← VibeTech

תנאי שימוש

עודכן לאחרונה: 7 בספטמבר 2026

תנאי שימוש אלה ("התנאים" או "ההסכם") מסדירים את הגישה והשימוש בפלטפורמת VibeTech, באתר, בכלים ליצירת צ'אטבוטים וסוכני AI, בשירותי הטמעה וסיוע נלווים, ב-API, באינטגרציות ובשירותים נוספים המוצעים על ידי וייבטק מערכות בינה בע"מ (VIBETECH AI SYSTEMS LTD), ח.פ. 517329801, חברה ישראלית ("החברה", "אנחנו" או "אנו") (יחד: "השירות"). תנאים אלה כוללים את תנאי עיבוד המידע שבחלק ב', המהווים חלק בלתי נפרד ומחייב מההסכם ככל שהם רלוונטיים.

יצירת חשבון, הרשמה לשימוש חינמי או בתשלום, רכישת חבילה, סימון תיבת אישור או שימוש אחר בשירות מהווים הסכמה לתנאים אלה. אם התנאים מאושרים בשם חברה, ארגון או ישות משפטית אחרת ("הלקוח"), המאשר מצהיר כי הוא מוסמך לחייב אותה בתנאים אלה.

חלק א' – תנאי שימוש

1. השירות

השירות מאפשר ללקוחות ליצור, להגדיר, לבדוק, להפעיל ולהטמיע צ'אטבוטים וסוכנים מבוססי AI באמצעות אתרי אינטרנט, כתובות URL, מסמכים, קבצים, הנחיות ומידע אחר שסופק או נבחר על ידי הלקוח. בהתאם לחבילה, השירות עשוי לכלול יצירה והגדרה, חיבור מקורות מידע, בדיקה, קבלת קישור מתארח, הטמעה באתר, שימוש ב-API ואינטגרציות וקבלת שירותי התחלה, הגדרה, הטמעה, אינטגרציה, תמיכה או סיוע אחר. ניתן להשתמש בשירות באופן עצמאי או בסיוע החברה. התכונות, המכסות, הפונקציונליות והסיוע עשויים להשתנות בין החבילות. החברה רשאית לעדכן, לשנות ולשפר את השירות מעת לעת.

השירות מיועד לשימוש עסקי ומקצועי בלבד ואינו מוצע לצרכנים פרטיים לשימוש אישי, ביתי או משפחתי. ההרשמה לשירות והשימוש בו מיועדים לעסקים, ארגונים ובעלי עסק הפועלים במסגרת עיסוקם.

2. חשבונות ומשתמשים מורשים

הלקוח אחראי למסירת מידע נכון ולשמירת סודיות ואבטחת פרטי ההתחברות. הלקוח רשאי לאפשר לעובדים, קבלנים ואנשים מורשים אחרים ("משתמשים") להשתמש בשירות, והוא אחראי לניהול הרשאותיהם ולשימוש המתבצע באמצעות חשבונו. על הלקוח להודיע לחברה בהקדם על גישה בלתי מורשית הידועה לו. ככל שהחבילה מאפשרת זאת, חברות קשורות של הלקוח רשאיות להשתמש בשירות והלקוח יישאר אחראי לשימוש ולתשלומים הקשורים אליו. הלקוח לא יהיה אחראי במידה שבה גישה בלתי מורשית נובעת במישרין מחולשה בשירות שהלקוח לא גרם לה ולא נמנע מלנקוט לגביה אמצעי צמצום סבירים לאחר שקיבל על כך הודעה סבירה מהחברה.

3. שימוש חינמי ותקופות ניסיון

החברה עשויה להציע שימוש חינמי מוגבל, לרבות הודעות, טוקנים, קרדיטים או משאבים אחרים. היקף, תקופת ומגבלות השימוש החינמי יוצגו בשירות ועשויים להשתנות. לאחר מיצוי המכסה החינמית ייתכן שתידרש רכישת חבילה בתשלום. אלא אם צוין אחרת, שימוש חינמי אינו מחייב רכישה. החברה רשאית לשנות או להפסיק מסלולים חינמיים ומבצעים, אך לא תחייב בדיעבד עבור שימוש שהוצע במפורש ללא תשלום.

4. חבילות והזמנות

החבילות, המחירים, תקופות החיוב, המכסות, התכונות, הסיוע והמגבלות יוצגו בעת הרכישה או הבחירה ("הזמנה"). אישור הזמנה או השלמת התשלום מהווים הסכמה לתנאים המסחריים שהוצגו. כל הזמנה מהווה חלק מההסכם. המחירים והמכסות אינם חייבים להופיע בתנאים אלה וניתן לעדכנם מעת לעת.

5. מנויים וחידוש אוטומטי

כאשר חבילה מוצעת כמנוי מתחדש, היא תתחדש אוטומטית לתקופות חיוב נוספות אלא אם בוטלה לפני מועד החידוש, אלא אם צוין אחרת בעת הרכישה. המחיר ותקופת החיוב יוצגו לפני הרכישה. ברכישת מנוי מתחדש הלקוח מאשר לחברה ו/או לספק התשלום לחייב את אמצעי התשלום בדמי המנוי.

6. תשלום ומסים

התשלום יבוצע במטבע המוצג בהזמנה. הלקוח אחראי לשמור אמצעי תשלום תקף. עסקאות המבוצעות באמצעות ספק תשלום עשויות להיות כפופות גם לתנאי אותו ספק. במקרה של כשל או איחור בתשלום, החברה רשאית לנסות לבצע את החיוב מחדש ולהשהות פונקציות בתשלום עד לקבלת התשלום. תשלומים ששולמו אינם ניתנים להחזר אלא אם נקבע אחרת או שהדין מחייב זאת. הלקוח אחראי למסים החלים על רכישתו, למעט מסים המוטלים על הכנסת החברה.

החברה רשאית לשנות חיובים חוזרים או להוסיף חיובים חדשים בהודעה סבירה מראש. אלא אם הדין מחייב אחרת או שהוסכם אחרת במפורש, שינוי בחיוב חוזר יחול לא לפני החידוש הבא של הלקוח, והלקוח רשאי להימנע מהחיוב המעודכן באמצעות ביטול לפני אותו חידוש. לקוח הסבור שחויב בטעות יודיע לחברה בתוך 60 ימים ממועד החיוב או הודעת החיוב הרלוונטיים, יפרט את הסכום שבמחלוקת ואת הבסיס למחלוקת, וימשיך לשלם במועד סכומים שאינם במחלוקת. החברה תבדוק את המחלוקת בתום לב ותתקן טעות חיוב שאומתה. פסקה זו אינה מגבילה זכות או סעד שלא ניתן לוותר עליהם על פי דין.

7. מגבלות שימוש וחריגות

חבילות עשויות לכלול מגבלות על הודעות, טוקנים, שיחות, סוכנים, מקורות מידע, אחסון, אינטגרציות, API או משאבים אחרים. כאשר ניתן לרכוש שימוש נוסף או קיימים חיובי חריגה, המחיר או מנגנון החיוב יוצגו לפני יצירת החיוב. החברה רשאית להגביל או להשהות פונקציות כאשר מגיעים למכסה.

8. שירותי סיוע

חבילות מסוימות עשויות לכלול או לאפשר רכישת שירותי התחלה, הגדרה, הטמעה, אינטגרציה, תמיכה טכנית או סיוע אחר ("שירותי סיוע"). היקף השירות ייקבע לפי החבילה, ההזמנה או תיאור השירות. אלא אם הוסכם אחרת, הסיוע אינו מעביר לחברה את האחריות לתוכן הלקוח, לכללים העסקיים, למקורות המידע, להנחיות, להחלטות ההגדרה או לשימוש בצ'אטבוט או בסוכן. הלקוח אחראי לספק את המידע, החומרים, הגישה והאישורים הדרושים. עיכוב מצד הלקוח עשוי לגרום לעיכוב מקביל בהטמעה. עבודה החורגת מההיקף שנרכש עשויה להיות כרוכה בתשלום נוסף, בכפוף לאישור הלקוח.

