מדיניות פרטיות
עודכן לאחרונה: 29 ביולי 2026
קפיטל סולושן סוכנות לביטוח (2023) בע"מ, ח.פ 516850534 (להלן: "אנחנו", "החברה" או "Agento") מפעילה מערכת CRM ייעודית לסוכנויות ביטוח ולסוכני ביטוח ופנסיה (להלן: "המערכת"), הזמינה באתר agento.co.il ובתת-הדומיינים שלו. מדיניות פרטיות זו מסבירה איזה מידע אישי נאסף במסגרת המערכת, לאילו מטרות הוא משמש, עם מי הוא משותף, כיצד הוא מאובטח, ואילו זכויות עומדות לכם.
שתי קטגוריות של אנשים - ושני תפקידים שונים שלנו
ההבחנה הזו היא הבסיס לכל המסמך:
א. משתמשי המערכת - הסוכנות, בעליה ועובדיה, המשתמשים במערכת. ביחס למידע האישי שלהם אנחנו בעלי השליטה במאגר, ומדיניות זו חלה עליו במלואה.
ב. לקוחות הסוכנות - המבוטחים והעמיתים שפרטיהם מנוהלים במערכת על ידי הסוכנות. ביחס אליהם הסוכנות היא בעלת המאגר ואנחנו פועלים כמחזיק ומעבד מידע מטעמה בלבד, לפי הוראותיה ולפי ההסכם שנחתם עמה. איננו עושים במידע זה שימוש עצמאי, איננו מוכרים אותו, ואיננו פונים ללקוחות הסוכנות בשמנו או מטעמנו. פנייה בנוגע למידע של לקוח סוכנות מופנית בראש ובראשונה לסוכנות שאיתה הוא מתנהל.
1. הגדרות
"מידע אישי" - מידע כהגדרתו בחוק הגנת הפרטיות, התשמ"א-1981, המתייחס לאדם מזוהה או לאדם הניתן לזיהוי, לרבות שם, מספר זהות, פרטי התקשרות, נתוני מיקום ומזהים מקוונים.
"מידע רגיש" - מידע אישי שגילויו עלול לפגוע בפרטיות בעוצמה גבוהה, ובכלל זה מידע על מצב בריאותי, מצב כלכלי, החזקות פיננסיות ופנסיוניות, והרגלי צריכה של מוצרי ביטוח.
"עיבוד" - כל פעולה במידע, לרבות איסוף, שמירה, עיון, שינוי, שיתוף, העברה ומחיקה.
2. הסכמה, מסירת מידע ותחולה
אין חובה חוקית למסור לנו מידע, ומסירתו נעשית מרצון. עם זאת, בלא מידע מסוים לא נוכל לספק את השירות - למשל, בלא פרטי התקשרות לא ניתן לפתוח חשבון משתמש, ובלא נתוני לקוחות לא ניתן לנהל תיק ביטוח.
השימוש במערכת מהווה הסכמה למדיניות זו. השימוש מיועד לבגירים (מגיל 18) הפועלים במסגרת עיסוקם. ייתכן שבמסגרת נתוני הלקוחות שהסוכנות מנהלת יופיעו פרטיהם של קטינים (למשל מוטבים בפוליסה); מידע כזה מעובד על ידינו אך ורק מטעם הסוכנות ובאחריותה.
3. מידע שאתם מוסרים לנו ישירות
- פרטי חשבון והרשאה: שם מלא, כתובת דוא"ל, מספר טלפון, תפקיד ומחלקה בסוכנות, שם משתמש וסיסמה (מאוחסנת בגיבוב חד-כיווני בלבד), והגדרות אימות דו-שלבי.
- פרטי הסוכנות: שם הסוכנות, מספר סוכן ומספרי סוכן מול חברות הביטוח, לוגו, פרטי התקשרות וחתימה גרפית לשימוש במסמכים.
- פרטי חיוב: ככל שנדרשים לצורך ההתקשרות. פרטי כרטיס אשראי אינם נשמרים אצלנו ומעובדים אצל חברת סליקה מורשית בלבד.
- פניות ותמיכה: תוכן פניות, צרופות והתכתבויות מול התמיכה.
