Privacy Policy, Confidentiality, and Data Usage
Labayh is a comprehensive online solution for therapeutic and wellbeing services to both individuals and businesses. We are providing 1:1 sessions, webinars, support groups, entertainment program packages, psychological and quality assessments for mental health and workplace well-being - all provided by licensed therapists. At Labayh, we are committed to protecting your data and ensuring its use in a secure and transparent manner. This policy explains how we collect your data, why we need it, and how we maintain and protect it in compliance with the applicable laws and regulations in the Kingdom of Saudi Arabia. In the event of any conflict between this policy and the Saudi Personal Data Protection Law, the provisions of the Saudi Personal Data Protection Law shall prevail.
Updates to This Policy:
We may update this privacy policy periodically or based on updates to the Saudi Information Security System. We will notify you of any significant changes through the application, notifications, or via email.
- The last review of this policy was on: February 1, 2026.
Information We Collect About You:
When you use our services, we may collect different types of information to ensure a better experience:
Personal Information: Name, date of birth and national ID number (if required for the service), email, phone number, and account details such as username.
Health Information: This includes the health data you provide when using our medical or psychological services, such as:
Health records shared during sessions or diagnostic services.
General health status or symptoms you disclose.
Prescriptions if you receive treatment recommendations from consultants.
Medical reports you submit as part of your consultations
Additional Health Data (Apple HealthKit and Google Health Connect): If you grant permission, the application may access specific health data from Apple HealthKit and Google Health Connect such as activity levels, sleep patterns, or heart rate, for the purpose of supporting and improving the health services provided to you. We confirm that this data:
Is accessed only after obtaining your explicit consent and through your device settings.
Is used exclusively for the purpose of providing health services and is not used for any marketing or advertising purposes.
Is not shared with any third party, and you may revoke access at any time through your device settings.
Technical Information: Device type, operating system and version, and IP address.
Usage Information: How you interact with our services, including pages visited, time spent on the app, and technical errors affecting the security and stability of your experience.
Financial Data: When making payments through our platform, we may collect certain payment-related details, such as:
Payment method used (credit card, Mada, Apple Pay, STC Pay, etc.).
The last four digits of your card (the rest of the card numbers are encrypted) , and card expiration date.
Date and value of financial transactions within the app.
Billing details and subscription records.
How We Collect This Data:
We collect your information through various methods to ensure the best possible experience:
Directly from You: When you register, book sessions, fill out forms, or contact us for support.
Automatically: Through cookies, logs, and analytical tools to understand how you interact with our services and analyze technical errors.
From Third Parties: When you interact with our services via social media.
Why We Need Your Data:
We use your data to improve your experience and ensure efficient service delivery. We also use some technical and operational data to analyze performance, identify security vulnerabilities, and fix errors affecting your experience or the platform’s security. The main purposes for collecting data are:
Compliance with Legal Requirements: Such as Ministry of Health laws, to protect the rights of our users, consultants, and doctors.
Service Delivery: Providing the services you've requested, such as medical consultations and analysis.
Service Improvement: Enhancing service quality and user experience through data and performance analysis and feature development.
Verification of Your Information: Ensuring the accuracy of the data and verifying its correctness.
Communication with You: Regarding session appointments, important notifications, service updates, or sending offers (if you have agreed to receive such offers).
Business and Operational Management: Including conducting archival or statistical analyses.
Do We Share Your Data with Third Parties?
We respect your privacy in accordance with the Personal Data Protection Law and will only share your data in the following legal cases:
With Your Consent: We will request your consent before sharing any data that is not essential for providing the service, and you may withdraw your consent at any time.
To Comply with Regulations: If we are required to meet legal obligations or government requests.
With External Service Providers: Who assist us in delivering our services, such as payment processing or cloud hosting, provided they strictly adhere to data protection regulations and comply with the Saudi Personal Data Protection Law or our specified instructions. Licensed by the Communications, Space and Technology Commission, Category (C).
How We Protect Your Data:
We implement advanced security measures to protect your data from breaches or unauthorized use by securing our networks, internal devices, servers, and continuously updating technologies to address vulnerabilities.
We strictly adhere to our internal policies related to confidentiality and data protection, as well as how data is used.
Sensitive data is encrypted to ensure its safety.
Your data is retained for the duration required to provide the service and comply with local laws, such as Ministry of Health regulations.
How Do We Store Your Personal Data?
Your data is securely stored within the borders of the Kingdom of Saudi Arabia, using cloud computing services provided by our trusted vendors.
What Are Your Rights?
The Right to Know How We Use Your Data: You can learn the legal basis for collecting your personal data and the purpose for its use.
The Right to Access Your Data: You can request to know the data we hold about you, and it will be provided in a clear and readable format.
The Right to Obtain a Copy of Your Data: You can request a copy of your data in a clear and readable format.
The Right to Correct Your Data: If your data is inaccurate or incomplete, you can notify us and we will correct it.
The Right to Delete Your Data: You can request the deletion of your data in certain cases, unless there is a legal reason to retain it.
The Right to Restrict Processing: You can request limiting the use of your data in certain circumstances.
The Right to Object to Processing: You can object to the use of your data for specific purposes, such as direct marketing.
How Can You Exercise Your Rights?
You can exercise your rights regarding your personal data through the following methods:
Through Account Settings: Some rights, such as editing your data, opting out of marketing communications, or deleting your account, can be exercised directly from your account settings in the app.
Sending a Request via Email: You can contact us at [email protected] and specify the request you wish to submit.
Using a Dedicated Form: If you have a specific request, such as requesting a copy of your data, we may provide you with a special form to facilitate the process.
Contacting Customer Support: You can reach out to our customer service team for assistance in processing your requests.
We will review and handle all requests in accordance with applicable laws and regulations and will notify you of any actions taken as soon as possible.