آخر تحديث: ١٤ آب ٢٠٢٦ · النسخة 2026-08-14.1 · Last updated: 14 August 2026 · version 2026-08-14.1
عربيسياسة الخصوصية
١. نظرة عامة
"سنّك" ("المنصّة") هي منصّة إدارة عيادات أسنان، وتضمّ ثلاث واجهات: مساحة عمل الطاقم الطبي، بوابة مريض بلا كلمة مرور، وموقعًا إلكترونيًا عامًا لكل عيادة. توضّح هذه السياسة البيانات التي تتعامل معها المنصّة عبر الواجهات الثلاث وكيفية حمايتها، سواء كان القارئ عضو طاقم في عيادة، مريضًا لدى عيادة تستخدم سنّك، أو زائرًا لموقع عيادة إلكتروني.
٢. من يتحكّم بالبيانات
كل عيادة أسنان ("العيادة") هي المتحكّم بالبيانات الخاصة بمرضاها — العيادة هي من يقرّر ما يُسجَّل ومن يطّلع عليه ضمن طاقمها. سنّك هي المنصّة التقنية التي تستخدمها العيادة لتخزين تلك البيانات وإدارتها بأمان.
٣. البيانات التي نخزّنها
- حسابات الطاقم: الاسم، البريد الإلكتروني، الدور (طبيب/استقبال)، بيانات الدخول.
- حسابات المرضى: الاسم، رقم الهاتف، واسم مستخدم تصدره العيادة — يُستخدم فقط للدخول إلى بوابة المريض (بلا كلمة مرور على هذه الواجهة إطلاقًا).
- السجلّ السريري: خطط العلاج، تاريخ الزيارات، الوصفات والإرشادات السريرية، وملاحظات العيادة حول الحالة.
- الصور والملفّات: الصور والفحوصات والملفّات التي ترفعها العيادة إلى ملفّ المريض.
- بيانات الحجز: طلبات المواعيد، الحجوزات المؤكَّدة، والطبيب المعيَّن.
- الرسائل: محادثات بين المريض وعيادته المعالِجة.
- الإشعارات: رمز جهاز (device token) عند تفعيل التذكيرات/التنبيهات على أحد الأجهزة — قابل للإزالة في أي وقت.
- استفسارات الموقع العام: عند استخدام نموذج تواصل أو حجز على موقع عيادة، تُخزَّن التفاصيل المُرسَلة لتتمكّن العيادة من الرد.
- سجلّ الموافقة: عند أول دخول إلى مساحة العمل أو بوابة المريض، وعند إرسال طلب حجز عام، نسجّل موافقتك على شروط الاستخدام وسياسة الخصوصية (نسخة السياسة ووقت الموافقة) — سجلّ إثبات لا يُعدَّل.
- بيانات تقنية أساسية لتشغيل الخدمة بأمان (تسجيل الدخول ومعلومات الجهاز الضرورية).
٤. أين تُخزَّن البيانات، ومن يستطيع الاطّلاع عليها
تُخزَّن السجلّات المُهيكَلة في قاعدة بيانات تفرض عزلًا كاملًا بين العيادات على مستوى قاعدة البيانات نفسها (سياسات أمان على مستوى الصفّ): لا يمكن لعيادة الاستعلام إلا عن صفوف مرضاها — الوصول عبر العيادات مستحيل بنيويًا، لا مجرّد قيد في الواجهة.
تُخزَّن الصور والملفّات في مخزن سحابي خاص. لا تُتاح هذه الملفّات عبر رابط عام مباشر أبدًا — يجلبها التطبيق فقط عبر روابط موقَّعة قصيرة الصلاحية أو اتصال خاص من نفس المصدر، تُنشأ من جديد في كل مرّة تُعرَض فيها.
ضمن العيادة الواحدة، لا يطّلع على سجلّ المريض إلا مقاعد الطاقم المخوَّلة في تلك العيادة — لا طاقم عيادة أخرى، ولا الجمهور.
٥. وصول مشغِّل المنصّة
لا يطّلع فريق تشغيل سنّك على بيانات العيادات بشكل اعتيادي. هناك هوية واحدة مسمّاة لمسؤول المنصّة يمكنها الدخول إلى مساحة عمل عيادة لأغراض الدعم الفني فقط؛ يُسجَّل كل دخول من هذا النوع (من، متى، أي عيادة) في سجلّ تدقيق دائم، وأي سجلّ يُنشأ أو يُعدَّل أثناء تلك الجلسة يُختم بأنه تمّ "نيابة عن" جلسة الدعم تلك. هذه الصلاحية غير قابلة للمنح لأي حساب آخر.
