מדיניות פרטיות
עודכן לאחרונה: 6 בספטמבר 2026
1. מי אנחנו
מיצי (Mitzi Pro) היא מערכת לניהול הפקות, לקוחות ותכני רשתות חברתיות, המופעלת על ידי EDY Production, ישראל. לפניות בנושא פרטיות: info@mitzi.pro.
2. תפקידנו במידע
מיצי נמכרת לעסקים. העסק שרכש את המערכת הוא בעל השליטה במידע שהוא מזין אליה — פרטי הלקוחות שלו, הפרויקטים, החומרים והתכנים. אנחנו פועלים עבורו כמעבד מידע: אנחנו מאחסנים ומעבדים את המידע לפי הוראותיו ולצורך הפעלת השירות בלבד. אם הגעתם לכאן כלקוח של עסק שמשתמש במיצי, הפנייה בעניין המידע שלכם צריכה להיות מופנית לאותו עסק.
ביחס לחשבונות המשתמשים של אנשי הצוות במערכת ולפרטי ההתקשרות מול העסק עצמו — אנחנו בעלי השליטה במידע.
3. איזה מידע מעובד
- אנשי צוות: שם, כתובת דוא״ל, תפקיד והרשאות, פרטי התחברות (הסיסמה נשמרת מוצפנת חד־כיוונית ואינה גלויה לנו), ורישום הפעולות שביצעו במערכת.
- לקוחות העסק: שם, דוא״ל, טלפון, פרטי חברה, פרויקטים, מסמכים, רשומות כספיות, וחומרים שהועלו למערכת.
- תוכן שהועלה: וידאו ותמונות. חומרים אלה מכילים לרוב אנשים מזוהים, ולכן הם עצמם מידע אישי.
- אישורי לקוח: הערות, סימונים ואישורים שלקוח הקצה מזין בעמוד הצפייה, וכתובת הדוא״ל שבה אימת את זהותו.
איננו אוספים כתובות IP. אין במערכת רישום של כתובות IP או של סוג הדפדפן. ספקי התשתית שלנו רושמים כתובות IP בשכבה שלהם במהלך הפעלה רגילה של שירות אינטרנט, לפי מדיניות השמירה שלהם.
4. חיבור לאינסטגרם
עסק שמשתמש במיצי יכול לחבר חשבון אינסטגרם עסקי כדי לתזמן ולפרסם ממנו תכנים. החיבור נעשה דרך מסך ההרשאות הרשמי של אינסטגרם, ורק על ידי מנהל במערכת.
מה אנחנו מקבלים מאינסטגרם
- מזהה החשבון, שם המשתמש וסוג החשבון — כדי להציג לאיזה חשבון הפוסט ייצא.
- אסימון גישה (access token) — כדי לפרסם בשמכם במועד שתזמנתם, ללא נוכחות אדם.
- תגובות על הפוסטים שלכם, שם המגיב ומועד התגובה — רק אם אישרתם את הרשאת התגובות, וכדי להציג ולנהל אותן מתוך המערכת.
מה אנחנו לא עושים
- איננו מפרסמים דבר שלא נוצר ותוזמן על ידכם במערכת.
- איננו קוראים הודעות פרטיות, רשימות עוקבים או נתוני חשבונות אחרים.
- איננו מוכרים מידע מאינסטגרם, איננו משתמשים בו לפרסום ואיננו מעבירים אותו לצד שלישי.
אסימוני הגישה
אסימון הגישה נשמר מוצפן (AES‑GCM) במסד הנתונים הייעודי של אותו עסק, ומפתח ההצפנה מוחזק בסביבה נפרדת ממסד הנתונים. אסימון פג תוקף מחודש אוטומטית כל עוד החיבור פעיל.
ניתן לנתק את החשבון בכל רגע מתוך המערכת (הגדרות ← אינטגרציית רשתות), או להסיר את מיצי מתוך הגדרות אינסטגרם. בשני המקרים אסימון הגישה נמחק מיידית ולא ניתן עוד לפרסם בשמכם. פירוט מלא בעמוד מחיקת מידע.
5. למה אנחנו משתמשים במידע
- כדי לספק את השירות שהעסק רכש ולנהל את ההתקשרות מולו.
