Privacy Policy
Patient Privacy and
Cookie Management Policy
At Aster DM healthcare, we prioritize the privacy and security of our patients and users. This Data and Cookie Policy outlines how we collect, use, store, and protect your personal information when you visit our website, interact with our services, or engage with our digital platforms.
Introduction
Our commitment to transparency and confidentiality ensures that your data is handled with the utmost care, in compliance with all relevant laws and regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR).

Content And Scope
How and when we collect your Personal Information
How we collect Personal Information
Use of Personal Information and Legal Basis for Processing of Personal Information:
Your Control over your Personal Information
Sharing and Transferring of Personal Information
Use of Cookies
Security
Third Party references and Links
Children’s Privacy
Term of storage of Personal Information
International Users and Personal Data
Modifications Of the Privacy Policy
Contact Us
Annexure 1
Content And Scope
Aster DM Healthcare and its group of companies (hereinafter referred to as “Aster DM Healthcare,” “us,” “we,” or “our”) a Free Zone Company registered with Hamriyah Free Zone Authority, Sharjah and having its communication address at Office No. 3301, 33rd Floor, Aspect Tower-D, Business Bay, PO Box 8703, Dubai, UAE registered office is the “Data Controller” in respect of your Personal Information. We are engaged in providing quality healthcare services from primary to quaternary with an extensive network of hospitals, clinics, diagnostics labs and pharmacies.
We are committed to respecting your privacy and we strive to take due care and protection of the information we possess, receive, and process regarding people associated with us (the User). In this regard, we adhere to the various governing laws, statutes, and regulations across geographies where Aster operates (refer to Annexure-1). This Privacy (“Policy”) applies to the collection, storage, processing, disclosure, and transfer of Personally Identifiable Information (defined below), particularly when you access the websites and microsites operated by Aster for any information or services (“Services”). The terms ‘you’ or ‘your’ refer to you as the User (registered or unregistered) of the website and/or Services.
Data Subject
- This Policy applies to Users as Data Subjects including but not limited to patients, job applicants, volunteers, Very Important Persons (where applicable), etc.
- Very Important persons include Senior visitors (leaders and heads of state), Foreign ministers during their visit to the UAE, Ambassadors and Delegates in the UAE, Ministers and Undersecretaries of the Ministry of the UAE, Chairmen and Undersecretaries of the government departments of the UAE, Royals and crown princes of the UAE and other Emirates including their immediate family members (wives, sons, daughters, brothers and sisters), Al Nahyan and Al Maktoum family members, Members with prefix “Sheikh” or “Sheikha” in their official identity, Members with prefix “High Excellence” or “Her Excellence” in their official identity.
- VIP Patient means A Patient identified by the ADHIE Operator as a VIP who receives or has received healthcare services in the Emirate of Abu Dhabi and in respect of whom there are increased levels of control over access to that Patient's Data.
1. How and when we collect your Personal Information
We collect your ‘Personal Information’ directly from you, from third parties and automatically through our website. This Personal Information, for instance, would include but is not limited to the type of device you are using, the time that you logged on to our website, your IP address, Cookies and other Personal Information as listed below. Personal Information means any information that relates to a natural person, which either directly or indirectly, in combination with other information available is capable of identifying such person. Personal Information shall have the meaning ascribed to “Personally Identifiable Information,” “Personal Data,” or equivalent terms as such terms are defined under Data Protection Laws. Personal Information encompasses both Sensitive Personal Data and Patient Health Information.
Information from Third-Party Services
If you access the services from an advertisement on a third-party website, application, or other service (a “Third-Party Service”) we may receive information from the owner of the Third-Party Service related to you or that advertisement.
Personal Information Collected
The kinds of information that we collect about you include but are not limited to the following:
A. If you are a Patient:
- Patient/Caregiver/Doctor/Health Care Professional Name,
- Birth date/age,
- Gender,
- Address (including country and pin/postal code),
- Phone number/mobile number,
- Email address,
- Physical, physiological, and mental health conditions, provided by you and/ or your Health Care Professional,
- Personal medical records and history,
- Valid financial information at the time of purchase of product/service and/or online payment,
- Login ID and password,
- User details as provided at the time of registration or thereafter,
- Records of interaction with Aster representatives,
- Usage details such as time, frequency, duration and pattern of use, features used and the amount of storage used,
- Master and transaction data and Email, Phone, lab reports, appointment details, order details, prescriptions, etc. stored in your User account,
- Any other information that is willingly shared by you (collectively referred to as “Personal Information”),
- Biometrics data,
- Genetic Data,
- Transgender Status,
- Intersex Status,
- Caste or Tribe,
- Religious or political belief or affiliation
- Sexual orientation,
- Marital status,
- Citizenship status,
- Family Personal Information (as the need may be) (collectively referred to as “Sensitive Personal Information”).
- Login and authentication information
- Online profile information
- Online activity
- Purchasing information
- Payment information, methods, and history
- Information about the device(s) you use
- Information about service usage
B. If you are a job applicant
- Name or alias,
- Gender,
- Passport number,
- Government IDs such as Emirates ID,
- Date of birth,
- Age,
- Nationality,
- Country and city of birth,
- Photographs,
- Mailing address,
- Telephone numbers,
- Email address and other contact details,
- Resume,
- Educational qualifications,
- Professional qualifications and certifications
- Employment and/or character references,
- Employment and training history,
- Criminal records,
- Details related to credentialing and privileging for doctors, nursing staff and pharmacists,
- Work-related health issues and disabilities,
- List of qualified dependents(s) including their pertinent information
- Family background for your next-of-kin and list of qualified dependent/s including their pertinent information,
- Results of exams and other diagnostic test/s for aptitude, IQ, behaviour, DHA /MOH eligibility (for GCC) etc.
C. If you are an Employee
- Name
- Age
- Date of Birth
- Gender
- Address (Including country and pin/postal code)
- Phone number/mobile number
- Email address
- Physical, physiological, and mental health conditions, provided by you and/ or your Health Care Professional, Prescriptions
- Health data, Personal medical records, Diagnostic reports and medical history
- Login ID and password
- Usage details such as time, frequency, duration and pattern of use, features used and the amount of storage used
- Biometrics data
- Transgender Status
- Caste or Tribe
- Sexual orientation
- Religion
- Marital status
- Citizenship status
- Family Personal Information
- Passport details
- Emirates ID and other Govt. ID
- Photographs, videography and digital images
- Resume
- Criminal Records
- Work-related health issues and disabilities
- UHDI
- Insurance details, Previous insurer and policy expiry date, Details of critical illness of employee and family members, if included in insurance, prescriptions, personal medical records and history.
- Tax details
- Employee identification number
- Details of educational qualifications, qualification country, professional qualifications, certifications, current or previous employer full name.
D. If you are a student or enrolled on any of the training programs run by Aster Group/ Aster Academy:
1. Information you provide during your application for admission:
- Personal contact information such as name, email address, telephone number, and other contact details
- Academic qualifications
- Performance, etc.
2. Information we acquire or generate upon enrollment and during your association with us:
- Academic or curricular undertakings
- Enrolled classes and scholastic performance
- Attendance record
- Co-curricular and extra-curricular activities
E. If you are CSR volunteers:
- Name
- Email ID
- Government ID
- Phone number.
- Address
- Date of Birth
F. If you are a Director or Shareholder:
- Personally Identifiable Information or Personal Data: Name, surname, address, telephone number, email address, date of birth, taxpayer identification number, national identification number.
- Financial information: Bank account details, shareholder registration number, number of shares.
- Health information: Health information relevant to the activities you attend, including food allergies and drug allergy information.
- CCTV Recording: Video recording by means of closed-circuit television (CCTV) for security purposes.
- Payment Information: Information related to payments, such as account numbers.
What does not include Personal Information?
- De-identified or anonymized information (i.e., information about you where information that can be used to identify an individual has been removed permanently).
- Aggregated consumer information (i.e., information taken from many people’s data and combined into anonymous groups or categories).
- General business contact information that does not identify an individual.
- The Personal Data you share voluntarily.
2. How we collect Personal Information
The methods by which we collect your Personal Information include but are not limited to the following:
- When you fill out the patient registration form,
- When you provide details to an Aster Health Care Professional or Aster representative,
- When you register on our website, use our App, or our Chatbot,
- When you provide your Personal Information to us during the course of receiving our Services,
- When you visit our facilities, via CCTVs.
- When you apply for a job using our job portal,
- When you use the features on our website,
- When you provide access to any other website,
- By the use of cookies (more fully detailed in Section 6 of this Policy).
