דלג לתוכן

Privacy Policy

Effective: 06/08/2026

NadlanCRM is a service operated by MenuWays Ltd., a private company registered in Israel (HP 514231802), registered address: 1 Snonit st., Caesarea 3079127, Israel. References to "we", "us" or "the Company" mean MenuWays Ltd.. References to "the Service" or "NadlanCRM" mean the SaaS product available at https://www.nadlancrm.co.il.

This policy describes how MenuWays Ltd. collects, uses, retains, and discloses personal data through NadlanCRM, including data we receive from Meta Platforms, Inc. through the Meta Marketing API.

Meta (Facebook) Integration

When a NadlanCRM customer ("the Agent") connects their Meta Business account to NadlanCRM, MenuWays Ltd. receives and processes the following data from Meta.

Data we collect:

  • Leads collected through Meta Lead Ads forms created by the Agent (full name, phone, email, and any custom field the Agent added to the form).
  • Identifiers and names of Facebook Pages owned by the Agent.
  • Ad account identifiers owned by the Agent.
  • Access tokens issued by Meta on the Agent's behalf.

How we use the data:

  • We forward leads in real time to the Agent's NadlanCRM environment.
  • We retain leads in the Agent's NadlanCRM for the duration of the subscription.
  • We do not use this data for any purpose other than forwarding it to the Agent who placed the ad.

Storage and security:

  • Lead data is held in the Agent's NadlanCRM environment on our production infrastructure in the United States. See Hosting, storage and security below.
  • Access tokens issued by Meta are encrypted by the application before they are written to our database.
  • We do not share Meta data with any third party other than the Agent.

Retention:

  • Lead data is retained for as long as the Agent's account is active, plus 30 days after cancellation.
  • The Agent may delete any lead from NadlanCRM at any time.

Your rights:

Disconnection:

An Agent may disconnect Meta from NadlanCRM at any time via account settings. We immediately revoke stored access tokens.

Legal basis:

  • Israeli Privacy Protection Law, 5741-1981
  • EU GDPR where applicable
  • Meta Platform Terms

Google Workspace Integration (Gmail and Calendar)

A NadlanCRM customer ("the Agent") may optionally connect their own Google account. Nothing is connected by default, and the Agent chooses which integrations to enable. This section describes the Google user data we receive, what we do with it, and every party it is shared with, transferred to, or disclosed to.

We never read the Agent's mailbox. We do not request permission to read Gmail, and the Service has no ability to do so. Sending is the only Gmail permission we ask for.

All permissions are requested together, in a single Google consent screen, the first time the Agent connects their account. That one approval covers both sending mail and calendar synchronisation. Google shows a checkbox for each permission and the Agent may approve one and decline the other; a declined permission simply means the corresponding feature does not operate.

Scopes we request, and why:

  • openid — confirms the identity of the Google account being connected. It grants no access to any Google service.
  • https://www.googleapis.com/auth/userinfo.email — reads the email address of the connected account, so the Service can show the Agent which account is connected and send mail from the correct address. We read the address only; we do not request the Agent's name or profile picture.
  • https://www.googleapis.com/auth/gmail.send — sends email on the Agent's behalf, so that mail the Agent sends from NadlanCRM comes from the Agent's own address rather than ours. This permission allows sending only. It does not permit reading, searching, listing or deleting any message in the mailbox.
  • https://www.googleapis.com/auth/calendar.events — two-way synchronisation of viewings, meetings and reminders with the Agent's primary calendar. This is the Events scope, not the full Calendar scope: it cannot create, delete or share calendars.

How we use the data:

  • Google user data is used only to provide the features above to the Agent whose account it is, and to that Agent's office where the office's own visibility settings allow it.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to build profiles for any purpose beyond the Agent's own CRM records.

With whom we share, transfer or disclose Google user data:

  • InterServer, Inc. (United States) — our hosting provider. Message text, calendar event details and encrypted OAuth tokens are stored in our application database on that infrastructure. See Hosting, storage and security.
  • Anthropic PBC (United States) — only where the Agent's office has explicitly enabled the optional AI features, and only for the two features that use them: classifying an incoming email as a potential enquiry, and extracting follow-up actions from a conversation. In those cases the text of the message is transmitted to Anthropic to be processed and a result returned. Anthropic does not use it to train its models, under the commercial terms in force between MenuWays Ltd. and Anthropic. AI features are off by default; see AI Processing.
  • No one else. Google user data is not shared with, transferred to, or disclosed to any other third party. It is not sold, rented, or made available to advertisers, data brokers, or other customers of NadlanCRM.
  • We may disclose data where we are legally compelled to do so, or where it is necessary to investigate abuse or a security incident affecting the Service.

