Privacy Policy
Clients give Ankora access to parts of their lives. This document explains what we see, what we do with it, and what we do not do. We wrote it to be read, not to shield us.
1. Who is responsible for the information
The owner of the database and the party responsible for the processing is ANKORA 360 LTD, company registration number 517395471. Privacy enquiries: hello@ankora.co.il.
Where Ankora carries out tasks for a business client and is exposed to information about that client's employees, customers or suppliers, the client is the owner of the database and Ankora acts as holder of the database on its behalf. This relationship is governed in full by the engagement agreement.
2. What information we receive
From site visitors. Details submitted through the contact form: name, phone, email and the content of the enquiry. In addition, technical usage data and IP address.
From clients. Contact and billing details, portal user details, time entries and task descriptions, and any operational material required to carry out the task: correspondence, calendar, documents, supplier details and personal preferences.
From systems the client opens to us. When a client grants us access to their mailbox, calendar, accounting system, CRM or office computer, we are exposed to the information held there. We access only what the task requires.
From calls and meetings. See section 5.
We do not ask for sensitive information that the task does not require. Where the client provides us with sensitive information for the purpose of a task, for example handling a matter with a health fund, that information is used for that task alone and is not retained beyond what the task requires.
3. What we do with the information
To deliver the service and to coordinate with third parties on the client's behalf. To bill and to manage the engagement. To maintain continuous operational context, so that we do not ask the same question twice. To improve the quality of execution. To meet legal obligations.
We do not sell information, do not rent it, and do not transfer it to a third party for that party's own marketing.
4. Access to the client's accounts and systems
This is the part most worth reading.
Access is granted by the client alone, explicitly, and to the systems the client names. The scope of the authorization is documented in writing.
Tasks are carried out within the scope that was defined. We do not read material that the task does not require, even where it is technically accessible.
On termination of the engagement, or when an operations manager changes, Ankora revokes the permissions under its control within three business days and notifies the authorized contact at the client. Permissions granted inside the client's own systems are under the client's control, and the client is to revoke them on its side.
5. Recording, documentation and monitoring
Calls and meetings with our team are recorded and transcribed, and actions taken by the operations manager inside client systems are logged.
This is not a mechanism for monitoring the client. It is what allows us not to ask the same question twice, to hand a task from one person to another without context falling away, and to improve the quality of the work. The record also serves as input to our AI systems as described in section 6.
Recordings are kept under restricted access and are deleted at the client's request. A client who prefers that their calls not be recorded may ask, and we will honor the request.
Where a call includes additional participants, we give notice of the recording at the start of the call, to the extent required by applicable law.
6. AI: what it does and what it does not
Ankora integrates AI systems into the operational layer. They summarize, classify, retrieve information, prepare drafts, document, and flag matters that may otherwise slip.
A decision made towards the client is always made by a person. There is no situation in which a system decides on its own to act towards a third party, to make a payment, or to change a commitment of the client.
Ankora does not train models on client information. Neither models of our own nor models of others. We work with AI providers under business terms in which the provider is contractually prohibited from training models on the data that passes through us.
The data that passes to the AI systems is limited to what the task requires. We work with leading AI tools such as Anthropic or OpenAI.
7. Sub-processors
Ankora relies on leading international infrastructure providers, the same providers the world's leading software companies rely on. Each of them processes information for us for one defined purpose, and is bound by contractual information security and confidentiality undertakings. The list is maintained on the security and trust page, where links to each provider's privacy policy also appear.
| Provider | Purpose of processing | Type of information | Country |
|---|---|---|---|
| Vercel | Hosting the site and the client area | Technical usage data | United States |
| Neon | Database of the operations system | Operational client data | United States |
| Upstash | Protection against abuse of the system | Technical usage data | United States |
| Resend | Sending messages from the system | Contact details and message content | United States |
| Google Workspace | Email, calendar and document storage | Operational correspondence and documents | Global |
| ClickUp | Task management and tracking | Operational client data | United States |
| Fireflies | Transcription and summary of calls | Recordings and transcripts | United States |
| Anthropic | The operational AI layer | Operational client data | United States |
| Google Analytics | Measurement of use of the marketing site | Anonymous usage data | Global |
8. Transfer of information outside Israel
The service relies on leading international tools, and the information is therefore stored on their servers in the United States, in line with the standards under which the world's leading software companies operate. These are the same providers used by the largest companies in the world, and the engagement with each of them includes information security and confidentiality undertakings.
9. Retention and deletion
Operational information is retained for as long as the engagement is active. Within thirty days of the end of the engagement the client may receive a full export of their data.
10. Rights
Under the Israeli Privacy Protection Law and Amendment 13 to it, and under the GDPR for those to whom it applies: to review the information, to correct inaccurate information, to request deletion, to object to processing, and to receive a portable copy.
Write to hello@ankora.co.il. We will respond within thirty days.
Where the request concerns information we received from a business client, for example an employee of a client, we will pass the request on to the client and assist them in handling it, because the information is theirs.
11. Information security
Encryption in transit and at rest, permissions on a need basis, structural separation between clients in the portal, an audit log, and periodic security reviews. The detail is set out on the security and trust page.
In the event of a serious security incident, we will notify the affected clients and the Israeli Privacy Protection Authority as required by law, without waiting for a full investigation.
13. Minors
The service is intended for adults and is conducted with the client only. Where a client asks us to carry out a task concerning their children, the request itself constitutes the client's authorization to provide the information required for that task, in accordance with applicable law. The information is used for that task alone.
14. Changes
Ankora may update this policy from time to time. The current version is published on this page.