← Back to Assure Tech Pro
Legal

Privacy Policy

Effective Date: January 15, 2026

This Privacy Policy governs the manner in which Assure Tech Pro (referred to as "We," "Us," or "Our") collects, uses, maintains, and discloses information collected from users (each, a "User") of the Assure Tech Pro platform (the "Platform"). Assure Tech Pro is an AI-powered health insurance claims platform for Third Party Administrators (TPAs), HMOs, and insurers.

1. Scope of This Policy

This policy applies to the Assure Tech Pro web-based platform accessible at https://www.assuretech.pro and any associated subdomains, APIs, and administrative interfaces. It covers all Users including TPA staff, HMO operators, insurer personnel, and authorized administrators who access the Platform for claims adjudication, pre-authorization, audit, and reporting functions.

2. Information We Collect and Its Use

We collect information necessary to provide the Platform's core functionality — automated claims adjudication, pre-authorization audit, post-discharge audit, and regulatory compliance reporting across HAAD, DOH, DHA, and CHI KSA jurisdictions.

A. Account and Authentication Data

When an organization onboards to Assure Tech Pro, we collect:

  • Organization details: Legal name, address, license/registration numbers, tax IDs
  • Administrator details: Name, email, phone, role for designated platform administrators
  • Authentication credentials: Hashed passwords, magic-link tokens, session identifiers (processed via bcrypt with timing-safe comparison)

B. Claims and Health Data (Processed on Behalf of Customers)

The Platform processes sensitive health and claims data on behalf of our customers (TPAs, HMOs, insurers) as a data processor. This includes:

Data Category Purpose and Usage
Member/Patient Demographics Name, policy ID, date of birth, gender, Emirates ID / national ID — used for member enrolment, eligibility verification, and claim matching.
Clinical & Claims Data Diagnosis codes (ICD-10), procedure codes, clinical notes, discharge summaries, itemized bills — processed by AI audit engines for pre-authorization and post-discharge adjudication.
Provider & Network Data Hospital/clinic details, tariff schedules, contract terms, network agreements — used for tariff validation and network compliance checks.
Financial & Audit Data Payment records, reconciliation logs, cryptographic audit trails — maintained for 100% audit trail coverage across pre-auth, adjudication, and finance matching.

C. Platform Usage and Technical Data

We collect operational metadata to ensure platform reliability, security, and performance:

  • Audit logs: User actions, API calls, decision timestamps, AI confidence scores — immutable cryptographic audit trail
  • Performance metrics: Response times, error rates, inference latency (sub-second AI processing)
  • Security events: Login attempts, rate limit triggers, permission changes
Important: All health and claims data is processed in accordance with applicable regulations (HAAD, DOH, DHA, CHI KSA, Indian TPA regulations). We act as a data processor; our customers (TPAs/HMOs/insurers) are the data controllers and determine the lawful basis for processing.

3. How We Use Your Information

We use collected information for the following purposes:

  1. Platform Operation: Delivering AI-driven claims adjudication, pre-authorization audit, post-discharge audit, and regulatory compliance modules.
  2. Security & Fraud Prevention: Cryptographic audit trails, authentication, authorization (RBAC), rate limiting.
  3. Regulatory Compliance: Generating mandated reports for HAAD/DOH/Shafafiya, DHA, CHI KSA, and Indian TPA authorities.
  4. Platform Improvement: Aggregated, anonymized usage analytics to improve AI model accuracy and platform performance.
  5. Customer Support: Responding to support requests, onboarding assistance, technical troubleshooting.

4. Data Sharing and Third Parties

We do not sell, trade, or rent personal or health information. Data is shared only in the following circumstances:

  1. With Your Organization: Data is accessible to authorized users within your TPA/HMO/insurer organization per role-based access control.
  2. Regulatory Authorities: When required by HAAD, DOH, DHA, CHI KSA, or Indian TPA regulations for mandatory reporting and audits.
  3. Sub-processors: We may engage trusted subprocessors for infrastructure (cloud hosting, database, email delivery). All subprocessors execute Data Processing Agreements (DPAs) and are bound by equivalent security obligations.
  4. Legal Compliance: To comply with lawful court orders, government requests, or to protect rights and safety.

5. Data Security

We implement appropriate technical and organizational measures to protect data:

  • Encryption: TLS 1.2+ in transit; AES-256 at rest for databases and backups
  • Access Control: Role-based permissions, principle of least privilege, session management with secure tokens
  • Audit Trail: Immutable cryptographic audit logs on every transaction (pre-auth, adjudication, finance)
  • Infrastructure: Hardened cloud environment, regular security patches, vulnerability scanning
  • Application Security: CSRF token rotation, input validation, SQL injection prevention, XSS protection

6. Data Retention

Retention periods align with regulatory requirements and contractual obligations:

  • Claims & Health Data: Retained per applicable jurisdiction (typically 7–10 years for health insurance records per HAAD/DOH/DHA/CHI KSA)
  • Audit Logs: Minimum 10 years for cryptographic audit trail integrity
  • Account Data: Retained for the duration of the service agreement; purged within 90 days of contract termination unless legal hold applies
  • Technical Logs: 12 months for security and performance monitoring

7. International Data Transfers

Assure Tech Pro serves operations across India, UAE, and Saudi Arabia. Data may be processed in the jurisdiction where your organization operates. We ensure appropriate safeguards (standard contractual clauses, adequacy decisions) for any cross-border transfers. Data residency requirements can be accommodated via dedicated deployment options — contact us for details.

8. Your Rights

As a data subject (or on behalf of your organization's data subjects), you have rights under applicable laws (UAE PDPL, KSA PDPL, India DPDP Act):

  • Access: Request a copy of personal data we process on your organization's behalf
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion where processing is no longer necessary (subject to legal retention obligations)
  • Restriction: Limit processing in certain circumstances
  • Portability: Receive data in a structured, commonly used format
  • Objection: Object to processing based on legitimate interests

To exercise these rights, contact your organization's Assure Tech Pro administrator or email us at contact@assuretech.pro. We will coordinate with your organization (the data controller) to fulfill requests within statutory timelines.

9. Children's Privacy

The Platform is a B2B enterprise system for insurance claims processing and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child's data has been submitted, contact us at contact@assuretech.pro.

10. Changes to this Privacy Policy

Assure Tech Pro may update this Privacy Policy to reflect changes in the Platform, regulations, or data processing practices. When we do, we will revise the "Effective Date" at the top of this page and notify active customers via email or in-platform notification. We encourage Users to review this policy periodically.

11. Contacting Us

If you have any questions about this Privacy Policy, our data processing practices, or your rights, please contact us at:

Assure Tech Pro

Email: contact@assuretech.pro