מדיניות פרטיות
Privacy Policy
This English version is provided for convenience. The Hebrew version is the legally binding text.
1. מי אנחנו
1. Who We Are
סוג: עוסק מורשה
שם מסחרי בשימוש: agents&me (לא רשום כשם עסק נוסף; העוסק החוקי הוא "תום אבן")
מספר עוסק: 200322006
כתובת: שדרות השושנים 8, רמת גן
אימייל ליצירת קשר ופניות פרטיות: hey@agentsandme.com
טלפון: +972-52-432-8284
אתר: https://getagents.today
Type: Licensed dealer (osek murshe)
Trade name in use: agents&me (not registered as an additional business name; the legal dealer is "Tom Even")
Business ID: 200322006
Address: 8 HaShoshanim Blvd., Ramat Gan
Contact and privacy inquiries email: hey@agentsandme.com
Phone: +972-52-432-8284
Website: https://getagents.today
מדיניות זו מתארת כיצד אנחנו אוספים, משתמשים, שומרים ומגינים על המידע האישי שלכם. היא נכתבה בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, ולתיקון 13 לחוק שנכנס לתוקף ב-14 באוגוסט 2025.
This policy describes how we collect, use, store, and protect your personal information. It was written in accordance with the Israeli Protection of Privacy Law (חוק הגנת הפרטיות, התשמ"א-1981) and Amendment 13 to the law, which entered into force on August 14, 2025.
2. איזה מידע אנחנו אוספים
2. What Information We Collect
אנחנו אוספים אך ורק את המידע הנדרש למתן השירות. בהתאם לעיקרון מזעור הנתונים בתיקון 13, אנחנו לא אוספים מידע "ליתר ביטחון".
We collect only the information required to provide the service. In line with the data minimization principle of Amendment 13, we do not collect information "just in case."
2.1 מידע שאתם מספקים באופן יזום
2.1 Information You Provide Actively
- בטופס ההרשמה לסדנה: שם מלא, כתובת אימייל, תפקיד מקצועי (אופציונלי), זמינות מועדפת (אופציונלי), מטרות שלכם (אופציונלי), ערוץ הגעה (אופציונלי).
- בטופס רכישת מקום בסדנה: שם מלא, כתובת אימייל, מספר טלפון נייד (לשליחת אישור ההרשמה בוואטסאפ), מספר המקומות, וקוד קופון אם יש. פרטי כרטיס האשראי מוזנים ומעובדים אצל חברת הסליקה ואינם עוברים דרכנו ואינם נשמרים אצלנו.
- בהרשמה לאזור החברים ("Inside"): שם, כתובת אימייל ומספר טלפון. הכניסה מתבצעת בקישור חד-פעמי לאימייל, ללא סיסמה.
- בתגובות פומביות באתר (במגזין "שאלות&תשובות" ובעמודי הניוזלטר): שם (אופציונלי) ותוכן התגובה. שימו לב: תגובה שתפרסמו נועדה להיות גלויה לציבור.
- בטפסי תוכן ושאלונים באתר (למשל מחשבון הזמן, שאלון "המוח שלך", תיבת השאלות): הפרטים שתמלאו ותוכן חופשי שתכתבו על עצמכם ועל העסק שלכם.
- בהנפקת תעודת סיום: שם פרטי ושם משפחה, לצורך הדפסתם על גבי התעודה.
- בפנייה ישירה באימייל: כל מידע שאתם בוחרים לשתף בפנייה.
- בעת רישום לניוזלטר: כתובת אימייל. הרישום מתבצע בפלטפורמה חיצונית (Substack או Kit) ומדיניות הפרטיות שלה חלה במקביל.
- Workshop registration form: full name, email address, professional role (optional), preferred availability (optional), your goals (optional), how you found us (optional).
- Workshop seat purchase form: full name, email address, mobile phone number (for sending the registration confirmation on WhatsApp), number of seats, and a coupon code if you have one. Credit card details are entered and processed at the payment processor; they do not pass through us and are not stored by us.
- Members area ("Inside") registration: name, email address, and phone number. Sign-in is via a one-time link sent by email, with no password.
- Public comments on the Site (in the "שאלות&תשובות" magazine and on newsletter pages): name (optional) and the comment content. Please note: a comment you post is intended to be publicly visible.
