Skip to content

Israeli data-transfer annex for sub-processors

BranderUX · Lev Kaplun · Israel

Data Processing EngagementPrivacy Policy

Israeli data-transfer annex for sub-processors

This is the annex BranderUX offers a vendor that will receive personal data we hold for our customers. It is written to the Israeli requirements: the Protection of Privacy Law 5741-1981, the Privacy Protection Regulations (Data Security) 5777-2017, and the Privacy Protection (Transfer of Information to Databases Abroad) Regulations 5761-2001.

It is short on purpose. A vendor that already holds ISO/IEC 27001 elects that route in clause 5 and signs the rest unchanged.

It is an offer, not a statement that any particular vendor has signed it. Which recipients are under it, and which are not, is published per recipient at /api/legal/recipients and stated in the engagement at /legal/dpa.

1. Scope

This annex applies to personal data that is subject to Israeli law and that the Vendor processes for BranderUX on behalf of BranderUX's customers. For that data the customer is the owner of the database, BranderUX is a holder of it, and the Vendor is a further holder.

Where the Vendor's standard terms and this annex differ about that data, this annex governs.

2. Purpose limitation

The Vendor processes the data only to provide the service BranderUX engaged it for, only on BranderUX's documented instructions, and for no purpose of its own.

Stated rather than implied: no training, fine-tuning or evaluation of any model on the data, and no use of it to build or improve any product other than the engaged service.

3. Access and correction

Where a person exercises the right to access or correct their data under sections 13 and 14 of the Protection of Privacy Law, the Vendor gives BranderUX the assistance and the information needed to answer within the statutory period.

The Vendor does not answer the person directly unless BranderUX asks it to in writing.

4. Confidentiality

The Vendor keeps the data confidential, limits access to personnel who need it for the engaged service, and places each of them under a written confidentiality undertaking that survives the end of their engagement.

5. Security, at the Vendor's election

The Vendor elects one of these two, in writing:

  • A current ISO/IEC 27001 certification whose scope covers the engaged service, applying the Annex A controls relevant to it, including access control, cryptography, operations security, supplier relationships and information security incident management.
  • Measures that meet the Privacy Protection Regulations (Data Security) 5777-2017 substantively: access control by named individual, encryption in transit and at rest, logging, a written incident procedure, and periodic review.

The Vendor tells BranderUX when its election changes, and at any time on request.

6. No onward transfer without written consent

The Vendor transfers the data to no further recipient, inside or outside its own country, without BranderUX's prior written consent. Where consent is given, the Vendor binds that recipient to terms no weaker than this annex and remains responsible for its acts.

This mirrors regulation 3 of the Privacy Protection (Transfer of Information to Databases Abroad) Regulations 5761-2001, under which the transfer to the Vendor is itself made.

7. Notice of a security event

The Vendor tells BranderUX of a security event affecting the data without delay and no later than 24 hours after becoming aware of it, with what it knows at that point, and keeps BranderUX updated as it learns more.

The Vendor does not wait for its own investigation to conclude before giving that notice.

8. Deletion at the end

On termination of the engagement, or earlier on BranderUX's written request, the Vendor deletes the data and confirms the deletion in writing.

It keeps only what a law binding on it requires it to keep, for no longer than that law requires, and this annex continues to apply to whatever it keeps.

9. Audit on request

Once a year, and after a security event affecting the data, the Vendor answers BranderUX's written questions about its compliance with this annex and provides its current certification, audit report or security documentation.

נספח העברת מידע ישראלי לספקי משנה

זהו הנספח ש-BranderUX מציעה לספק שיקבל מידע אישי שאנו מחזיקים עבור לקוחותינו. הוא נכתב לפי הדרישות הישראליות: חוק הגנת הפרטיות, התשמ"א-1981, תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017, ותקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001.

הוא קצר בכוונה. ספק שכבר מחזיק בתקן ISO/IEC 27001 בוחר במסלול הזה בסעיף 5 וחותם על היתר ללא שינוי.

זוהי הצעה, ולא הצהרה שספק כלשהו חתם עליה. אילו נמענים חתומים עליה ואילו לא מפורסם לכל נמען בכתובת /api/legal/recipients ונאמר בהתקשרות בעמוד /legal/dpa.

