1. Scope and roles
This policy applies to PulseBerry, its Fireberry add-on, Make application, API, and other Optimator applications expressly linking to this policy (the “Services”). It does not replace Fireberry’s, Make’s, or a customer’s own privacy policy.
The business that installs or connects a Service (the “Customer”) generally determines why and how personal information in its CRM is processed and is responsible for that data. Optimator processes Customer-provided data to deliver the Services and may act as a service provider or processor on the Customer’s instructions. Optimator is independently responsible for account, billing, security, support, and legal-compliance information it controls.
2. Information processed
Depending on the Service and configuration, we may process:
- Fireberry organization identifiers and internal Optimator account identifiers.
- Fireberry user identifiers, user names, first-seen and last-seen timestamps.
- License and subscription information, including license level, invoice name, plan, status, seat counts, quotas, and daily usage totals.
- API credential metadata, including a one-way SHA-256 hash, token prefix, issue, rotation, and last-use timestamps. We do not intentionally retain the raw organization token in the PulseBerry API database.
- Action and command data, including object type, record identifier, target user identifier, action type, notification text and display settings, version, status, and timestamps.
- Session, request, security, error, and audit information, such as session identifiers, IP address and device or browser data available in server logs, administrative actions, and diagnostic details.
- Support and business correspondence you choose to send us.
PulseBerry does not need a copy of an entire CRM record merely to deliver a refresh or notification command. However, record identifiers, user identifiers, and notification text can be personal information. Do not place passwords, API keys, medical information, payment-card data, government identifiers, or other sensitive information in notification text or support messages.
3. How information is obtained
Information is received from the Customer or its authorized users, from Fireberry’s application environment and APIs, from Make scenarios or direct API calls initiated by the Customer, and automatically from use of the Services. The Customer is responsible for providing legally required notices and obtaining any authorization, consent, or other lawful basis needed for information it submits.
4. Purposes and legal bases
- Provide, authenticate, isolate, operate, maintain, and support the Services.
- Route refresh and notification actions to the intended organization, record, or user.
- Apply plans, quotas, rate limits, licensing, and billing arrangements.
- Secure the Services, prevent fraud and abuse, troubleshoot errors, and investigate incidents.
- Communicate about support, operational changes, security, and the Customer relationship.
- Meet legal obligations and establish, exercise, or defend legal claims.
- Improve reliability and features using aggregated or de-identified information where practical.
These activities are based, as applicable, on performance of our agreement, our legitimate interests in operating and protecting a business service, compliance with law, and consent where the law requires it. We do not sell personal information and do not use Customer CRM data for third-party advertising.
5. Sharing and subprocessors
We may disclose information only as reasonably necessary to hosting, infrastructure, email, security, monitoring, support, and professional-service providers; to Fireberry, Make, or another integration selected by the Customer; during a corporate transaction subject to appropriate confidentiality; or where law, a competent authority, or protection of rights and safety requires it.
Third-party platforms operate under their own terms and privacy practices. Data may be processed outside Israel where a provider or integration operates. Where applicable, we use contractual or other legally recognized measures for international transfers. Customers should contact us before using the Services if they require a specific data-location or processing agreement.
6. Retention
PulseBerry’s operational sessions are short-lived, and refresh, notification, and action commands ordinarily expire after approximately ten minutes; deployment configuration may vary. Expired operational records are periodically removed. Account, user, license, usage, support, security, and administrative audit information may be retained while an account is active and afterward for a reasonable period needed for continuity, security, legal compliance, accounting, dispute resolution, and enforcement.
Deletion from active systems may not immediately remove information from backups or mandatory security records, which are deleted or overwritten on controlled schedules or retained as required by law. Aggregated or irreversibly de-identified data may be retained longer.
7. Security
We use measures designed for the nature of the Service, including encrypted transport, organization-level isolation, access restrictions, credential hashing, token rotation, short command lifetimes, rate limits, logging, and maintenance procedures. Customers must protect their Fireberry and Make accounts and treat the PulseBerry organization token like a password. A compromised token should be rotated immediately.
No system is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur. If we identify a security incident, we will investigate and notify affected Customers or authorities when required by applicable law and our role in the processing.
8. Customer instructions and rights
Users may have rights to inspect, correct, delete, or restrict certain personal information under applicable law. Where information is controlled by a Customer, requests should first be directed to that Customer. We will reasonably assist the Customer with verified requests as required by law and the applicable agreement.
Requests concerning information controlled directly by Optimator may be sent below. We may verify identity and authority, ask for the relevant organization identifier, and retain information where law or legitimate legal claims require it.
9. Customer responsibilities
The Customer must configure and use the Services lawfully, limit access to authorized personnel, maintain accurate user permissions, avoid unnecessary or sensitive data in commands, and comply with applicable privacy, employment, direct-marketing, database, and information-security duties. Optimator does not determine whether a Customer’s automation or message is lawful.
10. Business service and minors
The Services are designed for organizations and professional users, not consumers or children. Customers must not knowingly use the Services to process children’s information unless they are legally authorized and have agreed suitable safeguards with Optimator in advance.
