Privacy Policy
Data protection, privacy & information handling
Applies to: www.ditans.health, app.ditans.health, and all DITANS services Version: 1.0
Effective date: 30th March 2025 Last reviewed: 30th March 2026
1. Who we are
DITANS Health Innovation Ltd (“DITANS”, “we”, “us”, “our”) is a company registered in the Dubai International Financial Centre (“DIFC”), Dubai, United Arab Emirates.
| Registered name | DITANS Health Innovation Ltd |
| DIFC registration number | CL8544 |
| Registered address | Unit IH-00-01-02-OF-01- Level 2 – Innovation Hub- Dubai International Financial Centre |
| General contact | info@ditans.health |
| Data protection contact | ma@ditanshealth.com |
| Data Protection Officer | Mutasem AL Titi, ma@ditanshealth.com |
We operate a healthcare talent platform that connects healthcare professionals (“candidates“) with hospitals, clinics, pharmaceutical companies, recruitment agencies and other employers (“employers“).
For the personal data described in this policy, DITANS is the Controller. Our processing is governed by the Data Protection Law, DIFC Law No. 5 of 2020 (the “DP Law“) and the DIFC Data Protection Regulations (the “Regulations“), and is supervised by the DIFC Commissioner of Data Protection (the “Commissioner“).
This policy is the notice we are required to give you under Articles 29, 30 and 31 of the DP Law.
2. Who this policy covers
This policy applies to:
- Candidates — healthcare professionals who register, build a profile, apply for roles, or begin verification through our platform;
- Employer and recruiter users — individuals acting for hospitals, clinics, agencies, pharmaceutical companies and government bodies;
- Partner and supplier contacts — individuals at our verification, training and commercial partners;
- Website visitors — anyone who visits ditans.health or app.ditans.health, whether or not they register;
- Applicants for employment with DITANS.
If you are under 18, do not register or submit personal data to us. See section 15.
3. What personal data we collect
3.1 Data you give us directly
Account and identity data. Full name, email address, password (stored in hashed form), phone number, country of residence, nationality, date of birth, and government identity or passport details where these are required for credential verification.
Professional profile data. Profession and role type, specialty and sub-specialty, academic and professional qualifications, licences and registrations, work experience and employment history, structured skills selections, notice period, salary expectations, language ability, and availability.
Documents you upload. Degree certificates, transcripts, licences, good standing certificates, experience letters, passport copies, photographs, and your CV.
Verification data. Information you provide to initiate or evidence primary source verification through DataFlow, and training or examination status through Prometric.
Employer user data. Name, job title, employer, work email, work phone, and the content of job descriptions, search criteria, shortlists, interview notes and assessments you create in the platform.
Communications. The content of enquiries submitted through our contact form, support tickets, emails and any correspondence with us.
3.2 Data we receive from others
- DataFlow Group: primary source verification reports, verification status, and
- Prometric: training enrolment, examination and mock-test status and
- Employers and recruiters: application status, interview outcomes and hiring decisions relating to candidates.
- Referrers and partners: where a candidate or employer contact is introduced to us.
Where we receive your personal data from a source other than you, we give you the information required by Article 30 of the DP Law no later than one month after we obtain it, or at our first communication with you, whichever is earlier. The source is identified above.
3.3 Data collected automatically
IP address, device and browser type, operating system, referring URL, pages viewed, time on page, and interactions with the platform, collected through cookies and similar technologies. See section 7.
3.4 Special Categories of Personal Data
Certain data we handle may fall within Special Categories of Personal Data under Schedule 1 of the DP Law — in particular:
- criminal record data, where a good standing certificate, police clearance or equivalent forms part of a verification file;
- health data, where a medical fitness certificate or occupational health record is required by a destination regulator or
We process this data only where a condition in Article 11 of the DP Law is met — normally your explicit consent under Article 11(a), or Article 11(b) where the processing is necessary to exercise rights and obligations in the context of recruitment, visa or work permit processing. We do not process Special Categories of Personal Data for marketing, and we never use it as an input to automated decision-making without your explicit consent (Article 38(6)).
We do not require, and ask you not to submit, any Special Category data that a destination regulator or employer has not specifically requested.
