טיוטה. המסמך עוד לא עבר בדיקה משפטית, והנוסח עשוי להשתנות. הוא מתאר את אופן הפעולה של השירות בפועל נכון לתאריך העדכון.
1. על השירות
בול (bul.friman.app) הוא שירות Email API: ארגונים ועסקים (״הלקוחות״) שולחים דרכו מיילים טרנזקציוניים ודיוור לנמענים שלהם, ומקבלים דיווח על המסירה. המדיניות מתארת אילו נתונים בול מעבד, למה, כמה זמן הם נשמרים ואיך הם מוגנים.
לגבי הנמענים ותוכן ההודעות, הלקוח הוא בעל המידע, ובול מעבד את המידע מטעמו ולפי הוראותיו. לגבי פרטי החשבון של הלקוח עצמו, בול הוא האחראי למידע.
2. אילו נתונים מעובדים
- פרטי חשבון: שם הארגון, כתובת המייל להתחברות, דומייני השליחה והגדרות החשבון.
- מפתחות API: נשמרים כגיבוב (hash) בלבד. המפתח המלא מוצג פעם אחת, ביצירה.
- תוכן הודעות: שולח, נושא, גוף ההודעה (HTML וטקסט), כותרות, תגיות וקבצים מצורפים.
- נמענים: כתובות מייל, ושמות אם הלקוח מסר אותם.
- אירועים: נשלח, נמסר, נדחה, החזרה (bounce), תלונת ספאם, פתיחה, לחיצה והסרה מרשימה. באירועי פתיחה ולחיצה נשמרים גם הקישור שנלחץ, ה-User-Agent ולעיתים כתובת IP. הלקוח יכול לכבות מעקב לחיצות.
- בעלי כתובת ה-IP בפתיחות: כשנשמרת כתובת IP באירוע פתיחה, בול בודק למי היא שייכת (ספק או ארגון, לפי מספר ה-ASN) — כדי להבחין בין פתיחה של אדם לבין טעינה אוטומטית (סורק, טעינה מראש). הבדיקה נעשית דרך שירות חיצוני, Team Cymru (שאילתת DNS), ונשלחת אליו רק כתובת ה-IP — בלי כתובת מייל, בלי תוכן ההודעה ובלי שום מזהה אחר.
- רשימת חסימה: כתובות שהחזירו הודעה, הגישו תלונה או ביקשו הסרה, כדי לא לשלוח אליהן שוב.
- Webhooks ואינטגרציות: כתובות היעד והסודות שלהם (מוצפנים).
- לוגים תפעוליים: רשומות טכניות של בקשות ושל השליחה, לצורך תפעול, אבטחה ואבחון תקלות.
3. למה הנתונים משמשים
הנתונים משמשים רק להפעלת השירות: שליחת ההודעות ומסירתן, דיווח ללקוח בדשבורד, ב-API וב-webhooks, הגנה על מוניטין השליחה (כולל חסימה אוטומטית של כתובות בעייתיות), מדידת שימוש ומכסות, ואבטחה. בול לא מוכר נתונים, לא משתמש בהם לפרסום, ולא משתמש בתוכן ההודעות לאימון מודלים של בינה מלאכותית.
4. כמה זמן הנתונים נשמרים
- תוכן ההודעה (גוף ההודעה ותוכן קבצים מוטבעים): נמחק 30 יום אחרי השליחה. פרטי ההודעה (נמען, נושא, סטטוס, זמנים) נשמרים כל עוד החשבון פעיל, או עד שהלקוח מבקש למחוק.
- אירועים (מסירה, פתיחה, לחיצה וכו'): נמחקים אחרי 90 יום. נשאר רק סיכום יומי מצרפי (מספרים לפי סוג אירוע), בלי פרטי נמענים.
- קבצים מצורפים: נמחקים אוטומטית 30 יום אחרי ההעלאה.
- מפתחות Idempotency: 30 יום.
- רשימת החסימה: עד שהלקוח מסיר כתובת, כי היא נדרשת כדי לא לשלוח שוב למי שביקש להפסיק.
- גיבויי מסד הנתונים: מוצפנים. גיבוי יומי נשמר עד 35 יום (ותמיד נשמרים לפחות 7 הגיבויים האחרונים), ובשרת עצמו — 3 הגיבויים האחרונים.
