S
Smartiz Digital
Privacy Terms Security Cookies GDPR Sub-processors
Open App →
Trust & Legal Center

We take your privacy seriously.

All of our legal documents in one place. Clear, honest, and written in plain language — because you deserve to understand what happens to your data.

🏢 Smartiz Digital · Ramat Gan, Israel
✦ Operix · AI Operations Platform
📅 Last updated: April 2026
📧 privacy@smartiz.digital
Documents
Compliance
Contact
✉️ privacy@smartiz.digital 💬 support@smartiz.digital
Last updated: April 19, 2026 · Effective: April 19, 2026

Table of Contents

  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Basis (GDPR)
  5. Data Sharing & Sub-processors
  6. Data Retention
  7. International Transfers
  8. Your Rights
  9. Security
  10. Children
  11. Changes to This Policy
  12. Contact Us
✦
Plain language summary: We collect only what we need to run Operix. We never sell your data. You can delete everything at any time. We store data for 24 months after account closure.
01

Who We Are

Smartiz Digital ("Company," "we," "us," or "our") operates the Operix AI Operations Platform at app.smartiz.digital and the marketing website at smartiz.digital.

Legal name: Smartiz Digital
Address: 11 Hazeytim St, Ramat Gan 5243351, Israel
Privacy contact: privacy@smartiz.digital

This Privacy Policy applies to all users of Operix worldwide. For EU/EEA users, we act as the data controller under GDPR. For users in other regions, the same standards apply.

02

What Data We Collect

2.1 Data You Provide

  • Account data: Full name, email address, password (hashed), company name, preferred language
  • Profile data: Job title, team size, industry, onboarding preferences
  • Business data: Projects, tasks, CRM contacts, deals, budget entries, expenses — all content you create inside Operix
  • Payment data: Subscription plan choice, billing email (payment processing handled by Lemon Squeezy — we never see full card numbers)
  • Communications: Support tickets, emails you send to us

2.2 Data We Collect Automatically

  • Usage data: Pages visited, features used, time spent, clicks
  • Technical data: IP address, browser type, device type, operating system, timezone
  • Cookies: Session cookies, preference cookies, analytics cookies (see Cookie Policy)
  • Log data: Server logs, error reports, performance data

2.3 Data from Third Parties

  • Google OAuth: Name and email if you sign in with Google
  • Google Analytics: Aggregated usage statistics (anonymized)
⚠️
We never collect: Government IDs, passport numbers, credit card numbers, bank details, health data, or biometric data (except optional WebAuthn fingerprint stored only on your device).
03

How We Use Your Data

PurposeData UsedLegal Basis
Provide and operate OperixAccount, business, usage dataContract performance
Process payments & manage subscriptionsEmail, plan, billing dataContract performance
AI features (translation, insights, chat)Business data, queriesContract performance
Send transactional emails (receipts, alerts)Email, nameContract performance
Customer supportAccount, support communicationsLegitimate interest
Security, fraud preventionTechnical, usage dataLegitimate interest
Analytics & product improvementAnonymized usage dataLegitimate interest
Marketing emails (newsletter, updates)Email, nameConsent (opt-in)
Legal complianceAs required by lawLegal obligation

We never use your data for: selling to third parties, advertising to you based on your business data, or training AI models on your private business content without your explicit consent.

04

Legal Basis for Processing (GDPR)

Under GDPR Article 6, we process personal data based on:

  • Article 6(1)(b) — Contract: Processing necessary to deliver the Operix service you signed up for
  • Article 6(1)(f) — Legitimate Interest: Security, fraud prevention, product improvement, support
  • Article 6(1)(a) — Consent: Marketing emails, optional analytics cookies (consent can be withdrawn at any time)
  • Article 6(1)(c) — Legal Obligation: Tax records, legal requests from authorities
05

Data Sharing & Sub-processors

We share data only with trusted sub-processors required to operate Operix. We never sell data. Full list available in our .

Categories of recipients: Cloud infrastructure, AI processing, payment processing, email delivery, analytics. Each sub-processor is bound by a Data Processing Agreement (DPA).