- נתוני לקוחות שאתם מזינים: פרטי המבוטחים והעמיתים שאתם מנהלים - שם, מספר זהות, תאריך לידה, פרטי התקשרות, מצב משפחתי, עיסוק, נתוני שכר והכנסה, פוליסות והחזקות פנסיוניות, מוטבים, מסמכים סרוקים, חתימות, הערות ותיעוד שיחות.
4. מידע שנאסף שלא ישירות מכם
- ממקורות ביטוחיים ופנסיוניים מוסדרים: בהתאם להרשאות ולייפויי הכוח שהלקוח נתן לסוכנות, המערכת קולטת נתונים מהמסלקה הפנסיונית, ממאגר "הר הביטוח", מחברות הביטוח ובתי ההשקעות, ומקבצי מבנה אחיד שמופקים על ידם. הנתונים כוללים החזקות, יתרות, הפקדות, כיסויים ביטוחיים, דמי ניהול ומצב פוליסות.
- מקבצים שאתם מעלים: קבצי עמלות, קבצי הפקה, דוחות וקבצי מסלקה - מהם נגזרים נתונים לתיקי הלקוחות.
- נתוני שימוש טכניים: כתובת IP, סוג ודגם המכשיר, מערכת הפעלה, סוג הדפדפן, חותמות זמן, עמודים ופעולות במערכת, ונתוני התחברות וניתוק. נתונים אלה נאספים לצורכי אבטחה, תפעול ואיתור תקלות.
- יומן ביקורת: המערכת מתעדת פעולות מהותיות (התחברות, כשלי התחברות, שינוי הרשאות, צפייה ועריכה של מידע רגיש, ייצוא נתונים). התיעוד הזה הוא אמצעי אבטחה, והוא עשוי לשמש כראיה בבירור אירוע אבטחה.
5. המטרות שלשמן המידע משמש
- אספקת המערכת ותפעולה, לרבות ניהול תיקי לקוחות, השוואות, סימולציות, מסמכי הנמקה, טפסים וחתימות דיגיטליות.
- ניהול חשבון המשתמש, זיהוי, הרשאות ואבטחת גישה.
- תקשורת תפעולית מולכם: הודעות מערכת, תזכורות, התראות ועדכוני שירות.
- תמיכה טכנית וטיפול בפניות ובתקלות.
- שיפור המערכת, פיתוח יכולות חדשות ואבחון בעיות ביצועים.
- אבטחת מידע, מניעת שימוש לרעה, זיהוי הונאות ועמידה בהוראות הדין.
- קיום חובות חוקיות, לרבות חובות דיווח ושמירת מסמכים החלות על פעילות בתחום הביטוח והפנסיה.
- הגנה על זכויותינו המשפטיות ובירור מחלוקות.
איננו מוכרים מידע אישי. איננו עושים שימוש בנתוני הלקוחות של סוכנות אחת לטובת סוכנות אחרת. הפרדת הנתונים בין סוכנויות היא עיקרון ארכיטקטוני במערכת, ולא רק הגדרת הרשאות.
6. תקשורת עם לקוחות דרך המערכת
המערכת מאפשרת לסוכנות לתקשר עם לקוחותיה בכמה ערוצים. בכל אחד מהם המידע העובר הוא באחריות הסוכנות, ואנחנו משמשים צינור טכני:
- WhatsApp: התקשורת מתבצעת דרך WhatsApp Business Platform של Meta. תוכן ההודעות, מספרי הטלפון, הקבצים והמטא-דאטה של השיחה עוברים דרך שרתי Meta וכפופים גם למדיניות הפרטיות של Meta ולתנאי WhatsApp Business. הודעות יזומות מחוץ לחלון השירות בן 24 השעות נשלחות באמצעות תבניות שאושרו מראש על ידי Meta. אנו שומרים את היסטוריית השיחה בבסיס הנתונים של הסוכנות כדי שתהיה זמינה בממשק.
- מסרונים (SMS): נשלחים באמצעות חברת 019 מובייל בע"מ, ספק מורשה בישראל. לספק נמסרים מספר הטלפון ותוכן ההודעה בלבד.
- דואר אלקטרוני: נשלח ונקלט דרך שרתי דואר, לרבות תיבות שהסוכנות מחברת למערכת. תוכן ההודעות והצרופות נשמר בבסיס הנתונים של הסוכנות.
