Privacy Policy
Privacy Policy
This policy explains how جايسن إيلي عيسى, operating as Clinora, handles information when providing Clinora to clinics and clinic users, patients, and public-site visitors.
Who we are
The legal operator identified above, operating as Clinora, provides clinic-management software that helps small therapy, physiotherapy, rehabilitation, dental, and esthetic clinics manage appointments, patient records, notes, payment records, clinic expenses, reports, and daily operations.
What data we collect
The service may handle clinic account data, clinic user data, patient and clinic operational data, technical data, and support communications. The records handled depend on the services a clinic provides and the features it uses.
Clinic account and user data
We may process clinic names, specialty, contact details, account settings, user names, emails, roles, sign-in and session activity, security events, and support-related account information. Internal administration supports clinic provisioning, account access, and service operation.
Patient and clinic operational data
Clinics may enter patient identity and contact details, appointments, clinical notes, payments, reports, clinic expenses, imaging records, and attachments. Dental features also handle tooth charts, periodontal measurements, medical history, allergies, medications, patient alerts, procedures, treatment plans, and recall or follow-up records.
These records can include health-related and other sensitive personal data. Clinora is not limited to administrative information. The clinic decides what patient information to collect, why it is needed, who may access it, and what professional or legal retention duties apply.
Technical and security data
We process technical logs, device and session information, authentication events, selected sensitive-activity records, and service diagnostics to protect, monitor, maintain, and troubleshoot the service. These records may identify the user, clinic, affected record, action, and time.
Cookies/local storage
The service may use cookies, local storage, or similar browser storage for authentication, session continuity, security, and application preferences. Patient data is not used for advertising.
When public-site analytics is configured, Google Analytics remains off until you allow it through Analytics preferences. If allowed, we send Google Analytics information about public-page visits and contact-button use. We do not send patient records, clinic records, phone numbers, WhatsApp message text, raw URL queries or fragments, or external referrer URLs. You can turn analytics off again through Analytics preferences.
Analytics can also involve browser identifiers and technical information about the visit. Analytics choice is separate from essential account storage and from permission to send patient messages.
Why we use data
For clinic-directed patient records, Clinora processes information on the clinic’s behalf to provide the service and to secure, support, maintain, back up, and operate it. This includes scheduling, clinical recordkeeping, payment records, clinic expenses, reports, and consented appointment reminders.
Clinora also determines how it handles its own account administration, support enquiries, service security, and public-site information. These purposes are distinct from the clinic’s care decisions. Where an applicable Data Processing Agreement identifies the clinic as controller and Clinora as processor, those roles apply to the processing covered by that agreement; they do not make every provider a processor for every purpose.
Health and patient-related data
Clinics must have a lawful basis for collecting and using patient information, give required privacy notices, manage appropriate permissions, and obtain consent where required. Consent is not the only possible legal basis for patient recordkeeping. Clinora remains responsible for its own applicable legal and contractual duties.
Reading or accepting this policy does not authorize WhatsApp messages or unrelated uses of patient data.
WhatsApp appointment reminders
For clinics using WhatsApp reminders, Meta/WhatsApp provides message delivery. Reminders can come from Clinora’s shared sender on behalf of the clinic identified in the message. The recipient’s phone number and reminder content, including the patient’s first name, appointment time, clinic name, and clinic contact number, are sent to Meta/WhatsApp.
The clinic must record the recipient’s permission for appointment reminders and respect opt-outs. Ask your clinic about the reminder language before agreeing to messages. Appointment-reminder permission does not also authorize recall or follow-up outreach. Keeping an internal recall record is separate from sending a message.
Clinora records consent and opt-out information, send attempts, message identifiers, delivery and read information where available, and failures. Incoming messages and delivery events are received and stored to process opt-outs, associate events with reminders, and investigate delivery problems. Avoid sending clinical details in replies.
Reply STOP to stop reminders. For the shared sender, Clinora uses the most recent successfully sent reminder to that phone number to identify the clinic and patient whose reminder permission is withdrawn. STOP does not automatically disable messages from every clinic using Clinora. If the request cannot be matched, or you want to stop messages from other clinics, contact those clinics or Clinora using the contact details above. You can also ask your clinic for help or tell it directly to stop messages.
