Privacy Policy
Last updated:
This Privacy Policy explains how Xtudio handles personal information when you use our clinic management platform, its web panels, the patient portal and the staff mobile application (together, the “Service”), and when you visit x-tudio.com. We comply with the Egyptian Personal Data Protection Law No. 151 of 2020 (“PDPL”) and draw on internationally recognised principles, including those reflected in the EU GDPR.
Two roles you should understand. Xtudio is the data controller for the small set of information we receive directly to run the Service and this website: staff account credentials, subscription and billing details, website analytics and demo requests. For the far larger set of information a clinic records about its patients and staff — medical history, treatment plans, consent forms, photos, appointments, invoices, payroll — the clinic is the data controller and Xtudio acts as its data processor. The clinic decides what is recorded, who may see it and how long it is kept; Xtudio stores and processes it only on the clinic’s instructions.
1. Who we are
Xtudio is a clinic management platform for laser, dermatology and beauty clinics in Egypt and the Middle East. It brings patient records, scheduling, billing and accounting, inventory, staff and payroll, marketing and reporting together in one system. For any privacy-related question, contact us at privacy@x-tudio.com.
2. Information we receive directly
From clinic staff (when a clinic creates accounts for its team)
- Account credentials: name, email address, phone number, hashed password, optional two-factor authentication secret.
- Profile basics: avatar, role, branch, language preference.
From the subscribing clinic (for billing)
- Clinic name, billing contact, tax registration number, addresses of branches.
- Subscription package, billing cycle and payment method tokens. We do not store full card numbers; payment data is tokenised by our payment processor.
From patients who use the patient portal
- Login credentials for the portal (phone number or email and a password), language preference and the bookings, invoices and loyalty information you view there. The clinical content shown in the portal belongs to the clinic’s record (section 3).
From the staff mobile app
- Device push token (Firebase Cloud Messaging), device model, OS version, app version, IP address, timezone.
- Geolocation captured at attendance check-in and check-out only if the clinic has enabled geofenced attendance.
- Biometric authentication result (pass/fail only) if you enable fingerprint or Face ID app unlock; the biometric template never leaves your device’s secure hardware.
From visitors to x-tudio.com
- Demo requests: clinic name, your name, email, phone number, country and message, submitted through the contact form and protected by Google reCAPTCHA.
- Analytics and server logs as described in section 11.
Automatically (security and operations)
- Server logs — IP address, user agent, request paths, timestamps — used for security, abuse prevention and debugging.
- An audit log of significant actions inside a clinic’s workspace (creations, updates, deletions, exports).
3. Patient and staff data recorded by clinics
The Service is a platform that clinics use to run their practice. A clinic records information in Xtudio about its patients — identity and contact details, date of birth, medical history, treatment plans and sessions, prescriptions, consent forms, before-and-after photographs, appointments, invoices and payments, and communication preferences — and about its staff, such as schedules, attendance, payroll and commissions. Xtudio does not collect this information itself; it is entered or generated by the clinic in the course of using the Service, and Xtudio processes it strictly on the clinic’s behalf as a data processor.
Health information, photographs and identification documents are sensitive personal data under PDPL. Xtudio applies technical and contractual measures appropriate to that classification: isolated storage per clinic, encryption, role-based access and audit logging (section 7). The clinic, as controller, is responsible for obtaining the patient’s consent and for the lawful basis of its processing; Xtudio provides the consent templates, e-signature and consent flags the clinic uses to record it.
If you are a patient, your clinic is the controller of your record. Questions about what is stored about you, who can see it and how long it is kept should be directed to the clinic. We support clinics in responding, and if you cannot reach your clinic you may contact us directly (section 8).
4. Why we process this information
- Performance of contract: to deliver the features the clinic subscribed to, including the patient portal and the staff app.
- Legal obligation: issuing tax invoices for subscriptions and supporting the clinic’s own obligations under Egyptian tax, labour and social-insurance law.
- Consent: for demo-request follow-ups, product newsletters, and for any patient messaging a clinic sends on WhatsApp, SMS or email, which the patient can withdraw at any time.
- Legitimate interest: security monitoring, fraud prevention and product improvement using aggregated, non-identifying data.
5. How long we keep information
- Clinic-recorded patient and staff data: retained while the clinic’s subscription is active and for the period the clinic’s legal and medical-practice obligations require. The clinic controls correction and deletion through Xtudio. When a subscription ends, the clinic can export its data; we delete it after the agreed hand-over period.
- Staff and portal accounts: personal data (name, email, phone, profile) is purged within 30 days of account deletion. Account identifiers are retained for up to 90 days for audit and dispute resolution, then deleted.
