قانوني
DrAxis — Privacy Policy
How DrAxis collects, uses, and protects personal data across Tunisia, the EU, and the Gulf.
DrAxis — Privacy Policy
Status: DRAFT v1 — for internal team review. Not legal advice.
Must be reviewed by qualified legal counsel in each target jurisdiction before publication.
Last updated: 2026-08-23
Document control
| Field | Value |
|---|---|
| Document owner | DrAxis legal/operations |
| Version | 0.1 (DRAFT) |
| Effective date | [to be set at publication] |
| Review cycle | Annual, or upon material change in processing |
| Languages (target) | English, French, Arabic |
| Public URL | https://draxis.app/legal/privacy-policy |
1. Who we are
DrAxis ("we", "us", "our") is a clinical decision-support and reference platform for licensed healthcare professionals, operated by:
- Legal entity: [LEGAL_ENTITY_NAME]
- Registration number: [REGISTRATION_NUMBER]
- Registered address: [REGISTERED_ADDRESS]
- Country of establishment: Tunisia
- Contact — general:
legal@draxis.app - Contact — Data Protection Officer (DPO):
dpo@draxis.app
1.1 EU Representative (Art. 27 GDPR)
For users in the European Union, we have appointed an EU-based representative:
- Name: [EU_REP_NAME]
- Address: [EU_REP_ADDRESS]
- Email: [EU_REP_EMAIL]
1.2 Tunisian DPA registration
We are registered with the Instance Nationale de Protection des Données Personnelles (INPDP) under registration number [INPDP_REGISTRATION_NUMBER].
1.3 Gulf country contacts
For users in the Gulf Cooperation Council (GCC) region, local queries can be directed to legal@draxis.app in the first instance; we will route to the appropriate local representative where required.
2. Scope
This Privacy Policy applies to:
- The DrAxis mobile application (Android and iOS), distributed via Google Play and the Apple App Store.
- The DrAxis web application at
https://app.draxis.app(if applicable). - The DrAxis admin web application at
https://admin.draxis.app. - The DrAxis backend API at
https://api.draxis.app.
It covers the collection, use, storage, sharing, and deletion of personal data across all jurisdictions in which DrAxis is made available, including Tunisia, the European Union / European Economic Area, and the Gulf Cooperation Council member states (with particular attention to the Kingdom of Saudi Arabia and the United Arab Emirates).
3. Lawful basis and legal frameworks
We process personal data under the following legal frameworks:
| Jurisdiction | Framework | Lawful basis relied upon |
|---|---|---|
| Tunisia | Organic Law n° 2004-63 (DPA) | Consent; legitimate interest of the data controller; legal obligation |
| EU/EEA | GDPR (Reg. (EU) 2016/679) | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests; Art. 9(2)(h) medical diagnosis/treatment (where applicable) |
| KSA | PDPL (Royal Decree M/19) | Consent; compliance with legal obligations; legitimate interest |
| UAE | PDPL (Federal Decree-Law n° 45/2022) | Consent; performance of a contract; legal obligation |
| Qatar | PDPL (Law n° 13/2016) | Consent; legitimate interest; legal obligation |
| Bahrain | PDPL (Law n° 30/2018) | Consent; legitimate interest; legal obligation |
Where we rely on consent, you may withdraw it at any time by contacting dpo@draxis.app. Withdrawal does not affect the lawfulness of processing before withdrawal.
4. Personal data we collect
4.1 Data you provide directly
| Category | Examples | Purpose |
|---|---|---|
| Identity & contact | Full name, phone number (used for authentication via Firebase phone auth) | Account creation, authentication, account recovery |
| Professional credentials | Medical license number, specialty, seniority (Senior / Resident / Intern / External), hospital/clinic affiliation, country of practice | Verification of licensed HCP status; access control; audit |
| Verification documents | Photographs or scans of medical license, ID, or institutional affiliation letter | Identity and credential verification (admin-reviewed) |
| Profile content | Profile photo, bio, professional interests | Optional profile displayed to verified peers |
| Messages | Content of messages sent via in-app channels to other verified HCPs | Provision of the messaging feature |
| Attachments | Files shared in messages (e.g., clinical images, documents) | Provision of the messaging feature |
| Calculator inputs | Clinical parameters entered into calculators (e.g., age, weight, vital signs, lab values, comorbidities) | Generating calculator outputs at the user's request |
4.2 Data collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Device & technical data | Device model, OS version, app version, language, IP address (for security/rate-limiting) | Service operation, security, abuse prevention |
| Usage data | Screens viewed, calculators used, timestamps | Service improvement, audit (per Tunisian medical ethics retention rules) |
| Authentication tokens | Firebase ID tokens, App Check tokens | Authentication, anti-abuse |
| Crash & diagnostic data | Stack traces, non-identifying device telemetry (if/when a crash-reporting SDK is integrated) | Stability improvement |
4.3 Special categories of data (Art. 9 GDPR / Art. 9 Tunisian DPA)
Calculator inputs and attachments may reveal health data relating to patients. DrAxis is designed so that:
- Calculator inputs are transient — they are used to compute a result and are not persisted unless the user explicitly saves a result to their account.