4. Why we process your personal data, and our lawful basis
Under Article 10 of the DP Law we must have a lawful basis for every processing purpose. Ours are set out below.
| # | Purpose | Categories used | Lawful basis (Art. 10) | Retention |
| 1 | Creating and maintaining your account; | Account and identity data | 10(b) — | Life of account |
| authenticating you | performance of a contract with you | + 12 months | ||
| 2 | Building your | Profile data, documents, | 10(b) — | Life of account |
| candidate profile and making it | verification status | performance of a contract with you | + 12 months | |
| visible to employers | Â | Â | Â | |
| 3 | Matching | Profile data, | 10(b) — | Life of account |
| candidates to roles and | verification status, preferences | performance of a contract; 10(f) — legitimate interests in operating an | ||
| generating shortlists, | Â | effective matching service | ||
| including AI- | Â | Â | ||
| assisted matching | Â | Â | ||
| 4 | Initiating and | Identity data, qualification | 10(b) and, for Special | 6 years from verification, or as required by the destination regulator |
| tracking DataFlow primary source | documents, Special Category data where required | Categories, 11(a) explicit consent or 11(b) recruitment context | ||
| verification | Â | Â | ||
| 5 | Enabling Prometric training and examination | Account data, examination status | 10(b) — | 6 years |
| purchase | performance of a contract | |||
| 6 | Sharing candidate profiles with | Profile data, | 10(b) — steps taken at your | See section 9 |
| employers who have an active vacancy | verification status | request prior to a contract | ||
| 7 | Operating employer accounts, | Employer user data | 10(b) — | Life of account |
| vacancies and hiring workflows | performance of a contract | + 12 months | ||
| 8 | Responding to enquiries and | Communications | 10(b) or 10(f) — legitimate interests in | 24 months |
| providing support | responding to you | |||
| 9 | Marketing and platform updates by email or in-app message | Contact data, preferences | 10(a) — consent | Until you withdraw consent |
| 10 | Website analytics and performance measurement | Automatically collected data | 10(a) — consent (non-essential cookies) | See section 7 |
| 11 | Security, fraud prevention, | All categories as necessary | 10(f) — legitimate interests, expressly | 24 months from event |
| credential-fraud detection and | recognised at Article 13(3) | |||
| network integrity | Â | |||
| 12 | Meeting legal, regulatory, | As required | 10(c) — | Period required by that law |
| licensing and anti-money-laundering obligations | compliance with Applicable Law | |||
| 13 | Establishing, exercising or defending legal claims | As required | 10(f) legitimate interests; 11(f) for Special Categories | 6 years from the end of the relationship |
Where we rely on legitimate interests, those interests are: operating and securing the platform; preventing credential fraud in healthcare recruitment; and improving the quality of matching. We have assessed in each case that these interests are not overridden by your interests or rights. You may ask us for our assessment, and you may object under Article 34 (see section 12).
Where we rely on consent, you may withdraw it at any time, as easily as you gave it, without affecting the lawfulness of processing before withdrawal (Articles 12(5) and 32). Because our relationship with candidates is ongoing rather than a single transaction, we will periodically ask you to re-confirm any consent you have given, as required by Articles 12(6) to 12(10).
Providing your data. Providing account, profile and verification data is a contractual requirement — without it we cannot create your profile, submit you to employers, or process verification. Marketing consent, optional profile fields and non-essential cookies are entirely voluntary, and refusing them has no effect on your access to the platform (Article 39).
5. Automated matching, AI and profiling
Our platform uses automated and AI-assisted systems. Regulation 10 of the Regulations and Article 38 of the DP Law require us to tell you the following.
What the systems do. We use automated systems to (a) match candidate profiles against employer vacancies and rank the results; (b) assist employers in drafting job descriptions; (c) generate suggested interview questions; and (d) scan uploaded CVs to suggest structured profile fields.
Human-defined purposes. These systems are permitted to process personal data only for the purposes listed above. They are not permitted to define new purposes for processing on their own, and they do not do so.
Outputs and how they are used. The systems produce a relevance score and an ordered shortlist, together with suggested text for employers. The outputs are recommendations. A human employer user decides whom to contact, interview and hire. No decision that produces legal consequences for you, or otherwise significantly affects you, is made solely by automated processing.
Design principles. Our systems are designed to be ethical, fair, transparent, secure and accountable, as required by Regulation 10.3.1. Matching is based on declared skills, qualifications, specialty, experience, licence type and verification status. We do not use race, communal origin, religion, political affiliation, gender identity, sexual orientation or trade union membership as matching inputs, and we test for unjust bias in matching outcomes at least annually.
Your rights. You may object to any decision based solely on automated processing that has legal or similarly significant effects on you, and require that it be reviewed manually, by writing to info@ditans.health. You may also ask us for meaningful information about the logic involved and the significance and likely consequences for you.
On request, we will provide affected parties with the evidence and register described in Regulation 10.2.2(c) to (g), redacted only where necessary to protect intellectual property or comply with law.
