Who we are and what this policy covers
Hajjiri Heart is the patient app of the cardiology practice of Dr. Mohammad Al-Hajjiri (Amman, Jordan). Dr. Al-Hajjiri is the data controller for everything described here, under Jordan's Personal Data Protection Law No. 24 of 2023; the app is operated for his practice by his company, Al Qalb Al Mutanaghim for Computer Programming L.L.C., acting as data processor on his documented instructions. Wherever this policy says "the clinic", it means his practice and this arrangement. This one policy covers the patient app on iOS and Android, the clinic console used by your care team, and the clinic's public patient web pages, including account deletion. Accounts are opened only with a code issued by the clinic to its own patients; there is no public sign-up. The app is a record and communication companion for your care: it does not provide medical diagnosis, treatment, or emergency triage, and in an emergency you should call 911. Where a feature described here has not yet been switched on, the section says so, and the disclosure applies from the moment it appears in your app.
What we collect
To care for you safely, the clinic keeps the following, grouped so you can see the whole picture:
- Identity and contact: your name, date of birth, sex, preferred language, phone number, the email or phone you sign in with, your insurance and occupation as recorded by the clinic, and the clinic chart number. We do not collect your national ID or passport number; if that ever changes, this policy's version will change first and you will be asked to agree again.
- Emergency contacts: the names and phone numbers of two people you choose. You type them yourself; the app never reads your phone's contact list.
- Your health record: conditions and diagnoses, clinical summaries, lab and test results with their documents, medications, visit notes, clinic-issued letters and prescriptions (which can include a diagnosis), appointments (times, reason, outcome), follow-up plans, and your record timeline.
- Messages and media: your secure chat with the care team, including the urgency you mark, the photos and PDF documents you send, the voice notes your care team sends you (the app can play voice notes but cannot record audio), and any drawings or written labels you or your care team add on photos; each addition records who made it.
- The N-AI assistant: your questions and its answers, kept as your own conversation history, plus the clinic's tamper-evident safety log of each conversation.
- Reminders and notifications: your medication reminder schedules, your dose history (taken or skipped), and your in-app notifications inbox.
- Security and account records: your sign-in sessions (including network address and device browser information), one-time verification codes, the consents you have given with their exact text, date and version, and a tamper-evident log of activity on your account, including every time a member of staff opens your record.
- One usage number, nothing more: when an education article is opened, an unattributed counter for that article goes up. It is not linked to you, and there is no other usage tracking of any kind.
What we do not collect: your location, your phone's contact list, advertising identifiers, or your biometrics (Face ID and fingerprint stay entirely on your device and are never seen by the clinic). The app contains no analytics, tracking, or advertising software. Required versus optional: your identity and contact details, your emergency contacts, your health record, your messages, and the security records are all needed to run the app for you, resting on your activation consent and the provision of your care; optional, and there only if you choose them, are the N-AI assistant and its history (its own separate consent), the reminder schedules you create, and the on-device biometric lock. One more honest note: when someone books an appointment by phone before becoming a patient, the clinic keeps their name, number and appointment note until that booking is completed or cancelled.
Why we collect it, and our legal bases
We use your data for one purpose: delivering your cardiac care. It lets your doctor see your full picture, follow your results over time, reach you, and keep you safe. Under Jordan's Personal Data Protection Law we rely on: your explicit consent, given at activation and withdrawable at any time; the provision of your healthcare; the clinic's legal obligations, such as keeping medical records; protecting your vital interests, such as the in-app emergency guidance; and keeping the service secure. No decision about your care is ever made automatically: every clinical decision is made by your doctor, and AI features in this app explain and draft but never decide.
What we never do
We never sell your data. We never use your data for advertising, marketing, or data mining. We never share it with anyone except the processors named in this policy, each bound to act only on the clinic's instructions. No advertising or analytics companies are inside this app. Your record exists to care for you, and nothing else.
N-AI, the assistant
N-AI explains your own results, medications and appointments in plain language. It works only if you switch it on with its own separate consent, and you can withdraw that consent at any time from the More tab without affecting anything else. When you ask a question, your question and the relevant parts of your record are processed by Microsoft's Azure OpenAI service in Sweden, inside the European Union. The identity fields of your record (name, chart number, phone number, date of birth, national ID, address) are never sent, we additionally filter your name, chart number, phone number and date of birth out of clinic-written text before it is sent, and your age is sent only as an age range. Microsoft acts only on the clinic's instructions and never uses your data to train AI models. To detect misuse, Microsoft's safety systems may keep content they flag for up to 30 days under strict access controls, with any review located inside the European Economic Area. The clinic keeps its own tamper-evident safety log of each conversation, which is its record of what the assistant said; your visible conversation history is erased the moment you withdraw the N-AI consent or delete your account, while the safety log is retained. N-AI gives general explanations, not medical advice; it cannot diagnose or change your treatment, it has a daily question limit, and urgent-sounding messages are answered with emergency guidance instead of an AI reply. Always consult Dr. Al-Hajjiri before any medical decision.
