1. Roles
The Client is the controller (owner) of the personal information of its customers, leads, employees and contacts that is processed through the service. Mslahtk is the holder (processor) and processes that information only on the Client’s documented instructions, which are the settings the Client configures in the service, the Terms of Service and this DPA.
Mslahtk is the controller of the Client’s own account and billing information, which is governed by the Privacy Policy.
2. Subject Matter, Duration and Purpose
Processing covers the operation of the Client’s website, booking system, WhatsApp channel, AI assistants, CRM, reviews, attendance and related features, for as long as the Client’s subscription is active and during the return and deletion period described in section 10. The purpose is to provide the service to the Client and nothing else.
3. Categories of Information and Data Subjects
Data subjects: the Client’s customers and prospective customers, its employees and team members, and people who contact the Client through the service.
- Identification and contact details: name, phone number, email address, preferred language.
- Service information: appointments, orders, service history, notes the Client writes, review texts, CRM fields the Client defines.
- Communications: WhatsApp messages and media, call recordings and transcripts, email correspondence.
- Attendance: clock events and the device location recorded at the moment of a punch, for Clients that use the attendance module.
- The Client must not upload clinical records, government identification numbers, payment card numbers or other especially sensitive information into free-text fields or chats. Health-care Clients use the service for scheduling and communication, not as a medical record.
4. Our Obligations
Mslahtk shall:
- Process the information only for the Client and within its instructions, and never for our own marketing, profiling or resale.
- Keep it confidential. Where the Client is a health-care provider, we treat the information with the confidentiality required by section 19 of the Patient’s Rights Law, 5756-1996, and bind our staff and partners accordingly.
- Apply the security measures of the Data Security Regulations at the medium level or higher, as summarized on our Security page.
- Give access only to people who need it for their role: our operations staff, the Client’s own team members, and certified partners the Client has expressly granted access to. Administrative access is logged.
- Assist the Client in meeting its own duties: notices to data subjects, responses to access and correction requests, and security incident handling.
- Inform the Client if an instruction, in our opinion, breaches Israeli privacy law.
5. Subprocessors
The Client authorizes the subprocessors listed on our Subprocessors page. We remain responsible for their processing. We give at least 14 days’ notice, by email or in the dashboard, before adding or replacing a subprocessor; a Client that objects on reasonable grounds may terminate the affected service without penalty before the change takes effect.
6. Transfers Outside Israel
Our application and database are hosted in the United States (Railway, US West region), and some subprocessors process data in the United States or the European Union, as detailed on the Subprocessors page. Each recipient has undertaken in writing to protect the information to the standard required under Israeli law, in accordance with regulation 2(4) of the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, and the Client instructs us to transfer the information on that basis.
7. Security Measures
Encryption in transit (TLS) for every connection; encryption at rest on the cloud disks that hold the database and files; payment card numbers never stored; secrets and vendor tokens encrypted with AES-256-GCM; role-based access with one-time-code login; rate limiting, security headers and signature verification on incoming webhooks; audit logging of administrative actions kept for at least 24 months; a written security procedure, permissions register and database definitions document; a periodic security audit at least every 24 months. The current summary is published on our Security page.
8. Security Incidents
If we become aware of a security incident that affects the Client’s information (unauthorized access, loss, disclosure or corruption), we will notify the Client without undue delay and no later than 72 hours after confirming it, with what we know about the nature of the incident, the information and people affected, the measures taken and a contact person. We report serious incidents to the Privacy Protection Authority as the Data Security Regulations require, and we cooperate with the Client in any notification it must make to its own customers or authorities.
9. Requests from Data Subjects
If a person contacts us to access, correct or delete information that the Client controls, we will forward the request to the Client within five business days and will not respond on the Client’s behalf unless the Client asks us to. The service lets the Client export a customer’s information, correct it and delete it.
10. Retention, Return and Deletion
The Client controls retention within the service. During the subscription and for 30 days after it ends, the Client may export its data on request. After that period we permanently delete the Client’s data through the project retirement procedure, except billing and tax records we must keep under Israeli law, and security logs kept for the statutory period. On request we confirm deletion in writing.
11. Audits and Information
We answer the Client’s reasonable security questionnaires and provide our Security page, definitions document summary and the latest audit summary on request. Once a year, on 30 days’ written notice, the Client or an auditor bound by confidentiality may audit our compliance with this DPA, at the Client’s cost and without access to other clients’ information.
12. The Client’s Obligations
The Client is responsible for: having a lawful basis for the information it processes; giving its customers the notice required by section 11 of the Privacy Protection Law (the service shows a notice on the booking page and in the assistant’s first reply, which the Client may adapt); informing employees and obtaining their consent before using the attendance module; obtaining consent for any marketing message it sends through the service, in accordance with section 30A of the Communications Law; and not uploading information it is not allowed to share.
13. Liability and Precedence
The limitation of liability in the Terms of Service applies to this DPA. Where this DPA and the Terms conflict on the processing of personal information, this DPA prevails.
14. Term and Governing Law
This DPA applies for as long as we process personal information for the Client. It is governed by the laws of the State of Israel, and the competent courts in Israel have exclusive jurisdiction. Version 1.0, in force from September 7, 2026.
Questions about this agreement or a signed copy for your records? Write to [email protected].