Privacy Policy
Last updated
What this policy covers
This Privacy Policy explains how Mibsal ERP ("Mibsal", "we", "us") handles the information stored in the platform by a subscribing clinic ("you", "your clinic") and by the patients your clinic treats. It applies to every clinic using Mibsal ERP in Jordan. If any statement below stops being accurate, we will correct this page rather than leave it standing — that is a deliberate choice, not a courtesy.
Who controls patient data
Your clinic decides what patient information is entered into Mibsal ERP, who on your staff can see it, and how long you keep treating a given patient. In data-protection terms, your clinic is the controller of its patients' medical records; Mibsal is the processor — we operate the software and the infrastructure it runs on, on your instructions. We do not decide what data you collect, we do not use it for any purpose of our own, and we do not sell it or share it with advertisers. This distinction, and what it means for your own regulatory obligations, is set out fully in our Terms of Service.
What we store
Depending on how your clinic uses the platform, Mibsal ERP stores:
- Your staff accounts: names, email addresses, phone numbers, and the role each person holds.
- Patient records your clinic enters: contact details, medical history, allergies and other clinical alerts, appointments, dental charting, treatment plans, clinical notes, lab cases, invoices and payments.
- An activity log of who did what and when, kept automatically as you use the system.
We do not ask your clinic or your patients for anything beyond what the software's own screens collect, and we do not run any tracking or analytics script on the parts of the product your team or your patients use day to day.
How each clinic's data is kept separate
Every clinic's data is isolated at the database level: every record belongs to exactly one clinic, and every request the system serves is scoped to the clinic the logged-in user belongs to. There is no screen, report or export in Mibsal ERP that shows one clinic's patients, appointments or invoices to another clinic.
Who at Mibsal can see your data
Day to day, nobody at Mibsal looks at your clinic's data. A small number of people who operate the platform can, when needed for support or maintenance, access it through an administrative account — and every time that happens, it is written to an activity log, both on your clinic's own record and on our separate operator log, noting who did it, when, and from where. We do not have a support process that is invisible to you.
The audit log
Every clinic has its own activity log recording who changed what, and when. It is append-only: there is no screen, in your clinic or in ours, that can edit or delete an entry once it is written. You can read it, filter it, and export it at any time.
Signed clinical notes
Once a clinical note is signed, it becomes a permanent record. It cannot be edited or deleted afterwards, by any account, including ours. If a signed note needs correcting, the correction is added as a separate, dated addendum — the original stays exactly as it was signed, and both are kept on file.
Security measures we take
Access to Mibsal ERP requires a login, and what a staff member can see or do is governed by the permissions your clinic assigns them — a receptionist's account is not an accountant's account unless you make it one. Patient and clinical data is stored on servers we operate, isolated per clinic as described above, and every change of consequence is written to the audit log. We do not hold any external security certification (such as ISO 27001, HIPAA or SOC 2) today, and we do not claim to. If that changes, this page will say so.
What happens if a subscription lapses
If your clinic's trial or subscription lapses, we do not lock you out and we do not delete anything. Your clinic's account moves to a read-only state: you can still open every record, run every report, and export your data, but you cannot create or edit anything until the subscription is renewed. The moment payment is recorded, full access — including the ability to write — is restored immediately, with every record exactly as you left it.
Getting your data out
Your activity log can be exported from within Mibsal ERP at any time, whether your subscription is active or lapsed. For a full export of your clinic's other records — patients, appointments, invoices and clinical data — contact us at hello@mibsal.com and we will provide it.
Who we share data with
We share invoice data with Jordan's Income and Sales Tax Department (ISTD) through the JoFotara system, and only the invoices your clinic actually submits for e-invoicing. We use an email delivery provider to send the notifications the platform generates (appointment reminders, account emails and the like). We do not sell your data, we do not share it with advertisers, and we do not use it to train anything outside the operation of your own clinic's account.
Devices and offline use
When your clinic's staff use Mibsal ERP without a connection, the app can keep working for reading your schedule and patient records, and a new patient or appointment created offline is held on that device until it reconnects and syncs. Nothing else — no invoice, no JoFotara submission, no signed clinical note — is ever created or stored on a device while offline; those actions require a live connection by design.
Children's data
Dental patients are sometimes minors. Where your clinic treats a minor patient, the same rules above apply to that patient's record as to any other; obtaining the appropriate parental or guardian consent to treat and to record that data is your clinic's responsibility as the controller, not ours.
Changes to this policy
If we change how we handle your data in a way that matters, we will update this page and change the date at its top. We will not make a change here quietly.
Contact
Questions about this policy, or a request to export or correct data, can be sent to hello@mibsal.com.
