Legal
Privacy Policy
Last updated: 18 September 2026 · Version 2.0
- Introduction & scope
- Who we are
- Key definitions
- Data we collect
- How we collect it
- Why we use it
- Legal bases
- Health data & explicit consent
- The identity firewall
- Cookies & local storage
- Sharing & processors
- Cross-border transfers
- AI & automated processing
- Security
- Retention
- Your rights
- Children & minors
- Data breach
- Third-party links
- Changes
- Contact & complaints
- Governing law
1. Introduction & scope
Causeway Health ("Causeway", "the platform", "we", "us", "our") is a cross-border clinical corridor that facilitates initial and second surgical opinions, secure video consultations, and coordinated episodes of care between patients, treating clinicians and consulting surgeons. This Policy applies to everyone who uses the platform, patients, treating clinicians, consulting surgeons, and administrators, and to all personal data processed through it. It should be read together with our Terms & Conditions.
This Policy is designed to reflect the requirements of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its regulations, the UAE Federal Law No. 2 of 2019 concerning the Use of Information and Communication Technology in Health Fields (the "Health Data Law"), and the data-handling standards of the relevant UAE health authorities, including the Department of Health - Abu Dhabi (DOH), the Dubai Health Authority (DHA) and the Ministry of Health and Prevention (MOHAP), as applicable.
2. Who we are
The platform is operated by BlinkEdge LLC, a company established in the United Arab Emirates (Abu Dhabi), which acts as the data controller for personal data processed through Causeway, except where a treating facility or clinician acts as an independent or joint controller for their own patients' records. Where Causeway processes data on behalf of a partner healthcare provider under a written agreement, BlinkEdge LLC may act as a processor for that provider. The precise controller/processor allocation for each deployment should be set out in the relevant service agreement.
3. Key definitions
- Personal data - any information relating to an identified or identifiable natural person.
- Health data - personal data revealing a person's physical or mental health, including clinical history, imaging, diagnoses and treatment; treated as sensitive personal data.
- Processing - any operation performed on personal data, including collection, storage, use, disclosure, transfer and deletion.
- Controller - the party that determines the purposes and means of processing.
- Processor - a party that processes data on behalf of a controller.
- Pseudonymisation / de-identification - processing personal data so it can no longer be attributed to a specific person without separately held information.
- Consulting surgeon - an independent, verified surgeon who provides an opinion or consultation through the platform.
- Treating clinician - the patient's home clinician who refers a case and remains responsible for their care.
4. Data we collect
Account data
Name, WhatsApp mobile number, email address (optional for patients), role, time zone, and account status. For consulting surgeons: licence country, specialty, consultation rate, profile photo, and the credential documents submitted for verification (for example licence, CV, board certification).
Patient identity data
Where a case involves an identified patient: name, Emirates ID, date of birth, sex, and contact details. This data is stored in a separate, encrypted identity store and is governed by the identity firewall (section 9).
Clinical case data
Pseudonymous clinical information: age, sex, laterality, anatomical area, clinical summary, the question posed, uploaded imaging (including DICOM studies) and documents, consulting opinions, appointment details, case notes and case messages.
Payment data
For self-pay consultations: the amount, currency, status, our payment processor's transaction and payment references, and timestamps. Card details are entered directly with our payment processor; we do not receive or store full card numbers.
Communications & scheduling data
Per-case messages, case notes, proposed and confirmed appointment times, and the notifications we send you (WhatsApp, email, calendar invitations).
Technical & usage data
Authentication events, records of access to cases and files, actions taken on the platform, IP address, device/browser information and timestamps, recorded in an audit log for security and traceability. One-time passcodes are stored only as short-lived hashes.
5. How we collect it
- Directly from you - when you register, create or manage a case, upload files, message, pay, or attend a consultation.
- From your treating clinician - when a clinician refers a case on your behalf.
- Automatically - technical and usage data generated as you use the platform.
- From our processors - limited confirmations such as payment status from our payment processor, or delivery status from our messaging providers.
6. Why we use it
| Purpose | Examples of data used |
|---|---|
| Authenticate you and operate your account | Mobile number, one-time passcode, role, session data |
| Create, route and manage cases and opinions | Clinical case data, identity data (held in-country), account data |
| De-identify imaging and clinical data before sharing | Imaging, DICOM tags, clinical fields |
| Schedule and host video consultations | Appointment times, time zone, contact details |
| Send notifications, reminders and receipts | Mobile number, email, case reference |
| Process payments and issue receipts | Payment data, case reference |
| Suggest suitable consulting surgeons | De-identified clinical text, surgeon profiles |
| Maintain security, prevent misuse, meet legal duties | Audit log, technical data |
7. Legal bases
Depending on the processing, we rely on one or more of the bases recognised under the PDPL: your consent (including explicit consent for health data and for cross-border transfers); the performance of a contract or steps taken at your request; compliance with a legal obligation; the protection of vital interests; and our legitimate interests in operating, securing and improving the platform, balanced against your rights. Where we rely on consent, you may withdraw it at any time (section 16); withdrawal does not affect processing already carried out.
8. Health data & explicit consent
Health data is sensitive personal data and receives heightened protection. We process it to deliver the clinical services you or your clinician request, on the basis of explicit consent and/or the provision of healthcare by or under the responsibility of a treating clinician, consistent with the PDPL and the Health Data Law. We apply data minimisation: a consulting surgeon receives only the de-identified clinical information needed to answer the clinical question, never the patient's identity.
