Effective Date: February 27, 2025
Last Updated Date: February 27, 2025
ATHEAL’S GUIDING PRIVACY PRINCIPLES
Atheal was built for our families, ourselves, and you. Your privacy is one of our top priorities. We empower you to take control of your health, and that includes having control of certain aspects of your Personal Information. Please read the Privacy Policy in full to understand all of our Personal Information practices as we set out our guiding privacy principles immediately below.
- Your identity is not for sale for money. We do not disclose your Personal Information to third parties in exchange for money.
- We limit the information we collect and retain. We collect Personal Information to provide you with our products and Services. We retain your information for the period of time necessary to fulfill the purposes for which we collected it, including delivering requested products and Services, protecting the interests of our members, and for the period of time required by law.
- We limit the manners in which we share your test results with third parties. In order to deliver our product and services to you, it may be necessary for us to provide certain information to our Lab and Provider Partners. We will do so when such recipients agree to limitations regarding the use of your personal information
.
We encourage you to review the rest of this Privacy Policy to learn more about Atheal's transparent privacy practices.
PRIVACY POLICY
This Privacy Policy governs how Atheal ("Atheal", "Company", "we", "our", "us") collects, stores, and uses your Personal Information (as defined below), as well as other data and information arising out of and/or relating to you and/or your use of our Services – which include without limitation your use of the website Atheal.com (the "Site") and any other technologies, features, websites, mobile applications, content, and other services we offer (collectively, the "Services"). We may also provide you with "just-in-time" disclosures, supplemental terms and/or clarifications, further options, and additional information pertaining to our collection, storage, and usage of Personal Information, and other data and information.
Atheal may also collect, store, and use Personal Information regarding you that is linked or reasonably linkable to you and that identifies your past, present, or future health status or mental health status, as may be applicable ("Consumer Health Data"). This Privacy Policy provides information about how we collect Consumer Health Data, how we use it, what sources it is derived from, to whom we disclose it and how we otherwise process it.
This Privacy Policy does not apply to third-party websites, applications, products, services, or other properties, even if they may link to our Site or our Site may link to them. We recommend you review the privacy practices of those third parties before connecting with and/or accessing third-party offerings, and before sharing any Personal Information with those third parties.
To keep things simple, we use the same capitalized terms as those set forth in our Terms of Service, linked here, unless otherwise indicated herein. In the event of a conflict between our Privacy Policy and our Terms of Service, the latter will control.
Contents
It is important that you read and understand the entire Privacy Policy before using our Services. For ease of review, below is a table of contents that links to each section. Please note that the complete provisions and not the headings shall govern.
- Personal Information We May Collect, Use, and Disclose
- Sources of Personal Information
- Disclosure of Personal Information
- Aggregated, Deidentified, or Anonymized Information
- Cookies and Tracking Technologies
- Data Security
- Data Retention
- International Transfers of Your Personal Information
- Children's Privacy
- Your Privacy Rights
- Saudi Arabia Privacy Notice
- Changes to This Privacy Policy
- Contact Us
1. Personal Information We May Collect, Use, and Disclose
"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identifiable individual. Personal Information includes "personal data" as that term is defined in applicable privacy laws. Personal Information does not include "Publicly Available Information"; lawfully obtained, truthful information that is a matter of public concern; information that has been de-identified; or aggregate consumer information. "Publicly Available Information" includes: information that is made available from government records; information that a business has a reasonable basis to believe is lawfully available to the general public, either through widely distributed media, or by the consumer; and information that is made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. "Self-Reported Health Information" refers to Personal Information that relates to your physical or mental health and that you provide directly to us when you complete electronic forms designed for you to self-report your physical or mental health status, upload medical records, or link a wearable or Internet of Things device to our Services. For clarity, Self-Reported Health Information does not include other information such as (i) purchase data; or (ii) information collected via tracking technologies (e.g. cookies, web beacons) on unauthenticated pages on our websites.
We may disclose non-Personal Information, such as aggregated user statistics, to third parties.
In the table below, we set out the categories of Personal Information that we may collect, how we may use such Personal Information, and the categories of third parties to whom we may disclose such Personal Information where such disclosure may be considered a "sale" or "share" of Personal Information.
Please note that because of the overlapping nature of certain of the categories of Personal Information identified above, which may be required by applicable law, some of the Personal Information we collect may be reasonably classified under multiple categories. Further, we may disclose all Personal Information, for our business purposes, to (i) service providers; (ii) professional advisors (such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us); (iii) authorities and others (such as law enforcement, government authorities and private parties, as we believe in good faith to be necessary or appropriate); and (iv) business transferees (such as in the context of actual or prospective business transactions). For more information on to whom we may disclose your Personal Information, please see the section Disclosure of Personal Information.
