CareSyncHome

Legal

Privacy Policy

This Privacy Policy explains how CareSync For Technology LLC collects, uses, protects and processes personal data across its websites, applications and digital healthcare platform.

Effective
1 September 2026
Last updated
1 September 2026
Provided by
CareSync For Technology LLC, Cairo, Arab Republic of Egypt

1. Introduction

At CareSync, protecting privacy is fundamental to the way we design and operate our technology.

This Privacy Policy (“Privacy Policy” or “Policy”) explains how CareSync For Technology LLC, a company registered in Cairo, Arab Republic of Egypt (“CareSync,” “we,” “us,” or “our”), collects, uses, stores, shares and otherwise processes personal data in connection with our websites, mobile applications, web applications, administrative portals and related digital services.

CareSync provides white-label digital health technology to healthcare organizations and other authorized organizations. Depending on the deployment, CareSync may support patient access, appointment scheduling, telemedicine, home healthcare, patient engagement, chronic-care programs, patient support programs, provider workflows, administrative operations, analytics and related digital healthcare services.

This Policy applies to personal data processed through:

  • our website at care-sync.co
  • CareSync-branded digital services
  • mobile and web applications operated by CareSync
  • business and demonstration request forms
  • communications with CareSync
  • CareSync accounts and portals where this Policy is presented
  • other CareSync services that expressly link to this Policy

Because CareSync also provides technology to hospitals, clinics, healthcare networks, pharmaceutical companies, patient support program operators and other organizations, it is important to understand the distinction between information CareSync processes for its own purposes and information CareSync processes on behalf of a Customer Organization.

2. Who We Are

The organization responsible for this Policy is:

CareSync For Technology LLC Cairo, Arab Republic of Egypt

Website: care-sync.co

For purposes of applicable data-protection law, CareSync may act as either a data controller or a data processor, depending on the circumstances.

When CareSync acts as a controller

CareSync may determine how and why personal data is processed in connection with activities such as:

  • operating our corporate website
  • responding to sales and demonstration inquiries
  • managing business relationships
  • administering our own accounts and communications
  • maintaining website security
  • recruiting
  • managing CareSync's own vendors
  • conducting permitted business analytics
  • sending authorized business or marketing communications

When CareSync acts as a processor

Where CareSync provides technology to a hospital, clinic, pharmaceutical company, PSP operator, healthcare provider or other Customer Organization, the Customer Organization will commonly determine why patient, healthcare or program information is processed.

In those circumstances, CareSync generally processes information on the Customer Organization's behalf and according to its documented instructions and the applicable contractual arrangements.

The Customer Organization may therefore be the appropriate party to contact regarding your healthcare information or requests concerning personal data managed through its CareSync deployment.

3. Customer Organizations

A “Customer Organization” may include a:

  • hospital
  • healthcare system
  • medical group
  • clinic or polyclinic
  • healthcare professional organization
  • pharmaceutical or life-sciences organization
  • patient support program operator
  • home healthcare provider
  • insurer
  • employer
  • healthcare administrator; or
  • other organization authorized to use CareSync

When you use a CareSync-powered service provided under a Customer Organization's name or brand, your relationship with that organization may also be governed by its own privacy notice, patient consent documentation and terms.

4. Personal Data We May Collect

The information CareSync processes depends on how you interact with us and which CareSync services are enabled.

We apply the principle that personal data should be collected only where appropriate for legitimate and specified purposes.

4.1 Identity Information

This may include:

  • full name
  • username or account identifier
  • date of birth where relevant
  • gender where relevant to the service
  • customer or patient identifiers
  • professional identifiers
  • other identity information necessary to provide the applicable service

4.2 Contact Information

This may include:

  • email address
  • telephone number
  • mobile number
  • business contact information
  • country or region
  • mailing address where required
  • preferred communication method

4.3 Business and Professional Information

When you interact with CareSync in a professional capacity, we may process information such as:

  • organization name
  • job title
  • professional role
  • department
  • business email
  • business telephone number
  • organization type
  • areas of interest
  • professional credentials where relevant
  • information submitted when requesting a demonstration, proposal or consultation

5. Healthcare and Sensitive Personal Data

Certain CareSync deployments may process healthcare or other sensitive personal data.

