Kashfy
Legal

Privacy Policy

Last updated: July 2026

1. Introduction

This Privacy Policy explains how Kashfy ("we", "our", "us") collects, uses, discloses, and safeguards information when clinics and their patients interact with our platform, mobile presence, hosted chat widget, WhatsApp integration, dashboard, and any related services (together, the "Service").

By creating an account, using the dashboard, embedding our widget on your website, sending messages through a linked WhatsApp number, or otherwise interacting with the Service, you acknowledge that you have read and understood this policy.

We are committed to processing information in a manner consistent with applicable Egyptian data protection laws and, where relevant, international standards including the EU General Data Protection Regulation (GDPR) as a baseline reference.

2. Data Controller and Data Processor Roles

The Service is offered on a multi-party basis. Distinct data-protection roles apply depending on which data is being processed:

Clinic-owned patient data: When a clinic uses our platform to serve its own patients, the clinic itself is the data controller for the personal information of those patients (names, phone numbers, appointment histories, symptoms, medical notes). We act as the data processor on the clinic's behalf and process such information only pursuant to the clinic's instructions expressed through configuration and use of the Service.

Clinic account holder data: For the personal information of individuals who register a clinic account with us (owners, staff members, administrators), we act as the data controller and this policy applies directly.

Aggregated, statistical, or anonymised data: We may generate aggregated or anonymised information for the purpose of improving the Service, and such information is not treated as personal data.

3. Information We Collect

We collect several categories of information depending on how you interact with the Service:

3.1 Information you provide directly

Account registration details, including your name, email address, chosen password (stored only in cryptographically hashed form), and locale preference.

Clinic profile information, including clinic name, city, physical address, contact numbers, public email, logo, description, brand colour, and public URL slug.

Doctor records, including full name, medical specialty, biography, photograph, consultation fee, follow-up fee, session duration, working hours, and date-specific availability overrides.

Knowledge base entries you upload to guide the AI receptionist, which may include text notes and uploaded documents.

Team member invitations, including the invitee's email address and assigned role.

Payment and billing preferences you submit through the checkout flow, such as billing name and billing email. Card numbers and bank details are collected and stored solely by our payment gateway partner and are not visible to us.

Any correspondence you send us via email, in-app support, or WhatsApp.

3.2 Information we collect from patients contacting your clinic

When a patient contacts your clinic through the embedded chat widget on your website, through the Kashfy-hosted public page, or through a WhatsApp number that your clinic has linked to the Service, we process the messages exchanged during that conversation and the metadata associated with them.

Patient identifiers may include phone number (in the case of WhatsApp), a session identifier (in the case of the widget), first and last name where provided, age where provided, presenting symptoms or reason for visit where provided, and any files or images the patient attaches.

Appointment records generated on the patient's behalf include the selected doctor, appointment date and time, status (pending, confirmed, cancelled, completed), and notes captured during the booking.

Conversation transcripts are stored so that the AI receptionist can maintain context across turns and so that the clinic can review its own patient conversations for quality and follow-up purposes.

3.3 Information collected automatically

Device and connection information, including IP address, browser type and version, operating system, referring URL, and approximate location derived from IP.

Usage information, including pages viewed, features used, time spent, error events, and interaction timings, which help us understand how the Service is used and identify problems.

Cookies and similar technologies, as described in Section 12 below.

Security logs, including sign-in timestamps, authentication events, IP addresses, and user-agent strings retained for fraud prevention and audit purposes.

3.4 Information from third parties

When a clinic links a WhatsApp number to the Service, we receive limited profile information from the messaging integration platform, including the WhatsApp display name and phone number registered against the account.

When a clinic completes payment, we receive from our payment gateway a transaction identifier, the amount paid, the payment status, and confirmation timestamps. We do not receive the full card number or bank credentials.

