Shapes – Privacy Policy
Last updated: 26 August 2026
This Privacy Policy describes how DreamTeam HR Apps Ltd. d/b/a Shapes (collectively with its affiliates, “Shapes”, “we”, “our” or “us”), collects, stores, uses and discloses personal data of individuals (”you” or “your”) who:
- Visit or otherwise interact with our website (the “Site”) including emails and communications in relation to the Site, and any online content and advertisements, our events, webinars or marketing channels, or who express interest in Shapes as prospective customers, prospective users or prospective business partners (collectively, “Visitors” and “Prospects”);
- Interact with the Shapes Solution (“Solution”, and together with the Site, the “Services”) including business contact persons of our prospective or current customers, business partners, and service providers (collectively, “Business Contacts”).
When we process personal data about Business Contacts for our own purposes – for example, to authenticate Business Contacts, to provide and bill the Services, to communicate with the Customer about its account, to secure the Solution, to comply with our legal obligations, and to improve the Services – we act as an independent controller of that data and this Privacy Policy applies.
Please note that this Privacy Policy does NOT cover our privacy practices with respect to individuals who use the Solution under the direction of our Customers ("End Users"). The personal data that Customers and their End Users submit to, or that is generated within, the Solution ("Customer Personal Data") is processed by us as a processor on the Customer's behalf, in accordance with their instructions and the terms of our Data Processing Agreement (the "DPA"). This Privacy Policy should be read together with our Terms of Use and the DPA.
Specifically, this Privacy Policy describes our practices regarding:
If you are a Visitor, Prospect or Business Contact, please read this Privacy Policy carefully and make sure that you fully understand it.
You are not legally required to provide us with any personal data and may do so (or avoid doing so) at your own free will. However, please keep in mind that without it, we may not be able to provide you with the full range of the Services or deliver the best user experience. If you do not wish to provide us with your personal data, or to have it processed by us, please do not provide it to us and avoid visiting or interacting with our Services.
1. Data Collection & Processing
“Personal data” (or “personal information” under certain data protection laws) is any information that identifies, relates to, describes an individual or that is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual. It does not include aggregated, de-identified or anonymized information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual.
Specifically, we may collect, disclose or otherwise process the following types of personal data in relation to the Services:
- Business Contact Details: Name, business email address, business phone number, employer/organization, job title. We process contact details to manage our business relationship with you, and account support purposes.
- Account Credentials- login and authentication data: user IDs, login credentials, authentication tokens, multi-factor authentication identifiers, single sign-on identifiers. We process this data to create and secure your account.
- Billing and Payment Data: Information necessary to negotiate, conclude, administer and bill our agreements with Customers and Prospects, including signatory details, billing contact details, purchase orders, invoices, payment status and contractual records. We do not store full payment-card numbers; payment processing is performed by our payment-services Service Providers.
- Site Usage Data: This includes connectivity, technical and aggregated usage data related to your interaction with our Site – including IP addresses and approximate location derived from them, device data (such as type, operating system, device ID, browser type and version, location and language settings), date/time stamps, the cookies and pixels installed or used on our Site and/or your device, and recorded activity (sessions, page views, clicks and other interactions) in connection with the Site and Solution. We process this data to operate, secure and troubleshoot the Services and analyze and improve performance of our Services.
- Communications data: Personal data contained in our communications with you – including emails, inquiries, support tickets, transcripts of our phone and video conference calls, feedback, testimonials and survey responses, and interactions through social media channels. We process this data to provide you with support relating to the Services and to improve our Services.
How we collect personal data
- Directly from you through your interactions with us or our Services: When you fill in a web form, request a demo, register for an account, contact our sales or support teams, attend an event or webinar, subscribe to marketing communications, or otherwise communicate with us, you provide us with personal data directly.
- Automatically through your interaction with the Services: When you visit our Site or use the Solution, we automatically collect certain data through cookies and other tracking technologies (as further described in Section 6 below)
- From the Customer: When a Customer engages our Services, the Customer’s administrators may provide us with your contact details and account configuration to provision you as a Business Contact, billing contact, signatory or other Customer point of contact.
