Legal
Privacy policy
In short: we collect the minimum needed to run the platform. Your dental record is seen by the dentist treating you and by you. We don't sell your data to anyone, and you can ask us to delete your account at any time.
Who we are and the scope of this policy
"We" and "the platform" refer to Siha, operator of the Siha app and this website. This policy explains how we handle your personal data when you use the app, the site, or any of our services.
It does not cover what clinics or dentists do outside the platform, nor external websites we may link to.
Data we collect
Data you give us
- Account details: name, phone number, gender and date of birth if you enter them, and your city.
- Verification code: we send a one-time code to your phone to confirm the number is yours.
- Provider details: if you register as a dentist, clinic or student, we collect speciality, clinic address, opening hours and clinic photos, plus verification documents (practice licence, clinic frontage photo, and for students: university, year of study and student number).
- Content you upload: photos, documents, reviews, and messages you send inside the platform.
Data generated by your use
- Appointments and orders: the clinics you booked with, your appointments and their status, your store orders and delivery addresses.
- Payment data: for online payments the transaction is processed by the payment gateway; we store the result and its reference, not your card or wallet details.
- Device data: device type, operating system, app version, and your notification token if you enable notifications.
- Location: if you grant permission, we use your location to order clinics by proximity. The permission is optional and can be withdrawn from your phone settings without the app ceasing to work.
- Technical logs: IP addresses, error logs and request timestamps, for operations and security.
Your health data
The platform stores data of a health nature, which is your most sensitive data: your tooth chart and each tooth's condition and surfaces, treatment plans and their steps, medical history and allergies, dentist's notes, and clinical documents and images.
This data is entered by the treating dentist into your record, and is used solely to deliver and follow up care and to show it to you. It is not used for advertising, not shared with commercial parties, and never sold.
Why we use your data
- To create your account, verify your identity and secure sign-in.
- To show clinics and available times, and to make and manage bookings.
- To let your dentist keep your clinical record and to let you view it.
- To process store orders, payment and delivery.
- To send operational notifications: appointment confirmations, reminders, order status updates.
- For technical support and answering your enquiries.
- To prevent fraud and abuse and protect the platform's security.
- To improve the service through aggregated statistics that don't identify you.
Who sees your data
- The dentist or clinic you book with: sees your name, phone number and appointment, and the clinical record they create for you once you become their patient. Your records are not shown to a clinic you haven't visited.
- You: you can reach your record, chart, treatment plans, appointments and orders from the app.
- The platform team: limited, permission-restricted access for operations, support and provider verification, with administrative access logged.
- Competent authorities: we disclose data only on a valid legal request, and to the minimum extent necessary.
We do not sell or rent your personal data to anyone.
Service providers
We use technical parties that process some data on our behalf, only as far as their work requires:
- SMS provider: to send verification codes — only your phone number is passed.
- Online payment gateway: to execute payments — payment details are handled there, not by us.
- Notification service: to deliver notifications to your device — the device token and notification text are passed.
- Storage and hosting: to store files and images and run the servers.
We require these providers to use the data only for the agreed service.
How long we keep data
- Account data: for as long as your account exists.
- Clinical records: kept for as long as continuity of care requires and as applicable regulations require.
- Order and payment records: for the period accounting and legal requirements demand.
- Verification codes: expire within minutes and are deleted afterwards.
- Technical logs: for a limited period sufficient for operations and security.
Security
- Every connection between the app or site and our servers is encrypted over HTTPS.
- Passwords are stored hashed and cannot be read by us.
- Data access is restricted by role-based permissions, and sensitive administrative actions are logged.
- Uploaded files are served through time-limited links rather than permanent public URLs.
Even so, no method of transmission or storage is completely secure. Keep your verification code and password private and never share them — our team will never ask you for them.
Your rights
- Access: to know what data of yours we hold.
- Correction: edit your details from account settings, or write to us to correct what you can't change yourself.
- Deletion: request deletion of your account and personal data — see the next clause.
- Withdrawing permissions: turn off location or notification permissions from your phone settings at any time.
- Objection: write to us if you believe our use of your data is unjustified.
We respond within a reasonable period, and may ask for additional identity verification before acting on a request involving sensitive data.
Deleting your account
You can request deletion of your account at any time by writing to us from the phone number or email registered on the account at privacy@example.com.
When deletion is carried out:
- Your profile data is deleted and your upcoming appointments are cancelled.
- Your access is removed, and the account cannot be recovered afterwards.
- We may retain a minimum of records (such as order and invoice records, and records we are required to keep) after unlinking them from you where possible.
Children's privacy
The platform is intended for people aged 18 and over. A parent or guardian may create an account, book appointments for their child and manage the child's record, and is responsible for the data they enter on the child's behalf.
We do not knowingly collect data from children directly. If you learn that a child has created an account, write to us and we will delete it.
Notifications and permissions
- Notifications: we send operational notifications about your appointments and orders. You can turn them off in your phone settings, though you may then miss an appointment reminder.
- Location: optional, and used only to order clinics by proximity. We do not track your location in the background.
- Camera and files: requested only when you upload a photo or document, and not accessed otherwise.
Changes to this policy
We may update this policy as the service or regulatory requirements change. We update the "last updated" date at the top of the page and alert you in the app for material changes. Continuing to use the platform after publication means you accept the updated version.
How to reach us
For any question or request about your privacy:
- Email: privacy@example.com
- General support: support@example.com
- Phone: +964 000 000 0000
- Address: Baghdad, Iraq
See also the terms and conditions.