- כדי לשלוח הודעות תפעוליות — אישורי לקוח, תזכורות, קישורי צפייה.
- כדי לאבטח את המערכת, לאתר תקלות ולמנוע שימוש לרעה.
- כדי לעמוד בחובות חוקיות, לרבות חובות שמירת רשומות.
איננו מבצעים פרופיילינג, איננו מציגים פרסומות ואיננו מוכרים מידע לאיש.
6. ספקי משנה
| ספק | תפקיד | איזה מידע מגיע אליו |
|---|---|---|
| Supabase | מסד נתונים, הזדהות, אחסון קבצים והרצת פונקציות | כל נתוני המערכת, לרבות חומרים ומידע אישי |
| Vercel | אירוח האפליקציה ורשת הפצה | מטא־נתונים של בקשות. נתוני האפליקציה נמשכים ישירות מ‑Supabase |
| Resend | שליחת דוא״ל תפעולי | כתובות נמענים ותוכן ההודעה |
| סנכרון יומן (למי שחיבר יומן), ומודל ה‑AI של העוזר במערכת | אירועי יומן; והטקסט שנשלח לעוזר | |
| Meta / Instagram | פרסום תכנים וניהול תגובות | התוכן שבחרתם לפרסם ומזהה החשבון המחובר |
| Cloudflare | ניהול רשומות DNS של דומיינים | אין גישה לנתוני האפליקציה |
7. היכן המידע נשמר
לכל עסק מוקצה מסד נתונים נפרד ומבודד. מידע של עסקים שונים אינו מעורבב. אזור האחסון נקבע לכל התקנה בנפרד ומצוין בהסכם ההתקשרות; כיום בשימוש פרנקפורט (האיחוד האירופי) ו‑סידני (אוסטרליה). לעסק שמידע לקוחותיו נשמר מחוץ לישראל ולאיחוד האירופי מומלץ לוודא שההסכם מול לקוחותיו מכסה זאת.
8. עוגיות ואחסון מקומי
אין במיצי עוגיות פרסום, עוגיות אנליטיקה, פיקסלים או תגי שיווק. האחסון המקומי בדפדפן משמש לצרכים תפעוליים בלבד: שמירת ההתחברות של איש הצוות, ושמירת העדפות תצוגה. אסימון של צפייה בעמוד אישור לקוח נמחק עם סגירת הלשונית.
9. אבטחה
- הצפנת תעבורה (HTTPS/TLS) בכל החיבורים. זו אינה הצפנה מקצה לקצה.
- הפרדת גישה ברמת מסד הנתונים, כך שמשתמש רואה רק את המידע שהוא מורשה לו.
- אסימוני רשתות חברתיות מוצפנים במנוחה במפתח שמוחזק מחוץ למסד הנתונים.
- רישום פעולות (audit log) לפעולות משמעותיות במערכת.
10. שמירה ומחיקה
אנחנו שומרים מידע כל עוד הוא נדרש לצורך ההתקשרות ולתקופות שמירת רשומות שהדין מחייב. המערכת אינה מוחקת חומרים אוטומטית — מחיקה נעשית ביוזמת העסק. עם סיום ההתקשרות, מידע העסק נמחק או מוחזר לפי בקשתו. פירוט על מחיקת מידע שהתקבל מאינסטגרם בעמוד מחיקת מידע.
11. זכויותיך
לפי חוק הגנת הפרטיות ולפי ה‑GDPR במקום שהוא חל, עומדות לכם זכויות לעיין במידע, לתקן אותו, לבקש את מחיקתו ולהתנגד לעיבודו. פנייה כזו תטופל תוך 30 יום. חלק מהבקשות מבוצעות באופן ידני על ידינו ולא דרך המערכת. אם המידע שייך לעסק שמשתמש במיצי, נפנה אתכם אליו.
12. שינויים במדיניות
נעדכן עמוד זה כשיחולו שינויים, ותאריך העדכון בראש העמוד ישתנה בהתאם. שינוי מהותי יימסר גם ישירות לעסקים המשתמשים במערכת.
13. יצירת קשר
info@mitzi.pro · EDY Production, ישראל
Privacy Policy (English)
Last updated: 6 September 2026
1. Who we are
Mitzi Pro is a production, client and social-content management system operated by EDY Production, Israel. Privacy enquiries: info@mitzi.pro.
