This Privacy and Confidentiality Policy is issued by Iheal Information Technology L.L.C, a limited liability company incorporated in the Emirate of Dubai, United Arab Emirates, licensed by the Department of Economy and Tourism under trade licence number 1318231, whose registered office is at Office GDP 3-2-3213 and 3218, Al Quoz Industrial Area 3, Dubai, United Arab Emirates (the “Company”).
This Policy records the manner in which the Company processes Personal Data in connection with the Platform, the capacity in which it acts, and the rights available to Data Subjects. It forms part of, and is to be read together with, the Terms of Service and the Data Processing Addendum.
1. DEFINITIONS AND INTERPRETATION
1.1 In this Policy:
“Account Data” means Personal Data relating to a Practitioner and its personnel, including name, contact particulars, practice particulars, professional credentials, billing particulars and records of access to and support of the Platform.
“Anonymised Data” means data derived from Personal Data which has been irreversibly altered such that no Data Subject is or may be identified from it, whether alone or in combination with other information available to the Company or to any recipient.
“Applicable Law” means the laws of the United Arab Emirates, including those of the Emirate of Dubai, together with any regulation, resolution, decision or standard issued thereunder, and the law of any other jurisdiction which applies to the processing in question.
“Child” means a natural person below the age of 18 years.
“Client” means an individual to whom a Practitioner provides services and whose Personal Data is recorded on the Platform.
“Client Data” means Personal Data relating to a Client that is entered, uploaded, generated or transmitted through the Platform by or on behalf of a Practitioner, including client particulars, appointment and attendance records, session notes, intake and feedback responses, programmes and progress records, documents, invoices, communications and, where recorded by the Practitioner, audio recordings of sessions.
“Controller” means the person who determines the purposes and means of the processing of Personal Data.
“Data Protection Legislation” means Applicable Law governing the protection of Personal Data, including Federal Decree-Law No. 45 of 2021, save to the extent disapplied by clause 2.3.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Health Data” means Personal Data relating to the physical or mental health of a Data Subject, including data generated in the course of diagnosis, prevention, treatment, rehabilitation or health monitoring, and the fact that a Data Subject is or has been under the care of a Practitioner.
“Health Data Legislation” means Federal Law No. 2 of 2019, Cabinet Resolution No. 32 of 2020, Ministerial Resolution No. 51 of 2021, any instrument issued thereunder or in replacement of any of them, and the requirements of any competent health authority.
“Personal Data” means any information relating to a Data Subject by which that person is or may be identified.
“Platform” means the practice-management software and services made available by the Company at telmeapp.com and through its applications.
“Practitioner” means a person who registers for or uses the Platform in a professional or business capacity.
“Processor” means the person who processes Personal Data on behalf of and on the instructions of a Controller.
“Sub-processor Register” means the register of sub-processors published by the Company and updated from time to time published at https://telmeapp.com/sub-processors
“Technical Data” means device, browser, network, diagnostic, error and usage information generated upon access to the Platform, including, where the Platform is accessed through a mobile application, the device model, the operating system version, an application instance identifier and a notification token
1.2 In this Policy: headings do not affect construction; “including” is not a word of limitation; the singular includes the plural; a reference to a statute includes any amendment to or replacement of it; and a reference to a clause is a reference to a clause of this Policy.
1.3 Where any provision of this Policy is inconsistent with the Data Processing Addendum in respect of Client Data, the Data Processing Addendum shall prevail. Where any provision is inconsistent with a requirement of the Health Data Legislation, that requirement shall prevail.
2. SCOPE AND APPLICATION
2.1 This Policy applies to all Personal Data processed by the Company in connection with the Platform, whether the Data Subject is a Practitioner, a member of a Practitioner’s personnel, a Client, or a prospective Practitioner or Client.
2.2 This Policy does not govern the processing of Personal Data by a Practitioner in the conduct of that Practitioner’s own practice. Such processing is governed by the Practitioner’s own privacy notice and obligations.
2.3 Health Data relating to health services provided within the United Arab Emirates is governed by the Health Data Legislation and is excluded from the scope of Federal Decree-Law No. 45 of 2021 by Article 2 of that Decree-Law. Where this Policy describes a right, period or procedure by reference to that Decree-Law, the description does not apply to such Health Data except to the extent the Health Data Legislation provides to like effect.
