Privacy Policy

Last Updated: October 2025

At Codelines, we are committed to protecting your privacy and securing your personal information. This Privacy Policy explains how we collect, use, protect, and share your information when you use the TeleCare+ platform.

We fully comply with Saudi data protection laws and follow the highest security standards to protect your health information.

1. Information We Collect

1.1 Service Provider Information

  • Registration information: Name, email, phone number, password
  • Professional information: Medical license number, specialty, qualifications, experience
  • Financial information: IBAN, commercial registration, billing details
  • Clinic/facility data: Name, location, operating hours, services offered
  • Professional liability insurance information (if applicable)

1.2 Patient Information

  • Personal information: Name, date of birth, gender, contact information
  • Medical information: Medical history, symptoms, diagnoses, prescriptions, test results
  • Appointment information: Date and time of consultations, reason for visit, notes
  • Payment information: Payment method, transaction history (without storing full card details)

1.3 Technical Information

  • Device information: Device type, operating system, browser, IP address
  • Usage data: Pages visited, features used, session duration
  • Cookies for improving user experience
  • System logs for troubleshooting and problem resolution

2. How We Use Your Information

2.1 Service Delivery

  • Facilitate telemedicine consultations between patients and providers
  • Manage appointment scheduling and reminders
  • Process payments and billing
  • Maintain medical records securely
  • Enable communication between users and technical support

2.2 Platform Improvement

  • Analyze usage patterns to improve features and performance
  • Conduct research and development (using anonymized data)
  • Personalize user experience
  • Detect and prevent fraud and misuse

2.3 Legal Compliance

  • Comply with Saudi healthcare laws
  • Respond to legal requests from authorities
  • Protect rights and safety of users
  • Enforce terms of service and policies

3. Data Protection and Security

🔒 Security Measures

We employ advanced security technologies to protect your data:

  • End-to-end encryption (SSL/TLS) for all data transmission
  • Encryption of data at rest in databases
  • Strict access controls and multi-factor authentication
  • Continuous security monitoring and threat detection
  • Regular backups and disaster recovery plans
  • Periodic security audits and penetration testing
  • Employee training on data privacy and security
  • Compliance with National Cybersecurity Authority standards

4. Data Sharing and Disclosure

4.1 With Service Providers

Patient medical information is shared only with the relevant healthcare provider for consultation or treatment. Other providers cannot access this information without explicit consent.

4.2 With Third Parties

We may share data with:

  • Payment processors (to execute financial transactions)
  • Cloud service providers (for data hosting - servers within Saudi Arabia)
  • Analytics tools (anonymized data only)
  • Technical support providers (with limited and controlled access)

All third parties are bound by strict data protection contracts and cannot use your data for their own purposes.

4.3 Legal Disclosure

We may disclose your information when legally required by:

  • Saudi Ministry of Health
  • Saudi Commission for Health Specialties
  • Courts or judicial authorities
  • Law enforcement agencies (in criminal investigations)
  • Public health emergencies

5. Your Rights

Under Saudi data protection laws, you have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your data (subject to legal retention requirements)
  • Restriction: Request restriction of data processing
  • Portability: Obtain your data in a usable format
  • Objection: Object to certain processing of your data
  • Withdraw Consent: Withdraw your consent at any time (where applicable)
  • Lodge Complaint: File a complaint with the National Cybersecurity Authority

To exercise any of these rights, please contact us at: telecare@codelines.sa

6. Data Retention

6.1 Medical Records

According to Saudi Ministry of Health regulations, medical records must be retained for at least 10 years after the last consultation. Service providers are responsible for complying with these retention requirements.

6.2 Financial Data

Financial records are retained for 7 years in accordance with Saudi Zakat, Tax and Customs Authority requirements.

6.3 Technical Data

System logs and usage data are retained for up to 12 months for security and improvement purposes.

7. Children's Privacy

The TeleCare+ platform is not intended for children under 18 years of age without parental or legal guardian consent. Parents or guardians must create accounts and manage appointments on behalf of children.

8. International Data Transfers

🇸🇦 Local Data Storage

All user medical and personal data is stored on servers within the Kingdom of Saudi Arabia. We do not transfer sensitive data outside the Kingdom without explicit consent and compliance with National Cybersecurity Authority regulations.

9. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Maintain login sessions
  • Remember your preferences (language, settings)
  • Analyze platform usage and performance
  • Prevent fraud and enhance security

You can control cookies through your browser settings. Note that disabling them may affect platform functionality.

10. Medical Data Controller Responsibilities

⚕️ Data Roles and Responsibilities

  • Service Providers are data controllers for patient medical information
  • Codelines acts as a data processor, providing technical infrastructure
  • Service providers are responsible for medical data privacy compliance
  • Codelines ensures technical security and infrastructure protection

11. Updates to Privacy Policy

We may update this Privacy Policy from time to time. You will be notified of material changes via email or prominent notice on the platform. Please review this page regularly to stay informed about our practices.

12. Legal Compliance Framework

We comply with:

  • Anti-Cyber Crime Law (1428H)
  • Electronic Transactions Law (1428H)
  • National Cybersecurity Authority controls
  • Ministry of Health regulations for patient data protection
  • Zakat, Tax and Customs Authority rules for financial data
  • Saudi Commission for Health Specialties standards

13. Contact Information

For any questions or concerns about your privacy or this policy, or to exercise your data rights, please contact us:

Data Protection Officer

Company: Codelines

Product: TeleCare+

Email: telecare@codelines.sa

Privacy Email: privacy@codelines.sa

Phone: +966 50 022 9725

Website: www.codelines.sa

For data protection complaints:

National Cybersecurity Authority
Website: www.nca.gov.sa
Email: info@nca.gov.sa

By using TeleCare+, you acknowledge that you have read, understood, and agreed to this Privacy Policy.