We at Tokabot Ltd. (“Tokabot” “us“, “we“, or “our“) recognize and respect the importance of maintaining the privacy of our customers and, as a result, we have established this Privacy Notice. If not otherwise defined herein, capitalized terms have the meaning given to them in the Terms of Service, available at http://www.tokabot.com (“Terms“). This Privacy Notice describes the types of information we collect from you when you use our Services as either a Customer or a User or when you visit our Site and use any services available thereon. It also describes how we may use, transfer, store, and disclose the information collected, as well as your ability to control certain uses of the collected information.
When we process Personal Data (as defined below) relating to Customers or relating to visitors to the Site, we serve as the data controller of such processing activities. Our registered office is Derech Habsamim 1 Ganei Tikva and our company registration number is 515680965.
When we process information in the context of providing Services to Customers, including information relating to Users, the applicable Customer serves as a controller with respect to such Customer’s Users’ Personal Data.
“Personal Data” means any information that refers, is related to, or is associated with an identified or identifiable individual or as otherwise may be defined by applicable law.
Privacy Notice Key Points
The following key points listed below are presented in further detail throughout this Privacy Notice.
These key points do not substitute the full Privacy Notice.
- Personal Data We Collect. If you are the representative of a Customer, we collect Personal Data provided by you such as your name, email address, the company you work for and your job title. If you are a User, we collect your basic profile information from and on behalf of the Customer. We also collect information about your use of the Services. If you use our Site and/or contact us for questions or complaints, we will collect the information related to your use or inquiry, as applicable.
- How We Use Your Personal Data. We use the information (including Personal Data) we collect and/or receive from users of the Site, Customer and Users mainly to administer and provide and improve the Site and Services.
- Basis for Processing Your Personal Data. If you are the representative of a Customer, and/or a User, processing your Personal Data is necessary for the provision of the Services to you and/or the relevant Customer. Processing information about the use of the Site and/or Services is necessary for the purposes of developing and enhancing our products, Site and Services, for analytics and usage analysis, for fraud prevention and security and for our recordkeeping and protection of our legal rights – are all necessary for the purposes of legitimate interests that we pursue. Processing of User information for third-party marketing purposes on behalf of the Customer is based upon the consent of the User.
- Sharing the Personal Data We Collect. If you are a User or a Customer representative, we share your Personal Data with the applicable Customer as well as with our service providers and subcontractors who assist us in the operation of Services as well as with business partners and affiliates who may offer you personalized content and advertisement through Services. If you are a Site user, we share your Personal Data with our service providers and subcontractors who assist us in the operation of Site.
- International Transfer. We use service providers and/or subcontractors and/or cooperate with or have business partners and affiliates located in countries other than your own, and send them your Personal Data. We will ensure that we have agreements in place with such parties that ensure the same level of privacy and data protection as set forth in this Privacy Notice. You hereby consent to such international transfer.
- We implement industry standard measures aimed at reducing the risks of damage and unauthorized access or use of Personal Data, but they do not provide absolute information security. Such measures include physical, electronic, and procedural safeguards (such as secure servers, firewalls, antivirus and SSL encryption), access control, and other internal security policies.
- Your Rights. Subject to applicable law and additional rights as set forth below, you may have a right to access, update and/or delete your Personal Data and obtain a copy of the Personal Data we have collected about you. If you are a User, you can change your mind at any time about your election to receive having your Personal Data processed for direct marketing purposes and also have the right to object at any time to processing your personal data for certain purposes, including marketing purposes. If you are a User, please contact the relevant Customer to exercise either of your abovementioned rights.
- Data Retention. We retain information for as long as necessary for the purposes set forth in this Privacy Notice. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether those purposes can be achieved through other means, as well as applicable legal requirements. We retain Personal Data of Users in accordance with the instructions of the applicable Controller.
- We do not knowingly collect personally-identifiable information from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) is using the Site and/or Services without parental permission, please advise us immediately.
- Third-Party Applications and Services. All use of third-party applications or services, including use of the Services by Users, or any third party applications or website through the Site is at your own risk and subject to such third party’s privacy policies.
