1. Introduction
At CareSync, protecting privacy is fundamental to the way we design and operate our technology.
This Privacy Policy (“Privacy Policy” or “Policy”) explains how CareSync For Technology LLC, a company registered in Cairo, Arab Republic of Egypt (“CareSync,” “we,” “us,” or “our”), collects, uses, stores, shares and otherwise processes personal data in connection with our websites, mobile applications, web applications, administrative portals and related digital services.
CareSync provides white-label digital health technology to healthcare organizations and other authorized organizations. Depending on the deployment, CareSync may support patient access, appointment scheduling, telemedicine, home healthcare, patient engagement, chronic-care programs, patient support programs, provider workflows, administrative operations, analytics and related digital healthcare services.
This Policy applies to personal data processed through:
- our website at care-sync.co
- CareSync-branded digital services
- mobile and web applications operated by CareSync
- business and demonstration request forms
- communications with CareSync
- CareSync accounts and portals where this Policy is presented
- other CareSync services that expressly link to this Policy
Because CareSync also provides technology to hospitals, clinics, healthcare networks, pharmaceutical companies, patient support program operators and other organizations, it is important to understand the distinction between information CareSync processes for its own purposes and information CareSync processes on behalf of a Customer Organization.
2. Who We Are
The organization responsible for this Policy is:
CareSync For Technology LLC Cairo, Arab Republic of Egypt
Website: care-sync.co
For purposes of applicable data-protection law, CareSync may act as either a data controller or a data processor, depending on the circumstances.
When CareSync acts as a controller
CareSync may determine how and why personal data is processed in connection with activities such as:
- operating our corporate website
- responding to sales and demonstration inquiries
- managing business relationships
- administering our own accounts and communications
- maintaining website security
- recruiting
- managing CareSync's own vendors
- conducting permitted business analytics
- sending authorized business or marketing communications
When CareSync acts as a processor
Where CareSync provides technology to a hospital, clinic, pharmaceutical company, PSP operator, healthcare provider or other Customer Organization, the Customer Organization will commonly determine why patient, healthcare or program information is processed.
In those circumstances, CareSync generally processes information on the Customer Organization's behalf and according to its documented instructions and the applicable contractual arrangements.
The Customer Organization may therefore be the appropriate party to contact regarding your healthcare information or requests concerning personal data managed through its CareSync deployment.
3. Customer Organizations
A “Customer Organization” may include a:
- hospital
- healthcare system
- medical group
- clinic or polyclinic
- healthcare professional organization
- pharmaceutical or life-sciences organization
- patient support program operator
- home healthcare provider
- insurer
- employer
- healthcare administrator; or
- other organization authorized to use CareSync
When you use a CareSync-powered service provided under a Customer Organization's name or brand, your relationship with that organization may also be governed by its own privacy notice, patient consent documentation and terms.
4. Personal Data We May Collect
The information CareSync processes depends on how you interact with us and which CareSync services are enabled.
We apply the principle that personal data should be collected only where appropriate for legitimate and specified purposes.
4.1 Identity Information
This may include:
- full name
- username or account identifier
- date of birth where relevant
- gender where relevant to the service
- customer or patient identifiers
- professional identifiers
- other identity information necessary to provide the applicable service
4.2 Contact Information
This may include:
- email address
- telephone number
- mobile number
- business contact information
- country or region
- mailing address where required
- preferred communication method
4.3 Business and Professional Information
When you interact with CareSync in a professional capacity, we may process information such as:
- organization name
- job title
- professional role
- department
- business email
- business telephone number
- organization type
- areas of interest
- professional credentials where relevant
- information submitted when requesting a demonstration, proposal or consultation
5. Healthcare and Sensitive Personal Data
Certain CareSync deployments may process healthcare or other sensitive personal data.
Depending on the Customer Organization and services enabled, this may include information relating to:
- health status
- medical history
- healthcare appointments
- treatment or care programs
- treating healthcare professionals
- medications
- chronic-care programs
- patient support programs
- healthcare services requested or received
- clinical notes or information submitted by authorized healthcare professionals
- consent or program enrollment
- follow-up activities
- adherence-related information
- care coordination
- home healthcare requests
- telemedicine interactions
- other health-related information necessary for the relevant healthcare service
Healthcare information is treated as sensitive information where required by applicable law.
Where CareSync processes such information on behalf of a Customer Organization, that organization's instructions, privacy obligations, patient notices, consents and contractual arrangements govern the purposes for which the information is processed.