- Content forms and questionnaires on the Site (for example the time calculator, the "Your Brain" questionnaire, the question box): the details you fill in and free-form text you write about yourself and your business.
- Certificate of completion: first and last name, for printing on the certificate.
- Direct email inquiries: any information you choose to share in your message.
- Newsletter sign-up: email address. Registration takes place on an external platform (Substack or Kit) and its privacy policy applies in parallel.
שדות הקלט שבהם אתם מקלידים פרטים אישיים מסומנים אצלנו כשדות מוסתרים בכלי ניתוח השימוש, כך שתוכן ההקלדה בהם אינו נקלט בהקלטות השימוש המתוארות בסעיף 2.3.
Input fields where you type personal details are marked as masked fields in our usage-analytics tools, so what you type in them is not captured in the session recordings described in section 2.3.
2.2 מידע שנאסף באופן אוטומטי
2.2 Information Collected Automatically
בהתאם להגדרת "מידע אישי" בתיקון 13, גם המידע הבא נחשב מידע אישי:
Under the definition of "personal information" in Amendment 13, the following also counts as personal information:
- כתובת IP
- סוג דפדפן ומערכת הפעלה
- עמודים שביקרתם בהם באתר
- זמן ומשך הביקור
- אתר המקור שממנו הגעתם (referrer)
- IP address
- Browser type and operating system
- Pages you visited on the Site
- Time and duration of the visit
- The site you arrived from (referrer)
מידע זה נאסף באמצעות שירות האירוח שלנו (Netlify) ומשמש לאבטחה, איתור תקלות, ושיפור האתר.
This information is collected through our hosting service (Netlify) and is used for security, troubleshooting, and improving the Site.
2.3 ניתוח שימוש והקלטות שימוש (חשוב שתדעו)
2.3 Usage Analytics and Session Recordings (Important to Know)
אנחנו רוצים להיות מפורשים בנקודה הזו, כי היא לא מובנת מאליה ורוב האתרים לא מספרים אותה:
We want to be explicit on this point, because it is not obvious and most sites do not tell you:
- Google Analytics אוסף נתוני שימוש מצטברים: אילו עמודים נצפו, מאיפה הגעתם, סוג המכשיר.
- Microsoft Clarity עושה יותר מזה. הוא מתעד את סשן הגלישה עצמו: תנועות עכבר, גלילה, ולחיצות. זה עוזר לנו להבין איפה אנשים נתקעים בעמוד ולתקן. שדות שבהם מוקלדים פרטים אישיים (שם, אימייל, טלפון, תוכן חופשי) מסומנים כמוסתרים ותוכנם אינו נקלט בהקלטה.
- Google Analytics collects aggregate usage data: which pages were viewed, where you came from, device type.
- Microsoft Clarity does more than that. It records the browsing session itself: mouse movements, scrolling, and clicks. This helps us understand where people get stuck on a page, and fix it. Fields where personal details are typed (name, email, phone, free text) are marked as masked and their content is not captured in the recording.
שני הכלים פועלים כברירת מחדל, בהתאם לחובת היידוע שבחוק הגנת הפרטיות. אתם יכולים לכבות אותם בכל רגע דרך באנר העוגיות או הקישור "הגדרות עוגיות" בתחתית העמוד. הכיבוי תקף ומיידי, ואינו פוגע בשום דבר אחר באתר.
Both tools run by default, in accordance with the notification duty in the Protection of Privacy Law. You can turn them off at any moment via the cookie banner or the "Cookie settings" link at the bottom of the page. The opt-out is effective and immediate, and does not affect anything else on the Site.