3. Use of Personal Information and Legal Basis for Processing of Personal Information:
Your Personal Information may be used or processed for various purposes including but not limited to the following:
- To provide effective Services,
- To operate and improve the website and/or our Services,
- To perform studies, research, and analysis for improving our information, Services, and technologies and ensuring that the content displayed is customized to your interests and preferences,
- To contact you via phone, SMS, WhatsApp or email for appointments, technical issues, payment reminders, deals and offers and other announcements,
- To offer you medical tourism and other services via email and mobile number and via using SMS and WhatsApp.
- To send promotional communications via SMS, WhatsApp, email, and other channels, and to support related services such as customer support, marketing, analytics, advertising, and performance tracking etc.
- To carry out insurance-related purposes, including claims processing, verification, and billing,
- To advertise the products and Services of Aster and its third parties,
- To transfer information about you if we are acquired by or merged with another company,
- To share with our business partners for provision of specific Services you have ordered so as to enable them to provide effective Services to you,
- To administer or otherwise carry out our obligations in relation to any agreement you have with us,
- To build your profile on our website,
- To respond to subpoenas, court orders, or legal processes, or to establish or exercise our legal rights or defend against legal claims; and
- To investigate, prevent, or act regarding illegal activities, suspected fraud, violations of our terms of use, Breach of our agreement with you or as otherwise required by law,
- To aggregate Personal Information for research, statistical analysis, and business intelligence purposes, or otherwise transfer such research, statistical or intelligence data in an aggregated or non-personally identifiable form to third parties and affiliates, (referred to as “Purpose(s)”).
If you are a job applicant, your Personal Data will be collected and used by the Company for the following purposes, and we may disclose your Personal Data to third parties where necessary for the following purposes:
- Assessing and evaluating your suitability for employment in any current or prospective position within the organization; and
- Verifying your identity and the accuracy of your personal details and other information provided.
Legal Basis Processing of Your Personal Information
We will only process your Personal Information where we have a legal basis to do so. The legal basis will depend on the purposes for which we have collected and use your Personal Information. In almost every case, the legal basis will be one of the following:
- Consent: For example, where you have provided your Consent to receive certain marketing/promotional messages from us or where you have provided your explicit Consent for us to process your data during live telemedicine consultation services under tele-Medcare.
- Our legitimate interest: Where it is necessary for us to understand our customers, promote our services, and effectively provide services, provided in each case that this is done in a legitimate way that does not duly affect your privacy and other rights.
- Compliance with law/agreement: Where we are subject to a legal obligation and need to use your Personal Information in order to comply with that obligation. For example, when you may purchase products/services from us, or book appointments we need to use your contact details and payment information in order to process your order.
- Vital Interests: In some limited cases, we may need to process your Personal Information where it is necessary to protect your vital interests or the vital interests of another person.
We will always take steps to ensure that the processing of your Personal Information is fair and lawful and that it does not unduly affect your privacy.
Purpose Mapping
Purpose | Details | Legal Basis | Special Category |
To set you up as a patient and process your data in Aster Healthcare Group’s systems | We use your Personal Data to create a Medical Record within our systems in which we will hold your medical history. We also use it to establish your identity and the method you will use to pay for the services that we provide you with (i.e., via your insurance provider, cash, or some other means) | Contract We need to use your Personal Data to take steps so that you can enter a contract with us and/or healthcare. Providing Personal Data is a requirement to enter a contract. Failure to provide Personal Data would prevent us from entering a contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
To provide you with healthcare and related services | This is the primary reason you are likely to visit any of our facilities or use our services. We will therefore process your personal and health data for that and related purposes. We may also need to carry out diagnostic tests or imaging procedures, some of which may be conducted within the facility you visit while others may be conducted at other Aster DM Healthcare Group facilities or by specially vetted third parties in compliance with local regulations. This means that some of your data might need to be shared with other hospitals within the Aster DM Healthcare group or other third parties. | Contract We need to process your health information to perform our healthcare contract with you. You are required to provide Personal Data to perform our contract with you. If you do not provide us with your Personal Data, we will be unable to perform our contract with you. | Health Purposes Processing is necessary for health purposes |
To provide you with medical services in cases of emergency | Where there is a risk to your life or other consequences may occur that would cause you great harm, we need to process personal and health data to protect your vital interests. Sometimes, we need to share your data with third parties in order the achieve that. | Vital Interests We may also need to process your health information to protect your vital health interests for instance, in life-threatening emergencies.
| Vital Interests Processing is necessary to protect the vital interests of the Data Subject or of another natural person where the Data Subject is physically or legally incapable of giving Consent |
To settle your account | We will use your personal and health data to ensure that your account and billing are fully accurate and up to date. This may include sharing your Personal Information with your health insurance provider or employer both before and after you receive treatment at any of our healthcare facilities. | Contract We need to process your personal and health information to perform our healthcare contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. |
For internal or government clinical audits related to our Entities in the UAE | We may share your Personal Data with government auditors, Clinical Outcome Review Programmes and other government-led quality improvement projects. We may also share your Personal Data with other audit programmes set up by clinical standards accreditation bodies such as Joint Commission International. | Legal obligation To comply with our regulatory or legal obligations. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
For internal or government clinical audits at our hospitals outside of the UAE. | We may share your Personal Data with government auditors, Clinical Outcome Review Programmes and other government-led quality improvement projects. We may also share your Personal Data with other audit programmes set up by clinical standards accreditation bodies such as Joint Commission International. | Legitimate Interest To make improvements to our procedures and practices provided that we have put appropriate safeguards in place to protect your privacy so that this use does not override your interests unduly. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Public Interests Processing is necessary for reasons of public interest in the area of public health to ensure continued high standards of quality and safe health care, of medicinal products or medical devices. |
Contacting you and resolving queries or complaints | There may be times when you raise queries, or even complaints, with us. We take those communications very seriously and will usually need to use your Personal Data to resolve them fully. | Legitimate Interests It is in our interest to improve our standards of care, and service delivery, in any other way that will benefit our patients and other stakeholders provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Pubic interest processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Providing you with service information | We will use the contact information you have given us to get in touch and remind you about appointments you have booked with us, to inform you about test results, or to otherwise follow up with you about an appointment you have attended with us. We will generally do this by telephone, SMS, email or by messenger app (such as WhatsApp). | Contract In order to fulfil our contractual obligations, we need to process Personal Data to fulfil our contractual obligations. Providing Personal Data is a contractual requirement. Failure to do so might prevent us from performing our contract with you. In order to provide you medical tourism facility. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
Medical research | We also participate in medical research and may share Personal Data government-approved research projects. | Consent We will obtain your Consent before using your Personal Data for any medical research purposes to bring healthcare improvements to the public. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section "Data Subject Rights" and "Right to object" and the "Right to Withdraw Your Consent" in this Privacy Policy for more information. |
Medical research where your Consent has not been obtained | We also participate in medical research and may share Personal Data with government approved research projects where allowed by regulatory bodies in the country. | Legitimate Interest It is in our legitimate interest to process Personal Data obtained from you for medical research purposes and share with government approved research projects where allowed by regulators provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Research Purposes Processing is necessary for Archiving and Research Purposes in accordance with Applicable Law |
Research and publication | We conduct research and publish results of the research in our magazine. | Consent We will obtain your Consent before using your Personal Data for any research and publication purposes to bring healthcare improvements to the public. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section "Data Subject Rights" and "Right to object" and the "Right to Withdraw Your Consent" in this Privacy Policy for more information. |
Grievance redressal | In order to redress complains and grievances and resolve escalations on the internet we would need to process your Personal Data. | Legitimate Interest It is in our legitimate interest to process Personal Data obtained from you while listing complains against Aster DM Healthcare on the Internet. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information | |
Clinical referrals | In order to provide you with comprehensive and high-quality health care, it may be necessary to refer your clinical case to other healthcare professionals at other facilities within the Aster DM Healthcare Group. In rare instances, it may also be necessary to refer your case outside of our network. | Contract We need to process your health information to perform our healthcare contract with you and fulfil your request. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
Patient transfer | In order to continue your treatment, we may need to transfer you to another health care facility in the country. | Contract We need to process your personal and health information in order to fulfil our contract with you and transfer you to another facility where you can continue your treatment | Health Purposes Processing is necessary for health purposes. |
Patient transfer at your request | To continue your treatment at another facility or in another country at your request | Contract We need to process your personal and health information in order to fulfil the contract with you and transfer you to another facility where you can continue the treatment | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Patient transfer when there is insufficient insurance coverage or where your treatment cannot be continued at our facility | To protect your life, we may need to transfer you to another healthcare facility outside the country. By doing so we have to communicate your personal and health data to third parties. The healthcare facility outside the country. | Vital Interests We need to process your personal and health information to protect your vital health interests for instance, in life threatening emergencies. | Vital Interests Processing is necessary to protect vital interests of the Data Subject or of another natural person where the Data Subject is physically or legally incapable of giving Consent |
