SorbetSorbet Agency

Privacy Policy

Last Updated: 9 July 2026 · Sorbet Agency

Sorbet Agency (“Sorbet”, “we”, “us”, “our”) is a digital marketing and web design agency based in Tel Aviv, Israel. This Privacy Policy explains how we collect, use, disclose, store, and protect information in connection with our website, our client dashboards and reporting platform, our integrations with third-party advertising, marketing, analytics, and business (CRM) systems, our website chatbot / AI sales-assistant services, and our other services (together, the “Services”).

We work with clients located in Israel, the European Union / European Economic Area, the United Kingdom, the United States, and other jurisdictions. This Policy is drafted to meet our obligations under the Israeli Protection of Privacy Law, 5741-1981 and its regulations, including Amendment 13 (“Israeli Privacy Law”); the EU/UK General Data Protection Regulation (“GDPR”); and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”). Where these laws differ, the section headed “Your Rights by Region” identifies which rules apply to you.

Sorbet acts in two different capacities, and your rights depend on which capacity applies:

Where Sorbet acts as a processor, a separate Data Processing Agreement (“DPA”) with the client governs the terms of that processing and takes precedence over this Policy for that data. Clients are responsible for ensuring they have a valid legal basis and, where required, a DPA in place with Sorbet before connecting third-party accounts containing personal data.

1. Information We Collect

Each client is given access to a dedicated Sorbet platform (dashboard) that consolidates data from the client’s connected advertising, marketing, CRM, and website systems. Operating this platform means Sorbet has visibility into a range of the client’s own business and financial information, including revenue and sales figures, deal values, pipeline stage, and lead volumes, for the purpose of generating the client’s reporting and running the client’s campaigns. This information belongs to the client (or the client’s own customers/leads); Sorbet processes it strictly as a processor/service provider on the client’s instructions, as described throughout this Section 1 and in Section 10 (Confidentiality of Business & Financial Data).

1.1 Information You Provide Directly

Name, job title, company name, email address, phone number, billing and payment details, login credentials, and any other information you submit through contact forms, onboarding questionnaires, the “Book Online” scheduler, support requests, proposals, or other communications with us.

1.2 Job Applicant / Recruitment Information

Our website invites candidates to submit a CV/resume, together with a cover letter and any other information the candidate chooses to include (which may contain name, contact details, employment history, education, and, depending on what the candidate includes in their CV, special categories of data such as photo, age/date of birth, military service, or nationality), by email to [email protected] for open or prospective roles.

1.3 Information Collected Automatically from Our Website

When you visit sorbetagency.com, we (and our website platform, Wix, and analytics/advertising partners) may automatically collect device and usage information such as IP address, browser type, pages viewed, referring/exit pages, approximate location, and interaction data, using cookies and similar technologies described in Section 7 below.

1.4 Information from Connected Advertising & Marketing Platforms (Read and Write Access)

Our dashboard and campaign-management platform connect to clients’ advertising and marketing accounts, including Meta (Facebook/Instagram) Ads and Pages, Google Ads, Google Analytics 4, Google Search Console, LinkedIn (including LinkedIn Ads and LinkedIn Lead Gen Forms), TikTok, and other advertising or marketing systems the client authorizes. We also connect to SEO/competitive-research tools such as Semrush and Ahrefs; these primarily return keyword, ranking, and site-audit data rather than personal data, but are listed here for completeness.

These connections are not limited to reporting. Depending on the service the client has engaged us for, our access may include:

We only request the specific permissions needed to provide the service the client has engaged us for, through each platform’s own authorization/OAuth flow. The client controls and can revoke this access at any time directly within the relevant platform or by notifying us.

Data obtained from Meta and Google advertising accounts through these API connections is used solely for the stated function of that engagement — reporting, campaign management, and related dashboard functionality. This data is not combined with other personal information or PII datasets in a way that could identify an individual end user, and is not used for retargeting, profiling, or advertising purposes outside the stated function, except where the client has separately and explicitly authorized a specific retargeting or audience-building activity as part of the engaged service.

