C
Clindo Privacy Policy
Last updated
August 29, 2026
clindo.io · clinic & dental practice management

Privacy Policy

This policy explains what Clindo collects through the Clindo web application, the ClindoMobile app for clinic staff, and clindo.io — and what it does not. It's written to match how the product actually works, not a generic template.

In short

  • 1ClindoMobile is a staff tool. It's used by dentists, doctors, receptionists and clinic administrators to run their clinic — not by patients directly.
  • 2Patient records belong to the clinic. Your clinic controls that data; Clindo processes it only to provide the service, under the clinic's instructions.
  • 3The mobile app requests one Android permission — to play a sound and vibrate when a patient is called in. No camera, microphone, contacts, or location access.
  • 4We don't sell data, run ads, or use analytics/advertising SDKs in the mobile app.
  • 5Records are deactivated, not instantly erased, when a clinic removes a patient or staff member — the same safeguard that protects a clinic's medical records from accidental loss. Full erasure can be requested; see Retention & deletion.
01

Who this policy covers

Clindo is a clinic and dental-practice management platform built by a small team based in the Palestinian Territories. It has three parts, all covered by this one policy:

  • the clindo.io marketing website;
  • the Clindo web application, used from a browser by clinic staff and, for some clinics, by patients through a limited patient-facing view of their own record; and
  • ClindoMobile, the Android/iOS app covered by this Google Play listing, used by clinic staff to manage patients, appointments, treatments and billing from a phone or tablet.

Where something applies to only one of these — for example, a browser-only feature — this policy says so explicitly.

02

Two roles: controller & processor

Because Clindo is software a clinic subscribes to, two different kinds of data flow through it, and Clindo plays a different role for each:

Your account data

Your name, login, contact details and role as a Clindo user. Here, Clindo is the data controller — we decide how it's used, as described in this policy.

Patient data

Everything a clinic's staff enter about their patients — records, treatments, documents, billing. Here, the clinic is the data controller and Clindo is a data processor, handling that data only to provide the service and only on the clinic's instructions.

If you're a patient with a question about your own medical record, the fastest path is your clinic — they hold the record and control it. We'll still help; see Your rights.

03

Information we collect

3.1 Your staff accountPersonal info

When your clinic creates your login, or you edit your own profile, we hold:

FullNameSurnameEmailLoginName Mobile1SMSMobileNumberNationalIdGender BirthdayAddressNotesAvatar photo

plus your role and permissions (which tabs, patients, and clinic rooms you're allowed to see), and, for doctors, whether your access to patient data is limited to patients you've treated.

3.2 Patient records your clinic keepsHealth infoFinancial infoFiles & docs

Entered by clinic staff, on the clinic's behalf, as part of running the practice:

  • Identity & contact — name, national ID, birthday, gender, marital status, occupation, address, phone numbers, email, tags, custom fields.
  • Clinical records — medical history, diagnoses, symptoms, main complaint, treatment plans, treatment notes and progress, and any medical reports or prescriptions staff write into the app.
  • Billing — treatment costs, payments recorded, discounts and outstanding balances. Clindo does not process card payments and never sees card numbers — these are internal accounting entries a staff member types in.
  • Documents — files a staff member attaches to a patient, treatment, or dental-lab order (for example X-rays, scans, referral letters or lab-order files), picked using the device's own file picker.

3.3 Device & login security dataDevice IDs

Each time you sign in, we automatically collect a device fingerprint and a few technical details — a device identifier, IP address, browser/platform, screen resolution, language and time zone — to protect accounts against unauthorized sign-ins from unrecognized devices. This isn't used for advertising or tracking outside the app.

3.4 What stays on your deviceDevice IDs

ClindoMobile keeps your sign-in token in the operating system's encrypted keystore, and caches your clinic's patient list in a local database so it's usable with a weak or dropped connection. Both are cleared when you sign out or uninstall the app.

3.5 Messages sent through our WhatsApp integrationMessages

Clinics can optionally connect their own WhatsApp number to Clindo to send appointment reminders and confirmations to patients. When a clinic uses this, the patient's phone number and the message content pass through our messaging gateway and then through WhatsApp's own infrastructure (operated by WhatsApp LLC / Meta), subject to WhatsApp's Privacy Policy. We don't read a clinic's other WhatsApp conversations — only messages sent through this integration pass through our systems.

3.6 Google Drive backup (web app only)Files & docs

From the web application's maintenance settings, a clinic administrator can optionally connect a Google Drive account to back up patient files. If connected, we access only the files the clinic chooses to store there, solely to save and retrieve that clinic's backups. This is not available in ClindoMobile, and access can be revoked at any time from the clinic's Google Account permissions.

3.7 Time-clock hardware (optional add-on)

Some clinics attach a biometric time-clock terminal for staff attendance. The terminal itself verifies a fingerprint, card or face locally — only the resulting punch record (staff ID, timestamp, and which method was used) is sent to our servers. We never receive fingerprint images or facial templates.

