Privacy Policy

Bupa Arabia is committed to respecting your Privacy and recognizes your need for appropriate protection and management of any Personal Data you share with us, in alignment with applicable Personal Data Protection laws and regulations in the Kingdom of Saudi Arabia (“KSA”). We will only Use your Personal Data to deliver the products and services you have requested from us and to meet our legal responsibilities.


This Privacy Notice applies to all our Customers, Visitors, Users who Access, Use our website or mobile application. This Privacy Notice intends to inform you about the following:


    1- The type of Personal Data we may Collect about you and the Purposes for which we Collect it when you Use our website or mobile application.
    2- How we Use the Personal Data Collected from you and with whom we may share it.
    3- Your Privacy Rights regarding your Data.

We fully understand how important your Personal Data is to you, and we will exert our effort to protect the security of your Personal Data. We have always been committed to maintaining your trust and will adhere to Privacy principles to protect your Personal Data.


This Privacy Notice shall apply to Personal Data about you and Related Parties that may be Processed when you visit our offices, Use our website or mobile application, apply for or Use any product, or service provided by us, handle any business, or make any transaction with us, participate in any of our marketing events and surveys, and in any way contact or correspond with us, no matter the Data is provided by yourself or by the Related Parties, or Collected or acquired by us from other sources according to KSA PDPL (Personal Data Protection Law), regulation, regulatory provision, or based on your or Related Parties’ authorization or Consent.

1- We collect the Personal Data to provide you or your Related Parties with various products and services and continuously improve our products and services, or to contact or communicate with you or your Related Parties, understand the needs of you or your Related Parties, build, review, maintain and develop our relationship with you or your Related Parties, we may receive and keep the Personal Data provided by yourself or by Related Parties, or, according to law, regulation, regulatory provision, or your Related Parties’ authorization or Consent, Collect , enquire, and verify by proper methods your and/or Related Parties’ Personal Data from/with members of Bupa Arabia or other Third-Parties (including but not limited to credit reference agencies, Data service providers, relevant authorities, employers, counterparties).


2- The Personal Data we Collect may be on paper, electronic, or any other form.


3- When you visit, browse, or Use our website and/or applications as a Visitor, we may Collect Data about the browser or device you Use (such as IP (Internet Protocol) address, operating system, and browser version), your browsing actions, and patterns for the Purposes stated in the table-A. We Use Cookies and other similar technologies to Collect the above Personal Data. You may disable Cookies by changing your settings (for details, please refer to the section “How We Use Cookies and Other Technologies” in this Notice).


4- Technical Data which cannot identify any Individual will not be treated as Personal Data. However, when such Technical Data can identify the Individual alone or in combination with other Data, we will protect it as your Personal Data.


5- When you are a connected person/Legal Guardian of our prospect or existing non-Individual Customers or your Related Parties to the transactions (including Children, corporate, enterprise, institution, and other legal Entities) (Here we refer to connected person/Legal Guardian means any other person with whom our prospect or existing non-Individual Customer has a relationship, including but not limited to, a director, supervisor or Employee of a company, Partners or members of a Partnership, any shareholder, substantial owner, controlling person, or beneficial owner, trustee, settlor or protector of a trust)


6-Bupa Arabia reserves the right to deny the provision of such services in case of refusal to provide Consent to Collection of the above stated Personal Data as is available with you or your Related Parties, or the Personal Data so provided is found to be, inaccurate, or untrue. If you refuse to provide that Personal Data (or the Personal Data so provided is incomplete, inaccurate, or untrue). You may decide, at your free choice, to provide us, or allow us to Collect from you or any Third-Party as you agree


7- You can choose not to provide such Personal Data. Your failure to provide such Personal Data will make you unable to participate in or utilize the corresponding convenience or functions but will not affect your normal Use of our other services.


8- We obtain most of your Personal Data directly from you and through the products and services you Use. Some Personal Data may be obtained from other sources. For example, we may verify some of the Personal Data you give us with your employer or our references. Generally, when we obtain Personal Data from someone other than you, (other Third-Parties we may have, we record the source of that Personal Data). We may obtain your Consent in writing or through electronic means before Collecting Personal Data. In some cases, we may be required by law to obtain your Explicit Consent, in which case we ensure that we do so.


9- We may invite you to subscribe to our updates, and alerts or to participate in our marketing events or survey via our website and/or applications. If you accept the relevant invitation, we may Collect the Personal Data you provide to us by filling out contact forms or questionnaires, etc. The said Personal Data may include name, Iqama number, telephone number, email address, etc. Refusal to provide such Personal Data will not affect your visiting, browsing, or using our website and/or applications.


