הסכם עיבוד נתונים (DPA)

נספח עיבוד נתונים להסכם השירות בין FORTVISION לבין הלקוח · גרסה 1.0 · 3 בספטמבר 2026
תבנית לחתימה. מסמך זה הוא נוסח סטנדרטי שמוצע ללקוחות FORTVISION. הוא נכנס לתוקף רק לאחר שמולא ונחתם על ידי שני הצדדים. הנוסח האנגלי והעברי זהים במהותם; במקרה של סתירה יגבר הנוסח האנגלי אלא אם הוסכם אחרת בכתב. אין במסמך זה משום ייעוץ משפטי — מומלץ שכל צד יבחן אותו עם יועציו.

הצדדים

נספח זה ("הנספח") נערך בין FORTVISION ("המעבד" / "הספק") לבין שם הלקוח, ח.פ./ע.מ. מספר, שכתובתו כתובת ("בעל השליטה" / "הלקוח"), ומהווה חלק בלתי נפרד מהסכם השירות שביניהם ("ההסכם העיקרי").

1. הגדרות

  1. "דיני הגנת המידע" — חוק הגנת הפרטיות, התשמ"א-1981 ותקנותיו, לרבות תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017 ("החוק הישראלי"); וכן, ככל שחל, תקנה (EU) 2016/679 ("GDPR") ו-UK GDPR.
  2. "מידע אישי", "עיבוד", "בעל שליטה", "מעבד", "נושא המידע" ו"אירוע אבטחה" — כמשמעותם בדיני הגנת המידע. "בעל שליטה" כולל "בעל מאגר" ו"מעבד" כולל "מחזיק" לפי החוק הישראלי.
  3. "נתוני הלקוח" — מידע אישי שהלקוח (או מי מטעמו, לרבות משתמשיו ולקוחות הקצה שלו) מזין, מעלה, מחבר או יוצר בפלטפורמה.
  4. "תת-מעבד" — צד שלישי שהמעבד מסתייע בו לעיבוד נתוני הלקוח.

2. תפקידי הצדדים והיקף העיבוד

  1. הלקוח הוא בעל השליטה בנתוני הלקוח, והמעבד מעבד אותם בשם הלקוח ובהתאם להוראותיו המתועדות בלבד. הוראות הלקוח ניתנות באמצעות ההסכם העיקרי, נספח זה והשימוש בפלטפורמה ובממשקיה.
  2. נושא העיבוד: מתן פלטפורמת ניהול לידים, שיווק, פרסום ותקשורת עם לקוחות ("הפלטפורמה").
  3. אופי ומטרת העיבוד: איסוף, אחסון, ארגון, ניתוח, שליחת תקשורת (אימייל, SMS, WhatsApp, LinkedIn), סנכרון מול פלטפורמות פרסום ומסחר שהלקוח חיבר, יצירת תוכן בעזרת AI לבקשת הלקוח, גיבוי ומחיקה.
  4. סוגי מידע אישי: פרטי זיהוי וקשר (שם, אימייל, טלפון, חברה, תפקיד), נתוני התנהגות באתרי הלקוח (צפיות, קליקים, עגלות, רכישות), תוכן תקשורת עם לידים ולקוחות, נתוני קמפיינים, ופרטי משתמשי הלקוח בפלטפורמה.
  5. קטגוריות נושאי מידע: לידים ולקוחות של הלקוח, מבקרי אתרי הלקוח, עובדי הלקוח ומשתמשיו המורשים.
  6. משך העיבוד: למשך תקופת ההסכם העיקרי ועד להשלמת המחיקה או ההחזרה לפי סעיף 9.
  7. המעבד יודיע ללקוח מיד אם לדעתו הוראה של הלקוח מפרה את דיני הגנת המידע, ורשאי להשעות את ביצועה עד להבהרה.

