מדיניות פרטיות
Professional draft for legal review — not legal advice. Have counsel approve it before you rely on it, and complete the items marked […].
מדיניות זו מסבירה כיצד משה בן צבי מהנדסים יועצים בע״מ ("החברה", "אנחנו") אוספת ומעבדת מידע אישי באמצעות אתר זה והאיזור האישי שבו. אנו מעבדים את המידע במידה המזערית הנדרשת, בהתאם לחוק הגנת הפרטיות, התשמ״א־1981 (כולל תיקון 13) ולתקנות מכוחו, וכן — במקום שבו הוא חל — לתקנה האירופית להגנת נתונים (GDPR). This policy explains how M. Ben-Zvi Consulting Engineers Ltd. ("the Company", "we") collects and processes personal data through this website and its member area. We process the minimum data necessary, under Israel's Protection of Privacy Law, 5741-1981 (including Amendment No. 13) and its regulations, and — where it applies — the EU General Data Protection Regulation (GDPR).
1. מי אחראי למידע (בעל השליטה)
- בעל השליטה במאגר / Controller: משה בן צבי מהנדסים יועצים בע״מ · M. Ben-Zvi Consulting Engineers Ltd. Company registration no.: [ח.פ. — להשלים / to complete].
- כתובת / Address: יהושע בן נון 27, תל אביב-יפו, ישראל. 27 Yehoshua Ben Nun St., Tel Aviv-Yafo, Israel.
- ליצירת קשר בנושאי פרטיות / Privacy contact: office@benzvi-eng.co.il.
- אחסון ומיקום העיבוד / Hosting & data location: [שרת ייעודי בשליטת החברה — יש לציין מדינת אחסון: ישראל/האיחוד האירופי / self-hosted server under the Company's control — state hosting country: Israel / EU].
- EU representative (GDPR Art. 27), if designated: [to complete after legal review — see §12].
אין עלינו חובה למנות ממונה הגנת פרטיות (DPO), אך הכתובת לעיל היא כתובת הקשר לכל עניין פרטיות. We are not required to appoint a statutory Data Protection Officer; the address above is our contact point for all privacy matters.
2. איזה מידע אנו אוספים, לשם מה, ועל סמך איזה בסיס חוקי
אנו אוספים רק את המידע הדרוש להפעלת השירות. הטבלה מפרטת כל פעילות עיבוד, מטרתה והבסיס החוקי לפי סעיף 6 ל-GDPR. We collect only what the service needs. The table lists each processing activity, its purpose and its GDPR Art. 6 legal basis.
| מידע / Data | מטרה / Purpose | בסיס חוקי / Legal basis |
|---|---|---|
| דוא״ל, סיסמה (מאוחסנת כ-hash בלבד, Argon2id), שם / Email, password (stored only as an Argon2id hash), name | יצירת חשבון וניהולו / Create & run your account | ביצוע חוזה / Contract — 6(1)(b) |
| אסימוני אימות דוא״ל ואיפוס סיסמה (hash, חד-פעמיים) / Email-verification & password-reset tokens (hashed, single-use) | אימות בעלות ושחזור גישה / Verify ownership & restore access | ביצוע חוזה + אבטחה / Contract 6(1)(b) + security 6(1)(f) |
| סוד 2FA (מוצפן AES-256-GCM) וקודי שחזור / TOTP secret (AES-256-GCM encrypted) & recovery codes | אימות דו-שלבי אופציונלי / Optional two-factor authentication | ביצוע חוזה 6(1)(b) |
| מזהה וכתובת דוא״ל מ-Google/Microsoft / Identifier & email from Google/Microsoft | כניסה עם ספק חיצוני (לבחירתכם) / "Sign in with" (your choice) | ביצוע חוזה 6(1)(b) |
| מזהה הפעלה (session) ב-Redis; עוגיית מזהה / Session id in Redis; id cookie | שמירת מצב מחובר / Keep you signed in | ביצוע חוזה 6(1)(b) |
| כתובת IP וסוג דפדפן / IP address & user-agent | הגבלת קצב, נעילת חשבון ומניעת ניצול לרעה / Rate-limiting, lockout & abuse prevention | אינטרס לגיטימי / Legitimate interest 6(1)(f) |
| יומן אירועי אבטחה / Security audit log | זיהוי אירועים, חקירת תקריות ואחריותיות / Detection, investigation & accountability | אינטרס לגיטימי 6(1)(f) |
| בדיקת סיסמה שנחשפה (HaveIBeenPwned) / Breached-password check | מניעת שימוש בסיסמאות שדלפו / Block known-leaked passwords | אינטרס לגיטימי 6(1)(f) — נשלחת רק קידומת גיבוב, ללא מידע מזהה / only a hash prefix is sent, no personal data |
| טופס יצירת קשר: שם, חברה, דוא״ל, טלפון, הודעה / Contact form: name, company, email, phone, message | מענה לפנייתכם / Respond to your enquiry | צעדים טרום-חוזיים / 6(1)(b) or 6(1)(f) |
איננו אוספים "מידע בעל רגישות מיוחדת" (כגון מידע רפואי, ביומטרי, גנטי, פוליטי או פיננסי), איננו מבצעים החלטות אוטומטיות בעלות השלכה משפטית או משמעותית דומה, ואיננו עורכים פרופיילינג. נא לא לכלול פרטים רגישים בהודעה חופשית בטופס יצירת קשר. We do not collect "specially sensitive data" (e.g. health, biometric, genetic, political or financial data), we make no automated decisions producing legal or similarly significant effects, and we do not profile you. Please do not include sensitive details in a free-text contact message.