Providing improved quality services | We take measures to continually improve the quality of the services we provide. This includes monitoring or recording telephone calls to our contact numbers for training and security purposes and conducting pre and post treatment surveys. | Legitimate Interests It is within our legitimate business interests to take measures to improve the quality and efficiency of the services we provide to you provided that our interests are not overridden by your interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Public Interests Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Recruiting new staff | We will process your Personal Data if you apply for a job at Aster DM Healthcare Group. This includes all phases of the recruitment process including shortlisting, assessment, and interview, and offers of a position made to successful candidates. | Contract We need to process your Personal Data to take steps to enter into a contract of employment with you. | |
Recruiting new staff: processing your application | We may use external vendors to facilitate the recruitment of candidates | Legitimate Interests It is within our legitimate business interests to employ increasingly efficient processes and technology when searching for and assessing new talent to join our business provided that our interests are not overridden by your interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
Vetting and onboarding candidates | Aster DM Healthcare may use external vendors to conduct appropriate due diligence to ensure that we know who are we Hering. | Legitimate Interests It is in our legitimate business interest to use your Personal Data to conduct proper due diligence before we engage you as an employee, provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
Marketing | We may use your Personal Data to bring information about our services and products. This may include contact information you have given us to contact you by phone, by email, SMS, or other messaging platform you agree to. | Consent We will only contact you if you Consent to us doing so and have not withdrawn that Consent. You can withdraw your Consent at any time. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section Your Rights, Right to Object to How We Use Your Personal Information for Direct Marketing Purposes and the Right to Withdraw Your Consent for more information. |
Law enforcement requests | There may be times when we are required to provide the Personal Data of our patients or employees to law enforcement agencies such as the police, public health authorities and others. We will cooperate with these agencies when we receive such requests. | Legal Obligation In these situations, we are compelled to process your Personal Data to comply with a legal obligation to which we are subject. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
Appointment bookings | In order for us to book your appointment we must process your personal and health information. | Contract We must process your Personal Information to enter a contract with you if you are our new patient or fulfil our contractual obligations if you are our existing patient. You are required to provide Personal Data in order to enter or perform our contract with you. If you do not provide us with your Personal Data, we will be unable to perform our contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Vetting and onboarding new business partners and vendors | Before engaging with new suppliers, vendors, or business partners, it is Aster DM Healthcare Group’s policy to conduct appropriate due diligence to ensure that we know who we are doing business with. These checks may require us to process Personal Data belonging to board directors, officers or other employees of these companies or organisations. | Legitimate Interests It is in our legitimate business interest to use your Personal Data to conduct proper due diligence before we engage in any business venture with you or your organisation, provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
CCTV Recordings | Storing and reviewing CCTV images is necessary to maintain our facilities safe. | Legal Obligation To comply with our legal and regulatory obligations to maintain safe and secure premises for visitors to our premises and our employees. | |
Processing for financial and accounting purposes | Analysis of financial results, internal and external audit requirements, receiving professional advice (e.g., tax, financial, legal, or public relations advice) | Legitimate Interests It is in our legitimate business interest to use your Personal Data conduct to, where necessary, conduct internal audits, consult with public relations experts and other experts to maintain efficient and effective operations, provided that these interests are not overridden by your own interests. | Public Interest Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Managing our accounting records | We need to maintain our accounting records | Legal Obligation To comply with relevant financial accounting and tax requirements. | |
Keeping your records | We need to keep your medical records to comply with relevant laws | Legal Obligation To comply with laws regulating the duration of storage of medical records. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law. |
Incident Reporting | You can always reach out to Aster DM Healthcare and report a complaint | Legitimate Interest It is in our legitimate interest to know about incidents that happen within our hospitals provided that these interests are not overridden by your own interests. | Public Interest Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Communicating with embassies and agencies about your treatment | Sometimes Aster DM Healthcare will need to communicate with your home country’s embassy or an agency about your treatment. | Contract We need to process your personal and health data to enter a contract with you | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Occupational health | We need to process your Personal Information in order to assess your work capacity, whether you can perform the specific work or perform other employment related health service | Contract We need to process your personal and health data to perform our healthcare contract with you and provide you with requested services | Health Purposes Processing is necessary for health purposes, including preventative or occupational medicine, the assessment of the working capacity of an employee, medical diagnosis, the provision of health care or treatment or the management of health care systems or services or pursuant to a contract with a health professional provided that Processing is by or under the responsibility of a health professional subject to the obligation of professional secrecy or duty of confidentiality |
Sharing your data with Health Information Exchange in Dubai, Sharjah, Ras Al Khaimah, Umm Al Quwain, Fujairah | Where you give us your Consent, we can share your personal and health information with the Health Information Exchange. By doing so all healthcare providers involved in your treatment can access your information. | Consent Please note that for us to share your personal and health data with HIE systems in Dubai, Sharjah, Ras Al Khaimah, Umm Al Quwain, Fujairah, we need your Consent. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section Data Subject Rights, and Right to Object in this Privacy Policy for more information.
|
Sharing your data with Governmental Authorities | We need to process and share your Personal Data and Patient Health Data with relevant government authorities. | Legal Obligation We need to share your Personal Data with Government Authorities as a legal requirement. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law. |
Sharing your data with NABIDH, RIAYATI, MALAFFI and any other Health Information Exchange | Where you give us your Consent, we can share your personal and health information with the Health Information Exchange. By doing so all healthcare providers involved in your treatment can access your information. However, even if we do not receive your Consent, we must share your personal and health information with NABIDH, RIAYATI and MALAFFI. | Legal Obligation We need to share your Personal Data with Health Information Exchange platform as a legal requirement. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
Processing for delivery of medicines | We may share your Personal Data with to process your request for deliver medicines. | Contract We need to process your personal and health data, in some cases to perform our contract with you. |
4. Your Control over your Personal Information
We will respect your legal rights in relation to your Personal Data. Aster is committed to protecting them and ensuring compliance if you wish to exercise any of the rights under the respective privacy laws. You must submit the Data Subject Request through email at [email protected] and fill the Data Subject Request Form (link to be added here). The request will be processes in accordance with the Aster’s Data Subject Rights Procedure.
Please note that if as per regulation it is required to pay a reasonable fee for an access request, we will inform you of the fee before processing your request.
We will respond to your request as soon as reasonably possible and/or as per the applicable timeframes laid down by the respective privacy laws/regulations. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing of the same as soon as practically possible.
Please note that depending on the request that is being made, we will only need to provide you with access to the Personal Information contained in the documents requested, and not to the entire documents themselves. For example, the Company may not be obliged to provide the employee with access to the disciplinary records, investigation reports, or decisions to terminate, that the organization has created for evaluative and/or investigative purposes of the employee.
You have the right to withdraw your Consent at any point, provided such withdrawal of the Consent is intimated to us in writing through an email at [email protected] requesting the same. Once you withdraw your Consent to share the Personal Information collected by us, we shall have the option not to fulfil the purposes for which the said Personal Information was sought, and we may restrict you from using our Services or the website or parts of it as the case may be.
Data Subject Rights
Rights | UAE | Saudi Arabia | Oman | Qatar | Bahrain | Jordan | India |
Right to Obtain Information: Request for clear & concise information about the processing of their Personal Data. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Data Portability: Request to receive their Personal Data in a structured, machine-readable format and transfer it to another controller if feasible. | ῼ | 🗶 | ῼ | 🗶 | 🗶 | ῼ |
🗶 |
Right to Rectification and Erasure: Request to correct, rectify, or erase Personal Data. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Restrict Processing: Request restrictions on Processing, especially when contesting the accuracy of the Personal Data. | ῼ | 🗶 | 🗶 | 🗶 | 🗶 | ῼ | 🗶 |
Right to Object: Request to object to the processing of Personal Data | ῼ | 🗶 | 🗶 | ῼ | ῼ | ῼ | 🗶 |
Right to Stop Processing: Request to stop Processing, especially for direct marketing, profiling, or statistical surveys. | ῼ | ῼ | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 |
Right to Withdraw Consent: Request to withdraw consent for specific Processing activities. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Object to Automated Decision Making: Request to object to decisions based solely on automated Processing, unless necessarily required. | ῼ | 🗶 | 🗶 | 🗶 | ῼ | ῼ | 🗶 |
Right to be Notified of any Data Breach: Right to be informed of any Breaches affecting their Personal Data. | 🗶 | 🗶 | ῼ | 🗶 | 🗶 | ῼ | 🗶 |
Right to Nominate: Right to nominate someone else to exercise their data rights in case of incapacity or death. | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | ῼ |
Right to Grievance Redressal: Right to lodge a complaint and seek resolution for grievances related to their Personal Data Processing. |
ῼ | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | ῼ |
Withdrawing Consent:
- The Consent that you provide for the collection, use and disclosure of your Personal Information will remain valid until such time it is withdrawn by you by submitting your request in writing or via email to [email protected] or in accordance with the applicable legal requirements.