Limited Use:

  • NadlanCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
  • We do not use Google Workspace APIs user data — raw, aggregated, or derived — to develop, train, or improve any foundational or generalized artificial intelligence or machine learning model. Where such data is transmitted to Anthropic PBC as described above, it is sent solely so that a result can be returned for the Agent, and is not used by Anthropic to train its models.

Retention and deletion:

  • Detected enquiries that the Agent has not acted on are purged automatically after the retention period configured for the Service.
  • Inbox scanning has been withdrawn and we no longer request permission to read Gmail. Where an Agent used it previously, disconnecting Google deletes the detected enquiries and the inbound mail we held only because we read the mailbox; the same deletion is available on demand from the Agent's email settings. Mail the Agent sent through NadlanCRM is kept: the Agent authored it, and it is the office's own record of what it told a client.
  • Correspondence threaded onto a contact card, and synchronised calendar events, are retained for as long as the Agent's account is active, and are deleted when the account and its office data are deleted.
  • The Agent may delete any individual record from NadlanCRM at any time.

Disconnection and revocation:

An Agent may disconnect Google from NadlanCRM at any time in account settings. On disconnection we call Google's token revocation endpoint to invalidate the grant, and we delete the stored tokens. The Agent may also revoke our access directly at https://myaccount.google.com/permissions.

AI Processing (Anthropic)

NadlanCRM offers optional features that process text using a large language model operated by Anthropic PBC (United States). These features are off by default. An office enables them explicitly and can switch them off at any time.

What is sent, and when:

  • Content the Agent writes or requests — property descriptions, translations, comparative market analysis, client summaries, drafts of emails and messages, and the in-product assistant. Sent when the Agent uses the feature.
  • Incoming email from unknown senders — sender address and name, subject and message body, sent only for messages that pass a relevance filter applied first in our own systems, in order to identify enquiries that should become leads.
  • Conversation content, where the office enables conversation action extraction — WhatsApp conversations held on the office’s own business number, and email correspondence with contacts already recorded in the CRM. Used to identify meetings, tasks and follow-ups that were agreed, and to present them to the Agent for approval.

What is not sent:

  • Full client, property or transaction records. Only the text being processed, and the names needed to attribute it.
  • Payment details, identity document numbers or authentication credentials.
  • Content from an office that has not enabled these features, or from an Agent who has opted out.

Processing terms:

  • Anthropic processes the text to return a result and does not use it to train its models, under the commercial terms in force between MenuWays Ltd. and Anthropic.
  • This processing takes place on Anthropic's infrastructure in the United States. Our own hosting is also in the United States, with InterServer in New Jersey (see Hosting, storage and security). Both involve a transfer of personal data outside Israel and the European Economic Area.
  • No automated decision produces a legal or similarly significant effect. Every suggestion is presented to the Agent, who accepts, edits or rejects it; nothing reaches a calendar, a task list or a client profile without that approval.

Controls:

  • The office manager enables or disables AI features for the whole office.
  • Conversation action extraction is enabled separately, per office, and the office chooses which channels are read.
  • An individual Agent may opt out, after which their conversations are not sent at all.

Retention:

  • Conversation content and the suggestions derived from it are stored in the office’s NadlanCRM environment for as long as the account is active, and are deleted with it.
  • Anthropic’s retention of submitted text is governed by its own terms and is not controlled by MenuWays Ltd.
  • An Agent may delete any conversation, message or suggestion from NadlanCRM at any time.

Hosting, storage and security

Where the Service runs:

  • NadlanCRM runs on infrastructure provided by InterServer, located at the 365 Data Centers NJ3 facility in Carlstadt, New Jersey, United States. The application database is held there.
  • Backups are held at a separate data centre in the United States.
  • Because MenuWays Ltd. is established in Israel and this infrastructure is in the United States, storing and processing data through the Service involves a transfer of personal data outside Israel and the European Economic Area.