3. עוגיות (Cookies)
אנו משתמשים אך ורק בעוגיות חיוניות ותפקודיות — אין עוגיות פרסום או מעקב של צד שלישי. לכן, על פי הדין, די בהודעה זו ואין צורך בבקשת הסכמה נפרדת. אם בעתיד נוסיף מדידת שימוש (analytics), נבקש את הסכמתכם מראש (opt-in). We use only strictly-necessary / functional cookies — no third-party advertising or tracking cookies. Under ePrivacy rules this notice is sufficient and no consent banner is required. If we ever add usage analytics, we will ask for your prior opt-in consent first.
| עוגייה / Cookie | תפקיד / Role |
|---|---|
bz_sess | מזהה הפעלה מאובטח (httpOnly) — שמירת מצב מחובר / Secure session id — keeps you signed in |
bz_csrf | הגנה מפני זיוף בקשות חוצה-אתרים / Cross-site request-forgery protection |
| העדפת שפה / language | זכירת בחירת עברית/אנגלית / Remembers your language choice |
| בחירת עוגיות / notice | זכירה שההודעה נסגרה / Remembers you dismissed the cookie notice |
4. עם מי אנו חולקים מידע
- איננו מוכרים מידע ואיננו משתמשים במעבדי צד-שלישי חיצוניים לאחסון. כל השירות מתארח בתשתית בשליטת החברה. We do not sell data and do not use third-party SaaS processors for storage; the service runs on infrastructure under the Company's control.
- אם תבחרו "כניסה עם Google/Microsoft", אותם ספקים פועלים כבעלי-שליטה עצמאיים למידע שהם מעבדים, לפי מדיניותם. If you choose "Sign in with Google/Microsoft", those providers act as independent controllers under their own policies.
- דוא״ל יוצא נשלח דרך שרת הדואר של החברה. Outbound email is sent through the Company's own mail server.
- ייתכן גילוי אם נדרש על פי דין או צו שיפוטי. We may disclose data where required by law or valid legal process.
5. העברת מידע אל מחוץ למדינה
אם השרת ממוקם בישראל, העברות מהאזור הכלכלי האירופי נשענות על החלטת ההלימות (Adequacy) של האיחוד האירופי לגבי ישראל (חודשה ב-15.1.2024 ותקפה נכון למועד זה). אם השרת ממוקם באיחוד האירופי, אין העברה בינלאומית. If the server is in Israel, transfers from the EEA rely on the EU adequacy decision for Israel (renewed 15 Jan 2024, in force as of this date). If the server is in the EU, no international transfer occurs. [Confirm hosting location — see §1.]
