The short version
This website does not ask you to create an account, and it does not hold your medical record. What it collects is the small amount of information you type into it — an enquiry, a newsletter address — plus the technical data any website receives in order to answer a request.
- We never sell your data, and we run no advertising trackers.
- Nothing that identifies you is sent to a third party until you have said yes.
- Your consultation itself happens on WhatsApp, which is a service run by Meta, not by us — section 6 explains exactly what that means for you.
- You can ask for a copy of everything we hold, or ask us to delete it, and we answer within 30 days.
This notice covers the website
Your clinical record — what a doctor writes during a consultation, your prescriptions and your test results — is held under the clinic's own patient-confidentiality rules and the duties the Pakistan Medical & Dental Council places on Dr Hammad Aslam, MBBS (Diabetologist). Ask at reception for a copy of that record.
Who is responsible
Aslam Clinic & Sugar Center decides why and how the information described here is used. In data-protection language, we are the controller.
- Registered address
- Mohalla Masjid Siddique, Circular Road, Jalalpur Jattan 50780, Gujrat, Punjab, Pakistan
- Privacy officer
- the clinic's privacy officer
- Privacy email
- privacy@aslam.clinic
- Phone
- +92 308 0429292
- Representative in the EU or UK
- None appointed. The clinic operates from Pakistan and offers no goods or services targeted at the EU or UK market; write to the privacy officer above.
What we collect, and why
Everything below is collected because you did something that needs it. There is no background profiling.
| What | When | Why | Our lawful basis |
|---|---|---|---|
| Your name, email address and message | When you send the contact form | So a person at the clinic can read your question and reply to it | Consent, which you give by ticking the box on the form |
| Your email address | When you subscribe to the newsletter | To send the health newsletter you asked for, and nothing else | Consent, confirmed by clicking the link in the email we send |
| Your name, email address and the request itself | When you submit a data request | To identify you well enough to answer safely, and to prove we answered in time | Legal obligation — we must be able to show a request was handled |
| The medicines in your basket | While you browse the pharmacy | So your basket survives moving between pages | Necessary for the service you asked for. It is stored on your own device, not on our servers |
| Your consent choice | When you answer the cookie banner | So we do not ask again, and so we can prove what you agreed to | Legal obligation — a consent we cannot evidence is not a consent |
| IP address, browser type, the page requested and the time | On every request, in server logs | Keeping the site up, blocking abuse, and rate-limiting the contact form so it cannot be used to send spam | Legitimate interest in keeping a health service online and unabused |
Please do not send us health details through this website
The contact form is a general enquiry channel. It is not encrypted end to end and it is not part of your medical record. If you need to describe a symptom, a diagnosis or a medicine you are taking, use WhatsApp on +92 308 0429292 or speak to us at the clinic.
What we deliberately do not do
The absences matter as much as the collections, so they are stated rather than left to be inferred:
- No advertising or marketing trackers of any kind — no Meta pixel, no Google Ads tag, no remarketing.
- No analytics product is installed on this site. Not Google Analytics, not any alternative.
- No profiling, no behavioural scoring, and no automated decision that has a legal or similarly significant effect on you.
- No sale, rental or sharing of your data with data brokers. Not now, and not as a future option we are keeping open.
- No purchase of contact lists. Every address on our newsletter was typed in by the person who owns it.
Who else sees it
We use a small number of suppliers to run the site. Each one is bound by a contract to process data only on our instructions, and each is listed here so you can look them up yourself.
| Supplier | What they do | Where the data sits |
|---|---|---|
| Vercel Inc. | Serves this website and keeps short-lived request logs | United States and global edge locations |
| MongoDB, Inc. (Atlas) | The database holding enquiries, subscriptions and consent records | The region configured for this deployment |
| Cloudflare, Inc. (R2) | Stores the images and documents shown on the site | Global object storage |
| Google LLC (Workspace / SMTP) | Delivers the emails the site sends and receives | United States |
| Upstash, Inc. | Rate-limits the forms so they cannot be used to send bulk spam | Region configured for this deployment |
| Meta Platforms, Inc. (WhatsApp) | Carries the conversation you choose to start with the clinic | United States and global |
Beyond these, we disclose information only where the law requires it — a court order, a lawful demand from a regulator, or a genuine emergency in which someone's life is at risk.
