local storage.

Our public marketing pages may run advertising and analytics tools such as the Meta Pixel to measure the performance of ad campaigns (for example, on Facebook or Instagram). Where active, these tools can set cookies or use similar identifiers in the visitor's browser to record that an ad led to a visit or a signup, and may share limited interaction data with Meta for that purpose. This is standard advertising-measurement behavior, and where local law requires consent for non-essential cookies, we present the appropriate notice before those cookies are set.

You can control cookies through your browser settings, including blocking or deleting them; doing so may affect how our marketing pages measure ad performance but will not prevent you from using the core Praxis application.

5. WhatsApp and SMS messaging

When a clinic enables appointment notifications, Praxis sends booking confirmations and reminders over WhatsApp using Meta's WhatsApp Business/Cloud API, and falls back to SMS only if a WhatsApp message fails to deliver. Messages use pre-approved "utility" templates for transactional purposes (confirmations, reminders) — Praxis does not send marketing messages over this channel.

The phone number used is the one the clinic (or the patient, for online bookings) provided for that appointment. Message content, delivery status, and the template used are recorded against the appointment for the clinic's own record-keeping and to avoid sending duplicate messages.

Meta processes the message content and delivery metadata as the operator of the WhatsApp Cloud API; see Meta's own privacy policy for how it handles that data on its side.

6. Third-party processors

  • Kashier — our payment gateway for card, InstaPay, mobile wallet, and cash-reference payments. Kashier processes and stores cardholder data on our behalf; Praxis only receives payment status and a transaction reference.
  • Meta (WhatsApp Cloud API) — delivers WhatsApp appointment notifications, and, where a clinic enables it later, the Meta Pixel for ad measurement on marketing pages.

We do not sell personal data to third parties, and we do not share patient clinical data with advertisers.

7. Data retention

Patient and clinic data is retained for as long as the clinic's account is active, plus [DATA_RETENTION_PERIOD] afterward, unless a longer period is required by law or a shorter period is requested and we are able to honor it (see Section 8).

When a patient record is deleted from a clinic's active list, Praxis performs a soft delete: the row is kept as the anchor for that patient's historical visit records (so appointment and billing history stays consistent), but the patient's phone number is released (rewritten so it no longer matches a normal Egyptian number) so the same number can be used to register a new, separate patient file. The underlying visit history is not purged automatically.

Database backups are encrypted before they leave the server and are retained on a rolling basis for operational recovery; they are not a separate, indefinite copy of deleted data.

8. Your rights and how to exercise them

If you are a patient of a clinic that uses Praxis, your medical file belongs to that clinic, not to Praxis — the clinic is the data controller for it. Requests to access, correct, or delete your patient file should go to the clinic directly; Praxis provides the clinic the tools to make those changes (editing a patient's details, or soft-deleting the record as described in Section 7).

If you cannot reach the clinic, or your request concerns account/billing data that Praxis itself controls, you can contact us at [SUPPORT_EMAIL] and we will route or action the request as appropriate. We may need to verify your identity, and some requests are limited by the constraints above (for example, visit history tied to a soft-deleted patient record is kept as the clinic's anchor record, not fully erased).

Clinic staff can request access to or correction of their own account details at any time through the clinic's admin, or by contacting us directly.

9. Security measures

Tenant isolation: every clinic's data is scoped in application code and enforced again at the database level with row-level security, so one clinic's staff cannot query another clinic's data even in the event of an application bug.

Passwords are hashed with argon2id. File attachments are served only via short-lived signed URLs, never a permanent public link. Uploaded images are re-processed on our servers to strip embedded location and camera metadata before storage.

Every read or write of patient data is written to an audit log. Database backups are encrypted before they touch disk.

No system is perfectly secure, and we make no guarantee beyond reasonable, industry-standard safeguards appropriate to the sensitivity of the data involved.

10. International data handling

Praxis is operated for the Egyptian market. Some of our processors — notably Meta, for WhatsApp delivery and, where enabled, advertising measurement — may process data outside Egypt as part of their global infrastructure. We select processors that are widely used for this purpose and rely on their own data-protection commitments for that onward processing.

11. Changes to this policy

We may update this policy as the product changes. Material changes will update the date below, and where required by law we will provide additional notice.

12. Contact us

Questions about this policy, or privacy requests that your clinic cannot resolve, can be sent to [SUPPORT_EMAIL].

[COMPANY_LEGAL_NAME], [COMPANY_ADDRESS].

Terms of Service

Back to home