9. מגבלות שימוש בשירות

אין להשתמש בשירות:

  • למטרה בלתי חוקית, הונאה או הטעיה;
  • להפרת זכויות צד שלישי;
  • להעתקה בלתי מורשית של רכיבים קנייניים;
  • להנדסה לאחור, למעט אם הדין אוסר הגבלה זו;
  • למכירה או הפצה בלתי מורשית של השירות;
  • לעקיפת מגבלות טכניות, אבטחה או שימוש;
  • להשגת גישה בלתי מורשית;
  • לפגיעה באבטחה או בתפקוד השירות;
  • להפצת קוד זדוני;
  • לבדיקות חדירה או אבטחה ללא אישור;
  • או להעתקה בלתי מורשית של רכיבים קנייניים בעיקר לצורך יצירת מוצר מתחרה מהותית.

10. API ואינטגרציות

החברה רשאית לקבוע מגבלות טכניות ומגבלות שימוש סבירות. הלקוח יפעל בהתאם לתיעוד ולמגבלות הרלוונטיות. החברה רשאית להגביל גישה כאשר הדבר נדרש באופן סביר לצורכי אבטחה, זמינות או עמידה במכסות.

11. תוכן הלקוח ומקורות מידע

"תוכן הלקוח" כולל אתרים, URL, מסמכים, קבצים, טקסט, הנחיות, נתונים, תמונות וחומרים אחרים שהלקוח מספק לשירות. הבעלות בתוכן נשארת בידי הלקוח. הלקוח מעניק לחברה זכות מוגבלת ולא בלעדית לאחסן, להעתיק, להעביר, לגשת ולעבד את התוכן ככל שנדרש באופן סביר לצורך אספקת השירות, תחזוקתו, אבטחתו והתמיכה בו. הלקוח מצהיר שיש בידיו את הזכויות, ההרשאות והבסיס החוקי הנדרשים. ניתן להשתמש רק במקורות מידע שהלקוח מורשה להשתמש בהם למטרה הרלוונטית. עצם העובדה שמידע נגיש לציבור אינה בהכרח מעניקה הרשאה להעתיק, לעבד או להשתמש בו מסחרית.

12. תוצרי AI

תוצרי AI עלולים להיות שגויים, חלקיים, לא מעודכנים או בלתי מתאימים למטרה מסוימת. הלקוח אחראי לבדוק את הצ'אטבוט או הסוכן לפני הפרסום, לקבוע שההגדרות והתוצרים מתאימים לשימוש המיועד ולפקח על פעולתו. החברה אינה מתחייבת לדיוק, לשלמות או לאמינות תוצרי AI. אין להסתמך על השירות כמקור יחיד לייעוץ משפטי, רפואי, פיננסי או מקצועי אחר או לקבלת החלטות שבהן טעות עלולה לגרום לנזק מהותי.

13. משתמשי קצה ואחריות הלקוח

הלקוח אחראי למערכת היחסים שלו עם האנשים המשתמשים בצ'אטבוט או בסוכן ("משתמשי הקצה"). לפני פרסום הצ'אט, הלקוח אחראי לוודא שהפעלתו עומדת בדינים החלים, לרבות דיני פרטיות, הגנת מידע, הגנת הצרכן ושקיפות בנוגע ל-AI. הלקוח אחראי:

  • למסירת הודעות פרטיות, מדיניות, תנאים וגילויים הנדרשים;
  • לקבלת הסכמה או קיום בסיס חוקי אחר לעיבוד מידע;
  • ליידוע משתמשי הקצה שמדובר במערכת אוטומטית או מבוססת AI כאשר הדבר נדרש;
  • להנגשת מדיניות הפרטיות שלו;
  • לקביעה אם נדרשים תנאים או גילויים נוספים;
  • לכך שלא ייאסף במכוון מידע אישי או רגיש שאינו נדרש או שאיסופו אינו חוקי;
  • להתאמת הצ'אט ותוצריו למטרה;
  • ולטיפול בזכויות ובבקשות של משתמשי הקצה.

החברה רשאית לספק קישורי פרטיות, גילויי AI, הודעות, תבניות או נוסחים מוצעים. נוסחים אלה ניתנים לנוחות ולמידע בלבד, אינם מהווים ייעוץ משפטי ואינם התחייבות לכך שהשימוש של הלקוח עומד בדין. האחריות לבדיקה, התאמה ותחזוקה של ההודעות, המדיניות וההסכמות נשארת אצל הלקוח. תנאי החברה ומדיניות הפרטיות שלה אינם מחליפים את תנאי הלקוח או את מדיניות הפרטיות שלו כלפי משתמשי הקצה.

14. אישור לפני פרסום

החברה רשאית לדרוש מהלקוח, לפני פרסום או הטמעת צ'אטבוט או סוכן, לאשר שהוא אחראי להודעות הפרטיות, גילויי ה-AI, הבסיס החוקי, ההסכמות והציות הנדרש ביחס למשתמשי הקצה. אישור זה נוסף לחובות הלקוח ואינו מחליף אותן.

15. שירותי צד שלישי

השירות עשוי להסתמך על ספקי AI, ענן, אחסון, בסיסי נתונים, אנליטיקה, תשלום וספקי טכנולוגיה אחרים. אינטגרציות אופציונליות עשויות להיות כפופות לתנאי הספק הרלוונטי. הלקוח מצהיר כי הוא מורשה למסור הרשאות או פרטי גישה הנדרשים לאינטגרציה. שירותי צד שלישי אינם בשליטת החברה, וייתכן שהלקוח יידרש להתקשר בהסכם נפרד עם ספקיהם. במידה המרבית המותרת על פי דין, השימוש בשירות צד שלישי אופציונלי שהלקוח בוחר להשתמש בו הוא באחריות הלקוח; החברה אינה נותנת מצג או אחריות ביחס לאותו שירות, ומחלוקת הנוגעת לתנאים הנפרדים של הספק תופנה לספק. החברה אינה אחראית לכשל, מעשה או מחדל שנגרמו אך ורק משירות צד שלישי שאינו בשליטתה הסבירה. אין בסעיף זה כדי לשלול אחריות להפרת ההסכם על ידי החברה עצמה, לרשלנות רבתי שלה או למעשה מכוון שלה.

16. סודיות

כל צד ישמור בסוד מידע עסקי, מסחרי, טכני, אבטחתי או פיננסי שאינו ציבורי שקיבל מהצד השני. תוכן הלקוח ומידע לא-ציבורי שלו הם מידע סודי של הלקוח. מידע לא-ציבורי על הטכנולוגיה, הארכיטקטורה, האבטחה, הפונקציונליות והעסק של החברה הוא מידע סודי של החברה. כל צד ישתמש במידע הסודי רק לצורך ההתקשרות, יגן עליו באופן סביר ויגביל גישה לגורמים הזקוקים למידע וכפופים לחובת סודיות.

מידע סודי אינו כולל מידע שהצד המקבל יכול להוכיח כי: (א) הפך לציבורי ללא הפרת חובה; (ב) היה ידוע לו כדין וללא חובת סודיות לפני שנמסר; (ג) התקבל כדין מצד שלישי ללא חובת סודיות; או (ד) פותח באופן עצמאי ללא שימוש במידע הסודי של הצד המוסר. צד מקבל רשאי למסור מידע סודי במידה הנדרשת על פי דין, תקנה או צו תקף של בית משפט או רשות ממשלתית. ככל שהדין מתיר, הוא ימסור לצד המוסר הודעה סבירה מראש וסיוע סביר, על חשבון הצד המוסר, אם הצד המוסר מבקש להתנגד למסירה או לצמצם אותה.

