PC Passion Clinics Service Desk Legal, Privacy & Data Protection

Privacy Policy

This policy explains how Passion Clinics Service Desk processes personal data when users access the platform or connect and use WhatsApp Business services.

Effective date: 11 July 2026 Publicly accessible without login English & العربية

English Privacy Policy

This policy applies to Passion Clinics Service Desk, including its support, ticketing, automation, WhatsApp Business Platform, reporting, and related administration features.

1. Who controls your data

Passion Clinics is the organization responsible for the personal data processed through this Service Desk for its own operations. Authorized administrators and service personnel may access data only as needed for their assigned duties.

2. Data we may process

  • Account and profile data: name, business email, phone number, job role, department, language, permissions, and login records.
  • Support and service data: tickets, requests, replies, attachments, approvals, status history, assignment records, and audit logs.
  • WhatsApp account data: WhatsApp Business Account ID (WABA ID), Phone Number ID, display phone number, business profile details, message templates, quality and verification status, webhook subscription information, and connection status.
  • WhatsApp communications: sender and recipient identifiers, message content, attachments, timestamps, delivery/read status, conversation category, and bot or agent actions.
  • Usage and technical data: IP address, browser/device details, session and security events, error logs, and feature usage.
  • Analytics and billing references: message volume, delivery statistics, conversation categories, estimated or Meta-provided usage costs, billing account references, and payment setup status.
Payment card protection: the Service Desk does not request or store full payment card numbers, expiry dates, or CVV codes. Where payment setup is available, it is completed on Meta's secure pages and the system stores only limited status or reference information.

3. How we use data

  • Authenticate users and administer roles, permissions, and licenses.
  • Create, route, track, resolve, and report on support tickets and service requests.
  • Connect and manage WhatsApp Business accounts, phone numbers, templates, webhooks, and messaging.
  • Deliver automated bot responses, agent conversations, notifications, and approved message templates.
  • Provide operational reports, delivery analytics, usage information, and billing references.
  • Protect the platform, investigate errors or abuse, enforce access controls, and maintain audit records.
  • Comply with applicable laws, regulatory duties, and valid legal requests.

4. Meta and WhatsApp integration

When an authorized user connects a WhatsApp Business account, the platform exchanges data with Meta Platforms and WhatsApp through their official APIs and onboarding interfaces. Meta and WhatsApp process data under their own terms and privacy policies. The Service Desk uses the permissions granted by the authorized business only for the features described in this policy.

5. Legal and operational basis

Data is processed as needed to provide contracted or requested services, operate the organization's internal support and communications functions, protect legitimate operational and security interests, comply with legal obligations, and obtain consent where applicable law requires it.

6. Sharing and disclosure

We do not sell personal data. Data may be shared only with:

  • Authorized Passion Clinics personnel and approved system administrators.
  • Meta/WhatsApp where required to provide WhatsApp Business Platform functionality.
  • Hosting, email, security, backup, and technical service providers acting under appropriate obligations.
  • Regulators, courts, or law-enforcement authorities where disclosure is legally required.
  • A successor organization in a lawful restructuring, merger, or transfer, subject to applicable safeguards.

7. Retention

We retain data only for as long as necessary for the purposes described above, the organization's configured retention requirements, legitimate operational needs, dispute resolution, security, and applicable legal obligations. WhatsApp access credentials are retained in encrypted form while the integration remains active and are removed or invalidated when the connection is disconnected or deleted. Data that is no longer required is deleted, anonymized, or securely archived as appropriate.

8. Security

Reasonable administrative, technical, and organizational safeguards are used, including HTTPS, role-based access controls, restricted administrator access, encrypted storage for sensitive integration credentials, audit logging, backups, and monitoring. No method of transmission or storage is completely risk-free, but we continuously work to reduce foreseeable risks.

9. Cookies and sessions

The platform uses essential session and security cookies required for login, language preferences, CSRF protection, and safe operation. These cookies are not used to sell personal data or build third-party advertising profiles.

10. International processing

Some service providers, including Meta/WhatsApp and infrastructure providers, may process data in countries other than the user's location. Where required, appropriate contractual, technical, and organizational safeguards are applied in accordance with applicable data protection requirements.

11. Your choices and rights

Subject to applicable law and organizational requirements, users may request access, correction, restriction, objection, portability, or deletion of personal data. Requests may require identity verification. To request deletion, follow the dedicated Data Deletion Instructions.

