המסמך מוצג באנגלית. הנוסח האנגלי הוא המחייב.

Privacy Policy

Version 1 · 6 October 2026

This policy explains what we do with your personal data as a Kavix account holder.

It does not cover the people who sign your agreements. For them you are the controller and we act on your instructions — that is governed by the Data Processing Agreement, and the notice those people see is the one you write.

The English text is the authoritative version.


Who we are

Kavix is operated by Yossi Raz, trading as Innovago, in Israel. Contact: privacy@innovago.com

We are a sole trader, not a company, and no data protection officer is appointed — the thresholds that would require one are not met. The contact above reaches the person responsible.

What we collect about you

Data Why Lawful basis
Your name and email address to create and identify your account performance of a contract
Your password, stored only as a scrypt hash to let you sign in performance of a contract
Your business's legal details they appear on your agreement and in mail sent on your behalf performance of a contract
Session records: device description, times to keep you signed in and let you end sessions performance of a contract
Sign-in attempts, with IP address to limit abuse of the sign-in form legitimate interest in keeping accounts secure
Error and operational logs to keep the Service working legitimate interest in operating a reliable service

We do not profile you, advertise to you, sell anything about you, or build a picture of you across other services. There are no analytics or advertising trackers in Kavix.

Cookies

Two, both strictly necessary, both without consent requirements:

  • a session cookie holding a random token, so you stay signed in
  • a short-lived sign-in state cookie during Google sign-in, which protects against cross-site request forgery and is deleted immediately afterwards

No analytics cookies, so no cookie banner. That is a design decision, not an oversight.

Where your data is, and who else touches it

Everything is hosted in the European Union.

Who What they do Where
Vercel runs the application Frankfurt
Neon the database Frankfurt
Brevo sends email France
Google optional sign-in, if you choose it EU/US under its own terms

These are our sub-processors. The current list is published and we will give notice before adding one.

How long we keep it

Your account data is kept while the account is open, and for 12 months after it is closed — long enough to answer a question about what happened, not long enough to be a collection. Sign-in attempt records are kept for 90 days. Operational logs are kept for 30 days.

Your rights

Under the GDPR and Israel's Privacy Protection Law you may ask for a copy of your data, correction of it, deletion of it, or restriction of how it is used; you may object to processing based on legitimate interest, and you may ask for your data in a portable form.

Write to privacy@innovago.com. We answer within one month. If we refuse, we will say why and tell you how to complain.

If you are unhappy with the answer you may complain to your data protection authority, or in Israel to the Privacy Protection Authority.

Security

Passwords are stored as scrypt hashes, never in plain text. Session tokens and email links are stored only as hashes. Your customers' personal data is encrypted with per-record keys, and a database copy alone decrypts nothing because the master key is not in the database. Access between businesses is enforced by the database itself rather than by application code.

No system is immune. If a breach affects you we will tell you without undue delay.

Changes

We will notify material changes to the address on your account at least 14 days before they take effect. Earlier versions are kept.


Drafted with care, not by a lawyer, and to be reviewed by one before the Service is offered commercially.