AI reading of lab reports
When you or the clinic upload a lab report, clinic staff can ask the app to read the report and propose result entries, so your results reach your record faster and with fewer typing mistakes. The report file is sent, as printed, to the same Microsoft Azure OpenAI service in Sweden; because it is the lab's own document, it may carry your name or other details the lab printed on it. Microsoft processes it only to extract the values, on the clinic's instructions, under the same no-training commitment and the same misuse-detection terms as the assistant. Nothing is saved automatically: a member of your care team reviews every extracted value before it becomes part of your record.
SMS codes and password safety
Sign-in verification codes are delivered by SMS to the phone number the clinic holds for you. Our SMS delivery provider receives your phone number and the code, and nothing else about you. Separately, when you choose or change your password, the app checks it against known breached passwords using a privacy-preserving method: only a five-character fragment of a cryptographic fingerprint leaves our systems, never your password and never anything that identifies you.
Where your data lives
Your data is stored and processed in the European Union by providers bound to the clinic with data-processing agreements: the clinic's database runs on Microsoft Azure in Sweden, its app services are pinned to Frankfurt, Germany, and the files you and the clinic upload live on the same EU-hosted systems. Your care team accesses it from the clinic in Jordan. These EU providers work under Europe's strict data-protection regime: Microsoft is directly subject to the EU General Data Protection Regulation (GDPR) for the processing at its EU establishments and keeps the data inside the EU Data Boundary, and Vercel is contractually committed to GDPR-standard processor terms, including the EU's 2021 standard contractual clauses. Before this storage began, the controller verified and documented in writing, as Article 15(b) of Jordan's law requires, that the protection these providers give is not lower than what Jordanian law prescribes. Jordanian law allows this kind of cross-border storage with your explicit consent, which you give during activation and can withdraw at any time. The one exception to the EU picture is SMS delivery: Twilio, a United States provider, receives your phone number and the verification code only, under the safeguards listed in the next section. Wherever your data is, it is encrypted on the way and where it rests.
Who handles your data
Your care team at the clinic handles your data, each member within their role. To run the app, the clinic relies on a small set of service providers, each acting only on the clinic's instructions, never for their own purposes, and each bound by a data-processing agreement to protect your data to the same standard as this policy:
- Microsoft (Azure, Sweden, EU): the clinic's database, and the Azure OpenAI service behind N-AI and lab-report reading
- Vercel (Frankfurt, EU): hosts the clinic's secure console and the app's services
- Twilio (United States): delivers your SMS verification codes; receives your phone number and the code only, bound by its data-processing addendum incorporating the EU's 2021 standard contractual clauses, and covered by the controller's written Article 15(b) verification
- Have I Been Pwned: the breached-password safety check; receives a five-character fingerprint fragment, nothing identifying
- RxLabelGuard: medication safety information for the clinic's console, checked by medicine name only; it never receives your identity (switches on when the clinic subscribes)
If this list ever changes, we update this policy, raise its version, and ask for your consent again before the change applies to you.
Your rights, and exactly where to use them
Under Jordan's Personal Data Protection Law, these choices are always yours, and each lives in the app:
- See your record: it is the app itself, and everything in it
- Take a copy: More, then Download my record
- Correct anything wrong: More, then Request a record correction; a person at the clinic reviews and applies it
- Withdraw your consent at any time, without penalty: More, then Withdraw consent opens the withdrawal form, where you choose exactly which purposes to withdraw, all of them, or another purpose in your own words; withdrawing either core purpose stops the app entirely, your record stays with the clinic as the law requires, and to erase the rest you request deletion. A delegate can also submit the withdrawal for you at the clinic
- Withdraw the N-AI consent alone: More, then Withdraw N-AI consent (only the assistant stops)
- Object to, or ask to limit, processing you are not comfortable with: contact the clinic
- Take your data with you: the record copy above is yours to keep and share
- Request deletion of your account and personal data: More, then Delete my account, or via the clinic's account-deletion page, which explains how to request it without the app
- Be told without undue delay if your data is ever put at risk
- Complain to the Personal Data Protection Unit at Jordan's Ministry of Digital Economy and Entrepreneurship; we would also ask you to tell the clinic first so we can put it right
The clinic answers rights requests within 15 working days, free of charge, as Jordan's Regulation No. 68 of 2025 requires (extendable once, with reasons). The Personal Data Protection Unit can be reached directly: phone +962 6 580 5700, email PDP@modee.gov.jo, at the Ministry of Digital Economy and Entrepreneurship, 8th Circle, Bayader Wadi Al-Seer, P.O. Box 9903, Amman 11191. Complaining, to the clinic or to the Unit, never has any negative consequence for you or your care, and the law backs these rights with real administrative fines and penalties for those who violate them.
