Privacy Policy
1.Who We Are (Data Controller)
The data controller responsible for your personal data is health.systems, a brand operated by Enterprise.Systems, a company organized under the laws of the State of Israel ("we", "us", or the "Company").
For any privacy matter, including to exercise your rights, you can contact our Data Protection Officer (DPO):
2.Data We Collect
We collect only what we need to run the Service. The table below summarises the categories of personal data we process.
| Category | Details |
|---|---|
| Email address | To create and identify your account and to contact you. |
| Phone number | Collected and verified by SMS one-time code (through Twilio). Your verified number is stored to secure your account, enforce one account per person, and prevent abuse of the free scan. It is deleted when you erase your account. |
| Device fingerprint | A technical identifier used to secure your account and limit abuse of the free scan. |
| Face camera video | Processed in real time to derive a colour signal (rPPG); raw video frames are NOT stored and are discarded after processing. |
| Wellness metrics & observations | Derived values such as heart rate (HR), respiration rate (RR), heart-rate variability (HRV), and a stress index, together with qualitative face-wellness signals and eye-colour observations. These are wellness signals only — not a diagnosis. |
| Eye (conjunctiva) images | Close-up images of the white of your eye, captured during a scan. Stored on our infrastructure with restricted access and compared only against your own prior image to observe change over time. You can delete these images at any time (see Your GDPR Rights). |
| Voice recordings (optional voice check-in) | Only with your separate opt-in consent, an approximately 12-second voice clip is analyzed for its sound qualities (energy, pace, and pitch steadiness). The recording is deleted immediately after these sound features are measured — on our servers it never outlives the request that processed it. We never store your voice, never create a transcript, and never analyze what you said. Only derived numeric values are kept, compared solely against your own earlier check-ins; they are wellness reflections of how your voice sounded — never an assessment of your mood or mental state, and never a diagnosis. You can withdraw this consent at any time in Account, and the derived values are erased with the rest of your data (see Your GDPR Rights). |
| Scan timestamps | The date and time of each check-in, to build your timeline of trends. |
| Reminder settings & push subscription (optional) | If you turn on the morning reminder (off by default), we store your chosen reminder time, time-zone offset, and language, and — where you also grant the browser notification permission — your browser's push subscription (the push service endpoint URL and its encryption keys). These identify your browser for delivery only; they carry no message content, are used for at most one reminder per day plus an optional weekly summary, and are deleted when you disable reminders, unsubscribe, or erase your data. |
| Guided session results (breathing / recovery) | When you complete a guided two-reading session, we store the session type, its timestamps, and the resulting before/after wellness values (your own within-session change in pulse and breathing rate). These are wellness reflections of how your body settled — not a fitness score and not a medical measurement — and are erased with the rest of your data. |
| Referral data | If you use or share a referral code, we record the code and, where you were referred by someone, a link to the referring account. Used only to grant free-scan credits — we do not collect any other information about who referred you. |
| Subscription & payment state | Your plan type, subscription dates, and remaining scan credits. Full payment-card details are entered with and held by PayPal and are never stored by us. |
| IP address | Collected for security and abuse prevention; anonymised. |
| Browser / device info | Basic technical details (e.g. device type, OS, app version) to deliver and troubleshoot the Service. |
Scanning before you verify
You can take your first check-in before verifying your phone number. The data from that scan — your wellness metrics, its timestamp, and any eye image — is stored against the account and device you used and stays associated with them. Verifying your phone afterwards simply confirms the account that already holds that data; it is not re-collected or moved. To continue past your first check-in, phone verification is required.
3.What We Do Not Collect
- We do not perform biometric identification.
- We do not perform facial recognition.
- We do not collect or produce health diagnosis data — checkup.report is a wellness product, not a diagnostic one.
- Blood-oxygen saturation (SpO₂) is measured only for internal research and validation; it is never displayed to you and never included in your reports.