- Upon receipt of your written request to withdraw Consent, we may require a reasonable period of time to process your request subject to applicable governing laws, statutes, and regulations. We will notify you of any consequences of granting your request, including any legal implications that may affect your rights and obligations with respect to us.
- While we respect your decision to withdraw Consent, please be advised that, depending on the nature and scope of your request, we may be unable to process your request subject to applicable governing laws, statutes, and regulations. In such instances, we will notify you prior to completing the processing of your request, as outlined above.
- Please note that withdrawing Consent does not affect our right to continue collecting, using, and disclosing your Personal Information where such activities are permitted or required under applicable laws, even without Consent.
Exceptions where Data Subject Requests can be denied
Where any request is refused by DPO/Designated Team in accordance with the internal Data Subject Rights Procedure, it shall provide the Data Subject the reasons in writing for such refusal and shall inform the Data Subject regarding the right to file a complaint with the Authority against the refusal, within such period and in such manner as may be specified by regulations.
5. Sharing and Transferring of Personal Information
Aster complies with applicable laws and take necessary precautions before sharing your data. Aster enters into data-sharing agreements, implementing technical and organizational safeguards, ensuring transferees adhere to this policy. Additionally, we assess the data protection standards of any country before sharing your Personal Data with cloud providers, affiliates, agents, third-party service providers, partners, authorities, banks, or financial institutions.
By Consenting to share your Personal Data, you authorize Aster to transfer or share it across borders with cloud providers, affiliates, agents, insurance providers, third-party service providers, partners, authorities, banks, financial institutions, or for marketing purposes, as necessary to provide services or in compliance with applicable laws.
We may share your information with authorized third-party vendors and service providers that help us with specialized services, including customer service, email deployment, business analytics, marketing (including but not limited to advertising, attribution, deep-linking, direct mail, mobile marketing, optimization and retargeting) advertising, performance monitoring, hosting, and data processing. These authorized third-party vendors are subject to risk assessment test and will not use your information for purposes other than those related to the services they are providing to us. All such data sharing is conducted in accordance with applicable data localization requirements, security protocols, and applicable regulatory standards.
If you choose to engage in public activities on the third-party sites that we link to, you should be aware that any information you share there can be read, collected, or used by other users of these sites and forums. You should use caution in disclosing personal information while participating in these areas. We are not responsible for the information you choose to submit in public areas.
Please note that, in line with regulatory requirements and basis your consent, all health-related data is securely shared with government-mandated Health Information Exchanges (HIEs) such as NABIDH, RIAYATI, MALAFFI, and other applicable platforms to support better care coordination and public health outcomes.
Aster adheres to data localization principles where required by law, ensuring Personal Data is stored within the same jurisdiction as it is collected. However, in certain cases—such as with Patient Health Information where authorized by the User or with approval from relevant health authorities—data may be transferred outside the jurisdiction.
A Data Processor shall only disclose the Personal Data to a Third Party on documented instructions from the Data Controller. The Federal Law No. 2 of 2019 (Health Data Law) by default prohibits the transfer, storage, generation or processing of Patient Health Information that relates to health services. The UAE's Ministry of Health and Prevention (MoHAP) Resolution 51/2021 relaxed the relaxes the data transfer restriction for certain types of processing operation, namely.
- Overseas treatment
- Medical testing
- Scientific research
- Insurance claims and coverage
- Organisations cooperating with the UAE Government or its institutions
- Wearables and healthcare monitoring devices
- Pharmacovigilance reporting
- Data approved by a health authority
- Telemedicine
- Formal request
Exceptions
There are certain exceptions under which Patient Health Information can be transferred or shared outside the country of collection, by virtue of a decision issued by the Federal or local governmental Health authority in the State and after getting approval from the Dubai Health Authority or any other Authority wherever applicable. Such exceptions include, but are not limited to:
- Matters of public interest
- Information that is already publicly available
- Medical diagnosis, the provision of healthcare or social care, treatment, or health insurance services
- Protection of the Data Subject’s vital interests
- Compliance with legal obligations or the exercise of established rights in the areas of employment, social security, or social protection laws, as permitted under applicable legislation
- Establishment, exercise, or defense of legal claims, including international judicial cooperation
- Execution of a contract that serves the Data Subject’s interests.
6. Use of Cookies
- Cookies are small bits of data cached in a user’s browser. Aster utilises cookies to determine whether or not you have visited the home page in the past. However, no other user information is gathered. Aster may use non-personal "aggregated data" to enhance the operation of our website or analyse interest in the areas of our website.
- If you would like to find out more about cookies, including how we use them and what choices are available to you, please refer to our Cookie Policy.
- You may also be able to control or limit the collection of this technical data through your browser or device settings.
7. Security
The security of your Personal Information is important to us. We have adopted and maintained reasonable technical and organizational security measures and procedures including rigorous third-party risk assessments, strong access controls and information sharing on a need-to-know basis, encryption of Personal Data, secure storage of Personal Data, rapid data Breach management procedures, etc. to ensure that the Personal Information collected is secure at rest and in transit. We restrict access to your Personal Information to our and our affiliates’ employees, agents, third-party service providers, partners, and agencies on a need-to-know basis and absolutely limited to the purposes as specified above in this Policy.
8. Third Party references and Links
- During Your interactions with us, it may happen that we provide/include reference to third parties or fiduciaries, and/or links and hyperlinks to third-party websites. It may also happen that you include links and hyperlinks to third-party websites. The reference of such third parties or listing of such third-party external sites (by you or by us) does not imply endorsement of such party or site by Aster. Such third parties and third-party sites are governed by their own terms and conditions and have their own privacy Policies. We do not make any representations regarding the availability and performance of any of the third parties or third-party sites. We are not responsible for the content, terms of use, privacy policies and practices of such third-party websites.
- Do-not-track requests: There is no standard for how online service should respond to “Do Not Track” signals or other mechanisms that may allow you to opt out of the collection of information across networks of websites and online Services. Therefore, we do not honor “Do Not Track” signals. As standards develop, we will revisit this issue and update this Policy if our practices change.
9. Children’s Privacy
We understand the importance of taking extra precautions to protect the privacy and safety of children using our website or Services. Minors are not permitted to use the website or services, and we request that minors under the age of 18 not submit any Personal Information to the website. Since information regarding minors under the age of 18 is not collected, we do not knowingly distribute Personal Information regarding minors under the age of 18. By accessing this website, you affirm and guarantee that you are 18 years of age or older.
We hold no liability for any unsolicited information provided by you, and you Consent to the usage of such information in accordance with this Privacy Policy. If we become aware that a person submitting Personal Data is under 18, we will delete all the information as soon as possible unless it is with the Consent and involvement of a parent or guardian. If you believe we might have any information from or about a child under 18, please contact us at email lD: [email protected]
10. Term of storage of Personal Information
Aster will retain your personal information for as long as necessary, in accordance with the required timeframe and in compliance with the internal data retention policy.
11. International Users and Personal Data
We welcome users from around the world and are committed to respecting their privacy. We encourage them to visit Aster Medical Travel on (https://astermedicaltravel.ae) for more details on how we handle their Personal Data.
12. Modifications Of the Privacy Policy
We reserve the right to change this Policy from time to time to meet the requirements and standards. We will not reduce your rights under this Policy without your explicit Consent. If changes are significant, we will provide a more prominent notice (including, for certain Services, email notification of Policy changes). Therefore, customers are encouraged to frequently visit these sections in order to be updated about the changes on the website.
Modifications will be effective on the day they are posted and the date of this Privacy Policy of when it was last updated will appear at the top of this document
13. Contact Us
If you have any questions regarding this Privacy Notice, you may contact our Group Data Protection Officer:
DPO Details: [email protected]
Contact No.- +971565037221
Or you can write to us/post at:
The Data Protection Officer,
Aster DM Healthcare Limited.
