1. Who we are
ITIG Tech is the trade name of a sole proprietorship registered with the Lebanese Ministry of Finance under number 4120940, located in Jdeideh, Metn, Lebanon. We build and operate ITIG Clinic, clinic management software for clinics in Lebanon, and its add-ons AutoGreet AI, SmartPage, and ITIG Rx.
For anything in this policy, write to support@itigtech.com or message us on WhatsApp at +961 79 060 517.
2. Who this policy covers
This policy covers four groups of people:
- Visitors to www.itigtech.com.
- People who contact us, on WhatsApp, by phone, by email, or through the form on this site.
- Clinics that subscribe to ITIG Clinic, and their staff who use it.
- Patients whose data a clinic records or exchanges inside ITIG Clinic, including through AutoGreet AI on WhatsApp, a SmartPage booking page, or the patient portal.
3. What we collect and why
For each group, this is what is processed and the reason.
- Website visitors: this website sets no cookies of its own and stores nothing in your browser. It uses Cloudflare Web Analytics, which counts page views without cookies, identifiers, or fingerprinting and reports only aggregates such as page, referrer, browser type, and country. Our hosting provider, Cloudflare, also processes your IP address and request details to serve and protect the site, as any host does.
- People who contact us: your name, clinic or pharmacy name, phone number, email address, message, and preferred reply language, so that we can answer you. Form submissions are stored on Cloudflare (a key-value store in our account) and, once we configure it, forwarded to us by email through Resend. WhatsApp messages to our number are processed by WhatsApp (Meta) under its own terms.
- Clinic customers and their staff: account details (name, email, role, phone), sign-in and security records (a password hash, sessions, failed sign-in attempts, two-factor secrets if enabled), subscription and invoice records, support conversations, and an audit log of actions taken in the software. We use these to provide, secure, bill, and support the service and to meet our legal duties.
- Patients, on the clinic’s behalf: identity and contact details including the WhatsApp phone number, appointments, clinical records (visits, diagnoses, prescriptions, allergies, documents, photos, recordings), billing and insurance details including NSSF numbers, WhatsApp messages exchanged with the clinic, entries made on a booking page, portal sign-in codes, and consent records. We process these only to provide the service to the clinic, on its instructions.
4. Our role: the clinic is the controller, we are its processor
When you visit this site or contact us, ITIG Tech decides why and how your data is used and is the data controller.
When a clinic uses ITIG Clinic to care for its patients, the clinic decides why and how patient data is used and is the data controller. ITIG Tech is its processor: we act only on the clinic’s instructions, we access patient data only to provide and support the service, and every such access is written to the audit trail. We never use patient data for our own purposes, and we never sell it.
If you are a patient of a clinic that uses our software, the clinic is responsible for your data. Please send requests about your data to the clinic. We assist the clinic in answering.
5. Health data and the care it receives
Health data is sensitive. Inside ITIG Clinic it is protected by the measures below, described in more detail on our security page.
- Each clinic’s records are separated from every other clinic’s by row-level security enforced in the database itself.
- Access inside a clinic follows roles. In a clinic with several doctors, a doctor opens only their own patients by default. Receptionists see no clinical fields unless the clinic owner widens it. Psychiatric and other sensitive visits are visible to doctors only.
- Every access to a patient record is written to an audit log that the database refuses to update or delete.
- Backups are encrypted. WhatsApp access tokens, AutoGreet AI conversation text, and two-factor secrets are additionally encrypted field by field.
- Our staff access patient data only to provide or support the service, and that access is logged like any other.
- We do not use health data for advertising, profiling, or any purpose other than the service.
6. Legal basis and consent
We process personal data under Lebanese Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data. For clinics and their staff, the basis is the subscription agreement and our legitimate need to operate and secure the service. For website visitors and people who contact us, the basis is answering your request and running the site.
For patient data, the clinic is responsible for having a lawful basis and for informing its patients. The software records consent where it matters: a patient’s opt-in to WhatsApp reminders is recorded per patient with its source and date, a booking made on a SmartPage page records the privacy notice version the patient accepted and the name they typed, and a patient can withdraw messaging consent at any time by replying STOP.
7. WhatsApp and AutoGreet AI
Messages between a clinic and its patients travel through the WhatsApp Cloud API operated by Meta Platforms. Meta processes the phone numbers, message content, media, timestamps, and delivery status under WhatsApp’s own terms. The clinic connects its own WhatsApp Business number.
AutoGreet AI is an assistant that answers patient messages on the clinic’s number. To draft a reply, the text of the patient’s message, up to ten earlier messages of the same conversation within 24 hours, and the clinic’s entered facts are sent to Anthropic in the United States, which acts as our sub-processor under commercial terms with a data processing agreement. The patient’s name, phone number, and record identifiers are not sent. Anthropic does not use this data to train models and deletes it within 30 days. A message that reads as medical, urgent, or an emergency is not sent to the model at all: the patient receives a holding text with the Lebanese Red Cross number and the conversation goes to a person at the clinic.
The first automated reply in each conversation tells the patient they are talking to the clinic’s automated assistant. Conversation text is encrypted at rest and deleted after 30 days. The clinic must inform its patients that it uses WhatsApp and an automated assistant, for example with a notice in the waiting room, and must obtain opt-in before sending reminders.