3. התחייבויות המעבד

  1. לעבד את נתוני הלקוח אך ורק למטרות המפורטות בסעיף 2 ולא למטרותיו העצמאיות; לא למכור נתוני לקוח ולא להשתמש בהם לאימון מודלים כלליים.
  2. להבטיח שכל אדם המורשה לעבד נתוני לקוח מטעמו מחויב לסודיות (בחוזה או בדין) והוסמך בהתאם, ושהגישה ניתנת על בסיס צורך בלבד.
  3. לסייע ללקוח, במידה סבירה ובהתחשב באופי העיבוד, בקיום חובותיו לפי דיני הגנת המידע — לרבות מענה לנושאי מידע, אבטחת מידע, דיווח על אירועי אבטחה, תסקירי השפעה על פרטיות והתייעצות מוקדמת עם רשות.
  4. לנהל רישום של פעולות העיבוד המבוצעות עבור הלקוח, ככל שהדבר נדרש בדין.

4. אמצעי אבטחה

  1. המעבד יישם וישמור אמצעים טכניים וארגוניים הולמים להגנה על נתוני הלקוח מפני עיבוד בלתי מורשה או בלתי חוקי ומפני אובדן, הרס או נזק מקריים, בהתחשב במצב הטכנולוגיה, עלויות היישום, אופי העיבוד והסיכונים לנושאי המידע.
  2. האמצעים המיושמים בפלטפורמה במועד חתימת נספח זה מתוארים בעמוד app.fortvision.com/security ("עמוד האבטחה"), המהווה חלק מנספח זה. המעבד רשאי לעדכן את האמצעים מעת לעת ובלבד שרמת ההגנה הכוללת לא תפחת באופן מהותי.
  3. המעבד יסווג את מאגרי המידע ויחיל את חובות תקנות אבטחת מידע בהתאם לרמת האבטחה החלה עליהם, לרבות נוהל אבטחה, ניהול הרשאות, תיעוד אירועים ובקרת גישה.

5. תתי-מעבדים

  1. הלקוח מאשר באופן כללי את ההסתייעות בתתי-המעבדים המפורטים בעמוד האבטחה במועד החתימה, ואת אלה המפורטים להלן:
    תת-מעבדתפקידמיקום
    Vercel Inc.אירוח האפליקציה וה-APIארה"ב
    Upstash Inc.מסד נתונים (Redis)לפי הגדרת המסד
    Amazon Web Servicesאימייל (SES), אחסון וגיבויים (S3), מסד נתונים (Aurora), Lambda/API Gatewayאירלנד (EU); SES לפי הגדרה
    Cloudflare Inc.CDN לקריאייטיביםגלובלי
    Anthropic PBCשירותי AIארה"ב
    OpenAIשירותי AIארה"ב
    Google LLCשירותי AI (Gemini), כניסה, APIsארה"ב / גלובלי
    Twilio Inc.SMS ושיחותארה"ב / גלובלי
    MicroPaySMS בישראלישראל
    Unipileאינטגרציית LinkedInEU
  2. המעבד יודיע ללקוח בכתב (לרבות בדוא"ל או בעדכון עמוד האבטחה בצירוף הודעה) לפחות 14 ימים לפני הוספה או החלפה של תת-מעבד. הלקוח רשאי להתנגד מטעמים סבירים הקשורים להגנת מידע בתוך תקופה זו; אם לא יימצא פתרון סביר, הלקוח רשאי לסיים את השירות המושפע ללא קנס.
  3. המעבד יטיל על כל תת-מעבד, בחוזה, חובות הגנת מידע שאינן פחותות מאלה שבנספח זה, ויישאר אחראי כלפי הלקוח למעשי תתי-המעבדים.
  4. פלטפורמות שהלקוח בוחר לחבר לחשבונו (למשל Meta, Google Ads, TikTok, LinkedIn, Shopify, Wix, WooCommerce) פועלות כבעלות שליטה עצמאיות לפי תנאיהן ואינן תתי-מעבדים של המעבד.

6. העברות בינלאומיות

  1. נתוני הלקוח עשויים להיות מעובדים בישראל, באיחוד האירופי ובארה"ב. העברה של מידע אישי הכפוף ל-GDPR מחוץ ל-EEA תיעשה על בסיס החלטת נאותות (לרבות ההחלטה בנוגע לישראל) או על בסיס הסעיפים החוזיים הסטנדרטיים של הנציבות האירופית (2021/914), שייחשבו כמשולבים בנספח זה במקרה הצורך (מודול 2, בעל שליטה→מעבד).
  2. העברת מידע ממאגר בישראל תיעשה בהתאם לתקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001.

