Privacy 

INTRODUCTION 

Doha Islamic Insurance - Shamel Privacy Policy 

Last updated: 14th November 2025 

1. About Doha Islamic Insurance - Shamel (the Controller) 

Doha Islamic Insurance - Shamel (“SHAMEL”, “we”, “our”, “us”) is a listed company regulated by the Qatar Central Bank (QCB) and licensed to provide insurance services. 

Registered Address: New Hetmi - Zone No.: 17. Street: 930 Building 4 Floor No.: 8 Doha-Qatar 

Commercial Registration Number: 115041 

Contact Centre: +974 44292880 

Official Website: https://shamel.com.qa  

Data Protection Officer (DPO): [email protected] 

2. Purpose and Scope 

This Privacy Policy explains how SHAMEL collects, uses, stores, shares, and protects Personally Identifiable Information (PII) in accordance with Qatar’s Personal Data Privacy Protection Law (PDPPL), ISO/IEC 27701:2019, and Qatar Central Bank (QCB) regulations. It applies to all SHAMEL services, including websites, mobile apps, call centres, brokers, branches, and subsidiaries, and to all visitors, customers, employees, contractors, and third parties interacting with SHAMEL’s products, services, and Shamelital platforms. 

3. Definitions 

Personal Data (PII): Any information relating to an identified or identifiable natural person. 

Data Subject: The individual whose personal data is processed. 

Controller: Entity determining the purposes and means of processing personal data. 

Processor: Entity processing personal data on behalf of the controller. 

Consent: Freely given, specific, informed, and unambiguous indication of the data subject’s wishes. 

Data Breach: Any incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. 

4. Categories of Personal Data We Collect 

Category 

Examples 

Identity & KYC Data 

Full name, nationality, date/place of birth, QID/passport, gender, marital status, dependents, employer, job title 

Contact Data 

Address, email, phone numbers 

Financial Data 

Bank account, credit/debit card, salary, tax ID, income details 

Policy & Contract Data 

Product type, policy number, issue/expiry dates, premiums, claims history 

Special Category Data 

Medical records, health conditions, disability details, death certificates, genetic/biometric data 

Risk & Underwriting Data 

Vehicle details, property details, travel history, lifestyle or occupation risk factors 

Anti-Fraud & Compliance Data 

Sanctions, AML/CFT checks, criminal records, credit bureau reports 

Surveillance Data 

Visitor logs, CCTV, call recordings 

Shamelital Data 

IP address, geolocation, cookies, device/browser details, online interactions with SHAMEL apps/websites 

5. Data Collection and Processing Practices 

SHAMEL collects only the minimum personal data necessary for legitimate business purposes. Data is collected via online forms, applications, and other interactions, and is regularly reviewed to ensure minimization. Special categories of data (e.g., health, biometrics) are only collected with explicit consent and where legally required. 

6. Legal Basis for Processing 

SHAMEL processes personal data based on: 

- Contractual necessity: To deliver requested products/services. 

- Legal obligation: To meet regulatory requirements (QCB, AML, MoPH). 

- Legitimate interest: For business development, fraud prevention, and security. 

- Consent: For direct marketing or where required by law. 

- Vital interest: For emergencies. 

7. Data Subject Rights 

You have the right to: 

- Access, correct, or delete your data. 

- Restrict or object to processing (including marketing). 

- Withdraw consent at any time. 

- Request portability. 

- Be notified of breaches within 72 hours. 

- File a complaint with SHAMEL or the National Cyber Security Agency (NCSA). 

8. Consent Management 

SHAMEL obtains valid, informed consent before collecting or processing personal data. Consent requests are presented separately from other terms, written in plain language, and specific to each purpose. Consent is recorded, securely stored, and can be withdrawn at any time. Explicit consent is required for sensitive data. Cookie consent: Non-essential cookies are only set after explicit, informed user consent. Users can accept, reject, or customize preferences via a cookie banner. 

9. Security and Confidentiality Measures 

SHAMEL applies security controls in accordance with ISO 27001, 27701, and 22309 standards. These controls include, but are not limited to: 

- Encryption and pseudonymization. 

- Role-based access and multi-factor authentication (MFA). 

- Continuous security monitoring. 

- Disaster recovery (DR) with backup in a secondary data center located in Qatar. 

- Secure disposal of data at end-of-life. 

- Privacy by Design and Default in all systems and processes. 

10. Third-Party Sharing and Cross-Border Transfers 

We may share data with subsidiaries, reinsurers, brokers, adjustors, TPAs, technology providers (hosting, cloud, payment gateways), regulators and authorities (QCB, MoPH, courts). International transfers: Your data may be transferred outside Qatar. SHAMEL ensures compliance using Binding Corporate Rules, contractual safeguards, and adequacy decisions. DPIAs are conducted for high-risk transfers. 

11. Retention and Disposal 

- Policy term + 10 years. 

- AML/KYC: minimum 15 years (QCB rules). 

Data is securely deleted or anonymized after retention ends. SHAMEL maintains defined retention periods, secure deletion, and records of disposal for compliance. 

12. Automated Decision-Making 

SHAMEL may use automation for underwriting, fraud detection, and claims. You may request human review and contest decisions. 

13. Children’s Data 

SHAMEL applies special safeguards for minors under 18. Parental/guardian consent is required. Child data is processed with enhanced security, age verification, and child-friendly privacy notices. 

14. Compliance Monitoring and Breach Notification 

SHAMEL monitors compliance through regular audits, training, and management reviews. Any data breach is promptly reported to QCB, NCSA, and affected by data subjects as required. Breach registers and incident logs are maintained, and corrective actions are taken to prevent recurrence. 

15. Contact Us 

Data Protection Officer (DPO): [email protected] 

Call Centre: +974 44292880 

Mail: Data Protection Officer, SHAMEL, New Hetmi - Zone No.: 17. Street: 930 Building 4 Floor No.: 8 Doha-Qatar 

16. Updates to this Notice 

SHAMEL may update this Notice from time to time to reflect legal, regulatory, or operational changes. Updated versions will be published on online.Shamel.com.qa and SHAMEL mobile apps.