Privacy notice: DOZI Med-Ops Academy
Last updated 2026-10-03
This notice explains what personal data DOZI Med-Ops Academy handles, why, who else processes it, how long it is kept and what rights you have. It applies to people who use Academy and to people whose data Academy handles.
Who we are
DOZI Med-Ops is operated by DOZI AI Remedies, Smadar 7, Hadera, Israel ("DOZI", "we").
Privacy contact: doron@doziai.com.
Our two roles
For your user account (your name, email, organization, role, sign-in activity) DOZI decides how the data is used: we are the controller.
For the content an organization puts into Academy, that organization is the controller and DOZI processes the data only on its instructions, as its processor. Questions about that content are best sent to the organization; if you send them to us, we pass them on.
What we collect
Academy offers training courses and certificates. It handles:
- To enroll without an account: the name you want on your certificate and your email.
- Your course progress, quiz answers and results, and your certificate.
- If you leave your details to hear about a course: email, name (optional) and the course.
- Your IP address, used briefly to limit abuse of the enrollment and contact forms.
- When a course is paid: the purchase record. Card details go to the payment provider; we never see them.
- Staff of a distributor or clinic enrolled by their organization: name, organization and progress.
Why we use it, and on what basis
- To provide the service your organization signed up for (contract, GDPR Art. 6(1)(b)).
- To keep the service secure, prevent abuse and fix faults (legitimate interest, Art. 6(1)(f)).
- To keep records the law requires, such as regulatory and tax records (legal obligation, Art. 6(1)(c)).
- For anything optional, such as hearing about new courses, only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
Who else processes the data
We use these service providers, each bound by a data-processing agreement:
- Supabase: database, file storage and sign-in. Data is stored in the EU (Frankfurt, Germany).
- Vercel: hosting of the application. Server functions run in the EU (Frankfurt); pages are delivered through a global network.
- GROW, through Make: payments for paid courses, when used.
Transfers outside the EU and Israel
Data is stored in the EU. Some providers are in the United States; transfers to them rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. Israel has an EU adequacy decision.
How long we keep it
- Enrollment, progress and certificates: while the course is offered and for as long as a certificate may need to be verified.
- Contact requests: until you ask us to stop, or 24 months without contact.
- Purchase records: as long as tax law requires.
- IP addresses for abuse limits: up to one day, and only as a one-way hash when stored.
Security
Connections are encrypted, each organization's data is separated at the database level, access follows each user's role, and changes are recorded in an audit trail.
Your rights
You can ask us, at doron@doziai.com:
- To see the data we hold about you, and get a copy (GDPR Art. 15 and 20; Israeli Privacy Protection Law, section 13).
- To correct it (Art. 16; section 14).
- To delete it or restrict its use, where the law allows (Art. 17 and 18).
- To object to its use based on legitimate interest, and at any time to direct marketing (Art. 21).
- To withdraw a consent you gave, without affecting what was done before.
Complaints
We reply within one month. You may also complain to the data protection authority where you live or work: in the EU, your national supervisory authority; in Israel, the Privacy Protection Authority (gov.il/en/departments/the_privacy_protection_authority).
Changes
When this notice changes we update the date at the top, and tell account holders about material changes.