3. למה אנחנו אוספים את המידע (מטרות השימוש)
3. Why We Collect the Information (Purposes of Use)
| מידע | מטרה |
|---|---|
| שם + אימייל מטופס הרשמה | יצירת קשר בנוגע לסדנה, שליחת פרטים על מועדים זמינים, מענה לשאלות |
| תפקיד + מטרות | התאמת תכני הסדנה לקהל, הבנת צרכי המשתתפים |
| ערוץ הגעה | הבנת מקורות תנועה לאתר (סטטיסטי, מצטבר) |
| טלפון נייד (ברכישה בלבד) | שליחת אישור ההרשמה ותזכורת לפני הסדנה בוואטסאפ |
| שם ותוכן בתגובה פומבית | הצגת התגובה באתר. תוכן שאתם בוחרים לפרסם |
| תוכן חופשי בשאלונים | התאמת התשובה או ההמלצה שתקבלו |
| אימייל לניוזלטר | שליחת תכנים שבועיים בלבד אם נתתם הסכמה מפורשת לכך |
| נתוני שימוש (IP, דפדפן) | אבטחת האתר, אנליטיקה אגרגטיבית, איתור תקלות |
| נתוני ניתוח שימוש והקלטת סשן | הבנת איפה אנשים נתקעים באתר ותיקון התקלה. ראו סעיף 2.3 |
| Information | Purpose |
|---|---|
| Name + email from the registration form | Contacting you about the workshop, sending details about available dates, answering questions |
| Role + goals | Tailoring workshop content to the audience, understanding participants' needs |
| Referral channel | Understanding traffic sources to the Site (statistical, aggregate) |
| Mobile phone (purchase only) | Sending the registration confirmation and a pre-workshop reminder on WhatsApp |
| Name and content of a public comment | Displaying the comment on the Site. Content you choose to publish |
| Free text in questionnaires | Tailoring the answer or recommendation you receive |
| Newsletter email | Sending weekly content only, and only if you gave explicit consent |
| Usage data (IP, browser) | Site security, aggregate analytics, troubleshooting |
| Usage-analytics and session-recording data | Understanding where people get stuck on the Site and fixing it. See section 2.3 |
שימוש שיווקי דורש הסכמה מפורשת ונפרדת. מילוי טופס ההרשמה לבדו אינו מהווה הסכמה לקבלת חומרים שיווקיים. תקבלו מאיתנו רק את התקשורת שאליה הסכמתם במפורש (סעיף 30א לחוק התקשורת, "חוק הספאם").
Marketing use requires explicit, separate consent. Filling in the registration form does not by itself constitute consent to receive marketing materials. You will receive from us only the communications you explicitly agreed to (Section 30A of the Israeli Communications Law (חוק התקשורת), the "Spam Law").
4. שיתוף מידע עם צדדים שלישיים (מעבדי משנה)
4. Sharing Information with Third Parties (Sub-Processors)
איננו מוכרים, משכירים או סוחרים במידע האישי שלכם. אנחנו משתפים מידע מינימלי עם מעבדי משנה (sub-processors) שמסייעים לנו להפעיל את העסק. רשימה מלאה ועדכנית:
We do not sell, rent, or trade your personal information. We share minimal information with sub-processors that help us run the business. Full, up-to-date list:
| ספק | תפקיד | מיקום | נתונים מועברים |
|---|---|---|---|
| Netlify, Inc. | אירוח האתר ואחסון פניות מטופס | ארה"ב | שם, אימייל, תפקיד, תוכן הפנייה, IP, user-agent |
| Substack, Inc. | שירות ניוזלטר (אופציונלי). הרישום מתבצע ישירות מול Substack ואיננו מקבלים גישה לכתובות האימייל של המנויים אלא דרך לוח הבקרה של Substack עצמה | ארה"ב | אימייל בלבד (רק במנויים) |
| Google LLC (Workspace) | שרת אימייל ארגוני | ארה"ב / EU | תכתובות אימייל |
| Google LLC (YouTube) | סרטונים משובצים | ארה"ב | נתוני נגן (רק בעת ניגון) |
| Google LLC (Analytics) | ניתוח שימוש מצטבר באתר | ארה"ב | נתוני שימוש, IP, מזהה מכשיר. ללא שם או אימייל |
| Microsoft Corporation (Clarity) | הקלטת סשן גלישה לשיפור חוויית המשתמש (ראו סעיף 2.3) | ארה"ב | תנועות עכבר, גלילה, לחיצות, IP, סוג מכשיר. תוכן שדות אישיים מוסתר ואינו נשלח |
| Kit (ConvertKit LLC) | רשימת תפוצה לתכנים (אופציונלי) | ארה"ב | אימייל בלבד, ורק אם נרשמתם |
| Grow (GrowPayments) | סליקת תשלומים לסדנאות (בעת רכישה) | ישראל | שם, אימייל, פרטי חיוב. פרטי כרטיס אשראי מעובדים על ידי Grow ואינם מגיעים אלינו |
| Morning (Greeninvoice) | הנפקת חשבוניות וקבלות | ישראל | שם, אימייל, פרטי עסקה לצורך מסמך חשבונאי |
