SHEMESH CPA

Privacy Policy

Updated for Amendment 13 to the Protection of Privacy Law

Date of update: September 2026 | Amendment 13 in force from: 14 August 2025

This is an English translation provided for convenience. The Hebrew version is the operative text and prevails in the event of any discrepancy.

Eran Shemesh, CPA (a licensed sole proprietor, osek murshe), trading as "Shemesh CPA" (שמש רואי חשבון) (hereinafter: "the Firm", "we") respects your privacy and is committed to safeguarding your personal information in accordance with the Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13 (5784-2024), and with the Protection of Privacy Regulations (Data Security), 5777-2017. As certified public accountants we hold financial and particularly sensitive information, and we are therefore bound by strict standards of security and privacy beyond what the law requires.

1Principal Definitions

"Personal information"Any datum relating to an identified person or to an identifiable person, including financial, accounting, business and commercial information. "Sensitive information" (in the professional sense)Financial information, accounting documents, bank details, business standing — subject to a Medium security level in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017. This definition is distinct from "sensitive information" as defined by statute under the Law (health, criminal record, sexual orientation and the like). "Database owner / operator"Eran Shemesh, CPA, trading as Shemesh CPA, as defined in the Protection of Privacy Law. "Processing of information"Any act or series of acts performed on personal information — collection, storage, use, transfer, deletion. "Outsourcing provider (Regulation 15)"An external party that processes personal information on behalf of the Firm. The engagement with it is subject to the requirements of Regulation 15.

2Databases and Bases of Processing

The Firm maintains the following databases (Amendment 13 abolished the registration requirement for private bodies that are not data brokers — registration is not required of a private CPA):

Professional client databaseFinancial, accounting and business information of clients, required for performance of the service contract. Marketing leads databaseEnquiry information from the website (name, telephone, email) — on the basis of express consent. Direct mail databaseFor the purpose of marketing and professional updates — on the basis of optional consent only. Legal compliance databaseReports to the tax authorities, the National Insurance Institute and the Registrar of Companies — a legal obligation.

The types of information we collect:

3Purposes of the Processing of Information

We use your personal information for the following purposes only:

Purpose limitation:

In accordance with Amendment 13, we undertake not to use the information for purposes other than those defined, without your express consent.

4Transfer of Information to Third Parties

Fundamental principle: we undertake not to disclose, sell or transfer the personal information to third parties, except:

5Outsourcing Providers — Regulation 15 of the Protection of Privacy Regulations

In accordance with Regulation 15 of the Protection of Privacy Regulations (Data Security), 5777-2017:

The engagement with an external provider that processes personal information on behalf of the Firm is subject to the requirements of Regulation 15, including the provider's undertaking to keep the information secure and to use it only for the purposes of the engagement.

Cross-border transfer mechanisms (Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001):

Domain Registrars

ProviderCountryPurposeLegal basis
DynadotUSARegistration and management of the domain name shecpa.co.ilLegitimate interest
Name.comUSARegistration of additional domainsLegitimate interest

Hosting and Infrastructure

ProviderCountryPurposeLegal basis
NetlifyUSAHosting and publication of the website, receipt of enquiries from the forms and recording of cookie consent choicesLegitimate interest
Google Analytics (Google LLC)USAStatistical analysis of website use (including IP address and device identifiers) and aggregated age, gender and interest statistics (Google Signals); and, only for visitors who choose "Accept all", Google personalised advertising and remarketingConsent (cookie banner)

Cloud & Productivity

ProviderCountryPurposeLegal basis
Google WorkspaceUSA / EUEmail, documents, calendar, Drive — client communicationsPerformance of a contract / legitimate interest
ZapierUSAAutomation of work processes (transfer of leads)Legitimate interest
Make.comEU (Czech Republic)Advanced automation of business processesLegitimate interest

Artificial Intelligence (AI) Models

ProviderCountryPurposeLegal basis
Claude (Anthropic)USAStreamlining writing, analysis, assistance with professional tasksLegitimate interest
ChatGPT (OpenAI)USAStreamlining writing, analysis, assistance with professional tasksLegitimate interest
Gemini (Google)USA / EUStreamlining writing, analysis, assistance with professional tasksLegitimate interest
Manus AIUSAAutomation of administrative tasksLegitimate interest
Grok (xAI)USAContent analysis and internal information processingLegitimate interest
DeepSeekChinaContent analysis — without the transfer of identifying personal informationNot applicable — no transfer of personal information
AI governance and human oversight — Amendment 13 + guidelines of the Privacy Protection Authority:

