Privacy policy
What this policy covers
This policy deals with two separate contexts, and the rules are not the same in both. The first is the public OptiFlow website — the pages anyone can browse and the contact form on them. The second is the application itself, which business customers sign in to and in which information about that business’s own customers is managed.
The distinction is not merely technical. Information collected on the website is collected by us, for our own purposes. Information held inside the application, by contrast, belongs to the business using it: that business decides what is collected and why, and we process it on its behalf in order to provide the service.
Wherever the distinction matters, this policy states explicitly which of the two it is talking about.
Information collected on this website
When you browse the site, basic operational data is recorded so the pages can be served, work correctly and be protected: IP address, browser and device type, display language, the page you arrived from and the pages you viewed.
The website does not ask for sensitive information and does not ask for health information. Do not enter patient details or a business’s customer details on this website, and do not upload clinical documents to it.
The website does not build a personal advertising profile, and we do not sell information or pass it to a third party for that third party’s own marketing.
Demo requests and contact forms
A demo request or contact form collects the details you choose to give — usually your name, your business name, a phone number, an email address, and a free-text description of what you are looking for.
We use those details to get back to you, arrange a demo, understand what you need, and keep a record of the commercial conversation. We will not use them for anything else without telling you first.
Do not enter patient details, exam findings, medical documents or payment details in the form. Payment details are not collected anywhere on this website.
If you ask us to stop sending marketing contact, we will record that and stop. We may still send an operational message about a request you yourself submitted.
Analytics and cookies
Essential cookies are used to make the site work and to remember basic preferences you chose. Without them parts of the site will not behave as expected.
Usage measurement, where it is switched on, exists to show which pages are useful and where visitors get stuck — at the level of general patterns, not to identify a particular person. If such tools are enabled, a notice will let you choose, and your choice will be remembered.
You can block or delete cookies in your browser settings. Blocking essential cookies may break parts of the site.
The exact wording of the consent mechanism, and the actual list of cookies in use, must be completed during legal review and a technical check of the site before publication.
Information held inside the OptiFlow application
Inside the application, the business manages information about its own customers: contact details and interaction history, appointments, exam and prescription records and attachments, orders, payments and financial documents, alongside operational information such as products, tasks and follow-up. Some of this information is sensitive by its nature.
That information is entered by the business and its staff, and it remains theirs. We process it in order to provide the service, support it, back it up and keep it stable and secure — not for purposes of our own.
Access to information inside the application follows the role the business assigns to each member of staff. Our own people access it only where that is needed to handle a support request, perform maintenance or protect security, and only to the narrow extent that purpose requires.
OptiFlow supports documenting and managing exam and prescription workflows. Professional and clinical judgement remains the optometrist’s responsibility.
Who is responsible for what
The business is the party that decides what information is collected about its customers, for what purpose, who it is disclosed to and when it is deleted. It is therefore responsible for obtaining the consents it needs from its own customers, for setting its staff’s permissions correctly, for maintaining medical confidentiality where that applies, and for making sure the way it uses the system matches the obligations that apply to it.
We are responsible, as the provider, for making the service available, processing information in line with the engagement and the business’s instructions, applying reasonable protective measures, helping the business handle its customers’ requests within what the system can do, and informing the business of a security incident affecting its information.
We do not use a business’s customer information for our own marketing, we do not sell it, and we do not share it with another business.
An individual who wants to know what information is held about them, or to have it corrected or deleted, should contact the business that treats them. That business holds the relationship and the information; we will assist it in handling the request.
Suppliers who process information for us
To run the service we rely on suppliers who provide infrastructure and storage, monitoring, support tooling and message delivery. Such a supplier is given access only to what providing the service requires, is bound to confidentiality, and may not use the information for its own purposes.
Services that act on the business’s behalf — sending messages to its customers, connecting to a point-of-sale system, or importing data from an examination device — run only where the business asked for them. In that case the supplier receives the details needed to carry out that action, and no more.
A current list of suppliers, including their role and where they operate, is provided to a business customer on request as part of the engagement. We do not publish it on a public page.
Hosting and storage
Information is held in a managed server environment with periodic backups. Each business sees only its own data, and information does not move between businesses.
Uploaded files — documents or images attached to a customer record, for example — are stored with restricted access and are not publicly reachable. A document link sent to an individual gives access to that one document only.
The country or region where storage and processing take place will be stated on this page in the approved wording. While that value is missing, we will not name one.
Backups are kept for a defined period and exist for restoration only. Deleting information from the application does not immediately erase a backup taken earlier; that copy is removed as the backup cycle rotates.
Security
Traffic between the browser and the service is encrypted. Access requires authentication, and permissions follow the role a member of staff has in the business, so each person sees what their role requires.
We keep security updates current, restrict internal access to what is needed, record significant activity in the system, and test that backups are valid and can be restored.
The business is responsible for its own side: keeping sign-in details confidential, removing access when someone leaves, using up-to-date devices, and being wary of anyone impersonating us to ask for credentials.
No protective measure provides absolute security, and we do not claim otherwise. We do not display a security standard, certification or approval here, and we will not do so without a document that evidences it.
How long information is kept
Marketing enquiry details are kept for a reasonable period so we can continue the conversation and keep a record of it, after which they are deleted or kept in a form that does not identify a person.
Information inside the application is kept while the engagement with the business is in force, and in line with the record-keeping obligations that apply to the business itself — financial documents and professional records, for example. That is the business’s call, not ours.
When an engagement ends, an export-and-deletion process is carried out in accordance with the agreement.
Exact retention periods will be settled during legal review and in consultation with an accountant, and only then written here as figures. We will not state a period that has not been approved.
Your rights over your information
A person whose information is held may ask to see it, ask for an inaccurate detail to be corrected, ask for information to be removed where there is no obligation or legitimate need to keep it, and ask that marketing contact stop.
Where the information sits inside a business’s system — in a customer record at an optical store, for example — the request is handled by that business, because it is the party managing the information. If you come to us, we will pass the request to the business and help it respond within what the system can do.
A request may be limited where certain information must be kept, such as a professional record or a financial document, or where the information also concerns another person.
The precise scope of these rights, the timescales for responding, and how a requester’s identity is verified must all be completed during legal review. This document does not set out the law and does not pretend to.
Processing outside Israel
Some of the supporting services we rely on may run, be hosted or be supported outside Israel. In that case information may be processed, or accessed remotely, from another country.
Any such transfer happens only to provide the service, is limited to what that requires, and is subject to the supplier’s undertaking to maintain confidentiality and protective measures.
The relevant countries or regions, and the legal arrangement that permits the transfer, will be written on this page after legal review. Until then this document makes no statement about any particular transfer framework.
Contacting us about privacy
Privacy enquiries — including a request to see, correct or remove information, or to stop marketing contact — are handled by our privacy contact, whose details appear on this page.
To help us deal with it, please describe the request briefly and give the context: whether it concerns an enquiry you left on the website, or information held about you by a business whose customer you are.
We will reply within a reasonable time. If the request concerns information managed by a business customer, we will pass it to that business and tell you we have done so.
Changes to this policy
If we update this policy we will update the date shown at the top of it, so it is always clear which version you are reading.
A material change — a change in what information is used for, or in the kinds of information collected — will be announced prominently on the site, and business customers will be told directly through the channel we normally use with them.
Continuing to use the website or the service after an update means accepting the updated wording, to the extent the law allows. Where fresh consent is required, we will ask for it.
Privacy enquiries: through the contact form on this site · CRYSTAL-OPTIC
