Privacy Policy
Effective date: May 16, 2026
1. Who we are
Project Line ('we', 'us', 'our') is the developer of Intelligent Clinic Management Platform, a SaaS platform for medical and dental clinics. We are established in Israel. No representative in the European Union under Article 27 GDPR has been appointed yet; one will be appointed and named on this page before we begin processing personal data of clinics established in the EU, and until then EU enquiries reach us at the address below. For any privacy question or to exercise your rights, contact us at support@projectlineil.com.
2. Scope of this policy
This policy describes how we handle personal data when a clinic (the 'Customer') uses Intelligent Clinic Management Platform. The clinic is the data controller for its patient information. Project Line acts as a data processor on the clinic's behalf, under written instructions and our Data Processing Agreement.
3. What data we process
- Clinic profile: business name, country, city, address, time zone, working hours, contact phone and email, owner's name, medical license number, taxation mode and tax rates, default currency.
- Doctor account: email, password hash, language preference, UI settings.
- Patient records (entered by the clinic): first/last name, phone, identity document, date of birth, allergies, chronic conditions, current medications, visit history, prescriptions, invoices, appointments.
- Voice calls: caller phone number, call timestamps, call duration. The AI voice agent does not record calls — audio is processed in real time (speech-to-speech) by the OpenAI Realtime API and neither audio nor a transcript is stored.
- Doctor's microphone (desktop app): when the clinician uses voice dictation or the AI clinical assistant, the desktop app captures the doctor's microphone and streams the audio in real time to the OpenAI Realtime API for speech-to-text; the audio is not stored.
- Operational data: log entries, error reports (with patient identifiers redacted), usage statistics.
- Remote support (screen sharing): when a clinic staff member starts a remote support session and gives consent, screen frames are relayed in real time to the support operator over an encrypted WebSocket and are not recorded — neither the frames nor a transcript are stored; only session metadata (who, when, why, duration) is kept.
4. Why we process it
We process the above data solely to operate the service on behalf of the clinic: deliver inbound and outbound calls, manage the clinic's calendar, generate prescriptions, send appointment reminders, allow the clinic to export its data, and provide customer support. We do not use clinic or patient data to train AI models or for advertising of any kind. The clinic's own mailings to its patients fall into two groups: service messages — invoices, changes to the terms, account-security notices and appointment reminders — are sent as part of the contract, while marketing messages such as clinic news and offers are sent only with the recipient's separate consent, which may be withdrawn at any time (section 3A of the Terms of Service). Patient records are health data: a special category under Article 9 GDPR and protected health information under HIPAA. We process them only because the service cannot work without them — without the patient's record there is no appointment, no prescription and no invoice; the lawful basis belongs to the clinic (consent or the contract for medical treatment, Article 9(2)(h) GDPR — medical diagnosis and the provision of health care), and Project Line processes such data only on the clinic's documented instructions.
5. Lawful basis
For European patients (GDPR): we rely on the clinic's lawful basis for processing patient data (consent or contract for medical treatment), with Project Line acting as processor under Article 28 GDPR. For US patients (HIPAA): a Business Associate Agreement (BAA) is available on the BAA page.
6. Sub-processors
We rely on the following trusted infrastructure providers:- Microsoft Azure — hosting, Azure SQL Database (Israel Central), Azure Storage. HIPAA-eligible.
- OpenAI — Realtime voice + transcription, zero-data-retention enterprise terms; no model training on clinic data.
- Twilio — telephony and SMS carrier. No BAA is in place with Twilio; for clinics in the United States the AI phone assistant and patient SMS are switched off, and inbound calls are only bridged to the clinic's own phone, with Twilio acting as a telecommunications conduit (no recording, no AI).
- Meta (WhatsApp Business) — delivery of approved templates only.
- Stripe / Cardcom / Tranzila (per clinic choice) — payment tokenization. We never see the card number.
- Green Invoice (Israeli clinics, per clinic choice) — issuing the tax invoice; invoice lines only, no clinical content.
- Zoho (Zoho Mail) — transactional email delivery: notifications to patients and clinics, login codes, invoices. Recipient email address, recipient name and message content only; US (zoho.com data center); EU SCCs and Zoho DPA.
7. Where data is stored
Primary storage: Microsoft Azure SQL Database in the Israel Central region. Backups are encrypted and stored in the same region: point-in-time restore covers 7 days, weekly copies are kept for 8 weeks and monthly copies for 12 months. Each clinic has its own isolated row-set with token-scoped access — no cross-clinic visibility, even by us, without explicit access.
