Legal

YADOCT PRIVACY POLICY

This policy explains how Yadoct collects, uses, and protects your data.

Last Updated: 16 July 2026 Effective Date: 22 May 2026 Jurisdiction: People's Democratic Republic of Algeria Applicable Law: Algerian Law No. 18-07 on protection of personal data Data Controller: EURL Yadoct Contact: [email protected]


1. PURPOSE, SCOPE AND DEFINITIONS

This Privacy Policy describes how Yadoct processes personal data in accordance with Algerian Law No. 18-07 when you use our platform, including web, mobile, and clinic systems (the "Services").

Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Health Data: Sensitive personal data related to physical or mental health.
  • User: Any patient or healthcare provider using the Services.
  • Provider: Licensed healthcare professional or medical organization using Yadoct.

This Policy applies exclusively to users aged 18 years and above.

2. ROLES AND RESPONSIBILITIES

2.1 Yadoct

Yadoct acts as data controller for platform operations including:

  • Account management
  • Appointment systems
  • Messaging infrastructure
  • Telemedicine infrastructure

2.2 Healthcare Providers

Healthcare Providers act as independent data controllers for:

  • Medical diagnosis
  • Clinical decision-making
  • Treatment and prescriptions

Yadoct does not provide medical services and does not interfere with clinical decisions.

3. CATEGORIES OF DATA COLLECTED

We apply data minimization principles and only collect data necessary for healthcare services.

3.1 Identity and Account Data

  • Full name
  • Date of birth (18+ verification)
  • Phone number
  • Email address
  • Authentication credentials

3.2 Health Data (Sensitive Data)

  • Medical history
  • Symptoms and consultation notes
  • Prescriptions
  • Laboratory and imaging results
  • Allergies and chronic conditions
  • Vaccination records

3.3 Technical Data

  • Device type and operating system
  • IP address
  • Authentication logs
  • Application usage logs

3.4 Communication Data

  • Messages between patient and provider
  • Appointment history
  • Support communications

3.5 Device Permissions (Optional)

  • Camera (document upload, profile image)
  • Microphone (telemedicine calls)
  • Location (provider search)
  • Notifications (alerts)

4. PURPOSE AND LEGAL BASES

We process personal data only for specific, explicit, and legitimate purposes:

4.1 Purposes

  • Provision of healthcare appointment services
  • Telemedicine consultations
  • Medical record management
  • Communication between users and providers
  • Platform security and fraud prevention
  • Legal compliance under Algerian Law No. 18-07
  • Service improvement using aggregated anonymized data

4.2 Legal Bases

  • Contract performance (Service delivery)
  • Legal obligations (health, tax, regulatory compliance)
  • Explicit consent (optional features only)
  • Legitimate interest (security, fraud prevention, system stability)

5. PROHIBITED USE OF DATA

We explicitly state:

  • We do not sell personal or health data
  • We do not use health data for advertising
  • We do not perform automated medical diagnosis or treatment decisions
  • We do not profile users for behavioral advertising

6. DATA SHARING AND DISCLOSURE

We share data only when strictly necessary.

6.1 Healthcare Providers

Data is shared with selected providers for medical consultation and treatment.

6.2 Service Providers (Processors)

We use third-party processors under strict contractual agreements:

  • Payment processing (Chargily Pay)
  • Cloud infrastructure and hosting
  • Messaging and notification services (SMS/email)
  • Telemedicine infrastructure

Processors are prohibited from using data for any independent purpose.

6.3 Legal Authorities

Data may be disclosed when required by Algerian law or valid legal request.

6.4 Business Transfers

In case of merger or acquisition, users will be informed prior to any data transfer.

7. TELEMEDICINE AND RECORDING CONSENT

Telemedicine services may involve audio/video communication.

  • Recording is disabled by default
  • Recording requires explicit consent from both patient and provider
  • Users may withdraw consent at any time
  • Recordings are stored only for the minimum necessary duration defined by clinical policy

8. ARTIFICIAL INTELLIGENCE AND AUTOMATION

8.1 Scope of AI Use

Yadoct offers optional AI-assisted features strictly limited to administrative support and clinical documentation, namely (i) the generation of draft consultation summaries for Healthcare Providers and (ii) support-request intake assistance. These tools:

  • are optional and, for consultation summaries, initiated solely by the Healthcare Provider on a case-by-case basis;
  • do not provide medical diagnosis, treatment recommendations, or any autonomous clinical decision; and
  • perform no automated decision-making producing legal or similarly significant effects on any person.

