Privacy Policy

    Effective from April 22, 2026

    About This Policy

    DaktariSheba is a product of KiyanSolutions UG, a company registered in Germany. This policy applies to all users of our platform: patients, doctors, and ambulance service providers. It explains what data we collect when you use our platform, why we collect it, and how we keep it safe.

    We do not sell, rent, trade, or otherwise monetise your personal or health data. We do not use health data for advertising or behavioural profiling for marketing purposes.

    Data Controller: KiyanSolutions UG, operator of DaktariSheba. Where required by applicable law, we will designate a Data Protection Officer or EU Representative and publish the contact details accordingly. Until then, all privacy enquiries should be sent to [email protected] (Subject: Privacy Request).

    What We Collect

    Personal details

    • Name, date of birth, gender
    • Phone number and email
    • Profile photo (if you upload one)
    • Address

    Health data (patients)

    • Medical history and health records you share
    • Prescriptions from your consultations
    • Lab results and diagnostic reports
    • Appointment history
    • Vitals (blood pressure, glucose, etc.)
    • Vaccination records (vaccine type, date, dose, and schedule)
    • Medical document images you upload or capture for OCR (for example prescriptions and test reports)
    • Voice recordings you submit for voice-to-text features (for example AI chat and voice prescription)

    Professional data (doctors)

    • BMDC registration number and medical licence details
    • Specialisation, qualifications, and years of experience
    • Clinic or hospital affiliation and chamber schedule
    • Consultation fees and availability

    Professional data (ambulance providers)

    • Vehicle registration and type
    • Service area and real-time location (while on duty, with permission)
    • Provider name and contact details

    Technical data

    • Device type, browser, and operating system
    • IP address and approximate location
    • How you navigate the platform (pages visited, features used)

    Location data

    • Approximate location from IP address for security and analytics
    • Precise device location (with your permission) to help find nearby doctors, clinics, pharmacies, labs, and ambulance providers

    Legal Basis for Processing (GDPR)

    Because DaktariSheba is operated by a German company, we process your data in line with the EU General Data Protection Regulation (GDPR) and applicable Bangladesh laws. Our legal bases are:

    • Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) for processing health data, voice recordings, medical document images, and AI feature inputs. Health data is a special category under GDPR Art. 9 and we only process it with your explicit consent or where another Art. 9 basis applies.
    • Contract (Art. 6(1)(b) GDPR) to provide the services you request, such as booking appointments, storing your prescriptions, and processing payments.
    • Legal obligation (Art. 6(1)(c) GDPR) to comply with Bangladesh healthcare, financial, and tax regulations.
    • Legitimate interests (Art. 6(1)(f) GDPR) for platform security, fraud prevention, and improving the service, where these interests do not override your rights.
    • Vital interests (Art. 6(1)(d) and Art. 9(2)(c) GDPR) in medical emergencies where you cannot give consent.

    You can withdraw consent at any time from the app settings or by emailing [email protected]. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

    AI-Powered Features and Third-Party AI Processing

    AI features on DaktariSheba are optional and require your explicit consent before activation. AI systems are probabilistic, may be trained on historical patterns, and may produce inaccurate, incomplete, misleading, or outdated outputs — including outputs that appear confident. AI outputs are informational and educational only and are not a medical diagnosis, prescription, or substitute for professional medical advice.

    Several features on DaktariSheba use third-party AI services to process your data. Specifically:

    • Lab report scanning, prescription OCR, and document analysis, powered by Google Gemini, operated by Google LLC.
    • AI Health Chat, powered by OpenAI (GPT models), operated by OpenAI, L.L.C.
    • Voice input and voice chat, powered by OpenAI Whisper, operated by OpenAI, L.L.C.

