PolyCDS CDS by Polyclinico LTD. – Organizational Privacy Policy
Last updated: April 12, 2026
Polyclinico LTD. ("Polyclinico," "we," "us," or "our") provides PolyCDS CDS, a clinical decision support platform designed for use by healthcare organizations, including HMOs, hospitals, clinics, medical groups, insurers, and other professional healthcare entities.
This Privacy Policy explains how we collect, use, process, protect, and share information when an organization and its authorized users access or use PolyCDS CDS, including through web, mobile, API, EHR, SMART on FHIR, CDS Hooks, or other integrated environments.
PolyCDS CDS is intended to support clinical workflows and professional decision-making. It is not a replacement for physician judgment, institutional policy, or regulatory compliance obligations.
1. Scope of this Policy
This Policy applies to the use of PolyCDS CDS by:
- Healthcare providers and clinical institutions;
- HMOs, hospitals, clinics, and medical centers;
- Health insurers and payers;
- Authorized physicians, nurses, medical staff, administrative users, and other professionals using PolyCDS CDS on behalf of an organization;
- Organizational administrators who manage access, integrations, billing, and governance.
Where PolyCDS CDS is provided under a separate written agreement, Business Associate Agreement, Data Processing Agreement, institutional pilot agreement, or enterprise services agreement, that agreement will control in the event of a conflict with this Policy.
2. Our Role in Processing Data
Our role may vary depending on how PolyCDS CDS is used.
For organizational account management, billing, security, analytics, support, service administration, and general platform operations, Polyclinico may act as a data controller or independent service provider.
When PolyCDS CDS processes clinical queries, patient-related information, EHR context, uploaded clinical materials, medical images, laboratory data, or other content submitted by or on behalf of an organization, we generally act as a data processor, service provider, or, where applicable, Business Associate.
The organization remains responsible for:
- Determining whether patient information may be submitted to PolyCDS CDS;
- Ensuring that use of PolyCDS CDS complies with applicable privacy, healthcare, medical-device, insurance, data-protection, and institutional rules;
- Managing user access, permissions, and internal governance;
- Reviewing and validating any clinical output before use in patient care.
3. Information We Collect
We collect and process only the information reasonably necessary to provide, secure, operate, support, and improve PolyCDS CDS.
3.1 Organizational and Account Information
We may collect:
- Organization name;
- Department, clinic, hospital, HMO, or insurer details;
- Authorized user names;
- Work email addresses;
- Professional role, specialty, credentials, or license-related information;
- Account administrator details;
- Subscription, procurement, billing, and contractual information.
3.2 Usage and Technical Information
To operate and secure the platform, we may collect:
- IP address;
- Device and browser information;
- Login activity;
- Session metadata;
- System logs;
- API activity;
- Security events;
- Feature usage;
- Performance and availability data;
- Audit logs relating to organizational use.
3.3 Clinical and User-Submitted Content
Depending on the organization's configuration and use case, PolyCDS CDS may process content submitted by authorized users, including:
- Clinical questions;
- Case descriptions;
- Differential diagnosis prompts;
- Medication-related queries;
- Laboratory values;
- Medical summaries;
- Clinical notes;
- Uploaded files;
- Medical images such as ECG, X-ray, ultrasound, MRI, CT, dermatology images, or other clinical materials;
- EHR-derived context where integration has been enabled.
PolyCDS CDS does not require identifiable patient information in order to function. Organizations and users should avoid submitting identifiable patient information unless it is necessary, permitted under applicable law, authorized by the organization, and covered by the appropriate written agreement.
3.4 Integration Data
Where PolyCDS CDS is integrated with institutional systems, we may process technical and clinical data required to enable the integration, including data received through:
- EHR systems;
- SMART on FHIR;
- FHIR APIs;
- CDS Hooks;
- SSO or identity providers;
- Clinical data repositories;
- Secure institutional APIs;
- Other approved organizational systems.
The exact categories of integration data depend on the configuration selected by the organization.
3.5 Billing and Payment Information
For paid services, billing and payment processing may be handled by third-party payment processors. We do not intentionally store full payment card details unless expressly stated and handled through compliant payment infrastructure.
4. How We Use Information
We use information for the following purposes:
- To provide and operate PolyCDS CDS;
- To authenticate users and manage access;
- To enable organizational administration;
- To deliver clinical decision support functionality;
- To generate responses, summaries, structured outputs, and workflow support;
- To support EHR, API, SMART on FHIR, CDS Hooks, and other integrations;
- To maintain security, availability, and reliability;
- To monitor system performance and detect abuse or misuse;
- To provide customer support and technical troubleshooting;
- To comply with legal, contractual, regulatory, and audit obligations;
- To improve PolyCDS CDS responsibly, including quality, usability, and safety improvements;
- To maintain audit trails, governance controls, and administrative reporting for organizations.