1. תחולה

נספח זה חל על מידע אישי שחל עליו הדין הישראלי ושהספק מעבד עבור BranderUX בשם לקוחותיה. לגבי אותו מידע, הלקוח הוא בעל המאגר, BranderUX היא מחזיקה בו, והספק הוא מחזיק נוסף.

בכל הבדל בין תנאיו הסטנדרטיים של הספק לבין נספח זה לגבי אותו מידע, נספח זה גובר.

2. הגבלת מטרה

הספק מעבד את המידע אך ורק כדי לספק את השירות שעבורו התקשרה עמו BranderUX, אך ורק לפי הוראותיה המתועדות, ולא לשום מטרה משלו.

במפורש ולא במשתמע: אין אימון, כוונון או הערכה של מודל כלשהו על המידע, ואין שימוש בו לבניית מוצר או לשיפורו מלבד השירות שעליו הוסכם.

3. עיון ותיקון

כאשר אדם מממש זכות עיון או תיקון לפי סעיפים 13 ו-14 לחוק הגנת הפרטיות, הספק נותן ל-BranderUX את הסיוע ואת המידע הדרושים כדי להשיב בתוך התקופה הקבועה בדין.

הספק אינו משיב לאותו אדם ישירות אלא אם BranderUX ביקשה זאת ממנו בכתב.

4. סודיות

הספק שומר על סודיות המידע, מגביל את הגישה אליו לעובדים הזקוקים לו לצורך השירות שעליו הוסכם, ומחתים כל אחד מהם על התחייבות לשמירת סודיות בכתב שממשיכה לחול לאחר תום העסקתו.

5. אבטחה, לפי בחירת הספק

הספק בוחר באחת משתי הדרכים האלה, בכתב:

  • תעודת ISO/IEC 27001 בתוקף שהיקפה מכסה את השירות שעליו הוסכם, תוך יישום בקרות נספח A הרלוונטיות לו, ובכללן בקרת גישה, הצפנה, אבטחת תפעול, יחסי ספקים וניהול אירועי אבטחת מידע.
  • אמצעים המקיימים באופן מהותי את תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017: בקרת גישה לפי אדם מזוהה, הצפנה בהעברה ובמנוחה, תיעוד, נוהל אירועים כתוב, וסקירה תקופתית.

הספק מודיע ל-BranderUX כאשר בחירתו משתנה, ובכל עת לפי בקשה.

6. אין העברה נוספת בלא הסכמה בכתב

הספק אינו מעביר את המידע לשום נמען נוסף, בתוך מדינתו או מחוצה לה, בלא הסכמתה המוקדמת בכתב של BranderUX. ניתנה הסכמה, יחייב הספק את אותו נמען בתנאים שאינם חלשים מנספח זה ויישאר אחראי למעשיו.

זהו יישום של תקנה 3 לתקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001, שמכוחה נעשית ההעברה אל הספק עצמו.

7. הודעה על אירוע אבטחה

הספק מודיע ל-BranderUX על אירוע אבטחה הנוגע למידע ללא דיחוי ולא יאוחר מ-24 שעות לאחר שנודע לו עליו, עם מה שידוע לו באותה שעה, וממשיך לעדכן ככל שנלמד עוד.

הספק אינו ממתין לסיום הבדיקה שלו לפני מתן ההודעה.

8. מחיקה בסיום

עם סיום ההתקשרות, או קודם לכן לפי בקשתה בכתב של BranderUX, מוחק הספק את המידע ומאשר את המחיקה בכתב.

הוא שומר רק את מה שדין המחייב אותו מחייב לשמור, ולא לזמן ארוך יותר מהנדרש באותו דין, ונספח זה ממשיך לחול על כל מה שנשמר.

9. ביקורת לפי בקשה

אחת לשנה, ולאחר אירוע אבטחה הנוגע למידע, משיב הספק על שאלותיה בכתב של BranderUX בדבר עמידתו בנספח זה ומספק את התעודה, דוח הביקורת או תיעוד האבטחה העדכניים שלו.