2. Sources of Personal Information
We may collect Personal Information about you from the following categories of sources:
- Directly from you through self-reported information, i.e. directly from you through your interactions with us, including without limitation when you use the Site or Services (e.g. creating an account with us, completing electronic forms, uploading medical records, linking a wearable device to our Services) or otherwise contact us via chat, email, phone, or text.
- Through cookies and other tracking technologies, as discussed in more detail in Cookies and Other Tracking Technologies (Section 5 of this Policy).
- Through linked wearable devices connected to our Services (which may include historical data related to your use of the wearable devices).
- From third party healthcare service providers, laboratory service providers, and other providers of medical and medical-adjacent services (our "Lab and Provider Partners"), with your permission and in accordance with applicable law and the context in which you provided the data.
- From other third parties, including our third party service providers, business and marketing partners, affiliates, analytics providers, ad network providers, ad agencies, and advertisers.
- From third parties that you choose (such as lab providers).
- From government agencies or public records.
- From social media and other content platforms.
3. Disclosure of Personal Information
Below is a simple chart designed to help you understand, at a general level, what information we will and will not share with third party tracking technology partners (including third party advertising platforms), followed by more details about our disclosure of your Personal Information:
In full, we may disclose Personal Information that we collect, generate or that you provide, to the following:
- Our affiliates. We may share Personal Information among our affiliates to provide our Services, and for internal administrative purposes.
- Our service providers. We share certain Personal Information with our service providers to provide services on our behalf, such as payment processing, analytics, hosting, marketing, customer and technical support, professional advisors (such as our lawyers, auditors, bankers and insurers) and other services.
- Our payment processing platforms. Payment card information you use to make a purchase on the Service is collected and processed directly by our payment processors. They may use your payment-related data in accordance with their privacy policy.
- Our Lab and Provider Partners. We have engaged with various third-party Lab and Provider Partners in connection with various facets of our Services. Such partnership may involve receiving and sharing Personal Information, including without limitation Consumer Health Data, with your permission in accordance with applicable law and the context in which you provided the data.
- Third party platform advertisers. We will not disclose your Lab Results or Self-Reported Health Information without your express, affirmative consent. We may otherwise share certain information gathered through tracking technologies like cookies and web beacons with third-party platform providers. We also partner with third parties who use cookies to serve interest-based advertising and content on their respective third-party platforms that may be based on your preferences, location, and/or interests.
- Third parties related to compliance and harm prevention. Under certain circumstances, we may be required to disclose your Personal Information if required to do so by law or in response to valid requests by public authorities, and/or in response to a threat of harm involving an individual's health and/or safety. This may include law enforcement, government authorities and private parties.
- Third parties related to a change of ownership or other corporate transformation. Notwithstanding anything to the contrary in this Privacy Policy, if we or our subsidiaries are involved in an actual or potential merger, acquisition, asset sale, or other corporate transformation, your Personal Information – including without limitation your Lab Results and any and all other Self-Reported Health Information – may be transferred to the prospective, acquiring or surviving entity (and their respective representatives).
- At your request, other persons or entities that are relevant to your care. At your request, we may also share Personal Information, such as your Lab Results (as defined in our Terms of Service), with your general practitioner, your specialist, or your provider's health system.
- Third parties designated by you. We may share your Personal Information with third parties where you have instructed us or provided your consent to do so such as when you choose to share results.
- Other users and the public. If you choose to make your Personal Information available to others and the public through the Service, such as when you provide comments, reviews, survey responses or share other content, that Personal Information will be available to other users of the Service and the public. This information can be seen, collected and used by others, including being cached, copied, screen captured or stored elsewhere by others (such as search engines) and we are not responsible for any such use of this information.
We do not disclose your Personal Information to third parties in exchange for money.
4. Aggregated, Deidentified, or Anonymized Information
We may create aggregated, de-identified, or anonymized information from Personal Information by removing certain data components (such as your name, email address, or linkable tracking ID) that makes the data identifiable, or through aggregation, obfuscation or other means. For example, we may de-identify any information and data provided and/or generated in connection with your use of our Services (including without limitation your Lab Results and other Personal Information), in compliance with applicable law.
5. Cookies and Tracking Technologies
We use cookies and similar tracking technologies and analytics services to track activity on the Site and Services.
a. Cookies
Cookies are files with a small amount of data which may include unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies we may use include web beacons to track information and analyze the Services. Beacons (also known as pixel tags, clear GIFs) are small objects that are embedded in an image on a website; they can transmit information directly to Atheal, or to another person or entity of our designation. For the purposes of this Privacy Policy, cookies, beacons, and other such tracking technologies shall, collectively, be embraced by the term "Cookies." You can instruct your browser to refuse certain Cookies or to indicate when a Cookie is being sent. However, if you do not accept certain Cookies, you may not be able to use some portions of our Service.
