מדיניות פרטיות

עודכן לאחרונה: 2 באוגוסט 2026

1. כללי

מדיניות פרטיות זו ("המדיניות") מסדירה את אופן איסוף, השימוש, השמירה והגילוי של מידע במסגרת השימוש במערכת flow, לרבות אתר האינטרנט, האפליקציות והממשקים הנלווים (להלן: "המערכת"), המופעלים על ידי פלואו מערכות מתקדמות בע״מ (להלן: "החברה", "אנחנו", "אנו").

השימוש במערכת מהווה הסכמה מלאה לתנאי מדיניות זו. אם אינך מסכים/ה לתנאים — אינך רשאי/ת לעשות שימוש במערכת.

2. סוגי המידע הנאסף

במסגרת השימוש במערכת אנו עשויים לאסוף את סוגי המידע הבאים:

  • פרטי זיהוי: שם, תעודת זהות / ח.פ., כתובת, טלפון ודואר אלקטרוני.
  • מידע עסקי, פיננסי וחשבונאי: מסמכים, אישורים, דוחות, חשבוניות וכל מידע הנדרש לצורך מתן השירותים.
  • מידע על השימוש במערכת: כתובת IP, סוג דפדפן, לוגים, פעולות שבוצעו במערכת ומועדים.
  • תכתובות: לרבות הודעות וואטסאפ, דואר אלקטרוני, SMS וקבצים שהועלו על ידי המשתמש או בשמו.

3. מטרות השימוש במידע

  • אספקה, תפעול, אבטחה, ניטור ושיפור של המערכת והשירותים.
  • תקשורת עם המשתמש, לרבות תמיכה, תזכורות, אישורים ובקשת מסמכים.
  • קיום חובות משפטיות החלות על החברה ומענה לדרישות רשויות מוסמכות על פי דין.
  • מניעת שימוש לרעה, הונאה או פעילות בלתי חוקית, והגנה על זכויות החברה וצדדים שלישיים.

4. בסיס משפטי לעיבוד המידע

עיבוד המידע נעשה על בסיס: (א) הסכמת המשתמש; (ב) הצורך לצורך מתן השירות שהוזמן; (ג) קיום חובה חוקית של החברה; (ד) האינטרסים הלגיטימיים של החברה בניהול תקין, מאובטח ומשופר של שירותיה.

5. שיתוף המידע עם צדדים שלישיים

החברה לא תמכור מידע אישי לצדדים שלישיים. שיתוף מידע מותר רק במקרים הבאים:

  • ספקי שירותים הפועלים מטעם החברה (לדוגמה: אחסון ענן, תשתיות, שירותי שליחת הודעות וספקי בינה מלאכותית) — המחויבים על פי חוזה לשמור על סודיות המידע ולעבדו רק לפי הנחיות החברה.
  • על פי צו שיפוטי, דרישת רשות מוסמכת או חובה שבדין.
  • לצורך הגנה על זכויות החברה, רכושה, ביטחון המערכת או בטיחות צדדים שלישיים.
  • במסגרת עסקה תאגידית (מיזוג, רכישה או העברת נכסים), בכפוף לשמירה על עקרונות מדיניות זו.

6. אחסון ושמירת המידע

המידע נשמר על שרתים מאובטחים בישראל ו/או בענן ציבורי באזורי עיבוד מקובלים. תקופת השמירה תיקבע בהתאם לצורכי אספקת השירות ולדרישות כל דין החל. בכל מקרה, החברה אינה אחראית לחובות שמירת רשומות של המשתמש עצמו כלפי רשויות המס או כל גורם אחר.

7. אבטחת מידע

החברה נוקטת באמצעי אבטחה סבירים ומקובלים בענף להגנה על המידע, לרבות הצפנה בתעבורה (TLS), הגבלת גישה, גיבויים ולוגים. עם זאת, אין מערכת אבטחה הרמטית, והחברה אינה מתחייבת ואינה ערבה לכך שלא תארע פריצה, אובדן או דליפת מידע כלשהי. השימוש במערכת נעשה על אחריות המשתמש בלבד.

8. זכויות המשתמש

בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, למשתמש עומדות הזכויות לעיין במידע שהחברה מחזיקה אודותיו, לבקש את תיקונו של מידע שגוי או חסר, ולבקש את מחיקתו — והכל בכפוף לחובות ולזכויות החברה על פי דין. בקשות יש להפנות לפרטי ההתקשרות שבסעיף 13. החברה תשיב לבקשה בתוך הזמן הקבוע בדין.

