Privacy Policy
Version 2026-09-14. Last updated 14 September 2026.
This policy explains what personal data Mustaed collects when you use the practitioner app, why, where it is stored, who can see it, and your rights under the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulation.
1. Who is responsible for your data
The controller of your personal data is Dr. Anas Alsolami, a Saudi physician acting as an individual, who operates Mustaed. Mustaed is not yet a registered company; if it becomes one, we will tell you before your data is moved to it. Privacy contact: support@mustaed.app.
2. What we collect
| Data | Examples | Required? |
|---|---|---|
| Account | Name, email address, and a password (stored by our sign-in provider only as a secure hash; we never see it) | Required to create an account |
| Profile | Specialty, city, SCFHS licence number, employer, years of experience | Specialty and city are asked at first login; the rest is optional |
| Preferences | Whether you receive reminder emails, and which language appears first | Set by you |
| Certificates | Certificate name, issuing body, issue and expiry dates | Entered by you |
| Documents | Photos or PDFs of your certificates that you choose to upload | Optional |
| Session requests | The course and training centre you request, and any note you add | Only when you send a request |
| Email delivery records | Whether each reminder email was sent, delivered or bounced | Created when we email you |
| Usage events | Which features are used (for example "certificate added" or "centre page viewed"), recorded as codes and yes/no values, never your name, licence number or anything you type | Collected automatically |
| Technical logs | IP address, browser type and time of sign-in and page requests, kept by our sign-in and hosting providers | Collected automatically, for security |
We do not process sensitive data as defined in the PDPL, such as health data, and we do not ask for your national ID or payment details. Please upload only course certificates, not your national ID, Iqama, passport or SCFHS licence card, and do not include health information in notes.
3. Why we use it, and the legal basis
| Purpose | Legal basis under the PDPL |
|---|---|
| Run your account; show your certificates, expiry status and documents | Performing our agreement with you (the Terms of Use), Article 6(2) |
| Renewal reminder emails 90, 30 and 7 days before a certificate expires, and after it expires (you can switch them off in your profile) | Article 6(2) |
| Your credentialing file (PDF), when you ask for it | Article 6(2) |
| Send your session request to a training centre you choose | Your consent, given on the request screen each time, Articles 5 and 15(1) |
| Security and preventing misuse | Our legitimate interests, Article 6(4) |
| Understanding, in aggregate, which features are used | Our legitimate interests, Article 6(4) |
We will not use your data for a new purpose without telling you first and, where the law requires, asking for your consent. We do not make decisions about you by automated means alone. We do not sell your data or use it for advertising.
4. Who we disclose your data to
- You. Only you can see your certificates, documents, reminders and profile.
- Training centres you send a request to. Only when you send a request and agree on the request screen, that centre receives your name, specialty and SCFHS licence number, with the course and your note, so it can confirm your place. It does not see your certificates, documents or other requests. Calling or emailing a centre yourself from the directory shares nothing with it through Mustaed.
- Mustaed. Only the controller, to approve training centres, give support you ask for and keep the service running.
- Authorities, where the law requires it.
- Service providers (processors) that process data on our behalf, under their published terms:
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign-in and document storage | Mumbai, India |
| Resend | Sends reminder emails | The United States |
| Railway | Hosts the website | The United States |
The credentialing file you download goes to your own device; who you share it with is your choice.
5. Transfer outside Saudi Arabia
Your data is stored and processed outside the Kingdom, in India (Supabase), the United States (Resend) and the United States (Railway). We transfer it to provide the service you asked for, transfer only the data each provider needs, and assessed the risks of these transfers on 13 September 2026. You can ask us for a summary of that assessment.
6. How long we keep it
We keep your data while your account is open. When you delete your account, your profile, certificates, documents, session requests, reminders, email delivery records, usage events and sign-in records are deleted from our database and storage at once and cannot be recovered. Our database plan currently keeps no backups; if that changes, backup copies will expire within 7 days. Our email provider keeps its delivery logs for up to 30 days, and our hosting provider keeps request logs for up to 30 days.
7. Your rights
Under the PDPL you have the right to:
- be informed of the legal basis and purpose of collecting your data (this policy);
- access your personal data;
- obtain a copy of your personal data in a readable, clear format (email us; your credentialing file covers your details, certificates and documents);
- request correction, completion or updating (in your profile and dashboard, or by email);
- request destruction of your data (use Delete account on your profile page, or email us);
- withdraw consent to sharing with a centre, by cancelling a pending request; this does not affect processing already carried out;
- complain to the competent authority, the Saudi Data and AI Authority (SDAIA), through the National Data Governance Platform (dgp.sdaia.gov.sa);
- claim compensation before the competent court for damage caused by a violation.
Email support@mustaed.app from your account's email address. We may verify your identity. We respond within 30 days, which may be extended once by up to 30 days if we tell you why in advance. Requests are free.
8. Security
Database rules restrict every table holding your data to you. Documents are stored privately and opened only through links that expire after 60 seconds. Data is encrypted in transit. No system is perfectly secure: if a leak of, damage to, or unauthorised access to your personal data may harm you or your rights, we will notify SDAIA within 72 hours of becoming aware of it and notify you without undue delay.
9. Cookies
We use essential cookies only, to keep you signed in. Your choice of app language is stored on your device. We do not use advertising or tracking cookies.
10. Age
You must be 18 or older, with full legal capacity, to create an account. If we learn an account belongs to someone under 18, we will delete it.
11. Changes
If we change this policy in a way that affects you, we will tell you in the app or by email before the change applies. Each version is dated at the top of this page.
