Privacy Policy
Your privacy is important to us. This policy explains how MEDAS Solutions collects, uses, and protects your information.
Last updated: December 2025
1. Introduction
MEDAS Solutions ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, use our products, or engage with our services.
We comply with applicable data protection laws including the General Data Protection Regulation (GDPR), UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, and other regional privacy regulations in the GCC countries where we operate.
2. Information We Collect
2.1 Information You Provide
- Contact Information: Name, email address, phone number, organization name, job title
- Demo Request Information: Facility type, size, region, product interests
- Communication Data: Content of emails, messages, and support requests
- Account Information: Login credentials for our software platforms
2.2 Information Collected Automatically
- Device Information: Browser type, operating system, device identifiers
- Usage Data: Pages visited, time spent, click patterns
- Location Data: General geographic location based on IP address
- Cookies: See our Cookie Policy section below
2.3 Healthcare Data
Our healthcare software products may process patient health information on behalf of healthcare organizations. This data is processed strictly according to our Business Associate Agreements (for HIPAA) and Data Processing Agreements with our clients. We do not access patient data except as necessary to provide technical support with explicit authorization.
3. How We Use Your Information
We use collected information for the following purposes:
- Respond to demo requests and inquiries
- Provide and improve our products and services
- Send relevant product updates and communications
- Analyze website usage to improve user experience
- Comply with legal obligations
- Prevent fraud and ensure security
- Conduct research and analytics
4. Legal Basis for Processing (GDPR)
We process personal data based on:
- Consent: When you opt-in to marketing communications or cookies
- Contract: To fulfill our contractual obligations to you
- Legitimate Interest: For business operations, security, and improving services
- Legal Obligation: To comply with applicable laws and regulations
5. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Cloud hosting, email services, analytics providers who assist in our operations
- Business Partners: With your consent, for joint offerings or referrals
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with mergers, acquisitions, or asset sales
6. Data Security
We implement robust security measures to protect your information:
- ISO 27001 certified information security management
- Encryption of data in transit and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
7. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:
- Contact inquiries: 3 years from last interaction
- Customer account data: Duration of business relationship plus 7 years
- Marketing communications: Until consent is withdrawn
- Website analytics: 26 months
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw previously given consent
To exercise these rights, please contact us at privacy@medassolutions.com.
9. Cookie Policy
Our website uses cookies to enhance your browsing experience. Types of cookies we use:
- Essential Cookies: Required for website functionality
- Analytics Cookies: Help us understand website usage
- Marketing Cookies: Used for personalized advertising (with consent)
- Preference Cookies: Remember your settings and choices
You can manage cookie preferences through our cookie consent banner or your browser settings.
10. International Data Transfers
As a company operating across the GCC, we may transfer data between our offices in UAE, Saudi Arabia, Qatar, Kuwait, Bahrain, and our development center in India. We ensure appropriate safeguards are in place for any international transfers, including:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
- Binding Corporate Rules
11. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by posting a prominent notice on our website or sending you a direct communication.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
MEDAS Solutions - Data Protection Officer
Email: privacy@medassolutions.com
Phone: +971 56 546 3880
Address: Al Shoala Building, Al Naboodah E-301, Dubai, UAE
14. Supervisory Authority
If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection supervisory authority. For UAE residents, complaints can be filed with the UAE Data Office.
Have Questions About Your Data?
Our team is here to help you understand how we protect your information.
Contact Us