Luminata Software Development LTD (Anita24)
Last updated: 2026-08-16
Who this policy is for. This policy is for organizations that subscribe to and administer the Anita24 platform — businesses, municipalities, nonprofits, clinics, schools and similar bodies ("Customers", "you") — and for the individual account users who sign in to the Anita24 dashboard on their behalf. It explains what we do with your account and configuration data, and how we handle the personal data of the people you serve when we process it on your instructions.
If you are a member of the public who has chatted, messaged or spoken with an AI agent operated by an organization using Anita24, this is not the policy that describes your interaction. Please read the Privacy Policy for End Users instead.
This policy uses the same defined terms as the Customer Terms of Service: "Customer", "End User", "Service" and "Agent".
Luminata Software Development LTD (company no. [company registration number — to be confirmed by counsel]), a company incorporated in Israel, of [registered business address — to be confirmed by counsel] ("Luminata", "we", "us"), operates the Anita24 platform.
For privacy matters you can reach us at support@anita24.com, or for general support at support@anita24.com. Postal correspondence should be addressed to the registered address above and marked "Privacy".
Anita24 is a software-as-a-service platform. You configure one or more AI-powered service Agents, connect the communication channels you want them to use — a chat widget on your website, WhatsApp, Facebook Messenger, Instagram messaging and telephone voice calls (incoming and outgoing, including voicemail handling) — and the Agent then communicates with the people you serve on your behalf. An administration dashboard lets you configure Agents, connect channels, review conversations and maintain a knowledge base.
This distinction determines who owes what duty, so please read it carefully.
(a) Personal data of the people you serve ("End Users"). When an End User writes to or speaks with your Agent, you are the data controller of that personal data and Luminata acts as your processor / service provider. We process it only to provide the platform to you, on your documented instructions, and as described in this policy and in the data processing terms that form part of your subscription agreement. You decide why the data is collected, how long it stays, and who inside your organization sees it.
(b) Your account and configuration data. When you sign up, administer your subscription, configure Agents, contact support, or when we monitor and secure the platform, Luminata is the controller of that data.
(c) What being the controller means for you. As controller of End User data, you are responsible for: having a lawful basis for the communications you initiate or accept; giving End Users the notice their local law requires; obtaining any consent that law requires before you contact them or record them; honouring their rights requests; and — where applicable — registering or notifying your database with the Israeli Privacy Protection Authority, or completing your own record of processing activities under the GDPR. We give you tools to help; we cannot discharge these duties for you.
| What we collect | Why | Legal basis (GDPR, where it applies) |
|---|---|---|
| Account identifiers: name, business email, phone, organization name, role, password credentials | To create and secure your account and authenticate users | Performance of a contract |
| Subscription and billing data: plan, invoices, payment status. Card details are handled by third-party payment processors and are not stored by us | To bill you and keep statutory accounting records | Contract; legal obligation |
| Configuration data: business hours, services, contact details, Agent settings, channel connections and the credentials or authorizations you grant through the relevant provider's official flow | To operate the Agents you configured | Contract |
| Knowledge-base source material: the website addresses and documents you supply, whose publicly available content is imported to answer questions | To build and maintain your Agent's knowledge base | Contract |
| Usage and diagnostic data: sign-in events, feature usage, error and performance logs, IP address and device/browser information | To keep the service running, secure, and to improve it | Legitimate interests in operating and securing the service |
| Support correspondence | To answer you and keep a record | Contract; legitimate interests |
| Marketing contact data | To send service and product communications you can opt out of at any time | Legitimate interests; consent where required |
We do not use your dashboard content to build advertising profiles, and we do not sell personal data.
Acting on your instructions, the platform processes: the content of messages and calls, including voice audio and text derived from it; contact details an End User chooses to share, such as name, phone number and email address; the details of the request, booking or enquiry; the channel identifiers needed to deliver and display a conversation; and delivery and status metadata. Conversations are stored and made available to you in your dashboard.
We process this data to deliver the service to you, to keep it secure and reliable, and to comply with law. We do not use Customer Content, Agent Output or End User personal data to train or fine-tune general-purpose generative artificial-intelligence models, and our agreements with our AI model providers do not permit them to do so. Any tuning or configuration we carry out using your data is performed solely for your own deployment and is not used for the benefit of any other customer. We do not use End User conversation content for our own marketing and we do not sell it. Where we use conversation data to maintain, debug and improve the platform, we do so in the way permitted by the data processing terms in your subscription agreement.