10- When you are our prospect or existing Individual services Customer/corporate Customers or your Related Parties to the transactions, for us to provide you with our products and to handle relevant business, we may Collect the following Data upon your Consent or authorization for the mention purposes


Purposes or Functions (Products/ Services/ Functions)
  • To provide you with Medical Insurance.
  • To provide a connected person/Legal Guardian of our prospect or existing non-Individual Customers or your Related Parties with Medical Insurance.
  • Message service functions
  • Appointment for Insurance Policy Data, other service To provide you with more accurate, personalized, and convenient service and improve your Customer service experience.

Personal Data we may need to Collect

a. Personal Data, including name, sex, nationality, citizenship, national/IQAMA ID or residence number, Job Title, mobile number, Email address, signature, occupation, telephone number, , contact Data, birth date, place of birth, marital status, family status, place of residence (include historic address, contact address and permanent address), company/employer and any relationship with Politically Exposed Person and relevant Personal Data, etc.
b. Health Data (Medical history, related to your health conditions or diseases, your family details (including spouse, children), etc.
c. Biometrics Data, such as signature, handwriting, fingerprint, voice, face recognition Data, etc..
d. Credit Data (Personal Account Information, including Account Number, etc.)
e. Your Insurance Policy Data and Data related to transactions. We Collect the above Personal Data so that we can send you prompt notifications on Enterprise Privacy Policy Data and other new product-related notifications.
f. Personal Data you provide when raising your feedback, suggestion, or complaint, Personal Data you input when participating in campaigns or surveys. We will conduct an analysis of the Personal Data and will contact you or provide you with the relevant response, service, or products based on that Data.
g. Any other Personal Data as deemed necessary for the purpose of providing you or your Related Parties with medical insurance. However, such Personal Data will be clearly specified, and Consent will be sought for Collection of the same through electronic or physical mode.
Note: - The above Data are the Personal Data we must Collect to provide you with our products or services, to fulfill our contract with you, and to comply with laws, regulations, and regulatory requirements.

1. We will Use your Personal Data/Sensitive Personal Data to realize the Purposes and functions mentioned in the above section of this Notice “How We Collect Your Personal Data.”

2. When you visit, browse, or use our website and/or applications as a Visitor, we may Use your Personal Data for the following Purposes:
a) To respond to your queries and requests.
b) To provide you with Data related to products, or services that you request from us or which we feel may interest you, subject to your prior Consent.
c) To perform contracts or agreements entered between you and us, if you agree to purchase a service from Bupa Arabia
d) To allow you to interact with us on our website and/or applications.
e) To notify you about changes to our website and/or applications.
f) To ensure the content of our website and/or application is presented effectively on your device.
g) To maintain proper and secure operation of our website and/or applications to prevent and Control risk, or to detect and prevent misuse or abuse of our website, applications, products, or services.
i) To make statistics and analysis of the Use of our business, products, services, or functions. However, such statistics will not contain any of your Personal Data

3. When you are our prospect or existing Customer or a Related Party or a Legal Guardian of our Individual/non-Individual Customers, we may Use your Personal Data for the following Purposes:
a) To provide you or Related Parties with products or services, to recognize or verify the Identity of you and/or Related Parties, or to approve, manage, handle, execute, or effect transactions requested or authorized by you or Related Parties.
b) To comply with any applicable Laws and any order or requirement from any authority.
c) To perform Bupa Arabia’s compliance obligations (including regulatory compliance, and/or compliance with any applicable laws or requirement of any authority), or to implement any policy or procedure made by Bupa Arabia for the performance of compliance obligations.
d) To enforce or defend Bupa Arabia, or to perform Bupa Arabia’s obligations.
e) As required by or to fulfil Bupa Arabia’s reasonable operational requirements (including Data statistics, analysis, Processing, handling, Archiving, recording, system, product and service design, research, development and improvement, planning, insurance, audit, and administrative Purposes).
f) Subject to your or your Related Parties’ authorization, market or promote relevant products or services to you or your Related Parties, to assess your or your Related Parties’ interests in relevant products or services, or to conduct market research or survey or satisfaction survey; and
g) To obtain or utilize administrative, consultancy, telecommunications, computer, payment, Data Storage, Processing, outsourcing, and/or other products or services.

