Intelligent Clinic Management Platform
Security and privacy

Your clinic's data is protected at the architectural level

Privacy is not a feature here but the foundation: isolation between clinics, encryption, auditing, daily backups and strict control over who processes medical information, and how.

Clinic isolation

Each clinic's data is held in an isolated dataset, accessible strictly by token. Every request is confined to your clinic alone, and the isolation is verified continuously by automated checks.

Encryption

Data in transit travels over TLS. Sensitive fields (names, contacts, clinical notes) are encrypted in the database. A clinic's integration credentials are stored encrypted.

Hosting

The infrastructure runs in Microsoft's certified cloud. Data is hosted in the Israel region, on an enterprise platform with its own data-centre certifications.

Access and audit

Sign-in by personal staff PIN codes with role-based permissions. Key actions are written to a secured audit log with an integrity chain.

Backups and your rights

Encrypted backups are taken daily. At any time the clinic can export its entire database (Excel / ZIP) and request the permanent erasure of all data.

Calls are not recorded

The telephone assistant stores neither audio nor transcripts. The system retains call metadata (number, time, duration) and anything the assistant files at the patient's request, such as a message for the doctor or a repeat-prescription request.

Voice technology and your data

The platform runs two voice assistants — an in-app assistant for the doctor and a telephone assistant for patients. Speech recognition and synthesis run on an enterprise-grade speech platform, and telephony on a licensed global carrier.

Under our agreements, voice and text data is handled in transit only: it is not stored by the provider and is not used to train models (zero-data-retention terms). Written confirmation is provided on request; the current provider list is on the Sub-processors page.

Speech · zero data retentionTelephony · licensed carrierNo training on your data

Sub-processors

Medical information is not shared with third parties other than trusted infrastructure providers, each under its own Data Processing Agreement (DPA) or Business Associate Agreement (BAA):

Cloud hostingSpeech synthesis/recognitionTelephonyWhatsApp delivery

The named, up-to-date list of providers is published on the Sub-processors page.

Compliance and status

The platform is a productivity tool, not a medical device. It does not diagnose and does not take clinical decisions: the final decision always rests with the doctor, and the doctor's note is the authoritative record.

The architecture is built on the principle of privacy by design and is aligned with the requirements of the UK GDPR / Data Protection Act 2018 (ICO), the EU GDPR and — for US clinics — the HIPAA safeguards. The full legal documents — Privacy Policy, Terms of Service and EULA — are available on this website.

Documents on request

On written request we provide clinics and their IT departments with the Data Processing Agreement (UK/EU GDPR), the BAA (HIPAA) for US clinics, and the speech provider's written confirmation of non-retention.

Request documents →