Raznameh Clinics · Platform guidelines

Everything your clinic needs, written down once.

Six guides, one for each kind of person who uses the platform. Every section opens by saying what it is, why it matters and what you will see — so you can find the one you need in seconds and skip the rest.

System blueprints

See how the whole thing works

Seven visual pages for managers, buyers and new staff: what the platform is built from, what happens when somebody books an appointment, the same business seen from each seat in it, and every module in the catalogue.

1 SurfacesThe mobile app, the client and practitioner portals, the back office and the public site
↓ HTTPS · JWT · WebSocket ↓
2 API gatewayThe only backend the app knows about — 28 endpoint groups, realtime chat and calls, and every secret
↓ Internal API ↓
3 Business coreOdoo 19 and 52 modules — bookings, credits, policies, pay, records and reports
↓ Data layer ↓
4 Data & servicesPostgreSQL and Redis, plus payments, messaging, storage and AI behind interfaces

See how the whole thing works

Security and compliance

Start with the country you operate in

The encryption, the access control, the audit log and the server hardening are the same everywhere. What changes by country is the rights and governance machinery on top — so each country has a page of its own, and they all rest on the shared one.

Read this one first Security & compliance The shared core every country page rests on How records are encrypted, who can open one, what the audit log records and how the server is hardened. The same in every country, built once — which is why the country pages below are short.
  • Encryption, access control and the audit log
  • Odoo Community's own security model, and how sign-in is protected
  • Server hardening, and the boundary between us and your infrastructure
  • A side-by-side matrix of what each country adds
United States USA HIPAA · HITECH · 42 CFR Part 2 The largest of the country pages. Everything HIPAA asks of a practice in one list, in ordinary words, with what the software does about each one beside it.
  • Every patient right, including the parts most systems leave out
  • All the security safeguards, and which are yours rather than ours
  • Breach notification: four factors, 60 days, per-state thresholds
  • Seven walkthroughs of what actually happens inside the software
European Union GDPR Regulation (EU) 2016/679 Lawful basis under Article 9(2)(h) rather than consent, erasure carried out by destroying the encryption key, and the two breach deadlines.
  • Why treatment records must not rest on consent
  • Erasure that honours the right without destroying the evidence
  • The 72-hour clock, and the keys-compromised question
  • Processing register and impact assessment as live records
Deutschland Germany § 203 StGB · § 630f BGB · NIS2 The European rules apply here unchanged — and then Germany adds a layer of its own, one piece of which is criminal law and decides whether a practice may lawfully buy at all.
  • § 203 StGB: why the supplier choice is the therapist’s legal risk
  • What a § 203 undertaking says, clause by clause
  • Ten years from the end of treatment, not from the file date
  • An honest account of the statutory rail we do not have
United Kingdom UK GDPR DPA 2018 · NHS Code of Practice 2021 What the United Kingdom adds on top of GDPR: the serious-harm test as a workflow that expires by itself, and the NHS retention schedule as shipped data.
  • Withholding that needs a named professional and lapses at six months
  • Twenty years after last contact for mental-health records
  • Access to Health Records Act 1990
  • Caldicott Principle 7, and why break-glass is a feature
Australia Privacy Act 13 APPs · NDB scheme · state retention law One federal law with no small-business exemption for a health provider, eight sets of state rules on retention, and a patient who can sue without waiting for a regulator.
  • All thirteen Australian Privacy Principles, one by one
  • APP 8: why nothing has to leave the country
  • Seven years from the last entry, and until 25 for a child
  • Essential Eight, ISO 27001 — and why SOCI does not apply
Shared by all of them Secure documents The machinery every country page relies on How a clinical record is encrypted, who can open one, and the whole life of a document from filing to disposal.
  • Envelope encryption, and why there are two keys rather than one
  • Access that follows the treatment relationship
  • Disposal by destroying a key rather than deleting a row
  • Seven risks stated plainly, with what stays yours

The six categories

Pick the guide that matches the person

Each category is a complete guide. Subcategories are its numbered sections — the same numbering the printed and Word editions use.

Reading these on paper?

Every guide is also a Word document with the same numbering, ready to print or hand out.