Skip to main content

Privacy policy

What personal data Saff handles, why we handle it, and the choices you have.

Last updated: 22 August 2026

Who we are and what this covers

Saff is a patient-queue, appointment and clinic-management platform operated by Saff FZ LLC. This policy covers the Saff website and the Saff application. It does not cover a clinic's own website, its paper records, or any service a clinic offers outside Saff.

Your clinic is the controller of your health data

When a clinic uses Saff to run its queue and keep its records, that clinic decides what is collected and why: it is the data controller, and Saff acts as its processor, handling data only on the clinic's instructions. Requests about your medical record therefore start with your clinic, and the product gives the clinic the tools to answer them. We are the controller in our own right only for the marketing site, waitlist sign-ups, clinic applications and the security logs we need to keep the platform safe.

What data is held

The categories below are the ones the platform actually stores. Not every clinic uses every module, so what exists for you depends on which parts of Saff your clinic has switched on.

Account and identity
Name, email address, phone number, preferred language, calendar and numeral preferences, sign-in credentials and, for staff, a two-factor secret.
Patient profile
Date of birth, sex, nationality, national-ID type and number, emergency contact name, phone and relationship, blood type, allergies, chronic conditions and current medications.
Clinical records
Visit notes, problem list, vital signs, immunisations, family and social history, prescriptions, lab orders and results, referrals, mental-health notes, pre-visit form answers and documents your clinic uploads.
Appointments and queue activity
Bookings, walk-ins, check-in times, queue position, wait and travel estimates, visit progress, cancellations, no-shows and the reviews you choose to leave.
Billing and insurance
Invoices, payments, refunds, packages and loyalty tiers, coupons, insurance eligibility checks, claims and pre-authorisations.
Messages and notifications
Notification history and delivery status, your per-channel contact preferences, quiet hours and do-not-disturb settings, questions you send your doctor and the replies you receive.
Consent records
What you agreed to, which version of the text you were shown, a hash of that text, when you agreed, when you withdrew, and a shortened description of the browser you used.
Location
Your approximate position, and only while you have explicitly turned on location sharing so the clinic can estimate when you will arrive. It is used for that estimate and nothing else.
Technical and security records
Audit entries recording who accessed or changed which record, with the IP address stored as a hash and the browser string truncated; plus the operational logs that keep the service running.

Why the data is processed

Data is processed to run the queue and show wait estimates, to book, confirm, remind and cancel appointments, to let clinicians record and read clinical notes, prescriptions and lab orders, to issue invoices and record payments, to answer your requests, and to keep the platform secure and auditable. The lawful bases are the contract between you and your clinic, the clinic's legal obligations for medical records, our legitimate interest in operating and securing the platform, and, for anything optional, your explicit consent.

Messages you receive without opting in

Booking confirmations, reminders, "you're next" alerts, cancellations made by the clinic and visit-completed notices are operational: they are part of the care you asked for, so they are sent without a marketing opt-in. Marketing and bulk messages are separate and require consent, which you can withdraw per channel at any time.

How the data is protected

Sensitive columns (phone numbers, national-ID numbers, emergency contacts, allergies, chronic conditions, medications, blood type, clinical and mental-health notes, prescription contents, lab notes and results, uploaded-document keys, patient messages and team chat) are encrypted at rest with AES-GCM, each column bound to its own identifier so ciphertext cannot be moved between columns. Where the product must search on an encrypted value it stores a keyed HMAC fingerprint instead of the value. Every read and write is scoped to a single clinic at the database layer, so one clinic's data is unreachable from another's session. Staff can enable time-based two-factor authentication, session cookies are host-locked and secure in production, public forms are protected against automated abuse, and sensitive actions are written to an append-only audit trail.

What we deliberately keep out of our logs

Our application logs never carry names, phone numbers, email addresses, message bodies or clinical content. They carry identifiers, hashes, counts and fixed status labels only. The audit trail records who did what to which record, with the IP address hashed, the browser string truncated, and, where extra detail is stored, the names of the fields that changed rather than their values.

Cookie policy

Saff uses a small number of cookies, all of them first-party except the one that keeps bots off our public forms. We set no advertising cookies and, today, no analytics cookies at all. Nothing optional runs until you say yes.

Strictly necessary cookies

These make sign-in, security and language selection work. They carry no advertising identifier and are exempt from the consent requirement, so they cannot be switched off inside the product. Blocking them in your browser will stop you from signing in.

NamePurposeCategoryDuration
authjs.session-tokenKeeps you signed in and identifies your session. Prefixed with __Host- and marked secure in production.Strictly necessaryUntil you sign out or the session expires
authjs.csrf-tokenProtects sign-in and account forms against cross-site request forgery.Strictly necessaryBrowser session
authjs.callback-urlRemembers where you were so you land back on the right page after signing in.Strictly necessaryBrowser session
__Host-saff-platformSigns in Saff platform operators. It is never set for clinic staff or patients.Strictly necessaryUntil sign-out or expiry
NEXT_LOCALERemembers the language you picked with the language switch, so pages render in Arabic or English as you chose. Set only when you use the switch.Preferences12 months
saff_sidebarRemembers whether a clinic team member folded or expanded the staff sidebar, so the next page opens at the same width. Set only when the collapse button is used.Preferences12 months
saff_densityRemembers the display density a clinic team member chose on a desktop, comfortable or compact. Set only when the density control is used.Preferences12 months
Cloudflare TurnstileChecks that the clinic application and demo request forms are sent by a person. Set by Cloudflare.Strictly necessaryShort-lived, set per challenge

Stored in your browser, never sent to us

These two values live in your browser's local storage. They are read by the page you are looking at and are never transmitted to our servers, which is also why your cookie choices have to be made again if you clear your browsing data or switch browser.

