Legal

CareWay Privacy Policy

Effective date: July 28, 2026Last updated: July 28, 2026Policy version: 1.0

This Privacy Policy explains how CareWay collects, uses, discloses, stores, and protects personal data when you use the CareWay mobile application, web application, application programming interfaces, symptom assistant, and related services (collectively, “CareWay” or the“Service”).

CareWay is a patient platform developed and operated by Whizz Multi-Solutions, through its Whizz Tech practice (“Whizz,” “we,” “us,” or “our”). CareWay may be provided to you for, or on behalf of, a hospital, health cluster, ministry, or other healthcare organization (a “Healthcare Provider”).

Please read this Policy before using CareWay. If a short permission notice or just-in-time disclosure shown in the app conflicts with this Policy, the notice that gives you more privacy protection will apply.

1. Who is responsible for your personal data?

Responsibility depends on the data and the CareWay deployment:

  • Your Healthcare Provider is generally the controller of clinical records, hospital patient numbers, appointments, visits, and other care-delivery data obtained from or written to its health information systems. Its own privacy notice and legally required medical-record retention rules also apply.
  • Whizz generally processes that Healthcare Provider data on the Provider’s instructions to operate CareWay.
  • Whizz is responsible for data it determines how to use for CareWay account administration, authentication, platform security, support, service reliability, and compliance, unless a deployment agreement says otherwise.

Where Saudi Arabia’s Personal Data Protection Law (“PDPL”) applies, “controller,” “processor,” “personal data,” “sensitive data,” and “processing” have the meanings given by that law. Health data and data revealing a person’s identity, including a national identifier, require particularly careful handling.

If you are unsure which organization controls a record, contact us usingSection 18. We will either handle the request or direct it to the appropriate Healthcare Provider.

2. Summary of CareWay’s privacy practices

  • CareWay uses identity, contact, national-identifier, and health information to identify patients and provide account and healthcare-related features.
  • CareWay can retrieve and display connected hospital records, support appointment activity, and allow a person you authorize to act for you.
  • The optional symptom assistant processes health-related text. Optional voice input processes microphone audio and a transcript.
  • CareWay does not contain advertising SDKs and does not sell personal data. We do not use health data for advertising, cross-app tracking, or data brokerage.
  • The app does not request device location, contacts, calendars, camera, photos, Apple HealthKit, Google Health Connect, or an advertising identifier in the reviewed version.
  • You can decline microphone and speech-recognition permissions and type symptoms instead.
  • You may request access, correction, a copy, withdrawal of consent where applicable, and deletion, subject to healthcare, legal, security, and record-retention requirements.

3. Personal data we collect

The data actually collected depends on the features you use and the Healthcare Provider connected to your account.

3.1 Account, identity, and contact data

We may collect:

  • first, middle, and last name;
  • email address and telephone number;
  • country code and date of birth;
  • national or government identifier;
  • account and patient identifiers, authentication-provider identifiers, and selected Healthcare Provider or tenant;
  • password credentials for email/password authentication; and
  • access tokens, refresh tokens, session identifiers, email-verification status, and password-reset or email-change records.

Your password is used to authenticate you through CareWay’s identity service. CareWay does not need to display your password to its staff. Please never send us your password by email or through a support request.

3.2 Health and healthcare data

Depending on the connected Healthcare Provider and features enabled, we may process:

  • hospital and medical-record numbers, including GMRN, HMRN, episode, or equivalent identifiers;
  • hospitals and facilities with which you have a patient relationship;
  • appointments, appointment slots, specialties, practitioners, booking requests, cancellations, and cancellation reasons;
  • visits, encounter timelines, and visit summaries;
  • symptoms and medical-history summaries;
  • diagnoses, conditions, allergies, medications, procedures, laboratory results, vital signs, abnormalities, and other clinical-summary content; and
  • the identity of the patient whose records are being viewed when an authorized representative is acting for another person.

Most underlying clinical records remain in the Healthcare Provider’s systems. CareWay transmits requests to those systems and may temporarily cache or preprocess results so the Service can respond reliably.

3.3 Symptom-assistant, text, audio, and transcript data

If you use the symptom assistant, we process:

  • the symptoms and other free-form text you submit;
  • a random chat-session identifier;
  • your name and age on the first message of a chat session;
  • assistant questions and responses, possible condition labels, and suggested specialties; and
  • if voice input is used, microphone audio and its transcript.

