Privacy & data protection policy
How we collect, use, protect, retain, and transfer personal data.
Effective date: 9 September 2026. This is a UAE-first international privacy baseline. Privacy obligations vary by location and circumstances; references to international laws apply only where those laws govern the processing concerned.
1. Who we are and scope
You Recruit (https://yourecruit.care ) is operated by KPM Global Services UAE (“You Recruit”, “we”, “us”, or “our”), based in Dubai, United Arab Emirates. We are the controller or responsible organisation for personal data processed through this website and our licensing, recruitment, exam-support, facility, and advisory services, except where another organisation determines the purposes and means of processing.
This policy applies to visitors, enquirers, candidates, healthcare professionals, customers, facility representatives, suppliers, and business contacts. Read it with our terms of service and cookie policy .
2. Laws and privacy frameworks
Our primary framework is UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) and its implementing requirements. Where applicable to particular processing, we also address the EU General Data Protection Regulation (“GDPR”), UK GDPR and Data Protection Act 2018, California Consumer Privacy Act as amended by the CPRA, and other mandatory national or state privacy, direct-marketing, consumer, and electronic-communications laws. DIFC or ADGM rules apply only where the relevant establishment or processing falls within those jurisdictions.
These references do not mean every law applies to every visitor or that KPM Global Services UAE is established in each jurisdiction. Mandatory rights available under the law governing your data are not restricted.
3. Personal data we collect
- Identity and contact: name, email, telephone, country, address, and language.
- Professional: CV, profession, specialty, qualifications, licences, employment, references, eligibility, exam, and application status.
- Credentials: passport details, certificates, registrations, Good Standing Certificates, DataFlow/PSV references, and authority correspondence when required.
- Transactions: selected service, invoice, payment status, refund, and support history. Complete card details are handled by the payment provider and are not intentionally stored by us.
- Communications: forms, consultation notes, email, telephone, WhatsApp, feedback, complaints, and consent records.
- Technical and usage: IP address, browser, device, approximate location, referral source, pages, timestamps, security logs, and browser-storage choices.
- Business: employer, facility, supplier, ownership, project, workforce, and authorised-representative information.
4. Sensitive data and patient information
Credentials, identity documents, biometric identifiers appearing on documents, health information, and criminal or disciplinary history may receive enhanced protection. We process such data only where necessary and lawful—for example, with explicit consent, to establish or defend legal claims, to meet employment or regulatory obligations, or as otherwise permitted by law.
Do not send patient records, clinical photographs, medical reports, or identifiable patient data through website forms, WhatsApp, or ordinary email. We are not a healthcare provider through this website and do not request protected health information for general enquiries. Where a specific business engagement requires regulated health data, separate written safeguards must be agreed first. HIPAA applies only if a covered-entity or business-associate relationship is expressly established; this website does not create one.
5. How and why we use data
- Respond to enquiries and provide consultations, quotations, purchased services, support, and refunds.
- Assess licensing or job readiness and coordinate applications, PSV, recruitment, onboarding, and facility projects when instructed.
- Administer exam-package access, customer records, invoices, fraud prevention, and service messages.
- Manage candidates, clients, consultants, suppliers, contracts, complaints, and legal claims.
- Secure, troubleshoot, measure, and improve the website and services.
- Send requested updates or lawful marketing with an available opt-out.
- Meet regulatory, tax, accounting, employment, sanctions, anti-fraud, and law-enforcement obligations.
6. Legal bases
Depending on the law and processing, we rely on consent; steps requested before a contract; performance of a contract; legal obligations; vital or public interests where legally available; and legitimate interests such as responding to business enquiries, recruiting candidates, securing systems, preventing fraud, improving services, and defending claims. Where we rely on legitimate interests, we consider necessity, proportionality, and your rights. Withdrawing consent does not affect processing already lawfully completed.
7. Sources
We collect data from you; authorised representatives; employers, recruiters, referees, educational and licensing institutions; public professional sources; regulators and verification providers; and our technology, communications, analytics, scheduling, and payment providers. If you provide another person's data, you must be authorised and provide any required notice.
