Table of Contents
Who We Are
Smartiz Digital ("Company," "we," "us," or "our") operates the Operix AI Operations Platform at app.smartiz.digital and the marketing website at smartiz.digital.
Legal name: Smartiz Digital
Address: 11 Hazeytim St, Ramat Gan 5243351, Israel
Privacy contact: privacy@smartiz.digital
This Privacy Policy applies to all users of Operix worldwide. For EU/EEA users, we act as the data controller under GDPR. For users in other regions, the same standards apply.
What Data We Collect
2.1 Data You Provide
- Account data: Full name, email address, password (hashed), company name, preferred language
- Profile data: Job title, team size, industry, onboarding preferences
- Business data: Projects, tasks, CRM contacts, deals, budget entries, expenses — all content you create inside Operix
- Payment data: Subscription plan choice, billing email (payment processing handled by Lemon Squeezy — we never see full card numbers)
- Communications: Support tickets, emails you send to us
2.2 Data We Collect Automatically
- Usage data: Pages visited, features used, time spent, clicks
- Technical data: IP address, browser type, device type, operating system, timezone
- Cookies: Session cookies, preference cookies, analytics cookies (see Cookie Policy)
- Log data: Server logs, error reports, performance data
2.3 Data from Third Parties
- Google OAuth: Name and email if you sign in with Google
- Google Analytics: Aggregated usage statistics (anonymized)
How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and operate Operix | Account, business, usage data | Contract performance |
| Process payments & manage subscriptions | Email, plan, billing data | Contract performance |
| AI features (translation, insights, chat) | Business data, queries | Contract performance |
| Send transactional emails (receipts, alerts) | Email, name | Contract performance |
| Customer support | Account, support communications | Legitimate interest |
| Security, fraud prevention | Technical, usage data | Legitimate interest |
| Analytics & product improvement | Anonymized usage data | Legitimate interest |
| Marketing emails (newsletter, updates) | Email, name | Consent (opt-in) |
| Legal compliance | As required by law | Legal obligation |
We never use your data for: selling to third parties, advertising to you based on your business data, or training AI models on your private business content without your explicit consent.
Legal Basis for Processing (GDPR)
Under GDPR Article 6, we process personal data based on:
- Article 6(1)(b) — Contract: Processing necessary to deliver the Operix service you signed up for
- Article 6(1)(f) — Legitimate Interest: Security, fraud prevention, product improvement, support
- Article 6(1)(a) — Consent: Marketing emails, optional analytics cookies (consent can be withdrawn at any time)
- Article 6(1)(c) — Legal Obligation: Tax records, legal requests from authorities
Data Sharing & Sub-processors
We share data only with trusted sub-processors required to operate Operix. We never sell data. Full list available in our .
Categories of recipients: Cloud infrastructure, AI processing, payment processing, email delivery, analytics. Each sub-processor is bound by a Data Processing Agreement (DPA).
Legal disclosures: We may disclose data to law enforcement, courts, or regulatory authorities when legally required. We will notify you if legally permitted to do so.
Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account & business data | Duration of account + 24 months after closure | Service continuity, legal |
| Payment records | 7 years | Tax/legal obligation |
| Support communications | 3 years | Service quality |
| Server logs | 90 days | Security monitoring |
| Analytics data | 26 months (Google Analytics default) | Product analytics |
| Marketing consent records | Until withdrawal + 3 years | Legal compliance |
Upon account deletion, all personal data is removed from active systems within 30 days and from backup systems within 90 days, unless a longer retention period is required by law.
International Data Transfers
Smartiz Digital is based in Israel. Data may be transferred to and processed in:
- Israel — recognized as adequate by the EU (European Commission adequacy decision)
- United States — via Supabase, Anthropic, Lemon Squeezy (protected by Standard Contractual Clauses)
- Australia — Supabase infrastructure (protected by Standard Contractual Clauses)
All international transfers are protected by appropriate safeguards under GDPR Chapter V.