Marketing and Client Generation

ProviderCountryPurposeLegal basis
Instantly.aiUSASending marketing emails only to people who have given express consent to direct mailConsent
WhatsApp (Meta)USA / EUReceiving and answering enquiries you send us on WhatsAppEnquiry initiated by the data subject
WbizToolIsrael / EUSending marketing WhatsApp messagesConsent
NewOaks.aiUSAAI chatbot for lead managementConsent / legitimate interest
Meta Forms (Facebook / Instagram)USA / EULead forms on social networksConsent

Professional Software for Certified Public Accountants

ProviderCountryPurposeLegal basis
FinbotIsraelManagement of client files and accounting documentsPerformance of a contract
Yesh Heshbonit (Invoice Maven)IsraelIssuing invoices and managing fiscal documentsPerformance of a contract
ArdeniIsraelPayroll management and payslipsPerformance of a contract
QontoEU (France)Business account and payment managementPerformance of a contract
MorningIsraelBusiness financial management, invoices, expensesPerformance of a contract
HashavshevetIsraelBookkeeping software and tax reportingPerformance of a contract
SummitIsraelClient management and work processesPerformance of a contract

The information transferred to the providers below includes financial and sensitive data. The engagement with them is subject to the requirements of Regulation 15, and the providers are required to apply security measures appropriate to the sensitivity of the information.

6Retention of Information — Retention Policy by Type (CPA)

In accordance with the requirements of the Auditors Law, the Income Tax Ordinance, the Value Added Tax Law and the Protection of Privacy Law:

Accounting documents and books (bookkeeping, reports, invoices)7 years
Payslips and payroll files7 years
Tax returns, assessments, objections7 years from filing
Service contracts with clients7 years from termination
Marketing leads (that did not become clients)3 years / until consent is revoked
Website technical data (cookies, logs, Google Analytics)Up to 14 months
Requests to exercise rights (access, deletion)3 years (evidentiary)

Information required in order to comply with a legal obligation will be retained for as long as required, including after the end of the business relationship.

7Information Security

We implement the following security measures:

Security level classification:

In accordance with the Protection of Privacy Regulations (Data Security), 5777-2017, the Firm's databases are classified at a Medium security level — determined by virtue of the holding of sensitive financial information and a marketing database numbering more than 10,000 records.

8Security Incidents and Reporting

In accordance with the Protection of Privacy Law and the Protection of Privacy (Data Security) Regulations, 2017, in the event of a severe security incident we undertake:

9Your Rights in the Personal Information (Amendment 13)

In accordance with the Law, you are entitled to exercise the following rights — a response within 30 days:

Right of access (Section 13)To receive a copy of the information held about you in our databases, in Hebrew, English or Arabic at your choice. A written request with identifying documentation must be submitted. Right of correction (Section 14)To request the correction of information that is incorrect, incomplete or not up to date. Right of deletionTo request the deletion of information — subject to statutory retention obligations (7 years for accounting documents). Objection to processing (offered by us)To object to marketing processing at any time, at no cost. Receiving the information in a structured format (offered by us)To receive a structured copy of your information in a machine-readable format. Withdrawal of consent (Section 8C — Amendment 13)To withdraw consent to any processing given on the basis of consent, at any time — withdrawing consent shall be as simple as giving it. Removal from direct mail (Section 17F)To demand removal from the direct mail database — the Firm is obliged to remove and to confirm. Click "Unsubscribe" in any message or contact us directly.

How to exercise your rights:

  1. Send a written request to the email address shemesh@shecpa.co.il with the subject: "Request to exercise a privacy right".
  2. Include your name, contact details and a detailed description of the request. We will contact you to verify your identity, asking only for what is proportionate to the type of request.
  3. Alternatively, use the online form on the website.
  4. We will handle your enquiry within 30 days as required by law.
  5. If the request is refused, you are entitled to appeal to the Privacy Protection Authority.

10Cookies and Tracking

The website uses cookies for the purpose of:

You can change or withdraw consent at any time via the "Cookie settings" button at the bottom of the website. Withdrawing consent stops the analytics and deletes the Google Analytics cookies from your browser.

11Privacy Protection Coordinator (DPO) and Contact

Privacy Protection Coordinator: Eran Shemesh

The Privacy Protection Coordinator is responsible for the Firm's compliance with the requirements of the Protection of Privacy Law and for handling enquiries from data subjects.

Eran Shemesh also serves as the Information Security Officer in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017.

Telephone: 052-4485784

Email: shemesh@shecpa.co.il

Address: Dizengoff 148, Tel Aviv

Response hours: Sunday–Thursday, 07:00–20:30

For enquiries to the Privacy Protection Authority: gov.il/privacy

You may also contact us through the data rights request form

on the website.

Version 4.1 (Amendment 13 + Regulation 15) | Shemesh CPA | Updated September 2026

English homeExercise your data rightsEnglish-speaking accountantHebrew version