12. Sensitive information and children

The Service Desk is intended for authorized business users and is not directed to children. Users should avoid sending unnecessary health, financial, identity, or other sensitive information through WhatsApp or support tickets. Where sensitive information is legitimately required, it must be handled according to the organization's approved policies and applicable law.

13. Changes to this policy

We may update this policy when the platform, integrations, or legal requirements change. The current version and effective date will remain available on this page.

14. Contact

Organization Passion Clinics
Privacy and support contact info@passionclinics.com

سياسة الخصوصية

تسري هذه السياسة على نظام مكتب خدمات باشن كلينك، بما في ذلك الدعم الفني والتذاكر والأتمتة ومنصة واتساب للأعمال والتقارير والوظائف الإدارية المرتبطة بها.

1. الجهة المسؤولة عن البيانات

تُعد باشن كلينك الجهة المسؤولة عن البيانات الشخصية التي تتم معالجتها من خلال نظام مكتب الخدمات لأغراض تشغيلها. ولا يطّلع على البيانات إلا الموظفون والمسؤولون المخولون بالقدر اللازم لتنفيذ مهامهم.

2. البيانات التي قد نعالجها

  • بيانات الحساب والملف الشخصي: الاسم، البريد الإلكتروني للعمل، رقم الهاتف، المسمى الوظيفي، القسم، اللغة، الصلاحيات وسجلات الدخول.
  • بيانات الدعم والخدمات: التذاكر والطلبات والردود والمرفقات والموافقات وسجل الحالات والإسناد وسجلات التدقيق.
  • بيانات حساب واتساب: معرف حساب واتساب للأعمال WABA، ومعرف رقم الهاتف، والرقم الظاهر، وبيانات الملف التجاري، والقوالب، وحالة الجودة والتحقق، واشتراك Webhook، وحالة الاتصال.
  • محادثات واتساب: معرفات المرسل والمستلم، ومحتوى الرسائل، والمرفقات، والتوقيتات، وحالات الإرسال والتسليم والقراءة، وفئة المحادثة، وإجراءات البوت أو الموظف.
  • بيانات الاستخدام والبيانات التقنية: عنوان IP، وبيانات المتصفح والجهاز، والجلسات والأحداث الأمنية، وسجلات الأخطاء، واستخدام الخصائص.
  • التحليلات ومراجع الفوترة: حجم الرسائل، وإحصاءات التسليم، وفئات المحادثات، والتكاليف التقديرية أو التي توفرها Meta، ومراجع حساب الفوترة، وحالة إعداد الدفع.
حماية بيانات البطاقة: لا يطلب النظام ولا يخزن رقم بطاقة الدفع الكامل أو تاريخ الانتهاء أو رمز CVV. وعند إتاحة إعداد الدفع، تتم العملية داخل صفحات Meta الآمنة، ولا يحتفظ النظام إلا بحالة محدودة أو مرجع مرتبط بعملية الإعداد.

3. أغراض استخدام البيانات

  • التحقق من المستخدمين وإدارة الأدوار والصلاحيات والتراخيص.
  • إنشاء تذاكر الدعم وطلبات الخدمات وتوجيهها وتتبعها ومعالجتها وإعداد التقارير عنها.
  • ربط وإدارة حسابات وأرقام وقوالب وWebhooks ورسائل واتساب للأعمال.
  • تشغيل ردود البوت والمحادثات مع الموظفين والإشعارات والقوالب المعتمدة.
  • عرض التقارير التشغيلية وإحصاءات التسليم والاستهلاك ومراجع الفوترة.
  • حماية النظام والتحقيق في الأخطاء أو إساءة الاستخدام وتطبيق الصلاحيات والاحتفاظ بسجلات التدقيق.
  • الالتزام بالأنظمة واللوائح والطلبات القانونية الصحيحة.

4. التكامل مع Meta وواتساب

عندما يربط مستخدم مخول حساب واتساب للأعمال، يتبادل النظام البيانات مع Meta Platforms وواتساب عبر الواجهات الرسمية وواجهات الربط المعتمدة. وتعالج Meta وواتساب البيانات وفق شروطهما وسياسات الخصوصية الخاصة بهما. ولا يستخدم النظام الصلاحيات التي تمنحها المؤسسة إلا لتقديم الخصائص الموضحة في هذه السياسة.

