Menu

Discover AlefOS

Discover AlefOS↗An assistant for your customers↗Your MCP, under your domain↗Documentation↗

Your customer journey

Proposals & quotes↗Documents & signatures↗Customer space↗

Uses & integrations

Industry use cases↗All use cases↗Integrations↗

Your project

Deployment & pricing↗Request a demo↗Deployment↗

Resources & help

Resources↗Blog↗Customer support↗Client access↗Legal Center↗
Back to the home page ↗
AlefOS
EN⌄
English ✓Français

AlefOS Legal Center

Data Processing Agreement

The parties’ obligations for data processed on the Customer’s behalf in its bespoke OS project.

Version 2026.09 · Updated September 9, 2026

AlefOS is operated by MyBot Ltd. Official company website: mybot.ltd.

On this page
  1. 1. What this agreement covers
  2. 2. Where this fits in the contract stack
  3. 3. Key definitions
  4. 4. Who does what
  5. 5. What we actually do with your data
  6. 6. Duration
  7. 7. What data is processed
  8. 8. Who the data is about
  9. 9. We only do what you tell us
  10. 10. Your obligations as controller
  11. 11. Confidentiality within our team
  12. 12. How we secure your data
  13. 13. Sub-processors we use
  14. 14. Cross-border transfers
  15. 15. We help you meet your obligations
  16. 16. If someone contacts us about their data
  17. 17. If there's a data breach
  18. 18. What happens to your data when the contract ends
  19. 19. Audit rights
  20. 20. Contacts without an account
  21. 21. Liability split
  22. 22. Governing law
  23. 23. Final provisions

1. What this agreement covers

This DPA defines how AlefOS handles personal data on your behalf. It supplements the Terms of Service and overrides them on data protection matters.

This Data Processing Agreement ('DPA') sets out the conditions under which AlefOS processes personal data on behalf of the Customer in connection with services provided through the AlefOS product.

This DPA applies to all processing of personal data carried out by AlefOS as Processor where the Customer determines the purposes and essential means of the processing in the course of its professional activity.

This DPA forms an integral part of the Terms of Service and any contractual relationship entered into between:

MyBot Ltd
Israeli company registration number 516373891
Ashkelon, Israel
Email: support@alefos.ai
Data Protection Contact: MyBot Ltd
(hereinafter 'AlefOS' or the 'Processor')

and the business customer using AlefOS in the course of its activity, including any artisan, professional tenant, company, operator, or contracting entity (hereinafter the 'Customer' or the 'Controller').

This DPA also covers personal data processed for the Customer in the design, adaptation, operation and support of its company-branded OS under the signed quotation. The agreed processing scope identifies the relevant services, operations, categories of data and people, duration and instructions; it does not incorporate an entire product roadmap.

2. Where this fits in the contract stack

The DPA sits above the Terms of Service on data matters. If there's a conflict, the DPA wins.

This DPA supplements the Terms of Service and Privacy Policy applicable to the AlefOS service.

In the event of conflict between this DPA and the Terms of Service, this DPA shall prevail for any matter relating to the processing of personal data carried out on behalf of the Customer.

Mandatory law and the priority rules of any applicable transfer clauses remain unaffected. A commercial quotation does not override the DPA on processing matters merely because it is more specific about price or delivery.

3. Key definitions

Plain language versions of the GDPR terms used throughout this document.

For the purposes of this DPA:

a) 'Personal Data' means any information relating to an identified or identifiable natural person;

b) 'Processing' means any operation or set of operations performed on personal data, whether or not by automated means;

c) 'Controller' means the entity that determines the purposes and means of processing;

d) 'Processor' means the entity that processes personal data on behalf of the Controller;

e) 'Data Subject' means the natural person to whom the personal data relates;

f) 'Personal Data Breach' means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;

g) 'Applicable Law' means any applicable rule relating to data protection, including where relevant Regulation (EU) 2016/679, Israeli privacy law, and any other mandatory applicable rule.

