Privacy Policy

What personal and health data Al-Zahra AI collects, why, who it is shared with, where it is held, and the rights you hold over it.

Version
1.0
Effective date
27 July 2026
Last reviewed
27 July 2026
Next review
27 July 2027

1. Who we are

Al-Zahra AI is a preventive health platform. We decide how and why your personal data is processed, which makes us the controller of that data.

We operate across the Gulf Cooperation Council. Each country has its own data protection framework and its own regulator, and health data is treated as sensitive data under all of them. This policy sets a single standard intended to meet or exceed each of those frameworks. Where the law of your country of residence gives you a stronger right than this policy describes, that stronger right applies and we will honour it.

For anything relating to your data, contact info@alzahra.ai.

2. What we collect

Account and identity. Name, email address, mobile number, date of birth, sex at birth, country and city, preferred language, and preferred units of measurement.

Health data. Laboratory reports you upload; biomarker results extracted from them; questionnaire answers; conditions, medications, allergies and family history; vitals and body measurements; and everything we generate from these, including health scores, biological age estimates, disease risk assessments, nutrition plans and recommendations.

Connected device data. Where you choose to connect them: wearables, continuous glucose monitors, and similar services.

Care relationship data. Which healthcare provider and which clinicians you are connected to, when each connection started and ended, and the consent you gave for it.

Technical and usage data. IP address, device and browser information, pages viewed, actions taken, and access logs.

Payment data. Handled by our payment processor. We receive confirmation of payment and limited transaction detail. We never see or store your full card number.

4. Artificial intelligence and automated processing

We calculate health scores, biological age estimates and disease risk assessments algorithmically. We use artificial intelligence to read uploaded laboratory reports and to draft written summaries.

These are decision support, not decisions, and they are not a diagnosis. We do not use them to make any decision producing legal or similarly significant effects about you without review by a licensed clinician. You may ask for a clinician to review any algorithmic output on your record, and you may object to automated processing.

Where processing involves a third-party AI provider, we send the minimum text necessary, remove direct identifiers wherever the task permits, contract so that nothing sent is retained or used to train that provider's models, and record each use against your record so it appears in your access log.

5. Who we share it with

Healthcare providers you connect to. Their authorised clinical staff can access your record for as long as the connection is active. Administrative staff see scheduling and contact details only, not clinical data. When a connection ends, access ends immediately — except for records a clinician personally authored, which they are independently required to retain.

Service providers acting on our instructions. Hosting and database infrastructure, email delivery, payment processing, and AI model providers. Each is bound by contract to process data only as we direct and to protect it to the standard this policy sets.

Regulators, courts and authorities. Where we are legally required to disclose, or where a health regulator with jurisdiction over you or your provider requires it.

A successor to the business. If the business is acquired or merged, subject to the acquirer being bound by this policy.

We do not sell your personal data. We do not share it with advertisers, insurers or employers.

6. Your access log

Every access to your health record is logged: who accessed it, when, what they saw, and on what basis. You can review this log yourself from your account at any time. We regard this as your right rather than a feature, and we do not switch it off.

7. How long we keep it

Account data is kept for the life of your account plus twelve months. Marketing preferences are kept until withdrawn plus twelve months. Financial records are kept for the period tax law requires.

Health records are treated differently, and you should understand why. Healthcare laws in several countries where we operate require health records to be retained for a substantial minimum period after your last interaction with a healthcare provider — in some cases for decades. Where such a requirement applies to your record, we are not permitted to delete it on request within that period.

In that situation we restrict processing instead of deleting. The record is retained solely to satisfy the legal obligation, access to it is limited to that purpose, and it is removed from analytics, from model training and from every form of communication. If you ask us to delete your data we will tell you plainly which parts were deleted, which were restricted, and the reason for the difference.

8. Where your data is held

Al-Zahra AI is currently hosted on cloud infrastructure located in Frankfurt, Germany, operated by our hosting provider under contract to us. Encrypted backups are held in the same region.

We are working to move health data processing into the Gulf region. Several countries where we operate restrict or prohibit the transfer of health data outside their borders, or permit it only with regulatory approval or a specified safeguard. We do not onboard a healthcare provider in a jurisdiction whose data localisation requirements we cannot currently meet, and we will update this section and notify registered users when our hosting position changes.

Where a transfer of your data is otherwise necessary — for example a specialist second opinion your own clinician requests — we rely only on a lawful basis available in your jurisdiction, obtain your explicit consent, transfer the minimum required, and log it.

9. How we protect it

  • TLS 1.2 or higher on every connection; AES-256 encryption at rest, including backups.
  • Row-level access control on every table holding health data, so a clinician can reach your record only while an active care assignment exists. Access is not granted by job title; it is granted by an active, dated relationship with you.
  • Append-only audit logging of every access to health data.
  • Credentials and API keys held in an encrypted secret store, never in application tables, and not retrievable through our interfaces even by our own administrators.
  • Named production access only, with multi-factor authentication.
  • Backups verified by restore drill at least quarterly.

No system is completely secure. If a breach affects your personal data, we will notify the competent regulator and you, in accordance with the law applicable to you, without undue delay.

10. Your rights

Subject to the law of your country of residence, you may ask us to:

  • give you a copy of the data we hold about you;
  • correct data that is inaccurate or incomplete;
  • delete your data, subject to the retention rules in section 7;
  • restrict how we process it;
  • provide it in a portable, machine-readable format, or transfer it to another provider;
  • stop processing based on our legitimate interests, including model improvement;
  • have a human review any automated output on your record; and
  • withdraw a consent you previously gave.

To exercise any of these, email info@alzahra.ai. We respond within 30 days. There is no charge, except where a request is manifestly excessive or repetitive.

If you are not satisfied with our response, you may complain to the data protection regulator in your country of residence. Where your complaint concerns clinical care rather than data, you may also complain to the health regulator that licenses your provider. If you tell us where you live, we will tell you which regulators apply to you.

11. Children

The Platform is intended for adults. An account for a person under 18, or under the age of majority in your country if higher, may be created only by a parent or legal guardian, who is responsible for it.

If we learn that a minor has created an account without that authority, we will suspend it and delete the data unless retention is legally required.

12. Cookies

We use cookies that are strictly necessary for the Platform to function, such as keeping you signed in. We also use optional analytics cookies to understand how the Platform is used; these are set only if you agree, and you can change your choice at any time.

We do not use advertising cookies and we do not permit third-party advertising trackers.

13. Changes to this policy

We version this policy and record which version you accepted. Where a change materially affects how we handle your data, we will notify registered users at least 30 days before it takes effect. Earlier versions are available on request.

14. Contact

Al-Zahra AI — info@alzahra.ai