1. Introduction
SmartClinic ("we", "our", or "the Platform") is a cloud-based clinic management platform designed for healthcare providers. We are committed to protecting the privacy and security of your personal and health-related information in compliance with applicable data protection laws, including the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), and the Israeli Privacy Protection Law.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have regarding your data.
2. Information We Collect
2.1 Information Provided by Clinic Staff
- Account details: name, email address, phone number, job title, license number
- Authentication credentials (securely hashed passwords)
- Role and permission assignments
- Work schedules and availability
2.2 Patient Information (Entered by Clinic Staff)
- Demographics: name, date of birth, gender, contact information, identification number
- Medical history, diagnoses, and clinical notes
- Appointment records and treatment plans
- Prescriptions and medication history
- Laboratory orders and results
- Billing and payment records
- Uploaded documents, images, and dental charts
2.3 Automatically Collected Information
- IP addresses and browser/user-agent data (for security and audit logs)
- Login timestamps and session activity
- Device and browser type
3. How We Use Your Information
We process personal data for the following purposes:
- Providing and operating the clinic management platform
- Managing user accounts, roles, and access permissions
- Scheduling appointments and managing patient care workflows
- Generating invoices, processing payments, and financial reporting
- Sending transactional emails (appointment confirmations, verification emails, invoices)
- Maintaining audit logs aligned with HIPAA Security Rule principles for all system actions
- Ensuring platform security through login monitoring and account lockout protections
- Improving platform performance and fixing bugs
4. Data Storage and Security
We implement industry-standard technical and organizational measures to protect your data:
- All data is encrypted in transit using TLS/SSL
- Passwords are hashed using bcrypt with appropriate salt rounds
- Sensitive configuration data is encrypted at rest using AES-256
- Access is controlled through role-based permissions (RBAC) with the principle of least privilege
- Comprehensive, immutable audit logs record all data access and modifications
- JWT-based authentication with token expiration and refresh token rotation
- Account lockout after repeated failed login attempts
- Session inactivity timeouts for unattended terminals
Data is hosted on secure cloud infrastructure within the European Union (Hetzner Cloud, Germany) with regular backups and disaster recovery procedures.
5. Data Sharing and Disclosure
We do not sell, rent, or trade personal or patient information. Data may be shared only in the following circumstances:
- Within your clinic: Staff members with appropriate permissions can view and manage patient data according to their assigned role
- Service providers: We use trusted third-party services for email delivery (SMTP), cloud hosting, and file storage (S3-compatible), all bound by data processing agreements
- Legal requirements: When required by law, court order, or regulatory authority
- Emergency access: Under HIPAA Break-the-Glass provisions, authorized personnel may access patient data in emergencies with full audit trail logging
6. HIPAA-Ready Architecture
SmartClinic is architected following HIPAA security and privacy guidelines to support healthcare providers who require compliance. While SmartClinic has not undergone formal HIPAA certification, our platform incorporates the technical safeguards required by the HIPAA Security Rule:
- Protected Health Information (PHI) access is restricted to authorized users only
- All PHI access is logged in immutable audit trails
- Emergency access (Break-the-Glass) procedures are available with mandatory justification and review
- User accounts are deactivated (soft-deleted) to preserve audit history
- Credential retrieval and offboarding procedures are tracked
- Data retention policies comply with applicable healthcare record retention requirements
7. Data Retention
Patient records and clinical data are retained in accordance with applicable healthcare regulations and the retention policies configured by each clinic. When a staff account is deactivated, the account is soft-deleted (marked inactive) rather than permanently removed, to preserve audit trail integrity.
Permanent deletion of user accounts without clinical records is available to super administrators upon request.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data, subject to legal retention obligations
- Restriction: Request restriction of processing in certain circumstances
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, please contact your clinic administrator or email us at [email protected].
9. Cookies and Tracking
SmartClinic uses only essential cookies and local storage required for platform functionality:
- Authentication tokens (JWT access and refresh tokens) stored securely in local storage
- User session preferences (locale, theme, glass design settings)
- Cloudflare Turnstile CAPTCHA for bot protection on public forms
We do not use analytics cookies, advertising trackers, or third-party profiling scripts.
10. Children's Privacy
SmartClinic is a business-to-business platform intended for use by healthcare professionals. We do not knowingly collect personal information directly from individuals under the age of 16. Patient records for minors are entered and managed by authorized clinic staff.
11. International Data Transfers
Our servers are located in Germany (EU). If you access the platform from outside the European Economic Area, your data will be transferred to and processed in the EU. We ensure appropriate safeguards are in place for any cross-border data transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
© 2026 SmartClinic. All rights reserved.