٦. هوية المريض بلا كلمة مرور
لا يضع المرضى ولا نخزّن لهم كلمة مرور. يتمّ الدخول إلى بوابة المريض باسم المستخدم الذي أصدرته العيادة مع رقم الهاتف المستخدَم عند الحجز؛ ويمكن للعيادة إعادة إصدار اسم المستخدم عند فقدانه.
٧. تصدير واستيراد بيانات العيادة
يمكن للعيادة تصدير نسخة كاملة أو جزئية من سجلّاتها الخاصة (المرضى، الزيارات، الصور، المحادثات، الوصفات) كأرشيف واحد قابل للنقل، واستيراد أرشيف كهذا لاحقًا. هذه العملية مقتصرة دائمًا على العيادة نفسها — لا يمكن لعيادة تصدير أو استيراد بيانات عيادة أخرى إطلاقًا.
٨. الإشعارات ورموز الأجهزة
عند تفعيل الإشعارات، يُخزَّن رمز جهاز يحدّد ذلك المتصفّح/الجهاز لإرسال تذكيرات المواعيد والرسائل العاجلة إليه. يمكن تعطيل الإشعارات في أي وقت من الإعدادات، ما يزيل الرمز. لا تُشارَك هذه الرموز مع أي معلن أو طرف ثالث.
٩. لا نبيع بياناتك ولا نعرض إعلانات
لا نبيع أو نؤجّر أو نتاجر بأي بيانات شخصية مع أي جهة، ولا تحمل سنّك أي إعلانات أو تتبّع إعلاني من أي نوع. تُستخدم البيانات فقط لتشغيل ملفّ المريض والمنصّة نفسها.
١٠. المدفوعات والفوترة
يُشترَك بسنّك بسعر واحد معلن على الموقع لكل خطة، بلا خصومات أو مفاوضات لأي عيادة — شهريًا أو سنويًا (السنوي بسعر عشرة أشهر مقابل اثني عشر). لا نجمع ولا نخزّن أي بيانات بطاقة دفع على خوادمنا؛ تُعالَج المدفوعات عبر مزوّد دفع متخصّص ومتوافق مع معايير أمان البطاقات، خارج التطبيق تمامًا.
١١. مدّة الاحتفاظ بالبيانات والاسترجاع بعد الإلغاء
عند إلغاء العيادة اشتراكها: يتحوّل حسابها فورًا للقراءة فقط (بلا تعديل)، ويمكنها تصدير أرشيف كامل من بياناتها في أي وقت، ونحتفظ بنسخة قابلة للاسترجاع الكامل لمدة ٦ أشهر لخطتي Solo أو Standard أو ١٢ شهرًا لخطة Premium — نفس هذا الرقم يحدّد أيضًا أقصى مدى يمكن لعيادة نشطة الاسترجاع إليه من نسخها الاحتياطية. بعد انتهاء هذه المدة تُزال بيانات العيادة نهائيًا من أنظمتنا. هذا الوعد التجاري مستقلّ تمامًا عن حذف حساب دخول فردي (طبيب أو مريض واحد)، الموضّح في الفقرة التالية — ذاك يخصّ هوية شخص واحد ومدّته ٣٠ يومًا فقط.
تتحكّم العيادة أيضًا بمدّة الاحتفاظ ببياناتها أثناء الاشتراك النشط. يمكن للعيادة أرشفة (حذف ناعم) السجلّات التي لم تعد بحاجتها؛ وتبقى السجلّات المؤرشَفة قابلة للاسترجاع من قِبل العيادة لفترة قبل الإزالة النهائية. لا تفرض المنصّة حذفًا تلقائيًا شاملًا للسجلّات السريرية — هذا القرار يعود للعيادة المسؤولة عنها.