4. The above Personal Data Collection and Use in this Notice shall not impact our Use of your Personal Data for the Purposes otherwise agreed between you or Related Parties and us.

5. If we Use your Personal Data for Purposes other than the Purposes of Collection and Use as outlined in this Notice or other agreements between you or Related Parties and us, we shall obtain your Consent before using your Personal Data for such additional Purposes.

We will only Process your Personal Data if we have a Lawful Basis to do so. This includes but is not limited to coordinating the performance of a contract, complying with Legal Obligations, and protecting material interests, approvals, or legitimate interests pursued by us or Third Parties as is allowed by applicable law and regulations time being in force.

We comply with the applicable laws and regulations on Data Storage. When we Collect or Process your Personal Data, we will, according to applicable laws and regulations, regulatory, archival, accounting, auditing, or reporting requirements, and the Purposes as outlined in this Notice, store your Personal Data for a period as minimum as necessary to fulfill the Purposes of Personal Data Collection. Personal Data Collected from the website and/or mobile applications are being Stored on our servers located within the Kingdom of Saudi Arabia governed by appropriate security techniques to protect and preserve the Data. After the Retention period expires, we will Destroy, Delete, or de-identify relevant Personal Data, or where the Destruction, Deletion, or anonymization is not possible, store your Personal Data securely and separate it from other Data Processing. These requirements do not apply to the Personal Data that needs to be retained according to applicable laws and regulations, regulatory, archival, accounting, auditing, or reporting requirements, a special agreement between you or your Related Parties and us, or for record check or inquiry from you, your Related, regulators, or other authorities. We might require keeping your Personal Data even after the purpose of its Collection has ended in the following cases

a. If there is a legal justification for us to keep it for a specified period by law, regulation, or security reasons.

b. If the Personal Data is closely related to a case before a judicial authority and its Retention is required for this purpose

c. If all personal elements have been anonymized

1. Personal Data security is our top priority. We will always endeavor to safeguard your Personal Data against unauthorized or accidental Access, Processing, or damage. We maintain this commitment to Personal Data security by implementing appropriate physical, electronic, and managerial measures to secure your Personal Data. We will take responsibility by law if your Personal Data suffers from Unauthorized Access, Public Disclosure, Deletion, or Damage for a reason attributable to us and so impairs your lawful rights and interests.

2.We maintain a strict security system to prevent Unauthorized Access to your Personal Data. We exercise strict management over our staff members who may have Access to your Personal Data, including but not limited to Access Control applied to distinct positions, a Contractual Obligation of confidentiality agreed with relevant staff members, formulation and implementation of Personal Data security-related policies and procedures, and Personal Data security related training offered to staff.

3. We will not Disclose your Personal Data to any Third-Party unless the Disclosure is made to comply with laws, regulations, and regulatory requirements or according to this Notice or other agreement (if any) or based on your or your Related Parties’ Consent or authorization. When we Use services provided by external service providers (Entities or Individuals), we also impose strict confidentiality obligations on them and request them to abide by the security standards of KSA PDPL when Processing Personal Data.

4.For the security of your Personal Data, you shall also be responsible to take care of your Personal Data, such as your account Information, Identity Verification Information (e.g., username, password, dynamic password, Verification code, etc.), and all the documents, devices, or other media that may record or otherwise relate to such Data, and shall ensure your Personal Data and relevant documents, devices or other media are used only in a secured environment. You shall not, at any time, disclose to any other person or allow any other person to Use such Data and relevant documents, devices, or other media. Once you think your Personal Data and/or relevant documents, devices, or other media have been Disclosed, lost, or stolen, or may otherwise affect the security of your Use of our products, devices, or services, you shall notify us immediately so that we may act appropriately to prevent further Loss from occurring.

5.We will organize regular staff training and drills on emergency response. If unfortunately, a Personal Data security incident occurs, we will adopt the emergency plan and take relevant actions and remediation measures to mitigate the severity and Losses in connection therewith. Meanwhile, we will, following the applicable requirements set out in law and regulation, inform regulatory authorities about the Data of the security incident and its possible impact, the actions and measures we have taken or will take, suggestions to prevent and mitigate the risk, and applicable remediation measures.

