Privacy Policy
Last updated: 12 July 2026
Nexacare is a clinic management platform for clinics in Egypt and the MENA region. This policy explains what data we handle, in which roles, where it is stored, and the choices available to clinics and their patients.
1. Who we are
Nexacare ("we") provides software that clinics use to manage appointments, patient records, prescriptions, messaging and billing. You can reach us at support@nexacare.care.
2. Our role: processor for patient data, controller for account data
For patient data entered or collected through the platform, the clinic is the data controller and Nexacare acts as a processor on the clinic's instructions. For the account data of clinic staff (name, email, sign-in records) and for demo or contact requests, Nexacare is the controller.
3. Data we process for clinics
Patient identifiers and contact details, appointment and queue history, clinical documentation (visits, diagnoses, prescriptions, vitals, allergies, attached documents), messaging consent and delivery logs, and billing records — all scoped to the clinic that created them.
4. Health data under Egypt's data protection law
Patient health data is sensitive personal data under Egypt's Personal Data Protection Law No. 151 of 2020. The duties of obtaining patient consent and establishing the lawful grounds for care sit with the clinic as controller; Nexacare supports this with per-patient, per-channel consent records and audit logs, and processes health data only to provide the service.
5. Where data is stored
The cloud service is hosted on Vercel with the database on Neon, in data centers located in the European Union. Encrypted backups are kept on separate infrastructure. Self-hosted installations store data on infrastructure the clinic controls.
6. How we protect it
Every record is scoped to its clinic and enforced at two layers, including PostgreSQL row-level security; connections are encrypted in transit; backups are encrypted; staff access is role- and scope-gated; and sensitive actions are recorded in an audit log.
7. Messaging and consent
Appointment reminders, confirmations and recall messages are sent by email or WhatsApp only where the clinic has recorded the patient's consent for that channel. Delivery attempts are logged. A patient can withdraw consent at their clinic at any time.
8. Retention and deletion
Clinic data is retained while the clinic's account is active. When a clinic closes its account, a complete export remains available, and data is deleted within [30] days of closure, after which it ages out of encrypted backups on the backup retention schedule.
9. Rights of patients and staff
Patients exercise access, correction and deletion rights through their clinic, and we assist the clinic in fulfilling them. Clinic staff can access and correct their account data in the app and may request deletion of their account.
10. Sub-processors
We rely on a small set of infrastructure providers to run the service: Vercel (hosting), Neon (database), Resend (transactional email), and a WhatsApp delivery channel where the clinic enables it. We will notify clinics of material changes to this list.
11. Breach notification
If we become aware of a personal data breach affecting a clinic's data, we will notify the affected clinic without undue delay, including what we know, the likely impact, and the measures taken.
12. Changes to this policy
We will announce material changes to this policy to clinic owners by email or in the app before they take effect.
Questions? Contact us at support@nexacare.care.