Official Address: 33rd Floor - Aspect Tower, Business Bay, P.O. Box: 8703 - Dubai - U.A.E
If you have any questions, concerns, or complaints regarding our compliance with the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us. We will investigate and attempt to resolve complaints and disputes and will make every reasonable effort to honour your wish to exercise your rights as quickly as possible and, in any event, within the timescales provided by data protection laws.
Annexure 1
S. No. | Applicable Laws |
1. | UAE Regulations:
|
2. | Kingdom of Saudi Arabia Personal Data Protection Law (Cabinet Decision No. 98/1443) Implementing Regulations:
|
3. | Oman Personal Data Protection Law (Oman Sultani Decree No. 6/2022) Implementing Regulations:
|
4. | Bahrain Personal Data Protection Law (Law No. (30) of 2018) Implementing Regulations:
|
5. | Qatar Personal Data Privacy Protection Law (Law no. 13 of 2016) Guidelines: Controller and Processor, National Cyber Security Agency |
6. | Jordan Personal Data Protection Law (No. (24) of 2023) |
7. | Indian Digital Personal Data Protection Act, 2023 |
How and when we collect your Personal Information
We collect your ‘Personal Information’ directly from you, from third parties and automatically through our website. This Personal Information, for instance, would include but is not limited to the type of device you are using, the time that you logged on to our website, your IP address, Cookies and other Personal Information as listed below. Personal Information means any information that relates to a natural person, which either directly or indirectly, in combination with other information available is capable of identifying such person. Personal Information shall have the meaning ascribed to “Personally Identifiable Information,” “Personal Data,” or equivalent terms as such terms are defined under Data Protection Laws. Personal Information encompasses both Sensitive Personal Data and Patient Health Information.
Information from Third-Party Services
If you access the services from an advertisement on a third-party website, application, or other service (a “Third-Party Service”) we may receive information from the owner of the Third-Party Service related to you or that advertisement.
Personal Information Collected
The kinds of information that we collect about you include but are not limited to the following:
A. If you are a Patient:
- Patient/Caregiver/Doctor/Health Care Professional Name,
- Birth date/age,
- Gender,
- Address (including country and pin/postal code),
- Phone number/mobile number,
- Email address,
- Physical, physiological, and mental health conditions, provided by you and/ or your Health Care Professional,
- Personal medical records and history,
- Valid financial information at the time of purchase of product/service and/or online payment,
- Login ID and password,
- User details as provided at the time of registration or thereafter,
- Records of interaction with Aster representatives,
- Usage details such as time, frequency, duration and pattern of use, features used and the amount of storage used,
- Master and transaction data and Email, Phone, lab reports, appointment details, order details, prescriptions, etc. stored in your User account,
- Any other information that is willingly shared by you (collectively referred to as “Personal Information”),
- Biometrics data,
- Genetic Data,
- Transgender Status,
- Intersex Status,
- Caste or Tribe,
- Religious or political belief or affiliation
- Sexual orientation,
- Marital status,
- Citizenship status,
- Family Personal Information (as the need may be) (collectively referred to as “Sensitive Personal Information”).
- Login and authentication information
- Online profile information
- Online activity
- Purchasing information
- Payment information, methods, and history
- Information about the device(s) you use
- Information about service usage
B. If you are a job applicant
- Name or alias,
- Gender,
- Passport number,
- Government IDs such as Emirates ID,
- Date of birth,
- Age,
- Nationality,
- Country and city of birth,
- Photographs,
- Mailing address,
- Telephone numbers,
- Email address and other contact details,
- Resume,
- Educational qualifications,
- Professional qualifications and certifications
- Employment and/or character references,
- Employment and training history,
- Criminal records,
- Details related to credentialing and privileging for doctors, nursing staff and pharmacists,
- Work-related health issues and disabilities,
- List of qualified dependents(s) including their pertinent information
- Family background for your next-of-kin and list of qualified dependent/s including their pertinent information,
- Results of exams and other diagnostic test/s for aptitude, IQ, behaviour, DHA /MOH eligibility (for GCC) etc.
C. If you are an Employee
- Name
- Age
- Date of Birth
- Gender
- Address (Including country and pin/postal code)
- Phone number/mobile number
- Email address
- Physical, physiological, and mental health conditions, provided by you and/ or your Health Care Professional, Prescriptions
- Health data, Personal medical records, Diagnostic reports and medical history
- Login ID and password
- Usage details such as time, frequency, duration and pattern of use, features used and the amount of storage used
- Biometrics data
- Transgender Status
- Caste or Tribe
- Sexual orientation
- Religion
- Marital status
- Citizenship status
- Family Personal Information
- Passport details
- Emirates ID and other Govt. ID
- Photographs, videography and digital images
- Resume
- Criminal Records
- Work-related health issues and disabilities
- UHDI
- Insurance details, Previous insurer and policy expiry date, Details of critical illness of employee and family members, if included in insurance, prescriptions, personal medical records and history.
- Tax details
- Employee identification number
- Details of educational qualifications, qualification country, professional qualifications, certifications, current or previous employer full name.
D. If you are a student or enrolled on any of the training programs run by Aster Group/ Aster Academy:
1. Information you provide during your application for admission:
- Personal contact information such as name, email address, telephone number, and other contact details
- Academic qualifications
- Performance, etc.
2. Information we acquire or generate upon enrollment and during your association with us:
- Academic or curricular undertakings
- Enrolled classes and scholastic performance
- Attendance record
- Co-curricular and extra-curricular activities
E. If you are CSR volunteers:
- Name
- Email ID
- Government ID
- Phone number.
- Address
- Date of Birth
F. If you are a Director or Shareholder:
- Personally Identifiable Information or Personal Data: Name, surname, address, telephone number, email address, date of birth, taxpayer identification number, national identification number.
- Financial information: Bank account details, shareholder registration number, number of shares.
- Health information: Health information relevant to the activities you attend, including food allergies and drug allergy information.
- CCTV Recording: Video recording by means of closed-circuit television (CCTV) for security purposes.
- Payment Information: Information related to payments, such as account numbers.
What does not include Personal Information?
- De-identified or anonymized information (i.e., information about you where information that can be used to identify an individual has been removed permanently).
- Aggregated consumer information (i.e., information taken from many people’s data and combined into anonymous groups or categories).
- General business contact information that does not identify an individual.
- The Personal Data you share voluntarily.
How we collect Personal Information
The methods by which we collect your Personal Information include but are not limited to the following:
- When you fill out the patient registration form,
- When you provide details to an Aster Health Care Professional or Aster representative,
- When you register on our website, use our App, or our Chatbot,
- When you provide your Personal Information to us during the course of receiving our Services,
- When you visit our facilities, via CCTVs.
- When you apply for a job using our job portal,
- When you use the features on our website,
- When you provide access to any other website,
- By the use of cookies (more fully detailed in Section 6 of this Policy).
Use of Personal Information and Legal Basis for Processing of Personal Information:
Your Personal Information may be used or processed for various purposes including but not limited to the following:
- To provide effective Services,
- To operate and improve the website and/or our Services,
- To perform studies, research, and analysis for improving our information, Services, and technologies and ensuring that the content displayed is customized to your interests and preferences,
- To contact you via phone, SMS, WhatsApp or email for appointments, technical issues, payment reminders, deals and offers and other announcements,
- To offer you medical tourism and other services via email and mobile number and via using SMS and WhatsApp.
- To send promotional communications via SMS, WhatsApp, email, and other channels, and to support related services such as customer support, marketing, analytics, advertising, and performance tracking etc.
- To carry out insurance-related purposes, including claims processing, verification, and billing,
- To advertise the products and Services of Aster and its third parties,
- To transfer information about you if we are acquired by or merged with another company,
- To share with our business partners for provision of specific Services you have ordered so as to enable them to provide effective Services to you,
- To administer or otherwise carry out our obligations in relation to any agreement you have with us,
- To build your profile on our website,
- To respond to subpoenas, court orders, or legal processes, or to establish or exercise our legal rights or defend against legal claims; and
- To investigate, prevent, or act regarding illegal activities, suspected fraud, violations of our terms of use, Breach of our agreement with you or as otherwise required by law,
- To aggregate Personal Information for research, statistical analysis, and business intelligence purposes, or otherwise transfer such research, statistical or intelligence data in an aggregated or non-personally identifiable form to third parties and affiliates, (referred to as “Purpose(s)”).