Customer, Customer Application and Authorized Users have the meanings given in the Terms. Their contractual labels do not alter the parties’ legal roles for a particular processing purpose.

4. Who does what

The Customer determines the purposes and essential means of the processing covered by this DPA. MyBot acts as processor for those operations, not for every activity it performs. If the Customer is itself a processor, it must have authority from the relevant controller to engage MyBot and communicate the applicable instructions.

MyBot’s separate purposes for its own commercial relationship, account administration, billing and applicable security or legal obligations are described in the Privacy Policy. Support access to a customer file for the Customer’s requested service remains processing on its behalf; administration of the support relationship is assessed separately. Neither party’s role removes its own statutory duties.

5. What we actually do with your data

MyBot processes Customer Data on documented instructions to provide the commissioned service: receiving authorized calls and messages, transcribing or structuring them, managing contacts, professional memory, groups, calendars and related operations included in the project. Hosting, necessary technical logging, maintenance and assistance are included only for that purpose and scope.

MyBot does not reuse those data for its own unauthorized business purposes. The Customer’s own business purposes are precisely the purposes for which the service is provided on its behalf. This clause does not authorize MyBot to train general third-party AI models, build a shared prospect database or prospect using the Customer’s contacts or communications.

6. Duration

Processing lasts for the commissioned service and the return or deletion operations required at its end. Temporary content, final records, logs and backups follow their respective retention purposes and triggers. MyBot’s separate legal retention obligations must identify the data and purpose concerned; they do not extend all Customer Data indefinitely. Section 18 and the Data Retention page govern the distinction.

7. What data is processed

Identity, calls, messages, transcripts, signals, logs — whatever the service needs to function based on how you use it.

Depending on the Customer's use, processed categories of personal data may include:

a) identification data, including name, surname, phone number, company name, role, and contact identifier;

b) communication data, including inbound and outbound calls, communication metadata, inbox messages, group messages, timestamps, duration, and call direction;

c) call audio content, where recording is enabled;

d) transcripts derived from audio content;

e) relationship and tracking data, including operational signals, PION signals, missions, statuses, relationship histories, and Ghost or Phantom profiles;

f) technical, access, and security data, including logs, IP addresses, session identifiers, browser or device environment data;

g) any other data entered, imported, generated, or transmitted by the Customer in the course of using the service.

Depending on the commissioned scope, this also includes files, company-specific configuration, permissions, assignments, requests received from external users and derived relationship information. Inferences are personal data where they relate to an identifiable person and are not necessarily accurate. Administration metadata are distinguished from the underlying business content.

8. Who the data is about

Your clients, your callers, your team, your Ghost contacts — anyone whose data flows through your use of AlefOS.

Data subjects may include, in particular:

a) the Customer's customers, prospects, business contacts, and interlocutors;

b) callers, recipients, inbound or outbound contacts;

c) the Customer's collaborators, employees, representatives, agents, or contractors;

d) authorized users of the service;

e) Ghost, Phantom, or silent contacts resulting from relevant phone interactions;

f) any other person whose data is introduced by the Customer into the service.

Where included in the commissioned service, data subjects also include visitors and external users of the Customer’s branded interfaces. A contact record does not by itself constitute a user account. Former members and people who never registered retain their applicable rights.

9. We only do what you tell us

MyBot processes personal data only on documented instructions, including the agreed processing description, authorized configuration and additional written instructions. This also applies to transfers, unless applicable Union or Member State law requires processing; in that case MyBot informs the Customer before processing unless the law prohibits such information on important public-interest grounds.

Where the GDPR applies, MyBot immediately informs the Customer if it considers an instruction to infringe applicable Union or Member State data protection provisions. The affected instruction may be suspended to address that issue. A technical configuration does not make an unlawful instruction lawful.

10. Your obligations as controller

You must have the legal right to submit this data, inform people when required, and handle requests from your contacts yourself.

