Privacy Policy | Lenzic
Last updated: 10 October 2026
This page describes the information Lenzic actually collects on getlenzic.com and in the clinic software, and what we do with it.
Who we are
Lenzic is management software for optical shops and eye clinics. This policy covers the marketing site and the cloud app for the international market, including the UAE and the Gulf.
- Brand: Lenzic
- Website: https://getlenzic.com
- App: https://app.getlenzic.com
- Email: info@getlenzic.com
- Phone: +971508902417
- WhatsApp: +971508902417
What information we collect
We keep three separate kinds of information: people who visit the website, our customers (clinics and optical shops), and patients whose records a clinic types into the software.
Site visitors
- Opening the home page, the blog, the contact page or this page increases that day's page-view count. To count a unique visitor for the day, we store a SHA-256 fingerprint of the date, IP address and browser string. The raw IP is not kept in that statistic.
- The blog has no comments.
- Demo request: name, phone, clinic or shop name, chosen plan, and an optional message.
- Contact form: name, mobile, email if you add one, clinic name, city, subject, message, the page address the form was sent from, and utm parameters when the link has them. We also store the IP address and browser string with that message.
- Signing in: username or email, and a password. The short check on the login page stays in that session only. We do not use Google reCAPTCHA.
Customers (clinics and optical shops)
The clinic holds the software account. There is no public sign-up form on the marketing site.
- Staff: name, username, email, role and password. The password is stored as a hash, not as plain text.
- The business: name, short id, phone, WhatsApp, a Bale username if someone enters one, logo, and online booking settings.
- Day-to-day work, where that module is in use: appointments, invoices, inventory, suppliers, expenses, the cash drawer and payroll.
- Password reset: the email address and a temporary token that lasts about 60 minutes.
- On sign-in, the IP address and browser string are stored with the session.
- A log of staff actions in the panel, so the clinic can trace changes.
Patient data inside the software
The clinic or optical shop types this in. They decide why it is collected, so they are the controller of patient records. Lenzic only processes those records to run the software for that clinic. We do not use patient records for advertising and we do not sell them.
In the vocabulary of the GDPR and the UAE Personal Data Protection Law, that is a controller and processor relationship. It describes our role. It is not a certificate that every duty in those laws has been audited.
- The file: name, father's name when the clinic records it, mobile, date of birth, file number, and status flags the clinic sets on the file.
- If the clinic records them: insurer name and policy number.
- The exam: vision measurements including sphere (SPH), cylinder (CYL) and axis, near addition (ADD) when used, and the notes the practitioner writes on that visit. An uploaded prescription image is stored with the visit.
- Appointments booked in the panel or on the public booking link: name, mobile, date, time, exam service and a note. The public booking page lives on the app domain.
- Sales: invoice lines, amounts, payment method and any balance.
- Files the clinic attaches to a patient record.
- If the clinic turns on an online insurance check: the identifier they type, the policy number, and the answer returned by the connection they configured.
- If the clinic saves a WhatsApp number, the booking page can open a WhatsApp chat. That conversation then sits with WhatsApp. We do not keep a copy of the chat.
- The browser on a clinic computer can keep a local copy of working data so the panel still opens offline. That copy stays on the device.
Why we use it
- To reply to demo requests and contact messages, and to count visits on the marketing site.
- To sign staff in, and to slow bulk form posts. The contact form has a send limit and a hidden field aimed at bots.
- To run the clinic: reception, appointments, exams, sales, inventory and reports.
- The in-panel assistant: if an AI API key is configured, the staff question and the records needed to answer it are sent to an OpenAI-compatible service (api.openai.com unless another address is configured). With no key, the answer stays inside Lenzic.
- Support, security checks, and the backup file a clinic admin downloads.
Embedded content from other sites
The marketing pages do not embed YouTube or Aparat videos, maps, or a live chat widget. Pages are not framed by other sites.
The Vazirmatn and Syne fonts load from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). That request can expose your IP address to Google.
A WhatsApp link on our contact page, or on a clinic booking page, opens WhatsApp. We do not store that conversation.
Where data is stored, and how we protect it
Server location: [[hosting location]]. Application files stay on that server's disk. The software does not define a separate content-delivery network.
- Each clinic sees its own records, and staff access follows their role.
- Passwords are hashed.
- The session cookie is HttpOnly.
- Responses send headers that block framing by other sites, stop browsers guessing a file type, limit referrer detail, and restrict script and image sources.
- A clinic admin can download a zip of their own data. The file is removed from the server after the download. The software does not define an automatic backup to a second server.
We do not claim that the whole database is encrypted at rest. Session payloads are not encrypted in the default configuration either.
How long we keep data
Clinic and patient records stay while that clinic account is active.
After the account ends, we allow an export window of [[export period]] so the clinic can download a backup. After that window, that clinic's data is deleted. The window is not an automatic timer in the software yet. Deletion follows the end of the contract or a request from the clinic.
Demo requests and contact messages stay while we need them to reply and follow up. A sign-in session ends with the session cookie. A password-reset token lasts about 60 minutes.
Your rights and patient rights
You can ask for access, correction, deletion or a copy of your information.
- A staff user can update their name and email on the profile page, and can delete their own user account. Deleting one staff account does not erase the clinic's patient files.
- A clinic admin can correct a file, export a patient PDF, and download a zip backup.
- A patient asks the clinic, not Lenzic, for access, correction, deletion or a copy. The clinic is the controller. We act on a patient request when the clinic asks us to, including during the export window.
Children
The marketing site and user accounts are not meant for children, and we do not ask children to submit the demo or contact forms.
If a patient is a child, the clinic decides to create that file and remains responsible for it.
Changes to this policy
When this text changes, we update this page and the date at the top. We do not keep a public archive of older versions.
Contact us
Questions about this policy can go to the details below, or through the contact page.
- Email: info@getlenzic.com
- Phone: +971508902417
- WhatsApp: +971508902417
- Contact page: /contact