- Demo requests: kept for 12 months from the last contact, then deleted unless a subscription follows.
- Mobile push tokens and notification preferences: removed immediately on account deletion or device unregistration.
- Server logs: 90 days, except where a longer period is necessary for an open security incident.
- Backups: encrypted backups are kept on a rolling schedule and expire automatically; deleted data disappears from backups as they rotate.
6. Who we share information with
Xtudio does not sell personal data and does not use patient data for advertising. We share data only with vetted processors that help us deliver the Service, and only to the extent necessary:
- Cloud hosting and content delivery — hosts the application, the clinic databases and encrypted backups, and protects the site at the network edge.
- Messaging — Meta’s WhatsApp Business Platform, Messenger and Instagram, when a clinic connects its own accounts (sections 12 and 13); SMS providers for one-time codes and reminders where enabled.
- Push notifications — Google Firebase Cloud Messaging for the mobile app.
- Transactional email — for account emails such as password resets and alerts.
- Payment processing — for Xtudio subscription billing, and, where a clinic enables online patient payments, the payment provider it chooses. No medical data is sent to payment processors.
- Website analytics and anti-abuse — Google Analytics and reCAPTCHA on x-tudio.com only.
Some of these processors operate outside Egypt. Data transferred internationally is encrypted in transit and protected by contractual safeguards recognised under PDPL Article 12. Clinic databases and patient records are hosted in the region we specify in the subscription agreement.
7. How we keep information safe
- Encryption in transit (TLS 1.2+) and at rest for databases and backups; patient photographs are encrypted at rest.
- Isolation per clinic: each clinic’s data lives in its own separate PostgreSQL schema; no clinic can read another’s records.
- Role-based access control with granular permissions, including masking of patient phone numbers for roles that do not need them, and optional two-factor authentication.
- Rate limiting and brute-force protection on authentication endpoints; per-user logins so every action is attributable.
- Audit logging of sensitive actions and exports; security review of new releases; strict security headers on all responses.
In the event of a personal data breach, Xtudio will notify the Personal Data Protection Centre and the affected clinic without undue delay in accordance with PDPL, and support the clinic in notifying affected patients where required. To report a suspected security issue, contact security@x-tudio.com.
8. Your rights
Under PDPL and equivalent regimes you have rights of access, correction, deletion, restriction, portability, objection and withdrawal of consent.
If you are a patient, requests about your clinical record should go to your clinic (the controller), which can act on them directly in Xtudio. Requests that concern Xtudio directly — for example deleting a portal or mobile-app account, or a demo request you sent us — can be sent to privacy@x-tudio.com. If you cannot reach your clinic, contact us and we will assist. We respond within 30 days and may ask you to verify your identity first.
9. Account deletion
Staff can delete their Xtudio mobile-app account from Settings → Account → Delete account; patients can request portal account deletion from their clinic or from us. On confirmation:
- All active sessions and access tokens are revoked across every device.
- The account is marked as deleted and can no longer authenticate.
- Mobile push tokens and notification preferences are removed immediately.
- Personal data (name, email address, phone number, profile) is permanently purged within 30 days. Account identifiers may be retained for up to 90 days solely for audit and dispute resolution, after which they are deleted.
- Clinical and employment records held by the clinic (treatment history, invoices, attendance, payroll) are retained by the clinic, which is the data controller and is bound by medical-practice, tax and labour retention rules.
No app access? Email privacy@x-tudio.com and we will process the request manually.
10. Children’s data
Xtudio accounts are not directed at children under 18. Clinics may record treatment of minors in a patient record with the consent of a parent or guardian, which the clinic is responsible for obtaining. If you believe a minor has registered an account, contact us and we will remove it.
11. Cookies & analytics
We use essential cookies (sign-in sessions, CSRF protection, language preference) across the platform, and your browser’s local storage to remember the light or dark theme. On our public marketing site (x-tudio.com) we also use Google Analytics to understand how visitors find and use the site; this sets Google cookies and shares usage data such as pages visited, device type and approximate location with Google. We do not use analytics inside the clinic panels, the portal or the app, and analytics data is never linked to patient records. You can block analytics cookies in your browser or via Google’s opt-out tools without affecting the site; blocking essential cookies may break sign-in.
12. Facebook Messenger & Instagram Direct messaging
Some Xtudio clinics connect their official Facebook Page and Instagram Business account so their reception staff can reply to patient messages from a single inbox, alongside WhatsApp. When you message one of these connected accounts, the clinic operating that account is the data controller for the conversation and Xtudio acts as a data processor, storing and displaying the messages on the clinic’s behalf. Our processing is consistent with Meta’s Platform Terms, Developer Policies, Messenger Platform Policy and Instagram Messaging API Policy.