- Communications. Subject to your consent and applicable law, if you are a Customer we may send you e-mail or other messages about us or our Services. You can stop receiving future communications from us by following the UNSUBSCRIBE link located at the bottom of each communication, by emailing us at
- Changes to the Privacy Notice. We may change this Privacy Notice from time and shall notify you of such changes.
- Comments and Questions. If you have any comments or questions about this Privacy Notice, or if you are the representative of a Customer or visitor to the Site wish to exercise your legal rights with respect to your Personal Data, please contact us at firstname.lastname@example.org.
Personal Data We Collect
If you are the representative of a Customer, we collect Personal Data provided by you such as your name, email address, the company you work for and your job title.
If you are a User, we collect your basic profile information from and on behalf of the Customer. We also collect information about your use of the Services. In order to use the Services, you must have a valid Facebook** account or account with the Customer’s website or App, as applicable. We collect Personal Data made available to us by Customer, which may include account information. We recommend that you review the Customer’s policies prior to using our Services.
** Per every user connected to Tokabot service via Facebook Messenger the following data will be utilized by our system: First name, Last Name, PS ID (the specific ID of every user in a specific Facebook page which Tokabot is serving, Image, Gender, Locale, Time zone)
This is the basic data provided by Facebook.
This data is collected by Tokabot on behalf of our customer and for the customer use only. (The data controller). The data is not shared by Tokabot with any 3rd party.
We also collect Personal Data when you make use of the Site, request information from us, complete online forms, or contact us for any other reason.
It is your voluntary decision whether to provide us with any such Personal Data, but if you refuse to provide such information we may not be able to provide you with the Site and/or Services.
How We Use Your Personal Data
Tokabot and any of our trusted third-party subcontractors and service providers may use the information we collect from Customers or from Users on behalf of Customers or from visitors to the Site for any of the following purposes: (1) to respond to your inquiries or requests, contact, and communicate with you; (2) provide you with the Site and/or Services, including customer support, where relevant; (3) develop new products or services and conduct analyses to improve our current Site, Content, and Services; (3) review the usage and operations of our Services; (4) if you are a User subject to your consent, provide you with promotional materials on behalf of the Customer and their respective business partners; (5) to review the usage and operations of our Site and Services; (6) to use your data in an aggregated, non-specific format for analytical purposes (as detailed below); (7) to prevent fraud, protect the security of our Site and Services, and address any problems with the Site and/or Services; (8) to provide customer support; and (9) to satisfy our legitimate interests, while at all times ensuring that your rights and freedoms are not affected.
By analyzing all information we receive, including all information concerning users, we may compile statistical information across a variety of platforms and users (“Statistical Information“). Statistical Information helps us and the Customer understand trends and customer needs so that new products and services can be considered and so that existing products and services can be tailored to customer desires. Statistical Information is anonymous and aggregated and we will not link Statistical Information to any Personal Data. We share such Statistical Information with our partners, without restriction, on commercial terms that we can determine in our sole discretion. We share such Statistical Information relating to Users with the applicable Customer.
We may use certain analytics tools (“Analytics Tools“) to collect information about the use of the Services. We do not combine the information collected through the use of the Analytics Tools with Personal Data. We use the information we get from Analytics Tools only for purposes of our provision of Services to the Customer.
We may use your Personal Data as required or permitted by any applicable law.
Basis for Processing Your Personal Data
If you represent a Customer or are a User, processing your Personal Data is necessary for the performance of the Terms and the provision of the Services to you and/or the Customer, including responding to your inquiries or requests, contacting and communicating with you and providing customer support, as applicable.
Processing for the purposes of developing new and enhancing our Content, Site and Services, for analytics and usage analysis, for fraud prevention and security and for our recordkeeping and protection of our legal rights – are all necessary for the purposes of legitimate interests that we pursue. In conducting such processing activities, we balance these legitimate interests against the rights and interests of our users. If you would like more information regarding how we make such determinations, please contact us through the contact information specified below.
