Effective January 1, 2025 · Last updated April 15, 2026
01
Introduction
Shinobi Clinix Ltd. ("Shinobi Clinix", "we", "us") operates an AI-powered customer engagement platform for healthcare providers, including dental clinics and wellness centers. This policy explains how we collect, use, and protect your information in accordance with the Israeli Privacy Protection Law (חוק הגנת הפרטיות, תשמ"א-1981) and its regulations, as well as applicable international data protection standards. By using our platform, you agree to this Privacy Policy.
02
Information We Collect
Account info
•Full name, email, phone number
•Encrypted password
•Role in your organization and clinic name
Patient data
•Contact info and WhatsApp conversation history
•Appointment details and language preferences
•Conversation metadata and follow-up stages
Knowledge base
•Documents, FAQs, pricing and service catalogs
•Business hours and practitioner information
Usage & communication
•Login timestamps, device info, IP address
•Support tickets, feedback and error logs
03
How We Use Your Information
•Operating and maintaining the AI chatbot platform
•Processing appointments and sending WhatsApp reminders
•Improving features and optimizing AI responses
•Sending service updates and security alerts
•Complying with applicable laws and regulations
04
Quality Assurance & Platform Optimization
As part of our commitment to delivering reliable and high-quality services, Shinobi Clinix employs standard industry practices for platform optimization and service continuity:
•Service monitoring - we may review platform interactions, including conversation data, to evaluate and improve the performance of our AI systems, ensure accuracy of automated responses, and enhance overall service quality
•Technical support & intervention - authorized Shinobi Clinix personnel may access your account environment in real-time to identify, diagnose, and resolve technical issues, ensuring seamless and uninterrupted service delivery for your clinic
•No AI model training - your data is never used to train AI models. We use the OpenAI Business API, which by default, and under a signed Data Processing Addendum, does not train on data submitted through it
All such activities are performed exclusively by authorized personnel under strict confidentiality obligations. Access is limited to what is necessary for the stated purposes and is never used for unrelated commercial purposes or shared with third parties.
05
Data Sharing & Disclosure
•WhatsApp (Meta) - phone numbers and conversation content for message delivery
•Cloud hosting - all platform data, encrypted at rest
•Analytics - anonymized usage data only
•Legal - when required by law or court order
•Business transfers - in the event of a merger or acquisition
06
Data Retention
•Account information - duration of account + 2 years
•Conversation history - 365 days by default, configurable per clinic
•Voice messages - 30 days; the audio file itself is never stored
•Appointment records - retained for accounting and audit purposes; personal identifiers are anonymized after 24 months of inactivity
Retention is enforced automatically by scheduled jobs, not by manual deletion. You may request anonymization at any time, subject to legal requirements.
07
Data Security
•Encryption - TLS 1.3 in transit, AES-256 at rest
•Access control - role-based permissions; two-factor authentication (TOTP) is available and can be mandated for your clinic on request
•Application error monitoring and automated health checks. We do not currently operate a dedicated intrusion detection system or a security operations centre
•Regular encrypted backups with disaster recovery
•Audit logs for sensitive administrative actions; appointment event ledgers are append-only and cannot be edited or deleted
08
Your Rights (GDPR & Israeli Privacy Law)
•Access - request a copy of your personal data
•Rectification - request correction of inaccurate data
•Anonymization - request that your personal identifiers be removed. We de-identify rather than delete, so anonymized records remain for accounting and audit compliance
•Restrict - limit how we process your data
•Portability - receive your data in machine-readable format
•Object - object to processing based on legitimate interests
•Withdraw consent - at any time, without affecting prior processing
Contact support@shinobigrp.com - we respond within 30 days.
09
International Data Transfers
Shinobi Clinix is based in Israel, recognized by the European Commission as providing adequate data protection. For transfers to other countries we use Standard Contractual Clauses (SCCs) or other appropriate safeguards.
10
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect data from children. If you believe a child has provided personal data, contact us immediately.
11
Cookies & Tracking
We use essential cookies only - for session management, authentication, and security. No advertising or tracking cookies. You can disable cookies in your browser settings, though this may affect functionality.
12
Changes to This Policy
We may update this policy periodically. Changes will be posted here with an updated date. Significant changes will be communicated via email or platform notification. Continued use of the platform constitutes acceptance.