Hôpital Al Shifa
Effective Date: 17 August 2026
Last Updated: 17 August 2026
Applies to: Al Shifa Hospital Website, Patient Mobile Application (iOS and Android), Facebook/Meta Applications and Integrations, X (Twitter) Developer Integrations, and related digital services
1. Introduction
Hôpital Al Shifa ("Al Shifa", "Hospital", "we", "our", or "us") is committed to protecting the privacy, confidentiality, integrity, and security of the personal and health information entrusted to us.
This Privacy Policy explains how Al Shifa collects, uses, stores, processes, shares, protects, and deletes personal information when patients, visitors, healthcare professionals, or other users interact with:
Healthcare information is particularly sensitive. Al Shifa applies enhanced confidentiality and security controls to medical and health-related information.
- the Al Shifa Hospital website;
- the Al Shifa patient mobile application for Android;
- the Al Shifa patient mobile application for iOS;
- Al Shifa's Facebook/Meta applications and integrations;
- Al Shifa's X (formerly Twitter) developer applications and integrations; and
- other Al Shifa digital services that link to this Privacy Policy.
2. Information We May Collect
The information collected depends on the Al Shifa service or functionality used.
2.1 Identity and Contact Information
We may collect:
- full name;
- patient or medical record number;
- date of birth;
- gender;
- nationality;
- identification or passport information where required;
- mobile telephone number;
- email address;
- address;
- emergency contact information; and
- other information necessary to identify or communicate with you.
2.2 Health and Medical Information
When you use patient-related digital services, we may process health information including:
- medical history;
- diagnoses;
- allergies;
- medications and prescriptions;
- laboratory orders and results;
- radiology orders, reports, and related information;
- appointments;
- physician and clinical notes;
- procedures and treatment information;
- vital signs;
- vaccination information;
- clinical documents;
- referrals;
- discharge information; and
- other information forming part of your medical record.
2.3 Appointment and Healthcare Service Information
We may collect information regarding:
- requested appointments;
- selected physicians or specialties;
- appointment dates and times;
- appointment status;
- cancellations and rescheduling;
- referrals; and
- communications associated with healthcare services.
2.4 Account Information
Where users create a digital account, we may process:
- username;
- email address;
- mobile number;
- account identifiers;
- authentication information;
- account preferences; and
- login and security records.
2.5 Device and Technical Information
Our digital services may automatically collect certain technical information, including:
- IP address;
- device type;
- operating system and version;
- application version;
- browser type;
- device identifiers where permitted;
- login timestamps;
- application activity;
- diagnostic information;
- crash information; and
- security and audit logs.
2.6 Communications
When you communicate with Al Shifa electronically, we may process information contained in:
- contact forms;
- support requests;
- emails;
- SMS communications;
- approved messaging services;
- feedback;
- complaints; and
- other communications initiated by you or required for delivering healthcare services.
3. How We Use Personal Information
Al Shifa may use personal information to:
- provide healthcare and hospital services;
- identify and authenticate patients and users;
- create and maintain patient records;
- manage appointments;
- provide access to medical information;
- facilitate prescriptions, laboratory, radiology, pharmacy, and other clinical services;
- send appointment confirmations and reminders;
- communicate important healthcare or service information;
- provide requested digital services;
- respond to questions and support requests;
- operate and maintain our website and mobile applications;
- protect patient accounts and hospital systems;
- prevent fraud, misuse, and unauthorized access;
- maintain security and audit records;
- investigate technical or security incidents;
- improve the quality, reliability, and performance of our services;
- comply with applicable laws, regulations, court orders, and lawful government requirements; and
- protect the rights, safety, property, and legitimate interests of patients, staff, and Al Shifa.
4. Healthcare Confidentiality
Al Shifa treats patient medical information as confidential.
Access to medical information is restricted according to professional responsibilities, authorized roles, legitimate healthcare purposes, operational requirements, and applicable legal obligations.