8.2 Third-Party AI Processor

Certain AI features are delivered using the Google Gemini API, provided by Google acting as a data processor on Yadoct's behalf under contractual safeguards. Where a consultation summary is generated, only the following may be transmitted to this processor, and for the sole purpose of producing the summary:

  • the consultation audio, and only when a Provider explicitly starts a recording; and
  • a de-identified clinical context (such as age, sex, vital signs, allergies and relevant history) from which direct identifiers - including name, phone number, email, postal address and internal identifiers - are removed beforehand.

8.3 Limited Use

Data transmitted to our AI processor is used only to provide the requested feature; is not used or transferred for advertising or any unrelated purpose; is not sold; and is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models. All transmission is encrypted and data minimization is applied throughout.

8.4 Consent for Consultation Recording

Consultation recording and AI summarization are disabled by default. Because a recording captures the patient's voice and health information, the Healthcare Provider must inform the patient and obtain their consent before starting any recording. The patient may refuse or withdraw consent at any time, and the Healthcare Provider remains responsible for obtaining and documenting that consent.

9. DATA STORAGE AND RESIDENCY

9.1 Primary Storage (Algeria)

Core personal and medical data is stored in infrastructure located in Algeria.

9.2 External Processing

Some technical operations may involve external providers for:

  • Messaging
  • Video streaming
  • File delivery
  • Analytics

Such processing is limited to operational necessity and subject to:

  • Encryption in transit
  • Data minimization
  • Contractual safeguards prohibiting reuse

10. DATA RETENTION POLICY

Retention is strictly limited to what is necessary:

  • | Data Type | Retention Period |
  • | :--- | :--- |
  • | Medical records | As required by Algerian healthcare law and continuity of care obligations |
  • | Financial records | As required by tax and accounting regulations |
  • | Account data | Until deletion request is processed (subject to legal retention limits) |
  • | Communication logs | Limited retention for support and dispute resolution |
  • | Telemedicine recordings | Not allowed |

After retention periods, data is securely deleted or anonymized.

11. DATA SECURITY MEASURES

We implement industry-standard safeguards:

  • TLS encryption in transit
  • AES encryption at rest for sensitive data
  • Role-Based Access Control (RBAC)
  • Strict authentication mechanisms
  • Audit logging of access to medical data
  • Continuous monitoring and vulnerability management
  • Device-based identity verification: we may ask you to confirm your identity (for example, your name and date of birth) when you sign in from a new or unrecognized device, to protect your account
  • We perform security checks to protect your data and detect unsafe environments (for example, blocking access while USB debugging is enabled)

Incident Response In case of a data breach:

  • We assess risk immediately
  • Notify authorities as required by law (without undue delay)
  • Notify affected users where risk is significant

12. USER RIGHTS UNDER LAW 18-07

Users have the right to:

  • Access their personal data
  • Rectify inaccurate data
  • Request deletion (subject to legal obligations)
  • Restrict processing
  • Object to processing in specific cases
  • Data portability (where technically feasible)
  • Withdraw consent at any time

Requests: [email protected]

Response time: within legally reasonable timeframe under Algerian Law No. 18-07.

12.1 DELETING YOUR ACCOUNT AND DATA

You can request deletion of your account and personal data at any time:

  • In the app: open Profile and tap "Delete account".
  • On the web: visit https://yadoct.com/account-deletion and submit the request form (no login required).
  • By email: [email protected]

Once your identity is verified, your account and personal profile data are permanently deleted. Some medical and financial records may be retained for the minimum period required by Algerian healthcare, tax and accounting law, after which they are securely deleted or anonymized.

13. CHILDREN AND AGE RESTRICTION

The Services are strictly restricted to individuals aged 18 years and above. We do not knowingly collect or process data from minors. If such data is identified, it is promptly deleted unless legally required to retain.

14. INTERNATIONAL DATA TRANSFERS

Where data processing occurs outside Algeria:

  • Only minimum necessary data is transferred
  • Data is encrypted during transmission
  • Contractual safeguards are enforced
  • Processing is strictly limited to operational purposes
  • No replication or independent use is permitted

15. COOKIES AND TRACKING

Yadoct does not use cookies or tracking technologies for analytics, advertising, or profiling. Only essential session mechanisms may be used to ensure secure authentication.