| Provider | Role | Location | Data transferred |
|---|---|---|---|
| Netlify, Inc. | Site hosting and storage of form submissions | USA | Name, email, role, inquiry content, IP, user-agent |
| Substack, Inc. | Newsletter service (optional). Registration takes place directly with Substack and we do not receive access to subscribers' email addresses except through Substack's own dashboard | USA | Email only (subscribers only) |
| Google LLC (Workspace) | Business email server | USA / EU | Email correspondence |
| Google LLC (YouTube) | Embedded videos | USA | Player data (only during playback) |
| Google LLC (Analytics) | Aggregate site usage analytics | USA | Usage data, IP, device identifier. No name or email |
| Microsoft Corporation (Clarity) | Browsing session recording for user experience improvement (see section 2.3) | USA | Mouse movements, scrolling, clicks, IP, device type. Content of personal fields is masked and not sent |
| Kit (ConvertKit LLC) | Content mailing list (optional) | USA | Email only, and only if you signed up |
| Grow (GrowPayments) | Payment processing for workshops (at purchase) | Israel | Name, email, billing details. Credit card details are processed by Grow and do not reach us |
| Morning (Greeninvoice) | Issuing invoices and receipts | Israel | Name, email, transaction details for the accounting document |
כל הספקים מחזיקים בהתחייבויות פרטיות חוזיות (Data Processing Agreements). העברת מידע מחוץ לישראל מתבצעת בהתאם לתקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001. ארה"ב נחשבת כיום כמדינה ללא רמת הגנה נאותה לפי התקנות, וההעברה נשענת על חריגי תקנה 2, לפי סוג המידע:
All providers are bound by contractual privacy commitments (Data Processing Agreements). Transfer of information outside Israel is carried out in accordance with the Israeli Privacy Protection Regulations (Transfer of Data to Databases Abroad) (תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001). The USA is currently considered a country without an adequate level of protection under these regulations, and the transfer relies on the exemptions in Regulation 2, according to the type of information:
- מידע הדרוש למתן השירות שביקשתם (הרשמה לסדנה, רכישה, אזור החברים, תכתובת איתנו): ההעברה נדרשת לשם קיום ההתקשרות איתכם. בלי להעביר את כתובת האימייל שלכם לשרת שמאחסן את הטופס, לא ניתן לשלוח לכם את פרטי הסדנה.
- מידע שיווקי (רשימת תפוצה): על בסיס הסכמתכם המפורשת, שניתנת בנפרד וניתנת לביטול בכל עת.
- נתוני ניתוח שימוש (סעיף 2.3): על בסיס האינטרס הלגיטימי שלנו לתפעל ולשפר את האתר, בכפוף לזכותכם לכבות אותם בכל רגע.
- Information required to provide the service you requested (workshop registration, purchase, members area, correspondence with us): the transfer is required in order to perform our engagement with you. Without transferring your email address to the server that stores the form, we cannot send you the workshop details.
- Marketing information (mailing list): based on your explicit consent, given separately and revocable at any time.
- Usage-analytics data (section 2.3): based on our legitimate interest in operating and improving the Site, subject to your right to turn it off at any moment.
רשימה זו מתעדכנת בעת הוספה או החלפה של מעבד משנה. שינויים מהותיים יפורסמו בעמוד זה לפני יישום.
This list is updated whenever a sub-processor is added or replaced. Material changes will be published on this page before implementation.
5. עוגיות (Cookies)
5. Cookies
האתר משתמש בעוגיות מינימליות:
The Site uses minimal cookies:
- עוגיות חיוניות: נדרשות לפעולת האתר (העדפת שפה, מצב התצוגה, שמירת בחירתכם בנוגע לעוגיות עצמן, וכניסה לאזור החברים). לא ניתן לכבות אותן, כי בלעדיהן האתר לא עובד.
- עוגיות ניתוח שימוש: משמשות את הכלים שבסעיף 2.3. הן פועלות כברירת מחדל, ואתם יכולים לכבות אותן בכל רגע.