6. כמה זמן נשמור את המידע
| קטגוריה / Category | תקופת שמירה / Retention |
|---|---|
| מידע חשבון / Account data | למשך קיום החשבון; נמחק/יהפוך אנונימי תוך 30 יום ממחיקה / Life of the account; deleted or anonymised within 30 days of closure |
| אסימון אימות דוא״ל / Email-verification token | עד 24 שעות / Up to 24 hours |
| אסימון איפוס סיסמה / Password-reset token | עד שעה / Up to 1 hour |
| הפעלות (sessions) / Sessions | 12ש׳ חוסר-פעילות / 7 ימים מקסימום / 12h idle / 7-day max |
| יומן אבטחה / Security audit log | עד 12 חודשים; מנותק מזהותכם בעת מחיקת חשבון / Up to 12 months; de-identified on account deletion |
| IP להגבלת קצב / IP for rate-limiting | זמני (דקות עד שעות) / Transient (minutes–hours) |
| פניות טופס קשר / Contact-form messages | 12–24 חודשים, או עד סיום הטיפול / 12–24 months, or until the enquiry is resolved |
| גיבויים מוצפנים / Encrypted backups | מתחלפים במחזור של עד ~30 יום / Rotate within ~30 days |
7. אבטחת מידע
אנו נוקטים אמצעים טכניים וארגוניים ההולמים את הסיכון (סעיף 32 ל-GDPR ותקנות הגנת הפרטיות (אבטחת מידע) התשע״ז־2017): גיבוב סיסמאות ב-Argon2id, הצפנת AES-256-GCM לסודות רגישים, TLS/HTTPS, עוגיות httpOnly/Secure, הפעלות אטומות בצד השרת, אסימונים חד-פעמיים, הגבלת קצב ונעילה, אימות דו-שלבי, בדיקת סיסמאות שדלפו, יומן אבטחה, וגיבויים מוצפנים. We apply technical and organisational measures appropriate to the risk (GDPR Art. 32 and Israel's 2017 Data Security Regulations): Argon2id password hashing, AES-256-GCM encryption of sensitive secrets, TLS/HTTPS, httpOnly/Secure cookies, opaque server-side sessions, single-use tokens, rate-limiting & lockout, two-factor authentication, breached-password checks, an audit log, and encrypted backups. No method is perfectly secure, but we work to protect your data and to detect and respond to incidents.
8. הזכויות שלכם
בכפוף לדין החל, יש לכם זכות: לעיין במידע (סעיף 13 לחוק / GDPR Art. 15), לתקן מידע שגוי או לא מעודכן (סעיף 14 / Art. 16), למחיקה (Art. 17), להגבלת עיבוד (Art. 18), לניוד מידע שמסרתם (Art. 20), ולהתנגד לעיבוד המבוסס על אינטרס לגיטימי (Art. 21). Subject to applicable law you may: access your data (PPL s.13 / GDPR Art. 15), rectify inaccurate or outdated data (s.14 / Art. 16), request erasure (Art. 17), restrict processing (Art. 18), port data you provided (Art. 20), and object to processing based on legitimate interests (Art. 21).
ניתן לממש חלק מהזכויות ישירות מהאיזור האישי (עדכון פרטים, ייצוא נתונים ומחיקת חשבון), או לפנות אלינו. נשיב תוך 30 יום (GDPR: עד חודש, בר-הארכה בחודשיים בבקשות מורכבות). מימוש הזכויות ללא תשלום, אלא אם הבקשה קנטרנית או חוזרת באופן מוגזם. You can exercise several rights directly from your account page (update details, export your data, delete your account), or contact us. We respond within 30 days (GDPR: within one month, extendable by two months for complex requests). There is no charge unless a request is manifestly unfounded or excessive.
9. משיכת הסכמה
במקום שבו העיבוד מבוסס על הסכמה, ניתן למשוך אותה בכל עת, מבלי לפגוע בחוקיות העיבוד שקדם למשיכה. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
10. אירועי אבטחה
במקרה של אירוע אבטחה חמור נפעל על פי הדין: דיווח מיידי לרשות להגנת הפרטיות כנדרש, ויידוע נפגעים כאשר קיים סיכון גבוה לזכויותיהם (GDPR: דיווח לרשות המפקחת תוך 72 שעות ככל שרלוונטי). In a serious security incident we act as the law requires: prompt notification to the Israeli Privacy Protection Authority where applicable, and notice to affected individuals where there is a high risk to their rights (GDPR: notify the supervisory authority within 72 hours where relevant).
11. קטינים
האתר והאיזור האישי אינם מיועדים לילדים, ואיננו אוספים ביודעין מידע מקטינים מתחת לגיל [16/18 — להשלים]. The site and member area are not directed to children; we do not knowingly collect data from minors under [16/18 — to confirm].
12. תלונות
אם לדעתכם הפרנו את הדין, ניתן לפנות אלינו תחילה, וכן להגיש תלונה לרשות להגנת הפרטיות בישראל (gov.il), או — לתושבי האיחוד האירופי — לרשות המפקחת המקומית. If you believe we have breached the law, please contact us first; you may also complain to the Israeli Privacy Protection Authority, or — for EU residents — your local supervisory authority.
13. שינויים ויצירת קשר
נעדכן מדיניות זו מעת לעת; הגרסה המעודכנת תפורסם כאן עם תאריך חדש. לשאלות: office@benzvi-eng.co.il. We may update this policy from time to time; the current version is posted here with its date. Questions: office@benzvi-eng.co.il.