Depending on the Customer Organization and services enabled, this may include information relating to:

  • health status
  • medical history
  • healthcare appointments
  • treatment or care programs
  • treating healthcare professionals
  • medications
  • chronic-care programs
  • patient support programs
  • healthcare services requested or received
  • clinical notes or information submitted by authorized healthcare professionals
  • consent or program enrollment
  • follow-up activities
  • adherence-related information
  • care coordination
  • home healthcare requests
  • telemedicine interactions
  • other health-related information necessary for the relevant healthcare service

Healthcare information is treated as sensitive information where required by applicable law.

Where CareSync processes such information on behalf of a Customer Organization, that organization's instructions, privacy obligations, patient notices, consents and contractual arrangements govern the purposes for which the information is processed.

CareSync does not independently use patient healthcare information for unrelated advertising or marketing purposes merely because that information is hosted or processed through the CareSync platform.

6. Account and Authentication Information

Where you create or receive access to a CareSync account, we may process information including:

  • account identifier
  • username
  • protected authentication credentials
  • role
  • organization affiliation
  • branch or department
  • access permissions
  • authentication events
  • login history
  • session information
  • account security information

7. Appointment and Service Information

Depending on the enabled CareSync modules, information may include:

  • requested healthcare service
  • healthcare provider
  • appointment date and time
  • facility or service location
  • booking status
  • cancellation or rescheduling information
  • service preferences
  • telemedicine request information
  • home healthcare request information
  • administrative information needed to coordinate services

8. Communications

When you communicate with CareSync or use enabled communication functionality, we may process:

  • emails
  • inquiries
  • support requests
  • feedback
  • messages
  • communication preferences
  • notification status
  • information you choose to submit through communication features

Where communications occur between a patient and a Customer Organization or healthcare professional through the platform, CareSync may process those communications on behalf of the relevant Customer Organization.

9. Information Collected Through Our Website

When you visit the CareSync website or request information about our services, we may collect information such as:

  • full name
  • work email address
  • organization
  • professional role
  • telephone number
  • country
  • organization type
  • services or solutions of interest
  • inquiry details
  • other information you voluntarily submit

Information submitted through business inquiry forms should not include patient medical information unless a form specifically states that it is designed and secured for that purpose.

10. Technical and Device Information

When you use our websites, applications or services, certain technical information may be generated automatically.

This may include:

  • Internet Protocol address
  • browser type
  • device type
  • operating system
  • application version
  • device identifiers
  • language settings
  • pages or screens accessed
  • dates and times of access
  • session duration
  • referral information
  • system events
  • error logs
  • diagnostic information
  • security-related logs

11. Location Information

CareSync does not necessarily collect precise location information in every deployment.

Where location functionality is necessary for a particular feature, such as identifying an appropriate service area or coordinating a location-based healthcare service, location information may be processed only in accordance with the applicable configuration, permissions and legal requirements.

Website systems may also infer an approximate geographic area from information such as an IP address.

12. Cookies and Similar Technologies

Our website and certain digital services may use cookies and similar technologies.

Essential Cookies

Necessary for security, authentication, navigation, session management and website functionality.

Preference Cookies

Used to remember language, display preferences and other user selections.

Analytics Technologies

Where enabled, analytics technologies may help us understand how visitors use our website, general traffic patterns and technical performance.

Marketing Technologies

Where legally permitted and appropriately enabled, technologies may be used to understand the effectiveness of business marketing activities.

Where applicable law requires consent for non-essential cookies or similar technologies, CareSync will seek such consent before activating them.