Data that leaves the country
Pakistan has not been recognised by the European Commission as offering an equivalent level of protection, and several of the suppliers above are based in the United States. That means data moves across borders, and you are entitled to know on what footing.
- Transfers to our suppliers rely on the European Commission's Standard Contractual Clauses, or on the supplier's certification under the EU–US Data Privacy Framework where it holds one.
- We keep the amount of data that crosses a border as small as the service allows — the site collects a name, an email address and a message, not a medical history.
- PMDC's code of conduct prohibits moving patient information to another jurisdiction without informed consent. We treat that as binding for clinical data, which is why clinical data is not held on this website at all.
Write to privacy@aslam.clinic and we will tell you which safeguard applies to a specific supplier and send you a copy of it.
WhatsApp, honestly
This clinic runs on WhatsApp: you book on it, you are told your turn on it, and your prescription comes back on it. That is a genuine convenience and it carries a genuine trade-off, which we would rather state plainly than bury.
- The contents of your messages are encrypted end to end, so Meta cannot read them. This is real protection and it is not nothing.
- The metadata is not protected in the same way: Meta knows that your number messaged the clinic's number, when, and how often. For a clinic, the fact of contact is itself sensitive.
- A copy of the conversation sits on your phone and on the clinic's phone. Anyone who can unlock either device can read it. Lock your phone.
- Meta does not offer a data-processing agreement covering clinical use of consumer WhatsApp, so the responsibility for what is sent through it stays with us and with you.
- Backups are the weak point. If your WhatsApp backs up to iCloud or Google Drive without end-to-end encryption switched on, your clinic conversation is in that backup. Turning on encrypted backups is worth the two minutes.
You are never required to use WhatsApp
Walk in during opening hours (Mon & Wed 4:00–8:00 PM · Sat 10:00 AM–5:00 PM) or telephone +92 308 0429292. You will not be treated differently, and nothing about your care depends on having a smartphone.
The full WhatsApp notice, including what the automated assistant does with a message before a human reads it, is at /legal/whatsapp.
Automated assistance
An automated assistant answers the clinic's WhatsApp line outside consulting hours and triages routine messages during them. It is a scheduling and routing tool. It does not diagnose you, it does not prescribe, and it never makes a decision about your care on its own.
- You are told you are talking to an automated assistant at the start of the conversation.
- You can ask for a human at any point and one will pick the conversation up during opening hours.
- Anything the assistant flags as urgent is escalated to a clinician rather than answered.
- No automated decision is made about you that has a legal or similarly significant effect, so the profiling rules in Article 22 of the GDPR are not engaged.
The AI Transparency Notice at /legal/ai sets out what the assistant can and cannot do, who supplies it, and how to complain about an answer it gave.
How long we keep things
Every category below has an end date, and a scheduled job enforces it against the database rather than trusting anyone to remember. The full reasoning for each window is at /legal/data-retention.
| Record | What it holds | Why it is kept | How long | What happens then |
|---|---|---|---|---|
| Website enquiries | Name, email address, subject and the message text. | Answering the question that was asked, and following it up. | 3 months | Deleted — Deleted 90 days after the enquiry, once it can no longer be an open conversation. |
| Newsletter subscriptions (active) | Email address, the date consent was given and how it was given. | Sending the health newsletter that was asked for. | Until it is withdrawn | Kept by design — Kept while the subscription is live. Ends the moment someone unsubscribes. |
| Newsletter opt-outs | Email address and the fact that it opted out. | Making sure an address that left is never re-added by an import. | Until it is withdrawn | Kept by design — A suppression record is kept indefinitely. Deleting it would allow the address to be re-subscribed by mistake, which is the harm the opt-out was meant to prevent. |
| Newsletter send records | Subject, body and the list of addresses a send targeted. | Answering 'what did you send me, and when?'. | 2 years | Identifiers stripped — After two years the addresses are stripped and only the counts and the copy remain, which is enough to answer the question without keeping a mailing list nobody needs. |
| Administrative audit trail | Admin identity, the action taken, IP address and browser string. | Detecting and investigating unauthorised access to the console. | 2 years | Deleted — Two years of security forensics. Longer would keep IP addresses past any plausible investigation. |
| Consent records | What was agreed to, the policy version, the time, and a hashed identifier. | Proving that a consent was freely given, specific and informed. | 3 years | Deleted — Three years. Consent proof has to outlive the consent, because it is needed after a dispute starts, not before. |
| Data-subject requests | The requester's name and email, what they asked for, and what was done. | Showing that rights requests were answered inside the deadline. | 3 years | Deleted — Three years, so a pattern of unanswered requests is visible to an auditor rather than erased by the next sweep. |
How it is protected
- Everything travels over HTTPS, and the site instructs browsers to refuse an unencrypted connection to it for the next two years.
