Privacy Policy
Effective date: 16 May 2026
1. Who we are
Project Line ('we', 'us', 'our') is the developer of Intelligent Clinic Management Platform, a SaaS platform for medical and dental clinics. We are established in Israel and have no establishment in the United Kingdom. A UK representative under Article 27 of the UK GDPR will be appointed and named on this page before we begin processing the data of clinics established in the United Kingdom; until then, all such requests should be sent to the contact address below. For any privacy question or to exercise your rights, contact us at support@projectlineil.com.
2. Scope of this policy
This policy describes how we handle personal data when a clinic (the 'Customer') uses Intelligent Clinic Management Platform. The clinic is the data controller for its patient information. Project Line acts as a data processor on the clinic's behalf, under written instructions and our Data Processing Agreement.
3. What data we process
- Clinic profile: business name, country, city, address, time zone, working hours, contact phone and email, owner's name, medical licence number, taxation mode and tax rates, default currency.
- Doctor account: email, password hash, language preference, UI settings.
- Patient records (entered by the clinic): first/last name, phone, identity document, date of birth, allergies, chronic conditions, current medications, visit history, prescriptions, invoices, appointments.
- Voice calls: caller phone number, call timestamps, call duration. The AI voice agent does not record calls — audio is processed in real time (speech-to-speech) by the OpenAI Realtime API and neither audio nor a transcript is stored.
- Doctor's microphone (desktop app): when the clinician uses voice dictation or the AI clinical assistant, the desktop app captures the doctor's microphone and streams the audio in real time to the OpenAI Realtime API for speech-to-text; the audio is not stored.
- Operational data: log entries, error reports (with patient data stripped out before they are recorded), usage statistics.
- Remote support (screen sharing): when a clinic staff member starts a remote support session and gives consent, screen frames are relayed in real time to the support operator over an encrypted WebSocket and are not recorded — neither the frames nor a transcript are stored; only session metadata (who, when, why, duration) is kept.
4. Why we process it
We process the above data solely to operate the service on behalf of the clinic: deliver inbound and outbound calls, manage the clinic's calendar, generate prescriptions, send appointment reminders, allow the clinic to export its data, and provide customer support. We do not use clinic or patient data to train AI models or for advertising of any kind. The clinic's own mailings to its patients fall into two groups: service messages — invoices, changes to the terms, account-security notices and appointment reminders — are sent as part of the contract, while marketing messages such as clinic news and offers are sent only with the recipient's separate consent, which may be withdrawn at any time (section 3A of the Terms of Service; PECR 2003, reg. 22). Patient records are health data: a special category under Article 9 GDPR and protected health information under HIPAA. We process them only because the service cannot work without them — without the patient's record there is no appointment, no prescription and no invoice; the lawful basis belongs to the clinic (consent or the contract for medical treatment, Article 9(2)(h) GDPR — medical diagnosis and the provision of health care), and Project Line processes such data only on the clinic's documented instructions.
5. Lawful basis
For European patients (EU GDPR): we rely on the clinic's lawful basis for processing patient data (consent or contract for medical treatment), with Project Line acting as processor under Article 28 GDPR. For UK patients: we process under the UK GDPR and the Data Protection Act 2018, with Project Line acting as processor under Article 28 UK GDPR; the supervisory authority is the Information Commissioner's Office (ICO). For US patients (HIPAA): a Business Associate Agreement (BAA) is available on the BAA (US) page.
6. Sub-processors
We rely on the following trusted infrastructure providers:- Microsoft Azure — hosting, Azure SQL Database (Israel Central), Azure Storage. HIPAA-eligible.
- OpenAI — Realtime voice + transcription, zero-data-retention enterprise terms; no model training on clinic data.
- Twilio — telephony and SMS carrier. No BAA is in place; for US clinics the AI phone assistant and patient SMS are switched off, and inbound calls are only bridged to the clinic's own telephone with Twilio acting as a telecommunications conduit (no recording, no AI).
- Meta (WhatsApp Business) — delivery of approved templates only.
- Stripe / Cardcom / Green Invoice / Tranzila (per clinic choice) — payment tokenisation. We never see PAN.
