Privacy Notice
This Privacy Notice applies to the personal data, including sensitive personal data collected, controlled and processed by the [Jeddah Institute for Speech & Hearing]
[Jeddah Centre for Speech, Hearing and Medical Rehabilitation] (referred to as “we”, “us”, “JISH”).
Any reference to a JISH “location” means this website, or any JISH office or premises.
The JISH head office address is at Rawdah District, Rawdat Al Khaleej Street,
P.O. Box 3080, Jeddah 21471, Kingdom of Saudi Arabia.
To whom this Privacy Notice applies
This Privacy Notice is directed to individuals who are patients/users/clients/customers, prospective patients/users/clients/customers, visitors to any of our locations, third parties, contractors/subcontractors/consultants and employees, of JISH.
Definitions
For the purposes of this Privacy Notice, when we refer to:
“personal data”, we mean any information in any form concerning an identified individual, or an individual who can, directly or indirectly, be identified by reference, in particular, to his or her name, personal identification number, or by reference to one or more factors specific to his or her physical, physiological, intellectual, professional, cultural, economic, or social identity. In determining whether an individual is identifiable, all the means that the data controller or any other person uses or may have access to, should be taken into consideration.
“processing”, we mean any operation or set of operations which is performed upon personal data, whether or not by automatic means, including collecting, recording, organizing, classifying into groups, storing, adapting, altering, retrieving, using, disclosing by transmission, dissemination, transference or otherwise making available for others, or combining, blocking, erasing or destroying such personal data.
How do we collect your personal data?
We obtain personal data mainly through any information you provide directly to us or through information provided to us by third parties, or which we otherwise have access to.
Below is a list of ways in which we collect your personal data.
a) Personal data collected directly from you or via your representative, including:
- When you visit any JISH location
- When you enter and use our website
- When you contact us for any enquiry, complaint or for any other reason
- By direct messages in response to JISH activities on JISH social media accounts
b) Personal data collected from other sources, including:
- Other medical professionals
- Public and/or regulatory and/or supervisory authorities
c) Personal data collected from publicly available sources, including:
- The internet
- The press and the media
- Public and/or regulatory and/or supervisory authorities
- Social media applications
- Lists and databases maintained by other entities including international organisations
When do we collect and how do we use your personal data?
We may collect and process your personal data for one or more of the following reasons including but not limited to :
- Where you have given us your consent
- For the provision of medical services to you
- For the performance of a contract we have with you, or taking steps to enter into a contract with you
- In the course of supplying products/providing services to you as a patient/user/client/customer or discussing possible products/services we might provide to you as a prospective patient/user/client/customer and for completing your orders when you buy products and/or services from us
- Communicating with you about our products and services, including providing marketing information, subject to your consent where applicable
- Carrying out statistical analysis, including showing you products and services during your browse time which appear relevant from the information we have about you. This can include using the data you provide for statistical purposes and analyzing how we can improve the services, products or our website for you, and to improve our website and to ensure that the content is secure, presented in the best manner for you
- Providing you with our support through our customer services teams, online or over the phone
- When you reach out to us on social media or through the internet
- Safeguarding legitimate interests pursued by us or by a third party, including to maintain our accounts and records/database, enhance the security of our network and information systems, safeguard the security of our staff, premises and assets, defend, investigate or prosecute legal claims, and consult with external legal and/or tax consultants or other consultants
- Protecting our rights
- Complying with any applicable legal obligations including in relation to compliance
- Managing and maintaining our relationships with you and for ongoing patient/user/customer service
- Resolving complaints, and handling your requests in regard to your personal data
- Managing our operations and complying with our internal policies and procedures
- Undertaking client/customer due diligence
- Recruitment
- Record keeping
- Marketing
What personal information may you provide us?
- Contact Information: including your name, postal address, email address, telephone number, payment address, delivery address to offer our services to you
- Services Information: including purchase history of JISH services and other personal data in relation to matters where we interact
- Supplier Information: including details and other information about supplier providing goods and services to JISH
- Employment Information: including job title, position, employer entity and address
- Online Information: including details about how you access and use our website services, including your online activity behaviour, based on your interaction with us and our website
What personal information do we share with third parties?
We may share your personal data outside JISH under certain circumstances listed below.
When we do so, we require those third parties to have appropriate technical and organizational measures in place to protect your personal data.
We may share your personal data as follows:
- To professional credentialing entities such as Saudi Commission for Health Specialties, and American Speech and Hearing Association ASHA for CEU purposes.
- where required by applicable law and to protect our rights
- to prevent fraud or other criminal activity and to make sure your information is accurate and that your payment is safe; we may pass on the information we have about you to other companies, financial organizations or other organizations specializing in the prevention of fraud and crime
How long do we keep your information for?
We will hold your personal data on our systems for the longest of the following periods:
- As long as it is necessary for the relevant activity or services
- Any retention period that is required by law
- The end of the period in which litigation or investigations might arise in respect of the services, or any retention period as per any applicable retention policy (which can be made available upon request)
What are your rights?
Under certain circumstances, you may have different rights in relation to the personal data we hold about you. Please see the summary of your rights below:
- Right to be informed
- Right to have access
- Right to request correction
For more information about your rights or if you wish to make a complaint, please contact us via
Email address: [[email protected]]
Data Security
We have put in place appropriate security measures to:
- Prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed (e.g., access control, network security, communication security etc.)
- Deal with any suspected personal data breach and will notify you and the Competent Authority of the breach where we are legally required to do so based on the requirements outlined in the law.
Do we link to other websites?
Our website may contain links to and from third party websites. These websites have their own privacy policies. If you follow a link to any of these websites, please make sure that you read their privacy policies before you submit any information to these websites. We do not accept any responsibility or liability for third party websites, or the policies included therein.
Compliance with National Data Protection Laws
JISH is committed to complying with the Personal Data Protection Law (PDPL) of Saudi Arabia and any other applicable data protection laws. We ensure that our data processing activities are in line with legal requirements and that we take all necessary steps to protect your personal data and uphold your rights.
By aligning the Privacy Notice with PDPL, we seek to ensure transparency, and compliance with national data protection standards and regulations, providing reassurance to you about the handling of your personal data.
Updates to this Privacy Notice
We may modify or amend this Privacy Notice from time to time at our discretion and any update will be binding on you.