- Saved results store the output and the calculator identifier, not the raw patient inputs, unless the user explicitly chooses to save inputs.
- Attachments shared in messaging may contain patient-identifiable information; users are solely responsible for anonymizing patient data before sharing, in line with their own professional secrecy obligations.
Where DrAxis processes patient health data on behalf of a healthcare provider (e.g., a hospital subscription), the healthcare provider is the controller and DrAxis is the processor — see our Data Processing Addendum (06-data-processing-addendum.md).
5. How we use your data
| Purpose | Legal basis | Data categories |
|---|---|---|
| Account creation and authentication | Contract / consent | Identity, phone number |
| Verifying licensed HCP status | Legitimate interest (platform integrity) | Credentials, verification documents |
| Providing calculator, drug, and reference tools | Contract | Calculator inputs (transient) |
| Providing messaging between verified HCPs | Contract | Messages, attachments |
| Audit logging (who did what, when) | Legal obligation (Tunisian medical ethics; GDPR Art. 32) | User ID, action, timestamp, IP |
| Preventing abuse, fraud, and unauthorized access | Legitimate interest | Device data, usage data, IP |
| Service improvement (aggregated, non-identifying) | Legitimate interest | Usage data |
| Responding to legal requests | Legal obligation | As requested |
We do not use your personal data for:
- Selling personal data to third parties.
- Profiling for marketing purposes.
- Training machine-learning models on identifiable patient data.
6. Sharing and recipients
6.1 Sub-processors
We engage the following sub-processors. Each is bound by written agreement including data protection terms.
| Sub-processor | Purpose | Country / region | Transfer mechanism |
|---|---|---|---|
| Google LLC / Firebase | Phone authentication, App Check, hosting, cloud messaging | Global (EU data location configurable) | Google's GDPR terms; SCCs |
| OVHcloud | VPS hosting (backend + database) | [CONFIRM_REGION — must be EU for GDPR] | EU-hosted; SCCs if outside EU |
| [Payment provider] | Subscription billing (if/when applicable) | TBD | TBD |
An up-to-date list of sub-processors is maintained at https://draxis.app/legal/sub-processors and is reviewed at least annually.
6.2 Cross-border transfers
Personal data may be transferred outside your country of residence:
- Tunisia → EU: covered by adequacy where the recipient is in the EU; otherwise SCCs.
- EU → Tunisia: Tunisia is not covered by an EU adequacy decision. Transfers rely on Standard Contractual Clauses (SCCs) supplemented by transfer impact assessments, or on your explicit consent.
- Gulf → Tunisia / EU: KSA PDPL restricts cross-border transfers of KSA-residents' personal data; we rely on explicit consent and/or NDMO approval as required.
- Within EU: no transfer issue.
You may request a copy of the safeguards used for any such transfer by contacting dpo@draxis.app.
6.3 Law enforcement & legal requests
We may disclose personal data where required by law, court order, or competent authority, in any jurisdiction where we operate. We will challenge requests that are over-broad or unlawful where feasible, and log every disclosure in our audit log.
7. International data transfers — detailed safeguards
For transfers from the EU/EEA to a third country not covered by an adequacy decision (including Tunisia), we rely on:
- Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/0147) between DrAxis (as controller) and any non-adequate recipient; and
- Transfer Impact Assessments considering the destination country's surveillance laws, access rights, and practical effectiveness of remedies.
For transfers of KSA-residents' personal data outside KSA, we comply with PDPL Articles 29 (Cross-Border Transfer) and 30 (Transfer to Similar Level of Protection Countries), relying on:
- Explicit consent of the data subject; or
- NDMO approval where required; or
- Transfer to a country recognized by NDMO as providing an adequate level of protection.
8. Data retention
We retain personal data only for as long as necessary for the purposes set out in this policy, or as required by law. Summary:
| Data category | Retention period | Basis |
|---|---|---|
| Account data (identity, phone, credentials) | While account is active + 30 days after deletion request (then hard-deleted) | Contract; user request |
| Verification documents | 12 months after verification decision, then deleted | Audit; risk management |
| Audit logs | 10 years | Tunisian Code of Medical Ethics (Art. 64 — 10-year medical record retention); GDPR Art. 32 security |
| Messages & attachments | While account is active; deleted with account | Contract |
| Calculator inputs (transient) | Not persisted unless user saves a result | Data minimization |
| Saved calculator results | While account is active; deleted with account | Contract |
| Server logs (IP, request metadata) | 90 days | Security; abuse prevention |
Full details in 05-data-retention-policy.md.
