Privacy Policy
At EICADD Early Intervention Centers for Autism and Developmental Disorders we handle data about children and their families, and we treat protecting that data as an inseparable part of the care itself. This policy explains transparently what data we collect, why, on what legal basis, who we share it with, how long we keep it, how we protect it, and what your rights are and how to exercise them. Please read it carefully, and do not hesitate to contact us with any question.
Who we are and who is responsible for your data
The party responsible for processing your personal data (the "data controller") is EICADD centers, operating through two branches: the Amman branch in the Hashemite Kingdom of Jordan (Building 224, Alqods Center, Wasfi Al-Tal Street, Khalda) and the Ajman branch in the United Arab Emirates (Villa 1, Altala Street, Almuntazi 1). Each branch is responsible for the data of the families it serves, and central management coordinates protection policies across both.
EICADD is a rehabilitation and early-intervention center specialising in autism and developmental disorders. It is not a hospital or a medical facility in the legal sense. Nevertheless, we apply to children's files the same level of protection that the law requires for health data.
We have appointed a data protection officer who receives every privacy-related request and question at info@eicadd.com, or through the phone numbers published on the contact page.
Scope of this policy
This policy applies to:
- The eicadd.com website in all its languages and pages.
- Your communication with us by email, phone, WhatsApp, or any contact or booking form we make available on the website.
- Our official pages on YouTube, Instagram and Facebook, to the extent that data reaches us from them.
- The broad outline of what happens to your child's data inside the center. The details of in-center processing are explained in the informed-consent form the parent or guardian signs when the service begins.
This policy does not apply to external websites or services we link to. Each has its own privacy policy.
Definitions
- "Personal data": any information that identifies a natural person directly or indirectly, such as a name, phone number, email address, photograph or IP address.
- "Sensitive data" or "special categories": health, genetic and biometric data, data relating to disability or developmental or psychological condition, and any data concerning a child.
- "Processing": any operation performed on data, from collection, storage and use to sharing and deletion.
- "Parent or guardian": the father, mother or legal guardian who has the authority to make decisions on behalf of the child.
- "Rehabilitation file": the record the center creates for each child, containing assessment results, the intervention plan, session notes and reports.
Data we collect
We collect only what we genuinely need for a specific purpose, and we always ask you for as little information as possible. The data varies depending on how you interact with us:
- Contact and inquiry data: your name, phone number, email address, preferred branch, language, and the text of your message, call or WhatsApp conversation.
- Preliminary data about the child: their age, and any general description of the concerns prompting you to contact us, to the extent you choose to share it.
- Booking data: the requested appointment, the type of service or assessment, and the confirmation date.
- Data of trainees and applicants to training and certification programs: name, qualifications, employer, contact details, attendance record, assessment results and certificate issuance data.
- Technical data: IP address, browser type and operating system, pages visited, time and duration of the visit, and the referring page. This is collected in aggregate and is not used to track you personally.
- Cookie data: according to your choice in the consent panel, as detailed in the Cookie Policy.
- Photos, videos and reviews: only if you have expressly consented in writing to the publication of your child's image or your experience in our Success Stories or channels.
Inside the center, and never through the website, the child's rehabilitation file is created. It includes assessment results, including those produced by AI tools, reports provided by the parent or guardian, the intervention plan, specialists' notes, and session recordings where they exist and where prior consent has been given.
We never ask you through this website for reports, assessment results or detailed information about your child's case. If you voluntarily send such information by email or WhatsApp, we treat it in strict confidence, transfer it to the appropriate rehabilitation file, and delete it from the messaging channels.
How we obtain data
- Directly from you: when you contact us, book, enrol in a training program, or visit the center.
- Automatically from your device: through your browser and cookies, within the limits of your choice.
- From third parties with your consent: such as a specialist or school referring the child to us, or an employer enrolling its staff in a training program.
- From public platforms: such as reviews you publish yourself on Google or on our social media pages.