- Essential cookies: required for the Site to function (language preference, display mode, saving your choice regarding the cookies themselves, and members-area sign-in). They cannot be turned off, because the Site does not work without them.
- Usage-analytics cookies: used by the tools described in section 2.3. They run by default, and you can turn them off at any moment.
נאמר את זה בפירוש, כי הרבה אתרים מעמידים פנים אחרת: חוק הגנת הפרטיות הישראלי מחייב אותנו ליידע אתכם על איסוף המידע, ולא לבקש את אישורכם מראש לפני שהוא מתחיל. לכן עוגיות ניתוח השימוש נטענות כשאתם מגיעים לאתר, ואנחנו אומרים לכם את זה בבאנר במקום להסתיר את זה בשורה במסמך.
We will say this plainly, because many sites pretend otherwise: the Israeli Protection of Privacy Law requires us to inform you about the data collection, not to request your prior approval before it starts. That is why the usage-analytics cookies load when you arrive at the Site, and we tell you so in a banner instead of hiding it in a line in a document.
הכפתור עובד באמת. לחיצה על "בלי אנליטיקה" בבאנר, או על "הגדרות עוגיות" בתחתית כל עמוד, מפסיקה את איסוף נתוני ניתוח השימוש בכל עמודי האתר, מיידית ובאופן קבוע, עד שתשנו את דעתכם. הבחירה נשמרת בדפדפן שלכם. אם אתם גולשים מדפדפן אחר או ממכשיר אחר, תצטרכו לבחור שוב.
The button really works. Clicking "No analytics" in the banner, or "Cookie settings" at the bottom of every page, stops the collection of usage-analytics data across all pages of the Site, immediately and permanently, until you change your mind. The choice is saved in your browser. If you browse from a different browser or device, you will need to choose again.
איננו משתמשים בפיקסלים פרסומיים של רשתות חברתיות (Meta, LinkedIn, TikTok) ואיננו מבצעים רימרקטינג.
We do not use social network advertising pixels (Meta, LinkedIn, TikTok) and we do not run remarketing.
6. כמה זמן אנחנו שומרים את המידע
6. How Long We Keep the Information
- פניות מטופס הרשמה (ליד ללא עסקה): עד 24 חודשים מיום הפנייה האחרונה, או עד שתבקשו מחיקה.
- תכתובות אימייל שיווקיות וכלליות (ללא עסקה): עד 24 חודשים מהתכתובת האחרונה, או עד שתבקשו מחיקה.
- תכתובות ומסמכים הקשורים לעסקה בפועל (חשבוניות, קבלות, תיאומי סדנה, תכתובות לגבי ביטול או החזר): עד 7 שנים, בהתאם לדרישות חוק מס הכנסה וחוק מע"מ לעוסק מורשה.
- נתוני אנליטיקה: עד 14 חודשים, באופן אגרגטיבי בלבד.
- הרשמה לניוזלטר: עד שתבטלו את ההרשמה (כפתור unsubscribe בכל מייל).
- Registration form inquiries (lead without a transaction): up to 24 months from the last contact, or until you request deletion.
- Marketing and general email correspondence (no transaction): up to 24 months from the last correspondence, or until you request deletion.
- Correspondence and documents related to an actual transaction (invoices, receipts, workshop scheduling, cancellation or refund correspondence): up to 7 years, per the requirements of Israeli income tax law and VAT law for a licensed dealer.
- Analytics data: up to 14 months, in aggregate form only.
- Newsletter subscription: until you unsubscribe (an unsubscribe button in every email).
אנחנו עורכים סקירה שנתית של נתונים שאנחנו מחזיקים, ומוחקים מידע שאינו דרוש עוד למטרה שלשמה נאסף, בהתאם לתקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017.
We conduct an annual review of the data we hold, and delete information no longer needed for the purpose for which it was collected, in accordance with the Israeli Privacy Protection Regulations (Data Security) (תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017).
7. הזכויות שלכם ונוהל מימושן
7. Your Rights and How to Exercise Them
על פי החוק, אתם זכאים:
Under the law, you are entitled to:
- זכות עיון: לקבל עותק של כל המידע שאנחנו מחזיקים עליכם.
