מדיניות פרטיות — MyAgnt
עדכון אחרון: 19 ביולי 2026 · הגרסה העברית היא הגרסה המחייבת
MyAgnt הוא שירות "צוות עובדים דיגיטלי" לעסקים קטנים, הפועל בעיקר דרך WhatsApp. השירות מופעל על ידי Carolina Erijman ("אנחנו", "השירות"). יצירת קשר: Flowmart.co@gmail.com · אתר: myagnt.io.
מדיניות זו מסבירה איזה מידע השירות מעבד, למה, כמה זמן הוא נשמר, ומה הזכויות שלכם. היא חלה גם על בעלי עסקים שמנויים על השירות ("בעל העסק") וגם על לקוחות הקצה שמתכתבים עם העסק ב-WhatsApp ("לקוח").
1. איזה מידע אנחנו מעבדים
- הודעות WhatsApp — תוכן ההתכתבות בין הלקוח לעסק, המתקבל דרך פלטפורמת WhatsApp Business של Meta.
- פרטי קשר — שם, מספר טלפון, ופרטים שהלקוח מסר בשיחה לצורך השירות (למשל סוג הטיפול המבוקש).
- תורים ופגישות — מועדים, משך, סטטוס, והקשר לעסק וללקוח.
- מידע עסקי של בעל העסק — הגדרות העסק, שעות פעילות, שירותים ומחירים, כפי שבעל העסק מסר.
- נתוני יומן דרך Google — רק אם בעל העסק חיבר יומן Google (ראו סעיף 5).
איננו אוספים מידע לצרכי פרסום, ואיננו סורקים מידע שאינו נחוץ להפעלת השירות.
2. למה (מטרות העיבוד)
- מתן השירות עצמו: מענה ללקוחות ב-WhatsApp בשם העסק, תיאום ותזכור תורים, וניהול שוטף של העסק כפי שבעל העסק הגדיר.
- זיכרון שירות: השירות זוכר עובדות רלוונטיות מהשיחות (למשל העדפת טיפול) כדי לתת שירות טוב יותר.
- אבטחה, מניעת שימוש לרעה, וחובות על פי דין.
איננו מוכרים מידע אישי, ואיננו משתמשים בו לפרסום של צד שלישי.
3. עיבוד באמצעות בינה מלאכותית
השירות משתמש במודל שפה של Anthropic (דרך ה-API המסחרי שלה) כדי להבין הודעות ולנסח תשובות. ההודעות הרלוונטיות לשיחה מועברות לעיבוד ומוחזרות; על פי תנאי השירות המסחריים של Anthropic, קלט ופלט ה-API אינם משמשים לאימון המודלים שלה כברירת מחדל. איננו מאמנים מודלים על המידע שלכם, ומידע המתקבל מ-Google אינו משמש לאימון או שיפור של מודלי בינה מלאכותית כלשהם.
4. שמירת מידע (Retention)
- עובדות זיכרון שמקורן בלקוח קצה (למשל העדפות שעלו בשיחה): נשמרות עד כ-90 יום מרגע הכתיבה, ולאחר מכן פוקעות אוטומטית.
- הגדרות ומידע של בעל העסק: נשמרים כל עוד החשבון פעיל.
- תורים והיסטוריית הודעות: נשמרים כל עוד החשבון פעיל, כרשומות תפעוליות של העסק.
- בסגירת חשבון או לפי בקשה — המידע נמחק, למעט מה שנדרש לשמור על פי דין.
5. יומן Google — מה אנחנו קוראים, מה אנחנו כותבים
אם בעל העסק בוחר לחבר את יומן ה-Google שלו (חיבור בהסכמה מפורשת, דרך מסך ההרשאות של Google):
- מה אנחנו קוראים: רשימת היומנים (כדי שבעל העסק יבחר איזה יומן לחבר), זמני תפוס/פנוי, ומועדי אירועים — אך ורק כדי לחשב זמינות אמיתית לפני קביעת תור.
- מה אנחנו כותבים: אירועי תורים שהשירות קבע, ביומן אחד שבעל העסק הגדיר. כברירת מחדל האירוע מכיל מינימום מידע: שם השירות + שם פרטי של הלקוח בלבד (למשל "לק ג'ל — דנה"). בלי טלפון, בלי שם משפחה, בלי תוכן שיחה. בעל העסק יכול לבחור רמה חשופה עוד פחות ("תפוס" בלבד) או, בהסכמה מפורשת ומודעת, רמה מפורטת יותר.
- מה לעולם לא נשלח ליומן: תוכן שיחות, הערות פנימיות, ופרטי קשר מעבר לרמה שבעל העסק הגדיר.
- אחסון: אנו שומרים העתק סנכרון של זמני תפוס/פנוי ומועדי אירועים לצורך חישוב זמינות מהיר, ואסימוני גישה (tokens) מוצפנים. ניתוק היומן מפסיק את הסנכרון; בעל העסק יכול לנתק בכל עת גם דרך הגדרות האבטחה של חשבון Google.
עמידה במדיניות Google: השימוש של MyAgnt במידע המתקבל מ-Google APIs יעמוד ב- Google API Services User Data Policy, לרבות דרישות ה-Limited Use (הנוסח המחייב באנגלית — ראו למטה).