8. Disclosure and processors
We disclose only what is reasonably necessary to UAE health authorities; DataFlow or other verification bodies; exam or study-platform operators; employers and facilities; consultants and professional advisers; payment, hosting, email, CRM/CMS, scheduling, analytics, security, cloud, and communications providers; and public authorities where legally required. Depending on enabled features, providers may include SendGrid, Notion or Sanity, Google Analytics, Calendly, WhatsApp/Meta, LinkedIn, our payment provider, and Coolify hosting infrastructure.
We do not sell personal data for money or share it for cross-context behavioural advertising. We do not intentionally use sensitive data to infer characteristics. Data may be disclosed during a merger, financing, reorganisation, or sale under confidentiality and notice requirements. Regulatory or employer submissions are made with your instruction or another lawful basis.
9. International transfers
The UAE is our primary operating location. Providers, authorities, employers, or source institutions may process data elsewhere. Where transfer restrictions apply, we use an approved adequacy mechanism, contractual safeguards such as standard contractual clauses, consent or another permitted derogation, and supplementary security measures as appropriate.
10. Retention
- General enquiries and inactive marketing contacts: normally up to 24 months after last meaningful contact.
- Unsuccessful candidate records: normally up to 24 months unless another period is agreed or required.
- Active licensing, recruitment, facility, customer, and credential files: for the engagement and a reasonable claims or compliance period afterward.
- Contracts, invoices, transactions, tax, consent, complaint, and legal records: generally up to seven years or the applicable statutory period.
- Security logs and analytics: for the shortest period reasonably needed for security and measurement.
We may retain data longer for a legal hold, dispute, regulator request, safeguarding concern, or documented obligation. We then delete, anonymise, or securely archive it. Backup deletion may occur on a delayed cycle.
11. Security and breach response
We use proportionate administrative, contractual, technical, and physical safeguards, including access controls, least-privilege handling, secure hosting and transmission, confidentiality, backups, monitoring, and vendor review. Internet and email transmission cannot be guaranteed completely secure. We assess, contain, and document personal-data breaches and notify competent authorities and affected people where and within the time required by law.
12. Cookies and similar technologies
Necessary browser storage remembers consent preferences and lead-popup state. Optional analytics is activated only after consent where required. We do not currently use advertising cookies. See our cookie policy and settings .
13. Your privacy rights
Subject to applicable law, identity verification, and lawful exceptions, you may request:
- confirmation, access, and a copy of personal data;
- correction, deletion, or restriction;
- data portability in a usable format;
- withdrawal of consent and objection to direct marketing or legitimate-interest processing;
- information about sources, purposes, recipients, retention, safeguards, and qualifying automated decisions;
- human review of a solely automated decision producing legal or similarly significant effects; and
- non-discriminatory treatment for exercising protected rights.
We do not currently make solely automated decisions producing legal or similarly significant effects. California residents may exercise applicable disclosure, deletion, correction, opt-out, limitation, and non-discrimination rights. Because we do not sell or share information for cross-context behavioural advertising, no sale/share opt-out is presently required. We honour recognised opt-out signals where legally required and technically applicable.
Email healthcare@kpmglobal.ae with “Privacy Request”. We may request proportionate identity or authority evidence. Authorised agents may apply where permitted. We respond within the applicable legal period and explain any extension, refusal, fee, or exception.
14. Marketing
Service messages necessary to an enquiry or contract are not marketing. Unsubscribe using the message link or contact us to stop promotions. We may retain minimal suppression data to respect your opt-out.
15. Children
Our services are intended for adults aged 18 and over. We do not knowingly collect children's data or sell or share data of people under 18. A parent or guardian who believes a child submitted data should contact us for review and deletion.
16. Third-party services
External authority portals, study platforms, social networks, schedulers, payment services, and employer systems have their own privacy terms. We are not responsible for their independent processing.
17. Complaints
Please contact us first so we can investigate. Where applicable, you may complain to the UAE Data Office or another competent UAE authority, your EU/EEA supervisory authority, the UK Information Commissioner's Office, the California Privacy Protection Agency or Attorney General, or another regulator with lawful jurisdiction.
18. Changes
We may update this policy for legal, vendor, or service changes. The effective date identifies the current version. Material changes will be highlighted or communicated directly where required.
19. Contact
Privacy Lead, KPM Global Services UAE
You Recruit · Dubai, United Arab Emirates
healthcare@kpmglobal.ae · +971 55 249 0091
This policy provides transparency and is not a substitute for jurisdiction-specific legal advice or required contractual data-processing terms.