Back to home

Privacy Policy

Last updated: August 12, 2026

1. Introduction

Welcome to the Privacy Policy of “build it up” (the “System,” “Website,” “we,” “us,” or “our”), operated by Elad Kofman, trading as Otef Digital Agency (the “Company” or “Operator”).

build it up provides businesses and individuals (the “Users” or “Website Owners”) with a platform for creating, editing, managing, and hosting websites and landing pages. The System also enables the management of Leads and inquiries. The Service is available at builditup.io and its subdomains, on which customer websites are also hosted.

This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with the Israeli Privacy Protection Law, 5741–1981 and the regulations issued under it — including Amendment No. 13 to the Privacy Protection Law, which took effect in August 2025 — and other applicable Israeli privacy requirements.

Important distinction: We act as a data controller in relation to User accounts, payments, support, security, and use of build it up. In relation to Leads, inquiries, and Visitor content collected through customer websites, the Website Owner is the controller responsible for determining the purposes of processing, while we act as its infrastructure provider/data processor, subject to the Data Processing Agreement (DPA).

Please note: This Policy is a notice explaining how information is handled; browsing does not create blanket consent. Where a specific activity requires consent, we request a separate, clear, and freely given choice.

2. Information We Collect

2.1 Information Provided by System Users

  • Registration details: full name, email address, and phone number
  • Business details: business name, field of activity, logo, and images
  • User-uploaded content: text, images, videos, and documents for Users’ websites
  • Consent records: the date and time Terms and Privacy Policy were accepted, the document version, source of acceptance, and basic security data
  • Domain details, website settings, User permissions, edit history, and operational data required to provide the Service
  • Payment information, where applicable, which is processed by secure payment providers

2.2 Information from Visitors to Customer Websites

When Visitors submit forms on customer websites, the System may store and process information such as name, phone number, email address, inquiry content, custom fields, IP address, browser information, the URL of the page from which the inquiry was submitted, and a record of consent to submit the form. This information is stored for the Website Owner and transferred to it so that it can respond to the inquiry.

The Website Owner is responsible for presenting appropriate privacy notices to its Visitors, obtaining required consents, using Leads in accordance with law, and responding to its Visitors’ requests for access, correction, or deletion. build it up will assist the Website Owner through reasonable measures and subject to the capabilities of the System.

2.3 Information Collected Automatically

  • IP address and device and browser information
  • Usage and analytics data
  • Cookies and similar identifiers
  • Approximate geographic location

2.4 Information Received from Third Parties

We may receive information from external service providers, such as authentication, analytics, and advertising providers, but only to the extent required to operate and improve the System.

2.5 ChatGPT, Claude, and AI Application Connections

When a User connects an AI application to a build it up account through a secure connector or MCP, we receive the account identity, connection and permission details, and the data that the application sends with each tool call—for example, a request to read a website, edit content, create a campaign, or review Leads. We also retain an operational and security record of the action, such as its time, action name, result, duration, credit usage, and information needed to diagnose failures and prevent misuse.

The connector does not give us automatic access to the User’s full conversation history, personal memory, or other conversations in the external application. We process only information the application explicitly sends to perform an action in the account. Action results are returned to the connected application, and infrastructure, storage, model, or media providers receive information only to the extent needed to perform the requested action and subject to their applicable agreements and safeguards.

Access tokens are protected and retained until expiry or revocation. Action records are retained for as long as needed for security, support, billing, dispute handling, and legal compliance. A connected application can be disconnected from the System’s connections screen; disconnection prevents future token use but does not erase business information lawfully created in the account before disconnection. Requests for access, correction, or deletion can be submitted using the contact details in Section 7.

2.6 Google Connections and Google User Data

Connecting Google services is optional and starts only after the User gives explicit consent on Google’s authorization screen. Basic account details—identifier, name, and email address—identify and display the connected account. For Calendar, we read the calendar list to identify the selected calendar and display, create, update, and delete only events on calendars the User owns, so meetings, reminders, and availability managed in the System stay synchronized.

