1. Introduction
This Privacy Policy describes how personal information is collected, stored, processed, and protected in the MedLearn system for building online courses for healthcare professionals ("the System"), operated by the System operator ("the Company").
The policy was prepared in accordance with the Protection of Privacy Law, 5741-1981 (including Amendment 13), the Protection of Privacy (Information Security) Regulations, 5777-2017, and the guidelines of the Privacy Protection Authority.
This policy is an integral part of the Terms of Use. Use of the system constitutes agreement to its terms.
2. Database Owner and Data Processor
The medical or organizational institution that purchased a subscription to the system is the owner of the database regarding its employees' and learners' data, and it determines the purposes of processing.
The Company acts as a data holder and processor on behalf of the institution, and processes information solely in accordance with its instructions and for the purpose of providing the service.
Inquiries from institutional employees regarding their personal information will be directed primarily to the institution's manager; the company will assist the institution in fulfilling these inquiries.
3. Types of Information Collected
Identifying information: Full name, email address (or alternative username), mobile phone number, profile picture (optional), institutional affiliation, team, and role.
Learning Information: course affiliations, progress in content units, viewing times, answers and results of quizzes and summative exams, grades, certificates issued, and assignments given.
Operational and Technical Information: IP address, browser and device type, login and logout times, language preferences, and activity logging in the Audit Log.
Billing Information: Institution details for invoicing purposes, payment history, and references. Credit card details are processed directly by the payment provider and are not stored on the company's servers.
The system is not intended for storing identified medical information of patients, and uploading such information is prohibited.
4. Purposes of Information Use
Service Provision: account creation, identity verification, building and displaying learning content, managing courses and exams, and issuing certificates.
Control and Management: Presenting progress reports to institution managers, managing permissions, documenting actions for internal audit purposes and regulatory compliance.
Information Security: Anomaly detection, prevention of unauthorized access, and investigation of security incidents.
Service improvement: Aggregate and anonymous usage analysis to improve user experience and system stability.
Operational communication: Sending essential service messages via email and SMS, including one-time verification codes, password resets, and task updates.
5. Legal Basis for Processing
The processing relies on the contractual agreement between the company and the institution and between the institution and its employees, on a legitimate interest in managing training and securing the system, and on legal obligations incumbent on medical institutions in the field of training and documentation.
Providing information is not a legal requirement, but it is a necessary condition for using the system. Without basic information, it is not possible to create an account or provide the service.
7. Information Security
The Company implements technological and organizational protection measures in accordance with information security regulations: traffic encryption (TLS), data encryption at rest, role-based access control and row-level permissions, environment separation, and two-factor authentication via a one-time code.
Access to information is limited to role holders who need it for their work only, and every sensitive action is documented in an audit log.
Periodic backups and ongoing controls are performed to identify vulnerabilities. However, no online system is completely immune, and the company cannot guarantee absolute immunity.
In the event of a serious security incident, the company will act in accordance with the reporting obligations stipulated in the regulations and will notify the database owner and the Privacy Protection Authority as required.
8. Data Retention Period
The information is stored for as long as the institution's subscription is active and for the period required for the purposes for which it was collected.
Upon termination of the engagement, the institution may request data export within 30 days; thereafter, the information will be deleted or anonymized, except for information for which there is a legal retention obligation (such as accounting documentation according to tax laws).
Certificate records and certificate verification may be retained for a longer period for the purpose of verifying their validity, in accordance with the institution's directive.
9. Data Subject Rights
According to Article 13 of the Protection of Privacy Law, every person is entitled to inspect information about them held in a database.
Should a person find that the information is incorrect, incomplete, unclear, or not updated — they may request its correction or deletion, in accordance with Section 14 of the Law.
In accordance with Amendment 13 to the Law, the data subject is entitled to receive information on the processing method and data sources, and to object to certain uses subject to the law.
The exercise of rights shall be made by contacting the institution's manager or the company at the contact details at the end of this document. A response will be provided within the period prescribed by law.
Nothing herein shall derogate from the institution's right to continue to retain information required for control, compliance, and proof of completed training.
11. Processing by Artificial Intelligence
For the purpose of script writing, content translation, slide analysis, test question creation, and narration production, instructional content may be sent to artificial intelligence providers acting as sub-processors.
The content sent is limited to the training materials themselves. Do not upload sensitive personal information or identified medical information of patients to these contents.
The outputs may contain inaccuracies and require professional review by the institution before use.
12. Minors
The system is intended for professional use by adults aged 18 and over only and does not knowingly collect information about minors.
13. Policy Changes
The Company may update this policy from time to time. A material update will be brought to the attention of users through a notification in the system or by email, and will continue to apply to usage from the moment of its publication.
14. Contact Us and Data Protection Officer
For privacy inquiries, exercising rights of inspection, correction or deletion, and for reporting a data security incident — you can contact us by phone at 04-3005117 or through the contact us page on the website.
A complaint can also be filed with the Privacy Protection Authority in the Ministry of Justice.