Legal disclosures: We may disclose data to law enforcement, courts, or regulatory authorities when legally required. We will notify you if legally permitted to do so.

06

Data Retention

Data TypeRetention PeriodReason
Account & business dataDuration of account + 24 months after closureService continuity, legal
Payment records7 yearsTax/legal obligation
Support communications3 yearsService quality
Server logs90 daysSecurity monitoring
Analytics data26 months (Google Analytics default)Product analytics
Marketing consent recordsUntil withdrawal + 3 yearsLegal compliance

Upon account deletion, all personal data is removed from active systems within 30 days and from backup systems within 90 days, unless a longer retention period is required by law.

07

International Data Transfers

Smartiz Digital is based in Israel. Data may be transferred to and processed in:

  • Israel — recognized as adequate by the EU (European Commission adequacy decision)
  • United States — via Supabase, Anthropic, Lemon Squeezy (protected by Standard Contractual Clauses)
  • Australia — Supabase infrastructure (protected by Standard Contractual Clauses)

All international transfers are protected by appropriate safeguards under GDPR Chapter V.

08

Your Rights

You have the following rights regarding your personal data. To exercise any right, email privacy@smartiz.digital. We respond within 30 days.

👁️

Right of Access

Request a copy of all personal data we hold about you.

✏️

Right to Rectification

Correct inaccurate or incomplete personal data.

🗑️

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

⏸️

Right to Restriction

Request that we limit how we process your data.

📦

Data Portability

Receive your data in a structured, machine-readable format.

🚫

Right to Object

Object to processing based on legitimate interest or for marketing.

🤖

Automated Decisions

Request human review of automated decisions that affect you.

↩️

Withdraw Consent

Withdraw consent at any time where processing is consent-based.

ℹ️
You also have the right to lodge a complaint with your local Data Protection Authority. In Israel: Privacy Protection Authority. In the EU: your national DPA.
09

Security

We implement industry-standard security measures. See our full for details. In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR.

10

Children

Operix is intended for users 18 years of age and older. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact privacy@smartiz.digital and we will delete the account immediately.

11

Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by email and by posting a notice in the Operix application at least 30 days before changes take effect. Continued use after the effective date constitutes acceptance.

12

Contact Us

Privacy inquiries & data requests

We respond to all privacy requests within 30 days. For urgent matters, please include "URGENT" in your subject line.

✉️ privacy@smartiz.digital 💬 support@smartiz.digital
📍 11 Hazeytim St, Ramat Gan 5243351, Israel
Last updated: April 19, 2026 · Effective: April 19, 2026
✦
Plain language summary: Use Operix legally and responsibly. Don't abuse it or harm others. We can suspend accounts that violate these terms. You own your data. We own the software.
01

Agreement to Terms

By accessing or using Operix ("Service"), operated by Smartiz Digital ("Company"), you agree to be bound by these Terms of Service. If you disagree, do not use the Service.

These Terms apply to all users, including individuals and organizations. If you use Operix on behalf of an organization, you represent that you have authority to bind that organization.

02

Eligibility

  • You must be at least 18 years old
  • You must provide accurate registration information
  • One person or legal entity may not maintain more than one free account
  • Accounts registered by bots or automated methods are prohibited
03

Account Responsibilities

You are responsible for:

  • Maintaining the confidentiality of your account credentials
  • All activity that occurs under your account
  • Notifying us immediately of unauthorized use at security@smartiz.digital
  • Ensuring your team members comply with these Terms
04

Acceptable Use

You may:

  • Use Operix for lawful business operations
  • Invite team members within your plan limits
  • Export your data at any time
  • Integrate Operix with permitted third-party services

You may not:

  • Use Operix to violate any applicable law or regulation
  • Upload or transmit malicious code, viruses, or harmful content
  • Attempt to gain unauthorized access to our systems
  • Scrape, crawl, or extract data from Operix using automated means
  • Resell or sublicense access to Operix without written permission
  • Use Operix to store or process illegal content
  • Impersonate other users or Smartiz Digital
  • Circumvent rate limits or other technical restrictions
05

Subscriptions & Billing

Operix offers paid subscription plans. By subscribing:

  • You authorize recurring billing via Lemon Squeezy, our payment processor
  • 14-day free trial available on all paid plans — no credit card required to start
  • Subscriptions auto-renew monthly unless cancelled before the renewal date
  • Prices are in USD and exclude applicable taxes (VAT/GST calculated at checkout)
  • Plan upgrades take effect immediately; downgrades take effect at next billing cycle

Refund Policy

We offer a 30-day money-back guarantee for first-time subscribers. To request a refund, email billing@smartiz.digital within 30 days of your first payment. Refunds are not available for subsequent billing cycles.

