What we collect — at a glance
This table is a plain summary only. The detailed sections below govern. "Controller" and "Processor" are explained in section 3.
| If you are… | What is collected, in brief | Our role |
|---|---|---|
| A patient (incl. a walk-in your clinic registered) | Your identity and contact details, basic profile details, the health information your doctor or clinic enters about you, your appointment details, and your clinic's billing records | We are the Processor; your clinic is the Controller of your medical record |
| A guardian / a minor | The above, plus the guardian–dependent relationship | Processor (clinic is Controller) |
| A doctor or secretary (clinic staff) | Your account and account-security data, plus a log of your actions inside patient records (sections 4, 6) | We are the Controller for your account; the clinic controls staffing |
| A clinic owner | The above, plus clinic business details, subscription details, and verification records | Controller (account/platform); Controller with the clinic for business data |
| A website visitor | Essential cookies, your language choice, and technical data needed to serve and secure the site | Controller |
We use no analytics or advertising trackers, and we do not sell your personal data (sections 9, 10).
If a clinic registered you, that account and that record exist because the clinic decided to create them. Asking you first is the clinic's responsibility, and so is deciding which of its staff may open your record — neither decision is ours (sections 3.4, 5).
1. Who we are, scope, versions, and updates
1.1 Who we are. The Platform is operated by Clareeva, a company registered in Palestine ("Clareeva", "we", "us"). Clareeva is a software platform that lets clinics in Palestine manage appointments, patient records, reception, billing, and clinical documentation. Each clinic that uses Clareeva is a separate business that decides how it treats its own patients' information.
Clareeva is an online service and does not operate a public office, so no postal address is given. Every route to reach us is listed in section 18; written contact is by email.
1.2 What this policy covers. This policy explains how personal information is handled on the Clareeva Platform: information about patients (including people a clinic registers who never use the site themselves), clinic staff, clinic owners, and visitors to our public pages. It also explains which decisions are ours and which belong to your clinic (section 3).
1.3 What this policy does not cover. It does not cover a clinic's own separate systems, paper records, or the private practices of individual doctors outside Clareeva. It does not replace any notice, consent form, or agreement your clinic gives you directly. Limits on our legal liability are set out in our Terms & Conditions (a companion document — see section 19).
1.4 Versions and updates. This policy carries a version number and a last-updated date at the top. When we change it, we update both and follow section 17.
2. Definitions (in plain words)
- Personal data — any information that identifies you or can be linked to you, such as your name, phone number, or health details.
- Health data (medical information) — information about your body, health, diagnoses, treatment, or care. It is among the most sensitive categories of personal data and we treat it with extra care.
- Controller — the party that decides why and how personal data is used.
- Processor — a party that handles personal data on behalf of, and under the instructions of, a Controller.
- Service provider — an outside company we use to help run the Platform, acting on our instructions (section 10).
- One-time code — a short code sent once to your phone or email to confirm it is you.
- De-identification — removing obvious identifiers from a piece of text before it is sent onward. It reduces risk but is not the same as making data fully anonymous.
3. Our roles — who is responsible for what
Responsibility depends on the type of data. This split matters because it decides who you ask to see, correct, or delete information.
3.1 Your clinic is the Controller of your medical record — we are the Processor. When a clinic (through its doctors and secretaries) creates or enters a patient's medical information — complaints, clinical notes, diagnoses, orders, prescriptions, uploaded medical files, intake answers, and any AI-assisted drafts — the clinic decides why and how that information is used. We process it on the clinic's behalf and according to its instructions. The clinic remains responsible for:
- deciding whether to register a patient on the Platform at all, and creating that patient's account and record — including for a person who is not present and may never sign in;
- asking that patient for the consent the law requires — before the record is created, and before its staff open it (section 3.4);
- having a lawful basis to collect and keep its patients' data;
- deciding which of its staff may see which patient's record;
- responding to its patients' requests about their medical records;
- giving its patients any required in-clinic notice (section 6).
3.2 We are the Controller of accounts, platform operations, and the public site. For the information we decide how to use ourselves, we are the Controller. This includes account and login identity, platform security and audit logs, the subscription relationship with clinic owners, and our public pages and "browse clinics" pages.
3.3 Contractual arrangements with clinics. The contractual detail of the processing relationship between us and a clinic is set out in a Data Processing Agreement, a separate document between us and that clinic setting out our obligations as its Processor, rather than in this public policy.
