← Back

Privacy Policy

Version 1.0 · Effective date: 2025 · Governed by UAE Federal Decree-Law No. 45 of 2021 (PDPL)

1. Who We Are

EM Blueprint ("we", "us", "our") is an online examination preparation platform for medical professionals. We are committed to protecting your personal data in accordance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and all applicable regulations.

For any privacy-related enquiries, contact us at: privacy@emblueprint.com

2. Data We Collect

We collect only the data necessary to provide and improve the platform.

CategoryData collectedPurpose
Account data Full name, email address, password (hashed) Authentication and account management
Usage data Questions answered, options selected, time taken, session dates Tracking your progress and generating performance analytics
Device fingerprint Anonymous browser/device identifier (no IP address, no location) Detecting multi-device account sharing (security)
Consent records Date/time of Terms and Privacy Policy acceptance, version numbers Legal compliance and dispute resolution
Access code The access code used at registration Linking your account to the correct question bank

We do not collect your IP address, precise location, phone number, or payment card details (payments are processed directly by our payment provider).

3. How We Use Your Data

We use your personal data solely for the following purposes:

  • Providing access to the platform and your question bank
  • Displaying your personal progress statistics and performance analytics
  • Detecting and preventing unauthorised account sharing
  • Sending transactional emails (account confirmation, security alerts, subscription notices)
  • Maintaining records of your consent to our legal agreements
  • Complying with applicable laws and regulations

We do not use your data for advertising, profiling for third-party purposes, or automated decision-making that produces legal effects.

4. Watermarking Disclosure

Dynamic watermark: All question content displayed to you is overlaid with a dynamic watermark containing your account email address, a short user ID, and the current date. This is used to identify unauthorised sharing or reproduction of platform content. The watermark is a security measure and does not constitute collection of additional personal data beyond what you have already provided.

5. Device Security Monitoring

To protect the integrity of your account and our content, we record an anonymous device fingerprint each time you log in. This fingerprint does not contain your IP address or location. It is used only to detect if your account is being accessed from an unusually high number of devices, which may indicate credential sharing.

Device fingerprint data is automatically deleted after 90 days of inactivity.

6. Legal Basis for Processing

Under the UAE PDPL, we process your personal data on the following legal bases:

  • Contract performance: Processing necessary to provide the subscription service you have purchased
  • Consent: Where you have expressly agreed (e.g., watermarking, security monitoring)
  • Legitimate interests: Security monitoring, fraud prevention, and platform improvement
  • Legal obligation: Where required by UAE law

7. Data Sharing

We do not sell, rent, or trade your personal data. We may share data only in the following limited circumstances:

  • Service providers: Supabase (database and authentication infrastructure, hosted in data centres compliant with applicable law). These providers process data solely on our behalf under data processing agreements.
  • Payment processors: If you make a purchase, payment data is handled directly by our payment provider (Stripe or equivalent). We do not receive or store card numbers.
  • Legal requirements: If required by a UAE court order, regulatory authority, or applicable law.

8. Data Retention

Data typeRetention period
Account data (name, email)Duration of subscription + 2 years after termination
Usage data (attempts, sessions)Duration of subscription + 1 year
Device fingerprints90 days from last login
Consent records5 years (legal compliance)
Security event logs1 year

9. Your Rights

Under the UAE PDPL, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Delete your personal data (subject to legal retention obligations)
  • Restrict the processing of your data in certain circumstances
  • Withdraw consent where processing is based on consent (note: this may affect your ability to use the platform)
  • Lodge a complaint with the UAE Data Office if you believe your rights have been infringed

To exercise any of these rights, contact us at privacy@emblueprint.com. We will respond within 30 days.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Passwords stored using industry-standard hashing (bcrypt via Supabase Auth)
  • All data transmitted over HTTPS/TLS
  • Row-level security policies ensuring users can only access their own data
  • Session tokens that expire after 30 minutes of inactivity
  • One active session per account at any time

11. Cookies

We use strictly necessary cookies and local storage for session management and security purposes. For full details, please read our Cookie Policy.

12. Children's Data

This platform is intended solely for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has registered, contact us immediately at privacy@emblueprint.com and we will delete the account.

13. Changes to This Policy

We will notify you by email of any material changes to this Privacy Policy. Where required by law or where changes are significant, we will ask for your re-consent before you can continue using the platform. The effective date at the top of this page indicates when the current version was last updated.

14. Governing Law

This Privacy Policy is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). Any disputes are subject to the exclusive jurisdiction of UAE courts.

© 2025 EM Blueprint. All rights reserved. · Terms and Conditions · Cookie Policy