Last updated: 29 July 2026 · Version: 2026-07-29-d
This Privacy Policy (“Policy”) describes how Mikhail Gutentov, an Israeli authorized dealer (עוסק מורשה), tax / licensed dealer number 346700693, address Shalom Aleichem 7, Apt. 2, Bat Yam, Israel (the “Operator”, “we”, “us”, “our”), collects, uses, stores, shares, and otherwise processes personal data in connection with the Yomit platform at https://yomit.co, related APIs, and mobile applications (collectively, the “Service”).
Privacy requests and notices: gutiontovmihail@gmail.com.
This Policy should be read together with our Terms of Service and Disclaimer. Capitalized terms not defined here have the meaning given in the Terms.
Processing of personal data is subject to the Israeli Protection of Privacy Law, 5741-1981, as amended (including by Amendment 13, described in Section 2 below), and other laws that may apply depending on where you or your workers are located.
English is the authoritative language of this Policy. Translations are for convenience only.
1. Scope and Key Distinctions
Like other workplace SaaS products, Yomit processes different categories of information in different roles. Please read this section carefully.
(A) Account and Operator-controlled data. When you register directly with us, contact support, or interact with billing, we act as an independent data controller (database owner) for that personal data — for example your name, email, username, language preference, Terms acceptance records, and security logs related to your login.
(B) Customer workspace / “Customer Data”. When a business customer (“Customer”) stores information about its employees, contractors, objects, tasks, reports, attendance, GPS samples, HR fields, messages, contracts, or similar operational content in its Yomit workspace, the Customer generally determines the purposes and means of that processing. In that context, the Customer is the data controller, and the Operator acts as a processor / service provider on the Customer’s instructions to provide the Service.
If you are an employee or contractor of a Customer and have questions about Customer Data (for example: why your location is tracked, who in your company can see reports, or how long your employer keeps records), please contact your company’s administrator first. We will assist the Customer as reasonably required.
You are not required by law to use the Service. If you choose not to provide data we need to operate an account, we may be unable to provide the Service.
2. Amendment 13 to the Protection of Privacy Law
Amendment 13 to the Israeli Protection of Privacy Law, 5741-1981, introduced enhanced obligations for organizations that hold databases of personal data, including strengthened data-security duties, mandatory notification of certain data breaches to the Privacy Protection Authority (and, in qualifying cases, to affected individuals), updated database registration and classification duties, and, for databases meeting statutory thresholds, a duty to appoint a Data Protection Officer. The Amendment also expanded the enforcement powers (including administrative fines) of the Privacy Protection Authority.
We have reviewed our practices in light of Amendment 13 and address the relevant duties throughout this Policy, including in Section 19 (Security Incidents and Breach Notification), Section 24 (Data Protection Officer), and Section 25 (Database Registration).
3. Categories of Personal Data We Process
Depending on how the Service is used, we may process the following categories:
- Identity and account data: name, username, email address, phone (if provided), role, language, company affiliation, profile photo URL (if provided), and authentication credentials (stored in hashed form).
- Business and operational content: objects/sites, teams, tasks, daily reports, work items, quantities, order numbers, contracts and related metadata, invoices and finance fields you choose to store, catalogs of actions/resources, chat/discussion messages, and uploaded files/attachments.
- HR and employment-related fields (Customer-controlled when stored in a company workspace): fields a Customer chooses to record (for example personal ID numbers, emergency contacts, salary-related fields, absences). Customers should collect only what they need and are authorized to collect.
- Location and attendance data: GPS coordinates and timestamps from mobile/web location samples, day-start / day-end punch events, coordinates attached to reports, and related device metadata when these features are enabled.
- Technical and usage data: IP address, browser/device type, operating system, app version, approximate network information, cookies and similar technologies, session tokens, diagnostic logs, and security event logs.
- Support and communication data: emails and messages you send to us, and in-app support-related content.
- Translation / AI content: free-text fields submitted to machine-translation or AI features may be transmitted to subprocessors solely to deliver that feature.
- Payment-related data: if paid plans are enabled, billing contact details and payment status. Card data, if any, is typically processed by a payment provider and not stored in full by us.
4. Employee and Workplace Data
Workplace personal data that a Customer enters about its own employees or contractors (identity fields, role, emergency contacts, salary-related fields, absences, and similar HR content) is processed by the Operator strictly as instructed by the Customer, which acts as the controller for that data. The Operator does not use such data for its own independent purposes (for example marketing) beyond providing, securing, and supporting the Service.
5. GPS and Location Data
Location data can be sensitive in a workplace context. Where a Customer enables GPS or location-related features, the Service collects coordinates and timestamps from the relevant user’s device only while and to the extent the feature is active. Customers should use location data only for legitimate work purposes (such as attendance verification or site routing) and in accordance with applicable law, including providing prior notice to affected workers.
