מדיניות פרטיות
עדכון אחרון: ספטמבר 2026
1. מבוא
TazOne ("החברה", "אנחנו") מפעילה את פלטפורמת TazOne לניהול קליניקות תזונה. מדיניות פרטיות זו מסבירה כיצד אנו אוספים, משתמשים, מאחסנים ומגנים על המידע האישי שלך, בהתאם לחוק הגנת הפרטיות, התשמ"א-1981 ותקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017 (תיקון 13).
2. מידע שאנו אוספים
2.1 פרטי חשבון
- שם, כתובת אימייל, סיסמה מוצפנת
- פרטי פרופיל: שם תצוגה, שפה מועדפת, אזור זמן
2.2 נתוני לקוחות (מידע בריאותי)
- פרטי זיהוי: שם, אימייל, מספר טלפון
- נתונים רפואיים: הערות רפואיות, אלרגיות, משקל, מטרות תזונתיות, תפריטים, תרגילים
- פגישות: תאריכים, סוג, הערות
2.3 נתוני שימוש ואנליטיקה
- צפיות בדפים, לחיצות על כפתורים, זמן שהייה (PostHog, שרתי EU)
- לוגי שגיאות אנונימיים (Sentry)
2.4 מידע תשלום
- מעובד באופן מאובטח דרך Grow by Meshulam (ספק תשלומים ישראלי)
- איננו שומרים מספרי כרטיס אשראי מלאים; רק טוקנים מוצפנים
3. שימוש במידע
אנו משתמשים במידע שנאסף לצרכים הבאים:
- הפעלת השירות ואספקת התכונות שביקשת
- שיפור חוויית המשתמש והשירות
- עיבוד תשלומים ושליחת חשבוניות
- שליחת הודעות טרנזקציוניות באימייל (Resend) ובוואטסאפ (Meta WhatsApp Business)
- תמיכה טכנית ופתרון בעיות
4. אבטחת מידע בריאותי
נתונים רפואיים (הערות רפואיות, אלרגיות) וההודעות שאתם מחליפים עם המטפל/ת או המרפאה באפליקציה — כולל התצוגה המקדימה ברשימת ההודעות — מוצפנים במנוחה באמצעות הצפנת AES-256-GCM, עם וקטור אתחול ייחודי לכל ערך שנשמר. ההצפנה מתבצעת בשרת לפני השמירה ומפוענחת רק בעת הצגה למשתמש המורשה. המפתחות מוחזקים בשרת האפליקציה בלבד ולעולם אינם נשלחים למסד הנתונים, ולכן גיבוי, עותק משוכפל או יומן של מסד הנתונים מכיל טקסט מוצפן בלבד ולא ניתן לחפש בו את תוכן ההודעות. אין מדובר בהצפנה מקצה לקצה: TazOne מפענחת את תוכן ההודעות כדי להציג אותו לכם ולמטפל/ת שלכם.
אמצעי אבטחה נוספים:
- הגנת גישה מבוססת שורות (RLS) ברמת מסד הנתונים
- בידוד נתונים מלא: רק התזונאי/ת שיצר/ה את הלקוח יכול/ה לגשת לנתוניו
- תקשורת מוצפנת בלבד (HTTPS עם HSTS)
- יומן ביקורת (audit log) בלתי ניתן לשינוי לכל פעולה על מידע בריאותי
- הגנה מפני מתקפות: CSP, הגבלת קצב (rate limiting), זיהוי בוטים
5. הודעות WhatsApp
TazOne משתמשת ב-WhatsApp Business API של Meta לשליחת הודעות ללקוחות התזונאי/ת. שימוש זה כפוף למדיניות WhatsApp Business.
5.1 הסכמה (Opt-in)
הודעות WhatsApp נשלחות רק כאשר התזונאי/ת הפעיל/ה את התכונה עבור לקוח/ה ספציפי/ת והזין/ה את מספר הטלפון של הלקוח/ה. ההפעלה מהווה אישור שהלקוח/ה נתן/ה הסכמה מפורשת לקבלת הודעות דרך WhatsApp.
5.2 סוגי הודעות
ההודעות הנשלחות הן טרנזקציוניות בלבד ומוגבלות ל:
- אישור קליטה כלקוח/ה חדש/ה
- אישור, עדכון או ביטול פגישות
- סיכום פגישה
- שליחת תפריט תזונתי חדש או מעודכן
- שיתוף מסמכים
איננו שולחים הודעות שיווקיות או פרסומיות דרך WhatsApp.
5.3 מידע המועבר ל-Meta
בעת שליחת הודעת WhatsApp, המידע הבא מועבר לשרתי Meta: מספר הטלפון של הלקוח/ה ותוכן ההודעה. המידע מעובד בהתאם למדיניות הפרטיות של WhatsApp.
5.4 ביטול הסכמה (Opt-out)
התזונאי/ת יכול/ה לבטל את שליחת ההודעות לכל לקוח/ה בכל עת דרך הגדרות הלקוח/ה במערכת. לקוחות המעוניינים להפסיק לקבל הודעות יכולים לפנות לתזונאי/ת שלהם ישירות.
