Data Processing Agreement (DPA)
Annex to the Service Agreement between Figureit and Customer
Effective date: May 5, 2026 | Last updated: May 5, 2026
Note: This DPA is incorporated into the Service Agreement by reference. Separate execution is not required when this DPA is incorporated into a signed Service Agreement, but is available if the parties prefer separate documentation.
This Data Processing Agreement ("DPA") is entered into between Figureit Ltd., Company Reg. 517093555, of 58 Ha’Rakevet St., Tel Aviv-Yafo ("Figureit", "Processor", or "we") and the customer that has signed a Service Agreement with the Processor ("Customer" or "Controller"). This DPA forms an integral part of the Service Agreement.
This DPA applies whenever the Processor processes personal data on behalf of the Customer in the course of providing the Services. In any conflict between this DPA and the Service Agreement regarding the processing of personal data, the DPA prevails.
This DPA is written in accordance with the Israeli Privacy Protection Law, 1981 and Amendment No. 13 (effective August 2025), and is aligned with the principles of the EU General Data Protection Regulation (GDPR) as a guideline.
1. Scope and Background
- This DPA applies to the processing of personal data carried out by the Processor on behalf of the Customer for the purpose of providing the Services as defined in the Service Agreement.
- The Customer is the Controller of the personal data, and the Processor acts solely as a Processor in accordance with the Customer’s instructions.
- This DPA enters into force on the effective date of the Service Agreement and remains in force for as long as the Processor processes personal data on behalf of the Customer, and for any period thereafter as required by law.
- To the extent the Processor qualifies as a "holder" (מחזיק) of the Customer’s database under the Israeli Privacy Protection (Information Security) Regulations, the Processor will comply directly with the obligations applicable to a holder under those Regulations, including Regulations 2 and 15(a).
2. Definitions
"Personal Data" — information about an identified or identifiable individual, as defined under the Privacy Protection Law.
"Processing" — any operation performed on personal data, including collection, storage, organization, analysis, alteration, retrieval, disclosure, deletion, or destruction.
"Data Subject" — the individual to whom the personal data relates.
"Sub-processor" — a third party engaged by the Processor to process personal data on behalf of the Customer.
"Data Protection Law" — the Israeli Privacy Protection Law, 1981 (including Amendment 13 and its regulations), the GDPR, and any applicable privacy law binding on the parties.
Capitalized terms not defined here have the meaning given in the Service Agreement.
3. Description of Processing
- The subject matter, purpose, nature of processing, categories of personal data, and categories of data subjects are detailed in Schedule A to this DPA.
- The Processor shall process personal data solely on the documented instructions of the Customer, including those reflected in the Service Agreement and this DPA.
- The Processor shall promptly inform the Customer if, in its opinion, an instruction conflicts with applicable Data Protection Law.
4. Processor Obligations
- The Processor shall process personal data only for the purpose of providing the Services and in accordance with the Customer’s instructions.
- The Processor shall ensure that any person authorized to process personal data on its behalf is bound by an obligation of confidentiality.
- The Processor shall implement reasonable and customary information security measures, as detailed in Schedule C to this DPA.
- The Processor shall, to the extent reasonably possible, assist the Customer in fulfilling its obligations under Data Protection Law, including responding to data subject requests, performing data protection impact assessments (DPIAs), and consulting with the supervisory authority where required.
- The Processor shall provide the Customer, at least once per year, with a written report on its compliance with this DPA and the applicable provisions of the Privacy Protection (Information Security) Regulations, and shall promptly notify the Customer of any security incident as set forth in Section 8.
5. Information Security
- The Processor implements technical and organizational security measures appropriate to the sensitivity of the personal data and the risks of its processing, including encryption, access controls, monitoring, hardening, and incident response procedures. Further detail is provided in Schedule C.
- The Processor shall periodically review and update its security measures in light of technological developments and identified risks.
6. Sub-processors
- The Customer provides general authorization for the engagement of sub-processors to process personal data on its behalf, provided that the Processor enters into a written agreement with each sub-processor that imposes data-protection obligations no less protective than those set forth in this DPA.
- The list of sub-processors engaged at the effective date of this DPA is attached as Schedule B. Updates to this list will be communicated to the Customer in accordance with Section 6.3.
