מדיניות זו מתארת כיצד Naor Aharoni — אוטומציות ומערכות CRM ("אנחנו", "השירות") אוסף, משתמש ומגן על מידע — במסגרת מתן שירותי בניית מערכות CRM ואוטומציות עסקיות, ובמסגרת המערכות שאנו מפעילים עבור לקוחותינו. היא כוללת פירוט מלא של גישתנו לנתוני Google (Calendar/Drive) ולתקשורת דרך WhatsApp.
מדיניות זו חלה על כלל המערכות שאנו מפעילים. נכון להיום המערכת הפעילה היא “Hila Bartov CRM” (עבור סוכנות “אורגני על סטרואידים”).
בעת חיבור חשבון Google, המערכת מבקשת את ההרשאות הבאות בלבד. לכל אחת — מה ניגשים, למה, ואיך משתמשים:
https://www.googleapis.com/auth/calendar.readonlySensitiveמה: קריאה בלבד מיומן Google — אירועים וזמני פנוי/תפוס.
למה: הצגת פגישות עתידיות בכרטיס-הלקוח + חישוב סלוטים פנויים ללינקי קביעת-פגישות.
איך: קריאת אירועים בחלון זמן ושיבוץ לכרטיס-לקוח לפי מייל-משתתף. קריאה בלבד — לא משנים/יוצרים/מוחקים אירועים תחת הרשאה זו.
https://www.googleapis.com/auth/calendar.eventsSensitiveמה: יצירה ועריכה של אירועי-יומן בחשבון המשתמש.
למה: קביעת פגישה ביומן כשלקוח בוחר מועד דרך לינק-הזמנה.
איך: יצירת אירוע, הזמנת הלקוח ובעל-המערכת, ולעיתים קישור Google Meet. רק אירועים שהמערכת יוצרת.
https://www.googleapis.com/auth/drive.fileNon-sensitiveמה: גישה רק לקבצים/תיקיות שהמערכת עצמה יצרה ב-Drive.
למה: יצירת תיקיית-לקוח ותיוק מסמכים (למשל סיכום-שיחה כ-Google Doc).
איך: יצירת תיקייה, שיתופה עם הלקוח והצוות, וכתיבת מסמכים שהמערכת מפיקה. אין גישה לקבצים אחרים.
https://www.googleapis.com/auth/driveRestrictedמה: גישה מלאה ל-Drive של המשתמש — הרשאה מוגבלת (restricted).
למה: ניהול תיקיות-לקוח קיימות שהעסק יצר ידנית + תיוק לתוכן — מה ש-drive.file לא מתיר.
איך: בעל-המערכת בוחר תיקיית-אב קיימת; המערכת יוצרת בתוכה תיקיות-לקוח ומתייקת מסמכים. גישה רק לצורך פיצ’ר תיקיות-הלקוח — לא סורקים את שאר ה-Drive.
הצהרת Limited Use: השימוש של Naor Aharoni — אוטומציות ו-CRM, ושל המערכות שאנו מפעילים (לרבות “Hila Bartov CRM”), במידע המתקבל מ-Google APIs — וכן העברתו לכל אפליקציה אחרת — יעמדו ב-Google API Services User Data Policy, לרבות דרישות ה-Limited Use.
אנו משתמשים ב-WhatsApp Business Platform (של Meta) לתקשורת. שימוש זה כפוף גם למדיניות ולתנאי השימוש של Meta/WhatsApp.
איננו מוכרים מידע אישי. מידע משותף רק עם ספקי-תשתית הפועלים מטעמנו — Cloudflare (אירוח), ספק בסיס-נתונים מנוהל (Postgres) (אחסון מטא-נתונים של אירועי-יומן ואסימוני-גישה), ו-Google/Meta (ה-APIs) — או כנדרש על-פי חוק. איננו מעבירים נתוני Google לאף גורם אחר.
נתונים נשמרים בבסיס-נתונים מנוהל ומאובטח; כל התעבורה מוצפנת ב-TLS/HTTPS; אסימוני-הגישה של Google נשמרים בצורה מאובטחת ומשמשים רק לקריאות-API מטעם המערכת; הגישה מוגבלת לבעלי-הרשאה.