CareSync does not independently use patient healthcare information for unrelated advertising or marketing purposes merely because that information is hosted or processed through the CareSync platform.
6. Account and Authentication Information
Where you create or receive access to a CareSync account, we may process information including:
- account identifier
- username
- protected authentication credentials
- role
- organization affiliation
- branch or department
- access permissions
- authentication events
- login history
- session information
- account security information
7. Appointment and Service Information
Depending on the enabled CareSync modules, information may include:
- requested healthcare service
- healthcare provider
- appointment date and time
- facility or service location
- booking status
- cancellation or rescheduling information
- service preferences
- telemedicine request information
- home healthcare request information
- administrative information needed to coordinate services
8. Communications
When you communicate with CareSync or use enabled communication functionality, we may process:
- emails
- inquiries
- support requests
- feedback
- messages
- communication preferences
- notification status
- information you choose to submit through communication features
Where communications occur between a patient and a Customer Organization or healthcare professional through the platform, CareSync may process those communications on behalf of the relevant Customer Organization.
9. Information Collected Through Our Website
When you visit the CareSync website or request information about our services, we may collect information such as:
- full name
- work email address
- organization
- professional role
- telephone number
- country
- organization type
- services or solutions of interest
- inquiry details
- other information you voluntarily submit
Information submitted through business inquiry forms should not include patient medical information unless a form specifically states that it is designed and secured for that purpose.
10. Technical and Device Information
When you use our websites, applications or services, certain technical information may be generated automatically.
This may include:
- Internet Protocol address
- browser type
- device type
- operating system
- application version
- device identifiers
- language settings
- pages or screens accessed
- dates and times of access
- session duration
- referral information
- system events
- error logs
- diagnostic information
- security-related logs
11. Location Information
CareSync does not necessarily collect precise location information in every deployment.
Where location functionality is necessary for a particular feature, such as identifying an appropriate service area or coordinating a location-based healthcare service, location information may be processed only in accordance with the applicable configuration, permissions and legal requirements.
Website systems may also infer an approximate geographic area from information such as an IP address.
13. How We Use Personal Data
CareSync may process personal data for the following purposes, depending on our role and the nature of your interaction with us.
Providing Our Services
We may process data to:
- create and administer accounts
- authenticate users
- enable access to authorized services
- facilitate healthcare workflows
- support appointment booking
- facilitate telemedicine functionality
- coordinate home healthcare functionality
- support patient engagement
- support chronic-care and patient support programs
- deliver reminders and notifications
- support healthcare professionals
- operate administrative dashboards
- enable configured integrations
Operating and Improving CareSync
We may process information to maintain the platform, improve user experience, monitor performance, troubleshoot errors, develop improvements and support service continuity.
Security and Fraud Prevention
Information may be used to authenticate users, monitor suspicious activities, maintain audit records, prevent unauthorized access, investigate security incidents and safeguard CareSync infrastructure.
Customer Support
We may use information to answer questions, resolve support requests, troubleshoot technical issues and assist Customer Organizations.
Business Communications
CareSync may use appropriate professional contact information to respond to inquiries, schedule demonstrations, prepare proposals and manage customer relationships.
Marketing
Where permitted by applicable law and where any required consent has been obtained, CareSync may send information about CareSync services, product developments, events, webinars and relevant industry content.
Legal and Regulatory Purposes
Personal data may be processed where necessary to comply with applicable law, fulfill regulatory requirements, establish or defend legal rights, maintain required records or protect the rights and safety of CareSync, our customers, users or others.
14. Legal Bases for Processing
Where applicable data-protection laws require a lawful basis, CareSync processes personal data only where an appropriate basis applies.
Depending on the circumstances, this may include:
- your valid consent
- performance of a contract or steps related to entering into a contract
- compliance with a legal obligation
- establishment, exercise or defense of legal rights
- legitimate interests where permitted and where those interests do not override applicable individual rights; or
- another basis authorized by applicable law
When CareSync processes information on behalf of a Customer Organization, the Customer Organization is generally responsible for determining the appropriate legal basis for the relevant processing where it acts as controller.
15. Consent
Where CareSync relies on consent, we seek to ensure that consent is appropriate for the relevant processing activity.
Withdrawal of consent does not ordinarily affect processing that was lawfully performed before the withdrawal.
Where a Customer Organization is responsible for obtaining consent, questions or withdrawal requests may need to be directed to that organization.
