Oryx Software Solutions LLC FZ ("Oryx", "we", "us", "our") provides a cloud-based Electronic Medical Records (EMR) platform with built-in AI tools for clinics operating in the United Arab Emirates. This Privacy Policy explains what information we collect, why we collect it, how it is protected, and the rights you have over it.
This policy applies to clinics, doctors, and staff who use Oryx (our "Customers") and to the patients whose data our Customers process using Oryx. If you are a patient, your clinic is the data controller for your medical records; Oryx acts as a data processor on the clinic's behalf.
In short: we store your data on UAE-based servers, encrypt it end-to-end, never sell it, only use it to run and improve the product, and give you full control to export or delete it. Full detail below.
1. Information We Collect
1.1 Account & clinic information
- Clinic name, address, DHA facility license, and billing details
- Names, roles, contact details, and login credentials of doctors, nurses, receptionists, and admin staff
1.2 Patient health information
- Identity details (name, date of birth, gender, national ID/passport, contact information)
- Medical records: history, diagnoses, assessments, prescriptions, lab and imaging results, and clinical notes entered or generated during consultations
- Insurance details: payer, policy number, plan, and claims/reimbursement data
- Appointment and scheduling history
- Billing and invoicing records
1.3 Communications data
- Messages exchanged with our AI receptionist over WhatsApp for the purpose of booking, rescheduling, or answering questions about appointments
- Support requests sent via WhatsApp, email, or our contact form
1.4 Usage & device data
- Log data such as IP address, browser type, device identifiers, and pages/features accessed
- Audit trail data: who accessed or modified a record, and when — required for DHA compliance
2. How We Use Information
| Purpose | Examples |
| Deliver the core product | Storing and displaying patient records, scheduling, invoicing |
| Power the AI features | Organizing and summarizing patient charts; the WhatsApp AI receptionist booking appointments; generating insurance reimbursement forms and filing eClaims |
| Regulatory compliance | NABIDH submission, DHA audit trails, HIPAA-aligned safeguards |
| Accounting integration | Syncing invoices and payments to a clinic's connected Zoho Books account, where enabled |
| Support & communication | Responding to support requests, sending appointment reminders and service notifications |
| Security | Detecting fraud, unauthorized access, and abuse; maintaining audit logs |
| Product improvement | Understanding aggregate usage patterns to improve reliability and features |
We do not use patient health information to train third-party AI models, and we do not sell any personal or health data to third parties.
3. AI Features — How They Handle Data
Oryx's AI features process clinic and patient data to save staff time. Specifically:
- AI Assistant: reads and organizes a patient's existing chart to surface relevant history and pre-fill routine fields. It does not make diagnostic decisions — clinical judgment remains with the treating doctor.
- AI Receptionist (WhatsApp): processes incoming WhatsApp messages to check availability, book or reschedule appointments, and answer routine questions. Conversation content is stored as part of the patient's record for continuity of care.
- Insurance AI: reads invoice and policy data to match diagnosis/procedure codes and generate reimbursement forms formatted for the relevant payer, then files the eClaim. This data is shared only with the specific insurer the claim is addressed to.
Where Oryx uses third-party AI infrastructure providers to run these features, those providers process data solely on our instructions, under contractual confidentiality and data-protection obligations, and do not retain data for their own purposes.
4. Data Storage, Location & Security
- All clinic and patient data is stored on servers located in the United Arab Emirates.
- Data is encrypted in transit (TLS) and at rest (AES-256).
- Access is role-based: each staff member only sees the data relevant to their role, and every access or change is logged in a complete audit trail.
- We maintain safeguards aligned with DHA data protection requirements, NABIDH integration standards, and HIPAA principles for the protection of health information.
5. Sharing of Information
We share data only in the following circumstances:
- With regulators: DHA and NABIDH, as required by UAE healthcare law, to keep a clinic's records compliant and up to date.
- With insurance payers: claim and reimbursement data necessary to process a specific patient's eClaim (e.g. Daman, AXA, NAS, and other UAE insurers).
- With accounting integrations you enable: invoice and payment data sent to a clinic's own connected Zoho Books account.
- With service providers: infrastructure, hosting, and messaging providers (such as WhatsApp Business API providers) who process data on our behalf under confidentiality obligations, strictly to deliver the service.
- Where required by law: in response to a valid legal or regulatory request.
We never sell personal or health data, and we never share it for third-party advertising.
6. Data Retention
Patient medical records are retained for as long as required by DHA regulation and for the duration of the clinic's use of Oryx. If a clinic ends its subscription, we retain data only as needed to meet legal retention obligations, after which it is securely deleted, unless the clinic requests an export beforehand.
7. Your Rights
Depending on your role and applicable law, you may have the right to:
- Access a copy of the personal data we (via your clinic) hold about you
- Request correction of inaccurate data
- Request deletion of data, subject to legal record-keeping requirements for medical records
- Request an export of your data in a portable format
- Object to certain processing, such as marketing communications
Patients should direct these requests to their clinic in the first instance, as the clinic controls the record. Clinics can contact us directly using the details below.
8. Cookies & Website Analytics
Our marketing website uses only essential cookies required for the site to function, plus limited analytics to understand traffic and improve the site. We do not use third-party advertising trackers.
9. Children's Data
Oryx is used by clinics to manage medical records for patients of all ages, including minors, as part of legitimate healthcare treatment provided by the clinic. Such data is handled with the same safeguards described in this policy, and access is restricted to authorized clinic staff and the minor's legal guardians as permitted by the clinic's own consent processes.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our product or legal requirements. We will update the "Last updated" date above, and where changes are material, we will notify clinics directly.
11. Contact Us
For any privacy questions or requests, contact us via WhatsApp at +971 58 587 1103 or through the contact form on our website.