- זכות תיקון: לדרוש תיקון מידע שגוי או לא מדויק.
- זכות מחיקה: לדרוש מחיקת מידע (כפוף לחובות חוקיות שלנו לשמור מסמכי הנהלת חשבונות).
- זכות ביטול הסכמה: לחזור בכם מכל הסכמה שיווקית בכל עת ובאופן מיידי.
- זכות תלונה: להתלונן בפני הרשות להגנת הפרטיות ללא חובת פנייה מוקדמת אלינו.
- Right of access: receive a copy of all the information we hold about you.
- Right of correction: demand correction of wrong or inaccurate information.
- Right of deletion: demand deletion of information (subject to our legal obligations to keep bookkeeping documents).
- Right to withdraw consent: withdraw any marketing consent at any time, with immediate effect.
- Right to complain: file a complaint with the Israeli Privacy Protection Authority, with no obligation to contact us first.
7.1 נוהל מימוש זכויות (DSAR)
7.1 Rights Request Procedure (DSAR)
למימוש כל אחת מהזכויות, פעלו לפי הנוהל הבא:
To exercise any of these rights, follow this procedure:
- שלחו אימייל ל-hey@agentsandme.com עם כותרת "בקשת מימוש זכויות פרטיות" וציינו את סוג הבקשה (עיון / תיקון / מחיקה / ביטול הסכמה).
- אימות זהות: נבקש מכם לאשר את הזהות באמצעות שליחת הבקשה מאותה כתובת אימייל שאיתה נרשמתם, או באמצעות ציון 2 פרטים מתוך הפנייה המקורית. אימות הזהות מגן עליכם מבקשות זדוניות בשמכם.
- אישור קבלה: נשלח אישור קבלה תוך 2 ימי עסקים.
- מענה מלא: נשלים את הבקשה תוך 30 יום ממועד אימות הזהות. במקרים מורכבים נודיע לכם על הארכה לעד 60 יום נוספים, עם נימוק.
- עלות: הטיפול בבקשה אינו כרוך בתשלום. בקשות חוזרות, מוגזמות או מופרכות עלולות להיות כרוכות באגרה סבירה בהתאם לחוק.
- סירוב חלקי: אם נסרב לבקשה במלואה או בחלקה (למשל בשל חובות שמירת מסמכים מס הכנסה), נסביר את הסיבה ונפנה אתכם לרשות להגנת הפרטיות לערעור.
- תיעוד: כל הבקשות מתועדות ביומן פנימי לצרכי ביקורת.
- Send an email to hey@agentsandme.com with the subject "Privacy rights request" and state the request type (access / correction / deletion / consent withdrawal).
- Identity verification: we will ask you to confirm your identity by sending the request from the same email address you registered with, or by stating 2 details from your original submission. Identity verification protects you against malicious requests made in your name.
- Acknowledgment: we will send an acknowledgment within 2 business days.
- Full response: we will complete the request within 30 days of identity verification. In complex cases we will notify you of an extension of up to 60 additional days, with reasoning.
- Cost: handling the request is free of charge. Repeated, excessive, or unfounded requests may carry a reasonable fee in accordance with the law.
- Partial refusal: if we refuse the request in whole or in part (for example due to income tax document retention obligations), we will explain the reason and refer you to the Privacy Protection Authority to appeal.
- Documentation: all requests are logged in an internal register for audit purposes.
7.2 תוצאת המחיקה
7.2 What Deletion Means
בקשת מחיקה תביא להסרת המידע ממסדי הנתונים שלנו ומשרתי מעבדי המשנה (Netlify) תוך 30 יום, למעט מידע שאנו חייבים לשמור על פי דין (חשבוניות, תכתובות הקשורות לעסקה: עד 7 שנים בהתאם להוראות מס הכנסה).
A deletion request will result in the removal of the information from our databases and from the sub-processors' servers (Netlify) within 30 days, except for information we are required to keep by law (invoices, transaction-related correspondence: up to 7 years per income tax requirements).
8. הודעה על אירוע אבטחה (Data Breach)
8. Data Breach Notification
בהתאם לתיקון 13 לחוק הגנת הפרטיות, אנחנו מתחייבים להליך הבא במקרה של אירוע אבטחה חמור:
In accordance with Amendment 13 to the Protection of Privacy Law, we commit to the following process in the event of a serious security incident:
- חקירה מיידית: תוך 24 שעות מגילוי האירוע.