4. How We Use Information

We use the information described above for the following purposes:

Providing the Service: to authenticate you, provision your clinic workspace, deliver messages between patients and the AI receptionist, generate appointment records, apply your knowledge base and doctor availability to conversations, and enable your team to collaborate.

Communications: to send transactional messages such as email verifications, password resets, appointment reminders on your behalf, billing invoices, service announcements, and responses to your support requests.

Billing and payments: to determine the applicable subscription tier, count included bookings, calculate any overage fees, generate invoices, process payments, and pursue collection of amounts owed.

Security and fraud prevention: to detect and prevent unauthorised access, account takeover, spam, abuse, and violations of our Terms of Use.

Product improvement: to understand which features are used, diagnose bugs, and prioritise improvements. Where possible, this analysis is performed on aggregated or de-identified data.

AI model context: to construct the working context supplied to our artificial-intelligence provider so that the receptionist's replies reflect your clinic's information. Content is sent to the AI provider under contractual data-protection commitments and is not used by that provider to train models.

Legal compliance: to comply with applicable laws, respond to lawful requests from authorities, and enforce our contracts.

6. How We Share Information

We do not sell personal data. We share information only in the limited circumstances described below.

6.1 Within your clinic workspace

Data that belongs to a clinic workspace is visible to that clinic's owner and to team members whom the owner has invited and assigned an appropriate role. It is not visible across clinic workspaces.

6.2 With sub-processors and service providers

We rely on carefully selected sub-processors to deliver the Service. These include:

- a cloud hosting and database provider that stores workspace data at rest and serves it to authenticated requests;

- a cloud application-hosting infrastructure provider that runs the Service's web servers;

- an artificial-intelligence service provider that generates the receptionist's replies from the context we send it;

- a messaging-integration platform that connects our Service to WhatsApp on your clinic's behalf;

- an email delivery provider that sends transactional emails;

- a payment gateway that processes card and wallet transactions;

- analytics and error-tracking providers that help us monitor the Service.

Each sub-processor is bound by contractual data-protection commitments and is permitted to use the information solely to deliver its portion of the Service.

6.3 Legal disclosures

We may disclose information if we believe in good faith that disclosure is required by law, regulation, court order, or valid legal process; is necessary to protect the rights, property, or safety of Kashfy, our users, or the public; or is necessary to investigate or prevent fraud, security, or technical issues.

6.4 Business transfers

If Kashfy is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections and the surviving entity's obligation to honour this Policy.

6.5 With your consent or at your direction

We may share information for other purposes with your consent or at your direction, such as when you connect a third-party tool to your clinic workspace.

7. Data Retention

We retain personal data only for as long as it is necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Active clinic workspaces: workspace data is retained for the life of the subscription and for a reasonable grace period thereafter.

Conversation transcripts: retained by default while the clinic account is active, unless the clinic deletes an individual conversation. Clinics can delete conversations from the dashboard at any time.

Appointment records: retained by default while the clinic account is active, to allow appointment history and follow-up.

Billing and tax records: retained for the period required by applicable tax and accounting laws, typically five to ten years.

Security and audit logs: retained for a period sufficient to allow investigation of incidents, typically twelve months.

Deleted content: when content is deleted, it is removed from primary storage promptly and from backups within a limited additional period.

8. Data Security

We take administrative, technical, and physical measures designed to protect information from loss, misuse, unauthorised access, disclosure, alteration, and destruction. These measures include but are not limited to:

Encryption in transit: all traffic between your browser, the WhatsApp integration, and our servers is encrypted using industry-standard Transport Layer Security.

Encryption at rest: personal data stored in our databases and file storage is encrypted at rest.

Access controls: production access is restricted to authorised personnel, protected by strong authentication, and logged.

Row-level authorisation: our multi-tenant database is configured so that requests can only reach data belonging to the authenticated clinic workspace.

Least-privilege API keys: server-to-server integrations use scoped credentials rather than shared secrets.

