1. Information We Collect
We collect the minimum amount of information needed to deliver our services and operate our business. The categories of information are:
- Contact information you provide voluntarily: name, phone number, email address, business name, business location.
- Order information: the service you subscribed to, billing dates, subscription status.
- Payment information: processed by our third-party payment provider. We do not store, log, or have access to your full credit card details on our servers.
- Technical information: IP address, browser type, device type, pages visited, basic analytics data, collected through standard server logs and cookies.
- Communications: messages you send us via WhatsApp, email, phone, or contact forms.
2. Mandatory vs. Optional Information
Israeli Privacy Protection Law (Amendment 13) requires us to clearly state which information is mandatory to provide and which is optional.
- Required (you cannot use our service without it): email address, phone number, payment information, and basic billing details. These are needed to deliver the service and meet Israeli tax/accounting law.
- Optional (improves the service but not required): business profile details, communication language preference, marketing consent, and additional contact channels.
- You may decline to provide optional information without affecting your ability to use the core service.
3. How We Collect Your Information
We collect information through the following methods:
- Directly from you: when you contact us via WhatsApp, phone, email, or signup forms.
- Automatically: through a few essential cookies (your language preference and your cookie choice) and standard server logs (IP address, browser type, page visits) used for security and basic analytics.
- From PayPlus, our payment processor: transaction confirmations and billing status. The full card number never reaches our servers and is never stored by us. Tax documents are issued through SmartBee, and authentication and notifications run on Google Firebase.
- For our own sales prospecting we collect publicly listed business contact details (business name, category, address, public phone number, website and public social profiles) from Google Maps listings and public social pages, using Apify as a technical collector. We do not buy consumer data from data brokers and we do not collect information from advertising networks. See section 17.
4. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve the services you subscribed to.
- To process payments through our payment provider.
- To send service-related notifications, billing confirmations, and important account updates.
- To respond to your questions and provide customer support.
- To comply with legal obligations under Israeli law (including tax and accounting requirements).
- To prevent fraud and abuse of our services.
5. Sharing Your Information and Our Subprocessors
We do not sell, rent, or trade your personal information. We share information only with the service providers below, only to the extent needed to run the service, and each of them is bound by a written data-processing undertaking. The maintained list, with locations and purposes, is published on our Subprocessors page.
- Railway (United States, US West region): hosting of the application and its database.
- Google: Firebase for login, file storage and app notifications; the Gemini API (paid tier) to generate AI replies and content. Google does not use our prompts or outputs to train its models.
- Meta Platforms: the WhatsApp Business Platform that carries WhatsApp messages.
- Brevo (France): transactional email.
- PayPlus (Israel): card payments for our subscriptions. SmartBee (Israel): tax documents.
- Sentry (United States): error monitoring, configured without personal data by default. Cloudflare (United States): DNS, edge security and bot protection.
- Apify (Czech Republic): collection of public business listings for our own prospecting only, never client data.
- Anthropic (United States): AI tooling our operations team uses to run and support the platform; data sent through its API is not used for training.
- Telegram: operational alerts to our team, without customer identifiers.
- Certified Mslahtk partners: see a client’s data only when that client grants access from the dashboard, and the client can revoke it at any time.
- Authorities and legal counsel: when the law requires it or to establish or defend a legal claim.
6. Data Received from Meta Platforms (WhatsApp Business Platform)
When a customer connects a WhatsApp Business Account ("WABA") to Mslahtk through Meta's Embedded Signup, we receive data from Meta Platforms, Inc. ("Platform Data") in order to operate the messaging service on behalf of our customer. For Platform Data, our customer is the data controller and Mslahtk acts as a data processor on their behalf.
Platform Data we receive includes:
- WABA identifier, business display name, business profile information, and verification status.
- Phone number identifier, display phone number, and phone-number quality rating.
- Incoming and outgoing message content (text, media, templates, interactive messages) exchanged between our customer and their end users.
- Message metadata: timestamps, delivery status (sent / delivered / read / failed), and conversation identifiers.
- End-user identifiers limited to the phone number and the display name the end user has set on their WhatsApp profile.
- We use Platform Data strictly to: (a) display conversations to our customer inside their Mslahtk dashboard so they can reply to their own end users, (b) send reminders, confirmations, and follow-ups that the customer has pre-configured, (c) provide the customer with delivery and engagement reporting on the messages they sent, and (d) automatically process the content of inbound messages using AI to draft replies, take bookings, and capture leads on the customer's behalf, according to the customer's configuration.
- What we do NOT do with Platform Data: we do not sell it; we do not use it for advertising or to build advertising profiles; we do not use it to train machine-learning or generative AI models; and we do not share it across customers: each customer's Platform Data is logically isolated and accessible only to authorized users of that customer.
- End users who messaged a business that uses Mslahtk can request deletion of their data by following our Data Deletion Instructions (linked in the footer of this page) or by contacting the business they messaged directly.
7. Cookies & Analytics
Our website uses a few essential cookies (your language preference and your cookie choice). We do not use tracking, advertising, or third-party analytics cookies. Standard server logs are used for security and basic site performance monitoring only. Our site footer includes an embedded Google Map; when a page footer loads, your IP address is sent to Google to display the map.
Our intake and dashboard applications load no advertising pixel unless you give a separate marketing consent, and our server-side Meta Conversions API integration is not active. If we activate it we will describe it here first, and it will only report events with hashed identifiers.
8. Data Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit (HTTPS), secure hosting, access controls, two-factor authentication on admin accounts, and limited data retention. No system is 100% secure, but we work to protect your data and notify the Israeli Privacy Protection Authority and affected users in the event of a material security incident as required by Amendment 13 of the Privacy Protection Law.