2. Our role
Mitzi is sold to businesses. The business that licenses it is the controller of the data it enters — its own clients, projects, media and content. We act as its processor, storing and processing that data on its instructions and only to operate the service. If you are a client of a business that uses Mitzi, address requests about your data to that business. For the staff user accounts and our own commercial relationship with the business, we are the controller.
3. What we process
- Staff: name, email, role and permissions, credentials (passwords are stored as one-way hashes and are not visible to us), and an audit record of actions.
- The business’s clients: name, email, phone, company details, projects, documents, financial records and uploaded material.
- Uploaded content: video and images, which routinely contain identifiable people and are therefore personal data in their own right.
- Client approvals: comments, drawings and decisions submitted on a review page, and the email address used to verify that session.
We do not collect IP addresses. The application records no IP address and no user-agent anywhere. Our infrastructure providers log IP addresses at their own layer in the ordinary course of running a web service, under their own retention policies.
4. Instagram connection
A business using Mitzi may connect an Instagram professional account in order to schedule and publish its own content. The connection is made through Instagram’s official permissions screen, and only by an administrator of that business.
What we receive: the account id, username and account type, so we can show which account a post will go out from; an access token, so a post you scheduled can be published at the time you chose without anyone present; and, only if you granted the comments permission, the comments on your own posts together with the commenter’s username and timestamp, so they can be read and answered inside Mitzi.
What we do not do: we publish nothing that you did not create and schedule in Mitzi. We do not read direct messages, follower lists or any other account’s data. We do not sell Instagram data, do not use it for advertising, and do not pass it to any third party.
Tokens are stored encrypted (AES-GCM) in that business’s own dedicated database, with the encryption key held in a separate environment from the database. A token is refreshed automatically for as long as the connection remains active.
You can disconnect at any time from inside Mitzi (Settings → Social integration), or by removing Mitzi in your Instagram settings. Either deletes the access token immediately and ends our ability to publish on your behalf. See Data deletion.
5. Why we use it
- To provide the service the business licensed and to manage that relationship.
- To send operational email — approvals, reminders, review links.
- To secure the system, diagnose faults and prevent misuse.
- To meet legal obligations, including record-keeping.
We do not profile, do not show advertising, and do not sell data to anyone.
6. Sub-processors
| Provider | Function | Data reaching it |
|---|---|---|
| Supabase | Database, authentication, file storage, function execution | All application data, including media and personal data |
| Vercel | Application hosting and CDN | Request metadata; application data is fetched directly from Supabase |
| Resend | Transactional email delivery | Recipient addresses and message content |
| Calendar sync (where connected) and the in-app assistant model | Calendar events; text sent to the assistant | |
| Meta / Instagram | Content publishing and comment management | The content you chose to publish and the connected account id |
| Cloudflare | DNS records for customer domains | No access to application data |
7. Where data is stored
Each business is given a separate, isolated database; data belonging to different businesses is never pooled. The hosting region is set per deployment and stated in that customer’s agreement. Regions currently in use are Frankfurt (EU) and Sydney (Australia).
8. Cookies and local storage
There are no advertising cookies, no analytics cookies, no tracking pixels and no marketing tags in Mitzi. Browser storage is strictly functional: a staff member’s signed-in session and display preferences. A client review session is cleared when the browser tab closes.
9. Security
- Transport encryption (HTTPS/TLS) on every connection. This is not end-to-end encryption.
- Row-level access control in the database, so a user sees only what they are entitled to.
- Social tokens encrypted at rest under a key held outside the database.
- An audit log of significant actions.
10. Retention and deletion
We retain data for as long as it is needed for the engagement and for statutory record-keeping periods. The system does not delete media automatically; deletion is initiated by the business. On termination, a business’s data is deleted or returned at its request. For Instagram data specifically, see Data deletion.
11. Your rights
Under Israeli privacy law and, where it applies, the GDPR, you may access, correct, request deletion of, and object to the processing of your personal data. We respond within 30 days. Some requests are fulfilled manually rather than through the product. If the data belongs to a business using Mitzi, we will direct you to that business.
12. Changes
We update this page when things change, and the date at the top changes with it. Material changes are also communicated directly to businesses using the system.
13. Contact
info@mitzi.pro · EDY Production, Israel