Privacy Policy
How Synora processes personal data under Egypt's Personal Data Protection Law 151/2020: what is collected, why, where it is kept, for how long, and your rights.
1. Who we are and the law we follow
This policy explains how Nano System for Artificial Intelligence (نانو سيستم للذكاء الاصطناعي), a Limited Liability Company (LLC) registered in the Arab Republic of Egypt at the Cairo Investment Commercial Registry Office under commercial register no. 213792, tax registration no. 755-247-124, with its registered office at 53 Capital Mall, behind the Court, 2nd floor, Fifth Settlement, New Cairo, Cairo, Egypt ("Nano AI", "we") handles personal data in Synora, the dental clinic management service, and on the Synora website.
We follow Egypt's Personal Data Protection Law (Law 151 of 2020) and its executive regulations, the Anti-Cybercrime Law (Law 175 of 2018), and the rules on medical confidentiality that bind the clinics we serve.
2. Our two roles: controller and processor
- Patient data — everything a clinic records about its patients. The clinic is the controller; we are its processor and handle this data only on the clinic's instructions, to provide the service, under the Data Processing Agreement (/legal/dpa). Patients who want to exercise their rights should contact their clinic first; we help the clinic answer.
- Account, billing and website data — the clinic's staff accounts, subscription and payment records, and messages sent to us through the website. For this data we are the controller.
3. What data is processed
- Staff accounts: name, email, phone, role, branch, password (stored only as a one-way hash), two-step verification settings, language.
- Clinic data: clinic name, branches, rooms, services, prices, settings, and the connection details of the clinic's own WhatsApp and payment accounts (stored encrypted).
- Patient data, entered by the clinic: identity and contact details, date of birth, medical and dental history, allergies and medicines, the dental chart, diagnoses, treatment plans and notes, prescriptions, images and documents, appointments, lab cases, invoices, payments and installments, insurance details, messages, and marketing-consent and opt-out records.
- Billing: plan, period, amounts and the Paymob payment reference. Card details are entered on Paymob's page and never reach us.
- Technical data: IP address, browser and device (user agent), session and sign-in records, and the audit log of actions in the account.
- Website: the name, phone, clinic name, email and message you send through a form on the Synora website; only if you allow analytics cookies, the website usage statistics described in section 13; and only if you allow marketing cookies, the advertising-measurement data the Meta Pixel collects, also described in section 13.
4. Patient health data is sensitive personal data
Health, medical and dental data, and data about children, are sensitive personal data under Law 151 of 2020. They may be processed only with the patient's explicit, documented consent (or a guardian's, for a minor) or another basis the law allows, and with stronger protection.
The clinic, as controller, obtains and keeps that consent and holds any licence the Personal Data Protection Center requires of it. We, as processor, apply the technical and organisational measures in section 8 and will hold the licences or permits the law requires of us for processing sensitive data.
5. Why we use data
- to provide and secure the service the clinic subscribed to (the contract with the clinic, and the clinic's instructions for patient data);
- to bill the subscription, send receipts and renewal reminders (the contract, and our legal duties on tax and accounting);
- to keep technical logs, detect abuse and investigate incidents (our legal duties under Law 175 of 2018, and our legitimate interest in a secure service);
- to answer questions and requests sent through the website (your request);
- to send product news to a clinic owner only if they opted in at sign-up; they can withdraw free of charge at any time, from the Subscription screen in the app or through the unsubscribe link every such message carries;
- to measure and improve our advertising on Facebook and Instagram, only if you allow marketing cookies on the Synora website (your consent, which you can withdraw at any time; section 13).
We do not sell personal data, do not use patient data for advertising or profiling, and do not use it to train artificial-intelligence models.
6. Service providers (sub-processors)
We share data only with the providers below, only what each needs, under contract terms that protect it:
- Hosting: the servers that run Synora, its database and its file storage. The provider will be named here before this policy is final (see section 7).
- Paymob (Egypt): online payment of subscriptions — the payer's name, email, phone and the amount. Clinics that connect their own Paymob account use it for their patients' payments under their own agreement with Paymob.
- Meta Platforms (WhatsApp Cloud API): only when a clinic connects its WhatsApp Business account — the patient's phone number and the message text are sent to Meta to deliver the message.
- An email-delivery provider (SMTP): account emails, receipts, reminders and, when the clinic uses email, messages to patients — the recipient's address and the message. The provider will be named here before this policy is final.
- An error-monitoring service (Sentry-compatible): technical error reports with the account's internal user ID, never names, contact details or request contents. The provider will be named here before this policy is final.
- Have I Been Pwned: when you choose a password, only the first five characters of a one-way hash of it are sent to check it against known breached passwords — never the password itself.
- Google (Google Tag Manager and Google Analytics 4): statistics about the use of the Synora website only, as section 13 describes. No app, clinic or patient data is ever sent to Google.