2.4 The Company applies the standard of protection required by the Health Data Legislation to all Client Data, irrespective of whether the Practitioner concerned is licensed by a health authority. Nothing in this clause constitutes a representation as to the regulatory status of any Practitioner.
2.5 Where a Practitioner is established in, or a Client is located in, a jurisdiction whose law applies to processing through the Platform, including the Dubai International Financial Centre, the Abu Dhabi Global Market or a jurisdiction outside the State, the Practitioner shall inform the Company before such processing commences. The Company gives no assurance as to compliance with the law of any such jurisdiction save as expressly agreed in writing.
2.6 The Platform is made available through a website and through mobile applications for iOS and Android. This Policy applies to each equally. Where a provision applies only to access through a mobile application, it says so.
3. CAPACITY IN WHICH THE COMPANY ACTS
3.1 In relation to Client Data, the Practitioner is the Controller and the Company is the Processor. The Practitioner determines the categories of Personal Data collected, the purposes for which they are processed and the periods for which they are retained. The Company processes Client Data solely on the documented instructions of the Practitioner for the purpose of providing the Platform, upon the terms of the Data Processing Addendum.
3.2 In relation to Account Data, Technical Data and Personal Data processed in connection with the community and referral functions, the Company is the Controller.
3.3 Where a Client submits information through a form served by the Company before any relationship with a Practitioner has been established on the Platform, the Company is the Controller of the Technical Data generated upon that submission and may be the Controller of the submission itself until it is attributed to a Practitioner.
3.4 Nothing in this clause 3 operates to transfer to a Practitioner any obligation which Applicable Law imposes upon the Company, or to transfer to the Company any obligation which Applicable Law imposes upon a Practitioner in respect of its own practice.
4. CATEGORIES OF PERSONAL DATA PROCESSED
4.1 The Company processes the following categories of Personal Data:
Registration-of-interest data
Composition: Name, mobile number, electronic mail address, practice type, and information volunteered in an enquiry or feedback form
Capacity and purpose: Controller. Communication with prospective Practitioners concerning availability, pricing and onboarding.
Account Data
Composition: As defined in clause 1.1
Capacity and purpose: Controller. Establishment and administration of the account, invoicing, support, and security of the Platform.
Client Data
Composition: As defined in clause 1.1. May include Health Data.
Capacity and purpose: Processor, upon the Practitioner’s instructions. Health Data is processed in accordance with the Health Data Legislation and clause 2.4.
Audio and inputs to automated processing
Composition: Session audio recorded by the Practitioner, and text or observations submitted for automated note generation
Capacity and purpose: Processor. Processed only where the functions in clause 9 are enabled, and retained for the period in clause 9.4.
Payment data
Composition: Amounts, dates, status and references
Capacity and purpose: Card particulars are processed by the Company’s payment provider and are not retained by the Company.
Community data
Composition: Practitioner profile, publications, event listings, referrals, and communications with other Practitioners
Capacity and purpose: Controller of the function. Visible to other Practitioners and, at the Practitioner’s election, to prospective Clients.
Device access data
Composition: Photographs selected by the Practitioner from the camera or photograph library of the Practitioner’s device.
Capacity and purpose: Controller in respect of a Practitioner profile photograph. Access to the camera and to the photograph library is requested only at the point at which the Practitioner elects to set a photograph, is used for no other purpose, and may be withdrawn at any time in the settings of the device. The Company does not access the location, contacts, calendar, microphone or health records held upon the Practitioner’s device.
Technical Data
Composition: As defined in clause 1.1
Capacity and purpose: Controller. Operation, security, maintenance and improvement of the Platform.
4.2 The Company does not require, and requests that Practitioners do not submit, Client Data which the function in use does not require. The Company does not process biometric data for the purpose of identifying any Data Subject.
5. PURPOSES AND LAWFUL BASIS
5.1 The Company processes Account Data and payment data because such processing is necessary for the performance of its contract with the Practitioner; Technical Data on the basis of its legitimate interest in operating, securing and maintaining the Platform; registration-of-interest data on the basis of the request made by the prospective Practitioner to be contacted; and community data on the basis of the Practitioner’s election to participate.
5.2 The Company processes Client Data as Processor upon the instructions of the Practitioner. The lawful basis for such processing is a matter for the Practitioner as Controller.
5.3 In respect of Health Data, the requirements of the Health Data Legislation as to the grounds upon which such data may be processed and disclosed apply in place of the bases stated in this clause 5.
