Legal
Privacy Policy
Effective Date: August 1, 2026 · Last Updated: August 1, 2026
1. Introduction & Overview
Welcome to Yosor ("Yosor," "we," "us," or "our"). Yosor operates an online reservation and scheduling ecosystem connecting individual end-users ("Clients," "Patients," or "Users") with third-party service providers, including physiotherapy centers, medical clinics, wellness spas, and beauty salons ("Service Providers") across the Middle East region (including the Kingdom of Saudi Arabia and Jordan).
This Privacy Policy explains how Yosor collects, processes, stores, discloses, and protects your personal data when you visit our website, use our mobile application, or book services through our platform. By accessing or using Yosor, you acknowledge that you have read and understood the data practices described herein.
2. Regulatory Compliance & Regional Legal Framework
Yosor is committed to adhering to all applicable data protection laws and health data regulations across the jurisdictions in which we operate, including but not limited to:
- Kingdom of Saudi Arabia (KSA): The Personal Data Protection Law (PDPL) promulgated by Royal Decree No. (M/19) and implemented by the Saudi Data and Artificial Intelligence Authority (SDAIA), alongside Ministry of Health (MOH) telehealth and patient record standards.
3. Information We Collect
We collect data directly from you, automatically through your interactions with our platform, and from third-party partners (such as designated clinics or salons).
3.1 Personal & Account Information
- Full name, national ID or residency number (where legally required for healthcare verification), gender, date of birth, and language preferences.
- Contact details: Mobile phone number, email address, physical/delivery address, and emergency contact details.
- Account credentials: Username, encrypted passwords, and authentication PINs.
3.2 Sensitive Health & Clinical Data (For Physiotherapy & Clinic Bookings)
When scheduling appointments with licensed physiotherapy centers or medical clinics, you may provide sensitive data required for proper consultation and triage:
- Brief medical history, symptoms, referral documents, or physical therapy notes submitted prior to or during booking.
- Health insurance coverage details, policy numbers, and pre-authorization documents.
3.3 Booking & Transaction Information
- Appointment history: Selected facility, practitioner/stylist, date, time, service category (e.g., hair styling, hydrotherapy, post-injury rehab, facial treatment).
- Payment data: Billing address, transaction reference numbers, payment method details (tokenized credit/debit card numbers, Apple Pay, Mada, Benefit, STC Pay, or cash-on-arrival records). Note: Full payment card details are processed securely by PCI-DSS compliant third-party gateways and are never stored on Yosor servers.
3.4 Technical & Location Data
- Device IP address, operating system, browser type, unique device identifiers (UDID), and mobile network information.
- Precise or approximate geolocation data (with explicit consent) to display nearby clinics, spas, and salons.
4. Purpose and Legal Basis for Processing
| Processing Purpose | Categories of Data | Legal Basis (PDPL & Regional Regulations) |
|---|---|---|
| Account creation & identity verification | Account Info, Contact Details | Performance of Contract |
| Facilitating appointments with Clinics/Physiotherapy | Account Info, Health & Medical Notes, Insurance | Explicit Consent & Healthcare Provision |
| Facilitating bookings with Spas & Salons | Account Info, Service Preferences, Schedule | Performance of Contract |
| Processing payments & invoicing | Transaction Details, Billing Data | Performance of Contract & Financial Legal Obligation |
| SMS/Push notifications for reminders & updates | Mobile Number, Device ID, Booking Logs | Legitimate Interest & Consent |
| Platform security, fraud prevention & audit | Technical Data, IP Logs, Access Records | Legal Obligation & Legitimate Interest |
5. Sharing & Disclosure of Information
Yosor does not sell or rent your personal information to third parties. We disclose data strictly on a need-to-know basis under the following circumstances:
- Third-Party Service Providers: The specific physiotherapy center, clinic, spa, or salon with whom you book an appointment receives your name, contact number, appointment notes, and relevant preferences to render the service.
- Payment Processing Partners: Authorized payment gateways (e.g., Mada, Visa, Mastercard, Apple Pay, local GCC payment switches) process financial transactions securely.
- Technical Sub-processors: Trusted cloud infrastructure hosting providers, SMS aggregators, and customer support portal vendors operating under strict data processing agreements (DPAs).
- Regulatory & Legal Authorities: Government bodies, Ministries of Health, law enforcement agencies, or data protection regulators when mandated by statutory laws or court orders within GCC jurisdictions.
6. Cross-Border Transfers & Local Data Residency
In compliance with Saudi Arabia's PDPL data residency requirements and UAE Health Data Law provisions, sensitive health data and personal data of residents are primarily stored on local cloud infrastructure located within the respective sovereign borders (e.g., local KSA cloud zones for Saudi users).
Where international data transfers are strictly necessary for platform operation or sub-processor maintenance, Yosor ensures that adequate safeguard measures — such as Standard Contractual Clauses approved by relevant data protection authorities — are in place.
7. Data Retention & Security Measures
7.1 Data Security Controls
Yosor enforces robust administrative, physical, and technical security safeguards, including:
- End-to-end data encryption in transit using TLS 1.3 and at rest using AES-256 encryption.
- Strict Role-Based Access Control (RBAC) ensuring staff and providers access data strictly required for service delivery.
- Regular vulnerability scans, penetration testing, and annual security audits.
7.2 Retention Period
We retain personal information for as long as your account remains active or as needed to provide services. Medical and appointment logs are retained in compliance with regional healthcare record retention statutes (typically 5 to 10 years depending on local health ministry regulations).
8. Data Subject Rights
Under applicable regional privacy laws (including Saudi PDPL and UAE PDPL), users retain the following rights regarding their personal data:
- Right to Information / Access: Request copy of personal data held by Yosor and details on processing activities.
- Right to Rectification: Request correction of inaccurate, incomplete, or out-of-date information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of personal data when processing is no longer necessary or upon consent withdrawal, subject to legal retention overrides.
- Right to Withdraw Consent: Revoke consent previously given for promotional marketing or optional data sharing at any time.
- Right to Object / Restrict Processing: Limit processing in specific circumstances outlined by applicable laws.
To exercise any of these rights, please contact our Data Protection Officer at privacy@yosor.app.
9. Cookies & Tracking Technologies
Yosor utilizes essential cookies for session management and user authentication, operational cookies for language preferences, and performance analytics cookies (such as Google Analytics) to improve user experience. You can manage cookie preferences through your web browser settings.
10. Policy Amendments & Contact Us
We may update this Privacy Policy from time to time to reflect regulatory changes or platform updates. Material updates will be communicated via mobile app notifications or email prior to taking effect.
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact our privacy compliance team at:
Yosor Data Protection Office
Email: privacy@yosor.net
Support Desk: support@yosor.net
Middle East Operations Center: Riyadh, Kingdom of Saudi Arabia / Amman, Jordan