Google user data — Limited Use. Sorbet’s use and transfer of information received from Google APIs (Google Analytics, Search Console, Google Ads, YouTube) to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the reporting and campaign-management features the client has engaged us for, is never sold, is never transferred for advertising, and is not read by humans except as needed for security, to comply with law, or with the client’s explicit consent.

1.5 Information from Connected CRM & Business Systems

For clients who engage us to integrate, manage, or report on their customer relationship management (CRM) or business systems, including Salesforce, HubSpot, Klaviyo, and similar platforms, we may access business and financial information stored in those systems, such as:

We access CRM, business-system, and revenue/sales data only to the extent authorized by the client (for example, to sync leads, trigger campaigns, build audience segments, or generate unified reporting on revenue and pipeline outcomes) and only for that client’s own account. We do not use one client’s CRM, revenue, or financial data to benefit another client, and we do not use it to build independent profiles outside the scope of the engagement. See also Section 10 (Confidentiality of Business & Financial Data).

1.6 Website Chatbot / AI Sales-Assistant Data

For clients who engage us to deploy a chatbot on their website, Sorbet builds and operates the chat widget and its supporting server in-house; it is not a third-party chat SaaS product resold to clients. The chatbot is powered by the OpenAI API, which is used solely as the underlying LLM sub-processor that generates chat responses. We use OpenAI’s zero-data-retention API tier, so OpenAI does not store or train on the content of chatbot conversations. Chat data itself is stored in Sorbet’s own database. The chatbot is designed to answer visitor questions, qualify leads, and support the client’s sales process.

Depending on what a visitor chooses to share in the conversation, the chatbot may collect:

The chatbot is configured for lead-generation and customer-support purposes only and is not designed or intended to solicit payment card numbers, government ID numbers, or other special-category/sensitive data. For clients operating in regulated or sensitive sectors (for example, healthcare or clinical-trial-related services), the chatbot includes an active safeguard: it is configured to detect when a visitor begins sharing confidential, health, or clinical information, interrupt that part of the exchange, and avoid repeating the sensitive content back to the visitor or retaining it further. If a client’s chat flow is later expanded to take orders or payments, this Policy and the underlying service agreement will need to be updated accordingly before that expansion goes live.

1.7 Cross-Platform Reporting

Where authorized, our platform combines data from multiple connected sources (e.g., Meta, Google, LinkedIn, Google Analytics, and a client’s CRM) into unified dashboards so a client can compare advertising performance, lead generation, website traffic, and pipeline/revenue outcomes in one place. Cross-platform reporting is generated only within the authorized client’s own account and is not combined with, or used for the benefit of, any other client.

2. API Access and Permissions

Many of our integrations are built directly on the APIs of the relevant platform (e.g., Meta Marketing API, Google Ads API, LinkedIn Marketing API, Salesforce API, Brevo API). When a client connects an account, the client authorizes Sorbet to access specified data and/or functionality through that platform’s official permission or OAuth process.

On certain platforms, completing an API connection during onboarding is a mandatory prerequisite set by the platform itself — for example, some ad platforms require a live API integration to be established, and in some cases require the associated app or use case to be reviewed and approved by the platform, before full account access or certain permissions (such as Lead Ads access) are granted. In those cases, the API connection step is not optional; it is required by the third-party platform in order for the client’s account to be approved for use with our services, and we will explain this to the client during onboarding.

We request only the scopes/permissions needed for the services engaged. Clients may disconnect any integration at any time; once disconnected, we stop syncing new data from that source, subject to the technical, legal, security, backup, and operational requirements described in Section 5.

3. How We Use Information

We use the information described above to:

Legal bases under GDPR: where GDPR applies, we (or the client, as controller) rely on one or more of the following legal bases: performance of a contract with the client, the client’s or Sorbet’s legitimate interests in providing/operating the Services, compliance with a legal obligation, and, where required (e.g., certain cookies or direct marketing to individuals), consent.

4. Data Sharing and Sub-Processors

We do not sell personal information, marketing data, lead data, CRM data, or other third-party platform data.