Agent responses are produced by automated systems, including third-party artificial-intelligence model providers listed in section 8. Conversation content and relevant knowledge-base material are sent to those providers so that a response can be generated; content supplied by you or your End Users may also be processed automatically to build the knowledge base and to produce a general description of your organization for the Agent to work from.
Accuracy. Automated output can be incomplete, outdated or simply wrong. It is not medical, legal, financial, tax, insurance, psychological or other professional advice. You are responsible for reviewing how your Agent is configured, for the information you place in its knowledge base, and for any decision you or your End Users take on the basis of an Agent's output. Where an interaction carries legal or similarly significant consequences for an individual, you must ensure a human being reviews it; the platform is not designed to take solely automated decisions of that kind on your behalf. The corresponding contractual obligations are set out in clause 7 of the Customer Terms of Service.
Where you enable voice channels, calls to and from your Agents may be recorded and converted to text so that the Agent can respond and so that you can review the conversation in your dashboard. You are responsible for ensuring that the notice and consent your jurisdiction requires for recording a call is actually given — including any announcement at the start of the call — and for configuring the platform accordingly. Recording and transcription of your End Users' calls happens on your instructions, not ours.
To run the platform we rely on the following categories of service provider, who may process personal data on our behalf:
We impose contractual data-protection obligations on each of them. We will make available an up-to-date list on request and will give you notice of a new or replacement sub-processor as set out in your subscription agreement.
Beyond these providers we disclose personal data only: to you and the users you authorize; where you instruct us to send it to a system you have connected; where we must do so by law, court order or a lawful authority request; where necessary to establish, exercise or defend legal claims or to prevent fraud or abuse; and to a successor entity in connection with a merger, acquisition or asset sale, subject to this policy.
If you connect Google Calendar or another Google Workspace service, we access that data only to provide the connected features in your Anita24 workspace, such as checking availability and booking meetings. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use raw, aggregated or derived Google user data to create, train or improve foundational or generalized machine learning or artificial intelligence models.
We are established in Israel and our providers operate in Israel, the European Economic Area and the United States, so personal data may be transferred outside your country. Israel benefits from a European Commission adequacy decision. Where a transfer is not covered by an adequacy decision, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses, together with supplementary technical and organizational measures where these are required. You can request further detail of the safeguards used for a given transfer at support@anita24.com.
We retain Customer account, billing and configuration data for the life of your subscription and for [retention period for account, billing and configuration data — to be confirmed by counsel] afterwards, except where a longer period is required by tax, accounting or other law, or to defend a legal claim.
We retain End User conversation data for the period configured for your account, by default [retention period for conversation data — to be confirmed by counsel], after which it is deleted or irreversibly anonymized. Voice recordings and their transcripts are retained for [retention period for voice recordings and transcripts — to be confirmed by counsel] unless you set a shorter period. As controller you may instruct us to shorten these periods or to delete specific records, and we will act on that instruction. These are the only retention periods we publish; the Customer Terms of Service do not restate them.
On termination, Customer Content and End User personal data are exported and deleted in accordance with clause 15.6 of the Customer Terms of Service — an export window followed by deletion or de-identification — or in accordance with any different period agreed in your order form or data processing agreement. Legally required retention and routine backups, which are overwritten on their normal cycle, are the exceptions.
Deletion requests received through Meta. Where a person asks Meta to delete data associated with their use of our Facebook-based integrations, that request reaches us through Meta's data deletion callback. We record it, return a confirmation code and a status address at which progress can be checked, and complete deletion of the associated data within [deletion SLA in days — to be confirmed by counsel]. Because you are the controller of that data, we will also make the request visible to you where the person is identifiable in your workspace. Individuals who reach this page from that callback should read the Privacy Policy for End Users, which describes the same flow from their point of view.
We maintain technical and organizational measures appropriate to the risk, including: encryption of data in transit using industry-standard transport security and encryption at rest; role-based access control and authentication for the dashboard; separation of each Customer's data; access by our personnel only where needed for support, operation or security, under confidentiality obligations; logging and monitoring; and periodic review of our security measures. We seek to align our measures with the Israeli Protection of Privacy (Data Security) Regulations 5777-2017 at the level applicable to the databases we operate.