Files and images:

  • Files uploaded to the Service — property photographs, contract documents and office logos — are stored on Cloudflare R2, part of Cloudflare’s global network, and are encrypted at rest by Cloudflare.
  • The storage region hint is set to Eastern Europe. This is a placement hint, not a jurisdiction restriction: no jurisdiction restriction is configured, so files may be held or served from Cloudflare locations in other countries.

Security measures:

  • Traffic between your browser and the Service is encrypted in transit using HTTPS. The Service sends HTTP Strict Transport Security with a duration of one year, including subdomains.
  • Access credentials and third-party access tokens — Google, Meta and WhatsApp OAuth tokens, mail server passwords, and integration secrets — are encrypted by the application before they are written to the database.
  • Each office’s data is separated at the database level, and access within an office follows the role of the signed-in Agent.

Data controller:

MenuWays Ltd. (HP 514231802)
1 Snonit st., Caesarea 3079127, Israel
Contact: [email protected]


מדיניות פרטיות

תאריך תוקף: 06/08/2026

NadlanCRM הוא שירות המופעל על ידי MenuWays Ltd., חברה פרטית בע"מ הרשומה בישראל (ח.פ. 514231802), כתובת רשומה: רחוב סנונית 1, קיסריה 3079127, ישראל. הפניות ל"אנחנו", "אותנו" או "החברה" מתייחסות ל-MenuWays Ltd.. הפניות ל"השירות" או ל-"NadlanCRM" מתייחסות למוצר ה-SaaS הזמין בכתובת https://www.nadlancrm.co.il.

מדיניות זו מתארת כיצד MenuWays Ltd. אוספת, משתמשת, שומרת ומגלה מידע אישי דרך NadlanCRM, לרבות מידע שאנחנו מקבלים מ-Meta Platforms, Inc. דרך Meta Marketing API.

אינטגרציה עם Meta (פייסבוק)

כאשר לקוח של NadlanCRM ("הסוכן") מחבר את חשבון Meta Business שלו ל-NadlanCRM, MenuWays Ltd. מקבלת ומעבדת את הנתונים הבאים מ-Meta.

נתונים שאנחנו אוספים:

  • פניות (לידים) שנאספו דרך טפסי Meta Lead Ads שיצר הסוכן (שם מלא, טלפון, דוא"ל, וכל שדה מותאם שהסוכן הוסיף לטופס).
  • מזהים ושמות של דפי פייסבוק בבעלות הסוכן.
  • מזהי חשבונות פרסום בבעלות הסוכן.
  • אסימוני גישה שהונפקו על ידי Meta בשם הסוכן.

כיצד אנחנו משתמשים בנתונים:

  • אנחנו מעבירים פניות בזמן אמת לסביבת ה-NadlanCRM של הסוכן.
  • אנחנו שומרים פניות ב-NadlanCRM של הסוכן למשך תקופת המנוי.
  • אנחנו לא משתמשים בנתונים אלה לאף מטרה אחרת מעבר להעברתם לסוכן שהציב את המודעה.

אחסון ואבטחה:

  • נתוני הפניות נשמרים בסביבת ה-NadlanCRM של הסוכן, על תשתית הייצור שלנו בארצות הברית. ראה אירוח, אחסון ואבטחה להלן.
  • אסימוני גישה שהונפקו על ידי Meta מוצפנים על ידי המערכת לפני שהם נכתבים למסד הנתונים שלנו.
  • אנחנו לא משתפים נתוני Meta עם אף צד שלישי מלבד הסוכן.

שמירה:

  • נתוני פניות נשמרים כל עוד חשבון הסוכן פעיל, ועוד 30 ימים לאחר ביטול.
  • הסוכן רשאי למחוק כל פנייה מ-NadlanCRM בכל עת.

הזכויות שלך:

ניתוק:

סוכן רשאי לנתק את Meta מ-NadlanCRM בכל עת דרך הגדרות החשבון. אנחנו מבטלים מיידית את אסימוני הגישה השמורים.