We may share limited information with trusted service providers who help us operate our website, dashboards, platform, hosting/infrastructure, analytics, customer support, email delivery, payment processing, chatbot/AI functionality, and security (“sub-processors”). These providers may include, for example, our website/hosting provider (Wix), cloud infrastructure providers, our chatbot/AI platform provider (and, if applicable, the underlying LLM provider it relies on to generate responses), and the advertising/CRM platforms themselves as necessary to deliver the connected service. Sub-processors are contractually restricted to using information only to provide services to us and may not use it for their own independent purposes.

We may also disclose information where required by law, to protect our rights or the rights of others, to investigate fraud or security issues, or in connection with a merger, acquisition, or sale of assets (subject to confidentiality protections).

5. Data Retention

As a general principle, we retain information only for as long as needed for the purpose it was collected for and delete or anonymize it once that purpose no longer applies, subject to the legal, accounting, and security needs described below. Approximate retention criteria by category:

Clients (and, where applicable, individuals) may request deletion of their data by contacting us using the details in Section 14. Some information may be retained after such a request where required by law, security, accounting, backup, or legitimate business needs, in which case it will be securely isolated and/or anonymized where feasible.

Under the Israeli Protection of Privacy Law and its regulations, including Amendment 13, personal data may not be retained for longer than necessary to fulfil the purpose for which it was collected. Consistent with this, we align retention with the categories above. Billing, invoicing, and related financial records are kept for 7 years to comply with recordkeeping obligations under the Israeli Tax Ordinance and Companies Law.

Under the GDPR/UK GDPR storage-limitation principle (Art. 5(1)(e)), we do not keep personal data in identifiable form for longer than necessary for the purposes set out in this section. Where you ask us to delete your data and no legal or accounting exception applies, we will do so within the timeframe required by applicable law.

Consistent with CCPA/CPRA disclosure requirements, the categories and retention criteria above describe how long we keep each category of personal information, or the criteria used to determine that period, where a fixed period cannot be given (for example, because retention depends on the length of the client engagement).

6. Data Security and Breach Notification

We take reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, disclosure, alteration, or destruction, including access controls, encryption in transit, and limiting integration permissions to what is necessary for the service.

You should never share passwords, API keys, access tokens, or login credentials with anyone, including Sorbet staff outside authorized account-setup processes.

Access to the Sorbet client dashboard/platform is secured with two-factor authentication (2FA). Account holders primarily authenticate using a one-time verification code sent to their email address, or via a third-party authenticator app (e.g., Google Authenticator or Authy) using the TOTP standard. Where enabled for a specific account, a verification code may also be sent via WhatsApp to the phone number on file as an additional option. This use of WhatsApp is limited to delivering account-security verification codes; it is not used to send marketing or promotional messages and is a separate function from the client-facing chatbot described in Section 1.6.

If we become aware of a security incident affecting personal data we control or process, we will notify affected clients and take the following steps depending on where the affected individuals or the incident are located:

7. Cookies and Tracking Technologies

Our website and platform use cookies, pixels, tags, and similar technologies for the following purposes:

Where required by applicable law (including GDPR/ePrivacy rules and evolving Israeli guidance), we will obtain consent before setting non-essential cookies via a cookie consent banner, and allow you to change your preferences at any time. You can also control cookies through your browser settings; disabling cookies may affect site functionality.

8. International Data Transfers

Sorbet is based in Israel and may use service providers and platforms located in other countries (including the United States and EU). As a result, information may be processed or stored outside your country of residence.

9. Your Rights by Region

9.1 Israel

Under the Israeli Protection of Privacy Law, 5741-1981 (as amended by Amendment 13), individuals may request to inspect the personal information held about them in a database, request correction of inaccurate information, and object to certain uses (such as direct mailing). Where Sorbet or a client’s database is subject to registration requirements, we will maintain such registration as required. You also have the right to lodge a complaint with the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות) if you believe your rights under this law have been violated. To exercise these rights with Sorbet, contact us at [email protected].

9.2 European Union / EEA / United Kingdom (GDPR / UK GDPR)

If GDPR or UK GDPR applies to you, you have the right to request access to, rectification or erasure of, restriction of or objection to processing of, and portability of your personal data, and the right to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at [email protected].