- Meta Platforms (Meta Pixel): only if you allow marketing cookies on the Synora website — the pages you view there, events such as a click on a sign-up or walkthrough button, cookie identifiers, your IP address and browser (user agent), to measure and improve our advertising, as section 13 describes. Meta also uses this data under its own privacy policy. No app, clinic or patient data is ever sent to Meta through the Pixel.
We give clinics at least 14 days' notice of a new sub-processor for patient data (DPA section 7).
7. Where data is stored and transfers abroad
The location of the servers that store Synora's data will be stated here before this policy is final. If any personal data is stored or accessed outside Egypt, we will transfer it only as Articles 14 to 16 of Law 151 of 2020 allow: to a country with a level of protection not lower than Egypt's, with the licence or permit the Personal Data Protection Center requires, and under written safeguards with the recipient. We will tell clinics before changing the storage location.
Website visitors who allow marketing cookies: the Meta Pixel data described in section 13 goes to Meta Platforms Ireland Limited and Meta Platforms, Inc., and may be processed in Ireland, the United States and other countries where Meta operates, under the safeguards Meta applies to its own transfers. Website statistics may likewise be processed by Google outside Egypt (section 13).
8. How we protect data
- each clinic's data is isolated from every other clinic's by row-level security in the database, which fails closed;
- connections are encrypted (HTTPS); passwords are stored as one-way hashes (Argon2); third-party credentials and two-step verification secrets are encrypted;
- access inside a clinic follows roles and permissions set by the clinic; two-step verification is available to every user;
- the audit log records sign-ins and changes to records, and cannot be altered or deleted by the application;
- if our support staff open a clinic's account to help it, the access is time-limited and recorded, with its reason, in that clinic's audit log;
- the database is backed up daily; backups are encrypted and kept for 30 days;
- our staff are bound by confidentiality and see patient data only when a clinic's request requires it.
9. How long data is kept
- Patient and clinic records: for as long as the clinic's account exists. The clinic decides how long its medical records must be kept; we never delete them because a payment was missed.
- After an account is closed: available for export for 60 days, then deleted within 30 days, and removed from backups as they roll over (up to 30 days). Our own invoices and billing records are kept for the period tax law requires.
- Technical logs: see section 10.
- Error reports: no longer than 90 days in the error-monitoring service.
- Website form messages: while we are in contact about your request, and deleted on request.
- Website statistics in Google Analytics: for the data-retention period set in our Google Analytics account, at most 14 months (section 13).
- Meta Pixel data (only with marketing consent): kept by Meta for the periods set in Meta's own data policy, which we do not control; the website stops sending it as soon as you withdraw consent (section 13).
- Marketing-consent records (who agreed or withdrew, when, to which wording, how, and from which IP address and browser): the platform keeps electronic consent records, their dates and the version number of the wording they relate to, for verification, compliance and legal proof under the applicable legislation, for as long as the account is active and for no less than 3 to 5 years after it ends or the consent is withdrawn. They are never edited — a withdrawal is a new record. If a patient's record is erased, the proof is kept without the IP address and browser, and no further marketing is sent.
10. Technical logs (180 days)
In line with Article 2 of the Anti-Cybercrime Law (Law 175 of 2018), we keep technical access records — sign-in sessions with IP address and device details, password-reset requests, and rate-limit records — for 180 days, after which they are deleted automatically. Sign-in, sign-out and failed sign-in events in a clinic's audit log are kept as part of that audit log for the life of the account.
We disclose these records only on a judicial order or a lawful request from a competent authority, and otherwise use them only to secure the service and investigate incidents.
11. Data breaches
If we become aware of a personal data breach affecting a clinic's data, we notify the clinic without undue delay and within 24 hours at most, with what we know about its nature, the data and people affected, its likely consequences and the measures taken. We cooperate fully so that the clinic can notify the Personal Data Protection Center within 72 hours, as Article 7 of Law 151 of 2020 requires, and the patients concerned where needed. For breaches of data we control, we notify the Center ourselves.
12. Your rights
Under Law 151 of 2020 you have the right to:
- know what data is held about you and get a copy of it;
- correct inaccurate data and complete incomplete data;
- withdraw your consent — this stops processing based on it from then on, but does not remove medical records the clinic must keep by law;
- ask for erasure — subject to the medical-record and tax retention duties that require some records to be kept, in which case identifying details can be removed while the clinical and financial record is kept;
- restrict processing, and object to it where the law allows;
- receive your data in a structured, machine-readable format (portability);
- complain to the Personal Data Protection Center.
Patients: send your request to your clinic; the clinic can correct your record in Synora, and we help it answer everything else. Staff, clinic owners and website visitors: email hello@nano-ai.net. We may ask you to prove your identity. We answer within 30 days of receiving a complete request.
