I. Purpose of this privacy policy

Your privacy is important to us. We comply with the UAE Federal Law 2 of 2019 on use of ICT (Information and Communication Technology) in the areas of health (Health Data Law) and its regulations and other data protection regulations such as those of the Abu Dhabi Department of Health and the Dubai Health Authority. Where the EU General Data Protection Regulation (GDPR) is applicable, we also observe and implement the regulations of the GDPR. This privacy policy informs you about how Mediclinic Middle East (MCME) processes personal data about you using Mediclinic application (app).

II. Your partner

Mediclinic application is operated by Mediclinic Middle East Management Service FZ.LLC.
Telemedicine services are provided by employed doctors/midwives, affiliated doctors, and other partners of MCME.
In the case of treatment in a MCME hospital or an outpatient unit of MCME, the data processing is carried out by the respective hospital or outpatient unit at the respective business address,   MEDICLINIC MIDDLE EAST MANAGEMENT SERVICES FZ-LLC, v, Dubai, UAE of P.O.Box:123812 Dubai, UAE,  is the  data controller.
When you personally enter a hospital or an outpatient unit, you will receive additional information on data processing in connection with your treatment with the entry form.
For the purposes of this privacy policy, MCME and its involved partners are referred to as service providers ("SP").
The respective SP will then process your personal data as responsible parties in connection with the provision of the medical service requested by you via Mediclinic app.

III. Basis of data processing

The SP processes your personal data based on the following grounds:

  • On the one hand, based on contractual relationships entered or initiated between you and the SP, in particular the user contract for Mediclinic app and other contractual relationships for medical consultation and service provision.
  • For the fulfilment of legal obligations resulting from health insurance legislation and any medical storage requirements.
  • For the vital interest of the patient, where and if applicable,
  • For legitimate business purposes,
  • Based on your explicit consent, as deemed necessary by applicable laws.

IV. Purpose of data processing

The SP may process your personal data for the following purposes:

  • For identification purposes.
  • For the generation and the operation of your Mediclinic app profile, to manage your treatment plan and time schedule and all functionalities offered by Mediclinic app.
  • In order to collect and share information with the relevant SP whose services you wish to use.
  • For contact purposes, concerning any questions relating the operation of Mediclinic app.
  • For providing medical consultancy and medical services according to contractual relationship between you and the relevant SP. Particularly to exercise contractual rights and to comply with contractual duties.
  • For mandatory record keeping, and for archiving purposes.
  • For communication with health insurance companies and regulators in connection with insurance-related purposes;
  • For the improvement of the service provided by the relevant SP.

V. Data security

The security of sensitive medical and other personal data is essential for maintaining confidentiality, data protection and professional secrecy. In cooperation with the developer BeeHealthy and other participating technology partners, we use appropriate technical and organisational measures in accordance with the current state of the art to ensure that your data is protected. We commit third parties to data protection and data security by means of agreements.

VI. Your rights

In connection with the processing of your personal data, you have various rights by law. Please note that the type and extent of such rights may vary depending on the applicable data protection legislation:

  • More information: You have the right to request information about which of your personal data is being processed by the SP, and how it is being processed. Please feel free to file a request for information.
  • Rectification: If your personal data is incorrect, you have the right to have it corrected.
  • Withdrawal of consent: Your personal data will usually not be processed solely based on your consent, without any connection to a contractual relationship. However, if that were the case, you might withdraw your consent at any time. Please note that such withdrawal shall only be effective for the future and shall not affect any other basis of data processing.
  • Right to object: If the processing of your personal data is based on the legitimate interest of a SP, you might object to the use of your personal data. However, only if you find yourself in such a particular situation that your personal interest prevents us from using your personal data. However, please note that possible overriding interests of the respective SP may remain reserved. Furthermore, you have the right to object to any processing of your personal data for direct marketing purposes at any time. However, please note that your objection shall not affect any processing activity which may be based upon further grounds.
  • Restriction: Under certain circumstances, you may have the right to request that the processing of your personal data shall be restricted. This may be the case if you doubt the accuracy of your personal data. Please note that the restriction of processing may limit or prohibit the further provision of the SP’s services.
  • Data portability: If provided for under applicable data protection law, you have the right to request that your personal data, which you provided to us, will be handed out to you in the form required by law. In this case, you may also wish to pass such data on to a new controller. However, overriding, conflicting interests may remain reserved.
  • Right to erasure: See point IX below.
  • Complaint: Depending on the applicable data protection legislation, you may have a legal right to lodge a complaint with the data protection authority responsible for you.

VII. Internal and external recipients of your personal data

The SP may engage third party persons when processing your personal data (especially within the MCME -). This may especially be true for processing administrative services, for quality assurance and in connection with IT (Information Technology) services.

The SP may pass on the personal data required for billing to the insurance companies and other cost units responsible for you. Insurers may have access to medical data based on legal rights to information or your consent.

If necessary, personal data may also be forwarded to UAE governmental and related departmental regulatory agencies or private agencies partnered with and collecting on behalf of the UAE government and related departmental and regulatory bodies, for collection purposes. We also reserve the right to pass on data to public authorities as provided for by law.

Certain services within the MCME app may be subject to legal and regulatory notification obligations in the UAE, for medical registers, medical statistics, or performance measurements, which provide for data to be passed on to third parties and authorities in anonymised or non-anonymised form.

Please note that the transfer of anonymised data will be done in accordance with UAE federal law 2 of 2019. .

VIII. Place of data processing

Your personal and health data will usually be processed in the UAE. If your personal data is disclosed abroad, this will only take place in countries that have a recognised, equivalent data protection standard or where specifically assured guarantees are in place. Please direct any questions you might have in this regard to the contact below.

IX. Deletion/duration of retention of personal data

In principle, you can delete your account with the Mediclinic app at any time. The deletion of the account does not automatically result in the deletion of your personal data. Your personal data will be stored for t if is necessary to fulfil the respective treatment contract, the retention periods provided by law, from public health and health insurance legislation, as well as retention for internal documentation purposes..

X. Contacts

To ensure the best possible protection of your personal data, we have appointed a data protection officer.

For questions in connection with the processing of your personal data as well as inquiries in connection with your rights, please contact our data protection officer directly at: MEDICLINIC MIDDLE EAST MANAGEMENT SERVICES FZ-LLC, Dubai, UAE of P.O.Box:123812 Dubai, UAE dataprivacy@mediclinic.ae.

We request that you make enquiries in writing, enclosing a valid copy of your ID. If you contact us by email, we will assume that you wish to receive correspondence by email, regardless of whether the transmission is encrypted or not. We reserve the right to request further suitable identification measures. Thank you for your understanding.