נאור אהרוניNaor Aharoni

מדיניות פרטיות

מפעיל: Naor Aharoni — אוטומציות ומערכות CRM · תאריך תחילה: 11 ביוני 2026 · עודכן לאחרונה: 11 ביוני 2026

מדיניות זו מתארת כיצד Naor Aharoni — אוטומציות ומערכות CRM ("אנחנו", "השירות") אוסף, משתמש ומגן על מידע — במסגרת מתן שירותי בניית מערכות CRM ואוטומציות עסקיות, ובמסגרת המערכות שאנו מפעילים עבור לקוחותינו. היא כוללת פירוט מלא של גישתנו לנתוני Google (Calendar/Drive) ולתקשורת דרך WhatsApp.

מדיניות זו חלה על כלל המערכות שאנו מפעילים. נכון להיום המערכת הפעילה היא “Hila Bartov CRM” (עבור סוכנות “אורגני על סטרואידים”).

1. איזה מידע אנחנו אוספים

2. כיצד אנחנו משתמשים במידע

3. נתוני Google שאליהם אנו ניגשים — לפי הרשאה (scope)

בעת חיבור חשבון Google, המערכת מבקשת את ההרשאות הבאות בלבד. לכל אחת — מה ניגשים, למה, ואיך משתמשים:

https://www.googleapis.com/auth/calendar.readonlySensitive

מה: קריאה בלבד מיומן Google — אירועים וזמני פנוי/תפוס.

למה: הצגת פגישות עתידיות בכרטיס-הלקוח + חישוב סלוטים פנויים ללינקי קביעת-פגישות.

איך: קריאת אירועים בחלון זמן ושיבוץ לכרטיס-לקוח לפי מייל-משתתף. קריאה בלבד — לא משנים/יוצרים/מוחקים אירועים תחת הרשאה זו.

https://www.googleapis.com/auth/calendar.eventsSensitive

מה: יצירה ועריכה של אירועי-יומן בחשבון המשתמש.

למה: קביעת פגישה ביומן כשלקוח בוחר מועד דרך לינק-הזמנה.

איך: יצירת אירוע, הזמנת הלקוח ובעל-המערכת, ולעיתים קישור Google Meet. רק אירועים שהמערכת יוצרת.

https://www.googleapis.com/auth/drive.fileNon-sensitive

מה: גישה רק לקבצים/תיקיות שהמערכת עצמה יצרה ב-Drive.

למה: יצירת תיקיית-לקוח ותיוק מסמכים (למשל סיכום-שיחה כ-Google Doc).

איך: יצירת תיקייה, שיתופה עם הלקוח והצוות, וכתיבת מסמכים שהמערכת מפיקה. אין גישה לקבצים אחרים.

https://www.googleapis.com/auth/driveRestricted

מה: גישה מלאה ל-Drive של המשתמש — הרשאה מוגבלת (restricted).

למה: ניהול תיקיות-לקוח קיימות שהעסק יצר ידנית + תיוק לתוכן — מה ש-drive.file לא מתיר.

איך: בעל-המערכת בוחר תיקיית-אב קיימת; המערכת יוצרת בתוכה תיקיות-לקוח ומתייקת מסמכים. גישה רק לצורך פיצ’ר תיקיות-הלקוח — לא סורקים את שאר ה-Drive.

4. מה איננו עושים בנתוני Google

הצהרת Limited Use: השימוש של Naor Aharoni — אוטומציות ו-CRM, ושל המערכות שאנו מפעילים (לרבות “Hila Bartov CRM”), במידע המתקבל מ-Google APIs — וכן העברתו לכל אפליקציה אחרת — יעמדו ב-Google API Services User Data Policy, לרבות דרישות ה-Limited Use.

5. WhatsApp ו-Meta

אנו משתמשים ב-WhatsApp Business Platform (של Meta) לתקשורת. שימוש זה כפוף גם למדיניות ולתנאי השימוש של Meta/WhatsApp.

6. שיתוף וספקי-משנה

איננו מוכרים מידע אישי. מידע משותף רק עם ספקי-תשתית הפועלים מטעמנו — Cloudflare (אירוח), ספק בסיס-נתונים מנוהל (Postgres) (אחסון מטא-נתונים של אירועי-יומן ואסימוני-גישה), ו-Google/Meta (ה-APIs) — או כנדרש על-פי חוק. איננו מעבירים נתוני Google לאף גורם אחר.

7. אבטחה ואחסון

נתונים נשמרים בבסיס-נתונים מנוהל ומאובטח; כל התעבורה מוצפנת ב-TLS/HTTPS; אסימוני-הגישה של Google נשמרים בצורה מאובטחת ומשמשים רק לקריאות-API מטעם המערכת; הגישה מוגבלת לבעלי-הרשאה.

