ConferTBHCI

Legal

Privacy Policy

Last updated: 17 September 2026

1. Who we are 2. Data we collect 3. How we use data 4. Lawful basis & consent 5. The identity firewall & de-identification 6. How we protect data 7. Sharing & processors 8. Cross-border transfers 9. Automated processing & AI 10. Retention 11. Your rights 12. Children 13. Changes 14. Contact

1. Who we are

Confer is a clinical second-opinion platform that connects treating clinicians and patients with consulting surgeons for remote surgical second opinions. The platform is operated in the United Arab Emirates in connection with The Bespoke Health Care Initiative (TBHCI) ("we", "us", "Confer"). We act as the controller of personal data processed through the platform, and engage the processors listed in section 7.

2. Data we collect

Account data

For patients and clinicians: name, WhatsApp mobile number, email address (optional for patients), role, time zone, and — for surgeons — licence country, specialty, consultation rate, profile photo, and credential documents you upload for verification.

Patient identity data

When a case is created, identifying details of the patient may be entered (name, Emirates ID, date of birth, sex, contact). This information is held in a separate, encrypted store and is described in section 5.

Clinical case data

Pseudonymous clinical information about a case: age, sex, laterality, anatomical area, clinical summary, the question posed, uploaded imaging and documents, consulting opinions, case notes, and messages exchanged about the case.

Payment data

When a self-pay consultation is paid, payment is processed by our payment processor (Stripe). We store a payment record (amount, currency, status, processor references and timestamps). We do not store full card numbers.

Technical & log data

Authentication events, access to cases and files, actions taken, IP address, and timestamps are recorded in an audit log for security and traceability. One-time passcodes are stored only as short-lived hashes.

3. How we use data

4. Lawful basis & consent

We process personal data on the bases permitted under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and applicable health-sector regulation, including your consent, the performance of the service you request, our legitimate interests in operating and securing the platform, and compliance with legal obligations. Where a case is routed to a surgeon outside the UAE, we obtain and record explicit consent for that cross-border transfer before any data is sent (see section 8).

5. The identity firewall & de-identification

Confer separates who the patient is from what the case is about at the data-model level. Patient identity is stored in a separate, encrypted store and is never included in the information a consulting surgeon receives. A consulting surgeon works from a pseudonymous case reference and de-identified clinical data only.

Before imaging can be shared, identifying metadata is removed — DICOM identity tags are stripped and image EXIF metadata is discarded. Files that cannot be automatically de-identified (for example, burned-in annotations or PDFs) are withheld for manual review rather than shared. Within messages and notes, participants are asked not to include identifying details, and clinicians see a patient as "Patient" rather than by name.

6. How we protect data

7. Sharing & processors

We do not sell personal data. We share data only as needed to provide the service, with the following categories of processors, each bound by their terms and applicable data-protection obligations:

We may also disclose data where required by law or to protect the rights, safety, and security of patients, users, or the platform.

8. Cross-border transfers

Patient identity and case data are stored on UAE-based infrastructure. A case is only routed to a surgeon outside the UAE after explicit, recorded patient consent for that transfer, and in that event only the de-identified, pseudonymous case is transmitted — never patient identity. Certain processors (for example, for AI suggestions, video, messaging, email, and payments) may process limited data outside the UAE; where they do, only the minimum necessary data is shared, and never patient identity through the identity firewall.

9. Automated processing & AI

To help match a case to a suitable consulting surgeon, Confer may send de-identified clinical text (anatomy, laterality, age, sex, summary, and the question) together with candidate surgeon profiles to an AI provider (Anthropic), which returns ranked suggestions with reasoning. No patient identity is included in this processing. AI suggestions are decision-support only; the choice of surgeon and all clinical decisions rest with the human clinician and the patient. Second opinions are advisory and do not replace the treating clinician's judgement.

10. Retention

We retain case, clinical, and payment records for as long as necessary to provide the service and to meet legal, regulatory, medical-record, and financial-retention obligations. When you delete your account, we remove your personal identifying details and disable sign-in, while retaining de-identified case and payment records where required as legal or medical records.

11. Your rights

Subject to applicable law, you may have the right to access, correct, or request deletion of your personal data, to withdraw consent, to object to or restrict certain processing, and to data portability. Patients can update their name, email, time zone, and (with re-verification) mobile number, and can request account deletion, from the account page. To exercise other rights, contact us using the details below. You may also have the right to lodge a complaint with the UAE Data Office.

12. Children

A case may concern a patient who is a minor; such cases must be created and managed by an authorised adult (a treating clinician or the child's parent/guardian). The platform's accounts are intended for adults acting in those capacities.

13. Changes

We may update this policy from time to time. Material changes will be indicated by updating the date above and, where appropriate, by notice through the platform.

14. Contact

For privacy questions or to exercise your rights, contact TBHCI / Confer at the address published on our website. A data protection point of contact should be inserted here prior to launch.

© TBHCI · Confer. This document is a template pending legal review and does not constitute legal advice.