Back

Privacy Policy

Version 1.0 — Last updated: August 1, 2026

Compliant with Egyptian Personal Data Protection Law (PDPL) and Nigerian Data Protection Regulation (NDPR).

1. Data Controller & Contact Details

Data Controller: Ctrl F2 Technology Solutions

Address: Cairo, Egypt

Email: privacy@telemedcare.com

Data Protection Officer (DPO): Dr. Ahmed El Zahaaby

DPO Contact: dpo@telemedcare.com

2. Personal Data Categories Collected

CategoryExamplesLegal Basis
Identity DataFull name, date of birth, gender, profile photoContract
Contact DataEmail address, phone number, home addressContract
Health DataMedical history, symptoms, prescriptions, consultation notes, lab resultsExplicit Consent
Payment DataCard tokens (last 4 digits), billing address, transaction historyContract + Consent
Professional Data (Doctors)Medical licence, specialty, university, experience, certificationsLegal Obligation
Technical DataIP address, browser type, device ID, session duration, login timestampsLegitimate Interest
Communication DataChat messages, video recordings (with consent), support ticketsContract + Consent
Preference DataLanguage, notification settings, cookie preferencesConsent

3. Data Retention Periods

Data CategoryRetention Period
Account & Identity DataActive account + 30 days after deletion request
Health Records7 years (medical record-keeping regulations)
Payment/Transaction Records7 years (tax regulations)
Consent RecordsIndefinitely (anonymised on account deletion)
Audit Logs5 years
Video Recordings90 days after consultation
Technical/Session Data12 months

4. Third-Party Data Sub-Processors

ProviderRoleData Processed
Amazon Web Services (AWS)Cloud infrastructure, file storage (S3), email delivery (SES), authentication (Cognito)All data categories
SupabasePostgreSQL database hostingAll data categories
StripePayment processing (international cards)Payment data, identity data
PaystackPayment processing (African markets)Payment data, identity data
Daily.coVideo consultation infrastructureVideo/audio streams, session metadata
Upstash (Redis)Session caching, rate limitingSession tokens, temporary data
Google (Gemini AI)Document verification analysisDoctor credential documents (licence, ID)

We do not sell your personal data to any third party.

5. Your Rights

Under PDPL (Egypt) and NDPR (Nigeria), you have the right to:

  • Access — Request a copy of all personal data we hold
  • Rectification — Correct inaccurate or incomplete data
  • Erasure — Request deletion (subject to legal retention)
  • Data Portability — Receive your data in machine-readable format
  • Withdraw Consent — Withdraw optional consents at any time
  • Object — Object to processing based on legitimate interest
  • Restriction — Request limitation of processing

6. How to Submit a Rights Request

You can exercise your rights through:

  • In-app: Settings → Privacy & Consent → manage consents, request data export, or delete account
  • Email: Send your request to dpo@telemedcare.com

We will respond within 30 days. Identity verification may be required.

7. Right to Lodge a Complaint

If you are unsatisfied with our response, you may lodge a complaint with:

  • Egypt: Egyptian Data Protection Center (EDPC) — www.edpc.gov.eg
  • Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng

8. Cookies & Tracking

We use the following cookie categories:

  • Strictly Necessary: Session token, CSRF protection, language preference. Cannot be declined.
  • Analytics: Page views, session duration, user flow (opt-in only).
  • Marketing: Advertising retargeting (opt-in only, not currently active).

You can manage cookie preferences at any time from Settings → Privacy → Cookie Preferences, or via the cookie banner on first visit.

9. Security Measures

  • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication available for all accounts
  • Role-based access control with principle of least privilege
  • Regular security audits and penetration testing
  • Automatic session timeouts and login lockout
  • Full audit logging of all data access and modifications

10. Policy Updates

Material changes will be communicated via email and an in-app re-consent prompt at least 14 days before taking effect. You must re-accept to continue using the platform. Prior versions are accessible at /privacy-policy/versions.

Last updated: August 1, 2026

© 2026 Ctrl F2 Technology Solutions. All rights reserved.