17. פרטיות

עיבוד מידע אישי על ידי החברה למטרותיה שלה מפורט במדיניות הפרטיות. כאשר החברה מעבדת מידע אישי בשם הלקוח, יחול חלק ב' (תנאי עיבוד המידע) להלן.

18. נתוני שירות

החברה רשאית לאסוף מידע טכני, תפעולי, אבטחתי וביצועי לגבי השימוש בשירות. ניתן להשתמש בו לצורך הפעלה, אבטחה, איתור תקלות, ניתוח ושיפור השירות. לניתוחים רחבים, השוואת ביצועים (benchmarking) או שיפור מוצר, החברה תשתמש במידע מצרפי או שעבר הסרת זיהוי באופן שאינו מזהה באופן סביר לקוח או משתמש קצה. אין בסעיף זה כדי להעביר לחברה בעלות בתוכן הלקוח.

19. קניין רוחני

השירות, התוכנה, הטכנולוגיה, הממשקים, התיעוד, העיצובים, סימני המסחר והחומרים הקנייניים הם בבעלות החברה או ניתנו לה ברישיון. לא מועברת ללקוח בעלות בטכנולוגיה. תוכן הלקוח נשאר בבעלותו.

20. משוב

החברה רשאית להשתמש במשוב ובהצעות לצורך פיתוח ושיפור השירות ללא תמורה, ובלבד שלא תזהה את הלקוח כמקור ללא רשות ולא תרכוש בעלות במידע הסודי שלו.

21. שימוש בשם ובלוגו

החברה לא תשתמש בפומבי בשם, בלוגו או בסימני המסחר של הלקוח כדי להציגו כלקוח ללא הסכמתו מראש.

22. זמינות ושינויים

החברה רשאית לעדכן ולשפר את השירות ואינה מתחייבת להפעלה רציפה וללא תקלות. ייתכנו הפסקות עקב תחזוקה, תקלות, אירועי אבטחה, כשלים של ספקים או נסיבות שאינן בשליטת החברה הסבירה. במהלך תקופת החיוב הנוכחית של לקוח בתשלום, החברה לא תפחית באופן מהותי את פונקציות הליבה הכלולות בהזמנה הרלוונטית, אלא אם הדבר נדרש באופן סביר עקב דין, אבטחה או שינוי של צד שלישי שאינו בשליטתה הסבירה של החברה. אם החברה תפחית פונקציות ליבה אלה באופן מהותי מסיבה אחרת ולא תשיב פונקציונליות מקבילה בעיקרה בתוך זמן סביר לאחר הודעה, הלקוח רשאי לסיים את השירות בתשלום שהושפע ולקבל החזר יחסי של תשלומים מראש עבור יתרת תקופת החיוב שלא נוצלה.

23. היעדר אחריות

במידה המרבית המותרת על פי דין, השירות מסופק "כמות שהוא" ו"כפי שהוא זמין". החברה מסירה כל אחריות מפורשת, משתמעת או מכוח דין שלא נקבעה במפורש בהסכם, לרבות אחריות משתמעת לסחירות, להתאמה למטרה מסוימת ולאי-הפרת זכויות. החברה אינה מתחייבת שהשירות או תוצרי ה-AI יהיו תמיד מדויקים, רציפים, זמינים במועד, נטולי שגיאות או מאובטחים לחלוטין. החרגות אלה יחולו רק במידה המותרת על פי דין.

24. הגבלת אחריות

במידה המרבית המותרת על פי דין, אף צד לא יהיה אחראי לנזקים עקיפים, מיוחדים, מקריים, תוצאתיים או עונשיים, לרבות אובדן רווחים, הכנסות, מוניטין, הזדמנויות עסקיות או מידע. האחריות המצטברת של החברה לא תעלה על הסכומים ששולמו או שיש לשלמם לחברה עבור השירות במהלך 12 החודשים שקדמו לאירוע שהוביל לתביעה. אין בכך כדי להגביל אחריות שאסור להגביל על פי דין.

25. שיפוי

במידה המותרת על פי דין, הלקוח ישפה ויגן על החברה, החברות הקשורות אליה ונציגיה בגין תביעות צד שלישי, נזקים, חבויות, קנסות, עלויות ושכר טרחה משפטי סביר הנובעים מ:

  • שימוש בלתי חוקי או בלתי מורשה של הלקוח בשירות;
  • תוכן או מקורות מידע המפרים זכויות צד שלישי;
  • איסוף או עיבוד מידע אישי של הלקוח בניגוד לדין;
  • אי-מסירת הודעת פרטיות, הסכמה, גילוי AI או הודעה אחרת שנדרשה על פי דין;
  • הוראות, הגדרות או כללים עסקיים של הלקוח;
  • תביעות הנוגעות למוצרים, לשירותים או לפעילות העסקית של הלקוח;
  • או הפרה מהותית של ההסכם.

השיפוי יחול ככל שהעניין נובע ממעשה, מחדל, הוראה או חובה של הלקוח ולא ככל שנגרם מהפרת ההסכם או הדין על ידי החברה, מרשלנות רבתי שלה או ממעשה מכוון שלה.

26. השעיה

החברה רשאית להשעות את השירות בשל סיכון אבטחה מהותי, פעילות בלתי חוקית או הונאה, הפרה מהותית, אי-תשלום, סיכון מהותי לשירות או עקיפת מגבלות שימוש או אבטחה. ככל שניתן באופן סביר, החברה תודיע ללקוח ותיתן הזדמנות סבירה לטיפול בבעיה.

27. ביטול וסיום

ניתן לבטל מנוי מתחדש באמצעות החשבון או בפנייה אל [email protected]. אלא אם צוין אחרת, הביטול מונע את החידוש הבא והשירות בתשלום נמשך עד סוף התקופה שכבר שולמה. כל צד רשאי לסיים את ההסכם בהודעה בכתב אם הצד השני הפר אותו הפרה מהותית ולא תיקן את ההפרה בתוך 30 ימים מקבלת הודעה בכתב המתארת אותה, ככל שההפרה ניתנת לתיקון. צד רשאי לסיים את ההסכם לאלתר אם לא ניתן באופן סביר לתקן את ההפרה המהותית או אם הדין מתיר סיום מיידי.

אם הלקוח מסיים את ההסכם עקב הפרה מהותית של החברה שלא תוקנה, החברה תחזיר תשלומים מראש עבור יתרת תקופת החיוב הנוכחית שלא נוצלה. אם החברה מסיימת את ההסכם עקב הפרה מהותית של הלקוח שלא תוקנה, סכומים שנצברו עד מועד הסיום וסכומים מחויבים שאינם ניתנים לביטול ושצוינו במפורש בהזמנה יישארו לתשלום. הסיום אינו פוגע בזכויות או בחבויות שנצברו לפני כניסתו לתוקף. כאשר מנוי בתשלום מסתיים בעקבות ביטול, החברה רשאית להעביר את החשבון למסלול חינמי שהיא מציעה באותה עת. כאשר ההסכם מסתיים, תסתיים זכות הלקוח לגשת לשירות ולהשתמש בו. החזרה, ייצוא ומחיקה של תוכן הלקוח ומידע אישי כפופים לתנאי עיבוד המידע ולמדיניות הפרטיות.

28. המשך תחולה

סעיפים שמטבעם צריכים להמשיך לאחר סיום ההתקשרות ימשיכו לחול, לרבות תשלום, קניין רוחני, סודיות, הגנת מידע, הגבלת אחריות ושיפוי.