- From third parties and public sources: We may receive personal data about you from third party services, social media and other business initiatives. For the purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), the categories of personal information we have collected in the preceding twelve (12) months include: identifiers; commercial information; customer record information; internet or other electronic network activity information; geolocation data (approximate); audio, electronic, visual or similar information (call/video recordings, where applicable); professional or employment-related information; and inferences drawn from the foregoing. We do not knowingly collect sensitive personal information for the purpose of inferring characteristics about consumers.
2. Data Uses & Lawful Bases for Processing
We process personal data as described in this Privacy Policy for the purposes set out in the table below – for the performance of our Services and/or contractual obligations (“Performance of a Contract”); to comply with our legal obligations (“Legal Obligations”); to support our legitimate interests in maintaining and improving our Services, e.g. in understanding how our Services are used and how our campaigns are performing, and gaining insights which help us dedicate our resources and efforts more efficiently; in promoting our Services; providing customer services and technical support; and protecting and securing our Visitors, Business Contacts, ourselves and our Services (“Legitimate Interests”); or with your consent (“Consent”) when applicable, such as to inform you about offers and products in which you have expressed interest. Where the EU GDPR, UK GDPR or another framework requires identification of a lawful basis, we rely on the lawful basis indicated in the right-hand column. Where more than one basis is shown, we rely on the most appropriate one in the circumstances.
If you reside or are interacting with the Services in a territory governed by privacy laws under which “consent” is the only or most appropriate legal basis for processing personal data as described in this Privacy Policy, we will seek your consent in the manner required by applicable law. Under the EU GDPR and UK GDPR, where we rely on consent, we obtain it through a clear affirmative action. You may withdraw consent at any time by contacting us at [email protected]
Specifically, we collect and use personal data (including in the last 12 months) for the following purposes (and in reliance on the legal bases for processing noted next to them, as appropriate):
| Purpose | Lawful bases for processing |
|---|---|
| To invoice and process payments | Performance of a Contract |
| To facilitate, operate, enhance, and provide usage of our Services and all related features and functions | Performance of a Contract Legitimate Interests |
| To provide you with assistance and support, to test and monitor the Services, diagnose or fix technical issues | Performance of a Contract Legitimate Interests |
| To personalize our Services, including by recognizing an individual and remembering their information when they return to our Services, and to provide further localization and personalization capabilities | Performance of a Contract Legitimate Interests |
| To explore and pursue growth opportunities by facilitating a stronger local presence and tailored experiences | Performance of a Contract Legitimate Interests |
| To contact you with general or personalized service-related messages (such as password retrieval or billing issues), as well as promotional messages that may be of specific interest to you | Performance of a Contract Consent Legitimate Interests |
| To gain a better understanding on how individuals evaluate, use, and interact with our Services, to utilize such information to continuously improve our Services, offerings, and the overall performance, user-experience and value generated therefrom | Legitimate Interests |
| To create aggregated, statistical data, inferred non-personal data or anonymized or pseudonymized data (de-identified data), which we or others may use to provide and improve our respective Services, or for any other business purpose | Legitimate Interests |
| To enforce our Terms and agreements, resolve disputes, and protect our business interests and the interests and rights of third parties | Legitimate Interests |
| To support and enhance our data security measures, including for the purposes of preventing and mitigating the risks of fraud, error or any illegal or prohibited activity | Legal Obligations Performance of a Contract Legitimate Interests |
| To comply with our contractual and legal obligations and requirements, and maintain our compliance with applicable laws, regulations and standards | Legal Obligations Performance of a Contract Legitimate Interests |
| To facilitate and optimize our marketing campaigns, ad management and sales operations, and to manage and deliver advertisements for our Services more effectively, including on other websites and applications. | Consent Legitimate Interests |
| To facilitate, sponsor and offer certain events, webinars and promotions | Legitimate Interests Consent |
| For any other lawful purpose that you consent to in connection with the provisioning our Services | Legal Obligations Consent |
Artificial intelligence and machine learning
In our capacity as a controller of Visitor, Prospect and Business Contact Data, we may, where applicable, use AI and machine-learning to detect security anomalies, abuse and fraud, to assist our teams in handling support and sales enquiries, and for analytics and service-improvement relating to our Site.