The Customer represents, warrants, and undertakes that it shall:

a) have all rights, authority, permissions, and legal bases necessary to entrust personal data to AlefOS;

b) provide notice to data subjects in accordance with Applicable Law;

c) ensure the lawfulness of recording, transcription, analysis, and relationship communications;

d) respond to requests from data subjects where it acts as Controller;

e) not use the service in any unlawful manner or contrary to applicable regulation;

f) not provide AlefOS with instructions that are manifestly contrary to Applicable Law.

The Customer maintains the authority of its administrators and instructions for internal and external audiences. These obligations do not release MyBot from its own processor duties or from cooperating with lawful rights requests.

11. Confidentiality within our team

Everyone at AlefOS with access to your data is bound by a confidentiality obligation — contractual or statutory.

AlefOS shall ensure that persons authorized to process personal data are subject to an appropriate duty of confidentiality or a suitable statutory confidentiality obligation.

12. How we secure your data

MyBot implements appropriate technical and organizational measures for the agreed processing, considering its nature, scope, context, purposes and risks. These cover relevant access management, confidentiality, integrity, availability and the evaluation of protective measures. Authorized access is limited to service needs.

The applicable security description and any project-specific annex identify the measures for the commissioned service and their scope. They do not promise every future architecture feature, a certification or the complete absence of risk. Changes must maintain appropriate protection and respect the agreed obligations.

13. Sub-processors we use

The applicable processing agreement records the Customer’s specific or general written authorization for subprocessors. Under a general authorization, MyBot informs the Customer in advance of intended additions or replacements, giving a meaningful opportunity to object on data protection grounds before the change. The project agreement specifies the notice and objection arrangements; the right is not replaced by silently editing a web page.

MyBot imposes equivalent applicable data protection obligations on subprocessors and remains responsible for their performance of those obligations. The Subprocessors page identifies the supplier categories and the project inventory identifies the actual entities, services, data, regions and transfer safeguards. A Customer-contracted service or an independent AI assistant is not automatically a MyBot subprocessor. A software model such as Whisper is not itself a legal entity.

14. Cross-border transfers

Storage, processing, backups and remote support access may involve different countries. The processing description identifies the relevant locations and safeguards for the project; a storage region alone does not establish the location of every operation.

Where applicable law requires it, transfers use a valid adequacy decision, appropriate contractual safeguards or another lawful mechanism meeting its conditions. MyBot supplies information about the applicable mechanism on request. A provider name, customer authorization or target architecture does not by itself establish that a transfer is lawfully covered.

15. We help you meet your obligations

Taking account of the nature of processing and the information available to it, MyBot assists the Customer with data subject rights, security, breach obligations, impact assessments and prior consultation as required by applicable law. Assistance is provided through appropriate technical and organizational measures.

Any separately agreed charges for additional work must be disclosed and must not make legally required assistance optional or prevent the Customer from meeting mandatory duties.

16. If someone contacts us about their data

People may contact support@alefos.ai without an active account. For a request about processing on the Customer’s behalf, MyBot informs the relevant Customer and assists it, with a clear referral that avoids sending the requester back and forth. MyBot responds on the Customer’s instructions or as required by law. Requests concerning MyBot’s own processing are handled by MyBot as the relevant controller. Identity checks are limited to what is necessary for the request.

17. If there's a data breach

MyBot notifies the Customer without undue delay after becoming aware of a personal data breach affecting data processed on its behalf. Notification is not limited to breaches that MyBot considers likely to require action by the Customer.

Available information includes the nature of the breach, affected data and people, likely consequences, measures taken or proposed and a contact for follow-up. Information may be supplied progressively as the investigation develops. This processor notification is distinct from the Customer’s own duty to notify a supervisory authority within the applicable period.

18. What happens to your data when the contract ends

At the end of the relevant processing services, MyBot returns or deletes personal data at the Customer’s choice, and deletes existing copies unless applicable law requires retention. Making data inaccessible is not, by itself, deletion.

The agreed exit description identifies data returned, formats, retrieval arrangements, active-system deletion and backup cycles. Backups pending expiry remain protected and excluded from ordinary use; if restored for recovery, applicable deletion instructions must be reapplied. Technical constraints do not authorize indefinite retention. Any retention imposed by law is limited to the required data, purpose and period.

