Privacy Policy

Updated on 16 June 2026

Privacy and security hold the utmost importance to us Heale Tech Ltd (Heale, we or us) and we are committed to protecting and respecting your privacy. This privacy policy (Privacy Policy) is meant to help you understand how your personal data, as defined in the Data Protection Law DIFC Law No. 5 of 2020 (as amended from time to time) (Personal Data) and information is collected, used and disclosed when you access or use our website (located at: www.heale.io), any related websites, social media platforms owned or operated by us and associated mobile applications (together the Sites).

Heale Tech Ltd is a private company registered in the Innovation Hub, Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates, with trade licence number 7537. Please read this Privacy Policy carefully to understand our views and practices regarding your Personal Data and how we will treat it. This Privacy Policy applies together with applicable UAE health data regulations, including Federal Law No. 2 of 2019 on the use of information and communication technology in the health sector, where relevant to the data processed on our platform.

OUR TWO ROLES: CONTROLLER AND PROCESSOR

Heale processes Personal Data in two distinct capacities, and your rights are exercised differently depending on which applies.

Website and account data — controller. For data relating to visitors to our Sites and holders of platform accounts (such as registration details, business contact details, billing information and technical data), Heale determines the purposes and means of the processing and acts as controller. This Privacy Policy describes that processing.

Client Data processed on the platform — processor. Policy information, member and dependant details, identity documents, and other insurance-related documentation and health insurance information entered or uploaded by or on behalf of our clients (employers, insurers and brokers) is processed by Heale solely on behalf of, and under the documented instructions of, the relevant client, which acts as controller (Client Data). The relevant client is responsible for the lawfulness of that processing and for informing you about it. If you are an insured member or dependant and wish to exercise your rights in respect of Client Data, please contact the relevant controller (for example, your employer or insurer); we will assist that controller in responding to your request in accordance with our contractual obligations.

INFORMATION WE COLLECT FROM YOU AS CONTROLLER

Account and registration data. When you sign up to our Sites or create an account, we gather registration details, including your name, business email address, login credentials, professional role and organisation, and phone number (used for multi-factor authentication and important notifications).

Communications. When you contact us via contact forms, phone, email, chat services or other means for questions about our services or customer support, or when you participate in surveys or user interviews, we collect the Personal Data you provide in these interactions, including contact details and message content.

Billing data. Where you subscribe to paid services, we process invoicing details and payment-related information through our payment provider, Stripe. Billing is handled separately from our platform, and Heale does not store full payment card numbers.

Technical and usage data. When you visit our Sites, we automatically collect technical information such as your IP address, browser type and version, time zone settings, device information, pages viewed and interactions with the Sites, collected through logs and cookies (see the Cookies section below).

HOW WE USE YOUR PERSONAL DATA

We process Personal Data for which we are controller on the following legal bases under the DIFC Data Protection Law:

Performance of a contract — to create and administer your account, provide the Sites and our services, process payments, and provide customer support.

Legitimate interests — to secure the Sites and our platform, prevent fraud and misuse, maintain audit trails, and improve and develop our services, provided these interests are not overridden by your rights.

Compliance with legal obligations — to meet our regulatory, accounting and record-keeping obligations under applicable law.

Consent — for marketing communications and non-essential cookies. You may withdraw your consent at any time by contacting us at support@heale.io or using the opt-out mechanisms provided; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

DISCLOSURE OF YOUR PERSONAL DATA

We do not sell Personal Data. We disclose Personal Data only to the following categories of recipients:

Hosting provider — Amazon Web Services, UAE region (me-central-1), which hosts our platform and its data.

Payment provider — Stripe, which processes subscription billing information. Billing is handled separately from our platform, and Stripe has no access to, or integration with, Client Data processed on the platform.

Website analytics — Google Analytics, used on our marketing website only. It is not deployed on the platform and does not process Client Data.

Service providers — a limited number of providers supporting the operation of the Sites, such as communications delivery, acting under contractual obligations of confidentiality and data protection.

Legal and regulatory recipients — courts, regulators or other authorities where disclosure is required by applicable law, or where necessary to establish, exercise or defend legal claims.

Corporate transactions — in the event of a merger, acquisition or reorganisation, subject to appropriate confidentiality safeguards and applicable law.

Client Data processed on the platform is disclosed only to the users authorised by the relevant controller through the platform’s role-based permissions, and to the sub-processors approved under our agreements with controllers.

WHERE WE STORE YOUR PERSONAL DATA

Personal Data processed through our platform is hosted in the United Arab Emirates, in the AWS UAE region (me-central-1). We do not store or transfer Client Data processed on the platform outside the United Arab Emirates.

Certain limited categories of Personal Data for which Heale is controller — billing information processed by our payment provider and technical data collected through website analytics — may be processed by those providers outside the UAE. Where this occurs, we transfer Personal Data only as permitted by the DIFC Data Protection Law, on the basis of an adequacy decision of the DIFC Commissioner of Data Protection or subject to appropriate safeguards, and we remain responsible for its protection.