4.Legal Basis for Processing (GDPR Art. 6)
We rely on the following legal bases:
- Consent (Art. 6(1)(a)) — for processing your wellness data and, separately and optionally, for research use. You may withdraw consent at any time.
- Performance of a contract (Art. 6(1)(b)) — to deliver the Service you sign up for, including accounts, scans, and billing.
- Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent fraud and abuse, and maintain service quality, balanced against your rights.
Where we process data revealing health information, we do so on the basis of your explicit consent or as otherwise permitted under Article 9 GDPR.
5.How We Use Your Data
- To provide wellness insights from your check-ins;
- To detect trends over time across your own readings;
- To improve the quality and reliability of the Service;
- To generate anonymised, aggregate statistics — only where you have given explicit, separate consent;
- To secure the Service, verify accounts, prevent fraud, and comply with law;
- To communicate with you about your account, billing, and important changes.
We do not use your data for advertising and we do not sell it.
AI-generated Personal Insight (premium)
Personal Insight is an optional premium feature that turns your wellness history into a short, plain-language narrative. To generate it, we send a de-identified, qualitative summary of your check-ins to Anthropic (the maker of the Claude AI models), acting as our subprocessor. This summary contains no name, email, phone number, or account identifier, and no raw measurements — only qualitative descriptions (for example, "your resting pulse has been easing down across recent check-ins"). Anthropic processes this input solely to return the generated text to us under contract; the result is shown only to you.
6.Data Retention
- Account data is retained while your account is active and for up to 30 days after deletion, after which it is erased.
- Scan data is retained for longitudinal (over-time) tracking while your account is active.
- Following an account-deletion request, all of your data is deleted within 30 days, except where we are legally required to retain limited records (e.g. for tax or fraud-prevention obligations), which are kept only as long as the law requires.
7.Data Sharing, Disclosure & Subprocessors
We do not sell your personal data. We share it only with the service providers ("subprocessors") that make the Service work, and only as needed, in the limited cases below:
| Recipient | What is shared & why |
|---|---|
| RunPod (cloud hosting & compute) | Hosts our servers and runs the wellness processing. Data is processed on infrastructure located in the EU (Czech Republic). |
| Cloudflare (CDN & secure tunnel) | Delivers the site and routes traffic to our servers over an encrypted tunnel. Handles data in transit only. |
| Twilio (SMS verification) | Sends and checks the one-time code used to verify your phone number. |
| PayPal (payment processor) | Processes your subscription or per-scan purchase and handles all card details. We never receive your full card data. |
| Anthropic (AI Personal Insight) | Generates the optional premium Personal Insight narrative from a de-identified, qualitative summary of your wellness history. Receives no identifying data. |
| Law enforcement / authorities | Only when required by a valid legal order or to comply with applicable law. |
All subprocessors are bound by data-protection agreements that restrict their use of your data to providing services to us.
7A.Integrations You Connect
This is different from the subprocessors above, and the difference matters. Every recipient in Section 7 is a supplier we chose and we bound by a data-protection agreement, working on our instructions. An integration you connect is the opposite: you choose it, you start the data flow, and we have no contract with it and no control over what it does next.
You can create an API key from your account and give it to software you choose — your own, or an external platform. While that key is active, the platform holding it can read from your account the categories of data you allowed, which may include:
- check-in results (heart rate, breathing rate and the other wellness signals derived from a scan, and the written reflection that accompanies them);
- voice check-in results (the vocal qualities we measure — never a recording, which is deleted as described in Section 2);
- guided breathing and recovery session results;
- activities and daily journal entries you have logged, and the self-relative patterns derived from them;
- your trends, timeline and readiness score.
What you control. When you create a key you choose which of those capability groups it may use, and a request outside them is refused. You can see your keys and revoke any of them at any time from your account; revocation takes effect immediately, on the next request. A key only ever reaches your own account — it cannot read anyone else's data.