29. כוח עליון

אף צד לא יהיה אחראי לעיכוב או אי-ביצוע, למעט חובות תשלום, הנובעים מנסיבות שאינן בשליטתו הסבירה, לרבות אסונות טבע, מלחמה, טרור, הפרות סדר, פעולות ממשלתיות, כשלי אינטרנט או תקשורת רחבים, כשל משמעותי בתשתיות ענן ואירועים דומים.

30. שינויים בתנאים

החברה רשאית לעדכן תנאים אלה. על שינוי מהותי המשפיע על לקוחות קיימים בתשלום תימסר הודעה סבירה. ככל שהדין מחייב זאת, תתקבל הסכמה נוספת.

31. שירותים סטנדרטיים ו-Enterprise

התנאים חלים על השירותים הסטנדרטיים המוצעים באתר, לרבות שירות עצמי ושירות הכולל סיוע. שירותי Enterprise, שירותים מותאמים אישית או שירותים מנוהלים עשויים להיות כפופים להסכם נפרד. הסכם פרטני שנחתם יגבר במקרה של סתירה.

32. יחסי הצדדים

הצדדים הם קבלנים עצמאיים. ההסכם אינו יוצר שותפות, מיזם משותף, שליחות, זכיינות, יחסי נאמנות או יחסי עבודה.

33. היעדר זכויות לצד שלישי

אלא אם נאמר אחרת במפורש, התנאים נועדו לחברה וללקוח בלבד. למשתמש קצה או לצד שלישי אחר אין זכות לאכוף אותם.

34. הודעות

החברה רשאית למסור הודעות באמצעות השירות או לדוא"ל המשויך לחשבון. הודעות משפטיות לחברה יישלחו אל [email protected]. הלקוח אחראי לשמור פרטי קשר עדכניים.

35. המחאה

הלקוח אינו רשאי להמחות את ההסכם ללא הסכמה מראש ובכתב של החברה, אלא אם הדין קובע אחרת. החברה רשאית להמחותו במסגרת מיזוג, רכישה, ארגון מחדש או מכירת עיקר הפעילות או הנכסים הרלוונטיים.

36. הפרדה וויתור

אם הוראה אינה תקפה או אינה ניתנת לאכיפה, יתר ההוראות יישארו בתוקף. אי-אכיפה אינה מהווה ויתור.

37. מלוא ההסכם

התנאים, ההזמנות והמסמכים ששולבו בהם במפורש מהווים את מלוא ההסכם בין הצדדים בנוגע לשירות.

38. דין וסמכות שיפוט

על ההסכם יחולו דיני מדינת ישראל. אלא אם דין קוגנטי מחייב אחרת, לבתי המשפט המוסמכים בתל אביב-יפו תהיה סמכות שיפוט בלעדית. זכויות שלא ניתן לוותר עליהן על פי דין לא ייפגעו.

39. שפה

התנאים עשויים להיות מוצגים במספר שפות. אלא אם הדין אוסר זאת, במקרה של סתירה בין הגרסה האנגלית לבין תרגום, הגרסה האנגלית תגבר.

40. יצירת קשר

וייבטק מערכות בינה בע"מ (VIBETECH AI SYSTEMS LTD)
ח.פ. 517329801
יצחק נבון 4 בית 15, קריית אונו 5557222, ישראל
דוא"ל: [email protected]

חלק ב' – תנאי עיבוד מידע (DPA)

1. תחולה

תנאים אלה מהווים את הסכם עיבוד המידע בין הלקוח לחברה בכל מקרה שבו החברה מעבדת מידע אישי בשם הלקוח. הם חלק בלתי נפרד ומחייב מתנאי השימוש. אין צורך ב-DPA נפרד אלא אם הדין מחייב תנאים נוספים או שהצדדים הסכימו אחרת.

2. הגדרות ותפקידי הצדדים

למונחים "מידע אישי", Controller, Processor, Data Subject, Personal Data Breach ומונחים מקבילים תהיה המשמעות לפי דיני הגנת המידע החלים. בהתאם לנסיבות, הלקוח עשוי לפעול כ-Controller או Processor. כאשר הלקוח הוא Controller, החברה תפעל בדרך כלל כ-Processor. כאשר הלקוח הוא Processor עבור Controller אחר, החברה תפעל כ-Subprocessor ככל שרלוונטי. הלקוח אחראי לכך שיש בידיו סמכות ובסיס חוקי להורות לחברה לעבד מידע.

3. הוראות עיבוד

החברה תעבד מידע אישי של הלקוח רק ככל שנדרש לצורך אספקת השירות, תחזוקתו, אבטחתו והתמיכה בו; בהתאם להגדרות והשימוש של הלקוח; בהתאם להסכם ולהזמנות; בהתאם להוראות מתועדות של הלקוח; או ככל שהדין מחייב. אם החברה סבורה באופן סביר שהוראה של הלקוח מפרה את דיני הגנת המידע, היא תיידע אותו ללא דיחוי ותהיה רשאית להשהות את העיבוד הרלוונטי עד לבירור.

4. פרטי העיבוד

מטרת העיבוד היא אספקת השירות, הפעלתו, אבטחתו והתמיכה בו. העיבוד יימשך בדרך כלל במשך תקופת השימוש, בכפוף למדיניות שמירה, גיבויים והוראות הדין. המידע עשוי לכלול שיחות, מידע שמשתמשי הקצה מוסרים, פרטי קשר, מידע טכני ומידע אישי הכלול בתוכן הלקוח. נושאי המידע עשויים לכלול לקוחות, לקוחות פוטנציאליים, מבקרים באתר, עובדים, נציגים ומשתמשי קצה אחרים. פעולות העיבוד עשויות לכלול איסוף, גישה, ארגון, אחסון, שליפה, העברה לספקים מורשים, שימוש לצורך יצירת תשובות AI, מחיקה ופעולות נוספות הנדרשות לצורך השירות.

5. סודיות

אנשים המורשים על ידי החברה לעבד מידע אישי יהיו כפופים להתחייבויות סודיות מתאימות.

6. אבטחת מידע

החברה תיישם ותתחזק אמצעים טכניים וארגוניים סבירים ומתאימים להגנת המידע מפני גישה, גילוי, שינוי, אובדן או השמדה בלתי מורשים או בלתי חוקיים, בהתחשב באופי, בהיקף ובהקשר העיבוד ובסיכונים שניתן לצפות באופן סביר. האמצעים הננקטים בפועל מפורטים בנספח א' להלן.

7. מעבדי משנה

הלקוח מעניק לחברה הרשאה כללית להשתמש במעבדי משנה הדרושים באופן סביר לצורך השירות, לרבות ספקי ענן, אחסון, בסיסי נתונים, AI, ניטור, תקשורת וטכנולוגיה. החברה תחזיק רשימה עדכנית של מעבדי משנה מהותיים המעבדים מידע אישי ותעמיד אותה לרשות הלקוח לפי בקשה. כאשר הדין מחייב זאת, החברה תמסור הודעה סבירה מראש על הוספה או החלפה של מעבד משנה מהותי. הלקוח רשאי להתנגד מטעמים סבירים ומתועדים הנוגעים להגנת מידע, בתוך 30 יום ממועד ההודעה. הצדדים יפעלו בתום לב למציאת פתרון סביר. אם לא קיים פתרון סביר, הלקוח רשאי להפסיק את השימוש בחלק השירות המושפע בהתאם לזכויותיו החוזיות והחוקיות. החברה תחייב את מעבדי המשנה בחובות מתאימות של הגנת מידע, סודיות ואבטחה ותישאר אחראית במידה הנדרשת על פי דין.

