Privacy Policy

What we collect, why, where it is stored, who can reach it — and who decides about it.

Last updated: 23 August 2026

The most important line on this page: the platform stores no patient names and no medical records. It was designed around de-identified patient references from day one, and detailed clinical data stays in your own hospital information system.

1Who we are and our role

i Care Tracer is a cloud platform operated from the Kingdom of Saudi Arabia at icaretracer.com. For privacy matters: info@icaretracer.com, phone 0548999500.

Our role has two distinct sides:

  • For your facility's data inside the platform we are a Processor. The facility is the Controller, deciding what is entered, why, and how long it is kept.
  • For website visitors, quotation requests and marketing we are the Controller, and this policy governs that directly.

2What we collect

  • Account data: name, email, mobile, job title, department, permissions, and facility name.
  • Content the facility enters: assessments, evidence, incidents, risks, KPIs, policies, committee minutes, claims and denial data.
  • Uploaded files: documents and images attached as evidence — their content is the facility's responsibility alone.
  • Physician and staff data: names, performance metrics, credentialing, clinical privileges and training records.
  • Audit log: who did what and when inside the platform — an accreditation requirement, not an option.
  • Usage and billing data: AI operation counts, storage consumed, and subscription details.
  • Technical data: IP address, browser type, sign-in times and error logs.
  • Marketing data: what you enter in the contact form or on the Plans page to obtain a quotation.

3What we deliberately do not collect

  • Patient names, national IDs or medical records. Patient fields in the platform are de-identified references whose linking key stays with the hospital alone.
  • Payment card details. Payments are handled by a licensed payment gateway and card data never passes through our servers.
  • We use no advertising trackers and no third-party analytics, on the site or inside the platform.

4Why we process, and on what basis

  • Performance of the contract: running the platform, delivering the service, issuing invoices.
  • Legitimate interest: platform security, abuse prevention, and product improvement based on aggregate — never individual — usage patterns.
  • Consent: marketing messages and quotation requests, withdrawable at any time.
  • Legal obligation: retaining audit logs and invoices for the periods the law requires.

5AI inside the platform

Some platform features call an AI model at an external provider. What is sent is only the text or aggregated data you ask it to analyse at that moment — never your database and never your archive.

  • Your data is not used to train the provider's models, under the commercial terms we contract on.
  • Every AI call is logged with its feature, time and consumption — for allowances and billing, not to review content.
  • AI output is advisory by nature and needs qualified human review before it informs any decision.
  • Do not enter data identifying an individual patient into AI fields — the design does not require it, and refraining is the user's responsibility.

6Who we share data with

We do not sell, rent or share data for marketing. We rely on a limited set of service providers to run the platform:

  • Cloud hosting provider — servers, database and file storage.
  • AI model provider — for the analysis and generation features.
  • Email provider — for notifications and written offers.
  • Licensed payment gateway — for subscription payments.

Disclosure may also occur on a lawful request from a competent authority, and we will notify the facility unless the law forbids it.

7Where data is stored, and transfers outside the Kingdom

For facilities whose own policy or regulator requires in-Kingdom hosting, in-Kingdom deployment is available as a special arrangement — talk to us before contracting.
The platform's servers and the AI provider are currently located outside the Kingdom of Saudi Arabia. The Saudi Personal Data Protection Law requires approved safeguards for transferring personal data abroad.
  • We rely first on data minimisation: the platform holds no patient-identifying health data, the most sensitive category under the law.
  • We contract with providers on data-protection terms covering confidentiality, use restrictions and incident notification.

8How long we keep data

  • Facility data: for the life of the subscription. On termination it is made available for full export, then deleted after two written notices.
  • Trial data: kept for 60 days after the trial ends, then deleted.
  • Audit logs and invoices: retained for the periods accounting and accreditation rules require.
  • Marketing and quotation data: until you ask for deletion, or two years after the last contact.

9How we protect data

  • All traffic encrypted over HTTPS.
  • Every facility is isolated at the data layer — no facility can see another's data.
  • Role-based permissions, protected sessions, and hashed passwords never stored as text.
  • Uploaded files are checked by real file signature, not merely by extension.
  • An audit log that cannot be edited from the interface.

No information system is absolutely secure, and we do not claim otherwise.

10Your rights

Under Saudi law a data subject has the right to:

  • Be informed how their data is collected and on what basis.
  • Access their data and obtain a copy of it.
  • Have inaccurate or incomplete data corrected.
  • Request destruction of their data when it is no longer needed.
  • Withdraw consent at any time where consent was the basis.

If you are a member of staff at a client facility, your request goes first to your facility as the Controller, and we will support it. To contact us directly: info@icaretracer.com — we respond within thirty days.

You also have the right to complain to the Saudi Data and AI Authority (SDAIA), the regulator supervising the law.

11Cookies

We use two cookies only, and both are strictly necessary:

  • The session cookie: keeps you signed in, and ends when you sign out or it expires.
  • The language cookie: remembers your Arabic/English choice.

We use no advertising cookies and no third-party analytics cookies.

12Data breaches

If an incident affects the confidentiality or integrity of personal data, we notify the affected facility and the regulator within seventy-two hours of becoming aware, stating what happened, what was done and what we recommend.

13Changes to this policy

We may update this policy as the platform or the applicable law changes. Any material change is notified to clients by email thirty days before it takes effect, and the last-updated date stays visible at the top of this page.