عند طلب حذف حساب فردي (انظر البند ١٤) — وهو إجراء مختلف تمامًا عن إلغاء اشتراك العيادة أعلاه: يُعطَّل ذلك الحساب فورًا ويُمنَع الدخول به، وتُزال بيانات هويته ودخوله (حساب الدخول ورموز الإشعارات الخاصة به فقط) خلال ٣٠ يومًا. أما السجلّات السريرية فلا تُحذَف فورًا أبدًا — فهي سجلّ طبي تحتفظ به العيادة المسؤولة للمدّة التي يفرضها القانون والممارسة الطبية (خمس سنوات افتراضيًا أو أكثر إذا ألزم القانون)، ثم تخضع للمراجعة والإزالة. هذا التدرّج مقصود: الحذف الفوري لسجلّ طبي قد يضرّ بسلامة المريض وبالالتزامات القانونية للعيادة.
١٢. القاصرون
بعض المرضى قاصرون. تُنشأ حسابات بوابتهم وسجلّاتهم وتُدار من قِبل العيادة المعالِجة وفق ممارسات الموافقة الخاصة بها مع وليّ الأمر؛ وتبقى العيادة الجهة المسؤولة عن تلك الموافقة.
١٣. الأمان
كل الاتصالات مشفَّرة أثناء النقل. يُفرَض الوصول إلى البيانات السريرية على مستوى قاعدة البيانات لكل طلب، لا في واجهة التطبيق فقط. لا يُشحَن أي مفتاح أو بيانات اعتماد سرّية داخل التطبيق الذي يُنزَّل أو يُشغَّل في المتصفّح.
يُشتَقّ نطاق العيادة من هوية صاحب الطلب على الخادم في كل مرّة، ولا يُقبَل معرّف عيادة قادم من المتصفّح؛ فبيانات كل عيادة معزولة عن غيرها على مستويين: التدقيق في كل استعلام، وسياسات قاعدة البيانات كخطّ دفاع ثانٍ.
يمكن لأي مستخدم إنهاء جلساته على كل الأجهزة من إعدادات حسابه. وعند تعطيل حساب — بطلب منك أو من العيادة — تُغلَق جلساته على جميع الأجهزة فورًا، لا على الجهاز الذي قدّم الطلب وحده.
١٤. الحقوق
للوصول إلى المعلومات أو تصحيحها أو طلب حذفها، يُرجى التواصل مباشرة مع العيادة المعنية — فهي من يحتفظ بالسجلّ ويمكنها تنفيذ الطلب. يمكن أيضًا التواصل مع سنّك عبر نموذج التواصل على sennak.com، وسنُحيل الطلب إلى العيادة المناسبة أو نجيب مباشرة عن الأسئلة المتعلّقة بالمنصّة نفسها.
حذف الحساب — طلبٌ يُنفَّذ، لا زرّ يمحو: يبدأ الحذف بطلب، والعيادة التي تحتفظ بالسجلّ هي من ينفّذه.
- إن كنت تستطيع الدخول: من الإعدادات (للطاقم) أو من بوابة المريض. يُسجَّل طلبك، ويُعطَّل حسابك فورًا وتُغلَق جلساتك على كل الأجهزة، وتُخطَر العيادة لتتولّى الباقي.
- إن كنت لا تستطيع الدخول: استخدم صفحة الطلب العامة على sennak.com/legal/delete-account، وتُحال إلى العيادة المعنية.
- في الحالتين: التعطيل فوري، أمّا إزالة السجلّات فتخضع للتدرّج ومدد الاحتفاظ الموضّحة في البند ١١، ولالتزامات العيادة المهنية والقانونية تجاه السجلّ الطبّي.
لا يحذف تعطيلُ الحساب سجلّك السريري لدى العيادة، ولا يُلغي حجوزات أو فواتير قائمة؛ هذه أمور تُسوّى مع العيادة نفسها.
١٥. مزوّدو الخدمة من الباطن ونقل البيانات
نستعين بعدد محدود من مزوّدي البنية التحتية لتشغيل المنصّة، ولا يتجاوز دور أي منهم المعالجة التقنية اللازمة للخدمة:
- Cloudflare — الاستضافة وشبكة التوصيل والتخزين الخاص للملفّات والحماية من إساءة الاستخدام (بما فيها التحقّق من الروبوتات).
- Supabase — استضافة قاعدة البيانات ونظام تسجيل الدخول.
- Google / Firebase — إيصال الإشعارات إلى الأجهزة فقط (تمرّ عبره رموز الأجهزة، لا السجلّات السريرية).
