Bahrain Blood
Donor Network
Legal

Privacy Policy

Last updated 22 April 2026. Compliant with the Personal Data Protection Law (PDPL) of the Kingdom of Bahrain.

1. Who we are

Bahrain Blood Donor Network (the “Platform”) is owned and operated by MSS Technology Company W.L.L (Commercial Registration pending), Manama, Kingdom of Bahrain. For all data-protection inquiries, contact contact@bahrainblood.com.

2. What we collect

  • Identity: full name (English + optional Arabic), date of birth, gender, nationality.
  • Contact: email, Bahrain mobile number.
  • Medical: blood group, last donation date, donation history you voluntarily log.
  • Location: area of residence (city, not GPS).
  • Identity verification (optional): CPR number — stored AES-256-GCM encrypted; only the first four digits are visible to admins; images are deleted after verification.
  • Account security: bcrypt-hashed password (we never see your plaintext).
  • Operational metadata: timestamps, session tokens, notification preferences.

3. How we use it

  • Match you with nearby patients who need your blood type in an emergency, urgent, or scheduled scenario.
  • Notify you via your preferred channels (WhatsApp, SMS, email) when such a match exists.
  • Show hospitals your contact details only after you’ve consented and been matched to an active request.
  • Maintain aggregate statistics (donor counts, fulfillment rates) for public-facing transparency.

We do not sell your data, run advertising, or share it with third parties outside the active-request matching workflow.

4. Your rights under PDPL

  • Access: request a copy of all personal data we hold about you.
  • Correction: edit your profile anytime from your account dashboard.
  • Deletion: delete your account — removes all PII immediately.
  • Portability: export your donation history as JSON/CSV.
  • Objection: opt out of any notification channel individually.

Exercise any right by emailing contact@bahrainblood.com.

5. Retention

Active accounts: retained for the life of the account. Closed accounts: anonymized within 30 days. Activity logs: auto-expire after 90 days via MongoDB TTL.

6. Security

TLS in transit; encrypted at rest in MongoDB Atlas; CPR numbers AES-256-GCM; passwords bcrypt (12 rounds); session cookies httpOnly + secure + sameSite strict.

7. Changes

We’ll update this page and notify registered donors by email when the substance of this policy changes.