This Policy explains how Income Technologies handles personal data connected with Intact. Organizational customers control most equipment and personnel data entered into their workspaces, while we process that data to provide the Service. We do not sell personal data. We use service providers, including hosting and support providers, and may transfer data internationally with appropriate safeguards where required.
Income Technologies Ltd. is an Israeli company that operates Intact, an equipment-management service available through https://intact.systems and related mobile and web applications.
For Account administration, direct sales, billing, AppSumo redemption, security, product analytics, website operations, communications, and our legal obligations, Income Technologies generally acts as a data controller or equivalent responsible business.
For personal data that an organizational Customer enters into its Intact workspace for equipment-management purposes, the Customer generally determines why and how the data is used. In that context, the Customer is generally the controller or business, and Income Technologies acts as its processor or service provider. Individuals should usually direct requests about that Customer-controlled data to the organization that provided or collected it.
This Privacy Policy applies to personal data processed through the Intact websites, registration page, mobile and web applications, customer support, onboarding, direct subscriptions, AppSumo redemptions, and related communications.
It does not apply to third-party websites, AppSumo, app stores, payment processors, Zoom, customer systems, or other third-party services that have their own privacy notices. It also does not replace a Customer's privacy notice to its employees, contractors, volunteers, students, responders, or equipment users.
If a signed agreement or DPA contains more specific data-protection terms, that agreement applies to the extent of a conflict.
Names, work email addresses, phone numbers, organization name, role, language, country, login details, authentication information, Account settings, permissions, billing contacts, and communications preferences.
Equipment identifiers, serial numbers, categories, quantities, descriptions, photos, condition and status, assignment and return records, vault records, repair, wear, loss and disposal records, signatures, timestamps, PDF receipts, expiration dates, notes, user profiles, and other data entered or generated in a Customer workspace. Depending on Customer configuration, this may include employee or contractor identifiers, photographs, signatures, location-related information, qualifications, permits, or other operational records.
IP address, device and browser type, operating system, app version, device identifiers, session information, authentication events, pages and features used, clicks, errors, crash reports, diagnostics, API activity, audit logs, security events, approximate location derived from IP, and network information.
Support requests, emails, messages, screenshots, recordings where disclosed and consented to, meeting details, troubleshooting information, feedback, survey responses, and files or information voluntarily provided during support or onboarding.
Redemption code, AppSumo order or purchase reference, purchased tier, redemption status, purchase and refund status, email address, Account association, fraud-prevention indicators, and communications needed to validate or support the AppSumo Deal. We generally do not receive full payment-card details from AppSumo.
Plan, billing cycle, transaction identifiers, invoices, payment status, tax information, billing address, and limited payment-method details received from our payment processor. Payment providers generally process full payment-card information directly.
Cookie identifiers, consent preferences, referral URLs, campaign information, and website analytics as described below.
Information received when Customer connects an integration, uses single sign-on, purchases through AppSumo, communicates through a support platform, or otherwise authorizes a third party to provide information to us.
Intact is not designed for classified information, state secrets, highly sensitive criminal-investigation data, or restricted defense information unless expressly approved under a signed agreement. Customers should not upload such information to the standard Service.
We collect personal data directly from individuals when they register, use the Service, sign or receive equipment, contact support, attend onboarding, complete forms, or communicate with us.
We collect data from Customers and their Admins when they create user profiles, import records, assign permissions, enter equipment information, or configure workflows.
We collect data automatically through the websites, applications, servers, APIs, logs, cookies, SDKs, and security tools.
We receive limited information from AppSumo, payment processors, app stores, authentication providers, integrations, business partners, and publicly available sources where lawful.
Where the GDPR or UK GDPR applies, we rely on the legal bases described below. The applicable basis depends on the context and our role.
Where we rely on legitimate interests, those interests generally include operating and improving Intact, securing systems, supporting Customers, preventing fraud, enforcing agreements, and conducting ordinary business operations. Individuals may have a right to object as described below.
Organizational Customers are responsible for determining whether they may lawfully collect and use personal data in Intact, providing required privacy notices, selecting lawful bases, responding to individuals, setting permissions and retention, and ensuring data is relevant and accurate.
When we act as a processor or service provider, we process Customer-controlled personal data only to provide and secure the Service, comply with Customer's documented instructions, and meet legal obligations. We do not use such data for unrelated advertising or sell it.
Where required, we will enter into a DPA with the Customer. The DPA may include processing details, confidentiality, security measures, subprocessors, assistance with rights requests, breach notification, deletion or return, audits, and international-transfer clauses.
We disclose personal data only as reasonably necessary for the purposes described in this Policy:
We do not sell personal data for money. We do not share Customer-controlled personal data for cross-context behavioral advertising. If our practices change in a way that creates a statutory sale or sharing right, we will update this Policy and provide required choices before doing so.
We use third-party subprocessors to help provide the Service. A current subprocessor list may be made available on our website or upon request at admin@incometec.co.il.
Where required by a DPA, we will provide notice of material new subprocessors and an opportunity to raise reasonable data-protection objections. We remain responsible for our subprocessors to the extent required by applicable law and contract.
