Privacy Policy

Last updated: 16 June 2025

1. Who We Are
Dr Ahmed Serag, Consultant Andrologist & Digital Training Creator (“we, us, our”) operates the website drahmedserag.com and the associated learning platform Thrive Apprentice LMS.

2. What Personal Data We Collect
2.1 Information you give us
Account data: name, e-mail, password (hashed).
Purchase data: billing address, last 4 digits of card (via Stripe).
Medical intake forms: any health information you choose to submit when booking a consultation.

2.2 Information we collect automatically
– Usage statistics, device type, IP address (for fraud & analytics).
– Cookies (see Section 7).

2.3 Information from third parties
– Payment providers (Stripe, PayPal).
– E-mail marketing (FluentCRM) for tag / open-rate tracking.

3. Why We Process Your Data —and How Long We Keep It
1. To deliver your online courses and track your learning progress
Legal basis: performance of a contract (GDPR Art. 6 (1)(b)).
Retention: while your account remains active, plus an additional two years for audit and support purposes.

2. To arrange and manage medical-consultation bookings
Legal basis: performance of a contract (Art. 6 (1)(b)) and the provision of health care (special-category condition—Art. 9 (2)(h)).
Retention: ten years, in line with Egyptian Ministry of Health record-keeping rules for clinical documentation.
3. To send educational or promotional e-mail updates—only when you have opted in
Legal basis: your explicit consent (Art. 6 (1)(a)).
Retention: until you withdraw that consent; every e-mail includes an unsubscribe link, and you can also e-mail us at privacy@drahmedserag.com to opt out at any time.


4. Sharing & International Transfers
We host on a2hosting; e-mail is sent via Amazon SES (EU-West). Stripe may transfer data to the USA under Standard Contractual Clauses.


5. Your Rights
You can access, rectify, erase, restrict, port, or object to processing at any time. Send a request to privacy@drahmedserag.com. We respond within 30 days.

6. Security
Data is encrypted in transit (TLS 1.3). Database-at-rest encryption AES-256. Role-based access for clinic staff.

7. Cookies
We use functional cookies (_wp_lang_), analytics (Google Analytics 4 IP-anonymised), and marketing (Facebook Pixel). Manage preferences via the Cookie Banner at page bottom.

8. Children
The site is not intended for under-18s. We do not knowingly collect data from children.

9. Updates
We may amend this notice; the “Last updated” date will change. Material changes will be announced by e-mail.

10. Contact
Data Protection Officer
Dr Ahmed Serag Clinic, Cairo, Egypt
📧 privacy@drahmedserag.com