Our use of AI on Customer Personal Data is governed by the DPA and AI Modules Schedule, not this Policy. Where AI features are powered by third-party AI providers (for example, large-language-model providers), those providers act as our Service Providers under contractual obligations of confidentiality and data protection. To the extent that we train or fine-tune models (for example, our own product-usage data), we do so in accordance with applicable law and we remove any personal data prior to such use.
3. Data Disclosure
We disclose personal data only as described in this Privacy Policy in the following instances:
- Service Providers: We engage selected third-party service providers to provide services on our behalf or complementary to our own – including hosting and storage, content delivery, security and fraud detection and prevention, monitoring and observability, provision/maintenance/improvement of the Site, customer relationship management, support and ticketing, billing and payment processing, communications (call and session recording services, email, text messages and notification distribution), performance management, e-signature, data optimization and marketing, social and advertising networks, data enrichment providers, and our legal, financial and compliance advisors and auditors (“Service Providers”). Service Providers may have access to personal data only to the extent needed to perform their services for us and may only use the data as determined in our agreements with them.
- Service Integrations: Some Solution features rely on integrations with third-party services chosen and configured by the Customer (for example, productivity, CRM, marketing, analytics, advertising, identity and storage providers). When a Business Contact connects an integration, certain data may be transmitted between the Solution and the third-party service. The third-party provider’s processing of that data is governed by its own terms and privacy notice.
- Legal Compliance and Protecting rights and Safety: We may be required to disclose personal data to government, regulatory or law-enforcement authorities, or to other third parties, in response to a subpoena, court order, warrant or other valid legal process, or where we believe in good faith that disclosure is required by law, is appropriate to investigate or prevent fraud, abuse or illegal activity, or is necessary to protect the rights, property or personal safety of Shapes, our personnel, visitors, Business Contacts or the general public.
- Affiliates and Organizational Changes: We may share personal data with our parent, subsidiaries and affiliates, for the purposes described in this Privacy Policy. If Shapes undergoes a corporate change in control or ownership such as a merger, acquisition, reorganization of all or part of our business, sale of assets, or insolvency, personal data may be disclosed with parties involved in such an event. Where the change materially affects how your personal data is processed, we will notify you of this event and the choices you may have as required by applicable law.
- With Your Consent or at Your Direction: We may disclose personal data in additional ways with your express consent or at your direction.
Shapes only discloses personal data to third parties that demonstrate that they provide the necessary measures to safeguard the security of the personal data they process.
For the purposes of the CCPA, in the past 12 months, we may have disclosed the following categories of personal information to the recipients listed above: identifiers; commercial information; customer record information; internet or other electronic network activity information; geolocation data; and inferences. We did so in pursuit of the business and commercial purposes described in Section 2 above
4. Data Location
We operate internationally and the personal data we process may be transferred to, and processed in, countries other than your country of residence. These other countries may have data-protection laws that are different from those of your country. We are committed to protect personal data in accordance with this Privacy Policy and customary industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction from or to which such personal data is transferred.
We and our Service Providers maintain, store and process personal data in Israel, the European Economic Area, the United Kingdom, the United States and other locations where our Service Providers operate as reasonably necessary for the proper performance of the Services or as required by law.
Where personal data originating in the European Economic Area (“EEA”), United Kingdom or Switzerland is transferred to a country that has not been recognized by the European Commission, the Swiss Federal Council and/or the UK Information Commissioner’s Office (ICO) as offering an adequate level of data protection, we rely on appropriate transfer mechanisms recognized by applicable data protection laws, such as Standard Contractual Clauses as approved by the relevant data protection authority. You can obtain a copy of these clauses by contacting us as indicated below.
5. Data Retention
We retain personal data for as long as is reasonably necessary to fulfil the purposes for which we collected it, including to provide the Services, comply with our legal, accounting and reporting obligations, resolve disputes, prevent fraud and abuse, and establish, exercise or defend legal claims, all in accordance with our data retention policy and applicable laws.