Why we use your data and the legal basis
We process your data only for a specific and legitimate purpose, and on a clear legal basis. The main purposes and their legal basis are:
- Answering your inquiry, arranging the appointment and following up with you: based on your consent and on the steps preceding a service contract.
- Providing assessment and intervention services to the child and managing their rehabilitation file: based on the service contract signed with the parent or guardian, and on explicit written consent for processing health data.
- Running training and certification programs, issuing certificates and verifying them: based on the contract with you or with your employer.
- Operating and securing the website and preventing abuse: based on our legitimate interest in protecting our systems and visitors.
- Measuring website performance and understanding which content helps parents: based solely on your consent to analytics cookies.
- Sending news, educational material or training offers: based on your consent, with the option to unsubscribe at any time.
- Publishing success stories, photos or videos: based on separate, explicit, written and revocable consent.
- Complying with laws and regulations and responding to lawful official requests: based on legal obligation.
- Defending our legal rights or demonstrating compliance: based on our legitimate interest.
Whenever we rely on legitimate interest we always balance it against your rights and interests, and we do not proceed if the processing would override them. We do not use your data for any new purpose materially different from the one it was collected for without informing you and obtaining your consent where required.
Sensitive and health data
Data relating to a child's health and developmental condition is sensitive by nature, and we process it under stricter rules:
- It is collected only inside the center, with the explicit written consent of the parent or guardian, after the purpose and use have been explained.
- It is accessed only by the specialists directly involved in the child's case, to the minimum extent necessary for their work, and all of them are bound by professional and contractual confidentiality.
- It is stored in encrypted systems separate from marketing and website systems.
- It is never used for marketing purposes and never shared with any commercial party.
- The parent or guardian may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it, and we may be required to retain parts of the file under a legal obligation.
If you are involved in the child's care (for example a specialist or school), we share nothing from the file with you without written authorisation from the parent or guardian.
Artificial intelligence and automated decisions
Inside the center we use AI-based assessment tools to support specialists in measuring certain indicators. We are committed to the following principles:
- AI is an assistive tool only. Any assessment or intervention plan concerning your child is reviewed and approved by a qualified specialist, and no decision affecting the child is made in a fully automated way.
- The parent or guardian has the right to request an explanation of the results, to contest them, and to request an independent human review.
- Data processed by these tools remains within the rehabilitation file, is not used to train models for external parties, and is not shared in any form that allows the child to be identified.
- Any use of data for research or tool development takes place only after full de-identification, with separate consent where required, and under ethical review.
The website itself makes no automated decisions about you and does not build profiles of visitors.
Children's privacy
This website is intended for parents and professionals, not for children, and it offers no services aimed at anyone under 18. We do not knowingly collect any personal data from children through the website. Any data concerning a child reaches us exclusively from their father, mother or legal guardian.
If we learn that a child has sent us data through the website without a parent's consent, we delete it immediately. If you are a parent or guardian and believe your child has provided us with data, write to info@eicadd.com.
Inside the center, we handle children's data according to the principle of the best interests of the child, and we explain to the child, in a way suited to their age and abilities, what is happening whenever that is possible.
Photos, videos and success stories
We never publish any photo, video, name or story concerning a child or family without separate, explicit, written consent from the parent or guardian that clearly specifies the type of content, the platforms and the duration of publication.
- This consent can be withdrawn at any time. We remove the content from the platforms we control within 10 working days, noting that copies saved or reshared by others are outside our control.
- Reviews shown in the Success Stories section were originally published by parents on public platforms such as Google. We display them as they are, and their author may ask us to remove them from our website at any time.
- We do not use children's images in paid advertising without specific consent for that purpose.
Who we share data with
We do not sell, rent or trade your data with anyone, and we do not share it with advertisers. We may share your data only with the following categories, to the minimum extent necessary, and under agreements that bind them to confidentiality and data protection:
- Hosting, infrastructure and email providers that run the website and our systems.
- Providers of the file-management, booking and invoicing systems used by the center.
- Analytics providers, only if you have consented to analytics cookies.