8. שמירת מידע ומחיקה

אנו שומרים מידע כל עוד נדרש למתן השירות/החיבור פעיל, או כנדרש בחוק. ניתן לבקש מחיקה בכל עת ב-naorfm0@gmail.com; נמחק נתוני Google שאוחסנו אצלנו בתוך 30 יום (למעט הנדרש בחוק).

9. ביטול גישה (Revoke)

ניתן לבטל את גישת המערכת לחשבון Google בכל עת — דרך myaccount.google.com/permissions ("הסר גישה"), או דרך מסך ההגדרות של המערכת. לאחר הביטול אין עוד גישה לנתוני Google.

10. הזכויות שלך

בכפוף לדין (לרבות חוק הגנת הפרטיות בישראל וה-GDPR ככל שחל) — זכות לעיון, תיקון ומחיקה, והפסקת קבלת הודעות. לפנייה: naorfm0@gmail.com.

11. קטינים

השירות והמערכות מיועדים לשימוש עסקי ואינם מכוונים לקטינים מתחת לגיל 18.

12. עדכונים

נעדכן מדיניות זו מעת לעת; גרסה מעודכנת תפורסם כאן עם תאריך "עודכן לאחרונה" חדש.

13. יצירת קשר

Naor Aharoni — אוטומציות ומערכות CRM · ישראל · דוא"ל: naorfm0@gmail.com

Privacy Policy

Operator: Naor Aharoni — Automation & CRM · Effective date: 11 June 2026 · Last updated: 11 June 2026

This policy describes how Naor Aharoni — Automation & CRM (“we”, “us”) collects, uses, and protects information — when providing CRM & business-automation services, and within the systems we operate for our clients. It fully details our access to Google data (Calendar/Drive) and communication via WhatsApp.

This policy applies to all systems we operate. The currently live system is “Hila Bartov CRM” (for the “Organic on Steroids” agency).

1. Information we collect

2. How we use information

3. Google data we access — by scope

When connecting a Google account, the system requests only the scopes below. For each: what is accessed, why, and how it is used:

https://www.googleapis.com/auth/calendar.readonlySensitive

What: Read-only access to Google Calendar — events and free/busy.

Why: Show upcoming meetings on the client card + compute free slots for booking links.

How: Reads events in a time window and attaches them to a client card by attendee email. Read-only — never modifies, creates, or deletes events under this scope.

https://www.googleapis.com/auth/calendar.eventsSensitive

What: Create and edit calendar events in the user’s account.

Why: Place an appointment on the calendar when a client books a slot via a link.

How: Creates the event, invites the client and the system owner, optionally adds a Google Meet link. Only events the system creates.

https://www.googleapis.com/auth/drive.fileNon-sensitive

What: Access only to files/folders the system itself created in Drive.

Why: Create a client folder and file documents (e.g., a meeting summary as a Google Doc).

How: Creates a folder, shares it with client and team, writes documents it generates. No access to any other files.

https://www.googleapis.com/auth/driveRestricted

What: Full access to the user’s Drive — a restricted scope.

Why: Manage pre-existing client folders the business made by hand + file into them — which drive.file cannot reach.

How: The owner selects an existing parent folder; the system creates client folders within it and files documents. Limited to the client-folders feature; does not scan the rest of the Drive.

4. What we do NOT do with Google data

Limited Use disclosure: The use and transfer to any other app, by Naor Aharoni — Automation & CRM and the systems we operate (including “Hila Bartov CRM”), of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. WhatsApp and Meta

We use the WhatsApp Business Platform (by Meta) for communication. That use is also subject to Meta/WhatsApp’s policies and terms.

6. Sharing and sub-processors

We do not sell personal information. It is shared only with infrastructure providers acting on our behalf — Cloudflare (hosting), a managed database provider (Postgres) (storing calendar-event metadata and access tokens), and Google/Meta (the APIs) — or as required by law. We do not transfer Google data to any other party.

7. Security and storage

Data is stored in a managed, secured database; all traffic is encrypted with TLS/HTTPS; Google access tokens are stored securely and used only for the system’s API calls; access is restricted to authorized users.

8. Retention and deletion

We retain information as long as needed to provide the service / while the connection is active, or as required by law. Request deletion anytime at naorfm0@gmail.com; we delete the Google data stored with us within 30 days (except where law requires retention).

9. Revoking access

You can revoke the system’s access to your Google account anytime — via myaccount.google.com/permissions (“Remove access”), or from the system’s settings screen. After revocation there is no further access to Google data.

10. Your rights

Subject to law (including Israel’s Protection of Privacy Law and the GDPR where applicable) — rights to access, correct, and delete, and to stop receiving messages. Contact: naorfm0@gmail.com.

11. Children

The service and systems are for business use and are not directed to children under 18.

12. Changes

We may update this policy from time to time; an updated version will be posted here with a new “Last updated” date.

13. Contact

Naor Aharoni — Automation & CRM · Israel · Email: naorfm0@gmail.com