Privacy Policy
What Practeca stores, where it lives, who can reach it, and how you get it back.
Last updated
Who is responsible for what
Practeca provides software that clinics use to run their practice. When a clinic records patient information in Practeca, the clinic is the data controller — it decides what is collected and why. Practeca is the data processor: we store and protect that information and act on the clinic’s instructions.
This means a patient who wants their record corrected, exported or erased should contact their clinic. If a patient contacts us directly, we refer them to the clinic rather than acting on the record ourselves.
What we store
Practeca holds three broad categories of information.
- Clinic and staff accounts — clinic name, locations, working hours, services and prices, plus each user’s name, email, role and permissions.
- Patient records entered by the clinic — identifying details, contact numbers, appointments, visit notes, prescriptions, lab and imaging orders, attachments uploaded by clinic staff, and invoices. Health data is sensitive personal data and is treated as such.
- Operational records — an audit trail of key actions (who did what, and when), message delivery logs, and error reports used to keep the service running.
We do not sell data, we do not share it with advertisers, and we do not use patient data to build products for anyone other than the clinic that entered it.
Where it is hosted
Practeca runs on Supabase infrastructure hosted in the European Union (Ireland), which is GDPR-compliant hosting. Clinics that require data to remain inside Egypt should contact us before signing — a dedicated Egyptian regional instance can be scoped on request.
We do not claim that data stays inside Egypt by default, because it does not. If in-country residency is a requirement for you, raise it with us first rather than assuming it.
Practeca is built to align with Egypt’s Personal Data Protection Law (Law No. 151 of 2020), which classifies health data as sensitive personal data requiring explicit consent.
How it is protected
- Encrypted in transit and at rest.
- Row-level security on every table. Every record carries the clinic it belongs to, and every database policy enforces it. One clinic cannot read another clinic’s data, even in the event of an application bug.
- Access inside a clinic is limited by role. A receptionist cannot open clinical notes; clinical access is separated from scheduling access.
- Key actions are written to an audit trail attributed to the acting user.
- Daily encrypted backups, with point-in-time recovery on the production database.
Practeca staff do not browse clinic data as a matter of course. Administrative access to a clinic’s account requires a second authentication step and is recorded in the platform audit log.
Who else processes data
We use a small number of subprocessors to deliver the service. Each receives only what its function requires.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, authentication and file storage (EU, Ireland) |
| Netlify | Application hosting and content delivery |
| Twilio | WhatsApp messages to and from patients |
| Resend and Zoho | Transactional and account email |
| Sentry | Error reporting (configured to exclude patient identifiers) |
| Upstash | Rate limiting |
| Cloudflare | Bot protection on sign-in |
Patient messaging
When a clinic uses Practeca to message patients over WhatsApp, the message content and the patient’s phone number pass through Twilio and WhatsApp, and are subject to their handling as well as ours. Clinics decide what is sent. We do not add marketing of our own to those messages.
How long it is kept
- Clinical records are retained, not deleted. Visits, prescriptions and patient records are archived rather than erased, because medical records carry legal and clinical retention obligations. Archiving removes a record from day-to-day use while preserving history.
- Audit logs are retained for the life of the clinic account.
- Backups roll off on their retention schedule, so an archived record may persist in a backup for a period after archiving.
- If a clinic leaves Practeca, we export its data on request and then remove the account on the clinic’s written instruction, subject to the retention points above.
Getting your data out
A clinic can request a full export of its records — patients, visits, prescriptions and invoices — at any time, in a standard format it can take to another system. This is included in every plan and is not conditional on why you are asking. Email help@practeca.com and we will arrange it.
If something goes wrong
If we become aware of a breach affecting clinic or patient data, we will notify the affected clinics without undue delay, with what we know, what we have done, and what the clinic may need to do. We would rather send an early notice that turns out to be minor than a late one that was not.
Contact
Questions about this policy, a data request, or a concern about how information is handled: help@practeca.com. For commercial and contractual questions: business@practeca.com.
Practeca is operated from Cairo, Egypt.
Changes
If this policy changes in a way that affects how clinic or patient data is handled, we will update the date at the top of this page and tell active clinics by email. We will not make a material change quietly.