Privacy Policy
Site owner and database controller
- Business name: Kesher — Communication Solutions.
- Address: 14 Chazon Ish St., Apt. 3, Modiin Illit, Israel.
- Email for privacy inquiries: [email protected]
- Phone: 077-921-9000
- Websites: קשר.ישראל (Hebrew) and kesher-phone.com (English), including the customer dashboard.
General
This policy explains what information is collected when you use Kesher's website, dashboard and phone system services, what it is used for, who it may be shared with, how long it is kept and what rights you have regarding it. Among other things, it is meant to provide the information required under the Israeli Privacy Protection Law, 5741-1981, and in particular Section 11 of that law.
You are not legally required to give us personal information. However, without certain details we cannot open an account, provide the service, issue an invoice or handle an inquiry.
This policy applies equally to everyone.
What information is collected
- Customer and contact details: name, organization name, phone number and email address.
- Dashboard sign-in details: your username. Your password is not stored in plain text — if you chose "stay signed in", only an encrypted token is stored in your browser.
- Phone system data: extensions, queues, menus, users and permissions, call history (caller number, destination, duration and time), recordings if you turned them on, and number lists for the group dialer. This data is stored in the phone system itself; the dashboard displays it and keeps a temporary copy so screens load quickly.
- Invoices and billing: invoice details, amounts and payment status.
- Contact form inquiries: name, phone, email, the department you chose, your message and any files you attached.
- Problem reports and requests: what you wrote in the report, screenshots and files you attached, and technical information about your browsing — as described in the next section.
- Technical information and server logs: IP address (also used to restrict sign-in by address, if set up for the account), browser type, request times, and slow or failed requests — for security and troubleshooting.
Reporting a problem — the technical information that is sent
When you report a problem using the "Report a problem" button, technical information is attached to the report to help us understand what happened, without you having to explain every step. It is collected in your browser while you browse, sent only when you submit a report, and shown in detail in the report window, under "What is sent", before you send it.
What is collected:
- The last 40 clicks: what you clicked, on which screen, and its position in the window (including how far the page was scrolled).
- Network requests the page sent: the address without parameters, the request type, the result, how long it took, and the error message the server returned if the request failed.
- Page errors and warnings, and resources (an image, a script) that failed to load.
- File upload and drag attempts: how many files, and their type and size.
- Form submissions, which field was changed, special keys (Enter, Escape, Ctrl shortcuts), confirmation dialogs that appeared and how they were answered, moving between screens and pages, and loss of network connection.
- Browser and screen details, page load times, and the last pages you visited.
What is never collected: passwords, what you typed in fields, content you pasted, the names of files you uploaded on the site's screens, and the parameters in addresses.
So that this information is not lost when you move between pages, it is kept in the browser tab (sessionStorage) for up to 30 minutes and deleted when the tab is closed. If you don't send a report, the information never leaves your browser.
What the information is used for
- Running the phone system and the dashboard, and managing the account and permissions.
- Showing calls, history and reports, and sending reports and emails you asked to send.
- Issuing invoices, billing and collection.
- Answering inquiries, handling problem reports and improving the service.
- Securing the system, preventing misuse and troubleshooting.
- Meeting legal obligations.
We will not send you marketing messages without consent given as required by law.
Who the information may be shared with
We do not sell personal information, and we do not pass it to third parties for advertising. Information may be accessible to providers who work for us, only to the extent the service requires:
- The telephony infrastructure provider that operates the phone system — where phone system data, calls and recordings are stored.
- Google (Gmail, Drive, Sheets and Apps Script) — for sending email, storing report and inquiry files, and backing up inquiries.
- Fly.io — hosting for the website and reporting system servers.
- Cloudflare — domain management and protection of traffic to the site.
- Competent authorities or a court, when there is a legal obligation or authority to do so.
Some providers store information on servers outside Israel. Such transfers are made in accordance with the law.
Cookies and browser storage
The site uses only cookies and storage that are necessary for it to work. There are no advertising cookies, and no third-party tracking or analytics tools.
session— your dashboard sign-in. Expires after 10 minutes of inactivity.kesher_remember— only if you chose "stay signed in": an encrypted token, for 30 days.kesher_login— your username, to fill it in at your next sign-in. No password and no secret.kfb_id— a random browser ID, for one year, so that someone who reported a problem without signing in can see the reply to their report.- Local storage (localStorage): accessibility settings, dashboard display preferences, and confirmation that you have seen the cookie notice.
- Tab storage (sessionStorage): the browsing trail for problem reports (see above). Deleted when the tab is closed.
You can block or delete cookies in your browser settings. Without the session cookie you cannot sign in to the dashboard.
How long information is kept
- Problem reports: a closed report is deleted automatically, together with its screenshots and files, 12 months after the last activity on it. Files stored in Google Drive are moved to the trash, and Google deletes them permanently within 30 days.
- Lock against deletion: an authorized staff member can lock a report against deletion when it is needed for handling that is still ongoing, for an inquiry, or to meet a legal obligation. A locked report is not deleted — neither automatically nor manually — until the lock is removed. After the lock is removed, the report is deleted under the regular rule, and not before 30 days have passed since the unlock.
- Files emailed to a staff member: kept in that staff member's mailbox, and deleted under the team's procedures once they are no longer needed.
- Contact form inquiries: also kept in a backup spreadsheet, as long as they are needed for handling and service.
- Call recordings: according to the retention period set in the account's phone system.
- Invoices and billing records: for the period the law requires such documents to be kept.
- All other information: as long as the account is active, and as long as it is needed for the purposes it was collected for or by law.
Information security
We take reasonable security measures: encrypted connections (HTTPS), encrypted sign-in tokens, permissions that limit each user and staff member to what they need, signed identity between our servers, and databases that are not open to the public. No method can guarantee complete protection against intrusion or failure.
Your rights
- Access: under Section 13 of the Privacy Protection Law, you may review the information held about you in the database, subject to the exceptions in the law.
- Correction or deletion: under Section 14 of the law, if the information is not correct, complete, clear or up to date, you may ask for it to be corrected or deleted.
- Deleting a report or inquiry: you may ask us to delete a report or inquiry you sent before the retention period ends.
You can send requests by email to [email protected], by phone at 077-921-9000 or through the contact page. To handle a request, we will ask for reasonable details to verify your identity and locate the information.
Minors
The service is intended for businesses and organizations, and for use by adults. We do not knowingly collect information about minors.
Changes to this policy
This policy may be updated, for example when services, systems or providers change. When there is a material change, we will give notice in a reasonable way. The current version is always published on this page. See also the terms of use and the accessibility statement.