בסיס משפטי:

  • חוק הגנת הפרטיות, התשמ"א-1981
  • תקנת GDPR של האיחוד האירופי, כאשר רלוונטי
  • תנאי הפלטפורמה של Meta

אינטגרציה עם Google Workspace (Gmail ויומן)

לקוח NadlanCRM (״הסוכן״) רשאי לחבר את חשבון Google שלו, לפי בחירתו. שום דבר אינו מחובר כברירת מחדל, והסוכן בוחר אילו אינטגרציות להפעיל. סעיף זה מתאר אילו נתוני משתמש של Google אנחנו מקבלים, מה אנחנו עושים בהם, ועם מי הם משותפים, מועברים או נמסרים.

אנחנו לא קוראים את תיבת הדואר של הסוכן. איננו מבקשים הרשאה לקריאת Gmail, ולשירות אין יכולת לעשות זאת. ההרשאה היחידה שאנחנו מבקשים ב-Gmail היא שליחה.

כל ההרשאות מתבקשות יחד, במסך הסכמה אחד של Google, בפעם הראשונה שהסוכן מחבר את החשבון. אישור אחד מכסה גם שליחת מייל וגם סנכרון יומן. Google מציגה תיבת סימון לכל הרשאה, והסוכן יכול לאשר אחת ולסרב לשנייה; הרשאה שלא אושרה פירושה פשוט שהתכונה המתאימה לא פועלת.

ההרשאות שאנחנו מבקשים, ולמה:

  • openid — אימות הזהות של חשבון ה-Google שמתחבר. אינה מעניקה גישה לשום שירות של Google.
  • https://www.googleapis.com/auth/userinfo.email — קריאת כתובת המייל של החשבון המחובר, כדי שהשירות יוכל להציג לסוכן איזה חשבון מחובר ולשלוח מהכתובת הנכונה. אנחנו קוראים את הכתובת בלבד; איננו מבקשים את השם או את תמונת הפרופיל.
  • https://www.googleapis.com/auth/gmail.send — שליחת דואר בשם הסוכן, כדי שמייל שהסוכן שולח מ-NadlanCRM ייצא מהכתובת שלו ולא משלנו. הרשאה זו מאפשרת שליחה בלבד. היא אינה מאפשרת לקרוא, לחפש, לרשום או למחוק הודעות בתיבה.
  • https://www.googleapis.com/auth/calendar.events — סנכרון דו-כיווני של פגישות, צפיות ותזכורות עם היומן הראשי של הסוכן. זו הרשאת האירועים בלבד, לא הרשאת היומן המלאה: היא אינה מאפשרת ליצור, למחוק או לשתף יומנים.

איך אנחנו משתמשים בנתונים:

  • נתוני משתמש של Google משמשים אך ורק לאספקת התכונות שלמעלה לסוכן שהחשבון שלו, ולמשרד שלו במידה שהגדרות הנראות של המשרד מתירות זאת.
  • איננו משתמשים בנתוני Google לפרסום, ואיננו מוכרים אותם.
  • איננו משתמשים בנתוני Google לבניית פרופילים מעבר לרשומות ה-CRM של הסוכן עצמו.

עם מי אנחנו משתפים, מעבירים או מוסרים נתוני משתמש של Google:

  • InterServer, Inc. (ארצות הברית) — ספק האירוח שלנו. טקסט ההודעות, פרטי אירועי היומן ואסימוני OAuth מוצפנים נשמרים במסד הנתונים של המערכת על גבי תשתית זו. ראה אירוח, אחסון ואבטחה.
  • Anthropic PBC (ארצות הברית) — רק כאשר המשרד של הסוכן הפעיל במפורש את תכונות ה-AI האופציונליות, ורק לשתי התכונות שמשתמשות בהן: סיווג מייל נכנס כפנייה אפשרית, וחילוץ משימות המשך משיחה. במקרים אלה טקסט ההודעה נשלח ל-Anthropic לעיבוד ולהחזרת תוצאה. Anthropic אינה משתמשת בו לאימון המודלים שלה, בהתאם לתנאים המסחריים שבין MenuWays Ltd. לבין Anthropic. תכונות ה-AI כבויות כברירת מחדל; ראה עיבוד באמצעות AI.
  • אף אחד אחר. נתוני משתמש של Google אינם משותפים, מועברים או נמסרים לשום צד שלישי נוסף. הם אינם נמכרים, אינם מושכרים, ואינם זמינים למפרסמים, לסוחרי מידע או ללקוחות אחרים של NadlanCRM.
  • ייתכן שנמסור מידע כאשר אנו מחויבים לכך על פי דין, או כאשר הדבר נדרש לחקירת שימוש לרעה או אירוע אבטחה בשירות.

