Skip to content
PhysiPlan
What's inside How it works Book a demo FAQ
عربي Sign in Book a demo
What's inside How it works Book a demo FAQ Sign in Book a demo

Privacy Policy

Last updated: 5 October 2026

This policy explains what data PhysiPlan handles, who is responsible for it, where it is kept and who helps us process it. If you are a patient, your clinic is your first point of contact for anything about your records.

1. Who we are

PhysiPlan is physiotherapy clinic management software for clinics in Jordan, the Gulf and the region. It is a product of YAMX LLC, a Wyoming (USA) limited liability company, and it is built in Jordan. In this policy, "we" and "us" mean YAMX LLC.

You can reach us at support@physiplan.pro.

2. Who is responsible for which data

  • Patient data: the clinic is the controller. The clinic decides what it records about its patients and why. We process that data only on the clinic's behalf, to provide PhysiPlan to that clinic.
  • Clinic account and contact data: we are the controller. This covers the clinic's details and the names, emails, phone numbers and roles of its staff accounts.
  • Demo requests from this website: we are the controller.

3. What data we handle

  • Clinic and staff accounts: clinic name and details, staff names, email addresses, phone numbers, roles and sign-in records, and records of the clinic's subscription and payments to us.
  • Patient records entered by the clinic: identity and contact details, appointments, assessments, plans of care, session notes, questionnaire answers, files and images, payments, packages and insurance claims, and WhatsApp messages exchanged with the clinic. Much of this is health data, which needs extra care.
  • Demo requests: the demo form on this website opens your own email app with your details filled in. We receive only what you choose to send: your name, phone or WhatsApp number, clinic name, city and, if you add it, your email address.
  • Technical data: our hosting providers keep standard logs (such as IP address, browser type and time of request) to run and protect the service. The app keeps your sign-in session in your browser's local storage so you stay signed in. This website does not use advertising cookies.

4. How we use data

  • To provide PhysiPlan to the clinic and run the features the clinic switches on.
  • To set up and manage clinic accounts, answer support requests and handle billing.
  • To reply to demo requests.
  • To keep the service secure and to meet our legal obligations.

We use patient data only to provide the service to the clinic that entered it. We do not sell personal data.

5. Providers that process data for us

We use the following providers (sub-processors). Each receives only the data it needs for its task.

  • Supabase: database, sign-in and file storage. Holds all clinic and patient data.
  • Vercel: hosts this website and the PhysiPlan web app.
  • OpenAI: powers the in-app assistant, the calendar assistant and the WhatsApp booking assistant. It receives the text of the request and the clinic data needed to answer it (for example patient names, appointment times or notes), images a staff member attaches to the in-app assistant, and patient messages sent to the booking assistant. It may also turn patient voice notes into text where the clinic uses that option.
  • Deepgram: turns speech into text. It receives voice recordings that clinic staff dictate into notes and voice notes patients send to the clinic's WhatsApp assistant.
  • Meta (WhatsApp): the WhatsApp network itself, also used directly for some reminders and for sign-in codes. It receives phone numbers and message content.

AI features give suggestions only. The clinician reviews them and makes every clinical decision.

6. Where data is stored, and data leaving Jordan

Our database is hosted by Supabase in Seoul, South Korea (Amazon Web Services region ap-northeast-2). The website and app are hosted on Vercel. This means clinic and patient data is transferred outside Jordan and stored in South Korea. The providers listed in section 5 may also process the data they receive outside Jordan.

7. How we protect data

  • Each clinic's data is separated from every other clinic at the database level (row-level security).
  • Staff access is based on roles, so each team member sees only what their role allows.
  • All connections to PhysiPlan use HTTPS.

8. If something goes wrong

If we become aware of a personal data breach that affects a clinic's data, we will notify the affected clinics without undue delay and within 72 hours of becoming aware of it. Each clinic is responsible for notifying its own patients where required.

9. How long we keep data

We keep a clinic's data while its account is active. Clinics can export or delete their data. When a clinic closes its account, it has 30 days to export its data, and we delete the clinic's data within 90 days of closure, or sooner if the clinic asks.

10. Your rights

The Jordan Personal Data Protection Law No. 24 of 2023 applies to the personal data we handle.

  • Patients: to see, correct or delete your records, contact your clinic. The clinic controls your data and can act on your request in PhysiPlan. If you contact us, we will pass your request to your clinic.
  • Clinic staff and demo requesters: contact us at support@physiplan.pro.

11. Changes to this policy

We may update this policy. The date at the top shows when it last changed. We will tell clinics about important changes.

12. Contact

YAMX LLC, support@physiplan.pro. See also our Terms of Service.

PhysiPlan

Made in Jordan by YAMX LLC. © 2026

Privacy Terms Sign in عربي support@physiplan.pro