6. Attendance Data
Attendance-related data (punch events, timestamps, and any associated location or photo evidence) is processed to support the Customer’s internal workforce-management workflows. The Operator does not independently monitor or evaluate worker attendance; the Customer controls how attendance data is used, reviewed, and acted upon.
7. Sources of Data
- Directly from you (registration forms, profile settings, support requests).
- From Customer administrators who invite you and configure roles.
- Automatically from your devices when you use the Service (logs, cookies, location samples if permitted).
- From third-party services you or the Customer connect (for example maps/geocoding providers returning coordinates).
8. Purposes of Processing
We process personal data for the following purposes:
- to create and administer accounts and authenticate users;
- to provide, operate, maintain, and improve the Service and its features;
- to enable Customer workflows (tasks, reports, contracts, dashboards, messaging, attendance/location features);
- to provide customer support and respond to inquiries;
- to process subscriptions, invoices, and payments where applicable;
- to provide optional machine translation / AI-assisted features;
- to monitor security, prevent fraud and abuse, and enforce the Terms;
- to comply with legal obligations and establish, exercise, or defend legal claims;
- to communicate service-related notices (including Terms updates and security notices).
Where we act as processor for Customer Data, we process that data to provide the Service to the Customer and according to the Customer’s configuration and instructions (subject to our security and legal constraints).
9. Legal Bases for Processing
Depending on applicable law, processing may be based on: performance of a contract (providing the Service); legitimate interests (securing and improving the Service, preventing abuse); consent where required (for example certain cookies or optional features); and legal obligations.
10. Mandatory or Voluntary Notice
Where required under Section 11 of the Israeli Protection of Privacy Law, we indicate whether providing certain personal data is a legal obligation or is voluntary, and, if voluntary, the consequences of not providing it. In general: information needed to create and secure your account is required to use the Service; optional profile fields, certain HR fields configured by a Customer, and participation in optional features (such as location tracking, where not otherwise mandated by the Customer’s own policies) are voluntary, subject to the Customer’s own workplace requirements.
11. Customer Responsibilities as Controller
Customers that use location tracking, attendance, or HR features are responsible for: (a) informing workers about the monitoring; (b) obtaining any consents or works-council / collective approvals required; (c) limiting collection to what is necessary; (d) providing the mandatory/voluntary notice described in Section 10 to their own workers where applicable; and (e) responding to worker privacy requests regarding Customer Data.
12. Sharing of Personal Data
We do not sell personal data. We may share personal data with:
- Service providers / subprocessors that help us host, store, secure, deliver email, provide maps/geocoding, monitor performance, process payments, or perform machine translation / AI processing needed for features you use;
- Other authorized users inside the relevant company or contract context, according to roles and permissions configured by the Customer;
- Professional advisors (legal, accounting) under confidentiality obligations;
- Authorities and courts when required by law, legal process, or to protect rights, safety, and security;
- A successor in connection with a merger, acquisition, or sale of assets relating to the Yomit business, subject to continued confidentiality and privacy commitments.
13. Subprocessors
We require subprocessors that process personal data for us to implement appropriate confidentiality and security measures substantially consistent with this Policy. A current illustrative list of categories includes: cloud hosting, database/backup storage, email delivery, maps/geocoding APIs, and AI/translation APIs. Details of specific vendors may be provided on request for enterprise Customers.
14. Machine Translation and AI Processing
Where a Customer or user enables machine-translation or AI-assisted features, relevant free-text content is transmitted to the applicable AI/translation subprocessor solely to generate the requested output. Such providers process the content under contractual confidentiality and data-protection commitments and do not use it to train their general-purpose models except as disclosed in their own terms.
15. International Transfers
Servers, backups, or subprocessors (including AI and translation providers) may be located outside Israel, including in the European Economic Area, the United Kingdom, or the United States. Where we transfer personal data internationally, we take reasonable contractual and organizational measures appropriate to the risk.
By enabling features that require such providers (for example machine translation), Customers instruct us to make the transfers necessary to deliver those features.
16. Cookies and Similar Technologies
We use cookies and similar technologies that are necessary for authentication, session security, load balancing, and storing preferences such as language or theme. These are required for the Service to function as requested.
If we introduce non-essential analytics or marketing cookies in the future, we will update this Policy and, where required, provide additional notice or consent mechanisms.
17. Security Measures (Operator)
We implement industry-reasonable technical and organizational measures designed to protect personal data, including access controls, hashed passwords, encryption in transit where configured, environment isolation, and logging. No method of transmission or storage is completely secure.
18. Customer Security Responsibilities
You and Customer administrators must also protect accounts (strong passwords, careful permission assignment, device security, and prompt off-boarding of former workers). Customers are responsible for configuring role-based access appropriately and for promptly notifying us of any suspected compromise of a Customer administrator account.
