Sehtak Acceptable Use Policy
Version: 1.1 Effective date: 2026-06-08 Document URL: https://sehtak.ae/legal/aup
This Acceptable Use Policy ("AUP") is incorporated into the Sehtak Terms of Service ("Terms", at sehtak.ae/legal/terms). Breach of this AUP is a material breach of the Terms and entitles Sehtak to suspend or terminate access without notice.
Defined terms not defined here have the meanings given in the Terms.
1. Clinical and Regulatory Conduct
You must not use the Services to:
1.1 Provide medical advice, diagnose, prescribe, dispense, or perform a regulated health activity unless you are a UAE-licensed practitioner acting within the scope of your licence.
1.2 Practise outside the licensed scope of your facility's UAE health-authority licence (DHA, DOH, MOHAP, or SHA).
1.3 Use the Services from a facility whose licence has lapsed, been suspended, or been revoked.
1.4 Prescribe or dispense controlled substances via telehealth, in violation of UAE Federal Decree-Law 38/2024. Controlled-substance dispensing must follow the in-person processes mandated by UAE law and DHA / MOHAP regulation.
1.5 Use the Services to deliver telehealth services unless the facility has registered the Sheryan telehealth add-on (or its DOH / MOHAP equivalent) and uploaded the certificate for Sehtak verification, and unless the practitioner conducting the telehealth encounter holds a current telehealth-eligible licence and complies with DHA Telehealth Standards V4 (or its successor) and the equivalent DOH / MOHAP standards.
1.5a Engage in any practice violating UAE Federal Decree-Law No. 4 of 2023 (Medical Liability Law), including without limitation: practising outside scope, falsifying a clinical record, abandoning a patient mid-encounter, or failing to maintain the standard of care of a reasonably competent practitioner in the same specialty.
1.5b Publish, transmit, or facilitate health-related advertising that violates Cabinet Decision No. 31 of 2022 on the Regulation of Health Advertising, including without limitation: unsubstantiated outcome claims, before/after photos used in a misleading way, miracle-cure claims, comparative advertising that disparages another licensed practitioner, or any advertisement that has not been pre-approved by the competent UAE health authority where pre-approval is required.
1.6 Submit any insurance claim, NABIDH / Malaffi / Riayati submission, or regulatory report that is inaccurate, incomplete, misleading, or fraudulent.
1.7 Misrepresent the source of an AI-generated output as a manually-written note when communicating with a patient, regulator, payer, or third party. AI Scribe drafts must be reviewed, edited where necessary, and accepted by a licensed practitioner before they become part of the medical record, and the record must reflect the practitioner's professional judgement, not the AI's verbatim output.
2. Patient and Data Conduct
You must not:
2.1 Access another patient's record, another facility's data, or any part of the Services you are not authorised to access.
2.2 Share login credentials, multi-factor authentication seeds, recovery codes, or session tokens with anyone, including other staff at the same facility — every staff member must have their own account.
2.3 Bypass, attempt to bypass, or assist anyone in bypassing identity-verification (UAE Pass SOP3, eKYC), MFA, role-based access controls, tenancy boundaries, or feature gates.
2.4 Upload, store, or transmit any content that you do not have the right to share, including content that infringes a third party's intellectual property, privacy, or confidentiality.
2.5 Upload malware, viruses, or any code intended to disrupt or compromise the Services or other users.
2.6 Use the Services to harass, threaten, defame, or discriminate against any patient, staff member, or other user.
2.7 Solicit, groom, or otherwise target a minor through the Services.
2.8 Use the patient family-link feature for anyone other than a minor in your legal custody or an adult who has expressly granted you the right to manage their account.
2.9 Export, copy, or transmit Customer Data (including PHI) outside the UAE except through Sehtak-provided functionality and with a lawful basis under PDPL Articles 22–24.
3. Security and Platform Conduct
You must not:
3.1 Reverse engineer, decompile, disassemble, derive the source code of, or extract the model weights of any part of the Services.
3.2 Scrape, crawl, or otherwise extract bulk data from the Services without an explicit written API agreement with Sehtak.
3.3 Probe, scan, or test the vulnerability of the Services without prior written authorisation under Sehtak's responsible-disclosure programme.
3.4 Conduct, encourage, or facilitate a denial-of-service attack, including through excessive automated requests beyond the rate limits Sehtak publishes for your tier.
