Legal

Privacy Policy

This policy explains what personal data On Call collects from locum physicians and healthcare facilities in Saudi Arabia, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Last updated: 15 September 2026.

العربية

Overview

Who this policy covers

On Call operates a two-sided marketplace connecting locum physicians with healthcare facilities (hospitals, clinics, medical centers, and polyclinics) in Saudi Arabia that need temporary clinical coverage. This policy applies to anyone who creates an account, browses the platform, or otherwise shares personal data with us, as a physician, a facility representative, or a visitor to our marketing pages.

On Call acts as the data controllerfor the personal data described below, in line with Saudi Arabia’s Personal Data Protection Law (PDPL) and its implementing regulations issued by the Saudi Data & AI Authority (SDAIA).

What we collect

The data we hold

We collect the following categories of personal data:

  • Account and contact data: full name, email address, phone number, and password (stored as a salted, one-way cryptographic hash: we never store or can retrieve your actual password).
  • Professional identifiers (physicians): medical specialty, years of experience, city, indicative day rate, and your Saudi Commission for Health Specialties (SCFHS) license number where provided.
  • Business identifiers (facilities): facility name, facility type, city, Commercial Registration (CR) number, and Ministry of Health (MOH) license details where provided.
  • Verification documents: where you go through our credential-verification flow, we collect scanned or photographed copies of supporting documents, which may include your SCFHS license, national ID or Iqama, degree certificate, CR certificate, or MOH license, depending on your role. These are among the most sensitive documents we hold, and are handled accordingly (see “How we protect your data” below).
  • Marketplace activity: shift postings, applications, cover notes, acceptances, declines, and withdrawals.
  • Messages: the content of private message threads between a physician and a facility tied to a specific accepted application, plus timestamps and read state.
  • Consent and session records: the version of this policy and the Terms of Service you agreed to, the date and time of that agreement, and session/authentication metadata (such as login timestamps and device/browser information) needed to keep your account secure.
  • Technical data: request metadata (such as IP address and browser user agent) processed transiently for security, rate-limiting, and abuse prevention, and by our infrastructure/CDN provider (Cloudflare) as part of ordinary web traffic handling.

We do not collect payment card data, biometric data, or precise geolocation.

Why we collect it

Purpose of processing

We use personal data to:

  • Create and secure your account, and verify your identity and professional/business credentials before you can post or accept shifts.
  • Operate the marketplace: display shifts and applications to the appropriate parties, and connect an accepted application to a private message thread.
  • Show facilities the professional credentials relevant to deciding whether to accept an applicant, and help physicians judge the legitimacy of a posting facility.
  • Send account, application, and messaging notifications relevant to your activity on the platform.
  • Maintain the security and integrity of the platform, including detecting and preventing fraud, abuse, and unauthorized access, and maintaining an internal record of administrative actions taken on your account (audit log).
  • Meet our legal and regulatory obligations as a Saudi Arabia-based service handling health-sector workforce data.

Our lawful basis for this processing is your consent (given at signup and recorded with a version and timestamp), the necessity of processing to perform our contract with you (providing the marketplace service), our legal obligation to verify health-sector marketplace participants, and our legitimate interest in keeping the platform secure, trustworthy, and accountable. Where processing relies on your consent, you may withdraw it at any time (see “Your rights” below), though withdrawing consent for processing necessary to operate your account will generally mean we can no longer provide the service to you, and may require closing your account.

Sharing

Who sees your data

Physician profile data relevant to an application (name, specialty, experience, SCFHS license number where provided) is visible to the facility reviewing that application. Facility data relevant to a posted shift (facility name, type, city, CR/MOH details where provided) is visible to physicians browsing or applying to that shift. Message content within a thread is visible only to the two participants on that application.

Verification documents are visible only to you and to our administrators reviewing your verification request: every administrator view of a verification document is permanently logged (who viewed it, and when), as a specific accountability control given the sensitivity of these documents. Administrators (a small, access-controlled group) can access account and marketplace data as needed to operate, secure, and support the platform, and every sensitive administrative action is recorded in an internal audit log.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

Sub-processors

Who processes data on our behalf

We share personal data with the following service providers, strictly to operate the platform, under contractual data-protection terms:

  • Google Cloud (via our authorized Saudi reseller): application hosting and database, hosted in Saudi Arabia (Dammam region).
  • Google Cloud Storage: storage of verification documents, including national ID/Iqama scans, once this storage integration is live (see “Where we store your data” below).
  • Cloudflare: content delivery, DDoS and abuse protection at our network edge; processes request metadata (IP address, browser user agent) as part of ordinary web traffic routing.
  • Resend: delivery of transactional emails (account verification, password reset, notifications); processes your email address, name, and the content of the specific email being sent.