7. אירועי אבטחה

  1. המעבד יודיע ללקוח ללא דיחוי בלתי סביר ולא יאוחר מ-72 שעות לאחר שנודע לו על אירוע אבטחה הנוגע לנתוני הלקוח.
  2. ההודעה תכלול, ככל הידוע: תיאור האירוע, קטגוריות והיקף משוער של נושאי המידע והרשומות, ההשלכות הצפויות, האמצעים שננקטו או שמוצע לנקוט, ופרטי איש קשר. מידע שאינו זמין במועד ההודעה יימסר בהמשך ללא דיחוי.
  3. המעבד ישתף פעולה עם הלקוח בחקירת האירוע, בצמצום נזקיו ובדיווח לרשויות ולנושאי המידע ככל שנדרש, ולא יודיע לנושאי המידע או לרשויות בשם הלקוח ללא הסכמתו אלא אם הדין מחייב זאת.

8. זכויות נושאי מידע

  1. ככל שנושא מידע יפנה ישירות למעבד בבקשה הנוגעת לנתוני הלקוח, המעבד יפנה אותו ללקוח ויודיע ללקוח על הפנייה בתוך 5 ימי עסקים, ולא ישיב לגופה אלא לפי הוראת הלקוח או חובה בדין.
  2. המעבד יסייע ללקוח, באמצעות כלי הפלטפורמה ובאמצעים סבירים נוספים, במענה לבקשות עיון, תיקון, מחיקה, הגבלה, ניוד והתנגדות.

9. מחיקה והחזרה בסיום ההתקשרות

  1. עם סיום ההסכם העיקרי, ולפי בחירת הלקוח שתימסר בכתב, המעבד ימחק את כל נתוני הלקוח או יחזירם ללקוח בפורמט מקובל הניתן לקריאה על ידי מכונה, וימחק את העותקים הקיימים — בתוך 30 יום מסיום ההתקשרות (ובהיעדר בחירה — ימחק).
  2. למרות האמור, המעבד רשאי לשמור נתוני לקוח ככל שהדין מחייב, ועותקי גיבוי יימחקו במחזור הגיבויים הרגיל ובלבד שלא ייעשה בהם שימוש אחר.
  3. לבקשת הלקוח, המעבד יאשר בכתב את השלמת המחיקה.

10. ביקורת

  1. המעבד יעמיד לרשות הלקוח את המידע הדרוש להוכחת עמידה בחובותיו לפי נספח זה, לרבות עמוד האבטחה, תיאורי הבקרות ותשובות לשאלוני אבטחה סבירים (עד פעם בשנה, אלא אם אירע אירוע אבטחה).
  2. הלקוח (או מבקר בלתי תלוי מטעמו, הכפוף לסודיות) רשאי לערוך ביקורת, לרבות בדיקות, לא יותר מפעם בשנה ובהודעה מוקדמת של 30 יום, בשעות העבודה, באופן שלא יפגע בפעילות המעבד ובלקוחותיו האחרים, ועל חשבון הלקוח. המעבד רשאי לספק דוחות של תתי-מעבדים במקום גישה ישירה לתשתיותיהם.

11. אחריות, תקופה ודין

  1. אחריות הצדדים בקשר לנספח זה כפופה למגבלות האחריות ולסעדים שבהסכם העיקרי, אלא אם הדין אוסר על הגבלה כאמור.
  2. נספח זה נכנס לתוקף במועד חתימתו על ידי שני הצדדים ויעמוד בתוקפו כל עוד המעבד מעבד נתוני לקוח.
  3. במקרה של סתירה בין נספח זה לבין ההסכם העיקרי בענייני הגנת מידע — יגבר נספח זה. הדין החל וסמכות השיפוט — כקבוע בהסכם העיקרי; בהיעדר קביעה — דיני מדינת ישראל ובתי המשפט המוסמכים בתל-אביב-יפו.