13. How We Use Personal Data

CareSync may process personal data for the following purposes, depending on our role and the nature of your interaction with us.

Providing Our Services

We may process data to:

  • create and administer accounts
  • authenticate users
  • enable access to authorized services
  • facilitate healthcare workflows
  • support appointment booking
  • facilitate telemedicine functionality
  • coordinate home healthcare functionality
  • support patient engagement
  • support chronic-care and patient support programs
  • deliver reminders and notifications
  • support healthcare professionals
  • operate administrative dashboards
  • enable configured integrations

Operating and Improving CareSync

We may process information to maintain the platform, improve user experience, monitor performance, troubleshoot errors, develop improvements and support service continuity.

Security and Fraud Prevention

Information may be used to authenticate users, monitor suspicious activities, maintain audit records, prevent unauthorized access, investigate security incidents and safeguard CareSync infrastructure.

Customer Support

We may use information to answer questions, resolve support requests, troubleshoot technical issues and assist Customer Organizations.

Business Communications

CareSync may use appropriate professional contact information to respond to inquiries, schedule demonstrations, prepare proposals and manage customer relationships.

Marketing

Where permitted by applicable law and where any required consent has been obtained, CareSync may send information about CareSync services, product developments, events, webinars and relevant industry content.

Legal and Regulatory Purposes

Personal data may be processed where necessary to comply with applicable law, fulfill regulatory requirements, establish or defend legal rights, maintain required records or protect the rights and safety of CareSync, our customers, users or others.

16. How We Share Personal Data

CareSync may disclose personal data only where appropriate for legitimate business, healthcare, operational or legal purposes.

Depending on the circumstances, information may be shared with:

Customer Organizations

Authorized users of hospitals, clinics, PSP operators or other Customer Organizations according to the relevant deployment and assigned permissions.

Healthcare Professionals and Authorized Personnel

Appropriately authorized physicians, nurses, patient educators, healthcare coordinators, program managers, healthcare administrators or other authorized personnel.

Service Providers

Selected providers that support cloud infrastructure, hosting, security, communications, customer support, identity management, system monitoring, software development, analytics, email delivery or other technology operations.

Integrated Third Parties

Approved integrated systems such as electronic health record systems, hospital information systems, laboratories, identity systems, communication platforms and other authorized services.

Corporate Transactions

Where reasonably necessary in connection with a merger, acquisition, investment, restructuring, financing, sale of assets or similar transaction.

Legal Disclosure

Where necessary or permitted to comply with applicable law, respond to lawful requests, protect legal rights, investigate suspected fraud or respond to security incidents.

17. Aggregated and De-Identified Information

CareSync may generate aggregated, statistical or de-identified information where permitted by applicable law and contractual arrangements.

Such information may be used to evaluate platform performance, understand usage trends, improve products, improve operational workflows, develop analytics and support business planning.

18. Data Residency and Hosting

CareSync supports configurable hosting and data-residency models depending on the applicable customer deployment.

Data may therefore be hosted:

  • within Egypt
  • within the country in which a Customer Organization operates
  • in another approved hosting location; or
  • within dedicated infrastructure agreed with the Customer Organization

The actual hosting architecture and residency arrangement applicable to enterprise data is determined by the relevant deployment and contractual arrangements.

CareSync does not represent that every CareSync deployment uses the same hosting location.

19. International Data Transfers

Because CareSync may support organizations operating across different jurisdictions, personal data may in some circumstances be transferred or accessed across national borders.

Where personal data is transferred internationally, CareSync seeks to apply the legal, technical, contractual and organizational safeguards required by applicable data-protection laws.

Where Egyptian data-protection requirements apply, cross-border transfers will be handled subject to applicable Egyptian legal and regulatory requirements.