13. Cookies and similar technologies
The Synora app uses only cookies that are strictly necessary for it to work:
- access_token — keeps you signed in; expires after 15 minutes;
- refresh_token — renews your session securely; expires after 90 days, or when you sign out;
- synora_lang — remembers the language you chose (Arabic or English), so the app and the website open in it; contains only that language code; expires after one year.
The app also stores your theme, display preferences and selected branch in your browser's local storage. It uses no advertising or analytics cookies. You can delete cookies in your browser settings, but you will then need to sign in again.
The Synora website sets the same strictly necessary synora_lang language cookie: every page you open records its language there, so the app opens in the language you were reading. It is shared between the website and the app on the same domain, holds nothing but the language code, and is never used to identify or track you, which is why it needs no consent.
When website statistics or advertising measurement are switched on, the website shows a cookie banner with two independent choices, Analytics and Marketing, and three equal buttons: "Accept all", "Reject all" and "Customize", which lets you switch each choice on or off (both start off). Nothing optional runs until you choose.
Analytics. The website uses Google Tag Manager and Google Analytics 4, services provided by Google, to produce aggregated statistics about how the website is used: how many visits, which pages, and which buttons lead to sign-up or a walkthrough request. It works as follows:
- Google Analytics sets its cookies (_ga, and _ga_ followed by an ID; they hold a random identifier and expire after up to two years) only after you allow Analytics, with "Accept all" or the Analytics switch.
- Until you choose, and if you do not allow Analytics, Google's tags run in consent mode with analytics storage denied: they set no analytics cookies and send only cookie-free pings (for example, that a page was viewed), which Google may use to estimate statistics in aggregate.
- Google receives your IP address with each request, as any website does; as Google documents, Google Analytics 4 does not log or store IP addresses. Google may process this data outside Egypt, including in the United States.
- The statistics are kept for the data-retention period set in our Google Analytics account, at most 14 months.
Marketing (advertising measurement). Only if you allow Marketing, with "Accept all" or the Marketing switch, the website's Google Tag Manager container loads the Meta Pixel, a tool provided by Meta Platforms Ireland Limited and Meta Platforms, Inc. It works as follows:
- What it sends to Meta: the pages you view on the website; events such as a click on a sign-up or walkthrough button and the fact that a walkthrough request was sent (never what you wrote in the form); cookie identifiers (the _fbp cookie, and _fbc when you arrive from a Facebook or Instagram ad; they expire after 90 days); and your IP address and browser details (user agent).
- Why: to measure and improve our ads on Facebook and Instagram, and to build ad audiences (for example, people who visited the website) for them. Meta also uses this data under its own privacy policy.
- Until you allow Marketing, the Meta Pixel does not load and sets no cookies, and Google's advertising consent types (ad storage, ad user data and ad personalisation) stay denied; they are granted only together with Marketing.
- Meta may process this data outside Egypt, including in Ireland and the United States, and keeps it for the periods set in Meta's own data policy.
Your answers are remembered in a cookie named synora_consent, which holds only a format version and your two answers (for example v2.a1.m0), stays on this website, and expires after 180 days, when the banner asks again. It is strictly necessary to respect your choice. An answer given before the Marketing choice existed counts as "no" to Marketing.
You can change either choice at any time with "Cookie settings" at the bottom of every page of the website. Turning Analytics off stops analytics cookies from then on and deletes the Google Analytics cookies the website can reach. Turning Marketing off stops the Meta Pixel from then on (the page reloads without it) and deletes the _fbp and _fbc cookies the website can reach. Withdrawing does not undo what was sent before it. You can also delete cookies in your browser settings, and manage how Meta uses your data in your Facebook or Instagram settings.
The Synora app (app.synoradental.com) does not use Google Tag Manager, Google Analytics, the Meta Pixel or any other analytics or advertising tag. When the website instead uses Cloudflare Web Analytics for page-view statistics, it counts visits without cookies and without storing anything in your browser.
14. Data Protection Officer and privacy contact
We are appointing a Data Protection Officer, as Articles 8 and 9 of Law 151 of 2020 require, to oversee our compliance, handle data-subject requests and breach notifications, and liaise with the Personal Data Protection Center; the officer will be registered with the Center and named here. Until then, privacy requests are handled by the company's management at hello@nano-ai.net (subject: "Privacy request"), or by post to 53 Capital Mall, behind the Court, 2nd floor, Fifth Settlement, New Cairo, Cairo, Egypt.
15. Changes to this policy
We will publish any change here with a new date, and give clinic owners at least 30 days' notice of material changes by email and in the product.
Operator
| Operator | Nano System for Artificial Intelligence — Limited Liability Company (LLC) (Nano AI) |
|---|---|
| Commercial Register No. | 213792 — Cairo Investment Commercial Registry Office |
| Tax Registration No. | 755-247-124 — Nasr City 1 Tax Office |
| Registered office | 53 Capital Mall, behind the Court, 2nd floor, Fifth Settlement, New Cairo, Cairo, Egypt |
| hello@nano-ai.net |