Your Rights
You have the following rights regarding your personal data. To exercise any right, email privacy@smartiz.digital. We respond within 30 days.
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restriction
Request that we limit how we process your data.
Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interest or for marketing.
Automated Decisions
Request human review of automated decisions that affect you.
Withdraw Consent
Withdraw consent at any time where processing is consent-based.
Security
We implement industry-standard security measures. See our full for details. In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR.
Children
Operix is intended for users 18 years of age and older. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact privacy@smartiz.digital and we will delete the account immediately.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by email and by posting a notice in the Operix application at least 30 days before changes take effect. Continued use after the effective date constitutes acceptance.
Contact Us
Privacy inquiries & data requests
We respond to all privacy requests within 30 days. For urgent matters, please include "URGENT" in your subject line.
Agreement to Terms
By accessing or using Operix ("Service"), operated by Smartiz Digital ("Company"), you agree to be bound by these Terms of Service. If you disagree, do not use the Service.
These Terms apply to all users, including individuals and organizations. If you use Operix on behalf of an organization, you represent that you have authority to bind that organization.
Eligibility
- You must be at least 18 years old
- You must provide accurate registration information
- One person or legal entity may not maintain more than one free account
- Accounts registered by bots or automated methods are prohibited
Account Responsibilities
You are responsible for:
- Maintaining the confidentiality of your account credentials
- All activity that occurs under your account
- Notifying us immediately of unauthorized use at security@smartiz.digital
- Ensuring your team members comply with these Terms
Acceptable Use
You may:
- Use Operix for lawful business operations
- Invite team members within your plan limits
- Export your data at any time
- Integrate Operix with permitted third-party services
You may not:
- Use Operix to violate any applicable law or regulation
- Upload or transmit malicious code, viruses, or harmful content
- Attempt to gain unauthorized access to our systems
- Scrape, crawl, or extract data from Operix using automated means
- Resell or sublicense access to Operix without written permission
- Use Operix to store or process illegal content
- Impersonate other users or Smartiz Digital
- Circumvent rate limits or other technical restrictions
Subscriptions & Billing
Operix offers paid subscription plans. By subscribing:
- You authorize recurring billing via Lemon Squeezy, our payment processor
- 14-day free trial available on all paid plans — no credit card required to start
- Subscriptions auto-renew monthly unless cancelled before the renewal date
- Prices are in USD and exclude applicable taxes (VAT/GST calculated at checkout)
- Plan upgrades take effect immediately; downgrades take effect at next billing cycle
Refund Policy
We offer a 30-day money-back guarantee for first-time subscribers. To request a refund, email billing@smartiz.digital within 30 days of your first payment. Refunds are not available for subsequent billing cycles.
Intellectual Property
Our Property
Smartiz Digital owns all rights in the Operix software, platform, design, trademarks, and documentation. These Terms do not grant you any ownership rights.
Your Data
You own all data you input into Operix. We claim no ownership over your business data, content, or files. By using Operix, you grant us a limited license to process your data solely for the purpose of providing the service to you.
AI Features
Operix includes AI-powered features (translation, insights, forecasting, agents) powered by Claude AI (Anthropic). Regarding AI:
- AI outputs are for informational purposes only — not professional, legal, or financial advice
- You are responsible for verifying AI-generated content before acting on it
- We do not use your private business data to train AI models without explicit consent
- AI processing may involve temporary transmission to Anthropic's servers (covered by DPA)
Service Availability
We target 99.5% uptime and will communicate planned maintenance in advance. However, we do not guarantee uninterrupted service. Scheduled maintenance windows will be announced at least 48 hours in advance via email and in-app notification.
We are not liable for losses caused by service interruptions beyond our reasonable control.
Termination
By you: Cancel your subscription at any time through account settings or by emailing billing@smartiz.digital. Service continues until end of billing period.
