د

Effective 2 July 2026

Privacy Policy

This Privacy Policy explains what personal information Dawa ("we", "us", "our") collects when you use the Dawa mobile application and the website at https://mydawa.app (together, the "Service"), how we use it, and the rights you have over your information. This policy applies to patients, doctors and clinic reception users of the Service.

1. Who we are

The data controller is DAWA BOOKING, based in Sulaymaniyah, Kurdistan Region, Iraq. You can reach us at support@dawa.iq for any privacy question or to exercise your rights described below.

Dawa is a booking-only marketplace. We do NOT collect, host or process medical records, prescriptions, diagnoses or clinical notes.

2. Information we collect

Account details you provide: mobile phone number, name, date of birth, gender, and (optionally) a profile photo you upload.

Family-member details: if you book on behalf of a family member, you provide their name, relationship to you, age and gender.

Booking details: the doctor, clinic, date and time of every appointment you create, plus the free-text "reason for visit" you type when booking. Please do not enter sensitive clinical information in this field — it is only meant as a short note (e.g. "toothache", "annual check-up").

City + approximate location: when you allow location access, we read your device's GPS coordinates ONCE per session to identify the nearest supported city (Erbil, Sulaymaniyah, Duhok, etc.) so we can show doctors in your area. We do not track your continuous location. If you deny permission the app works fully with a manual city selector.

Device + technical data: your language, theme, and non-identifying diagnostic logs (e.g. HTTP status codes, error timestamps) needed to keep the Service running.

Authentication data: one-time SMS codes and, if you set one, a hashed password. We never store your password in plain text — we use industry-standard bcrypt hashing.

3. How we use your information

We use your information only for the purposes below, on the following legal bases under GDPR Article 6:

• To create and authenticate your account (contract, Art. 6(1)(b)). • To let you book, cancel and manage appointments with doctors (contract). • To let doctors and their reception staff see who booked and contact you if the appointment needs rescheduling (contract + legitimate interest, Art. 6(1)(f)). • To detect and prevent abuse, spam, brute-force attacks, and fraud (legitimate interest). • To improve the Service — aggregated, non-identifying analytics only (legitimate interest). • To communicate essential service messages by SMS or in-app notification, e.g. OTP codes, booking confirmations (contract + legitimate interest). • To comply with a legal obligation when we receive a lawful request from a competent authority (legal obligation, Art. 6(1)(c)).

We do not use your data for advertising and we do not sell it to anyone.

4. Who we share your information with

Doctors and their reception staff: when you book an appointment they see your name, phone number, gender, age (computed from your date of birth), and the reason-for-visit note you typed. They only see this for the appointments you booked with them.

SMS provider (OTPIQ): to send the one-time verification code to your phone during sign-in or password reset. OTPIQ receives only your phone number and the code itself.

Map providers: when you tap "Get directions" the app opens Google Maps, Waze or Apple Maps in a separate app or browser tab and passes only the clinic's coordinates to them. Map tiles inside the app are served by OpenStreetMap. These providers have their own privacy policies which govern their use of your data once you interact with them.

Infrastructure providers: we host the Service on cloud infrastructure operated by our platform partner. Data is stored in encrypted form at rest.

We never share your data with advertisers, data brokers, or marketing companies.

5. International transfers

Our servers and our platform partner's infrastructure may be located outside Iraq / the Kurdistan Region. When your data crosses borders we rely on standard contractual clauses and infrastructure providers that offer adequate security controls.

6. How long we keep your data

Account data (phone, name, DOB, gender, photo): kept as long as your account exists. If you delete your account we remove or anonymise these fields within 30 days.

Booking history: kept for up to 3 years after the appointment date for our own audit and dispute-resolution needs, then automatically deleted.

Security logs (failed logins, IP addresses): kept for 6 months.

Backups: encrypted, kept for up to 90 days for disaster recovery.

7. Your rights

Under GDPR-equivalent principles you have the right to:

• Access — request a copy of the personal data we hold about you. • Rectify — correct any inaccurate data (most fields are editable directly in Profile → Edit). • Erase — ask us to delete your account and personal data ("right to be forgotten"), subject to legal-retention exceptions. • Restrict — ask us to pause processing while a complaint or correction is being resolved. • Portability — receive your data in a machine-readable format so you can move it elsewhere. • Object — object to processing based on our legitimate interests. • Withdraw consent — where processing relies on consent (e.g. location access), you can revoke it at any time in your device settings.

To exercise any of these rights, email support@dawa.iq from the phone number associated with your account. We will respond within 30 days.

8. Children

The Service is intended for users aged 18 and over. If you are a parent or legal guardian and become aware that a child under 18 has created an account without your consent, please contact support@dawa.iq and we will delete the account and its data promptly.

Family-member records (created by an adult account) may contain information about minors, e.g. a parent booking a paediatric appointment for their child. This is allowed — the parent is responsible for the data they add.

9. Security

We protect your data with reasonable and appropriate technical and organisational measures, including HTTPS/TLS transport encryption, encryption at rest, hashed passwords (bcrypt), account lockout on brute-force attempts, rate limiting on sensitive endpoints, and least-privilege access to production data. No online service can guarantee absolute security; we encourage you to use a strong, unique password and to keep your phone secure.

10. Cookies and similar technologies

The mobile app and the website use local storage on your device to remember your language preference, theme, session token, city selection and other UI settings. We do NOT use third-party advertising or tracking cookies.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do we will change the effective date at the top of this page and, for significant changes, notify you inside the app. Continued use of the Service after the updated policy takes effect means you accept the changes.

12. Contact us

For any question about this policy, your data, or to exercise any of your rights, email support@dawa.iq. You also have the right to lodge a complaint with your local data-protection authority.

Questions? support@dawa.iq

Back to home

وَإِذَا مَرِضْتُ فَهُوَ يَشْفِينِ ﴿٨٠﴾

سُورَةُ الشُّعَرَاء — ٨٠

“کاتێک نەخۆش دەکەوم، ئەو (اللە) شیفام ئەدات”

سورەتی الشعراء — ئایەتی ٨٠

“And when I am ill, it is He (Allah) who cures me”

Surah Ash-Shu'ara — Verse 80