Privacy Policy
Last Updated: March 19, 2026
asaphos.com ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the AsaphOS platform and related services (the "Services").
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Services immediately.
1. Data Controller vs. Data Processor
Important: Who Controls Your Community Member Data?
AsaphOS operates as a multi-tenant platform where each Community is managed by a Community Administrator. Under data protection laws:
Community Administrator (Data Controller)
If you are a Community Administrator, you are the data controller for the personal data of your Community Members. This means you are legally responsible for:
- Obtaining valid consent from members before entering their personal data;
- Informing members about what data you collect and how it is used;
- Responding to member requests for data access, correction, or deletion;
- Complying with GDPR, CCPA, Israeli Privacy Protection Law, and all applicable data protection regulations;
- Maintaining your own privacy notice for your community.
AsaphOS (Data Processor)
AsaphOS acts as the data processor, meaning:
- We process Community Member data only according to the Community Administrator's instructions;
- We implement appropriate technical and organizational security measures;
- We provide tools that enable Community Administrators to fulfill their data protection obligations;
- We do not independently verify that consent has been obtained from Community Members.
2. Information We Collect
2.1 Information You Provide
We collect personal information that you voluntarily provide to us when you:
- Create an Account: name, email address, password, phone number, preferred language;
- Set up a Community: community name, description, branding settings, custom domain;
- Manage Members: member names, contact information, family relationships, dates of birth, notes (as entered by Community Administrators);
- Use Platform Features: event details, prayer requests, messages, announcements, lesson content, form responses, donation records;
- Process Payments: billing information, payment method details (processed by our third-party payment providers — we do not store full payment card numbers);
- Contact Support: any information included in support communications.
2.2 Information Collected Automatically
When you access or use the Services, we may automatically collect:
- Device Information: device type, operating system, browser type and version, screen resolution;
- Usage Data: pages visited, features used, actions taken, date/time stamps;
- Network Information: IP address, approximate geographic location (country/region level), internet service provider;
- Cookies and Similar Technologies: see Section 7 for details.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the Services: operating the Platform, processing transactions, managing accounts;
- Improve the Services: analyzing usage patterns, identifying bugs, developing new features;
- Communicate with you: sending service-related notifications, billing updates, security alerts, and support responses;
- Ensure security: detecting and preventing fraud, unauthorized access, and other security threats;
- Comply with legal obligations: fulfilling legal requirements, responding to lawful requests from authorities;
- Enforce our Terms: protecting our rights and the rights of other users.
We do not sell your personal information to third parties. We do not use your data for targeted advertising.
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal data based on the following legal grounds:
- Contract Performance: processing necessary to provide the Services you requested (Article 6(1)(b));
- Legitimate Interest: processing necessary for our legitimate interests, such as improving the Services, ensuring security, and preventing fraud (Article 6(1)(f));
- Legal Obligation: processing necessary to comply with applicable laws (Article 6(1)(c));
- Consent: where you have given explicit consent for specific processing activities, such as analytics cookies (Article 6(1)(a)). You may withdraw consent at any time.
5. Information Sharing & Disclosure
We do not sell, trade, or rent your personal information. We may share information in the following limited circumstances:
- Service Providers: trusted third-party companies that assist us in operating the Platform (hosting, payment processing, email delivery, error monitoring), all bound by strict data processing agreements;
- Community Administrators: Community Member data is accessible to the Community Administrator(s) of the community you belong to;
- Legal Requirements: when required by law, regulation, legal process, or enforceable government request;
- Protection of Rights: when necessary to protect the safety, rights, or property of asaphos.com, our users, or the public;
- Business Transfers: in connection with a merger, acquisition, or sale of all or part of our business, with notice to affected users.
6. Third-Party Service Providers
Your data may be processed by the following categories of service providers:
- Hosting & Infrastructure: cloud hosting services for data storage and application delivery;
- Payment Processing: PayPal, Tranzila, and other payment gateways for subscription billing and donations (these providers have their own privacy policies);
- Email Delivery: transactional email services for notifications and bulk messaging;
- Error Monitoring: anonymized error tracking to maintain platform stability;
- Analytics: aggregated usage analytics to improve the Services (when consent is provided).
All service providers operate under data processing agreements that require them to protect your data and use it only for the purposes we specify.