What we record. For each API request we log the endpoint, method, response status and timing, so you can see your own usage and so we can investigate abuse. We do not log request or response bodies. This log is deleted with your account like the rest of your data.
What you are responsible for. Please review a platform's own privacy policy and security practices before connecting it — once data reaches it, that platform decides what happens next, and it becomes the controller of the copy it holds. Revoking a key, or deleting your checkup.report account, stops future access but cannot retrieve data an integration already received: our erasure obligations under Section 10 cover our systems, not copies elsewhere. To have those copies deleted, contact the platform directly.
8.Research Data & Consent
We use data for research only with your explicit, separate consent, which is off by default. If you opt in:
- Your data is de-identified in line with the HIPAA Safe Harbor standard, removing the 18 categories of identifiers (such as name, contact details, dates, and device identifiers);
- Research data is used to better understand wellness patterns and improve our methods;
- You may withdraw your research consent at any time from your account settings or by emailing [email protected]. Withdrawal stops future research use; data already irreversibly de-identified may not be retrievable, but no further identifiable data will be used.
9.International Transfers
Your account and wellness data are hosted in the European Union (Czech Republic). Some of our subprocessors — including Anthropic, Twilio, PayPal, and Cloudflare — are based in the United States, so certain limited data is transferred there to provide those functions. For any transfer outside the EU/EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), to ensure your data continues to be protected to EU standards. You may request a copy of the relevant safeguards by contacting our DPO.
10.Your GDPR Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain circumstances;
- Portability — receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interests;
- Withdraw consent at any time, without affecting prior lawful processing.
You can exercise these rights from your account settings or by emailing [email protected]. You also have the right to lodge a complaint with your local supervisory authority (in the EU) or the Israeli Privacy Protection Authority.
11.Israeli Privacy Protection Law
Under the Israeli Privacy Protection Law, 5741-1981, our database is operated and, where required, registered in accordance with the Law. You have the right to access the information held about you and to request its correction or deletion. To exercise these rights, contact [email protected].
12.Children
The Service is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it promptly.
13.Cookies
We use minimal cookies, limited to session management needed to keep you signed in and to operate the Service securely. We do not use tracking cookies, and we do not use advertising cookies or third-party ad networks.
14.Security Measures
- Encryption in transit — all traffic is encrypted using TLS 1.2+ (TLS 1.3 preferred); access to stored data, including any eye images, is restricted to a strict need-to-know basis;
- Access controls limiting who can access personal data on a need-to-know basis;
- Regular security reviews and hardening of our systems.
No method of transmission or storage is perfectly secure, but we work to protect your data using appropriate technical and organisational measures.
15.Breach Notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, in line with GDPR, and will inform affected users without undue delay where required.
16.Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide at least 30 days' notice by email and/or within the Service. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17.Contact & DPO
For any question about this Policy or your data, contact our Data Protection Officer:
Israel · EU processing: EU-CZ-1 (Czech Republic)
Email: [email protected]
General support: [email protected]
מדיניות פרטיות
1.מי אנחנו (בעל מאגר המידע)
בעל מאגר המידע האחראי למידע האישי שלכם הוא health.systems, מותג המופעל על ידי Enterprise.Systems, חברה המאוגדת לפי דיני מדינת ישראל ("אנחנו", "אנו" או "החברה").
בכל עניין הנוגע לפרטיות, לרבות מימוש זכויותיכם, תוכלו לפנות לממונה על הגנת הפרטיות (DPO) שלנו:
2.המידע שאנו אוספים
אנו אוספים רק את הנדרש להפעלת השירות. הטבלה שלהלן מסכמת את סוגי המידע האישי שאנו מעבדים.
