Welcome!
The website www.dinolaw.co.il (hereinafter: “the Site“) serves as an online platform offering information and services and is owned by Dino Smart Documents.
The privacy and security of users are of paramount importance to us. Therefore, we have taken and continue to take all possible measures to protect user privacy and the security of the information provided. As an integral part of this and as part of our Terms of Use, we have formulated this Privacy Policy to explain what information we collect, for what purposes, and what we do with the information. We also outline the security measures we take and provide a list of browsing guidelines for users.
It is clarified that the content on the site, including but not limited to this Privacy Policy, applies equally to all genders, and the use of singular gender is for convenience only. Similarly, the division of the Privacy Policy into headings or sections is for ease of reading and shall not be used for interpreting the Privacy Policy.
Types of Information Collected on the Site and Collection Methods
When a user browses the site, we may collect and/or the user may provide three types of information:
- Automatically Generated or Collected Information: A user who interacts with the site’s services allows us to collect technical details about the user or the device/software used. This information is collected independently using tools at our disposal or through monitoring services and services provided by third parties, including through “cookies”. For more information on cookies, please see our Cookie Policy.
- Information Provided by the User for Site Registration: A user wishing to prepare a small claims writ using the site’s services is required to register in the “Personal Area”. As part of the registration, the user will be asked to provide the following details: (1) Full name; (2) Identity card number; (3) Gender; (4) Full residential address; (5) Email; (6) Phone number. After providing the details, the user will receive an email to the email address provided during the registration process, and their details will be registered in the system. To ensure their privacy, a registered user who wishes to log back into the Personal Area will be asked to enter their ID number and mobile phone number, to which they will receive a one-time code for system entry.
- Information Provided by the User in the Context of Preparing the Small Claims Writ and Payment for the Service: Naturally, in the process of preparing the claim, the user will provide details and documents that will ultimately be reflected in the final claim document received. In addition, prior to receiving the claim document and as a condition for receiving it, the user will make a payment via credit card through a secure payment system.
Purpose of Information Collection on the Site
The collection and use of the aforementioned information on the site is for: (1) Providing the services and information offered on the site in the best possible way according to our discretion; (2) Promoting our commercial and marketing interests; (3) Improving and adapting the information and services on the site (including user experience) through user experience monitoring, characterization, and adaptation; (4) Opening a communication channel with site users; (5) Securing information to maximize the prevention of fraud or deceit; (6) Collecting statistical data for our legitimate interests.
Information Sharing
The information collected on the site may be shared with the following parties: (1) The State and its Agencies: For example, the police, the tax authority, the courts pursuant to a court order, etc. This is as needed or required by law, striving to minimize information disclosure to the extent possible under the circumstances; (2) Service Providers: We use supplementary service providers to provide company services (e.g., transferring credit card details to a clearing and credit company; security and cybersecurity companies; business or legal consultants; etc.). Accordingly, we share the information mentioned above with service providers to the extent and manner necessary for the provision of the relevant service provider’s services.
Data Retention Period
We will not retain the information received or provided by the user beyond what is necessary to fulfill the purposes for which the information was collected or provided, except in cases where we have a legal basis or requirement to retain this data. As a rule, the information will be retained indefinitely unless the user requests otherwise. One reason is our desire to ensure, as much as possible, that the claim document generated by the user is available to them at any time the site and its systems exist. Also, since there is no limit on the number of claims a user may generate through the system, their convenience requires that the details they provide be saved, as well as the documents they generated through the system (as opposed to a situation where the user would have to provide information about themselves each time anew).
User Rights Regarding Personal Data
The law strikes a balance between the user’s rights to the data and information they provided and our rights and obligations regarding data processing and the protection of our rights and the rights of others. The law is beyond our control and subject to change at any time. However, to simplify matters somewhat, we have chosen to summarize some of the common rights as of the date of publication of this Privacy Policy. It is clarified that this presentation is beyond what is required and it is solely the user’s responsibility to clarify their rights, and no claim will be heard relating to the non-disclosure or disclosure of said rights. Some of the rights include:
Right of Access: The user is entitled to receive a copy of the personal data stored by us and to inquire about how we use it. Usually, personal data will be provided to the user in digital format. Therefore, we may require the user to prove their identity before providing the requested information.
Right to Erasure: The user is granted the right to request that we delete their personal data, for example, when it is no longer needed for the original purpose for which it was collected, when it has become obsolete, or when the user no longer agrees to the grounds on which the data is processed. However, such a deletion request will be considered against other factors. For example, we may not be able to comply with a user’s request due to legal obligations imposed upon us.
Right to Restrict Processing: The user is granted the right to request that we temporarily cease processing their personal data. For example, in a situation where the user believes that we no longer need to use their personal data.
