Legal document

Privacy Policy

How we collect, secure, and process personal information in the MedLearn system for building online courses, in accordance with the Privacy Protection Law and Information Security Regulations.

Last updated: October 6, 2026

1. Introduction

This Privacy Policy describes how personal information is collected, stored, processed, and protected in the MedLearn system for building online courses for healthcare professionals ("the System"), operated by the System operator ("the Company").

The policy was prepared in accordance with the Protection of Privacy Law, 5741-1981 (including Amendment 13), the Protection of Privacy (Information Security) Regulations, 5777-2017, and the guidelines of the Privacy Protection Authority.

This policy is an integral part of the Terms of Use. Use of the system constitutes agreement to its terms.

2. Database Owner and Data Processor

The medical or organizational institution that purchased a subscription to the system is the owner of the database regarding its employees' and learners' data, and it determines the purposes of processing.

The Company acts as a data holder and processor on behalf of the institution, and processes information solely in accordance with its instructions and for the purpose of providing the service.

Inquiries from institutional employees regarding their personal information will be directed primarily to the institution's manager; the company will assist the institution in fulfilling these inquiries.

3. Types of Information Collected

Identifying information: Full name, email address (or alternative username), mobile phone number, profile picture (optional), institutional affiliation, team, and role.

Learning Information: course affiliations, progress in content units, viewing times, answers and results of quizzes and summative exams, grades, certificates issued, and assignments given.

Operational and Technical Information: IP address, browser and device type, login and logout times, language preferences, and activity logging in the Audit Log.

Billing Information: Institution details for invoicing purposes, payment history, and references. Credit card details are processed directly by the payment provider and are not stored on the company's servers.

The system is not intended for storing identified medical information of patients, and uploading such information is prohibited.

4. Purposes of Information Use

Service Provision: account creation, identity verification, building and displaying learning content, managing courses and exams, and issuing certificates.

Control and Management: Presenting progress reports to institution managers, managing permissions, documenting actions for internal audit purposes and regulatory compliance.

Information Security: Anomaly detection, prevention of unauthorized access, and investigation of security incidents.

Service improvement: Aggregate and anonymous usage analysis to improve user experience and system stability.

Operational communication: Sending essential service messages via email and SMS, including one-time verification codes, password resets, and task updates.

6. Disclosure of Information to Third Parties

The Company does not sell, rent, or trade personal information, and does not transfer it for third-party marketing purposes.

Information may be disclosed to infrastructure and service providers operating on behalf of the company and solely according to its instructions: cloud storage and databases, email and SMS messaging services, artificial intelligence services for translation and narration production, clearing and payments, and error monitoring.

Transfer of information outside the borders of Israel, if carried out by cloud providers, is subject to the Privacy Protection Regulations (Transfer of Information to Databases Outside the State's Borders), 2001, and to countries with an adequate level of protection or under an appropriate contractual commitment.

Information will be provided to an authorized body pursuant to a judicial order or legal obligation, in which case the institution will be notified, to the extent permitted by law.

Institution managers see the learning data of users affiliated with their institution only. The system implements full segregation between institutions.

7. Information Security

The Company implements technological and organizational protection measures in accordance with information security regulations: traffic encryption (TLS), data encryption at rest, role-based access control and row-level permissions, environment separation, and two-factor authentication via a one-time code.

Access to information is limited to role holders who need it for their work only, and every sensitive action is documented in an audit log.

Periodic backups and ongoing controls are performed to identify vulnerabilities. However, no online system is completely immune, and the company cannot guarantee absolute immunity.

In the event of a serious security incident, the company will act in accordance with the reporting obligations stipulated in the regulations and will notify the database owner and the Privacy Protection Authority as required.

8. Data Retention Period

The information is stored for as long as the institution's subscription is active and for the period required for the purposes for which it was collected.

Upon termination of the engagement, the institution may request data export within 30 days; thereafter, the information will be deleted or anonymized, except for information for which there is a legal retention obligation (such as accounting documentation according to tax laws).

Certificate records and certificate verification may be retained for a longer period for the purpose of verifying their validity, in accordance with the institution's directive.

9. Data Subject Rights

According to Article 13 of the Protection of Privacy Law, every person is entitled to inspect information about them held in a database.

Should a person find that the information is incorrect, incomplete, unclear, or not updated — they may request its correction or deletion, in accordance with Section 14 of the Law.

In accordance with Amendment 13 to the Law, the data subject is entitled to receive information on the processing method and data sources, and to object to certain uses subject to the law.

The exercise of rights shall be made by contacting the institution's manager or the company at the contact details at the end of this document. A response will be provided within the period prescribed by law.

Nothing herein shall derogate from the institution's right to continue to retain information required for control, compliance, and proof of completed training.

10. Cookies and Local Storage

The system uses cookies and local browser storage for essential operational purposes only: maintaining login status, securing the operation, saving language preference, and resuming viewing from the last point.

No use of advertising cookies or cross-site tracking for marketing purposes.

Cookies can be blocked in browser settings, but blocking essential cookies will prevent login and proper system usage.

11. Processing by Artificial Intelligence

For the purpose of script writing, content translation, slide analysis, test question creation, and narration production, instructional content may be sent to artificial intelligence providers acting as sub-processors.

The content sent is limited to the training materials themselves. Do not upload sensitive personal information or identified medical information of patients to these contents.

The outputs may contain inaccuracies and require professional review by the institution before use.

12. Minors

The system is intended for professional use by adults aged 18 and over only and does not knowingly collect information about minors.

13. Policy Changes

The Company may update this policy from time to time. A material update will be brought to the attention of users through a notification in the system or by email, and will continue to apply to usage from the moment of its publication.

14. Contact Us and Data Protection Officer

For privacy inquiries, exercising rights of inspection, correction or deletion, and for reporting a data security incident — you can contact us by phone at 04-3005117 or through the contact us page on the website.

A complaint can also be filed with the Privacy Protection Authority in the Ministry of Justice.

This document has been drafted generally and does not constitute legal advice. It is recommended to adapt it with the assistance of an attorney for the specific activities of the institution.