04

Data at a glance

A summary in the shape of Google Play's Data Safety categories, for the ClindoMobile app specifically:

CategoryExamples in ClindoShared with
Personal infoName, email, phone, address, national ID, user IDclinic staff only
Health infoMedical history, diagnoses, treatment notes, prescriptionsclinic staff only
Financial infoTreatment cost, payments recorded, balancesclinic staff only
Files & docsAttached X-rays, scans, lab-order filesclinic staff only
MessagesWhatsApp reminder text, patient phone numberWhatsApp / Meta*
Device / other IDsDevice fingerprint at sign-innot shared
App activitySign-in timestamps, sync activitynot shared

*Only when a clinic enables WhatsApp reminders. Nothing here is sold, or used for advertising, and ClindoMobile contains no third-party analytics or ad SDKs.

05

App permissions

ClindoMobile requests exactly one Android permission:

android.permission.MODIFY_AUDIO_SETTINGS

Used only to play a short chime and vibration when a patient is called into a room from the reception screen — the alert receptionists rely on even when their phone is on silent or face-down. It does not record audio.

The app does not request camera, microphone, contacts, location, or broad storage access. Attaching a document to a patient record opens the operating system's own file picker, which lets you choose a file without granting the app storage permission.

06

How we use information

  • To operate the app: authenticate sign-ins, sync a clinic's patients, appointments and treatments, and keep a role's view scoped to what it's allowed to see.
  • To protect accounts, by flagging sign-ins from unrecognized devices or locations.
  • To send appointment reminders and confirmations a clinic chooses to send via WhatsApp.
  • To provide support when a clinic or staff member contacts us.
  • To meet legal, tax, and healthcare recordkeeping obligations that apply to us or to a clinic we serve.
  • To maintain and improve the product — for example, understanding which features are used, based on aggregated, clinic-scoped activity, never sold or shared externally.

We do not use patient data to train third-party AI models, and we do not use any of this data for advertising.

07

How we share information

We share data only where it's necessary to run the service:

  • Within a clinic: staff see the patients, rooms and data their role permits — never other clinics' data. Clindo is multi-tenant and clinics are isolated from one another.
  • WhatsApp / Meta: only messages a clinic sends through our reminder integration, as described in 3.5.
  • Hosting & infrastructure providers: the servers and databases that store the above, bound to protect it and use it only to provide that infrastructure to us.
  • Legal reasons: if required by law, court order, or to protect the rights, safety or property of Clindo, a clinic, or the public.
  • Business transfers: if Clindo were involved in a merger, acquisition, or asset sale, data would transfer under the protections of this policy.

We do not sell personal data, and we do not share it with data brokers or advertisers.

08

Security

  • Traffic between the app and our servers is encrypted in transit (HTTPS).
  • Sign-in tokens are stored in the device's encrypted keystore, not in plain text.
  • Access inside the app is scoped by role and by tenant — for example, a doctor with limited access only sees patients they've treated, and reception staff only see the clinic rooms assigned to them.
  • New-device sign-ins are checked against the device fingerprint described in 3.3.

No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but the practices above reflect how the app is actually built, not a boilerplate promise.

09

Retention & deletion

When a clinic removes a patient or staff member, Clindo deactivates that record rather than instantly deleting it — the same protection that keeps a receptionist's misclick, or an accidental removal, from wiping a medical record a clinic may be legally required to keep. A deactivated record is hidden from normal use immediately.

To request that a specific record be permanently erased rather than deactivated, contact us (see Contact us). We'll act on the request to the extent permitted by law and by the recordkeeping obligations that apply to healthcare providers in the relevant jurisdiction — for patient data, we'll also confirm the request with the clinic that controls that record, since they're responsible for their own retention obligations.

On-device data — your cached sign-in token and offline patient cache — is removed the moment you sign out or uninstall the app.

10

Your rights

Depending on where you're located, you may have the right to access, correct, restrict, or request deletion of your personal data, and to object to certain uses.

  • Staff account data — contact us directly, or ask your clinic's administrator to update your profile from the app or web dashboard.
  • Patient data — contact your clinic first, since they control that record; we'll assist them, and you, on request.
11

Children's privacy

ClindoMobile is a professional tool for clinic staff and is not directed at children; we don't knowingly collect account data from anyone under 16 through the app. A clinic may record a minor patient's information as part of ordinary healthcare recordkeeping, entered by clinic staff with the consent of the patient's parent or guardian, under the clinic's own policies — the same way a paper chart would.

12

International transfers

Clindo is based in the Palestinian Territories. Data may be processed on servers located outside a clinic's own country. Where that happens, we take reasonable steps to keep it protected consistent with this policy, regardless of where it's processed.

13

Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and post the new version here. For material changes — for example, a new category of data we collect — we'll make a reasonable effort to notify clinic administrators directly before the change takes effect.

14

Contact us

Questions about this policy, or a request relating to your data, can go to:

Clindo

Phone+972 56 930 0644
LocationPalestinian Territories