A user wishing to exercise any of their rights in this context should send a message – along with identification and contact details – to our email address: [email protected]
Confidentiality and Data Security
To secure the information provided by the user, we employ electronic and physical means in accordance with the provisions of the Privacy Protection (Information Security) Regulations, 5777-2017 (to the extent and if these apply to us) and follow industry-standard information security procedures.
However, a completely hermetic and absolute security solution has yet to be found globally, but we are and will continue to make every effort to protect our users’ information to the greatest extent possible.
We undertake to maintain the confidentiality of the sensitive information in our possession and to ensure that all those acting on our behalf – including service providers – undertake to maintain the confidentiality of the information and refrain from using it, except for the purpose of fulfilling their duties and for the purpose for which the information was provided.
In addition, we employ electronic means in accordance with applicable law. Among other things, we implement advanced technological security measures to prevent the loss of personal information, damage to its integrity, unauthorized access to it, or its unlawful alteration. All this is in accordance with the rules set forth in applicable law and industry standards in the Internet industry. In this context, we work to implement additional protections and encryptions, including:
(1) Managing access permissions to the company’s information systems and limiting them; (2) Password management; (3) Implementing means for identifying and verifying the identity of the company’s customers (in particular to prevent access by “bots” and Internet fraud); (4) Installing firewalls; (5) Encryption of personal information transmitted over communication networks; (6) Recording access to the database and security events that raise concerns about damage to the integrity of the information or its unauthorized use; (7) Periodic backup of information; (8) Adopting internal procedures for maintaining and securing information; (9) Conducting routine audits to ensure that the above rules are enforced.
Security Measures We Employ
We do everything we can to provide site users with the most advanced security measures to protect user privacy as well as the confidentiality and integrity of the information at their disposal. Our security and control measures include the following:
- Communication Encryption: The transfer of information between our computers and user computers via the Internet is carried out via encrypted communication (SSL at the 128-bit level), including via an SSL certificate.
- Strong System Authentication: Identification using a secret code sent to the user at the highest level of complexity.
- Payment Security Standard: Payments are made through an external clearing provider that holds the PCI security standard. This standard combines various security procedures that help ensure the safe handling of credit card data (processing, storage, and transfer). The PCI standard includes 12 different requirements aimed at overcoming credit card vulnerabilities.
- Enhanced Identification Mechanism at the Time of Payment – 3D SECURE: Verification of the user’s identity on the debit card when making a payment in the site systems, through an additional layer of protection in the form of entering a one-time password that will be sent to the mobile phone or email address of the cardholder entered into the system.
- Activity Log: We maintain a detailed record of user actions on the site and its systems.
- Physical Protection: Our servers are installed in a secure data center protected from unauthorized access; the data center is located abroad and managed on an ongoing basis by a server management company also located abroad.
Guidelines for Secure Browsing
- We strongly recommend avoiding browsing the site from a public computer or other shared computers;
- It is recommended to access the site by typing its address and avoid clicking on links from unknown sources;
- We will never send a user a random email requesting them to provide identification or authentication details. A user who receives such an email should avoid clicking on the link and is recommended to delete the message from their email inbox;
- A user can identify that they are browsing the secure area of the site when the site address appearing in the browser address bar consists of the letters https (and not http – the ‘S’ at the end is the difference).
No Advertising, Only Notifications
We do not actively send advertisements to users (this does not mean that advertisements cannot appear on the site or during browsing). A user who chooses to register with Dino agrees to receive the following notifications (depending on the registration stage and the use they have reached) via email or SMS: (1) Notification of registration to the system and receipt of a one-time password to their mobile phone; (2) Notification that the small claims writ is ready, to which the writ will be attached; (3) Notifications regarding the preparation process of the claim (responding to malfunctions and/or offering solutions, a reminder to complete a claim, responding to user inquiries regarding claim preparation, etc.); (4) Service experience survey; (5) Payment confirmation and invoice, which will be sent directly from the clearing and credit company. In addition, if a user initiates contact with us, they agree that we will respond to them in an appropriate message to the email address from which they contacted us or to any other means they specified as a response address.
If any changes are made to the aforementioned notification policy, and if necessary, we will request the user’s consent in advance.
A user who wishes not to receive such notifications may send a request to the email address: [email protected]
Changes to the Privacy Policy
We reserve the right to make changes to the Privacy Policy from time to time and at our sole discretion, of course also subject to the requirements of the law. The Privacy Policy will be effective from the date of its publication onwards. If we believe that the Privacy Policy contains a change that may materially affect the privacy of users, we will send a notification to users who have left an email address for contact at least 10 days prior to the date of the change to the Privacy Policy on the site.
Contact Regarding the Privacy Policy
Questions, requests, or complaints regarding this Privacy Policy can be sent to the email address: [email protected]