Privacy Policy

How Medical Horus collects, uses, and protects your personal and health data, including a separate consent for sensitive health information and for the optional AI assistant.

Effective: Sep 28, 2026

1. Who We Are

Nilex Digital Systems ("Nilex Digital Systems", "we", "us", "our") is the data controller responsible for the personal data processed through the Medical Horus platform (the "Platform"), a clinic management service used in Egypt by patients, doctors, clinic staff and administrators, and browsed by members of the public. This Privacy Policy explains what personal data we collect, why, how it is protected, and the rights available to you under Egypt's Law No. 151 of 2020 on the Protection of Personal Data ("PDPL") and its Executive Regulations.

We are in the process of completing our formal registration as a data controller with Egypt's Personal Data Protection Center and designating a Data Protection Officer, as described in Section 13 below.

2. Who This Policy Covers

  • Patients who register to book appointments, complete clinical forms, and manage their care.
  • Doctors and clinic staff who use the Platform to deliver care and manage clinic operations.
  • Administrators who manage clinics on the Platform.
  • Visitors who browse public pages (doctor and clinic directories, articles, the help centre) without creating an account.

3. Personal Data We Collect

Depending on how you use the Platform, we collect:

Account and identity data: first and last name, email address, a password (stored only as an irreversible cryptographic hash, never in plain text), date of birth, gender, phone number, address, city and country, a profile picture, and a medical record number generated by the Platform.

Emergency and verification data: an emergency contact's name and phone number, and — for identity verification purposes — a national ID number. Whether national ID collection is necessary for every patient account is currently under internal review, and we intend to narrow its collection to what is genuinely required.

Health data (special category data): blood type, allergies, chronic conditions, current medications, clinical assessments, encounter notes, vital signs, diagnoses and prescriptions. This is "sensitive" or "special category" personal data under Article 14 of the PDPL, and we only collect and process it on the basis of your explicit, separate, written consent — see Section 5 below.

Assistant conversation data (only if you choose to use the optional AI assistant): the text of your questions and the assistant's replies. See Section 6.

Technical and account-activity data: sign-in timestamps, and a record of who accessed a given medical record and when (used to power the access log patients can view in their own account — see Section 9).

4. Why We Process Your Data, and On What Basis

We process personal data for the following purposes:

  • To create and administer your account and authenticate you.
  • To let patients book appointments and doctors/clinics manage schedules.
  • To record and retrieve clinical assessments, encounters, vitals, diagnoses, prescriptions and medical history so that treating doctors and clinics can deliver care.
  • To let patients manage family members (dependents) and grant or receive medical-record access between doctors.
  • To send account-related and appointment-related notifications by email.
  • To keep the Platform secure (rate limiting, audit logging, fraud and abuse prevention).
  • To comply with our legal and recordkeeping obligations.
  • Where you opt in, to provide the AI assistant feature.

Our lawful basis is, depending on the processing activity: your consent (in particular, your explicit consent for health data and for the AI assistant), the performance of the contract you enter into with us when you register and use the Platform's services, and compliance with legal obligations that apply to us or to the clinics operating on the Platform.

5. Explicit Consent for Health Data

Because clinical and health-related information is special category data under Article 14 of the PDPL, registering as a patient requires you to tick a distinct, separate consent checkbox for the collection and processing of your health data — this is presented separately from, and in addition to, your general acceptance of this Privacy Policy and our Terms of Service. You may withdraw this consent at any time through your account settings or by contacting us, though withdrawal does not affect the lawfulness of processing carried out before withdrawal, and clinics may retain records they are separately obliged to keep (see Section 8, Retention).

6. Third Parties We Share Data With, and the AI Assistant

We keep the number of external parties who can access your data to a minimum. As of the date of this Policy, exactly three third parties are involved in operating the Platform:

  1. Hostinger — provides the hosting and server infrastructure on which the entire Platform runs. We are still confirming the exact location of the data centre(s) used, and therefore cannot yet confirm whether your data is transferred outside Egypt as a result of hosting. We will update this Policy as soon as this is confirmed (see Section 11, Cross-Border Data Transfers).
  2. Google / Gmail SMTP — used solely to deliver transactional emails such as email verification, password reset and appointment notifications. We do not use this, or any other channel, to send marketing email.
  3. An AI model provider (to be confirmed) — used only if you actively enable the optional AI assistant. The assistant is off by default and requires you to give a separate, explicit, revocable consent, clearly distinguished from your general acceptance of this Policy, before any conversation content is sent to that provider. You can withdraw this consent at any time; when you do, we stop sending your future conversations to the provider, and your assistant conversation history is deleted immediately upon request (see Section 9).

