Privacy Policy
Last updated: 23 September 2026
This English text is provided for convenience. The binding version is the Hebrew one: הגרסה העברית
This policy describes how Activated Digital Ltd (אקטיבייטד דיגיטל בע”מ) (hereinafter: “the Company”), the operator of the irua.app service, collects, uses, stores and shares personal information. This document was drafted in accordance with the requirements of the Protection of Privacy Law, 5741-1981, the Protection of Privacy (Data Security) Regulations, 5777-2017, and in the spirit of the GDPR principles insofar as they are relevant to European customers.
1. Roles: who is the database owner?
The following distinction is important for understanding this entire document. With respect to different information — the Company has a different role:
- Information about the organizer (the customer of irua.app): company name, contact person details, billing details, platform usage data. Here Activated Digital is the owner of the database (Controller) — we decide what to collect and why.
- Information about event guests (the organizer’s invitees): names, phone numbers, email addresses, form answers, attendance confirmations, entry scan data. Here the organizer is the owner of the database, and Activated Digital acts on the organizer’s behalf as a holder (Processor) only.
- Information about anonymous site visitors: IP address, browser type, pages viewed. Here Activated Digital is the owner of the database.
This distinction affects to whom requests to exercise access/deletion rights should be addressed: with respect to a guest record — the address is the organizer; with respect to your account with us — the address is Activated Digital.
2. Types of information we collect
Organizer account details
- First and last name, email address, phone number.
- Company or business name, company number, invoicing address.
- Encrypted password (bcrypt) — we do not see the password at any stage.
- Role permissions within the account (Owner, Admin, Hostess and the like).
Event and guest data
- Guest names, phone numbers, email addresses and any additional field defined by the organizer.
- RSVP status, number of participants, group, notes.
- Metadata of WhatsApp messages that were sent (date, delivery status, message content).
- Entry scan actions (date/time, scanning device).
Transaction data (where relevant)
- Amount, card type, date, transaction identifier at the payment processing provider.
- Credit card details are not stored with us — payment processing is carried out directly with Upay, and we see only the result (approval/rejection) and the transaction identifier.
Technical and usage data
- IP address, browser type, operating system, resolution.
- Pages viewed, actions performed, timestamps.
- Session identifier and the “remember me” cookie (gl_remember, valid for 30 days).
- Server-side error and fault logs — for debugging purposes only.
3. Methods of collection
We collect information in one of the following four ways: (a) direct provision — upon registration, filling in forms or purchasing a package; (b) from the organizer — when the organizer uploads an invitee list, imports an Excel file, or uses the documented API; (c) automatically — while browsing the site (Cookies, server logs); (d) from third parties — for example the transaction approval result from the payment processing provider, or delivery status from the WhatsApp provider.
4. Purposes of use
- Provision of the service itself — managing the account, events, guests and messages.
- Operational communication — payment confirmations, invoices, security alerts.
- Billing and issuance of tax documents.
- Improving the service — analysis of aggregate (non-personal) usage patterns.
- Data security and fraud prevention.
- Compliance with legal obligations — authority requirements, court orders, the Penal Law.
- Sending our marketing material to existing customers, on the basis of consent and with the option to unsubscribe at any time. Marketing directed at the organizer’s guests is the organizer’s sole responsibility — see the WhatsApp Messaging Policy.
5. Lawful bases for processing
Processing of the information is carried out on the basis of one of the following categories, according to the purpose of the processing:
- Consent — upon opening an account, filling in an event registration form, or consenting to mailings.
- Performance of a contract — providing the service for which the subscriber paid.
- Legal obligation — retention of tax records, compliance with an authority’s demand.
- Legitimate interest — securing the system, preventing fraud, improving the service.
6. Sharing with third parties
We do not sell personal information to any third party, under any circumstances. Limited sharing is carried out with the service providers without which the platform cannot function — infrastructure, payment processing, and WhatsApp sending providers. Every such provider is subject to a contractual undertaking to maintain the confidentiality of the information and not to use it for any external purpose.
Separately from the above, limited technical browsing information from our public marketing site is passed to measurement and advertising providers (Google and Meta) — only after you have given explicit consent, which you may withdraw at any time. This sharing is not essential to operating the service, does not apply to the guest data you upload to the system, and is set out in section 11.
The updated list of all third parties that receive information, the type of information they receive, and the location of their servers — is published separately and may be reviewed here: the sub-processor list.
In addition, we may disclose information pursuant to a valid legal order, or in the event of a structural change in the Company (merger, sale of operations) — provided that the receiving party is subject to the same level of protection.
7. Transfer of information outside Israel
Some of our sub-processors store information outside Israel (for example Amazon CloudFront and Meta WhatsApp Business, the WhatsApp gateway provider, in the USA; and Google and Meta for measurement and advertising purposes, subject to your consent — see section 11). Such a transfer will be made only to countries whose level of privacy protection meets the requirements of the Protection of Privacy Regulations (Transfer of Information to Databases Outside the State’s Borders), 5761-2001, or subject to accepted contractual safeguards (Standard Contractual Clauses, to the extent possible).