3.4 Creating your account, and who may see your record — your clinic's responsibility, not ours. We supply software. We do not create patient accounts, and we take no part in the decision to create one. Every patient record on the Platform exists because a clinic chose to create it, or because the patient registered themselves. In particular:
- The decision to register you is your clinic's alone. A clinic can create a complete record for a person who is not present and never signs in. Whether that happens, and when, is decided in the clinic, by the clinic, for its own reasons.
- Asking you first is your clinic's obligation. We expect every clinic to obtain the consent the law requires from every patient — before it creates the account, and before its staff open the record — and clinics undertake this to us in writing.
- We do not check that you were asked. We are not present for the conversation, we do not verify that any consent exists, and we do not judge whether the clinic had good reason to register you or to open your record. Where the Platform offers a clinic a way to record that it asked you, that is a convenience for the clinic and not a check by us, and using it moves none of the clinic's responsibility to us.
- How that is recorded in practice. When a member of a clinic's staff registers you at the reception desk, they confirm on screen that you are present in front of them, that they showed you this policy and the Terms & Conditions, and that you agreed. We record that the confirmation was made, which member of staff made it, when, and which version of each document was in force at that moment. That confirmation is the clinic's statement about a conversation held at the clinic; it is not your acceptance — which is why, the first time you sign in to your account, you are shown both documents and asked to accept them yourself (section 6.3).
- Your phone number is recorded as the clinic enters it. When a clinic registers you at its desk, we do not send a code to the number to confirm it before creating the account; we rely on the clinic having taken it from you while looking at you. Your login details are then sent to that number by SMS. If the wrong number is entered, those details can reach somebody else — and that is the clinic's responsibility (Terms & Conditions, section 17.2). Clinic staff can issue a fresh password at any time, which invalidates the previous one immediately.
- Who may see your record is set by your clinic. The Platform limits access by role and by the patient's relationship to the clinic, but the clinic decides which of its staff hold which role. Staff actions inside a record are logged and visible to the clinic owner (section 4.2).
- If you were registered without being asked, or you believe a member of staff opened your record without cause, that is a matter between you and the clinic that holds the record. Raise it with the clinic and, if it is not resolved there, with the relevant professional or regulatory authority (section 19.5).
4. What we collect — by audience
Below is a summary by who you are. Not every clinic uses every feature.
4.1 Patients (including walk-in patients a clinic registers). - Identity and contact: your name, contact details, and basic identifiers, needed to log you in and to attach you to the right record. - Profile: basic details such as date of birth and gender, an optional photo, and an emergency contact. - Health data your clinic enters about you: your medical history, clinical notes, medical orders, prescriptions, uploaded medical files, and reports addressed to you. - Booking and intake: appointment details, your stated reason for the visit and intake answers, any files you attach, and family-visit details. - Billing: invoices, payments, and balances as your clinic records them. - Staff notes about you: notes written by a secretary or doctor, visible only to defined staff audiences. - Appointment-compliance signals: used to manage missed appointments (section 6). - Notifications: in-app messages sent to you.
4.2 Clinic staff (secretaries and doctors). - Account identity: your name, contact details, and identifiers, and a password stored in a protected form that cannot be read back as text. - Security data (if you enable it): two-factor elements and recovery codes, stored in a protected form. - Verification files: for doctors, identity documents, practice licence, and certificates uploaded for review. - Activity logs: a record of the actions you take inside the system — including which patient records you act on, the action, a timestamp, and technical details of the request. These logs are visible to your clinic owner and to platform administrators, and are used for security and accountability (section 6). We tell you this plainly so that our logging is not a hidden form of monitoring.
4.3 Clinic owners. - The staff/account data above, plus clinic business details, staff-management records and the invitations you send, and subscription details.
4.4 Website visitors. - Essential cookies and your language preference (section 9), and technical data needed to serve, secure, and troubleshoot the site.
4.5 Records of your agreement (everyone who signs up). When you accept this policy and our Terms & Conditions — at registration, or when we ask you to accept a new version — we record which document you accepted, which version, and when. For a clinic owner, this also covers the Data Processing Agreement. We keep this as proof of your agreement; it holds no more than that.
