Back to home

Privacy Policy

Last updated: 2026-08-30

Working draft — placeholder wording pending review by a qualified lawyer and the CNDP. Not a binding legal document.

This page describes the personal data docare processes and how it is protected. It is a working draft: the binding privacy policy will be issued after review by a qualified lawyer and, where required, the CNDP.

Who processes your data

docare is a practice-management platform used by doctors. For a patient's medical records, the treating doctor or practice is expected to act as the data controller and docare as a processor acting on their instructions. For a doctor's own account and billing data, docare acts as the controller. The final controller/processor allocation is subject to legal review.

What data is processed

Depending on who you are:

  • Doctors: name, email, professional details, authentication data, subscription and billing status, and any public-profile content you publish.
  • Patients (entered by your doctor): identity and contact details, and health data — allergies, conditions, medical history, consultation notes, prescriptions, lab results, uploaded medical documents, appointments, and appointment-related messages.
  • Public visitors: booking and review form entries, and a one-way hashed IP address used only to rate-limit abuse (the raw address is never stored).

Why it is processed

To provide the practice-management service; to run doctor-initiated AI assistance (transcription, extraction, summarisation, drafting) that a doctor always reviews before it enters a record; to send appointment-related messages; to operate the public professional page and online booking; to take subscription payments; and for security, abuse prevention and audit logging.

AI processing

AI features run only when a doctor starts them. Only the minimum data needed for the requested operation is sent to the AI provider (for example, a consultation summary is built from a restricted, doctor-approved payload — not the patient's entire file). The AI drafts; the doctor decides. The AI provider and its current data-handling position are listed in our internal processor register; a zero-retention arrangement is being pursued before production.

Third parties

docare relies on sub-processors for AI, WhatsApp messaging, email delivery, payments, database hosting, file storage and application hosting. Each is being placed under a data-processing agreement, and the basis for any transfer outside Morocco is part of the legal review.

Security

Access to patient data is restricted to the owning practice and enforced on the server for every request. Traffic is encrypted in transit. Provider credentials such as WhatsApp tokens are encrypted at rest. Logs are kept free of medical content and secrets. Sensitive actions are recorded in an audit trail.

Retention

Medical records are not deleted automatically — they are subject to medical-record retention rules and are handled only through an explicit deletion or anonymisation process. Operational data (webhook and rate-limit ledgers, expired sessions) is pruned on a short schedule. The final retention periods will be set with legal advice.

Your rights

Subject to the applicable law and to medical-record obligations, you may request access to, correction of, export of, or deletion of personal data, and you may set communication preferences. Patients should contact their doctor's practice; doctors can contact docare support. The mechanisms to service these requests are being built on the platform's existing per-practice data model.

Cookies and local storage

docare sets a sign-in session cookie, a language-preference cookie, a short-lived cookie during WhatsApp connection, and stores your light/dark theme choice in your browser. It does not use advertising or cross-site tracking cookies.

Contact

A dedicated privacy contact address will be published here with the finalized policy.