What we receive from Meta and store when you message a connected account:
- A platform identifier — a Page-Scoped User ID (PSID) for Messenger or an Instagram-Scoped User ID (IGSID). These are specific to the account you messaged and cannot be used to identify you on other Pages or apps.
- Your public profile basics — the display name, username (Instagram only) and profile picture associated with your Facebook or Instagram account. We cache a copy of the profile picture so the staff inbox continues to display it after Meta’s temporary image link expires.
- Message content — the text, images, audio, video and files you send, together with timestamps, delivery and read receipts, reactions and button or quick-reply selections.
- Messaging-window timing — we log when your last message arrived so staff replies stay within Meta’s 24-hour standard messaging window, as required by Meta’s Platform Policy.
12.1 Instagram-specific data
When you contact a connected Instagram Business account, we additionally receive and store the following Instagram-specific items so the inbox can render the conversation faithfully:
- Story mentions — if you @-mention the connected account in your Instagram Story, the mention event (with a temporary media URL) is delivered to us so staff can see and reply. We do not download or persist the Story media beyond the link Meta gives us.
- Shared posts and Reels — when you share a Reel or post into the DM thread, we store the Meta-supplied reference (post ID and caption excerpt) so staff can see what you sent.
- Message reactions — emoji reactions you add to messages, anchored to the specific message ID they apply to.
- Read receipts — Instagram delivers a read receipt keyed to a specific message ID, and we mark only that message and earlier ones as read.
- Quick-reply selections — if you tap a quick-reply button, we receive its payload value (not the button title), used to route your reply inside the inbox.
Instagram conversations are stored under your Instagram-Scoped User ID (IGSID), which is unique to the account you contacted; it does not identify you on any other Page, app or Instagram account.
Automated replies. If a connected account is configured to send any automated reply, you will be told at the start of the conversation that you are chatting with an automated assistant and that a human can take over, in compliance with Meta’s Messenger and Instagram automation-disclosure rules.
Retention. Messenger and Instagram conversation data follows the retention periods in section 5: personal data is purged within 30 days of a deletion request and identifiers are kept for up to 90 days for audit, after which they are deleted.
Deleting your messaging data. You can remove Xtudio’s access from your Facebook settings (Settings & privacy → Settings → Apps and Websites) or your Instagram settings (Settings → Apps and Websites → Active). Doing so triggers our Data Deletion Callback at https://x-tudio.com/api/meta/data-deletion, which permanently deletes the conversations linked to your PSID (Messenger) or IGSID (Instagram) across our systems and returns a confirmation code you can use to track the request. You can also email privacy@x-tudio.com to request deletion manually.
13. WhatsApp messaging
Many Xtudio clinics connect their own WhatsApp Business Account so their reception staff can message patients — appointment confirmations and reminders, invoice receipts, follow-ups and free-form replies — through the clinic’s own WhatsApp number. The clinic is the data controller for these conversations and Xtudio acts as a data processor.
What we store when you message, or are messaged by, a connected clinic on WhatsApp:
- Your phone number in international format, used as the WhatsApp address.
- Message content — the text, images, documents, audio, video, location and contact cards exchanged, plus any template variables filled in (for example your name and appointment date).
- Delivery and read status — sent, delivered, read or failed receipts per message.
- Messaging-window timing — we log when your last inbound message arrived so staff replies stay within WhatsApp’s 24-hour customer-service window; outside it, only Meta-approved message templates are sent, as required by the WhatsApp Business Policy.
Consent. Clinics send WhatsApp messages only to patients who have opted in (a per-patient WhatsApp consent flag, with a separate flag for marketing messages). You can withdraw consent at any time by replying to ask the clinic to stop or by contacting the clinic.
Automated replies. If a clinic configures an automated reply, you are told at the start of the conversation that you are chatting with automation and how to reach a human.
Retention. WhatsApp conversation data follows the retention periods in section 5: personal data is purged within 30 days of a deletion request and identifiers are kept up to 90 days for audit, then deleted.
Deleting your WhatsApp data. Because WhatsApp is not a Facebook-login product, WhatsApp deletion requests are handled directly: email privacy@x-tudio.com (or ask the clinic) and we permanently delete the conversations tied to your phone number. (The Meta Data Deletion Callback at https://x-tudio.com/api/meta/data-deletion covers Messenger and Instagram, which are Facebook-login based.)
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes are notified to active clinic administrators by email at least 14 days in advance, and the date at the top of this page reflects the latest version.
15. Contact
- Privacy questions: privacy@x-tudio.com
- Security disclosures: security@x-tudio.com
- Data-subject requests: your clinic, or privacy@x-tudio.com if you cannot reach it