Privacy notice: DOZI Med-Ops Scout
Last updated 2026-10-03
This notice explains what personal data DOZI Med-Ops Scout handles, why, who else processes it, how long it is kept and what rights you have. It applies to people who use Scout and to people whose data Scout handles.
Who we are
DOZI Med-Ops is operated by DOZI AI Remedies, Smadar 7, Hadera, Israel ("DOZI", "we").
Privacy contact: doron@doziai.com.
Our two roles
For your user account (your name, email, organization, role, sign-in activity) DOZI decides how the data is used: we are the controller.
For the content an organization puts into Scout, that organization is the controller and DOZI processes the data only on its instructions, as its processor. Questions about that content are best sent to the organization; if you send them to us, we pass them on.
What we collect
Scout helps manufacturers find and contact distributors and research sites. It handles:
- Your account: name, email, organization, role, sign-in times.
- Your organization's company profile and product catalog.
- Business contact details of distributors and research sites, collected from public sources such as company websites and public registries: company, name, role, business email and phone, and where each detail was found.
- Outreach emails your organization sends through Scout and the replies it receives.
- Scores and notes Scout produces about each company.
If you received an email from a company using Scout
Companies use Scout to contact distributors and research sites about business partnerships. If one of them emailed you:
- The company named at the bottom of the email ("Sender") is the controller of your data and DOZI is its processor. That footer also links to the company's own privacy notice.
- Your business contact details were taken from the public source named in the email, usually your company's website.
- The company writes to you as a business, on the basis of its legitimate interest in finding distribution partners (GDPR Art. 6(1)(f)).
- The email says whether it was drafted by an AI system and whether a person reviewed it before it was sent.
- You can object at any time and for free: use the link at the bottom of the email or reply STOP. The thread closes and your address goes on that company's do-not-contact list, stored only as a one-way fingerprint (hash), so it cannot be contacted again from Scout.
- The do-not-contact fingerprint is kept for as long as it is needed to honor your objection; the rest is deleted when the company no longer needs it, or when you ask.
Why we use it, and on what basis
- To provide the service your organization signed up for (contract, GDPR Art. 6(1)(b)).
- To keep the service secure, prevent abuse and fix faults (legitimate interest, Art. 6(1)(f)).
- To keep records the law requires, such as regulatory and tax records (legal obligation, Art. 6(1)(c)).
- For anything optional, such as hearing about new courses, only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
Artificial intelligence
Some features send text to an AI model to draft, translate or analyze it. Only the text the feature needs is sent. Under the provider's commercial terms it is not used to train its models.
AI output is a draft or a suggestion. No decision with legal or similarly significant effect on you is taken by automated means alone.
Who else processes the data
We use these service providers, each bound by a data-processing agreement:
- Supabase: database, file storage and sign-in. Data is stored in the EU (Frankfurt, Germany).
- Vercel: hosting of the application. Server functions run in the EU (Frankfurt); pages are delivered through a global network.
- Anthropic: the AI model behind the drafting and analysis features (United States).
- n8n: the workflow that hands outreach emails to the sending company's mailbox and returns replies.
- The sending company's email provider (for example Google Workspace or Microsoft 365).
- GROW, through Make: payments for top-ups, when used.
Transfers outside the EU and Israel
Data is stored in the EU. Some providers are in the United States; transfers to them rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. Israel has an EU adequacy decision.
How long we keep it
- Account data: while your account is active.
- Your organization's content: while its subscription is active, then deleted or returned within 90 days unless the law requires longer.
- The do-not-contact fingerprints: as long as needed to honor each objection.
Security
Connections are encrypted, each organization's data is separated at the database level, access follows each user's role, and changes are recorded in an audit trail.
Your rights
You can ask us, at doron@doziai.com:
- To see the data we hold about you, and get a copy (GDPR Art. 15 and 20; Israeli Privacy Protection Law, section 13).
- To correct it (Art. 16; section 14).
- To delete it or restrict its use, where the law allows (Art. 17 and 18).
- To object to its use based on legitimate interest, and at any time to direct marketing (Art. 21).
- To withdraw a consent you gave, without affecting what was done before.
Complaints
We reply within one month. You may also complain to the data protection authority where you live or work: in the EU, your national supervisory authority; in Israel, the Privacy Protection Authority (gov.il/en/departments/the_privacy_protection_authority).
Changes
When this notice changes we update the date at the top, and tell account holders about material changes.