5.4 Where the Company relies upon consent, the Data Subject may withdraw it at any time by the means described in clause 21. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, nor processing carried out on another basis.
6. RESTRICTIONS UPON USE
6.1 The Company shall not sell, rent, licence or otherwise make available Personal Data to any third party for that third party’s own purposes.
6.2 The Company shall not process Client Data for the purposes of advertising, marketing or profiling, nor for the development or improvement of any product or service, including the Platform, save in respect of Anonymised Data under clause 6.4.
6.3 Neither the Company nor any provider engaged by it shall use Client Data or Account Data for the training, fine-tuning or evaluation of any artificial intelligence model. The Company shall impose this restriction by written terms and shall procure that it is passed down to any further provider.
6.4 The Company may produce and use Anonymised Data to operate, secure, maintain and improve the Platform and to report upon its use in aggregate. Neither the Company nor any provider shall attempt to re-identify any Data Subject. Data from which a Data Subject may be identified is not Anonymised Data and remains subject to clause 6.2. Anonymised Data shall not be produced from Health Data otherwise than as the Health Data Legislation permits.
6.5 The Company does not display advertising to Clients upon the Platform and does not make Client Data available to any advertising network, data broker or advertising analytics provider.
6.6 The obligations in this clause 6 are not qualified by the consent of any Practitioner or Client and shall not be varied save by amendment notified under clause 20.
7. LOCATION OF PROCESSING
7.1 The Company hosts Client Data and Account Data within the United Arab Emirates. Its primary servers, databases, document storage, search indices and backups are situated within the United Arab Emirates. Personal Data is processed outside the State only to the extent described in clause 8 and identified in the Sub-processor Register.
7.2 The Company’s storage is configured such that Client Data and Account Data held in the environments described in clause 7.1 are not replicated outside the United Arab Emirates.
7.3 Health Data relating to services provided within the United Arab Emirates is subject to restrictions upon its storage and processing outside the State under Article 13 of Federal Law No. 2 of 2019. That restriction is not capable of being satisfied by the consent of a Client, by the instruction or election of a Practitioner, by the configuration of any function of the Platform, or by contractual protections procured from a recipient. It is satisfied only by a decision of the competent health authority issued in coordination with the Ministry of Health and Prevention, subject to the conditions attaching to that decision, including retention of a copy within the State.
8. SUB-PROCESSORS AND TRANSFERS OUTSIDE THE STATE
8.1 The Company engages a limited number of providers which process Personal Data outside the United Arab Emirates, including in respect of diagnostic error reporting, address lookup, product analytics, notification delivery, content delivery, electronic mail delivery and communications with Clients. Each is identified in the Sub-processor Register, published at https://telmeapp.com/sub-processors, together with the categories of Personal Data it receives and the territory in which it operates
8.2 The Company shall notify Practitioners not less than 30 days before any provider is added or substituted. A Practitioner may object within 15 days, stating its grounds. Upon receipt of an objection the Company shall discuss the matter in good faith and shall, at the Practitioner’s election, refrain from transmitting that Practitioner’s Client Data to the provider objected to, suspend the affected function in respect of that Practitioner, or permit termination of the affected service without penalty and with a pro rata refund of sums paid in advance.
8.3 The Company shall not transmit Client Data to any provider situated outside the United Arab Emirates otherwise than in the operation of a function enabled by the Practitioner, in respect of which the provider is identified in the Sub-processor Register, and, where the Client Data constitutes Health Data, in accordance with clause 8.4.
8.4 The Company shall not store, process, generate or transfer Health Data outside the United Arab Emirates unless a decision of the competent health authority, issued in coordination with the Ministry of Health and Prevention, permits that activity, and then only within the limits and upon the conditions of that decision and with a copy retained within the State. Where no such decision is in force, the function shall not be operated in a manner which causes Health Data to leave the State, notwithstanding that a Practitioner has enabled it.
8.5 The Company shall engage each provider upon written terms which impose obligations no less protective than those in this Policy, restrict the provider to processing upon the Company’s instructions, prohibit the uses restricted by clause 6, and require equivalent terms to be imposed upon any further provider. The Company remains liable to the Practitioner for the acts and omissions of each provider as though they were its own.
