Legal Document

Privacy Policy

Last updated: April 30, 2026
|
Version: 1.0

Your privacy is a priority. This policy explains how we collect, use, and protect your personal and health data when you use the Shifa platform.

01

Information We Collect

We collect only the information necessary to provide our services. This includes: account data (name, email, phone), health data (medical profile, prescriptions, tests), usage data (pages visited, features used), and device data (device type, operating system, IP address).

We never collect any sensitive information without your explicit consent. All health information is encrypted with AES-256-GCM.

02

How We Use Information

We use your data only for the following purposes: providing the service (booking, prescription management), improving the platform (anonymized analytics), security (fraud and threat detection), communication (service notifications, important updates), and legal compliance when necessary.

We never use your data for advertising or share with any third party for that purpose.

03

Information Sharing

We share your data only in these cases: with your explicit consent, with healthcare providers you choose (doctor, pharmacist, lab), or when legally required by court order.

We never sell your data — not to insurers, not for research, not to any third party. This is a firm commitment.

04

Data Security

We use AES-256-GCM encryption to protect your data both in storage and in transit. Every access is recorded in tamper-proof audit logs.

For full technical details, see our Security page.

05

Your Rights

You have the following rights: access to your data, correction, complete deletion, data portability to another service, and withdrawing consent at any time.

To exercise any of these rights, contact us at privacy@shifa-iq.health and we'll respond within 30 days.

06

Cookies

We use technical cookies necessary to operate the platform (sessions, preferences). We don't use tracking or advertising cookies.

You can disable cookies in your browser settings, but some features may be affected.

07

Children's Privacy

We don't allow children under 13 to create independent accounts. Parents manage their children's profiles from their own accounts.

If we discover an account for a child without parental consent, we delete it immediately.

08

Changes to This Policy

We may update this policy periodically. Material changes will be notified in advance via the app and email at least 30 days before they take effect.

The last update date always appears at the top of the document.

09

Contact Us

For any privacy questions, contact us:

Email: privacy@shifa-iq.health Phone: +964 7723 690 551 Address: Baghdad, Iraq

Last updated: April 30, 2026 | Version: 1.0

Read Terms of Service