17. Aggregated and De-Identified Information
CareSync may generate aggregated, statistical or de-identified information where permitted by applicable law and contractual arrangements.
Such information may be used to evaluate platform performance, understand usage trends, improve products, improve operational workflows, develop analytics and support business planning.
18. Data Residency and Hosting
CareSync supports configurable hosting and data-residency models depending on the applicable customer deployment.
Data may therefore be hosted:
- within Egypt
- within the country in which a Customer Organization operates
- in another approved hosting location; or
- within dedicated infrastructure agreed with the Customer Organization
The actual hosting architecture and residency arrangement applicable to enterprise data is determined by the relevant deployment and contractual arrangements.
CareSync does not represent that every CareSync deployment uses the same hosting location.
19. International Data Transfers
Because CareSync may support organizations operating across different jurisdictions, personal data may in some circumstances be transferred or accessed across national borders.
Where personal data is transferred internationally, CareSync seeks to apply the legal, technical, contractual and organizational safeguards required by applicable data-protection laws.
Where Egyptian data-protection requirements apply, cross-border transfers will be handled subject to applicable Egyptian legal and regulatory requirements.
20. Data Retention
CareSync retains personal data only for as long as reasonably necessary for the purpose for which it was processed, subject to:
- applicable law
- regulatory requirements
- contractual commitments
- security requirements
- dispute-resolution needs
- legitimate record-keeping requirements
- Customer Organization instructions where CareSync acts as processor
Different types of information may have different retention periods.
For data processed on behalf of Customer Organizations, retention and deletion periods may be established in the applicable contract or deployment configuration.
21. Security
CareSync maintains technical and organizational measures designed to protect personal data against risks including unauthorized access, unauthorized disclosure, loss, misuse, alteration, destruction and inappropriate processing.
Depending on the deployment, controls may include:
- encryption in transit
- encryption at rest on managed infrastructure
- role-based access controls
- configurable administrative permissions
- authentication controls
- logging
- environment separation
- backup and recovery procedures
- security monitoring
- access-management procedures
No internet-connected system or method of electronic storage can be guaranteed to be completely secure.
22. Personal Data Breaches
CareSync maintains processes designed to identify, assess and respond to suspected personal data or security incidents.
Where a personal data breach occurs, CareSync will take actions required by applicable law and contractual obligations, which may include investigation, containment, mitigation, documentation, communication with the responsible Customer Organization and legally required notifications.
23. Your Privacy Rights
Depending on applicable law and CareSync's role in relation to your personal data, you may have rights including the right to:
- access your information
- request correction
- request deletion where legally available
- request restriction of processing
- withdraw consent
- object to certain processing
- receive information concerning certain personal data breaches where required by law
Other rights may be available depending on your jurisdiction.
24. Exercising Your Rights
If CareSync is responsible for the personal data concerned, you may submit a privacy request using the contact information provided below.
Before fulfilling a request, CareSync may need to verify your identity to protect your information from unauthorized disclosure.
Where CareSync processes the relevant information solely on behalf of a Customer Organization, we may refer or forward your request to that Customer Organization.
If your request relates to medical records, PSP enrollment, healthcare appointments, treatment information or other information managed by a specific healthcare organization, that organization may be the appropriate party to handle your request.
25. Children and Minors
CareSync's public corporate website and business inquiry functions are not intended for children to independently submit personal information.
However, healthcare organizations using CareSync may provide legitimate healthcare or patient-support services to children or minors.
Where children's personal data is processed through a CareSync customer deployment, appropriate protections must be applied in accordance with applicable law.
26. Direct Marketing
CareSync distinguishes healthcare and operational communications from promotional marketing communications.
Where required by applicable law, electronic direct marketing will be conducted only after obtaining the necessary consent or other lawful authorization.
Marketing communications should provide an appropriate method to unsubscribe or otherwise stop future marketing.
If you opt out of marketing, CareSync may still send communications necessary for account administration, service delivery, security, legal notices or other non-promotional purposes.
27. Healthcare Communications and Notifications
CareSync-powered services may send messages such as:
- appointment confirmations
- appointment reminders
- service updates
- patient-support reminders
- care-coordination notifications
- follow-up communications
- administrative notifications
- security alerts
Healthcare-related communications should not be relied upon as an emergency medical service.
28. Third-Party Websites and Services
CareSync websites or applications may contain links to websites, applications or services operated by third parties.
CareSync does not control the privacy practices of independent third parties.