חתימות

FORTVISION (המעבד)
שם ותפקיד החותם
חתימה ותאריך
הלקוח (בעל השליטה) שם החברה
שם ותפקיד החותם
חתימה ותאריך

איש קשר להגנת מידע: info@fortvision.com

Data Processing Addendum (DPA)

Data processing addendum to the service agreement between FORTVISION and the Customer · Version 1.0 · 3 September 2026
Template for countersignature. This is the standard wording FORTVISION offers its customers. It takes effect only once completed and signed by both parties. The Hebrew and English texts are substantively identical; in case of conflict the English text prevails unless otherwise agreed in writing. Nothing here is legal advice — each party should review it with its own advisers.

Parties

This addendum (the "Addendum") is made between FORTVISION (the "Processor" / "Provider") and Customer name, registration no. number, of address (the "Controller" / "Customer"), and forms an integral part of the service agreement between them (the "Main Agreement").

1. Definitions

  1. "Data Protection Law" means the Israeli Protection of Privacy Law, 5741-1981 and its regulations, including the Protection of Privacy Regulations (Data Security), 5777-2017 ("Israeli Law"); and, where applicable, Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.
  2. "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Security Incident" have the meanings given in Data Protection Law. "Controller" includes a "database owner" and "Processor" includes a "holder" under Israeli Law.
  3. "Customer Data" means Personal Data that the Customer (or anyone on its behalf, including its users and end clients) enters, uploads, connects or generates in the Platform.
  4. "Sub-processor" means a third party engaged by the Processor to process Customer Data.

2. Roles and scope of processing

  1. The Customer is the Controller of Customer Data and the Processor processes it on the Customer's behalf and only on its documented instructions. The Customer's instructions are given through the Main Agreement, this Addendum and its use of the Platform and its interfaces.
  2. Subject matter: provision of a lead-management, marketing, advertising and customer-communication platform (the "Platform").
  3. Nature and purpose: collection, storage, organisation, analysis, sending of communications (email, SMS, WhatsApp, LinkedIn), synchronisation with advertising and commerce platforms the Customer has connected, AI-assisted content generation at the Customer's request, backup and deletion.
  4. Types of Personal Data: identification and contact details (name, email, phone, company, role), behavioural data on the Customer's sites (views, clicks, carts, purchases), content of communications with leads and customers, campaign data, and details of the Customer's Platform users.
  5. Categories of Data Subjects: the Customer's leads and customers, visitors to the Customer's sites, the Customer's employees and authorised users.
  6. Duration: the term of the Main Agreement until deletion or return is completed under section 9.
  7. The Processor shall promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until clarified.

3. Processor obligations

  1. Process Customer Data solely for the purposes in section 2 and not for its own purposes; never sell Customer Data nor use it to train general-purpose models.
  2. Ensure that every person authorised to process Customer Data is bound by confidentiality (contractual or statutory) and appropriately trained, and that access is granted on a need-to-know basis.
  3. Assist the Customer, to a reasonable extent and taking into account the nature of processing, in meeting its obligations under Data Protection Law — including responses to Data Subjects, security, Security Incident notification, data-protection impact assessments and prior consultation with a supervisory authority.
  4. Maintain a record of the processing activities carried out for the Customer where required by law.

4. Security measures

  1. The Processor shall implement and maintain appropriate technical and organisational measures to protect Customer Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, having regard to the state of the art, implementation costs, the nature of processing and the risks to Data Subjects.
  2. The measures implemented in the Platform at the date of this Addendum are described at app.fortvision.com/security (the "Security Page"), which forms part of this Addendum. The Processor may update the measures from time to time provided the overall level of protection is not materially reduced.
  3. The Processor shall classify its databases and apply the duties of the Data Security Regulations according to the security level applicable to them, including a security procedure, access management, event logging and access control.