    When you use these features:

    • Health data you submit (symptoms, lab values, medications), medical document images, and voice recordings are transmitted to the relevant AI provider for processing.
    • AI requests are sent in anonymised form. Your name, phone number, email, and address are never included in AI requests.
    • Google and OpenAI each process this data under their own privacy terms as data processors acting on our behalf.
    • AI responses are for general informational purposes only and are not a medical diagnosis or prescription.
    • We do not use your identifiable health data to train AI models. Google and OpenAI do not use API inputs to train their general models under our commercial API agreements. Anonymised, aggregated patterns may be used to improve AI accuracy on our platform.

    You may decline or withdraw consent for AI feature usage at any time from Settings → Privacy → AI. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal and does not affect your ability to book appointments, access records, or use other platform features.

    AI infrastructure region. Backend AI orchestration runs on our EU-hosted infrastructure. When OpenAI or Google Gemini is invoked, the relevant inputs may be processed in the providers' US (or other) regions under Standard Contractual Clauses. Operational logs from AI features (used for debugging and abuse prevention) are retained for up to 30 days, after which they are deleted or anonymised, unless longer retention is required by law.

    International Data Transfers

    DaktariSheba is operated by KiyanSolutions UG in Germany, with infrastructure hosted in the European Union. Some of our service providers are located outside the European Economic Area (EEA):

    • Google LLC (United States) for Gemini OCR processing and Google Maps services.
    • OpenAI, L.L.C. (United States) for GPT and Whisper AI features.
    • Payment gateway partners in Bangladesh and other jurisdictions for processing transactions.
    • SMS, email, and push notification providers for transactional messages.

    For transfers outside the EEA, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission and, where available, supplementary technical and organisational measures such as encryption in transit and at rest. You can request a copy of the safeguards used for a specific transfer by contacting us at [email protected].

    Subprocessors

    We engage carefully selected service providers (“Subprocessors”) who process personal data on our behalf under written data processing agreements that require confidentiality, security safeguards, and compliance with applicable data protection laws. Subprocessors act solely under our instructions and may not use personal data for their own independent purposes.

    SubprocessorPurposeLocation
    OpenAI, L.L.C.AI Health Chat (GPT), voice transcription (Whisper)USA
    Google LLCGemini OCR for documents, Google Maps for nearby servicesUSA / Global
    Amazon Web Services (AWS)Application hosting, database, file storageEU (primary), with limited US redundancy
    Apple Push Notification service (APNs)Push notification delivery on iOSUSA / Global
    Firebase Cloud Messaging (FCM)Push notification delivery on AndroidUSA / Global
    Expo / EAS (Expo Application Services)Over-the-air updates, build pipeline, crash symbolicationUSA
    SMS gateway providersOTP and transactional SMS deliveryBangladesh / Global
    Email service providerTransactional email delivery (verification, receipts, alerts)EU / USA
    Payment gateway partnersProcessing payments and refundsBangladesh / Global

    This list may be updated as our infrastructure evolves. We will reflect any material change here and, where required by law, notify affected users.

    Third-Party SDKs and Analytics

    Our mobile app is built with Expo and React Native. We keep the SDK footprint small and do not embed advertising or behavioural tracking SDKs. The third-party components used in the mobile app are:

    • Expo Notifications for delivering push notifications. This uses Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android to deliver messages. We only send the device push token and the message content. No user profile data is shared with these services.
    • Google Maps (via react-native-maps on mobile and Google Maps JavaScript API on the web) to display clinics, pharmacies, labs, and ambulance locations. Google receives the map tiles request and your approximate viewport, subject to Google's privacy policy.
    • Google Fonts (Inter, Hind Siliguri, Source Serif, Inter Tight) loaded locally through Expo Google Fonts. No requests are made to Google Fonts servers at runtime.
    • Expo application services for over-the-air updates and crash symbolication, if enabled. Crash diagnostics are collected only when the app crashes and do not include your health data.

    We do not use Firebase Analytics, Google Analytics for Firebase, Crashlytics, Sentry, Mixpanel, Amplitude, Meta / Facebook SDK, AppsFlyer, or advertising SDKs inside the mobile app. If we add any of these in the future, we will update this policy and, where required, ask for your consent before they are enabled.

