Privacy policy
What personal data Saff handles, why we handle it, and the choices you have.
Last updated: [TO BE COMPLETED BY THE OPERATOR — effective date]
Who we are and what this covers
Saff is a patient-queue, appointment and clinic-management platform operated by [TO BE COMPLETED BY THE OPERATOR — registered legal entity name]. This policy covers the Saff website and the Saff application. It does not cover a clinic's own website, its paper records, or any service a clinic offers outside Saff.
Your clinic is the controller of your health data
When a clinic uses Saff to run its queue and keep its records, that clinic decides what is collected and why: it is the data controller, and Saff acts as its processor, handling data only on the clinic's instructions. Requests about your medical record therefore start with your clinic, and the product gives the clinic the tools to answer them. We are the controller in our own right only for the marketing site, waitlist sign-ups, clinic applications and the security logs we need to keep the platform safe.
What data is held
The categories below are the ones the platform actually stores. Not every clinic uses every module, so what exists for you depends on which parts of Saff your clinic has switched on.
- Account and identity
- Name, email address, phone number, preferred language, calendar and numeral preferences, sign-in credentials and, for staff, a two-factor secret.
- Patient profile
- Date of birth, sex, nationality, national-ID type and number, emergency contact name, phone and relationship, blood type, allergies, chronic conditions and current medications.
- Clinical records
- Consultation notes, problem list, vital signs, immunisations, family and social history, prescriptions, lab orders and results, referrals, mental-health notes, intake-form answers and documents your clinic uploads.
- Appointments and queue activity
- Bookings, walk-ins, check-in times, queue position, wait and travel estimates, visit progress, cancellations, no-shows and the reviews you choose to leave.
- Billing and insurance
- Invoices, payments, refunds, packages and loyalty tiers, coupons, insurance eligibility checks, claims and pre-authorisations.
- Messages and notifications
- Notification history and delivery status, your per-channel contact preferences, quiet hours and do-not-disturb settings, questions you send your doctor and the replies you receive.
- Consent records
- What you agreed to, which version of the text you were shown, a hash of that text, when you agreed, when you withdrew, and a shortened description of the browser you used.
- Location
- Your approximate position, and only while you have explicitly turned on location sharing so the clinic can estimate when you will arrive. It is used for that estimate and nothing else.
- Technical and security records
- Audit entries recording who accessed or changed which record, with the IP address stored as a hash and the browser string truncated; plus the operational logs that keep the service running.
Why the data is processed
Data is processed to run the queue and show wait estimates, to book, confirm, remind and cancel appointments, to let clinicians record and read clinical notes, prescriptions and lab orders, to issue invoices and record payments, to answer your requests, and to keep the platform secure and auditable. The lawful bases are the contract between you and your clinic, the clinic's legal obligations for medical records, our legitimate interest in operating and securing the platform, and — for anything optional — your explicit consent.
Where we rely on your consent
A small set of features never runs without a recorded, explicit opt-in: sharing your live location so the clinic can estimate your travel time, letting a family member or companion follow your queue status, sharing your record with another clinic, and marketing messages by email, SMS or WhatsApp. Each grant is stored with its kind, its version, a hash of the exact text you were shown and the time you agreed, so the record of what you consented to is reconstructable. Withdrawing consent adds a new record rather than erasing the old one — the history stays intact, but the feature stops.
Messages you receive without opting in
Booking confirmations, reminders, "you're next" alerts, cancellations made by the clinic and visit-completed notices are operational: they are part of the care you asked for, so they are sent without a marketing opt-in. Marketing and bulk messages are separate and require consent, which you can withdraw per channel at any time.
How the data is protected
Sensitive columns — phone numbers, national-ID numbers, emergency contacts, allergies, chronic conditions, medications, blood type, clinical and mental-health notes, prescription contents, lab notes and results, uploaded-document keys, patient messages and team chat — are encrypted at rest with AES-GCM, each column bound to its own identifier so ciphertext cannot be moved between columns. Where the product must search on an encrypted value it stores a keyed HMAC fingerprint instead of the value. Every read and write is scoped to a single clinic at the database layer, so one clinic's data is unreachable from another's session. Staff can enable time-based two-factor authentication, session cookies are host-locked and secure in production, public forms are protected against automated abuse, and sensitive actions are written to an append-only audit trail.
