Privacy Policy
How DHAT collects, uses, and protects data.
This draft is under legal review. The final text will be approved before launch.
This policy explains how DHAT handles personal data when you use our website or our platform. We treat mental healthcare data as among the most sensitive data there is, and we design our systems on that basis.
Who we are, and our role
DHAT is a software platform provided to licensed psychiatric clinics. The clinic is the controller of its patients' data; we act as a processor on the clinic's behalf, following its instructions and our agreement with it.
For visitors to this website and people who request a demo, we are the controller of that data.
The data we collect
We collect the minimum needed to provide the service:
- Contact details you give us in the demo request form: name, clinic name, work email, mobile number, and number of clinicians.
- Account data for platform users: name, email, role and permissions.
- Clinical data entered into the platform by the clinic, which remains the clinic's.
- Technical records kept for security: time of access, type of event, and the account involved.
Why we use it
- To provide and operate the platform for the clinic.
- To respond to you when you book a demo or get in touch.
- To protect accounts and detect unauthorised use.
- To meet legal obligations that apply to us.
Legal basis for processing
We process personal data on the basis of your consent where you give it, to perform the agreement with your clinic, or to comply with a legal obligation. You can withdraw consent at any time; doing so does not affect the lawfulness of processing carried out beforehand.
Sharing data
We do not sell personal data, rent it, or use it for advertising.
We may share data with technical service providers who work under contracts requiring them to protect it and process it only on our instructions, or with a competent authority where there is a binding legal request.
Where data is held and transferred
Hosting arrangements and the location where data is held are set out in the agreement with each clinic. Data is not transferred outside the agreed scope except as permitted by applicable law and with appropriate safeguards.
How long we keep it
We keep demo request data for as long as needed to respond and manage our relationship with you.
Clinical data is subject to the clinic's own retention policy and to the legal requirements for medical records. It is deleted or returned to the clinic at the end of the agreement, as agreed.
How we protect it
- Access is limited by role and need, and every account belongs to one named person.
- Each clinic's data sits in a logically separated scope.
- Encrypted in transit and at rest.
- Every view, edit, and export is recorded in an access log.
Your rights
Under the Personal Data Protection Law of Saudi Arabia, you have the right to:
- Be informed how your data is processed and why.
- Access your data and obtain a copy of it.
- Request correction of data that is inaccurate or incomplete.
- Request destruction of your data once it is no longer needed.
- Withdraw your consent to processing.
Data about minors
Where care involves a minor, the clinic obtains guardian consent as required by applicable law. We do not collect data about minors directly through this website.
Cookies
We use as few cookies as possible. Details are on the Cookies page.
Updates to this policy
We may update this policy as our services or legal requirements change. The last updated date appears at the top of this page, and we notify clinics of material changes.
Contact us
For any question about this policy, or to exercise your rights, write to hello@dhat.sa and we will reply within one business day.
For any question about this page, write to us at hello@dhat.sa