5.5 תיעוד
כל הודעת WhatsApp מתועדת ביומן הודעות פנימי הכולל: מזהה נמען, תבנית הודעה, סטטוס שליחה וחותמת זמן. מידע זה נשמר לצורך ביקורת ופתרון בעיות.
Google Calendar
כאשר מחברים חשבון Google, הפלטפורמה ניגשת ליומן הראשי לצורך סנכרון פגישות, בדיקת זמינות ואימות הופעת אירועים ביומן. המידע שנקרא כולל מזהי אירועים, כותרות, תיאורים, מועדי התחלה וסיום ומצב האירוע. סנכרון יכול לשמור מידע זה ברשומות הפגישות של TazOne.
בעת יצירה או עדכון של פגישה ביומן Google, נשלחים ל-Google כותרת הפגישה, ההערות והמועדים. מחיקת פגישה מקושרת עשויה למחוק גם את האירוע ביומן Google. פרטים אישיים שנכללים בכותרת או בהערות נכללים גם במידע המועבר.
אסימוני הגישה והרענון של Google נשמרים מוצפנים בשרת ומשמשים לגישה ל-API ולחידוש הגישה. ניתן לנתק את החיבור בהגדרות הקליניקה, בלשונית החיבורים; פעולה זו מוחקת את פרטי החיבור השמורים. ניתן גם לבטל את ההרשאה בהגדרות חשבון Google. ניתוק אינו מוחק אירועים קיימים ב-Google או פגישות שכבר יובאו ל-TazOne. על רשומות הפגישות חלים כללי השמירה והמחיקה המפורטים במדיניות זו.
6. דואר אלקטרוני
אנו משתמשים ב-Resend לשליחת אימיילים טרנזקציוניים: אימות חשבון, איפוס סיסמה, תזכורות חיוב והתראות מערכת. איננו שולחים ניוזלטרים או אימיילים שיווקיים.
7. שיתוף מידע עם צדדים שלישיים
איננו מוכרים או משתפים מידע אישי. המידע מועבר לצדדים שלישיים רק לצורך הפעלת השירות:
- Supabase — אימות משתמשים (AWS)
- Grow by Meshulam — עיבוד תשלומים (ישראל)
- Meta WhatsApp Business — שליחת הודעות ללקוחות (גלובלי)
- Resend — דואר אלקטרוני טרנזקציוני (ארה"ב)
- PostHog — אנליטיקה אנונימית (שרתי EU)
- Sentry — ניטור שגיאות (ארה"ב)
- Hostinger — אירוח שרתים (אירופה)
הרשימה המלאה זמינה בעמוד מעבדי המשנה. במקרים בהם נדרש על פי חוק, נמסור מידע לרשויות המוסמכות.
8. זכויותיך
בהתאם לחוק הגנת הפרטיות, 1981 ותיקון 13, עומדות לך הזכויות הבאות:
- זכות לעיין במידע האישי שלך
- זכות לתקן מידע שגוי
- זכות למחוק את חשבונך ואת כל הנתונים הקשורים
- זכות להתנגד לעיבוד מידע
- זכות לייצא את הנתונים שלך בפורמט קריא (JSON)
לביצוע כל אחת מהזכויות הנ"ל, פנה/י דרך הגדרות החשבון או בכתובת privacy@tazone.co.
9. שמירת מידע
מידע בריאותי של לקוחות נשמר ל-7 שנים בהתאם לחוק זכויות החולה, 1996. נתוני חשבון נשמרים כל עוד החשבון פעיל. לאחר מחיקת חשבון, כל הנתונים נמחקים תוך 30 יום, למעט מידע שנדרש לשמירה על פי חוק.
10. עוגיות (Cookies)
- עוגיות חיוניות: אימות משתמש, שמירת שפה והעדפות (SameSite=Lax, Secure)
- עוגיות אנליטיקה: PostHog (שרתי EU) — בכפוף להסכמתך. ניתן לדחות בבאנר העוגיות.
איננו משתמשים בעוגיות שיווקיות או עוגיות מעקב של צדדים שלישיים.
11. שינויים במדיניות
אנו שומרים את הזכות לעדכן מדיניות זו מעת לעת. על שינויים מהותיים תקבל/י הודעה באימייל או דרך הפלטפורמה.
12. יצירת קשר
לשאלות בנוגע למדיניות הפרטיות:
- דוא"ל: privacy@tazone.co
- טלפון: 050-622-9888
- אתר: tazone.co
Privacy Policy
Last updated: September 2026
1. Introduction
TazOne ("the Company", "we") operates the TazOne platform for nutrition clinic management. This privacy policy explains how we collect, use, store, and protect your personal information, in accordance with the Israeli Privacy Protection Law, 5741-1981, and the Privacy Protection Regulations (Data Security), 5777-2017 (Amendment 13).