- The Processor shall give the Customer at least 30 days’ prior notice of its intention to engage or replace any material sub-processor. The Customer may object on reasonable grounds related to data protection, and may terminate the Service Agreement if the Processor cannot reasonably address the objection, provided the objection is submitted within 14 days of the notice.
7. Data Subjects and Their Requests
- The Processor shall, by appropriate technical and organizational measures and to the extent possible, assist the Customer in fulfilling its obligations to respond to data subject requests (including rights of access, correction, deletion, objection, and portability).
- If the Processor receives a request directly from a data subject, it shall, without undue delay, inform the Customer and shall not respond directly to the request unless expressly instructed by the Customer or required by law.
8. Personal Data Breach
- In the event of a personal data breach affecting personal data processed for the Customer, the Processor shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware of the breach.
- The notification shall include, to the extent available: a description of the breach, the categories of data and approximate number of data subjects affected, the likely consequences, the measures taken, and recommendations for mitigating harm.
- The Processor shall, to the extent possible, assist the Customer in fulfilling its reporting obligations to the Privacy Protection Authority and to data subjects under applicable law.
9. International Data Transfers
- Some of the Processor’s sub-processors are located outside Israel, including in the United States and the European Union. The Customer authorizes the transfer of personal data to such sub-processors, subject to appropriate safeguards.
- For transfers subject to the GDPR or similar law, the Processor shall implement Standard Contractual Clauses (SCCs) or another mechanism that constitutes an adequate safeguard under applicable law.
10. Audits and Inspections
- The Customer is entitled to receive from the Processor reasonable documentation evidencing its compliance with this DPA, including certifications, third-party audit reports (such as SOC 2 or ISO 27001) where available, and information security certificates.
- Where such documentation is insufficient, and subject to at least 30 days’ prior written notice, the Customer may conduct an audit of the Processor no more than once per year, through an independent auditor that is not a competitor of the Processor, during normal business hours, in a manner that does not disrupt the Processor’s operations, and at the Customer’s sole cost.
11. Return and Deletion of Data
- Upon termination of the Services, and at the Customer’s election, the Processor shall delete or return the personal data in its possession.
- Unless the Customer requests otherwise, the Processor shall delete personal data from its active systems within 90 days of termination of the Services, except for data that must be retained by law.
- Upon completion of the deletion or return, the Processor shall, on the Customer’s written request, confirm in writing that the deletion or return has been carried out.
- Statutory retention requirements shall override the foregoing.
12. Liability, Term, and Termination
- This DPA shall remain in effect for as long as the Processor processes personal data on behalf of the Customer. Provisions relating to confidentiality, security, liability, and deletion shall survive termination as required.
- The parties’ liability under this DPA is subject to the limitation of liability set forth in the Service Agreement, except where such limitation is prohibited by Data Protection Law.
13. Miscellaneous
- In any conflict between this DPA and the Service Agreement regarding the processing of personal data, this DPA prevails.
- The Processor may update this DPA from time to time. Updates will be published at figureit.ai/dpa and will take effect 30 days after notice to the Customer, unless an earlier change is required by law.
- This DPA is governed by the laws of the State of Israel. The competent courts in Tel Aviv-Yafo shall have exclusive jurisdiction.
- For questions about this DPA: privacy@figureit.ai.
Schedule A — Description of Processing
Subject Matter: Processing of personal data in the course of providing Figureit Services to the Customer under the Service Agreement.
Purpose and Nature: Storage, analysis, AI-powered insight generation, reporting, and forecasting based on Customer Data.
Duration: For the term of the Service Agreement, subject to Section 11 of this DPA (deletion period of up to 90 days).
Categories of Data Subjects: Customer’s employees, advisors, and contractors; Customer’s end customers; suppliers and business contacts whose data the Customer uploads to the Platform.
Categories of Personal Data: Full names, contact details (email, phone, address), roles and employment details, business activity data (sales, purchasing, inventory), Platform interaction data. Sensitive data (health, biometric, payment-card data, etc.) shall not be entered unless expressly agreed in writing.
Nature of Processing: Storage, organization, analysis, computation, application of AI models, presentation through the Platform, backup, and use of anonymized or aggregated non-identifying data for service improvement.
