Privacy Policy · farab

LEGAL

Privacy Policy.

Your data, and your patients’ data.

Last updated July 27, 2026

This policy explains what farab does with information. It covers two very different things, and the difference matters: information about you when you visit this site or ask for a Leak Report, and information about your patients when you engage us and we operate follow-up systems on your behalf.

Section 02 sets out that distinction. If you are a practice deciding whether to work with us, read 02, 05 and 06 first.

01

Who we are

farab is a Meta advertising and patient follow-up agency based in Doha, Qatar, working with dental practices in the US. For any question about this policy, or to exercise a right described in section 11, email [email protected] and we will reply within five business days.

02

The two roles we play

Almost every complaint about agencies and data comes from blurring these. We keep them separate.

As a controller. When you visit this site, book a Leak Report call, or email us, we decide what happens to that information. This policy governs it.

As a processor. When you engage us as a client, we handle information about your patients inside advertising, messaging and CRM systems. We do not own that information and we do not decide what it is for. You do. We act only on your documented instructions, under the written agreement between us. Your own privacy notice, not this one, governs your patients.

Practical consequence: your patient list is never merged into any farab database, never used to build our own audiences, and never shared with another client. On termination it is exported to you in full and removed from our systems.

03

What we collect about you

  • What you give us. Name, practice name, role, email, mobile number, website, ad account details you choose to share, and anything you write in a form or message.
  • What the site records. Pages viewed, referring source, approximate location from IP, device and browser, and time on page, through cookies and similar technologies.
  • Call and message records. Emails, SMS, WhatsApp messages and, where you are told in advance and it is lawful where you are, call recordings and transcripts of Leak Report calls.
  • Advertising identifiers. Cookie-based identifiers used to measure which ad or page led to your inquiry.

04

What we process on behalf of a practice

Once you engage us, the systems we build handle information your patients give you. Typically: name, phone, email, the treatment they inquired about, appointment times, message history, and whether they attended.

Some of this is protected health information under US law. Where that is the case and you are a covered entity, we act as a business associate and will sign a Business Associate Agreement before we touch a patient record. The BAA, not this policy, sets the terms.

  • We do not sell, rent or license patient information. Ever.
  • We do not use one practice’s patient information to benefit another.
  • We do not upload patient lists, or any field derived from them, to advertising platforms unless you instruct it in writing and the platform’s health rules allow it.
  • Access is limited to the people working on your account, on individual logins with two-factor authentication.

05

Why we use it

  • To prepare and deliver your Leak Report and hold the call.
  • To confirm bookings, send reminders and follow up on inquiries.
  • To deliver the services you engage us for, and to report on them.
  • To improve our site, our offers and our own advertising.
  • To send updates and marketing where you have agreed, which you can stop at any time.
  • To meet legal, tax and record-keeping obligations.

06

Calls, texts and WhatsApp

When you give us a mobile number on a form, you agree that we may contact you about your request by phone, SMS or WhatsApp, including through automated systems and an AI voice agent that identifies itself as such. This is not a condition of buying anything. Message and data rates may apply. Reply STOP to end messages, HELP for help, or email us.

If you are a practice: consent to message your patients has to come from your patients, to you, at the point you collected their details. We will ask you to confirm in writing that it exists before any database campaign runs. Section 8 of the Terms of Service sets this out.

07

Cookies and advertising technology

This site uses cookies to function, to measure traffic, and to measure our advertising. We run the Meta pixel and Google Analytics on this site.

This is a business-to-business site. The pixel here observes visits by practice owners and marketing staff to an agency website. It is not installed on any patient-facing page by us for this purpose, and it is not configured to send any health-related event, patient identifier or treatment interest to any advertising platform.

When you first arrive we show a cookie banner. The Meta pixel and Google Analytics do not load at all until you accept it. Choosing Decline leaves only the cookies needed to make the site work. You can change your mind at any time in section 11a, block or delete cookies in your browser, and opt out of interest-based advertising through your Meta and Google ad settings.

08

Who we share information with

We do not sell your personal information. We share it only with providers who need it to run our business, and only for that purpose:

  • CRM, messaging and booking, to hold your details and run communications.
  • Calendar and email, to schedule and confirm calls.
  • Hosting and site infrastructure, to serve this website.
  • Advertising and analytics platforms, to measure our own campaigns.
  • Payment processors, to take payment. We never see or store your full card number.
  • Professional advisers and authorities, where we are legally required, or to establish or defend a legal claim.

A current list of the specific providers we use is available on request.

09

Where information goes

We are based in Qatar and work with practices in the US. Information may therefore be stored or accessed in Qatar and the United States, whose data protection laws differ from one another.

Where we move personal information out of a region that restricts transfers, we rely on the appropriate safeguard for that region, including standard contractual clauses. Ask us and we will tell you which applies to you.

10

How long we keep it

  • Inquiries that never became clients: up to 24 months from last contact, then deleted.
  • Client records: for the engagement and 7 years after, to meet tax and legal obligations.
  • Patient information processed for a client: for the engagement only. On termination we export it to you and delete it within 30 days, unless the law requires otherwise.
  • Website analytics: up to 26 months.

11

Your rights

Wherever you are, you can ask us to give you a copy of what we hold, correct it, delete it, or stop using it for marketing. Email us and we will act without undue delay.

If you are in California, you also have the right to know the categories collected and disclosed, to delete, to correct, to opt out of sale or sharing, and not to be discriminated against for exercising any of them. We do not sell personal information for money. We do disclose limited online identifiers, such as cookie and device identifiers, to Meta and Google so we can measure and target our own advertising. Under the CCPA that counts as “sharing” for cross-context behavioral advertising, so we tell you plainly rather than claim otherwise. You can stop it at any time using the choices in section 11a. Similar rights apply in Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws. We have never sold or shared patient information under any of these laws, and we never will.

If you are in Qatar, you have the rights given by Law No. 13 of 2016 on Personal Data Privacy Protection.

We may need to verify who you are before acting. An authorised agent may act for you with written proof.

11a

Your privacy choices

This is our “do not sell or share my personal information” page. There are three ways to stop the sharing described in section 11. Any one of them is enough.

Turn off advertising cookies on this site. Use the button below. It clears your choice and brings the cookie banner back so you can decline. Declining stops the Meta pixel and Google Analytics from loading at all.
Send a Global Privacy Control signal. We treat a GPC signal from your browser as a valid opt-out request, automatically, with no further action from you.
Email us. Write to [email protected] with the subject line “Do not sell or share”. We will action it within 15 business days and confirm when it is done. An authorised agent may do this for you with written proof.

We will not treat you any differently, charge you more, or give you a worse service for exercising any of these choices.

12

Security

We use individual accounts, two-factor authentication, encrypted transport, and access limited to the people who need it. Client and patient information is kept inside the client’s own tenant or a separated sub-account, not pooled.

No system is completely secure, so we do not promise absolute security. If a breach affects your information we will notify you, and any regulator we are required to notify, within the time the law allows.

13

Children

Our site and services are for businesses. We do not knowingly collect information from anyone under 18 through this site. Where a practice’s systems contain information about minor patients, that information is handled under our agreement with the practice and its own consent processes, not through this site.

14

Changes

We may update this policy. The current version is always posted here with its date. If a change materially affects how we use information about you, we will tell you by email before it takes effect.

CONTACT US

Questions about your privacy?

Want to know what we hold on you, want it corrected, or want it removed? Email us and we’ll take care of it. If you are a practice and need our Business Associate Agreement or sub-processor list, ask and we’ll send both.

[email protected]