Legal

Data Processing Addendum (database holder)

Effective 2026-07-30

This addendum governs the processing of personal data that a firm using the Kadin service (the database owner) entrusts to Kadin CRM Ltd. (כדין סי.אר.אם בע"מ), company number 515969343, Israel (the database holder), in accordance with the Protection of Privacy Law, 1981, including Amendment 13, and the Protection of Privacy Regulations (Data Security), 2017. The addendum forms an integral part of the Terms of Service and is accepted together with them when the account is opened. The Hebrew version of these documents is the authoritative one and prevails in case of any discrepancy with this translation.

1. Parties and definitions

Database holder (processor): Kadin CRM Ltd. (registered in Israel as כדין סי.אר.אם בע"מ), Company number 515969343.

Database owner (controller): the firm or business that contracts with Kadin and enters data into the Service.

"Personal data" means any information about an identified or identifiable person that the database owner enters or uploads into the Service, including client details, cases, documents, and correspondence.

2. Scope and purpose of processing

Kadin processes the personal data solely for the purpose of providing the Service to the database owner and in accordance with its documented instructions.

Kadin will not use the data for its own purposes, will not sell it, will not use it for advertising, and will not use it to train artificial intelligence models.

Categories of data subjects include, among others, the firm's clients, contacts, firm staff, and parties involved in cases.

3. Obligations of the database holder

To process the data only to the extent and for the period required to provide the Service.

To apply the security measures set out in section 5 and to update them as risks evolve.

Not to transfer the data to any third party, other than the infrastructure and service providers required to operate the Service, which are bound by equivalent confidentiality and security undertakings, or under binding law.

To assist the database owner in meeting its obligations towards data subjects and towards the Israeli Privacy Protection Authority.

4. Confidentiality of staff and authorized users

Every employee, contractor, or service provider acting for Kadin who may have access to the data has signed a written personal confidentiality undertaking towards the database owner and its clients, which is unlimited in time and continues to apply after the engagement with them ends. A copy of the undertaking will be provided to the database owner on request.

Access is limited on a need-to-know basis and managed through permissions.

Entry by Kadin staff into a firm's environment takes place through a dedicated access mechanism that records every entry: the identity of the person entering, the firm, the user account that was entered, the IP address, the time the access began, and the time it ended. The record is retained and is not deleted. Access takes place only for technical support the firm has requested, or to fix a fault preventing delivery of the Service, and in the narrowest scope possible.

Kadin acknowledges that some of the data is covered by attorney-client privilege, and technical access for support purposes does not constitute a waiver of that privilege.

5. Data security measures

Traffic encryption with TLS/HTTPS and HSTS, and AES-256 encryption of files in storage.

Logical isolation between the data of different firms, enforced at the database access layer, and enforcement of user-level permissions within each firm.

Audit logs for sensitive actions, including digital signatures, system administration actions, and support logins into a firm's environment.

Automated daily backup retaining up to the 6 most recent copies, for recovery in case of a fault.

Sign-in to the Service is performed with the user's Google or Microsoft account, so the password and authentication policy of the firm's own organisation applies to signing in to Kadin as well. In the client portal a dedicated password policy is enforced, alongside sign-in with a one-time code.

6. Infrastructure and service providers

In order to operate the Service, Kadin relies on infrastructure and service providers (storage, hosting, email delivery and the like), each of them bound by confidentiality and security undertakings equivalent to those in this addendum.

The database owner may ask for, and receive, details of these providers and of where they process the data. Notice of a material change will be given to the database owner, who may object and terminate the engagement if the objection is not resolved.

7. Location of data storage

The application servers, the database and the storage holding the database owner's files and documents are all located in the European Union.

Some of the infrastructure and service providers we rely on also operate outside Israel. Transfers of data to them are made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 2001, and subject to appropriate contractual undertakings. Details will be provided to the database owner on request.

8. Security incidents and reporting

On the occurrence of a serious security incident concerning the data of the database owner, Kadin will notify the database owner and the Israeli Privacy Protection Authority within 72 hours of discovering the incident.

The notice will describe the nature of the incident, the categories of data exposed as far as known, the steps taken to contain it, and recommendations for what follows.

Kadin will cooperate with the database owner in any clarification, investigation, or report required as a result of the incident.

9. Assistance with data subject rights

A request from a data subject that reaches Kadin directly will be forwarded to the database owner and will not be answered by Kadin independently.

Kadin will assist the database owner in giving effect to rights of review, correction, and erasure, through the export and deletion tools in the Service and through support, within a time frame that allows the database owner to meet the deadlines prescribed by law.

10. Audit and oversight

The database owner may request, once a year and on reasonable notice, information and documents about the security measures and about Kadin compliance with this addendum.

Kadin will respond in writing, and will allow a further audit where a reasonable suspicion of a breach of this addendum has arisen.

11. Return and deletion of data at the end of the engagement

On termination of the engagement, and for 30 days afterwards, the database owner may export its data: exporting cases and clients to an Excel file from the Service, downloading documents, and contacting support for a copy of the remaining data.

At the end of that period the data is deleted from Kadin systems, including the files in storage. Backup copies containing the data are deleted during the routine backup cycle.

At the request of the database owner, written confirmation that deletion has been completed will be provided.

12. Term, precedence, and contact

This addendum applies for as long as Kadin processes personal data for the database owner. In any conflict between this addendum and the Terms of Service on a data protection matter, this addendum prevails.

Data protection enquiries: support@kadin.co.il, phone 050-9434400.