9.3 United States (including California — CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we have collected about you, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information (as those terms are defined by the CCPA/CPRA) and to be free from discrimination for exercising these rights.

If you are a resident of another U.S. state with a comprehensive privacy law in effect, including, among others, Virginia, Colorado, Connecticut, Utah, and other states that have since enacted similar legislation, you have broadly similar rights: to confirm and access the personal information we hold about you, to correct or delete it, and to opt out of its use for targeted advertising, sale, or (in some states) certain profiling. Where the applicable state law requires it (for example, Colorado and Connecticut), you also have the right to appeal a denied request; instructions for doing so will be provided in our response if we deny a request.

We do not sell personal information for money. To the extent any use of cookies/pixels for advertising purposes could be considered “sharing” under CPRA, we provide a mechanism to opt out as described in Section 7.

9.4 Exercising Your Rights

To exercise any of the above rights, contact us using the details in Section 14. We may need to verify your identity before fulfilling a request. We will respond within the timeframe required by applicable law.

10. Confidentiality of Business & Financial Data

Because our platform gives Sorbet visibility into a client’s own revenue, sales, deal-value, lead, and other business/financial data (Section 1.5), Sorbet treats this information as confidential. We:

This confidentiality commitment is in addition to, and does not replace, any separate confidentiality or non-disclosure terms in the client’s services agreement or Terms & Conditions with Sorbet.

11. Client Responsibilities

Each client is responsible for ensuring it has the proper rights, permissions, and (where applicable) legal basis or consents to connect its advertising, analytics, CRM, or lead-generation accounts to our platform, and to authorize Sorbet’s read and/or write access to those accounts. Clients using CRM or email-marketing systems remain responsible for the accuracy of, and their own legal basis for holding, the contact and lead data in those systems.

Where Sorbet sends or helps send marketing communications (email, SMS, or similar) on a client’s behalf using the client’s own contact lists, the client is responsible for ensuring it holds valid opt-in consent for such messages and provides a working unsubscribe/opt-out mechanism, as required under the Israeli Communications Law (Telecommunications and Broadcasting), 5742-1982, Section 30A (the “Anti-Spam Law”), and, where applicable, equivalent laws such as GDPR/ePrivacy rules, the U.S. CAN-SPAM Act, and Canada’s CASL. Sorbet does not verify the consent basis of client-supplied contact lists and relies on the client’s warranty that valid consent exists. This does not apply to Sorbet’s own transactional use of email or WhatsApp to deliver two-factor authentication codes to dashboard account holders (Section 6), which is a security function, not a marketing communication.

12. Children’s Privacy

Our Services are directed to businesses and are not intended for individuals under 16 (or the relevant age of digital consent in your jurisdiction). We do not knowingly collect personal information from children through our website.

13. Third-Party Websites and Social Media Pages

Our website and platform may link to or integrate with third-party websites, platforms, or applications (including the advertising, analytics, and CRM platforms described above). We are not responsible for the privacy or security practices of those third parties, and your use of them is subject to their own terms and privacy policies.

Our website links to Sorbet’s own pages on Instagram, Facebook, and X (Twitter). If you click through to and interact with these pages (for example, by following, messaging, commenting, or liking), that platform collects and processes your information under its own privacy policy and terms, and Sorbet has no control over that processing. As the operator of these pages, Sorbet may, in some cases, act as a joint controller with the platform for aggregated page insights/analytics (e.g., follower demographics, post engagement statistics) that the platform makes available to page administrators; Sorbet does not itself receive individual message content or profile data beyond what the platform’s page-admin tools expose. We recommend reviewing Instagram’s, Facebook’s (Meta’s), and X’s own privacy policies before interacting with our pages.

14. Contact Us

Sorbet Agency
Midtown Tower, Menachem Begin 144, Tel Aviv, Israel
Email: [email protected]
DPO contact: [email protected]

15. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. Where changes are material, we will provide additional notice as required by applicable law. Continued use of our website or Services after changes are posted constitutes acceptance of the updated Policy.

Sorbet Agency · api.sorbetagency.com/privacy-policy