8. העברות בינלאומיות

מידע עשוי להיות מעובד בישראל ובמדינות אחרות שבהן פועלים החברה או מעבדי המשנה. כאשר הדין מחייב מנגנון מתאים להעברה בינלאומית, החברה תשתמש במנגנון המוכר בדין, לרבות החלטת Adequacy, SCC, מנגנון UK מתאים או אמצעי חוקי אחר.

9. זכויות נושאי מידע

החברה תעניק ללקוח סיוע סביר, ככל שהדבר אפשרי טכנית, בטיפול בבקשות למימוש זכויות פרטיות. כאשר הלקוח הוא Controller, האחריות למענה נשארת בידיו.

10. אירועי אבטחת מידע

אם ייוודע לחברה על אירוע אבטחה המשפיע על מידע אישי שהיא מעבדת בשם הלקוח, החברה תודיע ללקוח ללא דיחוי ככל שהדין מחייב ותספק מידע זמין באופן סביר לצורך הטיפול באירוע.

11. סיוע בציות

החברה תעניק סיוע סביר, בהתחשב באופי העיבוד ובמידע הזמין לה, בנוגע לחובות אבטחה, דיווח על אירועים והערכות השפעה על פרטיות.

12. ביקורות ומידע על ציות

החברה תעמיד מידע הנדרש באופן סביר להוכחת עמידתה בחובות החלות עליה כ-Processor. כאשר הדין מחייב זאת, החברה תאפשר ביקורת סבירה, בהודעה מראש, בשעות העבודה ובאופן המגן על אבטחת החברה ועל סודיות לקוחות אחרים. ככל שמספיק באופן סביר, ניתן לתת מענה באמצעות דוחות אבטחה, הסמכות, שאלונים או מסמכי ציות אחרים.

13. החזרה ומחיקה

לאחר סיום השירות, החברה תמחק או תחזיר מידע אישי בהתאם לדין, להוראות הלקוח ולתקופות השמירה המרביות המפורטות בסעיף 7 למדיניות הפרטיות, אלא אם קיימת חובה חוקית לשמור אותו. בקשת מחיקה מבוצעת בתוך 30 יום ממועד קבלתה. בכל מקרה, מידע אישי המעובד בשם הלקוח נמחק לכל המאוחר בתום תקופת השמירה המרבית החלה עליו, בתהליך מחיקה אוטומטי המופעל אחת ליום. מידע בגיבויים עשוי להישאר לתקופה מוגבלת גם לאחר מחיקה במערכות הפעילות ויישאר מוגן מפני שימוש שאינו קשור למטרת השמירה.

14. אחריות הלקוח

הלקוח אחראי לאיסוף ולעיבוד חוקי של מידע; לחוקיות ולאיכות המידע שסופק; למסירת הודעות פרטיות; לקבלת הסכמות או קיום בסיס חוקי אחר; לחוקיות הוראות העיבוד; לקביעה איזה מידע יועבר למערכת; להימנעות מאיסוף מיותר של מידע רגיש; ולהגדרה ושימוש מתאימים בשירות.

15. שימוש החברה במידע

החברה לא תמכור מידע אישי של הלקוח. החברה לא תשתמש במידע שהיא מעבדת בשם הלקוח לצורך שיווק ישיר למשתמשי הקצה שלו. החברה לא תשתמש בתוכן הלקוח או בשיחות משתמשי הקצה לצורך אימון מודלי AI כלליים של החברה אלא אם הלקוח הסכים לכך במפורש.

16. עדיפות

במקרה של סתירה בין תנאי עיבוד המידע לבין הוראה אחרת הנוגעת לעיבוד מידע בשם הלקוח, תנאי עיבוד המידע יגברו ביחס לעיבוד. DPA נפרד שייחתם בעתיד יגבר במקרה של סתירה.

נספח א' – אמצעים טכניים וארגוניים

האמצעים המפורטים להלן מיישמים את סעיף 6 לתנאי עיבוד המידע. הם מתארים את השירות כפי שהוא מופעל כיום ועשויים להתעדכן עם התפתחותו, אך לא יצומצמו באופן מהותי במהלך תקופת ההסכם.

אירוח ותשתית

  • האפליקציה ובסיס הנתונים פועלים על תשתית ענן מנוהלת המתארחת באיחוד האירופי (פרנקפורט).
  • בסיס הנתונים הוא שירות PostgreSQL מנוהל הכולל גיבויים אוטומטיים המופעלים על ידי הספק.

הצפנה

  • כל התעבורה בין המשתמשים, השירות וספקיו מוצפנת בעת ההעברה באמצעות TLS.
  • המידע בעת אחסון מוצפן על ידי שירות בסיס הנתונים המנוהל.
  • פרטי הגישה לתיבות דואר של לקוחות מוצפנים בנוסף בשכבת האפליקציה (AES-128-CBC עם אימות HMAC-SHA256).

בקרת גישה ואימות

  • הגישה ללוח הבקרה מאומתת באמצעות ספק זהויות חיצוני; האסימון של כל בקשה מאומת מול מפתחות החתימה המפורסמים של המנפיק.
  • הגישה למידע מוגבלת לחשבון המאומת: בקשה לסוכן, לשיחה או לליד של חשבון אחר אינה ניתנת להבחנה מבקשה למידע שאינו קיים.
  • שיחות של משתמשי קצה בווידג'ט משתמשות באסימונים חתומים קצרי-מועד, הקשורים לסוכן יחיד ופגים כברירת מחדל לאחר שבעה ימים.

בקרות ברמת האפליקציה

  • לכל סוכן רשימת דומיינים מורשים המגבילה את האתרים שבהם ניתן להטמיע את הווידג'ט שלו.
  • מגבלות קצב חלות על הנפקת אסימוני שיחה ועל הודעות יוצאות.
  • HTML המתקבל ממקורות חיצוניים עובר דרך מסנן מבוסס רשימת היתר המסיר סקריפטים, מטפלי אירועים, מסגרות וטפסים לפני אחסון או הצגה.

תיעוד וניטור

  • נתוני טלמטריה של אפליקציה, שגיאות וביצועים נאספים באמצעות ספק ניטור מנוהל המתארח באיחוד האירופי.
  • בקשות ואירועים רלוונטיים לאבטחה נרשמים בלוגים עם מטא-דאטה מובנית.

ניהול סודות

  • פרטי גישה ומפתחות API מסופקים לשירות כמשתני סביבה הנשמרים במאגר הסודות של ספק האירוח, ואינם נשמרים בקוד המקור.

מחזור חיי המידע

  • תהליך אוטומטי פועל אחת ליום ומוחק מידע שעבר את תקופות השמירה המרביות המפורסמות בסעיף 7 למדיניות הפרטיות.
  • לקוחות יכולים לייצא שיחות בפורמט JSON או CSV ונתוני לידים בפורמט CSV מתוך המסך הרלוונטי בשירות. לקוח או אדם אחר יכולים לבקש עותק של מידע אישי רלוונטי באמצעות פנייה לכתובת הדוא״ל לענייני פרטיות המופיעה במדיניות הפרטיות. לקוחות יכולים למחוק סוכן או שיחה מתוך השירות בכל עת; מחיקת החשבון כולו מתבצעת על ידי החברה לבקשת הלקוח, בדוא"ל או בשיחה.

בקרות מעבדי משנה

  • בקשות לספקי AI נשלחות עם ביטול איסוף המידע ברמת הספק בכל מקום שבו הספק תומך בכך, כך שתוכן הלקוח אינו נשמר לצורך אימון מודלים ואינו משמש לכך.

Terms of Service (English)

Last updated: 7 September 2026

These Terms of Service (the "Terms" or the "Agreement") govern access to and use of the VibeTech platform, website, chatbot and AI-agent creation tools, related implementation and assistance services, API, integrations and other services offered by Vibetech AI Systems Ltd, company number 517329801, an Israeli company (the "Company", "we" or "us") (together, the "Service"). These Terms include the Data Processing Terms in Part B, which form an integral and binding part of the Agreement to the extent they apply.