How long we keep it
Different data lives for different times, and here is the honest picture:
- Your medical record (results and their documents, medications, notes, letters, prescriptions, appointments, and your chat with the care team including its photos, documents and voice notes, which Jordanian health regulation treats as part of the record): kept for at least ten years after your last visit, as the law requires
- Your N-AI conversation history: until you withdraw the N-AI consent or delete your account, when it is erased; the clinic's tamper-evident safety log of assistant conversations is retained as the clinic's evidence of what the assistant said, for the same period as the medical record
- Reminder schedules, dose history, and your notifications inbox: until your deletion request is processed, then erased
- Consent records (the exact text you agreed to, with date and version, and any withdrawal you submit): kept for as long as the clinic may need to prove your consent and its withdrawal were handled lawfully, which is the medical-record retention period plus the legal limitation periods, then erased
- Security records: your sign-in sessions and one-time-code records are erased when a deletion request is fulfilled; the account activity log is append-only by design and is retained for the same period as the medical record, because it is the clinic's legal evidence of exactly what its systems and staff did
- Deletion requests: when you request deletion, the request is processed within 15 working days, and the clinic confirms to you in writing exactly what was erased and what the law required it to keep, and why
Deleting your account
You can request deletion from inside the app (More, then Delete my account, confirmed with a code to your phone) or, if you no longer have the app, via the clinic's public account-deletion page, which explains how to request it without the app. Your N-AI conversation history is erased the moment you confirm the request in the app, or at the latest when the deletion completes. The clinic then processes the request within 15 working days: your sign-in is closed; your reminders, dose history, notifications, emergency contacts, and any upcoming bookings are erased or cancelled; and everything the law does not require the clinic to keep is erased or anonymized. Jordanian health regulation requires the clinic to keep the medical record itself for at least ten years, so deletion cannot erase the clinical record before that time: instead the record is blocked, out of everyday use, for its legal retention. You receive written confirmation of exactly what was removed and what had to remain. Until the request is processed you can cancel it at any time, from the same screen or by telling the clinic, and you can equally start a deletion request by phoning the clinic, without the app.
Children
This app is for adults only. The clinic's system refuses to register a patient younger than 18 and cannot issue an activation code for one, so no child can have an account. Dr. Al-Hajjiri still treats patients under 18 normally at the clinic, just without the app. The app is not directed at children and has no public sign-up, and we never use any patient's data for marketing or profiling.
How we protect it
Security is designed into the app, not added on top. In plain language, this is what protects your record:
- Encryption everywhere: your data is encrypted on its way to our systems and where it is stored; staff sign-in secrets carry their own extra layer of field-level encryption, and your ID document, if ever recorded, is stored the same way
- Your password is never stored: only a modern one-way protection of it (Argon2id with an additional server secret); the clinic cannot see your password, and new passwords are checked against known data breaches privately
- Strong sign-in on both sides: your account uses a long passphrase and SMS codes for sensitive steps; every member of clinic staff signs in with their own account and a second factor (an authenticator code), every time
- Least privilege: staff see only what their role allows, and the system is built so a patient session can only ever reach that patient's own data
- Everything clinic-side leaves a trace: every staff access to your record, including simply opening it, lands in an append-only, tamper-evident audit log that the clinic can verify
- Short sessions: the app signs you out after an hour of inactivity and re-verifies you regularly; withdrawing consent or resetting your password signs you out everywhere at once
- An optional Face ID or fingerprint lock for the app on your phone, which stays entirely on your device
- Abuse protection: sign-in attempts, code requests, and traffic in general are rate-limited and monitored for automated attacks
- Engineering discipline: security checks run on every code change, including tests that try to reach one patient's data from another's account, scans for leaked secrets, and dependency-vulnerability audits; the clinic's secrets are kept outside the code in managed, access-controlled configuration, and scanners block any secret from ever entering the code
- Your part: keep your phone and passphrase safe, and tell the clinic immediately if you think someone else has used your account
Everyone who handles your data, Dr. Al-Hajjiri, his staff, and Al Qalb Al Mutanaghim for Computer Programming L.L.C., is bound by confidentiality without time limit. In the unlikely event of a breach that could seriously affect you, the clinic notifies you within 24 hours of learning of it (by SMS and in the app) and the Personal Data Protection Unit within 72 hours, as Article 20 of the law requires.
Cookies
The patient app uses no cookies at all. The clinic console and the clinic's public patient web pages use exactly one strictly-necessary cookie: the sign-in session cookie that keeps a signed-in staff member signed in, which expires with the session and identifies nobody else. Your language choice on the web pages is remembered inside your own browser's storage and never leaves your device. There are no advertising, analytics, or third-party cookies anywhere, so there is nothing to track and nothing to opt out of.
Changes to this policy
If we change what we collect, who processes it, or where it lives, we update this page, raise the version number at the top, and ask for your consent again in the app before the change applies to you. The version and date at the top are always the ones that bind us.
Contact
For anything about your data, or to use any of your rights, contact the clinic: from the More tab in the app, on the Health Line +962 7 9311 1123, by email at support@hajjiriheart.app, or at the clinic in Amman. Requests are answered within 15 working days, free of charge.
Held under Jordan's Personal Data Protection Law, No. 24 of 2023. Dr. Mohammad Al-Hajjiri is the data controller; Al Qalb Al Mutanaghim for Computer Programming L.L.C. operates the app as data processor. Policy version 4.1, effective 24 August 2026.
