Last updated: 6 August 2026
This page provides a general overview and is not a substitute for legal advice.
1. Who we are & scope
Intel Lab Diagnostics LLC ("Intel Lab", "we", "us", "our") is a Dubai Health Authority–licensed medical laboratory (DHA License 0046381) operating in the United Arab Emirates. We are the data controller responsible for the personal information described in this policy.
This policy applies to this website and to the bookings, enquiries, and accounts you make through it. Your clinical testing and results are additionally handled by our laboratory under UAE healthcare regulation, as described in sections 5 and 6.
2. Information we collect
- Identity & contact data: name, email, phone number, and the delivery/collection address you provide.
- Booking & enquiry data: the tests or packages you request, appointment details, and any message you send us through the website, hotline, or WhatsApp.
- Health data: the tests and packages you book, sample collection details, and the diagnostic results generated by our laboratory. Health data is sensitive personal data and is given a higher level of protection.
- Account data: login credentials and booking history when you create an account.
- Payment data: payments are processed by our payment provider (see section 7); we do not store your full card details on our systems.
- Technical data: device, browser, and usage information collected via cookies and similar technologies (see section 12).
3. How we use your information
We process your information to:
- Fulfil bookings, arrange sample collection, run tests, and deliver diagnostic results;
- Respond to enquiries and provide customer support;
- Take payment and issue invoices or receipts;
- Operate, secure, and improve our website and services;
- Meet our legal, regulatory, and clinical record-keeping obligations, including reporting to health authorities where required.
4. Legal basis & consent
We process personal data on the basis of your consent, the performance of our contract with you, our legitimate interests in operating the laboratory, and our legal obligations as a DHA-licensed provider. Health data is processed only where permitted under the PDPL and the ICT Health Law and with appropriate safeguards. Where we rely on consent, you may withdraw it at any time, subject to our legal record-keeping duties for clinical records.
5. Where your data is stored
Clinical & diagnostic records. Your test orders and results are held within our Laboratory Information System (LIS) on secured premises in the United Arab Emirates, in line with UAE health-data requirements. Access is restricted to authorised laboratory personnel.
Website booking & enquiry data. The identity, contact, and booking information you submit through this website is handled by reputable cloud service providers that help us operate the site, as described in section 7. Some of this infrastructure may be located outside the UAE; where that is the case, the data is protected in transit and at rest by encryption and by contractual safeguards with those providers. This website infrastructure does not hold your clinical laboratory records.
6. Sharing your information & NABIDH
We do not sell your personal data. We share it only in the following circumstances:
- Health authorities (NABIDH): as a DHA-licensed facility, we are required to share relevant patient and result data with the Dubai Health Authority's NABIDH health information exchange, which supports safe, connected care across licensed providers in Dubai.
- Service providers: the specialist technology providers described in section 7, plus sample-logistics partners, under confidentiality and data-protection obligations, and only for the purposes we specify.
- Legal & regulatory: where required by law, regulation, or a competent authority, or to protect our legal rights.
- With your direction: for example, when you ask us to share a report with a referring physician.
7. Our technology service providers
We rely on a small number of specialist technology providers, each engaged for a specific function and identified here by that function. Each processes personal data only on our documented instructions, under contracts imposing confidentiality, security, and data-protection obligations consistent with the PDPL, and each maintains its own published privacy and security commitments and recognised international security certifications. A current list of providers is available on request via the contact details in section 16.
- The hosting & content-delivery provider serves the website from a secure global network and protects it against attacks and malicious traffic, including automated bot-protection challenges on our forms. It processes technical data such as IP addresses and request metadata.
- The authentication & database provider operates our secure login service and stores your account, profile, booking, and enquiry data. Passwords are stored only in hashed form, never as plain text.
- The payment provider processes card payments under the PCI DSS security standard. Your full card details are entered directly with, and held by, the payment provider — they never touch our systems. We receive only a payment confirmation and limited reference data, such as the card's last four digits.
- The email delivery provider sends transactional messages — booking confirmations, status updates, reminders, and account emails — to the address you provide.
- The address-lookup service suggests buildings and addresses as you type your collection address; the text you type into that field is processed by the mapping service to return suggestions.
- The analytics service collects aggregated usage statistics, subject to your cookie consent, to help us understand and improve the site. It is configured not to build profiles of identified individuals.
- The session-replay and heatmap services record how visitors move through the site — clicks, scrolling, and mouse movement — subject to your cookie consent, so we can find pages that are confusing or broken. Text on pages that show personal or health information is masked in your browser before the recording is sent, and what you type into forms is never captured. One of the two providers also runs an advertising network, and alongside its own analytics cookies it sets that network's identifiers, which can be used to measure advertising performance.