| סוג | פרטים |
|---|---|
| כתובת דוא"ל | ליצירת החשבון, לזיהויו וליצירת קשר עמכם. |
| מספר טלפון | נאסף ומאומת באמצעות קוד חד-פעמי ב-SMS (דרך Twilio). המספר המאומת נשמר לצורך אבטחת החשבון, אכיפת חשבון אחד לאדם ומניעת ניצול לרעה של הבדיקה החינמית. הוא נמחק כאשר אתם מוחקים את חשבונכם. |
| טביעת אצבע של המכשיר | מזהה טכני המשמש לאבטחת החשבון ולמניעת ניצול לרעה של הבדיקה החינמית. |
| וידאו פנים מהמצלמה | מעובד בזמן אמת לגזירת אות צבע (rPPG); פריימים גולמיים אינם נשמרים ונמחקים לאחר העיבוד. |
| מדדי רווחה ותצפיות | ערכים נגזרים כגון דופק (HR), קצב נשימה (RR), שונות קצב הלב (HRV) ומדד מתח, יחד עם אותות רווחה איכותניים של הפנים ותצפיות על צבע העין. אלה אותות רווחה בלבד — לא אבחנה. |
| תמונות עין (לחמית) | תמונות תקריב של לובן העין, הנלכדות במהלך בדיקה. נשמרות בתשתית שלנו עם גישה מוגבלת ומושוות רק לתמונה הקודמת שלכם עצמכם כדי להבחין בשינוי לאורך זמן. תוכלו למחוק תמונות אלה בכל עת (ראו זכויותיכם לפי GDPR). |
| הקלטות קול (בדיקת קול — אופציונלית) | רק בהסכמה נפרדת ומפורשת (opt-in), קטע קול של כ-12 שניות מנותח עבור תכונות הצליל שלו (אנרגיה, קצב ויציבות גובה הצליל). ההקלטה נמחקת מיד לאחר מדידת תכונות הצליל — בשרתים שלנו היא אינה שורדת את הבקשה שעיבדה אותה. אנחנו לעולם לא שומרים את הקול שלכם, לעולם לא יוצרים תמלול ולעולם לא מנתחים את תוכן הדברים. נשמרים רק ערכים מספריים נגזרים, המושווים אך ורק לבדיקות הקודמות שלכם עצמכם; אלה השתקפויות רווחה של איך הקול נשמע — לעולם לא הערכה של מצב הרוח או המצב הנפשי, ולעולם לא אבחנה. ניתן למשוך את ההסכמה בכל עת בחשבון, והערכים הנגזרים נמחקים יחד עם שאר המידע שלכם (ראו זכויותיכם לפי GDPR). |
| חותמות זמן של בדיקות | התאריך והשעה של כל בדיקה, לבניית ציר הזמן של המגמות שלכם. |
| הגדרות תזכורת ומינוי התראות (אופציונלי) | אם תפעילו את תזכורת הבוקר (כבויה כברירת מחדל), נשמור את שעת התזכורת שבחרתם, היסט אזור הזמן והשפה, ובמקום שבו גם אישרתם הרשאת התראות בדפדפן — את מינוי ההתראות של הדפדפן (כתובת שירות ההתראות ומפתחות ההצפנה שלו). אלה מזהים את הדפדפן לצורך מסירה בלבד; אינם נושאים תוכן הודעות, משמשים לכל היותר לתזכורת אחת ביום ולסיכום שבועי אופציונלי, ונמחקים כשתכבו את התזכורות, תבטלו את המינוי או תמחקו את המידע. |
| תוצאות תרגולים מודרכים (נשימה / התאוששות) | כשאתם משלימים תרגול מודרך בן שתי קריאות, אנו שומרים את סוג התרגול, חותמות הזמן שלו ואת ערכי הלפני-ואחרי (השינוי שלכם בדופק ובקצב הנשימה בתוך אותו תרגול). אלה השתקפויות רווחה של איך הגוף נרגע — לא ציון כושר ולא מדידה רפואית — ונמחקים יחד עם שאר המידע שלכם. |
