Privacy and Personal Data Protection Policy
Last Updated: 20/07/2026
This Policy explains how White Esnad Medical Services Company collects, uses, processes, stores, and shares personal data when using the White Esnad application or any related services.
By using the Application, creating an account, or requesting any service through it, you acknowledge that you have read and understood this Policy, and you agree to the processing of your data in accordance with this Policy and the applicable laws and regulations in the Kingdom of Saudi Arabia.
- Data Controller
White Esnad Medical Services Company is the data controller of the personal data collected and processed through the White Esnad Application, for the purposes of providing services, managing requests, communicating with users, processing payments, fulfilling regulatory requirements, and improving the user experience.
Controller Information:
Company Name: White Esnad Medical Services Company
Commercial Registration No.: 1010828302
Unified National Number: 7030945013
VAT Number: 311413779200003
Address: Riyadh, Kingdom of Saudi Arabia
Email: info@esnadmedical.sa
Contact Number: 920012895
- Purpose of this Policy
This Policy aims to clarify the following:
- The types of personal data that may be collected.
- The reasons for collecting and processing data.
- How data is used, stored, and shared.
- How personal and health data is protected.
- The user’s rights in relation to their data.
- How to contact the Company to exercise rights or submit inquiries or complaints.
- Data We May Collect
The Company may collect and process the following data depending on the nature of your use of the Application and the type of service requested.
3.1 Identity and Contact Data
Such as:
- Name.
- Mobile number.
- Email address.
- City and address.
- National ID number, Iqama number, border number, or passport number, when needed.
- Date of birth or age, when needed.
- Nationality, when needed.
- Any other identification data necessary to provide the service, verify the user, or fulfill regulatory requirements.
3.2 Account Data
Such as:
- Login details.
- Verification code.
- Account settings.
- Account status.
- Accountancy history within the Application.
3.3 Beneficiary or Patient Data
If the service request is made on behalf of another person, data relating to the beneficiary or patient may be collected, such as:
- Name.
- Age or date of birth, when needed.
- Gender.
- Relationship between the requester and the beneficiary.
- Contact details of the guardian or legal representative, when needed.
- Any data necessary to perform the requested service.
3.4 Health Data
Some services may require the collection or processing of health data, such as:
- General health condition.
- Medical history.
- Medications used.
- Allergies.
- Chronic or infectious diseases.
- Medical reports or attachments.
- Medical or nursing notes.
- Physician instructions or treatment plans when provided by the customer.
- Any health data necessary to assess, provide, or document the service.
Health data is treated as sensitive data and is handled confidentially and only to the extent necessary to provide the service or fulfill regulatory or operational obligations.
3.5 Location and Address Data
Address or geographical location data may be collected when needed to:
- Determine the place where the service will be provided.
- Direct the team to the customer’s location.
- Improve visit scheduling.
- Verify the service location.
- Facilitate communication and operational coordination.
The user can manage location permissions through the device settings. Disabling location access may affect some Application features or the accuracy of service delivery.
3.6 Payment and Billing Data
When electronic payment is used, data related to the payment transaction may be processed, such as:
- Transaction amount.
- Payment status.
- Transaction number.
- Payment method.
- Transaction date.
- Invoice or receipt.
Payment data is processed through approved payment service providers. The Company does not normally retain full bank card details unless permitted by law and in accordance with approved protection standards.
3.7 Usage and Device Data
Technical data may be collected to support and improve the operation of the Application, such as:
- Device type.
- Operating system.
- Internet Protocol address.
- Login records.
- Technical error and crash data.
- Application usage patterns.
- Notifications and interactions within the Application.
3.8 Support and Complaint Data
When contacting the Company, we may collect data related to inquiries or complaints, such as:
- Content of the request or complaint.
- Data of communication.
- Communication channel.
- Documents, images, or attachments provided by the user.
- Actions taken to handle the request.
3.9 Workforce Data
If the Application is used by the Company’s team or service providers, some workforce-related data may be processed, such as:
- Work account data.
- Tasks and schedules.