- אזור אישי ללקוח: ככל שהסוכנות מפעילה אותו, הלקוח מזדהה בכניסה חד-פעמית ורואה את המידע שהסוכנות בחרה לחשוף לו בלבד.
7. עיבוד באמצעות בינה מלאכותית
חלק מיכולות המערכת נשענות על מודל בינה מלאכותית של ספק חיצוני - Anthropic PBC (מודל Claude) - לצורך:
- חילוץ נתונים ממסמכים: כאשר מתקבל מסמך מלקוח בערוץ WhatsApp או באזור האישי, או כאשר מועלה מסמך למערכת, תוכן המסמך עשוי להישלח לספק המודל כדי לחלץ ממנו נתונים באופן אוטומטי - למשל פרטי חשבונית, או תמצית מסמך רפואי בתביעת בריאות. במקרים אלה עשוי לעבור גם מידע רגיש, לרבות מידע בריאותי.
- קריאת הסכמי עמלות: קובצי הסכם שמעלה הסוכנות נשלחים לספק המודל כדי לחלץ מהם את טבלת שיעורי העמלה, לאישור ידני של המשתמש.
- לשונית הידע וניסוח תוכן: שאלות ובקשות ניסוח שמזין המשתמש.
הצהרה: אין אימון מודלים על נתוני לקוחות. ההתקשרות שלנו עם ספק המודל אוסרת עליו במפורש לעשות שימוש בתוכן שאנו שולחים לו כדי ליצור, לפתח, לאמן או לשפר מודלים או מערכות בינה מלאכותית כלשהן - שלו או של אחרים. האיסור חל גם על גרסאות מצטברות, אנונימיות או נגזרות של המידע. תוכן הלקוחות מוגדר בהסכם כמידע סודי של הלקוח.
ביחס למידע שמקורו בערוץ WhatsApp, איסור זה הוא גם דרישה מפורשת של תנאי WhatsApp Business Platform, ואנו מקיימים אותה.
העיבוד הוא נקודתי ולצורך הפעולה המבוקשת בלבד: הקטע הרלוונטי נשלח, התוצאה מוחזרת ונשמרת אצלנו, והמסמך אינו נשמר אצל ספק המודל מעבר לנדרש להשלמת הבקשה. סוכנות רשאית לבקש מאיתנו לכבות את יכולות החילוץ האוטומטי בחשבונה, ואז מסמכים ייקלטו ויישמרו ללא כל עיבוד אוטומטי.
8. שיתוף מידע עם צדדים שלישיים
איננו מעבירים מידע אישי לצדדים שלישיים אלא במקרים הבאים:
- נותני שירות מטעמנו ("מעבדי משנה") הנדרשים לתפעול המערכת: ספקי תשתית ואחסון ענן, ספקי דואר, ספק סליקת מסרונים, Meta עבור ערוץ ה-WhatsApp, ספק מודל הבינה המלאכותית (סעיף 7), וספק סליקת אשראי. ספקים אלה מחויבים בהתחייבויות סודיות ואבטחת מידע, ורשאים לעבד את המידע רק לפי הוראתנו ולמטרות שלשמן נמסר.
- גופים מוסדיים וחברות ביטוח - כאשר אתם, המשתמשים, יוזמים העברת טופס, בקשה או מסמך אליהם.
- מכוח הדין - בהתאם לצו שיפוטי, דרישת רשות מוסמכת או חובה חוקית.
- הגנה על זכויות - בהליך משפטי, לצורך בירור מחלוקת, או כדי למנוע פגיעה בגוף או ברכוש.
- שינוי מבני - במקרה של מיזוג, רכישה, גיוס הון או העברת פעילות, בכפוף לכך שהגורם הנעבר יקבל על עצמו את התחייבויות מדיניות זו.
אנו עשויים לעשות שימוש במידע סטטיסטי מצטבר ואנונימי, שאינו מאפשר זיהוי של אדם או של סוכנות, לצורך שיפור המערכת ולצרכים עסקיים.