If you are a job applicant, your Personal Data will be collected and used by the Company for the following purposes, and we may disclose your Personal Data to third parties where necessary for the following purposes:
- Assessing and evaluating your suitability for employment in any current or prospective position within the organization; and
- Verifying your identity and the accuracy of your personal details and other information provided.
Legal Basis Processing of Your Personal Information
We will only process your Personal Information where we have a legal basis to do so. The legal basis will depend on the purposes for which we have collected and use your Personal Information. In almost every case, the legal basis will be one of the following:
- Consent: For example, where you have provided your Consent to receive certain marketing/promotional messages from us or where you have provided your explicit Consent for us to process your data during live telemedicine consultation services under tele-Medcare.
- Our legitimate interest: Where it is necessary for us to understand our customers, promote our services, and effectively provide services, provided in each case that this is done in a legitimate way that does not duly affect your privacy and other rights.
- Compliance with law/agreement: Where we are subject to a legal obligation and need to use your Personal Information in order to comply with that obligation. For example, when you may purchase products/services from us, or book appointments we need to use your contact details and payment information in order to process your order.
- Vital Interests: In some limited cases, we may need to process your Personal Information where it is necessary to protect your vital interests or the vital interests of another person.
We will always take steps to ensure that the processing of your Personal Information is fair and lawful and that it does not unduly affect your privacy.
Purpose Mapping
Purpose | Details | Legal Basis | Special Category |
To set you up as a patient and process your data in Aster Healthcare Group’s systems | We use your Personal Data to create a Medical Record within our systems in which we will hold your medical history. We also use it to establish your identity and the method you will use to pay for the services that we provide you with (i.e., via your insurance provider, cash, or some other means) | Contract We need to use your Personal Data to take steps so that you can enter a contract with us and/or healthcare. Providing Personal Data is a requirement to enter a contract. Failure to provide Personal Data would prevent us from entering a contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
To provide you with healthcare and related services | This is the primary reason you are likely to visit any of our facilities or use our services. We will therefore process your personal and health data for that and related purposes. We may also need to carry out diagnostic tests or imaging procedures, some of which may be conducted within the facility you visit while others may be conducted at other Aster DM Healthcare Group facilities or by specially vetted third parties in compliance with local regulations. This means that some of your data might need to be shared with other hospitals within the Aster DM Healthcare group or other third parties. | Contract We need to process your health information to perform our healthcare contract with you. You are required to provide Personal Data to perform our contract with you. If you do not provide us with your Personal Data, we will be unable to perform our contract with you. | Health Purposes Processing is necessary for health purposes |
To provide you with medical services in cases of emergency | Where there is a risk to your life or other consequences may occur that would cause you great harm, we need to process personal and health data to protect your vital interests. Sometimes, we need to share your data with third parties in order the achieve that. | Vital Interests We may also need to process your health information to protect your vital health interests for instance, in life-threatening emergencies.
| Vital Interests Processing is necessary to protect the vital interests of the Data Subject or of another natural person where the Data Subject is physically or legally incapable of giving Consent |
To settle your account | We will use your personal and health data to ensure that your account and billing are fully accurate and up to date. This may include sharing your Personal Information with your health insurance provider or employer both before and after you receive treatment at any of our healthcare facilities. | Contract We need to process your personal and health information to perform our healthcare contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering a contract. |
For internal or government clinical audits related to our Entities in the UAE | We may share your Personal Data with government auditors, Clinical Outcome Review Programmes and other government-led quality improvement projects. We may also share your Personal Data with other audit programmes set up by clinical standards accreditation bodies such as Joint Commission International. | Legal obligation To comply with our regulatory or legal obligations. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
For internal or government clinical audits at our hospitals outside of the UAE. | We may share your Personal Data with government auditors, Clinical Outcome Review Programmes and other government-led quality improvement projects. We may also share your Personal Data with other audit programmes set up by clinical standards accreditation bodies such as Joint Commission International. | Legitimate Interest To make improvements to our procedures and practices provided that we have put appropriate safeguards in place to protect your privacy so that this use does not override your interests unduly. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Public Interests Processing is necessary for reasons of public interest in the area of public health to ensure continued high standards of quality and safe health care, of medicinal products or medical devices. |
Contacting you and resolving queries or complaints | There may be times when you raise queries, or even complaints, with us. We take those communications very seriously and will usually need to use your Personal Data to resolve them fully. | Legitimate Interests It is in our interest to improve our standards of care, and service delivery, in any other way that will benefit our patients and other stakeholders provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Pubic interest processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Providing you with service information | We will use the contact information you have given us to get in touch and remind you about appointments you have booked with us, to inform you about test results, or to otherwise follow up with you about an appointment you have attended with us. We will generally do this by telephone, SMS, email or by messenger app (such as WhatsApp). | Contract In order to fulfil our contractual obligations, we need to process Personal Data to fulfil our contractual obligations. Providing Personal Data is a contractual requirement. Failure to do so might prevent us from performing our contract with you. In order to provide you medical tourism facility. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
Medical research | We also participate in medical research and may share Personal Data government-approved research projects. | Consent We will obtain your Consent before using your Personal Data for any medical research purposes to bring healthcare improvements to the public. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section "Data Subject Rights" and "Right to object" and the "Right to Withdraw Your Consent" in this Privacy Policy for more information. |
Medical research where your Consent has not been obtained | We also participate in medical research and may share Personal Data with government approved research projects where allowed by regulatory bodies in the country. | Legitimate Interest It is in our legitimate interest to process Personal Data obtained from you for medical research purposes and share with government approved research projects where allowed by regulators provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Research Purposes Processing is necessary for Archiving and Research Purposes in accordance with Applicable Law |
Research and publication | We conduct research and publish results of the research in our magazine. | Consent We will obtain your Consent before using your Personal Data for any research and publication purposes to bring healthcare improvements to the public. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section "Data Subject Rights" and "Right to object" and the "Right to Withdraw Your Consent" in this Privacy Policy for more information. |
Grievance redressal | In order to redress complains and grievances and resolve escalations on the internet we would need to process your Personal Data. | Legitimate Interest It is in our legitimate interest to process Personal Data obtained from you while listing complains against Aster DM Healthcare on the Internet. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information | |
Clinical referrals | In order to provide you with comprehensive and high-quality health care, it may be necessary to refer your clinical case to other healthcare professionals at other facilities within the Aster DM Healthcare Group. In rare instances, it may also be necessary to refer your case outside of our network. | Contract We need to process your health information to perform our healthcare contract with you and fulfil your request. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract. |
Patient transfer | In order to continue your treatment, we may need to transfer you to another health care facility in the country. | Contract We need to process your personal and health information in order to fulfil our contract with you and transfer you to another facility where you can continue your treatment | Health Purposes Processing is necessary for health purposes. |
Patient transfer at your request | To continue your treatment at another facility or in another country at your request | Contract We need to process your personal and health information in order to fulfil the contract with you and transfer you to another facility where you can continue the treatment | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Patient transfer when there is insufficient insurance coverage or where your treatment cannot be continued at our facility | To protect your life, we may need to transfer you to another healthcare facility outside the country. By doing so we have to communicate your personal and health data to third parties. The healthcare facility outside the country. | Vital Interests We need to process your personal and health information to protect your vital health interests for instance, in life threatening emergencies. | Vital Interests Processing is necessary to protect vital interests of the Data Subject or of another natural person where the Data Subject is physically or legally incapable of giving Consent |
Providing improved quality services | We take measures to continually improve the quality of the services we provide. This includes monitoring or recording telephone calls to our contact numbers for training and security purposes and conducting pre and post treatment surveys. | Legitimate Interests It is within our legitimate business interests to take measures to improve the quality and efficiency of the services we provide to you provided that our interests are not overridden by your interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Public Interests Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Recruiting new staff | We will process your Personal Data if you apply for a job at Aster DM Healthcare Group. This includes all phases of the recruitment process including shortlisting, assessment, and interview, and offers of a position made to successful candidates. | Contract We need to process your Personal Data to take steps to enter into a contract of employment with you. | |