- הודעה לרשות להגנת הפרטיות: מיידית עם גילוי אירוע אבטחה חמור, ולא יאוחר מ-72 שעות, אם האירוע צפוי לפגוע בפרטיות.
- הודעה לאנשים שנפגעו: בהקדם האפשרי, ולא יאוחר מ-72 שעות, באמצעות אימייל לכתובת האחרונה שמסרתם, ופרסום הודעה בעמוד זה.
- תוכן ההודעה: אופי האירוע, סוג המידע שנפגע, צעדים שננקטו, פעולות מומלצות לכם, ופרטי איש קשר.
- תיעוד: כל אירוע מתועד ביומן אבטחה פנימי לצרכי ביקורת ולמידה.
- Immediate investigation: within 24 hours of discovering the incident.
- Notification to the Privacy Protection Authority: immediately upon discovery of a serious security incident, and no later than 72 hours, if the incident is likely to harm privacy.
- Notification to affected individuals: as soon as possible, and no later than 72 hours, by email to the last address you provided, plus a notice published on this page.
- Notification content: the nature of the incident, the type of information affected, steps taken, recommended actions for you, and contact details.
- Documentation: every incident is logged in an internal security register for audit and learning.
9. אבטחת מידע
9. Data Security
אנחנו מיישמים אמצעי אבטחה סבירים בהתאם לרמת הסיכון של מסד הנתונים שלנו (רמה בסיסית לפי תקנות אבטחת מידע 2017). במקום רשימת הכללות, אלה האמצעים שמופעלים בפועל:
We implement reasonable security measures according to the risk level of our database (basic level under the 2017 Data Security Regulations). Instead of a list of generalities, these are the measures actually in place:
- הצפנת תעבורה: HTTPS בכל האתר, עם אכיפת HSTS ברמת השרת.
- כניסה ללא סיסמה: הכניסה לאזור החברים מתבצעת בקישור חד-פעמי חתום קריפטוגרפית שתקף ל-30 דקות. אין סיסמה שאפשר לנחש, לדלוף או לעשות בה שימוש חוזר.
- עוגיית התחברות מוקשחת: חתומה, מסומנת HttpOnly ו-Secure כך שקוד בדפדפן אינו יכול לקרוא אותה.
- בדיקת הרשאה בכל פנייה: הזכאות שלכם מחושבת מחדש בכל בקשה מול תאריך המנוי בפועל, ולא נסמכת על סטטוס שמור שעלול להתיישן.
- הסתרת שדות אישיים בכלי הניתוח: תוכן שדות שם, אימייל, טלפון וטקסט חופשי מסומן כמוסתר ואינו נקלט בהקלטות השימוש.
- הפרדת מידע התשלום: פרטי כרטיס אשראי מעובדים אצל חברת הסליקה בלבד. הם אינם עוברים דרך השרתים שלנו ואינם נשמרים אצלנו.
- גיבוי יומי של מאגרי העבודה והתכנים.
- סקירת אבטחה: נערכה סקירת אבטחה מקיפה באפריל 2026, וממצאיה מטופלים באופן שוטף. הסקירה הבאה מתוכננת לאפריל 2027.
- Traffic encryption: HTTPS across the entire Site, with HSTS enforced at the server level.
- Passwordless sign-in: members-area sign-in uses a cryptographically signed one-time link valid for 30 minutes. There is no password to guess, leak, or reuse.
- Hardened session cookie: signed, marked HttpOnly and Secure, so browser code cannot read it.
- Authorization check on every request: your entitlement is recalculated on every request against the actual subscription date, rather than relying on a stored status that can go stale.
- Masking of personal fields in analytics tools: the content of name, email, phone, and free-text fields is marked as masked and is not captured in session recordings.
- Payment data separation: credit card details are processed by the payment processor only. They do not pass through our servers and are not stored by us.
- Daily backup of work and content repositories.
- Security review: a comprehensive security review was conducted in April 2026, and its findings are being addressed on an ongoing basis. The next review is planned for April 2027.
אנחנו מנהלים יומן פנימי של אירועי אבטחה ושל בקשות למימוש זכויות, לצורכי ביקורת ולמידה.
