Legal
Privacy Policy
How Dijla Health collects, protects, and gives you control over your health information.
Last updated: July 2026
On this page
Introduction & scope
Dijla Health ("we", "our", "the platform") connects patients, families, doctors, pharmacies, and labs across Iraq. This policy explains what information we collect, why we collect it, how it is protected, and the choices you have over it.
This policy applies to the Dijla Health patient and family experience, the provider portal used by clinics, pharmacies, and labs, and the underlying platform that powers both. It does not apply to third-party sites we may link to.
Information we collect
We collect only what is needed to provide safe, coordinated care and to run a trustworthy provider network.
- Identity documents — national ID, passport, civil status ID, refugee certificate, or a platform-generated reference number for patients without a formal document. These are stored in an isolated, encrypted Identity Vault, kept separate from your medical records.
- Health records — visit notes, prescriptions, lab and radiology results, consent history, and family or pediatric records where applicable.
- Consent records — every grant, scope, and revocation you make, plus a log of who accessed your data and when.
- Account and provider data — for clinics, pharmacies, and labs: facility licenses, employee credentials, and organizational details used for verification.
- Usage data — basic technical logs (device, browser, timestamps) needed for security and to keep the platform running reliably.
Why we process your information
We process your health information to deliver care coordination, prescription fulfillment, lab and radiology workflows, and account security — always tied to a lawful basis: your explicit consent, your care relationship with a verified provider, or a legal or regulatory obligation, such as mandatory reporting of communicable diseases under Iraqi public-health law.
Iraq does not yet have a comprehensive data-protection law equivalent to the GDPR. In the absence of one, we voluntarily apply HIPAA-inspired and GDPR-inspired principles — minimum-necessary access, purpose limitation, and patient consent — because it is the right way to handle health data, not because a regulator requires it.
How access to your data is controlled
Role alone never grants access to your data. Every request to view or change sensitive information is checked against six things at once, and access always stays narrowly scoped — for example, a pharmacist can see prescription-related data only, never your full medical history, and front-desk staff can see identity, check-in, and billing information only, never clinical notes.
- Role — what kind of user is asking (doctor, pharmacist, front desk, admin…)
- Organization — which clinic, pharmacy, or lab they belong to
- Credential — whether their professional license or certification is currently verified and active
- Consent — whether you have granted access for this specific purpose
- Data category — how sensitive the specific record is
- Purpose — why the data is being requested (treatment, dispensing, billing, and so on)
Audit logging of sensitive access
Every view of sensitive data, every prescription created or edited, every dispensing action, every lab result upload, every employee credential change, and every payment is written to an append-only audit log — a record that can be added to but never edited or deleted.
The log captures who accessed what, when, from where, and why, so any access to your information can be reviewed after the fact.
Your consent controls & emergency access
You control who can see your health information. Consent can be granted or revoked at any time, scoped to a specific data category (for example, lab results only), a specific purpose (for example, treatment, not billing), and a specific time window.
In a genuine medical emergency, a clinician may use break-glass access to view your records without prior consent when doing so is necessary to protect your health. Break-glass access is never silent — it is logged, flagged for review, and visible to you.
Data classification
We classify information by sensitivity so the most sensitive data receives the strongest protection:
- Public — general provider-directory information.
- Internal — operational settings and non-sensitive analytics.
- Confidential — provider financials, employee records, and contracts.
- Restricted health data — medical records, prescriptions, lab results, diagnoses, and pediatric or pregnancy-related information.
- Highly restricted — identity document images, audit logs, and emergency access records.
How long we keep your data
Healthcare records are never destructively deleted. We use soft-delete and status-history instead — a corrected or removed record keeps its history rather than disappearing, so care decisions and audits can always be traced.
In the absence of a specific Iraqi retention law, we follow a conservative, internationally recognized standard: adult medical records are retained for 10 years, and pediatric records are retained until the patient turns 25 or for 10 years from the last visit, whichever is longer.
Security measures
Identity documents are stored in a dedicated Identity Vault, isolated from ordinary medical records. Data is encrypted at rest using keys managed through a dedicated key-management service (KMS), and access to encryption keys is itself controlled and logged.
We choose hosting and key-management arrangements built for the security and legal realities of Iraqi healthcare data, and every architectural decision about hosting and encryption is documented for government inspection. These practices are built to align with recognized frameworks such as OWASP ASVS, NIST CSF, and ISO 27001 — we do not claim formal certification we do not hold.
The role of AI
Dijla Health uses AI to summarize, score, translate, and flag — never to replace clinical judgment. AI never diagnoses, prescribes, approves lab results, releases licenses, or overrides your consent settings. A licensed healthcare provider always reviews AI-assisted output before it affects your care, and every AI-assisted clinical summary carries the notice: "AI-assisted summary. Must be reviewed by a licensed healthcare provider."
AI only ever sees what you and your care team have already consented to share, through the same access controls described above — never more.
Your rights
You have the right to:
- Know what information we hold about you and why.
- Access and review your health records and consent history.
- Correct inaccurate information.
- Grant, narrow, or revoke consent for specific providers, data categories, or purposes at any time.
- Request an explanation of any break-glass emergency access to your records.
- Reach us with any question about how your data is used and protected — through our Contact page, which routes privacy requests to the right team.
Families & pediatric records
Family accounts let a parent or guardian manage the health records of children and dependents on their behalf, with the same consent and access controls applied throughout childhood.
We do not require a national ID to register a patient. Undocumented individuals, refugees, and internally displaced persons receive the same standard of data protection and access control as any other patient, and their status is never exposed to provider staff who do not need it for care.
Changes to this policy
We may update this policy as the platform evolves. Material changes will be reflected here with a new "last updated" date. Continued use of the platform after an update means you accept the revised policy.
Contact us
Questions about this policy or how your data is handled? Reach our team through the Contact page and we will route your request to the right people.
Have a question about your data?
Our team can walk you through exactly how your information is protected.
Contact us