AITermi respects your privacy. This policy explains what information is collected, how we use it, to whom it is transferred, and how you can exercise your rights.
Our two roles
It is important to distinguish between two types of information:
- Our information: details of visitors to the website, inquirers and customers of AITermi. With respect to this information we are the database owner, and this policy applies to it in full.
- Our customers' information: the customer and lead data that a business enters into its system. This information belongs to that business, which is the database owner, and we hold and process it solely on its behalf and in accordance with its instructions. We make no independent use of it, do not sell it and do not use it for marketing.
If you have reached this page as an end customer of a business that uses AITermi, any request concerning your information should be addressed to that business. We will assist it in handling the request.
What information is collected
- Details you provided in the contact form, when scheduling a meeting or when signing up: name, phone, email, business name.
- Account details and an encrypted password for system users.
- Website usage data — pages viewed, traffic source, clicks on links and buttons, starting and submitting forms, and scroll depth — through Google Analytics and Meta Pixel, only after your consent in the cookie notice. The tools identify the browser by means of cookies (an online identifier, which is personal information under the Privacy Protection Law, 5741-1981); they do not receive a name, phone number, email address or form content.
- Technical server logs: IP address, browser type and access times, for security and operational purposes.
- Data you entered into the CRM system, including your customers' details and correspondence with them.
Why we use it
To provide and operate the service, for support, for billing and issuing invoices, to secure the system, and to respond to inquiries. We will not use your information for any other purpose without your consent.
Where the information is stored
Our servers and databases are located on Google Cloud in the Israel region (me-west1). Each business has its own separate database, and there is no shared database that mixes data between customers. Communications are encrypted with SSL.
However, some of the third-party services that power certain features process information outside Israel. Details are in the next section.
Sub-processors
We use the following providers, each for a defined purpose and to the minimum extent necessary:
- Google Cloud: hosting of the servers and databases, in Israel.
- Google Analytics and Google Tag Manager (Google): measuring use of the website; Meta Pixel (Meta): measuring the results of advertising on Meta and building audiences for advertising. Both are loaded only after your consent, and the data is transferred to Google and Meta servers outside Israel on the basis of your consent (Privacy Protection (Transfer of Data Abroad) Regulations, 5761-2001, reg 2(1)). The list of cookies is in the "Cookies" section. Withdrawing consent: the "Cookie settings" link at the bottom of every page; withdrawal stops the loading and deletes the tools' cookies.
- Google Gemini: text processing for the AI agent. Content sent to the agent is processed by the provider outside Israel.
- Google Workspace: outgoing email and, upon a connection you initiate, also Calendar, Gmail and Search Console.
- Messaging providers: Green API for WhatsApp, and Meta for Messenger and Instagram, in accounts that you own.
- Morning (Green Invoice): issuing invoices and collecting payments.
- AWS Route53: DNS services for the system's addresses.
- Communication providers in integration projects: according to the project and in accounts in your name, as specified in the price quote.
This list is updated from time to time. A customer who wishes to receive advance notice of the addition of a sub-processor may request this in writing.
Disclosure of information to third parties
We do not sell information and do not transfer it to any party that is not required for operating the service, except where required by law or by an order of a competent authority.
Information security
- SSL traffic encryption, and passwords stored as a one-way hash.
- Full separation between customers: a separate database and a separate runtime environment for each business.
- Server access only through a secure tunnel, with minimal permissions.
- Ongoing security monitoring, blocking of intrusion attempts, and daily backup of the databases.
- Ongoing security updates to the infrastructure and software.
Information security incident
If a security incident concerning your information is discovered, we will notify you without delay and no later than 72 hours from the time of its discovery, set out what we know and what is being done, and assist you in reporting to the Privacy Protection Authority if required.
How long the information is retained
- Data of an active system: for as long as the engagement is in effect.
- Upon termination of the engagement: 14 days to download the data, followed by deletion from the servers. Existing backups are deleted in the regular backup cycle.
- Inquiries from prospects who did not become customers: up to 24 months.
- Accounting documents: according to the retention periods required by law.
Your rights
Under the Privacy Protection Law, you are entitled to inspect the information held about you, to request its correction if it is inaccurate or out of date, and to request its deletion, subject to retention obligations under law. A written request to the address at the bottom of the page will be answered within 30 days.
Cookies
- Name
- cookie-consent
- Type
- Local storage
- Created when
- On every choice
- Purpose
- Your choice (accept / decline) and the time it was made
- Holder
- aitermi (the business)
- Outside Israel
- No
- Name
- _ga, _ga_YFS2GGE5NH
- Type
- Cookies, two years
- Created when
- Only after "Accept"
- Purpose
- Google Analytics 4 — a browser identifier for measuring pages, clicks and form submissions
- Holder
- Google LLC / Google Ireland
- Outside Israel
- Yes — Google data centers worldwide
- Name
- _fbp (and _fbc when arriving from a Meta ad)
- Type
- Cookies, 90 days
- Created when
- Only after "Accept"
- Purpose
- Meta Pixel — a browser identifier for measuring conversions from Meta ads and for building audiences
- Holder
- Meta Platforms Ireland Ltd / Meta Platforms, Inc.
- Outside Israel
- Yes — Ireland and the US
- Name
- Google Tag Manager (gtm.js)
- Type
- Script, no cookie of its own
- Created when
- Only after "Accept"
- Purpose
- Loads the two tools above
- Holder
- Outside Israel
- Yes
Essential, not dependent on consent: aitermi-a11y (local storage) — the accessibility settings.
Changes to the policy
This policy may be updated. A material change will be communicated to customers by advance notice. The date of the last update appears at the bottom of the page.
Contact
A question, an inspection request or a deletion request:
Email: yoni@aitermi.com
Phone: 052-8826702
Version 2.0. Last updated: October 2026.