Privacy Notice - NEOM Wellness Application

We are committed to protecting the personal information of patients who interact and engage with NEOM Health and Wellbeing services through the NEOM Wellness application.

This Notice, governed by the Personal Data Protection Law of Saudi Arabia (PDPL), explains how we responsibly and lawfully collect and use your information, and how we protect your privacy.

Key Documents

We have four documents that set out key terms:

About NEOM

NEOM is a legal entity based in the Kingdom of Saudi Arabia. As a business entity in Saudi Arabia, we comply with the laws of Saudi Arabia as well as other relevant global laws and regulations.

NEOM is a company incorporated in the Kingdom of Saudi Arabia with commercial registration number 1010504644 and having its registered address at:

The Information Technology and Communications Complex (ITCC)
2nd Floor Building IN-01
Al Nakheel District 12382
Riyadh, P.O. Box 10, 11411,
Kingdom of Saudi Arabia

If you have any concerns or questions about how we look after your personal data, contact our Personal Data Protection Office at the following email address:

Email: data.privacy@neom.com

What Personal Data Do We Collect

Personal data is any data, regardless of its source or form, that identifies a person - such as a patient or health service customer of Health and Wellbeing - i.e. you, or may make the identification of that person possible.

NEOM processes the following personal information:

Source of Personal Data

Your personal data is collected by NEOM:

The Purposes for Processing your Personal Data

We only use personal data for the purpose it was collected for. We process your personal data for the following reasons:

Legal Basis for Processing

We only process personal data relying on a legal basis:

Purpose Lawful Basis
For registration, account activation, and authentication of users to the NEOM Wellness Application. Art. 6(4) - pursuant to another law e.g. Private Health Institutions Law.
For healthcare information, including scheduling, clinical interactions, lab results, diagnostics, etc., stored in the clinical records system. Art. 6(4) - pursuant to another law e.g. Private Health Institutions Law.

Providing Personal Data to NEOM

The collection of your personal data is mandatory for the provision of Health and Wellbeing services. Without it, NEOM cannot provide health services or complete the other tasks outlined in this Notice.

Storage and Destruction

Personal data is only stored for as long as necessary to fulfill the purposes for which it was collected. We adhere to defined retention periods in line with regulatory, legal, and professional standards. This retention period may vary depending on individual circumstances. We regularly review data retention periods to ensure personal data is not kept longer than required.

Who We Share Your Personal Data With

We may rely on third parties who provide health services on behalf of NEOM. These data processors can only act on our instructions, and we share personal data in compliance with applicable laws. If we share data with other organizations, we ensure they have appropriate safeguards in place. In some circumstances, we are legally required to share information, such as under a court order or to cooperate with regulators.

Personal data will not be transferred, disclosed, or processed outside the Kingdom of Saudi Arabia, except when necessary for data processing, analytics, or technical support services.

Your Data Privacy Rights

Patients have certain rights under Saudi Arabia's privacy laws:

If you wish to exercise any of these rights or have any questions, contact us at:

Email: data.privacy@neom.com