Privacy Policy
Privacy Policy
All HMD applications — Patient, Pro (Practitioners) & Emergency Services · Working version 0.1 — 3 August 2026
Title I — Who processes your data, what data and why
Article 1 — Editor, scope and roles
This privacy policy applies to all "Hey My Doctor" (HMD) services: the Patient application, the Pro (Practitioners) application, the Emergency Services application and the website heymydoctor.com. It supplements the General Terms and Conditions of Use and Sale; in the event of any doubt regarding the processing of your data, this policy shall prevail.
Editor and point of contact: Healicore Softwares FZCO (77995), Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Data Protection Officer (DPO): privacy@heymydoctor.com.
1.1 Roles depending on the context
- For your account and the data you enter for yourself (or for a person you legally represent), HMD acts as data controller.
- In the care relationship, the Practitioner you authorise is the data controller of the data they consult or produce about you; HMD then acts as a processor and technical host, on their behalf.
- For an Emergency Service, access to your data pursues a distinct purpose of safeguarding life (see Article 14).
Article 2 — Data we process
We process only the data necessary for the operation of the service (minimisation principle). Depending on the features you use:
- Identity and contact details: name, email address, telephone number, and where applicable postal address (to find nearby practitioners or direct emergency responders).
- Account and technical identifiers: user identifier, notification (push) token, connection and audit logs.
- Health data (special category): medical record — allergies, conditions, treatments, vaccinations, blood type, organ donation, vital signs/measurements, and data from connected devices (see Article 4).
- Content you add: photos of test results, documents and examinations, notes, and messages exchanged with the practitioners you have authorised.
- Precise location: only when you enable it, for the "around me" directory and to direct emergency responders to your actual position via "I Am Safe".
- Emergency contacts: the persons you designate as "I Am Safe" contacts (name, telephone, email).
- Subscription: the status of your Premium subscription (the purchase is handled by the store — see Article 6). We never store your card number.
- On the Practitioner / Emergency Service side: professional identity, profession, jurisdiction, licence number and supporting documents provided for account verification.
Article 3 — Purposes and legal bases
We process your data for the following purposes, on the legal bases indicated:
- Providing and securing the service (account management, health record, appointments, messaging, directory): performance of the contract between us.
- Processing your health data and connecting a connected device: your explicit consent, which you may withdraw at any time.
- Enabling emergency access to vital data: your prior consent and, where applicable, the safeguarding of your vital interests or those of a third party.
- Complying with our legal obligations (accounting, retention of medical records, security): legal obligation.
- Improving the reliability and security of the service: our legitimate interest, in compliance with your rights.
We do not use your data for advertising, nor for fully automated decision-making producing legal effects concerning you. The artificial intelligence features produce assistance "to be validated" by a professional and do not replace medical advice.
Article 4 — Connected devices and wellness data (Oura, WHOOP, Apple Health, Health Connect…)
Connecting a connected device is optional, enabled by you, and reserved for certain monitoring features (Premium offering). You may revoke it at any time, which stops any new synchronisation.
4.1 How the data reaches HMD
- Via your phone's health platforms — Apple Health (HealthKit) and Google Health Connect: the data is read on your device, only for the types you authorise.
- Via the manufacturers' APIs — Oura and WHOOP: you connect your own account through a secure authorisation (OAuth 2.0); HMD then receives, on your behalf, only the measurements necessary for monitoring. We never receive your manufacturer credentials.
4.2 Data that may be imported
Depending on the device and your authorisation: heart rate, heart rate variability (HRV), oxygen saturation (SpO₂), respiratory rate, temperature, sleep, activity and recovery indicators. These measurements are wellness data; once recorded in your record, they are processed as health data. Neither Oura nor WHOOP measures blood pressure; HMD does not derive any measurement from your phone's sensors.
Connected device data is used for monitoring and information; it does not constitute a diagnosis. It is neither sold, nor used for advertising purposes, nor shared with the device manufacturer beyond the connection you have authorised.
Title II — What we do not do, whom we share with, and how we protect
Article 5 — What we never do
- No sale, rental or transfer of your data to third parties.
- No targeted advertising and no sharing with data brokers.
- No advertising tracking across applications or websites (no tracking within the meaning of Apple's App Tracking Transparency).
- No health data stored in iCloud or in a consumer backup service.
- No use of your health data for purposes other than those described here without your consent.
Article 6 — Sharing and recipients
Your data is accessible only to the strictly necessary recipients:
- The Practitioners you authorise (access is revocable at any time and each consultation is logged).
