Privacy Policy

Last updated: 2026-08-08 · Policy version: 2026-08-08

This policy explains how Quality Systems LLC (operator of elaj ™) processes personal data. For a GDPR summary, see the GDPR page.

1. Who we are and roles

For organization account, subscription, and security data we typically act as a controller. For patient and clinic operational data entered by clinic users, we act as a processor on behalf of the organization (the controller), under the service contract and a Data Processing Agreement (DPA).

2. Data we collect

3. Purposes and legal bases

We operate the platform, provide support, process subscriptions, protect security, and fulfil data-subject requests. Bases include contract performance, legitimate interests (security and support), legal obligation, and consent where required. Health data is a special category and is processed on the clinic’s instructions and applicable healthcare bases.

4. Sharing and sub-processors

We may use hosting, email, SMS, payment, and AI providers to run the service. We do not sell personal data.

5. Retention

We retain data as needed to provide the service or meet legal duties. Communication logs and raw payment/AI payloads follow configurable retention rules (for example about 90–365 days for operational payloads/logs, and longer windows for medical and accounting records per clinic policy and law). After the relationship ends, data may be deleted or anonymized.

6. Security

We apply role-based access, tenant isolation, audit logging of patient chart access, and transport encryption (HTTPS). No online system can guarantee absolute security.

7. Your rights

Where GDPR applies you may request access, rectification, erasure (or anonymization), restriction, and portability. For patient data in a clinic account, requests usually go through the clinic as controller; the platform provides DSAR tools for authorized staff.

8. Cookies

We use essential cookies for session, authentication, and language. We do not currently use non-essential marketing cookies. If those are added later, a separate consent mechanism will be shown.

9. Data breaches

If a personal data breach occurs we follow an internal procedure for assessment, containment, and notification as required (including the 72-hour supervisory authority window where GDPR applies).

10. Contact

For privacy requests, use the contact page or email [email protected].