9. עוגיות (Cookies)

המערכת עושה שימוש בעוגיות תפקודיות הנדרשות להפעלתה (לדוגמה: שמירת התחברות ואחסון העדפות). לא נעשה שימוש בעוגיות פרסום צד ג'.

10. שירותי צד שלישי

המערכת משתלבת עם שירותי צד שלישי, ובכלל זה — אך לא רק — Meta (WhatsApp Business API), Google (אימות SSO, Google Drive), Anthropic (מנוע Claude ל‑AI) וספקי SMS / דואר אלקטרוני. השימוש בשירותים אלה כפוף למדיניות הפרטיות ולתנאי השימוש של אותם ספקים, והחברה אינה אחראית לפעולותיהם, לזמינותם או למדיניותם.

11. מידע משירותי Google (Google User Data)

המערכת מציעה חיבור אופציונלי לשירותי Google באמצעות OAuth. חיבור זה נעשה רק ביוזמת מנהל/ת הארגון, וניתן לניתוק בכל עת.

  • Google Drive (הרשאת drive): המערכת מציגה תכולה של תיקיות דרייב שהמשתמש קישר ידנית ללקוחות משרדו, מאפשרת הורדה וייבוא של קבצים מתוכן, ושומרת לתוכן מסמכים שהמשתמש בחר במפורש לשמור. המערכת אינה סורקת את הדרייב באופן יזום ואינה ניגשת לתכנים מעבר לפעולות שהמשתמש מבצע.
  • Gmail (הרשאת gmail.readonly, ככל שתופעל): איתור קבצי חשבוניות מצורפים לצורך הצגתם במערכת בלבד.
  • אימות (SSO): קבלת שם וכתובת דואר אלקטרוני לצורך התחברות בלבד.

השימוש של המערכת במידע המתקבל מ‑Google API עומד ב‑Google API Services User Data Policy, לרבות דרישות ה‑Limited Use:

  • מידע מ‑Google משמש אך ורק לאספקת התכונות הגלויות למשתמש שתוארו לעיל, ואינו משמש לכל מטרה אחרת.
  • המידע אינו נמכר, אינו מועבר לצדדים שלישיים למטרות פרסום, ואינו משמש להצגת פרסומות.
  • המידע אינו משמש לאימון או פיתוח של מודלי בינה מלאכותית מוכללים (generalized AI/ML).
  • בני אדם אינם קוראים את המידע, למעט בהסכמת המשתמש, לצורכי אבטחה, לצורך עמידה בדין או כאשר המידע עבר אגרגציה למטרות תפעול פנימיות.
  • אסימוני הגישה (Tokens) נשמרים מוצפנים במנוחה. ניתוק החיבור בהגדרות המערכת מוחק את האסימונים ומבטל את הגישה; ניתן לבטל הרשאות גם דרך הגדרות חשבון Google.

12. שינויים במדיניות

החברה שומרת לעצמה את הזכות לעדכן מדיניות זו מעת לעת. גרסה מעודכנת תפורסם בדף זה עם תאריך עדכון. המשך שימוש במערכת לאחר עדכון מהווה הסכמה לגרסה המעודכנת.

13. יצירת קשר

בכל שאלה הנוגעת למדיניות זו ניתן לפנות לפלואו מערכות מתקדמות בע״מ בוואטסאפ שמספרו 054-302-5750, או בכל ערוץ תקשורת אחר שסופק על ידי החברה.

14. דין חל וסמכות שיפוט

על מדיניות זו יחול הדין הישראלי בלבד. סמכות השיפוט הייחודית והבלעדית בכל סכסוך הנוגע למדיניות זו או לשימוש במערכת מוקנית לבתי המשפט המוסמכים במחוז תל-אביב–יפו, ולהם בלבד.

Privacy Policy

Last updated: August 2, 2026

1. General

This Privacy Policy (the "Policy") governs the collection, use, retention and disclosure of information in connection with the use of the flow system, including the website, applications and related interfaces (the "System"), operated by Flow Advanced Systems Ltd. (the "Company", "we", "us").

Use of the System constitutes full agreement to this Policy. If you do not agree to these terms, you must not use the System.