8. How long we keep it
While the clinic's subscription is active, we keep all data necessary to operate the service. Within 30 days of cancellation we permanently delete all clinic and patient records from the live database. Backups are taken of the database as a whole, so data belonging to a deleted clinic stays inside encrypted backup copies until those copies expire (no longer than 12 months); backups serve disaster recovery of the whole system only and are not otherwise processed. Before closing the account the clinic must export its records from the application (ZIP export) and retain them for the period its own law requires. HIPAA sets no retention period for medical records — state law does; HIPAA compliance documentation (policies, procedures, notices, risk analyses) must be kept for 6 years under 45 CFR §164.316(b)(2)(i). The clinic can request immediate deletion by email at any time.
9. Sharing & disclosure
We do not sell patient or clinic data. We do not share it with marketing, analytics or social networks. We disclose only as required:- To sub-processors above, strictly for service operation.
- To comply with a binding legal order; we will notify the clinic unless prohibited.
- In the event of a business transfer, with prior notice and the same level of protection.
10. Your rights
Patients should address access, correction or deletion requests to their clinic first — the clinic is the controller. The clinic can act on these requests directly in the Intelligent Clinic Management Platform application. If the clinic does not respond within 30 days, you may contact us at support@projectlineil.com or submit a request via the Patient Portal. Clinics have the right to: (a) export their complete dataset as a ZIP at any time; (b) request permanent deletion within 30 days; (c) receive a copy of our DPA / BAA on request; (d) lodge a complaint with their local supervisory authority (CNIL, AEPD, Garante, BfDI, ICO, IL PPA, US HHS-OCR). Anyone who receives marketing messages may withdraw that consent at any time — through the unsubscribe link in the email (or the unsubscribe button the mail application shows), by replying STOP to a text or WhatsApp message, or by asking the clinic to clear the consent tick in the patient record. Withdrawal is free, takes effect immediately and does not stop service messages.
10A. California residents (CCPA/CPRA)
If you are a California resident: medical information your clinic holds under HIPAA and under the California Confidentiality of Medical Information Act (CMIA) is exempt from the CCPA (Cal. Civ. Code §1798.145(c)(1)); rights over that information are exercised through your clinic under HIPAA, and Project Line handles such requests only on the clinic's instructions. For other personal information — website visitors and the business contact details of clinic staff — Project Line acts as the clinic's service provider (Cal. Civ. Code §1798.140(ag)): we process it only to provide the service under our written contract, and we do not sell or share personal information, and have not done so in the preceding 12 months. California residents may request to know, delete and correct their personal information, opt out of its sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising these rights (Cal. Civ. Code §§1798.100–1798.125). Send your request to your clinic or to support@projectlineil.com; we verify the request before acting on it and answer within 45 days.
11. Security
Concrete controls in place today:- Transport. TLS 1.2+ enforced on every endpoint. HSTS. Strict CSP with nonce-based script whitelisting;
X-Frame-Options: DENY;X-Content-Type-Options: nosniff. - Encryption at rest. Azure SQL TDE (AES-256). Encrypted backups: 7 days of point-in-time restore, weekly copies for 8 weeks, monthly copies for 12 months.
- Secrets management. All API keys, connection strings and tokens stored encrypted in Azure App Service Configuration — never in source code.
- Authentication. Opaque 256-bit session tokens, SHA-256-hashed, constant-time comparison. Access token 8h, refresh 30d.
- Per-tenant isolation. Every SQL query enforces
ClinicId. Cross-clinic access is technically impossible. - SMS / Email codes. 6-digit, 10-min lifetime, single-use.
- Rate limiting. 3-tier (public 20/5min, mobile 10/15min, authenticated 40/5min).
- PII redaction. Phone/email/identity numbers are scrubbed from logs before reaching Application Insights.
- Audit log. Hash-chained tamper-evident entries with subject/action/outcome/timestamp/IP.
- Voice. Audio is streamed directly to OpenAI Realtime over WebSocket and is not recorded — neither audio nor transcripts are stored; only call metadata is kept.
- Incident response. 72-hour GDPR Art. 33 breach window. Affected clinics notified by email.
12. Children
Clinics may treat patients under 18. We rely on the clinic to obtain parental consent for processing minors' data in accordance with the clinic's jurisdiction.
13. Changes to this policy
We will post any material change to this page at least 30 days before it takes effect, and notify the clinic's primary contact by email.
14. Contact
Project Line
Email: support@projectlineil.com
Jurisdiction: Israel