9. The identity firewall & de-identification
Causeway separates who the patient is from what the case is about at the data-model level. Patient identity is stored in a separate, encrypted store; a consulting surgeon works only from an opaque case reference and de-identified clinical data. Before imaging is shared, DICOM identity tags are stripped and image metadata is discarded; files that cannot be automatically de-identified (for example burned-in annotations or free-form PDFs) are withheld for manual review. Within messages and notes, participants are asked not to include identifying details, and clinicians see a patient as "Patient" rather than by name.
10. Cookies & local storage
We use strictly necessary cookies and browser storage to keep you signed in (a secure, same-site session cookie), to protect against cross-site request forgery, and to remember minor interface preferences on your device. We do not use advertising cookies or sell tracking data. Video consultations are provided by our video processor, which may set its own cookies within the embedded call to deliver the session.
11. Sharing & processors
We do not sell personal data. We share data only as needed to provide the service, with the categories of processors below, each engaged under terms requiring appropriate confidentiality and security. Specific processors may change; the current list is maintained and available on request.
| Processor | Purpose | Data involved |
|---|---|---|
| Stripe | Self-pay payment processing | Payment data, case reference (no identity) |
| Daily.co | Embedded video consultations | Session connection data (no identity fields) |
| Meta (WhatsApp Business Platform) | One-time passcodes and notifications | Mobile number, case reference, message content |
| SendGrid | Transactional email | Email address, case reference, message content |
| Anthropic | AI surgeon-match suggestions | De-identified clinical text only (no identity) |
| Cloud/hosting provider (UAE) | Application and database hosting | All platform data, encrypted at rest |
We may also disclose data to consulting surgeons and treating clinicians as needed to deliver a case, to professional advisers under confidentiality, and where required by law, regulation, court order or a competent authority, or to protect the rights, safety and security of patients, users or the platform.
12. Cross-border transfers
Patient identity and case data are stored on UAE-based infrastructure. A case is routed to a surgeon outside the UAE only after the patient's explicit, recorded consent for that specific transfer, and in that event only the de-identified, pseudonymous case crosses the border, never patient identity. Cross-border processing of health data is subject to the Health Data Law and to any approvals required from the relevant health authority; the service is designed to operate within a lawful transfer pathway, including through appropriately licensed clinicians. Certain processors (for example for AI suggestions, video, messaging, email and payments) may process limited, non-identifying data outside the UAE; where they do, we share the minimum necessary and rely on the safeguards permitted under the PDPL.
13. AI & automated processing
To help match a case to a suitable consulting surgeon, Causeway may send de-identified clinical text (anatomy, laterality, age, sex, summary and question) together with candidate surgeon profiles to an AI provider, which returns ranked suggestions with reasoning. No patient identity is included. These suggestions are decision-support only: the choice of surgeon and all clinical decisions are made by humans, the treating clinician and the patient. We do not make decisions producing legal or similarly significant effects based solely on automated processing.
14. Security
- Encryption at rest - identifying and sensitive fields are encrypted with authenticated encryption (AES-256-GCM); keys are held outside the database.
- Encryption in transit - the platform is served over HTTPS with strict transport security.
- Access control - access to a case is limited to the treating clinician, the assigned consulting surgeon, the patient, and authorised administrators; uploaded files are served only to authorised parties.
- Authentication - sign-in uses WhatsApp one-time passcodes; consulting surgeons are verified by an administrator before activation.
- Auditability - access and actions are recorded in an audit log.
- Application hardening - strict Content-Security-Policy, cross-site request forgery protection, and secure, same-site session cookies.
- Blind-indexing - lookups on identifiers use keyed hashes rather than plaintext.
No system is perfectly secure, but we maintain organisational and technical measures proportionate to the sensitivity of the data and review them over time.
15. Retention
We retain case, clinical and payment records for as long as necessary to provide the service and to meet legal, regulatory, medical-record and financial-retention obligations, including any minimum medical-record retention periods set by UAE health authorities. Audit logs are retained for security and traceability. One-time passcodes expire within minutes. When you delete your account (section 16), we remove your personal identifying details and disable sign-in, while retaining de-identified case and payment records where their retention is required by law or as medical or financial records.
16. Your rights
Subject to applicable law and to our legal retention obligations, you may have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to certain processing; withdraw consent; and request portability of data you provided. Patients can update their name, email, time zone, and (with re-verification by one-time passcode) mobile number, and can request account deletion, directly from the account page. To exercise other rights, contact us using the details in section 21. We will respond within the period required by law. You also have the right to lodge a complaint with the UAE Data Office.
17. Children & minors
A case may concern a patient who is a minor; such cases must be created and managed by an authorised adult, a treating clinician or the child's parent or legal guardian, who provides the necessary consent. Platform accounts are intended for adults acting in those capacities. We do not knowingly allow minors to create their own accounts.
18. Data breach
We maintain procedures to detect, assess and respond to personal-data breaches. Where a breach is likely to result in a risk to your rights, we will notify the UAE Data Office and affected individuals as and where required by the PDPL, and take steps to contain and remediate the incident.
19. Third-party links
The platform may link to third-party sites or services (for example a payment page or a video session). Their processing is governed by their own privacy notices, and we are not responsible for their practices. Review their notices before providing personal data.
20. Changes
We may update this Policy from time to time. Material changes will be indicated by updating the date and version above and, where appropriate, by notice through the platform. Continued use after an update takes effect indicates awareness of the revised Policy.
21. Contact & complaints
For privacy questions, to exercise your rights, or to raise a concern, contact BlinkEdge LLC at the address published on our website. A named data-protection point of contact and a formal grievance channel should be inserted here prior to launch. If you are not satisfied with our response, you may contact the UAE Data Office.
22. Governing law
This Policy and any dispute relating to our processing of personal data are governed by the laws of the United Arab Emirates. The specific Emirate and forum should be confirmed with counsel and made consistent with the Terms & Conditions.