Skip to content
DrAxis
Features Security Legal
EN FR AR
Features Security Legal
← Back to legal index

Legal

DrAxis — Privacy Policy

How DrAxis collects, uses, and protects personal data across Tunisia, the EU, and the Gulf.

Last updated: 2026-08-23
⚠ Draft — for internal review. Not legal advice.

DrAxis — Privacy Policy

Status: DRAFT v1 — for internal team review. Not legal advice.
Must be reviewed by qualified legal counsel in each target jurisdiction before publication.
Last updated: 2026-08-23

Document control

FieldValue
Document ownerDrAxis legal/operations
Version0.1 (DRAFT)
Effective date[to be set at publication]
Review cycleAnnual, or upon material change in processing
Languages (target)English, French, Arabic
Public URLhttps://draxis.app/legal/privacy-policy

1. Who we are

DrAxis ("we", "us", "our") is a clinical decision-support and reference platform for licensed healthcare professionals, operated by:

  • Legal entity: [LEGAL_ENTITY_NAME]
  • Registration number: [REGISTRATION_NUMBER]
  • Registered address: [REGISTERED_ADDRESS]
  • Country of establishment: Tunisia
  • Contact — general: legal@draxis.app
  • Contact — Data Protection Officer (DPO): dpo@draxis.app

1.1 EU Representative (Art. 27 GDPR)

For users in the European Union, we have appointed an EU-based representative:

  • Name: [EU_REP_NAME]
  • Address: [EU_REP_ADDRESS]
  • Email: [EU_REP_EMAIL]

1.2 Tunisian DPA registration

We are registered with the Instance Nationale de Protection des Données Personnelles (INPDP) under registration number [INPDP_REGISTRATION_NUMBER].

1.3 Gulf country contacts

For users in the Gulf Cooperation Council (GCC) region, local queries can be directed to legal@draxis.app in the first instance; we will route to the appropriate local representative where required.


2. Scope

This Privacy Policy applies to:

  • The DrAxis mobile application (Android and iOS), distributed via Google Play and the Apple App Store.
  • The DrAxis web application at https://app.draxis.app (if applicable).
  • The DrAxis admin web application at https://admin.draxis.app.
  • The DrAxis backend API at https://api.draxis.app.

It covers the collection, use, storage, sharing, and deletion of personal data across all jurisdictions in which DrAxis is made available, including Tunisia, the European Union / European Economic Area, and the Gulf Cooperation Council member states (with particular attention to the Kingdom of Saudi Arabia and the United Arab Emirates).


3. Lawful basis and legal frameworks

We process personal data under the following legal frameworks:

JurisdictionFrameworkLawful basis relied upon
TunisiaOrganic Law n° 2004-63 (DPA)Consent; legitimate interest of the data controller; legal obligation
EU/EEAGDPR (Reg. (EU) 2016/679)Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests; Art. 9(2)(h) medical diagnosis/treatment (where applicable)
KSAPDPL (Royal Decree M/19)Consent; compliance with legal obligations; legitimate interest
UAEPDPL (Federal Decree-Law n° 45/2022)Consent; performance of a contract; legal obligation
QatarPDPL (Law n° 13/2016)Consent; legitimate interest; legal obligation
BahrainPDPL (Law n° 30/2018)Consent; legitimate interest; legal obligation

Where we rely on consent, you may withdraw it at any time by contacting dpo@draxis.app. Withdrawal does not affect the lawfulness of processing before withdrawal.


4. Personal data we collect

4.1 Data you provide directly

CategoryExamplesPurpose
Identity & contactFull name, phone number (used for authentication via Firebase phone auth)Account creation, authentication, account recovery
Professional credentialsMedical license number, specialty, seniority (Senior / Resident / Intern / External), hospital/clinic affiliation, country of practiceVerification of licensed HCP status; access control; audit
Verification documentsPhotographs or scans of medical license, ID, or institutional affiliation letterIdentity and credential verification (admin-reviewed)
Profile contentProfile photo, bio, professional interestsOptional profile displayed to verified peers
MessagesContent of messages sent via in-app channels to other verified HCPsProvision of the messaging feature
AttachmentsFiles shared in messages (e.g., clinical images, documents)Provision of the messaging feature
Calculator inputsClinical parameters entered into calculators (e.g., age, weight, vital signs, lab values, comorbidities)Generating calculator outputs at the user's request

4.2 Data collected automatically

CategoryExamplesPurpose
Device & technical dataDevice model, OS version, app version, language, IP address (for security/rate-limiting)Service operation, security, abuse prevention
Usage dataScreens viewed, calculators used, timestampsService improvement, audit (per Tunisian medical ethics retention rules)
Authentication tokensFirebase ID tokens, App Check tokensAuthentication, anti-abuse
Crash & diagnostic dataStack traces, non-identifying device telemetry (if/when a crash-reporting SDK is integrated)Stability improvement

4.3 Special categories of data (Art. 9 GDPR / Art. 9 Tunisian DPA)

Calculator inputs and attachments may reveal health data relating to patients. DrAxis is designed so that:

  • Calculator inputs are transient — they are used to compute a result and are not persisted unless the user explicitly saves a result to their account.
  • Saved results store the output and the calculator identifier, not the raw patient inputs, unless the user explicitly chooses to save inputs.
  • Attachments shared in messaging may contain patient-identifiable information; users are solely responsible for anonymizing patient data before sharing, in line with their own professional secrecy obligations.