Examples of Cookies we use:
- Strictly Necessary. We may use Cookies that we consider are strictly necessary to allow you to use and access our website, including Cookies required to prevent fraudulent activity, improve security or allow you to make use of shopping cart functionality.
- Performance. We may use Cookies that are useful in order to assess the performance of our website, including as part of our analytic practices or otherwise to improve the content, products or Services offered through our website.
- Functionality. We may use Cookies that are required to offer you enhanced functionality when accessing our website, including identifying you when you sign in to our website or keeping track of your specified preferences, including in terms of the presentation of content on our website.
- Advertising. We may use Cookies to deliver content, including ads, relevant to your interests on our website and third party sites based on how you interact with advertisements or content.
We implement measures designed to limit the types of Cookies (excluding Strictly Necessary Cookies) for individuals accessing our Services who have opted out of such tracking.
b. Analytics
We may use Google Analytics or other service providers for analytics services. These analytics services may use Cookies and other tracking technologies to help us analyze how users use the Services. Information generated by these services (e.g., your IP address and other usage information) may be transmitted to and stored by Google Analytics and other service providers on servers in Saudi Arabia (or elsewhere) and these service providers may use this information for purposes such as evaluating your use of the Service, compiling statistic reports on the Service's activity, and providing other services relating to Service activity and other Internet usage.
c. Third-Party Ad Networks
Certain companies may participate in advertising networks and may display an Advertising Option Icon for Interest-based Ads that links to an opt-out tool which allows you to exercise certain choices regarding targeting.
6. Data Security
The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is completely secure. Atheal uses certain safeguards designed to protect the security and integrity of your Personal Information. If you complete a purchase with us, your financial information (as defined in Personal Information We May Collect, Use, and Disclose) will be processed by our payment processor.
In accordance with ISO 27001:2022 standards, we implement comprehensive information security management systems including:
- Risk assessment and management processes
- Security policies and procedures
- Physical and environmental security measures
- Access controls and authentication mechanisms
- Network and communications security
- System acquisition, development, and maintenance security
- Incident management procedures
- Business continuity management
- Compliance with legal and regulatory requirements
Additionally, we implement technical and organizational measures required by HIPAA to protect personal health information, including:
- Encryption of data at rest and in transit
- Regular security assessments and audits
- Staff training on data protection practices
- Data breach notification procedures
- Data Protection Impact Assessments where required
- Appointment of data protection officers where required
7. Data Retention
We will retain your Personal Information for as long as is necessary to provide you with Services, to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. We will also retain certain Personal Information for internal analysis purposes. This information is generally retained for a shorter period but may be retained for longer periods of time when this data, for example, is used to strengthen the security or to improve the functionality of our Services, or we are legally obligated to retain this data for longer time periods. Our determination of precise retention periods will be based on (i) the length of time we have an ongoing relationship with you; (ii) whether there is a legal obligation to which we are subject; and (iii) whether retention is advisable in light of our legal position, including regard to applicable statutes of limitations, litigation or regulatory investigations.
8. International Transfers of Your Personal Information
Your information, including Personal Information, may be transferred to – and maintained on – information systems located outside of your country, province, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside of Saudi Arabia and choose to provide information to us, please note that we transfer the data, including Personal Information, to Saudi Arabia and process it there.
We ensure that international transfers of data comply with applicable laws including:
- Ensuring compliance with Saudi data protection laws for data processed within Saudi Arabia
- Implementing data transfer agreements with appropriate protections where required
- Ensuring that recipients of data have adequate data protection measures in place
9. Children's Privacy
Atheal's Services are not intended for children under the age of eighteen (18) years and we do not knowingly collect Personal Information from such persons. If you become aware that a child has provided us with Personal Information, please contact us at privacy@atheal.com, with the subject line "Minor Access". If we become aware that we have collected Personal Information from children without verification of parental consent, we take steps to remove that information from our information systems.
10. Your Privacy Rights
You may have certain rights and choices regarding our collection, use, and disclosure of your Personal Information based on applicable laws (such as due to your location or place of residency).
a. Opting out of promotional electronic communications from us
We may use your Personal Information to send you updates regarding existing products and Services, information about new products and Services, upcoming events, surveys, and other announcements and inquiries. Please note that Atheal may send you marketing and advertising messages on behalf of a third party (including subject to a paid arrangement); provided, under such a circumstance, Atheal will not disclose your Personal Information to said third party. If you no longer wish to receive promotional email communications from us, you may opt out via the unsubscribe link included in such emails or communicate your opt-out request using the information below. We will comply with your request as soon as reasonably practicable. Please note that if you opt out of receiving promotional emails from us, we may still send you administrative messages that are required in order to provide you with the Service or for other reasons disclosed in this Policy.
b. Deleting your content or closing your account
You may be able to delete certain content through your account. If you wish to request to close your account, please contact us.
