Data-retention schedule
This schedule sets out how long we keep each kind of data and when it is deleted. We keep data only as long as we need it, or as the law requires.
Draft, pending legal review
This document is an in-house draft, prepared for review by legal counsel in Oman. It is not legal advice, is not yet in force, and may change.
What we keep, and for how long
- Consultation notes and clinical records
- Kept for the period the health regulator requires. That period is being confirmed with counsel; until then we keep them and do not delete them early.
- Visit summaries, sick-leave certificates, prescriptions
- Kept with the clinical record, on the same basis.
- Files or photos shared in a consultation
- Kept with the consultation record; removable at the patient's or doctor's request.
- Booking details
- Kept while the account is active and for a reasonable period after, for records and disputes.
- Consent records
- Kept as long as the related record is kept, as evidence of what was agreed.
- Payment records and invoices
- Kept for the period tax and commercial law require.
- Reviews
- Kept while published; a review is never linked to a patient identity.
- Verification documents (licence, civil ID)
- Deleted the moment a claim is approved or rejected; only a hash of the document survives.
- Text you type into the care finder
- Kept for a short window (about 90 days) and never linked to your identity.
- Complaint and incident records
- Kept as evidence that a report was logged, routed, and closed.
- Security and access logs
- Kept for a limited period for security, then deleted.
Deletion
When a period ends, we delete the data or make it anonymous so it no longer identifies you. Some records must be kept longer because the law requires it, such as tax records.
This document is published in Arabic and English. If the two versions ever differ, the Arabic version is the one that applies.