Where does your chatbot send your patients’ data? If you don’t know, that’s the problem.
Every message a patient sends your clinic is health data under UAE law. If your tools move it abroad, the fine lands on your trade license — not your vendor’s. Two minutes here and you’ll know exactly what you’re exposed to, and how Anaya removes it.
Four laws watch every patient message you receive.
ICT Health Law (Federal Law 2 of 2019)
Patient data from care delivered in the UAE stays in the UAE. Names, phone numbers, and appointment details count — not just medical records.
Personal Data Protection Law (45 of 2021)
Your clinic is the data controller. Consent, purpose limits, and impact assessments are your duty even when a vendor does the processing.
Cybercrimes Law (34 of 2021)
Unlawful handling of residents’ personal data is a criminal matter — fines and possible detention, not just a penalty notice.
ADHICS & DHA standards
Your emirate’s health authority audits how patient data is secured — UAE hosting, access controls, audit trails — and your license rides on the result.
What it costs the clinic. Every time.
| If your clinic… | You face |
|---|---|
| …uses a tool that processes patient data outside the UAE | AED 500,000–700,000 per violation |
| …handles patient data unlawfully | AED 50,000–500,000 and possible detention |
| …fails a DoH/DHA data audit | License suspension or revocation |
| …breaches its PDPL duties as controller | Administrative penalties by Cabinet decision |
Your chatbot vendor is a subscription on a credit card. Your clinic is licensed, inspected, and here. Guess where the fine goes.
Anaya was built inside these laws. Staying compliant is doing nothing.
- Nothing leaves the UAE. Calls, WhatsApps, transcripts, recordings — processed, stored, and backed up on UAE soil. There is no offshore copy to be fined for.
- Nobody sees more than their job needs. Role-based access, mandatory MFA, company devices only, and a log of every access. Data can’t be downloaded, exported, or copied out.
- Real patients never enter our test systems. Development and QA run on synthetic data.
- High-risk changes get assessed first. Impact assessments before deployment — the PDPL’s requirement, done as routine.
The questions clinic owners ask us.
“Isn’t this the vendor’s problem?”
You can outsource the phone. You can’t outsource the liability — regulators license, audit, and fine the clinic. That’s you.
“Our current tool works fine.”
Ask your vendor one question: where are our patients’ messages processed? A straight answer naming a UAE server is the only good outcome. Anything else — including silence — is your exposure, running daily.
“Is Anaya certified?”
There’s no badge for this — only architecture. Ours was built to the ICT Health Law, the PDPL, and emirate standards, reviewed by UAE counsel. Ask us the hard questions; we like them.
Answer every patient. Keep every byte in the UAE.
Hear Anaya live — then ask her team the compliance question your current vendor can’t answer.