8.6 The Company maintains a record of the flow of Personal Data through the Platform identifying, per provider, the categories transmitted, the territory of processing, whether the data includes Health Data, and the ground relied upon under clause 8.4 or 8.5. That record is available to a Practitioner upon request under clause 23.
8.7 The Company shall use reasonable endeavours to reduce the number of providers processing Personal Data outside the United Arab Emirates.
9. AUTOMATED PROCESSING
9.1 Where a Practitioner enables the relevant function, the Platform processes observations, text or audio submitted by that Practitioner by automated means in order to produce a draft session note or structured summary. The providers engaged, and the territories in which they operate, are identified in the Sub-processor Register.
9.2 Output constitutes a drafting aid only. It is not verified by the Company, may be inaccurate or incomplete, and does not constitute clinical or professional advice. The Practitioner shall review and approve such output before it is incorporated into any record.
9.3 These functions are optional and may be disabled at any time. Where they are not enabled, no Client Data is transmitted to any provider of automated processing services.
9.4 Audio submitted for automated processing is retained only for so long as is necessary to produce the output, whereupon it is deleted from the Company’s systems and from those of each provider. Text and observations are retained only as part of the record generated from them. No provider retains Client Data after the output is delivered, uses Client Data to train, fine-tune or evaluate any model, or applies human review to Client Data. The Company shall procure these restrictions by written terms and record them in the Sub-processor Register.
9.5 These functions do not produce any decision concerning a Data Subject taken solely by automated means and producing a legal or similarly significant effect. Every output is subject to the Practitioner’s review under clause 9.2, and no clinical, professional, financial or eligibility determination is made by the Platform.
9.6 The Company shall carry out and maintain an assessment of the effect of these functions upon the protection of Personal Data before any material change to them, and shall retain it for production to a competent authority upon request.
10. COMMUNICATIONS WITH CLIENTS
10.1 Where a Practitioner uses the Platform to transmit appointment confirmations, reminders, intake links, payment links or programmes to a Client, such communications are delivered through a third-party messaging provider identified in the Sub-processor Register, to which the content of the communication and the Client’s mobile number are transmitted.
10.2 Where the content of a communication would disclose that a Client is or has been under the care of a Practitioner, that content constitutes Health Data and its transmission is subject to clauses 7.3 and 8.4.
10.3 The Company distinguishes communications necessary for the delivery of a service requested by the Client from promotional communications. A Practitioner transmitting communications through the Platform warrants that it holds a record of the recipient’s consent where consent is required, that the communication complies with Applicable Law governing unsolicited electronic communications, including the regulatory policy of the Telecommunications and Digital Government Regulatory Authority and Cabinet Decision No. 56 of 2024, and that it will act promptly upon any withdrawal of consent. The Company may suspend the messaging function where it has reasonable grounds to believe this clause has been contravened.
10.4 The Company transmits communications to a Client on its own account only where necessary for the operation or security of the Platform, and does not transmit promotional communications to Clients.
10.5 Where a Practitioner enables notifications upon a mobile device, the Company transmits notifications through the notification service of the device operating system, identified in the Sub-processor Register. Such a service operates outside the United Arab Emirates.
10.6 A notification transmitted under clause 10.5 contains no Client Data. It records only that an event has occurred upon the Practitioner’s account. The particulars of that event are retrieved from the Company’s systems within the United Arab Emirates upon the Practitioner opening the application. No Client name, service description, appointment particular, note or other Client Data forms part of the payload of a notification.
10.7 A Practitioner may disable notifications at any time in the settings of the device or of the Platform. Notifications are not used for promotional purposes.
11. DISCLOSURE
11.1 The Company discloses Personal Data only:
- to providers engaged in the operation of the Platform, each identified in the Sub-processor Register, engaged upon written terms, and receiving only such Personal Data as is necessary for its function;
- to another Practitioner, where the Practitioner uses the community or referral functions and elects to disclose information through them, in which case the receiving Practitioner becomes Controller of the Personal Data so disclosed in its own right;
- to its professional advisers, and to a competent authority where required by Applicable Law, in which case the Company shall notify the affected Practitioner in advance unless prohibited from doing so; and
- to a purchaser, investor or financier in connection with a sale, merger, reorganisation or financing of the Company’s business, subject to clause 11.2.
11.2 Upon any transaction under clause 11.1(d), Client Data shall remain subject to this Policy, to the Data Processing Addendum and to the requirements of Applicable Law governing its location and retention. Any examination of Client Data shall be limited to that which is necessary, shall be conducted under controlled conditions, and shall be conducted within the United Arab Emirates.
