גיוסית
המערכתProduct יכולות AIAI מחיריםPricing שאלות נפוצותFAQ
התחברותSign in חודש ניסיון חינםFree trial month
חזרה לדף הביתBack to home

מדיניות פרטיות — גיוסית

גרסה 1.4
תאריך עדכון: 9 בספטמבר 2026


מסמך זה מסביר איזה מידע גיוסית אוספת, איפה הוא נשמר, מי עוד רואה אותו ומה הזכויות שלך. הוא מנוסח בשפה פשוטה ופונה אליך — הלקוח שמשתמש במערכת.

ספק השירות: גיוסית, עוסק מורשה 313129785
פניות בנושא פרטיות: support@giusit.com
וואטסאפ: 052-6206724

לגיוסית אין כתובת פיזית לפרסום. כל פנייה מתקבלת בערוצים שלמעלה.

מסמך זה קיים גם באנגלית. בכל מקרה של סתירה בין הנוסחים — הנוסח העברי גובר.


1. מידע שאנחנו אוספים עליך

אתה נכנס לגיוסית באמצעות חשבון Google שלך בלבד. אין במערכת סיסמאות, ואנחנו לא מבקשים ממך ליצור סיסמה.

בעת ההתחברות אנחנו מקבלים מגוגל טוקן זהות מאומת, וקוראים ממנו ארבעה פרטים בלבד:

  • מזהה המשתמש שלך אצל גוגל
  • כתובת האימייל שלך (רק אם היא מאומתת אצל גוגל)
  • השם שלך
  • כתובת תמונת הפרופיל שלך

אלה הפרטים שמתקבלים בהתחברות. אנחנו לא מבקשים גישה לתיבת הדואר שלך או לאנשי הקשר שלך, ולא בונים עליך פרופיל התנהגותי.

בשליחת משוב מתוך המערכת נשלחים אלינו הטקסט שכתבת, שמך, כתובת המייל שלך, שם הארגון ומזהה הארגון, שם המסך שממנו נשלח המשוב ומועד השליחה. המידע משמש לטיפול בפנייה, למענה ולשיפור המערכת. אין צירוף אוטומטי של קורות חיים או פרטי מועמדים; מומלץ לא לכלול אותם בטקסט המשוב.

המשוב מועבר דרך Gmail API לחשבון הדואר של גיוסית. הרשאת השליחה היא של חשבון גיוסית בלבד, ואין בקשת הרשאת Gmail מהמשתמשים. לא נשמר עותק של המשוב בבסיס הנתונים של המערכת או ביומני היישום; עותקי דואר נשמרים בחשבון גיוסית ומעובדים על ידי Google. רענון העמוד מוחק טיוטת משוב שלא נשלחה.

2. מידע על מועמדים

גיוסית אינה יוזמת איסוף מידע על מועמדים. אנחנו לא סורקים לוחות דרושים, לא רוכשים מאגרי מועמדים ולא פונים למועמדים ביוזמתנו. כל המידע על מועמדים מגיע ממך — אתה מזין אותו למערכת או מעלה קובץ שממנו הוא חולץ.

המידע שניתן לשמור על מועמד:

  • שם
  • כתובת אימייל
  • מספר טלפון
  • מיקום
  • תפקיד
  • תפקיד קודם
  • מיומנויות, ותק מקצועי וניסיון ניהולי
  • תקציר קורות חיים
  • קישור לפרופיל לינקדאין
  • קובץ קורות חיים

בנוסף, אתה יכול לסמן מועמד כחסום ולציין סיבה בטקסט חופשי. הסיבה נשמרת בדיוק כפי שכתבת אותה — אנחנו לא בודקים אותה, לא מסננים אותה ולא מפרשים אותה. שים לב שכל מה שתכתוב בשדה הזה נשמר כמידע על אדם מזוהה, ובאחריותך לוודא שהוא ענייני ורלוונטי לתהליך הגיוס.

3. התפקידים המשפטיים — מי בעל המידע ומי מחזיק בו

  • אתה בעל המאגר. המידע על המועמדים הוא שלך. אתה קובע איזה מידע להזין, לשם מה הוא משמש, כמה זמן הוא נשמר ומתי הוא נמחק.
  • גיוסית היא מחזיקת המאגר. אנחנו מאחסנים ומעבדים את המידע עבורך בלבד, לפי ההוראות שלך ולצורך הפעלת השירות.