Creating an account, signing up for free or paid use, purchasing a plan, ticking an acceptance box or otherwise using the Service constitutes acceptance of these Terms. If the Terms are accepted on behalf of a company, organization or other legal entity (the "Customer"), the person accepting represents that they are authorized to bind that entity to these Terms.

Part A – Terms of Service

1. The Service

The Service allows Customers to create, configure, test, operate and embed AI-based chatbots and agents using websites, URLs, documents, files, instructions and other information provided or selected by the Customer. Depending on the plan, the Service may include creation and configuration, connecting data sources, testing, a hosted link, website embedding, API and integration use, and onboarding, setup, implementation, integration, support or other assistance. The Service may be used independently or with the Company's assistance. Features, quotas, functionality and assistance may vary between plans. The Company may update, modify and improve the Service from time to time.

The Service is intended for business and professional use only and is not offered to private consumers for personal, household or family use. Registration and use of the Service are intended for businesses, organizations and business owners acting in the course of their trade.

2. Accounts and authorized users

The Customer is responsible for providing accurate information and for keeping login credentials confidential and secure. The Customer may allow employees, contractors and other authorized persons ("Users") to use the Service and is responsible for managing their permissions and for any use made through its account. The Customer must promptly notify the Company of any unauthorized access it becomes aware of. Where the plan allows, the Customer's affiliates may use the Service and the Customer remains responsible for their use and related payments. The Customer is not responsible to the extent unauthorized access results directly from a vulnerability in the Service that the Customer did not cause and did not fail to mitigate after receiving reasonable notice from the Company.

3. Free use and trial periods

The Company may offer limited free use, including messages, tokens, credits or other resources. The scope, duration and limits of free use will be shown in the Service and may change. Once the free quota is exhausted, a paid plan may be required. Unless stated otherwise, free use does not require a purchase. The Company may change or discontinue free tiers and promotions but will not retroactively charge for use that was expressly offered free of charge.

4. Plans and Orders

Plans, prices, billing periods, quotas, features, assistance and limitations will be shown at the time of purchase or selection (an "Order"). Confirming an Order or completing payment constitutes acceptance of the commercial terms presented. Each Order forms part of the Agreement. Prices and quotas need not appear in these Terms and may be updated from time to time.

5. Subscriptions and automatic renewal

Where a plan is offered as a renewing subscription, it will renew automatically for additional billing periods unless cancelled before the renewal date, unless stated otherwise at the time of purchase. The price and billing period will be shown before purchase. By purchasing a renewing subscription, the Customer authorizes the Company and/or its payment provider to charge the payment method for the subscription fees.

6. Payment and taxes

Payment is made in the currency shown in the Order. The Customer is responsible for keeping a valid payment method on file. Transactions made through a payment provider may also be subject to that provider's terms. In the event of a failed or late payment, the Company may retry the charge and suspend paid functionality until payment is received. Fees paid are non-refundable unless stated otherwise or required by law. The Customer is responsible for taxes applicable to its purchase, excluding taxes on the Company's income.

The Company may change recurring fees or introduce new fees by giving reasonable advance notice. Unless required by law or expressly agreed otherwise, a change to recurring fees will take effect no earlier than the Customer's next renewal, and the Customer may avoid the changed fee by cancelling before that renewal. A Customer that believes it was billed incorrectly must notify the Company within 60 days after the relevant charge or billing statement, describe the disputed amount and the basis of the dispute, and continue to pay any undisputed amounts when due. The Company will review the dispute in good faith and correct any confirmed billing error. This paragraph does not limit any right or remedy that cannot be waived by law.

7. Usage limits and overages

Plans may include limits on messages, tokens, conversations, agents, data sources, storage, integrations, API or other resources. Where additional usage can be purchased or overage charges apply, the price or billing mechanism will be shown before the charge is created. The Company may limit or suspend functionality when a quota is reached.

8. Assistance services

Certain plans may include, or allow the purchase of, onboarding, setup, implementation, integration, technical support or other assistance ("Assistance Services"). The scope of service is determined by the plan, the Order or the service description. Unless agreed otherwise, assistance does not transfer to the Company responsibility for Customer Content, business rules, data sources, instructions, configuration decisions or the use of the chatbot or agent. The Customer is responsible for providing the information, materials, access and approvals required. Delay on the Customer's side may cause a corresponding delay in implementation. Work beyond the purchased scope may involve additional fees, subject to the Customer's approval.

9. Restrictions on use

The Service may not be used:

  • for any unlawful, fraudulent or deceptive purpose;
  • to infringe the rights of any third party;
  • to make unauthorized copies of proprietary components;
  • for reverse engineering, except where the law prohibits this restriction;
  • for unauthorized resale or distribution of the Service;
  • to circumvent technical, security or usage limitations;
  • to obtain unauthorized access;
  • to harm the security or functioning of the Service;
  • to distribute malicious code;
  • for penetration or security testing without authorization;
  • or to make unauthorized copies of proprietary components primarily to build a materially competing product.

10. API and integrations

The Company may set reasonable technical and usage limits. The Customer will act in accordance with the applicable documentation and limits. The Company may restrict access where reasonably required for security, availability or quota compliance.

11. Customer Content and data sources

"Customer Content" includes websites, URLs, documents, files, text, instructions, data, images and other materials the Customer provides to the Service. The Customer retains ownership of its content. The Customer grants the Company a limited, non-exclusive right to store, copy, transmit, access and process the content as reasonably required to provide, maintain, secure and support the Service. The Customer represents that it holds the rights, permissions and lawful basis required. Only data sources the Customer is authorized to use for the relevant purpose may be used. The fact that information is publicly accessible does not necessarily grant permission to copy, process or use it commercially.

12. AI output

AI output may be incorrect, incomplete, outdated or unsuitable for a particular purpose. The Customer is responsible for testing the chatbot or agent before publishing, for determining that the configuration and output are suitable for the intended use, and for supervising its operation. The Company does not warrant the accuracy, completeness or reliability of AI output. The Service must not be relied upon as the sole source of legal, medical, financial or other professional advice, or for decisions where an error could cause material harm.

13. End Users and Customer responsibilities

The Customer is responsible for its relationship with the people who use its chatbot or agent ("End Users"). Before publishing the chat, the Customer is responsible for ensuring that its operation complies with applicable laws, including privacy, data protection, consumer protection and AI transparency laws. The Customer is responsible for:

  • providing the required privacy notices, policies, terms and disclosures;
  • obtaining consent or maintaining another lawful basis for processing data;
  • informing End Users that they are interacting with an automated or AI-based system where required;
  • making its own privacy policy available;
  • determining whether additional terms or disclosures are required;
  • not intentionally collecting personal or sensitive data that is unnecessary or unlawful to collect;
  • ensuring the chat and its output are fit for purpose;
  • and handling End Users' rights and requests.

The Company may provide privacy links, AI disclosures, notices, templates or suggested wording. These are provided for convenience and information only, do not constitute legal advice and are not a commitment that the Customer's use complies with the law. Responsibility for reviewing, adapting and maintaining notices, policies and consents remains with the Customer. The Company's Terms and Privacy Policy do not replace the Customer's own terms or privacy policy towards its End Users.

14. Confirmation before publishing

Before a chatbot or agent is published or embedded, the Company may require the Customer to confirm that it is responsible for the privacy notices, AI disclosures, lawful basis, consents and compliance required with respect to End Users. This confirmation is in addition to, and does not replace, the Customer's obligations.