9. מיקום השרתים והעברת מידע אל מחוץ לישראל
המערכת, בסיסי הנתונים, המסמכים והגיבויים מאוחסנים בישראל, בתשתית הענן של Oracle Cloud Infrastructure באזור הישראלי. זהו מקום השמירה של המידע בכללותו.
עם זאת, חלק מהשירותים הנקודתיים המפורטים בסעיף 8 מופעלים על ידי ספקים הפועלים גם מחוץ לישראל, ולכן פריטי מידע מסוימים עוברים אליהם לצורך אותה פעולה בלבד: תוכן הודעות WhatsApp עובר דרך שרתי Meta, ומסמכים הנשלחים לחילוץ אוטומטי עוברים לספק מודל הבינה המלאכותית בארצות הברית. העברות אלה נעשות בהתאם להוראות הדין הישראלי ותוך התקשרות חוזית המחייבת את הספק בסטנדרטים של סודיות ואבטחת מידע.
10. תקופת שמירת המידע
מידע נשמר כל עוד חשבון הסוכנות פעיל ולמשך הזמן הדרוש למטרות שלשמן נאסף. לאחר סיום ההתקשרות, המידע נשמר לתקופה נוספת הנדרשת לפי דין - ובכלל זה חובות שמירת מסמכים החלות על פעילות ביטוחית ופנסיונית - ולאחר מכן נמחק או עובר אנונימיזציה. גיבויים נשמרים לתקופה מוגבלת ומוחלפים במחזוריות.
מחיקה מלאה עם סיום ההתקשרות: סוכנות רשאית לבקש, בסיום ההתקשרות, את מחיקת מלוא המידע שבחשבונה, ובכלל זה נתוני הלקוחות שניהלה במערכת. נבצע את המחיקה למעט מידע שקיימת חובה חוקית לשמרו, ונמסור על כך אישור בכתב. לפני המחיקה ניתן לקבל עותק של המידע בפורמט נגיש. בקשה למחיקת מידע של אדם בודד מטופלת כמפורט בסעיף הזכויות ובעמוד מחיקת נתונים.
11. אבטחת מידע
אנו מיישמים אמצעי הגנה טכניים וארגוניים המותאמים לרגישות המידע, ובהם:
- הצפנת התעבורה בין הדפדפן לשרת (TLS), והצפנה של שדות מזהים ורגישים בבסיס הנתונים.
- הפרדה לוגית מלאה בין נתוני סוכנויות שונות.
- ניהול הרשאות מבוסס תפקיד, ובקרת גישה ברמת הלקוח הבודד ובמסגרת קבוצות לקוחות.
- אימות דו-שלבי, מדיניות סיסמאות, הגבלת קצב ניסיונות התחברות ונעילת חשבון לאחר כשלים חוזרים.
- יומן ביקורת לפעולות רגישות והתראות על אירועים חריגים.
- גיבויים מוצפנים, לרבות גיבוי מחוץ לאתר, ובדיקות שחזור תקופתיות.
- עדכוני אבטחה שוטפים לתשתית ולרכיבי התוכנה.
אף מערכת אינה חסינה לחלוטין. אם ייוודע לנו על אירוע אבטחה שעלול לפגוע בפרטיותכם, נפעל לטיפול בו ולדיווח בהתאם לחובות הדין.
12. עוגיות (Cookies)
המערכת עושה שימוש בעוגיות ובאחסון מקומי בדפדפן לצורך תפעולה בלבד: שמירת מצב ההתחברות (טוקן הזדהות), שמירת העדפות תצוגה, ואבטחה. אלה עוגיות חיוניות ותפקודיות, ובלעדיהן לא ניתן להתחבר למערכת. איננו עושים שימוש בעוגיות שיווק או פרסום, ואיננו מפעילים כלי אנליטיקה או מעקב של צד שלישי - לא Google Analytics, לא פיקסלים ולא משואות רשת. ניתן לחסום או למחוק עוגיות דרך הגדרות הדפדפן, אך חסימה תמנע את השימוש במערכת.
