This policy describes how Kadin CRM Ltd. (registered in Israel as כדין סי.אר.אם בע"מ) collects, uses, and protects information when you use the Kadin service at kadin.co.il (the "Service"). Questions: support@kadin.co.il.
1. Who we are
The Service is operated and provided by Kadin CRM Ltd. (registered in Israel as כדין סי.אר.אם בע"מ), Company number 515969343 (the "Company", "Kadin" or "we"). This is the legal entity every customer of the Service contracts with.
Privacy and data protection contact: support@kadin.co.il, phone 050-9434400.
2. Information we collect
Account data: name, email address, role, and firm you belong to.
Google or Microsoft sign-in data: the basic profile (name, email, picture) for identification. The optional calendar, files, and mailbox connections are described in the "Optional Google and Microsoft 365 connections" section below.
Firm content: cases, clients, tasks, documents, and correspondence the firm enters or uploads into the Service. This content belongs to the firm, and we hold it on behalf of the firm only.
Usage data: technical logs (IP address, browser, errors) for security and operations.
3. Optional Google and Microsoft 365 connections
Every external connection is optional, is initiated by the user, and can be disconnected at any time. The Service requests a separate permission for each connected service, and only if you have chosen to connect it.
Google Calendar (calendar.events.owned): creating, updating, and deleting the events the Service itself created in your calendar, to keep court hearings and client meetings in sync. The scope is limited to events you own and does not give access to your calendar as a whole.
Google Drive (drive.file): limited access only to files created or opened through Kadin, for editing documents in Google Docs. We do not access, read, or scan any other files in your Drive.
Microsoft 365, calendar (Calendars.ReadWrite): syncing court hearings and meetings with Outlook.
Microsoft 365, mail (Mail.Read): if you have connected a mailbox, the Service only reads the messages in order to display them in the mail screen and to let you file a message and its attachments into a case. Access is read-only: we never send, modify, label, or delete messages.
Microsoft 365, files (Files.ReadWrite): uploading a document you chose to edit and saving it back, for editing in Office on the web.
This data is not used for advertising or sale, and we do not train AI models on it.
You can disconnect any connection at any time from the settings page in the Service, or via https://myaccount.google.com/permissions for Google. Disconnection revokes the tokens in our systems within 24 hours at most.
Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
4. How we use information
To provide the Service and display data your firm has entered.
To maintain, secure, and improve the Service.
To contact you about your account or the Service.
We do not sell personal data, we do not use it for third-party ads, and we do not train AI models on user data or on firm content.
5. Storage & security
Data is stored on secure cloud infrastructure. Traffic is encrypted via TLS/HTTPS.
The application servers, the database and the file storage are all located in the European Union. Files and documents are encrypted at rest to the AES-256 standard.
The tokens for the external connections are encrypted at rest and revoked when the connection is disconnected.
Internal access is role-based and audited.
We run an automated daily backup of the system data and retain the most recent backups (up to 6 copies), for recovery in case of a fault. The backup covers your firm data in the system; uploaded files and documents are not included in this backup, and you are advised to keep your own copy of them.
6. Sharing with third parties
We use infrastructure providers (hosting, storage) that act as sub-processors. We do not share user data for marketing purposes and we do not sell information.
A firm that contracts with us may ask for, and receive, details of the infrastructure and service providers we rely on and of where the data is processed.
Disclosure may be required by binding law; in that case we will notify the firm where the law permits.
7. Data retention & deletion
Data is retained while the account is active.
You may request account deletion by emailing support@kadin.co.il, or start a self-service deletion of the company from the system settings. Data from the external connections (tokens and fields extracted from emails) is removed immediately upon disconnection of the connection or deletion of the account.
On termination of the engagement, firm content is deleted as set out in the Data Processing Addendum, after the firm has been given an opportunity to receive a copy of its data.
8. Your rights under Amendment 13 to the Protection of Privacy Law
Under the Protection of Privacy Law, 1981 (including Amendment 13, which took effect on 14 August 2025), you have the following rights: the right to review the information held about you, the right to correct inaccurate information, the right to erasure (subject to legal retention obligations), and the right to object to direct marketing.
Submit requests to support@kadin.co.il. We respond within 30 days.
For content entered by a client firm, the firm is the database owner (controller) and Kadin is a database holder (processor). A request received from a data subject is passed to the firm for handling, and we assist the firm as set out in the Data Processing Addendum.
9. Client portal, consent, and PDF protection
Access to the client portal is conditional on accepting the privacy policy, the terms of service, and the notice regarding transfer of information to third parties. Your consent is stored with a timestamp and IP address, and when one of these documents is materially updated you will be asked to accept it again.
PDF documents downloaded from the portal are delivered password protected. The password is a 4-digit "personal code" issued to you, which you receive from the firm when you are invited to the portal. You can change the code at any time in the portal settings.
10. Data security and security incidents
The Service operates at the medium security level defined by the Protection of Privacy Regulations (Data Security), 2017, including AES-256 encryption for files, HTTPS with HSTS, audit logs for signatures and super-admin actions, and logical isolation between firms.
In the event of a security incident affecting your information, we will notify you and the Israeli Privacy Protection Authority within 72 hours of discovering the incident, as required by Amendment 13.
11. Children
The Service is not intended for users under 16.
12. Changes & contact
This policy may be updated; the current version is always published at this URL, and a material update presents a new consent screen in the portal on the next sign-in.
Questions: support@kadin.co.il.