Healthcare information is personal. DarDoc collects information to create accounts, organise bookings, deliver services, process payments, maintain clinical records, communicate with customers, and meet legal and regulatory obligations.
This article explains the main principles in plain language. The full DarDoc Privacy Policy remains the controlling public document.
What information DarDoc may collect
Depending on how you use DarDoc, information can include:
Name, date of birth, gender, nationality, and identification
Telephone number, email address, and service address
Medical history, symptoms, allergies, medications, prescriptions, and results
Booking and service history
Payment, invoice, and transaction information
Messages and support conversations
Device, browser, and technical information
General location information used to arrange a service
DarDoc does not need every category for every service.
Why health information is different
Health information is sensitive personal data.
DarDoc’s public policy states that health information receives additional protections, including restricted access, encryption, and separation from non-clinical data where appropriate.
Only people who need relevant information for the service, legal requirement, or authorised operation should have access.
Where data is stored
DarDoc’s Privacy Policy states that personal data collected through the platform is stored on servers located in the UAE.
The policy also describes encryption, role-based access, multi-factor authentication, audit logging, staff training, and security review measures.
Does DarDoc sell customer data?
DarDoc states that it does not sell, rent, trade, or otherwise commercialise personal data.
Information may still need to be shared with parties involved in delivering the service, such as:
Treating professionals
Licensed provider entities
Laboratories
Pharmacies
Payment processors
Infrastructure providers
Regulators or authorities when legally required
These are service and compliance relationships, not the sale of customer data.
Payment information
Payment cards are handled through approved payment processors and tokenised payment systems.
For Home Nursing, the customer pays through Stripe. DarDoc employees and caregivers should not ask for a card PIN or request that a complete card number be sent through a chat.
Booking for a child
When a service is booked for a minor, the parent or legal guardian provides the relevant information and consent.
Information about the child should be used for service delivery, clinical records, and legal or regulatory purposes. DarDoc’s policy states that a minor’s data is not used for marketing.
Your privacy rights
Subject to applicable laws and healthcare record requirements, you may be able to request:
Access to your data
Correction of inaccurate information
Restriction of certain processing
A portable copy of eligible data
Withdrawal of consent where consent is the legal basis
Deletion of eligible information
Deletion is not absolute. DarDoc may be legally required to retain health, financial, or regulatory records for a defined period.
Marketing and service messages
Transactional messages can include confirmations, payment receipts, appointment updates, and service reminders. These messages are part of delivering an active service.
Marketing messages require the relevant consent. You can withdraw marketing consent without cancelling necessary messages about a current booking.
How to make a privacy request
Email [email protected] with:
Your full name
Contact information associated with the account
The right you want to exercise
Enough information to verify your identity
Do not send unnecessary medical details in the initial request.
DarDoc’s public policy states that it normally responds within 30 days, with a possible extension for complex or high-volume requests where legally permitted.