Privacy Policy

Last updated: 20 June 2026

This Privacy Policy explains how TapDoc, operated by Medform Software LTD ("Medform", "we"), collects, uses and protects personal data when you use the Platform. Medform Software LTD is the data controller for the data described below. We design for data minimisation: we deliberately collect as little as possible.

1. Data we collect

Patients

  • Name and mobile number, verified by one-time SMS code.
  • Booking details (selected professional, time, and the free-text need you describe in chat).
  • We do not collect government ID numbers.

Professionals

  • Account details (name, email, password hash) and profile/minisite content you publish.
  • Google Calendar authorization tokens (stored encrypted at rest) used only to read free/busy and write the appointments you receive.
  • Subscription and billing metadata (processed by Paddle; we do not store full card details).

Unclaimed listings

For unclaimed professional listings we process limited professional information obtained from public sources, including business directories (e.g. Google Places) and official public licensing registers. Where we process such data without collecting it from you directly, this section serves as our notice under GDPR Article 14 and equivalent laws. You may request access, correction or removal at any time via our data requests page.

2. How we use data & legal bases

  • To provide the service (matching, booking, calendar sync): performance of a contract / legitimate interests.
  • To verify your phone: consent and security.
  • To process payments: contract and legal obligation (via Paddle).
  • To maintain accurate public listings: legitimate interests, balanced against your rights, with opt-out.

3. Health-related information

When you describe your need in chat or book a particular type of professional, the information you provide may reveal data about your health. Where this is the case, such data is treated as a special category of personal data under the GDPR (Article 9) and equivalent laws. We process it only on the basis of your explicit consent, given when you submit a booking or describe your need, and solely to connect you with the professional you select. You may withdraw consent at any time via our data requests page; withdrawal does not affect bookings already made. We do not use this information for advertising or profiling.

4. Processors we share data with

  • Google: Places/Maps (search & location) and Calendar (free/busy & events).
  • Twilio: SMS one-time-passcode verification.
  • Paddle: merchant of record for billing and tax.
  • Google Gemini: to interpret your chat request; we send the text you type, not your identity. We never send your Google Calendar data to Gemini or any other AI system.
  • Hosting & database providers (e.g. Vercel, Neon) to operate the Platform.

5. Google Calendar data & Limited Use

TapDoc's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. When a professional connects a Google Calendar, we request only the minimum access needed to (a) read free/busy information so patients see genuine availability, and (b) create, update and delete the appointment events generated by bookings received through the Platform.

We specifically commit that data obtained from Google Calendar (and any Google Workspace APIs):

  • is used only to provide and improve these booking and availability features that are visible to you in the app;
  • is not used, retained, or transferred to develop, train, or improve any generalized or non-personalized artificial intelligence or machine-learning models;
  • is never sent to our AI chat assistant (Google Gemini) or any other AI/ML system;
  • is not sold or shared with third parties, and is not used for advertising or profiling;
  • is not read by our staff except with your explicit consent, for security/abuse investigation, or where required by law.

Calendar authorization tokens are stored encrypted at rest. You can disconnect your Google account at any time, which revokes our access.

6. International transfers

We operate across Australia, Israel, New Zealand, Ireland, Sweden, Norway, Denmark, the UAE, Singapore and Poland. Where data is transferred internationally, we rely on appropriate safeguards (such as Standard Contractual Clauses) where required.

7. Retention

We keep personal data only as long as necessary for the purposes above or as required by law. One-time-passcodes expire within minutes. You can request deletion of your data.

8. Your rights

Depending on your jurisdiction (e.g. GDPR/EEA, UK GDPR, Australia's APPs, UAE PDPL, Singapore PDPA, Israel's Privacy Protection Law), you may have rights to access, correct, delete, restrict or object to processing, and to data portability. Exercise these via our data requests page or privacy@tapdoc.ai.

9. Security

We use industry-standard measures including encryption in transit and encryption at rest for sensitive tokens. No system is perfectly secure, but we work to protect your data.

10. Cookies

We use essential cookies to operate the Platform and optional cookies to improve it. You can choose your preference via the cookie banner.

11. Children

The Platform is not directed to children and we do not knowingly collect their data.

12. EU representative & Data Protection Officer

Medform Software LTD is established outside the EU/EEA. Because we offer services to individuals in the EU/EEA (including Ireland, Sweden, Poland, Norway and Denmark), we have appointed a representative under Article 27 of the GDPR. You may contact our representative, or our Data Protection Officer, at privacy@tapdoc.ai.

  • EU representative: [name and EU postal address]

13. Contact

The data controller is Medform Software LTD, registered in Israel. Privacy enquiries: privacy@tapdoc.ai. Postal address: [registered address].