Privacy Policy
Last updated: August 2026
Legal Draft Notice: This page is a working draft prepared to give the design and development team real, UAE-grounded content to build against. It is not legal advice and must be reviewed, verified, and finalized by qualified UAE legal counsel before it is published on the live website.
1. Introduction & Scope
THE RAJ (“THE RAJ,” “we,” “us,” or “our”) provides healthcare growth, turnaround, and full P&L management services to clinics, hospitals, and home healthcare businesses. This Privacy Policy explains how we collect, use, store, share, and protect personal data in two distinct contexts: (1) data collected through our website, marketing, and the free strategic audit process, and (2) data we may encounter while embedded alongside a client's team during an active engagement, which can include patient health information belonging to the client, not to THE RAJ.
- Applies To — Website visitors, prospective clients booking a strategic audit, and personal data processed in the course of client engagements
- Governing Framework — UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”), and, for health-related data specifically, UAE Federal Law No. 2 of 2019 Concerning the Use of Information and Communication Technology in Health Fields and its Cabinet Decision No. 32 of 2020
- Territorial Reach — This policy is written primarily for our UAE operations; where THE RAJ operates in Saudi Arabia, Qatar, the USA, Spain, Nepal, or India, the applicable local data protection law also applies alongside this policy
2. Information We Collect
We collect different categories of data depending on how you interact with us.
- Website & Audit Booking Data — Name, company/clinic name, email address, phone number, country of operation, and any details you voluntarily share when requesting a free strategic audit
- Business & Financial Data — Revenue ranges, operational metrics, and P&L information shared by a prospective or existing client during scoping conversations and the engagement itself
- Technical & Usage Data — IP address, browser type, device information, pages visited, and referral source, collected automatically via cookies and analytics tools
- Health-Related Data (Client Engagements Only) — Where THE RAJ is embedded within a client's operations, our team may be exposed to patient health information that is created, held, and controlled by the client (e.g. a licensed clinic or hospital), not by THE RAJ. We do not independently collect health data from patients directly
3. How We Use Your Information
- Respond to Inquiries — To schedule and conduct your complimentary 30-minute strategic audit
- Deliver Services — To scope, propose, and deliver the growth and turnaround engagement described in a signed services agreement
- Communicate — To send updates, reporting, and relevant information about your engagement or, with consent, marketing communications
- Improve Our Website — To understand how visitors use www.theraj.me and improve its content and performance
- Comply With Law — To meet our obligations under the PDPL, UAE health data regulations, and any other applicable law
4. Legal Basis & the UAE PDPL
Federal Decree-Law No. 45 of 2021 (the PDPL) is the UAE's general data protection law. It gives individuals rights over their personal data and requires organizations to have a lawful basis — such as consent, contractual necessity, or legitimate interest — before processing personal data. The PDPL applies to our processing of general business and marketing data (names, contact details, company information).
- Consent — Where you submit a form on our website or request an audit, you are giving us consent to contact you about that request
- Contractual Necessity — Processing needed to negotiate, scope, and deliver a signed services agreement
- Legitimate Interest — Limited use of business contact data for relevant follow-up, balanced against your right to object at any time
5. Health Data & Sector-Specific Protection
Personal health data is treated differently under UAE law and under this policy. The PDPL itself excludes personal health data from its general scope specifically because a dedicated law already governs it: Federal Law No. 2 of 2019 Concerning the Use of Information and Communication Technology in Health Fields, together with its implementing Cabinet Decision No. 32 of 2020.
- Client Owns the Health Data — In every engagement, the client clinic, hospital, or home healthcare provider remains the data controller for its own patients' health information. THE RAJ's embedded team operates within the client's existing, regulator-approved systems rather than creating a parallel record
- Local Regulator Applies — Depending on where the client is licensed, the relevant health data authority applies — the Dubai Health Authority (DHA) in Dubai, the Department of Health (DoH) in Abu Dhabi, or the Ministry of Health and Prevention (MOHAP) federally elsewhere in the UAE
- Platform-Level Standards — Where a client facility is connected to a unified health information exchange such as Dubai's NABIDH platform, THE RAJ's team follows that platform's consent, access-control, and interoperability standards rather than operating outside them
- Data Localization — UAE health data law generally requires health data relating to individuals in the UAE to be stored within the UAE unless an approved exception applies — a requirement we respect in how any client system we touch is configured
- No Independent Clinical Use — THE RAJ does not use patient health data for any purpose beyond supporting the client's own operational, marketing, and financial turnaround objectives as scoped in the signed engagement
6. Data Sharing & Disclosure
- Service Providers — Vetted vendors supporting our own marketing, CRM, and operations (e.g. email or scheduling tools), bound by confidentiality obligations
- Client Personnel — Data is shared with the relevant client team members strictly on a need-to-know basis to deliver the engagement
- Legal & Regulatory Requests — Disclosure where required by UAE law, a competent court, or a relevant regulator
- No Sale of Data — THE RAJ does not sell personal data or patient health information to third parties, under any circumstances
7. International Data Transfers
THE RAJ operates across the UAE, Saudi Arabia, Qatar, the USA, Spain, Nepal, and India. Where personal data is transferred across these borders — for example, centralized reporting or team coordination — we apply appropriate safeguards consistent with the PDPL's cross-border transfer requirements. Health data relating to UAE-based patients is handled according to the data localization principles described in Section 5 above and is not transferred outside the UAE without the approvals required by law.
8. Data Retention
- Website & Marketing Data — Retained only as long as needed to respond to your inquiry or maintain a business relationship, or as required by law
- Engagement Records — Business and financial records retained per the terms of the signed services agreement and applicable UAE commercial record-keeping requirements
- Health-Related Records — Retention of any patient health information remains governed entirely by the client's own retention obligations under UAE health law and DHA/DoH/MOHAP standards, not by THE RAJ
9. Your Rights Under the PDPL
- Right to Access — Request confirmation of what personal data we hold about you
- Right to Correction — Request correction of inaccurate or incomplete data
- Right to Erasure — Request deletion of your data, subject to legal and contractual retention requirements
- Right to Restrict or Object — Request that we limit certain processing, or object to processing based on legitimate interest
- Right to Data Portability — Request your data in a portable format, where technically feasible
- Right to Withdraw Consent — Withdraw consent at any time for processing based on consent, without affecting prior lawful processing
- Right to Lodge a Complaint — Raise concerns with the UAE Data Office if you believe your rights under the PDPL have been infringed
10. Data Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data involved, including access controls, encryption in transit, and confidentiality obligations for all team members and vendors. Where our team is embedded within a client's systems, we operate within the client's own security and access-control framework rather than introducing separate, unmanaged access.
11. Cookies & Website Analytics
Our website uses cookies and similar technologies to understand visitor behavior and improve performance. You can control cookies through your browser settings; a full Cookie Policy with a consent banner should be finalized alongside this page before launch.
12. Children's Privacy
Our website and services are directed at healthcare businesses and their management, not at children. We do not knowingly collect personal data from children through our website.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in UAE law. The “last updated” date at the top of the published page will reflect the most recent revision.
14. Contact Us
Questions about this policy or requests relating to your personal data can be directed to THE RAJ using the details below.
- Website: www.theraj.me
- Email: [email protected]
- Phone: +971-551553033
- Postal Address: [To be added — registered UAE business address]
Open items for counsel before publishing: confirm the appointment (or non-appointment) of a formal Data Protection Officer, finalize the Cookie Policy and consent banner, and confirm the registered business address and any DIFC/ADGM-specific considerations if THE RAJ is structured through either free zone.