אנחנו מצהירים במפורש:

  • גיוסית אינה עושה שימוש עצמאי במידע המועמדים שלך לשום מטרה משלה.
  • גיוסית אינה מאחדת מידע בין ארגונים ואינה בונה מאגר מועמדים חוצה־לקוחות.
  • גיוסית אינה משתמשת במידע המועמדים שלך לאימון מודלים.
  • אנחנו לא מוכרים מידע ולא משתפים אותו עם צדדים שלישיים, למעט ספקי המשנה המפורטים בסעיף 11 ולמעט חובה שבדין.

פנייה של מועמד: אם מועמד יפנה אלינו ישירות בבקשה לעיין במידע עליו, לתקן אותו או למחוק אותו — נפנה אותו אל הלקוח שהעלה את המידע, ונעדכן אותך על כך. אנחנו לא נמחק ולא נשנה מידע במאגר שלך על סמך פנייה של מועמד בלי הוראה ממך.

4. בידוד בין ארגונים

הבידוד בין ארגונים אצלנו לא נשען על קוד האפליקציה בלבד. הוא נאכף בתוך בסיס הנתונים עצמו, באמצעות מנגנון Row Level Security של PostgreSQL, במצב כפוי (FORCE), על כל טבלה שמחזיקה מידע של ארגון.

המשמעות המעשית: גם אם תהיה שגיאה בקוד השאילתה, בסיס הנתונים עצמו לא יחזיר שורה ששייכת לארגון אחר, ולא יאפשר לכתוב או לעדכן שורה של ארגון אחר. גם למשתמש בסיס הנתונים של האפליקציה עצמו אין מעקף — זו המשמעות של המצב הכפוי.

מדיניות הבידוד הזו מגובה בבדיקות אוטומטיות שרצות על כל שינוי בקוד לפני פריסה, ובבדיקת אימות ייעודית שמריצה שני ארגונים זה מול זה מול בסיס נתונים אמיתי ומוודאת שאף אחד מהם אינו רואה, מעדכן או יוצר מידע של האחר.

5. אחסון קובצי קורות חיים

קובצי קורות החיים אינם נשמרים בבסיס הנתונים ואינם נשמרים על שרת האפליקציה. הם נשמרים בדלי אחסון פרטי בשירות Cloudflare R2, באזור מזרח אירופה (EEUR).

  • הדלי פרטי. אין לקבצים כתובת ציבורית ואין להם קישור גלוי שניתן לשתף.
  • הדפדפן שלך לעולם אינו פונה ישירות לשירות האחסון. כל בקשה עוברת דרך השרת שלנו, שחותם אותה מולו בעצמו.
  • שם האובייקט באחסון אטום — הוא מורכב ממזהים אקראיים ואינו מכיל את שם המועמד, את שם הקובץ המקורי או כל פרט מזהה אחר.
  • בבסיס הנתונים נשמרים רק מטא־דאטה — שם הקובץ המקורי, סוג הקובץ, גודלו, ו־checksum מסוג SHA-256 שמאפשר לזהות שינוי או פגיעה בקובץ.
  • כל הורדה עוברת אימות הרשאה מול בסיס הנתונים לפני שהקובץ נשלף מהאחסון. אם למשתמש אין הרשאה לאותו מועמד, השרת לא פונה בכלל לשירות האחסון.

6. עיבוד באמצעות בינה מלאכותית — גילוי מלא

כאשר אתה בוחר להעלות קובץ קורות חיים לחילוץ פרטים אוטומטי, או להפעיל התאמת מועמדים למשרה או משרות למועמד, מידע מקצועי נשלח לשירות של חברת Anthropic, הפועל מחוץ לישראל.