13. דיוור ופניות שיווקיות
אנו שולחים לכם, כמשתמשי המערכת, הודעות תפעוליות הנוגעות לשירות: עדכוני מערכת, תזכורות, התראות והודעות תמיכה. אלה אינן דיוור שיווקי והן ממשיכות להישלח כל עוד החשבון פעיל. איננו מקיימים דיוור שיווקי למשתמשי המערכת. ככל שנתחיל בכך בעתיד, הדבר ייעשה בהתאם להוראות חוק התקשורת (בזק ושידורים), התשמ"ב-1982, ובכפוף להסכמה מראש ולאפשרות הסרה בכל עת.
14. הזכויות שלכם
בהתאם לחוק הגנת הפרטיות, התשמ"א-1981 ולתקנות מכוחו, עומדות לכם הזכויות הבאות:
- עיון: לדעת אם מוחזק אצלנו מידע עליכם ולעיין בו.
- תיקון: לבקש לתקן מידע שאינו נכון, שלם, ברור או מעודכן.
- מחיקה: לבקש למחוק מידע, בכפוף לחובות שמירה על פי דין.
- הסרה מדיוור: לבקש להפסיק קבלת פניות שיווקיות.
נטפל בבקשה תוך 30 ימים. אם המידע שלכם מנוהל במערכת על ידי סוכנות, נפנה את הבקשה לסוכנות שהיא בעלת המאגר, ונסייע לה לטפל בה. לבירור זהות המבקש נבקש פרטים מזהים, כדי שלא נמסור מידע לגורם שאינו זכאי לו.
15. שינויים במדיניות
אנו רשאים לעדכן מדיניות זו מעת לעת, בהתאם לשינויים במערכת, בשירותים או בדין. הנוסח המחייב הוא זה המפורסם בעמוד זה, ותאריך העדכון האחרון מופיע בראשו. שינוי מהותי יובא לידיעת משתמשי המערכת.
16. יצירת קשר
בכל שאלה בנוגע למדיניות זו, ולבקשות עיון, תיקון או מחיקה:
להוראות מחיקת נתונים ראו את עמוד מחיקת נתונים.
Privacy Policy
Last updated: July 29, 2026
Capital Solution Insurance Agency (2023) Ltd., Company No. 516850534 ("we", "us", or "Agento") operates a CRM platform built for insurance and pension agencies and their agents (the "Platform"), available at agento.co.il and its sub-domains. This policy explains what personal information the Platform collects, why, who it is shared with, how it is protected, and what rights you have.
Two groups of people, two different roles for us
This distinction underpins the whole document:
A. Platform users - the agency, its owners and its staff. For their personal information we are the data controller, and this policy applies to it in full.
B. The agency's clients - the insured individuals and pension members whose details the agency manages in the Platform. For them the agency is the controller and we act solely as a processor on its behalf, under its instructions and our agreement with it. We make no independent use of that information, we do not sell it, and we never approach an agency's clients in our own name. A request about an agency client's data is directed first to the agency they deal with.
1. Definitions
"Personal information" - information as defined in the Israeli Protection of Privacy Law, 5741-1981, relating to an identified or identifiable person, including name, ID number, contact details, location data and online identifiers.
"Sensitive information" - personal information whose disclosure would materially harm privacy, including health status, financial status, financial and pension holdings, and insurance purchasing history.
"Processing" - any operation on information, including collection, storage, access, modification, sharing, transfer and deletion.
2. Consent, provision of information, and scope
You are under no legal obligation to give us information, and you do so voluntarily. Without certain information, however, we cannot provide the service - without contact details no account can be opened, and without client data no insurance portfolio can be managed.
Using the Platform constitutes acceptance of this policy. The Platform is intended for adults (18+) acting in a professional capacity. Client data managed by an agency may include details of minors (for example, policy beneficiaries); we process such data solely on the agency's behalf and under its responsibility.
3. Information you provide directly
- Account and access details: full name, email address, phone number, role and department within the agency, username and password (stored only as a one-way hash), and two-factor authentication settings.
- Agency details: agency name, agent number and carrier-issued agent numbers, logo, contact details, and a graphical signature used in documents.
- Billing details: as required for the engagement. Card details are not stored by us and are processed only by a licensed payment processor.
- Support enquiries: the content of enquiries, attachments and correspondence with support.
- Client data you enter: details of the insured individuals and members you manage - name, ID number, date of birth, contact details, marital status, occupation, salary and income data, policies and pension holdings, beneficiaries, scanned documents, signatures, notes and call records.