We do not use organizational clinical content for unrelated advertising purposes.
5. Clinical Decision Support and Human Review
PolyCDS CDS is a clinical decision support tool. Outputs generated by PolyCDS CDS may include summaries, suggestions, differential diagnoses, medication information, guideline references, image-related observations, laboratory interpretation support, or other clinical assistance.
All outputs must be reviewed by qualified healthcare professionals before use. PolyCDS CDS does not independently diagnose, treat, prescribe, approve claims, deny claims, determine medical necessity, or replace institutional clinical governance.
Organizations are responsible for determining how PolyCDS CDS outputs may be used within their clinical, administrative, insurance, or operational workflows.
6. Use of Data in AI Systems
We take a conservative approach to AI data use.
Unless expressly agreed otherwise in a written enterprise agreement, we do not use identifiable patient information, protected health information, or organization-submitted clinical content to train general-purpose AI models.
We may use:
- Aggregated data;
- De-identified data;
- Anonymized technical and usage data;
- Safety, performance, and reliability signals;
- Feedback provided by users or organizations, where permitted.
We do not:
- Sell patient data;
- Sell organizational clinical content;
- Attempt to re-identify anonymized data;
- Use identifiable clinical inputs for shared model training without appropriate authorization;
- Allow third-party AI providers to use submitted clinical content for their own model training unless expressly permitted by the organization and applicable law.
Where third-party AI providers are used, we take reasonable steps to configure services in a privacy-preserving manner, consistent with the applicable agreement and service configuration.
7. Legal Basis for Processing
Where GDPR, Israeli privacy law, HIPAA, or other privacy frameworks apply, the legal basis for processing may include:
- Performance of a contract with the organization;
- Compliance with legal obligations;
- Legitimate interests in operating, securing, and improving the Service;
- Consent, where specifically required;
- Processing necessary for healthcare, clinical, or institutional purposes, where applicable and authorized by law;
- Processing under a Data Processing Agreement, Business Associate Agreement, or other written arrangement.
The organization is responsible for ensuring that it has a lawful basis to submit, access, process, or transmit any personal data or patient-related information through PolyCDS CDS.
8. Sharing and Disclosure of Information
We do not sell personal data, patient data, or organizational clinical content.
We may share information only where necessary and appropriate, including with:
- Cloud hosting providers;
- Infrastructure and security providers;
- Authentication and identity management providers;
- Analytics and monitoring providers;
- Payment and billing providers;
- AI model and technical service providers;
- Legal, regulatory, or compliance advisors;
- Public authorities, where required by law;
- Successors in the event of merger, acquisition, restructuring, financing, or sale of assets, subject to appropriate safeguards.
All third-party service providers are required to process information under confidentiality, security, and data-protection obligations appropriate to their role.
9. Third-Party Service Providers
PolyCDS CDS relies on carefully selected third-party providers to operate, secure, and improve the platform. These may include providers of cloud infrastructure, AI model access, monitoring, logging, security, billing, communications, and support tools.
We take reasonable steps to evaluate, configure, and oversee such providers.
To the extent permitted by applicable law, Polyclinico is not responsible for unauthorized access, data loss, downtime, or breach caused solely by a third-party provider where such incident is outside our reasonable control and where we have acted responsibly in selecting, configuring, and supervising that provider.
This limitation does not apply where an incident results from our own negligence, misconfiguration, failure to implement reasonable safeguards, or breach of applicable legal or contractual obligations.
10. International Data Transfers
Depending on the organization's deployment, user location, hosting configuration, integration architecture, and third-party providers, data may be processed in countries other than the country where the organization or users are located.
Where required, we use appropriate safeguards, which may include:
- Data Processing Agreements;
- Standard Contractual Clauses;
- Business Associate Agreements;
- Technical and organizational safeguards;
- Access controls;
- Encryption;
- Regional hosting options, where available and agreed.
Organizations with specific data-residency requirements should address these requirements in the applicable enterprise agreement.
11. Data Retention
We retain data only for as long as necessary for the purposes described in this Policy, unless a longer retention period is required by law, contract, audit, regulatory obligation, dispute resolution, or organizational configuration.
Retention periods may vary depending on:
- The type of data;
- The organization's agreement with us;
- Audit and compliance requirements;
- Security needs;
- Backup and disaster recovery processes;
- Legal or regulatory obligations.