    On the web, we use minimal first-party analytics for page-view counts and error reporting. See our Cookie Policy for details.

    Device Permissions We Request

    • Camera to capture profile photos, prescriptions, certificates, and other medical documents.
    • Microphone to record voice input for voice consultation support, voice prescription, and AI voice chat.
    • Location to show nearby doctors, clinics, labs, pharmacies, and ambulances.
    • Notifications to send appointment reminders, medication reminders, and care alerts.

    You can control permissions any time from your device settings. If a permission is denied, some related features may not work.

    How We Use It

    • Connecting you with the right doctor and booking appointments
    • Managing your prescriptions and health records
    • Sending appointment reminders and health alerts
    • Processing payments
    • Providing customer support
    • Meeting legal and regulatory requirements
    • Improving the platform based on usage patterns

    Who We Share It With

    • Your chosen doctors and clinics, so they can treat you.
    • Service partners: ambulance providers, labs, and pharmacies when needed for your care.
    • Payment processors, to handle transactions securely.
    • Authorities, only when required by law.

    We never sell your personal or health data to advertisers or marketing companies.

    How We Protect Your Data

    Your data is encrypted both in transit and at rest. We use access controls, security audits, and monitoring to prevent unauthorized access. That said, no online system is perfectly secure, so we do our best but cannot guarantee absolute protection.

    How Long We Keep It

    We keep your data while your account is active and as needed to meet legal, medical, accounting, and anti-fraud obligations under applicable Bangladesh laws and regulations. You can request deletion from within the app (Account Deletion) or by contacting us at [email protected]. Once a deletion request is confirmed, we delete or de-identify data that we are not legally required to retain.

    Your Rights

    Under GDPR and applicable Bangladesh laws, you can:

    • Access the personal data we hold about you.
    • Correct inaccurate information.
    • Delete your account and personal data directly from the app or the Account Deletion page.
    • Ask us to delete your data through [email protected].
    • Withdraw consent for data processing.
    • Download your health records (data portability).
    • Restrict or object to specific kinds of processing.
    • Opt out of marketing messages.
    • Lodge a complaint with your local data protection authority. In the EU, this is the supervisory authority of your country of residence. In Germany, this is your state data protection authority.

    Account Deletion

    You can permanently delete your DaktariSheba account and all associated data in two ways:

    From inside the app

    1. Open the DaktariSheba app.
    2. Go to Settings.
    3. Tap Account.
    4. Tap Delete My Account.
    5. Confirm the deletion when prompted.

    From the web (no app install required)

    Visit our dedicated Account Deletion page for instructions on how to request deletion by email. You can also email [email protected] from your registered email address or phone number.

    What gets deleted: Your profile, personal details, health records, appointment history, and all associated data are permanently deleted. Anonymised, aggregated data that cannot identify you may be retained for platform analytics.

    Retention period: Deletion is processed within 30 days. Certain data may be retained longer if required by Bangladesh law (for example, financial transaction records kept for up to 7 years).

    Children and Minimum Age

    The Services are intended for users aged 16 and above. We do not knowingly allow children under 16 to create their own DaktariSheba account or to provide personal data directly to us. Where required by applicable law, users between 16 and 18 may need parental or legal-guardian consent.

    Health records for children under 16 may be managed by a parent or legal guardian through our Family Health Hub, using the guardian's own DaktariSheba account. In that case the guardian is responsible for the lawful basis to upload and manage the child's data.

    If we become aware that an account has been created by a person under 16 without the required consent, we may suspend the account and delete associated data in accordance with applicable law.

    Updates to This Policy

    If we make meaningful changes, we will let you know through the platform or by email. Continued use after an update means you accept the revised policy.

    Contact

    Data Controller: KiyanSolutions UG (Germany), operator of DaktariSheba.

    For anything privacy-related:
    Email: [email protected]
    Phone: +880 1673-639809
    Address: 56 Inner Circular (VIP) Road, Eastern Trade Center (3rd Floor), Room 07-10, Nayapaltan, Dhaka-1000