طَود

PRIVACY

سياسة الخصوصية

آخر تحديث: ٢٩ يوليو ٢٠٢٦ · تسري على منصّة طَود وقنواتها (واتساب، إنستغرام، الويب، البريد)

مَن نحن، ودورنا

طَود منصّة برمجية تُشغّل العيادات الطبية في سلطنة عُمان. العيادة هي المتحكّم في بيانات مرضاها، وطَود معالِج يعمل بتوجيهها ونيابةً عنها. لا نستخدم بيانات مرضى أي عيادة لأغراضنا، ولا نبيعها، ولا نشاركها مع عيادة أخرى.

ما الذي نجمعه

لا نخزّن بيانات البطاقات البنكية إطلاقاً. عند تفعيل الدفع الإلكتروني تتم العملية لدى مزوّد الدفع، ولا يصلنا منها إلا نتيجة العملية ورقمها المرجعي.

لماذا نعالجها

المساعد الذكي وما يُرسَل إليه

تعتمد سُرى على نماذج لغوية من Google (Gemini). عند ردّها على رسالة، يُرسَل نصّ الرسالة وسياق العيادة اللازم للإجابة — الخدمات، أوقات الدوام، وتوفّر الأطباء — إضافةً إلى معلومات موجزة عن المريض عند الحاجة لتمييز المراجع من الجديد. لا تُرسَل السجلات الطبية التفصيلية ولا البيانات المالية إلى النموذج. ولا تُستخدم هذه المعطيات لتدريب أي نموذج.

سُرى لا تشخّص ولا تصف علاجاً. وعند اشتباه حالة طارئة تتوقّف وتُنبّه فريق العيادة فوراً.

الأطراف التي نستعين بها

كلٌّ منهم يعالج البيانات بتوجيهنا وبقدر ما تتطلّبه خدمته فقط.

العزل بين العيادات

كل صفّ بيانات مرتبط بعيادة واحدة، والعزل مفروض في قاعدة البيانات نفسها لا في واجهة التطبيق — بحيث ترفض القاعدة الوصول حتى لو أخطأ الكود. ولكل موظف دور يحدّد ما يراه، فموظف الاستقبال لا يرى السجلّ الطبي، ولا يرى المحاسب ما لا يخصّ المال.

الاحتفاظ والحذف

نحتفظ ببيانات المريض ما دامت العيادة مشتركة، ثم لمدّة تفرضها الأنظمة الطبية والضريبية في عُمان. عند حذف سجلّ من داخل النظام يُعلَّم كمحذوف ويختفي من كل الشاشات، ويُحتفظ به في السجلّ غير القابل للتعديل للمراجعة والمساءلة. وعند انتهاء علاقتنا بالعيادة، تُسلَّم لها بياناتها ثم تُحذف نهائياً بطلب منها.

حقوقك

وفق قانون حماية البيانات الشخصية العُماني (المرسوم السلطاني ٦/٢٠٢٢)، للمريض أن يطلب الاطّلاع على بياناته أو تصحيحها أو حذفها أو الاعتراض على معالجتها. وجّه الطلب إلى عيادتك — فهي المتحكّم في بياناتك. وتلتزم طَود بتنفيذ ما تطلبه العيادة خلال المدد النظامية.

التواصل

لأي سؤال يخصّ هذه السياسة: playmoham19@gmail.com


ENGLISH

Privacy Policy

Who we are

TAWD is software that runs medical clinics in the Sultanate of Oman. The clinic is the controller of its patients' data; TAWD is a processor acting on the clinic's instructions. We do not use one clinic's patient data for our own purposes, do not sell it, and never share it with another clinic.

What we collect

  • Patient details entered by the clinic: name, phone, date of birth, appointments.
  • Clinical records written by the doctor: diagnosis, treatment plan, prescriptions, dental chart.
  • Messages sent and received over WhatsApp, Instagram and web chat, including voice notes.
  • Financial records: invoices, payments and payment method — never card details.
  • Clinic staff details and an audit trail of the actions each of them performs.

We never store bank card data. Where online payment is enabled, the transaction happens at the payment provider and we receive only its result and reference.

Why we process it

  • Booking, confirming and reminding patients of appointments.
  • Letting the AI assistant «Sura» answer patient enquiries on the clinic's behalf.
  • Issuing invoices and receipts and computing VAT as Omani law requires.
  • Running the clinic: inventory, payroll, insurance claims and management reporting.
  • Security and error tracking, through an audit log that cannot be edited or deleted.

The AI assistant

Sura is built on Google Gemini. To answer a message we send the message text and the clinic context needed to reply — services, working hours, doctor availability — plus a brief patient summary where needed to tell a returning patient from a new one. Detailed medical records and financial data are never sent to the model, and none of it is used to train any model. Sura does not diagnose or prescribe, and stops and alerts clinic staff when a message suggests an emergency.

Processors we rely on

  • Supabase — database hosting and authentication.
  • Vercel — application hosting.
  • Meta (WhatsApp Business Platform and Instagram) — message delivery.
  • Google — language models and text-to-speech.
  • Resend — outbound email.
  • n8n — automation (reminders, follow-ups, waitlists).

Isolation between clinics

Every row belongs to exactly one clinic, and that isolation is enforced by the database itself rather than by the application — so access is refused even if application code is wrong. Each staff member has a role that limits what they see: reception cannot open the clinical record, and accounting sees only what concerns money.

Retention and deletion

Patient data is kept while the clinic is subscribed, and thereafter for the period Omani medical and tax rules require. Deleting a record inside the system marks it deleted and removes it from every screen while retaining it in the immutable audit log. When our relationship with a clinic ends, its data is exported to it and then permanently deleted on request.

Your rights

Under Oman's Personal Data Protection Law (Royal Decree 6/2022) a patient may request access, correction, deletion, or object to processing. Address the request to your clinic — it is the controller. TAWD carries out what the clinic instructs within the statutory periods.

Contact

playmoham19@gmail.com