Privacy Policy
Last updated: May 2026
1. General
The Hibur Bari platform (tipulim.app) is committed to protecting your privacy and personal data in accordance with the Protection of Privacy Law, 5741-1981, the Protection of Privacy Regulations (Information Security), 5777-2017, and the Patient's Rights Law, 5756-1996. This policy explains what types of information we collect, how it is used, how it is protected, and what your rights are regarding your data.
2. Information We Collect
As part of the service, we collect the following types of information: • Identifying personal information: full name, email address, phone number, national ID number • Medical information: treatment summaries, clinical notes, intake questionnaires, session transcripts • Appointment information: appointment dates, treatment types, status • Payment information: payment amounts, dates, payment methods (without full card details) • Technical information: IP address, browser type, device information — for security purposes only
3. Purposes of Use
The information collected is used solely for the following purposes: • Managing appointments and sending reminders • Maintaining medical records as required by law • Processing payments and issuing receipts • Communicating with the patient (reminders, updates, follow-up) • Improving the service and maintaining the system — based solely on internal system data, and not on Google user data • Complying with legal and regulatory requirements The information will not be used for marketing or commercial purposes that are not directly related to providing the service, except with your explicit consent.
4. Transfer of Information to Third Parties
Your information will not be transferred to any third party, except in the following cases: • Infrastructure providers: hosting, database, and messaging services — operating under a Data Processing Agreement (DPA) and bound by confidentiality • Google Calendar sync (optional): If the practitioner has chosen to connect their Google Calendar, appointment details (treatment type, the patient's first name, and the appointment date and location) will be sent to that practitioner's Google Calendar for display purposes. No medical details, phone number, email, or ID number will be sent. The sync is enabled solely at the practitioner's initiative and can be disconnected at any time. • Legal obligation: as required by a court order or a demand from a competent authority • Your consent: only where you have given explicit prior consent Credit card details are not stored in the system at all — they are processed directly by a PCI-DSS-certified payment processor.
5. Data Security
The system meets the requirements of the medium security level under the Protection of Privacy Regulations (Information Security), including: • Encryption of all communications (TLS/HTTPS) • Encryption of sensitive data in the database • Two-factor authentication (MFA) for access to medical information • Complete data isolation between different practitioners • Logging and monitoring of access to all sensitive data • Daily encrypted backups • Role-based access control
6. Data Retention and Deletion
Medical records are retained for 7 years in accordance with the Patient's Rights Law. After this period, the information is securely deleted. Identifying personal information (name, phone, ID number) can be deleted at any time upon your request — medical records will be retained in anonymized form in accordance with the law.
7. Your Rights
Under the Protection of Privacy Law, you have the following rights: • Right of access: the right to receive a copy of all personal information held about you • Right to rectification: the right to request the correction of incorrect or inaccurate information • Right to erasure: the right to request deletion of your personal information (subject to legal retention obligations) • Right to portability: the right to receive your information in a structured, readable format • Withdrawal of consent: the right to withdraw consent that has been given, at any time To exercise your rights, you can contact us through the settings page in your personal area, or reach out directly to your practitioner.
8. Use of Cookies
The system uses only essential cookies for authentication management and preference storage. No marketing or third-party tracking cookies are used.
9. Changes to This Policy
We reserve the right to update this policy from time to time. In the event of a material change, notice will be sent to registered users. Continued use of the service after an update constitutes acceptance of the updated policy.
10. Google API Services
The use and transfer of raw or derived user data received from Google APIs (including Google Calendar) will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data received from Google will be used solely for the specific function requested by the user — syncing appointments to the practitioner's Google Calendar — and for no other purpose whatsoever. Specifically: Google user data will not be used to improve the service, for advertising, to train models, to transfer to third parties, or for any purpose other than displaying the appointment in the calendar. Access to Google data is retained only while the practitioner has connected their calendar, and can be revoked at any time from the Settings page.
11. Data Processing Location
All system data — including medical records — is stored in Israel: the database (AWS Aurora), file storage (AWS S3), and identity management (AWS Cognito) all run in the AWS Israel region (il-central-1). The application servers, which process requests without persisting data, currently run on Vercel infrastructure in the European Union (Dublin, Ireland), and communication between them and the data stores in Israel is encrypted end-to-end (TLS). The transfer of information between the application servers and the data stores is carried out in accordance with the requirements of the Protection of Privacy Law, 5741-1981, and its regulations.
12. Contact
For questions regarding privacy or to exercise your rights, you can contact us: • Email: privacy@tipulim.app • Through the contact form on the website