Policy documents

Privacy policy

How NITARTI collects, uses, stores and protects personal information in refrigeration monitoring, municipal management, worker monitoring and safety, and the IoT platform for development partners.

Version 1.0 · Updated August 19, 2026 · Applies to the NITARTI website, app and system

1. General and database owner

This privacy policy describes how Science App Ltd, company no. 515462216 (hereinafter: "NITARTI" or “the Company”), collects and processes personal information under Israel’s Protection of Privacy Law, 1981 (including Amendment 13), and Protection of Privacy (Data Security) Regulations, 2017.

The policy applies to the Company website, the NITARTI app and all system use. Using the services constitutes acceptance of this policy, which forms an integral part of theTerms of Use.

In any conflict, mandatory law always prevails, followed by this policy’s provisions concerning privacy and data processing.

Privacy officer: Oded Savyon

Email: info@nitarti.com · Phone: 052-691-0337 · Sun–Thu, 09:00–17:00

Address: 4 Moshe Dayan St, Haifa

2. Information collected

2.1 Information you provide

  • Contact and enquiry details: Full name, role, phone, email, organization and message content in contact forms, demo requests or service enquiries.
  • Account details: Username, authentication details, permissions, organization and site assignments, and alert preferences.
  • Billing details: Business/company details, invoices and payment history. Card details are provided directly to the payment processor and are not stored on NITARTI servers.
  • Professional documentation: Identification documents, refrigerant-handling licenses, professional liability insurance and their validity dates.

2.2 Field monitoring data

The system continuously collects data from sensors, controllers and connected systems. Data types depend on the installed module:

ModuleData collected
Industrial and commercial refrigerationTemperatures (outdoor/indoor units, refrigerant inlet/outlet, evaporator, condenser), door status, current and voltage, phase loss, compressor load, fan and heater status, alerts and events.
Municipal managementShelter door status (open/closed, remote opening), facility and equipment readiness, electricity and water use by building/area, electrical panel and fire-system status, lighting, panic buttons and field-unit GPS locations for command and control.
Worker and construction-site safetyWorker-tag data: worker ID, relative site/floor location, entry and exit, contractor/team assignment; panic-button events; protective-equipment indication (dress code); cabinet electrical loads; water/flood detection; presence in hazardous areas.
Partner IoT infrastructureDevice data, telemetry, device identifiers, operational logs and partner end-user data.
Service requests and spare partsRequest details, fault classification, remote diagnosis, arrival times, replaced parts, photos, signatures and approvals.

2.3 Automatically collected technical information

IP address, device and browser type, operating system, device ID, system activity logs (who viewed, approved or changed settings, and when), website usage and cookies as described in theCookie policy.

3. Purposes of use and legal basis

Information is used only for the following purposes:

  • Service provision: Continuous monitoring, anomaly detection, alerts, incident management, and managing and documenting service requests.
  • Contract performance: Account setup, billing, collection, customer service and support.
  • Safety and protection of life and property: Safety, distress, electrical-fault, flood and shelter-readiness alerts.
  • Dispute resolution: Evidence records for service and warranty enquiries.
  • Security and fraud prevention: Detecting unauthorized access and monitoring security incidents.
  • Product improvement: Statistical and aggregate processing that cannot identify a customer or individual, to improve detection algorithms and reduce false alerts.
  • Legal obligations: Reporting, accounting and responding to orders and requests from competent authorities.

Providing information is voluntary, but some data is necessary to provide the service.

4. Worker monitoring, tags and location: special provisions

The worker monitoring and safety module is intended solely for safety and operational management , not behavioral tracking, productivity measurement or discipline. NITARTI provides the tool; the employer or site manager owns the database of employee data and is responsible for lawful use.

  • Notice and consent: The customer must inform every employee or subcontractor in writing beforehand about the system, collected data, purpose and retention, and obtain consent under applicable law and collective or individual employment agreements.
  • Proportionality: Location is collected at area/floor/compound level for emergency locating, preventing entry to hazardous areas and safety attendance monitoring, not continuous tracking outside the site.
  • Access restrictions: Location and tag data is available only to designated customer roles (safety officer, site manager, control room) according to permissions.
  • Panic button: Pressing the panic button immediately generates an alert and location. These are retained as incident records and used for no other purpose.
  • Prohibited use: Customers may not use system data for dismissal, fines or disciplinary action based on covert monitoring contrary to law.

