سياسة الخصوصيةPrivacy Policy
1. من نحن
منصة "دكتوري" (Doctori) خدمة رقمية لحجز المواعيد الطبية في جمهورية العراق، تشغل من قبل دكتوري (Doctori) ("نحن"، "المنصة"، "دكتوري")، ومقرها بغداد، جمهورية العراق.
نحن المتحكم بالبيانات فيما يخص البيانات التي نجمعها منك مباشرة، ونعمل معالجا فيما يخص البيانات الطبية التي يسجلها الدكاترة عن مرضاهم.
- البريد العام للخصوصية: [email protected]
- مسؤول حماية البيانات (DPO): [email protected]
- العنوان البريدي: العراق · بغداد
- البريد الإلكتروني للمؤسس: [email protected]
2. البيانات التي نجمعها
2.1 بيانات الحساب (لكل المستخدمين)
- الاسم الكامل، رقم الهاتف
- تاريخ الميلاد، الجنس، المحافظة
- اللغة المفضلة
لا نطلب من المريض صورة شخصية ولا بريدا الكترونيا ولا عنوان سكن. صورة الملف الشخصي خاصة بالدكاترة وحدهم، ويرفعها فريق دكتوري لا الدكتور بنفسه.
2.2 بيانات المريض الطبية
- فصيلة الدم، الطول، الوزن
- الحساسية، الأمراض المزمنة، الأدوية الحالية، ملاحظاتك
- الوصفات الطبية التي يصدرها لك الدكتور
هذه البيانات تدخلها انت، ولك ان تتركها فارغة.
2.3 بيانات أفراد العائلة
- اسم كل فرد وصلة قرابته وجنسه وتاريخ ميلاده، ورقم هاتفه ان اضفته
- ملاحظات تكتبها انت عنه
لا يملك المرافق ملفا طبيا مستقلا: البيانات الطبية في حسابك تعود اليك انت.
2.4 بيانات الدكتور
- رقم الترخيص الطبي العراقي، التخصص + التخصصات الفرعية
- العيادات والمستشفيات، ساعات الدوام، رسوم الاستشارة المعلنة
- السيرة الذاتية والشهادات
2.5 بيانات الحجز
- الدكتور + العيادة + الموعد، حالة الحجز
- ملاحظات المريض، وقت الوصول الفعلي + رقم الطابور
2.6 البيانات المالية (للدكاترة)
- اشتراكات الدكتور وفواتير الاشتراك
2.7 بيانات الجهاز والاتصال
- نوع الجهاز ونظام التشغيل، إصدار التطبيق
- رموز الإشعارات، معرف الجهاز (للأمان فقط)
- عنوان IP · لسجلات التدقيق فقط
2.8 سجلات التدقيق (Audit Logs)
كل عملية حساسة (تسجيل دخول، تعديل ملف طبي، إصدار وصفة، عملية مالية) · الوقت + المستخدم + النوع + النتيجة.
2.9 ما لا نجمعه
- ❌ بيانات الموقع الجغرافي المستمر (GPS tracking)
- ❌ قائمة جهات الاتصال
- ❌ محتوى الرسائل خارج التطبيق
- ❌ معرفات إعلانية (IDFA / GAID)
- ❌ بيانات سلوكية لأغراض إعلانية
- ❌ بيانات تتبع من أطراف ثالثة
3. الأساس القانوني للمعالجة
| الغرض | الأساس القانوني |
|---|---|
| إنشاء الحساب والمصادقة | تنفيذ العقد |
| الحجز وإدارة المواعيد | تنفيذ العقد |
| معالجة السجل الطبي | المصلحة الحيوية + تنفيذ العقد |
| الاتصالات التسويقية | الموافقة (قابلة للسحب) |
| التحليلات الداخلية | المصلحة المشروعة |
| منع الاحتيال | المصلحة المشروعة |
4. كيف نستخدم بياناتك
- تشغيل الخدمة: المصادقة، البحث عن الدكاترة، الحجز، إدارة الطابور، إصدار الوصفات.
- الأمان: كشف محاولات الدخول المشبوهة، منع الاحتيال، حماية الحسابات.
- الاتصال التشغيلي: إشعارات تأكيد الحجز، تذكير بالموعد، إشعار قرب الدور.
- الاتصالات التسويقية (بموافقتك المنفصلة فقط).
- التحليلات الداخلية: قياس استخدام الميزات · بدون أدوات تتبع خارجية.