20. Data Retention

CareSync retains personal data only for as long as reasonably necessary for the purpose for which it was processed, subject to:

  • applicable law
  • regulatory requirements
  • contractual commitments
  • security requirements
  • dispute-resolution needs
  • legitimate record-keeping requirements
  • Customer Organization instructions where CareSync acts as processor

Different types of information may have different retention periods.

For data processed on behalf of Customer Organizations, retention and deletion periods may be established in the applicable contract or deployment configuration.

21. Security

CareSync maintains technical and organizational measures designed to protect personal data against risks including unauthorized access, unauthorized disclosure, loss, misuse, alteration, destruction and inappropriate processing.

Depending on the deployment, controls may include:

  • encryption in transit
  • encryption at rest on managed infrastructure
  • role-based access controls
  • configurable administrative permissions
  • authentication controls
  • logging
  • environment separation
  • backup and recovery procedures
  • security monitoring
  • access-management procedures

No internet-connected system or method of electronic storage can be guaranteed to be completely secure.

22. Personal Data Breaches

CareSync maintains processes designed to identify, assess and respond to suspected personal data or security incidents.

Where a personal data breach occurs, CareSync will take actions required by applicable law and contractual obligations, which may include investigation, containment, mitigation, documentation, communication with the responsible Customer Organization and legally required notifications.

23. Your Privacy Rights

Depending on applicable law and CareSync's role in relation to your personal data, you may have rights including the right to:

  • access your information
  • request correction
  • request deletion where legally available
  • request restriction of processing
  • withdraw consent
  • object to certain processing
  • receive information concerning certain personal data breaches where required by law

Other rights may be available depending on your jurisdiction.

24. Exercising Your Rights

If CareSync is responsible for the personal data concerned, you may submit a privacy request using the contact information provided below.

Before fulfilling a request, CareSync may need to verify your identity to protect your information from unauthorized disclosure.

Where CareSync processes the relevant information solely on behalf of a Customer Organization, we may refer or forward your request to that Customer Organization.

If your request relates to medical records, PSP enrollment, healthcare appointments, treatment information or other information managed by a specific healthcare organization, that organization may be the appropriate party to handle your request.

25. Children and Minors

CareSync's public corporate website and business inquiry functions are not intended for children to independently submit personal information.

However, healthcare organizations using CareSync may provide legitimate healthcare or patient-support services to children or minors.

Where children's personal data is processed through a CareSync customer deployment, appropriate protections must be applied in accordance with applicable law.

26. Direct Marketing

CareSync distinguishes healthcare and operational communications from promotional marketing communications.

Where required by applicable law, electronic direct marketing will be conducted only after obtaining the necessary consent or other lawful authorization.

Marketing communications should provide an appropriate method to unsubscribe or otherwise stop future marketing.

If you opt out of marketing, CareSync may still send communications necessary for account administration, service delivery, security, legal notices or other non-promotional purposes.

27. Healthcare Communications and Notifications

CareSync-powered services may send messages such as:

  • appointment confirmations
  • appointment reminders
  • service updates
  • patient-support reminders
  • care-coordination notifications
  • follow-up communications
  • administrative notifications
  • security alerts

Healthcare-related communications should not be relied upon as an emergency medical service.

28. Third-Party Websites and Services

CareSync websites or applications may contain links to websites, applications or services operated by third parties.

CareSync does not control the privacy practices of independent third parties.

Information submitted directly to a third-party service is governed by that third party's privacy policy.

29. App Stores

CareSync-powered mobile applications may be distributed through platforms such as the Apple App Store or Google Play.

These platforms independently process certain information relating to account activity, downloads, devices, purchases where applicable and application usage.

Their processing is governed by their own privacy policies and terms.

30. Healthcare Professionals and Workforce Users

Healthcare professionals, patient educators, program personnel, administrators and other workforce users may provide personal and professional information to CareSync or a Customer Organization.