The current app can use either the device’s speech-recognition service or an optional cloud transcription service. For cloud transcription, a temporary audio file is created on the device, uploaded for transcription, and the app attempts to delete that temporary file immediately after the transcription attempt, whether it succeeds or fails. The transcript becomes editable text and is sent to the symptom assistant only when you choose to submit it.

Device speech recognition may be processed by Apple, Google, or another operating-system speech provider according to your device settings and that provider’s terms. A CareWay deployment may use a Whizz-configured transcription endpoint or OpenAI’s audio transcription API.Section 7 explains these recipients.

3.4 Delegation and consent data

If you ask another CareWay user to act for you, or another user asks you to act for them, we may process:

  • both users’ account identifiers, names, and email addresses;
  • the requested and granted actions;
  • consent status, version, start, expiry, and change timestamps;
  • acceptance, rejection, revocation, expiry, or block reasons; and
  • audit events showing access performed on another patient’s behalf.

An authorized representative may see only the data and perform only the actions covered by the active consent and applicable Healthcare Provider rules. Do not delegate access to someone you do not trust.

3.5 Technical, security, audit, and usage data

When you use CareWay, our servers and infrastructure may collect:

  • IP address, request time, endpoint, HTTP method, status, and response time;
  • browser or app user agent, operating environment, and network information sent as part of a request;
  • account, tenant, actor, and represented-patient identifiers;
  • login, logout, token, email-change, account-deletion, permission, delegation, and other security events;
  • correlation identifiers and error or diagnostic details;
  • feature-operation records, including whether a response used a cache or a connected Healthcare Provider system; and
  • support and troubleshooting information you choose to provide.

CareWay does not use this data to build advertising profiles. We use it to authenticate users, prevent abuse, enforce permissions, investigate incidents, maintain availability, diagnose errors, meet audit obligations, and improve technical reliability.

3.6 Data stored on your device

The mobile app stores selected information in app-managed secure storage, including:

  • access and refresh tokens;
  • your selected Healthcare Provider, hospital, and account association;
  • cached scheduling payloads such as hospital or practitioner results;
  • limited preferences, such as whether a delegation introduction was shown; and
  • up to five recently visited CareWay screen names, routes, and visit times, used to show recent shortcuts.

Signing out clears CareWay authentication tokens and its scheduling cache. Some non-authentication preferences, including the last selected Healthcare Provider and recent-screen shortcuts, may remain until cleared or overwritten. Device operating systems, backups, and secure keychains may have their own retention behavior.

The CareWay web application stores OpenID Connect authentication state and tokens in the browser’s session storage and uses necessary authentication and tenant cookies. Current web authentication defaults limit the server authentication cookie to a 24-hour absolute lifetime and a 30-minute sliding idle period. Closing the browser session normally clears session storage; signing out is the safer way to end an active session.

4. How we collect personal data

We collect data:

  • directly from you when you register, complete or edit your profile, submit a symptom, use voice input, book or cancel an appointment, delegate access, or contact support;
  • from Google or Apple if you choose federated sign-in, such as the provider account identifier, verified email, and token needed to authenticate you;
  • from your Healthcare Provider and its connected health information systems;
  • from another CareWay user when that user requests delegation involving you; and
  • automatically from CareWay apps, servers, identity systems, security tools, and infrastructure when you use the Service.

If you provide data about another person, you must be authorized to do so and must not use CareWay to access another person’s records without valid consent or legal authority.

5. Why we use personal data

We use personal data only for specified purposes, including to:

  1. create, verify, secure, and administer your account;
  2. match your CareWay account to the correct patient record;
  3. retrieve and display hospital, appointment, visit, and clinical-summary data;
  4. search for practitioners and slots, and submit bookings or cancellations;
  5. provide symptom intake, speech transcription, and specialty suggestions;
  6. enable, record, enforce, and revoke delegated access;
  7. send transactional messages such as account verification, security, password-reset, or email-change messages;
  8. provide support and respond to rights requests;
  9. prevent fraud, unauthorized access, and misuse;
  10. log access to health information and maintain service integrity;
  11. diagnose failures, measure service performance, and maintain availability; and
  12. comply with legal, regulatory, healthcare, audit, and court requirements.

We will not use health, national-identifier, audio, transcript, or clinical data for advertising, data brokerage, or unrelated marketing. We will not repurpose personal data in a way incompatible with the purpose disclosed at collection without first giving an updated notice and obtaining consent when the law requires it.