| נתוני הפניה | אם אתם משתמשים בקוד הפניה או משתפים אותו, אנו רושמים את הקוד, ובמקום שבו הופניתם על ידי מישהו — קישור לחשבון המפנה. משמש רק להענקת זיכויים לבדיקות חינם — איננו אוספים מידע אחר על מי שהפנה אתכם. |
| מצב מנוי ותשלום | סוג התוכנית שלכם, מועדי המנוי ויתרת זיכויי הבדיקות. פרטי כרטיס התשלום המלאים מוזנים ומוחזקים אצל PayPal ואינם נשמרים אצלנו לעולם. |
| כתובת IP | נאספת לצורכי אבטחה ומניעת ניצול לרעה; עוברת אנונימיזציה. |
| פרטי דפדפן / מכשיר | פרטים טכניים בסיסיים (סוג מכשיר, מערכת הפעלה, גרסת יישום) לאספקת השירות ולפתרון תקלות. |
בדיקה לפני אימות
תוכלו לבצע את הבדיקה הראשונה לפני אימות מספר הטלפון. הנתונים מאותה בדיקה — מדדי הרווחה, חותמת הזמן וכל תמונת עין — נשמרים תחת החשבון והמכשיר שבהם השתמשתם ונותרים משויכים אליהם. אימות הטלפון לאחר מכן רק מאשר את החשבון שכבר מחזיק בנתונים אלה; הם אינם נאספים מחדש או מועברים. כדי להמשיך מעבר לבדיקה הראשונה, נדרש אימות טלפון.
3.מה איננו אוספים
- איננו מבצעים זיהוי ביומטרי.
- איננו מבצעים זיהוי פנים.
- איננו אוספים או מפיקים מידע אבחנתי רפואי — checkup.report הוא מוצר רווחה, לא מוצר אבחוני.
- רוויון חמצן בדם (SpO₂) נמדד רק לצורכי מחקר ואימות פנימיים; הוא לעולם אינו מוצג לכם ואינו נכלל בדוחות שלכם.
4.הבסיס החוקי לעיבוד (GDPR סעיף 6)
אנו מסתמכים על הבסיסים החוקיים הבאים:
- הסכמה (סעיף 6(1)(a)) — לעיבוד נתוני הרווחה שלכם, ובנפרד ובאופן רשות, לשימוש מחקרי. ניתן לחזור מההסכמה בכל עת.
- ביצוע חוזה (סעיף 6(1)(b)) — לאספקת השירות שאליו נרשמתם, לרבות חשבונות, בדיקות וחיוב.
- אינטרסים לגיטימיים (סעיף 6(1)(f)) — לשמירת אבטחת השירות, מניעת הונאה וניצול לרעה ושמירה על איכות השירות, באיזון מול זכויותיכם.
במקום שבו אנו מעבדים מידע החושף פרטי בריאות, אנו עושים זאת על בסיס הסכמה מפורשת שלכם או כמותר אחרת לפי סעיף 9 ל-GDPR.
5.כיצד אנו משתמשים במידע
- כדי לספק תובנות רווחה מהבדיקות שלכם;
- כדי לזהות מגמות לאורך זמן בקריאות שלכם;
- כדי לשפר את האיכות והאמינות של השירות;
- כדי להפיק סטטיסטיקות מצרפיות ואנונימיות — רק אם נתתם הסכמה מפורשת ונפרדת;
- כדי לאבטח את השירות, לאמת חשבונות, למנוע הונאה ולעמוד בדין;
- כדי לתקשר עמכם בנוגע לחשבונכם, לחיוב ולשינויים חשובים.
איננו משתמשים במידע שלכם לפרסום ואיננו מוכרים אותו.