- The admin console is reachable only with a password, and every action taken inside it is written to an audit trail with the account, the time and the address it came from.
- Admin passwords are stored as bcrypt hashes. Nobody at the clinic can read yours, and neither can we.
- The forms are rate-limited, and every field is validated and sanitised before it reaches the database.
- A strict content-security policy blocks scripts and frames the site did not ask for, which is what stops an injected advert or tracker from running.
- Access to the console is limited to staff who need it, and is removed the day someone stops needing it.
If you have found a weakness in this site, please tell us at security@aslam.clinic. The disclosure policy at /legal/security explains what we promise in return.
Your rights
These rights are yours under the GDPR if you are in the EU or the UK, and we extend the same rights to everyone who uses this site regardless of where they live — including patients in Pakistan, whose statutory rights are still working their way through Parliament.
- Access
- Ask for a copy of everything we hold about you.
- Rectification
- Have anything wrong corrected.
- Erasure
- Ask us to delete it, unless a law or a live dispute requires us to keep it — in which case we tell you which.
- Restriction
- Ask us to stop using something while a disagreement about it is resolved.
- Portability
- Receive what you gave us in a machine-readable file you can take elsewhere.
- Objection
- Object to any use we base on legitimate interest, and to marketing at any time and without giving a reason.
- Withdrawing consent
- Withdraw a consent whenever you like. It does not undo what was lawful beforehand, and it never affects your care.
- Complaint
- Complain to us, and to a supervisory authority, without going through us first.
Use the form at /legal/data-request, or write to privacy@aslam.clinic. We answer within 30 days and we do not charge. We will ask you to confirm your identity — not to make it difficult, but because handing your data to someone claiming to be you is the failure we are trying to avoid.
Children
The clinic treats children, and their care is arranged by a parent or guardian. This website is not designed for a child to use on their own: the forms should be completed by an adult, and we do not knowingly collect information from anyone under sixteen without a guardian involved.
If you believe a child has sent us something, write to privacy@aslam.clinic and we will remove it.
If something goes wrong
A suspected breach reaches the privacy officer within 24 hours of being noticed, is assessed the same day, and — where there is a real risk to you — is reported to the relevant supervisory authority within 72 hours and told to you directly without undue delay. We will say what happened, what it means for you, and what we have done about it. The full procedure is at /legal/governance.
Complaining
Tell us first if you can: complaints@aslam.clinic, and you will hear from a person within 5 days. You do not have to, and you never lose a right by trying.
- In the EU or the UK, complain to your national data-protection authority — the Information Commissioner's Office in the UK, or your own country's authority in the EU.
- In Pakistan, matters of clinical care and clinic conduct can be raised with Punjab Healthcare Commission: https://www.phc.org.pk/
- Unauthorised access to a computer system is an offence under the Prevention of Electronic Crimes Act 2016 and can be reported to the FIA's Cybercrime Wing.
Changes to this notice
Every version carries a number and a date, both printed at the top of this page. A change to wording bumps the minor number. A change to what we actually do with your data — a new purpose, a new recipient, a longer retention window — bumps the major number, and where you had consented, we ask you again rather than assuming the old answer still holds. This notice is read end to end at least every 12 months.