7. Cookies & Tracking Technologies
We use cookies and similar technologies on our Platform:
Essential Cookies (Always Active)
Required for the Platform to function. These include session cookies, CSRF protection tokens, and language preferences. They cannot be disabled.
Analytics Cookies (Optional)
Help us understand how visitors interact with our Platform. These cookies are only activated with your consent and can be disabled at any time through the cookie consent banner.
We do not use advertising cookies, social media tracking pixels, or any third-party marketing trackers.
You can manage your cookie preferences at any time by clicking the cookie settings link in the footer of any page. You can also configure your browser to block or delete cookies, but this may affect Platform functionality.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- TLS/SSL encryption for all data in transit;
- Encryption of sensitive data at rest;
- Multi-tenant data isolation ensuring each Community can only access its own data;
- Regular security updates and vulnerability assessments;
- Access controls and authentication mechanisms;
- Regular automated database backups.
While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Data Retention
- Active Accounts: We retain your personal information for as long as your Account is active and the Services are being provided.
- After Cancellation: Upon subscription cancellation, your data is retained for 90 days (for dispute resolution and account recovery). After 90 days, data is permanently deleted unless a legal hold applies.
- Deletion Requests: You may request immediate deletion of your data at any time. We will process deletion requests within 30 days, subject to legal obligations.
- Backups: Encrypted backups may persist for up to 90 days after deletion from active systems, after which they are automatically purged.
- Legal Requirements: We may retain certain data longer if required by law (e.g., tax records, legal disputes).
10. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
10.1 Rights Under GDPR (EU/EEA/UK Residents)
- Right of Access: request a copy of the personal data we hold about you;
- Right to Rectification: request correction of inaccurate or incomplete data;
- Right to Erasure: request deletion of your personal data ("right to be forgotten");
- Right to Restrict Processing: request that we limit how we use your data;
- Right to Data Portability: receive your data in a structured, commonly used, machine-readable format;
- Right to Object: object to processing based on legitimate interests or direct marketing;
- Right to Withdraw Consent: withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at the address provided in the Contact section. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10.2 Rights Under CCPA (California Residents)
- Right to Know: request information about the categories and specific pieces of personal information we collect;
- Right to Delete: request deletion of personal information we have collected;
- Right to Opt-Out: opt out of the "sale" of personal information (note: we do not sell personal information);
- Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.
AsaphOS does not sell or share your personal information. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request under CCPA.
10.3 Rights Under Israeli Privacy Protection Law
If you are a resident of Israel, you have rights under the Protection of Privacy Law, 5741-1981, including:
- The right to access your personal data held in our databases;
- The right to request correction or deletion of inaccurate data;
- The right to object to the use of your data for direct marketing.
To exercise any of your privacy rights, please email us at [email protected] with "Privacy Request" in the subject line.
11. International Data Transfers
AsaphOS is operated from Israel. Your personal information may be stored and processed in Israel or other countries where our service providers operate.
Israel has been recognized by the European Commission as providing an adequate level of data protection. For transfers to countries without an adequacy decision, we use Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
By using the Services, you acknowledge that your data may be transferred to and processed in countries outside your own. We ensure that appropriate safeguards are in place for all international transfers.
12. Children's Privacy
Account Registration: AsaphOS accounts are available only to individuals aged 18 or older. We do not knowingly collect personal information directly from children.
Community Member Data about Minors: Community Administrators may enter data about minor community members (e.g., for children's check-in, family records). In such cases, the Community Administrator is responsible for:
- Obtaining verifiable parental or guardian consent (as required by COPPA, GDPR, or local law);
- Ensuring data about minors is handled with appropriate care;
- Honoring parental requests to access or delete children's data.
If we become aware that personal information of a child has been collected without proper consent, we will take steps to delete such information promptly.
13. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify affected Community Administrators within 72 hours of discovery (as required by GDPR);
- Provide details about the nature of the breach, data affected, and measures taken;
- Assist Community Administrators in fulfilling their own notification obligations to members and authorities;
- Document the breach and our response for compliance records.
Community Administrators remain responsible for notifying their own Community Members and relevant supervisory authorities as required by applicable law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page.
For material changes, we will provide at least 30 days' notice via email or through the Platform. Your continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.
15. Contact Information
If you have any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
asaphos.com (אספאואס.קום)
Data Protection Contact
We aim to respond to all privacy-related inquiries within 30 days.