Privacy Policy
Last Updated: October 2025
At Codelines, we are committed to protecting your privacy and securing your personal information. This Privacy Policy explains how we collect, use, protect, and share your information when you use the TeleCare+ platform.
We fully comply with Saudi data protection laws and follow the highest security standards to protect your health information.
1. Information We Collect
1.1 Service Provider Information
-
Registration information: Name, email, phone number, password
-
Professional information: Medical license number, specialty, qualifications, experience
-
Financial information: IBAN, commercial registration, billing details
-
Clinic/facility data: Name, location, operating hours, services offered
-
Professional liability insurance information (if applicable)
1.2 Patient Information
-
Personal information: Name, date of birth, gender, contact information
-
Medical information: Medical history, symptoms, diagnoses, prescriptions, test results
-
Appointment information: Date and time of consultations, reason for visit, notes
-
Payment information: Payment method, transaction history (without storing full card details)
1.3 Technical Information
-
Device information: Device type, operating system, browser, IP address
-
Usage data: Pages visited, features used, session duration
-
Cookies for improving user experience
-
System logs for troubleshooting and problem resolution
2. How We Use Your Information
2.1 Service Delivery
-
Facilitate telemedicine consultations between patients and providers
-
Manage appointment scheduling and reminders
-
Process payments and billing
-
Maintain medical records securely
-
Enable communication between users and technical support
2.2 Platform Improvement
-
Analyze usage patterns to improve features and performance
-
Conduct research and development (using anonymized data)
-
Personalize user experience
-
Detect and prevent fraud and misuse
2.3 Legal Compliance
-
Comply with Saudi healthcare laws
-
Respond to legal requests from authorities
-
Protect rights and safety of users
-
Enforce terms of service and policies
3. Data Protection and Security
🔒 Security Measures
We employ advanced security technologies to protect your data:
-
End-to-end encryption (SSL/TLS) for all data transmission
-
Encryption of data at rest in databases
-
Strict access controls and multi-factor authentication
-
Continuous security monitoring and threat detection
-
Regular backups and disaster recovery plans
-
Periodic security audits and penetration testing
-
Employee training on data privacy and security
-
Compliance with National Cybersecurity Authority standards
4. Data Sharing and Disclosure
4.1 With Service Providers
Patient medical information is shared only with the relevant healthcare provider for consultation or treatment. Other providers cannot access this information without explicit consent.
4.2 With Third Parties
We may share data with:
-
Payment processors (to execute financial transactions)
-
Cloud service providers (for data hosting - servers within Saudi Arabia)
-
Analytics tools (anonymized data only)
-
Technical support providers (with limited and controlled access)
All third parties are bound by strict data protection contracts and cannot use your data for their own purposes.
4.3 Legal Disclosure
We may disclose your information when legally required by:
-
Saudi Ministry of Health
-
Saudi Commission for Health Specialties
-
Courts or judicial authorities
-
Law enforcement agencies (in criminal investigations)
-
Public health emergencies
5. Your Rights
Under Saudi data protection laws, you have the following rights:
-
Access: Request a copy of your personal information
-
Correction: Request correction of inaccurate information
-
Deletion: Request deletion of your data (subject to legal retention requirements)
-
Restriction: Request restriction of data processing
-
Portability: Obtain your data in a usable format
-
Objection: Object to certain processing of your data
-
Withdraw Consent: Withdraw your consent at any time (where applicable)
-
Lodge Complaint: File a complaint with the National Cybersecurity Authority
To exercise any of these rights, please contact us at: telecare@codelines.sa
6. Data Retention
6.1 Medical Records
According to Saudi Ministry of Health regulations, medical records must be retained for at least 10 years after the last consultation. Service providers are responsible for complying with these retention requirements.
6.2 Financial Data
Financial records are retained for 7 years in accordance with Saudi Zakat, Tax and Customs Authority requirements.
6.3 Technical Data
System logs and usage data are retained for up to 12 months for security and improvement purposes.
7. Children's Privacy
The TeleCare+ platform is not intended for children under 18 years of age without parental or legal guardian consent. Parents or guardians must create accounts and manage appointments on behalf of children.
8. International Data Transfers
🇸🇦 Local Data Storage
All user medical and personal data is stored on servers within the Kingdom of Saudi Arabia. We do not transfer sensitive data outside the Kingdom without explicit consent and compliance with National Cybersecurity Authority regulations.
9. Cookies and Tracking
We use cookies and similar tracking technologies to:
-
Maintain login sessions
-
Remember your preferences (language, settings)
-
Analyze platform usage and performance
-
Prevent fraud and enhance security
You can control cookies through your browser settings. Note that disabling them may affect platform functionality.
10. Medical Data Controller Responsibilities
⚕️ Data Roles and Responsibilities
-
Service Providers are data controllers for patient medical information
-
Codelines acts as a data processor, providing technical infrastructure
-
Service providers are responsible for medical data privacy compliance
-
Codelines ensures technical security and infrastructure protection
11. Updates to Privacy Policy
We may update this Privacy Policy from time to time. You will be notified of material changes via email or prominent notice on the platform. Please review this page regularly to stay informed about our practices.
12. Legal Compliance Framework
We comply with:
-
Anti-Cyber Crime Law (1428H)
-
Electronic Transactions Law (1428H)
-
National Cybersecurity Authority controls
-
Ministry of Health regulations for patient data protection
-
Zakat, Tax and Customs Authority rules for financial data
-
Saudi Commission for Health Specialties standards
13. Contact Information
For any questions or concerns about your privacy or this policy, or to exercise your data rights, please contact us:
Data Protection Officer
Company: Codelines
Product: TeleCare+
Email: telecare@codelines.sa
Privacy Email: privacy@codelines.sa
Phone: +966 50 022 9725
Website: www.codelines.sa
For data protection complaints:
National Cybersecurity Authority
Website: www.nca.gov.sa
Email: info@nca.gov.sa
By using TeleCare+, you acknowledge that you have read, understood, and agreed to this Privacy Policy.