4. Information collected other than directly from you
- From regulated insurance and pension sources: subject to the authorisations and powers of attorney the client granted the agency, the Platform ingests data from the Israeli Pension Clearing House (Mislaka), the "Har HaBituach" insurance registry, insurers and investment houses, and the standard-format files they issue. This covers holdings, balances, deposits, insurance cover, management fees and policy status.
- From files you upload: commission files, production files, reports and clearing-house archives, from which client portfolio data is derived.
- Technical usage data: IP address, device type and model, operating system, browser type, timestamps, pages and actions within the Platform, and sign-in and sign-out events. This is collected for security, operations and troubleshooting.
- Audit log: the Platform records material actions (sign-in, failed sign-in, permission changes, viewing and editing of sensitive data, data export). This log is a security control and may serve as evidence when investigating a security incident.
5. Purposes for which information is used
- Providing and operating the Platform, including client portfolio management, comparisons, simulations, suitability documents, forms and digital signatures.
- Managing user accounts, identification, permissions and access security.
- Operational communication with you: system messages, reminders, alerts and service updates.
- Technical support and handling enquiries and faults.
- Improving the Platform, developing new capabilities and diagnosing performance issues.
- Information security, prevention of misuse, fraud detection and compliance with the law.
- Meeting legal obligations, including reporting and record-retention duties applicable to insurance and pension activity.
- Protecting our legal rights and resolving disputes.
We do not sell personal information. We do not use one agency's client data for the benefit of another. Separation of data between agencies is an architectural principle of the Platform, not merely a permission setting.
6. Communicating with clients through the Platform
The Platform lets an agency communicate with its clients over several channels. In each of them the content is the agency's responsibility and we act as a technical conduit:
- WhatsApp: communication runs over Meta's WhatsApp Business Platform. Message content, phone numbers, files and conversation metadata pass through Meta's servers and are also subject to Meta's privacy policy and the WhatsApp Business terms. Messages initiated outside the 24-hour service window are sent using templates pre-approved by Meta. We store the conversation history in the agency's database so it is available in the interface.
- SMS: sent through 019 Mobile Ltd., a licensed Israeli provider, which receives only the phone number and the message content.
- Email: sent and received through mail servers, including mailboxes the agency connects to the Platform. Message content and attachments are stored in the agency's database.
- Client portal: where the agency enables it, the client authenticates with a one-time login and sees only the information the agency chose to expose.
7. Processing using artificial intelligence
Some Platform capabilities rely on a third-party AI model provider - Anthropic PBC (the Claude model) - for:
- Extracting data from documents: when a document arrives from a client over the WhatsApp channel or the client portal, or is uploaded to the Platform, its contents may be sent to the model provider to extract data automatically - for example invoice details, or a summary of a medical document in a health claim. Sensitive information, including health information, may be included in such a transfer.
- Reading commission agreements: agreement files uploaded by the agency are sent to the model provider to extract the table of commission rates, for the user to approve manually.
- The knowledge tab and content drafting: questions and drafting requests entered by the user.
Declaration: no model training on customer data. Our agreement with the model provider expressly prohibits it from using the content we send in order to create, develop, train or improve any AI models or systems - its own or anyone else's. The prohibition extends to aggregated, anonymised and derived forms of the information. Customer content is defined in that agreement as the customer's confidential information.
For information originating in the WhatsApp channel, this prohibition is also an express requirement of the WhatsApp Business Platform terms, and we comply with it.
Processing is one-off and solely for the requested operation: the relevant excerpt is sent, the result is returned and stored by us, and the document is not retained by the model provider beyond what is needed to complete the request. An agency may ask us to switch off automatic extraction for its account, in which case documents are received and stored with no automated processing at all.
8. Sharing information with third parties
We do not transfer personal information to third parties except as follows:
- Service providers acting for us ("sub-processors") required to operate the Platform: cloud infrastructure and storage providers, mail providers, the SMS provider, Meta for the WhatsApp channel, the AI model provider (section 7), and the payment processor. These providers are bound by confidentiality and security undertakings and may process the information only on our instructions and for the purpose for which it was given.
- Institutional bodies and insurers - when you, the user, initiate the transfer of a form, request or document to them.