Where DrAxis processes patient health data on behalf of a healthcare provider (e.g., a hospital subscription), the healthcare provider is the controller and DrAxis is the processor — see our Data Processing Addendum (06-data-processing-addendum.md).


5. How we use your data

PurposeLegal basisData categories
Account creation and authenticationContract / consentIdentity, phone number
Verifying licensed HCP statusLegitimate interest (platform integrity)Credentials, verification documents
Providing calculator, drug, and reference toolsContractCalculator inputs (transient)
Providing messaging between verified HCPsContractMessages, attachments
Audit logging (who did what, when)Legal obligation (Tunisian medical ethics; GDPR Art. 32)User ID, action, timestamp, IP
Preventing abuse, fraud, and unauthorized accessLegitimate interestDevice data, usage data, IP
Service improvement (aggregated, non-identifying)Legitimate interestUsage data
Responding to legal requestsLegal obligationAs requested

We do not use your personal data for:

  • Selling personal data to third parties.
  • Profiling for marketing purposes.
  • Training machine-learning models on identifiable patient data.


6. Sharing and recipients

6.1 Sub-processors

We engage the following sub-processors. Each is bound by written agreement including data protection terms.

Sub-processorPurposeCountry / regionTransfer mechanism
Google LLC / FirebasePhone authentication, App Check, hosting, cloud messagingGlobal (EU data location configurable)Google's GDPR terms; SCCs
OVHcloudVPS hosting (backend + database)[CONFIRM_REGION — must be EU for GDPR]EU-hosted; SCCs if outside EU
[Payment provider]Subscription billing (if/when applicable)TBDTBD

An up-to-date list of sub-processors is maintained at https://draxis.app/legal/sub-processors and is reviewed at least annually.

6.2 Cross-border transfers

Personal data may be transferred outside your country of residence:

  • Tunisia → EU: covered by adequacy where the recipient is in the EU; otherwise SCCs.
  • EU → Tunisia: Tunisia is not covered by an EU adequacy decision. Transfers rely on Standard Contractual Clauses (SCCs) supplemented by transfer impact assessments, or on your explicit consent.
  • Gulf → Tunisia / EU: KSA PDPL restricts cross-border transfers of KSA-residents' personal data; we rely on explicit consent and/or NDMO approval as required.
  • Within EU: no transfer issue.

You may request a copy of the safeguards used for any such transfer by contacting dpo@draxis.app.

6.3 Law enforcement & legal requests

We may disclose personal data where required by law, court order, or competent authority, in any jurisdiction where we operate. We will challenge requests that are over-broad or unlawful where feasible, and log every disclosure in our audit log.


7. International data transfers — detailed safeguards

For transfers from the EU/EEA to a third country not covered by an adequacy decision (including Tunisia), we rely on:

  1. Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/0147) between DrAxis (as controller) and any non-adequate recipient; and
  2. Transfer Impact Assessments considering the destination country's surveillance laws, access rights, and practical effectiveness of remedies.

For transfers of KSA-residents' personal data outside KSA, we comply with PDPL Articles 29 (Cross-Border Transfer) and 30 (Transfer to Similar Level of Protection Countries), relying on:

  • Explicit consent of the data subject; or
  • NDMO approval where required; or
  • Transfer to a country recognized by NDMO as providing an adequate level of protection.


8. Data retention

We retain personal data only for as long as necessary for the purposes set out in this policy, or as required by law. Summary:

Data categoryRetention periodBasis
Account data (identity, phone, credentials)While account is active + 30 days after deletion request (then hard-deleted)Contract; user request
Verification documents12 months after verification decision, then deletedAudit; risk management
Audit logs10 yearsTunisian Code of Medical Ethics (Art. 64 — 10-year medical record retention); GDPR Art. 32 security
Messages & attachmentsWhile account is active; deleted with accountContract
Calculator inputs (transient)Not persisted unless user saves a resultData minimization
Saved calculator resultsWhile account is active; deleted with accountContract
Server logs (IP, request metadata)90 daysSecurity; abuse prevention

Full details in 05-data-retention-policy.md.