מה בדיוק נשלח:

  • חילוץ פרטים מ־CV — קובץ PDF נשלח במלואו; מקובץ DOCX מחולץ אצלנו טקסט ורק הטקסט נשלח.
  • התאמת מועמדים למשרה — נשלחים תיאור המשרה ועד 60 כרטיסים מקצועיים של מועמדים שנבחרו לאחר סריקה מקומית של המאגר. השרת מסיר כתובות אימייל, מספרי טלפון, קישורים ופרטי קשר מהקטעים שנשלחים. קובץ קורות חיים מלא אינו נשלח בפעולה זו.
  • התאמת משרות למועמד — נשלחים הנתונים המקצועיים בכרטיס וטקסט שחולץ מקורות החיים, לאחר סינון פרטי קשר, לצורך ניתוח מקצועי וחיפוש משרות פתוחות בארגון. תיאורי המשרות שאותרו והמידע המקצועי נשלחים לדירוג. מגבלות קריאת קובץ מוצגות בתוצאה. קובץ קורות החיים עצמו אינו נשלח בפעולה זו.

המידע נשלח אך ורק לצורך חילוץ פרטים או דירוג התאמה מקצועית. בחיפוש מועמדים למשרה הנתונים המקצועיים שהושלמו נשארים זמניים ואינם נכתבים לכרטיסי המועמדים. רק הבדיקה האחרונה שהושלמה נשמרת בכרטיס המשרה, עם תאריך, ציונים, נימוקים ופערים. היא מוחלפת בבדיקה הבאה שהושלמה, גם אם אין בה התאמות, או נמחקת עם המשרה. פרטי קשר וזמינות קורות החיים נקראים מהכרטיסים העדכניים; מועמד שנמחק אינו מוצג בתוצאות. סגירת הכרטיס אינה מבטלת בדיקה שכבר החלה. בחיפוש משרות למועמד, הפעלת הבדיקה מאשרת גם השלמה אוטומטית של שדות מקצועיים ריקים בכרטיס מתוך קורות החיים. ערכים קיימים, אימייל, טלפון ו־LinkedIn אינם מוחלפים או מושלמים. רק הבדיקה האחרונה שהושלמה נשמרת בכרטיס, עם תאריך, ציונים, נימוקים, פערים ומצב קריאת הקובץ. היא מוחלפת בבדיקה הבאה שהושלמה או נמחקת עם המועמד. נתוני שימוש וחיוב נשמרים בנפרד ואינם כוללים היסטוריית דירוגים. למשרות נשמרים תיאור פנימי ואינדקס חיפוש המתעדכנים מהנתונים שהוזנו. השימוש נעשה דרך ממשק בתשלום שבו התוכן שנשלח אינו משמש לאימון מודלים.

בחילוץ לצורך יצירת מועמד, התוצאה היא טיוטה בלבד. היא מוצגת לבדיקה, ורשומת מועמד נוצרת במערכת רק אחרי שאישרת אותה. אם לא אישרת — לא נוצרת רשומה.

אם אינך מעוניין שקורות חיים יישלחו לעיבוד חיצוני, אל תשתמש בחילוץ האוטומטי; אפשר להזין מועמד ידנית ולהעלות את הקובץ בלי חילוץ.

7. קבצי ייבוא זמניים

קובץ שהעלית לחילוץ אוטומטי נשמר תחילה כאובייקט זמני ונפרד, ולא כקובץ של מועמד. תוקפו פג בתוך 24 שעות ממועד ההעלאה, ואחריהן לא ניתן עוד להשתמש בו.

הקובץ הזמני נמחק בכל אחד מהמצבים הבאים:

  • ביטול — ביקשת לבטל את הייבוא.
  • כישלון — החילוץ נכשל מכל סיבה שהיא.
  • אישור — אישרת את הטיוטה; במקרה זה נוצר עותק קבוע תחת המועמד החדש, והעותק הזמני נמחק.

8. שימור ומחיקה של מידע

  • המידע נשמר כל עוד החשבון שלך פעיל.
  • מחיקה מתבצעת לפי בקשתך. פנה אלינו ל־support@giusit.com.
  • נשלים את המחיקה בתוך 30 יום ממועד קבלת הבקשה.
  • המחיקה כוללת גם את קובצי קורות החיים באחסון, ולא רק את הרשומות בבסיס הנתונים.
  • מחיקה מגיבויים אינה מיידית — היא מתרחשת במחזור הגיבויים הבא (ראה סעיף 9).

9. גיבויים

בשלב זה גיוסית אינה מפעילה מנגנון גיבוי עצמאי משלה מעבר לעמידות התשתית של ספקי האירוח והאחסון (ראה סעיף 11). איננו מצהירים על יעד שחזור או על תדירות גיבוי, ואיננו יכולים להתחייב לשחזור מידע שנמחק. כאשר יופעל מנגנון גיבוי, נעדכן מסמך זה ונפרסם גרסה חדשה שלו.