Reminder bodies must not include diagnoses, treatment details, clinical notes, or financial details. Even a brief message naming a clinic may reveal a healthcare relationship. Contact the clinic directly for appointment changes, care questions, or urgent help.
Who can access data
Authorized clinic users access clinic data based on their account and role. Provider support access is limited to what is needed for support, security, maintenance, backup, or troubleshooting.
Service providers and hosting
Contabo provides server hosting for the application and database. Backblaze B2 provides private attachment storage. Off-server backups use separately configured storage. Resend delivers account emails, such as password-reset and account-verification messages, using the recipient address and the email content.
Meta/WhatsApp processes recipient numbers, reminder content, and messaging events for WhatsApp delivery. Google Analytics processes public-site analytics when configured and allowed by the visitor. Providers may also process technical information for their own security and service operation under their applicable terms and privacy notices.
Clinora is operated from Lebanon. Hosting, storage, and communication providers may process information outside Lebanon. The countries involved depend on the hosting and provider arrangements; contact us for information relevant to your clinic.
Data security
We use account and role-based access controls, session controls, authenticated backend routes, and operational safeguards to reduce the risk of unauthorized access. Patient attachments are served through authenticated backend routes, not public static hosting.
No system can guarantee perfect security or prevent every loss. This does not reduce Clinora’s responsibility to meet applicable security duties and agreed safeguards.
Backups and retention
Active clinic records are retained to support care, clinic operations, record history, and applicable professional or legal obligations. Deactivating a patient or user does not delete the underlying records.
After a clinic stops using Clinora, data return and deletion must be arranged under the applicable agreement and legal retention requirements. Ending access does not itself erase clinic records. Contact us to coordinate the records needed and any deletion request.
Support, security, audit, consent, and messaging records serve different purposes from the active patient file. Retention must take account of the time needed to resolve enquiries, investigate incidents, demonstrate permissions, respect opt-outs, and meet applicable legal obligations; it is not permission to keep all information indefinitely.
Backups support disaster recovery and operational reliability. Deleted or corrected data may remain in backup copies and retained object versions until those copies or versions are removed under the applicable retention and storage lifecycle arrangements. Removing an attachment from the clinic view does not establish that every stored copy has already been erased.
Patient and user rights
Patients may request access to or correction of their information, and deletion or objection where applicable, usually through the clinic that maintains their records. These rights remain subject to applicable law, including professional recordkeeping duties. A request to correct a clinical record may require preserving an auditable history.
Clinic users may contact their clinic administrator or Clinora using the privacy contact above about account information. Patients can also contact Clinora: we will help route clinic-record requests and assist the responsible clinic as appropriate, and address requests concerning information for which we are responsible. We may need to verify identity or authority without asking for unnecessary clinical details.
Clinic responsibilities
Clinics are responsible for lawful collection and use, required notices and permissions, consent where required, staff access decisions, and professional recordkeeping. They should enter only information needed for their services and check contact details before sharing information or arranging messages.
Support access
Support requests should avoid unnecessary patient details. If support access to clinic data is needed, access should be limited to the issue being investigated.
Reports and exports
Reports and exports are generated for clinic operations. A report of the current view is not a complete export of all clinic records. Contact us to discuss a broader record request. After a clinic downloads or shares an export, the clinic is responsible for protecting that file.
Service and marketing communications
We may send service or account communications to clinic contacts, including account access, support, and service notices. These are separate from promotional communications. Receiving a service message or accepting this policy does not itself authorize marketing.
We do not sell clinic data or patient data, and patient data is not used for advertising.
Children and minors
Clinics may maintain records for minors when appropriate for their professional services. The clinic must manage required permissions and consent, including the authority of a parent, guardian, or other caregiver, and protect the patient’s applicable rights.
Changes to this policy
We may update this policy as the service and legal requirements evolve. The date above identifies the published revision. We will provide further notice or seek agreement where required by law or an applicable clinic agreement.
Contact us
For privacy questions, contact the legal operator, operating as Clinora, using the contact details listed above.