6. How your data is shared with employers
Candidate profiles are visible to employer and recruiter users who hold an active, verified account on the platform.
- Model A (search-visible): your profile is searchable by verified employers from the moment you complete it, and you may set your profile to hidden at any time from your account settings; or
Before your personal data is disclosed to a third party for the first time, or used on their behalf for direct marketing, we will tell you and expressly offer you the right to object (Article 34(1)(b)).
Employers who receive your data act as independent Controllers in respect of their own use of it, and their own privacy notices apply. We require every employer user to accept contractual data protection terms before receiving candidate data.
7. Cookies, analytics and digital communications
This section is our notice under Regulation G of the Regulations and Articles 29(1)(h)(viii) and 31 of the DP Law.
7.1 Our default position
No non-essential cookie, tag, pixel or tracking technology runs on our website or platform before you give consent. On your first visit you are shown a consent banner with clear, colour-neutral options that neither promote nor discourage acceptance.
Boxes for non-essential purposes are unticked by default. We do not treat silence, inactivity, continued scrolling or continued browsing as consent (Regulation 9.3.3).
Our default privacy settings are configured so that no more than the minimum personal data necessary to deliver the service is collected (Article 14(4) and Regulation 9.2.3).
7.2 Changing your preferences
You can change your cookie and communications preferences at any time through the Privacy Preferences link in the footer of every page, or in Account settings → Privacy once you are signed in. Withdrawing consent takes effect immediately and is no harder than giving it.
7.3 Marketing and electronic communications
We send marketing emails, SMS and in-app messages only where you have given a clear, affirmative, unambiguous consent, given separately from your acceptance of our terms of service. Every marketing message contains a working unsubscribe link and a link to your preference centre. You may object to direct marketing at any time and without giving a reason (Article 34(1)(c)), and we will stop.
Service messages that are necessary to operate your account verification status, application updates, security alerts, changes to terms are not marketing and are sent on the basis of our contract with you.
8. Who we share your personal data with
| Recipient category | Examples | Why |
| Verification partner | DataFlow Group | To initiate and complete primary source verification |
| Training and examination partner | Prometric | To enrol you in training and examinations you purchase |
| Employers and recruiters | Hospitals, clinics, agencies, pharmaceutical companies, government bodies | To present you for roles, on the basis described in section 6 |
| Cloud hosting and infrastructure | AWS | To host the platform and store data |
| Analytics and marketing technology | Google Analytics | Website measurement, with your consent |
| Payment processor | Stripe | To process fees you pay |
| Professional advisers | Lawyers, auditors, insurers | Where necessary and confidential |
| Regulators and authorities | DIFC Commissioner of Data Protection; other competent authorities | Where required by Applicable Law, subject to Article 28 |
| Corporate transactions | Prospective investors or acquirers | Under confidentiality, in a due diligence or transaction context |
Every processor we appoint is engaged under a written agreement meeting Article 24(5) of the DP Law. Processors may not appoint sub-processors without our prior written authorisation, and may process your data only on our documented instructions.
Where a public authority requests your personal data, we assess the validity and proportionality of the request, minimise what we disclose, and seek written assurances where practicable, as required by Article 28.
9. International transfers
DITANS operates across candidate source markets and placement markets outside the DIFC. Transferring your personal data out of the DIFC is intrinsic to the service.
Transfers to adequate jurisdictions. Where the destination appears on the Commissioner’s list of adequate jurisdictions in Appendix 3 of the Regulations — which includes the United Kingdom, EU and EEA member states, Ireland, Singapore, South Korea, Canada, California and the Abu Dhabi Global Market — the transfer is made under Article 26 and no additional safeguard is required.
Transfers to non-adequate jurisdictions. Several markets we operate in are not on that list, including the United Arab Emirates outside the DIFC, Saudi Arabia and the other GCC states, India, the Philippines, Nepal, Nigeria, South Africa, Egypt, Jordan, Ukraine, and the United States other than California. For these we rely on Article 27, and in particular:
- the standard contractual clauses adopted by the Commissioner under Article 27(2)(c) and Regulation 5, which we have entered into with the relevant recipients; and
- where an individual placement cannot be covered by those clauses, Article 27(3)(b) — the transfer is necessary to perform a contract with you — or Article 27(3)(a), your explicit consent given after we have informed you of the risks arising from the absence of an adequacy decision.
You may request a copy of the safeguards in place for any specific transfer by writing to info@ditans.health. We will provide it free of charge.
10. How long we keep your data
We keep personal data only for as long as is necessary for the purposes it was collected for. Our retention periods are set out in the table at section 4.