- Visit completion status.
- Reports and notes related to the service.
- Location data when needed for operational purposes.
- Login and usage records according to granted permissions.
- Legal Basis for Processing Data
The Company processes personal data based on one or more of the following legal bases, depending on the nature of the data and the purpose of processing:
- User consent.
- Performing the service request or taking steps based on the user’s request.
- Fulfilling contractual obligations.
- Compliance with legal, regulatory, health, or accounting requirements.
- Protecting the vital interests of the beneficiary or patient when needed.
- Pursuing the Company’s legitimate interests, if this does not conflict with the user’s statutory rights and freedoms.
- Purposes of Collecting and Using Data
The Company uses personal data for the following purposes:
- Creating and managing the user account.
- Verifying the user’s identity or contact details.
- Receiving, reviewing, and fulfilling service requests.
- Scheduling appointments and directing the team.
- Providing healthcare, home care, or supportive services.
- Documenting the service and managing related records.
- Communicating with the user regarding requests, appointments, or support.
- Processing payments and issuing invoices.
- Managing complaints and inquiries.
- Improving service quality and user experience.
- Sending important notifications and alerts.
- Protecting the Application and preventing fraud or misuse.
- Complying with laws, regulations, and requests issued by competent authorities.
- Managing internal operations and operational reports.
- Sending awareness, informational, or marketing messages or notifications related to the Company’s services, where applicable and subject to regulatory requirements and obtaining the user’s consent whenever required.
- Sensitive Data
The data processed through the Application may include sensitive data, particularly health data or any other data classified as sensitive under the relevant laws and regulations.
The Company is committed to handling sensitive data with a higher level of care and confidentiality. Sensitive data will not be processed or shared except to the extent necessary to provide the service, fulfill a regulatory obligation, or based on the user’s consent whenever required.
- Sharing Data with Third Parties
The Company may share certain personal data, to the extent necessary and in accordance with applicable laws and regulations, with third parties that assist in providing the services or operating the Application, such as:
- The Company’s team assigned to perform the service.
- Healthcare or operational service providers related to fulfilling the request.
- Electronic payment service providers.
- Hosting and cloud computing service providers.
- Messaging, notification, and communication service providers.
- Maps or location service providers when needed.
- Technical support and application development providers.
- Systems used to manage requests, customers, records, or invoices.
- Governmental, regulatory, or judicial authorities where there is a legal obligation or official request.
The Company does not sell users’ personal or health data.
Data is shared only to the extent necessary to achieve the specified purpose, perform the service, fulfill a legal obligation, or based on the user’s consent whenever required.
- Data Processors and Service Providers
The Company may engage external parties to process data on its behalf, such as providers of hosting, payment, messaging, technical support, analytics, maps, or request management systems.
The Company is committed to taking the necessary measures to ensure that such parties handle data in accordance with confidentiality, protection, and applicable legal requirements, and in a manner appropriate to the nature of the service they provide.
- Payment Data
Payment transactions are processed through approved payment service providers.
The Company may retain data related to the payment transaction, such as the transaction number, payment status, transaction amount, invoice, and payment method, for accounting, customer service, dispute resolution, and regulatory compliance purposes.
The Company does not control all payment processing procedures carried out by the payment provider, and such transactions are also subject to the terms and policies of the payment service provider.
- Geographical Location Data
The Application may use geographical location data or address information to facilitate service delivery and direct the team to the customer’s or beneficiary’s location.
Location data is used only for operational purposes related to the service, such as determining the service location, improving scheduling, or following up on request execution.
The user may disable location sharing through the device settings, noting that this may affect some Application features or the quality-of-service delivery.
- Notifications and Alerts
The Application may send notifications or messages to the user regarding:
- Request confirmations.
- Service status updates.
- Appointment reminders.
- Payments and invoices.
- Support and complaints.
- Important alerts related to the account or service.
- Updates to policies or terms when needed.
- Awareness, informational, or marketing materials related to the Company’s services, in accordance with regulatory requirements and the user’s consent whenever required.