06

Intellectual Property

Our Property

Smartiz Digital owns all rights in the Operix software, platform, design, trademarks, and documentation. These Terms do not grant you any ownership rights.

Your Data

You own all data you input into Operix. We claim no ownership over your business data, content, or files. By using Operix, you grant us a limited license to process your data solely for the purpose of providing the service to you.

07

AI Features

Operix includes AI-powered features (translation, insights, forecasting, agents) powered by Claude AI (Anthropic). Regarding AI:

  • AI outputs are for informational purposes only — not professional, legal, or financial advice
  • You are responsible for verifying AI-generated content before acting on it
  • We do not use your private business data to train AI models without explicit consent
  • AI processing may involve temporary transmission to Anthropic's servers (covered by DPA)
08

Service Availability

We target 99.5% uptime and will communicate planned maintenance in advance. However, we do not guarantee uninterrupted service. Scheduled maintenance windows will be announced at least 48 hours in advance via email and in-app notification.

We are not liable for losses caused by service interruptions beyond our reasonable control.

09

Termination

By you: Cancel your subscription at any time through account settings or by emailing billing@smartiz.digital. Service continues until end of billing period.

By us: We may suspend or terminate accounts for Terms violations, non-payment, or fraudulent activity. We will provide notice where possible. Upon termination, you have 30 days to export your data.

10

Limitation of Liability

To the maximum extent permitted by law, Smartiz Digital's total liability to you for any claims arising from these Terms or your use of Operix shall not exceed the amount you paid in the 12 months preceding the claim.

We are not liable for indirect, incidental, consequential, or punitive damages, loss of profits, or loss of data.

11

Governing Law

These Terms are governed by the laws of the State of Israel, without regard to conflict of law principles. Disputes shall be resolved in the courts of Tel Aviv-Jaffa, Israel.

For EU users, mandatory consumer protection laws of your country of residence apply in addition to these Terms.

12

Contact

Legal & general inquiries

For questions about these Terms or legal matters.

✉️ hello@smartiz.digital 💳 billing@smartiz.digital
📍 11 Hazeytim St, Ramat Gan, Israel
Last updated: April 19, 2026
🛡️
Our commitment: Security is not an afterthought at Smartiz Digital — it's built into every layer of Operix. We apply industry-standard practices to protect your business data.
01

Infrastructure Security

🔐

TLS Encryption

All data in transit encrypted with TLS 1.3. HTTPS enforced everywhere.

🗄️

Encrypted at Rest

All database data encrypted at rest using AES-256 via Supabase.

☁️

Cloud Infrastructure

Hosted on Hostinger VPS (Ubuntu 22.04) with Supabase for database.

🔒

Row-Level Security

Supabase RLS policies ensure users can only access their own data.

🌐

HTTPS Only

SSL certificates via Let's Encrypt. HTTP redirects to HTTPS automatically.

🚧

Nginx Firewall

Nginx reverse proxy with rate limiting and security headers configured.