- Zoho (Zoho Mail) — transactional email delivery: notifications to patients and clinics, sign-in codes, invoices. Recipient email address, recipient name and message content only; US (zoho.com data centre); UK Addendum/IDTA and Zoho DPA.
7. Where data is stored
Primary storage: Microsoft Azure SQL Database in the Israel Central region. Backups: point-in-time restore covers 7 days; weekly backups are kept for 8 weeks and monthly backups for 12 months. Backups are encrypted and held in the same region. Each clinic has its own isolated row-set with token-scoped access — no cross-clinic visibility, even by us, without explicit access.
8. How long we keep it
While the clinic's subscription is active, we keep all data necessary to operate the service. Within 30 days of subscription cancellation, the clinic's data and its patients' data are deleted from the live database. Backups are taken of the database as a whole, so data belonging to a deleted clinic remains in the encrypted backups until those backups expire (no more than 12 months); the backups serve disaster recovery of the system as a whole and are not otherwise processed. Before closing the account the clinic must export its records (export function in the application) and keep them for the period that the law of its own country lays down for health records — in the United Kingdom the NHS Records Management Code of Practice 2021 sets a minimum of 8 years after the patient's last contact for adult health records, and 10 years after death for GP records. The clinic, as controller, can request deletion by email at any time, subject to those retention obligations.
9. Sharing & disclosure
We do not sell patient or clinic data. We do not share it with marketing, analytics or social networks. We disclose only as required:- To sub-processors above, strictly for service operation.
- To comply with a binding legal order; we will notify the clinic unless prohibited.
- In the event of a business transfer, with prior notice and the same level of protection.
10. Your rights
Patients should address access, correction or deletion requests to their clinic first — the clinic is the controller. The clinic can fulfil these from the Intelligent Clinic Management Platform application directly. If the clinic does not respond within 30 days, you may contact us at support@projectlineil.com or submit a request via the Patient Portal. Clinics have the right to: (a) export their complete dataset as a ZIP at any time; (b) request permanent deletion within 30 days; (c) receive a copy of our DPA / BAA on request; (d) lodge a complaint with their local supervisory authority (in the UK, the ICO; elsewhere, for example, the CNIL, the AEPD, the Garante, the BfDI, the Israeli PPA or the US HHS Office for Civil Rights). Anyone who receives marketing messages may withdraw that consent at any time — through the unsubscribe link in the email (or the unsubscribe button the mail application shows), by replying STOP to a text or WhatsApp message, or by asking the practice to clear the consent tick in the patient record. Withdrawal is free, takes effect immediately and does not stop service messages.
11. Security
Concrete controls in place today:- Transport. TLS 1.2+ enforced on every endpoint. HSTS. Strict CSP with nonce-based script allow-listing;
X-Frame-Options: DENY;X-Content-Type-Options: nosniff. - Encryption at rest. Azure SQL TDE (AES-256). Encrypted backups: 7 days of point-in-time restore, weekly backups for 8 weeks, monthly backups for 12 months.
- Secrets management. All API keys, connection strings and tokens stored encrypted in Azure App Service Configuration — never in source code.
- Authentication. Opaque 256-bit session tokens, SHA-256-hashed, constant-time comparison. Access token 8h, refresh 30d.
- Per-tenant isolation. Every SQL query enforces
ClinicId. Cross-clinic access is technically impossible. - SMS / Email codes. 6-digit, 10-min lifetime, single-use.
- Rate limiting. 3-tier (public 20/5min, mobile 10/15min, authenticated 40/5min).
- PII redaction. Phone/email/identity numbers are scrubbed from logs before reaching Application Insights.
- Audit log. Hash-chained tamper-evident entries with subject/action/outcome/timestamp/IP.
- Voice. Audio is streamed directly to OpenAI Realtime over WebSocket and is not recorded — neither audio nor transcripts are stored; only call metadata is kept.
- Incident response. 72-hour GDPR / UK GDPR Art. 33 breach-notification window. Affected clinics notified by email.
12. Children
Clinics may treat patients under 18. We rely on the clinic to obtain parental consent for processing minors' data in accordance with the clinic's jurisdiction.
13. Changes to this policy
We will post any material change to this page at least 30 days before it takes effect, and notify the clinic's primary contact by email.
14. Contact
Project Line
Email: support@projectlineil.com
Jurisdiction: Israel