We at Rhodium for Website Management LLC, hereinafter referred to as the ("Company" and/or "Application"), acknowledge and understand any concerns regarding the disclosure and/or use of your personal data and/or information. Out of care from the Application and respect for your privacy, you will find below all the consents, information, and/or data that will be used and/or circulated after obtaining your prior consent, in addition to their uses and purposes. By agreeing to the Privacy Policy referred to below, you agree, possessing full customary, legal, and Sharia-recognized capacity, to the following:
First: Collection of Information and Data
The data collected by the Application/Company is the following data and/or any related and/or closely associated data:
Personal Data
- Full name
- Gender
- Marital status
- Date of birth
- Contact details and phone number
- Geographical address
- Nationality
- Prior consents required from the end-user in necessary cases
Medical Data
- Data of previous and current medical visits
- Medical history
- Genetic family diseases
- Medications taken by the patient periodically and/or non-periodically
- Allergies to any natural, synthetic, or food materials, preparations, and/or foods used in pharmaceutical industries and/or that may affect or cause an adverse reaction to prescribed and/or taken medications
- Vaccines received by the patient and their approximate dates
- Clinical forms and notes
- Vital signs of the disease
- Vital signs stored via phones, tablets, smartwatches, and downloaded programs
- Laboratory and radiological test results
- Medical procedures taken
- Initial and final diagnosis
- Medical referrals to other parties
- Patient's health insurance card data
- Sports practiced by the patient
Payment and Financial Transaction Data
The Application/Company saves and processes the following financial data of the end-user to complete the business, tasks, and services desired through the use of the Company's program:
- Bank account and payment card details
- Billing details and payment addresses
- Record of financial transactions and purchase movements made within the Application
- Electronic payment data (such as the name on the card, expiration date, and the first and last numbers of the payment card), noting that we do not store full credit card numbers or the CVV secret code on our servers
- Mobile payment services, including but not limited to (Apple Pay)
Technical Usage Data, Session Logs, and Medical Appointments
All appointments booked with doctors, hospitals, care providers, and/or service providers available through the Application are saved on the Company's servers and storage entities and/or entities contracted by the Company for storage. This generally includes, without limitation:
- Session dates
- Procedures followed
- Prescribed medications
- Initial and final diagnosis
- Any recommendations for visits to various entities
- Medical reports
- Prescribed medications
- Evaluation of clinics, institutions, and entities providing the service
- Any data that would develop the Company's system and improve the end-user's (care recipient's) experience
Mechanism of Collecting Data and Information
All information and data referred to in Clause First of the Privacy Policy are collected by any of the following methods:
- Information available to the public
- Information requested by the Application
- Bank information provided to us
- Information processed and analyzed from all provisions of Clause First of the Privacy Policy
- Polls and requested services
- Cookies
- Identifiers
- Any form of information collection upon the Company's request and/or prior consent of the end-user and/or any permitted exchange of information and/or any exchange that would achieve the best interest and/or best healthcare for the end-user
Second: Purpose of Use
The purpose of using this data and/or information referred to in Clause (First) of the Privacy Policy is to:
- Achieve the best possible end-user experience.
- Outline optimal treatment plans and/or methods that ensure the best results, and outline alternative options ensuring the highest match rate for desired results if any obstacle or impediment arises regarding any option presented by the program for any reason.
- Process data in a manner that ensures the fastest and most accurate analysis of customer data upon retrieval, request, and analysis to achieve desired results.
- Enable the user to book appointments, coordinate treatment trips, and securely create, update, and save a Digital Health Passport to ensure continuity of healthcare and facilitate authorized service providers' access to medical history and reports when needed.
- Analyze usage patterns to improve the end-user experience and collect evaluations about care providers.
- Comply with applicable legislation, respond to legal requests from competent authorities, and protect the platform and users from fraud or security breaches.
Third: Security and Preventive Measures
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to our employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data upon our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulatory authority of a breach where we are legally required to do so. In the event of any data security and integrity breach that would cause severe harm, we are committed to notifying you within (24) hours of discovering the breach process, providing you with the necessary measures to avoid any consequences, and we will also notify the competent regulatory authorities in accordance with the law.
Fourth: Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These rights are:
- Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully, or where we are required to erase your personal data to comply with local law. However, we may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you at the time of your request.
- Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
- If you want us to establish the data's accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise, or defend legal claims.
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Fifth: Privacy Policy Updates
In the event of a need for any updates to the Privacy Policy to align with local legislation and/or comply with contractual and/or legal requirements with third parties dealt with by the Company to provide services through its owned and prepared program, you will be provided with the updated texts and/or policies to obtain your prior consent to apply the modified policies. You will be notified within 24 hours of any amendment to the Privacy Policy if in-app notifications are visible and/or activated, or upon your login to the application, and/or immediately upon the occurrence of any updates and/or amendments to the application.