We do not use these providers’ access to your data for any purpose beyond operating On Call on our behalf, and we require appropriate data-protection commitments from each of them.

Your rights

Data-subject rights

Under the PDPL, you have the right to:

  • Know what personal data we hold about you and why.
  • Access a copy of your personal data.
  • Correct inaccurate or incomplete personal data. You can update most of your profile directly in your account settings; contact us for fields that require verification.
  • Delete your personal data, subject to information we are legally required to retain.
  • Object to certain processing, and withdraw consent where processing relies on it.
  • Lodge a complaint with SDAIA, the competent Saudi authority, if you believe your data has been mishandled.

Access and portability, self-service:signed-in users can download a copy of their personal data at any time from Profile settings (“Download my data”), or via our mobile app’s Profile screen. No request needed.

Deletion, self-service:signed-in users can permanently delete their own account from Profile settings (“Delete account”), or via our mobile app, after confirming their password. This anonymizes your account immediately; some records tied to shifts, applications, and messages are kept in an anonymized form as described under “How long we keep data” below.

For correction requests we don’t yet support in your account settings, or for any other request, contact us at hello@oncall.onl. We aim to respond to verified requests within 10 business days. We may need to verify your identity first, to make sure we don’t disclose or delete the wrong person’s data.

One limited exception: our internal administrative audit log (a record of actions taken by our own staff, such as which administrator reviewed which verification document, and when) is not deletable on request, because it exists specifically to hold us accountable: deleting it on request would defeat that purpose. It does not contain your marketplace activity or messages, only a record of internal administrative actions.

Security

How we protect your data

We apply technical and organizational safeguards appropriate to the sensitivity of the data we hold, including password hashing, session protections designed so logout or a password change immediately invalidates prior sessions, authenticated and audit-logged access to verification documents, file-type verification on every upload, encrypted connections (HTTPS/TLS), security headers and a restrictive content policy, rate limiting on sensitive actions, and role-based access control for our administrative staff. Full technical detail is published in our engineering documentation (docs/SECURITY.md) for transparency with technically sophisticated users and partners.

No system is completely secure, and we continue to review and improve these safeguards. If we become aware of a data breach affecting your personal data, we will notify SDAIA as required by law and, where required, notify you directly.

Residency

Where we store your data

We are in the process of migrating our infrastructure to be hosted within Saudi Arabia (Google Cloud’s Dammam, me-central2, region), consistent with PDPL data-residency expectations for health-sector-adjacent data. As of this policy’s last-updated date, our application database is intended to be, and is being migrated to be, hosted within Saudi Arabia; verification-document storage (including national ID/Iqama scans) is intended to move to a Saudi Arabia-region cloud storage bucket, and until that migration completes these files are stored on our application server’s own disk rather than in that cloud location; and our content-delivery/security provider (Cloudflare) operates a global network and may process limited request metadata at edge locations outside Saudi Arabia as an ordinary part of routing traffic to our Saudi Arabia-hosted servers. We will update this section as this migration completes.

Retention

How long we keep data

We retain account and marketplace data for as long as your account is active, and for a limited period afterward to meet legal, tax, audit, and dispute-resolution obligations typical for a Saudi health-sector marketplace. Verification documents are retained for a limited period after your verification decision to allow for appeals or disputes, after which the document files are deleted while a record that verification occurred is kept. Message threads are retained alongside the application they belong to, and are redacted or deleted when both participating accounts have closed. Our detailed internal retention schedule is published in docs/compliance/retention-policy.md.

Children

Children

On Call is intended for licensed medical professionals and business representatives of healthcare facilities, and is not directed at or intended for use by children. We do not knowingly collect personal data from children.

Changes

Updates to this policy

We may update this policy as the platform evolves or as Saudi data-protection requirements are clarified. We will update the “Last updated” date above and, where changes are material, seek renewed consent at your next login.

Contact

Questions about this policy

Reach the On Call team at hello@oncall.onl. See also our Terms of Service.