KidmaTech CRM Data Processing Agreement
Русский · עברית · English · العربية
Terms · Privacy Policy · Data Processing Agreement
Version of 14 September 2026.
An agreement between KidmaTech (ח.פ 328628482), Sd. Yerushalayim 3a/3, Kiryat Bialik, Israel, and the business that has connected KidmaTech CRM (hereinafter «the Business»).
This document exists because Israel's Data Security Regulations of 2017 require it directly: whoever holds someone else's database of personal data must have a written agreement with its owner. The CRM stores the correspondence of the Business's clients — precisely such a database.
1. Roles
The law calls these roles «database owner» and «database holder». Here, for simplicity, they are the Business and KidmaTech.
The Business is the owner of the database of its clients. It decides what data to collect and why, and it answers to its own clients for the lawfulness of that collection — including notifying them about the processing and obtaining the necessary consent.
KidmaTech is the holder of the database: it stores and processes this data on the Business's instructions and only to the extent needed to run the service.
2. What data and what actions
KidmaTech processes what arrives in the channels connected by the Business and what the Business itself enters into the client card:
- correspondence from the connected channels: message text, attachments (voice messages, photographs, documents), the sender's display name, their identifier in the channel, message times;
- the client card: name, phone number, email, notes written by the Business's staff, the history of enquiries;
- recordings and transcripts of meetings, if the Business has connected such an integration;
- access keys to the connected accounts — in encrypted form.
Actions: receiving and storing, showing to the Business's staff, replying on behalf of the Business, transcribing voice messages into text, preparing replies with the assistant, anonymisation and deletion on request.
There is one purpose: running the service. Using this data for KidmaTech's own ends — advertising, resale, profiling, training models — is prohibited, and KidmaTech does not do it.
3. Duration
For as long as the connection to KidmaTech CRM is active. After it ends — see clause 8.
4. Where the data is stored
On a server in Germany (Frankfurt, Oracle Cloud), that is, within the European Union. By accepting this agreement the Business is aware of that and accepts it. KidmaTech gives advance notice of any change to the country of storage.
5. Security measures
KidmaTech undertakes to:
- keep the access keys to the Business's channels and the integration tokens in encrypted form, with the key material held separately from the database;
- grant access to the data only to those of its people who need it for their work, and only to the extent needed;
- ensure that such people are bound by a duty of confidentiality and know the rules for handling the data;
- separate the data of different businesses so that one cannot see another's;
- keep backups and protect them no less strongly than the database itself;
- transmit data only over secure connections.
6. Engaging third parties
KidmaTech engages only those without whom the service does not work, and only for the part the Business has connected itself: the channel platforms (WhatsApp, Telegram, Meta for Facebook and Instagram), Zoom and Google — if the Business has granted access to them, and Oracle Cloud as the hosting provider. Voice messages are transcribed by speech recognition software running on our own server: no audio leaves it for that purpose. KidmaTech gives the Business advance notice before engaging a new contractor that would receive access to the data; the Business may object and, in that case, terminate the agreement.
7. Incidents
If an event occurs in which the Business's data could have reached outsiders, been altered or lost, KidmaTech informs the Business without delay and passes on everything it knows: what happened, which data is affected, what has already been done. KidmaTech notifies the Israeli Privacy Protection Authority in those cases where the law obliges KidmaTech itself to do so, and assists the Business in fulfilling its own duty to notify.
8. Return and destruction
When the connection ends — at the Business's request and no later than 30 days — KidmaTech:
- provides the Business's data in machine-readable form (an export without keys and tokens), and
- deletes it from the working database and from backups within their ordinary rotation cycle.
Channel access keys are erased immediately when a channel is disconnected.
The exception is information KidmaTech is required by law to retain. Such records remain, but the personal data in them is anonymised.
9. Verification
The Business may ask KidmaTech for information on how this agreement is being performed: what security measures are applied, who has access, whether there have been incidents. KidmaTech answers within a reasonable time.
10. Rights of the Business's clients
A request from a client of the Business — to see their data, correct it or delete it — is addressed to the Business: the database is theirs. KidmaTech provides the means to carry it out (export, anonymisation, deletion) and assists if the Business asks.
11. Miscellaneous
This agreement is an annex to the Terms of Use and applies together with them. The law of the State of Israel applies.
KidmaTech · Sd. Yerushalayim 3a/3, Kiryat Bialik, Israel · admin@kidmatech.com