02

Authentication Security

  • Password hashing: bcrypt with salt via Supabase Auth
  • WebAuthn / Biometric login: Optional fingerprint/face authentication — keys stored only on your device
  • QR code login: Time-limited, single-use tokens
  • Google OAuth: Standard OAuth 2.0 flow — we never see your Google password
  • Session tokens: JWT with configurable expiry, invalidated on logout
  • Multi-workspace isolation: Complete data isolation between workspaces
03

Access Controls

  • RBAC (Role-Based Access Control): Owner, Admin, Manager, Member, Viewer roles
  • Principle of least privilege: Each role has minimum necessary permissions
  • Admin panel: Protected by separate authentication, only accessible to verified admins
  • API keys: Server-side only, never exposed to clients
04

Data Protection

  • Backups: Supabase automatic daily backups
  • Retention: User data retained for 24 months post-closure, then securely deleted
  • Payment data: Never stored by us — handled entirely by Lemon Squeezy (PCI-DSS compliant)
  • AI data handling: Queries to Claude API are not stored or used for training
05

Incident Response

In the event of a security breach:

  • We will assess and contain the incident within 24 hours
  • Affected users will be notified within 72 hours (as required by GDPR)
  • Relevant supervisory authorities will be notified as required by law
  • Post-incident reports will be provided to affected customers upon request
🚨
Discovered a security vulnerability? Please disclose responsibly to privacy@smartiz.digital. We aim to respond within 48 hours and will acknowledge your contribution.
06

SSL Certificate Status

DomainStatusExpiry
app.smartiz.digitalValid~86 days
smartiz.digitalValid~86 days
lrtnlmpdcdmmifhrezru.supabase.coValid~41 days (renew soon)
Last updated: April 19, 2026
🍪
Summary: We use essential cookies to run Operix, analytics cookies to improve it, and preference cookies to remember your settings. You can opt out of non-essential cookies at any time.
01

What Are Cookies?

Cookies are small text files stored on your device by your browser. They help websites remember your preferences, keep you logged in, and understand how you use the service.

02

Cookies We Use

Essential Cookies REQUIRED

Required for Operix to function. Cannot be disabled.


CookiePurposeDuration
sb-sessionSupabase authentication sessionSession
sb-auth-tokenLogin state7 days
operix_langLanguage preference1 year
vcp_*Visual control panel preferences (theme, font)1 year

Analytics Cookies

Help us understand how users interact with Operix to improve the product.


CookiePurposeDuration
_gaGoogle Analytics — unique user identification2 years
_ga_*Google Analytics — session data2 years

Functional Cookies

Remember your preferences and personalize your experience.


CookiePurposeDuration
operix_onboarding_done_*Tracks onboarding completion per userPersistent
opx_lLanding page language preference1 year
03

Managing Cookies

You can control cookies through:

  • Browser settings: Block or delete cookies in your browser preferences
  • Cookie banner: Accept or decline non-essential cookies when you first visit
  • Google Analytics opt-out: Google Analytics Opt-out Browser Add-on

Note: Disabling essential cookies will prevent Operix from functioning correctly.

04

Third-Party Cookies

Some third-party services set their own cookies:

  • Google Analytics — usage analytics (opt-out available)
  • Lemon Squeezy — payment flow cookies (only during checkout)
  • Google OAuth — authentication cookies (only when using Google sign-in)
Last updated: April 19, 2026
🇪🇺
GDPR Compliance: Smartiz Digital is committed to full compliance with the EU General Data Protection Regulation (GDPR) for all users in the EU/EEA. This page explains your rights and how to exercise them.
01

Applicable Regulations

GDPR (EU/EEA) CCPA (California) LGPD (Brazil) Israel Privacy Law

As a global SaaS platform, we comply with privacy regulations across jurisdictions. GDPR is our baseline standard — all users benefit from GDPR-level protections regardless of location.

02

Your GDPR Rights — How to Exercise Them

RightWhat It MeansHow to RequestResponse Time
Access (Art. 15)Get a copy of all your personal dataEmail privacy@smartiz.digital with subject "Data Access Request"30 days
Rectification (Art. 16)Correct inaccurate dataUpdate in app settings, or email us30 days
Erasure (Art. 17)Delete all your data ("right to be forgotten")Email privacy@smartiz.digital with subject "Delete My Account"30 days
Portability (Art. 20)Export your data in JSON/CSV formatUse in-app export, or email us30 days
Restriction (Art. 18)Limit how we process your dataEmail privacy@smartiz.digital30 days
Objection (Art. 21)Object to processing for marketing or legitimate interestUnsubscribe link in emails, or email usImmediate for marketing
Withdraw ConsentWithdraw previously given consentCookie settings or email usImmediate
ℹ️
We may ask for identity verification before fulfilling requests. We will not discriminate against you for exercising your privacy rights. All requests are free of charge.
03

