1. General and database owner
This privacy policy describes how Science App Ltd, company no. 515462216 (hereinafter: "NITARTI" or “the Company”), collects and processes personal information under Israel’s Protection of Privacy Law, 1981 (including Amendment 13), and Protection of Privacy (Data Security) Regulations, 2017.
The policy applies to the Company website, the NITARTI app and all system use. Using the services constitutes acceptance of this policy, which forms an integral part of theTerms of Use.
In any conflict, mandatory law always prevails, followed by this policy’s provisions concerning privacy and data processing.
Privacy officer: Oded Savyon
Email: info@nitarti.com · Phone: 052-691-0337 · Sun–Thu, 09:00–17:00
Address: 4 Moshe Dayan St, Haifa
2. Information collected
2.1 Information you provide
- Contact and enquiry details: Full name, role, phone, email, organization and message content in contact forms, demo requests or service enquiries.
- Account details: Username, authentication details, permissions, organization and site assignments, and alert preferences.
- Billing details: Business/company details, invoices and payment history. Card details are provided directly to the payment processor and are not stored on NITARTI servers.
- Professional documentation: Identification documents, refrigerant-handling licenses, professional liability insurance and their validity dates.
2.2 Field monitoring data
The system continuously collects data from sensors, controllers and connected systems. Data types depend on the installed module:
| Module | Data collected |
|---|---|
| Industrial and commercial refrigeration | Temperatures (outdoor/indoor units, refrigerant inlet/outlet, evaporator, condenser), door status, current and voltage, phase loss, compressor load, fan and heater status, alerts and events. |
| Municipal management | Shelter door status (open/closed, remote opening), facility and equipment readiness, electricity and water use by building/area, electrical panel and fire-system status, lighting, panic buttons and field-unit GPS locations for command and control. |
| Worker and construction-site safety | Worker-tag data: worker ID, relative site/floor location, entry and exit, contractor/team assignment; panic-button events; protective-equipment indication (dress code); cabinet electrical loads; water/flood detection; presence in hazardous areas. |
| Partner IoT infrastructure | Device data, telemetry, device identifiers, operational logs and partner end-user data. |
| Service requests and spare parts | Request details, fault classification, remote diagnosis, arrival times, replaced parts, photos, signatures and approvals. |
2.3 Automatically collected technical information
IP address, device and browser type, operating system, device ID, system activity logs (who viewed, approved or changed settings, and when), website usage and cookies as described in theCookie policy.
3. Purposes of use and legal basis
Information is used only for the following purposes:
- Service provision: Continuous monitoring, anomaly detection, alerts, incident management, and managing and documenting service requests.
- Contract performance: Account setup, billing, collection, customer service and support.
- Safety and protection of life and property: Safety, distress, electrical-fault, flood and shelter-readiness alerts.
- Dispute resolution: Evidence records for service and warranty enquiries.
- Security and fraud prevention: Detecting unauthorized access and monitoring security incidents.
- Product improvement: Statistical and aggregate processing that cannot identify a customer or individual, to improve detection algorithms and reduce false alerts.
- Legal obligations: Reporting, accounting and responding to orders and requests from competent authorities.
Providing information is voluntary, but some data is necessary to provide the service.
4. Worker monitoring, tags and location: special provisions
The worker monitoring and safety module is intended solely for safety and operational management , not behavioral tracking, productivity measurement or discipline. NITARTI provides the tool; the employer or site manager owns the database of employee data and is responsible for lawful use.
- Notice and consent: The customer must inform every employee or subcontractor in writing beforehand about the system, collected data, purpose and retention, and obtain consent under applicable law and collective or individual employment agreements.
- Proportionality: Location is collected at area/floor/compound level for emergency locating, preventing entry to hazardous areas and safety attendance monitoring, not continuous tracking outside the site.
- Access restrictions: Location and tag data is available only to designated customer roles (safety officer, site manager, control room) according to permissions.
- Panic button: Pressing the panic button immediately generates an alert and location. These are retained as incident records and used for no other purpose.
- Prohibited use: Customers may not use system data for dismissal, fines or disciplinary action based on covert monitoring contrary to law.
5. Municipal management module: special provisions
- The municipality owns the database of infrastructure and resident data collected in its system; NITARTI acts as its data holder and processor.
- Shelter data, readiness and remote opening follow Home Front Command guidance and municipal procedures. NITARTI is not a security authority and does not make operational decisions.