11.3 A disclosure under clause 11.1(c) shall be limited to the Personal Data specified in the requirement, and the Company shall record the authority, the requirement relied upon, the Personal Data disclosed and the date. Where a request is received from an authority of another jurisdiction, the Company shall not comply otherwise than in accordance with a procedure recognised by Applicable Law, shall notify the affected Practitioner unless prohibited from doing so, and shall challenge any request which appears unlawful, excessive or inconsistent with Applicable Law.
12. RETENTION
12.1 Registration-of-interest data is retained until the Data Subject requests its erasure or until it ceases to be relevant to the purpose for which it was provided, and in any event no longer than 24 months from the last communication with the Data Subject.
12.2 Account Data is retained for the duration of the Practitioner’s account and thereafter for such period as Applicable Law requires the Company to retain commercial and tax records. Technical Data is retained for 90 days, save where a longer period is necessary to investigate a security incident or to comply with Applicable Law.
12.3 Client Data is retained in accordance with the Practitioner’s instructions, subject to clause 12.4.
12.4 Health Data is subject to a minimum retention period prescribed by Applicable Law of 25 years from the date upon which the last health procedure was performed upon the Client, or such longer period as Applicable Law requires. Neither the Company nor the Practitioner may erase the affected records before expiry of that period, notwithstanding any request of the Practitioner or of the Client. The Company shall identify the affected records, shall notify the Practitioner where an erasure request is so affected, and shall retain such records securely and process them for no purpose other than compliance with that requirement.
12.5 Where a Practitioner’s account is closed while records remain subject to a minimum retention period, the manner in which those records are held for the remainder of that period shall be as agreed between the Company and the Practitioner.
12.6 Upon termination of an account the Practitioner may, for 90 days, export its Client Data in a structured, commonly used and machine-readable format. The Company shall not erase Client Data during that period save upon written instruction.
12.7 Upon expiry of that period the Company shall delete the Practitioner’s Client Data from its active systems, and from its backups upon expiry of the backup cycle then current, being no more than 35 days. This clause does not apply to records subject to clause 12.4 or 12.8. The Company shall certify deletion in writing upon request.
12.8 The Company shall retain Personal Data beyond the periods in this clause 12 where required by Applicable Law, by order of a competent authority, or for the establishment, exercise or defence of a legal claim, and only for so long as that requirement subsists.
12.9 A Practitioner may request closure of its account from within the Platform, including from the mobile applications. Upon such a request the Company shall proceed in accordance with clauses 12.6 and 12.7. Records subject to the minimum retention period in clause 12.4 cannot be erased before the expiry of that period, and the Company shall identify such records to the Practitioner at the time the request is made.
13. SECURITY
13.1 The Company shall implement and maintain technical and organisational measures appropriate to the nature, scope and sensitivity of the Personal Data it processes, including encryption in transit and at rest, controls governing access, segregation of the production environment, monitoring and logging of activity, and maintenance of backups within the United Arab Emirates. It shall review those measures annually and upon any material change to the Platform, and shall maintain a documented process for the management of vulnerabilities and of changes to the production environment.
13.2 The Company’s personnel are bound by obligations of confidentiality, are subject to screening appropriate to their function before being afforded access to Personal Data, receive training upon the protection of Personal Data upon appointment and annually thereafter, and are afforded access only to such Personal Data as their function requires.
13.3 The Company shall require each provider engaged by it to maintain security standards appropriate to the Personal Data it handles and to comply with Data Protection Legislation and, where applicable, the Health Data Legislation.
13.4 The Company does not publish particulars of its internal configuration, publication of which would itself constitute a security risk. And a Practitioner requiring further information for its own due diligence may request it, whereupon the Company shall provide it upon appropriate terms.
13.5 No representation is made that the measures described in this clause 13 are proof against every eventuality.
14. CONFIDENTIALITY OF CLIENT DATA
14.1 The Company’s personnel do not examine Client Data save where necessary to provide support requested by the Practitioner, to investigate or remedy a technical fault, to preserve the security or integrity of the Platform, or where required by Applicable Law.
14.2 Access afforded for the purpose of support is limited to that which is necessary to resolve the matter raised and does not constitute authority to examine unrelated Client Data.