10. עוגיות

המערכת משתמשת בשתי עוגיות תפקודיות בלבד:

עוגייהתפקידמאפיינים
עוגיית התחברותשומרת שאתה מחובר בין עמודיםHttpOnly, SameSite=Lax, תוקף שבעה ימים
עוגיית הזמנהזמנית — מחזיקה הזמנה לצוות עד להשלמת ההצטרפותHttpOnly, SameSite=Lax, נמחקת בסיום התהליך

עוגיית ההתחברות מסומנת HttpOnly, כלומר קוד JavaScript בדפדפן אינו יכול לקרוא אותה. בסביבת הייצור שתי העוגיות מסומנות גם Secure ונשלחות רק על גבי חיבור מוצפן.

אין במערכת עוגיות פרסום, אין מעקב ואין כלי אנליטיקה. איננו משתמשים ב־Google Analytics, בפיקסלים של רשתות חברתיות או בכל כלי מדידה חיצוני.

האתר השיווקי (giusit.com) אינו מפעיל שרת, אינו מכיל טפסים ואינו אוסף עליך מידע כלשהו. היעד החיצוני היחיד שהוא פונה אליו הוא שירות הגופנים של גוגל (Google Fonts), שמקבל את כתובת ה־IP של המבקר כחלק מבקשת הגופן.

11. ספקי משנה

לצורך הפעלת השירות אנחנו נעזרים בספקים הבאים:

ספקתפקידמיקום
Googleזיהוי והתחברות (Google OAuth), העברת משוב ואחסונו בדואר גיוסית (Gmail)מחוץ לישראל
Anthropicחילוץ פרטים מקורות חיים והתאמת מועמדים למשרותמחוץ לישראל
Cloudflare R2אחסון קובצי קורות חייםמזרח אירופה (EEUR)
Stripeסליקת תשלומיםמחוץ לישראל
Renderאירוח השרת ובסיס הנתוניםמחוץ לישראל
Google Fontsהגשת גופנים באתר השיווקימחוץ לישראל

המידע שלך מאוחסן ומעובד גם מחוץ לישראל. השימוש בשירות מהווה הסכמה להעברה זו. Stripe מקבל את כתובת האימייל שלך לצורך יצירת חשבון החיוב וזיהוי התשלום; Stripe אינו מקבל מידע על מועמדים.

12. אבטחת מידע

להלן אמצעי האבטחה שמיושמים בפועל. איננו מצהירים על אמצעים שאינם קיימים:

  • בידוד ברמת בסיס הנתונים — Row Level Security כפוי, כמתואר בסעיף 4.
  • עוגיית התחברות HttpOnly — אינה נגישה לקוד JavaScript בדפדפן, ומסומנת Secure בסביבת הייצור.
  • אימות סוג הקובץ וחתימתו לפני קבלה — מתקבלים רק קובצי PDF ו־DOCX. אנחנו בודקים שסיומת הקובץ, סוג התוכן המוצהר וחתימת הבתים בתחילת הקובץ מסכימים ביניהם. קובץ שמנסה להתחזות לסוג אחר נדחה.
  • אחסון פרטי — קובצי קורות החיים אינם נגישים מהאינטרנט הפתוח, כמתואר בסעיף 5.
  • אימות הרשאה לפני כל הורדה — מול בסיס הנתונים, לפני פנייה לאחסון.
  • checksum מסוג SHA-256 לכל קובץ שנשמר.
  • התקשורת מול שירות האחסון נכפית להיות מוצפנת (HTTPS) ברמת הקוד.

מה איננו מצהירים: איננו מצהירים על הצפנת מידע במנוחה מעבר להצפנה שספקי האירוח והאחסון מספקים בעצמם, ואיננו מצהירים על עמידה בתקן אבטחה או בהסמכה כלשהי.

13. אירוע אבטחה

אם ייוודע לנו על אירוע אבטחה שנוגע למידע שלך, נודיע לך על כך בתוך 72 שעות מרגע שנודע לגיוסית על האירוע. ההודעה תכלול את מה שידוע לנו באותו שלב: מה קרה, איזה מידע מעורב, ומה הצעדים שאנחנו נוקטים.

