Privacy Policy
Sofira · getsofira.com · Operated by RSfit OÜ, Estonia · Effective 24 September 2026
1. Who we are and what this policy covers
1.1 This policy explains how RSfit OÜ (“we”, “us”, “our”), a private limited company (osaühing) registered in the Republic of Estonia under registry code 17602521, with its registered office at Raua põik 3, Kesklinn, Tallinn, Harju County, Estonia, handles personal data when you use getsofira.com and the landing pages we operate under it (together, the “Platform”).
1.2 We are the data controller for the limited data described in Section 4. We are established in the European Union, so the EU General Data Protection Regulation (GDPR) applies to everything we do. Because the Platform is directed at people in the United Arab Emirates, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) applies as well. Where the two differ, we apply the stricter rule.
1.3 This policy does not cover the Partner Facilities you may book with through the Platform. Each is a separate, licensed healthcare provider and a separate data controller with its own privacy notice (Section 8).
1.4 Capitalised terms have the meaning given in our Terms of Service. This policy takes effect on 24 September 2026.
2. The short version
We do not collect your name, contact details or anything about your health. The Suitability Check runs in your browser and its answers never leave your device. When you book with a Partner Facility, you give your details to them, not to us. Here is everything we do process:
| What | Why | How long |
|---|---|---|
| Server logs: IP address, browser type, pages requested, time | Keep the Platform running and secure | 30 days |
| Ad-click parameter in the URL (e.g. a click ID from Meta) | Tell the Partner Facility that a booking came from us | 90 days in logs |
| Language preference | Show the site in English or Arabic | On your device only (local storage) |
| Emails you send us | Reply to you | 12 months |
3. What we deliberately do not collect
3.1 We do not collect, receive, store or process Health Information. That includes your answers to the Suitability Check, any symptom, condition, medication, goal or concern you have, and any information you later give to a Clinician.
3.2 The Suitability Check is a program that runs entirely in your web browser. Your answers are held only in your browser’s memory while you complete it and are discarded when you leave the page. They are not sent to our servers, not stored in cookies and not visible to us. We cannot recover them for you.
3.3 We do not operate any booking, registration or contact form that collects your name, email address, phone number or Emirates ID. Every such form on the Platform is served by, and submits directly to, the Partner Facility named next to it, from infrastructure located in the UAE.
3.4 We do not use analytics, session-replay, heat-mapping or error-reporting tools, and in particular none that capture what you type.
3.5 Because we hold no Health Information, we are not a party subject to Federal Law No. 2 of 2019 on the use of ICT in health fields. Partner Facilities are, and the health data you give them stays with them inside the UAE.
4. The data we do process
4.1 Server logs. When your browser requests a page, our hosting provider Vercel Inc. records your IP address, browser and operating system, the page requested, the referring page and the time. These logs exist to detect abuse and diagnose faults.
4.2 Analytics. We do not currently use any analytics service. If we introduce one, it will be cookieless and aggregate, and we will update this policy before it goes live (Section 14).
4.3 Ad-click parameters. If you arrive from an advertisement on Meta (Facebook, Instagram) or Google, the link may carry a click identifier such as fbclid or gclid and our own campaign code. These appear in the page address and therefore in our server logs. When you continue to a Partner Facility’s booking form, we pass our campaign code (never the platform’s click identifier) into the link so the Partner Facility can tell us that a booking originated from the Platform.
4.4 Language preference. If you switch between English and Arabic, we store that choice in your browser’s local storage. It never reaches our servers.
4.5 Correspondence. If you email hello@getsofira.com or any other address we publish, we process your email address, your name if you give it and the content of your message in order to reply. Please do not include Health Information; if you do, we will delete the message once we have redirected you to the Partner Facility.
5. Why we process it and on what legal basis
| Processing | Purpose | GDPR basis | PDPL basis |
|---|---|---|---|
| Server logs | Security, fault-finding, abuse prevention | Legitimate interests (art. 6(1)(f)) | Legitimate interests of the controller (art. 4(1)) |
| Ad-click parameters | Attributing bookings to our marketing under our agreements with Partner Facilities | Legitimate interests (art. 6(1)(f)) | Legitimate interests (art. 4(1)) |
| Language preference | Displaying the Platform in your language | Strictly necessary for the service you request; stored on your device only | Necessary to provide the service |
| Correspondence | Replying to you | Legitimate interests, or performance of a contract where you are asking about the Terms (art. 6(1)(b),(f)) | Necessary to respond to your request |
5.1 We have balanced each legitimate interest against your rights and concluded that the processing is minimal, expected and low-risk. You may object at any time (Section 12).