Schedule B — List of Sub-processors
At the effective date of this DPA, the Processor engages the following sub-processors:
- Amazon Web Services (AWS) — cloud infrastructure, storage, and runtime systems. Location: United States / European Union.
- Google Cloud Platform (including BigQuery) — cloud infrastructure, data warehouse, and AI services. Location: United States / European Union / Israel.
- Render — database hosting and infrastructure. Location: United States.
- OpenAI — large language model (LLM) services powering AI capabilities. Location: United States.
- Anthropic (Claude) — large language model (LLM) services powering AI capabilities. Location: United States.
- Additional operational service providers: email, analytics, billing, and customer relationship management (CRM).
Schedule C — Technical and Organizational Measures
The Processor applies reasonable technical and organizational security measures appropriate to the nature of the Services and the level of risk, as implemented in the relevant service environment. These include, among others:
- Encryption: TLS 1.2 or higher in transit; encryption at rest where technically feasible.
- Access Controls: Role-based access control (RBAC), principle of least privilege, and multi-factor authentication for Processor staff.
- Network Security: Infrastructure-level security measures, as implemented in the operating environment.
- Monitoring and Oversight: Secure logging and incident response procedures, as appropriate.
- Vulnerability Management: Periodic security scans and patching, with additional measures (including penetration testing) where implemented.
- Organizational Security: Confidentiality agreements with personnel, security training, and data access procedures.
- Business Continuity: Backup and recovery procedures, in accordance with the service environment.
- Sub-processor Management: Vendor screening, binding DPAs, ongoing oversight.
הסכם עיבוד נתונים (DPA)
נספח להסכם השירות בין Figureit לבין הלקוח
תאריך תחילה: 5 במאי 2026 | עדכון אחרון: 5 במאי 2026
הערה: ה-DPA נכלל בהסכם השירות על דרך הפניה. חתימה נפרדת אינה חובה כאשר ה-DPA הוטמע בהסכם השירות, אך נדרשת אם הצדדים בוחרים בתיעוד נפרד.
הסכם עיבוד נתונים זה (להלן: "ה-DPA") נחתם בין פיגראיט בע"מ, ח.פ. 517093555, מרח׳ הרכבת 58, תל אביב-יפו (להלן: "Figureit", "המעבד" או "הספק") לבין הלקוח אשר התקשר עם הספק בהסכם שירות (להלן: "הלקוח"). ה-DPA מהווה חלק בלתי נפרד מהסכם השירות.
ה-DPA חל בכל מקרה שבו הספק מעבד מידע אישי בשם הלקוח במסגרת אספקת השירותים. במקרה של סתירה בין ה-DPA לבין הסכם השירות בכל הנוגע לעיבוד מידע אישי — יגברו הוראות ה-DPA.
ה-DPA נכתב בהתאם לחוק הגנת הפרטיות, התשמ"א-1981 ולתיקון מס׳ 13 (אוגוסט 2025), ובהתאם לעקרונות תקנות הגנת המידע הכלליות של האיחוד האירופי (GDPR) כקו מנחה.
1. תחולה ורקע
- ה-DPA חל על עיבוד מידע אישי המבוצע על ידי הספק בשם הלקוח לצורך אספקת השירותים, כהגדרתם בהסכם השירות.
- הלקוח הוא בעל מאגר המידע / בקר ("Controller"), והספק פועל כמעבד ("Processor") בלבד, בהתאם להוראות הלקוח.
- ה-DPA נכנס לתוקף במועד תחילת הסכם השירות ועומד בתוקף כל עוד הספק מעבד מידע אישי בשם הלקוח, ולתקופה הנדרשת לאחר מכן לפי דין.
- במקרים בהם המעבד נחשב "מחזיק" של מאגר המידע של הלקוח לפי תקנות הגנת הפרטיות (אבטחת מידע), המעבד יקיים גם את החובות החלות עליו ישירות כמחזיק לפי התקנות, לרבות תקנות 2 ו-15(א).
2. הגדרות
"מידע אישי" — מידע על אדם מזוהה או הניתן לזיהוי, כהגדרתו בחוק הגנת הפרטיות.