By us: We may suspend or terminate accounts for Terms violations, non-payment, or fraudulent activity. We will provide notice where possible. Upon termination, you have 30 days to export your data.
Limitation of Liability
To the maximum extent permitted by law, Smartiz Digital's total liability to you for any claims arising from these Terms or your use of Operix shall not exceed the amount you paid in the 12 months preceding the claim.
We are not liable for indirect, incidental, consequential, or punitive damages, loss of profits, or loss of data.
Governing Law
These Terms are governed by the laws of the State of Israel, without regard to conflict of law principles. Disputes shall be resolved in the courts of Tel Aviv-Jaffa, Israel.
For EU users, mandatory consumer protection laws of your country of residence apply in addition to these Terms.
Contact
Legal & general inquiries
For questions about these Terms or legal matters.
Infrastructure Security
TLS Encryption
All data in transit encrypted with TLS 1.3. HTTPS enforced everywhere.
Encrypted at Rest
All database data encrypted at rest using AES-256 via Supabase.
Cloud Infrastructure
Hosted on Hostinger VPS (Ubuntu 22.04) with Supabase for database.
Row-Level Security
Supabase RLS policies ensure users can only access their own data.
HTTPS Only
SSL certificates via Let's Encrypt. HTTP redirects to HTTPS automatically.
Nginx Firewall
Nginx reverse proxy with rate limiting and security headers configured.
Authentication Security
- Password hashing: bcrypt with salt via Supabase Auth
- WebAuthn / Biometric login: Optional fingerprint/face authentication — keys stored only on your device
- QR code login: Time-limited, single-use tokens
- Google OAuth: Standard OAuth 2.0 flow — we never see your Google password
- Session tokens: JWT with configurable expiry, invalidated on logout
- Multi-workspace isolation: Complete data isolation between workspaces
Access Controls
- RBAC (Role-Based Access Control): Owner, Admin, Manager, Member, Viewer roles
- Principle of least privilege: Each role has minimum necessary permissions
- Admin panel: Protected by separate authentication, only accessible to verified admins
- API keys: Server-side only, never exposed to clients
Data Protection
- Backups: Supabase automatic daily backups
- Retention: User data retained for 24 months post-closure, then securely deleted
- Payment data: Never stored by us — handled entirely by Lemon Squeezy (PCI-DSS compliant)
- AI data handling: Queries to Claude API are not stored or used for training
Incident Response
In the event of a security breach:
- We will assess and contain the incident within 24 hours
- Affected users will be notified within 72 hours (as required by GDPR)
- Relevant supervisory authorities will be notified as required by law
- Post-incident reports will be provided to affected customers upon request
SSL Certificate Status
| Domain | Status | Expiry |
|---|---|---|
| app.smartiz.digital | Valid | ~86 days |
| smartiz.digital | Valid | ~86 days |
| lrtnlmpdcdmmifhrezru.supabase.co | Valid | ~41 days (renew soon) |
What Are Cookies?
Cookies are small text files stored on your device by your browser. They help websites remember your preferences, keep you logged in, and understand how you use the service.
Cookies We Use
Managing Cookies
You can control cookies through:
- Browser settings: Block or delete cookies in your browser preferences
- Cookie banner: Accept or decline non-essential cookies when you first visit
- Google Analytics opt-out: Google Analytics Opt-out Browser Add-on
Note: Disabling essential cookies will prevent Operix from functioning correctly.
Third-Party Cookies
Some third-party services set their own cookies:
- Google Analytics — usage analytics (opt-out available)
- Lemon Squeezy — payment flow cookies (only during checkout)
- Google OAuth — authentication cookies (only when using Google sign-in)
Applicable Regulations
As a global SaaS platform, we comply with privacy regulations across jurisdictions. GDPR is our baseline standard — all users benefit from GDPR-level protections regardless of location.