5.2 We do not process special-category data (GDPR art. 9) or sensitive data (PDPL art. 1) of any kind, by design.
5.3 We do not make decisions about you by automated means that have legal or similarly significant effects. The Suitability Check produces an indication only, on your device, and no Partner Facility receives it.
6. Cookies and similar technologies
6.1 We do not set advertising, tracking or analytics cookies, and we do not show a cookie banner because there is nothing to consent to.
6.2 We use one item of browser local storage, lang, to remember your language choice. It contains only the value en or ar, never leaves your device and can be cleared through your browser settings.
6.3 Our hosting provider may set a strictly necessary cookie for load-balancing or security. Such cookies contain no personal data beyond a random session token and expire when you close your browser.
6.4 Partner Facility booking forms are embedded or linked from the Platform. Any cookies they set are governed by that Partner Facility’s privacy notice, not by this policy.
7. Advertising platforms
7.1 We place advertisements on Meta platforms (Facebook, Instagram) and may place them on Google. When you see or click an advertisement, Meta or Google processes data about you as an independent controller under its own privacy policy: Meta Privacy Policy and Google Privacy Policy. We do not control that processing.
7.2 We do not install the Meta Pixel, Google Ads tag, Google Analytics or any other advertising or measurement script on the Platform. We do not send events, page views, form contents or any other data about you back to Meta or Google, and we do not use their custom-audience, remarketing or lookalike features.
7.3 We measure advertising results in two ways only: aggregate click counts reported to us by the advertising platform, and the number of bookings each Partner Facility reports to us as carrying our campaign code. The Partner Facility’s report contains counts, not names.
7.4 We do not target advertising on the basis of any health condition, interest or attribute. Advertisements are targeted by location (UAE) and broad demographic settings only.
7.5 You can control the advertisements you see through Meta’s and Google’s own ad-preference settings.
8. Partner Facilities as independent data controllers
8.1 When you proceed from the Platform to book a consultation, you leave our processing and enter the Partner Facility’s. The Partner Facility is the data controller for everything you give it: your identity and contact details, your Emirates ID or passport details if requested, your Health Information, your consultation record, any prescription and any payment.
8.2 Partner Facilities are licensed healthcare providers in the UAE and are bound by UAE law on health data, including Federal Law No. 2 of 2019, the PDPL and the rules of their licensing authority. Their booking forms and records are hosted in the UAE.
8.3 We are not a joint controller with any Partner Facility. We do not receive your booking, your record or any Health Information from them. The only data that flows from a Partner Facility to us is an aggregate count of bookings carrying our campaign code.
8.4 Each Partner Facility’s privacy notice applies from the moment you open its form:
| Partner Facility | Licensing authority | Privacy notice |
|---|---|---|
| Dubai Health – Telemedicine | Dubai Health Authority (DHA) | dubaihealth.ae |
8.5 To access, correct or delete data a Partner Facility holds about you, contact that Partner Facility. If you write to us instead, we will tell you whom to contact; we cannot act on the request ourselves because we do not hold the data.
9. Where your data is stored and international transfers
9.1 The Platform is hosted by Vercel Inc. and served from its global edge network; server logs are stored in the United States. Email sent to our addresses is handled by Namecheap, Inc. (email forwarding) in the United States.
9.2 Because you are in the UAE and our processors are in the United States, the limited data described in Section 4 is transferred from the UAE to the United States. Under the PDPL, transfers out of the UAE are permitted to countries with an adequate level of protection or under appropriate safeguards; we rely on the safeguards described in Section 9.3. No Health Information is ever transferred, because we never hold any.
9.3 Transfers from us, as an EU controller, to processors in the United States are made under the EU–US Data Privacy Framework where the processor is certified under it, and otherwise under the European Commission’s standard contractual clauses.