- סגירת חשבון: לפי בקשה בכתב, נתוני החשבון נמחקים ממסד הנתונים. עותקים בגיבויים נמחקים כשהגיבויים נמחקים לפי גילם — בדרך כלל תוך 35 יום.
5. אבטחה
- כל התקשורת עם השירות מוצפנת ב-TLS (HTTPS). שליחת דואר לשרתי הנמענים מוצפנת ב-TLS כשהשרת המקבל תומך בכך.
- הפרדה בין לקוחות ברמת מסד הנתונים (Row-Level Security): כל לקוח רואה רק את הנתונים שלו.
- סודות (webhooks, חיבורים לשירותים חיצוניים) מוצפנים ב-AES-256-GCM. מפתחות API נשמרים כגיבוב בלבד.
- גישת ניהול לשרתים רק דרך רשת פרטית מוצפנת ובמפתחות SSH, מאחורי חומת אש.
- גיבויים מוצפנים לפני שהם יוצאים מהשרת.
6. ספקי משנה
בול נעזר בספקים הבאים כדי להפעיל את השירות:
- Amazon Web Services — שליחת מייל (Amazon SES) ותורי עבודה, באזור ישראל (il-central-1).
- Supabase — מסד הנתונים, באיחוד האירופי (אירלנד).
- OVHcloud — שרתי האפליקציה ושרת השליחה של בול, בגרמניה.
- Cloudflare — DNS, הגנה מפני התקפות, ואחסון קבצים מצורפים וגיבויים מוצפנים (R2).
- Team Cymru — זיהוי הבעלים של כתובת IP באירועי פתיחה (ASN וארגון). מקבל רק את כתובת ה-IP, בלי כתובת מייל או תוכן.
7. נתוני Google Postmaster Tools
בול מתחבר ל-Google Postmaster Tools API בהרשאת קריאה בלבד (postmaster.traffic.readonly), דרך חשבון Google של מפעיל בול. ההרשאה משמשת רק למעקב אחר מוניטין השליחה של הדומיינים ששולחים דרך בול ושמאומתים ב-Postmaster Tools.
- מה נקרא: נתונים מצרפיים ברמת דומיין: שיעור תלונות ספאם, הצלחת אימות SPF, DKIM ו-DMARC, הצפנה, שגיאות מסירה, וסטטוס העמידה בדרישות השולחים של Gmail. אין גישה לתיבות דואר, להודעות או לפרטים של משתמשי Gmail.
- לשם מה: הצגת המוניטין בדשבורד ללקוח שהדומיין שלו, והאטה או עצירה של השליחה כשהמוניטין יורד, כדי להגן על המסירה.
- מה לא נעשה: הנתונים לא נמכרים, לא מועברים לצד שלישי, לא משמשים לפרסום, ולא משמשים לאימון מודלים של בינה מלאכותית.
- אחסון: אסימון ההרשאה מוצפן ב-AES-256-GCM. אפשר לבטל את ההרשאה בכל עת ב-myaccount.google.com/permissions.
השימוש של בול במידע שמתקבל מ-Google APIs, וההעברה שלו לכל אפליקציה אחרת, יעמדו ב-Google API Services User Data Policy, כולל דרישות ה-Limited Use.
8. עוגיות
הדשבורד משתמש בעוגיית התחברות הכרחית בלבד. אין עוגיות פרסום או ניתוח. Cloudflare עשוי להציב עוגיות אבטחה טכניות.
9. זכויות
לקוחות יכולים לבקש עיון, תיקון או מחיקה של המידע שלהם. נמען שקיבל הודעה דרך בול יכול להסיר את עצמו דרך קישור ההסרה שבהודעה, או לפנות לארגון ששלח אותה. פניות שמגיעות לבול בנושא זה יועברו ללקוח הרלוונטי.
11. שינויים
כשהמדיניות משתנה, התאריך בראש הדף מתעדכן. שינוי מהותי יימסר ללקוחות במייל.
Draft. This document has not yet been reviewed by a lawyer, and the wording may change. It describes how the service actually operates as of the date below.
1. About the service
Bul (bul.friman.app) is an Email API service. Organizations and businesses ("customers") use it to send transactional email and newsletters to their recipients and to receive delivery reports. This policy explains what data Bul processes, why, how long it is kept and how it is protected.
For recipients and message content, the customer is the data controller and Bul processes the data on the customer's behalf and instructions. For the customer's own account details, Bul is the controller.