If a clinic registered you at its desk, there are two separate records, and they are never merged:
- The clinic's confirmation — that a named member of staff showed you both documents and that you agreed. It holds that staff member's name, the date of the confirmation, and the version of each document in force at the time. It is the clinic's statement, not yours (section 3.4).
- Your own acceptance — recorded when you read both documents in your account and accept them yourself, in the form described at the top of this paragraph.
The clinic's confirmation is kept even after you accept for yourself, because it is a record of something that happened. You can ask for a copy of both (section 13).
5. Where the data comes from
- From you — when you register, log in, book, fill in an intake form, upload a file, or write a review.
- From your clinic, about you — this is important: much of a patient's record is entered by the clinic's staff, not by the patient. A secretary can register a walk-in patient standing at the desk, typing that patient's details for them, and a doctor writes the clinical record. If your clinic created your record, the information came from the clinic, and your clinic is the Controller of it (section 3). The clinic decided to do that, and asking you first was the clinic's responsibility (section 3.4). An account created at a desk is active immediately and its login details are sent to the phone number the clinic gave, so you can sign in whenever you like — and you may never do so.
- From a guardian — for a minor or dependent, a guardian may provide the information.
- Automatically — technical data and cookies are collected when you use the site (sections 4.4 and 9).
6. Why we use the data, and on what basis
6.1 Purposes. - To provide the service — create and manage accounts; book, reschedule, and cancel appointments; maintain the clinical record; produce prescriptions, orders, and reports; record payments and track balances. - To verify identity and secure access — one-time codes, password login, and optional staff two-factor authentication. - To communicate — appointment confirmations and reminders, verification messages, and service notices (section 8). - To keep the Platform safe and accountable — limiting abuse, and audit logs of staff actions so clinics and platform administrators can investigate misuse and protect patients. - To manage missed appointments — according to the rule each clinic sets. - To run the business — subscriptions and support for clinic owners. - To meet legal duties — including duties of medical confidentiality and any record-keeping obligations. - AI assistance for doctors — see section 7.
6.2 Our legal basis. We rely on performance of the service and our contract with you; on the clinic's provision of medical care and its professional duties; on our legitimate interests in securing the Platform, preventing abuse, and keeping audit logs, balanced against your rights; on legal obligation, where a law requires us to keep or disclose information; and on consent, where consent is the appropriate basis.
6.3 Acceptance. Creating an account or using the Platform means you accept this policy and the Terms & Conditions. For patients a clinic registers who may never use the site themselves, obtaining any required consent and giving any required notice is entirely the clinic's responsibility. We expect every clinic to ask the patient before it creates an account or opens a record, and we do not verify that it did (section 3.4).
Registration at a clinic's desk has two stages, and neither replaces the other:
- The clinic records that it asked you — the member of staff confirms on screen that you are present, that they showed you both documents, and that you agreed; this is stored under their name (sections 3.4 and 4.5).
- Then you accept for yourself — the first time you sign in to your account, both documents are put in front of you before anything else and you cannot go further until you accept. Until you do, there is no record on the Platform that you accepted, only a record that the clinic said it asked you.
In either case you may object to your record existing at all (sections 13 and 19.5).
7. AI features
Some clinics use optional AI features, disabled by default, to help doctors write notes.
7.1 What they do. A doctor can dictate a note aloud and have it turned into text, can have the Platform help draft or clean up a clinical note, and can produce a history analysis or a patient-facing report letter.
7.2 Dictation, not consultation recording. The voice feature is built and presented as a dictation tool for the doctor: the doctor describes the case aloud and it becomes text. It is not designed to record the conversation between a patient and their doctor, and there is no patient-side or ambient recording in the product. Because a microphone captures whatever sound is near it, a doctor could nonetheless capture a patient's voice — and recording a patient's voice requires that patient's consent, which is the responsibility of the clinic and the treating doctor; the doctor's screen says so.
7.3 The content is clinical information, and it is processed by service providers. Dictated or typed content is clinical information about the patient, and it is processed by service providers acting on our instructions (section 10).
7.4 De-identification is best-effort, not anonymisation. On the paths where we remove identifiers before sending, the removal is best-effort. We cannot promise the result is fully anonymous, and the Platform must not be described as anonymising anything.
7.5 We do not store the audio or the raw output. Dictation audio is not saved on our servers, and raw output is not stored as a separate file. What we do keep is a metadata record of each request (that a request happened, for which patient, and its status) — not the content. The note or report the doctor chooses to save becomes part of the clinical record in the ordinary way.
