Privacy Policy

سياسة الخصوصية وحماية البيانات

German Health Hub is committed to protecting your personal and health data in full compliance with UAE federal and emirate-level data protection law, including PDPL, MoHAP, DHA, and TDRA/EDE regulations.

✓ UAE PDPL Compliant✓ MoHAP Aligned✓ DHA Certified✓ ADHICS Security
Effective Date: 5 July 2026  | Version: 2.0  | Next Review: July 2027

1. Introduction & Legal Framework

German Health Hub ("GHH", "we", "us", or "our") is committed to protecting your personal health data in full compliance with applicable UAE federal and emirate-level legislation, including:

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its Executive Regulations

UAE Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields

Ministry of Health and Prevention (MoHAP) Circular No. 28/2019 on Health Data Protection

Emirates Health Authority (EHA) Health Information Management Regulations

Dubai Health Authority (DHA) Health Data Governance Framework and Patient Rights Charter

Telecommunications and Digital Government Regulatory Authority (TDRA / EDE) Digital Communications Regulations

UAE Cybercrime Law – Federal Law No. 34 of 2021

Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard

This Privacy Policy governs how we collect, process, store, share, and protect your personal and health data when you use our website, mobile applications, services, and platforms.

2. Who We Are (Data Controller)

German Health Hub operates as the Data Controller for all personal data collected through our services.

Registered Entity: German Health Hub FZ-LLC

Jurisdiction: United Arab Emirates

Licensed Activity: Health Information Services, At-Home Clinical Diagnostics, Telemedicine Support

Regulatory Oversight: MoHAP, DHA (Dubai), DOH (Abu Dhabi)

As a Data Controller, we determine the purposes and means of processing your personal data. We have appointed a Data Protection Officer (DPO) as required under PDPL Article 14, whose contact details are provided at the end of this policy.

We process health data as a Health Information Controller under the UAE Health Data Law (Federal Law No. 2 of 2019), which imposes heightened obligations on entities processing sensitive health records.

3. Personal Data We Collect

We collect the following categories of personal data, consistent with MoHAP and DHA data classification standards:

3.1 Identity & Contact Data

• Full name, date of birth, nationality, Emirates ID number

• Email address, phone number, residential address (emirate and area)

• Gender and marital status (where clinically relevant)

3.2 Health & Medical Data (Special Category)

• Blood test results, biomarker values, diagnostic reports

• Medical history, chronic conditions, medications, allergies

• Weight, height, BMI, and other anthropometric measurements

• Consultation notes, clinical protocols, and treatment plans

• Images or files you upload for medical analysis (e.g., lab reports, scans)

3.3 Financial & Transaction Data

• Payment card details (processed via PCI-DSS compliant payment gateways — we do not store card numbers)

• Order history, invoices, and receipts

• Promo code usage

3.4 Technical & Usage Data

• IP address, browser type, device identifiers

• Pages visited, session duration, click-path data

• Cookies and similar tracking technologies (see Section 9)

3.5 Communications Data

• Chat transcripts with our AI assistant (ChatGHH)

• WhatsApp messages initiated by you

• Support emails and feedback submissions

Note: We do not knowingly collect data from individuals under the age of 18 without verifiable parental consent, in compliance with UAE Child Protection Law (Federal Law No. 3 of 2016).

5. How We Use Your Data

We use your personal and health data solely for the following purposes:

Service Delivery

• Arranging and confirming at-home phlebotomy visits

• Processing laboratory tests and delivering results

• Providing AI-assisted health analysis and recommendations

• Dispensing supplements and health products ordered through our platform

Clinical & Medical Purposes

• Generating personalised health protocols and recommendations

• Supporting doctor review and clinical oversight of your data

• Facilitating referrals to specialist practitioners (with your consent)

Communication

• Sending appointment reminders, result notifications, and health reports

• Responding to your support enquiries and chat conversations

• Sending educational health content (with your marketing consent)

Legal & Regulatory Compliance

• Maintaining health records as required by UAE health authorities

• Responding to lawful requests from DHA, MoHAP, DOH, or law enforcement

• Conducting internal audits and compliance assessments

Platform Improvement

• Anonymised and aggregated analytics to improve our services (no individual is identifiable)

• Security monitoring and fraud detection

We will never sell, rent, or trade your personal or health data to third parties for their own marketing purposes.