Lawful Bases Summary

Processing ActivityLawful BasisCan Opt Out?
Running the Operix serviceContract (Art. 6(1)(b))No (required for service)
Billing & paymentsContract (Art. 6(1)(b))No (required for service)
Security & fraud preventionLegitimate interest (Art. 6(1)(f))No (overriding interest)
Analytics & product improvementLegitimate interest (Art. 6(1)(f))Yes (cookie settings)
Marketing emailsConsent (Art. 6(1)(a))Yes (unsubscribe at any time)
Tax/legal complianceLegal obligation (Art. 6(1)(c))No (legal requirement)
04

International Transfers

When your data is transferred outside the EU/EEA, we ensure appropriate safeguards:

  • Israel: European Commission adequacy decision — treated the same as EU transfers
  • United States: Standard Contractual Clauses (SCCs) with Supabase, Anthropic, Lemon Squeezy
  • Australia: Standard Contractual Clauses with Supabase
05

Right to Lodge a Complaint

If you believe we have violated your privacy rights, you have the right to lodge a complaint with:

  • Israel: The Privacy Protection Authority — gov.il
  • EU/EEA: Your national Data Protection Authority (find yours at edpb.europa.eu)
  • UK: Information Commissioner's Office — ico.org.uk

We encourage you to contact us first at privacy@smartiz.digital so we can resolve your concern directly.

Data Protection Contact

For all GDPR-related requests and inquiries.

✉️ privacy@smartiz.digital
📍 11 Hazeytim St, Ramat Gan 5243351, Israel
Last updated: April 19, 2026 · Last change: April 2026 (Zoho added)
🔗
Transparency commitment: We maintain a complete list of all third-party sub-processors who may process your personal data. We will update this page and notify customers at least 30 days before adding new sub-processors.
01

Infrastructure & Database

ProcessorPurposeDataLocationDPA
HostingerVPS hosting, web serverAll application data (server)🇺🇸 USA / 🇳🇱 EUYes
SupabaseDatabase, authentication, realtime, storageAll user & business data🇺🇸 USA / 🇦🇺 AustraliaYes
02

AI Processing

ProcessorPurposeDataLocationDPA
Anthropic (Claude AI)AI chat, translation, insights, forecasting, AI agentsBusiness data submitted for AI processing (not stored by Anthropic)🇺🇸 USAYes
ℹ️
Data sent to Anthropic for AI processing is not stored beyond the request and is not used to train AI models. Covered by Anthropic's usage policy and API DPA.
03

Payments & Billing

ProcessorPurposeDataLocationDPA
Lemon Squeezy (Link, LLC)Payment processing, subscriptions, invoicing, tax complianceEmail, billing address, payment method (cards processed by Stripe — we never see card numbers)🇺🇸 USAYes — Merchant of Record
04

Email

ProcessorPurposeDataLocationDPA
Zoho MailBusiness email (support, billing, privacy communications)Email content, sender/recipient addresses🇺🇸 USA / 🇮🇳 India / 🇪🇺 EUYes
05

Analytics

ProcessorPurposeDataLocationDPA
Google Analytics 4Website usage analyticsAnonymized usage data, IP (anonymized), browser, device🇺🇸 USAYes

Google Analytics data is anonymized before processing. IP addresses are anonymized. We have enabled data minimization settings.

06

Authentication

ProcessorPurposeDataLocationDPA
Google (OAuth)Optional Google sign-inName, email (only when Google login used)🇺🇸 USAYes
07

Change Notifications

We will notify all active customers by email at least 30 days before adding any new sub-processor that processes personal data. Subscribe to sub-processor updates by emailing privacy@smartiz.digital with subject "Sub-processor Updates".

Change log:

DateChange
April 2026Added: Zoho Mail (business email)
April 2026Initial list published
© 2026 Smartiz Digital · 11 Hazeytim St, Ramat Gan 5243351, Israel
Privacy Terms Security Cookies GDPR Contact