1.Entrusted Processing and Sharing
For the Purposes set out above in the Bupa Arabia Privacy Notice, we may provide or Disclose all or part of your Personal Data to the following recipients under the preconditions that such provision or Disclosure is necessary and is made with proper protective measures (please refer to section “How We Protect Your Personal Data” for details) and the recipients may also, for the aforesaid Purposes, Use, Process or further Disclose the Personal Data they receive provided that corresponding protective measures are adopted under the applicable laws or our requirements:
a) any member of Bupa Arabia.
b)any Contractor, subcontractor, agent, Third-Party product or service provider, professional consultant, business Partner, or associated person of Bupa Arabia (including their Employees, directors, and officers).
c)any regulator of Bupa Arabia or any other authority, or any organization or Individual designated by such regulators or authorities.

Subject to applicable laws and regulations, we will seek your Consent and notify you of the Data Sharing/Transferring, including the Data receiver's Identity, contact Data, the purpose of Processing, method of Processing, and the type of Personal Data (if the cross-border Transfer involved, we will also notify you the manner and method of exercise your right). We may Disclose Personal Data about you to affiliated and non-affiliated Third Parties. If we do this, we make sure there are appropriate Privacy, Data Handling, and security arrangements in place to protect your Personal Data.
a) Affiliates : We may share Personal Data about you with the Bupa Arabia affiliates for legal and regulatory Purposes, to manage business risks, and to ensure we have corrected and up-to-date Personal Data about you, such as your current address, date of birth, etc. We may also share your Personal Data to better manage your total relationship with the Bupa Arabia affiliates and enable other affiliates of the Bupa Arabia to bring suitable products and services to your attention. Bupa Arabia will share your Personal Data with the Bupa Arabia affiliates for these Purposes unless prohibited by law or you tell us not to do so.
b) Authorized Business Partners: We may Partner with other companies to offer you products or services. We may Disclose Personal Data and/or non-personal or de-identified Personal Data Collected about you to such Third-Party Partners to provide those services.
c) Sharing Personal Data where ownership or liability is shared with Third Parties: If you have a product or service where ownership or liability is shared with Third Parties, we may share your Personal Data with them in connection with the product or service. Also, if you authorize us, we may provide your Personal Data to your lawyer, accountant, or Third Parties you have identified.
d) Government and Law Enforcement ; Compliance; Other Purposes Permitted by Law: Not withstanding any other provision of this Notice to the contrary, we reserve the right to Disclose Personal Data to Third-Parties as we believe appropriate to comply with legal Process and/or to respond to governmental or regulatory requests for any other purpose permitted by applicable law.

2. Transfers

Without your Consent, we will not Transfer your Personal Data to any other company, organization, or Individual. In exceptional cases to provide the cross-border service, after obtaining your Consent, your Personal Data may be transferred abroad too. Under these circumstances, we will adopt appropriate, necessary, and effective security methods (encryption) to protect your Personal Data. Also, we will inform you of the Identity, contact, etc. of the Personal Data recipient according to the requirements of applicable laws and regulations and request the Personal Data recipient to comply with the Bupa Arabia Privacy Notice. If the Personal Data recipient changes the Purposes, methods, etc. of Personal Data Processing under the Bupa Arabia Privacy Notice, it shall obtain Consent From you.

3. Public Disclosure

We will not Disclose your Personal Data to the Public unless we have your Consent to do so.

4. Special circumstances for Personal Data Processing:

We will Process your Personal Data (Collection, Storage, Use, analysis, Transfer, Disclosure) based on your Consent. To the extent allowed by laws and regulations, we may Process your Personal Data without your Consent under the following circumstances:

a) Where it is necessary to protect your Vital Interests in an emergency or respond to Public health emergencies
b) When the Processing achieves actual interest for the Data Subject, it is impossible to contact him/her, or it is difficult to achieve this.
c) Other circumstances stipulated by laws and regulations.

Bupa Arabia makes all its efforts to high-quality services to all Users in a manner that guarantees their following rights under the limits stipulated in the Personal Data Protection Law as well as other regulations subject to other legal requirements as mandated under applicable laws including but not limited to those specified by insurance sector regulators:

1. Right to be Informed: You have the right to be informed about the Collection and usage of your Data including why and how we Collect your Data, the Purposes for Processing your Data, Retention periods for that Data, who will it be shared with, what are the security measures we take to protect this Personal Data and what your rights are.
2. Right to Access: You have the right to Access your Personal Data with Bupa Arabia and are entitled to obtain a copy of it or transfer it to another party.