תובנה אישית שנוצרת על ידי AI (פרימיום)
תובנה אישית היא תכונת פרימיום אופציונלית ההופכת את היסטוריית הרווחה שלכם לנרטיב קצר בשפה פשוטה. כדי להפיקה, אנו שולחים סיכום איכותני ונטול-זיהוי של הבדיקות שלכם אל Anthropic (יצרנית מודלי ה-AI מסוג Claude), הפועלת כמעבד-משנה מטעמנו. סיכום זה אינו כולל שם, דוא"ל, מספר טלפון או מזהה חשבון, ואינו כולל מדידות גולמיות — אלא רק תיאורים איכותניים (למשל, "הדופק במנוחה שלכם נמצא במגמת ירידה לאורך הבדיקות האחרונות"). Anthropic מעבדת קלט זה אך ורק כדי להחזיר לנו את הטקסט שנוצר, על פי חוזה; התוצאה מוצגת לכם בלבד.
6.שמירת מידע
- נתוני חשבון נשמרים כל עוד החשבון פעיל ועד 30 יום לאחר המחיקה, ולאחר מכן נמחקים.
- נתוני בדיקות נשמרים למעקב לאורך זמן כל עוד החשבון פעיל.
- לאחר בקשת מחיקת חשבון, כל הנתונים שלכם נמחקים בתוך 30 יום, למעט במקום שבו אנו נדרשים בדין לשמור רישומים מוגבלים (למשל לצורכי מס או מניעת הונאה), הנשמרים רק למשך הזמן שהדין מחייב.
7.שיתוף מידע, גילוי ומעבדי-משנה
אנו איננו מוכרים את המידע האישי שלכם. אנו משתפים אותו רק עם ספקי השירות ("מעבדי המשנה") המאפשרים את פעולת השירות, ורק ככל הנדרש, במקרים המוגבלים שלהלן:
| נמען | מה משותף ומדוע |
|---|---|
| RunPod (אחסון ומחשוב בענן) | מארח את השרתים שלנו ומריץ את עיבוד הרווחה. המידע מעובד בתשתית הממוקמת באיחוד האירופי (צ'כיה). |
| Cloudflare (CDN ומנהרה מאובטחת) | מספק את האתר ומנתב תעבורה לשרתים שלנו דרך מנהרה מוצפנת. מטפל במידע במעבר בלבד. |
| Twilio (אימות SMS) | שולח ובודק את הקוד החד-פעמי המשמש לאימות מספר הטלפון שלכם. |
| PayPal (מעבד תשלומים) | מעבד את המנוי או הרכישה לפי בדיקה ומטפל בכל פרטי הכרטיס. איננו מקבלים לעולם את פרטי הכרטיס המלאים שלכם. |
| Anthropic (תובנה אישית מבוססת AI) | מפיקה את נרטיב התובנה האישית האופציונלי (פרימיום) מתוך סיכום איכותני ונטול-זיהוי של היסטוריית הרווחה שלכם. אינה מקבלת מידע מזהה. |
| רשויות אכיפת חוק | רק כאשר נדרש לפי צו חוקי תקף או לצורך עמידה בדין. |
כל מעבדי המשנה כפופים להסכמי הגנת מידע המגבילים את השימוש שלהם במידע שלכם לאספקת שירותים עבורנו בלבד.
7A.אינטגרציות שאתם מחברים
זהו מצב שונה ממעבדי המשנה שלמעלה, וההבדל מהותי. כל נמען בסעיף 7 הוא ספק שאנחנו בחרנו ואנחנו כבלנו בהסכם הגנת מידע, הפועל לפי הוראותינו. אינטגרציה שאתם מחברים היא ההפך: אתם בוחרים אותה, אתם מתחילים את זרימת המידע, ולנו אין איתה חוזה ואין שליטה על מה שהיא עושה בהמשך.