- Emergency Services, according to the level of consent you have set (none / vital summary / full record) and under the conditions of Article 14.
- Our technical processors, bound by contract and acting on our instructions: certified health host; Apple App Store and Google Play for Premium subscription billing; Stripe for the payment of teleconsultations (paid to the practitioner); the connected device providers you connect (Oura, WHOOP) and the Apple Health / Google Health Connect platforms.
- The authorities, where required by law.
For the subscription and teleconsultations, your card number is processed by the store or by Stripe and is never stored by HMD.
Article 7 — International transfers
The Editor is established in the United Arab Emirates. Your data may be processed in countries other than your country of residence. These transfers are governed by appropriate safeguards (standard contractual clauses or equivalent mechanisms) and limited to the purposes described. Details by jurisdiction appear in the terms applicable to your country [to be completed by the DPO].
Article 8 — Hosting and security
Your health data is hosted on an infrastructure compliant with the requirements applicable in the relevant jurisdiction (HDS / GDPR / HIPAA / ISO 27001 or equivalents). We implement encryption in transit and at rest, access partitioning, minimisation of exposed data and an immutable audit log that traces every access. In the event of a data breach likely to result in a high risk, we inform the persons concerned and the competent authorities in accordance with the law.
Title III — Retention, your rights, and protection of minors
Article 9 — Retention periods
- Account and associated data: retained for as long as your account is active.
- Medical record: retained for the period required by the applicable legal obligations, then deleted or anonymised [precise period by jurisdiction — to be completed by the DPO].
- Security and audit logs: retained for a limited period for evidentiary and security purposes.
- Following an account deletion request, erasure (or anonymisation) is carried out within 30 days, subject to the data that the law requires to be retained.
Article 10 — Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time (with no retroactive effect) and the right to define directives on the fate of your data after your death.
You exercise these rights directly from the application (record, access management, authorisations) or by writing to the DPO at privacy@heymydoctor.com. You may also lodge a complaint with the data protection authority of your country.
Article 11 — Control of your access and account deletion
You control who accesses your record: booking an appointment authorises the practitioner concerned, and you may revoke that access at any time. You may delete your account from the application (My account › Delete my account) or on the dedicated web page. Certain data in the medical record may be retained for the period required by law, then deleted.
Article 12 — Minors and represented persons
A minor or a protected person is managed via the account of their legal representative, whose consent is required for the processing of health data. The co-management of a child may be shared with a second manager, up to a limit of two managers per child. Connecting connected devices is not offered for child profiles. Upon reaching the age of majority, the person regains control of their own record.
Title IV — Application-specific provisions, cookies, changes and contact
Article 13 — Pro (Practitioners) application
Within the care relationship, the Practitioner is the data controller of the data they process about their patients; HMD acts as a processor and host, on their instructions and in compliance with professional secrecy. The Practitioner must access only the authorised records, obtain the consent of their patients and comply with the ethical rules of their jurisdiction. Professional identifiers and supporting documents are processed for the verification and security of the account.
Article 14 — Emergency Services application (Emergency)
Emergency accounts are verified by HMD (not self-service). Access to a patient's data pursues exclusively the safeguarding of life and health, according to the consent set by the patient: vital summary (reading of an emergency token), exceptional access to the full record ("break-glass", justified, time-bounded and notified), or remote medical dispatch accepted on the patient's phone. Every access is traced, timestamped, attributed and proportionate to the emergency; any abusive use results in revocation and possible sanctions. The patient retains a right of access to the full intervention report, upon reasoned request.
Article 15 — Cookies and trackers
The applications do not use advertising cookies or third-party trackers for marketing purposes. Strictly necessary technical data (session, security) may be used to operate the service. The website heymydoctor.com may use strictly necessary cookies; any non-essential cookie would be subject to your prior consent.
Article 16 — Changes to the policy
We may amend this policy (changes to the service or the law). Substantial changes are notified to you; the applicable version is dated at the top of the document. Continued use after entry into force constitutes information, subject to the consents that must be obtained anew.
Article 17 — Contact, DPO and complaints
For any question relating to your data or to exercise your rights: privacy@heymydoctor.com or Healicore Softwares FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Day-to-day support is provided via the application's Help & support screen. You may also refer the matter to the competent data protection authority of your country of residence.
Consent
By creating an account and enabling the relevant features, you consent to the processing of your health data described in this policy. Connecting a connected device and emergency access to your data are subject to specific consent, which you may withdraw at any time from the application.
