iCenna Logo

تواصل معنا

+966 559 748 864

iCenna Privacy Policy

How iCenna collects, uses and protects Personal Data

Version: 1.0

Last Updated: 2026-08-14


This Privacy Policy explains how iCenna Company (“iCenna”, “we”, “us”, “our”), a healthcare software-as-a-service company incorporated in the Kingdom of Saudi Arabia (commercial registration 4030497928; registered address: 8125 Prince Sultan Street, 2086 Ar Rawdah District, Jeddah 23435), collects, uses, discloses and protects Personal Data when you visit our websites, contact us, or use our cloud services (together, the “Services”). We process Personal Data in accordance with the Saudi Personal Data Protection Law (“PDPL”) and its Implementing Regulations, and other applicable laws.

Important — two roles. When healthcare organisations (our customers) use the iCenna platform to manage their operations and patient records, the customer is the Controller of that data and iCenna processes it only as a Processor on the customer’s instructions, under

our Data Processing Agreement (available at

https://iCenna.com/data-processing-agreement). If you are a patient of one of

our customers, please direct privacy questions and requests to your healthcare

provider; we will support them in responding. This Policy primarily describes

the processing for which iCenna is itself the Controller (our websites,

marketing, sales, support and business operations).


1. Personal Data We Collect

  1. Contact and account data: name, job title, organisation, email, phone number, and login credentials for administrative accounts.
  2. Business and billing data: commercial registration details, VAT number, billing address, and payment references (we do not store full card numbers).
  3. Usage and device data: IP address, browser and device identifiers, log files, and interactions with our websites and Services, including through cookies and similar technologies.
  4. Support and communications data: the content of your enquiries, support tickets, call recordings where notified, and feedback.
  5. Customer Content processed as Processor: data our customers submit to the platform, which may include patient health data. We process this only under the customer’s instructions and our Data Processing Agreement, and it is not used for our own purposes.


2. Purposes and Legal Bases

We process Personal Data for the following purposes, relying on the legal bases available under the PDPL:

  1. Providing and operating the Services — performance of a contract or steps at your request prior to a contract.
  2. Account administration, billing and collections — performance of a contract; compliance with legal obligations (e.g., tax and audit).
  3. Security, fraud prevention and service integrity — legitimate interest / actual interest of the Controller, consistent with PDPL requirements and without prejudice to data subjects’ rights.
  4. Product improvement and analytics — legitimate interest, using aggregated or de-identified data wherever possible.
  5. Marketing communications — your consent, which you may withdraw at any time; every marketing message includes an opt-out.
  6. Compliance with law and requests of competent authorities — legal obligation.

We do not sell Personal Data, and we do not use patient data processed on behalf of our customers for advertising.


3. Cookies

Our websites use strictly necessary cookies to operate, and — with your consent where required — analytics and preference cookies to understand usage and improve our sites. You can manage cookies through your browser settings and, where available, our cookie banner. Disabling some cookies may affect site functionality.


4. Disclosure of Personal Data

We disclose Personal Data only as needed and with appropriate safeguards, to:

  1. Service providers (sub-processors) such as cloud hosting and
  2. communications providers, bound by contracts requiring confidentiality and
  3. security consistent with this Policy and the PDPL. The current list is
  4. published at https://iCenna.com/sub-processors.
  5. Our affiliates and professional advisers for legitimate business operations, on a need-to-know basis.
  6. Competent authorities where disclosure is required by law, regulation or a binding request in the Kingdom of Saudi Arabia.
  7. A successor entity in connection with a merger, acquisition or reorganisation, subject to this Policy continuing to apply.


5. Data Residency and International Transfers

Customer Content, including patient health data, is hosted within iCenna’s dedicated cloud tenancy in data centres located in the Kingdom of Saudi Arabia. Where any Personal Data must be transferred outside the Kingdom (for example, to a communications provider), we do so only in accordance with the PDPL’s provisions on transfers outside the Kingdom, including ensuring an adequate level of protection, applying appropriate safeguards such as contractual clauses, limiting the transfer to the minimum necessary, and obtaining any approvals required by the competent authority. Providers processing outside the Kingdom, and the safeguards applied, are identified at https://iCenna.com/sub-processors


6. Artificial Intelligence

The Services include AI features developed, owned and operated by iCenna. All AI hosting and inference involving Personal Data takes place within iCenna’s cloud tenancy in the Kingdom of Saudi Arabia. AI features provide suggestions and decision support only, and clinical decisions always remain with qualified healthcare professionals. Where iCenna acts as Processor, AI processing of Customer Content is governed by the Data Processing Agreement.


7. Security

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data we process, aligned with applicable Saudi cybersecurity requirements, including encryption in transit and at rest, role-based access controls, logging and monitoring, and regular security testing. Details relevant to platform customers are set out in the iCenna Cloud Service Policy. No system is completely secure; if we become aware of a breach of Personal Data that is likely to cause harm, we will notify the competent authority and affected parties as required by the PDPL.


8. Retention

We retain Personal Data only as long as necessary for the purposes described above, to comply with legal obligations (such as tax, audit and health-records retention laws), to resolve disputes and to enforce agreements. Customer Content is retained for the duration of the customer’s subscription and a limited retrieval period thereafter, after which it is deleted or de-identified in accordance with our Data Processing Agreement, unless retention is required by law.


9. Your Rights

Subject to the PDPL and its Implementing Regulations, you have the right to:

  1. be informed about how your Personal Data is processed;
  2. request access to, and a copy of, your Personal Data;
  3. request correction, completion or updating of inaccurate data;
  4. request destruction of your Personal Data when it is no longer needed, subject to legal retention requirements;
  5. withdraw consent at any time, where processing is based on consent, without affecting prior processing.

To exercise these rights, contact us using the details in Section 11. We will verify your identity and respond within the timeframes required by law. If you are a patient of an iCenna customer, we will refer your request to your healthcare provider, who controls your records, and assist them in responding. You may also lodge a complaint with the Saudi Data & AI Authority (SDAIA) or other competent authority.


10. Children

Our websites and direct services are intended for business users and are not directed at children. Patient data relating to minors is processed only on behalf of our healthcare customers, under their control and applicable law.


11. Contact Us

Privacy Office, iCenna

Company, 8125 Prince Sultan Street, 2086 Ar Rawdah District, Jeddah 23435,

Kingdom of Saudi Arabia — Privacy@iCenna.com

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date and, for material changes, provide additional notice (such as email or in-service notice). Continued use of the Services after the effective date constitutes acknowledgement of the updated Policy.