Temporary message bodies and ingestion buffers are distinct from final transcripts and structured professional memory. Their respective rules are described in the Data Retention page. Ending a member’s access, disconnecting a provider and terminating the company’s service have different scopes. Contractual export and applicable switching rights remain governed by the Terms and the project agreement without reducing individual data protection rights.

19. Audit rights

MyBot makes available the information necessary to demonstrate compliance with this DPA and allows and contributes to applicable audits, including inspections conducted by the Customer or its mandated auditor.

Reasonable arrangements protect confidentiality, security and other customers’ data and organize scope, notice and frequency. Relevant documentation and independent evidence may support the review, but do not automatically replace an audit right required by law. Trade-secret protection must not empty that right of substance; no certification is claimed unless actually held and applicable.

20. Contacts without an account

An authorized professional interaction may create a contact record without creating an active user account. The Customer determines the lawful purpose and the appropriate information for the person, including where data are collected indirectly.

An exception to individual information must meet the applicable legal conditions; a general Privacy page is not an automatic exemption. This DPA does not commission a sequence of relationship SMS messages or treat such messages as automatically non-marketing. Any communications and the information mechanism must be specified and lawfully authorized for the relevant service. MyBot assists the Customer within its processor obligations.

21. Liability split

Each party is liable for its own breaches. Your communications, your legal bases, your content — your responsibility. Our infrastructure security — our responsibility.

21.1 Each party shall be responsible for its own failures to comply with obligations incumbent on it under Applicable Law.

21.2 The Customer remains solely responsible for the purposes, legal bases, content, communications, messages, calls, and decisions it initiates or operates using the service.

21.3 AlefOS's liability under this DPA is subject to the liability limitations set out in the Terms of Service, except where prohibited by mandatory Applicable Law.

22. Governing law

Same as the Terms of Service: Israeli law, courts of Israel, unless your local mandatory rules say otherwise.

This DPA shall be governed by the law specified in the Terms of Service, unless mandatory data protection law requires otherwise.

Any dispute relating to this DPA shall be subject to the jurisdiction specified in the Terms of Service, subject to any mandatory applicable forum.

23. Final provisions

One bad clause doesn't invalidate the rest. This DPA is active for as long as we process data on your behalf.

23.1 If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in effect.

23.2 This DPA enters into force on the effective date of the contractual relationship between the Customer and AlefOS.

23.3 This DPA remains applicable for as long as AlefOS processes personal data on behalf of the Customer.

The version applicable to an existing agreement is preserved. A draft or revised web page does not amend that agreement on its own. Changes and their effective date follow the applicable contractual and legal requirements.

Legal Center · Terms of Use · Privacy Policy · Cookie & Session Policy · Refund Policy · Data deletion · Subprocessors · Data Retention · Security · Privacy Requests · Legal Notice

Your work, in context.

Your business in ChatGPT and compatible assistants. Your domain, your permissions, continuity of work.

AlefOS
Discuss your project ↗Discover AlefOS ↗

Your environment

+
Discover AlefOSAn assistant for your customersCustomer spaceAI CRMTeam & permissionsDeploymentDeployment & pricing

Everyday work

+
Proposals & quotesDocuments & signaturesIBOX · conversations & follow-upContacts & relationshipsGroups & teamworkCalendar & BookingMissions & responsibilitiesProducts & services

Your connections

+
Your MCP, under your domainWhatsApp BusinessCalls & CallOSCall providersMeeting providersIntegrations

Your industry

+
Real estateSalons & beauty institutesInsurance brokersMaintenance & field serviceConsulting firmsIndustry use casesAll use cases

Explore & get started

+
DocumentationResourcesBlogAI actions & human controlRequest a demoCustomer support

AlefOS operated by MyBot Ltd · mybot.ltd © 2026

View my proposal Client accessLegal CenterPrivacyTerms
Français ↗