6. שיתוף מידע — עם מי
איננו מעבירים מידע אישי לאף גורם, מלבד ספקי המשנה המפעילים את השירות עבורנו:
| ספק | תפקיד |
|---|---|
| Meta (WhatsApp Business Platform) | תשתית המסרים — ההודעות עוברות דרך WhatsApp |
| Anthropic | עיבוד שפה (AI) דרך API מסחרי |
| Railway | אירוח השרתים ומסד הנתונים |
| חיבור היומן — רק אם בעל העסק חיבר יומן |
כל ספק מחויב חוזית להגנת המידע. מעבר לכך — שיתוף רק אם נדרש על פי דין.
7. אבטחה
המידע מאוחסן במסד נתונים עם הפרדה מלאה בין עסקים (כל עסק רואה רק את המידע שלו), תקשורת מוצפנת (HTTPS/TLS), ואסימוני גישה מאוחסנים מוצפנים. אין מערכת חסינה לחלוטין, אך אנו פועלים לפי נהלים מקובלים בתעשייה.
8. הזכויות שלכם
על פי חוק הגנת הפרטיות, התשמ"א-1981 (כפי שתוקן), זכותכם לעיין במידע עליכם, לבקש תיקון של מידע שגוי, ולבקש מחיקה. לקוח קצה יכול לפנות אלינו ישירות או דרך העסק שבו קיבל שירות. פנייה: Flowmart.co@gmail.com. נענה בתוך זמן סביר ובהתאם לדין.
9. שינויים במדיניות
נעדכן עמוד זה בכל שינוי מהותי; תאריך "עדכון אחרון" ישקף זאת.
MyAgnt ("we", "the Service") is an AI employee-team service for small businesses, operating primarily over WhatsApp. Operated by Carolina Erijman. Contact: Flowmart.co@gmail.com. Website: myagnt.io. This policy applies to subscribing business owners ("Owner") and to their customers who message the business on WhatsApp ("Customer"). The Hebrew version above is the binding version; this English version is provided for convenience and for Google's review.
1. Data we process
- WhatsApp messages — conversation content between a Customer and the business, received via Meta's WhatsApp Business Platform.
- Contact details — name, phone number, and details a Customer shares in conversation for the purpose of the service.
- Appointments — times, duration, status, linked to the business and Customer.
- Owner business data — business settings, working hours, services and prices, as provided by the Owner.
- Google Calendar data — only if the Owner connects a Google Calendar (see Section 5).
We do not collect data for advertising and do not scan data that is not needed to operate the Service.
2. Purposes
Providing the Service itself (replying to Customers on WhatsApp on the business's behalf, scheduling and reminding about appointments, day-to-day business assistance as configured by the Owner); service memory (remembering relevant facts from conversations to serve Customers better); security, abuse prevention, and legal obligations. We do not sell personal data and do not use it for third-party advertising.
3. AI processing
The Service uses Anthropic's language models via their commercial API to understand messages and draft replies. Under Anthropic's commercial terms, API inputs and outputs are not used to train Anthropic's models by default. We do not train models on your data, and data obtained from Google is not used to train or improve any artificial-intelligence models.
4. Retention
- Memory facts derived from end-customer conversations (e.g., a stated preference): retained up to approximately 90 days, then expire automatically.
- Owner configuration and business data: retained while the account is active.
- Appointments and message history: retained while the account is active, as the business's operational records.
- On account closure or upon request, data is deleted except where retention is legally required.
5. Google Calendar data — what we access, use, store, and share
If an Owner chooses to connect their Google Calendar (explicit consent via Google's OAuth screen):
- What we read: the Owner's calendar list (so they can choose which calendar(s) to connect), free/busy times, and event times — solely to compute real availability before booking an appointment.
- What we write: appointment events created by the Service, into the single calendar the Owner designated. By default an event contains minimal content: the service name + the Customer's first name only. No phone number, no last name, no conversation content. The Owner may choose a more private level ("busy" only) or, with explicit informed opt-in, a more detailed one.
- What is never sent to the calendar: conversation content, internal notes, or contact details beyond the Owner's configured level.
- Storage: we store a sync copy of busy/free times and event times to compute availability, and encrypted access tokens. Disconnecting stops the sync; the Owner can also revoke access at any time via Google security settings.
- Sharing: Google user data is not transferred to any third party except as necessary to provide or improve the Service's user-facing features, to comply with applicable law, or as part of a merger/acquisition with prior notice — and never to advertisers or data brokers.
Limited Use disclosure: MyAgnt's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Sharing — processors
We share personal data only with the sub-processors that operate the Service:
| Provider | Role |
|---|---|
| Meta (WhatsApp Business Platform) | Message transport — messages travel through WhatsApp |
| Anthropic | AI language processing via commercial API |
| Railway | Application and database hosting |
| Calendar integration, only when connected |
Each is contractually bound to data protection. Beyond that, only where required by law.
7. Security
Per-business data isolation at the database level (each business can only access its own data), encrypted transport (HTTPS/TLS), and encrypted storage of access tokens. No system is perfectly secure, but we follow industry-standard practices.
8. Your rights
Under Israel's Protection of Privacy Law, 5741-1981 (as amended), you may access data held about you, request correction of inaccurate data, and request deletion. Customers may contact us directly or through the business that served them. Contact: Flowmart.co@gmail.com.
9. Changes
We will update this page upon any material change; the "Last updated" date will reflect it.