Privacy Policy
Last updated: September 2026
Vistory stores photos of people, so we take privacy especially seriously. This policy explains what we collect, what we do with it, who we share it with, and what your rights are.
1. Introduction and roles
Vistory by ClinicHub is operated by Ron Tabachnik, exempt dealer no. 211381702, trading as Digitab, 36 Golda Meir St., Netanya, Israel. This policy follows Israel's Privacy Protection Law, 1981 and its amendments, the Privacy Protection (Data Security) Regulations, 2017, and the EU General Data Protection Regulation (GDPR) where it applies.
For the people who sign up to Vistory, we are the data controller. For a business's clients and their photos, the business is the controller, and we are a processor acting on its behalf and following its instructions.
2. What we collect
a. Vistory users (business owners and team members):
- name, email address, password (stored only as a one-way hash, never as text), preferred language and role in the workspace
- the version of the terms you accepted, and when
- business details: business name, Brand Kit (logo, colours and fonts), plan and storage used
- if you sign in with ClinicHub: your ClinicHub account ID, name and email. Your ClinicHub password never reaches us.
b. The business's clients (entered by the business, or received from ClinicHub if the business connected it): name, phone, email, date of birth and notes, where entered; whether they consented to being photographed and to marketing use, who recorded it and when; and their ClinicHub client ID when connected.
c. Photos and documentation: the photos themselves, their date, stage and angle, the session and service they belong to, edit recipes, and posts made in Social Studio. Client photos are sensitive data, which may be medical information, and are protected accordingly. On upload, all EXIF data is removed, including location (GPS), device model and serial number.
d. ClinicHub connection: access tokens (stored encrypted), and the clients, appointments, services and professionals you approved sharing. Vistory does not receive prices, payments, medical records or notes from ClinicHub.
e. Technical and security data: IP address, browser and device type, sign-in logs, and an audit log of sensitive actions (upload, deletion, export, permission changes).
f. Payment: card details go directly to the card processor (Cardcom) through ClinicHub's billing system. We keep only your plan, subscription status and billing account ID.
3. How we use it
- to provide the service: storing photos, showing them to authorised people, comparing, editing, creating posts and exporting
- to manage your account, workspace, team and permissions
- to sync with ClinicHub, when the business has connected it
- to send service messages, such as password resets
- to measure storage and usage for your plan
- for security, abuse prevention and legal compliance
- for support and troubleshooting
We don't sell personal data, we don't use photos to train AI models, for research or for marketing, and we don't show ads. If we add AI-based tools, we'll describe them here before they are switched on.
4. Who we share it with
Data goes only to parties needed to run the service, and only as much as they need:
- Cloud infrastructure provider, hosting the database, encrypted in transit and at rest. Location: EU.
- ClinicHub's image server, storing photos in a separate Vistory area. Signed access only, over TLS. Location: EU.
- Application hosting provider, running the website and server. Data passes through it encrypted while being processed. Location: EU / US.
- Email provider, for service messages only, such as password resets. It receives the email address and message content. Location: US.
- ClinicHub and Cardcom, for subscription billing. Israel.
- ClinicHub, when the business connected it: documented photos appear read-only in the client's ClinicHub file, only to people allowed to open that client. Israel / EU.
- Competent authorities, only under a court order or legal obligation.
Transfers to the EU rely on the EU's adequacy decision for Israel. Transfers to the US use recognised transfer mechanisms, such as Standard Contractual Clauses (SCCs).
5. How we protect photos
- All photos are private. They have no public address, and Vistory has no share links.
- Each view gets a signed link that expires within minutes, issued only after permissions are checked again. A copied link stops working shortly.
- Every file is decoded and re-encoded on the server, so malicious code hidden in a file doesn't survive and location data is removed.
- Permissions are role-based, and a team member can be limited to specific clients.
- Traffic is encrypted (TLS). Passwords are stored as hashes, and ClinicHub connection tokens are stored encrypted.
- Every upload, deletion, export and permission change is recorded in an audit log.
No system is completely secure. If we discover a security incident affecting personal data, we'll notify the affected businesses as soon as possible and within 72 hours at the latest, and report to the Privacy Protection Authority as the law requires.
6. How long we keep data
- Account and workspace: while they are active.
- Photos and documentation: until the business deletes them or closes the workspace. A deleted session can be restored for 30 days, and deleted photos are permanently removed from storage within 30 days.
- Photos the business must keep by law, for example as part of a medical record: keeping them is the business's duty (see the Terms of Use, section 6).
- Unfinished uploads: deleted after 24 hours.
- Audit and security logs: as long as needed for security and legal compliance, and no longer than 7 years.
- When a workspace is closed, its client details are deleted too. Backup copies are deleted in the normal backup cycle.
7. Your rights
Under the Privacy Protection Law, and the GDPR where it applies, you can:
- see the data we hold about you
- ask us to correct inaccurate data
- ask us to delete it, except data we must keep by law
- receive your data in a portable format. Photos can be downloaded from Vistory at any time.
- object to certain processing, or ask us to restrict it
If you are a client of a business that uses Vistory: your details and photos belong to that business, so please send requests to see, correct or delete them to the business first. You can also contact us, and we'll pass the request on and help the business handle it.
Requests: info@clinichub.co.il. We reply within 30 days.
8. Cookies and browser storage
We use only essential cookies, with no third-party tracking, advertising or analytics cookies:
- vistory_session: keeps you signed in, for up to 30 days
- vistory_ws: your active workspace
- vistory_locale: the language you chose
- vistory_ch_flow: a temporary cookie while signing in or connecting with ClinicHub
Accessibility menu settings are kept only in your browser's local storage and are never sent to us.
9. Messages
We send only the service messages needed to run your account, such as password resets. Marketing messages are sent only with your consent, under section 30A of Israel's Communications (Telecommunications and Broadcasting) Law, 1982, and you can unsubscribe at any time.
10. Minors
Vistory is for users aged 18 and over. Photos of clients who are minors are uploaded by the business, which is responsible for getting a parent's or guardian's consent.
11. Changes to this policy
We may update this policy from time to time. We'll give advance notice of a material change, by email or in the service. The date of the latest update is shown at the top of this page.
12. Contact
Privacy questions and requests to exercise your rights: info@clinichub.co.il, phone 053-2919054.
