עודכן לאחרונה: 25 ביוני 2026
Unidoc ("אנחנו", "השירות") היא פלטפורמת ניהול משרד מבוססת ענן לעסקים. מדיניות זו מסבירה אילו מידע אנו אוספים, כיצד אנו משתמשים בו, עם מי אנו חולקים אותו, וכיצד תוכלו לממש את זכויותיכם. המדיניות נכתבה בהתאם לחוק הגנת הפרטיות, התשמ"א-1981 ותקנותיו, ועקרונותיה תואמים גם את ה-GDPR האירופי.
Unidoc היא בעלת השליטה במידע (Data Controller) ביחס לחשבונות המשתמשים והגדרות החשבון. ביחס לתוכן שמעלים לקוחות עסקיים (הרשומות, הקבצים והמסמכים שלהם), Unidoc פועלת כמעבדת מידע (Processor) עבור אותו עסק, והעסק הוא בעל השליטה במידע של לקוחותיו.
אנו נעזרים בספקים מהימנים לצורך הפעלת השירות. איננו מוכרים מידע אישי.
| ספק | מטרה | מידע |
|---|---|---|
| Anthropic (Claude) | עוזר ה-AI שבמערכת | כאשר אתם משתמשים בצ'אט ה-AI, תוכן הרשומות שהעוזר ניגש אליו לפי בקשתכם נשלח למודל. כתובות דוא"ל וטלפון של אנשי קשר אינן נכללות בשיחה עם המודל. |
| Hetzner (אחסון Object Storage, האיחוד האירופי) | אחסון קבצים ומסמכים | קבצים, מסמכים שנוצרו ומסמכים חתומים. |
| Google Firebase Cloud Messaging | התראות Push לנייד | אסימון ההתקן להתראות. |
| שירות דוא"ל (SMTP) | שליחת דוא"ל מהשירות | כתובת הנמען ותוכן ההודעה (הזמנות, איפוס סיסמה, בקשות חתימה, התראות). |
| Sentry | ניטור שגיאות | נתוני אבחון טכניים, ממוזערים ללא פרטים מזהים ככל הניתן. |
אנו שומרים מידע כל עוד החשבון פעיל וכנדרש לצורך אספקת השירות, עמידה בחובות חוקיות, יישוב מחלוקות ואכיפת הסכמים. יומני התראות ופעילות נשמרים לתקופה מוגבלת (כברירת מחדל כ-90 יום עבור התראות). עם מחיקת חשבון נמחק או יואנונימיזציה המידע, למעט מה שנדרש לשמור על-פי דין.
אנו מיישמים אמצעי אבטחה מקובלים: הצפנת תעבורה (HTTPS), הפרדת דיירים (multi-tenant isolation) כך שאף ארגון אינו רואה מידע של ארגון אחר, גיבוב סיסמאות, אסימוני גישה קצרי-מועד, בקרת הרשאות מבוססת-תפקיד, ויומני ביקורת. גישת תמיכה לחשבון מתאפשרת רק לאחר הסכמה מפורשת שלכם, מוגבלת בזמן, לרוב לקריאה-בלבד, ומתועדת.
בכפוף לדין החל, יש לכם זכות לעיין במידע שלכם, לתקנו, למחקו, ולקבלו בפורמט נייד. ניתן לממש זכויות אלו בפנייה אלינו (פרטים בסעיף 11). משתמשי קצה של לקוח עסקי יפנו תחילה לאותו עסק כבעל השליטה במידע.
הקבצים נשמרים בשרתים באיחוד האירופי. חלק מהשירותים (כגון עוזר ה-AI וההתראות) עשויים לעבד מידע מחוץ לישראל/האיחוד האירופי, בכפוף לאמצעי הגנה מקובלים.
השירות מיועד לשימוש עסקי ואינו מיועד לילדים מתחת לגיל 16. איננו אוספים ביודעין מידע מילדים.
אנו עשויים לעדכן מדיניות זו מעת לעת. עדכון מהותי יפורסם בעמוד זה עם תאריך עדכון חדש.
בשאלות פרטיות או למימוש זכויות: support@unidoc.co.il
Last updated: June 25, 2026
Unidoc ("we", "the Service") is a cloud-based office-management platform for businesses. This policy explains what information we collect, how we use it, who we share it with, and how you can exercise your rights. It is written to align with Israel's Protection of Privacy Law, 5741-1981 and its regulations, and its principles are consistent with the EU GDPR.
Unidoc is the Data Controller for user accounts and account settings. For content uploaded by business customers (their records, files and documents), Unidoc acts as a Processor on that business's behalf, and the business is the Controller of its own customers' data.
We rely on trusted providers to run the Service. We do not sell personal information.
| Provider | Purpose | Data |
|---|---|---|
| Anthropic (Claude) | In-app AI assistant | When you use the AI chat, the record content the assistant accesses at your request is sent to the model. Contact emails and phone numbers are excluded from the AI conversation. |
| Hetzner (Object Storage, EU) | File & document storage | Files, generated documents, and signed documents. |
| Google Firebase Cloud Messaging | Mobile push notifications | Push device token. |
| Email (SMTP) | Service emails | Recipient address and message content (invites, password resets, signing requests, notifications). |
| Sentry | Error monitoring | Technical diagnostics, minimized to avoid personal data where possible. |
We retain data while your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes and enforce agreements. Notification and activity logs are kept for a limited period (by default about 90 days for notifications). When an account is deleted, data is deleted or anonymized except where retention is legally required.
We apply industry-standard measures: encrypted transport (HTTPS), strict multi-tenant isolation so no organization can see another's data, password hashing, short-lived access tokens, role-based access control, and audit logging. Support access to an account is granted only with your explicit consent, is time-limited, usually read-only, and is logged.
Subject to applicable law, you have the right to access, correct, delete, and port your data. To exercise these rights, contact us (section 11). End users of a business customer should first contact that business as the data controller.
Files are stored on servers in the EU. Some services (such as the AI assistant and push notifications) may process data outside Israel/the EU, subject to appropriate safeguards.
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect data from children.
We may update this policy from time to time. Material changes will be posted here with a new "last updated" date.
For privacy questions or to exercise your rights: support@unidoc.co.il