7.6 A doctor reviews the AI output. AI drafts are a starting point for the doctor. The treating doctor is responsible for reviewing, correcting, and deciding what goes into the record.
8. Messages and notifications
We send you in-app notifications, emails to verified addresses, and SMS text messages where your clinic enables them.
- Verification codes contain only a short code and no health information.
- The login-details message, when a clinic registers you at its desk, contains the clinic's name, your phone number, a generated password and a link to the site, and no health information. We advise changing that password at your first sign-in, and remind you to on screen.
- Appointment reminders, where a clinic enables them, contain what is needed to identify the appointment. This does not describe your condition, but the fact that you have an appointment at a particular clinic can itself suggest a care relationship, so we treat it carefully. Appointment reminder SMS are off by default and are enabled per clinic.
Message bodies are not written to our application logs, and phone numbers are masked in our logs.
9. What is stored in your browser
We keep this minimal, and we do not use advertising or analytics trackers.
9.1 Cookies. We use essential cookies to keep you signed in and to protect forms; an optional cookie that lets staff skip two-factor authentication on a device you chose to remember (revocable); and a functional cookie that remembers your language choice.
9.2 Data stored in your browser. Interface preferences (such as theme and view options) are kept in your browser and contain no health information. Unsaved clinical-note drafts are also kept in the doctor's browser until saved or cleared — this is the one place clinical content can rest in the browser, which matters on shared clinic computers.
10. Service providers, and processing outside Palestine
We use a limited number of carefully selected service providers to run the Platform — for hosting, file storage, messaging, email, and the optional AI features. These providers handle data only as far as is necessary to perform their service, and on our instructions.
We do not sell your personal data, and we do not use clinical records to train our own models.
Some of these providers operate outside Palestine, which means your data may be processed or stored outside it. Where that happens, we choose providers with reasonable care and apply appropriate safeguards.
11. How long we keep data
- Short-lived security items — such as verification codes, confirmation links, and sessions — expire automatically after short periods.
- Technical and delivery logs are kept for limited periods and are then pruned or stripped of personal details.
- Clinical and account data are kept for as long as the record or account exists, and as far as needed for the purposes described in this policy or required by law.
- Backups are taken regularly and are replaced within a limited cycle.
Medical-record retention duties may require us or your clinic to keep certain health records even if you ask for deletion. In that case we keep only what the law or the clinic's duty requires (section 13).
12. How we protect data (security measures, not guarantees)
We apply a range of security measures, including: encryption of the connection in transit; storing passwords in a protected form that cannot be read back as plain text; optional two-factor authentication for staff; encryption of clinical free text at rest; encrypted database backups; access limited by role and by the relationship to the patient — though which of its staff hold which role is the clinic's decision (section 3.4); limits on repeated login attempts; uploaded files stored privately and served only through access-checked views; audit logging of sensitive actions; and additional hardening of the platform-administration panel.
Two plain statements: - Clinical free text is encrypted at rest; patient identifiers remain readable, because they are needed to log you in, verify identity, and search records. - No system is perfectly secure. We cannot and do not guarantee that data can never be accessed, altered, or lost. We work to reduce that risk and to respond if something goes wrong (section 16).
13. Your rights, how to use them, and their limits
Subject to applicable law, you may ask to: access the personal data held about you; correct inaccurate data; delete data (subject to the limits below); object to or ask us to restrict certain uses; and receive a readable copy of your account data.
How to make a request — two channels:
- For your medical records (to see, correct, or delete health information a clinic entered about
you), contact your clinic. The clinic is the Controller of that record and decides on the
request; we assist the clinic as its Processor.
- For account, login, platform, or general privacy matters, contact us at
support@clareeva.com.
- If you were registered without being asked, or a staff member opened your record, contact
your clinic — the decision to register you and the access its staff have are the clinic's, not
ours (sections 3.4, 19.5).
Limits you should know about:
- You can download a copy of your account data yourself. From your profile, "Download my data"
produces a readable copy of the data we control. It deliberately excludes your clinical
record — what your clinic authored, holds, and discloses as the Controller — as well as notes about
other people and our security logs. The copy itself explains what is left out and where to ask
for it.
- You can close your account yourself, but closing is not deletion (section 15).