Hospital employees, healthcare professionals, contractors, and authorized service providers with access to confidential information are expected to comply with applicable confidentiality and information-security requirements.
5. Sharing and Disclosure of Information
Al Shifa does not sell patient medical records or personal information.
We may disclose information where reasonably necessary to:
- physicians and authorized healthcare professionals involved in your care;
- laboratories, pharmacies, radiology providers, and other authorized healthcare service providers;
- healthcare information-system and technology providers supporting hospital operations;
- hosting, cloud, infrastructure, cybersecurity, communications, and technical service providers;
- insurance or payment organizations where applicable and authorized;
- professional advisers, auditors, and regulators;
- public authorities where disclosure is legally required; or
- other parties where you have provided valid authorization or consent.
6. International Data Processing
Some technology providers supporting Al Shifa's digital services may operate infrastructure or provide technical services from jurisdictions outside Djibouti.
Where personal information is transferred or remotely processed outside Djibouti, Al Shifa will take reasonable measures to ensure that appropriate confidentiality, security, contractual, and data-protection safeguards are applied according to applicable requirements.
7. Information Security
Al Shifa maintains administrative, organizational, physical, and technical measures designed to protect personal information against unauthorized access, accidental loss, unlawful disclosure, alteration, destruction, misuse, and cyber threats.
No electronic system can be guaranteed to be completely secure. Al Shifa continuously works to manage and reduce information-security risks.
8. Data Retention
Al Shifa retains personal and medical information only for as long as reasonably necessary for healthcare delivery, continuity of patient care, medical-record requirements, legal and regulatory obligations, contractual requirements, billing and financial requirements, security and audit purposes, and legitimate hospital operational requirements.
Deletion of a digital account does not necessarily require deletion of information that Al Shifa is legally, medically, or regulatorily required to retain as part of the official patient medical record.
9. Your Privacy Rights and Choices
Subject to applicable laws, medical-record requirements, and identity verification, users may request to access, correct, update, or delete eligible personal information, withdraw consent where applicable, or ask questions about how their information is processed.
Al Shifa may verify the identity of a person submitting a privacy request before disclosing, modifying, or deleting information.
10. Account Deletion
Users of Al Shifa digital applications who have created an account may request deletion of their account through the available account-management functionality or through the privacy/contact mechanism provided by Al Shifa.
Detailed instructions are published at https://hopital-alshifa.dj/account-deletion
Deleting an application from a mobile device does not by itself delete the user's Al Shifa account or hospital medical record.
11. Website Privacy
When visiting the Al Shifa website, certain information may automatically be processed, such as IP address, browser type, pages visited, timestamps, device information, and security logs.
Al Shifa may use cookies or similar technologies where necessary to operate website functionality, maintain security, remember user preferences, understand website performance, and improve digital services.
12. Android / Google Play Privacy
The Al Shifa Android application may request access to device features only where required for specific application functionality, including camera, file access, notifications, network access, and biometric authentication where supported and voluntarily enabled.
Information disclosed in the application's Google Play Data Safety section should be consistent with the actual data practices described in this Privacy Policy.
13. Apple iOS Privacy
The Al Shifa iOS application may request access to device functionality only where needed to provide an application feature, including camera, photos or files, notifications, and biometric authentication such as Face ID or Touch ID.
Al Shifa will disclose applicable data collection practices through Apple's App Privacy information in App Store Connect.
14. Biometric Authentication
Where the application allows Face ID, Touch ID, fingerprint, or another device-based biometric method for authentication, biometric verification is generally performed by the user's operating system or device.
Unless explicitly stated otherwise, Al Shifa does not receive or store the user's underlying fingerprint or facial biometric template merely because device biometric authentication is used to access the application.
15. Push Notifications
Users may receive notifications concerning appointments, appointment reminders, service updates, account security, healthcare-related communications, and other relevant hospital services.
Sensitive medical details should be minimized in lock-screen notifications where reasonably possible.