Income Technologies is based in Israel. Personal data may be processed in Israel and in other countries where we, Customers, or service providers operate. Those countries may have different data-protection laws.
Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use recognized safeguards such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful mechanisms, together with supplementary measures where appropriate.
Israel has been recognized by the European Commission as providing an adequate level of protection for certain transfers under EU law, but the availability and scope of any adequacy mechanism may change. We will use an alternative lawful safeguard where required.
Customers are responsible for transfers they initiate, including exports, integrations, Authorized User access from other countries, and uploads to the Service.
We retain personal data only for as long as reasonably necessary for the purposes described, contractual commitments, security, dispute resolution, and legal obligations. Actual periods may vary based on Customer settings, account status, backups, legal holds, and the type of data.
We may retain de-identified or aggregated information that does not reasonably identify an individual. Deletion from backups may occur through normal backup rotation rather than immediate removal from every backup copy.
Depending on location, role, and applicable law, individuals may have rights to request access, confirmation, correction, deletion, restriction, portability, objection, withdrawal of consent, and information about processing. Individuals may also have a right to complain to a data-protection authority.
Individuals may have rights under Articles 15-22, including access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and rights concerning certain automated decisions. We do not currently use Customer Data to make solely automated decisions that produce legal or similarly significant effects on individuals.
If the California Consumer Privacy Act applies, California residents may have rights to know, access, correct, delete, and receive information about categories and sources of personal information, purposes, and recipients, and to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly used. We will not unlawfully discriminate for exercising applicable rights.
Individuals may have rights under Israel's Protection of Privacy Law, 5741-1981, as amended, including rights to inspect personal information held in a database and request correction or deletion where information is inaccurate, incomplete, unclear, or outdated, subject to legal conditions and exceptions.
Send a request to admin@incometec.co.il. Describe the Account, organization, relationship to the data, and request. We may verify identity and authority, request additional information, and retain a record of the request. Authorized agents may be required to provide proof of authority.
If the data is controlled by a Customer, we may refer the request to that Customer or assist it as processor. We may deny or limit requests where permitted, including where identity cannot be verified, an exception applies, or fulfillment would adversely affect others. Appeals or complaints may be submitted through the same contact address where applicable.
We use reasonable technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. Measures may include access controls, role permissions, authentication safeguards, encryption in transit, encryption at rest where supported, logging, monitoring, backups, vulnerability management, provider reviews, confidentiality obligations, and incident-response procedures.
No service is completely secure. Customers must secure their devices, networks, credentials, integrations, exports, and local copies; use appropriate roles; remove departed users; and notify us promptly of suspected compromise.
If we become aware of a confirmed personal-data breach affecting Customer Data, we will notify affected Customers without undue delay where required by law or contract and provide information reasonably available to support their obligations.
We may use cookies, local storage, SDKs, and similar technologies to keep users signed in, remember settings, secure the Service, prevent fraud, diagnose errors, understand use, and improve performance.
Essential technologies are required for authentication, security, preferences, and core operation. Where required, non-essential analytics or marketing technologies will be used only with consent. Cookie controls may be available through a consent banner, browser settings, device settings, or application settings.
Disabling essential technologies may prevent parts of the Service from working. Third-party services may set their own technologies under their privacy policies.
We send transactional and service communications necessary to operate Accounts, including verification, security, billing, support, policy, and feature notices. These are not marketing and may be required while an Account remains active.
We may send marketing communications where permitted. Recipients may unsubscribe through the message or by contacting us. Opting out of marketing does not stop necessary service communications.
Customers are responsible for ensuring they have authority to provide contact details for their Authorized Users and for complying with laws applicable to messages they initiate through or in connection with the Service.
Intact is a business and professional service and is not directed to children under 16. Individuals under 16 must not create Accounts or provide personal data directly to us.
A school or other Customer may use Intact in a context involving minors only if it has a lawful basis, provides required notices, obtains required consent, applies appropriate safeguards, and complies with child-protection and education laws. Such Customers should contact us before entering sensitive data about minors.
If you believe a child provided personal data to us without proper authorization, contact admin@incometec.co.il.
Some browsers transmit "Do Not Track" signals. Because there is no universally accepted standard for responding, the Service may not respond to all such signals. We honor legally required browser-based opt-out signals where applicable to our practices.
We do not use personal data in Intact to make solely automated decisions that produce legal or similarly significant effects on individuals. Customers may make decisions using data in their workspaces, and those decisions are the Customer's responsibility.
We may update this Policy to reflect changes in the Service, law, technology, providers, or business practices. We will post the updated Policy with a revised effective date.
For material changes, we will provide reasonable notice through the Service, email, or another appropriate method. Where consent is legally required for a new use, we will request it before that use.
Individuals in the EEA or UK may complain to the data-protection authority in their place of residence, work, or the alleged infringement. Individuals in Israel may contact the Israeli Privacy Protection Authority where applicable.
If applicable law requires us to appoint an EEA or UK representative, the representative's details will be published in this Policy or made available upon request. The absence of published representative details should not be interpreted as a waiver of rights.
Income Technologies Ltd.
Country: Israel
Email: admin@incometec.co.il
Phone: +972 52 626-0128
Website: https://intact.systems