2. Types of Information Collected

  • Identification details: name, ID / company number, address, phone and email.
  • Business, financial and accounting information: documents, certificates, reports, invoices and any information required to provide the services.
  • System usage data: IP address, browser type, logs, actions performed in the System and timestamps.
  • Communications: including WhatsApp messages, email, SMS and files uploaded by or on behalf of the user.

3. Purposes of Use

  • Providing, operating, securing, monitoring and improving the System and services.
  • Communicating with the user, including support, reminders, approvals and document requests.
  • Fulfilling the Company's legal obligations and responding to lawful requests of authorized bodies.
  • Preventing misuse, fraud or unlawful activity, and protecting the rights of the Company and third parties.

4. Legal Basis for Processing

Processing is based on: (a) the user's consent; (b) necessity to provide the requested service; (c) the Company's legal obligations; and (d) the Company's legitimate interests in the orderly, secure and improved operation of its services.

5. Sharing with Third Parties

The Company will not sell personal information to third parties. Sharing is permitted only in the following cases:

  • Service providers acting on the Company's behalf (e.g. cloud hosting, infrastructure, messaging providers and AI providers) — contractually bound to maintain confidentiality and process data only per the Company's instructions.
  • Pursuant to a court order, a lawful authority request, or a legal obligation.
  • To protect the Company's rights, property, the security of the System or the safety of third parties.
  • In connection with a corporate transaction (merger, acquisition or asset transfer), subject to the principles of this Policy.

6. Storage and Retention

Data is stored on secure servers in Israel and/or in public cloud regions. Retention periods are determined by the needs of providing the service and by any applicable law. In any case, the Company is not responsible for the user's own record-retention obligations toward tax authorities or any other party.

7. Information Security

The Company employs reasonable, industry-standard security measures including in-transit encryption (TLS), access controls, backups and logging. However, no security system is impenetrable, and the Company does not warrant or guarantee against any breach, loss or leak of data. Use of the System is at the user's own risk.

8. User Rights

Under the Israeli Privacy Protection Law, 5741-1981, users may access the information the Company holds about them, request correction of inaccurate or incomplete information, and request its deletion — all subject to the Company's obligations and rights under applicable law. Requests should be sent to the contact details in Section 13. The Company will respond within the time required by law.

9. Cookies

The System uses functional cookies necessary for its operation (e.g. authentication and preferences). No third-party advertising cookies are used.

10. Third-Party Services

The System integrates with third-party services, including but not limited to Meta (WhatsApp Business API), Google (SSO, Google Drive), Anthropic (the Claude AI engine) and SMS / email providers. Use of these services is subject to those providers' own privacy policies and terms, and the Company is not responsible for their actions, availability or policies.

11. Google User Data

The System offers an optional connection to Google services via OAuth. The connection is initiated only by an organization administrator and can be disconnected at any time.

  • Google Drive (drive scope): the System displays the contents of Drive folders that the user has manually linked to their firm's clients, allows downloading and importing files from them, and saves documents into them when the user explicitly chooses to. The System does not proactively scan the user's Drive and does not access content beyond the actions the user performs.
  • Gmail (gmail.readonly scope, if activated): locating invoice attachments solely for display within the System.
  • Sign-in (SSO): receiving name and email address for authentication only.

The System's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • Google user data is used only to provide the user-facing features described above, and for no other purpose.
  • Google user data is never sold, never transferred to third parties for advertising purposes, and never used to serve advertisements.
  • Google user data is not used to train or develop generalized AI/ML models.
  • Humans do not read this data except with the user's consent, for security purposes, to comply with applicable law, or when aggregated for internal operations.
  • OAuth tokens are stored encrypted at rest. Disconnecting the integration in the System's settings deletes the tokens and revokes access; permissions can also be revoked at Google Account settings.

12. Changes to the Policy

The Company reserves the right to update this Policy from time to time. An updated version will be posted on this page with an updated date. Continued use of the System after an update constitutes agreement to the updated version.

13. Contact

For any question regarding this Policy, contact Flow Advanced Systems Ltd. via WhatsApp at +972-54-302-5750, or any other communication channel provided by the Company.

14. Governing Law and Jurisdiction

This Policy is governed exclusively by the laws of the State of Israel. Exclusive jurisdiction over any dispute relating to this Policy or the use of the System is granted to the competent courts of the Tel Aviv – Jaffa district, and to them alone.