Global Privacy Policy
Comprehensive data protection protocols, AI processing guidelines, and strict UAE regulatory compliance.
1. The "Zero Medical Data" Doctrine
GREHALA is an enterprise routing directory and a technological employment hub, not a health information custodian. We maintain an absolute "Zero Medical Data" retention policy to ensure total compliance with international (HIPAA) and regional UAE healthcare data parameters.
- No Patient Records: We do not collect, process, or archive Electronic Health Records (EHR), Electronic Medical Records (EMR), laboratory results, prescriptions, or clinical diagnostic data.
- Ephemeral Processing (Calculators): When utilizing our digital utilities (e.g., Medication Dosages, BMI, Ovulation Calculators, or Symptom Checkers), your inputs are processed instantaneously within your localized browser session (Client-Side). No physiological data is transmitted to, or stored within, GREHALA's backend database architectures.
2. Necessary Operational Data Collection
To facilitate the fundamental networking and job-matching capabilities of the platform, we collect the strict operational minimum of data points:
- Account Provisioning Data: Upon registration, we collect your explicit full name, verified email address, phone number, and hashed cryptographic password.
- Professional Credentials (For Jobs): If you utilize our job board, we store the resume data, licensing information (DHA/MOHAP/DOH), and employment history you voluntarily upload. This data is explicitly rendered public to potential employers on the platform.
- Automated Telemetry: We temporarily log IP addresses, browser user-agents, and access timestamps solely to prevent DDoS attacks, mitigate spam, and ensure the cryptographic integrity of the platform.
3. Artificial Intelligence & Algorithm Processing
GREHALA heavily utilizes advanced Artificial Intelligence and LLM (Large Language Model) infrastructure to power features like NAWA AI, CV Builders, and Cover Letter generators.
- Stateless Execution: Text prompts and queries submitted to our AI engines are executed in a stateless environment. The prompts are utilized strictly to generate the requested output in real-time and are subsequently purged. We do not use your personal queries to train underlying foundation models.
- ATS Scanner Logic: The resumes you submit for ATS (Applicant Tracking System) scanning are parsed temporarily in system memory (RAM) to generate keyword compatibility scores. The parsed binary files are explicitly excluded from long-term cold storage.
4. Third-Party Integration & Advertising Ecosystem
GREHALA operates on a freemium model. To sustain free access to our high-tier computational tools, we integrate with secure third-party advertising networks.
- Strict Non-Sale Guarantee: GREHALA categorically does not sell, lease, or broker your personal identification data (Names, Emails, Phone Numbers) to external data brokers or marketing agencies.
- Google AdSense & DART Cookies: We utilize Google as a primary third-party advertisement vendor. Google employs specific tracking scripts, known as DART cookies, to serve contextual advertisements based on your historic visits to GREHALA and other sites on the Internet.
- Opting Out: DART cookies do not extract personally identifiable information. If you wish to neutralize this tracking, you may actively opt out of personalized advertising by visiting the Google Ad and Content Network Privacy Policy.
5. WhatsApp Routing & External Platforms
GREHALA features seamless "Quick Connect" and "Book Appointment" buttons that redirect users to WhatsApp APIs or external hospital portals.
- Loss of Jurisdictional Control: The moment you click an external link or initiate a WhatsApp chat through our platform, your digital footprint leaves GREHALAβs encrypted ecosystem.
- Third-Party Liability: GREHALA cannot intercept, encrypt, or secure communications happening on WhatsApp. Any sensitive medical data, CVs, or financial information you transmit via these external channels is governed entirely by Meta's (WhatsApp) privacy policy and the respective hospital's IT security protocols.
6. UAE Regulatory Compliance & Subpoenas
As an entity operating within the UAE, GREHALA adheres to absolute legal compliance regarding national security and cyber law.
- Law Enforcement Cooperation: We will unequivocally disclose your personal data, IP logs, and platform activity to UAE governmental authorities, police departments, or judicial bodies if presented with a legally binding subpoena, warrant, or court order.
- Fraud Mitigation: If a user account is flagged for severe violations (e.g., impersonating a doctor, uploading forged medical licenses, or scamming job seekers), GREHALA reserves the absolute right to suspend the account and forward the compiled digital evidence to the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) or cybercrime units.
The "Right to be Forgotten"
You maintain ultimate sovereignty over your digital footprint. At any given moment, you may navigate to your account settings and initiate a total account deletion. This action triggers a cascading database protocol that irreversibly purges your profile, job listings, forum comments, and professional milestones from our active relational databases.
Last Updated: September 2026.
Continued usage of the GREHALA platform after updates to this document constitutes absolute acceptance of the revised privacy infrastructure.