Data Processing Agreement (DPA) | Active

Data Processing Agreement (DPA)

Governing the processing of personal data in the Active system and the parties' obligations under Israeli privacy protection law

Last updated: July 13, 2026

This Agreement governs the processing of the personal data that the user enters into the Active system, and sets out the parties' obligations in accordance with Israeli privacy protection law. This Agreement forms an integral part of the Terms of Use.

1. Introduction

This Data Processing Agreement is entered into between Active Flow Ltd. (the "Company" or the "Processor") and the customer using the system's services (the "Customer" or the "Controller"), and its purpose is to govern the processing of the personal data that the Customer enters into the system as part of receiving the services, in accordance with the Israeli Privacy Protection Law, 5741-1981 (including Amendment No. 13), the Privacy Protection Regulations (Data Security), 5777-2017, and the other regulations enacted thereunder (collectively: the "Privacy Protection Laws").

2. Definitions

3. Roles of the Parties

3.1. The Customer is the Data Controller of the database with respect to the personal data it enters into the system, and it determines the purposes and means of the processing.

3.2. The Company acts as the Data Processor, processing the data on the Customer's behalf and solely in accordance with its instructions, as detailed in this Agreement and in Appendix A.

3.3. Nothing in this Agreement grants the Company any ownership or control rights over the data the Customer enters into the system, and the data remains the Customer's property at all times.

4. Scope and Purposes of Processing

4.1. The Company will process the personal data solely for the purpose of providing, operating, securing and supporting the services, in accordance with the Customer's instructions as reflected in its account settings and its use of the system, and for no other purpose.

4.2. Some of the services include processing by means of artificial intelligence, such as call transcription, call analysis and insight generation. This processing is performed solely to provide the service to the Customer, and its outputs are available to the Customer in its account.

4.3. The Company will not use the personal data of the Customer's end customers for its own independent purposes, including marketing, and will not sell or rent such data to third parties.

4.4. The categories of data, the data subjects and the permitted processing operations are detailed in Appendix A to this Agreement.

5. Representations and Undertakings

5.1. The Customer represents that the data it enters into the system was collected by it lawfully, that a legal basis exists for its processing, including notifying data subjects to the extent required (and in particular with respect to call recording and transcription), and that its instructions to the Company do not violate the Privacy Protection Laws.

5.2. The Company represents that it possesses the knowledge, experience and means required to provide the services, and that it is not aware of any conflict of interest between itself and its obligations under this Agreement.

5.3. Each party will comply with the obligations applicable to it under the Privacy Protection Laws with respect to its role in the data processing.

6. Sub-Processors

6.1. The Customer authorizes the Company to engage sub-processors for the purpose of providing the services (such as cloud hosting, communications and telephony, artificial intelligence services, payment processing and email delivery), provided that the Company enters into a written agreement with them that includes data security and confidentiality obligations no less stringent than those set out in this Agreement and in the Data Security Regulations.

6.2. The Company will remain liable to the Customer for the processing performed by its sub-processors.

6.3. A list of the principal sub-processors will be provided to the Customer upon written request.

7. Data Security

7.1. The Company implements technological, physical and organizational security measures appropriate to the security level applicable to the database under the Data Security Regulations, including: encryption of data in transit and at rest, access permission management based on the need-to-know principle, user authentication, access logging and monitoring controls, environment separation, backups and recovery procedures.

7.2. The Company is certified to the international data security standard ISO 27001 and maintains an information security management system in accordance with it.

7.3. The Company binds its employees and authorized personnel to confidentiality undertakings, conducts periodic training on data security and privacy protection, and restricts access to data to those employees who require it for their role only.

7.4. The Company has appointed a person responsible for data security, who can be reached using the contact details set out in Appendix A.

8. Confidentiality

The Company will keep the personal data confidential and will not disclose or transfer it to any third party except to the extent required to provide the services through sub-processors as set out in Section 6, in accordance with the Customer's instructions, or where required by law. The confidentiality obligation will continue to apply after the end of the engagement.

9. Security Incidents

9.1. The Company will notify the Customer, without unreasonable delay after becoming aware of it, of any severe security incident concerning the Customer's personal data, and will provide the Customer with the details known to it about the incident, including the type of data exposed, the scope of the incident and the steps taken.

9.2. The Company will act without delay to mitigate the damage caused by the incident, remedy the deficiencies that led to it and prevent its recurrence, and will cooperate with the Customer as required for the Customer to comply with its reporting obligations, including reporting to the Privacy Protection Authority.

9.3. The Company will not publish or issue any public notice regarding a security incident concerning the Customer's data without prior coordination with the Customer, unless required by law.

10. Data Subject Rights and Requests from Authorities

10.1. The system allows the Customer to review, correct and delete data independently. Where additional assistance is required to respond to a data subject request (review, correction or deletion), the Company will assist the Customer reasonably and without delay.

10.2. If a data subject contacts the Company directly regarding data controlled by the Customer, the Company will refer the request to the Customer, unless otherwise required by law.

10.3. If the Company is required by a competent authority to disclose the Customer's data, it will notify the Customer before the disclosure, to the extent permitted by law.

11. Audit and Reporting

11.1. Upon the Customer's request, and no more than once a year, the Company will provide the Customer with a confirmation or report regarding its compliance with its obligations under this Agreement and under the Data Security Regulations.

11.2. The Company conducts periodic audits of its data security program, including as part of its ISO 27001 certification, and will provide the Customer with evidence of a valid certification upon request.

12. Termination and Data Deletion

12.1. The Company will retain the personal data only for as long as required to provide the services or as required by law.

12.2. Upon termination of the engagement, the Customer has a 30-day grace period to export its data from the system, as detailed in the Cancellation Policy. At the end of this period, or upon the Customer's written request, the Company will delete the personal data or return it to the Customer, except for copies it is required to retain by law or for defense against legal claims, which will remain subject to the confidentiality and security obligations of this Agreement.

13. Transfer of Data Outside Israel

Transfer of personal data outside the borders of Israel will be carried out only in accordance with the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, and subject to a written engagement with the receiving party ensuring an adequate level of protection for the data.

14. General

14.1. This Agreement is governed by the laws of the State of Israel, and exclusive jurisdiction is vested in the competent courts as set out in the Terms of Use.

14.2. In the event of any conflict between this Agreement and the Terms of Use regarding the processing of personal data, the provisions of this Agreement will prevail.

14.3. The Company may update this Agreement from time to time to reflect changes in law or in the services. Notice of any material change will be provided on the website or by email.

Appendix A - Processing Details

A.1. Categories of Data Subjects

A.2. Categories of Personal Data

A.3. Permitted Processing Operations

Collection, intake, storage, organization, review, analysis (including transcription and AI-powered analysis), transfer between service components, retrieval, correction, backup and deletion - all solely for the purpose of providing the services.

A.4. Security Level

The data is processed in accordance with the security level applicable to the database under the Data Security Regulations, and in accordance with the Company's information security management system, certified to the ISO 27001 standard.

A.5. Privacy and Data Security Contact