5. الأساس النظامي والتشغيلي

تتم معالجة البيانات بالقدر اللازم لتقديم الخدمات المطلوبة أو المتعاقد عليها، وتشغيل وظائف الدعم والاتصالات الداخلية، وحماية المصالح التشغيلية والأمنية المشروعة، والوفاء بالالتزامات النظامية، والحصول على الموافقة عندما تشترط الأنظمة المعمول بها ذلك.

6. مشاركة البيانات والإفصاح عنها

لا نبيع البيانات الشخصية. وقد تتم مشاركة البيانات فقط مع:

  • الموظفين والمسؤولين المخولين في باشن كلينك.
  • Meta وواتساب بالقدر اللازم لتقديم خدمات منصة واتساب للأعمال.
  • مزودي الاستضافة والبريد الإلكتروني والأمن والنسخ الاحتياطي والخدمات التقنية وفق التزامات مناسبة.
  • الجهات التنظيمية أو القضائية أو الأمنية عندما يكون الإفصاح مطلوبًا نظامًا.
  • جهة خلف قانونية في حالة إعادة هيكلة أو اندماج أو نقل مشروع بصورة مشروعة ومع تطبيق الضمانات اللازمة.

7. مدة الاحتفاظ

نحتفظ بالبيانات فقط للمدة اللازمة للأغراض الموضحة أعلاه، ولمتطلبات الاحتفاظ التي تعتمدها المؤسسة، والاحتياجات التشغيلية المشروعة، وتسوية النزاعات، والأمن، والالتزامات النظامية. تُحفظ بيانات الوصول إلى واتساب بصورة مشفرة ما دام التكامل فعالًا، وتُحذف أو تُلغى عند فصل الربط أو حذفه. وتُحذف البيانات غير اللازمة أو تُخفى هويتها أو تُؤرشف بصورة آمنة بحسب الحالة.

8. أمن البيانات

نطبق ضوابط إدارية وتقنية وتنظيمية معقولة، تشمل HTTPS، والصلاحيات المبنية على الأدوار، وتقييد وصول المسؤولين، وتشفير بيانات التكامل الحساسة، وسجلات التدقيق، والنسخ الاحتياطي والمراقبة. لا توجد وسيلة نقل أو تخزين خالية تمامًا من المخاطر، إلا أننا نعمل باستمرار على تقليل المخاطر المتوقعة.

9. ملفات الارتباط والجلسات

يستخدم النظام ملفات ارتباط أساسية لازمة لتسجيل الدخول وتفضيل اللغة وحماية CSRF والتشغيل الآمن. ولا تُستخدم هذه الملفات لبيع البيانات الشخصية أو إنشاء ملفات إعلانية لدى أطراف أخرى.

10. المعالجة خارج الدولة

قد يعالج بعض مزودي الخدمات، ومنهم Meta وواتساب ومزودو البنية التحتية، البيانات في دول أخرى. وعندما يكون ذلك مطلوبًا، يتم تطبيق الضمانات التعاقدية والتقنية والتنظيمية المناسبة وفق متطلبات حماية البيانات المعمول بها.

11. حقوقك وخياراتك

مع مراعاة الأنظمة ومتطلبات المؤسسة، يمكن طلب الوصول إلى البيانات أو تصحيحها أو تقييدها أو الاعتراض على معالجتها أو نقلها أو حذفها. وقد نطلب التحقق من الهوية قبل تنفيذ الطلب. ولطلب الحذف، اتبع صفحة تعليمات حذف البيانات.

12. البيانات الحساسة والأطفال

النظام مخصص لمستخدمي الأعمال المخولين، وليس موجهًا للأطفال. ينبغي عدم إرسال بيانات صحية أو مالية أو تعريفية أو حساسة لا حاجة لها عبر واتساب أو تذاكر الدعم. وإذا كانت البيانات الحساسة مطلوبة بصورة مشروعة، فيجب التعامل معها وفق سياسات المؤسسة المعتمدة والأنظمة ذات الصلة.

13. تحديث السياسة

قد نقوم بتحديث هذه السياسة عند تغير النظام أو التكاملات أو المتطلبات النظامية. وستظل النسخة الحالية وتاريخ سريانها متاحين عبر هذه الصفحة.

14. التواصل

الجهة باشن كلينك
التواصل بشأن الخصوصية والدعم info@passionclinics.com