1. Who is responsible for your data
⟨registered legal name⟩ ("Shefa") is the controller of the personal data described in this policy, which covers the Shefa website, mobile applications and support channels. It does not cover what a hospital, clinic or practitioner does with your data as part of your care — for that, see their own privacy notice. Once you attend an appointment, the provider is an independent controller of the clinical record it creates.
This policy is written to reflect the Personal Data Protection Law of the Kingdom of Saudi Arabia and its implementing regulations, including the additional protection those rules give to health data.
2. The data we collect
- Identity and contact data
- Name in Arabic and English, mobile number, email, gender, date of birth, and nationality or residency attributes where a provider or a regulation requires them.
- Account and authentication data
- Your verified mobile number, one-time password events (never the code itself once used), sessions, devices, sign-in times, and the terms and consents you have accepted with their version.
- Dependent data
- The profiles you create for people you book for, and the relationship or authority you declare.
- Booking data
- The provider, branch, service, practitioner, date and time, booking reference, status history, and the visit reason or intake answers the provider is approved to collect.
- Health-related data
- The fact that you booked a particular service or specialty, and any pre-visit information the provider asks for. We collect the minimum needed for the appointment.
- Payment data
- Amounts, currency, status, refunds, invoices and receipts. Card details are entered on the payment provider's own hosted page and never reach Shefa's systems.
- Location data
- The city or area you search in, and — only if you allow it — your device location, used to sort results by distance.
- Technical data
- Device and browser type, language, IP address, and security and error logs. Our logs are designed to exclude verification codes, tokens, card data and free-text health details.
- Content you provide
- Reviews, support messages and any attachments you send us.
- Preferences
- Language, notification channels, marketing consent, favourites and recent searches.
3. Health data
Data that reveals something about your health — including which specialty or service you booked — is sensitive. We limit who can see it to the staff and provider users who need it for a specific purpose, we exclude it from analytics wherever the analysis works without it, and we keep it out of the information we pass to service providers that do not need it. Payment records sent to our payment provider identify a booking by reference only and do not describe the care involved.
4. Why we process your data, and on what basis
- Creating and securing your account
- Necessary to provide the service you asked for, and to protect it against fraud and unauthorised access.
- Search, booking and appointment management
- Necessary to perform the service, including sharing the details the provider needs to deliver the appointment.
- Payment, invoicing, refunds and accounting
- Necessary to perform the service and to meet our legal obligations on tax, invoicing and record keeping.
- Notifications about your booking
- Necessary to perform the service. These are transactional and are not marketing.
- Support, complaints and disputes
- Necessary to handle your request and to establish or defend a legal claim.
- Reviews and quality
- Based on your submission, with moderation carried out for our legitimate interest in a trustworthy platform.
- Safety, security, and prevention of abuse
- Our legitimate interest in protecting patients, providers and the platform, and our legal obligations.
- Service improvement and statistics
- Our legitimate interest, using de-identified or aggregated data wherever it answers the question.
- Marketing
- Your consent, which you can withdraw at any time.
6. Where your data is processed
We keep personal data within the Kingdom of Saudi Arabia except where a transfer is permitted under the Personal Data Protection Law and its transfer rules. Every processor and every transfer is inventoried and assessed before it is enabled, and a transfer that does not meet the required safeguards is not used.
7. How long we keep it
We keep personal data only as long as the purpose requires, then archive, anonymise or delete it. Financial and tax records are kept for the period the applicable regulations require, regardless of whether your account is still open. Records subject to a dispute, a legal claim or a regulatory hold are retained until that ends.
8. How we protect it
- Traffic is encrypted in transit and sensitive data and backups are encrypted at rest.
- Access is granted on a least-privilege basis and tied to a purpose; sensitive fields are masked by default in internal tools, and revealing or exporting them is logged.
- Session credentials are held in secure server-side cookies that browser scripts cannot read, and you can revoke a session or device yourself.
- One-time passwords are short-lived, single-use and rate-limited.
- We never store card data; payment card details are handled entirely by the payment provider.
- Privileged actions are recorded in an append-only audit trail, and we test the platform independently before launch and periodically afterwards.
- We operate a documented incident process covering containment, assessment, notification and follow-up.
9. Your rights
Under the Personal Data Protection Law you have the right to be informed about how your data is used, to access it and obtain a copy, to ask for it to be corrected or completed, to ask for it to be destroyed, and to withdraw a consent you have given.
You can review and correct most of your profile data directly in your account. For anything else, submit a request from the privacy section of your account or write to us. We verify your identity before acting on a request, tell you the outcome within the period the regulations allow, and explain any part we cannot act on — for example where a record must be retained for tax, legal or dispute reasons.
Privacy requests and questions: privacy@shefa.sa
If you are not satisfied with our response, you may complain to the competent supervisory authority in the Kingdom of Saudi Arabia.
10. Children and dependents
Accounts are for adults. A child's data reaches the platform through a dependent profile created by a parent or guardian, who is responsible for the accuracy of that data and for the bookings made with it. A dependent's data is used only for their appointments and care coordination, and is subject to the same protections as any other patient data.
11. Ranking and automated processing
Search results are ordered by the criterion you choose and by relevance signals such as location, availability, rating and how completely a profile is verified. Paid placement is labelled as sponsored wherever it appears. We do not make decisions about your eligibility for care by automated means, and we do not use your health-related data to target advertising.
13. Changes to this policy
We update this policy as the platform and the applicable rules develop. The version and date at the top of this page identify the text in force, and we notify you of material changes through the platform or by message.
