CareHelmBack to home

Pending legal review — this page describes CareHelm's data handling as the product actually works today. It has not yet been reviewed by legal counsel and is not a final, binding policy.

Privacy Policy

Last updated: 10 August 2026

This policy explains what personal data CareHelm collects, why, and how it is handled. CareHelm plays two different roles depending on who you are — the first section below explains which one applies to you.

Controller and processor — which one applies to you

If you are a patient of a clinic that uses CareHelm, your clinic is the data controller: it decides what patient data to collect and why, and it is the right place to send a request about your own records. CareHelm acts as a data processor for that patient data — we process it only on the clinic's instructions, inside that clinic's own isolated workspace.

If you signed up for a CareHelm account yourself — as a clinic owner creating a workspace, or as a visitor submitting our contact form — CareHelm is the data controller for that account and contact information.

What we collect

Depending on how you use CareHelm, we process:

  • Patient records entered by clinic staff: name, national ID, date of birth, gender, phone number, email, and address.
  • Clinical documentation entered by clinicians: medical history, assessments, session notes, treatment plans, discharge summaries, outcome measures, and clinical photos or media.
  • Files uploaded to a patient's record (e.g. lab results, referral letters).
  • Audit log entries for every change made in the system: which user made it, what action, before/after values, the time, the IP address, and the browser/device (user-agent string) used — kept for accountability and security investigation.
  • Session and sign-in metadata: the IP address and user-agent recorded when you sign in, so an account holder can review and revoke their own active sessions.
  • Notification delivery records: which reminder or confirmation template was sent, in which language, and to which phone number or email — not a saved copy of the exact wording, since messages are composed from a template at the moment they are sent.
  • If you sign up for CareHelm yourself: your name, email, phone number, clinic name, and the plan you select.

Why we process it

For patient data, we process it strictly to provide the clinic's workspace to the clinic that operates it — scheduling, clinical documentation, billing, and patient reminders — as instructed by that clinic. For account data, we process it to create and run your CareHelm account, respond to your enquiries, and improve the product.

We also process audit-log and session data for security: detecting suspicious sign-ins, investigating incidents, and meeting the clinic's own record-keeping obligations.

Who else processes this data (sub-processors)

CareHelm uses a small number of specialist providers to deliver the service. Each is instructed to process data only for the purpose listed and only to the extent needed.

  • Meta (WhatsApp Cloud API) — delivers WhatsApp appointment reminders and confirmations.
  • An SMS gateway (SMS Misr for Egypt; Twilio is available for other regions) — delivers SMS reminders and one-time codes.
  • An email provider (SMTP) — delivers account and notification emails.
  • An S3-compatible object storage provider — stores uploaded patient files and documents.
  • Render — hosts the application and its managed database.

How long we keep data

These are the retention periods CareHelm is built around today. They are the clinic's proposed operating parameters, pending final sign-off from legal counsel, and are not yet a guaranteed contractual commitment:

  • Medical records — 10 years after a patient's last visit.
  • Audit logs — 7 years.
  • Notification/chat delivery logs — 24 months.
  • Contact-form and signup lead information that never converts to a clinic — anonymized after 24 months of inactivity.

Where a retention period requires data to be removed, CareHelm's approach is to anonymize the record while keeping a minimal audit skeleton — the fact that an event happened — so the clinic's own audit trail and legal obligations stay intact.

Your rights, and how to request them

If your data was entered by a clinic (patient records), start with that clinic — they control the data and are best placed to act on an access, correction, or deletion request. CareHelm supports the clinic in fulfilling that request.

If you are contacting us about your own CareHelm account or a contact-form submission, email us (below) and we will act on the request ourselves.

There is no automated self-service deletion in CareHelm today. Every deletion or erasure request is handled manually: we verify the requester, then anonymize the record while retaining the minimal audit trail required for security and legal record-keeping.

Security measures

Each clinic's data lives in its own isolated workspace. Role-based access keeps clinical notes away from staff who don't need them. Every change is recorded in an audit trail, and audit rows cannot be edited or deleted. Sign-in supports two-factor codes, and an account holder can review and revoke their own active sessions. Encrypted off-site backups and a written restore procedure are built into the product; enabling and verifying them is the responsibility of whoever operates a given deployment.

Egypt's Personal Data Protection Law (PDPL)

CareHelm is designed with Egypt's Personal Data Protection Law (Law No. 151 of 2020) in mind. A full legal compliance review, including any cross-border data transfer question, is in progress and not yet complete — see the pending-review notice at the top of this page.

Children's data

CareHelm is used by clinic staff to record patient information, including for pediatric patients. Where a patient is a minor, the treating clinic is responsible for obtaining the appropriate consent from a parent or guardian before entering their data — the same as for any other patient record.

Changes to this policy

We may update this policy as the product or our providers change. Material changes will be reflected here with a new "last updated" date.

Contact us

Questions about this policy can be sent to the address below.

Questions? Reach us at our contact form

CareHelmThe clinic system your front desk can read at a glance.Contact usPrivacy policyTerms of serviceEnglishالعربية24°41′N 46°41′E · AL-OLAYA STATION · KEEP THE WATCH