14.3 Access by the Company’s personnel to Client Data is logged and is not exercised from outside the United Arab Emirates. A Practitioner may request a record of access to its Client Data, which the Company shall provide within 30 days.
15. RIGHTS OF DATA SUBJECTS
15.1 A Data Subject in respect of whose Personal Data the Company is Controller may require the Company to inform it of the Personal Data held and the manner in which it is processed, to rectify inaccurate or incomplete Personal Data, to furnish a copy in a structured, commonly used and machine-readable format, to erase Personal Data which the Company is not required to retain, to restrict or cease processing in defined circumstances, to cease direct marketing, and, where processing is based upon consent, to withdraw that consent under clause 5.4. This clause applies to a Practitioner, to a member of a Practitioner’s personnel, to a prospective Practitioner who has submitted registration-of-interest data, and to a Client in respect of Personal Data of which the Company is Controller under clause 3.3.
15.2 The Company shall respond within 30 days of receipt and may extend that period once by 30 days where the request is complex or where a number of requests have been received from the same Data Subject, notifying the Data Subject of the extension and the reasons within the original period. The Company may first require verification of identity, and the period runs from completion of verification.
15.3 A Client should address a request concerning Client Data to the Practitioner, who is the Controller of it. Where a Client addresses such a request to the Company, the Company shall refer the Client to the Practitioner and notify the Practitioner of the request. Where the request concerns Personal Data of which the Company is Controller in its own right, the Company shall deal with it directly. The Company shall assist a Practitioner in responding to a Client’s request within the period available to that Practitioner.
15.4 The Company does not charge for responding to a request. Where a request is manifestly unfounded or excessive, in particular by reason of its repetitive character, the Company may charge a reasonable fee or decline to act upon it, informing the Data Subject in writing of the reasons and of the right to complain under clause 15.6.
15.5 A right under clause 15.1 does not extend to Personal Data which the Company is required by Applicable Law to retain, to Personal Data of another Data Subject, or to information subject to legal privilege or whose disclosure would prejudice the security of the Platform. Where the Company withholds Personal Data on any of these grounds it shall say so and identify the ground.
15.6 A Data Subject may complain to the Company under clause 19, to the UAE Data Office, and, in respect of Health Data, to the competent health authority of the relevant Emirate or to the Ministry of Health and Prevention. A Client may in addition complain to the professional body or health authority which regulates the Practitioner concerned.
16. PERSONAL DATA BREACH
16.1 Upon becoming aware of a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data, the Company shall investigate, shall take such steps as are necessary to contain it, and shall notify each affected Practitioner without undue delay and in any event within 24 hours of becoming aware.
16.2 A notification shall describe, so far as then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed by the Company, and the measures the Company recommends the Practitioner take, including any notification the Practitioner may be required to make to a Client or to a competent authority.
16.3 The Company shall not defer notification in order to complete its investigation. Where information is incomplete at the time of notification, the remainder shall be supplied in phases without further undue delay.
16.4 Where Applicable Law requires notification to a competent authority, the Company shall make it within the period and in the manner prescribed, or shall assist the Practitioner in making it, according to the capacity in which each party acts. Where the breach affects Health Data the Company shall in addition notify the competent health authority.
16.5 The Company maintains a record of every breach, whether or not notifiable, recording the facts, the effects and the remedial action taken, and shall produce it to a competent authority upon request. It shall preserve such logs and other evidence as are relevant for so long as is necessary for its investigation and for any regulatory proceeding.
16.6 The Company shall not name any Practitioner or Client in a public communication concerning a breach without prior written consent, save where required by Applicable Law. A notification under clause 16.1 does not constitute an admission of liability by either party.
17. COOKIES AND SIMILAR TECHNOLOGIES
17.1 The Company employs cookies and similar technologies necessary for the functioning of the Platform, including maintenance of an authenticated session, retention of preferences and prevention of fraudulent activity, together with a limited quantity of analytics employed to ascertain how the Platform is used.
17.2 The mobile applications do not employ cookies. They store data locally upon the device for the purposes described in clause 17.1 and generate the identifiers described in the definition of Technical Data. Where the Platform displays instructional video content, that content is delivered by the provider identified in the Sub-processor Register, configured such that it does not set tracking cookies or record the viewer for advertising purposes.
18. CHILDREN
18.1 Accounts upon the Platform are available only to persons of 18 years of age or above. The Company does not knowingly establish an account for any person below that age.