15. Third-party services

The Service may rely on AI, cloud, storage, database, analytics, payment and other technology providers. Optional integrations may be subject to the relevant provider's terms. The Customer represents that it is authorized to provide the permissions or access details required for an integration. Third-party services are not controlled by the Company, and the Customer may need to enter into a separate agreement with their providers. To the maximum extent permitted by law, an optional third-party service that the Customer chooses to use is used at the Customer's own risk; the Company makes no representation or warranty concerning that service, and disputes concerning the provider's separate terms must be directed to the provider. The Company is not responsible for a failure, act or omission caused solely by a third-party service outside its reasonable control. Nothing in this section excludes responsibility for the Company's own breach of the Agreement, gross negligence or wilful misconduct.

16. Confidentiality

Each party will keep confidential any non-public business, commercial, technical, security or financial information received from the other party. Customer Content and the Customer's non-public information are the Customer's confidential information. Non-public information about the Company's technology, architecture, security, functionality and business is the Company's confidential information. Each party will use confidential information only for the purposes of the engagement, protect it reasonably and limit access to those who need it and are bound by confidentiality obligations.

Confidential information does not include information that the receiving party can demonstrate: (a) became public without breach of an obligation; (b) was lawfully known to it without a duty of confidentiality before disclosure; (c) was lawfully received from a third party without a duty of confidentiality; or (d) was independently developed without use of the disclosing party's confidential information. A receiving party may disclose confidential information to the extent required by law, regulation or a valid court or governmental order. Where legally permitted, it will give the disclosing party reasonable advance notice and reasonable assistance, at the disclosing party's expense, if the disclosing party seeks to contest or limit the disclosure.

17. Privacy

The Company's processing of personal data for its own purposes is described in the Privacy Policy. Where the Company processes personal data on the Customer's behalf, Part B (Data Processing Terms) below applies.

18. Service Data

The Company may collect technical, operational, security and performance information about use of the Service. It may be used to operate, secure, troubleshoot, analyze and improve the Service. For broader analytics, benchmarking or product improvement, the Company will use aggregated or de-identified information that does not reasonably identify a Customer or End User. Nothing in this section transfers ownership of Customer Content to the Company.

19. Intellectual property

The Service, software, technology, interfaces, documentation, designs, trademarks and proprietary materials are owned by or licensed to the Company. No ownership of the technology is transferred to the Customer. Customer Content remains the Customer's property.

20. Feedback

The Company may use feedback and suggestions to develop and improve the Service without compensation, provided it does not identify the Customer as the source without permission and does not acquire ownership of the Customer's confidential information.

21. Use of name and logo

The Company will not publicly use the Customer's name, logo or trademarks to identify it as a customer without its prior consent.

22. Availability and changes

The Company may update and improve the Service and does not guarantee uninterrupted or error-free operation. Interruptions may occur due to maintenance, faults, security events, provider failures or circumstances beyond the Company's reasonable control. During a Customer's then-current paid billing period, the Company will not materially reduce the core functionality included in the applicable Order, except where reasonably required by law, security or a third-party change outside the Company's reasonable control. If the Company materially reduces that core functionality for another reason and does not restore substantially equivalent functionality within a reasonable period after notice, the Customer may terminate the affected paid Service and receive a pro-rata refund of prepaid fees for the unused remainder of the billing period.

23. Disclaimer of warranties

To the maximum extent permitted by law, the Service is provided "as is" and "as available". The Company disclaims all express, implied and statutory warranties not expressly stated in the Agreement, including implied warranties of merchantability, fitness for a particular purpose and non-infringement. The Company does not warrant that the Service or AI output will always be accurate, uninterrupted, timely, error-free or completely secure. These disclaimers apply only to the extent permitted by law.

24. Limitation of liability

To the maximum extent permitted by law, neither party will be liable for indirect, special, incidental, consequential or punitive damages, including loss of profits, revenue, goodwill, business opportunities or data. The Company's aggregate liability will not exceed the amounts paid or payable to the Company for the Service during the 12 months preceding the event giving rise to the claim. Nothing herein limits liability that cannot be limited by law.

25. Indemnification

To the extent permitted by law, the Customer will indemnify and defend the Company, its affiliates and representatives against third-party claims, damages, liabilities, fines, costs and reasonable legal fees arising from:

  • the Customer's unlawful or unauthorized use of the Service;
  • content or data sources that infringe third-party rights;
  • the Customer's collection or processing of personal data in breach of the law;
  • failure to provide a privacy notice, consent, AI disclosure or other notice required by law;
  • the Customer's instructions, configuration or business rules;
  • claims relating to the Customer's products, services or business activity;
  • or a material breach of the Agreement.

The indemnity applies to the extent the matter arises from an act, omission, instruction or obligation of the Customer, and not to the extent caused by the Company's breach of the Agreement or the law, its gross negligence or its wilful misconduct.

26. Suspension

The Company may suspend the Service due to a material security risk, unlawful or fraudulent activity, material breach, non-payment, material risk to the Service, or circumvention of usage or security limits. Where reasonably possible, the Company will notify the Customer and provide a reasonable opportunity to resolve the issue.

27. Cancellation and termination

A renewing subscription may be cancelled through the account or by contacting [email protected]. Unless stated otherwise, cancellation prevents the next renewal and paid service continues until the end of the period already paid for. Either party may terminate the Agreement by written notice if the other party materially breaches it and does not cure the breach within 30 days after receiving written notice describing the breach, where the breach is capable of cure. A party may terminate immediately if the material breach cannot reasonably be cured or if immediate termination is permitted by law.

If the Customer terminates due to the Company's uncured material breach, the Company will refund prepaid fees for the unused remainder of the then-current paid billing period. If the Company terminates due to the Customer's uncured material breach, amounts accrued through the effective termination date and any non-cancellable committed fees expressly identified in an Order remain due. Termination does not affect rights or liabilities accrued before it takes effect. When a paid subscription ends following cancellation, the Company may transition the account to a free plan that it then offers. When the Agreement terminates, the Customer's right to access and use the Service ends. The return, export and deletion of Customer Content and personal data are governed by the Data Processing Terms and Privacy Policy.

28. Survival

Sections that by their nature should survive termination will continue to apply, including payment, intellectual property, confidentiality, data protection, limitation of liability and indemnification.

29. Force majeure

Neither party will be liable for delay or non-performance, other than payment obligations, resulting from circumstances beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, governmental actions, widespread internet or communication failures, significant cloud infrastructure failures and similar events.

30. Changes to the Terms

The Company may update these Terms. Reasonable notice will be given of a material change affecting existing paying Customers. Where required by law, additional consent will be obtained.

31. Standard and Enterprise services

These Terms apply to the standard services offered on the website, including self-service and assisted service. Enterprise, custom or managed services may be subject to a separate agreement. A signed individual agreement prevails in the event of conflict.

32. Relationship of the parties

The parties are independent contractors. The Agreement does not create a partnership, joint venture, agency, franchise, fiduciary or employment relationship.

33. No third-party rights

Unless expressly stated otherwise, these Terms are intended for the Company and the Customer only. No End User or other third party has the right to enforce them.

34. Notices

The Company may deliver notices through the Service or to the email address associated with the account. Legal notices to the Company should be sent to [email protected]. The Customer is responsible for keeping its contact details up to date.

35. Assignment

The Customer may not assign the Agreement without the Company's prior written consent, unless the law provides otherwise. The Company may assign it in connection with a merger, acquisition, reorganization or sale of all or substantially all of the relevant business or assets.

36. Severability and waiver

If a provision is invalid or unenforceable, the remaining provisions remain in effect. Failure to enforce does not constitute a waiver.

37. Entire agreement

These Terms, the Orders and the documents expressly incorporated into them constitute the entire agreement between the parties regarding the Service.

38. Governing law and jurisdiction

The Agreement is governed by the laws of the State of Israel. Unless mandatory law requires otherwise, the competent courts of Tel Aviv-Jaffa will have exclusive jurisdiction. Rights that cannot be waived by law are not affected.