מכיוון שאתה בעל המאגר, האחריות להודיע למועמדים או לרשויות — ככל שנדרשת — היא שלך. אנחנו נספק לך את המידע שברשותנו כדי לאפשר לך לעשות זאת.

14. הזכויות שלך ושל המועמדים

לך ולמועמדים שבמאגר שלך יש זכות עיון במידע, זכות תיקון של מידע שגוי וזכות מחיקה.

הנתיב למימוש הזכויות:

  • מועמד פונה אל הלקוח שהעלה את המידע עליו — כלומר אליך. אתה בעל המאגר ואתה זה שיכול לעיין, לתקן ולמחוק.
  • לקוח פונה אל גיוסית בכתובת support@giusit.com. נטפל בבקשתך ונשיב לך בתוך 30 יום.

אם מועמד יפנה אלינו ישירות, נפנה אותו אליך כמתואר בסעיף 3.

15. שינויים במדיניות זו

אם נשנה מדיניות זו, נעדכן את מספר הגרסה ואת תאריך העדכון בראש המסמך. שינוי מהותי — למשל הוספת ספק משנה חדש או שינוי במטרות השימוש במידע — יפורסם מראש.

16. יצירת קשר

לכל שאלה בנושא פרטיות, לבקשת עיון, תיקון או מחיקה:

  • אימייל: support@giusit.com
  • וואטסאפ: 052-6206724
  • ספק השירות: גיוסית, עוסק מורשה 313129785

Privacy Policy — Giusit

Version 1.4
Last updated: 9 September 2026


This document explains what information Giusit collects, where it is stored, who else sees it, and what your rights are. It is written in plain language and addresses you — the customer who uses the system.

Service provider: Giusit, licensed dealer (osek murshe) 313129785
Privacy enquiries: support@giusit.com
WhatsApp: 052-6206724

Giusit has no physical address for publication. All enquiries are received through the channels above.

This document also exists in Hebrew. In any case of conflict between the two versions, the Hebrew version prevails.


1. Information we collect about you

You sign in to Giusit using your Google account only. There are no passwords in the system, and we never ask you to create one.

When you sign in, we receive a verified identity token from Google and read four details from it, and nothing else:

  • Your Google user identifier
  • Your email address (only if Google has verified it)
  • Your name
  • Your profile picture URL

These are the details received at sign-in. We do not request access to your mailbox or contacts, and we do not build a behavioural profile of you.

When you send feedback from the application, we receive your text, name, email address, organisation name and identifier, the name of the screen from which you sent it, and the submission time. We use this information to handle and reply to your feedback and improve the system. CVs and candidate details are not attached automatically; please avoid including them in your feedback.

Feedback is sent through the Gmail API to Giusit's mailbox. Sending permission belongs only to Giusit's account; users are not asked for Gmail permission. No copy of the feedback is stored in the application's database or logs. Email copies are retained in Giusit's account and processed by Google. Reloading the page discards an unsent feedback draft.

2. Information about candidates

Giusit does not initiate the collection of candidate information. We do not scrape job boards, we do not purchase candidate databases, and we do not contact candidates on our own initiative. All candidate information comes from you — you enter it into the system, or you upload a file from which it is extracted.

The information that can be stored about a candidate:

  • Name
  • Email address
  • Phone number
  • Location
  • Role
  • Previous role
  • Skills, professional seniority, and management experience
  • CV summary
  • LinkedIn profile link
  • CV file

In addition, you can mark a candidate as blacklisted and state a reason in free text. The reason is stored exactly as you wrote it — we do not review it, filter it, or interpret it. Note that whatever you write in that field is stored as information about an identifiable person, and it is your responsibility to ensure it is factual and relevant to the recruitment process.

3. Legal roles — who owns the database and who holds it

  • You are the database owner. The candidate information is yours. You decide what information to enter, what it is used for, how long it is kept, and when it is deleted.
  • Giusit is the database holder. We store and process the information for you alone, according to your instructions and for the purpose of operating the service.