- The error-monitoring service collects technical diagnostics when something goes wrong on the site so we can find and fix the fault.
- The media storage provider stores the images and content files displayed on this website; it does not receive your personal data.
Where any of these providers processes data outside the UAE, section 8 applies. None of them receives your clinical laboratory records, which remain in our on-premises Laboratory Information System (section 5).
8. International data transfers
Where website booking or enquiry data is processed outside the UAE by our infrastructure or service providers (see sections 5 and 7), we take steps required under the PDPL to ensure an adequate level of protection, including contractual safeguards and encryption. Your clinical laboratory records are maintained within the UAE.
9. Data retention
We retain clinical and diagnostic records for the minimum period required by UAE healthcare regulations, and other personal data only for as long as necessary for the purposes set out in this policy or to meet our legal obligations. When data is no longer required, it is securely deleted or anonymised.
10. How we protect your data
We use technical and organisational measures to protect your data, including encryption in transit and at rest, role-based access controls, and access limited to authorised personnel. Diagnostic reports are reviewed and signed off by a qualified pathologist before release. No system is completely secure, but we work to protect your information and to respond promptly to any incident in line with our legal obligations and the procedure in section 11.
11. Data breach response & notification
A "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data.
Our response plan. We maintain an incident-response procedure. If we become aware of a suspected breach we will promptly: (a) contain the incident and secure the affected systems; (b) assess the nature and scope of the data involved and the likely risk to the individuals concerned; (c) investigate the root cause; and (d) take corrective measures to prevent recurrence.
Notification. Where required by the PDPL, we will notify the UAE Data Office of a breach that risks the privacy or security of your personal data. Where a breach is likely to result in a serious risk to you, we will also notify you without undue delay, describing the nature of the breach, the categories of data concerned, the likely consequences, the measures we have taken, and practical steps you can take to protect yourself. Where a breach involves health information, we will additionally notify the competent health authorities as required by the ICT Health Law and DHA requirements.
Incidents at service providers. Our contracts require each provider described in section 7 to notify us without undue delay of any breach affecting our data and to cooperate fully in containment, investigation, and notification. In such cases we follow the same assessment and notification process set out above. Responsibility for a breach occurring within a provider's own infrastructure rests with that provider under its contractual and legal obligations; our responsibility is limited to our own acts and omissions — including our duty to select reputable providers and contract appropriate safeguards — to the maximum extent permitted by UAE law.
Records. We keep an internal record of personal data breaches, their effects, and the remedial action taken, and make it available to the competent authorities on request.
Reporting a concern. If you suspect a breach or misuse of your data, please contact us immediately using the details in section 16 — prompt reports help us contain incidents quickly.
12. Cookies & analytics
We use essential cookies to operate the site — including those set by the bot-protection challenge that keeps our forms safe — and, with your consent, analytics cookies to understand how the site is used so we can improve it (see section 7 for how the analytics service handles this data). You can manage your choice through the consent banner shown on your first visit and adjust your browser settings at any time. Disabling non-essential cookies will not affect your ability to book.
The analytics cookies you consent to also enable session-replay and heatmap services, which record a playback of your visit — the pages you view, and your clicks, scrolling, and mouse movement — so we can see where the site is confusing or broken. They are never loaded unless you accept; declining stops the recording entirely. Pages that display personal or health information are masked in your browser before anything is sent — the booking flow, your bookings and profile, the cart, and the sign-in pages — and what you type into forms is never captured. These recordings are processed outside the UAE under the safeguards described in section 8. One of them also sets identifiers belonging to its provider's advertising network; like the rest, they are set only if you accept analytics cookies, and never if you decline.
13. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, withdraw consent, and request a copy of your data. To exercise these rights, contact us using the details in section 16. We will respond within the timeframes required by the PDPL. If you are not satisfied with our response, you may raise the matter with the UAE Data Office or the relevant health authority.
14. Children & minors
Testing of a minor is arranged and consented to by a parent or legal guardian, who is responsible for the minor's information provided to us. We handle a minor's health data with the same care and confidentiality as any other patient's.
15. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "last updated" date above, and where appropriate we will notify you.
16. Contact us
For any privacy question or request — including to exercise your rights or to report a suspected data security incident — email info@intel-lab.ae, call our 24/7 hotline on +971 58 845 4335, or reach us via our contact page. This policy should be read together with our Terms of Service.