"עיבוד" — כל פעולה הנעשית במידע אישי, לרבות איסוף, אחסון, ארגון, ניתוח, שינוי, אחזור, גילוי, מחיקה או השמדה.
"בעל מידע" — האדם שאליו מתייחס המידע האישי.
"קבלן משנה" — צד שלישי שהמעבד נעזר בו לצורך עיבוד מידע אישי בשם הלקוח.
"דין הגנת פרטיות" — חוק הגנת הפרטיות התשמ"א-1981 (לרבות תיקון 13 ותקנותיו), ה-GDPR, וכל דין החל על הצדדים בקשר להגנת פרטיות.
מונחים שלא הוגדרו כאן תהא להם המשמעות שניתנה להם בהסכם השירות.
לעניין דין הגנת הפרטיות בישראל, ה"בקר" (Controller) מקביל ל"בעל מאגר המידע", וה"מעבד" (Processor) עשוי להיחשב כ"מחזיק" כהגדרת מונחים אלה בחוק הגנת הפרטיות, התשמ"א-1981 ובתקנות מכוחו.
3. תיאור העיבוד
- נושא העיבוד, מטרתו, אופיו, סוגי המידע האישי וקטגוריות בעלי המידע מפורטים בנספח א' ל-DPA זה.
- המעבד יבצע עיבוד מידע אישי אך ורק על בסיס הוראות מתועדות מאת הלקוח, לרבות ההוראות הגלומות בהסכם השירות וב-DPA זה.
- המעבד יודיע ללקוח באופן מיידי אם, לדעתו, הוראה כלשהי מנוגדת לדין הגנת פרטיות.
4. התחייבויות המעבד
- המעבד יעבד מידע אישי רק לצורך מתן השירותים ובהתאם להוראות הלקוח.
- המעבד יבטיח כי כל אדם המורשה לעבד מידע אישי מטעמו מחויב לחובת סודיות.
- המעבד ייקוט אמצעי אבטחת מידע סבירים ומקובלים, כמפורט בנספח ג' ל-DPA זה.
- המעבד יסייע ללקוח, ככל שהדבר אפשרי באופן סביר, במילוי חובותיו של הלקוח לפי דין הגנת פרטיות, לרבות תגובה לבקשות בעלי מידע, ביצוע הערכות השפעה (DPIA), והתייעצות עם הרשות להגנת הפרטיות בעת הצורך.
- המעבד יספק ללקוח, אחת לשנה לכל הפחות, דיווח כתוב על אופן עמידתו בהוראות ה-DPA ובהוראות תקנות הגנת הפרטיות (אבטחת מידע) הרלוונטיות, וכן יודיע ללקוח באופן מיידי על אירועי אבטחה כאמור בסעיף 8.
5. אבטחת מידע
- המעבד מיישם אמצעי אבטחת מידע טכניים וארגוניים סבירים, התואמים את רגישות המידע ואת הסיכונים הכרוכים בעיבודו, לרבות הצפנה, בקרות גישה, ניטור ובקרה, הקשחת מערכות ונהלי תגובה לאירועים. פירוט נוסף בנספח ג'.
- המעבד יבחן ויעדכן את אמצעי האבטחה מעת לעת בהתאם להתפתחויות טכנולוגיות ולסיכונים שזוהו.
6. קבלני משנה
- הלקוח מאשר באופן כללי את העסקתם של קבלני משנה לצורך עיבוד מידע אישי בשמו, ובלבד שהמעבד יחתום עם כל קבלן משנה על הסכם המבטיח רמת הגנה על מידע אישי שאינה נופלת מזו שב-DPA זה.
- רשימת קבלני המשנה הקיימים במועד תחילת ה-DPA מצורפת כנספח ב'. עדכונים לרשימה ימסרו ללקוח בהתאם לסעיף 6.3.
- המעבד יודיע ללקוח לפחות 30 ימים מראש על כוונה להוסיף או להחליף קבלן משנה מהותי. ללקוח עומדת הזכות להתנגד מטעמים סבירים הקשורים להגנה על המידע, ולסיים את הסכם השירות אם המעבד אינו יכול לטפל בהתנגדות באופן סביר, ובלבד שההתנגדות הוגשה בתוך 14 ימים מההודעה.