Recruiting new staff: processing your application | We may use external vendors to facilitate the recruitment of candidates | Legitimate Interests It is within our legitimate business interests to employ increasingly efficient processes and technology when searching for and assessing new talent to join our business provided that our interests are not overridden by your interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
Vetting and onboarding candidates | Aster DM Healthcare may use external vendors to conduct appropriate due diligence to ensure that we know who are we Hering. | Legitimate Interests It is in our legitimate business interest to use your Personal Data to conduct proper due diligence before we engage you as an employee, provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
Marketing | We may use your Personal Data to bring information about our services and products. This may include contact information you have given us to contact you by phone, by email, SMS, or other messaging platform you agree to. | Consent We will only contact you if you Consent to us doing so and have not withdrawn that Consent. You can withdraw your Consent at any time. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section Your Rights, Right to Object to How We Use Your Personal Information for Direct Marketing Purposes and the Right to Withdraw Your Consent for more information. |
Law enforcement requests | There may be times when we are required to provide the Personal Data of our patients or employees to law enforcement agencies such as the police, public health authorities and others. We will cooperate with these agencies when we receive such requests. | Legal Obligation In these situations, we are compelled to process your Personal Data to comply with a legal obligation to which we are subject. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
Appointment bookings | In order for us to book your appointment we must process your personal and health information. | Contract We must process your Personal Information to enter a contract with you if you are our new patient or fulfil our contractual obligations if you are our existing patient. You are required to provide Personal Data in order to enter or perform our contract with you. If you do not provide us with your Personal Data, we will be unable to perform our contract with you. | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Vetting and onboarding new business partners and vendors | Before engaging with new suppliers, vendors, or business partners, it is Aster DM Healthcare Group’s policy to conduct appropriate due diligence to ensure that we know who we are doing business with. These checks may require us to process Personal Data belonging to board directors, officers or other employees of these companies or organisations. | Legitimate Interests It is in our legitimate business interest to use your Personal Data to conduct proper due diligence before we engage in any business venture with you or your organisation, provided that these interests are not overridden by your own interests. Please note that you have the right to object to processing based on legitimate interest. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | |
CCTV Recordings | Storing and reviewing CCTV images is necessary to maintain our facilities safe. | Legal Obligation To comply with our legal and regulatory obligations to maintain safe and secure premises for visitors to our premises and our employees. | |
Processing for financial and accounting purposes | Analysis of financial results, internal and external audit requirements, receiving professional advice (e.g., tax, financial, legal, or public relations advice) | Legitimate Interests It is in our legitimate business interest to use your Personal Data conduct to, where necessary, conduct internal audits, consult with public relations experts and other experts to maintain efficient and effective operations, provided that these interests are not overridden by your own interests. | Public Interest Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Managing our accounting records | We need to maintain our accounting records | Legal Obligation To comply with relevant financial accounting and tax requirements. | |
Keeping your records | We need to keep your medical records to comply with relevant laws | Legal Obligation To comply with laws regulating the duration of storage of medical records. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law. |
Incident Reporting | You can always reach out to Aster DM Healthcare and report a complaint | Legitimate Interest It is in our legitimate interest to know about incidents that happen within our hospitals provided that these interests are not overridden by your own interests. | Public Interest Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices. |
Communicating with embassies and agencies about your treatment | Sometimes Aster DM Healthcare will need to communicate with your home country’s embassy or an agency about your treatment. | Contract We need to process your personal and health data to enter a contract with you | Performance of Contract Processing is required for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract. |
Occupational health | We need to process your Personal Information in order to assess your work capacity, whether you can perform the specific work or perform other employment related health service | Contract We need to process your personal and health data to perform our healthcare contract with you and provide you with requested services | Health Purposes Processing is necessary for health purposes, including preventative or occupational medicine, the assessment of the working capacity of an employee, medical diagnosis, the provision of health care or treatment or the management of health care systems or services or pursuant to a contract with a health professional provided that Processing is by or under the responsibility of a health professional subject to the obligation of professional secrecy or duty of confidentiality |
Sharing your data with Health Information Exchange in Dubai, Sharjah, Ras Al Khaimah, Umm Al Quwain, Fujairah | Where you give us your Consent, we can share your personal and health information with the Health Information Exchange. By doing so all healthcare providers involved in your treatment can access your information. | Consent Please note that for us to share your personal and health data with HIE systems in Dubai, Sharjah, Ras Al Khaimah, Umm Al Quwain, Fujairah, we need your Consent. You can withdraw your Consent at any time. Please see Section Your Rights and Control over your Personal Information in this Privacy Policy for more information. | Explicit Consent You can withdraw your Consent at any time. Please see Section Data Subject Rights, and Right to Object in this Privacy Policy for more information.
|
Sharing your data with Governmental Authorities | We need to process and share your Personal Data and Patient Health Data with relevant government authorities. | Legal Obligation We need to share your Personal Data with Government Authorities as a legal requirement. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law. |
Sharing your data with NABIDH, RIAYATI, MALAFFI and any other Health Information Exchange | Where you give us your Consent, we can share your personal and health information with the Health Information Exchange. By doing so all healthcare providers involved in your treatment can access your information. However, even if we do not receive your Consent, we must share your personal and health information with NABIDH, RIAYATI and MALAFFI. | Legal Obligation We need to share your Personal Data with Health Information Exchange platform as a legal requirement. | Legal Obligation The exercise of a function or requirement conferred on a person by Applicable Law |
Processing for delivery of medicines | We may share your Personal Data with to process your request for deliver medicines. | Contract We need to process your personal and health data, in some cases to perform our contract with you. |
Your Control over your Personal Information
We will respect your legal rights in relation to your Personal Data. Aster is committed to protecting them and ensuring compliance if you wish to exercise any of the rights under the respective privacy laws. You must submit the Data Subject Request through email at [email protected] and fill the Data Subject Request Form (link to be added here). The request will be processes in accordance with the Aster’s Data Subject Rights Procedure.
Please note that if as per regulation it is required to pay a reasonable fee for an access request, we will inform you of the fee before processing your request.
We will respond to your request as soon as reasonably possible and/or as per the applicable timeframes laid down by the respective privacy laws/regulations. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing of the same as soon as practically possible.
Please note that depending on the request that is being made, we will only need to provide you with access to the Personal Information contained in the documents requested, and not to the entire documents themselves. For example, the Company may not be obliged to provide the employee with access to the disciplinary records, investigation reports, or decisions to terminate, that the organization has created for evaluative and/or investigative purposes of the employee.
You have the right to withdraw your Consent at any point, provided such withdrawal of the Consent is intimated to us in writing through an email at [email protected] requesting the same. Once you withdraw your Consent to share the Personal Information collected by us, we shall have the option not to fulfil the purposes for which the said Personal Information was sought, and we may restrict you from using our Services or the website or parts of it as the case may be.
Data Subject Rights
Rights | UAE | Saudi Arabia | Oman | Qatar | Bahrain | Jordan | India |
Right to Obtain Information: Request for clear & concise information about the processing of their Personal Data. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Data Portability: Request to receive their Personal Data in a structured, machine-readable format and transfer it to another controller if feasible. | ῼ | 🗶 | ῼ | 🗶 | 🗶 | ῼ |
🗶 |
Right to Rectification and Erasure: Request to correct, rectify, or erase Personal Data. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Restrict Processing: Request restrictions on Processing, especially when contesting the accuracy of the Personal Data. | ῼ | 🗶 | 🗶 | 🗶 | 🗶 | ῼ | 🗶 |
Right to Object: Request to object to the processing of Personal Data | ῼ | 🗶 | 🗶 | ῼ | ῼ | ῼ | 🗶 |
Right to Stop Processing: Request to stop Processing, especially for direct marketing, profiling, or statistical surveys. | ῼ | ῼ | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 |
Right to Withdraw Consent: Request to withdraw consent for specific Processing activities. | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ | ῼ |
Right to Object to Automated Decision Making: Request to object to decisions based solely on automated Processing, unless necessarily required. | ῼ | 🗶 | 🗶 | 🗶 | ῼ | ῼ | 🗶 |
Right to be Notified of any Data Breach: Right to be informed of any Breaches affecting their Personal Data. | 🗶 | 🗶 | ῼ | 🗶 | 🗶 | ῼ | 🗶 |
Right to Nominate: Right to nominate someone else to exercise their data rights in case of incapacity or death. | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | ῼ |
Right to Grievance Redressal: Right to lodge a complaint and seek resolution for grievances related to their Personal Data Processing. |
ῼ | 🗶 | 🗶 | 🗶 | 🗶 | 🗶 | ῼ |
Withdrawing Consent:
- The Consent that you provide for the collection, use and disclosure of your Personal Information will remain valid until such time it is withdrawn by you by submitting your request in writing or via email to [email protected] or in accordance with the applicable legal requirements.
- Upon receipt of your written request to withdraw Consent, we may require a reasonable period of time to process your request subject to applicable governing laws, statutes, and regulations. We will notify you of any consequences of granting your request, including any legal implications that may affect your rights and obligations with respect to us.
