Privacy Notice
1. Who this notice covers
ShifaTH is operated by Al Aziz Co., Ltd. Legal identification and address: Al Aziz Co., Ltd. (บริษัท อัล อะซิส จำกัด), Thai registration number 0105567048733; address: 10 Soi Pracha Uthit 54, Yaek 6-2, Bang Mod, Thung Khru, Bangkok 10140, Thailand. Al Aziz Co., Ltd. is the controller of information used to provide and manage ShifaTH. Each Provider is responsible for its independent clinical processing and records. Contact our privacy team at privacy@shifath.com, including to reach the person responsible for data-protection matters.
This notice covers visitors, Users, patients whose information is provided by another person, Organization representatives and members, and people contacting platform support. It covers discovery, accounts, patient profiles, selected document storage and sharing, requests, conversations, coordination, appointments, verified-visit reviews, Provider participation, support and platform security as described below.
Privacy release: 0.5. This version applies when presented to you for the relevant use or agreement.
Providers maintain their own patient, medical, billing and appointment records. Please read the receiving Provider’s privacy notice for its independent use of your information.
2. Information and purposes
The information used depends on the action you take. We explain which fields are necessary for that action and what happens if you do not provide them.
| Activity | Information and source | Why it is used |
|---|---|---|
| Account and access | Account/contact details you provide, verification and session information, language and communication settings | Sign-in, recovery, account protection and relevant service messages |
| Patient profile and identity | Patient name, date of birth, medical-record sex, nationality, residence, language and management relationship; passport images and fields; identity or claim evidence including a selfie where the procedure requires it | Maintain the correct profile, check required identity, prevent duplicates, assess a claim and manage authority |
| Private patient documents | Selected reports, images, prescriptions and other uploaded files; generated previews, extracted text or translations where the relevant processing is used | Store and make the selected material readable to authorized profile users before any Provider delivery |
| Requests and Provider delivery | Patient and request details, clinical information or selected medical items where provided, chosen Providers, exact document versions, sharing declarations and passport-send decisions | Submit and handle the request and document delivery you authorize |
| Conversations and coordination | Original messages, authorized attachments, edit history, reading state and requested translations | Communication, optional platform coordination and traceable handling |
| Appointments and visits | Appointment details, attendance reports and supporting evidence received from you, the Provider or authorized platform staff | Coordinate an appointment, resolve attendance and establish review eligibility |
| Public reviews and Provider content | Review text/rating and a safe public label; Provider-supplied professional names, credentials, images, services and posts | Publish approved public information and verified-visit feedback |
| Provider participation | Interest-form contact name, Organization/type, required email, optional phone, country and message; authorized workforce membership and contract records | Assess participation, contact the representative, manage access and maintain the private agreement |
| Support, privacy and security | Complaint messages, relevant evidence, case history, privacy requests, access/security events and minimum audit records | Investigate concerns, protect access, carry out rights requests and record outcomes |
| Public search | Search text and settings, account identity where signed in, and installation/session identifiers where available | Provide and improve search |
We use account information to provide the service you request. We use necessary security and service-management records for our legitimate interests in protecting and operating ShifaTH, with safeguards for your rights, and records required to meet our legal obligations. For consent-based processing of health information, we require explicit consent from the patient or a person legally entitled to consent for them. This consent identifies the information, purposes and recipients. A representative’s declaration of authority is separate from patient consent.
We record search text, including searches made without signing in. Search text can contain personal information. Please do not enter names, passport numbers or detailed medical histories in public search.
Identity and profile-claim checks use the documents and evidence explained for that procedure. A selfie is not required for every patient profile.
Where necessary for an applicable payment or reconciliation arrangement, we use attendance, reference and financial records. We do not share an entire medical file for accounting.
3. When another person provides patient information
A User may provide information for a patient they are authorized to assist. That User must make the applicable submission declaration, identify their relationship and check the selected recipients, data and purpose. This records the User's declaration, not a statement that the patient personally clicked consent.
Where patient or lawful guardian consent is required, that consent must be obtained before the covered processing. If you provide another patient’s information, give them or their lawful guardian this notice. We also provide the notice required for information received indirectly, including before first disclosure where applicable. You can ask us where information about you came from and how it is being used.
You can contact privacy@shifath.com even if you do not have a ShifaTH account. We will check identity and authority proportionately before discussing another person's private records.
4. Who can receive or access information
Hospital requests may be sent to one, several, or all participating hospitals offered by the applicable flow. In the Clinic request flow, you select one participating Organization at a time. Each Organization receives only its own authorized request, conversation, status and information. Uploading a file to a private patient vault does not send it to a Provider.
Authorized profile managers and delegates have only their applicable permissions. Organization members access records under the permissions assigned for their Organization.
Authorized platform staff may access information for assigned coordination, support, security, privacy, identity review or audit work. Direct messages are not subject to routine pre-delivery human approval. In coordinated conversations, source messages remain visible only to their originating side and authorized coordinators; the coordinator writes a separate message to the intended destination and may attach an available file.
Service providers supporting hosting and storage, authentication, translation, document processing and notifications may process the data necessary for their assigned service. Their access is limited to that service and its lawful purposes, with confidentiality and appropriate contractual safeguards. This notice does not grant vendors permission to use patient content for unrelated advertising or model training.