Exceptions to this right include:

a. If the Restriction is necessary to protect the Data Subjects.
b. If the Restriction is necessary for security Purposes, implementing another law, or meeting judicial requirements.
c. If the Access is characterized or may lead to the following:
i. Poses a threat to security, harms the reputation of the Kingdom of Saudi Arabia, conflicts with the Kingdom of Saudi Arabia's interests.
ii. Affects the Kingdom of Saudi Arabia's relations with other countries.
iii. Prevents detection of a crime, affects the rights of the accused, affects the integrity of existing criminal procedures.
iv. Endangers the safety of Individuals.
v. Violates the Privacy of an Individual other than the owner.
vi.Conflicts with the interests of a Person Who Fully or Partially Lacks Legal Capacity.

3. Right to Update: You have the right to request Personal Data correction, completion, or update.

4. Right to Destroy: You have the right to request that your Personal Data be Destroyed when:

a. You consider that we no longer require the Personal Data for the Purposes for which it was obtained.
b. You have validly objected to our Use of your Personal Data.
c. Our Use of your Personal Data is contrary to the law or our other Legal Obligations.
d. You have Revoked your Consent to Collect and Process your Personal Data.

5. Right to Object: You have the right to object to the Processing of your Personal Data at any time, however, this right only applies in certain circumstances, such as the right can be exercised at any time when your Personal Data is Processed for direct marketing Purposes.

6. Right to Revoke Consent: You have the right to Revoke Consent to Collect and Process your Personal Data unless statutory or judicial requirements require otherwise.

You may submit a request to exercise your rights by contacting Privacy@Bupa.com.sa

We pay particular attention to the protection of Personal Data of a Person that fully or partially lacks legal capacity. We have no intention of Collecting any Personal Data of a Person that fully or partially lacks legal capacity unless it is agreed by their Legal Guardians, and it is necessary for the products or services offered to them. In the case where we Collect their Personal Data through our website or mobile application, the purpose would solely be to directly respond to the request without using their Data for any other Purposes. The Personal Data will not be Processed without notifying the Legal Guardian of the request except for the following:
  • We pay particular attention to the protection of Personal Data of a Person that fully or partially lacks legal capacity. We have no intention of Collecting any Personal Data of a Person that fully or partially lacks legal capacity unless it is agreed by their Legal Guardians, and it is necessary for the products or services offered to them. In the case where we Collect their Personal Data through our website or mobile application, the purpose would solely be to directly respond to the request without using their Data for any other Purposes. The Personal Data will not be Processed without notifying the Legal Guardian of the request except for the following:
  • When the sole purpose of Collecting the contact details is to respond directly to a specific request from the Data Subjects, this Data is not used to call them back again or for any other purpose.

The Personal Data we Collect with the Consent of your Legal Guardians, we will only Use or Disclose such Personal Data to the extent allowed by law and regulation or Expressly Consented by your Legal Guardians or necessary for the protection of the Data Subject’s interests.

We will be able to Access the Data Stored on the Cookies. When you visit, browse, and Use of any of our website or mobile applications may be recorded for analysis on the number of Visitors to the site and/or applications, routine Use patterns, and your personal Use patterns and improving your experience. Some of this Data will be gathered using “Cookies.”

The Data Collected by Cookies is anonymous aggregated Data and contains no Personal Data.

You can manage or disable Cookies based on your preference. Should you wish to disable the Cookies, you may do so by changing the settings on your local terminals. However, after changing the setting you may not be able to enjoy the convenience that Cookies bring, but your normal Use of other functions of the local terminals will not be affected.

Requests for Access to, correction, or Deletion of Personal Data, for withdrawal of authorization or Disposal of Personal Data beyond the Retention period, for a copy of this Notice, or inquiries about our practices regarding Personal Data and Privacy protection, should be addressed to:

Contact: Privacy@Bupa.com.sa

Office Address:

Al Khaldiyah-Nour Al Ehsan 3538 Unit 1

Jeddah 7505-23423, KSA

We regularly monitor our procedures and security measures to ensure that they remain effective. Bupa Arabia is committed to treating you with the greatest respect and consideration and providing the highest level of service. Even so, there may be a misunderstanding or times when you may feel you have been dealt with unjustly. Whatever the circumstances, our primary objective is to ensure your concerns are addressed. If you have any questions or complaints call 800 244 0307

Or

You may reach to our Data Privacy Office at:

Office Address:

Al Khaldiyah-Nour Al Ehsan 3538 Unit 1

Jeddah 7505-23423, KSA

This Privacy Notice may be revised from time to time. We urge you to request and review this Privacy Notice frequently to obtain the current version. Your continued provision of Personal Data or Use of our services following any changes to this Privacy Notice constitutes your acceptance of any such change.