Privacy Policy
1. Who We Are
RepHigh (“we,” “us,” “our”) is a patient relationship management (PRM) platform operated for private healthcare clinics in Dubai, UAE. We provide automated patient communication, follow-up, reactivation, and organic growth services via WhatsApp Business API and content workflows.
Data Role:
- For clinic staff and account data: RepHigh is the Data Controller
- For patient data processed on behalf of clinics: RepHigh is the Data Processor; the licensed healthcare clinic is the Data Controller
Registered Business: RepHigh, a business registered in India (MSME/Udyam)
Place of Business: Gurugram, Haryana, India
Data Protection Contact: support@rephigh.com
RepHigh is operated from India and serves clinics in the United Arab Emirates. Patient data is therefore processed by a party outside the UAE. Section 6 sets out exactly where that data is stored and what this means for your clinic.
2. Scope
This Privacy Policy applies to:
- Healthcare clinic owners, administrators, and staff who use the RepHigh platform (“Clinic Users”)
- Patients whose data is processed by RepHigh on behalf of clinics (“Patients”)
- Visitors to rephigh.com
3. Legal Basis for Processing
All data processing by RepHigh is grounded in lawful bases under UAE PDPL and UAE Federal Law No. 2 of 2019 (Health Data Law), including contractual necessity, explicit consent (obtained by clinic), legitimate interest, and legal obligation.
Critical Note on Health Data: Patient health data is classified as Sensitive Personal Data under UAE PDPL. Processing requires explicit, specific, informed consent. Clinics are responsible for obtaining and documenting this consent.
4. Data We Collect
4.1 Clinic User Data
Identity (name, title), contact (email, phone), business (clinic name, DHA license), financial (billing, tokenized payment), and usage data (login timestamps, IP).
4.2 Patient Data
Identity (first/last name), contact (WhatsApp number), appointment details (date, time, treatment type, doctor), engagement data (delivery status, read receipts), and reactivation data (last visit date).
What We Do NOT Collect: Medical diagnoses, prescriptions, test results, insurance information, or biometric data.
5. How We Use Data
RepHigh processes patient data exclusively to deliver DHA-compliant communication workflows: appointment reminders, post-visit follow-up, patient reactivation, no-show recovery, review collection, and AI-assisted message generation.
6. Data Residency and Storage
Patient data is stored on managed database infrastructure operated by Supabase, Inc. running on Amazon Web Services, and is currently hosted in the Asia-Pacific region, outside the United Arab Emirates. RepHigh is operated from India, so our personnel access this data from India.
We do not store medical diagnoses, prescriptions, test results, insurance information, or biometric data (see Section 4.2). The patient data we hold is contact information, appointment scheduling data, and message history.
What this means for your clinic: UAE Federal Law No. 2 of 2019 restricts the storage and processing of UAE health data outside the UAE. Clinics are the Data Controller and remain responsible for determining whether transferring patient data to RepHigh is permitted for their practice. We recommend you take your own compliance advice before uploading patient records. We will give clinics advance written notice before changing the storage location or region.
7. Data Retention
Patient communication logs and consent records: 25 years (DHA Health Data Quality Policy). Clinic account data: contract duration + 7 years. Billing records: 7 years. Marketing analytics: 2 years.
8. Data Sharing and Sub-Processors
RepHigh does not sell patient data. We share it only with the sub-processors below, each for a single stated purpose:
- Meta Platforms, Inc. — message delivery via the WhatsApp Business Platform. Message content and recipient phone numbers are transmitted to and processed by Meta. Your patients’ own use of WhatsApp is additionally governed by WhatsApp’s Privacy Policy.
- Supabase, Inc. (on Amazon Web Services) — database and authentication hosting.
- Anthropic PBC — AI-assisted drafting of message and review-reply text.
- Google LLC — Business Profile and Places data, where a clinic connects its Google account.
- Resend — transactional email delivery.
- Vercel Inc. — application hosting.
We will update this list before adding any new sub-processor that handles patient data.
8a. Google User Data
Where a clinic connects its Google Business Profile, RepHigh requests the business.manage scope. We use it only to read the clinic’s own reviews and location data, to post replies the clinic has approved, and to report on that clinic’s local visibility. We do not read any other Google account data, and we do not use Google user data for advertising, to train generalised AI or ML models, or to build profiles.
RepHigh’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
A clinic can revoke our access at any time from its Google Account permissions page or from RepHigh’s integration settings. Revoking access stops all further reading and posting immediately.
9. Security Measures
Encryption at rest and TLS in transit, database-level tenant isolation so no clinic can read another clinic’s data, role-based access control within each clinic account, application-layer encryption of third-party credentials, and an audit log of every message sent.
10. Data Subject Rights and Deletion
Patients have the right to: know what data is held, access their data, rectify inaccuracies, request erasure, withdraw consent, data portability, and object to processing. Contact your clinic or email support@rephigh.com.
Deleting your data is free and always available. Full instructions, timeframes, and the one narrow case where a record must be retained are set out on our Data Deletion page.
11. Consent Management
Clinics must obtain explicit, documented patient consent before adding any patient to RepHigh workflows. Every WhatsApp message includes opt-out instructions. Opt-outs are processed immediately.
12. Data Breach Notification
On becoming aware of a breach affecting patient data, RepHigh will investigate and contain it without undue delay, notify affected clinics no later than 72 hours after becoming aware, and provide the details known at that point. Because the clinic is the Data Controller, notification to the UAE Data Office, DHA, or affected patients is made by the clinic; we will give you the information you need to make it.
13. DHA-Specific Compliance
RepHigh is built to support clinics in meeting the DHA Health Data Quality Policy, DHA Standards for Telehealth Services, and DHA Medical Advertisement Guidelines, and is designed to be NABIDH-compatible. RepHigh is a communication and workflow platform; it is not a medical record system and is not itself DHA-licensed. All clinical decisions remain with DHA-licensed professionals.
14. Contact
Data Protection Contact
RepHigh, Gurugram, Haryana, India
Email: support@rephigh.com
Response time: 5 business days
Our full registered address is available on request and is stated on every invoice and Data Processing Agreement.
For data breach reports, email support@rephigh.com with “SECURITY” in the subject line.