6. Data Sharing & Third-Party Disclosure

We share your data only in the following strictly controlled circumstances:

6.1 Accredited Laboratories

Your test samples and personal identifiers are shared with UAE-licensed diagnostic laboratories (compliant with ISO 15189 and DHA/DOH licensing requirements) solely for the purpose of processing your tests.

6.2 Licensed Healthcare Professionals

Treating physicians, functional medicine doctors, and clinical consultants engaged by GHH who are bound by professional confidentiality obligations and UAE health data law.

6.3 Payment Processors

PCI-DSS Level 1 compliant payment gateways (e.g., Paymob) for transaction processing. Card data is never stored on our servers.

6.4 Technology & Cloud Providers

Carefully vetted technology providers (e.g., cloud hosting, analytics tools) operating under strict Data Processing Agreements (DPAs) that prohibit independent use of your data.

6.5 Regulatory & Law Enforcement Authorities

MoHAP, DHA, DOH, TDRA, UAE courts, or law enforcement agencies when lawfully required.

6.6 Emergency Services

Ambulance services, hospitals, or emergency responders if your life or safety is at immediate risk.

Cross-Border Transfers: If any data is transferred outside the UAE, we ensure the recipient country provides an adequate level of protection or we apply appropriate safeguards (Standard Contractual Clauses or equivalent) as required by PDPL Article 22. We will notify you of any such transfer.

7. Data Security

We implement robust technical and organisational security measures aligned with:

ADHICS (Abu Dhabi Healthcare Information and Cyber Security Standard)

ISO/IEC 27001 Information Security Management

NIST Cybersecurity Framework

UAE Cybercrime Law – Federal Law No. 34 of 2021

Technical Safeguards

• AES-256 encryption for data at rest

• TLS 1.3 encryption for all data in transit

• Multi-factor authentication for system access

• Role-based access control — staff access only the data necessary for their function

• Regular penetration testing and vulnerability assessments

• Automated intrusion detection and real-time monitoring

Organisational Safeguards

• All staff complete mandatory health data privacy training annually

• Signed confidentiality agreements for all employees and contractors

• Formal Data Breach Response Procedure

Breach Notification: In the event of a personal data breach, we will notify the affected individuals and relevant UAE authorities (TDRA / DHA as applicable) within 72 hours of becoming aware, in line with PDPL obligations and UAE Cybercrime Law requirements.

8. Data Retention

We retain your personal data only for as long as necessary and in accordance with UAE regulatory minimums:

| Data Type | Retention Period | Authority |

|---|---|---|

| Adult health/medical records | 10 years from last contact | DHA Policy |

| Diagnostic laboratory results | 7 years | MoHAP Circular 28/2019 |

| Minor health records | Until age 28 (10 years after majority) | DHA / MoHAP |

| Financial & transaction records | 5 years | UAE VAT Law |

| Chat and AI interaction logs | 2 years (anonymised after 90 days) | Internal Policy |

| Marketing consent records | 3 years from last interaction | PDPL |

| Website technical logs | 12 months | TDRA Guidelines |

After the applicable retention period, data is securely and irreversibly deleted or anonymised in accordance with NIST SP 800-88 standards. You may request earlier deletion subject to our legal retention obligations (see Section 11).

9. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies in compliance with TDRA guidelines and UAE Electronic Transactions Law.

Types of Cookies We Use:

Strictly Necessary Cookies *(No consent required)*

Essential for the website to function — session management, security tokens, load balancing.

