Privacy Policy
Effective Date: January 25, 2026
1. Introduction
KhadKhod is a software-as-a-service (SaaS) company specializing in healthcare and education. We are committed to protecting the privacy, confidentiality, and security of personal information, including personal health information, collected through our platforms in accordance with applicable law and, where required, with the informed consent of users.
This Privacy Policy describes how KhadKhod collects, uses, stores, discloses, and safeguards personal and health-related information in compliance with applicable privacy and data protection laws, including Ontario’s Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy legislation.
By accessing or using KhadKhod’s services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein, subject to your rights under applicable law.
2. What Information We Collect
KhadKhod collects and processes personal and health-related information only to the extent necessary to deliver, operate, and improve our healthcare and education software services, support learning and analytics, and conduct research where permitted by law and consistent with user consent or other lawful authority.
User-provided personal and health-related information, which may include educational background, training and learning activity data, and, where applicable, health-related information such as clinical case inputs, simulated or real diagnoses, treatment plans, medication information, and outcome data entered by users for educational or analytical purposes.
Platform and usage information, including interaction logs, feature usage patterns, technical performance metrics, and aggregated insights used to maintain, improve, and secure the platform and enhance user experience.
Research and analytical information, including aggregated, anonymized, or de-identified datasets used for academic research, product development, validation, and insights generation, in accordance with applicable privacy and data protection laws.
KhadKhod does not intentionally collect direct personal identifiers such as government-issued identification numbers (e.g., Social Insurance Numbers), financial information, precise location data, or covert surveillance information. Any personal or health-related information processed is limited to what is reasonably necessary for the stated purposes and handled in accordance with applicable law.
3. How We Use the Data
KhadKhod does not sell personal information or personal health information (PHI). We use such information only for legitimate and lawful purposes, with user consent where required, or as otherwise permitted or required by applicable law, and in a manner consistent with the delivery, operation, and improvement of our healthcare and education software services.
Permitted uses include:
Providing, operating, maintaining, and improving KhadKhod’s healthcare and education platforms, including personalized learning features, analytics, and core system functionality.
Supporting educational, clinical, and research activities, including the use of aggregated or de-identified data for academic research, model development, validation, and quality improvement.
Producing evidence-based insights to enhance healthcare education, clinical decision-support tools, and overall product performance, without identifying individual users.
Maintaining platform security, detecting and preventing fraud or misuse, ensuring system integrity, and meeting legal, regulatory, and contractual obligations.
Prohibited uses include:
Selling, marketing, or otherwise commercially exploiting personal or health-related information.
Linking datasets in a manner that could reasonably lead to the identification of an individual without explicit user consent and, where applicable, required ethics or institutional approvals.
Attempting to re-identify anonymized or de-identified information, except where required by law or expressly authorized under applicable legal frameworks.
4. Data Security and Protection Measures
KhadKhod implements reasonable administrative, technical, and organizational safeguards designed to protect personal and health-related information against unauthorized access, disclosure, alteration, loss, or misuse.
Security measures include:
Encryption of data in transit and at rest using industry-standard cryptographic protocols, where appropriate.
Use of secure hosting and infrastructure environments with access controls, monitoring, and logging consistent with industry best practices and applicable regulatory requirements.
Role-based access control (RBAC) to restrict access to information based on job function and the principle of least privilege.
Periodic security reviews, audits, and privacy impact assessments proportionate to the sensitivity and volume of data processed.
Incident detection, response, and breach management procedures aligned with applicable legal, regulatory, and contractual obligations.
5. Data Access and Sharing
KhadKhod maintains a data governance framework to ensure that access to and sharing of information are limited, controlled, and consistent with user consent, contractual obligations, and applicable law.
Parties who may access KhadKhod data include:
Authorized users, such as students, educators, researchers, or healthcare professionals, accessing their own information or platform features in accordance with their assigned role.
Authorized KhadKhod personnel and service providers who require access to perform operational, maintenance, security, or support functions, subject to confidentiality and data protection obligations.
Researchers or institutional partners who are granted access to aggregated or de-identified information for approved educational or research purposes, where required approvals have been obtained.
KhadKhod does not permit advertisers, data brokers, insurers, or other unauthorized third parties to access personal or health-related information.
6. Compliance with Privacy and Data Protection Laws
KhadKhod is committed to complying with applicable privacy and data protection laws in the jurisdictions in which it operates. Depending on the context, KhadKhod may act as a data controller or as a service provider or processor on behalf of institutional partners, in accordance with applicable law and contractual arrangements.
Compliance measures include:
Purpose limitation and data minimization practices to ensure information is collected, used, and disclosed only for clearly defined and lawful purposes.
Application of anonymization or de-identification techniques where personal identification is not necessary for the intended purpose.
Internal governance controls and approval processes for data access, sharing, retention, and cross-border processing, as required under applicable law.
7. Individual Rights and Data Management
KhadKhod respects the rights of individuals with respect to their personal and health-related information, subject to applicable legal requirements and limitations.
These rights may include:
The right to access information about how personal data is collected, used, and disclosed through the platform, subject to applicable exceptions.
The right to request correction of inaccurate or incomplete personal information, where permitted by law.
The right to withdraw consent or request deletion or anonymization of personal information, subject to legal, contractual, and operational requirements.
8. Changes to This Privacy Policy
KhadKhod may update this Privacy Policy from time to time to reflect changes in technology, legal or regulatory requirements, business practices, or security standards.
Material changes will be communicated through our website or platform. Continued use of KhadKhod’s services following the effective date of an updated Privacy Policy constitutes acceptance of the revised policy, to the extent permitted by law.