To determine the appropriate retention period, we consider the nature, sensitivity and volume of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the personal data, whether those purposes can be achieved by other means, and applicable legal, regulatory, tax, accounting and limitation-period requirements.
Once retention is no longer justified, we will securely delete, anonymize or aggregate the personal data, or restrict its processing as required. We do not retain personal information for longer than is reasonably necessary for the disclosed purposes.
6. Cookie & Tracking technologies
We and our Service Providers use cookies, pixels, log files and other similar tracking technologies (collectively “cookies”) to operate, monitor, secure, optimize, improve and personalize the Services and to analyze our performance and marketing activities. Some of these are strictly necessary; others are used only with your consent where required.
For full information about the categories of cookies we use, their purposes, providers, duration and how to manage them, please see our Cookie Policy. Where required by applicable law, you can manage your preferences via the Cookie Policy.
Please note though that if you block or restrict tracking technologies on your device, you will still be able to use our Services, but various features and functionality may be altered.
We do not currently respond to all browser “Do Not Track” signals, but you can manage your cookie preferences as described above.
7. Sale / Sharing for Targeted Advertising
Under some US data protection laws, such as the CCPA/CPRA, the disclosure of certain internet activity and device information with third parties through cookies may be considered a “sale” or “sharing” of personal information, or disclosure of cookies for “targeted advertising” (as such terms are defined in applicable data protection laws). We do so in pursuit of the business and commercial purposes described in Section 2 above.
You may opt out of any “sale” or “sharing” of your personal information by adjusting your preferences by following the instructions in the Cookie Policy. If you visit us from a different device or browser, or clear your cookies, you will need to re-apply your preferences.
8. Data Security
We implement and maintain appropriate administrative, physical, technical and organizational security measures designed to protect your personal data in accordance with generally accepted industry standards, and we comply with applicable laws and regulations. These measures include access controls and authentication, network and application security, encryption in transit and at rest, vulnerability management, secure software development, logging and monitoring, change management, business continuity, vendor risk management, personnel training and incident response.
Despite these measures, please be aware that no security control is perfect and we cannot guarantee that the Services will be immune from intrusion, malfunction, unlawful interception or other forms of misuse.
9. Your Privacy Rights
Data protection laws and regulations – including the EU or UK General Data Protection Regulation (GDPR), Israeli PPL and the CCPA – provide individuals with certain rights in respect of their personal data. You can exercise your rights by submitting a request to [email protected]
You may have the following rights (to the extent applicable to you):
- Right to know/access: to know/request access to your personal data
- Right to rectification: to have inaccurate or incomplete personal data corrected or completed.
- Right to erasure: to have personal data deleted in certain circumstances (sometimes referred to as the “right to be forgotten”).
- Right to restriction of processing: to restrict the processing of personal data by us in certain circumstances.
- Right to opt out (US state privacy laws): for US state residents, to direct us not to “sell” or “share” your personal data or process it for “targeted advertising”, as described above.
- Right to Limit Use of Sensitive Personal Information – to direct us to limit use/disclosure of sensitive personal information to what is necessary to provide the Services.
- Right to data portability: to obtain a copy or port personal data you provided to us
- Right to object: to object to processing based on our legitimate interests, including for direct marketing and certain forms of profiling.
- Right to equal services and prices: freedom from discrimination in the exercise of your rights (e.g. under the CCPA/CPRA).
- Right to withdraw consent: to withdraw any consent you have given, without affecting the lawfulness of processing carried out before withdrawal.
- Right not to be subject to solely automated decision-making: to request human review of decisions that produce legal or similarly significant effects on you and that are based solely on automated processing.
- Under some regulatory frameworks, such as the GDPR, you may also have the right to lodge a complaint with the relevant supervisory authority – in the European Economic Area (EEA) or the UK, as applicable.
We do not make decisions concerning Visitors, Prospects or Business Contacts that produce legal effects or similarly significant effects on them and that are based solely on automated processing. Where applicable law confers rights in relation to AI or automated decision-making – for example, Article 22 GDPR, or the EU AI Act – we will honor those rights as described in this section.