16. INFORMATIONAL CONTENT (QUEUE DISPLAY)

On in-clinic Queue Display screens (the waiting-room slideshow), Yadoct may show its own informational content — for example, prompts to download the Yadoct apps. This is not third-party advertising, and it is not advertising for doctors, clinics, or teleconsultation services. Yadoct does not operate ad networks, does not use advertising identifiers or behavioral tracking, and does not use personal or health data for this content.

17. THIRD-PARTY SERVICE PROVIDERS

We rely on external service providers for technical operations:

  • Hosting infrastructure
  • Communication systems
  • Payment processing
  • Telemedicine services

All providers are contractually bound to:

  • Maintain confidentiality
  • Process data only on instructions
  • Apply appropriate security measures
  • Not use data for independent purposes

18. NO COMMERCIALIZATION OF HEALTH DATA

We do not sell, rent, or commercially exploit personal or health data under any circumstances.

19. LIMITATION OF LIABILITY & MEDICAL RESPONSIBILITY

Yadoct acts exclusively as a technical platform connecting patients with independent, licensed healthcare professionals.

All medical services, including diagnosis, consultation, prescriptions, and treatment decisions, are the sole responsibility of the Healthcare Provider.

Yadoct does not provide medical services and does not interfere in any medical judgment or clinical decision-making.

Yadoct is not a party to the medical relationship between patients and Healthcare Providers.

Any dispute related to medical advice, diagnosis, treatment, or clinical outcomes must be resolved directly between the patient and the Healthcare Provider.

Yadoct shall not be held liable for any medical decisions, outcomes, or professional actions taken by Healthcare Providers.

20. CHANGES TO THIS POLICY

We may update this Policy to reflect legal, technical, or operational changes. Users will be notified of material updates. Continued use constitutes acceptance.

21. CONTACT

All requests: [email protected]

22. GOVERNING LAW

This Policy is governed exclusively by the laws of the People's Democratic Republic of Algeria, including Algerian Law No. 18-07. All disputes fall under Algerian jurisdiction.

23. HEALTHCARE PROVIDER VERIFICATION

All Healthcare Providers using Yadoct undergo a mandatory verification process before being approved on the platform.

This process includes:

  • Verification of identity (government-issued ID)
  • Verification of medical license or registration number (e.g. Ordre des Médecins or equivalent authority)
  • Validation of professional specialty and practice eligibility
  • Manual review and approval by the Yadoct administration team

Only verified healthcare professionals are allowed to offer telemedicine consultations on the platform.

24. PROVIDER CALENDAR AND APPOINTMENT IMPORT

To help Healthcare Providers move their existing schedules onto Yadoct, we offer optional tools that let a Provider import appointments. These features are entirely optional, require an explicit action by the Provider, and can be turned off at any time. We import only the information needed to create appointments (such as patient name, date, time, and reason) and apply data minimization throughout.

24.1 Import Methods

  • Spreadsheet import: A Provider may upload a file (for example an Excel or CSV schedule). The file is processed solely to extract appointment entries.
  • Image import: A Provider may submit a photo of a paper or on-screen schedule. The image is processed, including optical character recognition, solely to extract appointment entries.
  • Google Calendar synchronization: A Provider may connect a Google account so that calendar events can be imported as appointments.

Imported data is processed by Yadoct and its trusted processors under contract, used only to create and manage appointments on the platform, and retained under the same terms as other appointment data (Section 10). It is never sold and never used for advertising.

24.2 Google API Services — Limited Use

When a Provider connects Google Calendar, Yadoct requests read-only access to calendar data using the narrowest scopes necessary, and only to import appointments at the Provider's request.

Yadoct's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically, information obtained from Google APIs is:

  • used only to provide and improve the appointment-import feature;
  • not transferred to others except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition;
  • not used or transferred for advertising or any other unrelated purpose;
  • not used to develop, improve, or train generalized or non-personalized AI or machine-learning models; and
  • not accessed by humans unless you give explicit consent for specific data, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data is aggregated and anonymized for internal operations.

A Provider may disconnect Google Calendar at any time from the application settings, or from the Google account permissions page (https://myaccount.google.com/permissions), which revokes Yadoct's access.