Privacy Policy
What personal and health data Al-Zahra AI collects, why, who it is shared with, where it is held, and the rights you hold over it.
- Version
- 1.0
- Effective date
- 27 July 2026
- Last reviewed
- 27 July 2026
- Next review
- 27 July 2027
1. Who we are
Al-Zahra AI is a preventive health platform. We decide how and why your personal data is processed, which makes us the controller of that data.
We operate across the Gulf Cooperation Council. Each country has its own data protection framework and its own regulator, and health data is treated as sensitive data under all of them. This policy sets a single standard intended to meet or exceed each of those frameworks. Where the law of your country of residence gives you a stronger right than this policy describes, that stronger right applies and we will honour it.
For anything relating to your data, contact info@alzahra.ai.
2. What we collect
Account and identity. Name, email address, mobile number, date of birth, sex at birth, country and city, preferred language, and preferred units of measurement.
Health data. Laboratory reports you upload; biomarker results extracted from them; questionnaire answers; conditions, medications, allergies and family history; vitals and body measurements; and everything we generate from these, including health scores, biological age estimates, disease risk assessments, nutrition plans and recommendations.
Connected device data. Where you choose to connect them: wearables, continuous glucose monitors, and similar services.
Care relationship data. Which healthcare provider and which clinicians you are connected to, when each connection started and ended, and the consent you gave for it.
Technical and usage data. IP address, device and browser information, pages viewed, actions taken, and access logs.
Payment data. Handled by our payment processor. We receive confirmation of payment and limited transaction detail. We never see or store your full card number.
3. Why we process it, and on what legal basis
| What we do | Why | Basis |
|---|---|---|
| Create and secure your account | To provide the service | Performance of our contract |
| Generate health scores, biological age, risk assessments, plans | Core function of the Platform | Your explicit consent |
| Read laboratory reports you upload | To populate your record | Your explicit consent |
| Share your record with a provider you connect to | So they can give you care | Your explicit consent, per provider |
| Take payment | To charge for paid features | Performance of our contract |
| Security, fraud prevention, audit logging | To protect you and the Platform | Legitimate interests; legal obligation |
| Retain health records for statutory periods | Required by healthcare law | Legal obligation |
| Improve our models using de-identified data | To make the Platform better | Legitimate interests, subject to your objection |
| Send marketing messages | To tell you about the service | Your separate, optional consent |
Consent to health data processing is requested separately from acceptance of our Terms, and separately again from marketing consent. Declining marketing has no effect on your access. You can withdraw any consent at any time, which stops that processing going forward but does not undo processing already lawfully carried out.
4. Artificial intelligence and automated processing
We calculate health scores, biological age estimates and disease risk assessments algorithmically. We use artificial intelligence to read uploaded laboratory reports and to draft written summaries.
These are decision support, not decisions, and they are not a diagnosis. We do not use them to make any decision producing legal or similarly significant effects about you without review by a licensed clinician. You may ask for a clinician to review any algorithmic output on your record, and you may object to automated processing.
Where processing involves a third-party AI provider, we send the minimum text necessary, remove direct identifiers wherever the task permits, contract so that nothing sent is retained or used to train that provider's models, and record each use against your record so it appears in your access log.
6. Your access log
Every access to your health record is logged: who accessed it, when, what they saw, and on what basis. You can review this log yourself from your account at any time. We regard this as your right rather than a feature, and we do not switch it off.
7. How long we keep it
Account data is kept for the life of your account plus twelve months. Marketing preferences are kept until withdrawn plus twelve months. Financial records are kept for the period tax law requires.
Health records are treated differently, and you should understand why. Healthcare laws in several countries where we operate require health records to be retained for a substantial minimum period after your last interaction with a healthcare provider — in some cases for decades. Where such a requirement applies to your record, we are not permitted to delete it on request within that period.
In that situation we restrict processing instead of deleting. The record is retained solely to satisfy the legal obligation, access to it is limited to that purpose, and it is removed from analytics, from model training and from every form of communication. If you ask us to delete your data we will tell you plainly which parts were deleted, which were restricted, and the reason for the difference.
8. Where your data is held
Al-Zahra AI is currently hosted on cloud infrastructure located in Frankfurt, Germany, operated by our hosting provider under contract to us. Encrypted backups are held in the same region.
We are working to move health data processing into the Gulf region. Several countries where we operate restrict or prohibit the transfer of health data outside their borders, or permit it only with regulatory approval or a specified safeguard. We do not onboard a healthcare provider in a jurisdiction whose data localisation requirements we cannot currently meet, and we will update this section and notify registered users when our hosting position changes.
Where a transfer of your data is otherwise necessary — for example a specialist second opinion your own clinician requests — we rely only on a lawful basis available in your jurisdiction, obtain your explicit consent, transfer the minimum required, and log it.
9. How we protect it
- TLS 1.2 or higher on every connection; AES-256 encryption at rest, including backups.
- Row-level access control on every table holding health data, so a clinician can reach your record only while an active care assignment exists. Access is not granted by job title; it is granted by an active, dated relationship with you.
- Append-only audit logging of every access to health data.
- Credentials and API keys held in an encrypted secret store, never in application tables, and not retrievable through our interfaces even by our own administrators.
- Named production access only, with multi-factor authentication.
- Backups verified by restore drill at least quarterly.
No system is completely secure. If a breach affects your personal data, we will notify the competent regulator and you, in accordance with the law applicable to you, without undue delay.
10. Your rights
Subject to the law of your country of residence, you may ask us to:
- give you a copy of the data we hold about you;
- correct data that is inaccurate or incomplete;
- delete your data, subject to the retention rules in section 7;
- restrict how we process it;
- provide it in a portable, machine-readable format, or transfer it to another provider;
- stop processing based on our legitimate interests, including model improvement;
- have a human review any automated output on your record; and
- withdraw a consent you previously gave.
To exercise any of these, email info@alzahra.ai. We respond within 30 days. There is no charge, except where a request is manifestly excessive or repetitive.
If you are not satisfied with our response, you may complain to the data protection regulator in your country of residence. Where your complaint concerns clinical care rather than data, you may also complain to the health regulator that licenses your provider. If you tell us where you live, we will tell you which regulators apply to you.
11. Children
The Platform is intended for adults. An account for a person under 18, or under the age of majority in your country if higher, may be created only by a parent or legal guardian, who is responsible for it.
If we learn that a minor has created an account without that authority, we will suspend it and delete the data unless retention is legally required.
13. Changes to this policy
We version this policy and record which version you accepted. Where a change materially affects how we handle your data, we will notify registered users at least 30 days before it takes effect. Earlier versions are available on request.
14. Contact
Al-Zahra AI — info@alzahra.ai