11. Changes and contact
We may update this policy to reflect product, provider, security, or legal changes. The updated version applies from the date shown above, subject to any notice required by law or agreement. Material changes will be communicated through the Service, website, or Customer contact details where appropriate.
Questions, processor terms, and security reports may be sent to support@optimator.co.il. Please do not include credentials or sensitive CRM records in email.
1. תחולה ותפקידים
מדיניות זו חלה על PulseBerry, התוסף שלה ל-Fireberry, אפליקציית Make, ה-API ואפליקציות נוספות של Optimator שמפנות במפורש למדיניות זו (להלן: “השירותים”). היא אינה מחליפה את מדיניות הפרטיות של Fireberry, של Make או של הלקוח.
העסק שמתקין או מחבר שירות (להלן: “הלקוח”) קובע בדרך כלל מדוע וכיצד יעובד מידע אישי במערכת ה-CRM שלו ואחראי למידע זה. Optimator מעבדת מידע שהלקוח מוסר לצורך אספקת השירותים ועשויה לפעול כספק שירות או כמחזיק/מעבד בהתאם להוראות הלקוח. Optimator אחראית בנפרד למידע שהיא מנהלת לצורכי חשבון, חיוב, אבטחה, תמיכה ועמידה בדין.
2. המידע המעובד
בהתאם לשירות ולהגדרותיו, אנו עשויים לעבד:
- מזהה ארגון ב-Fireberry ומזהי חשבון פנימיים של Optimator.
- מזהי משתמשי Fireberry, שמות משתמשים ומועדי שימוש ראשון ואחרון.
- מידע על רישיון ומינוי, לרבות רמת רישיון, שם לחשבונית, מסלול, סטטוס, מספר מושבים, מכסות וסיכומי שימוש יומיים.
- מטא-נתונים של אישורי API, לרבות גיבוב חד-כיווני מסוג SHA-256, תחילית הטוקן ומועדי יצירה, החלפה ושימוש אחרון. איננו שומרים ביודעין את הטוקן הארגוני הגולמי במסד הנתונים של API PulseBerry.
- נתוני פעולות ופקודות, לרבות סוג אובייקט, מזהה רשומה, מזהה משתמש יעד, סוג פעולה, תוכן הודעה והגדרות תצוגה, גרסה, סטטוס וחותמות זמן.
- מידע על סשנים, בקשות, אבטחה, שגיאות ובקרה, כגון מזהי סשן, כתובת IP ונתוני מכשיר או דפדפן הזמינים בלוגים, פעולות מנהל ופרטי אבחון.
- פניות תמיכה ותכתובת עסקית שתבחרו לשלוח.
PulseBerry אינה זקוקה לעותק מלא של רשומת CRM רק כדי למסור פקודת רענון או הודעה. עם זאת, מזהי רשומות, מזהי משתמשים ותוכן הודעות עשויים להיחשב מידע אישי. אין לכלול בתוכן הודעה או בפניית תמיכה סיסמאות, מפתחות API, מידע רפואי, נתוני כרטיסי תשלום, מזהים ממשלתיים או מידע רגיש אחר.
3. מקורות המידע
המידע מתקבל מהלקוח או ממשתמשיו המורשים, מסביבת האפליקציות וממשקי ה-API של Fireberry, מתרחישי Make או מקריאות API ישירות שהלקוח יוזם, וכן באופן אוטומטי בעת השימוש בשירותים. הלקוח אחראי למסירת ההודעות הנדרשות בדין ולקבלת הרשאה, הסכמה או בסיס חוקי אחר למידע שהוא מעביר.
4. מטרות ובסיסי העיבוד
- אספקה, אימות, בידוד, הפעלה, תחזוקה ותמיכה בשירותים.
- ניתוב פעולות רענון והודעות לארגון, לרשומה או למשתמש המיועדים.
- יישום מסלולים, מכסות, הגבלות קצב, רישיונות וחיובים.
- אבטחת השירותים, מניעת הונאה ושימוש לרעה, פתרון תקלות ובדיקת אירועים.
- תקשורת בנושאי תמיכה, שינויים תפעוליים, אבטחה והקשר עם הלקוח.
- עמידה בחובות חוקיות וביסוס, מימוש או הגנה על טענות משפטיות.
- שיפור אמינות ותכונות באמצעות מידע מצרפי או מותמם, ככל שניתן.
העיבוד מבוסס, לפי העניין, על ביצוע ההסכם, אינטרסים לגיטימיים בהפעלת שירות עסקי ובהגנתו, עמידה בדין והסכמה כאשר היא נדרשת. איננו מוכרים מידע אישי ואיננו משתמשים בנתוני CRM של לקוחות לצורך פרסום של צדדים שלישיים.