תוכלו ליצור מהחשבון שלכם מפתח API ולמסור אותו לתוכנה שאתם בוחרים — שלכם או של פלטפורמה חיצונית. כל עוד המפתח פעיל, הפלטפורמה שמחזיקה בו יכולה לקרוא מהחשבון שלכם את קטגוריות המידע שהתרתם, ואלה עשויות לכלול:
- תוצאות בדיקות (דופק, קצב נשימה ושאר אותות הרווחה הנגזרים מסריקה, וההשתקפות המילולית הנלווית להם);
- תוצאות בדיקות קול (מאפייני הקול שאנו מודדים — לעולם לא הקלטה, שנמחקת כמתואר בסעיף 2);
- תוצאות תרגולי נשימה מודרכת והתאוששות;
- פעילויות ורישומי יומן יומיים שתיעדתם, והדפוסים היחסיים-לעצמכם הנגזרים מהם;
- המגמות, ציר הזמן וציון המוכנות שלכם.
מה בשליטתכם. ביצירת מפתח אתם בוחרים אילו מקבוצות היכולות הללו הוא רשאי להשתמש, ובקשה מחוץ להן נדחית. תוכלו לראות את המפתחות שלכם ולבטל כל אחד מהם בכל עת מהחשבון; הביטול נכנס לתוקף מיידית, כבר בבקשה הבאה. מפתח מגיע אך ורק לחשבון שלכם — הוא אינו יכול לקרוא מידע של אף אחד אחר.
מה אנחנו מתעדים. לכל בקשת API אנו רושמים את הנתיב, השיטה, סטטוס התגובה והתזמון — כדי שתוכלו לראות את השימוש שלכם וכדי שנוכל לחקור שימוש לרעה. איננו רושמים את גוף הבקשה או התגובה. רישום זה נמחק יחד עם חשבונכם כמו שאר המידע שלכם.
מה באחריותכם. בדקו את מדיניות הפרטיות ונהלי האבטחה של הפלטפורמה לפני החיבור — ברגע שהמידע מגיע אליה, היא זו שקובעת מה קורה הלאה, והיא הופכת לבעלת השליטה בעותק שברשותה. ביטול מפתח, או מחיקת חשבון checkup.report שלכם, עוצרים גישה עתידית אך אינם יכולים להשיב מידע שאינטגרציה כבר קיבלה: חובות המחיקה שלנו לפי סעיף 10 חלות על המערכות שלנו, לא על עותקים במקומות אחרים. למחיקת עותקים אלה יש לפנות ישירות לאותה פלטפורמה.
8.מידע למחקר והסכמה
אנו משתמשים במידע למחקר רק בהסכמה מפורשת ונפרדת שלכם, אשר כבויה כברירת מחדל. אם תבחרו להצטרף:
- המידע שלכם עובר הסרת זיהוי (de-identification) בהתאם לתקן HIPAA Safe Harbor, תוך הסרת 18 קטגוריות של מזהים (כגון שם, פרטי קשר, תאריכים ומזהי מכשיר);
- נתוני המחקר משמשים להבנה טובה יותר של דפוסי רווחה ולשיפור שיטותינו;
- תוכלו לחזור מהסכמת המחקר בכל עת מהגדרות החשבון או בדוא"ל אל [email protected]. החזרה עוצרת שימוש מחקרי עתידי; מידע שכבר עבר הסרת זיהוי בלתי הפיכה עשוי שלא להיות ניתן לאחזור, אך לא ייעשה שימוש נוסף במידע מזהה.
9.העברות בין-לאומיות
נתוני החשבון והרווחה שלכם מאוחסנים באיחוד האירופי (צ'כיה). חלק ממעבדי המשנה שלנו — לרבות Anthropic, Twilio, PayPal ו-Cloudflare — מבוססים בארצות הברית, ולכן מידע מוגבל מסוים מועבר לשם לצורך אספקת פונקציות אלה. לכל העברה אל מחוץ לאיחוד האירופי / האזור הכלכלי האירופי אנו מסתמכים על אמצעי הגנה מתאימים, לרבות סעיפי החוזה הסטנדרטיים (SCCs) של הנציבות האירופית, כדי להבטיח שהמידע שלכם ימשיך להיות מוגן לפי תקני האיחוד האירופי. תוכלו לבקש עותק של אמצעי ההגנה הרלוונטיים בפנייה ל-DPO שלנו.