RETENTION OF YOUR PERSONAL DATA

We retain Personal Data for which we are controller only for as long as necessary for the purposes for which it was collected, and thereafter as required by applicable law. Account data is retained for the duration of the account relationship and deleted or anonymised within a defined period after closure, subject to legal retention obligations. When determining retention periods, we take into account the nature of our relationship with you, the type of services provided, and mandatory retention periods provided by law.

Client Data processed on the platform is retained in accordance with the documented instructions of the relevant controller and applicable regulatory requirements. Upon termination of our services to a controller, Client Data is returned to the controller or securely deleted, at the controller’s choice, subject to any retention required by applicable law.

SECURITY

We implement technical and organisational measures designed to protect Personal Data against loss, misuse, unauthorised access, disclosure, alteration and destruction. These measures include encryption of data in transit (TLS 1.2 or higher) and at rest, role-based access controls on a least-privilege basis, multi-factor authentication, structured request logging and an append-only audit trail, network segregation and firewalls, and automated backups. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our Sites, you are responsible for keeping this password confidential, and we ask you not to share it with anyone. While no organisation can guarantee absolute security, we review and improve these measures on an ongoing basis.

COOKIES

We use essential cookies required for the Sites to function, and, with your consent, non-essential cookies for functionality and analytics. You can manage non-essential cookies through the cookie banner displayed on the Sites or through your browser settings. Disabling cookies may affect some functionality of the Sites. For more information, please see our Cookies Policy, available on the Sites.

YOUR RIGHTS

Where Heale acts as controller, you have the following rights under the DIFC Data Protection Law, subject to the conditions and exemptions set out in that law: the right to access your Personal Data and receive a copy; the right to rectification of inaccurate or incomplete data; the right to erasure; the right to restrict processing; the right to object to processing, including for direct marketing; the right to data portability; and the right to withdraw consent at any time where processing is based on consent.

To exercise these rights, contact us at support@heale.io. Please provide as much information as you can about your request so that we can deal with it as quickly as possible. We will respond within the timeframes required by the DIFC Data Protection Law.

If your request concerns Client Data processed on the platform on behalf of a controller, we will refer your request to the relevant controller and assist it in responding.

UPDATING YOUR DETAILS

Should any of the Personal Data you have provided to us change, such as your email address, name or payment details, or if you have concerns regarding the accuracy of Personal Data held on the Sites, please contact us at support@heale.io. We are committed to promptly reviewing and updating our records to ensure their accuracy.

PROTECTION OF CHILDREN’S PRIVACY

Our Sites are not directed to individuals under the age of eighteen (18), and we do not knowingly collect Personal Data from children for our own purposes. Personal Data relating to minors may be processed on the platform as Client Data (for example, dependants covered under a policy), solely on behalf of and under the instructions of the relevant controller. If we become aware that we have collected Personal Data from a child for our own purposes without appropriate consent, we will take steps to delete it as soon as possible.

MARKETING OPT OUT

Every marketing communication we send will include instructions allowing you to opt out of receiving future marketing messages. Should you decide at any point that you no longer wish to receive such communications, please contact us at support@heale.io. Even if you opt out of marketing communications, we will continue to send you communications concerning your account or any services you have requested or received from us.

THIRD PARTY LINKS AND WEBSITES

Our Sites may, from time to time, contain links to and from third-party websites. If you follow a link to any of these websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for those policies. Please check those policies before you submit any Personal Data to third-party websites.

OTHER TERMS

Your access to and use of our services is subject to our Terms of Services (which you sign with us) and our Website Terms of Use found at www.heale.io/legal/terms-of-use, and such other terms which may be made available to you in connection with your use of our services.

COMPLAINTS

You may submit a written complaint about how we handle your Personal Data to our Data Protection Officer at support@heale.io If you are not satisfied with our handling of your complaint, or we have not replied to you within a reasonable period of time, you are entitled to lodge a complaint with the DIFC Commissioner of Data Protection.

HOW TO CONTACT US

If you have any questions about how your Personal Data is collected, used and stored, please contact our Data Protection Officer at support@heale.io, or write to Heale Tech Ltd, Innovation Hub, Dubai International Financial Centre, Dubai, United Arab Emirates.

APPLICABLE LAW AND JURISDICTION

This Privacy Policy, its subject matter and its formation (and any non-contractual disputes or claims) are governed by the laws of the Dubai International Financial Centre. We both agree to the exclusive jurisdiction of the courts of the Dubai International Financial Centre.

CHANGES TO OUR PRIVACY POLICY

Any changes we may make to this Privacy Policy will be posted on this page and, where appropriate, notified to you by email. The current version is always available on the Sites.