9. Your rights
9.1 Rights under GDPR (EU/EEA users)
| Right | Description |
|---|---|
| Access (Art. 15) | Obtain a copy of your personal data |
| Rectification (Art. 16) | Correct inaccurate data |
| Erasure (Art. 17) | Request deletion ("right to be forgotten") |
| Restriction (Art. 18) | Limit processing in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests |
| Rights re: automated decision-making (Art. 22) | Not to be subject to solely automated decisions with legal/significant effect (DrAxis does not perform such decisions) |
| Withdraw consent | At any time, without affecting prior lawfulness |
9.2 Rights under Tunisian DPA (Law 2004-63)
- Right of access (Art. 28).
- Right to rectify inaccurate data (Art. 29).
- Right to object to processing for direct marketing (Art. 30).
- Right to lodge a complaint with INPDP.
9.3 Rights under KSA PDPL
- Right to be informed (Art. 8).
- Right to access (Art. 11).
- Right to correction (Art. 12).
- Right to destruction (Art. 13).
- Right to withdraw consent (Art. 7).
- Right to file a complaint with NDMO.
9.4 Rights under UAE PDPL
- Right to access (Art. 15).
- Right to correction (Art. 16).
- Right to deletion (Art. 17).
- Right to data portability (Art. 19).
- Right to withdraw consent (Art. 9).
9.5 How to exercise your rights
Email dpo@draxis.app with:
- Your registered phone number (so we can locate your account).
- The right(s) you wish to exercise.
- Any supporting detail.
We respond within 30 days (GDPR Art. 12(3); KSA PDPL Art. 11 requires response "without delay"). For complex requests, we may extend by up to 2 further months — we will inform you of the extension and reasons within the initial 30 days.
9.6 Supervisory authorities
You have the right to lodge a complaint with your local data protection authority:
- Tunisia: Instance Nationale de Protection des Données Personnelles (INPDP) —
https://inpdp.tn - EU: your local Data Protection Authority (e.g., CNIL for France) — list at
https://edpb.europa.eu - KSA: National Data Management Office (NDMO) —
https://ndmo.gov.sa - UAE: UAE Data Office —
https://www.tdcc.gov.ae
10. Security
We implement technical and organizational measures (TOMs) appropriate to the risk, including:
- TLS 1.3 in transit; AES-256 at rest for database and object storage.
- Firebase App Check + reCAPTCHA Enterprise for anti-abuse.
- Helmet, CORS allowlist, and rate-limiting on the backend.
- Audit logging of all verification decisions and attachment access.
- Role-based access control (doctor / admin) with verification gating.
- Regular security review and incident response procedures (see
08-incident-response-plan.mdand09-information-security-policy.md).
11. Children's data
DrAxis is a professional tool for licensed healthcare professionals aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact dpo@draxis.app so we can delete the account.
12. Changes to this policy
We may update this policy. Material changes will be notified in-app and/or by email at least 30 days before taking effect. The version history is maintained at https://draxis.app/legal/privacy-policy/history.
13. Contact
- Privacy questions:
dpo@draxis.app - General legal:
legal@draxis.app - Postal: [REGISTERED_ADDRESS]
14. Jurisdiction-specific annexes
Annex A — Tunisia
- Controller registered with INPDP under number [INPDP_REGISTRATION_NUMBER].
- DPO: [DPO_NAME],
dpo@draxis.app. - Tunisian law governs the processing of personal data of Tunisian residents, in addition to this policy.
- Complaints may be lodged with INPDP.
Annex B — European Union
- EU Representative: [EU_REP_NAME], [EU_REP_ADDRESS], [EU_REP_EMAIL].
- Lead supervisory authority: [IDENTIFIED — likely CNIL if French is primary language and OVH is in France].
- We do not carry out automated decision-making with legal or similarly significant effects (GDPR Art. 22).
- No data is used for direct marketing profiling.
Annex C — Kingdom of Saudi Arabia
- Personal data of KSA residents is processed in compliance with the PDPL and its Implementing Regulations.
- Cross-border transfers of KSA personal data outside KSA require your explicit consent or NDMO approval.
- Complaints may be lodged with NDMO.
Annex D — United Arab Emirates
- Personal data of UAE residents is processed in compliance with Federal Decree-Law n° 45 of 2022.
- Complaints may be lodged with the UAE Data Office.
Annex E — Qatar / Bahrain
- Processing complies with Qatar PDPL (Law n° 13/2016) and Bahrain PDPL (Law n° 30/2018) respectively.
- Complaints may be lodged with the relevant national authority.