Project Line

Privacy Policy

Effective date: May 16, 2026

1. Who we are

Project Line ('we', 'us', 'our') is the developer of Intelligent Clinic Management Platform, a SaaS platform for medical and dental clinics. We are established in Israel. No representative in the European Union under Article 27 GDPR has been appointed yet; one will be appointed and named on this page before we begin processing personal data of clinics established in the EU, and until then EU enquiries reach us at the address below. For any privacy question or to exercise your rights, contact us at support@projectlineil.com.

2. Scope of this policy

This policy describes how we handle personal data when a clinic (the 'Customer') uses Intelligent Clinic Management Platform. The clinic is the data controller for its patient information. Project Line acts as a data processor on the clinic's behalf, under written instructions and our Data Processing Agreement.

3. What data we process

4. Why we process it

We process the above data solely to operate the service on behalf of the clinic: deliver inbound and outbound calls, manage the clinic's calendar, generate prescriptions, send appointment reminders, allow the clinic to export its data, and provide customer support. We do not use clinic or patient data to train AI models or for advertising of any kind. The clinic's own mailings to its patients fall into two groups: service messages — invoices, changes to the terms, account-security notices and appointment reminders — are sent as part of the contract, while marketing messages such as clinic news and offers are sent only with the recipient's separate consent, which may be withdrawn at any time (section 3A of the Terms of Service). Patient records are health data: a special category under Article 9 GDPR and protected health information under HIPAA. We process them only because the service cannot work without them — without the patient's record there is no appointment, no prescription and no invoice; the lawful basis belongs to the clinic (consent or the contract for medical treatment, Article 9(2)(h) GDPR — medical diagnosis and the provision of health care), and Project Line processes such data only on the clinic's documented instructions.

5. Lawful basis

For European patients (GDPR): we rely on the clinic's lawful basis for processing patient data (consent or contract for medical treatment), with Project Line acting as processor under Article 28 GDPR. For US patients (HIPAA): a Business Associate Agreement (BAA) is available on the BAA page.

6. Sub-processors

We rely on the following trusted infrastructure providers: The full list, and every update to it, is published on the Sub-processors page.

7. Where data is stored

Primary storage: Microsoft Azure SQL Database in the Israel Central region. Backups are encrypted and stored in the same region: point-in-time restore covers 7 days, weekly copies are kept for 8 weeks and monthly copies for 12 months. Each clinic has its own isolated row-set with token-scoped access — no cross-clinic visibility, even by us, without explicit access.

8. How long we keep it

While the clinic's subscription is active, we keep all data necessary to operate the service. Within 30 days of cancellation we permanently delete all clinic and patient records from the live database. Backups are taken of the database as a whole, so data belonging to a deleted clinic stays inside encrypted backup copies until those copies expire (no longer than 12 months); backups serve disaster recovery of the whole system only and are not otherwise processed. Before closing the account the clinic must export its records from the application (ZIP export) and retain them for the period its own law requires. HIPAA sets no retention period for medical records — state law does; HIPAA compliance documentation (policies, procedures, notices, risk analyses) must be kept for 6 years under 45 CFR §164.316(b)(2)(i). The clinic can request immediate deletion by email at any time.

9. Sharing & disclosure

We do not sell patient or clinic data. We do not share it with marketing, analytics or social networks. We disclose only as required:

10. Your rights

Patients should address access, correction or deletion requests to their clinic first — the clinic is the controller. The clinic can act on these requests directly in the Intelligent Clinic Management Platform application. If the clinic does not respond within 30 days, you may contact us at support@projectlineil.com or submit a request via the Patient Portal. Clinics have the right to: (a) export their complete dataset as a ZIP at any time; (b) request permanent deletion within 30 days; (c) receive a copy of our DPA / BAA on request; (d) lodge a complaint with their local supervisory authority (CNIL, AEPD, Garante, BfDI, ICO, IL PPA, US HHS-OCR). Anyone who receives marketing messages may withdraw that consent at any time — through the unsubscribe link in the email (or the unsubscribe button the mail application shows), by replying STOP to a text or WhatsApp message, or by asking the clinic to clear the consent tick in the patient record. Withdrawal is free, takes effect immediately and does not stop service messages.

10A. California residents (CCPA/CPRA)

If you are a California resident: medical information your clinic holds under HIPAA and under the California Confidentiality of Medical Information Act (CMIA) is exempt from the CCPA (Cal. Civ. Code §1798.145(c)(1)); rights over that information are exercised through your clinic under HIPAA, and Project Line handles such requests only on the clinic's instructions. For other personal information — website visitors and the business contact details of clinic staff — Project Line acts as the clinic's service provider (Cal. Civ. Code §1798.140(ag)): we process it only to provide the service under our written contract, and we do not sell or share personal information, and have not done so in the preceding 12 months. California residents may request to know, delete and correct their personal information, opt out of its sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising these rights (Cal. Civ. Code §§1798.100–1798.125). Send your request to your clinic or to support@projectlineil.com; we verify the request before acting on it and answer within 45 days.

11. Security

Concrete controls in place today:

12. Children

Clinics may treat patients under 18. We rely on the clinic to obtain parental consent for processing minors' data in accordance with the clinic's jurisdiction.

13. Changes to this policy

We will post any material change to this page at least 30 days before it takes effect, and notify the clinic's primary contact by email.

14. Contact

Project Line
Email: support@projectlineil.com
Jurisdiction: Israel