18.2 Where a Client is a Child, the Practitioner is responsible for obtaining the consent of a parent or guardian as its own professional and legal obligations require, and for determining who may access that Client’s records. Where an intake or feedback form served by the Company may be completed by or in respect of a Child, the Practitioner is responsible for ensuring the requisite consent is in place before the form is transmitted. Nothing in this clause relieves the Company of an obligation which Applicable Law imposes upon it as operator of the Platform.
18.3 The Company does not collect, process, publish or share the Personal Data of a Child below the age of 13 save where explicit, documented and verifiable consent has been given by that Child’s parent or guardian, that consent may readily be withdrawn, the processing is limited to the purpose disclosed, and access is restricted accordingly.
18.4 The Company does not profile a Child, direct advertising to a Child, track a Child beyond the purpose for which the Child’s Personal Data was collected, or use the Personal Data of a Child for any commercial purpose.
18.5 A parent or guardian may exercise the rights in clause 15 on behalf of a Child and may withdraw consent given under clause 18.3 by contacting the Company under clause 21.
18.6 The Company shall report to the competent authority any matter which Applicable Law concerning the digital safety of children requires it to report, and shall co-operate with that authority.
19. COMPLAINTS
19.1 A complaint concerning the Company’s processing of Personal Data may be addressed to support@telmeapp.com or to the address in clause 21. The Company shall acknowledge within 5 business days and respond substantively within 30 days. Where it cannot respond within that period it shall say so, give its reasons, and state when it will respond.
19.2 A complainant who is dissatisfied may complain to the authorities identified in clause 15.6, and the Company shall inform a complainant of that right when it responds.
20. AMENDMENT
20.1 The Company may amend this Policy. Each amended version shall be published bearing a version number and date, and superseded versions shall be retained and furnished upon request.
20.2 Where an amendment materially affects the manner in which Personal Data is processed, the Company shall notify Practitioners in advance by electronic mail or through the Platform, and shall not rely upon continued use of the Platform as signifying acceptance.
20.3 No amendment shall reduce the protection afforded to Client Data already processed at the date of the amendment, nor authorise a use of Personal Data which was restricted at the time it was collected.
21. IDENTIFICATION AND CONTACT
21.1 Iheal Information Technology L.L.C, Office GDP 3-2-3213 and 3218, Al Quoz Industrial Area 3, Dubai, United Arab Emirates. Trade licence number 1318231. Commercial register number 2348510. Electronic mail: support@telmeapp.com. Enquiries concerning Personal Data: support@telmeapp.com.
22. RECORDS AND ACCOUNTABILITY
22.1 The Company maintains a record of its processing activities identifying the categories of Personal Data processed, the purposes and grounds, the recipients, the territories to which data is transferred, the retention periods applied and the security measures maintained. The record is available to a competent authority upon request.
22.2 The Company carries out an assessment of the effect of processing upon the protection of Personal Data before commencing any processing likely to present a high risk to Data Subjects, including processing of Health Data upon a substantial scale and the functions described in clause 9, and reviews each assessment upon any material change.
22.3 The Company maintains documented policies and procedures giving effect to this Policy and reviews them annually.
23. AUDIT AND ASSURANCE
23.1 The Company shall, upon written request and not more than once in any 12-month period, provide such information as is reasonably necessary to demonstrate compliance with this Policy and the Data Processing Addendum, including a description of the technical and organisational measures maintained under clause 13.1, subject to clause 13.4 and to acceptance of appropriate terms of confidentiality. It shall complete a Practitioner’s due-diligence questionnaire within 30 days of receipt.
23.2 Where the information provided does not reasonably satisfy a Practitioner, or where a competent authority requires it, the Practitioner may audit the Company’s processing of its Client Data upon not less than 30 days’ written notice, at its own cost, during business hours, in a manner which does not disrupt the Platform or compromise the confidentiality of any other Practitioner’s data, and by an auditor who is not a competitor of the Company and who has accepted appropriate terms of confidentiality.
24. GOVERNING LAW, LANGUAGE AND JURISDICTION
24.1 This Policy and any dispute arising out of it are governed by the laws of the United Arab Emirates as applicable in the Emirate of Dubai. The courts of Dubai have jurisdiction, without prejudice to the jurisdiction of any competent authority under Data Protection Legislation or the Health Data Legislation.