Information submitted directly to a third-party service is governed by that third party's privacy policy.
29. App Stores
CareSync-powered mobile applications may be distributed through platforms such as the Apple App Store or Google Play.
These platforms independently process certain information relating to account activity, downloads, devices, purchases where applicable and application usage.
Their processing is governed by their own privacy policies and terms.
30. Healthcare Professionals and Workforce Users
Healthcare professionals, patient educators, program personnel, administrators and other workforce users may provide personal and professional information to CareSync or a Customer Organization.
Depending on the deployment, this may include:
- name
- business contact information
- role
- organization
- department
- branch
- professional credentials
- account access
- activity records
- platform usage information
31. Data Generated Through Enterprise Use
CareSync may maintain records relating to the operation and security of enterprise services, including login activity, administrative actions, access events, configuration changes, system events, integration events, error logs and technical audit information.
These records may be necessary to support security, compliance, troubleshooting and contractual obligations.
32. Automated Processing and Analytics
CareSync may use software-based processes to organize, analyze or present information within the platform.
Unless expressly agreed and lawfully configured for a specific deployment, CareSync does not independently make medical diagnoses or replace the clinical judgment of qualified healthcare professionals.
Where a particular deployment involves automated decision-making that creates legal or similarly significant effects, additional disclosures and safeguards may be required under applicable law.
33. Changes to This Privacy Policy
We may revise this Privacy Policy from time to time to reflect changes in CareSync services, technology, regulatory requirements, security developments or privacy practices.
When we update this Policy, we will update the Last Updated date shown at the top.
Where changes are material and applicable law requires additional notice, we may provide notice through our website, platform, email, application notifications or another appropriate communication channel.
34. Relationship With Our Terms of Use
This Privacy Policy should be read together with the CareSync Terms of Use and any other notices, consents or contractual terms applicable to the relevant service.
Where CareSync processes data for a Customer Organization, additional privacy and data-protection terms may also be contained within Enterprise Agreements, Data Processing Agreements, service agreements, program-specific agreements, deployment documentation and Customer Organization privacy notices.
35. Egyptian Data Protection Framework
CareSync For Technology LLC is registered in Cairo, Arab Republic of Egypt.
Where applicable, CareSync processes personal data in accordance with relevant Egyptian data-protection requirements and other applicable laws governing its activities.
CareSync also recognizes that healthcare customers operating in other jurisdictions may be subject to additional privacy, healthcare and data-residency obligations.
The specific legal and regulatory requirements applicable to a deployment depend on the country of operation, Customer Organization, type of healthcare service, categories of personal data, hosting arrangement, integrations, enabled modules and CareSync's contractual role.
Nothing in this Policy should be interpreted as representing that every CareSync deployment is governed by an identical regulatory framework.
36. Data Protection Requests and Complaints
If you have a question about how CareSync processes personal data or wish to exercise an applicable privacy right, you may contact us using the details below.
Where your information is controlled by a hospital, clinic, healthcare provider, PSP operator or other Customer Organization, CareSync may direct you to that organization so your request can be handled by the appropriate data controller.
Where applicable, individuals may also have the right to submit a complaint to the competent data-protection authority.
37. Contact CareSync
For questions or requests relating to this Privacy Policy or CareSync's handling of personal information, please contact:
CareSync For Technology LLC Cairo, Arab Republic of Egypt
Privacy inquiries: moh.essam@care-sync.co
Data Protection Officer: moh.essam@care-sync.co
Security inquiries: moh.essam@care-sync.co
General inquiries: moh.essam@care-sync.co
Website: care-sync.co
When submitting a privacy request, please provide enough information for us to identify the relevant interaction, account or Customer Organization without including unnecessary sensitive medical information in an unsecured communication.
38. Our Privacy Principles
CareSync's privacy approach is based on:
Purpose Limitation
Personal data should be processed for clear and legitimate purposes.
Data Minimization
Only information reasonably necessary for the intended purpose should be processed.
Access Control
Personal data should be accessible only to appropriately authorized users.
Security by Design
Privacy and security safeguards should be considered throughout technology design and deployment.
Transparency
Individuals should receive appropriate information about how their data is processed.
Customer Control
Customer Organizations should maintain appropriate control over their healthcare workflows and agreed data environment.
Shared Responsibility
Effective healthcare privacy depends on CareSync, Customer Organizations, healthcare professionals, technology providers and users fulfilling their respective responsibilities.
© 2026 CareSync For Technology LLC. All rights reserved.