- Dun & Bradstreet — التحقّق من هوية المنشأة التجارية للمشغّل فقط (إجراء متاجر التطبيقات) — لا يصل إليه أي بيان عن عيادة أو مريض إطلاقًا.
قد تُخزَّن البيانات أو تُعالَج على بنية هؤلاء المزوّدين التحتية خارج العراق. يخضع كل مزوّد لشروط معالجة بيانات خاصة به، وتبقى الضمانات الموصوفة أعلاه (العزل على مستوى قاعدة البيانات، التخزين الخاص، الروابط قصيرة الصلاحية) سارية أينما جرت المعالجة. لا نبيع البيانات ولا نشاركها مع أي جهة أخرى.
١٦. التعديلات على هذه السياسة
سيُنشَر أي تعديل جوهري على هذه الصفحة مع تاريخ تحديث جديد أدناه. استمرار استخدام سنّك بعد أي تعديل يعني قبول النسخة المُحدَّثة.
١٧. التواصل معنا
سنّك — عبر نموذج التواصل على sennak.com.
EnglishPrivacy Policy
1. Overview
"Sennak" ("we", "us", "the platform") is a clinic-management platform for dental clinics, comprising a staff workspace, a passwordless patient portal, and each clinic’s own public website. This policy explains what data we handle across all three surfaces and how it is protected — whether you are a clinic staff member, a patient of a clinic that uses Sennak, or a visitor to a clinic’s public website.
2. Who controls your data
Each dental clinic ("clinic") is the data controller for the information of its own patients — the clinic decides what to record and who on its team can see it. Sennak is the technology platform the clinic uses to store and manage that information securely.
3. Information we store
- Staff accounts: name, email, role (dentist / receptionist), sign-in credentials.
- Patient accounts: name, phone number, and a clinic-issued username — used only to sign in to the patient portal (passwordless: no password exists for this surface).
- Clinical records: treatment plans, visit history, prescriptions and clinical advice, and notes the clinic records about your care.
- Photos & media: dental photos, scans, and files the clinic uploads to your file.
- Booking data: appointment requests, confirmed bookings, and the assigned dentist.
- Messages: chat messages between a patient and their treating clinic.
- Notifications: a device token, only if you enable reminders/alerts on a device — removable at any time.
- Public-site inquiries: details submitted through a contact or booking form on a clinic’s public website, so the clinic can respond.
- Consent records: on first sign-in to the workspace or patient portal, and when a public booking is submitted, we record your acceptance of the Terms of Use and this Privacy Policy (the policy version and time of consent) — an append-only evidence record.
- Basic technical data needed to operate the service securely (sign-in and device information).
4. Where your data lives, and who can see it
Structured records live in our database, which enforces per-clinic isolation at the database layer itself (row-level security): a clinic can only ever query its own patients’ rows — cross-clinic access is a database-level impossibility, not merely a UI restriction.
Photos and files live in a private cloud-storage bucket. They are never reachable by a direct public link — the app fetches them only through short-lived signed links or a private same-origin connection, generated fresh each time they are viewed.
Within a clinic, only that clinic’s authorized staff seats can see a patient’s records — never another clinic’s staff, and never the public.
5. Platform-operator access
Sennak’s own operating team does not browse clinic data as a matter of course. A single, named platform-administrator identity can enter a clinic’s workspace for support purposes; every such session is logged (who, when, which clinic) in a permanent audit trail, and any record created or changed during it is stamped as made "on behalf of" that support session. This capability cannot be granted to any other account.
6. Passwordless patient identity
Patients do not set or store a password with us. Sign-in to the patient portal uses the username your clinic issued you plus the phone number you booked with; your clinic can re-issue your username if you lose it.
7. Exporting & importing a clinic’s data
A clinic can export a full or partial copy of its own records (patients, visits, photos, chats, prescriptions) as a single portable archive, and import an archive back in. This operation is always scoped to that one clinic — a clinic can only ever export or import its own data, never another clinic’s.
8. Notifications & push tokens
If notifications are turned on, we store a device token identifying that browser/device so we can deliver appointment reminders and urgent messages to it. Notifications can be disabled at any time from Settings, which removes the token. Tokens are never shared with advertisers or other third parties.
9. We do not sell data or run ads
We do not sell, rent, or trade personal information to anyone, and Sennak carries no advertising or ad-tracking of any kind. Information is used solely to operate the clinic’s file for you and the platform itself.
