Official Privacy Policy of the Platform
Platform: Simpixy
Platform owner: Rami Pazhar, exempt dealer (the “Business” or “we”)
Simpixy places the highest importance on protecting privacy, confidentiality, and the security of personal, visual, and sensitive data processed in the digital platform for managing and storing media galleries (the “Platform” or “Software”).
This Privacy Policy describes how information is collected, processed, retained, and secured on the Platform, and regulates the legal and technological relationship between the Business and the various users (photographers, their clients, guests, and photographed persons).
The Policy is drafted to align with the Privacy Protection Law, 5741-1981, and regulations under it, including the Privacy Protection Regulations (Information Security), 5777-2017.
1. Control of information uploaded to the Platform
The Data Controller of the information and files is the photographer who controls the personal area allocated to them and the folders to which they upload media files of their clients and guests. The photographer independently and fully determines processing purposes, file types uploaded, permission and access levels of clients and other users, public exposure of images, and obtaining lawful consents.
The Platform is a Data Processor / data holder for its photographer customers. The Platform processes visual and sensitive information solely according to the customer’s automatic technical instructions in a self-service model. The Platform does not exercise human supervision or independent control over content. We make no commercial or marketing use of collected or processed content and information without an express contractual instruction, except as needed to improve and maintain the Platform — and in those cases the Platform uses only anonymous and statistical information.
2. Nature of processing on the Platform
The Platform has face-recognition capabilities for user and client convenience, used to catalog and locate photographs of users and photographed persons. Use of these tools is subject to permissions granted by users, clients, and photographers. The system computationally scans facial features of photographed persons, calculates unique physiological parameters, and creates a “digital template” for comparison, fast sorting, and service delivery.
Under the Privacy Protection Law, information used to identify a person by their characteristics constitutes “biometric information” and is classified as information of special sensitivity, imposing security, compliance, oversight, and formal notification duties to the Privacy Protection Authority regarding the existence of a database when activity exceeds 100,000 data subjects. At this stage, the Platform is not subject to a duty to notify or register the databases in its possession.
3. Information retained by the Business and collection purposes
Information processed and retained in the company’s systems falls into two main categories by collection method: information collected automatically during Platform use, and information collected as a result of users’ active, intentional actions.
Automatically collected information (metadata and system data): IP addresses, endpoint device identifiers, operating system type, browser type, approximate geographic location, session durations, and internal activity logs (upload, deletion, AI analysis creation, favorites marking, likes, and download). The system uses essential cookies for proper operation, preference storage, and information security, and may use pixel tools to improve the service.
Information collected from intentional actions: photographers’ administrative and billing details; end-client details (name and email, required only when downloading/uploading media); visual media files (photos, video) that the photographer chooses to upload; and facial-feature recognition templates.
4. Data confidentiality, non-access, folder blocking, and photographs of minors
The Platform declares and is absolutely committed that it does not transfer, sell, or share the personal information, photographs, or biometric data of the photographer and photographed persons with any external party or third party for marketing or commercial purposes without an express lawful instruction.
Platform staff and business owners have no routine access or ability to view raw visual content inside customers’ private folders. Folders are encrypted and logically isolated on cloud servers operated by Microsoft Azure and Wasabi.com in the European Economic Area (EEA). Online systems are blocked from human review by the Platform by default.
All client folders and galleries are fully blocked from public access. Access is limited and performed only under secure logical permission granted by photography clients or photographers as applicable (via personal/group passwords or unique token links).
Folders and galleries managed in the self-service system may contain diverse photographs, including of minors. The Platform has no control, human supervision, monitoring, filtering, or review of uploaded content, the nature of photographs, or the age of photographed persons. Full legal responsibility for the lawfulness of images and obtaining lawful parental consents rests solely with the photographer and the client/commissioning party.
Notwithstanding the above, if a material suspicion arises, or a technological alert or legal demand indicates abusive, harmful, or illegal use of the system (such as uploading prohibited materials, copying software, or use to degrade or humiliate a person), the Business reserves the right to immediately block and remove the infringing user, block IP access, and delete the content forthwith in accordance with law.
5. Permanent deletion mechanism and retention
When a photographer or client deletes a file or gallery from their workspace, the deletion command is applied immediately and finally in the company’s production systems and active databases and in sub-processor systems. Information deleted in this way cannot be restored.
No responsibility for data integrity after 90 days: Upon expiry of a photographer’s subscription without renewal, media files and biometric templates are retained in a frozen archive for 90 days only (subject to a series of scheduled notices). On day 90, a scheduled, absolute, and irreversible deletion of all galleries and biometric identifiers is performed. After 90 days and completion of erasure, the Platform and its owners bear no responsibility, liability, or warranty for data integrity or restorability; sole responsibility for backing up materials rests with the photographer. Administrative financial information is retained for 7 years under tax laws.
6. Rights of users and data subjects (photographed persons)
Every user and data subject (photographed person, end client, or casual guest) is entitled to review information retained about them in the database, and to demand its correction or deletion (right to be forgotten) if the information is inaccurate, incomplete, or not up to date.
Because the Business acts only as processor/holder of information for the photographer (the controller), direct requests by photographed persons for access or deletion are resolved only through direct contact with the professional photographer who managed the gallery. If such a request reaches the Business, we will refer the photographed person to the relevant photographer and assist the photographer technologically to fulfill the right as required by law.
7. Exclusive jurisdiction
Any legal dispute or conflict arising from this Policy or related to Platform activity shall be brought exclusively before the court of competent subject-matter jurisdiction in the State of Israel.