سياسة الخصوصية — منصة وصفة

تاريخ السريان: 2026-07-10 التطبيقات: الطاقم الطبي وبوابة المريض الحزم: com.wasfah.staff v1.1.1 · com.wasfah.patient v1.1.4

تشرح هذه السياسة كيف تجمع منصة وصفة (Wasfah) البيانات وتستخدمها وتحميها عبر تطبيق الطاقم الطبي وتطبيق / موقع بوابة المريض والخدمات المرتبطة (مثل https://api.wasfah.org وhttps://my.wasfah.org). تنطبق هذه السياسة على كلا التطبيقين؛ تختلف البيانات الظاهرة حسب دورك (طاقم أو مريض).

1) التطبيقات المشمولة

2) البيانات التي نتعامل معها

قد يتعامل النظام مع الأنواع التالية حسب التطبيق والدور:

3) كيف نستخدم البيانات

4) مشاركة البيانات

لا نبيع البيانات. تتم مشاركة البيانات داخل منظومة التشغيل (الخادم/قاعدة البيانات) ومع المستخدمين المصرّح لهم فقط حسب الدور والصلاحيات داخل المؤسسة الصحية (مثلاً الطبيب يرى مرضاه؛ المريض يرى بياناته فقط). قد تستخدم مزودي رسائل (مثل واتساب/SMS) لإرسال رموز OTP فقط عند تفعيل الاستعادة عبر الهاتف.

5) النقل والتخزين والأمان

6) الأذونات (Permissions)

نسعى إلى الحد الأدنى من الأذونات. قد يطلب تطبيق المريض إذن الوصول إلى الصور لرفع صورة الملف الشخصي، ويُطلب وقت الحاجة فقط. تطبيق الطاقم يقتصر على الأذونات اللازمة لمسارات العمل السريرية. قد تختلف الأذونات حسب إصدار التطبيق والوظائف المفعّلة.

7) الاحتفاظ بالبيانات

الاحتفاظ بالبيانات الطبية وسجلات التدقيق يتم وفق سياسة المؤسسة الصحية والمتطلبات القانونية/التنظيمية ذات الصلة.

8) حقوق المستخدمين وطلبات الخصوصية

للاتصال بخصوص الخصوصية: privacy@wasfah.org

9) خصوصية الأطفال

تطبيق الطاقم موجّه للبالغين من الطاقم الطبي. بوابة المريض موجّهة لمن يبلغ 18 عاماً فأكثر عند التسجيل الذاتي. قد تتضمن سجلات المؤسسة بيانات مرضى أطفال كجزء من السجل الطبي.

10) التغييرات على هذه السياسة

قد نقوم بتحديث هذه السياسة من وقت لآخر. سنقوم بتعديل “تاريخ السريان” عند أي تحديث جوهري. راجع أيضاً شروط الخدمة.

Privacy Policy — Wasfah Platform

Effective date: 2026-07-10 Apps: Staff & Patient Packages: com.wasfah.staff v1.1.1 · com.wasfah.patient v1.1.4

This Privacy Policy describes how the Wasfah platform collects, uses, and protects data across the Staff app and the Patient portal (mobile and web), and related services (for example https://api.wasfah.org and https://my.wasfah.org). The same policy applies to both apps; the data you see depends on your role (staff or patient).

1) Covered apps

  • Wasfah Staff (com.wasfah.staff) — authorized healthcare staff.
  • Wasfah Patient (com.wasfah.patient) — patient portal (app and website).

2) Data we handle

  • Account/auth data (email and/or phone with country code, password hash, name, user identifiers).
  • Patient profile data (patient portal): demographics, emergency contact, health summary fields, insurance, optional profile photo.
  • Clinical and administrative patient data (primarily via staff app): file numbers, admissions, vitals, labs, prescriptions, appointments, attachments where applicable.
  • Communications from care teams to patients in the portal; OTP messages for password recovery via email or WhatsApp when enabled.
  • Audit logs and technical logs for security and troubleshooting.

3) How we use data

  • To provide care workflows, appointments, results, prescriptions, and patient self-service.
  • To authenticate users and support password recovery (email and/or WhatsApp OTP when enabled by your organization).
  • To enforce role-based access control.
  • To support security, compliance, and technical support.

4) Sharing

We do not sell user or patient data. Data is shared only with authorized users within the healthcare organization and the system backend required to operate the service. Messaging providers (e.g. WhatsApp/SMS) may be used solely to deliver OTP codes when phone recovery is enabled.

5) Security

  • API communication typically uses HTTPS (example: https://api.wasfah.org/api).
  • Authentication (JWT) and role-based access controls restrict access.
  • Staff admins should use strong passwords and MFA when available.

6) Permissions

We aim to request only necessary permissions. The patient app may request photo library access for a profile picture, only when you use that feature. The staff app requests permissions required for clinical workflows. Permissions may vary by app version and enabled features.

7) Retention

Medical record retention follows the healthcare organization’s retention policy and applicable regulations.

8) Contact & account deletion

Patients may update much of their profile in the patient portal. For other privacy requests, contact your clinic or privacy@wasfah.org. Staff should contact their organization’s system administrators. To request deletion of your account and associated data, use wasfah.org/account-deletion.html. See also our Terms of Service.

This page is provided to satisfy app store privacy policy requirements for both Staff and Patient apps and should be kept consistent with actual product behavior.