שימוש מוגבל (Limited Use):

  • השימוש של NadlanCRM במידע שהתקבל מממשקי Google, וההעברה שלו לכל יישום אחר, יעמדו במדיניות נתוני המשתמש של שירותי Google API, לרבות דרישות השימוש המוגבל.
  • השימוש בנתוני משתמש גולמיים או נגזרים שהתקבלו מממשקי Workspace יעמוד במדיניות נתוני המשתמש של Google, לרבות דרישות השימוש המוגבל.
  • איננו משתמשים בנתוני משתמש מממשקי Google Workspace — גולמיים, מצטברים או נגזרים — לפיתוח, אימון או שיפור של מודל בינה מלאכותית או למידת מכונה כללי או בסיסי. כאשר נתונים כאלה נשלחים ל-Anthropic PBC כמתואר לעיל, הם נשלחים אך ורק כדי להחזיר תוצאה עבור הסוכן, ואינם משמשים את Anthropic לאימון המודלים שלה.

שמירה ומחיקה:

  • פניות שזוהו ושהסוכן לא טיפל בהן נמחקות אוטומטית בתום תקופת השמירה המוגדרת בשירות.
  • סריקת התיבה הוסרה ואיננו מבקשים עוד הרשאה לקריאת Gmail. אצל סוכן שהשתמש בה בעבר, ניתוק Google מוחק את הפניות שזוהו ואת הדואר הנכנס שהחזקנו רק משום שקראנו את התיבה; אותה מחיקה זמינה גם ביוזמת הסוכן מהגדרות האימייל. דואר שהסוכן שלח דרך NadlanCRM נשמר: הסוכן כתב אותו, והוא הרישום של המשרד עצמו לגבי מה שנאמר ללקוח.
  • התכתבות ששויכה לכרטיס איש קשר, ואירועי יומן מסונכרנים, נשמרים כל עוד חשבון הסוכן פעיל, ונמחקים עם מחיקת החשבון ונתוני המשרד.
  • הסוכן רשאי למחוק כל רשומה מ-NadlanCRM בכל עת.

ניתוק וביטול הרשאה:

הסוכן רשאי לנתק את Google מ-NadlanCRM בכל עת דרך הגדרות החשבון. בעת הניתוק אנחנו פונים לנקודת הקצה של Google לביטול אסימונים ומבטלים את ההרשאה, ומוחקים את האסימונים השמורים. הסוכן יכול גם לבטל את הגישה שלנו ישירות בכתובת https://myaccount.google.com/permissions.

עיבוד באמצעות AI (Anthropic)

NadlanCRM מציעה תכונות אופציונליות שמעבדות טקסט באמצעות מודל שפה של Anthropic PBC (ארצות הברית). התכונות כבויות כברירת מחדל. משרד מפעיל אותן במפורש, ורשאי לכבות אותן בכל עת.

מה נשלח, ומתי:

  • טקסט שהסוכן כותב או מבקש — תיאורי נכסים, תרגומים, ניתוח עסקאות (CMA), סיכומי לקוח, טיוטות של מיילים והודעות, ועוזר הצ’אט במערכת. נשלח כשהסוכן משתמש בתכונה.
  • מיילים נכנסים משולחים לא מוכרים — כתובת ושם השולח, נושא ותוכן ההודעה, ורק עבור הודעות שעברו סינון ראשוני אצלנו, כדי לזהות פניות שראוי שיהפכו ללידים.
  • תוכן שיחות, במשרד שהפעיל זיהוי פעולות מהשיחות — שיחות וואטסאפ שמתנהלות במספר העסקי של המשרד, והתכתבויות אימייל עם אנשי קשר ששמורים כבר במערכת. משמש לזיהוי פגישות, משימות ומעקבים שסוכמו, ולהצגתם לסוכן לאישור.