Upon termination of an organizational account, data may be exported, returned, deleted, or retained according to the applicable written agreement. Unless otherwise agreed, certain data may be retained for a limited period for legal, security, billing, audit, or compliance purposes.
12. Data Security
We implement reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
These safeguards may include:
- Encryption in transit;
- Encryption at rest, where applicable;
- Authentication and access controls;
- Role-based permissions;
- Audit logging;
- Secure development practices;
- Monitoring and incident detection;
- Administrative controls;
- Backup and recovery processes;
- Vendor security review;
- Internal access restrictions.
No system can be guaranteed to be completely secure. Organizations are responsible for maintaining appropriate endpoint security, user access controls, internal policies, and workforce training.
13. Healthcare Data, PHI, and Similar Regulated Data
Where PolyCDS CDS is used to process protected health information, patient data, or similar regulated health information, such use must be governed by an appropriate written agreement, such as a Business Associate Agreement, Data Processing Agreement, or equivalent healthcare data agreement.
Where applicable, we apply safeguards consistent with healthcare privacy and security expectations. However, the organization remains responsible for:
- Determining whether PHI or identifiable patient data may be submitted;
- Ensuring appropriate patient authorization or legal basis, where required;
- Managing access by its workforce;
- Ensuring that clinical staff use PolyCDS CDS in accordance with institutional policy;
- Reviewing outputs before clinical use;
- Maintaining medical records in the organization's official systems.
PolyCDS CDS is not intended to serve as the organization's official medical record unless expressly agreed in writing.
14. Insurance and Payer Use
Where PolyCDS CDS is used by insurers, payers, or health-plan organizations, the organization is responsible for ensuring that use of PolyCDS CDS complies with applicable laws and policies governing insurance, claims review, utilization management, medical necessity review, patient rights, transparency, fairness, and human oversight.
PolyCDS CDS should not be used as the sole basis for approving, denying, limiting, or modifying coverage, claims, benefits, or treatment access. Any such decision must remain subject to qualified professional review and applicable legal requirements.
15. Organizational Controls and Auditability
Depending on the subscription, deployment, or enterprise configuration, PolyCDS CDS may support organizational controls such as:
- User management;
- Role-based access;
- Administrative dashboards;
- Usage reporting;
- Audit logs;
- Security monitoring;
- Specialty-specific configurations;
- Source and guideline governance;
- Integration controls;
- Data-retention settings.
Organizations are responsible for configuring these controls appropriately and reviewing user activity in accordance with their internal policies.
16. User Responsibilities
Authorized users must:
- Use PolyCDS CDS only for permitted professional purposes;
- Follow the organization's policies and applicable laws;
- Avoid submitting unnecessary identifiable patient information;
- Review and validate clinical outputs;
- Protect login credentials;
- Report suspected security incidents;
- Use PolyCDS CDS only within their professional scope of practice.
Organizations are responsible for ensuring that their users are trained and authorized to use PolyCDS CDS.
17. Individual Rights
Depending on applicable law, individuals may have rights regarding their personal data, including the right to:
- Access personal data;
- Correct inaccurate data;
- Request deletion;
- Restrict processing;
- Object to processing;
- Receive a copy of data;
- Withdraw consent where processing is based on consent;
- File a complaint with a data-protection authority.
Where we process data on behalf of an organization, requests relating to patient data or organizational clinical content should generally be directed to the relevant organization. We will assist the organization in responding to such requests where required by law or contract.
18. Children's Data
PolyCDS CDS is intended for use by authorized professionals and organizations, not by children or direct consumer users.
PolyCDS CDS may process pediatric clinical information only where submitted by an authorized healthcare organization or professional in accordance with applicable law and institutional policy.
19. Incident Response
If we become aware of a security incident involving personal data or regulated healthcare data, we will take reasonable steps to investigate, mitigate, and notify affected organizations or authorities as required by applicable law and the relevant agreement.
Organizations are responsible for promptly notifying us of suspected unauthorized access, misuse, or security incidents involving their users or systems.
20. Changes to this Policy
We may update this Privacy Policy from time to time. Updated versions will be made available through the Service, our website, or other appropriate communication channels.
Where required by law or contract, we will provide notice of material changes.
Continued use of PolyCDS CDS after an updated Policy becomes effective means that the organization and its authorized users are subject to the updated Policy, unless otherwise agreed in writing.
21. Contact
For privacy, security, or data-protection questions, please contact:
Polyclinico LTD. Email: support@polyclini.co
For enterprise, institutional, or data-protection inquiries, organizations may also contact Polyclinico through their designated account representative or contractual contact channel.