Last updated: 8 October 2026
العربية · The Arabic version governs.
shoghlak helps mental-health clinics and independent practitioners manage bookings and client communication over WhatsApp, using an automated assistant called Sanad.
Operator: AI Automation Systems, a sole proprietorship registered in Egypt.
Contact: info@shoghlak.com
We collect: client name and mobile number; appointment, reschedule and cancellation records; the text of WhatsApp messages between the client and the clinic, in both directions, including messages from the automated assistant; free-text notes written by the practitioner about the client; system-generated alerts, including urgent-case alerts, which contain the text of the client's message; additional client details where recorded (age, gender, email, guardian name and number, the client's WhatsApp profile name, and message delivery status); practitioner login data (email, IP address, country and device fingerprint) and technical request logs; team WhatsApp numbers and account photos where provided.
We use it to: process bookings, reschedules and cancellations and send confirmations and reminders; run the Sanad assistant so it can reply to the client and complete a booking; notify the practitioner of bookings, changes and urgent cases; create online-meeting links when the practitioner chooses that; operate, debug and improve the service.
Data reaches the following processors, each for a stated purpose: Meta (WhatsApp) for sending and receiving messages; an AI model provider for generating the assistant's replies, including the in-app Siraj assistant (which sends the practitioner's question and app data within that practitioner's permissions: client names, status, notes and appointments); Google Calendar and Zoom, where the practitioner has connected them; Google for sign-in, where chosen; and hosting, database and email providers to operate the service.
Important: the text of client messages is sent to an AI model provider so the assistant can reply, and that provider may retain the text under its own terms.
Data is stored on cloud services outside Egypt. Technical logs on a server we rent also contain request data, including message text, and there is currently no set period after which these logs are deleted.
Conversations remain available to the clinic with no set time limit. There is currently no automatic deletion of data. Deletion requests reach us at info@shoghlak.com, and we handle them manually. Appointment records are kept permanently as a service record.
The owner can view all conversations, client records and alerts, including urgent-case alerts. A practitioner sees only their own clients (those with an appointment with them) and those clients' alerts; when booking for a new client who has no appointment with anyone, they see the client's name and the last 3 digits of the mobile number. Reception staff see client records, appointments and routine alerts, but not urgent-case alerts, and see conversations until the owner turns that off. The service operator can access data for operation, support and debugging. The shoghlak technical team can see patients' conversations with Sanad for support and troubleshooting, and this access is not currently logged automatically. We do not sell, rent or share data for marketing purposes.
If the patient's message contains words indicating a danger to themselves or to others, the system:
The app does not delete a client's data: it archives the client only (hidden from lists, with the data retained). A client wanting access to or deletion of their data can contact the clinic or us at info@shoghlak.com. There is no button in the app that exports or deletes data; such requests are handled manually. We may retain data where there is a legal basis or a dispute. In the same way, a client can request correction of inaccurate data, object to a specific use of their data, request data portability to another party, or withdraw consent previously given for a given processing activity, by contacting the clinic or us at info@shoghlak.com. Correcting data is done by the owner or reception staff inside the app. The app has no data export and does not record client consent, so these requests are handled manually.
Users' connections to the app and website are encrypted in transit (TLS). Google Calendar and Zoom connection tokens are encrypted with a dedicated key. App sign-in uses an emailed one-time code or a Google account; we store no passwords. We monitor incidents and app sign-ins. Our team's access to client data is not logged automatically, as stated above.
If this policy changes we update the date above. Questions: info@shoghlak.com