6. Legal grounds for processing

The legal ground depends on your location, the data, the Healthcare Provider, and the feature:

  • Providing the Service or taking requested steps: to create and operate your account and deliver the features you request.
  • Healthcare and public-interest authority: where processing is necessary for care delivery, health-system administration, continuity of care, public health, or another basis established by applicable health law.
  • Legal or regulatory obligation: for identity verification, security, medical-record, audit, incident, and lawful-disclosure requirements.
  • Consent: for optional microphone access, cloud transcription, optional federated sign-in, or other processing where consent is the required basis.
  • Permitted legitimate or actual interests: for proportionate platform security, fraud prevention, and reliability where applicable law permits that basis and it does not override your rights. We do not rely on this basis for sensitive data where the law prohibits doing so.

Where a feature is optional, the app will identify it as such. Identity and patient-matching information may be mandatory because CareWay cannot safely show clinical records or submit appointment actions without identifying the correct patient. If you do not provide mandatory data, the relevant account or healthcare feature may be unavailable.

Withdrawing consent does not affect processing already lawfully performed. It also does not stop processing that is required on another legal ground, but we will explain this if it applies.

7. When and with whom we disclose data

We disclose only the data reasonably necessary for the recipient’s role:

7.1 Healthcare Providers and authorized users

We exchange identity, patient-matching, appointment, visit, symptom, and clinical data with the Healthcare Provider connected to your account, its authorized practitioners and staff, and its health information systems. Information may also be visible to a representative whom you validly authorize.

7.2 Service providers

We use contracted providers to operate CareWay. Depending on deployment and the feature you choose, these may include:

  • cloud hosting, networking, storage, database, secret-management, email, monitoring, and security providers, including Google Cloud;
  • an identity and access-management service based on Keycloak;
  • Google Sign-In and Sign in with Apple when you select those options;
  • a Google Cloud-hosted CareWay symptom-assistant service; and
  • a Whizz-configured speech service or OpenAI’s API when cloud transcription is enabled and you choose voice input.

These providers may receive identifiers, technical data, and the content necessary to perform their service. We require processors acting for us to use personal data only on documented instructions, keep it confidential, apply appropriate security, assist with rights and deletion, and provide protection at least equivalent to the commitments in this Policy and applicable app-store requirements.

For additional information about independent provider practices, seeGoogle’s Privacy Policy,Apple’s Privacy Policy, andOpenAI’s Privacy Policy. These links do not replace this Policy or the contractual duties of a processor acting for CareWay.

7.3 Legal, safety, and organizational disclosures

We may disclose data:

  • when required by applicable law, regulation, court order, or a competent public authority;
  • to protect a person’s vital interests, investigate an incident, prevent fraud, or protect the rights and security of patients, Healthcare Providers, Whizz, or the public; or
  • as part of a merger, acquisition, financing, restructuring, or transfer of the Service, subject to confidentiality, lawful notice, and continued protection of the data.

We do not sell personal data, share it with data brokers, or share it for cross-context behavioral advertising. The reviewed CareWay mobile app contains no third-party advertising or behavioral-analytics SDK.

8. International transfers

CareWay is used in Saudi Arabia and may be operated or supported from countries where Whizz and its contracted providers have a presence. Depending on the deployment and optional features, personal data may be processed outside your country, including in Middle East and United States cloud regions. In particular, the reviewed app configuration can send symptom-assistant requests to a Google Cloud service in a United States region, and optional OpenAI cloud transcription may involve processing outside Saudi Arabia.

Before making a restricted transfer, the responsible controller must satisfy applicable health-data localization rules and the Saudi PDPL’s transfer requirements, including necessity and data minimization, an appropriate contractual or other lawful safeguard, transfer-risk assessment, and regulatory approval or exemption where required. A Healthcare Provider may disable an optional cross-border feature or use a different approved regional endpoint.

Contact us if you want information about the destination and safeguard applicable to your deployment.

9. Artificial intelligence and medical notice

The symptom assistant uses automated processing to structure symptom text and suggest healthcare specialties. It may display possible condition labels as part of the conversation. It does not make a final clinical decision, prescribe treatment, or determine whether you receive care. A clinician or the Healthcare Provider remains responsible for medical decisions.

Unless CareWay is expressly identified in the store listing and in-app materials as a regulated and approved medical device in your jurisdiction, CareWay is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.

Do not rely on the symptom assistant for an emergency. If you believe that you or another person may be experiencing an emergency, contact local emergency services or go to the nearest emergency department immediately.