5. מסירת מידע וספקי משנה
אנו עשויים למסור מידע רק ככל שנדרש באופן סביר לספקי אחסון, תשתית, דוא"ל, אבטחה, ניטור, תמיכה ושירותים מקצועיים; ל-Fireberry, ל-Make או לאינטגרציה אחרת שבחר הלקוח; במסגרת עסקה תאגידית הכפופה לסודיות מתאימה; או כאשר הדבר נדרש בדין, על ידי רשות מוסמכת או לצורך הגנה על זכויות ובטיחות.
פלטפורמות צד שלישי פועלות לפי התנאים ומדיניות הפרטיות שלהן. מידע עשוי להיות מעובד מחוץ לישראל במקום שבו ספק או אינטגרציה פועלים. כאשר נדרש, אנו משתמשים באמצעים חוזיים או אמצעים מוכרים אחרים להעברה בינלאומית. לקוח שדורש מיקום מידע מסוים או הסכם עיבוד מידע צריך לפנות אלינו לפני השימוש.
6. תקופת שמירה
סשנים תפעוליים של PulseBerry הם קצרי-חיים, ופקודות רענון, הודעה ופעולה פגות בדרך כלל לאחר כעשר דקות; הגדרות הפריסה עשויות להשתנות. רשומות תפעוליות שפג תוקפן נמחקות מעת לעת. מידע על חשבון, משתמשים, רישיון, שימוש, תמיכה, אבטחה ובקרת מנהל עשוי להישמר כל עוד החשבון פעיל ולאחר מכן לתקופה סבירה הנדרשת להמשכיות, אבטחה, עמידה בדין, הנהלת חשבונות, יישוב מחלוקות ואכיפה.
מחיקה ממערכות פעילות אינה מסירה בהכרח מידע באופן מיידי מגיבויים או מרשומות אבטחה שחובה לשמור. אלה נמחקים או נדרסים במחזורים מבוקרים או נשמרים כנדרש בדין. מידע מצרפי או מידע שעבר התממה בלתי הפיכה עשוי להישמר לזמן ארוך יותר.
7. אבטחת מידע
אנו משתמשים באמצעים המותאמים לאופי השירות, ובהם הצפנת תעבורה, בידוד ברמת הארגון, הגבלת גישה, גיבוב אישורים, החלפת טוקנים, חיי פקודה קצרים, הגבלת קצב, לוגים ונהלי תחזוקה. על הלקוחות להגן על חשבונות Fireberry ו-Make ולהתייחס לטוקן הארגוני של PulseBerry כסיסמה. יש להחליף טוקן שנחשף באופן מיידי.
אין מערכת מאובטחת לחלוטין. איננו יכולים להבטיח שגישה בלתי מורשית, אובדן או שימוש לרעה לעולם לא יתרחשו. אם נזהה אירוע אבטחה, נבדוק אותו ונודיע ללקוחות שנפגעו או לרשויות כאשר הדבר נדרש לפי הדין החל ובהתאם לתפקידנו בעיבוד.
8. הוראות הלקוח וזכויות
למשתמשים עשויות לעמוד זכויות לעיין, לתקן, למחוק או להגביל מידע אישי מסוים לפי הדין החל. כאשר המידע נמצא בשליטת לקוח, יש להפנות את הבקשה תחילה אליו. נסייע באופן סביר ללקוח בבקשות מאומתות כנדרש בדין ובהסכם החל.
בקשות הנוגעות למידע שנמצא בשליטה ישירה של Optimator ניתן לשלוח להלן. אנו רשאים לאמת זהות והרשאה, לבקש את מזהה הארגון הרלוונטי ולשמור מידע כאשר הדין או טענות משפטיות לגיטימיות מחייבים זאת.
9. אחריות הלקוח
על הלקוח להגדיר את השירותים ולהשתמש בהם כדין, להגביל גישה למורשים, לנהל הרשאות משתמשים מדויקות, להימנע ממידע מיותר או רגיש בפקודות ולעמוד בחובות החלות עליו בנושאי פרטיות, עבודה, דיוור ישיר, מאגרי מידע ואבטחת מידע. Optimator אינה קובעת אם אוטומציה או הודעה של הלקוח היא חוקית.
10. שירות עסקי וקטינים
השירותים מיועדים לארגונים ולמשתמשים מקצועיים, ולא לצרכנים או לקטינים. אין להשתמש בשירותים ביודעין לעיבוד מידע על קטינים אלא אם הלקוח מוסמך לכך כדין וסיכם מראש עם Optimator אמצעי הגנה מתאימים.
11. שינויים ויצירת קשר
אנו רשאים לעדכן מדיניות זו בשל שינויים במוצר, בספקים, באבטחה או בדין. הגרסה המעודכנת תחול מהמועד המופיע לעיל, בכפוף להודעה שנדרשת בדין או בהסכם. שינוי מהותי יימסר דרך השירות, האתר או פרטי הקשר של הלקוח, לפי העניין.
שאלות, בקשות להסכם עיבוד מידע ודיווחי אבטחה ניתן לשלוח ל-support@optimator.co.il. אין לכלול בדוא"ל פרטי גישה או רשומות CRM רגישות.