What we deliberately keep out of our logs
Our application logs never carry names, phone numbers, email addresses, message bodies or clinical content. They carry identifiers, hashes, counts and fixed status labels only. The audit trail records who did what to which record, with the IP address hashed, the browser string truncated, and — where extra detail is stored — the names of the fields that changed rather than their values.
Where the data is stored
Production data is held in [TO BE COMPLETED BY THE OPERATOR — country / region where production data is hosted today]. Saff's storage policy is to keep clinic and patient data inside the country the clinic operates in, and to move it across a border only where that country's rules allow it — under Egypt's Personal Data Protection Law (Law 151 of 2020) that means prior approval from the Personal Data Protection Centre, an adequacy assessment and the patient's explicit consent. Test and staging environments never carry real patient data.
How long it is kept
Clinical records are kept by your clinic for as long as the law requires it to keep them — [TO BE COMPLETED BY THE OPERATOR — statutory medical-records retention period] — because that decision belongs to the clinic as controller, not to us. Consent records and audit entries are kept for as long as they are needed as evidence that a rule was followed. Marketing-site data such as a waitlist entry is kept until you ask us to remove it or until it is no longer useful.
What happens when you delete your account
Deleting your patient account takes effect immediately: your sign-in stops working, any session you still have open is ended on its next request, and your profile disappears from the clinic's patient lists. What that action does NOT do is destroy the clinical record itself — your clinic is legally obliged to retain it for the statutory period, after which it is erased. If you want a copy, export your data before you delete the account.
Your rights
You can exercise the rights below from inside your patient account, or by writing to us or to your clinic. We will not charge you, and we will not ask why.
- Access and portability
- Download everything held under your patient account as a structured file, from the privacy section of your account. The file states plainly what it leaves out and why: notes a clinician wrote ABOUT you are staff clinical material and are requested through your clinic, and your national-ID number is withheld from a self-service download because it is an identity credential.
- Correction
- Edit your own profile details in your account. Ask your clinic to correct anything in a clinical record — the clinic amends the record and the change is captured in the audit trail.
- Deletion
- Delete your account from your account settings. Access ends immediately and your profile leaves the clinic's lists; the clinical record itself is retained by the clinic for the statutory period and erased afterwards.
- Withdrawing consent
- Turn off location sharing, a companion's access to your queue status or cross-clinic record sharing from the privacy section of your account. Withdrawal takes effect immediately and does not undo processing that was lawful before it.
- Stopping marketing
- Opt out of marketing email, SMS or WhatsApp separately per channel in your communication preferences. Operational messages about your own appointments continue.
- Restriction and objection
- Ask us or your clinic to pause a particular use of your data, or object to processing we base on a legitimate interest. We will act on it unless we are legally required to continue.
- Complaining
- Raise a complaint with your clinic, with us, or directly with the supervisory authority in your country. Complaining does not affect your care.
Children and dependants
Saff is not designed for children to use on their own. A parent, guardian or authorised carer registers the child as a patient, books on their behalf, and is the person who gives and withdraws any consent. The same protections apply to a dependant's record as to an adult's.
Changes to this policy
When this policy changes materially we will update the date at the top of the page and, where the change affects something you consented to, ask for that consent again rather than assuming the old one still stands.
Contact and complaints
For anything in this policy, or to exercise a right, contact us at the address below. If you believe your data has been mishandled you can also complain to the supervisory authority — [TO BE COMPLETED BY THE OPERATOR — competent supervisory authority for complaints] — and, for a clinical record, to your clinic directly.
- Operator
- [TO BE COMPLETED BY THE OPERATOR — registered legal entity name]
- [TO BE COMPLETED BY THE OPERATOR — privacy / data-protection contact email]
- Postal address
- [TO BE COMPLETED BY THE OPERATOR — registered business address]
- Data protection contact
- [TO BE COMPLETED BY THE OPERATOR — data protection officer or EU/UK representative, if one has been appointed]