9.4 Our processors, all bound by written data-processing agreements under GDPR art. 28:
| Processor | Role | Location |
|---|---|---|
| Vercel Inc. | Hosting, server logs | United States (global edge network) |
| Namecheap, Inc. | Domain and email forwarding | United States |
9.5 We do not sell personal data and we do not share it with anyone else, except where required by a lawful order of a court or authority with jurisdiction over us.
10. How long we keep data
| Data | Retention | Then |
|---|---|---|
| Server logs | 30 days | Deleted automatically |
| Server logs containing an ad-click parameter | 90 days, to reconcile Partner Facility booking reports | Deleted automatically |
| Emails | 12 months from last message | Deleted |
| Emails containing Health Information | Until we have replied with the Partner Facility’s contact | Deleted immediately after |
| Rights requests and our responses | 3 years, to evidence compliance | Deleted |
10.1 Where a legal claim is reasonably anticipated, we may keep the specific data relevant to it for as long as the claim is live.
11. Security
11.1 The Platform is served only over HTTPS. Access to server logs and email is limited to named staff with multi-factor authentication. Our hosting provider holds recognised security certifications (ISO 27001 and SOC 2 Type 2).
11.2 The most important security measure is architectural: we do not hold the data that would be most harmful if lost. There is no database of users, no store of Health Information and no payment data on our systems.
11.3 If a personal-data breach affecting you were to occur, we would notify the Estonian Data Protection Inspectorate within 72 hours as required by GDPR art. 33, notify the UAE Data Office as required by the PDPL, and tell you directly where the breach is likely to result in a high risk to you.
12. Your rights and how to use them
12.1 Under both the GDPR and the PDPL you have the right to:
- be told what data we hold about you and receive a copy (access);
- have inaccurate data corrected;
- have your data deleted where we no longer need it or you object;
- restrict our processing while a dispute is resolved;
- object to processing based on legitimate interests, including the ad attribution described above;
- receive the data you gave us in a portable format;
- not be subject to a solely automated decision with legal or similar effect (we make none);
- withdraw consent where processing is based on it (currently nothing is);
- complain to a supervisory authority (Section 15).
12.2 In practice, because we hold no account, no profile and no Health Information, an access request will usually return at most log lines matching an IP address you supply, and any emails you have sent us. We will tell you plainly if we hold nothing.
12.3 To exercise a right, email hello@getsofira.com. We may ask you to confirm the email address or IP address concerned so that we do not disclose data to the wrong person. We respond within one month under the GDPR and within the period required by the PDPL, whichever is shorter, and we do not charge a fee unless a request is manifestly unfounded or excessive.
12.4 Requests about data held by a Partner Facility must go to that Partner Facility (Section 8.5).
13. Children
The Platform is for adults aged 18 or over and is not directed at children. We do not knowingly process data about anyone under 18. Because we collect no identity data, we cannot verify age on the Platform; Partner Facilities verify age and identity before providing any consultation. If you believe a child has used the Platform, contact hello@getsofira.com.
14. Changes to this policy
14.1 We will update this policy when the Platform, our processors or the law change. The current version and its effective date are always at getsofira.com/privacy; earlier versions are available on request.
14.2 Any change that would mean we start collecting personal data we do not collect today, in particular any form submitted to our servers or any advertising script, will be announced on the Platform at least 14 days before it takes effect and will not apply to data collected before that date.
15. Contact and complaints
15.1 If you are unhappy with how we have handled your data or a request, you may complain to:
- Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, www.aki.ee, our lead supervisory authority under the GDPR;
- UAE Data Office, the supervisory authority under the PDPL, through the channels published at u.ae;
- the data-protection authority of any EU member state where you live or work.
15.2 Complaints about a Partner Facility’s handling of your health data go to that Partner Facility first, then to its licensing authority: DHA (Dubai), DoH (Abu Dhabi) or MOHAP (other emirates).
15.3 This policy is written in English. An Arabic version may be published at getsofira.com/privacy/ar; until then the English text is the operative version.
15.4 Data controller:
RSfit OÜ
Raua põik 3, Kesklinn, Tallinn, Harju County, Estonia
Registry code: 17602521
Email: hello@getsofira.com