When a retention period ends, when you withdraw consent, or when the basis for processing otherwise falls away, we securely and permanently delete, anonymise, pseudonymise or encrypt the data, in accordance with Article 22 of the DP Law. Where that is not technically possible, we archive it in a form that is put beyond further use.
We may retain data beyond these periods only where it is necessary for the establishment or defence of legal claims, or where Applicable Law requires it.
11. How we protect your data
We implement technical and organisational measures appropriate to the risk, taking into account the nature and scope of the processing and prevailing information security practice (Article 14(2)), including:
- encryption of personal data in transit and at rest;
- role-based access control and least-privilege access to candidate documents;
- multi-factor authentication for administrative accounts;
- logging and monitoring of access to personal data;
- vetting of staff and contractors, confidentiality undertakings, and regular data protection
If a personal data breach occurs that compromises the confidentiality, security or privacy of your data, we notify the Commissioner as soon as practicable (Article 41). Where the breach is likely to result in a high risk to you, we notify you directly, in clear and plain language, with recommendations for reducing the impact (Article 42).
12. Your rights
Under Part 6 of the DP Law you have the following rights. All are free of charge, and we respond within one month of a valid request. If a request is particularly complex, or if you have made several, we may extend that period by up to two further months and will tell you why within the first month.
| Right | What it means | Article |
| Withdraw consent  | Where we rely on consent, withdraw it at any time. Absolute right. | 32 |
| Access | Confirmation of whether we process your data, a copy of Access it, and information about its source, purposes, categories and recipients. | 33(1) |
| Rectification | Have inaccurate data corrected. | 33(1)(c) |
| Erasure | Have your data deleted where it is no longer necessary, where you withdraw consent, where processing is unlawful, or where you object and we have no overriding grounds. | 33(2) |
| Object | Object to processing based on legitimate interests, and object at any time to direct marketing. | 34 |
| Restrict processing | Require us to pause processing while accuracy is checked or an objection is resolved. | 35 |
| Data portability | Receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. | 37 |
| Object to automated decisions | Object to decisions based solely on automated processing with legal or similarly significant effects, and require manual review. | 38 |
| Non-discrimination | We will not deny you services, charge you differently, or degrade your service because you exercised a right. | 39 |
How to exercise your rights
As required by Article 40, we provide more than one method, at least one of which is free, available through our website, and does not require you to create an account:
- Online form — the Privacy Request form at [https://www.ditans.health/privacy-request] — no account needed, no
- Email — info@ditans.health
- Post — Data Protection Officer, DITANS Health Innovation Ltd, Unit IH-00-01-02-OF-01- Level 2 – Innovation Hub- Dubai International Financial Centre – Mutasem AL Titi, ma@ditanshealth.com
If we have reasonable doubt about your identity we may ask for additional information to verify it, and the response period begins when we receive it.
We maintain a register of any occasion on which we extend a response period or decline a request as manifestly unfounded or excessive, and the Commissioner may inspect it (Articles 33(9) and 33(10)).
13. Complaints
If you are unhappy with how we have handled your personal data, please contact our Data Protection Officer first — we would like the chance to put it right.
You also have the right at any time to lodge a complaint directly with the Commissioner, and to apply to the DIFC Courts:
Office of the Commissioner of Data Protection Level 14, The Gate, PO Box 74777, Dubai, United Arab Emirates commissioner@dp.difc.ae
Since 8 July 2025, you also have a private right of action to apply to the DIFC Court for compensation where you suffer damage, including distress, as a result of a contravention of the DP Law.
14. Employment applicants
If you apply for a role at DITANS, we process your application data on the basis of Article 10(b) — steps taken at your request before entering a contract — and, for any Special Category data required for visa or work permit processing, Article 11(b). We keep unsuccessful applications for [12] months and then delete them, unless you ask us to keep you on file.
15. Children
Our services are intended for professionals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it. Where a data subject is a minor by reference to the legal age of majority in the UAE, we will not rely on the exceptions in Article 38(2) to make solely automated decisions about them.
16. Changes to this policy
We review this policy at least annually and whenever our processing changes materially. Where a change materially affects your rights, we will notify registered users directly by email or in-app notice before it takes effect. The version number and effective date at the top of this policy always show the current version. Previous versions are available on request.
17. Contact us
Data Protection Officer DITANS Health Innovation Ltd, Dubai International Financial Centre, Dubai, UAE info@ditans.health
This policy is issued under Articles 14(5), 2S, 30 and 31 of the Data Protection Law, DIFC Law No. 5 of 2020, and Regulations S and 10 of the DIFC Data Protection Regulations.