We maintain an internal log of security events and of rights requests, for audit and learning purposes.
ומה שעדיין לא מושלם: אנחנו בעיצומו של תהליך להרחבת הגיבוי גם למאגרי ההזמנות והחברים, ולהחלפת מנגנון הגישה הניהולי במנגנון מבוסס-משתמש. אנחנו כותבים את זה כאן במקום לשתוק, כי הצהרת אבטחה שאי אפשר לגבות בראיות שווה פחות מכלום.
And what is still not perfect: we are in the middle of extending backups to the orders and members databases as well, and replacing the administrative access mechanism with a user-based one. We write this here instead of staying silent, because a security statement that cannot be backed by evidence is worth less than nothing.
על אף האמור, אין מערכת אבטחה שהיא מוגנת ב-100%. במקרה של אירוע אבטחה משמעותי המשפיע על המידע שלכם, נודיע לכם ולרשות להגנת הפרטיות בהתאם לחובות הדיווח.
Notwithstanding the above, no security system is 100% protected. In the event of a significant security incident affecting your information, we will notify you and the Privacy Protection Authority in accordance with the reporting obligations.
10. שימוש בבינה מלאכותית (AI)
10. Use of Artificial Intelligence (AI)
בשקיפות מלאה: agents&me הוא עסק שמלמד שימוש בסוכני AI, ואנחנו עצמנו עושים שימוש בסוכני AI בתפעול היומיומי, כולל בעיבוד פניות, ניסוח טיוטות תשובות, ועריכת תוכן.
In full transparency: agents&me is a business that teaches the use of AI agents, and we ourselves use AI agents in day-to-day operations, including processing inquiries, drafting replies, and editing content.
- אם אתם מתקשרים איתנו באימייל, ייתכן שטיוטה ראשונית של התשובה תיכתב על ידי סוכן AI ותיבדק על ידי אדם לפני השליחה.
- איננו מעבירים את המידע האישי שלכם לספקי AI לצורך אימון מודלים ציבוריים. שימוש ב-AI מוגבל לעיבוד הפנייה הספציפית שלכם במסגרת השירות שביקשתם.
- לא מבוצעות החלטות אוטומטיות חשובות (קבלה, דחייה, תמחור) על ידי AI ללא בקרת אדם, בהתאם לזכות העיון בהחלטות אוטומטיות לפי תיקון 13.
- If you correspond with us by email, an initial draft of the reply may be written by an AI agent and reviewed by a human before sending.
- We do not transfer your personal information to AI providers for the training of public models. AI use is limited to processing your specific inquiry within the service you requested.
- No significant automated decisions (acceptance, rejection, pricing) are made by AI without human oversight, in accordance with the right of access regarding automated decisions under Amendment 13.
11. קישורים לאתרים חיצוניים
11. Links to External Sites
האתר מכיל קישורים לאתרים חיצוניים (Substack, LinkedIn, YouTube ועוד). מדיניות הפרטיות הזו אינה חלה על אתרים אלה. אנא קראו את מדיניות הפרטיות שלהם.
The Site contains links to external sites (Substack, LinkedIn, YouTube, and others). This privacy policy does not apply to those sites. Please read their privacy policies.
12. שינויים במדיניות זו
12. Changes to This Policy
אנחנו עשויים לעדכן מדיניות זו מעת לעת. שינויים מהותיים יפורסמו בעמוד זה ויצוין תאריך העדכון בראש המסמך. במקרה של שינוי מהותי המשפיע על זכויותיכם, נודיע לכם באימייל אם נתתם לנו את כתובתכם.
We may update this policy from time to time. Material changes will be published on this page and the update date will be noted at the top of the document. In the event of a material change affecting your rights, we will notify you by email if you have given us your address.
13. דין חל וסמכות שיפוט
13. Governing Law and Jurisdiction
על מדיניות זו ועל פעילות האתר חל הדין הישראלי. סמכות השיפוט הבלעדית בכל מחלוקת נתונה לבתי המשפט המוסמכים במחוז תל אביב-יפו.
This policy and the operation of the Site are governed by Israeli law. Exclusive jurisdiction over any dispute is granted to the competent courts of the Tel Aviv-Jaffa district.