No system is perfectly secure. If a security incident affecting End User personal data occurs, we will notify you without undue delay and give you the information you reasonably need to meet your own notification duties to regulators and individuals. We will notify the relevant authority and affected individuals ourselves where we are the controller and the law requires it.
The Israeli Protection of Privacy Law 5741-1981, as amended (including Amendment 13), applies to our activities in Israel. Amendment 13 revised the duties attaching to databases containing personal data — including notification and, for certain databases, registration duties with the Privacy Protection Authority, expanded transparency obligations toward data subjects, a duty to appoint a data protection officer in defined circumstances, and strengthened enforcement.
Where you are established in Israel and you deploy Agents that collect personal data from End Users, the database duties in respect of that data fall on you as its owner and controller, not on Luminata as your processor. We meet our own duties in respect of the databases for which we are responsible. Nothing in this policy is a determination of your status under that law; please take your own advice.
Where we are the controller of your personal data — that is, in respect of your account, billing, configuration, usage and support data — you have the right to ask us to give you access to it; to correct it; to delete it; to restrict or object to how we use it, including any use based on our legitimate interests; to receive it in a portable, machine-readable form; and to withdraw a consent you have given, without affecting processing already carried out. Where the Israeli Protection of Privacy Law applies, you have the corresponding rights of review, correction and deletion under that law.
Write to support@anita24.com. We will respond within one month, or within any shorter period local law requires, and will tell you if we need longer. We may ask you to verify your identity.
Requests from End Users. If an End User asks us to exercise rights over data we hold on your behalf, we will normally direct them to you as controller and tell you about the request, unless the law requires otherwise. The route we publish to End Users is described in the Privacy Policy for End Users.
Complaints. You may complain to a supervisory authority: in Israel, the Privacy Protection Authority; in the EEA or the United Kingdom, the authority for your country of residence or workplace. We would appreciate the chance to address your concern first.
Our marketing website and the Anita24 dashboard use cookies and similar technologies that are strictly necessary to sign you in, keep your session, remember your preferences and protect our forms against automated abuse — the last of these through Cloudflare's bot-protection service, which processes your IP address and browser signals for that purpose.
Subject to your choice where consent is required, we also use analytics technologies, including Google Analytics 4, to understand how the website and dashboard are used so that we can improve them. You can decline non-essential cookies through the banner presented on your first visit, change your choice at any time, and control cookies through your browser settings. Declining non-essential cookies does not prevent you from using the service.
We may send you service messages about your subscription, security and changes to this policy; these are part of the service and cannot be opted out of while your account is open. We send product and marketing messages only where you have opted in or where the law otherwise allows, and every such message carries an unsubscribe link. You can also opt out at support@anita24.com.
The platform is a business tool. It is not directed at children and we do not knowingly collect personal data from children through Customer accounts; account users must be at least 18. Whether an Agent you deploy may lawfully interact with a minor is a question for you as controller, and if you configure an Agent for an audience that includes children — for example in a school setting — you must ensure the additional protections your law requires are in place.
We do not use your personal data to take decisions about you that produce legal effects or similarly significant effects and that are based solely on automated processing.
Privacy questions and requests should be sent to support@anita24.com, which reaches the person responsible for data protection at Luminata. [EU representative appointment details — to be confirmed by counsel]
We may update this policy to reflect changes to the service, our providers or the law. The version in force is always the one published at this address, and its date appears at the top as "Last updated". Where a change is material we will give you reasonable advance notice by email or through the dashboard before it takes effect. Your acceptance of this policy is recorded against its version identifier; continuing to use the platform after a change takes effect means you accept the updated version.
Luminata Software Development LTD, company no. [company registration number — to be confirmed by counsel]
[registered business address — to be confirmed by counsel], Israel
General and support: support@anita24.com
Privacy and data-protection requests: support@anita24.com
Legal notices: Admin@anita24.com
This policy sits alongside our Customer Terms of Service. The individuals your Agents serve are governed by the Privacy Policy for End Users and the End-User Terms of Service.
Last updated: 2026-08-16