← Back to home

Privacy Policy

Privacy Policy

All HMD applications — Patient, Pro (Practitioners) & Emergency Services · Working version 0.1 — 3 August 2026

Title I — Who processes your data, what data and why

Article 1 — Editor, scope and roles

This privacy policy applies to all "Hey My Doctor" (HMD) services: the Patient application, the Pro (Practitioners) application, the Emergency Services application and the website heymydoctor.com. It supplements the General Terms and Conditions of Use and Sale; in the event of any doubt regarding the processing of your data, this policy shall prevail.

Editor and point of contact: Healicore Softwares FZCO (77995), Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Data Protection Officer (DPO): privacy@heymydoctor.com.

1.1 Roles depending on the context

Article 2 — Data we process

We process only the data necessary for the operation of the service (minimisation principle). Depending on the features you use:

Article 3 — Purposes and legal bases

We process your data for the following purposes, on the legal bases indicated:

We do not use your data for advertising, nor for fully automated decision-making producing legal effects concerning you. The artificial intelligence features produce assistance "to be validated" by a professional and do not replace medical advice.

Article 4 — Connected devices and wellness data (Oura, WHOOP, Apple Health, Health Connect…)

Connecting a connected device is optional, enabled by you, and reserved for certain monitoring features (Premium offering). You may revoke it at any time, which stops any new synchronisation.

4.1 How the data reaches HMD

4.2 Data that may be imported

Depending on the device and your authorisation: heart rate, heart rate variability (HRV), oxygen saturation (SpO₂), respiratory rate, temperature, sleep, activity and recovery indicators. These measurements are wellness data; once recorded in your record, they are processed as health data. Neither Oura nor WHOOP measures blood pressure; HMD does not derive any measurement from your phone's sensors.

Connected device data is used for monitoring and information; it does not constitute a diagnosis. It is neither sold, nor used for advertising purposes, nor shared with the device manufacturer beyond the connection you have authorised.

Title II — What we do not do, whom we share with, and how we protect

Article 5 — What we never do

Article 6 — Sharing and recipients

Your data is accessible only to the strictly necessary recipients:

For the subscription and teleconsultations, your card number is processed by the store or by Stripe and is never stored by HMD.

Article 7 — International transfers

The Editor is established in the United Arab Emirates. Your data may be processed in countries other than your country of residence. These transfers are governed by appropriate safeguards (standard contractual clauses or equivalent mechanisms) and limited to the purposes described. Details by jurisdiction appear in the terms applicable to your country [to be completed by the DPO].

Article 8 — Hosting and security

Your health data is hosted on an infrastructure compliant with the requirements applicable in the relevant jurisdiction (HDS / GDPR / HIPAA / ISO 27001 or equivalents). We implement encryption in transit and at rest, access partitioning, minimisation of exposed data and an immutable audit log that traces every access. In the event of a data breach likely to result in a high risk, we inform the persons concerned and the competent authorities in accordance with the law.

Title III — Retention, your rights, and protection of minors

Article 9 — Retention periods

Article 10 — Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time (with no retroactive effect) and the right to define directives on the fate of your data after your death.

You exercise these rights directly from the application (record, access management, authorisations) or by writing to the DPO at privacy@heymydoctor.com. You may also lodge a complaint with the data protection authority of your country.

Article 11 — Control of your access and account deletion

You control who accesses your record: booking an appointment authorises the practitioner concerned, and you may revoke that access at any time. You may delete your account from the application (My account › Delete my account) or on the dedicated web page. Certain data in the medical record may be retained for the period required by law, then deleted.

Article 12 — Minors and represented persons

A minor or a protected person is managed via the account of their legal representative, whose consent is required for the processing of health data. The co-management of a child may be shared with a second manager, up to a limit of two managers per child. Connecting connected devices is not offered for child profiles. Upon reaching the age of majority, the person regains control of their own record.

Title IV — Application-specific provisions, cookies, changes and contact

Article 13 — Pro (Practitioners) application

Within the care relationship, the Practitioner is the data controller of the data they process about their patients; HMD acts as a processor and host, on their instructions and in compliance with professional secrecy. The Practitioner must access only the authorised records, obtain the consent of their patients and comply with the ethical rules of their jurisdiction. Professional identifiers and supporting documents are processed for the verification and security of the account.

Article 14 — Emergency Services application (Emergency)

Emergency accounts are verified by HMD (not self-service). Access to a patient's data pursues exclusively the safeguarding of life and health, according to the consent set by the patient: vital summary (reading of an emergency token), exceptional access to the full record ("break-glass", justified, time-bounded and notified), or remote medical dispatch accepted on the patient's phone. Every access is traced, timestamped, attributed and proportionate to the emergency; any abusive use results in revocation and possible sanctions. The patient retains a right of access to the full intervention report, upon reasoned request.

Article 15 — Cookies and trackers

The applications do not use advertising cookies or third-party trackers for marketing purposes. Strictly necessary technical data (session, security) may be used to operate the service. The website heymydoctor.com may use strictly necessary cookies; any non-essential cookie would be subject to your prior consent.

Article 16 — Changes to the policy

We may amend this policy (changes to the service or the law). Substantial changes are notified to you; the applicable version is dated at the top of the document. Continued use after entry into force constitutes information, subject to the consents that must be obtained anew.

Article 17 — Contact, DPO and complaints

For any question relating to your data or to exercise your rights: privacy@heymydoctor.com or Healicore Softwares FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Day-to-day support is provided via the application's Help & support screen. You may also refer the matter to the competent data protection authority of your country of residence.

Consent

By creating an account and enabling the relevant features, you consent to the processing of your health data described in this policy. Connecting a connected device and emergency access to your data are subject to specific consent, which you may withdraw at any time from the application.