Information may also be disclosed where a specific legal requirement or legally justified investigation requires it. Requests are assessed for authority, necessity and scope. Private patient information is not made public merely because an official request or support case exists.
Public Provider content and published reviews can be seen by anyone. Reviews use an anonymous author label by default, but identifying details in free text can reveal someone. Do not publish private medical or identity details.
5. Passport and document decisions
First delivery of the current passport version requires separate approval for each receiving Organization where the request requires a passport. Declining stops that Organization's request and passport delivery. It does not stop other destinations you approved. The same successfully delivered version is not sent again on a later request to that Organization. A new passport version requires the applicable new approval.
Medical reports and other files are selected for the relevant request or message. A Provider can download a delivered file and retain its own independent copy. A sent file is not a revocable viewing link.
The platform's direct-contact boundary does not remove information already contained in a document you select. Check its contents before sending it.
6. International processing
Data sent to a selected Thai Provider is received in Thailand. Service providers or authorized remote personnel may process information in other countries. We apply the transfer safeguards or other conditions required by applicable law. Contact privacy@shifath.com for the recipients, locations and safeguards relevant to your information.
7. Retention and deletion
We retain information for the following periods or purposes, and remove or anonymize it when that need ends, unless a specific legal duty or unresolved dispute requires relevant records to be kept longer. You can ask us about the retention that applies to your records.
| Information | Retention standard |
|---|---|
| Account and Organization access information | For the active account or membership; after closure, only information needed to finish closure, protect access, resolve a dispute or meet a legal duty |
| Patient profiles and private documents | While you maintain the profile or document for the requested service; eligible deletion or erasure requests end ordinary access and initiate removal |
| Identity and authority evidence | Until the check or claim and any related dispute are resolved; only necessary evidence of the outcome is retained afterward |
| Requests, conversations, appointments and attendance | Through handling of the request and related follow-up or disputes; closing one account does not automatically erase shared records that remain necessary for other participants |
| Support and privacy cases | Through resolution and review; afterward, only the records needed to demonstrate the outcome or meet a specific legal duty or dispute |
| Search records | Only for the period necessary to improve search; records containing personal information remain subject to minimization and applicable erasure rights |
| Agreements, financial records and minimum consent or security evidence | For the relevant relationship and the applicable legal record-keeping or claims period; this does not justify keeping unrelated patient content |
| Temporary processing copies and exports | Until the processing or download purpose ends; backup copies expire through the backup cycle and are protected against reuse after erasure |
Deleting an eligible patient-owned document blocks new platform views and downloads while its content and readable copies are removed. Only necessary non-content records of delivery and deletion may remain. We do not report deletion as complete while content removal has failed.
Closing an account stops use of the account. Erasure may delete, anonymize or detach platform-controlled data while retaining minimum justified records. Closing an account does not automatically erase all shared conversation history or cancel hospital appointments.
We cannot erase a copy already downloaded or imported into a Provider's independent system. You may exercise applicable rights directly with that Provider. ShifaTH does not operate or certify deletion in its external systems. Your applicable legal rights remain unchanged.
8. Your choices and rights requests
Depending on the applicable law and circumstances, you may request access and a copy, correction, portability, erasure, restriction, or object to processing. You may withdraw a consent-based permission through privacy@shifath.com. We explain the effect on the affected activity and handle any other processing only under its applicable lawful basis.
You do not have to close your account to ask a privacy question or withdraw a particular consent. Withdrawal does not undo lawful past processing and cannot recall independent Provider copies.
For profile-wide erasure through the app, a verified owning patient may request erasure of their own profile. If the profile is not yet self-owned, its authorized primary manager may request erasure only where no verified owner or pending claim conflicts. A delegate cannot erase the patient's entire profile merely through delegated access. Permission to delete a particular document is a separate permission. These app controls do not prevent a patient from making a statutory rights request through our privacy contact.
Use available privacy controls or contact privacy@shifath.com. If you cannot sign in, or are a represented patient without an account, the contact route remains available. We verify only what is necessary, record your request, identify applicable deadlines and explain any lawful restriction or refusal.
The in-app export contains data you are currently authorized to access; it is not an expanded view of Organization internal notes, other patients, hidden coordinated messages or credentials. A separate statutory access request is assessed under applicable law and is not automatically refused merely because a record is absent from the ordinary in-app export.
For access and copy requests under Thai law, we provide the requested access or copy without delay and within 30 days unless lawful grounds for refusal apply. Eligible erasure requests are handled without delay and within 90 days, subject to applicable legal exceptions. We explain any restriction that affects your request.
You may complain to the competent data protection authority. For Thailand, consult the Personal Data Protection Committee’s official website for its current complaint channel. You do not waive regulatory or court remedies by contacting us.
9. Security, notifications and website technologies
Safeguards include restricted permissions, private file access and records of authorized handling. Access must be appropriate to the person’s assigned role and the purpose of the activity. No system is represented as risk-free.
Notification preferences control supported channels. Notifications use the channels available in the service and limit sensitive content. Security notifications may remain necessary on an available channel.
Website technologies used for sessions, security and preferences are limited to those purposes. Any optional tracking requiring permission must be identified and offered with the applicable choice before it starts. Agreeing to the Terms or sending patient documents does not provide consent to unrelated advertising tracking.
10. Updates
We identify material changes to this notice and explain them to you. If a new consent is required, we ask for it separately before the affected processing.