Privacy Policy
Last updated: June 1, 2026
1. Introduction
Welcome to Wadud ("Platform", "we", "our", "us"). We are committed to protecting the privacy, confidentiality, and security of our users' ("Patient", "User", "you") personal and medical information. This Privacy Policy details how we collect, store, transmit, and protect data in compliance with standard HIPAA regulations and regional health privacy standards across Pakistan, Saudi Arabia, and the United Arab Emirates.
2. Information We Collect
To provide comprehensive telemedicine consultations, we collect several types of data:
- Personal Identity Info: Full name, date of birth, gender, location/region, email address, phone number, and ID credentials.
- Protected Health Information (PHI): Symptoms, medical histories, lab results, prescriptions, clinical notes, and video/audio consultation metadata.
- Technical/Usage Data: IP address, device type, operating system version, browser parameters, and platform interaction logs.
3. How Your Information is Secured
We deploy multiple layers of enterprise-grade security to ensure your data is secure:
- Encryption: All data in transit is encrypted using TLS 1.3, and all patient records at rest are encrypted using AES-256.
- WebRTC Streaming: Peer-to-peer video sessions are encrypted dynamically and are not recorded without explicit prior consent from both patient and doctor.
- Access Control: Only your assigned consulting healthcare professionals can access your medical records and history.
4. Sharing of Information
We will never sell or rent your personal information to third parties. We share data only:
- With your consulting doctor to enable expert healthcare diagnoses.
- With authorized diagnostic labs or pharmacy dispatchers, solely if you request a test or prescription delivery.
- When legally required by state authorities under judicial order or medical emergency regulations.
5. Your Rights
You have the right to request a full copy of your medical records, update any personal identity information, or request account closure and data deletion where legally permissible.