Back to Home

Privacy

Privacy Notice

Last updated: 10 September 2026

1. Who we are

Ruh Almasar Company for Information Technology ("Ruh", "we", "us"), located in Riyadh, Kingdom of Saudi Arabia, acts as the data controller responsible for your personal data.

If you have any questions, you can reach our data privacy team at: dpo@ruh.sa

Website: https://ruh.sa

2. What this notice covers

This notice explains how we collect, use, store, share, and protect personal data when you use Ruh's websites, mobile apps, wellness tools, telemedicine services, and related features (the "Services").

We process personal data in line with the Saudi Personal Data Protection Law (PDPL) and applicable requirements of SDAIA, NDMO, and NCA.

3. The data we collect

Depending on how you use Ruh, we may collect:

  • Identity and contact data ? name, email, phone number, age/gender, region/city, and national ID if provided for verification
  • Account data ? login details, verification status, OTPs, device tokens, and security logs
  • Wellness and usage data ? mood scores, journals, tasks, content activity, and AI companion chat
  • Telemedicine and health data ? appointments, session details, consents, clinical notes, prescriptions, files/chat, surveys, and referrals
  • Payment data ? invoice details, amounts, credits, payment status, and limited gateway information
  • Technical data ? IP address (where needed for security/consent records), device information, and basic diagnostics
  • Support communications ? messages you send to support or through contact forms

4. Sensitive data

Some information we process is sensitive under PDPL, especially health and mental-health data, clinical records, and identity verification data.

We process sensitive data only where allowed by law ? typically with your explicit consent and/or as needed to provide healthcare or telemedicine services you request.

5. How we collect your data

We collect data:

  • Directly from you (registration, profile, chats, surveys, bookings, uploads, consents)
  • From your use of the Services (logs, device tokens, essential analytics)
  • From practitioners on the platform (clinical documentation during care)
  • From payment and identity-verification providers you use
  • From your employer/organization, if you access Ruh through a company plan

6. How we use your data

We use your data to:

  • Provide and manage your account and the Services
  • Deliver wellness features and AI companion support
  • Schedule and provide telemedicine care and clinical documentation
  • Process payments, credits, and prevent fraud
  • Send service messages (OTP, bookings, security alerts)
  • Send marketing only if you opt in
  • Improve safety, quality, and performance
  • Meet legal, regulatory, and professional obligations
  • Handle support requests and data-subject rights

AI features may generate responses or summaries to support your experience. They do not replace licensed clinical judgment for telemedicine care.

7. Legal basis for processing

We process personal data under PDPL on one or more of these bases:

  • Consent (including explicit consent for sensitive data and optional marketing)
  • Providing the Services you request (including telemedicine and payments)
  • Legal or professional obligations
  • Legitimate interests, such as security, fraud prevention, and service improvement, balanced with your rights

You may withdraw consent where processing is based on consent. Withdrawing mandatory service consents may require account deactivation.

8. Cookies and tracking technologies

We may use cookies and similar technologies on web surfaces to keep you signed in, remember preferences, support security/payments, and measure basic performance.

You can manage cookies in your browser settings. Some features may not work if cookies are blocked.

In the mobile app, we may use device identifiers for push notifications and essential diagnostics. You can control push notifications in your device settings.

9. Sharing your data

We share personal data only when needed with:

  • Licensed practitioners involved in your care
  • Service providers who help us operate Ruh (such as hosting, messaging, payments, and video sessions), under appropriate contracts
  • Your organization, if you use an employer-sponsored plan and sharing is required to administer it
  • Advisers or auditors under confidentiality
  • Authorities when required by Saudi law

We do not share your data with third parties for their own marketing.

10. International transfers

Ruh's primary production systems are designed to store and process personal data in the Kingdom of Saudi Arabia.

If a transfer outside Saudi Arabia is required, we will do so only as permitted under PDPL.

11. Third-party links

The Services may link to third-party websites or payment pages. Their privacy practices are their own. Please review their notices before sharing data with them.

12. Data retention

We keep personal data only as long as needed for the purposes in this notice, then delete or anonymize it, unless the law requires longer retention.

  • Account and wellness data ? kept while your account is active; anonymized or removed when you request erasure, where allowed
  • Telemedicine / clinical records ? retained for about 10 years from the last clinical encounter, in line with applicable health requirements
  • Payment records ? retained as required by commercial and tax rules
  • OTP and temporary data ? kept only for short periods
  • Marketing preferences ? kept until you withdraw consent or your account is closed/anonymized

If you request erasure, we anonymize identifiers and remove unnecessary free text where possible. Clinical, payment, and certain audit records may still be retained for legal reasons.

13. Marketing communications

We send marketing only with your consent. You can withdraw anytime in Privacy Settings, via unsubscribe links, or by emailing dpo@ruh.sa.

Service messages (such as OTP, bookings, and security alerts) are not marketing and may continue as needed.

14. Children's privacy

Ruh is intended for users aged 18 or older, unless a parent or legal guardian manages access where we expressly allow it.

If you believe a child has provided personal data inappropriately, contact dpo@ruh.sa.

15. Your legal rights

Under PDPL, you may have the right to:

  • Be informed about how we use your data
  • Access your data
  • Request correction
  • Request destruction or anonymization, subject to legal and clinical retention
  • Withdraw consent where applicable

How to exercise your rights in the app

Go to Profile ? Your data & rights (or Privacy / Data settings). There you can:

  • Preview what data we hold and what would be anonymized or retained
  • Submit an anonymization / erasure request
  • Track your requests

You can also update marketing consent in Privacy Settings, or deactivate your account.

Privacy contact

For privacy requests or questions: dpo@ruh.sa

We may need to verify your identity before fulfilling a request.

16. Security measures and breach handling

We use appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, authentication, audit logging for sensitive actions, and vendor controls.

No system is completely secure. Please keep your login details confidential.

If a personal data breach occurs that requires notification under PDPL, we will take required steps, including notifying the competent authority and affected individuals when legally required. If you suspect unauthorized access to your account, contact dpo@ruh.sa.

17. Updates to this notice

We may update this notice from time to time. The "Last updated" date above will change when we do.

Where required, we will notify you of material changes in-app, by email, or through an updated acceptance step.