7. בעלי מידע ובקשותיהם
- המעבד יסייע ללקוח באמצעים טכניים וארגוניים מתאימים, ככל הניתן, במילוי חובותיו לטפל בבקשות בעלי מידע (לרבות זכות עיון, תיקון, מחיקה, התנגדות וניידות).
- אם המעבד יקבל בקשה ישירות מבעל מידע, הוא יודיע על כך ללקוח ללא שיהוי בלתי סביר ולא יענה לבקשה ישירות אלא אם ניתנה הוראה מפורשת מהלקוח או נדרש לכך לפי דין.
8. אירועי אבטחה במידע אישי
- במקרה של אירוע אבטחה במידע אישי המעובד עבור הלקוח, המעבד יודיע ללקוח ללא שיהוי בלתי סביר, ובכל מקרה לא יאוחר מ-72 שעות ממועד הגילוי.
- ההודעה תכלול, ככל הניתן: תיאור האירוע, סוגי המידע ומספרם המשוער של בעלי המידע שנפגעו, ההשלכות הצפויות, האמצעים שננקטו וההמלצות לצמצום הנזק.
- המעבד יסייע ללקוח, ככל הניתן, במילוי חובות הדיווח של הלקוח לרשות להגנת הפרטיות ולבעלי המידע לפי דין.
9. העברות מידע בינלאומיות
- חלק מקבלני המשנה של המעבד ממוקמים מחוץ לישראל, לרבות בארה"ב ובאיחוד האירופי. הלקוח מאשר העברת מידע אישי לקבלני משנה אלה, בכפוף לאמצעי הגנה מתאימים.
- ביחס להעברות הכפופות ל-GDPR או לדין דומה, המעבד יישם תניות חוזיות סטנדרטיות (SCCs) או מנגנון אחר המהווה אמצעי הגנה הולם לפי הדין הרלוונטי.
10. ביקורת ובחינה
- הלקוח רשאי לקבל מהמעבד מסמכים סבירים המעידים על עמידתו בהוראות ה-DPA, לרבות אישורים, דוחות ביקורת חיצוניים (כגון SOC 2 או ISO 27001) ככל שקיימים, ותעודות אבטחת מידע.
- ככל שהמסמכים שלעיל אינם מספיקים, ובכפוף להודעה מוקדמת בכתב של 30 ימים לפחות, רשאי הלקוח לבצע ביקורת אצל המעבד פעם בשנה לכל היותר, באמצעות מבקר עצמאי שאינו מתחרה של המעבד, בשעות העבודה המקובלות, באופן שלא ישבש את פעילות המעבד, ובמימון מלא של הלקוח.
11. החזרה ומחיקה של מידע
- עם סיום השירותים, ולפי בחירת הלקוח, המעבד ימחק או יחזיר את המידע האישי המצוי בידיו.
- אלא אם הלקוח מבקש אחרת, המעבד ימחק את המידע האישי ממערכותיו הפעילות תוך 90 ימים ממועד סיום השירותים, למעט מידע שיש לשמרו לפי דין.
- עם השלמת המחיקה או ההחזרה, המעבד ימסור ללקוח, לבקשתו הכתובה, אישור בכתב על ביצוע המחיקה או ההחזרה.
- הוראות שמירה הקבועות בדין יגברו על האמור לעיל.
12. אחריות, תקופה וסיום
- ה-DPA יישאר בתוקף כל עוד המעבד מעבד מידע אישי בשם הלקוח. הוראות הנוגעות לסודיות, אבטחת מידע, אחריות ומחיקה ימשיכו לחול גם לאחר סיומו, ככל שיידרש.
- אחריות הצדדים לפי ה-DPA כפופה להגבלת האחריות הקבועה בהסכם השירות, למעט במקרה שבו הגבלה כאמור אסורה לפי דין הגנת פרטיות.
13. שונות
- במקרה של סתירה בין הוראות ה-DPA לבין הסכם השירות בכל הנוגע לעיבוד מידע אישי — יגברו הוראות ה-DPA.
- המעבד רשאי לעדכן את ה-DPA מעת לעת. עדכונים יפורסמו בכתובת figureit.ai/dpa, וייכנסו לתוקף 30 ימים לאחר ההודעה ללקוח, אלא אם נדרש שינוי מיידי לפי דין.
