Effective date: [To be determined upon adoption]Last updated: [To be determined upon adoption]

Privacy Policy

This Privacy Policy explains how personal data is collected, processed, used, and protected when using the ZiyaraTech platform, in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (PDPL) and other applicable regulations.

1. Scope of This Policy

This Policy applies to the personal data processed through the Platform in relation to clients, users, patients, and other data subjects connected to the services provided through the Platform.

2. Data We Collect and Process

The data collected and processed varies according to the nature of the Platform's use and the services used, and may include:

Account and User Data

  • Name.
  • Mobile number.
  • Email address.
  • Account and login data.
  • Permissions associated with the user.

Facility Data

  • Facility name.
  • Contact data.
  • Branch data.
  • Data of doctors, staff, and users associated with the account.

Patient and Appointment Data

  • Identification and contact data.
  • Appointment and booking data.
  • Data related to the health services provided to the patient.
  • Health data entered or processed through the Platform.

Technical and Operational Data

  • Platform usage logs.
  • Device, browser, and connection data.
  • Operation, error, and security event logs.
  • Data necessary to operate the services, protect them, and improve their performance.

3. Sources of Data

The Platform may obtain data from:

  • The client or user directly.
  • Patients when using the services or communication channels connected to the Platform.
  • The systems and services the client connects to the Platform.
  • Technical data generated automatically while using the Platform.

4. Purposes of Data Processing

Data is processed to the extent necessary for the purposes connected with providing the Platform's services, including:

  • Creating and managing accounts.
  • Operating appointment and booking services.
  • Managing communications and notifications related to the services.
  • Enabling the client to manage its operations and users.
  • Providing support and resolving technical issues.
  • Protecting accounts and the Platform, and detecting unauthorized use.
  • Improving the Platform's performance and developing its services.
  • Complying with applicable regulatory requirements.

Personal data is not used for purposes incompatible with the purpose for which it was collected or processed, except as permitted by applicable regulations.

5. Client's Responsibility for Data

The client is responsible for the lawfulness of the data it collects, enters, or processes through the Platform, including obtaining consents or satisfying applicable regulatory requirements where necessary.

The client is also responsible for defining its users' permissions and controlling their access to the data it manages through the Platform.

6. Data Sharing

Personal data is not sold.

Data may be shared, to the extent necessary, with:

  • Service providers involved in operating the Platform or delivering its functionality.
  • Government or regulatory authorities where disclosure is required by law.
  • Other parties the client requests to connect its services with, or authorizes to share data with.

Service providers' processing of data is limited to what is necessary to deliver the services they are engaged for, subject to contractual obligations and applicable regulatory requirements.

7. Third-Party Services

Some of the Platform's functions may rely on services provided by third parties, such as communication, hosting, payment, notification, analytics, and other technical services.

These parties are provided with data only to the extent necessary to deliver the relevant service, according to the nature of each service.

8. Data Protection

Appropriate organizational and technical measures are taken to protect personal data from unauthorized access, use, disclosure, alteration, loss, or destruction.

Access to data is also restricted according to the permissions and need associated with performing the relevant tasks.

9. Data Retention Period

Data is retained for the period necessary to provide the services and achieve the purposes for which it was processed.

Upon expiry of the client's subscription, its data may be retained for up to 90 days to allow it to reactivate its account or recover its data, after which it is deleted or processed in accordance with approved procedures, unless applicable regulatory requirements require a longer retention period.

10. Data Subject Rights

A data subject may exercise the rights established under applicable regulations, including, as applicable:

  • Knowing how their personal data is processed.
  • Accessing their personal data.
  • Requesting correction, completion, or updating of inaccurate data.
  • Requesting destruction of their personal data in cases permitted by law.
  • Obtaining a copy of their personal data where that is an established right.

The exercise of these rights is subject to applicable regulatory requirements and exceptions.

11. Data Transfer and Location of Processing

The Platform may engage technical service providers to process or store some of the data necessary to provide its services.

Where data is processed or transferred outside the Kingdom of Saudi Arabia, this is done in accordance with the requirements and controls applicable to the transfer of personal data outside the Kingdom.

12. Cookies

The website may use cookies and similar technologies to operate the website, improve the user experience, and measure performance, as described in the Cookie Policy.

13. Amendments to This Privacy Policy

This Policy may be updated when the services, data processing practices, or applicable requirements change. The update becomes effective from its date of publication or the date specified for its effect.

14. Contact and Privacy Requests

Data subjects may reach out with inquiries or requests related to privacy and data rights through the Platform's official communication channels.

The information necessary to verify the identity of the requester may be requested before executing any request related to personal data.