19. Security Incidents and Breach Notification
If we become aware of a personal-data breach affecting the Service, we will take reasonable steps to investigate, contain, and remediate the incident and, where legally required (including under Amendment 13), notify affected Customers and/or the Privacy Protection Authority without undue delay. Customers are responsible for notifying their own affected data subjects where required by law, and we will provide reasonable information and assistance to support that notification.
20. Data Retention — General
We retain Operator-controlled account data while the account is active and for a reasonable period afterward needed for dispute resolution, tax, and legal compliance. As a general guideline, after account or company workspace closure we aim to delete or anonymize residual personal data within approximately twelve (12) months, unless a longer period is required or permitted by law, needed for ongoing disputes, or covered by the specific backup and security-log schedules in Sections 21 and 22.
21. Data Retention — Backups
Encrypted backups of the database (which may include personal data) are retained on a rotating schedule for up to twelve (12) months after the corresponding data is deleted or anonymized in the live system, solely for disaster-recovery purposes. Data in backups is not actively used for any purpose other than restoration and is deleted or overwritten as backups roll off the retention schedule.
22. Data Retention — Security Logs
Security-related logs (such as authentication events, access logs, and other diagnostic/security event data) are retained for up to twenty-four (24) months to support security monitoring, incident investigation, fraud prevention, and compliance with our obligations under applicable law, after which they are deleted or anonymized unless a longer period is required for an ongoing investigation or legal proceeding.
23. Data Subject Rights
Subject to the Israeli Protection of Privacy Law and other applicable laws, individuals may have rights to access, correct, or delete personal data, or to object to certain processing.
To exercise rights regarding data we control as Operator, contact gutiontovmihail@gmail.com. We may need to verify your identity before responding.
To exercise rights regarding Customer Data, contact your Customer administrator. We will support the Customer’s response as reasonably necessary.
24. Data Protection Officer (DPO)
For databases that meet the statutory thresholds under the Israeli Protection of Privacy Law (as amended by Amendment 13) requiring appointment of a Data Protection Officer, the Operator will designate a DPO (which may be the Operator personally, where permitted) responsible for overseeing compliance with data-protection obligations relevant to the Service. You may contact the DPO function at gutiontovmihail@gmail.com. Customers that separately qualify for a DPO duty with respect to their own databases remain responsible for their own appointment and compliance.
25. Database Registration Under Israeli Law
Israeli law may require registration or notification of certain databases with the Privacy Protection Authority, and Amendment 13 updated the applicable classification and registration duties for qualifying databases. Each party (Operator or Customer) is responsible for assessing and fulfilling registration or notice obligations for databases under its control. Customers remain responsible for databases of employee/contractor data they control.
26. Children’s Privacy
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
27. Automated Decision-Making
The Service may compute derived metrics (such as attendance summaries, progress percentages, or payroll-related estimates) from data entered by Customer users. These computations are informational aids for the Customer’s own decision-making and do not, by themselves, produce legal or similarly significant automated decisions about individuals without human involvement by the Customer.
28. Marketing Communications
We do not send marketing communications unrelated to the Service unless you opt in. Service-related notices (including security, billing, and Terms-update notices) are not marketing and may be sent regardless of marketing preferences.
29. Third-Party Links
The Service may contain links to third-party websites or services (for example map providers). We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them.
30. Business Transfers
If the Yomit business or its assets are acquired, merged, or transferred, personal data may be transferred to the successor entity as part of that transaction, subject to continued confidentiality and privacy commitments consistent with this Policy.
31. Complaints and Supervisory Authority
You may lodge a complaint with the Israeli Privacy Protection Authority or another competent supervisory authority where applicable, in addition to (or instead of) contacting us directly.
32. Changes to This Policy
We may update this Policy from time to time by posting a new version with an updated version identifier. Material changes may be communicated by email or in-product notice and may require re-acceptance together with the Terms.
Continued use of the Service after the effective date of an updated Policy (and after any required acceptance) constitutes acknowledgment of the updated Policy.
33. Relationship to Terms and Disclaimer
This Policy forms part of the Agreement together with the Terms of Service and the Disclaimer. In case of conflict on data-processing topics specifically, this Policy and Section 19 (Data Processing Terms) of the Terms should be read together and, to the extent inconsistent, the more specific and protective provision controls.
34. Contact
Operator: Mikhail Gutentov (עוסק מורשה), tax ID 346700693
Address: Shalom Aleichem 7, Apt. 2, Bat Yam, Israel
Email: gutiontovmihail@gmail.com
Website: https://yomit.co
This Policy is a commercial privacy template for Yomit and is not a substitute for advice from an Israeli attorney.