iCenna Logo

تواصل معنا

+966 559 748 864

PRIVACY POLICY

Document Ref: iCenna_Privacy_Policy_v1.0 (ENG) — Effective Date: July - 2026

This Privacy Policy (this “Policy”) explains how iCenna Company, Commercial Registration No. 4030497928, Kingdom of Saudi Arabia (“iCenna”, “we”, “us”, or “our”), collects, uses, discloses and protects Personal Data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia issued by Royal Decree No. M/19, as amended, and its Implementing Regulations (the “PDPL”). This Policy forms part of the Service Specifications under the iCenna Cloud Services Agreement (the “CSA”).

1. DEFINITIONS

1.1. “Personal Data”, “Sensitive Data”, “Processing”, “Controller”, “Processor” and “Data Subject” have the meanings given to them in the PDPL.

1.2. “Services” means the iCenna cloud services (including the Hospital Information System, Radiology/PACS, ERP, HR, Insurance & Revenue Cycle modules, patient portals and mobile applications) made available under a Sales Order and the CSA.

1.3. “Customer” means the healthcare provider or other entity that has entered into a Sales Order with iCenna.

1.4. “DPA” means the iCenna Data Processing Agreement entered into between iCenna and a Customer.

1.5. “SDAIA” means the Saudi Data & AI Authority, the competent authority for the supervision of the implementation of the PDPL.

2. SCOPE OF THIS POLICY AND OUR ROLES

2.1. This Policy applies to Personal Data we Process in connection with: (a) visitors to icenna.com and our other websites; (b) individuals who contact us, request demonstrations, or receive our marketing communications; (c) personnel of our Customers, partners and suppliers; and (d) users of the Services, including patients, where applicable.

2.2. Our role under the PDPL depends on the context of Processing:

a. iCenna as Controller. For Personal Data relating to website visitors, prospective customers, marketing contacts, job applicants, and Customer business contacts, iCenna determines the purpose and manner of Processing and acts as the Controller.

b. iCenna as Processor. For Personal Data contained in Customer Content processed within the Services — including patient demographics, medical records, appointment, insurance and billing data — the Customer (the licensed healthcare provider) is the Controller and iCenna acts solely as a Processor on the Customer's documented instructions, under the CSA and the DPA. Patients and other Data Subjects should direct requests concerning such data to the relevant healthcare provider; we will assist that provider in responding as described in the DPA.

3. PERSONAL DATA WE COLLECT

3.1. As Controller, we may collect: (a) identity and contact data (name, employer, job title, e-mail address, phone number); (b) communications and correspondence with us; (c) technical data (IP address, device and browser type, operating system, pages visited, and usage data collected via cookies and similar technologies); (d) event, demonstration and training registration data; and (e) recruitment data submitted by job applicants.

3.2. As Processor, the categories of Personal Data processed within the Services are determined by the Customer and typically include patient identification and demographic data, national ID/Iqama number, contact details, medical history, diagnoses, prescriptions, laboratory and radiology results, insurance and claims data (including data exchanged with NPHIES), and appointment and billing records. Such data may include Sensitive Data (health data) under the PDPL.

3.3. We collect Personal Data directly from You, automatically through Your use of our websites and the Services, and from our Customers when they configure and use the Services.

4. PURPOSES AND LEGAL BASES OF PROCESSING

4.1. As Controller, we Process Personal Data for the following purposes and on the following legal bases under the PDPL:

a. to operate our websites, respond to enquiries and provide requested information or demonstrations (actual interest of the Data Subject / steps at the Data Subject's request);

b. to conclude and perform contracts with Customers, partners and suppliers, including account management, invoicing and support (performance of a contract / legitimate interest);

c. to send marketing communications where permitted, subject to Your right to opt out at any time (consent);

d. to secure our websites, systems and the Services, prevent fraud and misuse, and comply with the NCA cybersecurity frameworks applicable to us (legitimate interest / compliance with legal obligations); and

e. to comply with applicable laws, regulations and lawful requests of competent Saudi authorities (compliance with legal obligations).

4.2. As Processor, we Process Personal Data within the Services solely for the purpose of providing, securing, supporting and improving the Services in accordance with the CSA, the DPA and the Customer's documented instructions. We do not use patient data for marketing, and we do not sell Personal Data.