3.5 Use the Services as a relay or proxy for any other system, traffic, or content.
3.6 Use the Services to develop, train, or improve a competing product or service, or to extract Sehtak's outputs to train a third-party machine-learning model.
3.7 Circumvent any tier limit, feature gate, doctor-seat cap, AI Scribe-seat cap, fair-use limit, or geographic restriction in the Services.
3.8 Misrepresent your identity, your facility's identity, your facility's licensure status, or any insurance, payer, or patient information in your interactions with the Services.
4. Communications Conduct
You must not use the Services to:
4.1 Send unsolicited marketing communications in violation of UAE Telecommunications and Digital Government Regulatory Authority ("TDRA") rules, the UAE Do-Not-Call registry, or PDPL marketing-consent requirements.
4.2 Send any communication that includes clinical content (diagnoses, lab values, prescription details, sensitive health context) over WhatsApp templates that are routed via Meta US infrastructure. Use the in-app patient view for clinical content.
4.3 Send communications to patients who have withdrawn their marketing consent or who appear on the TDRA Do-Not-Call list.
4.4 Use Sehtak's WhatsApp Business templates in any way other than the approved use Sehtak has registered with the relevant BSP and Meta.
4.5 Send phishing, fraud, scam, or other illegal communications, or use the Services to facilitate any of the foregoing.
4.6 Spoof sender IDs, impersonate another facility or doctor, or otherwise misrepresent the origin of a communication.
5. Payment, Billing, and Fraud Conduct
You must not:
5.1 Process payments through the Services for goods or services other than those reasonably incidental to the facility's regulated healthcare activities (medical services, pharmacy fulfilment, related supplies).
5.2 Process payments on behalf of any third party that is not the facility itself, unless under an Order Form expressly permitting it.
5.3 Conduct or facilitate money laundering, terrorist financing, sanctions evasion, or any other financial crime, in violation of UAE Federal Decree-Law 20/2018, Cabinet Resolution 74/2020, or the UAE Local Terror List.
5.4 Issue refunds, chargebacks, or credits in a manner intended to defraud Sehtak, the payment processor, an insurer, or a patient.
5.5 Misrepresent fees, surcharges, or processor fees to patients, or charge patients a separate Sehtak surcharge.
5.6 Submit insurance claims with knowingly inaccurate diagnostic codes, procedure codes, drug codes, or claim amounts.
6. AI Misuse
You must not use the Services to:
6.1 Generate falsified clinical documentation, retrospectively backdate records, or use AI to produce records of encounters that did not occur.
6.2 Substitute AI output for the professional judgement of a licensed practitioner where UAE law or DHA / DOH / MOHAP regulation requires practitioner judgement.
6.3 Use AI-generated translation as a substitute for a qualified medical interpreter where the law or clinical safety requires one.
6.4 Use AI receptionist, AI voice agent, or any AI-driven communication feature to provide medical advice to patients without practitioner review.
6.5 Use AI features to generate marketing content that contains misleading clinical claims, miracle-cure claims, or unsubstantiated outcome guarantees in violation of UAE advertising rules and Cabinet Decision 31 of 2022 on health advertising.
7. Consequences
7.1 Suspension. Sehtak may suspend access to all or part of the Services immediately and without prior notice if Sehtak has a credible basis to believe a breach of this AUP has occurred or is imminent.
7.2 Termination. Sehtak may terminate the Terms under §15 of the Terms.
7.3 Account-wide suspension on Facility breach. If a Facility breaches this AUP through the conduct of one or more of its staff, Sehtak may suspend the Facility account as a whole, not only the individual staff account, while the breach is investigated.
7.4 Cooperation with authorities. Sehtak will cooperate with UAE law enforcement, the UAE Data Office, and the relevant UAE health authorities in respect of any conduct that may breach UAE law, including by producing audit-log extracts and account records under lawful request.
7.5 No refund on termination for AUP breach. Termination for breach of this AUP under Terms §15.3 does not entitle the Facility to a refund of prepaid fees.
8. Reporting Violations
If you become aware of a breach of this AUP by another user, report it to abuse@sehtak.ae. If you discover a security vulnerability in the Services, report it to security@sehtak.ae under Sehtak's responsible-disclosure programme.
Sehtak FZ-LLC · Meydan Free Zone · Dubai · United Arab Emirates