Privacy policy
Last updated: 29 September 2026
This policy explains how data is handled in Doctal, a product owned and operated by TAIF - Marketing Agency — طيف للتسويق الالكتروني, a company registered in Bani Yas, Abu Dhabi, United Arab Emirates. Where this page says "we", it means that company.
1. Who decides and who carries out
The clinic subscribing to Doctal holds the relationship with its patients and decides what it collects from them and why. We process that data on the clinic's behalf and on its instructions, as the provider of the system. A request from a patient about her own data may reach us directly or through her clinic; we act on it either way.
For the clinic's own account data — company name, staff details, subscription records — we are the party responsible, as the service provider.
2. What data is processed
About a patient
- The name shown on her WhatsApp account, or the one the clinic records.
- Her WhatsApp number, or the conversation identifier Meta supplies when the number is not sent.
- The content of messages exchanged with the clinic, together with any attached photos, voice notes, documents, locations and contact cards, and the sent, delivered and read timestamps.
- Appointments: branch, doctor, service, time and status (attended, no show, cancelled), the session number within a package where one exists, and any deposit recorded.
- Notes and pipeline stage written by clinic staff, and qualification fields each clinic defines for itself.
- If the conversation began from a Click-to-WhatsApp ad, the data Meta sends about that ad in the same message notification: its identifier, headline, body text and image.
Doctal is not an electronic medical record and is not intended to hold diagnoses, prescriptions or medical reports. A patient may choose to send health information in a message, in which case it is stored within that conversation as sent; it is for the clinic to meet whatever its own law requires of it in handling such information.
About clinic staff
- Name, email address, role (owner, supervisor, sales rep, receptionist) and branch.
- A record of work: who answered which conversation and when, who reassigned it to whom and why, and response times — data the clinic's own supervisor uses to manage the team.
- Hashed sign-in credentials.
Technical data
Logs needed to run and protect the service: request times, outcomes and error messages. Doctal contains no advertising trackers, and the pages of doctal.cloud set no tracking cookies and load no third-party scripts.
3. WhatsApp and Meta
Doctal is built on the WhatsApp Business Platform (Cloud API) from Meta Platforms, Inc. Every message sent to or received from a patient therefore passes through Meta's servers, because that is the only way WhatsApp for business works. We would rather state this plainly than leave it implied:
- What reaches Meta: the patient's WhatsApp number and the clinic's number, message content and attachments, delivery and read notifications, the clinic's business account details, and message template approval requests. From Meta we receive inbound messages and delivery status updates.
- We see nothing the clinic does not: what appears in the system is what passed between a patient and her clinic. We do not use conversation content for marketing, do not sell it, and do not share it with advertisers.
- The 24-hour window: Meta does not allow free-form text more than 24 hours after a patient's last message; only a pre-approved template is accepted after that. This is why appointment reminders are usually sent as an approved template.
- Reporting ad results to Meta (optional, off by default): if a clinic switches it on to measure its advertising, an event is sent to Meta through the Conversions API stating that a conversation originating from an ad became a qualified lead or a sale, together with the referral identifier Meta itself supplied and the sale value. No message content is included in that event. It stays off unless the clinic explicitly enables it.
- What Meta does with its own data is governed by Meta's terms, not by this policy. See the WhatsApp Business terms and the WhatsApp privacy policy.
- The patient's own copy: deleting a conversation from Doctal does not remove it from the WhatsApp app on the patient's phone, nor from Meta's systems. See the data deletion page.
4. The AI agent and the model provider
On the tier that includes the AI agent, each message the agent answers sends the knowledge base the clinic wrote and an extract of the current conversation to the language-model provider, so that a reply can be composed. We select providers that do not use this content to train their models. On the tier without the agent, no conversation content is sent to any language-model provider at all.
A clinic can switch the agent off for one conversation or for all of them at any time, and the conversation returns to a member of staff.
5. Why this data is processed
- So the clinic can receive and answer its patients' messages in one place.
- To book and manage appointments and send their reminders.
- To route conversations to the team and measure response times inside the clinic.
- To show the clinic its results: conversations, appointments and where they came from.
- To protect the system from abuse and diagnose faults.
- To meet a legal obligation where one applies.
The data is used for nothing else. It is not sold, and it is not shared with any party for that party's marketing.
6. Isolation between clinics
Each clinic is a separate entity in the system. Every record in the database is bound to its clinic, and every query is scoped to it. No clinic can reach another's data, and no member of staff sees more than their role allows: a sales rep is not served her colleagues' conversations, and a receptionist is not served conversations at all. That restriction is enforced on the server, not in the interface.
7. Protection
- Encryption at rest: sensitive secrets — above all the WhatsApp access token and other integration keys — are stored encrypted with AES-256-GCM and are never displayed in full again once saved; only the last four characters are shown, so they can be recognised.
- Encryption in transit: all traffic to the system and to Meta's endpoints runs over HTTPS/TLS.
- Verified webhooks: inbound WhatsApp notifications are checked against their signature and a secret endpoint before being accepted, and every message is processed exactly once.
- Access control: our own team's access to production is limited to those who need it to run the service or support a clinic, and is exercised at a clinic's request or to resolve a fault.
No system is perfectly secure. If a breach affects a clinic's data, we notify that clinic, explain what happened and set out what we are doing about it.
8. Retention and deletion
- A clinic's data is kept for as long as its subscription runs, because it is the tool it works in daily.
- On termination: a copy of the clinic's data is made available on request, after which it is removed from live systems and from backups within 30 days at the latest.
- On an individual request from a patient, her data is deleted within the same period. The full procedure is on the data deletion page.
- We may retain a minimum of accounting records relating to a clinic's subscription where the law requires it; these contain no conversation content.
9. Who we rely on
| Party | Why | What reaches them |
|---|---|---|
| Meta Platforms, Inc. | The WhatsApp channel itself | Messages, numbers, delivery statuses and business account details |
| Language-model provider | AI agent replies (higher tier only) | The clinic's knowledge base and an extract of the current conversation |
| Hosting provider | Running the servers and the database | Data is stored on its infrastructure |
We use no third party for tracking, advertising or behavioural analytics.
10. Patient and clinic rights
Anyone whose data is processed in Doctal may ask to:
- know what is held about them,
- have anything incorrect put right,
- have their data deleted,
- stop receiving the clinic's messages.
Send the request to the clinic directly, or to us at info@doctal.cloud or on WhatsApp 01091813512. We respond within 30 days at the latest. Any WhatsApp user can also block the clinic's number in the app, which stops its messages immediately.
11. Children and emergencies
Doctal is a working tool for a clinic and is not expected to be contacted by a child directly. Where a clinic corresponds about a minor, a guardian should be party to it as the clinic's own law requires. Neither WhatsApp nor Doctal is a suitable channel for a medical emergency, and the clinic should make that clear to its patients.
12. Changes to this policy
We update this page whenever something material changes in the service. The date of the last update is shown at the top, and subscribing clinics are notified of material changes before they take effect.
13. Contact us
- CompanyTAIF - Marketing Agency — طيف للتسويق الالكتروني
- Registered addressBani Yas, Abu Dhabi, United Arab Emirates
- Company phone+971 50 111 5665
- WhatsApp (Egypt)01091813512
- Emailinfo@doctal.cloud