Processing of User information for third-party marketing purposes on behalf of the Customer is based upon the consent of the User
Please note that we may process your Personal Data for more than one legal basis depending on the specific purpose for which we are using your Personal Data. Please contact us if you would like details about the specific legal ground we are relying on to process your Personal Data.
Sharing the Personal Data We Collect
We may share your information, including Personal Data, as follows:
Business Partners, Service Providers, Affiliates and Subcontractors
If you are a User or representative of a Customer, we may disclose information, including Personal Data we collect and/or receive from and/or about you to the Customer and our trusted service providers, affiliates and subcontractors, who may use such information to: (1) help us provide you with Services; and (2) aid in their understanding of how users are using our Services and improve the Services; and (3) subject to your consent as may be required under applicable law, provide to you personalized content and advertising through the Services. If you are a Site user, we share your Personal Data with our service providers and subcontractors who assist us in the operation of Site.
We may transfer our databases containing your Personal Data if we sell our business or part of it, including in cases of liquidation. Information about our users, including Personal Data, may be disclosed as part of, or during negotiations of, any merger, sale of company assets or acquisition and shall continue being subject to the provisions of this Privacy Notice.
Law Enforcement Related Disclosure
We will fully cooperate with any law enforcement authorities or court order requesting or directing us to disclose the identity, behavior or (digital) content and information of or related to an individual, including in the event of any user suspected to have engaged in illegal or infringing behavior. We may also share your Personal Data with third parties: (i) if we believe in good faith that disclosure is appropriate to protect our rights, property or safety (including the enforcement of the Terms and this Privacy Notice); (ii) to protect the rights, property or safety of third parties; (iii) when required by law, regulation subpoena, court order or other law enforcement related issues; or (iv) as is necessary to comply with any legal and/or regulatory obligation. You can request such Personal Data as specified herein by emailing us at email@example.com.
Other Uses or Transfer of Your Information
We allow you to use our Site and/or Services in connection with third-party services, sites, and/or mobile applications, including, without limitation, Facebook or the website of the Customer. If you use our Site and/or Services with or through such third-parties, or if you click on any third party link on the Site, we may receive information (including Personal Data) about you from those third parties. Please note that when you use third-parties outside of our Services, their own terms and privacy policies will govern your use of those services.
We use subcontractors and service providers and have business partners and affiliates who are located in countries other than your own, and send them information we receive (including Personal Data). We will ensure that these third parties will be subject to written agreements ensuring the same level of privacy and data protection as set forth in this Privacy Notice, including appropriate remedies in the event of the violation of your data protection rights in such third country.
Whenever we transfer your Personal Data to third parties based outside of the European Economic Area (“EEA“), we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the European Commission.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give Personal Data the same protection it has in the EEA.
- Where we use providers based in the US, we may transfer data to them if they have been certified by the EU-US Privacy Shield which requires them to provide similar protection to Personal Data shared between the Europe and the US or any other arrangement which has been approved by the European Commission.
Please contact us through the contact information listed below if you would like further information on the specific mechanism used by us when transferring your Personal Data out of the EEA.
You hereby consent to such international transfer described above.
We make efforts to follow generally accepted industry standards to protect the Personal Data submitted to and collected by us, both during transmission and once we receive it, including by implementing the below:
Safeguards – The physical, electronic, and procedural safeguard we employ to protect your data include secure servers, firewalls, antivirus and SSL encryption of data.
Access Control – We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after employee termination.
Internal Policies – We maintain and regularly review and update our privacy related and information security policies.
Personnel – We require new employees to sign non-disclosure agreements according to applicable law and industry customary practice.
Encryption – We encrypt the data in transit using secure protocols.
Database Backup – Our databases are backed up on a periodic basis for certain data and which are verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality and integrity and are tested regularly to ensure availability, and are accessed only by authorized personnel.