We state explicitly:

  • Giusit makes no independent use of your candidate information for any purpose of its own.
  • Giusit does not combine information between organisations and does not build a cross-customer candidate pool.
  • Giusit does not use your candidate information to train models.
  • We do not sell information and do not share it with third parties, other than the subprocessors listed in section 11 and other than where required by law.

Enquiries from candidates: if a candidate contacts us directly asking to access, correct, or delete information about themselves, we will refer them to the customer who uploaded that information, and we will notify you. We will not delete or modify information in your database on the basis of a candidate's enquiry without an instruction from you.

4. Isolation between organisations

Isolation between organisations here does not rely on application code alone. It is enforced inside the database itself, using PostgreSQL Row Level Security in forced (FORCE) mode, on every table that holds organisation data.

What this means in practice: even if there were a bug in a query, the database itself will not return a row belonging to another organisation, and will not allow writing to or updating another organisation's row. Even the application's own database user has no bypass — that is what forced mode means.

This isolation policy is backed by automated tests that run on every code change before deployment, and by a dedicated verification check that runs two organisations against each other on a real database and confirms that neither can read, update, or create the other's data.

5. Storage of CV files

CV files are not stored in the database and are not stored on the application server. They are stored in a private storage bucket on Cloudflare R2, in the Eastern Europe (EEUR) region.

  • The bucket is private. The files have no public address and no shareable visible link.
  • Your browser never contacts the storage service directly. Every request goes through our server, which signs the request against storage itself.
  • The object name is opaque — it is composed of random identifiers and contains neither the candidate's name, nor the original filename, nor any other identifying detail.
  • Only metadata is stored in the database — the original filename, the file type, its size, and a SHA-256 checksum that allows a change to or corruption of the file to be detected.
  • Every download passes an authorisation check against the database before the file is retrieved from storage. If the user is not authorised for that candidate, the server does not contact the storage service at all.

6. AI processing — full disclosure

When you choose to upload a CV file for automatic detail extraction, or run a candidate search for a job or a job search for a candidate, professional information is sent to a service operated by Anthropic, located outside Israel.

Exactly what is sent:

  • CV detail extraction — a PDF file is sent in full; for DOCX, text is extracted on our side and only that text is sent.
  • Finding candidates for a job — the job description and up to 60 professional candidate cards selected through a local database search are sent. The server removes email addresses, phone numbers, links, and contact details from the excerpts. A full CV file is not sent for this operation.
  • Finding jobs for a candidate — professional profile data and text extracted from the CV, with contact details filtered out, are sent for professional analysis and retrieval of open jobs within the organisation. The shortlisted job descriptions and professional evidence are then sent for ranking. Reading limitations are shown with the result. The CV file itself is not sent.

The information is sent solely for detail extraction or professional matching. When finding candidates for a job, completed professional fields remain temporary and are not written to candidate profiles. Only the last completed check is retained on the job, including its date, scores, reasons and gaps. It is replaced by the next completed check, including an empty result, or deleted with the job. Contact details and CV availability are read from current profiles; deleted candidates are not shown in results. Closing the profile does not cancel a check that has already started. When finding jobs for a candidate, starting the check also authorises filling empty professional profile fields from the CV. Existing values, email, phone and LinkedIn are not replaced or completed. Only the last completed check is retained on the candidate, including its date, scores, reasons, gaps and CV reading status. It is replaced by the next completed check or deleted with the candidate. Separate usage and billing records do not contain a history of rankings. Internal job descriptions and search indexes are derived from and kept in sync with the supplied job data. The service is used through a paid interface under which the content sent is not used to train models.

For extraction that creates a candidate, the output is a draft only. It is presented for review, and a candidate record is created in the system only after you have approved it. If you do not approve it, no record is created.

If you do not want CVs sent for external processing, do not use automatic extraction; you can enter a candidate manually and upload the file without extraction.

7. Temporary import files

A file you upload for automatic extraction is first stored as a separate, temporary object — not as a candidate's file. It expires within 24 hours of upload, after which it can no longer be used.

The temporary file is deleted in each of the following cases:

  • Cancellation — you asked to cancel the import.
  • Failure — the extraction failed for any reason.
  • Approval — you approved the draft; in this case a permanent copy is created under the new candidate, and the temporary copy is deleted.

