Privacy Policy
We respect the privacy of clinics and patients and use data only to provide, secure, and improve Tabbaba.
Effective date: 18 June 2026
1. Who we are and scope
Tabbaba provides clinic management, appointment booking, and WhatsApp communication automation. This policy explains how we handle data when you use our websites, products, and services.
The clinic is generally responsible for its patient data. Tabbaba processes that data on the clinic’s behalf to provide the service under its instructions.
2. Data we process
- Clinic and user account data, including names, contact details, roles, and permissions.
- Operational data entered by clinics, including appointments, patient records, prescriptions, invoices, and visit notes.
- WhatsApp data needed for booking, replies, and reminders, including phone numbers, WhatsApp Business identifiers, message content, timestamps, and delivery status.
- Technical and security data, including IP address, browser type, sign-in records, errors, and feature usage.
- Support and sales information you send through forms, email, or WhatsApp.
3. How we use data
- Provide clinic management, appointment booking, WhatsApp replies, and reminders.
- Operate accounts, access controls, support, billing, and service reliability.
- Secure the platform, prevent misuse, and investigate errors or security incidents.
- Meet applicable legal and regulatory requirements.
4. WhatsApp and Meta
When WhatsApp is connected, we process necessary data through Meta’s WhatsApp Business Platform. Meta’s own terms and policies also apply. We do not sell patient message content or use it for advertising.
Clinics remain responsible for obtaining appropriate patient consent and using templates and messages in accordance with WhatsApp policies and applicable law.
5. Data sharing
We do not sell personal data. We may share the minimum necessary data with hosting and infrastructure providers, Meta, and support or payment providers that help us operate the service, or with authorities when required by law. Service providers must protect the data and use it only for the defined purpose.
6. Retention and deletion
We retain data while an account is active and as needed to provide the service and meet legal or contractual duties. After account closure or approval of a valid deletion request, we delete or de-identify data from active systems; backup copies expire under our secure retention cycle.
To request access, correction, export, or deletion, contact us at the address below and identify the clinic and associated account or phone number. We may verify identity and authority before acting on a request.
7. Security and your rights
We use access controls, encryption, secure connections, backups, and log monitoring to protect data. No electronic method is completely secure, so we continually review our safeguards.
Depending on applicable law, you may request a copy, correction, deletion, or restriction of certain processing. If you are a patient, we may direct your request to the clinic responsible for your record.
8. Updates
We may update this policy when the service or legal requirements change. We will publish the new version here and revise the effective date.