4.3. Where Processing of Sensitive Data (including health data) requires a specific legal basis, responsibility for establishing that basis (including any required patient consents or reliance on health-care provisions of the PDPL) rests with the Customer as Controller, as set out in the CSA and DPA.

5. DISCLOSURE OF PERSONAL DATA

5.1. We may disclose Personal Data to: (a) our employees and contractors bound by confidentiality obligations, on a need-to-know basis; (b) sub-processors and service providers (e.g., data center and infrastructure providers within the Kingdom) engaged in accordance with the DPA; (c) government platforms and competent authorities where required for the Services or by law, including NPHIES, MoH, CHI, ZATCA and SDAIA; (d) professional advisers; and (e) a successor entity in connection with a corporate transaction, subject to the PDPL.

5.2. We do not disclose Personal Data to third parties for their own marketing purposes.

6. DATA RESIDENCY AND CROSS-BORDER TRANSFERS

6.1. Customer Content within the Services, including patient data, is hosted in data centers located within the Kingdom of Saudi Arabia, as stated in the CSA.

6.2. We will not transfer Personal Data outside the Kingdom except in accordance with the transfer provisions of the PDPL and its Implementing Regulations (including the Regulation on Personal Data Transfer outside the Kingdom), the applicable NCA controls, and, for Customer Content, the DPA and the Customer's instructions.

7. SECURITY

7.1. We implement administrative, technical and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, loss or destruction.

7.2. Measures include encryption of data in transit and at rest, role-based access control and multi-factor authentication, logging and monitoring, vulnerability management, personnel confidentiality undertakings and security awareness training, and business continuity and disaster recovery arrangements.

8. RETENTION

8.1. As Controller, we retain Personal Data only for as long as necessary for the purposes described in this Policy, and thereafter as required by applicable Saudi law (including tax, commercial and employment record-keeping requirements), after which it is securely destroyed or anonymized in accordance with the PDPL and the DCC.

8.2. As Processor, we retain Customer Content for the duration of the Services Period and the retrieval period stated in the Service Specifications, after which it is securely deleted in accordance with the CSA and the DPA, except where retention is required by applicable law, including medical records retention requirements applicable to the Customer.

9. YOUR RIGHTS UNDER THE PDPL

9.1. Subject to the conditions and exemptions in the PDPL, Data Subjects have the right to: (a) be informed about the Processing of their Personal Data and its legal basis; (b) access their Personal Data and obtain a copy in a readable and clear format; (c) request correction, completion or updating of their Personal Data; (d) request destruction of their Personal Data where no longer needed; and (e) withdraw consent to Processing based on consent at any time, without affecting Processing carried out before withdrawal.

9.2. To exercise these rights in respect of data for which iCenna is the Controller, contact us using the details in Section 13. We will respond within the timeframes required by the PDPL and may need to verify Your identity before acting on a request.

9.3. Where iCenna is a Processor (patient and clinical data within the Services), requests should be directed to the relevant healthcare provider as Controller. If we receive such a request directly, we will forward it to the relevant Customer and assist as set out in the DPA.

9.4. If You believe Your rights under the PDPL have been infringed, You may lodge a complaint with the competent authority (SDAIA), without prejudice to any other remedies available to You.

10. COOKIES AND SIMILAR TECHNOLOGIES

10.1. Our websites use cookies and similar technologies that are strictly necessary for site operation, and, subject to Your choices, analytics and preference cookies that help us understand usage and improve our websites. You can manage cookies through Your browser settings and, where presented, our cookie preferences tool. Disabling certain cookies may affect site functionality.

11. MINORS

11.1. Our websites and marketing are not directed at minors, and we do not knowingly collect Personal Data from minors as Controller. Patient data of minors processed within the Services is processed on behalf of the Customer as Controller, which is responsible for obtaining any required consent of a parent or legal guardian in accordance with the PDPL and applicable health regulations.

12. CHANGES TO THIS POLICY

12.1. We may update this Policy from time to time to reflect changes in our practices, the Services or applicable law. The current version will always be available at iCenna.com/privacy-policy with its effective date. Material changes will be notified in accordance with the CSA, and where required by the PDPL, we will obtain fresh consent.

13. CONTACT AND DATA PROTECTION OFFICER

13.1.Questions, requests or complaints regarding this Policy or our

Processing of Personal Data may be addressed to our Data Protection

Officer at DPO@iCenna.com