Skip to content
CliniTower

Privacy Policy

Last updated: August 27, 2026

CliniTower ("CliniTower", "we", "us") operates clinitower.com and the CliniTower clinic management platform. The legal details of the operating entity are available on request at hello@clinitower.com and will be published on this page. This policy explains how we collect, use, and protect personal data when you visit clinitower.com or use the CliniTower clinic management platform (together, the "Service").

We serve clinics across the Middle East and North Africa and internationally. This policy is written to satisfy the EU and UK General Data Protection Regulation (GDPR), the Saudi Personal Data Protection Law (PDPL), UAE Federal Decree-Law No. 45 of 2021 and the UAE ICT Health Law, Egypt's Data Protection Law No. 151 of 2020, and comparable laws in other countries where our customers operate. Where local law grants you stronger rights than this policy, local law prevails.

1. Roles: when we are controller and when we are processor

For data about visitors to our website, waitlist signups, and clinic staff accounts, CliniTower is the data controller.

For patient data that a clinic enters into the platform (appointments, medical records, invoices, contact details), the clinic is the controller and CliniTower acts only as a processor on the clinic's documented instructions. Patients should direct requests about their data to their clinic; we will assist the clinic in responding.

2. Data we collect

  • Waitlist and contact data: email address and preferred language when you join our waitlist or contact us.
  • Account data: name, work email, phone number, clinic name, role, and login credentials when a clinic creates an account.
  • Billing data: subscription plan, invoices, and payment status. Card details are handled by our payment providers and never stored on our servers.
  • Platform content: information clinics enter into the Service, which may include patient identification, contact, appointment, clinical, and billing information, including health data.
  • Technical data: IP address, device and browser type, pages visited, and server logs, used for security and to operate the Service.

3. Why we use data and our legal bases

  • To provide and operate the Service: performance of a contract.
  • To contact you about the waitlist, onboarding, and service messages: performance of a contract or our legitimate interest in responding to your request.
  • To secure the Service, prevent abuse, and keep logs: legitimate interest and legal obligation.
  • To send marketing about CliniTower: your consent, which you may withdraw at any time.
  • To comply with law, including tax, e-invoicing, and health record retention rules: legal obligation.
  • Patient health data is processed only on the instructions of the clinic that controls it, never for our own marketing, and never sold.

4. Sharing

We do not sell personal data. We share it only with: infrastructure and hosting providers (currently Supabase and Cloudflare), payment processors, communication providers used to deliver reminders and messages (for example the WhatsApp Business API), professional advisers under confidentiality, and public authorities where the law requires it. Processors are bound by contracts that meet GDPR Article 28 and equivalent local standards.

5. International transfers and data residency

Website and waitlist data is currently hosted in the European Union (Frankfurt, Germany). For the clinic platform, we offer hosting arrangements that comply with local residency rules, including the Saudi PDPL's conditions on transfers of health data outside the Kingdom and the UAE ICT Health Law's prohibition on storing or transferring UAE health information outside the UAE except as permitted. Where a transfer is permitted, we use recognized safeguards such as standard contractual clauses or an adequacy decision.

6. Country-specific notices

  • European Union and United Kingdom: you have the rights listed in section 8 under the GDPR and UK GDPR, and the right to complain to your supervisory authority.
  • Saudi Arabia: we process personal data in accordance with the PDPL and its regulations issued by SDAIA. Health data receives the additional safeguards the PDPL requires, and you may complain to the competent authority in the Kingdom.
  • United Arab Emirates: we comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, for health information, with Federal Law No. 2 of 2019 (ICT Health Law) and its data residency requirements.
  • Egypt: we comply with the Personal Data Protection Law No. 151 of 2020, including its rules on sensitive data and licensing issued by the Egyptian data protection authority.
  • Other countries: where you use the Service from a country with its own data protection law (for example Jordan, Qatar, Bahrain, Kuwait, Oman, or Morocco), we honor the mandatory requirements of that law.

7. Retention

We keep waitlist data until you ask us to remove it or the waitlist is closed. Account and billing data is kept for the life of the contract plus the period required by tax and commercial law. Platform content, including patient records, is retained according to the controlling clinic's instructions and applicable medical record retention laws, then deleted or returned. Backups are purged on a rolling schedule.

8. Your rights

Subject to your local law, you may request access to, correction of, deletion of, or a copy of your personal data, object to or restrict certain processing, withdraw consent, and lodge a complaint with a supervisory authority. To exercise these rights, contact us at hello@clinitower.com. We respond within the time limits of the applicable law. If your data is controlled by a clinic, we will forward your request to that clinic and assist it in responding.

9. Security

We use encryption in transit, access controls, role-based permissions, audit logging, and network isolation appropriate to health-related data. No system is completely secure; if a breach affecting your data occurs, we will notify the competent authority and affected controllers or individuals as the applicable law requires.

10. Cookies

The website currently uses only the cookies and similar storage that are strictly necessary for it to function. We do not run third-party advertising trackers. If we introduce analytics cookies, we will ask for consent where the law requires it.

11. Children

Our website and waitlist are intended for adults. Patient records concerning minors are entered and controlled by clinics under the consent rules that apply to them as healthcare providers.

12. Changes and contact

We may update this policy and will post the new version here with a new date. Material changes affecting clinics under contract will be notified directly.

Contact: hello@clinitower.com. If appointed, our data protection officer can be reached at the same address.