9. Your rights

9.1 Rights under GDPR (EU/EEA users)

RightDescription
Access (Art. 15)Obtain a copy of your personal data
Rectification (Art. 16)Correct inaccurate data
Erasure (Art. 17)Request deletion ("right to be forgotten")
Restriction (Art. 18)Limit processing in certain circumstances
Portability (Art. 20)Receive your data in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interests
Rights re: automated decision-making (Art. 22)Not to be subject to solely automated decisions with legal/significant effect (DrAxis does not perform such decisions)
Withdraw consentAt any time, without affecting prior lawfulness

9.2 Rights under Tunisian DPA (Law 2004-63)

  • Right of access (Art. 28).
  • Right to rectify inaccurate data (Art. 29).
  • Right to object to processing for direct marketing (Art. 30).
  • Right to lodge a complaint with INPDP.

9.3 Rights under KSA PDPL

  • Right to be informed (Art. 8).
  • Right to access (Art. 11).
  • Right to correction (Art. 12).
  • Right to destruction (Art. 13).
  • Right to withdraw consent (Art. 7).
  • Right to file a complaint with NDMO.

9.4 Rights under UAE PDPL

  • Right to access (Art. 15).
  • Right to correction (Art. 16).
  • Right to deletion (Art. 17).
  • Right to data portability (Art. 19).
  • Right to withdraw consent (Art. 9).

9.5 How to exercise your rights

Email dpo@draxis.app with:

  • Your registered phone number (so we can locate your account).
  • The right(s) you wish to exercise.
  • Any supporting detail.

We respond within 30 days (GDPR Art. 12(3); KSA PDPL Art. 11 requires response "without delay"). For complex requests, we may extend by up to 2 further months — we will inform you of the extension and reasons within the initial 30 days.

9.6 Supervisory authorities

You have the right to lodge a complaint with your local data protection authority:

  • Tunisia: Instance Nationale de Protection des Données Personnelles (INPDP) — https://inpdp.tn
  • EU: your local Data Protection Authority (e.g., CNIL for France) — list at https://edpb.europa.eu
  • KSA: National Data Management Office (NDMO) — https://ndmo.gov.sa
  • UAE: UAE Data Office — https://www.tdcc.gov.ae

10. Security

We implement technical and organizational measures (TOMs) appropriate to the risk, including:

  • TLS 1.3 in transit; AES-256 at rest for database and object storage.
  • Firebase App Check + reCAPTCHA Enterprise for anti-abuse.
  • Helmet, CORS allowlist, and rate-limiting on the backend.
  • Audit logging of all verification decisions and attachment access.
  • Role-based access control (doctor / admin) with verification gating.
  • Regular security review and incident response procedures (see 08-incident-response-plan.md and 09-information-security-policy.md).

11. Children's data

DrAxis is a professional tool for licensed healthcare professionals aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact dpo@draxis.app so we can delete the account.


12. Changes to this policy

We may update this policy. Material changes will be notified in-app and/or by email at least 30 days before taking effect. The version history is maintained at https://draxis.app/legal/privacy-policy/history.


13. Contact

  • Privacy questions: dpo@draxis.app
  • General legal: legal@draxis.app
  • Postal: [REGISTERED_ADDRESS]

14. Jurisdiction-specific annexes

Annex A — Tunisia

  • Controller registered with INPDP under number [INPDP_REGISTRATION_NUMBER].
  • DPO: [DPO_NAME], dpo@draxis.app.
  • Tunisian law governs the processing of personal data of Tunisian residents, in addition to this policy.
  • Complaints may be lodged with INPDP.

Annex B — European Union

  • EU Representative: [EU_REP_NAME], [EU_REP_ADDRESS], [EU_REP_EMAIL].
  • Lead supervisory authority: [IDENTIFIED — likely CNIL if French is primary language and OVH is in France].
  • We do not carry out automated decision-making with legal or similarly significant effects (GDPR Art. 22).
  • No data is used for direct marketing profiling.

Annex C — Kingdom of Saudi Arabia

  • Personal data of KSA residents is processed in compliance with the PDPL and its Implementing Regulations.
  • Cross-border transfers of KSA personal data outside KSA require your explicit consent or NDMO approval.
  • Complaints may be lodged with NDMO.

Annex D — United Arab Emirates

  • Personal data of UAE residents is processed in compliance with Federal Decree-Law n° 45 of 2022.
  • Complaints may be lodged with the UAE Data Office.

Annex E — Qatar / Bahrain

  • Processing complies with Qatar PDPL (Law n° 13/2016) and Bahrain PDPL (Law n° 30/2018) respectively.
  • Complaints may be lodged with the relevant national authority.
← Back to legal index
DrAxis

Clinical intelligence for verified physicians.

Made in Tunisia for the world.

Product

FeaturesSecurity

Legal

Privacy Policy Terms of Service Medical Disclaimer Acceptable Use Data Retention Data Processing Addendum Cookie Policy

Company

legal@draxis.appdpo@draxis.appSupport

© DrAxis. All rights reserved.