- Water and electricity consumption is collected at facility/building/area level, not individual households, unless agreed otherwise in writing and subject to law.
- Security-sensitive data is handled under dedicated information-security arrangements in the municipal agreement.
6. IoT platform for development partners (White Label)
- In this service, the business partner is the database owner for its end users, and NITARTI acts as itsdata holder and processor only, following its instructions under a data-processing agreement.
- NITARTI will not independently use partner end-user data, contact or market to them, except for service provision, security and legal compliance.
- The partner is responsible for informing end users, obtaining consent and publishing its privacy policy.
- Regional-server or on-premise storage may be arranged contractually to meet regulatory requirements.
7. Disclosure to third parties
NITARTI does not sell personal information. Disclosure occurs only in these cases:
- Infrastructure and service providers: Hosting and cloud providers, licensed payment processors, SMS/email and analytics providers, as necessary and subject to confidentiality and security commitments.
- Professionals and technicians: Equipment and fault data is disclosed to the assigned professional solely for diagnosis and service.
- Customer representatives: Municipal control rooms, safety officers and main contractors, under customer-defined permissions.
- Legal requirements: Court orders, competent-authority requests, legal proceedings or protection of Company rights.
- Corporate changes: Merger, acquisition or business transfer, provided the acquirer accepts this policy.
8. Retention periods
| Information category | Retention period |
|---|---|
| User account details | While active and for 12 months after closure |
| Monitoring and alert data | According to the configuration and service tier in the agreement |
| Service and transaction records | 7 years from the transaction date |
| Enquiry and dispute records | 3 years after the enquiry closes |
| Worker location and tag data | Up to 12 months, except data forming part of a safety-incident record |
| Safety and distress incident records | 7 years for investigation, insurance and regulatory purposes |
| Security and anti-fraud data | 3 years from collection |
| Marketing information | Until the user withdraws consent |
Information required for accounting, tax or legal-rights protection will not be deleted before the applicable statutory period ends.
9. Information security
NITARTI implements technical and organizational protections under the Protection of Privacy (Data Security) Regulations, 2017, including encrypted traffic, role-based permissions, tenant separation, access audit logs, backups, security monitoring and vendor oversight.
For a serious security incident, the Company will act under the law, including notifying the Privacy Protection Authority and affected users where required. No system is completely immune, and absolute protection against intrusion cannot be guaranteed.
10. Data ownership and export rights
- Monitoring data originating from equipment installed at the customer belongs to the customer. NITARTI holds and processes it to provide the service.
- Customers may request historical monitoring data in a readable format (CSV/JSON or similar) at any time during subscription and for 14 days after it ends. Requests are answered within 14 business days.
- NITARTI may process anonymous aggregate data that cannot identify anyone for service improvement and research. Customers may ask the privacy officer to exclude their data from aggregate processing without affecting service.
11. User rights
Under the Protection of Privacy Law, you have the rights to: access the information held about you, correct incorrect or outdated information, anddelete , subject to section 8 retention periods and legal obligations.
Submit requests to the privacy officer. Responses are provided within 30 days, or up to 60 days in complex cases with advance notice. Users who believe their rights were infringed may also contact the Privacy Protection Authority.
12. Mailing and direct marketing
Marketing messages require explicit, separate consent under section 30A of the Communications Law (Telecommunications and Broadcasting). Each message includes an easy unsubscribe option; customer service can also remove you.
Operational alerts are not marketing messages. Anomaly, fault, distress and safety alerts are an essential service component. They are sent without marketing consent and cannot be disabled without cancelling the service itself.
13. Cookies and storage technologies
Full details of file types, purposes and management appear in theCookie policy.
14. Transferring data outside Israel
Some cloud and infrastructure services may be hosted or processed outside Israel. Transfers follow the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001, with contracts requiring adequate protection from recipients. Public-sector customers and regulated partners may arrange Israel-only hosting.
15. Minors
The service is for business and institutional use; registration is restricted to ages 18 and over. The Company does not knowingly collect minors’ information. Accidentally collected information will be deleted upon discovery.
16. Policy changes and contact
The Company may update this policy periodically. Material changes will be published on the site and registered users notified 14 days in advance. Continued use after the effective date constitutes acceptance of the updated version.
NITARTI · Customer service
Email: info@nitarti.com · Phone: 052-691-0337
Address: 4 Moshe Dayan St, Haifa · Website: nitarti.co.il
Business hours: Sunday–Thursday, 09:00–17:00