InvoiceBot Privacy Policy
English · Русский · עברית · العربية
Terms · Privacy · Data processing
Version of 9 September 2026. The service is provided by KidmaTech (ח.פ 328628482), Sd. Yerushalayim 3a/3, Kiryat Bialik, Israel. For any question about data: invoice_bot@kidmatech.com
This document is written in plain language on purpose. If anything here seems unclear, write to us and we will explain; a policy nobody can understand is useless to both sides.
1. What this service is
InvoiceBot is a Telegram bot through which a business issues receipts and invoices to its own clients. The documents themselves are issued by the business's accounting system (FinBot or Rivhit); the bot is a convenient way to use that system from a phone.
2. Two different sets of data — and our two roles
This is the part to understand before everything else.
Your clients' data (name, phone, email, tax ID, what was bought and for how much). You collected it from your own clients, for your own work. Your business owns this data. We only store and process it on your instruction, as a contractor. We do not decide what happens to it: we do what you asked and do not use it for our own purposes. Answering to your clients for having collected their data is likewise yours to do; the terms of that work are set out in a separate data processing agreement, which you accept when you connect.
Your own data (business name, tax status, your Telegram, the accountant's email, subscription details). Here we are the owner of the database, and everything written below about rights and obligations applies to us directly.
3. What data we store
About the business using the service: name, tax status (Osek Patur or Osek Murshe), interface language, the Telegram ID of the owner and of any authorised staff, the catalogue of services with prices, and the access key to the accounting system (stored encrypted).
About the accountant, if the business is connected through an accountant's console: name, Google email, Google account identifier, console language.
About the business's clients: name, phone, email, tax ID or ח.פ (if given), an internal note "for yourself", and the history of documents issued — what, when, for how much, paid by which method, and the last four digits of the card.
About the InvoiceBot subscription: plan, price, email for letters, the paid period, the card token and its last four digits, and the history of charges and declines.
We do not have, and never had, the full card number or its security code. The card is entered on a secure page of the CardCom payment system; all that reaches us is a token — a technical reference that can be used to charge money through our terminal, and nowhere else.
4. Why we store it
Only so that the service works: to issue a document, show the history, tell the owner of the business from an outsider, charge the subscription, and answer your question in support.
We do not sell data. We do not pass it to ad networks or data brokers. We do not build profiles on it and do not train models on it. We do not send marketing mailings without your separate consent.
5. Who the data is shared with
Only those without whom the service does not work:
- FinBot or Rivhit — the accounting system in which the document is issued. Client data and payment details go there. It is your system: you give us the access key yourself, and you are free to revoke it.
- CardCom — card payments. The amount, description and payer's contacts go there; the card number is entered directly with them, bypassing us.
- Telegram — the environment the bot runs in. Messages pass through Telegram's servers, as in any other chat.
- Google — only for the accountant's sign-in to the console. We receive the name, email and account identifier; we have no access to your mail or files.
- Oracle Cloud — the server the application runs on and where the database lives.
Beyond this, data is disclosed only where the law makes it mandatory.
6. Where the data is stored
On a server in Germany (Frankfurt, Oracle Cloud), that is, in the European Union. Storing data in the EU is permitted under Israeli law; the level of protection in the EU is recognised as adequate, and transferring data there does not require your separate permission.
7. How long we keep it
- Data on issued documents — for as long as the business is required to keep it under tax rules (currently seven years). This is a requirement of law, and we cannot delete such records at your request; but we anonymise the personal data inside them — see section 8.
- Data on clients for whom no document was issued — deleted at your request, immediately and in full.
- Business and subscription data — for as long as you use the service and a reasonable period after you leave, to settle accounts; then deleted.
- The access key to the accounting system — erased as soon as you disconnect the bot or ask us to delete it.
8. Your rights
You have the right to:
- know what we store about you — we provide an export, without secrets and keys;
- correct what is inaccurate — in the bot itself or through us;
- demand deletion. A client with no documents issued is deleted entirely. If there were documents, we keep the line in the history but erase the name, phone, email and tax ID in it — so that the record cannot identify a person, while the history of amounts and dates required by the tax authority is preserved;
- withdraw consent — including consent to any mailings;
- complain to the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות) if you believe we have infringed your rights.
A letter to invoice_bot@kidmatech.com is enough for any of these. We reply within the period set by law.
If you are a client of a business that uses InvoiceBot, please turn to that business first: the data is theirs and the decision about it is theirs to make. We will carry out their instruction, and if they do not respond, we will help you get in touch.
9. How we protect the data
- Access keys to accounting systems, bot tokens and card tokens are stored in the database encrypted; the key material is kept apart from the database, and a copy of the database without it is useless.
- Connections to the site and the console are over HTTPS only.
- The database file is accessible only to the application's service account.
- Sign-in to the accountant's console is through Google, with a limited session lifetime.
- One business's data is not available to another: the separation is checked by automated tests on every code change.
- Sign-in codes and session tokens are stored not as they are, but as irreversible fingerprints.
Absolute protection does not exist, and promising it would be dishonest. Should a serious data incident occur, we will notify the Privacy Protection Authority and those affected, as the law requires.
10. Cookies
One functional cookie, in the accountant's console, so that sign-in is not asked for on every page. There are no advertising or tracking cookies.
11. Children
The service is intended for businesses and is not aimed at children. We deliberately do not collect data about minors.
12. Changes to this policy
When we change this policy, we also change its version in the system, and at your next sign-in we ask for consent again. We will not quietly swap the terms you signed up under.
13. Contact
KidmaTech · Sd. Yerushalayim 3a/3, Kiryat Bialik, Israel · invoice_bot@kidmatech.com