Functional Cookies *(Consent required)*

Remember your language preference, region, and personalisation settings.

Analytics Cookies *(Consent required)*

Anonymised usage analytics to understand how visitors interact with our site (e.g., page views, session duration). We do not link analytics data to your identity.

Marketing Cookies *(Consent required)*

Used only if you have opted in to receive personalised health content.

You may manage your cookie preferences at any time through our Cookie Preference Centre (accessible in the website footer) or through your browser settings. Withdrawing consent for non-essential cookies will not affect your ability to use our core services.

10. Your Rights Under UAE Law

Under the UAE Personal Data Protection Law (PDPL) and applicable health regulations, you have the following rights:

Right of Access (Article 7)

Request a copy of all personal data we hold about you, free of charge, within 30 days.

Right to Rectification (Article 9)

Request correction of inaccurate or incomplete personal data without undue delay.

Right to Erasure / "Right to be Forgotten" (Article 10)

Request deletion of your data where it is no longer necessary, subject to our legal health record retention obligations.

Right to Restriction of Processing (Article 11)

Request that we limit processing of your data in certain circumstances (e.g., while accuracy is disputed).

Right to Data Portability (Article 12)

Receive your personal data in a structured, machine-readable format and transfer it to another provider.

Right to Object (Article 13)

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent (Article 6)

Withdraw previously given consent at any time. Withdrawal does not affect the lawfulness of prior processing.

Right to Lodge a Complaint

You have the right to file a complaint with the UAE Data Office (the national supervisory authority under PDPL) or with DHA / MoHAP for health-specific data complaints.

How to Exercise Your Rights: Submit a written request to our DPO (details in Section 12). We will respond within 30 days. We may request identity verification before processing your request to protect your data from unauthorised access.

11. AI-Assisted Services & ChatGHH

Our AI health assistant (ChatGHH) uses Large Language Model (LLM) technology to analyse health queries and uploaded medical documents.

Important Disclosures:

ChatGHH is not a licensed medical device under UAE Federal Law No. 4 of 1983 (Medical Products Regulation). It is a health information tool and does not constitute a medical diagnosis, prescription, or clinical advice.

• All AI-generated recommendations are reviewed and overseen by licensed healthcare professionals before being communicated as clinical protocols.

• Conversations and uploaded documents shared with ChatGHH are encrypted, stored securely, and accessible only to authorised GHH clinical staff for quality assurance and medical oversight purposes.

• You may request deletion of your chat history at any time by contacting our DPO, subject to any applicable clinical record retention obligations.

• AI responses referencing supplements, peptides, IV therapies, or blood tests are educational in nature. Always consult a licensed physician before commencing any treatment.

• We do not use your identifiable health data to train external AI models without your explicit, separate consent.

12. Changes to This Policy

We review and update this Privacy Policy at least annually and whenever there are material changes to our data practices or applicable UAE law.

When we make significant changes, we will:

• Post a prominent notice on our website homepage

• Send an email notification to registered users at least 14 days before changes take effect

• Obtain fresh consent where required by law

The effective date of the current version is displayed at the top of this page. We maintain an archive of previous versions available on request.

Continued use of our services after the effective date of any update constitutes acceptance of the revised policy, except where applicable law requires explicit re-consent.

13. Contact Our Data Protection Officer

If you wish to exercise your data rights, have questions about this policy, or wish to raise a data protection concern, please contact our designated Data Protection Officer (DPO):

Email

privacy@germanhh.com

Phone

+971 54 411 9999

Address

Dubai, United Arab Emirates

Regulatory Complaints: You may also file a complaint directly with the UAE Data Office (the national data protection supervisory authority) or with Dubai Health Authority (DHA) Patient Rights Department for health-specific concerns. We encourage you to contact us first so we can resolve your concern promptly.

This Privacy Policy is governed by and construed in accordance with the laws of the United Arab Emirates. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the UAE courts.
© 2026 German Health Hub. All rights reserved.