For connected Google marketing tools, Google Analytics access is read-only and is used to read properties, traffic, and conversion reports; Search Console access is read-only and is used to read verified sites, queries, pages, and search performance; and Google Ads access is used to show accessible accounts, read campaign performance, and create or change Search campaigns requested by the User. New campaigns are created paused with no spend. Activation, pausing, or budget changes require explicit in-product confirmation.

Connection tokens are encrypted and stored on the server. Access is limited to the authorized User and System services needed for synchronization, measurement, or an approved action, and can be revoked at any time in the System or in the User’s Google account. After disconnection, the System performs no new operations in the Google account. We do not sell Google data, use it for unrelated advertising, or build marketing profiles for another party.

Our use of raw or derived data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve, or train generalized artificial-intelligence models. When a User requests AI-assisted scheduling or marketing insights, only the minimum data needed to provide that user-facing feature is used, and not to train a generalized model.

2.7 Meta, Facebook, and Instagram Connections

Connecting Meta is optional and starts only after the User actively accepts our connection disclosure and then approves the request on Meta’s authorization screen. We do not receive the Facebook or Instagram password. Depending on the assets and permissions selected by the User, we may receive the connected account identifier and name, accessible Facebook Pages, professional Instagram accounts, ad accounts and pixels, approved permissions, access tokens, content data, metrics, and campaign results needed to provide the marketing tools.

We use this information to show available assets, bind the exact Page and account to the business, prepare content, publish content the User requested or approved, read performance, and manage campaigns according to the User’s choices. Connecting by itself does not publish content, activate a campaign, or create spend. A new campaign created by the System is saved paused with no spend until the separate confirmation required for activation or a budget change.

Access tokens are encrypted on the server; the browser receives only the names and identifiers needed to select an asset. We also retain consent evidence containing the accepted wording and versions, a server timestamp, and limited security data. The connection can be revoked in the System or in Meta settings. After revocation we perform no new actions, although lawful records, security evidence, and previously created outputs may be retained in accordance with Section 9.

Information sent to or received from Meta is also governed by the Meta Privacy Policy and the terms applicable to its business and developer tools. The User must connect only assets it is authorized to manage and ensure that customer content, audience, and data use is lawful. We do not sell Meta data or use it to train a generalized artificial-intelligence model.

3. How We Use Information

We use collected information for the following purposes:

  • Providing the System’s services, including website creation and hosting
  • Managing User accounts and verifying identity
  • Communicating with Users, including technical support and service notices
  • Improving the System and developing new features
  • Securing the System and preventing misuse
  • Complying with legal and regulatory requirements
  • Retaining evidence of consent, handling complaints, enforcing the Terms of Use, and defending against claims or misuse
  • Storing Leads and inquiries for Website Owners and sending email notifications to the Website Owner or its designated representative
  • Statistical analysis and research using anonymous or aggregated data

4. Information Security

We implement advanced security measures to protect information, including:

  • Encryption in transit (SSL/TLS) and at rest
  • Controlled and authenticated access to systems
  • Continuous monitoring for suspicious activity
  • Periodic backups and information recovery
  • Secure servers operated under stringent security standards

However, it is important to clarify: despite our extensive efforts, no computer system is completely immune from intrusion or failure. We cannot guarantee absolute security of information.

5. Sharing Information with Third Parties

We may share information with third parties in the following circumstances:

  • Service providers: hosting, analytics, payment-processing, and support providers acting on our behalf
  • Website Owners: when a Visitor submits a Lead or inquiry through a customer website, the information is transferred to the Website Owner or the person managing the website on its behalf
  • Legal requirements: in response to a court order, a demand by a competent authority, or a legal obligation
  • Protection of rights: to prevent fraud, protect safety, and enforce the Terms of Use
  • Business transfers: in connection with a merger, acquisition, or transfer of assets

We do not sell personal information to third parties for marketing purposes.

6. Responsibility for User Content and Hosted Websites

Material provision — please read carefully:

6.1 The System is a technical platform for hosting and creating websites and landing pages for its Users. Users and Website Owners are responsible for content and publication decisions within their control.