39. Language

These Terms may be presented in several languages. Unless prohibited by law, in the event of a conflict between the English version and a translation, the English version prevails.

40. Contact

Vibetech AI Systems Ltd
Company number: 517329801
Yitzhak Navon 4, House 15, Kiryat Ono 5557222, Israel
Email: [email protected]

Part B – Data Processing Terms (DPA)

1. Scope

These terms constitute the data processing agreement between the Customer and the Company whenever the Company processes personal data on the Customer's behalf. They form an integral and binding part of the Terms of Service. No separate DPA is required unless the law requires additional terms or the parties agree otherwise.

2. Definitions and roles of the parties

The terms "personal data", Controller, Processor, Data Subject, Personal Data Breach and equivalent terms have the meaning given under applicable data protection laws. Depending on the circumstances, the Customer may act as Controller or Processor. Where the Customer is a Controller, the Company will generally act as Processor. Where the Customer is a Processor for another Controller, the Company will act as Subprocessor where relevant. The Customer is responsible for having the authority and lawful basis to instruct the Company to process data.

3. Processing instructions

The Company will process the Customer's personal data only as required to provide, maintain, secure and support the Service; in accordance with the Customer's configuration and use; in accordance with the Agreement and Orders; in accordance with the Customer's documented instructions; or as required by law. If the Company reasonably believes that a Customer instruction violates data protection laws, it will inform the Customer without delay and may suspend the relevant processing until the matter is clarified.

4. Details of processing

The purpose of processing is to provide, operate, secure and support the Service. Processing generally continues for the duration of use, subject to retention policies, backups and legal requirements. The data may include conversations, information provided by End Users, contact details, technical information and personal data contained in Customer Content. Data subjects may include customers, prospective customers, website visitors, employees, representatives and other End Users. Processing operations may include collection, access, organization, storage, retrieval, transfer to authorized providers, use for generating AI responses, deletion and other operations required for the Service.

5. Confidentiality

Persons authorized by the Company to process personal data are bound by appropriate confidentiality obligations.

6. Security

The Company will implement and maintain reasonable and appropriate technical and organizational measures to protect data against unauthorized or unlawful access, disclosure, alteration, loss or destruction, taking into account the nature, scope and context of the processing and the risks that can reasonably be anticipated. The measures in place are described in Annex A below.

7. Subprocessors

The Customer grants the Company general authorization to use subprocessors reasonably required for the Service, including cloud, storage, database, AI, monitoring, communication and technology providers. The Company will maintain an up-to-date list of material subprocessors that process personal data and make it available to the Customer on request. Where required by law, the Company will give reasonable advance notice of the addition or replacement of a material subprocessor. The Customer may object on reasonable, documented data-protection grounds within 30 days of that notice. The parties will work in good faith to find a reasonable solution. If no reasonable solution exists, the Customer may stop using the affected part of the Service in accordance with its contractual and legal rights. The Company will bind subprocessors to appropriate data protection, confidentiality and security obligations and remains liable to the extent required by law.

8. International transfers

Data may be processed in Israel and in other countries where the Company or its subprocessors operate. Where the law requires an appropriate international transfer mechanism, the Company will use a mechanism recognized by law, including an adequacy decision, SCCs, an appropriate UK mechanism or another lawful measure.

9. Data subject rights

The Company will provide the Customer with reasonable assistance, where technically feasible, in handling requests to exercise privacy rights. Where the Customer is the Controller, responsibility for responding remains with the Customer.

10. Security incidents

If the Company becomes aware of a security incident affecting personal data it processes on the Customer's behalf, the Company will notify the Customer without undue delay where required by law and provide reasonably available information to help address the incident.

11. Compliance assistance

The Company will provide reasonable assistance, taking into account the nature of the processing and the information available to it, regarding security obligations, incident reporting and privacy impact assessments.

12. Audits and compliance information

The Company will make available information reasonably required to demonstrate compliance with its obligations as a Processor. Where required by law, the Company will allow a reasonable audit, on advance notice, during business hours and in a manner that protects the Company's security and the confidentiality of other customers. Where reasonably sufficient, this may be satisfied through security reports, certifications, questionnaires or other compliance documents.

13. Return and deletion

Upon termination of the Service, the Company will delete or return personal data in accordance with the law, the Customer's instructions and the maximum retention periods set out in section 7 of the Privacy Policy, unless there is a legal obligation to retain it. A deletion request is completed within 30 days of receipt. In any event, personal data processed on the Customer's behalf is deleted no later than the end of the maximum retention period applicable to it, by an automated deletion process that runs once a day. Data in backups may remain for a limited period after deletion from active systems and will remain protected against use unrelated to the retention purpose.

14. Customer responsibilities

The Customer is responsible for the lawful collection and processing of data; the lawfulness and quality of the data provided; providing privacy notices; obtaining consents or maintaining another lawful basis; the lawfulness of processing instructions; determining which data is submitted to the system; avoiding unnecessary collection of sensitive data; and appropriate configuration and use of the Service.

15. The Company's use of data

The Company will not sell the Customer's personal data. The Company will not use data it processes on the Customer's behalf for direct marketing to the Customer's End Users. The Company will not use Customer Content or End User conversations to train the Company's general-purpose AI models unless the Customer has expressly agreed.

16. Precedence

In the event of a conflict between the Data Processing Terms and another provision relating to processing data on the Customer's behalf, the Data Processing Terms prevail with respect to the processing. A separate DPA signed in the future prevails in the event of conflict.

Annex A – Technical and Organisational Measures

The measures below implement section 6 of the Data Processing Terms. They describe the Service as operated today and may be updated as it evolves, but will not be materially reduced during the term of the Agreement.

Hosting and infrastructure

  • The application and its database run on managed cloud infrastructure hosted in the European Union (Frankfurt).
  • The database is a managed PostgreSQL service with provider-operated automated backups.

Encryption

  • All traffic between clients, the Service and its providers is encrypted in transit over TLS.
  • Data at rest is encrypted by the managed database service.
  • Credentials for connected customer mailboxes are additionally encrypted at rest at the application layer (AES-128-CBC with HMAC-SHA256 authentication).

Access control and authentication

  • Dashboard access is authenticated through a third-party identity provider; every request's token is verified against the issuer's published signing keys.
  • Data access is scoped to the authenticated account: a request for another account's agent, conversation or lead is indistinguishable from one that does not exist.
  • End-user widget sessions use short-lived signed tokens bound to a single agent and expiring by default after seven days.

Application controls

  • Each agent carries a domain allow-list restricting the sites its widget may be embedded on.
  • Rate limits apply to session-token issuance and to outbound messages.
  • HTML received from external sources is passed through an allow-list sanitiser that strips scripts, event handlers, frames and forms before it is stored or displayed.

Logging and monitoring

  • Application, error and performance telemetry is collected through a managed observability provider hosted in the European Union.
  • Requests and security-relevant events are logged with structured metadata.

Secrets management

  • Credentials and API keys are supplied to the Service as environment variables held in the hosting provider's secret storage, and are never committed to source control.

Data lifecycle

  • An automated process runs daily and deletes data that has passed the maximum retention periods published in section 7 of the Privacy Policy.
  • Customers can export conversations in JSON or CSV format and lead data in CSV format from the relevant Service view. A Customer or other person may request a copy of applicable personal data by contacting the privacy email address in the Privacy Policy. Customers can delete an agent or a conversation from within the Service at any time; an entire account is deleted by the Company on the Customer's request, by email or on a call.

Subprocessor controls

  • Requests to AI providers are sent with provider-level data-collection opted out wherever the provider supports it, so Customer Content is not retained for or used in model training.