RepHighRepHigh
  • Pricing
  • Company
  • Chat with us
Log inSign up
For Dental ClinicsFor Aesthetic ClinicsFor Dermatology ClinicsFor Physiotherapy Clinics
GuidesDHA complianceFree reputation audit
PricingCompanyChat with us
Log inSign up

Privacy Policy

Effective Date: April 20, 2026 · Last Updated: August 1, 2026

Applicable Law: UAE PDPL, UAE Health Data Law, DHA Regulations, and India’s Digital Personal Data Protection Act 2023

1. Who We Are

RepHigh (“we,” “us,” “our”) is a patient relationship management (PRM) platform operated for private healthcare clinics in Dubai, UAE. We provide automated patient communication, follow-up, reactivation, and organic growth services via WhatsApp Business API and content workflows.

Data Role:

  • For clinic staff and account data: RepHigh is the Data Controller
  • For patient data processed on behalf of clinics: RepHigh is the Data Processor; the licensed healthcare clinic is the Data Controller

Registered Business: RepHigh, a business registered in India (MSME/Udyam)
Place of Business: Gurugram, Haryana, India
Data Protection Contact: support@rephigh.com

RepHigh is operated from India and serves clinics in the United Arab Emirates. Patient data is therefore processed by a party outside the UAE. Section 6 sets out exactly where that data is stored and what this means for your clinic.

2. Scope

This Privacy Policy applies to:

  • Healthcare clinic owners, administrators, and staff who use the RepHigh platform (“Clinic Users”)
  • Patients whose data is processed by RepHigh on behalf of clinics (“Patients”)
  • Visitors to rephigh.com

3. Legal Basis for Processing

All data processing by RepHigh is grounded in lawful bases under UAE PDPL and UAE Federal Law No. 2 of 2019 (Health Data Law), including contractual necessity, explicit consent (obtained by clinic), legitimate interest, and legal obligation.

Critical Note on Health Data: Patient health data is classified as Sensitive Personal Data under UAE PDPL. Processing requires explicit, specific, informed consent. Clinics are responsible for obtaining and documenting this consent.

4. Data We Collect

4.1 Clinic User Data

Identity (name, title), contact (email, phone), business (clinic name, DHA license), financial (billing, tokenized payment), and usage data (login timestamps, IP).

4.2 Patient Data

Identity (first/last name), contact (WhatsApp number), appointment details (date, time, treatment type, doctor), engagement data (delivery status, read receipts), and reactivation data (last visit date).

What We Do NOT Collect: Medical diagnoses, prescriptions, test results, insurance information, or biometric data.

5. How We Use Data

RepHigh processes patient data exclusively to deliver DHA-compliant communication workflows: appointment reminders, post-visit follow-up, patient reactivation, no-show recovery, review collection, and AI-assisted message generation.

6. Data Residency and Storage

Patient data is stored on managed database infrastructure operated by Supabase, Inc. running on Amazon Web Services, and is currently hosted in the Asia-Pacific region, outside the United Arab Emirates. RepHigh is operated from India, so our personnel access this data from India.

We do not store medical diagnoses, prescriptions, test results, insurance information, or biometric data (see Section 4.2). The patient data we hold is contact information, appointment scheduling data, and message history.

What this means for your clinic: UAE Federal Law No. 2 of 2019 restricts the storage and processing of UAE health data outside the UAE. Clinics are the Data Controller and remain responsible for determining whether transferring patient data to RepHigh is permitted for their practice. We recommend you take your own compliance advice before uploading patient records. We will give clinics advance written notice before changing the storage location or region.

7. Data Retention

Patient communication logs and consent records: 25 years (DHA Health Data Quality Policy). Clinic account data: contract duration + 7 years. Billing records: 7 years. Marketing analytics: 2 years.

8. Data Sharing and Sub-Processors

RepHigh does not sell patient data. We share it only with the sub-processors below, each for a single stated purpose:

  • Meta Platforms, Inc. — message delivery via the WhatsApp Business Platform. Message content and recipient phone numbers are transmitted to and processed by Meta. Your patients’ own use of WhatsApp is additionally governed by WhatsApp’s Privacy Policy.
  • Supabase, Inc. (on Amazon Web Services) — database and authentication hosting.
  • Anthropic PBC — AI-assisted drafting of message and review-reply text.
  • Google LLC — Business Profile and Places data, where a clinic connects its Google account.
  • Resend — transactional email delivery.
  • Vercel Inc. — application hosting.

We will update this list before adding any new sub-processor that handles patient data.

8a. Google User Data

Where a clinic connects its Google Business Profile, RepHigh requests the business.manage scope. We use it only to read the clinic’s own reviews and location data, to post replies the clinic has approved, and to report on that clinic’s local visibility. We do not read any other Google account data, and we do not use Google user data for advertising, to train generalised AI or ML models, or to build profiles.

RepHigh’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

A clinic can revoke our access at any time from its Google Account permissions page or from RepHigh’s integration settings. Revoking access stops all further reading and posting immediately.

9. Security Measures

Encryption at rest and TLS in transit, database-level tenant isolation so no clinic can read another clinic’s data, role-based access control within each clinic account, application-layer encryption of third-party credentials, and an audit log of every message sent.

10. Data Subject Rights and Deletion

Patients have the right to: know what data is held, access their data, rectify inaccuracies, request erasure, withdraw consent, data portability, and object to processing. Contact your clinic or email support@rephigh.com.

Deleting your data is free and always available. Full instructions, timeframes, and the one narrow case where a record must be retained are set out on our Data Deletion page.

11. Consent Management

Clinics must obtain explicit, documented patient consent before adding any patient to RepHigh workflows. Every WhatsApp message includes opt-out instructions. Opt-outs are processed immediately.

12. Data Breach Notification

On becoming aware of a breach affecting patient data, RepHigh will investigate and contain it without undue delay, notify affected clinics no later than 72 hours after becoming aware, and provide the details known at that point. Because the clinic is the Data Controller, notification to the UAE Data Office, DHA, or affected patients is made by the clinic; we will give you the information you need to make it.

13. DHA-Specific Compliance

RepHigh is built to support clinics in meeting the DHA Health Data Quality Policy, DHA Standards for Telehealth Services, and DHA Medical Advertisement Guidelines, and is designed to be NABIDH-compatible. RepHigh is a communication and workflow platform; it is not a medical record system and is not itself DHA-licensed. All clinical decisions remain with DHA-licensed professionals.

14. Contact

Data Protection Contact
RepHigh, Gurugram, Haryana, India
Email: support@rephigh.com
Response time: 5 business days

Our full registered address is available on request and is stated on every invoice and Data Processing Agreement.

For data breach reports, email support@rephigh.com with “SECURITY” in the subject line.

RepHigh

Patient growth,
on autopilot.

Get your free audit

Solutions

DentalAestheticDermatologyPhysiotherapy

Company

AboutPricingChat with us
© 2026 RepHigh · Gurugram, India · Serving clinics across the UAE
Privacy PolicyTerms of ServiceDHA ComplianceData Deletion