Handled properly, and we hand you the paperwork.
Saudi law makes you responsible for checking that whoever handles your patients' data does it correctly. Here is the evidence, on a page you can forward to whoever signs off on it.
Get the free audit →Free. Takes a week. Nothing to sign.
4 things that exist before any data moves
These are not intentions but documents, and we send them to you.
A signed processing agreement
Nothing moves until it is signed, and it names what we handle, what we never handle, and what happens at the end.
Only the 5 fields a booking needs
We collect a name, a phone number, the treatment asked about, the appointment, and the consent record. We do not collect more, because nothing else is needed to book an appointment.
Your data stays in the Kingdom
Enquiry data sits on servers inside Saudi Arabia, and it is worth asking your other vendors the same question.
A 72-hour breach procedure
It is written and tested, it covers telling you and the regulator inside the legal window, and you get a copy of it.
You stay the controller. We are only ever the processor.
This is the distinction the law turns on, and the one most vendors are vague about.
The relationship with the patient is yours, the consent record is yours, and the decision about what the data is used for is yours. If a patient asks you to delete theirs, you instruct us and we act on it.
We handle it only to do the job set out in the agreement, and only while that agreement runs. We do not train on it, sell it, or use it for another clinic, and at the end we hand it back or delete it.
What we see, and what we never touch
Booking an appointment does not need a medical record, so we never get one.
Ask us the hard version of these questions
Bring whoever handles compliance at your clinic, because these questions are better answered properly once than raised after a contract is signed.