5. مشاركة البيانات مع أطراف ثالثة
| المعالج | المنطقة | الغرض | الضمانات |
|---|---|---|---|
| مزود قاعدة البيانات والمصادقة والتخزين | الاتحاد الأوروبي | قاعدة البيانات، المصادقة، تخزين الملفات | DPA + SCCs |
| مزود إرسال الرسائل النصية | العراق | رموز التحقق عبر SMS / WhatsApp / Telegram | DPA |
| مزود الإشعارات لنظام iOS | عالمي | إشعارات iOS | الشروط القياسية للمزود |
| مزود الإشعارات لنظام Android | عالمي | إشعارات Android | الشروط القياسية للمزود |
| مزود شبكة توصيل المحتوى | عالمي | تسليم ملفات الموقع الثابتة | DPA |
لا نبيع بياناتك أبدا. لا نشاركها لأغراض إعلانية أو تسويقية. نشاركها فقط مع مزودي الخدمة الذين يشغلون المنصة، او لحماية الحياة، او بموافقتك الصريحة.
6. النقل العابر للحدود
تخزن بياناتك لدى مزود بنية تحتية سحابية معتمد ضمن الاتحاد الأوروبي. هذا يعني أن بياناتك تنقل من العراق إلى الاتحاد الأوروبي.
سبب الاختيار: غياب مزودي خدمات سحابية ذوي مستوى أمني وتقني مكافئ داخل العراق حاليا، واختيار مزود ضمن الاتحاد الأوروبي لأنه يخضع لمعايير حماية البيانات الأوروبية (GDPR).
الآلية القانونية للنقل:
- موافقتك الصريحة عند التسجيل.
- الشروط التعاقدية المعيارية (SCCs) الموقعة مع المزود.
- تشفير كامل أثناء النقل والتخزين.
يحق لك رفض النقل عبر الحدود · لكن لا يمكننا تقديم الخدمة في تلك الحالة.
7. مدد الاحتفاظ بالبيانات
| نوع البيانات | المدة | السبب |
|---|---|---|
| بيانات الحساب | سنتان من آخر تسجيل دخول، أو حتى الحذف الطوعي | اختيار المستخدم |
| السجلات الطبية | سنتان من آخر نشاط | اختيار المستخدم (أقصر من المعيار العالمي 7 سنوات) |
| السجلات المالية | 5 سنوات | قانون الضرائب العراقي |
| سجلات التدقيق | سنتان (سنة نشطة + سنة أرشيف) | احتياجات التحقيقات |
| تقارير الأخطاء | 90 يوما | هندسي فقط |
| رموز الإشعارات | حتى انتهاء الصلاحية | تشغيل الخدمة |
⚠️ إفصاح صريح: قرار الاحتفاظ بالسجلات الطبية لمدة سنتين فقط هو اختيار صريح للمنصة، وأقصر من المعيار الطبي العالمي (HIPAA: 6 سنوات؛ WHO: 10 سنوات).
8. الأمن
- تشفير كامل أثناء النقل والتخزين.
- قفل بيومتري اختياري داخل التطبيق.
- عزل صارم للوصول إلى البيانات حسب الدور والصلاحية.
- سجلات تدقيق محمية للعمليات الحساسة.
- ضوابط مشددة على الصلاحيات الإدارية.
- تدريب الفريق على حماية البيانات.
9. الأطفال
🚫 التطبيق غير مخصص للاستخدام المباشر من قبل الأطفال دون 13 سنة.
يستطيع الوالد/ة اضافة الطفل كـ "فرد عائلة" من حسابه المصادق عليه، ويحجز له من نفس الحساب.
من بلغ 13 سنة يستطيع انشاء حساب مستقل باسمه.
10. ملفات تعريف الارتباط والتتبع
- داخل التطبيق: لا أدوات تتبع طرف ثالث، لا معرفات إعلانية، لا أدوات تحليل خارجية.
- الموقع: cookies تقنية أساسية فقط (جلسة تسجيل الدخول).
11. التعديلات على السياسة
- تحدث السياسة عبر نشر النسخة الجديدة في الموقع او داخل التطبيق · وانت مسؤول عن مراجعتها بين فترة واخرى.
- يحق لك سحب موافقتك وإغلاق الحساب.
12. التواصل
- عام/خصوصية: [email protected]
- DPO: [email protected]
- شكاوى رسمية: [email protected]
1. Who We Are
The "Doctori" platform is a digital medical appointment booking service in the Republic of Iraq, operated by Doctori (دكتوري) ("we", "the Platform", "Doctori"), headquartered in Baghdad.
We are the Data Controller for data we collect directly from you, and a Data Processor for medical data recorded by doctors about their patients.
- General privacy: [email protected]
- Data Protection Officer (DPO): [email protected]
- Postal address: Iraq · Baghdad
- Founder email: [email protected]
2. Data We Collect
2.1 Account data
Full name, phone number, date of birth, gender, governorate, preferred language.