9. Your Rights
Under Israel's Privacy Protection Law (5741-1981) as amended by Amendment 13 (effective August 2025), you have the following rights:
- Right of access: request a copy of the personal information we hold about you.
- Right to rectification: request correction of inaccurate or incomplete information.
- Right to deletion: request deletion of your information, subject to legal retention obligations (e.g., tax records).
- Right to data portability: receive your data in a structured, machine-readable format (CSV or JSON), provided within 30 days of request.
- Right to object: object to processing of your data for direct marketing purposes.
- Right to withdraw consent: withdraw consent for any optional data processing at any time.
- Right to lodge a complaint: file a complaint with the Israeli Privacy Protection Authority (PPA) at https://www.gov.il/en/departments/the_privacy_protection_authority
10. Data Retention Periods
In compliance with Amendment 13, we retain your data only for as long as necessary, with the following specific periods:
- Account information: for the duration of your active subscription, plus 7 years after termination (Israeli tax law requirement).
- Billing and tax records: 7 years (Israeli Income Tax Ordinance requirement).
- WhatsApp Business Platform message content (Platform Data): up to 180 days from receipt, unless the customer has configured a different retention period in their account settings or a longer period is required by law.
- WhatsApp Business Platform message metadata and delivery logs: up to 24 months for troubleshooting, billing, and abuse prevention.
- Email and direct (non-WhatsApp) communications with our team: 3 years from the last interaction.
- Server logs (IP, browser data): 12 months.
- Marketing preferences and consent records: until you unsubscribe, plus 1 year for compliance auditing.
- Language preference cookie: 1 year (or cleared when you decline cookies).
- When a customer closes their Mslahtk account, Platform Data is deleted or anonymized within 90 days, except where retention is required by law. After all applicable periods, data is permanently deleted or fully anonymized.
- Phone call recordings and transcripts handled by the AI phone assistant: 12 months.
- Employee attendance records for businesses that use the attendance module, including punch location: according to the employer’s setting, 24 months by default.
- Business prospecting records: 12 months after the last contact, or immediately on request. A do-not-contact record (phone number only) is kept indefinitely so we never contact you again.
- Audit and security logs: at least 24 months, as the Data Security Regulations require.
11. Marketing Communications
We do not send marketing communications without your explicit, prior opt-in consent, in compliance with Section 30A of Israel's Communications Law (Anti-Spam Law).
- By default, you only receive transactional emails: invoices, account updates, support replies, and required legal notices.
- If you opt in to marketing, every promotional message will identify itself as marketing, include our business name and registration number (514184886), and contain a one-click unsubscribe link.
- Unsubscribe requests are honored within 3 business days.
- We respect Israel's national "Do Not Call Me" registry. To unsubscribe at any time, email [email protected].
12. Children's Privacy
Our services are intended for businesses and adult users (18+). We do not knowingly collect personal information from children under 16. If you become aware that a child under 16 has provided us with personal information without parental consent, please contact us at [email protected] and we will delete it immediately.
13. International Data Transfers
Our application and database are hosted by Railway in the United States (US West region). Google services (Firebase, Gemini API), Meta, Sentry and Cloudflare also process data in the United States and in other regions where they operate. Brevo and Apify process data in the European Union, and PayPlus and SmartBee in Israel.
Transfers outside Israel rest on the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001: each recipient has undertaken in writing to protect the data to the standard required under Israeli law (regulation 2(4)), and you are informed of the transfer through this policy. Transfers to the European Union rely on its data-protection framework. The European Union recognizes Israel as providing adequate data protection.
14. Phone Calls Answered by the AI Assistant
Businesses that enable the AI phone assistant have their calls answered by an automated assistant that can book appointments, answer questions and take messages. A caller is told at the start of the call that they are speaking with an automated assistant and that the call is recorded or transcribed, and can ask for a person at any time.
Recordings and transcripts are stored for the business to review, are used to create the appointment or lead the caller asked for, and are deleted after 12 months unless the business or the law requires a different period.
15. Information We Process for the Businesses We Serve
When a business uses Mslahtk to communicate with its customers, book appointments or manage its contacts, that business is the controller of its customers’ information and Mslahtk processes it on the business’s behalf, under our Data Processing Agreement.
This covers customer names and phone numbers, appointments, WhatsApp conversations and media, reviews, CRM records and call transcripts. We use it only to provide the service to that business, we do not use it for our own marketing, and we do not share it with other clients. If you are a customer of a business that uses Mslahtk and want to access, correct or delete your information, contact that business; we help it respond, and you can also write to us at [email protected].
16. Employee Attendance
Businesses that use the attendance module record their employees’ clock-in and clock-out events. At the moment of a punch the app records the device location, so the employer can verify the punch was made at the workplace. Location is never collected at any other time.
The employer is the controller of this information, sets the retention period, and is responsible for informing employees and obtaining their consent before they use the app. Mslahtk processes the information for the employer only and restricts access to the employer and the managers the employer designates.
17. Business Prospecting
To find businesses that may benefit from our services we collect publicly listed business details from Google Maps and public social pages, score them, and may send the business one message asking whether it agrees to receive information from us. We send no further marketing without that agreement, and every message carries a one-tap opt-out that we honor permanently.
If you received such a message, you have the right to know the source of your details (a public listing of your business), to be removed, and to ask us not to contact you again.
18. Privacy Officer and Requests
Our privacy officer is Rami Daood, reachable at [email protected]. Requests to access, correct or delete personal information are answered within 30 days. You may also file a complaint with the Israeli Privacy Protection Authority.
19. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated to active customers by email at least 30 days before they take effect.
Questions about this Privacy Policy or your data? Contact us at [email protected] or through our contact page.