- As required by law - pursuant to a court order, a demand from a competent authority, or a legal obligation.
- Protection of rights - in legal proceedings, to resolve a dispute, or to prevent harm to person or property.
- Corporate transactions - in a merger, acquisition, financing round or transfer of operations, provided the transferee assumes the obligations in this policy.
We may use aggregated, anonymised statistical information that cannot identify a person or an agency, to improve the Platform and for business purposes.
9. Server location and transfers outside Israel
The Platform, its databases, documents and backups are stored in Israel, on Oracle Cloud Infrastructure in the Israeli region. That is where the information resides as a whole.
Certain discrete services listed in section 8 are, however, operated by providers that also operate outside Israel, so specific items of information travel to them for that operation alone: WhatsApp message content passes through Meta's servers, and documents sent for automatic extraction pass to the AI model provider in the United States. Such transfers are made in accordance with Israeli law and under contractual arrangements binding the provider to confidentiality and information-security standards.
10. Retention
Information is retained while the agency's account is active and for as long as needed for the purposes for which it was collected. After the engagement ends, information is retained for the further period required by law - including record-retention duties applicable to insurance and pension activity - and is then deleted or anonymised. Backups are retained for a limited period and rotated.
Full deletion on termination: on ending the engagement, an agency may request deletion of all information in its account, including the client data it managed in the Platform. We will carry out the deletion except for information we are legally required to retain, and will confirm it in writing. A copy of the information in an accessible format may be obtained before deletion. A deletion request concerning an individual is handled as described in the rights section and on the data deletion page.
11. Information security
We apply technical and organisational safeguards proportionate to the sensitivity of the information, including:
- Encryption of traffic between browser and server (TLS), and encryption of identifying and sensitive fields in the database.
- Full logical separation between different agencies' data.
- Role-based permissions, plus access control at the level of the individual client and of client groups.
- Two-factor authentication, password policy, rate limiting of sign-in attempts and account lockout after repeated failures.
- An audit log of sensitive actions and alerting on anomalous events.
- Encrypted backups, including off-site copies, with periodic restore testing.
- Ongoing security updates to infrastructure and software components.
No system is entirely immune. If we become aware of a security incident that may affect your privacy, we will act to contain it and to report it as the law requires.
12. Cookies
The Platform uses cookies and browser local storage for its operation only: keeping you signed in (authentication token), storing display preferences, and security. These are essential and functional cookies, and without them you cannot sign in. We use no marketing or advertising cookies, and run no third-party analytics or tracking tools - no Google Analytics, no pixels, no web beacons. You can block or delete cookies through your browser settings, but doing so will prevent use of the Platform.
13. Marketing communications
We send you, as a Platform user, operational messages relating to the service: system updates, reminders, alerts and support messages. These are not marketing and continue while the account is active. We do not run marketing campaigns to Platform users. Should we do so in future, it will be in accordance with the Israeli Communications (Telecommunications and Broadcasts) Law, 5742-1982, subject to prior consent and with an opt-out available at any time.
14. Your rights
Under the Protection of Privacy Law, 5741-1981 and its regulations, you have the right to:
- Access: learn whether we hold information about you and review it.
- Rectification: request correction of information that is incorrect, incomplete, unclear or out of date.
- Deletion: request deletion of information, subject to retention duties imposed by law.
- Opt out: request that marketing communications stop.
We will handle a request within 30 days. If your information is managed in the Platform by an agency, we will refer the request to that agency as the controller of the database and assist it in handling it. We will ask for identifying details before responding, so that information is never disclosed to someone not entitled to it.
15. Changes to this policy
We may update this policy from time to time as the Platform, the services or the law change. The binding version is the one published on this page, and the date of the last update appears at the top. Material changes will be brought to users' attention.
16. Contact us
For any question about this policy, and for access, rectification or deletion requests:
- Company: Capital Solution Insurance Agency (2023) Ltd., Company No. 516850534
- Privacy officer: Itay Varsano - itay@cptl.co.il
- Privacy enquiries: privacy@agento.co.il
- Phone: 054-7477889
- Address: 11 Moshe Levi St., Rishon LeZion, Israel
- Website: agento.co.il
For data deletion instructions see the data deletion page.