Password handling: user passwords are stored as one-way cryptographic hashes and are never transmitted or logged in plaintext.

Incident response: we maintain an internal process for investigating suspected security incidents and, where required, notifying affected clinics.

Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk.

9. International Data Transfers

Our sub-processors may be located outside Egypt, including in the European Union, the United States, and other jurisdictions. When personal data is transferred internationally, we rely on lawful transfer mechanisms including standard contractual clauses where applicable, adequacy decisions where they apply, and vendor-side commitments to appropriate technical and organisational safeguards.

By using the Service, you understand that your information may be transferred to, and processed in, countries other than your country of residence.

10. Your Rights

Subject to applicable law, you may have the following rights in relation to personal data we hold about you as a controller:

Right of access: to request a copy of the personal data we hold about you.

Right of rectification: to request that inaccurate or incomplete personal data be corrected.

Right to erasure: to request that personal data be deleted where it is no longer necessary for the purposes for which it was collected, subject to certain exceptions.

Right to restrict processing: to request that we limit the processing of your personal data under specific circumstances.

Right to data portability: to receive personal data you have provided to us in a structured, commonly used, machine-readable format.

Right to object: to object to processing that is based on legitimate interests, subject to applicable exceptions.

Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

Right to lodge a complaint: to lodge a complaint with your local data-protection authority.

For personal data that a clinic controls (patient data), please direct such requests to the clinic itself, which is the data controller. We will assist the clinic in responding to your request where necessary.

To exercise any right you may have against Kashfy as a controller, contact us using the details in Section 15. We may need to verify your identity before acting on a request.

11. Notice to Patients

If you are a patient contacting a clinic through the Kashfy widget, the Kashfy-hosted clinic page, or a WhatsApp number registered by that clinic, please note:

- the clinic - not Kashfy - decides how to use your personal data, including your name, phone number, age, symptoms, and appointment records;

- Kashfy operates the technology that delivers your message to the clinic and generates automated replies on the clinic's behalf, in accordance with the clinic's configuration;

- the automated receptionist identifies itself as "Kashfy" regardless of which clinic you are contacting. This is the name of our AI platform, not a human staff member. Clinics using our service accept this as part of their subscription;

- you should direct any requests to exercise data-protection rights to the clinic first; we will support the clinic in fulfilling valid requests;

- the automated replies do not constitute medical advice or diagnosis. If you are experiencing an emergency, seek in-person medical care immediately.

12. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, and understand how the Service is used.

Strictly necessary: cookies required to authenticate you, keep your session active, and secure the Service. These cannot be disabled through consent controls without breaking core functionality.

Preference: cookies that remember settings such as your language selection and theme.

Analytics: cookies that help us understand usage patterns in aggregate. Where required by law, we rely on your consent to set analytics cookies.

You can control cookies through your browser settings. Blocking or deleting certain cookies may affect functionality.

13. Children

The Service is intended for use by clinics and their patients. It is not intended to be used directly by individuals under the age of fourteen. Where a minor is a patient, we expect the clinic to obtain appropriate consent from a parent or guardian before entering that patient's information into the Service.

If you become aware that a minor has provided us with personal data without appropriate authorisation, please contact us and we will take reasonable steps to delete such data.

14. Third-Party Websites and Services

The Service may contain links to third-party websites or services, or may integrate with third-party platforms at the clinic's direction. This Policy does not apply to third-party sites or services. Please review the privacy notices of any such third parties directly.

15. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will provide reasonable prior notice through the Service or by email to registered account holders and update the "Last updated" date at the top of this page. Your continued use of the Service after the effective date of an update constitutes acceptance of the revised Policy.

16. Contact Us

If you have questions, concerns, or requests regarding this Policy or our privacy practices, please contact us:

By email: privacy@kashfy.app

By post: Kashfy team, Cairo, Arab Republic of Egypt.

We will respond to your inquiry within a reasonable time, and in any event within the time frames required by applicable law.

·