10.זכויותיכם לפי GDPR
בכפוף לדין החל, יש לכם זכות:
- עיון במידע האישי שאנו מחזיקים עליכם;
- תיקון מידע שגוי או חסר;
- מחיקה של המידע שלכם ("הזכות להישכח");
- הגבלת העיבוד בנסיבות מסוימות;
- ניידות — קבלת המידע שלכם בפורמט מובנה וקריא במכונה;
- התנגדות לעיבוד המבוסס על אינטרסים לגיטימיים;
- חזרה מהסכמה בכל עת, מבלי לפגוע בעיבוד חוקי שקדם לכך.
תוכלו לממש זכויות אלה מהגדרות החשבון או בדוא"ל אל [email protected]. כמו כן עומדת לכם הזכות להגיש תלונה לרשות הפיקוח המקומית שלכם (באיחוד האירופי) או לרשות להגנת הפרטיות בישראל.
11.חוק הגנת הפרטיות
לפי חוק הגנת הפרטיות, התשמ"א-1981, מאגר המידע שלנו מנוהל, וככל שנדרש רשום, בהתאם לחוק. עומדת לכם הזכות לעיין במידע המוחזק עליכם ולבקש את תיקונו או מחיקתו. למימוש זכויות אלה, פנו אל [email protected].
12.ילדים
השירות אינו מיועד למי שמתחת לגיל 18. איננו אוספים ביודעין מידע אישי מילדים. אם אתם סבורים שילד מסר לנו מידע אישי, פנו אל [email protected] ונמחק אותו ללא דיחוי.
13.עוגיות
אנו משתמשים בעוגיות מינימליות, המוגבלות לניהול הפעלה (session) הנדרש כדי לשמור אתכם מחוברים ולהפעיל את השירות באופן מאובטח. איננו משתמשים בעוגיות מעקב, ואיננו משתמשים בעוגיות פרסום או ברשתות פרסום של צד שלישי.
14.אמצעי אבטחה
- הצפנה במעבר — כל התעבורה מוצפנת באמצעות TLS 1.2+ (עדיפות ל-TLS 1.3); הגישה למידע המאוחסן, לרבות תמונות עין כלשהן, מוגבלת לבסיס של צורך-לדעת קפדני;
- בקרות גישה המגבילות מי יכול לגשת למידע אישי על בסיס צורך לדעת;
- סקירות אבטחה תקופתיות והקשחת המערכות שלנו.
שום שיטת העברה או אחסון אינה מאובטחת באופן מושלם, אך אנו פועלים להגן על המידע שלכם באמצעים טכניים וארגוניים מתאימים.
15.הודעה על אירוע אבטחה
אם יתרחש אירוע אבטחת מידע אישי העלול להוביל לסיכון לזכויותיכם ולחירויותיכם, נודיע לרשות הפיקוח המוסמכת בתוך 72 שעות ממועד היוודע לנו על כך, בהתאם ל-GDPR, ונודיע למשתמשים המושפעים ללא דיחוי בלתי סביר במקום שבו הדבר נדרש.
16.שינויים במדיניות
אנו רשאים לעדכן מדיניות זו מעת לעת. אם נבצע שינויים מהותיים, נספק הודעה מראש של 30 יום לפחות בדוא"ל ו/או בתוך השירות. המשך השימוש בשירות לאחר מועד התחילה מהווה הסכמה למדיניות המעודכנת.
17.יצירת קשר ו-DPO
לכל שאלה בנוגע למדיניות זו או למידע שלכם, פנו לממונה הגנת הפרטיות שלנו:
ישראל · עיבוד באיחוד האירופי: EU-CZ-1 (צ'כיה)
דוא"ל: [email protected]
תמיכה כללית: [email protected]