We do not use symptom text, clinical records, audio, or transcripts for advertising or to train a general-purpose model. We require a processor handling this data for CareWay not to use it for its own model training unless we first provide a specific notice and obtain any consent required by law.

10. Microphone and speech-recognition choices

CareWay requests microphone access only when you choose voice input. A visible recording state must be shown while the app records. You can stop recording at any time, deny or revoke microphone and speech-recognition permission in device settings, and type symptoms instead.

Revoking permission stops future access but does not by itself delete audio or transcripts already lawfully processed. Use the request methods in Section 13 if you also want deletion.

11. Retention

We keep personal data only for the period needed for the disclosed purpose and applicable legal obligations. Current CareWay defaults and retention criteria are:

DataNormal retention criterion
Account and patient profileWhile the account is active, then erased or anonymized following a valid deletion request, subject to the exceptions below.
Healthcare Provider clinical recordsUnder the Healthcare Provider’s medical-record schedule and applicable healthcare law. Deleting CareWay does not necessarily delete the Provider’s legal medical record.
Cached visit summariesWhile needed to provide efficient access for an active patient; refreshed data can replace prior data. Orphaned cache records for deleted or anonymized patients are removed by a scheduled cleanup, normally weekly.
Server-side hospital-list cacheNormally up to 5 minutes before refresh.
On-device scheduling cacheUntil replaced, cleared, the account association changes, or you sign out.
On-device recent-screen shortcutsUp to five entries, until replaced or local app data is cleared. They are not currently cleared by signing out.
Web session storage and authentication cookieBrowser session storage normally lasts for the browser session. The server authentication cookie currently has a 24-hour absolute cap and a 30-minute sliding idle period, unless ended earlier by sign-out or revocation.
Access and refresh tokensUntil expiry, revocation, sign-out, or account deletion.
Symptom chat in the appHeld in the active app session; starting over creates a new session. The remote service may retain chat content or related logs only as long as needed to maintain the active conversation, enforce service quotas, prevent abuse, investigate failures, secure the service, and meet legal duties, after which the data must be deleted or anonymized. Contact us for the period configured for your deployment.
Temporary cloud-transcription audio on the deviceThe app attempts deletion immediately after the transcription attempt.
OpenAI API content, if that option is enabledSubject to the CareWay account’s OpenAI data controls. OpenAI currently documents default abuse-monitoring retention of up to 30 days, unless longer retention is legally or safety required; approved modified or zero-retention controls may reduce this.
Pending email-change recordNormally 12 hours, unless completed, replaced, or deleted earlier.
Standard HTTP/API audit logs90 days by current default.
Business/security audit events365 days by current default.
Detailed Healthcare Provider API-operation samples14 days by current default.
Aggregated API-operation metrics90 days by current default.
Delegation recordsFor the duration of the relationship and afterward as needed to prove authorization, revocation, access history, resolve disputes, and meet healthcare or audit obligations.
Rights and support requestsFor as long as needed to complete and document the request and meet legal, security, and dispute requirements.

Deployments may use a different period when required by the Healthcare Provider, law, a legal hold, litigation, fraud prevention, security investigation, backup cycle, or regulator. When a fixed period is not possible, we consider the sensitivity, amount, purpose, risk, legal requirements, and whether the data can be anonymized. Backups are protected and removed or overwritten on their normal cycle unless preservation is legally required.

12. Account deletion

You can request deletion of your CareWay account and associated CareWay data:

  • by emailing support@whizzms.com from the email associated with your account, with the subject “CareWay Account Deletion”.

Do not include your password, national identifier, medical records, or unnecessary health details in the request. We may ask you to reauthenticate or verify identity through a secure method before acting, to prevent an unauthorized person from deleting your account.

After a valid request, CareWay’s account-erasure process is designed to:

  • revoke active authorization and delegation relationships;
  • remove pending email-change data;
  • clear the national identifier and replace directly identifying profile data with an erased-account placeholder;
  • delete the CareWay identity-service account and unlink its Google or Apple sign-in association, where applicable;
  • soft-delete the CareWay patient and identity records; and
  • remove CareWay visit-summary caches through scheduled cleanup.

CareWay retains a stable pseudonymous account identifier, deletion timestamp, limited consent state, and audit evidence when necessary to preserve referential integrity, demonstrate who had access, prevent fraud, comply with healthcare or legal obligations, or establish or defend legal claims. Those retained records are restricted and are not used to continue providing an active account.