c. Additional rights available under Saudi law
Depending on applicable laws, you may have rights to:
- Access your personal data
- Rectify inaccurate data
- Delete your data
- Restrict or object to processing of your data
- Data portability
- Withdraw consent
- Lodge a complaint with a supervisory authority
Please see the section on Saudi Arabia Privacy Notice for further details on region-specific rights.
d. Mobile location data
You can disable our access to your device's precise geolocation in your mobile device settings.
e. Exercising your privacy rights
Please use the following information to exercise your rights as applicable. Please note that any request you submit to us is subject to an identification and residency verification process as permitted under applicable law, as well as certain other procedural requirements that may vary. Additionally, all requests are subject to certain exceptions under applicable law, which may vary. If you are a visually-impaired customer, a customer who has another disability or a customer who seeks support in other language, you may access your privacy rights by emailing us at privacy@atheal.com.
We do not charge a fee to process or respond to your verifiable consumer request unless its excessive, repetitive, manifestly unfounded, or in accordance with applicable law. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Depending on applicable law, you may be limited in how many verifiable or authenticated consumer request you make within a twelve (12) month period. If we have inadvertently collected information on your minor child, you may exercise the above rights on behalf of your minor child. Additionally, in some jurisdictions, you may designate an authorized agent to submit a request on your behalf, and if so, we may require proof of the agent's authorization by you and/or verification of the agent's own identity. Generally, a rights request must include:
- Sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative, which must include, at a minimum, your first and last name and email address.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to the request.
-
We cannot respond to your request or provide you with Personal Information if we cannot verify or authenticate your identity or authority to make the request and confirm that the Personal Information relates to you. We will only use Personal Information provided in a verifiable or authenticated consumer request to verify your (or your authorized agent's as applicable) identity or authority to make the request.
You are not required to create an account with us to submit a verifiable or authenticated consumer request. However, we do consider requests made through your password protected account sufficiently verified when the request relates to Personal Information associated with that specific account. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please contact privacy@atheal.com. We will respond to your request within thirty (30) days after receipt and we reserve the right to extend the response time by an additional thirty (30) days when reasonably necessary and provided consumer notification of the extension is made within the first thirty (30) days.
How to submit a request. To exercise any of the rights described in this Privacy Policy, please send your request(s) using one of the following methods:
- Emailing us at privacy@atheal.com
- Visiting the contact page at our Site at https://www.atheal.com/contact
- Calling us at +966 53 674 7161.
11. Saudi Arabia Privacy Notice
This Saudi Arabia Privacy Notice applies to any Saudi Arabia residents about whom we collect Personal Information. The provisions contained within this section are intended to provide notices in compliance with the Saudi Data Protection Law (SDPL) and other relevant Saudi laws and regulations.
For the purposes of this Saudi Arabia Privacy Notice, except where a different definition is noted, "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Saudi resident or household. Personal Information does not include Publicly Available Information, information that has been de-identified or aggregated, or other information subject to certain federal and state regulation.
If you are a visually-impaired customer, a customer who has another disability or a customer who seeks support in other language, you may access your privacy rights by emailing us at privacy@atheal.com.
a. Rights under Saudi Data Protection Law
Under the SDPL, Saudi residents have the following rights:
- Right to be informed - You have the right to be informed about the collection and use of your personal data.
- Right of access - You have the right to request a copy of your personal data.
- Right to rectification - You have the right to have inaccurate personal data corrected.
- Right to erasure - You have the right to have your personal data erased in certain circumstances.
- Right to restrict processing - You have the right to request the restriction or suppression of your personal data.
- Right to data portability - You have the right to obtain and reuse your personal data.
- Right to object - You have the right to object to the processing of your personal data in certain circumstances.
- Rights related to automated decision making - You have rights related to automated decision making including profiling.
b. Data Controller
Atheal is the data controller of your personal data. For inquiries about our data protection practices, please contact our Data Protection Officer at dpo@atheal.com.
c. Data Localization
In accordance with Saudi data protection laws, we store your personal data primarily within the Kingdom of Saudi Arabia. Any transfer of data outside of Saudi Arabia is conducted in compliance with the requirements of the SDPL and with appropriate safeguards in place.
d. Data Breach Notification
In the event of a data breach that might compromise your personal data, we will notify you in accordance with the requirements of the SDPL without undue delay.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page or other appropriate means. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). We recommend reviewing this Privacy Policy periodically for any changes. Your use of the Service after the effective date of any modified Privacy Policy indicates your acknowledging that the modified Privacy Policy applies to your interactions with the Service and our business.
13. Contact Us
Please contact privacy@atheal.com if you have any questions about this Privacy Policy. We are open to feedback around our privacy policies and practices. Because email communications are not always secure, please do not include any sensitive information in your email to us.
Your Essential Questions Answered
membership include