2. Data we process
- Account details: organization name, login email address, sending domains and account settings.
- API keys: stored as a hash only. The full key is shown once, when it is created.
- Message content: sender, subject, body (HTML and text), headers, tags and attachments.
- Recipients: email addresses, and names if the customer provides them.
- Events: sent, delivered, rejected, bounce, spam complaint, open, click and unsubscribe. Open and click events also record the clicked link, the User-Agent and sometimes an IP address. Customers can turn click tracking off.
- Owner of the IP address in opens: when an open event records an IP address, Bul looks up who it belongs to (network or organization, by ASN) to tell a person opening the email apart from automatic loading (scanners, prefetching). The lookup uses an external service, Team Cymru (a DNS query), and only the IP address is sent — no email address, no message content and no other identifier.
- Suppression list: addresses that bounced, complained or unsubscribed, so they are not emailed again.
- Webhooks and integrations: destination URLs and their secrets (encrypted).
- Operational logs: technical records of requests and sending, for operations, security and troubleshooting.
3. How the data is used
Data is used only to run the service: sending and delivering messages, reporting to the customer in the dashboard, API and webhooks, protecting sending reputation (including automatic suppression of problem addresses), measuring usage and quotas, and security. Bul does not sell data, does not use it for advertising, and does not use message content to train AI models.
4. Retention
- Message content (body and inline attachment content): deleted 30 days after sending. Message details (recipient, subject, status, timestamps) are kept while the account is active, or until the customer asks for deletion.
- Events (delivery, open, click, etc.): deleted after 90 days. Only an aggregate daily summary (counts per event type) remains, with no recipient details.
- Attachments: deleted automatically 30 days after upload.
- Idempotency keys: 30 days.
- Suppression list: until the customer removes an address, because it is needed to avoid emailing people who asked to stop.
- Database backups: encrypted. Each daily backup is kept for up to 35 days (and at least the 7 most recent backups are always kept); the server itself keeps the 3 most recent.
- Account closure: on written request, account data is deleted from the database. Copies in backups are removed as backups are deleted by age — normally within 35 days.
5. Security
- All traffic to the service is encrypted with TLS (HTTPS). Delivery to recipient mail servers uses TLS whenever the receiving server supports it.
- Customers are isolated at the database level (Row-Level Security): each customer can see only its own data.
- Secrets (webhooks, connections to external services) are encrypted with AES-256-GCM. API keys are stored as hashes only.
- Administrative access to servers is only through an encrypted private network with SSH keys, behind a firewall.
- Backups are encrypted before they leave the server.
6. Sub-processors
- Amazon Web Services — email sending (Amazon SES) and job queues, in the Israel region (il-central-1).
- Supabase — database, in the European Union (Ireland).
- OVHcloud — Bul's application servers and sending server, in Germany.
- Cloudflare — DNS, attack protection, and storage of attachments and encrypted backups (R2).
- Team Cymru — identifying the owner of an IP address in open events (ASN and organization). Receives only the IP address, no email address or content.
7. Google Postmaster Tools data
Bul connects to the Google Postmaster Tools API with read-only access (postmaster.traffic.readonly), through the Google account of Bul's operator. This access is used only to monitor the sending reputation of domains that send through Bul and are verified in Postmaster Tools.
- What is read: aggregate, domain-level data: spam complaint rate, SPF, DKIM and DMARC authentication success, encryption, delivery errors, and Gmail sender requirements compliance status. Bul has no access to mailboxes, messages or Gmail users' personal details.
- Why: to show reputation in the dashboard to the customer who owns the domain, and to slow down or pause sending when reputation drops, to protect deliverability.
- What we don't do: the data is not sold, not transferred to third parties, not used for advertising, and not used to train AI models.
- Storage: the authorization token is encrypted with AES-256-GCM. Access can be revoked at any time at myaccount.google.com/permissions.
Bul's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Cookies
The dashboard uses a strictly necessary login cookie only. There are no advertising or analytics cookies. Cloudflare may set technical security cookies.
9. Your rights
Customers can ask to access, correct or delete their data. A recipient who received a message through Bul can unsubscribe using the link in the message, or contact the organization that sent it. Requests that reach Bul about such messages are forwarded to the relevant customer.
11. Changes
When this policy changes, the date at the top is updated. Material changes are sent to customers by email.