2. Information We Collect
2.1 Account Details
- Name, email address, encrypted password
- Profile: display name, preferred language, timezone
2.2 Client Data (Health Information)
- Identifying details: name, email, phone number
- Medical data: medical notes, allergies, weight, nutritional goals, meal plans, exercises
- Appointments: dates, type, notes
2.3 Usage Data & Analytics
- Page views, button clicks, session duration (PostHog, EU servers)
- Anonymous error logs (Sentry)
2.4 Payment Information
- Processed securely through Grow by Meshulam (Israeli payment provider)
- We do not store full credit card numbers; only encrypted tokens
3. How We Use Information
- Operating the service and providing requested features
- Improving user experience and the service
- Processing payments and sending invoices
- Sending transactional messages via email (Resend) and WhatsApp (Meta WhatsApp Business)
- Technical support and troubleshooting
4. Health Data Security
Medical data (medical notes, allergies) and the messages you exchange with your practitioner or clinic in the app — including the preview shown in the message list — are encrypted at rest using AES-256-GCM encryption, with a unique initialisation vector for every stored value. Encryption occurs server-side before storage and is decrypted only when displayed to the authorized user. The keys are held by the application server and are never sent to the database, so a database backup, replica or log contains ciphertext only and message text cannot be searched there. This is not end-to-end encryption: TazOne can decrypt message content in order to display it to you and your practitioner.
Additional security measures:
- Row-Level Security (RLS) at the database level
- Full data isolation: only the practitioner who created a client can access their data
- Encrypted communication only (HTTPS with HSTS)
- Immutable audit log for all operations on health data
- Attack protection: CSP, rate limiting, bot detection
5. WhatsApp Notifications
TazOne uses Meta's WhatsApp Business API to send messages to practitioners' clients. This usage is subject to the WhatsApp Business Policy.
5.1 Consent (Opt-in)
WhatsApp messages are sent only when the practitioner has enabled the feature for a specific client and entered the client's phone number. Enabling constitutes confirmation that the client has given explicit consent to receive messages via WhatsApp.
5.2 Message Types
Messages are transactional only and limited to:
- New client onboarding confirmation
- Appointment booking, update, or cancellation
- Appointment summary
- New or updated meal plan delivery
- Document sharing
We do not send marketing or promotional messages via WhatsApp.
5.3 Data Shared with Meta
When sending a WhatsApp message, the following data is transmitted to Meta's servers: the client's phone number and message content. Data is processed in accordance with WhatsApp's Privacy Policy.
5.4 Opt-out
Practitioners can disable WhatsApp messages for any client at any time through the client settings in the platform. Clients who wish to stop receiving messages can contact their practitioner directly.
5.5 Record-Keeping
Every WhatsApp message is logged internally including: recipient identifier, message template, delivery status, and timestamp. This data is retained for auditing and troubleshooting purposes.
Google Calendar
When you connect a Google account, TazOne accesses its primary calendar to synchronize appointments, check availability, and verify whether linked events are present. Data read includes event identifiers, titles, descriptions, start and end times, and event status. Synchronization can store this information in TazOne appointment records.
Creating or updating a Google Calendar event sends the appointment title, notes, and scheduled times to Google. Deleting a linked appointment can also delete its Google event. Personal information included in titles or notes is included in this transfer.
Google access and refresh tokens are stored encrypted on the server for API access and automatic access-token renewal. Disconnecting Google Calendar in Clinic Settings under Integrations deletes the stored connection credentials. You can also revoke access in your Google Account settings. Disconnecting does not delete existing Google events or appointments already imported into TazOne. Appointment records remain subject to the retention and deletion provisions in this policy.
6. Email
We use Resend for transactional emails: account verification, password reset, billing reminders, and system notifications. We do not send newsletters or marketing emails.
7. Third-Party Data Sharing
We do not sell or share personal information. Data is shared with third parties only for operating the service:
- Supabase — User authentication (AWS)
- Grow by Meshulam — Payment processing (Israel)
- Meta WhatsApp Business — Client messaging (Global)
- Resend — Transactional email (USA)
- PostHog — Anonymous analytics (EU servers)
- Sentry — Error monitoring (USA)
- Hostinger — Server hosting (Europe)
The full list is available on our Sub-Processors page. Where required by law, we will disclose information to competent authorities.
8. Your Rights
Under the Israeli Privacy Protection Law, 1981, and Amendment 13, you have the right to:
- Access your personal information
- Correct inaccurate information
- Delete your account and all associated data
- Object to data processing
- Export your data in a machine-readable format (JSON)
To exercise any of these rights, use the account settings or contact privacy@tazone.co.
9. Data Retention
Client health information is retained for 7 years per the Israeli Patient Rights Law, 1996. Account data is retained while the account is active. After account deletion, all data is removed within 30 days, except information required to be retained by law.
10. Cookies
- Essential cookies: User authentication, language and preference storage (SameSite=Lax, Secure)
- Analytics cookies: PostHog (EU servers) — subject to your consent. Can be declined via the cookie banner.
We do not use marketing cookies or third-party tracking cookies.
11. Changes to This Policy
We reserve the right to update this policy from time to time. Material changes will be communicated via email or through the platform.
12. Contact
For privacy-related inquiries:
- Email: privacy@tazone.co
- Phone: +972-50-622-9888
- Website: tazone.co