Policies
Privacy Policy
Last updated: 7 May 2026
1. Who we are
This website (drjohnbirky.com) is operated by John Birky, MD, an individual physician licensed by the Dubai Health Authority (DHA license no. 99789241-001). For the purposes of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL"), Dr. Birky is the data controller for personal data collected through this site.
For privacy questions, contact: connect@drjohnbirky.com.
2. This site is informational only
This website is an educational and informational resource. It is not a patient portal. We do not request, collect, or store medical or health information through this website. Please do not share clinical details, symptoms, medications, test results, or other sensitive health information via the website or WhatsApp until a formal consultation has been established.
3. What personal data we collect
We only receive personal data that you voluntarily send to us, namely:
- Your name (if you provide it)
- Your phone / WhatsApp number when you message us
- Your email address if you write to us
- The free-text content of any message you send
We also receive standard, anonymous, cookieless website analytics (aggregate page views, country, referrer) via Cloudflare Web Analytics. This does not identify individual visitors.
4. Why we use it (purpose & legal basis)
We use the information solely to respond to your inquiry and, where appropriate, to arrange a private consultation. The legal basis under PDPL is your consent (provided when you choose to contact us) and our legitimate interest in responding to inquiries about our services.
5. Who we share it with
- Hosting & site infrastructure: Cloudflare, Inc. (data may be processed on servers outside the UAE, including the United States and the European Union).
- Messaging: WhatsApp / Meta Platforms, Inc. when you message us via WhatsApp. Your message is governed by WhatsApp's own privacy policy and may transit servers in the United States and Ireland.
- Email: Our email provider for the connect@drjohnbirky.com inbox.
We do not sell your data and we do not share it with advertisers. Cross-border transfers are limited to the providers above and rely on appropriate safeguards under PDPL.
6. How long we keep it
Inquiry messages and contact details are retained only as long as necessary to handle your request, and in any case no longer than 12 months after our last interaction, unless you become a patient (in which case separate medical-record retention rules apply to your clinical file, not to this website).
7. Your rights
Under PDPL you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw your consent at any time
- Object to or restrict certain processing
- Lodge a complaint with the UAE Data Office
To exercise any of these rights, email connect@drjohnbirky.com.
8. Security
We apply reasonable technical and organisational measures to protect information you send us. No method of transmission over the internet is 100% secure, and you share information at your own risk.
9. Children
This website is not directed at children under 18. We do not knowingly collect personal data from minors via the site.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the latest revision.