NamePurposeCategoryDuration
consent_v1Your cookie choices. Stored only in your browser and never sent to our servers.PreferencesUntil you clear site data or reset your preferences
theme_v1Whether you prefer the light or dark appearance, or want to follow your system setting.PreferencesUntil you clear site data

Analytics and marketing cookies

The consent banner offers analytics and marketing categories and both default to off. No analytics or advertising service is currently connected to Saff, so choosing "accept all" today does not switch anything on. If that changes, the banner will ask again before anything is set, and this page will list what was added.

Third-party cookies

The only third party that can set a cookie on our site is Cloudflare, whose Turnstile check protects the clinic application and demo request forms from automated abuse. It sees the request and the challenge result, not the answers you type into the form.

Changing your choices

Reopen the consent banner with the button below to review or change every optional category. You can also block or delete cookies in your browser settings. Remember that blocking the strictly necessary ones will break sign-in.

Who else can see your data

We do not sell personal data and we do not share it for advertising. Data reaches other companies only where a feature needs it, and in most cases your clinic chooses those providers itself and connects them with its own account credentials.

Messaging providers
Clinics connect their own SMS, email and WhatsApp accounts. The platform supports Twilio, MessageBird and SMSMisr for SMS, Resend and SendGrid for email, and the Meta WhatsApp Cloud API or 360dialog for WhatsApp. The provider receives the recipient's contact detail and the message content needed to deliver it.
Payment providers
Where a clinic takes payment online it connects its own Stripe, Fawry or Paymob account. Card details go to the payment provider, not to Saff.
Laboratories
When a clinic links a laboratory over a FHIR or HL7 connection, the order details needed to run the test are sent to that laboratory.
Bot protection
Cloudflare Turnstile checks that the clinic application and demo request forms are sent by a person. It sees the request, not your form answers.
Travel-time estimates
If the operator has enabled live travel times and you have consented to location sharing, a coordinate pair is sent to Google's Distance Matrix service to estimate your journey. Without either of those, distance is estimated locally with no third party involved.
Hosting and database
The infrastructure provider that runs the servers and the database in the region named above. It holds the data at rest; the sensitive columns reach it already encrypted.

Where the data is stored

Production data will be migrated to country-compliant infrastructure prior to clinic onboarding. Until that migration is complete, production runs from a single hosting region and data is not yet stored separately in the country where your clinic operates. Saff's storage policy is to keep clinic and patient data inside the country the clinic operates in, and to move it across a border only where that country's rules allow it. Test and staging environments never carry real patient data.

How long it is kept

Clinical records are kept by your clinic for as long as the law requires it to keep them (25 years from the date of the last medical service, the retention period required for health data under UAE Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in the Health Fields), because that decision belongs to the clinic as controller, not to us. Consent records and audit entries are kept for as long as they are needed as evidence that a rule was followed. Marketing-site data such as a waitlist entry is kept until you ask us to remove it or until it is no longer useful.

What happens when you delete your account

Deleting your patient account takes effect immediately: your sign-in stops working, any session you still have open is ended on its next request, and your profile disappears from the clinic's patient lists. What that action does NOT do is destroy the clinical record itself. Your clinic is legally obliged to retain it for the statutory period, after which it is erased. If you want a copy, export your data before you delete the account.

Your rights

You can exercise the rights below from inside your patient account, or by writing to us or to your clinic. We will not charge you, and we will not ask why.

Access and portability
Download everything held under your patient account as a structured file, from the privacy section of your account. The file states plainly what it leaves out and why: notes a clinician wrote ABOUT you are staff clinical material and are requested through your clinic, and your national-ID number is withheld from a self-service download because it is an identity credential.
Correction
Edit your own profile details in your account. Ask your clinic to correct anything in a clinical record. The clinic amends the record and the change is captured in the audit trail.
Deletion
Delete your account from your account settings. Access ends immediately and your profile leaves the clinic's lists; the clinical record itself is retained by the clinic for the statutory period and erased afterwards.
Withdrawing consent
Turn off location sharing, a companion's access to your queue status or cross-clinic record sharing from the privacy section of your account. Withdrawal takes effect immediately and does not undo processing that was lawful before it.
Stopping marketing
Opt out of marketing email, SMS or WhatsApp separately per channel in your communication preferences. Operational messages about your own appointments continue.
Restriction and objection
Ask us or your clinic to pause a particular use of your data, or object to processing we base on a legitimate interest. We will act on it unless we are legally required to continue.
Complaining
Raise a complaint with your clinic, with us, or directly with the supervisory authority in your country. Complaining does not affect your care.

Children and dependants

Saff is not designed for children to use on their own. A parent, guardian or authorised carer registers the child as a patient, books on their behalf, and is the person who gives and withdraws any consent. The same protections apply to a dependant's record as to an adult's.

Changes to this policy

When this policy changes materially we will update the date at the top of the page and, where the change affects something you consented to, ask for that consent again rather than assuming the old one still stands.

Contact and complaints

For anything in this policy, or to exercise a right, contact us at the address below. If you believe your data has been mishandled you can also complain to the supervisory authority (The UAE Data Office, established under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data) and, for a clinical record, to your clinic directly.

Operator
Saff FZ LLC
Email
privacy@saff.me
Postal address
Dubai, United Arab Emirates
Data protection contact
Data Protection Officer, Saff FZ LLC: dpo@saff.me
Privacy policy