Privacy Policy
Updated:
1. Who we are, and what this document is
This policy explains what personal data is collected through softwiz.io (the “Site”), why, who it is shared with, how long it is kept, and what rights you have in relation to it.
Database controller and Site operator:
- Yonatan Shamam, licensed dealer (עוסק מורשה) no. 302910187, trading as SoftWiz.io
- Address: 94 Yigal Alon St, Tel Aviv, Israel
- Email: info@softwiz.io
- Phone: 055-955-9680
This document is written under the Israeli Protection of Privacy Law, 5741-1981, as amended by Amendment 13 (in force 14 August 2025). If you are in the European Union, the GDPR also applies, as set out in section 11.
Scope: this policy covers data collected through the Site only. Data we encounter while scoping, implementing and supporting systems for our clients, including access to their CRM, is governed by the individual engagement agreement, not by this document.
2. Definitions
“Personal data”: information relating to an identified person, or to a person who can be identified directly or indirectly.
“Processing”: any operation performed on data, including collection, receipt, storage, access, disclosure, transfer, alteration or deletion.
“Data subject”: the individual the personal data relates to, including anyone contacting us through the Site.
“Processor”: a party processing data on our behalf and on our instructions only, with no right to use it for its own purposes.
“The database”: the collection of enquiries received through the Site’s forms, managed by us as described in this document.
3. What we collect
3.1 Information you provide
When you use the contact or support form we collect:
- Full name and email address: required; without them we cannot reply
- Phone, company, your message, and on the support form also which system and a relevant link: optional
Providing this is neither a legal nor a contractual obligation. You are not required to give it, but without a name and email we cannot get back to you. Leaving the optional fields blank does not prevent a reply.
3.2 Information collected technically
- IP address: captured on form submission for rate limiting and abuse prevention. It is one-way hashed (SHA-256) on receipt and never stored in raw form. The hash is deleted automatically within ten minutes.
- Connection data: our hosting provider (Cloudflare) processes basic connection data, including IP address, to deliver and secure the service, acting as our processor.
3.3 Server logs and statistical data
Our hosting provider generates technical server logs for operation and security. These are retained by them briefly under their own policy, and we do not use them to identify visitors.
We may derive aggregated, anonymous statistics from the enquiries we receive, for example how many arrived in a month, or which topics recur. Aggregated data of this kind cannot identify anyone, is not personal data, and we may use it to improve the service and the Site.
3.4 What we do not do
As at the date of this document:
- The Site sets no cookies of any kind
- There is no traffic analytics, including Google Analytics
- There are no advertising pixels or social-network tracking tools
- The Site loads no third-party resources: even the fonts are served from our own origin
- We do not profile you and take no automated decisions about you
- We do not sell personal data or trade in it
4. Minors
The Site is intended for business use and is not directed at minors. We do not knowingly collect data about anyone under 18. If you become aware that a minor has given us information, please contact us and we will delete it.
5. Why we use it
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and contacting you back | Your consent, given by submitting the form |
| Providing support to existing clients | Performance of our engagement with you |
| Rate limiting and abuse prevention | Our legitimate interest in securing the Site |
| Meeting legal obligations and handling legal proceedings | Legal obligation and defence of our rights |
We do not use the data for any purpose other than the one it was given for. We do not send marketing messages without prior, separate, documented consent as required by section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982. If such consent is ever given, you may withdraw it at any time, as easily as it was given.
6. Who we share it with
We do not share personal data with third parties, other than the service providers below, who act as our processors and on our instructions only:
| Provider | Role | Processing location |
|---|---|---|
| Cloudflare, Inc. | Site hosting, security, attack mitigation | Global network |
| Resend (Plus Five Five, Inc.) | Delivery of the emails sent by the Site’s forms | Ireland (European Union) |
| Google Workspace | The mailboxes that receive enquiries | Global network |
Data may also be disclosed where required by a court order or binding legal provision, or where necessary to defend our rights in legal proceedings.
Transfers outside Israel: some of the providers above process data outside Israel. Such transfers are made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001, to countries offering an adequate level of protection, or to providers contractually committed to an equivalent standard.
7. Security
We apply reasonable technical and organisational measures, including: HTTPS encryption in transit, one-way hashing of IP addresses, rate limiting, automated-submission filtering, and deliberately minimising both the data collected and the number of people with access to it.
No system is entirely secure, however, and we cannot guarantee absolutely that data will be protected against every unauthorised access.
8. Security incidents
In the event of a serious security incident as defined in law, we will act on the obligations that apply to us, including notifying the Privacy Protection Authority and informing affected data subjects where required.
9. How long we keep it
| Type of data | Retention |
|---|---|
| Form enquiries | Up to 24 months from the end of the engagement or the last contact, whichever is later |
| Correspondence with existing clients | For the engagement and up to 24 months afterwards |
| Hashed IP values | Deleted automatically within ten minutes |
| Server logs at the hosting provider | Briefly, under that provider’s policy |
| Data required for a legal obligation or to defend a claim | For the period prescribed by law, or absent one, until the limitation period expires |
At the end of these periods data is deleted or anonymised.
10. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate, incomplete, unclear or out of date
- Deletion of data no longer needed for the purpose it was collected for
- Withdraw consent you have given, without affecting the lawfulness of processing carried out beforehand
- Not receive marketing messages, should any be sent in future
To exercise these: info@softwiz.io. We respond within 30 days. If you believe your rights have been infringed, you may complain to the Israeli Privacy Protection Authority.
11. No automated decision-making or profiling
We take no decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Enquiries received through the Site are read and handled by a person.
12. External links
The Site links to sites and profiles outside our control, including those of the system vendors we implement and social networks. This policy does not apply to them, and we are not responsible for how they collect or process data.
13. Visitors in the European Union
If you are in the EU, the following also apply under the GDPR:
- Legal bases are those in section 4: consent (Art. 6(1)(a)), performance of a contract (6(1)(b)), legitimate interests (6(1)(f)) and legal obligation (6(1)(c))
- Additional rights: data portability, restriction of processing, and objection to processing based on legitimate interests
- The right to lodge a complaint with the supervisory authority in your country of residence
- Most outbound email processing takes place within the European Union (Ireland)
14. Transfer of the business
If the SoftWiz.io business, in whole or in part, is transferred to another party, including through a merger, sale, transfer of assets or restructuring, that party may receive the data collected, provided it undertakes to observe this policy or one no less protective of data subjects. We will announce this prominently on the Site.
15. Changes to this policy
We update this document from time to time, including when our services or the applicable law change. The last update date appears at the top of the page. A material change will be brought to your attention prominently on the Site.
16. Reporting a fault or a suspected data leak
If you identify a security weakness on the Site, or suspect data has been exposed improperly, please tell us immediately at info@softwiz.io. We take every report seriously, will investigate it and will respond to you. We will not pursue anyone who reports a weakness in good faith, provided they did not exploit it or compromise anyone else’s data.
17. Questions
For any question about this policy or how your data is handled:
- Email: info@softwiz.io
- Phone: 055-955-9680
- Address: 94 Yigal Alon St, Tel Aviv, Israel
18. Governing law
This policy is governed by the laws of the State of Israel, and the competent courts of the Tel Aviv-Jaffa district have exclusive jurisdiction.
This English text is provided for convenience. In any conflict between it and the Hebrew version, the Hebrew version prevails.