10. Payments & billing
Sennak is offered at one published price per plan, printed on our pricing page, with no discounts or negotiation for any clinic — billed monthly or yearly (yearly is priced at ten months for twelve). We do not collect or store any payment-card information on our own servers; payments are handled by a dedicated, card-industry-compliant payment processor, entirely outside the app.
11. Data retention & restore after cancellation
When a clinic cancels its subscription: its workspace becomes read-only immediately (no edits), it can export a complete archive of its data at any time, and we keep a fully restorable copy for 6 months on the Solo or Standard plan or 12 months on the Premium plan — the same number also caps how far back an active clinic can restore from its own backups. After that window, the clinic's data is permanently removed from our systems. This commercial promise is entirely separate from deleting one individual's sign-in account (staff or patient), described in the next paragraph — that concerns one person's identity only, and runs on a 30-day window.
The clinic also controls retention of its own data during an active subscription. A clinic may archive (soft-delete) records it no longer needs; archived records remain recoverable by the clinic for a period before permanent removal. We do not impose a platform-wide auto-delete on clinical records — that decision belongs to the clinic responsible for them.
When an individual account deletion is requested (see §14) — a different action from the clinic-level cancellation above: that one account is deactivated immediately and sign-in is blocked, and its identity/login data (the sign-in account and its own push tokens only) is removed within 30 days. Clinical records are never hard-deleted on the spot — they are a medical record the responsible clinic retains for as long as law and medical practice require (five years by default, or longer where the law demands), after which they are reviewed for purging. This staging is deliberate: instantly erasing a medical record can harm patient safety and the clinic’s legal obligations.
12. Minors
Some patients are minors. Their portal accounts and records are created and managed by the treating clinic under the clinic’s own consent practices with the patient’s guardian; the clinic remains the responsible party for that consent.
13. Security
All traffic is encrypted in transit. Access to clinical data is enforced at the database layer for every request, not only in the app’s interface. No credential or private key is ever shipped inside the app you download or run in your browser.
Which clinic a request may read is re-derived from the requester’s own identity on the server every time; a clinic identifier supplied by a browser is never trusted. Each clinic’s data is isolated on two levels: an explicit scope on every query, and database policies behind it as a second line of defence.
Any user can end their sessions on every device from their own account settings. When an account is deactivated — at your request or the clinic’s — its sessions end everywhere immediately, not only on the device that asked.
14. Your rights
To access, correct, or request deletion of your information, contact your clinic directly — they hold your records and can act on your request. You may also reach Sennak through the contact form at sennak.com, and we will route your request to the right clinic or answer platform-level questions directly.
Account deletion is a request that gets carried out, not a button that erases: it starts with a request, and the clinic that holds the record is who acts on it.
- If you can sign in: from Settings (staff) or from the patient portal. Your request is recorded, your account is deactivated immediately and your sessions end on every device, and the clinic is notified to handle the rest.
- If you cannot sign in: use the public request page at sennak.com/legal/delete-account, which routes your request to the right clinic.
- Either way: deactivation is immediate; removal of records follows the staged process and retention windows described in §11, and the clinic’s own professional and legal obligations toward the medical record.
Deactivating an account does not delete your clinical record at the clinic, and does not cancel outstanding appointments or invoices — those are settled with the clinic itself.
15. Sub-processors & data transfer
We rely on a small set of infrastructure providers to run the platform; none of them plays any role beyond the technical processing the service needs:
- Cloudflare — hosting, content delivery, the private media storage bucket, and abuse protection (including bot verification).
- Supabase — database and sign-in (authentication) hosting.
- Google / Firebase — push-notification delivery to devices only (device tokens transit it; clinical records never do).
- Dun & Bradstreet — business-identity verification of the platform operator only (an app-store requirement) — no clinic or patient data ever reaches it.
Data may be stored or processed on these providers’ infrastructure outside Iraq. Each provider is bound by its own data-processing terms, and the safeguards described above (database-level isolation, private storage, short-lived signed access) apply wherever the processing happens. We do not sell data, and we share it with no one else.
16. Changes to this policy
We will post any material change to this page with an updated date below. Continued use of Sennak after a change means acceptance of the revised policy.
17. Contact us
Sennak — via the contact form at sennak.com.