1.Who is responsible for your data
Shefa Digital (Deborah Cohen), a sole proprietorship under Israeli law operating the Shefy service, is the data controller for the personal data described in this policy, as regards account and platform data (see section 16 for the distinction with data you enter about your own clients).
2.Contact us
For any question about this policy or your personal data, you can write to us at [email protected]. Data controller: Shefa Digital (Deborah Cohen), sole proprietorship under Israeli law, business number 329856173, HaAlon 5, Hadera, Israel — see also our Legal Notice.
3.Scope
This policy applies to personal data processed in connection with your use of the Shefy service (marketing site and application). It does not apply to third-party services you may use alongside Shefy.
4.Account and profile data
First and last name, email address, password (hashed), phone number, date of birth, preferred language, and your role within your business (owner, staff member, accountant).
5.Business data
Business name, address, industry, VAT number and registration identifiers (SIREN/SIRET or an equivalent depending on your country), business contact details, and tax information required to generate your quotes and invoices.
6.Data about your own clients
Data you enter about your own clients (name, contact details, quote/invoice/appointment history) is processed by Shefy on your behalf, as a tool you use to manage your business — see sections 16 and 26 for details of this distinction.
7.Appointment data
Dates, times, service types, associated notes, and contact information related to appointment scheduling, where you use this feature.
8.Invoice, quote and payment metadata
Amounts, dates, statuses, recorded payment methods, and the history of the commercial documents you create in Shefy.
9.Communications data
The content and metadata of emails, SMS, and WhatsApp messages sent from Shefy to your clients, as well as your exchanges with our support team.
10.Technical, log and device data
IP address, browser and device type, and technical connection/error logs, necessary for the operation and security of the service.
11.Usage data
Interactions with Shefy's features (pages viewed, actions taken), used to improve the service and diagnose technical issues.
12.AI-related data
When you use an AI-assisted feature (for example initial setup or document import), the information you provide on that occasion (description of your business, submitted documents) is sent to our artificial intelligence provider solely to generate the requested suggestion — see section 21.
13.Imported documents and OCR
Documents you import (for example, supplier invoices) and the data automatically extracted from them through optical character recognition (OCR).
14.Purposes of processing
We process your data to: provide and operate the service, manage your account and subscription, ensure security and prevent fraud, provide support, improve the service, and comply with our legal obligations (in particular accounting and tax obligations).
15.Legal bases
Where the General Data Protection Regulation (GDPR) or an equivalent regulation applies to you, we process your data on the basis of the performance of our contract with you (providing the service), our legitimate interest (security, service improvement), compliance with a legal obligation, or, where required, your consent.
16.Our role: controller or processor
For your account and platform data (sections 4, 10, 11), Shefa Digital acts as data controller. For data you enter about your own clients (section 6) and, more broadly, the business data you manage through Shefy, Shefa Digital acts as a processor (or an equivalent role under your local regulation) acting on your behalf and on your instructions; you remain responsible, as the controller, for complying with your own obligations towards your clients.
17.Sub-processors — hosting and infrastructure
Our server infrastructure is hosted with third-party hosting/cloud providers located in the European Union. Storage of certain files (for example, imported documents) may be handled by a third-party cloud provider (Amazon Web Services).
18.Sub-processors — payment and billing
Payment for your own Shefy subscription is processed by a third-party online payment/billing provider. Where features for collecting payments from your own clients are offered, they are provided by third-party payment service providers (PSPs), separate from Shefa Digital.
19.Sub-processors — electronic invoicing
For users concerned, your invoices may be transmitted to an approved third-party dematerialization platform, for the purpose of complying with your electronic invoicing obligations.
20.Sub-processors — messaging
Delivery of transactional emails and SMS/WhatsApp messages is handled by third-party providers specialized in this type of communication.
21.Sub-processors — artificial intelligence
AI-assisted features rely on an artificial intelligence service hosted by a third-party cloud provider (Amazon Web Services, Bedrock service). Data you submit to these features is processed by this provider solely to generate the requested suggestion.
22.International data transfers
As Shefa Digital is established in Israel, some administrative processing may involve a transfer of data outside the European Union. Israel benefits from an adequacy decision of the European Commission under the GDPR. Where providers located outside the European Union are used (for example, certain cloud services), we aim to rely on appropriate safeguards (such as standard contractual clauses) to the extent required by applicable regulation.
23.Retention period
We retain your data for as long as your account is active, and then for as long as necessary to comply with our own legal obligations (in particular accounting and tax obligations, whose durations are set by applicable regulation) or to defend our rights, before deletion or anonymization. See also section 25 of our Terms of Service regarding account closure.
24.Security
We implement reasonable technical and organizational measures to protect your data (encryption of communications, access control, password hashing). As no system is infallible, we cannot, however, guarantee absolute security.
25.Your rights
Where the GDPR or an equivalent regulation applies to you, you have, over the data for which we are the controller, a right of access, rectification, erasure, restriction, objection, and portability, as well as the right to lodge a complaint with the competent supervisory authority. To exercise these rights, contact us at [email protected]. For data we process on behalf of a Shefy user regarding their own clients, please contact that user directly (see section 26).
26.Your responsibility towards your own clients
If you use Shefy to manage data about your own clients, you are responsible, as the controller of that data, for complying with your own obligations towards them (providing information, having a legal basis, retention periods, responding to their requests). Shefy then acts as a tool/processor on your behalf, under the conditions described in section 16.
27.Cookies and analytics
Our marketing site and application may use cookies or similar technologies strictly necessary for the service to function (for example, keeping you logged in), as well as, where applicable, audience-measurement tools. Where required by applicable regulation, we will ask for your consent before placing any non-essential cookies.
28.Children's data
Shefy is a professional tool intended for adults acting in a professional capacity. We do not knowingly collect data about children.
29.Changes to this policy
We may change this policy, in particular to reflect changes to the service, our sub-processors, or applicable regulation. We will communicate any material change to you by a reasonable means before it takes effect.
30.Contact
For any question about this policy or to exercise your rights, contact us at [email protected].