Privacy notice: DOZI Med-Ops Design
Last updated 2026-10-03
This notice explains what personal data DOZI Med-Ops Design handles, why, who else processes it, how long it is kept and what rights you have. It applies to people who use Design and to people whose data Design handles.
Who we are
DOZI Med-Ops is operated by DOZI AI Remedies, Smadar 7, Hadera, Israel ("DOZI", "we").
Privacy contact: doron@doziai.com.
Our two roles
For your user account (your name, email, organization, role, sign-in activity) DOZI decides how the data is used: we are the controller.
For the content an organization puts into Design, that organization is the controller and DOZI processes the data only on its instructions, as its processor. Questions about that content are best sent to the organization; if you send them to us, we pass them on.
What we collect
Design manages design controls, the risk file and the biocompatibility plan of a device under development. It handles:
- Your account: name, email, organization, role, sign-in times.
- Design-control records, risk items and plans your organization enters, including who authored and approved them.
- An audit trail of who changed what and when.
Why we use it, and on what basis
- To provide the service your organization signed up for (contract, GDPR Art. 6(1)(b)).
- To keep the service secure, prevent abuse and fix faults (legitimate interest, Art. 6(1)(f)).
- To keep records the law requires, such as regulatory and tax records (legal obligation, Art. 6(1)(c)).
- For anything optional, such as hearing about new courses, only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
Artificial intelligence
Some features send text to an AI model to draft, translate or analyze it. Only the text the feature needs is sent. Under the provider's commercial terms it is not used to train its models.
AI output is a draft or a suggestion. No decision with legal or similarly significant effect on you is taken by automated means alone.
Who else processes the data
We use these service providers, each bound by a data-processing agreement:
- Supabase: database, file storage and sign-in. Data is stored in the EU (Frankfurt, Germany).
- Vercel: hosting of the application. Server functions run in the EU (Frankfurt); pages are delivered through a global network.
- Anthropic: the AI model behind the drafting and analysis features (United States).
Transfers outside the EU and Israel
Data is stored in the EU. Some providers are in the United States; transfers to them rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. Israel has an EU adequacy decision.
How long we keep it
- Account data: while your account is active.
- Design-history records and the audit trail: for the period the organization must keep them by law.
- Other content: while the organization's subscription is active, then deleted or returned within 90 days unless the law requires longer.
Security
Connections are encrypted, each organization's data is separated at the database level, access follows each user's role, and changes are recorded in an audit trail.
Your rights
You can ask us, at doron@doziai.com:
- To see the data we hold about you, and get a copy (GDPR Art. 15 and 20; Israeli Privacy Protection Law, section 13).
- To correct it (Art. 16; section 14).
- To delete it or restrict its use, where the law allows (Art. 17 and 18).
- To object to its use based on legitimate interest, and at any time to direct marketing (Art. 21).
- To withdraw a consent you gave, without affecting what was done before.
Complaints
We reply within one month. You may also complain to the data protection authority where you live or work: in the EU, your national supervisory authority; in Israel, the Privacy Protection Authority (gov.il/en/departments/the_privacy_protection_authority).
Changes
When this notice changes we update the date at the top, and tell account holders about material changes.