1. Personal Data Protection & Privacy Policy
Introduction YAAT Saudi Arabia places the protection, privacy, and security of personal data as a top priority. The company is committed to full compliance with the laws and regulations of the Kingdom of Saudi Arabia, including the Personal Data Protection Law (PDPL) issued by Royal Decree No. (M/19) dated 09/02/1443H, and its amendments. This policy aims to establish transparency and enhance trust by clarifying data collection mechanisms, processing purposes, and protection methods.
Scope of Application This policy applies to all individuals and entities whose personal data is collected to benefit from the company’s services. It covers all data collected directly or indirectly through digital platforms, applications, or paper and electronic transactions.
Data We Collect
- Personal Information: Name, date of birth, nationality, and National ID/Iqama number.
- Contact Information: Address, phone numbers, and email.
- Professional Information: Job titles, qualifications, certifications, and professional records (specifically for healthcare workforce).
- Financial Information: Bank account details, payment transactions, and billing information.
- Technical Data: Cookies and interaction data with our digital platforms.
- Data of Minors/Incapacitated Persons: Collected only with the consent of the legal guardian for the benefit of the data subject.
Purposes and Legal Basis for Processing
- Managing and coordinating the healthcare workforce with medical facilities.
- Supervising professional programs and ensuring secure data handling.
- Executing service contracts and processing financial payments.
- Compliance with regulatory requirements issued by competent authorities in KSA.
Data Sharing and Disclosure Data may be shared with third parties (e.g., healthcare providers or regulatory bodies) only when strictly necessary for legal or operational purposes, ensuring high security standards under the PDPL.
Data Storage, Retention, and Destruction Data is stored in secure, certified data centers within the Kingdom. It is retained only as long as necessary to achieve the purpose of collection or as required by law, after which it is securely destroyed or anonymized.
Rights of the Data Subject
- Right to be Informed: To know the legal basis and purpose of collection.
- Right of Access: To access your data and obtain an electronic copy.
- Right to Correction: To request correction, completion, or updating of data.
- Right to Destruction: To request data deletion once the purpose ends.
- Right to Withdraw Consent: At any time, unless a legal basis prevents it.
Data Protection Officer (DPO) The company has appointed a DPO to ensure compliance, provide technical advice, and ensure processing practices align with regulatory requirements.
Notice Updates This policy is reviewed and updated regularly to keep pace with changes in regulations or operational practices. The date of the last update will be indicated at the top of the page.
Related Legislation
- National Data Governance Policies issued by the Saudi Data and AI Authority (SDAIA): (Main Principles and General Rules for Personal Data Protection, Main Principles and General Rules for Data Sharing). Link
- Electronic Transactions Law. Link
- Anti-Cybercrime Law. Link
- Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA). Link
2. Electronic Service Level Agreement (SLA)
Introduction This agreement clarifies the quality and standards of electronic services provided by YAAT. Obtaining any service through the platform constitutes an explicit and implicit agreement to these terms.
User Rights and Obligations
- Professional Conduct: Requests are handled fairly and confidentially.
- Personal Account: Users must register an account to apply for services and track progress.
- Data Accuracy: Registration must match official IDs. False data leads to automatic disqualification.
- Legal Responsibility: The user is fully responsible for their choices and compliance with regulations.
YAAT Rights and Obligations
- Response Speed: Commitment to interact with complete requests within a maximum of 3 business days.
- Privacy and Fairness: Adherence to privacy rules in processing requests.
- Request Management: YAAT reserves the right to cancel or suspend non-compliant requests.
- Maintenance: The company may temporarily disable services for scheduled maintenance or technical updates.
Contact Information & Technical Support
Support Email: Support@yaatx.com
Toll-Free / Unified Number: [Insert Number]
Live Chat: Available via the website during official working hours.
Expected Response Time: Initial Response within 24 hours; Request Resolution within 3 business days.
3. Terms and Conditions of YAAT Platform Usage
Acceptance of Terms
By accessing the platform, you agree to be bound by these terms, the Privacy Policy, and KSA regulations. If you disagree, you must cease usage immediately.
Eligibility and Data Integrity
- Users must be at least 18 years old.
- Users commit to providing accurate and updated information (qualifications, professional classifications).
- YAAT disclaims liability for consequences of false data.
- Your acceptance constitutes explicit consent for data processing per Article 4 of the PDPL.
Account Management and Security
- Users are fully responsible for the confidentiality of their credentials.
- YAAT must be notified immediately of any security breach.
- YAAT may suspend accounts that misuse the platform.
Acceptable Use
- Using the platform for illegal purposes.
- Attempting to breach systems, disable servers, or use harmful software.
- Identity theft or publishing defamatory content.
Intellectual Property Rights
All content (text, logos, designs, software) is the exclusive property of YAAT and protected by KSA copyright and trademark laws. No part may be copied or distributed without prior written consent.
Limitation of Liability
- YAAT acts as an intermediary/administrative platform and is not responsible for individual behaviors of practitioners or facilities outside the contract scope.
- The platform does not guarantee absolute protection against cyberattacks beyond its reasonable control and disclaims liability for damages unless resulting from gross negligence or intentional error.
Governing Law and Jurisdiction
These terms are governed by the laws of the Kingdom of Saudi Arabia. Any dispute shall be resolved before the competent courts in Riyadh.