- Messaging platforms you choose to contact us through, such as WhatsApp, which are subject to their own privacy policies.
- Specialists and consultants working with the center, bound by a duty of confidentiality, to the extent the child's case requires.
- Legal and financial advisers and auditors where needed, within professional confidentiality.
- Official, judicial and regulatory authorities where there is a legal obligation or an order issued by a competent authority, after we have verified that the request is lawful.
- Any party the parent or guardian authorises in writing, such as the child's specialist, school or insurer.
In the event of a restructuring, merger or transfer of ownership of the center, data may be transferred to the successor entity provided it commits to this policy, and we will inform you in advance.
Transfers of data outside your country
Your data may be stored on servers of providers located outside Jordan or the UAE, and limited data may be exchanged between the two branches for administrative coordination and to ensure continuity of care when a family moves between the two countries.
For any cross-border transfer we commit to the following:
- Choosing providers that apply internationally recognised protection standards, and concluding data-processing agreements with them containing contractual data-protection clauses.
- Ensuring that the receiving country provides an adequate level of protection, or applying additional safeguards such as encryption and standard contractual clauses.
- Complying with any restrictions local law places on transferring health data outside the country, including the requirements of the UAE federal law on the use of information technology in health fields.
- Obtaining your explicit consent where the law requires it.
How long we keep data
We keep data only for as long as necessary to fulfil the purpose it was collected for, or for the period the law requires, whichever is longer. Indicative periods:
- Contact messages and inquiries that do not become a rehabilitation file: 24 months from the last contact.
- Incomplete or cancelled booking data: 12 months.
- The child's rehabilitation file: for the duration of the service, then for the period required by the laws governing health and rehabilitation records in the relevant country, which in the UAE extends to no less than 25 years from the date of the last procedure.
- Trainee records and certificates: for the duration of the program, then 10 years for certificate verification purposes.
- Published photos and videos: until consent is withdrawn or the period specified in it ends.
- Financial records and invoices: the period required by the tax and accounting laws of the relevant country.
- Analytics data: anonymised and kept for a maximum of 14 months.
- The cookie-consent cookie: 6 months.
When the period ends we securely delete the data or anonymise it so that it can no longer be linked to any person. We review retention periods regularly.
How we protect your data
We apply technical and organisational measures appropriate to the nature and sensitivity of the data, including:
- Encryption in transit (HTTPS/TLS) across the whole website and messaging channels, and encryption at rest for rehabilitation files.
- Access control on the "minimum necessary" principle with role-based permissions, and two-factor authentication for sensitive systems.
- Audit logs for every access to or modification of rehabilitation files.
- Regular encrypted backups and data-recovery plans.
- Confidentiality agreements signed by all staff and collaborators, and regular training on data protection and information security.
- A data-protection impact assessment before any new system or tool that processes children's data is introduced.
- Periodic review of providers and systems, software updates and prompt patching of vulnerabilities as soon as they are discovered.
No system can be 100% secure, but we commit to due diligence and to continuously updating our procedures. On your side, we advise against sending detailed health information over unencrypted channels, and we recommend that you only communicate with the official numbers and email address published on our contact page.
Data breach notification
If a security breach affecting your personal data occurs, we immediately take the necessary steps to contain and investigate it.
- We notify the competent supervisory authority within 72 hours of becoming aware of the breach, wherever the law requires it.
- We notify you directly and without undue delay if the breach poses a risk to your rights or your child's rights, explaining the nature of the breach, the measures we have taken and what you can do.
- We document every incident and draw from it whatever is needed to improve our procedures.
Cookies and similar technologies
The website uses necessary cookies to operate and to remember your choice in the consent panel, and optional analytics cookies that are only enabled with your consent. We currently use no marketing or advertising cookies.
You can change your choice at any time from the "Cookie settings" button in the footer. Full details, including cookie names and durations, are set out in the Cookie Policy.
Third-party services and links
The website contains links to and embeds from third-party services whose practices we do not control, each with its own independent privacy policy:
- YouTube videos: they are not loaded and do not connect to YouTube's servers until you click the video yourself.
