This is not a legal document. It is a human answer to the questions a doctor asks before switching: where clinic data is kept, who can see it, what happens when a computer dies, and how to walk away if you change your mind. The full documents are at the bottom of the page.
The program on your desk is a window into the clinic, not a storage box. Records live on a protected server. If the computer breaks or is stolen, the data is fine: sign in from another one and everything is there.
Each clinic sees only its own data. Inside the clinic, every staff member signs in with a personal PIN and has rights that match the role, and every action stays in the log.
The whole database exports to Excel or ZIP with one button, and deletion is permanent once you ask for it. The data belongs to the clinic, not to us.
Clinic data is stored in Microsoft's certified cloud, in the Israel region — Israel Central. That means physically in the country, in Microsoft data centres with their own certifications, not on a server under a developer's desk.
Only program settings stay on your computer. Access keys for mail, payments, and telephony are kept encrypted on the server — never on your own disk.
Microsoft AzureIsrael Central regionKeys on the server only
A broken, stolen, or reinstalled computer does not kill your data: the data is on the server. Install the program on another machine, sign in, and the clinic is there.
The server makes backups on its own, without your involvement and without reminders:
• Point-in-time restore — the database can be rolled back to any moment within the last 7 days (“the way it was on Tuesday at 11:40”).
• Longer-term copies — weekly copies are kept for 8 weeks and monthly copies for 12 months while the clinic is using the platform, in case a damaged or missing record is noticed much later.
Restoring is not your job: you write to us, and we bring the data back. In addition, settings let you turn on a local copy on your own computer. It is off by default on purpose, so that patient data never lands on a local disk without your explicit decision.
Other clinics — never. Each clinic's data is separated from everyone else's, and every request is limited to your clinic. That isolation is verified automatically on every change to the program.
Inside the clinic — by role. Staff sign in with a personal PIN, and rights are separated: the person at the front desk does not see what the doctor sees.
We, the developer, do not browse your records. Access to the content is possible only when you have reported a problem and granted us that access, and the access itself is recorded.
The access log cannot be forged. Log entries are chained together with checksums: quietly erasing or rewriting a line does not work — the break shows up during verification.
While data travels over the internet it is inside a protected channel (TLS), the same way online banking works. The program never uses an open connection.
While data sits on the server the database is encrypted as a whole, and the most sensitive fields — names, contacts, treatment notes — carry an extra layer of encryption of their own.
Passwords and integration keys are stored encrypted on the server only and are never shown in the clear — not in email, not in logs.
Operations in Israel follow the Privacy Protection Law as amended by Amendment No. 13 (in force since 14 August 2025). The roles are split as follows: the clinic is the owner of the database, and we act as the holder on the clinic's behalf. The processing agreement under Regulation 15 of the Privacy Protection Regulations (Data Security), 2017 is signed at registration.
Registration and notification duties towards the Database Registrar rest with the clinic, depending on the size of the database and the sensitivity of the information. Transfers of data outside the country are carried out under Regulation 2 of the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 2001.
The exact wording is in the Privacy Policy. This page explains it in plain language and is not a substitute for legal advice.
In Israel, invoices and tax receipts are issued by Green Invoice, a licensed external service. The clinic contracts with them directly; the program only passes the invoice lines — amount, services, VAT. Clinical content is never sent there.
We do not see or store card numbers: payment happens on the payment provider's side, and the program receives only a payment reference that carries no card details. Invoicing is optional — the clinic decides whether to enable it at all.
Conversations are not recorded. Neither audio nor a transcript of a call is kept — not by us and not by the telephony provider.
What remains is call metadata (number, time, duration) and whatever the voice secretary filed at the patient's request: a message for the doctor, an appointment, or a repeat-prescription request. The same rule applies to the voice assistant inside the program.
You can export the entire database to Excel or ZIP at any moment and without explaining yourself — it is a button in settings, and there is no approval to wait for.
Deletion happens at the clinic's request and is permanent. The procedure, the timing, and what happens to backups are described on the Data deletion page.
Everything above is written in human language. The legally precise wording lives in these documents:
We send the DPA, the BAA, and the speech provider's written confirmation of non-retention to clinics and their IT specialists on request.
Ask a question →