Date of update: September 2026 | Amendment 13 in force from: 14 August 2025
This is an English translation provided for convenience. The Hebrew version is the operative text and prevails in the event of any discrepancy.
Eran Shemesh, CPA (a licensed sole proprietor, osek murshe), trading as "Shemesh CPA" (שמש רואי חשבון) (hereinafter: "the Firm", "we") respects your privacy and is committed to safeguarding your personal information in accordance with the Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13 (5784-2024), and with the Protection of Privacy Regulations (Data Security), 5777-2017. As certified public accountants we hold financial and particularly sensitive information, and we are therefore bound by strict standards of security and privacy beyond what the law requires.
The Firm maintains the following databases (Amendment 13 abolished the registration requirement for private bodies that are not data brokers — registration is not required of a private CPA):
Professional client databaseFinancial, accounting and business information of clients, required for performance of the service contract. Marketing leads databaseEnquiry information from the website (name, telephone, email) — on the basis of express consent. Direct mail databaseFor the purpose of marketing and professional updates — on the basis of optional consent only. Legal compliance databaseReports to the tax authorities, the National Insurance Institute and the Registrar of Companies — a legal obligation.We use your personal information for the following purposes only:
In accordance with Amendment 13, we undertake not to use the information for purposes other than those defined, without your express consent.
Fundamental principle: we undertake not to disclose, sell or transfer the personal information to third parties, except:
The engagement with an external provider that processes personal information on behalf of the Firm is subject to the requirements of Regulation 15, including the provider's undertaking to keep the information secure and to use it only for the purposes of the engagement.
Cross-border transfer mechanisms (Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001):| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Dynadot | USA | Registration and management of the domain name shecpa.co.il | Legitimate interest |
| Name.com | USA | Registration of additional domains | Legitimate interest |
| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Netlify | USA | Hosting and publication of the website, receipt of enquiries from the forms and recording of cookie consent choices | Legitimate interest |
| Google Analytics (Google LLC) | USA | Statistical analysis of website use (including IP address and device identifiers) and aggregated age, gender and interest statistics (Google Signals); and, only for visitors who choose "Accept all", Google personalised advertising and remarketing | Consent (cookie banner) |
| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Google Workspace | USA / EU | Email, documents, calendar, Drive — client communications | Performance of a contract / legitimate interest |
| Zapier | USA | Automation of work processes (transfer of leads) | Legitimate interest |
| Make.com | EU (Czech Republic) | Advanced automation of business processes | Legitimate interest |
| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Claude (Anthropic) | USA | Streamlining writing, analysis, assistance with professional tasks | Legitimate interest |
| ChatGPT (OpenAI) | USA | Streamlining writing, analysis, assistance with professional tasks | Legitimate interest |
| Gemini (Google) | USA / EU | Streamlining writing, analysis, assistance with professional tasks | Legitimate interest |
| Manus AI | USA | Automation of administrative tasks | Legitimate interest |
| Grok (xAI) | USA | Content analysis and internal information processing | Legitimate interest |
| DeepSeek | China | Content analysis — without the transfer of identifying personal information | Not applicable — no transfer of personal information |
| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Instantly.ai | USA | Sending marketing emails only to people who have given express consent to direct mail | Consent |
| WhatsApp (Meta) | USA / EU | Receiving and answering enquiries you send us on WhatsApp | Enquiry initiated by the data subject |
| WbizTool | Israel / EU | Sending marketing WhatsApp messages | Consent |
| NewOaks.ai | USA | AI chatbot for lead management | Consent / legitimate interest |
| Meta Forms (Facebook / Instagram) | USA / EU | Lead forms on social networks | Consent |
| Provider | Country | Purpose | Legal basis |
|---|---|---|---|
| Finbot | Israel | Management of client files and accounting documents | Performance of a contract |
| Yesh Heshbonit (Invoice Maven) | Israel | Issuing invoices and managing fiscal documents | Performance of a contract |
| Ardeni | Israel | Payroll management and payslips | Performance of a contract |
| Qonto | EU (France) | Business account and payment management | Performance of a contract |
| Morning | Israel | Business financial management, invoices, expenses | Performance of a contract |
| Hashavshevet | Israel | Bookkeeping software and tax reporting | Performance of a contract |
| Summit | Israel | Client management and work processes | Performance of a contract |
The information transferred to the providers below includes financial and sensitive data. The engagement with them is subject to the requirements of Regulation 15, and the providers are required to apply security measures appropriate to the sensitivity of the information.
In accordance with the requirements of the Auditors Law, the Income Tax Ordinance, the Value Added Tax Law and the Protection of Privacy Law:
| Accounting documents and books (bookkeeping, reports, invoices) | 7 years |
| Payslips and payroll files | 7 years |
| Tax returns, assessments, objections | 7 years from filing |
| Service contracts with clients | 7 years from termination |
| Marketing leads (that did not become clients) | 3 years / until consent is revoked |
| Website technical data (cookies, logs, Google Analytics) | Up to 14 months |
| Requests to exercise rights (access, deletion) | 3 years (evidentiary) |
Information required in order to comply with a legal obligation will be retained for as long as required, including after the end of the business relationship.
We implement the following security measures:
In accordance with the Protection of Privacy Regulations (Data Security), 5777-2017, the Firm's databases are classified at a Medium security level — determined by virtue of the holding of sensitive financial information and a marketing database numbering more than 10,000 records.
In accordance with the Protection of Privacy Law and the Protection of Privacy (Data Security) Regulations, 2017, in the event of a severe security incident we undertake:
In accordance with the Law, you are entitled to exercise the following rights — a response within 30 days:
Right of access (Section 13)To receive a copy of the information held about you in our databases, in Hebrew, English or Arabic at your choice. A written request with identifying documentation must be submitted. Right of correction (Section 14)To request the correction of information that is incorrect, incomplete or not up to date. Right of deletionTo request the deletion of information — subject to statutory retention obligations (7 years for accounting documents). Objection to processing (offered by us)To object to marketing processing at any time, at no cost. Receiving the information in a structured format (offered by us)To receive a structured copy of your information in a machine-readable format. Withdrawal of consent (Section 8C — Amendment 13)To withdraw consent to any processing given on the basis of consent, at any time — withdrawing consent shall be as simple as giving it. Removal from direct mail (Section 17F)To demand removal from the direct mail database — the Firm is obliged to remove and to confirm. Click "Unsubscribe" in any message or contact us directly.The website uses cookies for the purpose of:
You can change or withdraw consent at any time via the "Cookie settings" button at the bottom of the website. Withdrawing consent stops the analytics and deletes the Google Analytics cookies from your browser.
The Privacy Protection Coordinator is responsible for the Firm's compliance with the requirements of the Protection of Privacy Law and for handling enquiries from data subjects.
Eran Shemesh also serves as the Information Security Officer in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017.
Telephone: 052-4485784
Email: shemesh@shecpa.co.il
Address: Dizengoff 148, Tel Aviv
Response hours: Sunday–Thursday, 07:00–20:30
For enquiries to the Privacy Protection Authority: gov.il/privacy
You may also contact us through the data rights request form
on the website.
Version 4.1 (Amendment 13 + Regulation 15) | Shemesh CPA | Updated September 2026
English homeExercise your data rightsEnglish-speaking accountantHebrew version