Account deletion does not require a Healthcare Provider to destroy a legal medical record that it must retain. We will pass on an applicable destruction request to processors and, when appropriate, the Healthcare Provider, but the Provider will decide under its own legal obligations and explain any lawful retention.

Deleting the app from your device does not delete your account. Revoking Google or Apple sign-in access also does not by itself delete the CareWay account. Deleting CareWay does not delete your independent Google or Apple account.

13. Your privacy rights

Subject to applicable law and valid exceptions, you may have the right to:

  • be informed about how your personal data is processed;
  • access your personal data;
  • receive a clear, readable copy in a commonly used electronic format;
  • correct, complete, or update inaccurate data;
  • request destruction or deletion when the data is no longer needed or another legal basis does not require retention;
  • withdraw consent for processing based solely on consent;
  • object to or restrict certain processing where applicable;
  • ask about international transfers and recipients; and
  • complain to the responsible Healthcare Provider or data-protection authority.

Send a request to support@whizzms.com with the subject“CareWay Privacy Request.” State the right you want to exercise, the country and Healthcare Provider connected to your account, and the email associated with the account. Do not send a password, national identifier, or medical record by ordinary email.

We may verify identity, ask for clarification, protect another person’s data, or deny or limit a request when the law requires or permits it. For requests under the Saudi PDPL, the responsible controller will act without undue delay and normally within 30 days. A permitted extension of up to 30 additional days may apply for disproportionate effort or multiple requests; if so, the controller will notify you in advance and explain why.

If you act for a person who lacks legal capacity, we may request evidence of guardianship or legal authority. If another person’s data appears in a record, we may redact it before providing a copy.

14. Consent withdrawal and privacy controls

You may:

  • turn off microphone or speech-recognition access in device settings and use typed input;
  • stop using the optional symptom assistant;
  • choose email/password rather than Google or Apple sign-in, where offered;
  • reject, limit, expire, revoke, or block delegation through available delegation controls;
  • clear recent-screen shortcuts from the CareWay home screen;
  • sign out to revoke or clear the local session and scheduling cache; and
  • contact us to withdraw consent or exercise a right.

Some care-delivery and security processing cannot be stopped while you continue using an account because it is essential to safely provide the Service or is required by law. We will explain the consequence of withdrawal before acting where practical.

15. Security

We use administrative, technical, and organizational safeguards proportionate to the sensitivity of identity and health data. The reviewed CareWay implementation includes role- and tenant-based authorization, consent checks for delegated access, encrypted app storage for tokens and selected caches, encrypted national-identifier storage with a separate matching hash, secret management, audit logging, rate limiting, short-lived access credentials, and scheduled log retention.

Production communications are required to use encrypted transport. Access is limited to authorized personnel and systems with a business need. We assess processors and require confidentiality and security protections.

No method of transmission or storage can be guaranteed completely secure. If a personal-data breach is likely to harm you or conflict with your rights, the responsible controller will notify affected people and regulators as required by applicable law.

16. Children and persons lacking legal capacity

CareWay is a healthcare account service, not a general-audience children’s app. A person who cannot legally consent must use CareWay only through, or with the verified consent of, a parent, guardian, or other legally authorized representative and in accordance with the Healthcare Provider’s rules.

We may verify guardianship and provide age-appropriate notices. If you believe a minor or person lacking legal capacity has created or used an account without valid authorization, contact us so that the responsible controller can investigate and take appropriate action.

17. Changes to this Policy

We may update this Policy to reflect changes in CareWay, providers, law, or regulatory guidance. We will post the updated version with a new “Last updated” date. If a change materially affects sensitive data or an existing purpose, we will provide a prominent notice and obtain consent when required before the new processing begins.

18. Contact and complaints

CareWay / Whizz Multi-Solutions
Attn: CareWay Privacy
Office 218, Binghatti Azure
Jumeirah Village Circle, Dubai, United Arab Emirates
Email: support@whizzms.com
Website:Whizz Tech
Contact form: available on theWhizz Tech page

If a Healthcare Provider controls the relevant record, you may also contact that Provider through the privacy channel shown in CareWay, on the Provider’s website, or in the Provider’s own privacy notice.

For Saudi PDPL concerns, you may complain to the competent Saudi data-protection authority after first giving the responsible controller an opportunity to resolve the issue. Information about the Saudi PDPL and data-subject rights is available through theSaudi Data & AI Authority’s data-protection portal.

This Policy is intended to satisfy transparency requirements. It is not a contract that limits any non-waivable rights available under applicable law.