We do not use any analytics or advertising technology, and we do not use a payment gateway or payment processor of any kind — payments for clinic services are recorded manually by clinic staff, not processed electronically through the Platform.

7. Minors and Family Accounts

Nobody under 18 may register their own patient account. A parent or legal guardian must hold their own account and add the minor as a "family member" (dependent) in order to manage that minor's appointments, assessments and medical records. When a guardian adds a dependent, the guardian is confirming they have the legal authority to act for that person and is providing, on the minor's behalf, the consents described in this Policy (including the health-data consent in Section 5).

8. How Long We Keep Your Data

We keep account data for as long as your account remains active. Clinical and health records are subject to recordkeeping obligations that apply to the clinics using the Platform, and we are still finalising, together with those clinics, how long specific categories of clinical records must be kept and how that is reconciled with the erasure rights described in Section 9 below — this means we cannot yet give you a single, fixed retention period for every type of health record. Assistant conversation history is the exception: it is not treated as part of the clinical record, and is deleted immediately when you ask us to (see Section 9).

9. Your Rights

Under the PDPL, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure; request restriction of processing; object to processing; and request a portable copy of your data.

You can exercise any of these rights through a request form available in your account settings. Each request is reviewed by a member of our team, not resolved automatically. In most cases we can act quickly. For erasure requests involving clinical records specifically, please note that deletion is not instant or automatic: clinics have their own legal recordkeeping obligations, and we are still working through how those obligations are reconciled with your erasure rights, so an erasure request touching medical records will be reviewed individually rather than executed immediately. By contrast, if you ask us to delete your AI assistant conversation history, we do so immediately, because no clinician relies on that history for care.

You also have the right to lodge a complaint with Egypt's Personal Data Protection Center.

10. Security

We apply the following measures to protect your data:

  • Passwords are hashed with bcrypt; we never store or can retrieve your plain-text password.
  • All traffic to and from the Platform is encrypted in transit (HTTPS).
  • Access to records is controlled by role-based permissions enforced down to the level of the individual record, so, for example, a doctor can only see records they are authorised to see.
  • Authentication and verification endpoints are rate-limited, and our error messages are designed to avoid revealing whether a given email or account exists (no account-enumeration leaks).
  • We keep an audit log of access to medical records; patients can see, in their own account, who accessed their record and when.
  • We use standard security headers and cross-origin restrictions to reduce common web attack surfaces.

We continue to build out our security and compliance programme, including matters that are still in progress at the time of writing (for example, formal data-centre encryption-at-rest arrangements and backup policies), and we will update this Policy as that work is confirmed.

11. Cross-Border Data Transfers

Because we are still confirming the physical location of our hosting provider's data centre(s) (Section 6), we cannot yet confirm whether personal data is transferred outside Egypt, or under what safeguards. We are also in the process of applying for any cross-border transfer permit that may be required under the PDPL. We will update this Policy, and where required seek any additional consent, as soon as this is resolved.

12. Cookies and Local Storage

The Platform does not use tracking or advertising cookies. Your login session is kept using a token stored in your browser's local storage, not a cookie. For full details of the cookie and local-storage categories we use (or may use in future) and how to control them, see our Cookie Policy.

13. Our PDPL Compliance Programme

As of the date of this Policy: our registration as a data controller with Egypt's Personal Data Protection Center is in progress; we are in the process of designating a formal Data Protection Officer; and, as noted above, any cross-border transfer permit that may be required is also in progress. We are not yet able to state that any of these are complete, and we will update this Policy the moment each one is.

14. Data Breach Notification

If we become aware of a personal data breach, we will notify Egypt's Personal Data Protection Center within 72 hours of becoming aware of it, and, where required, notify affected individuals within 3 working days.

15. Changes to This Policy

We may update this Policy from time to time, for example as our compliance programme progresses or as the Platform's features change. Material changes may require you to re-confirm your consent before you can continue using the Platform. We will always show you the current version's effective date.

16. Contact Us

If you have questions about this Policy or want to exercise your rights outside the in-account request form, you can reach us at privacy@medicalhoruscloud.com.