How to exercise your rights
To exercise these rights, please contact us at [email protected]. We will respond within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf, subject to verification. The authorized agent may submit a request to exercise these rights by contacting us at [email protected]. We may require written authorization, verification of your identity, and direct confirmation from you that the agent is authorized to act on your behalf, in each case as permitted by applicable law.
We may need to verify your identity before responding and may ask for additional information for that purpose; any data submitted in connection with your request will be retained for a reasonable period as proof of the identity of the person submitting the request and/or proof of our response/fulfillment of the request.
We will not discriminate against you for exercising any of your rights under this Policy.
10. Communications
Service communications: We may contact you via email, phone, SMS and notifications with information that is integral to our Services – for example, service notifications, security alerts, login or password notices, billing notices, scheduled maintenance, releases and changes or updates to our Services. You cannot opt out of these communications.
Marketing communications: We may send you marketing communications about our Services, events, content and offerings – by email, in-product messaging, phone, SMS or other electronic means – subject to applicable law. You can opt out of marketing communications at any time by using the unsubscribe link in any marketing email or contacting us at [email protected]. Opting out of marketing does not affect service communications.
Where we engage in “direct mailing” within the meaning of section 17C of the PPL, we comply with the notice, opt-out and registration obligations applicable to such mailings, including providing a clear opt-out mechanism in each marketing communication.
11. Children
Our Services are designed for businesses and are not directed to or intended for use by children. We do not knowingly collect personal data from children - i.e. anyone under the age of consent (as determined under the applicable laws where the individual resides). If we learn that we have collected personal data from a child, we will take steps to promptly delete it. If you believe we may have collected such data, please contact us at [email protected].
12. Third-Party Links and Services
Our Site and Services may contain links to, or be integrated with, third-party websites and services. This Privacy Policy does not govern those third parties’ processing of your personal data. To the extent you disclose, submit or otherwise transit your information to third party services, we encourage you to review the privacy policy and terms and conditions of any third-party site or service you visit or use.
13. Data Controller/Processor
Several data-protection laws – including the EU and UK GDPR, Israeli PPL and US state privacy laws – distinguish between two main roles for parties processing personal data: (i) the entity that determines the purposes and means of processing (variously, the “controller”, “business” or “database controller”) and (ii) the entity that processes personal data on the controller’s behalf (variously, the “processor”, “service provider”, or “database holder”). The following table summarizes our roles:
| Category | Controller | Other Roles |
|---|---|---|
| Visitors / Prospect Data | Shapes | Service Providers acting on Shapes’ behalf are processors. |
| Business Contacts – for Shapes’ own purposes (authentication, billing, service communications, security, improvement, compliance) | Shapes | Service Providers acting on Shapes’ behalf are processors. |
| Business Contacts – to the extent it is included in Customer Personal Data | Customer | Shapes is processor. Shapes’ Service Providers acting on Shapes’ behalf in relation to Customer Personal Data are sub-processors. |
| Customer Personal Data | Customer | Shapes is processor. Shapes’ Service Providers acting on Shapes’ behalf in relation to Customer Personal Data are sub-processors. |
Some Business Contact Data may also be reflected in Customer Personal Data (for example, a Business Contact’s name and email appearing on records they have created within the Solution). To the extent that the same item of personal data falls within both Business Contact Data and Customer Personal Data, we process it as a controller for the purposes described in this Policy, and as a processor for the purposes set out in the DPA.
14. Contact Details
For questions, concerns or complaints about this Policy or our processing of your personal data, or to exercise your rights, please contact us as follows:
- Data Protection Officer: Shapes has appointed PrivacyTeam Ltd. as our Data Protection Officer, for monitoring and advising on Shapes’ ongoing privacy compliance and serving as a point of contact on privacy matters for data subjects and supervisory authorities. You can contact our DPO at: [email protected]
- General privacy enquiries: [email protected]
- Database Controller for the purposes of the Israeli PPL: DreamTeam HR Apps Ltd. d/b/a Shapes; [email protected]
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The amended version will be effective from the date it is published. Where we make material changes, we will provide notice as appropriate under the circumstances – for example, by posting a prominent notice on the Site, by email to your registered address, or by in-product notification. Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the updated Privacy Policy, to the extent permitted by law.