Privacy Policy – Private Therapy Clinic Dubai

Operated by a UK-Registered Company Providing Services in the UAE

At Private Therapy Clinic Dubai, we are committed to protecting your personal and sensitive data. We are a company registered in the United Kingdom, operating internationally to serve clients in Dubai and across the UAE. This Privacy Policy outlines how we collect, use, protect, and share your data in compliance with both UK data protection law (UK GDPR and the Data Protection Act 2018) and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).

By accessing our services in Dubai, you agree to the practices described in this policy.

1.Legal Basis & Jurisdiction

Private Therapy Clinic Ltd is incorporated in the United Kingdom and subject to the UK General Data Protection Regulation (UK GDPR). As we offer services in the United Arab Emirates, we also adhere to relevant provisions under UAE PDPL when handling data of individuals located in the UAE.

Our data storage and operational systems may be based in the UK or other secure jurisdictions that ensure an adequate level of data protection under international law.

2.What We Collect

To provide psychological and psychiatric services, we collect the following categories of data:

  • Identity & Contact Information: Your name, email address, phone number, date of birth, and address.
  • Health & Psychological Information: Medical history, clinical symptoms, psychological profile, family history, and any data relevant to your diagnosis or treatment.
  • Session & Progress Notes: Records of session discussions, treatment goals, practitioner insights, and updates on therapeutic outcomes.
  • Behavioural Data: Information related to personal behaviour, emotions, and mental health shared during clinical sessions.
  • Payment Details: Payment methods and card details processed securely via authorised third-party payment providers.

3.Why We Collect This Data

We collect your information for the following purposes:

  • To assess your clinical needs and deliver effective therapeutic care.
  • To manage scheduling, billing, and communication.
  • To monitor and review treatment effectiveness.
  • To meet ethical, regulatory, and clinical supervision obligations.
  • To ensure safety in cases where risk of harm is identified.
  • To comply with UK and UAE laws applicable to healthcare service providers.

4.Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Article 6(1)(b): Processing necessary for the performance of a contract.
  • Article 6(1)(c): Processing necessary for compliance with a legal obligation.
  • Article 6(1)(f): Processing based on our legitimate interests (e.g. managing appointments).
  • Article 9(2)(h): Processing of special category health data for the purposes of health care or treatment.

Under UAE PDPL, we process personal and sensitive health data where it is necessary for the delivery of healthcare services, with your explicit consent and in accordance with UAE data protection principles.

5.Data Sharing & Confidentiality

We keep your information strictly confidential, except in the following circumstances:

  • Clinical Supervision: Case material may be discussed (anonymised) for professional development and service quality.
  • Risk of Harm: If there is concern for your safety or the safety of others, we may notify relevant authorities or emergency contacts.
  • Legal Obligations: If required by a UK or UAE court or legal authority.
  • Client Consent: With your written authorisation, we may share information with other healthcare providers, schools, employers, or insurers.

6.Payment Data Security

Your financial data is processed securely by third-party payment processors. We do not store or access your full card details. All transactions are protected in line with PCI-DSS standards, and data is encrypted at rest and in transit.

7.International Data Transfers

As a UK-based company, some data may be stored or processed in the UK or the EEA. Any transfer of data from the UAE to the UK is done under standard contractual clauses and with adequate safeguards to ensure your rights are protected under both jurisdictions.

8.Data Security Measures

  • Digital records are stored on secure servers with multi-layered encryption and restricted access.
  • Physical data (if applicable) is held in locked facilities.
  • Only authorised clinical and administrative staff can access your information.
  • We implement regular data audits and staff training on privacy and confidentiality.

9.Accessing and Correcting Your Information

You have the right to:

  • Request access to your personal data.
  • Request correction of any inaccurate or outdated information.
  • Withdraw consent (where applicable).
  • Request erasure of your data (subject to legal or clinical retention requirements).

 

All requests should be submitted in writing to dubai@privatetherapyclinic.com. We aim to respond within 14 working days.

10.Complaints

If you are concerned about how your data is being handled, you may contact us at the above email address. If unresolved, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or, for UAE clients, the UAE Data Office once it is fully operational.

11.Policy Updates

We reserve the right to amend this policy at any time to reflect legal updates or changes in our operations. All major changes will be communicated via our website or directly to clients as appropriate.

Contact

Data Controller:

Private Therapy Clinic Ltd (UK Registered Company)

Email: dubai@privatetherapyclinic.com