מה לא נשלח:

  • כרטיסי לקוח, נכס או עסקה במלואם. נשלח רק הטקסט שמעובד, והשמות הדרושים לשיוך שלו.
  • פרטי תשלום, מספרי תעודת זהות או פרטי התחברות.
  • תוכן ממשרד שלא הפעיל את התכונות, או מסוכן שביטל אותן עבור עצמו.

תנאי העיבוד:

  • Anthropic מעבדת את הטקסט כדי להחזיר תוצאה, ואינה משתמשת בו לאימון המודלים שלה, בהתאם לתנאים המסחריים שבין MenuWays Ltd. לבין Anthropic.
  • העיבוד הזה מתבצע בתשתית של Anthropic בארצות הברית. גם האירוח שלנו נמצא בארצות הברית, אצל InterServer בניו ג׳רזי (ראה אירוח, אחסון ואבטחה). בשני המקרים מדובר בהעברת מידע אישי אל מחוץ לישראל ולאזור הכלכלי האירופי.
  • אין החלטה אוטומטית בעלת תוצאה משפטית או השפעה דומה. כל הצעה מוצגת לסוכן, שמאשר, עורך או דוחה אותה; שום דבר לא נכנס ליומן, לרשימת משימות או לכרטיס לקוח בלי האישור הזה.

שליטה:

  • מנהל המשרד מפעיל או מכבה את תכונות ה-AI עבור כל המשרד.
  • זיהוי פעולות מהשיחות מופעל בנפרד, לכל משרד, והמשרד בוחר אילו ערוצים נקראים.
  • סוכן יחיד רשאי לבטל את הסריקה עבור עצמו, ואז השיחות שלו אינן נשלחות כלל.

שמירת מידע:

  • תוכן השיחות וההצעות שנגזרו ממנו נשמרים בסביבת ה-NadlanCRM של המשרד כל עוד החשבון פעיל, ונמחקים יחד איתו.
  • שמירת הטקסט אצל Anthropic כפופה לתנאים שלה ואינה בשליטת MenuWays Ltd.
  • הסוכן רשאי למחוק כל שיחה, הודעה או הצעה מ-NadlanCRM בכל עת.

אירוח, אחסון ואבטחה

היכן השירות פועל:

  • NadlanCRM פועלת על תשתית של InterServer, במתקן 365 Data Centers NJ3 בקרלסטדט, ניו ג׳רזי, ארצות הברית. מסד הנתונים של האפליקציה נמצא שם.
  • גיבויים נשמרים במרכז נתונים נפרד בארצות הברית.
  • מאחר ש-MenuWays Ltd. רשומה בישראל והתשתית נמצאת בארצות הברית, אחסון המידע ועיבודו בשירות כרוכים בהעברת מידע אישי אל מחוץ לישראל ולאזור הכלכלי האירופי.

קבצים ותמונות:

  • קבצים שמועלים לשירות — תמונות נכסים, מסמכי חוזה ולוגואים של משרדים — נשמרים ב-Cloudflare R2, חלק מהרשת הגלובלית של Cloudflare, ומוצפנים במנוחה על ידי Cloudflare.
  • רמז אזור האחסון מוגדר למזרח אירופה. זהו רמז מיקום בלבד, לא הגבלת תחום שיפוט: לא הוגדרה הגבלת תחום שיפוט, ולכן ייתכן שקבצים יישמרו או יוגשו ממיקומים של Cloudflare במדינות אחרות.

אמצעי אבטחה:

  • התעבורה בין הדפדפן שלך לבין השירות מוצפנת בהעברה באמצעות HTTPS. השירות שולח כותרת HSTS לתקופה של שנה, כולל תת-דומיינים.
  • פרטי התחברות ואסימוני גישה של צדדים שלישיים — אסימוני OAuth של Google, Meta ו-WhatsApp, סיסמאות של שרתי דואר, וסודות אינטגרציה — מוצפנים על ידי המערכת לפני שהם נכתבים למסד הנתונים.
  • הנתונים של כל משרד מופרדים ברמת מסד הנתונים, והגישה בתוך המשרד נגזרת מתפקיד הסוכן המחובר.

בעל מאגר המידע:

MenuWays Ltd. (ח.פ. 514231802)
רחוב סנונית 1, קיסריה 3079127, ישראל
יצירת קשר: [email protected]