We never ask a patient for a profile photo, an email address, or a home address. Profile photos belong to doctors only, and are uploaded by the Doctori team rather than by the doctor.
2.2 Patient medical data
Blood type, height, weight, allergies, chronic conditions, current medications, your own notes, and the prescriptions your doctor issues you.
You enter these yourself and may leave them blank.
2.3 Family member data
Each member's name, relationship, gender and date of birth, plus a phone number if you add one, and any notes you write about them.
A family member has no separate medical record: the medical data on your account belongs to you.
2.4 Doctor data
Iraqi medical license number, specialty + subspecialty, affiliated clinics, working hours, declared fees, biography and credentials.
2.5 Booking data
Selected doctor + clinic + appointment time, status, patient notes, actual arrival time + queue number.
2.6 Financial data (doctors)
Doctor subscriptions and subscription invoices.
2.7 Device and connection data
Device type and OS, app version, push notification tokens, device identifier (security only), IP address (audit only).
2.8 Audit logs
Every sensitive operation: timestamp + user + type + result.
2.9 What we DO NOT collect
- ❌ Continuous geolocation (GPS tracking)
- ❌ Contact list
- ❌ Off-app message content
- ❌ Advertising identifiers (IDFA / GAID)
- ❌ Behavioral data for advertising
- ❌ Third-party tracking data
3. Lawful Basis for Processing
| Purpose | Lawful Basis |
|---|---|
| Account creation & auth | Contract |
| Booking | Contract |
| Medical record processing | Vital interest + Contract |
| Marketing communications | Consent (revocable) |
| In-house analytics | Legitimate interest |
| Audit logging | Legal obligation + Legitimate interest |
| Fraud prevention | Legitimate interest |
| Response to legal authorities | Legal obligation |
4. How We Use Your Data
- Service operation: authentication, doctor search, booking, queue management, prescription issuance.
- Security: detection of suspicious logins, fraud prevention, account protection.
- Operational communication: confirmations, reminders, queue-position notifications.
- Marketing communications (only with separate consent).
- In-house analytics: feature usage, performance — no external tracking tools.
5. Sharing With Third Parties
| Sub-processor | Region | Purpose | Safeguards |
|---|---|---|---|
| Database, authentication & storage provider | European Union | Database, authentication, file storage | DPA + SCCs |
| SMS messaging provider | Iraq | OTP via SMS / WhatsApp / Telegram | DPA |
| iOS push notification provider | Global | iOS push delivery | Provider's standard terms |
| Android push notification provider | Global | Android push delivery | Provider's standard terms |
| Content delivery network provider | Global | Static asset delivery | DPA |
We never sell your data. We never share for advertising or marketing. We share only with the service providers that operate the platform, to protect life, or with your prior explicit consent.
6. Cross-Border Transfer
Your data is stored with a certified cloud infrastructure provider within the European Union. This means your data is transferred from Iraq to the European Union.
Reason: absence of cloud providers of equivalent security/technical level in Iraq currently; an EU-based provider was chosen because it is subject to European data protection standards (GDPR).
Legal mechanism:
- Your explicit consent at sign-up.
- Standard Contractual Clauses (SCCs) signed with the provider.
- Fully encrypted in transit and at rest.
You may refuse cross-border transfer — but we cannot then provide the service.
7. Retention Periods
| Data type | Retention | Reason |
|---|---|---|
| Account data | 2 years from last login OR until voluntary deletion | User choice |
| Medical records | 2 years from last activity | User choice (shorter than 7-year norm) |
| Financial records | 5 years | Iraqi tax law minimum |
| Audit logs | 2 years (1 active + 1 archived) | Investigation needs |
| Error reports | 90 days | Engineering only |
| Push tokens | Until invalidated | Service operation |
⚠️ Explicit disclosure: 2-year retention for medical records is the platform owner's deliberate choice and is shorter than the international medical norm (HIPAA: 6 years; WHO: 10 years).
8. Security
- Fully encrypted in transit and at rest.
- Optional biometric lock inside the app.
- Strict role-based isolation of data access.
- Protected audit logging of sensitive operations.
- Tight controls on administrative privileges.
- Team training on data protection.
9. Children
🚫 The app is NOT intended for direct use by children under 13.
A parent may add a child as a "family member" from their authenticated account and book on the child's behalf from that same account.
From age 13, a person can create an account of their own.
10. Cookies and Tracking
- In-app: no third-party tracking, no advertising IDs, no external analytics tools.
- Website: essential session cookies only.
11. Changes to This Policy
- Updates are published on the website or in the app — you are responsible for reviewing the policy periodically.
- You may withdraw consent and close your account.
12. Contact
- General/privacy: [email protected]
- DPO: [email protected]
- Formal complaints: [email protected]