However, no method of transmission over the Internet, or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
How to Access and Limit Our Use of Certain Information
You have certain rights in relation to the Personal Data that we or the relevant controller hold about you, as detailed below. For any requests to exercise such rights with respect to information held by the relevant Customer, please contact the applicable Customer directly. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information and/or comply with any of your requests, as detailed below:
- Right of Access and Data Portability. You have a right to know what Personal Data we about you and, in some cases, to have the information communicated to you. Subject to the limitations in applicable law, you may be entitled to obtain from us a copy of the Personal Data you provided to us (excluding information that we obtained from other sources) in a structured, commonly-used, and machine-readable format, and you may have the right to (request that we) transmit such Personal Data to another party. If you wish to exercise this right please contact us letting us know what information in particular you would like to receive and/or transmit. Subject to applicable law, we may charge you with a fee. Please note that we may not be able to provide you with all the information you request, for instance, if the information includes Personal Data about another person. Where we are not able to provide you with information that you have asked for, we will endeavor to explain to you why. We will try to respond to any request for a right of access as soon as possible.
- Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, correct or delete inaccurate or outdated Personal Data and/or that we suspend the use of Personal Data, the accuracy of which you may contest, while we verify the status of that Personal Data. We will correct your Personal Data within a reasonable time from the receipt of your written request thereof.
- Deletion of Personal Data (“Right to Be Forgotten”). In certain circumstances you have a right to have Personal Data that we hold about you deleted. Should you wish to have any Personal Data about you deleted, please contact us, using the contact information specified in this Privacy Notice. Subject to applicable law, we will delete Personal Data provided to us by a user within a reasonable time from the receipt of a written (including via email) request by such user to delete such collected Personal Data. We cannot restore information once it has been deleted. We may retain certain Personal Data (including following your request to delete) for audit and record-keeping purposes, as well as other purposes, all as permissible and/or required under applicable law. We may also retain your information in an anonymized form.
- Right to Restrict Processing: You may request at any time that we limit the processing of your Personal Data if you believe that either: (i) the Personal Data is inaccurate and wish us to limit processing until we verify its accuracy; (ii) the processing is unlawful, but you do not wish us to erase the Personal Data; (iii) we no longer need the Personal Data for the purposes for which it was collected, but you still need it for the establishment, exercise, or defense of a legal claim; (iv) you have exercised your Right to Object (as specified below) and we are in the process of verifying our legitimate grounds for processing. We may continue to use your Personal Data after a restriction request either: (a) with your consent; (b) for the establishment, exercise or defense of legal claims; or (c) to protect the rights of another natural or legal person.
- Right to Object. Subject to applicable law, you may have the right to object to processing of your Personal Data for certain purposes.
- Withdrawal of Consent. You may withdraw your consent in connection with any processing of your Personal Data based on a previously granted consent.
- Supervisory Authority. If you are a European Citizen, you may have the right to submit a complaint to the relevant supervisory data protection authority.
Subject to applicable law, we retain information as necessary for the purposes set forth above. We may delete information from our systems, without notice to you, once we deem it is no longer necessary for the purposes set forth in this Privacy Notice. We may also retain your information in an anonymized form. In addition, retention by any of our processors may vary, in accordance with the processor’s retention policy.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether those purposes can be achieved through other means, as well as applicable legal requirements.
Please contact us through the contact information listed below if you would like details regarding the retention periods for different types of your Personal Data.
Where we act as a processor, we retain Personal Data of Users in accordance with the instructions of the applicable Controller.
Third-Party Applications and Services
All use of third-party applications or services, including those of the Customer, is at your own risk and subject to such third party’s privacy policies.
Tokabot does not knowingly collect personally-identifiable information from children under the age of sixteen (16). In the event that you become aware that an individual under the age of Sixteen (16) is using the Site and/or Services without parental permission, please advise us immediately.
We may update this Privacy Notice from time to time – we encourage you to review it periodically. By continuing to access or use the Site and/or Services after those changes become effective, you agree to be bound by the revised privacy notice. We will post the updated Privacy Notice on this page. Please come back to this page every now and then to make sure you are familiar with the latest version. Any new Privacy Notice will be effective from the date it is accepted by you.
Comments and Questions
If you have any comments or questions about our Privacy Notice, or if you are a Customer or Site visitor and wish to exercise any of your rights, please contact us at firstname.lastname@example.org.
Last updated: February 2019