- Google Maps: loaded automatically on the contact and branch pages to show the center's location, and Google may receive your IP address when that happens. The full text address is always shown next to every map.
- WhatsApp: when you choose to message us through it, the conversation is subject to WhatsApp's privacy policy in addition to this one.
- Social media: your interaction with our pages on Instagram, Facebook or YouTube is subject to those platforms' policies.
- Any other links to external websites are provided for convenience only, and we accept no responsibility for their practices.
Marketing communications
We send marketing messages only if you have consented, or if you are an existing client and the message concerns services similar to those you have received. In both cases you can unsubscribe at any time via the link in the message or by contacting us. We never send marketing material to children, and we never use health data for marketing purposes.
Your rights
As a data subject, or as a parent or guardian acting on behalf of your child, you have the following rights under the applicable laws:
- The right to be informed: to know whether we process your data, for what purpose, and who we share it with.
- The right of access: to obtain a copy of your data in a clear and readable form.
- The right to rectification: to correct any inaccurate data or complete what is missing.
- The right to erasure ("the right to be forgotten"): to request deletion of your data where there is no legal obligation or overriding legitimate interest to retain it.
- The right to restriction: to ask us to freeze the use of your data in certain situations, such as when you contest its accuracy.
- The right to data portability: to receive your data in a structured, commonly used format and transfer it to another party.
- The right to object: to processing based on legitimate interest, and to direct marketing at any time without giving reasons.
- The right to withdraw consent: at any time, without affecting the lawfulness of earlier processing.
- The right not to be subject to a fully automated decision: and to request human intervention and review of any result produced by an automated tool.
- The right to lodge a complaint: with us or with the competent supervisory authority.
To exercise any of these rights, write to info@eicadd.com explaining your request. We may ask you to verify your identity, and your status as parent or guardian where the request concerns a child's data, in order to protect the data from unauthorised access. We respond within 30 days of receiving the request. This period may be extended in complex cases, and we will inform you if so. Exercising your rights is free of charge unless a request is manifestly repetitive or excessive.
Legal frameworks and standards we comply with
This policy and our procedures are designed to comply with the laws applicable in the two countries where we operate, and with the best international standards:
- Jordan's Personal Data Protection Law No. 24 of 2023 and the regulations issued under it.
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields.
- The EU General Data Protection Regulation (GDPR) and the equivalent UK regulation, when we deal with families resident there.
- The US HIPAA privacy and security standards for health information, as a best-practice reference, although we are not a covered entity under it.
- The principles of children's online privacy protection: we collect no data from children and direct no marketing content at them.
- Information-security best practice under the international standard ISO/IEC 27001, as a guiding framework for our procedures.
Where these frameworks conflict, we always apply the rule that protects you and your child the most.
Right to lodge a complaint
If you are not satisfied with the way we handle your data, please write to us first at info@eicadd.com so that we can resolve the matter as quickly as possible. You also have the right at any time to lodge a complaint with the competent supervisory authority:
- In Jordan: the Personal Data Protection Council and the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship.
- In the UAE: the UAE Data Office, or the competent health authority in respect of health data.
- In the European Union or the United Kingdom: the data-protection authority of your country of residence.
Changes to this policy
We may update this policy from time to time to reflect changes in our services or in the law. The date of the most recent update is always shown at the top of the page. If a change is material and affects how we use your data, we will inform you by an appropriate means, such as a prominent notice on the website or a direct message, and we will ask for your consent again where the law requires it. We recommend that you review this page periodically.
How to contact us
For any question, request or complaint relating to privacy or to this policy, contact our data protection officer:
- Email: info@eicadd.com
- UAE branch, Ajman: +971 585 260 608. Villa 1, Altala Street, Almuntazi 1, Ajman.
- Jordan branch, Amman: +962 779 308 282. Building 224, Alqods Center, Wasfi Al-Tal Street, Khalda, Amman.
Please put "Privacy request" in the subject line so that we can handle it faster.