The user may control some notifications through the device settings, while essential notifications related to the service, account, or regulatory obligations may still be sent.
- Data Retention
The Company retains personal data for the period necessary to achieve the purposes for which it was collected, or for the period required by applicable laws, regulations, contracts, and health, accounting, or legal obligations.
After the need for the data ends, the Company deletes, anonymizes, or archives the data in accordance with internal policies and applicable laws and regulations, unless there is a legal or contractual basis for retaining it for a longer period.
- Data Protection
The Company takes appropriate organizational and technical measures to protect personal data against unauthorized access, loss, disclosure, alteration, or misuse.
These measures may include:
- Defining access permissions.
- Using dedicated accounts and permissions.
- Securing systems and applications.
- Monitoring login records when needed.
- Restricting access to health data.
- Training or instructing the team on confidentiality.
- Handling data based on the actual need to perform work.
Despite taking appropriate measures, the user acknowledges that the use of applications and electronic systems may involve ordinary technical risks.
- Data Subject Rights
In accordance with the applicable laws in the Kingdom of Saudi Arabia, the user may have the right to:
- Be informed of the purposes for collecting and processing their data.
- Access their personal data.
- Request correction of inaccurate or incomplete data.
- Request updating their data.
- Request deletion of their data whenever legally possible.
- Withdraw consent where processing is based on consent.
- Object to certain types of processing whenever legally available.
- Submit a complaint regarding the processing of their data.
These rights are exercised in accordance with the procedures determined by the Company and the relevant laws and regulations. The Company may require verification of the requester’s identity before processing certain requests.
- Exercising Rights
The user may exercise their rights relating to personal data by contacting the Company through the official channels stated in this Policy.
The Company may request additional information from the user to verify their identity or legal capacity before fulfilling the request, especially if the request relates to the data of another beneficiary or patient.
The Company reviews and responds to requests within a reasonable period, depending on the nature of the request and the relevant regulatory and operational requirements.
- Account Deletion and Data Deletion Requests
The user may request deletion of their account or data through the feature available within the Application or by contacting the Company through the official channels.
The Company may retain certain data after account deletion if such retention is necessary to comply with laws, regulations, contracts, health, accounting, or legal obligations, or to protect legal rights or handle existing complaints or disputes.
Account deletion does not necessarily cancel any financial or contractual obligations existing before the deletion date.
- Children’s and Minors’ Data
Some services may involve beneficiaries who are children or minors.
In such cases, the request and consent to data processing must be submitted by the parent, guardian, legal representative, or authorized person.
The requester undertakes that they have the legal capacity or authorization required to provide the beneficiary’s data and request the service on their behalf.
- Transfer or Processing of Data Outside the Kingdom
Some data may be processed or stored through technology service providers inside or outside the Kingdom in accordance with applicable laws and regulations.
Personal data will not be transferred or processed outside the Kingdom except as permitted by the relevant laws and regulations and with appropriate safeguards to protect the data.
- External Links and Services
The Application may contain links or integrations with external services, such as payment gateways, maps, notification services, or support services.
The Company does not fully control the privacy policies of such third parties, and users are advised to review their privacy policies when using their services.
- Complaints and Inquiries
The user has the right to submit an inquiry or complaint regarding the processing of their personal data through the Company’s official channels.
The user also has the right to approach the competent authority in accordance with the applicable laws in the Kingdom of Saudi Arabia if the complaint is not handled or responded to in accordance with regulatory requirements.
- Updates to this Privacy Policy
The Company may update this Policy from time to time in line with legal, operational, technical, or service-related changes.
The updated version will be published within the Application or through any appropriate method. Continued use of the Application after publication of the update will be deemed acceptance of the updated Policy, unless applicable laws require separate consent.
- Contact Information
For inquiries or requests relating to privacy and personal data protection, the Company may be contacted through the following details:
White Esnad Medical Services Company
Address: Riyadh, Kingdom of Saudi Arabia
Email: info@esnadmedical.sa
Contact Number: 920012895