- There is no self-service "delete all my data" button, and we do not promise one. Deleting a
patient's medical record is not ours to do: your clinic is the Controller of that record and may be
legally required to keep it. Requests that go beyond closing an account are handled manually —
write to support@clareeva.com.
- Some data must be retained despite a deletion request — such as health records subject to
retention duties, and security and audit logs kept unaltered for integrity.
- Notes that describe another person — for example the relative who accompanied you to a visit or
who paid your bill — belong to the clinic's record about someone else, and we will not remove them
at your request.
- For walk-in patients who never had a login, requests are made through the clinic that holds the
record.
14. Children and minors
Clareeva is used to provide care to patients of all ages, including children. A minor's record is usually created by the clinic and/or managed by a guardian, and the system links a dependent to a guardian. Date of birth is used to determine whether a patient is a minor. Where the law requires a guardian's involvement or consent for a minor's data — including consent to creating the child's record in the first place — that responsibility sits with the clinic and the guardian, and we do not verify it (section 3.4).
15. Closing an account and what happens to the data
Patients can close their own account from their profile page. We deliberately offer closing rather than deleting, because deleting would be a promise we cannot keep: your medical record belongs to the clinic that created it, not to us (section 3), and medical records are subject to retention duties (section 11).
What closing does: - your login stops working, and every open session and trusted device is signed out; - notifications, appointment reminders, SMS, and emails to you stop; - your clinic's staff see your account marked as closed, so they know you are not being contacted.
What closing does not do: - it does not delete your medical records. Consultation notes, prescriptions, uploaded files, and visit history stay with the clinics that treated you, and those clinics can still see them. That is how a medical record is meant to work, and in many cases how the law requires it to work; - it does not delete audit or security logs, which are kept unaltered for integrity.
Closing is not available while you hold active clinic staff membership or own a clinic (those end through your clinic, not through this page), or while you have an upcoming appointment — cancel it first, so the clinic is not left holding a slot for a patient it can no longer reach.
Reopening. Closing is reversible by you and nobody else. Sign in with your usual phone number and password; because the account is closed, we send a code to your registered phone, and confirming it reopens the account as it was. A platform administrator cannot reopen it for you.
Other account actions: a platform administrator may suspend any account to protect the safety of the Platform and the security of its users (disabled, not erased, and distinct from your own closure; this power is set out in full in the Terms & Conditions); a clinic may revoke a staff member's access; and a dependent may be graduated to their own profile.
16. If there is a data breach
If we become aware of a security incident affecting personal data, we will investigate, work to contain and fix the problem, assess who and what is affected, and notify the affected clinics and, where appropriate, affected individuals and any competent authority, in line with applicable law, without undue delay.
17. Changes to this policy
We may update this policy as the Platform and the law evolve. When we do, we will change the version number and last-updated date at the top. For significant changes, we will take reasonable steps to bring the update to your attention, and we may ask you to accept the new version before you carry on using the Platform. Continued use of the Platform after we publish an update means the updated policy applies.
18. How to contact us
- Account, platform, and general privacy questions:
support@clareeva.com. - Your medical records: contact your clinic, which is the Controller of that information (section 13).
19. Governing law, complaints, and limits on claims
19.1 Governing law. This policy and any dispute about it are governed by the laws applicable in Palestine.
19.2 Talk to us first. We aim to resolve concerns directly. If you have a complaint, a comment,
or a question about your privacy, write to support@clareeva.com and we will look at it and
reply.
19.3 No legal action. If you are not happy with the Platform — any feature, its content, its
appearance, its availability, any aspect of the Service, the outcome of using it, or how we handle
your information — your only remedy is to contact support at support@clareeva.com or to stop using
the Platform. You may not bring any claim, demand, action, or proceeding against us in respect of it,
and by using the Platform you waive any right to pursue us legally over it. We undertake to look at
everything that reaches us through support and to reply to it.
19.4 Relationship to the Terms & Conditions. Limits on our legal liability are set out in full in our Terms & Conditions, a separate companion document.
19.5 Complaints about care, registration, or access. A complaint about medical care, a doctor's conduct, or a medical record is not a dispute with us. Neither is a complaint that a clinic registered you without asking you, or that its staff opened your record: the decision to create a patient's account and the access a clinic's staff have to it are the clinic's alone, and we have no part in either (section 3.4). Raise it with your clinic and, if necessary, with the relevant professional or regulatory authority.