- על ה-DPA יחולו דיני מדינת ישראל. סמכות השיפוט הבלעדית נתונה לבתי המשפט המוסמכים בעיר תל אביב-יפו.
- לפניות בנושא ה-DPA: privacy@figureit.ai.
נספח א' — תיאור העיבוד
נושא העיבוד: עיבוד מידע אישי במסגרת אספקת שירותי Figureit ללקוח, לפי הסכם השירות.
מטרת העיבוד ואופיו: אחסון, ניתוח, הפקת תובנות מבוססות AI, דוחות ותחזיות, על בסיס נתוני הלקוח.
תקופת העיבוד: למשך תקופת הסכם השירות, ובכפוף לסעיף 11 ל-DPA זה (תקופת מחיקה של עד 90 ימים).
קטגוריות בעלי המידע: עובדים, יועצים וקבלנים של הלקוח; לקוחות הקצה של הלקוח; ספקים ואנשי קשר עסקיים שמידעם נטען על ידי הלקוח לפלטפורמה.
קטגוריות מידע אישי: שמות מלאים, פרטי התקשרות (דוא"ל, טלפון, כתובת), תפקידים ופרטי תעסוקה, נתוני פעילות עסקית (מכירות, רכש, מלאי), נתוני אינטראקציה עם הפלטפורמה. הלקוח לא יזין מידע רגיש (מידע על בריאות, ביומטריה, אשראי וכו') אלא אם הוסכם אחרת בכתב.
אופי העיבוד: אחסון, ארגון, ניתוח, חישוב, יישום מודלי AI, הצגה דרך הפלטפורמה, גיבוי, ושימוש במידע אנונימי או מצרפי שאינו מזהה לצרכי שיפור השירות.
נספח ב' — רשימת קבלני משנה
במועד תחילת ה-DPA, המעבד מעסיק את קבלני המשנה הבאים:
- Amazon Web Services (AWS) — תשתית ענן, אחסון ומערכות הרצה. מיקום: ארה"ב / האיחוד האירופי.
- Google Cloud Platform (כולל BigQuery) — תשתית ענן, מחסן נתונים ושירותי AI. מיקום: ארה"ב / האיחוד האירופי / ישראל.
- Render — אחסון מסדי נתונים ותשתית. מיקום: ארה"ב.
- OpenAI — שירותי מודלי שפה גדולים (LLM) להפעלת יכולות AI. מיקום: ארה"ב.
- Anthropic (Claude) — שירותי מודלי שפה גדולים (LLM) להפעלת יכולות AI. מיקום: ארה"ב.
- ספקי שירות תפעוליים נוספים: שירותי דוא"ל, אנליטיקה, חיוב וניהול קשרי לקוחות (CRM).
נספח ג' — אמצעי אבטחה טכניים וארגוניים
המעבד מיישם אמצעי אבטחה טכניים וארגוניים סבירים, התואמים את אופי השירות ואת רמת הסיכון, ככל שמיושמים בסביבת השירות הרלוונטית. בין היתר:
- הצפנה: TLS 1.2 ומעלה לתעבורה; הצפנת מידע במנוחה ככל שאפשרי טכנית.
- בקרות גישה: בקרת גישה מבוססת תפקיד (RBAC), עיקרון ההרשאות המינימליות, ואימות דו-שלבי לעובדי המעבד.
- אבטחת רשת: אמצעי אבטחה ברמת התשתית, ככל שמיושמים בסביבת ההפעלה.
- ניטור ובקרה: לוגים מאובטחים ונהלי תגובה לאירועי אבטחה, לפי הצורך.
- ניהול פגיעויות: סריקות אבטחה תקופתיות ועדכוני אבטחה, ופעולות נוספות (לרבות מבחני חדירה) ככל שמיושמות.
- אבטחה ארגונית: הסכמי סודיות לעובדים, הדרכות אבטחת מידע, ונהלי גישה למידע.
- המשכיות עסקית: גיבויים ותהליכי שחזור, בהתאם לסביבת השירות.
- ניהול קבלני משנה: סינון ספקים, הסכמי DPA, ופיקוח שוטף.