Your GDPR Rights — How to Exercise Them
| Right | What It Means | How to Request | Response Time |
|---|---|---|---|
| Access (Art. 15) | Get a copy of all your personal data | Email privacy@smartiz.digital with subject "Data Access Request" | 30 days |
| Rectification (Art. 16) | Correct inaccurate data | Update in app settings, or email us | 30 days |
| Erasure (Art. 17) | Delete all your data ("right to be forgotten") | Email privacy@smartiz.digital with subject "Delete My Account" | 30 days |
| Portability (Art. 20) | Export your data in JSON/CSV format | Use in-app export, or email us | 30 days |
| Restriction (Art. 18) | Limit how we process your data | Email privacy@smartiz.digital | 30 days |
| Objection (Art. 21) | Object to processing for marketing or legitimate interest | Unsubscribe link in emails, or email us | Immediate for marketing |
| Withdraw Consent | Withdraw previously given consent | Cookie settings or email us | Immediate |
Lawful Bases Summary
| Processing Activity | Lawful Basis | Can Opt Out? |
|---|---|---|
| Running the Operix service | Contract (Art. 6(1)(b)) | No (required for service) |
| Billing & payments | Contract (Art. 6(1)(b)) | No (required for service) |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f)) | No (overriding interest) |
| Analytics & product improvement | Legitimate interest (Art. 6(1)(f)) | Yes (cookie settings) |
| Marketing emails | Consent (Art. 6(1)(a)) | Yes (unsubscribe at any time) |
| Tax/legal compliance | Legal obligation (Art. 6(1)(c)) | No (legal requirement) |
International Transfers
When your data is transferred outside the EU/EEA, we ensure appropriate safeguards:
- Israel: European Commission adequacy decision — treated the same as EU transfers
- United States: Standard Contractual Clauses (SCCs) with Supabase, Anthropic, Lemon Squeezy
- Australia: Standard Contractual Clauses with Supabase
Right to Lodge a Complaint
If you believe we have violated your privacy rights, you have the right to lodge a complaint with:
- Israel: The Privacy Protection Authority — gov.il
- EU/EEA: Your national Data Protection Authority (find yours at edpb.europa.eu)
- UK: Information Commissioner's Office — ico.org.uk
We encourage you to contact us first at privacy@smartiz.digital so we can resolve your concern directly.
Data Protection Contact
For all GDPR-related requests and inquiries.
Infrastructure & Database
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Hostinger | VPS hosting, web server | All application data (server) | 🇺🇸 USA / 🇳🇱 EU | Yes |
| Supabase | Database, authentication, realtime, storage | All user & business data | 🇺🇸 USA / 🇦🇺 Australia | Yes |
AI Processing
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Anthropic (Claude AI) | AI chat, translation, insights, forecasting, AI agents | Business data submitted for AI processing (not stored by Anthropic) | 🇺🇸 USA | Yes |
Payments & Billing
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Lemon Squeezy (Link, LLC) | Payment processing, subscriptions, invoicing, tax compliance | Email, billing address, payment method (cards processed by Stripe — we never see card numbers) | 🇺🇸 USA | Yes — Merchant of Record |
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Zoho Mail | Business email (support, billing, privacy communications) | Email content, sender/recipient addresses | 🇺🇸 USA / 🇮🇳 India / 🇪🇺 EU | Yes |
Analytics
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Google Analytics 4 | Website usage analytics | Anonymized usage data, IP (anonymized), browser, device | 🇺🇸 USA | Yes |
Google Analytics data is anonymized before processing. IP addresses are anonymized. We have enabled data minimization settings.
Authentication
| Processor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Google (OAuth) | Optional Google sign-in | Name, email (only when Google login used) | 🇺🇸 USA | Yes |
Change Notifications
We will notify all active customers by email at least 30 days before adding any new sub-processor that processes personal data. Subscribe to sub-processor updates by emailing privacy@smartiz.digital with subject "Sub-processor Updates".
Change log:
| Date | Change |
|---|---|
| April 2026 | Added: Zoho Mail (business email) |
| April 2026 | Initial list published |