- While we respect your decision to withdraw Consent, please be advised that, depending on the nature and scope of your request, we may be unable to process your request subject to applicable governing laws, statutes, and regulations. In such instances, we will notify you prior to completing the processing of your request, as outlined above.
- Please note that withdrawing Consent does not affect our right to continue collecting, using, and disclosing your Personal Information where such activities are permitted or required under applicable laws, even without Consent.
Exceptions where Data Subject Requests can be denied
Where any request is refused by DPO/Designated Team in accordance with the internal Data Subject Rights Procedure, it shall provide the Data Subject the reasons in writing for such refusal and shall inform the Data Subject regarding the right to file a complaint with the Authority against the refusal, within such period and in such manner as may be specified by regulations.
Sharing and Transferring of Personal Information
Aster complies with applicable laws and take necessary precautions before sharing your data. Aster enters into data-sharing agreements, implementing technical and organizational safeguards, ensuring transferees adhere to this policy. Additionally, we assess the data protection standards of any country before sharing your Personal Data with cloud providers, affiliates, agents, third-party service providers, partners, authorities, banks, or financial institutions.
By Consenting to share your Personal Data, you authorize Aster to transfer or share it across borders with cloud providers, affiliates, agents, insurance providers, third-party service providers, partners, authorities, banks, financial institutions, or for marketing purposes, as necessary to provide services or in compliance with applicable laws.
We may share your information with authorized third-party vendors and service providers that help us with specialized services, including customer service, email deployment, business analytics, marketing (including but not limited to advertising, attribution, deep-linking, direct mail, mobile marketing, optimization and retargeting) advertising, performance monitoring, hosting, and data processing. These authorized third-party vendors are subject to risk assessment test and will not use your information for purposes other than those related to the services they are providing to us. All such data sharing is conducted in accordance with applicable data localization requirements, security protocols, and applicable regulatory standards.
If you choose to engage in public activities on the third-party sites that we link to, you should be aware that any information you share there can be read, collected, or used by other users of these sites and forums. You should use caution in disclosing personal information while participating in these areas. We are not responsible for the information you choose to submit in public areas.
Please note that, in line with regulatory requirements and basis your consent, all health-related data is securely shared with government-mandated Health Information Exchanges (HIEs) such as NABIDH, RIAYATI, MALAFFI, and other applicable platforms to support better care coordination and public health outcomes.
Aster adheres to data localization principles where required by law, ensuring Personal Data is stored within the same jurisdiction as it is collected. However, in certain cases—such as with Patient Health Information where authorized by the User or with approval from relevant health authorities—data may be transferred outside the jurisdiction.
A Data Processor shall only disclose the Personal Data to a Third Party on documented instructions from the Data Controller. The Federal Law No. 2 of 2019 (Health Data Law) by default prohibits the transfer, storage, generation or processing of Patient Health Information that relates to health services. The UAE's Ministry of Health and Prevention (MoHAP) Resolution 51/2021 relaxed the relaxes the data transfer restriction for certain types of processing operation, namely.
- Overseas treatment
- Medical testing
- Scientific research
- Insurance claims and coverage
- Organisations cooperating with the UAE Government or its institutions
- Wearables and healthcare monitoring devices
- Pharmacovigilance reporting
- Data approved by a health authority
- Telemedicine
- Formal request
Exceptions
There are certain exceptions under which Patient Health Information can be transferred or shared outside the country of collection, by virtue of a decision issued by the Federal or local governmental Health authority in the State and after getting approval from the Dubai Health Authority or any other Authority wherever applicable. Such exceptions include, but are not limited to:
- Matters of public interest
- Information that is already publicly available
- Medical diagnosis, the provision of healthcare or social care, treatment, or health insurance services
- Protection of the Data Subject’s vital interests
- Compliance with legal obligations or the exercise of established rights in the areas of employment, social security, or social protection laws, as permitted under applicable legislation
- Establishment, exercise, or defense of legal claims, including international judicial cooperation
- Execution of a contract that serves the Data Subject’s interests.
Use of Cookies
- Cookies are small bits of data cached in a user’s browser. Aster utilises cookies to determine whether or not you have visited the home page in the past. However, no other user information is gathered. Aster may use non-personal "aggregated data" to enhance the operation of our website or analyse interest in the areas of our website.
- If you would like to find out more about cookies, including how we use them and what choices are available to you, please refer to our Cookie Policy.
- You may also be able to control or limit the collection of this technical data through your browser or device settings.
Security
The security of your Personal Information is important to us. We have adopted and maintained reasonable technical and organizational security measures and procedures including rigorous third-party risk assessments, strong access controls and information sharing on a need-to-know basis, encryption of Personal Data, secure storage of Personal Data, rapid data Breach management procedures, etc. to ensure that the Personal Information collected is secure at rest and in transit. We restrict access to your Personal Information to our and our affiliates’ employees, agents, third-party service providers, partners, and agencies on a need-to-know basis and absolutely limited to the purposes as specified above in this Policy.
Third Party references and Links
- During Your interactions with us, it may happen that we provide/include reference to third parties or fiduciaries, and/or links and hyperlinks to third-party websites. It may also happen that you include links and hyperlinks to third-party websites. The reference of such third parties or listing of such third-party external sites (by you or by us) does not imply endorsement of such party or site by Aster. Such third parties and third-party sites are governed by their own terms and conditions and have their own privacy Policies. We do not make any representations regarding the availability and performance of any of the third parties or third-party sites. We are not responsible for the content, terms of use, privacy policies and practices of such third-party websites.
- Do-not-track requests: There is no standard for how online service should respond to “Do Not Track” signals or other mechanisms that may allow you to opt out of the collection of information across networks of websites and online Services. Therefore, we do not honor “Do Not Track” signals. As standards develop, we will revisit this issue and update this Policy if our practices change.
Children’s Privacy
We understand the importance of taking extra precautions to protect the privacy and safety of children using our website or Services. Minors are not permitted to use the website or services, and we request that minors under the age of 18 not submit any Personal Information to the website. Since information regarding minors under the age of 18 is not collected, we do not knowingly distribute Personal Information regarding minors under the age of 18. By accessing this website, you affirm and guarantee that you are 18 years of age or older.
We hold no liability for any unsolicited information provided by you, and you Consent to the usage of such information in accordance with this Privacy Policy. If we become aware that a person submitting Personal Data is under 18, we will delete all the information as soon as possible unless it is with the Consent and involvement of a parent or guardian. If you believe we might have any information from or about a child under 18, please contact us at email lD: [email protected]
Term of storage of Personal Information
Aster will retain your personal information for as long as necessary, in accordance with the required timeframe and in compliance with the internal data retention policy.
International Users and Personal Data
We welcome users from around the world and are committed to respecting their privacy. We encourage them to visit Aster Medical Travel on (https://astermedicaltravel.ae) for more details on how we handle their Personal Data.
Modifications Of the Privacy Policy
We reserve the right to change this Policy from time to time to meet the requirements and standards. We will not reduce your rights under this Policy without your explicit Consent. If changes are significant, we will provide a more prominent notice (including, for certain Services, email notification of Policy changes). Therefore, customers are encouraged to frequently visit these sections in order to be updated about the changes on the website.
Modifications will be effective on the day they are posted and the date of this Privacy Policy of when it was last updated will appear at the top of this document
Contact Us
If you have any questions regarding this Privacy Notice, you may contact our Group Data Protection Officer:
DPO Details: [email protected]
Contact No.- +971565037221
Or you can write to us/post at:
The Data Protection Officer,
Aster DM Healthcare Limited.
Official Address: 33rd Floor - Aspect Tower, Business Bay, P.O. Box: 8703 - Dubai - U.A.E
If you have any questions, concerns, or complaints regarding our compliance with the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us. We will investigate and attempt to resolve complaints and disputes and will make every reasonable effort to honour your wish to exercise your rights as quickly as possible and, in any event, within the timescales provided by data protection laws.
Annexure 1
S. No. | Applicable Laws |
1. | UAE Regulations:
|
2. | Kingdom of Saudi Arabia Personal Data Protection Law (Cabinet Decision No. 98/1443) Implementing Regulations:
|
3. | Oman Personal Data Protection Law (Oman Sultani Decree No. 6/2022) Implementing Regulations:
|
4. | Bahrain Personal Data Protection Law (Law No. (30) of 2018) Implementing Regulations:
|
5. | Qatar Personal Data Privacy Protection Law (Law no. 13 of 2016) Guidelines: Controller and Processor, National Cyber Security Agency |
6. | Jordan Personal Data Protection Law (No. (24) of 2023) |
7. | Indian Digital Personal Data Protection Act, 2023 |