Shefy Shefy
  • Features
  • Pricing
  • Contact
  • FR
  • Log in
FR EN
Log in Try for free
Legal document

Privacy Policy

Last updated: September 14, 2026 (version 2026-09-14-v3)

Lire cette page en français →

Table of contents

  1. Who is responsible for your data
  2. Contact us
  3. Scope
  4. Account and profile data
  5. Business data
  6. Data about your own clients
  7. Appointment data
  8. Invoice, quote and payment metadata
  9. Communications data
  10. Technical, log and device data
  11. Usage data
  12. AI-related data
  13. Imported documents and OCR
  14. Purposes of processing
  15. Legal bases
  16. Our role: controller or processor
  17. Sub-processors — hosting and infrastructure
  18. Sub-processors — payment and billing
  19. Sub-processors — electronic invoicing
  20. Sub-processors — messaging
  21. Sub-processors — artificial intelligence
  22. International data transfers
  23. Retention period
  24. Security
  25. Your rights
  26. Your responsibility towards your own clients
  27. Cookies and analytics
  28. Children's data
  29. Changes to this policy
  30. Contact

1.Who is responsible for your data

Shefa Digital (Deborah Cohen), a sole proprietorship under Israeli law operating the Shefy service, is the data controller for the personal data described in this policy, as regards account and platform data (see section 16 for the distinction with data you enter about your own clients).

2.Contact us

For any question about this policy or your personal data, you can write to us at [email protected]. Data controller: Shefa Digital (Deborah Cohen), sole proprietorship under Israeli law, business number 329856173, HaAlon 5, Hadera, Israel — see also our Legal Notice.

3.Scope

This policy applies to personal data processed in connection with your use of the Shefy service (marketing site and application). It does not apply to third-party services you may use alongside Shefy.

4.Account and profile data

First and last name, email address, password (hashed), phone number, date of birth, preferred language, and your role within your business (owner, staff member, accountant).

5.Business data

Business name, address, industry, VAT number and registration identifiers (SIREN/SIRET or an equivalent depending on your country), business contact details, and tax information required to generate your quotes and invoices.

6.Data about your own clients

Data you enter about your own clients (name, contact details, quote/invoice/appointment history) is processed by Shefy on your behalf, as a tool you use to manage your business — see sections 16 and 26 for details of this distinction.

7.Appointment data

Dates, times, service types, associated notes, and contact information related to appointment scheduling, where you use this feature.

8.Invoice, quote and payment metadata

Amounts, dates, statuses, recorded payment methods, and the history of the commercial documents you create in Shefy.

9.Communications data

The content and metadata of emails, SMS, and WhatsApp messages sent from Shefy to your clients, as well as your exchanges with our support team.

10.Technical, log and device data

IP address, browser and device type, and technical connection/error logs, necessary for the operation and security of the service.

11.Usage data

Interactions with Shefy's features (pages viewed, actions taken), used to improve the service and diagnose technical issues.

12.AI-related data

When you use an AI-assisted feature (for example initial setup or document import), the information you provide on that occasion (description of your business, submitted documents) is sent to our artificial intelligence provider solely to generate the requested suggestion — see section 21.

13.Imported documents and OCR

Documents you import (for example, supplier invoices) and the data automatically extracted from them through optical character recognition (OCR).

14.Purposes of processing

We process your data to: provide and operate the service, manage your account and subscription, ensure security and prevent fraud, provide support, improve the service, and comply with our legal obligations (in particular accounting and tax obligations).

15.Legal bases

Where the General Data Protection Regulation (GDPR) or an equivalent regulation applies to you, we process your data on the basis of the performance of our contract with you (providing the service), our legitimate interest (security, service improvement), compliance with a legal obligation, or, where required, your consent.

16.Our role: controller or processor

For your account and platform data (sections 4, 10, 11), Shefa Digital acts as data controller. For data you enter about your own clients (section 6) and, more broadly, the business data you manage through Shefy, Shefa Digital acts as a processor (or an equivalent role under your local regulation) acting on your behalf and on your instructions; you remain responsible, as the controller, for complying with your own obligations towards your clients.

17.Sub-processors — hosting and infrastructure

Our server infrastructure is hosted with third-party hosting/cloud providers located in the European Union. Storage of certain files (for example, imported documents) may be handled by a third-party cloud provider (Amazon Web Services).

18.Sub-processors — payment and billing

Payment for your own Shefy subscription is processed by a third-party online payment/billing provider. Where features for collecting payments from your own clients are offered, they are provided by third-party payment service providers (PSPs), separate from Shefa Digital.

19.Sub-processors — electronic invoicing

For users concerned, your invoices may be transmitted to an approved third-party dematerialization platform, for the purpose of complying with your electronic invoicing obligations.

20.Sub-processors — messaging

Delivery of transactional emails and SMS/WhatsApp messages is handled by third-party providers specialized in this type of communication.

21.Sub-processors — artificial intelligence

AI-assisted features rely on an artificial intelligence service hosted by a third-party cloud provider (Amazon Web Services, Bedrock service). Data you submit to these features is processed by this provider solely to generate the requested suggestion.

22.International data transfers

As Shefa Digital is established in Israel, some administrative processing may involve a transfer of data outside the European Union. Israel benefits from an adequacy decision of the European Commission under the GDPR. Where providers located outside the European Union are used (for example, certain cloud services), we aim to rely on appropriate safeguards (such as standard contractual clauses) to the extent required by applicable regulation.

23.Retention period

We retain your data for as long as your account is active, and then for as long as necessary to comply with our own legal obligations (in particular accounting and tax obligations, whose durations are set by applicable regulation) or to defend our rights, before deletion or anonymization. See also section 25 of our Terms of Service regarding account closure.

24.Security

We implement reasonable technical and organizational measures to protect your data (encryption of communications, access control, password hashing). As no system is infallible, we cannot, however, guarantee absolute security.

25.Your rights

Where the GDPR or an equivalent regulation applies to you, you have, over the data for which we are the controller, a right of access, rectification, erasure, restriction, objection, and portability, as well as the right to lodge a complaint with the competent supervisory authority. To exercise these rights, contact us at [email protected]. For data we process on behalf of a Shefy user regarding their own clients, please contact that user directly (see section 26).

26.Your responsibility towards your own clients

If you use Shefy to manage data about your own clients, you are responsible, as the controller of that data, for complying with your own obligations towards them (providing information, having a legal basis, retention periods, responding to their requests). Shefy then acts as a tool/processor on your behalf, under the conditions described in section 16.

27.Cookies and analytics

Our marketing site and application may use cookies or similar technologies strictly necessary for the service to function (for example, keeping you logged in), as well as, where applicable, audience-measurement tools. Where required by applicable regulation, we will ask for your consent before placing any non-essential cookies.

28.Children's data

Shefy is a professional tool intended for adults acting in a professional capacity. We do not knowingly collect data about children.

29.Changes to this policy

We may change this policy, in particular to reflect changes to the service, our sub-processors, or applicable regulation. We will communicate any material change to you by a reasonable means before it takes effect.

30.Contact

For any question about this policy or to exercise your rights, contact us at [email protected].

This policy describes the processing of personal data in connection with the Shefy service, operated by Shefa Digital. See also our Terms of Service.
Shefy Shefy
  • Features
  • Pricing
  • Contact
  • Log in
  • Terms of Service
  • Privacy Policy
  • Legal Notice
© 2026 Shefy — operated by Shefa Digital. All rights reserved.
Legal / Compliance Information Security Fraud Prevention Anti-Bribery AML/CTF & Sanctions