5. Sub-processors

  1. The Customer gives general authorisation to the Sub-processors listed on the Security Page at the date of signature and those listed below:
    Sub-processorRoleLocation
    Vercel Inc.Hosting of app and APIUSA
    Upstash Inc.Database (Redis)Per database configuration
    Amazon Web ServicesEmail (SES), storage and backups (S3), database (Aurora), Lambda/API GatewayIreland (EU); SES per configuration
    Cloudflare Inc.CDN for ad creativesGlobal
    Anthropic PBCAI servicesUSA
    OpenAIAI servicesUSA
    Google LLCAI services (Gemini), sign-in, APIsUSA / global
    Twilio Inc.SMS and voiceUSA / global
    MicroPaySMS in IsraelIsrael
    UnipileLinkedIn integrationEU
  2. The Processor shall give the Customer written notice (including by email or by updating the Security Page together with a notice) at least 14 days before adding or replacing a Sub-processor. The Customer may object on reasonable data-protection grounds within that period; if no reasonable solution is found, the Customer may terminate the affected service without penalty.
  3. The Processor shall impose on each Sub-processor, by contract, data-protection obligations no less protective than those in this Addendum, and remains liable to the Customer for the Sub-processors' acts.
  4. Platforms the Customer chooses to connect to its account (e.g. Meta, Google Ads, TikTok, LinkedIn, Shopify, Wix, WooCommerce) act as independent controllers under their own terms and are not Sub-processors of the Processor.

6. International transfers

  1. Customer Data may be processed in Israel, the European Union and the United States. Transfers of Personal Data subject to the GDPR outside the EEA are made on the basis of an adequacy decision (including the decision concerning Israel) or the European Commission's Standard Contractual Clauses (2021/914), which are deemed incorporated into this Addendum where required (Module 2, controller to processor).
  2. Transfers from a database in Israel are made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001.

7. Security Incidents

  1. The Processor shall notify the Customer without undue delay and no later than 72 hours after becoming aware of a Security Incident concerning Customer Data.
  2. The notice shall include, to the extent known: a description of the incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information not available at the time of notice shall be provided without undue delay thereafter.
  3. The Processor shall cooperate with the Customer in investigating and mitigating the incident and in notifying authorities and Data Subjects where required, and shall not notify Data Subjects or authorities on the Customer's behalf without its consent unless required by law.

8. Data Subject rights

  1. If a Data Subject contacts the Processor directly regarding Customer Data, the Processor shall refer them to the Customer and inform the Customer within 5 business days, and shall not respond substantively except on the Customer's instruction or where required by law.
  2. The Processor shall assist the Customer, through the Platform's tools and other reasonable means, in responding to requests for access, rectification, erasure, restriction, portability and objection.

9. Deletion and return on termination

  1. Upon termination of the Main Agreement, and at the Customer's written election, the Processor shall delete all Customer Data or return it to the Customer in a commonly used, machine-readable format and delete existing copies — within 30 days of termination (and, absent an election, delete).
  2. Notwithstanding the above, the Processor may retain Customer Data to the extent required by law, and backup copies shall be deleted in the ordinary backup cycle provided they are not otherwise used.
  3. On request, the Processor shall confirm completion of deletion in writing.

10. Audit

  1. The Processor shall make available to the Customer the information necessary to demonstrate compliance with this Addendum, including the Security Page, descriptions of controls and answers to reasonable security questionnaires (at most once a year, unless a Security Incident has occurred).
  2. The Customer (or an independent auditor on its behalf, bound by confidentiality) may conduct an audit, including inspections, no more than once a year on 30 days' notice, during business hours, in a manner that does not disrupt the Processor's operations or its other customers, and at the Customer's cost. The Processor may provide Sub-processor reports in lieu of direct access to their infrastructure.

11. Liability, term and governing law

  1. Each party's liability in connection with this Addendum is subject to the limitations of liability and remedies in the Main Agreement, unless such limitation is prohibited by law.
  2. This Addendum takes effect on signature by both parties and remains in force for as long as the Processor processes Customer Data.
  3. In case of conflict between this Addendum and the Main Agreement on data-protection matters, this Addendum prevails. Governing law and jurisdiction are as set out in the Main Agreement; absent such provision, the laws of the State of Israel and the competent courts of Tel Aviv-Jaffa.

Signatures

FORTVISION (Processor)
Name and title of signatory
Signature and date
Customer (Controller) Company name
Name and title of signatory
Signature and date

Data-protection contact: info@fortvision.com