8. Retention and deletion

  • Information is retained for as long as your account is active.
  • Deletion is performed at your request. Contact us at support@giusit.com.
  • We will complete the deletion within 30 days of receiving the request.
  • The deletion covers the CV files in storage as well, not only the database records.
  • Deletion from backups is not immediate — it occurs in the next backup cycle (see section 9).

9. Backups

At this stage Giusit does not operate its own independent backup mechanism beyond the infrastructure resilience provided by our hosting and storage providers (see section 11). We make no claim about a recovery objective or a backup frequency, and we cannot undertake to restore deleted information. When a backup mechanism is activated, we will update this document and publish a new version of it.

10. Cookies

The system uses two functional cookies only:

CookiePurposeAttributes
Session cookieKeeps you signed in between pagesHttpOnly, SameSite=Lax, seven-day lifetime
Invitation cookieTemporary — holds a team invitation until joining is completeHttpOnly, SameSite=Lax, deleted when the process ends

The session cookie is marked HttpOnly, meaning JavaScript running in the browser cannot read it. In the production environment both cookies are also marked Secure and are sent only over an encrypted connection.

There are no advertising cookies, no tracking, and no analytics tools. We do not use Google Analytics, social network pixels, or any external measurement tool.

The marketing site (giusit.com) runs no server, contains no forms, and collects no information about you. The only external destination it contacts is Google's font service (Google Fonts), which receives the visitor's IP address as part of the font request.

11. Subprocessors

We rely on the following providers to operate the service:

ProviderRoleLocation
GoogleIdentity and sign-in (Google OAuth); delivery and storage of feedback in Giusit's mailbox (Gmail)Outside Israel
AnthropicExtraction of CV details and candidate-to-job matchingOutside Israel
Cloudflare R2CV file storageEastern Europe (EEUR)
StripePayment processingOutside Israel
RenderServer and database hostingOutside Israel
Google FontsServing fonts on the marketing siteOutside Israel

Your information is stored and processed outside Israel as well. Use of the service constitutes consent to this transfer. Stripe receives your email address in order to create the billing account and identify the payment; Stripe does not receive candidate information.

12. Security

The following security measures are implemented in practice. We do not claim measures that do not exist:

  • Database-level isolation — forced Row Level Security, as described in section 4.
  • HttpOnly session cookie — not accessible to JavaScript in the browser, and marked Secure in the production environment.
  • File type and signature validation before acceptance — only PDF and DOCX files are accepted. We verify that the file extension, the declared content type, and the byte signature at the start of the file all agree. A file attempting to pose as a different type is rejected.
  • Private storage — CV files are not reachable from the open internet, as described in section 5.
  • An authorisation check before every download — against the database, before storage is contacted.
  • A SHA-256 checksum for every stored file.
  • Communication with the storage service is forced to be encrypted (HTTPS) at the code level.

What we do not claim: we make no claim of encryption at rest beyond that provided by our hosting and storage providers themselves, and we make no claim of compliance with any security standard or certification.

13. Security incidents

If we become aware of a security incident affecting your information, we will notify you within 72 hours of the moment Giusit became aware of the incident. The notification will include what is known to us at that point: what happened, what information is involved, and what steps we are taking.

Because you are the database owner, the responsibility to notify candidates or the authorities — to the extent required — is yours. We will provide you with the information in our possession to enable you to do so.

14. Your rights and candidates' rights

You and the candidates in your database have the right of access to the information, the right to correct inaccurate information, and the right to deletion.

The route for exercising these rights:

  • A candidate contacts the customer who uploaded their information — that is, you. You are the database owner and you are the one who can access, correct, and delete.
  • A customer contacts Giusit at support@giusit.com. We will handle your request and respond within 30 days.

If a candidate contacts us directly, we will refer them to you as described in section 3.

15. Changes to this policy

If we change this policy, we will update the version number and the update date at the top of the document. A material change — for example adding a new subprocessor or changing the purposes for which information is used — will be published in advance.

16. Contact

For any privacy question, or a request for access, correction, or deletion:

  • Email: support@giusit.com
  • WhatsApp: 052-6206724
  • Service provider: Giusit, licensed dealer (osek murshe) 313129785
גיוסית
המערכתProduct מחיריםPricing שאלות נפוצותFAQ יצירת קשרContact תנאי שימושTerms of Service מדיניות פרטיותPrivacy Policy
© 2026 גיוסית