Depending on the deployment, this may include:

  • name
  • business contact information
  • role
  • organization
  • department
  • branch
  • professional credentials
  • account access
  • activity records
  • platform usage information

31. Data Generated Through Enterprise Use

CareSync may maintain records relating to the operation and security of enterprise services, including login activity, administrative actions, access events, configuration changes, system events, integration events, error logs and technical audit information.

These records may be necessary to support security, compliance, troubleshooting and contractual obligations.

32. Automated Processing and Analytics

CareSync may use software-based processes to organize, analyze or present information within the platform.

Unless expressly agreed and lawfully configured for a specific deployment, CareSync does not independently make medical diagnoses or replace the clinical judgment of qualified healthcare professionals.

Where a particular deployment involves automated decision-making that creates legal or similarly significant effects, additional disclosures and safeguards may be required under applicable law.

33. Changes to This Privacy Policy

We may revise this Privacy Policy from time to time to reflect changes in CareSync services, technology, regulatory requirements, security developments or privacy practices.

When we update this Policy, we will update the Last Updated date shown at the top.

Where changes are material and applicable law requires additional notice, we may provide notice through our website, platform, email, application notifications or another appropriate communication channel.

34. Relationship With Our Terms of Use

This Privacy Policy should be read together with the CareSync Terms of Use and any other notices, consents or contractual terms applicable to the relevant service.

Where CareSync processes data for a Customer Organization, additional privacy and data-protection terms may also be contained within Enterprise Agreements, Data Processing Agreements, service agreements, program-specific agreements, deployment documentation and Customer Organization privacy notices.

35. Egyptian Data Protection Framework

CareSync For Technology LLC is registered in Cairo, Arab Republic of Egypt.

Where applicable, CareSync processes personal data in accordance with relevant Egyptian data-protection requirements and other applicable laws governing its activities.

CareSync also recognizes that healthcare customers operating in other jurisdictions may be subject to additional privacy, healthcare and data-residency obligations.

The specific legal and regulatory requirements applicable to a deployment depend on the country of operation, Customer Organization, type of healthcare service, categories of personal data, hosting arrangement, integrations, enabled modules and CareSync's contractual role.

Nothing in this Policy should be interpreted as representing that every CareSync deployment is governed by an identical regulatory framework.

36. Data Protection Requests and Complaints

If you have a question about how CareSync processes personal data or wish to exercise an applicable privacy right, you may contact us using the details below.

Where your information is controlled by a hospital, clinic, healthcare provider, PSP operator or other Customer Organization, CareSync may direct you to that organization so your request can be handled by the appropriate data controller.

Where applicable, individuals may also have the right to submit a complaint to the competent data-protection authority.

37. Contact CareSync

For questions or requests relating to this Privacy Policy or CareSync's handling of personal information, please contact:

CareSync For Technology LLC Cairo, Arab Republic of Egypt

Privacy inquiries: moh.essam@care-sync.co

Data Protection Officer: moh.essam@care-sync.co

Security inquiries: moh.essam@care-sync.co

General inquiries: moh.essam@care-sync.co

Website: care-sync.co

When submitting a privacy request, please provide enough information for us to identify the relevant interaction, account or Customer Organization without including unnecessary sensitive medical information in an unsecured communication.

38. Our Privacy Principles

CareSync's privacy approach is based on:

Purpose Limitation

Personal data should be processed for clear and legitimate purposes.

Data Minimization

Only information reasonably necessary for the intended purpose should be processed.

Access Control

Personal data should be accessible only to appropriately authorized users.

Security by Design

Privacy and security safeguards should be considered throughout technology design and deployment.

Transparency

Individuals should receive appropriate information about how their data is processed.

Customer Control

Customer Organizations should maintain appropriate control over their healthcare workflows and agreed data environment.

Shared Responsibility

Effective healthcare privacy depends on CareSync, Customer Organizations, healthcare professionals, technology providers and users fulfilling their respective responsibilities.

© 2026 CareSync For Technology LLC. All rights reserved.