8. Sub-processors
We use a small number of providers to run the service. Each processes data only to provide its function to us and is bound by contract.
- Microsoft Azure (UAE North region, with backups replicated to UAE Central): hosting of the application, the database, and encrypted backups.
- OVH Cloud (France, EU-WEST region): S3-compatible object storage for patient documents, photos, and recordings.
- Cloudflare: the hosting of this website and the demo environment (Pages), storage of contact-form submissions (Workers KV), DNS, and, if enabled, the Turnstile check on the contact form.
- Meta Platforms: the WhatsApp Cloud API for messages between clinics and patients.
- Anthropic (United States): drafting AutoGreet AI replies, as described above. The software can fall back to OpenAI or Google if we ever configure them. Today only Anthropic is configured, and we will update this policy before any change.
- Brevo: transactional email from the application, such as password resets, staff invitations, and subscription notices.
- Sentry: error reports from the application server, with names, phone numbers, dates of birth, notes, and credentials removed before they are sent. The browser sends nothing to Sentry.
- 8x8: the Jitsi Meet service, the public one at meet.jit.si, which hosts the room when a clinic holds a video visit. A room is created for one appointment.
- Google Fonts: the ITIG Clinic application references typefaces hosted by Google. When the browser fetches them, Google receives the browser’s address. This website does not use Google Fonts.
- Resend: delivery of contact-form emails from this website to us, once configured.
We update this list when a provider changes, and we give clinics 30 days’ notice of a new sub-processor for patient data.
9. International transfers
Patient records and backups are stored in the United Arab Emirates, outside Lebanon. Patient documents, photos, and recordings are stored in France. The text of patient WhatsApp messages handled by AutoGreet AI is processed in the United States. Error reports, email, and the providers above operate on global networks.
For every transfer we rely on contracts with data processing terms, on sending as little as possible (no patient identifiers to the model, no message text in the outbound message ledger, no personal data in error reports), and on encryption in transit and at rest.
10. How long we keep data
During a subscription:
- A clinic’s records are kept for as long as the clinic uses the service. A patient can be erased on the clinic’s request: identifiers are removed at once and a de-identified clinical file is kept for the clinic’s retention period (ten years by default, in line with medical record-keeping duties), then deleted. A legal hold blocks erasure.
- AutoGreet AI conversation text: 30 days. Raw WhatsApp webhook payloads: 30 days. Visit recordings a clinic deletes: 30 days after deletion. Cached request records: 7 days.
- The audit log is never deleted.
- Database backups age out after 35 days (point-in-time backups) and 42 days (independent encrypted backups).
After a subscription ends: the clinic owner can export the whole clinic at any time before the end. On a written request we delete or hand over the clinic’s data within 30 days. Unless asked earlier, we delete it no later than 90 days after the subscription ends, and backups then age out on the schedule above. Records we must keep by law, such as invoices and the audit log, are kept for the legally required period.
Contact-form submissions and enquiries are kept for up to 24 months after our last exchange, then deleted.
11. Security
The controls we apply are described on the security page: isolation in the database, an append-only audit log, encrypted backups with a rehearsed restore, Argon2id password hashing, optional two-factor login for owners and admins, rate limits, HMAC-verified webhooks, secrets held only in Azure, secret scanning and dependency audits in our build pipeline, and production configuration checks that stop the service from starting unsafely.
No system is perfectly secure. We hold no security certification and we say so. If you find a security issue, write to support@itigtech.com.
12. Your rights under Law 81 of 2018
You have the right to know whether we hold data about you, to access it, to have it corrected, and, where the law allows, to have it deleted or to object to its processing.
If you are a website visitor, someone who contacted us, or a clinic user, write to support@itigtech.com. We may ask you to confirm your identity, and we answer within 30 days.
If you are a patient of a clinic that uses our software, address your request to the clinic, which is the controller of your data. We assist the clinic in answering. Inside the software, the clinic can export your file for you and can erase your record on request.
13. Visitors from the European Union or the United Kingdom
We serve clinics in Lebanon and do not target the EU or the UK. If you contact us from there, the rights above apply to you as well, you may also have rights under the GDPR or the UK GDPR, and you may complain to your local data protection authority. The controller for your data as a visitor or correspondent is ITIG Tech at the address above.
14. Cookies and analytics on this website
This website sets no cookies of its own and uses no advertising technology. It loads one third-party script, the Cloudflare Web Analytics beacon, which sets no cookie and stores nothing in your browser. Cloudflare, which serves the site, may set a strictly necessary cookie to protect the site from automated traffic. If we enable the Turnstile check on the contact form, Turnstile sets its own cookie for that check only. The cookie policy has the details.
15. Children
Clinics that use ITIG Clinic may treat children. Their data is processed on the clinic’s behalf and under its responsibility, as for any other patient. This website and our services are offered to healthcare providers, not to children.
16. Changes to this policy
When we change this policy we publish the new version on this page with a new effective date. For changes that affect how clinics’ data is processed, we inform subscribing clinics in advance.
17. Contact and complaints
ITIG Tech, Jdeideh, Metn, Lebanon. Email support@itigtech.com. WhatsApp and phone +961 79 060 517.
If you are not satisfied with our answer, you may raise the matter with the competent Lebanese authority under Law No. 81 of 2018.