8. Retention periods
| Type of information | Default retention period | Note |
|---|---|---|
| Active organizer account | For the duration of the account | Deleted within 30 days of account closure, except for billing records |
| Guests at an event | Under the organizer’s control | The organizer may export and delete at any time from within the system |
| Invoices and tax records | 7 years | In accordance with the requirement of the Income Tax Ordinance |
| Server logs and message logs | Up to 24 months | For debugging purposes and for the resolution of disputes |
| Persistent identification Cookies | Up to 30 days | The “remember me” cookie — automatically cancelled upon logout |
9. Data security
The platform implements security measures corresponding to the obligations set out in the Protection of Privacy (Data Security) Regulations, 5777-2017, at a security level appropriate to the type of database and the type of information stored in it. This includes — encryption of traffic (HTTPS/TLS), encryption of passwords (bcrypt), HMAC signatures on API calls, separation of permissions, database backup, and logs of administrative actions. That said, no computer system can guarantee absolute security.
In the event of a severe data security incident affecting personal information of subscribers — we will act in accordance with the reporting obligation set out in the Regulations, and will notify the Privacy Protection Unit at the Ministry of Justice and the relevant account holders within the timeframes prescribed by law.
10. User rights
With respect to information of which we are the database owner, you have the following rights:
- Right of access — to receive a copy of the information we hold about you.
- Right of correction — to request the correction of erroneous or partial information.
- Right of deletion — to request the removal of the information (“the right to be forgotten”), subject to statutory retention obligations (for example tax records). The practical ways to exercise it are detailed in the Data Deletion Request document.
- Right to portability — to receive your information in a structured, machine-readable format.
- Right to object — to stop receiving marketing mailings at any time, by means of the “unsubscribe” link in every message.
With respect to information about a guest at an event — the request is addressed first to the organizer (the owner of the database). If the organizer does not handle the request, you may approach us and the interaction will be conducted jointly.
Every request to exercise a right will be answered within 30 days, as required by law. Requests should be addressed to: info@activated.digital.
11. Cookies and tracking technologies
We distinguish between essential cookies, without which the service does not work, and analytics and advertising cookies, which are written only after you have given explicit consent.
11.1 Essential cookies
- Session cookie: essential for logging in and for maintaining the connection with the server. Deleted when the browser is closed.
- “Remember me” cookie (gl_remember): optional, written only if you ticked the box upon logging in. Valid for 30 days, cancelled upon explicit logout.
- CSRF cookie: essential for protection against request forgery attacks.
- Language cookie (gl_locale): remembers the interface language you chose so you do not have to pick it again on every visit. Valid for one year, and contains no identifying information.
These cookies are required to operate the service and do not require consent. Disabling the essential cookies (Session, CSRF) will impair your ability to use the service.
11.2 Analytics and advertising cookies
On our public marketing site, and on the sign-up and login pages, we use third-party measurement and advertising tools in order to understand how visitors reach us and to measure the effectiveness of marketing campaigns. The tools are loaded through Google Tag Manager and are fully active only subject to your consent:
- Google Analytics 4 — aggregate usage statistics: traffic source, pages viewed and time on page.
- Google Ads — campaign conversion measurement and remarketing.
- Meta Pixel — conversion measurement for Facebook and Instagram campaigns, and audience building.
These are cross-site tracking technologies: they may recognise your browser on other websites, and they transfer information to Google and to Meta outside Israel. Full details — the sub-processor list. Until you consent, these tools write no cookies to your device and cannot recognise you between visits. They do, however, send Google a basic cookieless measurement signal as soon as the page loads — the page address, where you arrived from, and a temporary random identifier that is not stored on your device and cannot link one visit to another; personalised advertising is disabled. The tag manager itself (Google Tag Manager) loads either way, with every measurement and advertising category defaulted to denied — so nothing is stored on your device and nothing is linked to you until you accept.
We do not run advertising or cross-site tracking tools inside the system itself — that is, in the areas behind login, where your guest data is managed. The tools are limited to the public marketing and entry pages only.
11.3 Managing your preferences
You may change or withdraw consent at any time through the preference centre on the site. In addition: Google offers a blanket opt-out for Analytics via its official opt-out add-on, Meta allows ad preferences to be managed in your account settings, and every modern browser allows third-party cookies to be blocked or deleted in its settings.
12. Minors
The service is not intended for minors under the age of 18 and an account cannot be opened below that age. If it comes to our knowledge that information was collected from a minor without a guardian’s consent, we will delete it immediately. Event guests — do not open an account with us and are not required to disclose their age.
13. Changes to this policy
This policy may be updated from time to time. Material changes will be notified by email to account holders at least 15 days before they take effect. Continued use of the service after the effective date constitutes consent to the updated policy.
14. Contact details and the privacy protection officer
For questions, requests to exercise rights, or reporting a data security incident, you may contact:
Activated Digital Ltd (אקטיבייטד דיגיטל בע”מ)
Company No. 514400597
Dedicated privacy email: info@activated.digital
Telephone: 03-52-444-11
You are also entitled to approach the Privacy Protection Authority at the Ministry of Justice if in your view we acted contrary to law: gov.il/the Privacy Protection Authority.
Related documents
This policy is drafted in the masculine form for convenience only and is addressed to all genders alike.
This English version is provided for convenience only. The binding version of this policy is the Hebrew version; in the event of any discrepancy between the versions, the Hebrew version shall prevail. Hebrew version (מדיניות פרטיות).