6.2 Subject to applicable law, Otef Digital Agency and build it up are not responsible for outcomes directly caused by User content or actions in the following areas:

  • Content uploaded by Users to their websites
  • The accuracy, reliability, legality, or trustworthiness of that content
  • Infringement of copyright, trademarks, or intellectual property
  • Offensive, misleading, inciting, or unlawful content
  • Damage caused to third parties by content on Hosted Websites
  • The collection and processing of Visitors’ personal information by Website Owners

6.3 Website Owners using the System undertake to comply with all applicable laws, including the Israeli Privacy Protection Law, the Defamation (Prohibition) Law, the Copyright Law, and every other applicable law.

6.4 Website Owners who collect information from Visitors through their websites are responsible for obligations that apply to them as controllers, including obtaining required consents, publishing their own privacy policy, and enabling the exercise of data rights.

6.5 Initial Content, text, images, marketing proposals, and legal templates that we may provide to a Customer are intended only as a basis for customization. The Customer is responsible for reviewing their accuracy, legality, and suitability for its business before publication or use.

6.6 This allocation of responsibility does not reduce the System’s obligations under applicable law for its own processing, information security, and delivery of the Service.

7. Data Subject Rights

Subject to the Israeli Privacy Protection Law, the regulations issued under it, and the circumstances of the processing, you may have the following rights:

  • Access: to review personal information held about you
  • Correction or deletion: to request correction or deletion of information that is inaccurate, incomplete, unclear, or out of date, under the conditions set by law
  • Direct marketing: to request removal from direct-marketing communications
  • Withdrawal: to withdraw consent for future optional processing, subject to applicable exceptions
  • Additional rights: deletion, objection, or portability apply only where provided by the law governing the relevant processing

To exercise your rights, email us at support@builditup.io.

7.1 Privacy Inquiries (Amendment 13)

A dedicated channel for privacy inquiries and the exercise of data rights is available at support@builditup.io (please include “Privacy Inquiry” in the subject line).

8. Cookies

The System uses cookies and local storage for operation, security, and saved choices. Optional measurement, marketing, and external content run only after an explicit choice.

  • Strictly necessary: core operation and authentication
  • Functional: preferences and selections
  • Measurement: Umami, Google Analytics, and Vercel Analytics when configured and permitted
  • Marketing and external content: pixels, videos, forms, and social embeds when configured and permitted
  • Maps: Google Maps or OpenStreetMap remain available as functional content, load lazily, and may share IP address, referrer, and basic browser data with the provider

You can change your selection through “Privacy preferences” in the footer. Blocking necessary browser storage may impair sign-in and core operation.

9. Data Retention

We retain personal information for as long as necessary for the purposes for which it was collected or as required by law:

  • Active account information — for as long as the account remains active
  • After account closure — for up to 7 years for backup and legal requirements
  • Evidence of consent and legal records — for the period required for legal defense, compliance, and dispute management
  • Leads and inquiries from customer websites — while the website or Website Owner’s account remains active, unless deleted upon request or as required by law
  • Pseudonymous event-level analytics — for up to 26 months; display caches are retained for a shorter period

Information may remain in backups or logs for a limited transition period after deletion from the management interface, subject to our security and recovery policies.

10. Minors

The System is intended only for adult Users aged 18 or older. We do not knowingly collect information from minors. If we learn that information has been collected from a minor, we will act promptly to delete it.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be published on the Website and/or communicated through an appropriate notice. If a change requires new consent, it will be requested separately and will not be inferred merely from continued browsing.

12. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of the State of Israel. Proceedings shall be brought before the court that has jurisdiction under applicable law. Where the law permits the parties to agree on venue and the engagement is not a consumer transaction, venue shall be in the Southern District unless the parties agree otherwise in writing.

13. Contact Us

For questions or requests concerning this Privacy Policy, contact us at:

build it up — operated by Elad Kofman, trading as Otef Digital Agency

Email: support@builditup.io

Phone: 055-996-6472

Business hours: Sunday–Thursday, 9:00 AM–6:00 PM

Location: Kerem Shalom, Israel