5. Municipal management module: special provisions

  • The municipality owns the database of infrastructure and resident data collected in its system; NITARTI acts as its data holder and processor.
  • Shelter data, readiness and remote opening follow Home Front Command guidance and municipal procedures. NITARTI is not a security authority and does not make operational decisions.
  • Water and electricity consumption is collected at facility/building/area level, not individual households, unless agreed otherwise in writing and subject to law.
  • Security-sensitive data is handled under dedicated information-security arrangements in the municipal agreement.

6. IoT platform for development partners (White Label)

  • In this service, the business partner is the database owner for its end users, and NITARTI acts as itsdata holder and processor only, following its instructions under a data-processing agreement.
  • NITARTI will not independently use partner end-user data, contact or market to them, except for service provision, security and legal compliance.
  • The partner is responsible for informing end users, obtaining consent and publishing its privacy policy.
  • Regional-server or on-premise storage may be arranged contractually to meet regulatory requirements.

7. Disclosure to third parties

NITARTI does not sell personal information. Disclosure occurs only in these cases:

  • Infrastructure and service providers: Hosting and cloud providers, licensed payment processors, SMS/email and analytics providers, as necessary and subject to confidentiality and security commitments.
  • Professionals and technicians: Equipment and fault data is disclosed to the assigned professional solely for diagnosis and service.
  • Customer representatives: Municipal control rooms, safety officers and main contractors, under customer-defined permissions.
  • Legal requirements: Court orders, competent-authority requests, legal proceedings or protection of Company rights.
  • Corporate changes: Merger, acquisition or business transfer, provided the acquirer accepts this policy.

8. Retention periods

Information categoryRetention period
User account detailsWhile active and for 12 months after closure
Monitoring and alert dataAccording to the configuration and service tier in the agreement
Service and transaction records7 years from the transaction date
Enquiry and dispute records3 years after the enquiry closes
Worker location and tag dataUp to 12 months, except data forming part of a safety-incident record
Safety and distress incident records7 years for investigation, insurance and regulatory purposes
Security and anti-fraud data3 years from collection
Marketing informationUntil the user withdraws consent

Information required for accounting, tax or legal-rights protection will not be deleted before the applicable statutory period ends.

9. Information security

NITARTI implements technical and organizational protections under the Protection of Privacy (Data Security) Regulations, 2017, including encrypted traffic, role-based permissions, tenant separation, access audit logs, backups, security monitoring and vendor oversight.

For a serious security incident, the Company will act under the law, including notifying the Privacy Protection Authority and affected users where required. No system is completely immune, and absolute protection against intrusion cannot be guaranteed.

10. Data ownership and export rights

  • Monitoring data originating from equipment installed at the customer belongs to the customer. NITARTI holds and processes it to provide the service.
  • Customers may request historical monitoring data in a readable format (CSV/JSON or similar) at any time during subscription and for 14 days after it ends. Requests are answered within 14 business days.
  • NITARTI may process anonymous aggregate data that cannot identify anyone for service improvement and research. Customers may ask the privacy officer to exclude their data from aggregate processing without affecting service.

11. User rights

Under the Protection of Privacy Law, you have the rights to: access the information held about you, correct incorrect or outdated information, anddelete , subject to section 8 retention periods and legal obligations.

Submit requests to the privacy officer. Responses are provided within 30 days, or up to 60 days in complex cases with advance notice. Users who believe their rights were infringed may also contact the Privacy Protection Authority.

12. Mailing and direct marketing

Marketing messages require explicit, separate consent under section 30A of the Communications Law (Telecommunications and Broadcasting). Each message includes an easy unsubscribe option; customer service can also remove you.

Operational alerts are not marketing messages. Anomaly, fault, distress and safety alerts are an essential service component. They are sent without marketing consent and cannot be disabled without cancelling the service itself.

13. Cookies and storage technologies

Full details of file types, purposes and management appear in theCookie policy.

14. Transferring data outside Israel

Some cloud and infrastructure services may be hosted or processed outside Israel. Transfers follow the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001, with contracts requiring adequate protection from recipients. Public-sector customers and regulated partners may arrange Israel-only hosting.

15. Minors

The service is for business and institutional use; registration is restricted to ages 18 and over. The Company does not knowingly collect minors’ information. Accidentally collected information will be deleted upon discovery.

16. Policy changes and contact

The Company may update this policy periodically. Material changes will be published on the site and registered users notified 14 days in advance. Continued use after the effective date constitutes acceptance of the updated version.

NITARTI · Customer service

Email: info@nitarti.com · Phone: 052-691-0337

Address: 4 Moshe Dayan St, Haifa · Website: nitarti.co.il

Business hours: Sunday–Thursday, 09:00–17:00