אנו שומרים מידע כל עוד נדרש למתן השירות/החיבור פעיל, או כנדרש בחוק. ניתן לבקש מחיקה בכל עת ב-naorfm0@gmail.com; נמחק נתוני Google שאוחסנו אצלנו בתוך 30 יום (למעט הנדרש בחוק).
ניתן לבטל את גישת המערכת לחשבון Google בכל עת — דרך myaccount.google.com/permissions ("הסר גישה"), או דרך מסך ההגדרות של המערכת. לאחר הביטול אין עוד גישה לנתוני Google.
בכפוף לדין (לרבות חוק הגנת הפרטיות בישראל וה-GDPR ככל שחל) — זכות לעיון, תיקון ומחיקה, והפסקת קבלת הודעות. לפנייה: naorfm0@gmail.com.
השירות והמערכות מיועדים לשימוש עסקי ואינם מכוונים לקטינים מתחת לגיל 18.
נעדכן מדיניות זו מעת לעת; גרסה מעודכנת תפורסם כאן עם תאריך "עודכן לאחרונה" חדש.
Naor Aharoni — אוטומציות ומערכות CRM · ישראל · דוא"ל: naorfm0@gmail.com
This policy describes how Naor Aharoni — Automation & CRM (“we”, “us”) collects, uses, and protects information — when providing CRM & business-automation services, and within the systems we operate for our clients. It fully details our access to Google data (Calendar/Drive) and communication via WhatsApp.
This policy applies to all systems we operate. The currently live system is “Hila Bartov CRM” (for the “Organic on Steroids” agency).
When connecting a Google account, the system requests only the scopes below. For each: what is accessed, why, and how it is used:
https://www.googleapis.com/auth/calendar.readonlySensitiveWhat: Read-only access to Google Calendar — events and free/busy.
Why: Show upcoming meetings on the client card + compute free slots for booking links.
How: Reads events in a time window and attaches them to a client card by attendee email. Read-only — never modifies, creates, or deletes events under this scope.
https://www.googleapis.com/auth/calendar.eventsSensitiveWhat: Create and edit calendar events in the user’s account.
Why: Place an appointment on the calendar when a client books a slot via a link.
How: Creates the event, invites the client and the system owner, optionally adds a Google Meet link. Only events the system creates.
https://www.googleapis.com/auth/drive.fileNon-sensitiveWhat: Access only to files/folders the system itself created in Drive.
Why: Create a client folder and file documents (e.g., a meeting summary as a Google Doc).
How: Creates a folder, shares it with client and team, writes documents it generates. No access to any other files.
https://www.googleapis.com/auth/driveRestrictedWhat: Full access to the user’s Drive — a restricted scope.
Why: Manage pre-existing client folders the business made by hand + file into them — which drive.file cannot reach.
How: The owner selects an existing parent folder; the system creates client folders within it and files documents. Limited to the client-folders feature; does not scan the rest of the Drive.
Limited Use disclosure: The use and transfer to any other app, by Naor Aharoni — Automation & CRM and the systems we operate (including “Hila Bartov CRM”), of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use the WhatsApp Business Platform (by Meta) for communication. That use is also subject to Meta/WhatsApp’s policies and terms.
We do not sell personal information. It is shared only with infrastructure providers acting on our behalf — Cloudflare (hosting), a managed database provider (Postgres) (storing calendar-event metadata and access tokens), and Google/Meta (the APIs) — or as required by law. We do not transfer Google data to any other party.
Data is stored in a managed, secured database; all traffic is encrypted with TLS/HTTPS; Google access tokens are stored securely and used only for the system’s API calls; access is restricted to authorized users.
We retain information as long as needed to provide the service / while the connection is active, or as required by law. Request deletion anytime at naorfm0@gmail.com; we delete the Google data stored with us within 30 days (except where law requires retention).
You can revoke the system’s access to your Google account anytime — via myaccount.google.com/permissions (“Remove access”), or from the system’s settings screen. After revocation there is no further access to Google data.
Subject to law (including Israel’s Protection of Privacy Law and the GDPR where applicable) — rights to access, correct, and delete, and to stop receiving messages. Contact: naorfm0@gmail.com.
The service and systems are for business use and are not directed to children under 18.
We may update this policy from time to time; an updated version will be posted here with a new “Last updated” date.
Naor Aharoni — Automation & CRM · Israel · Email: naorfm0@gmail.com