16. Facebook / Meta Applications
Where Al Shifa uses Meta or Facebook developer services, the integration may process information permitted by the user and provided by Meta according to the permissions granted to the application.
Al Shifa will request only permissions necessary for the relevant functionality, use Meta-provided information only for disclosed and authorized purposes, and not sell Meta user information.
17. Facebook / Meta User Data Deletion
A user who has authorized an Al Shifa Facebook/Meta application may request deletion of information received through that integration.
Data deletion instructions are published at https://hopital-alshifa.dj/data-deletion
18. X (Formerly Twitter) Developer Integration
Where Al Shifa uses the X platform or X developer APIs, information obtained through the integration will be processed only for the authorized functionality and in accordance with applicable X developer requirements.
Disconnecting an X account will terminate future authorized access where applicable but may not automatically delete information that Al Shifa is legally required to retain.
19. Third-Party Services and SDKs
Al Shifa's website or applications may rely on third-party technologies for cloud hosting, authentication, push notifications, analytics, crash reporting, cybersecurity, communications, and healthcare information-system integration.
20. Analytics and Tracking
Al Shifa may use privacy-appropriate analytics to understand application reliability, performance, errors, and general usage.
Al Shifa does not authorize third-party analytics providers to use identifiable patient medical information for their independent advertising purposes.
21. Children's Privacy
Al Shifa provides healthcare services that may include care for children.
Personal or medical information concerning minors is handled according to applicable healthcare, consent, guardianship, confidentiality, and legal requirements.
22. Emergency and Medical Disclaimer
Al Shifa digital services are intended to support access to hospital services and information and are not necessarily suitable for emergency medical communication.
Users experiencing a medical emergency should use the appropriate emergency medical services or contact the Hospital through its designated emergency channels.
23. Links to External Services
Al Shifa digital services may contain links to external websites or services. Once a user leaves an Al Shifa-controlled digital service, the privacy practices of the external provider may apply.
24. Consent and Withdrawal
Where processing requires consent, Al Shifa will seek consent through an appropriate mechanism.
Users may withdraw consent for applicable future processing. Withdrawal does not invalidate processing that lawfully occurred before consent was withdrawn.
25. Changes to This Privacy Policy
Al Shifa may update this Privacy Policy to reflect changes in hospital services, application functionality, technology, third-party integrations, legal requirements, or platform requirements.
The "Last Updated" date at the beginning of this Policy will identify the latest revision.
26. Privacy and Data Protection Contact
Questions, concerns, complaints, account-deletion requests, or other privacy requests may be submitted to:
Hôpital Al Shifa Al Shifa Hospital, Route de Venise, Djibouti City, Republic of Djibouti Privacy / Data Protection Contact: Mohamed.salah@hopital-alshifa.dj Phone: +253 77290246 General Contact: +253 21 32 85 00 | info@alshifamc.com Website: https://hopital-alshifa.dj Patient Portal: https://patientportal.hopital-alshifa.dj
For privacy requests, please include sufficient information to identify the relevant account or service. Do not send passwords or unnecessary medical information by unsecured email.
27. Platform-Specific Privacy Resources
For deployment and developer-account purposes, Al Shifa publishes the following publicly accessible web resources:
- Main Privacy Policy: https://hopital-alshifa.dj/privacy-policy
- Account & Personal Data Deletion: https://hopital-alshifa.dj/account-deletion
- Facebook/Meta Data Deletion Instructions: https://hopital-alshifa.dj/data-deletion
28. Governing Principles
Al Shifa's processing of personal information is governed by applicable laws and regulations of the Republic of Djibouti and, where applicable, other data-protection requirements relevant to the services provided.
Privacy Commitment: Hôpital Al Shifa is committed to maintaining the confidentiality, integrity, availability, and appropriate use of patient and personal information across its clinical and digital services.
Mohamed Salah Elkhodary — Chief Information Officer, Hôpital Al Shifa

