Privacy Policy Summary
Important Note: This is a summary only, intended to present the main points of Nexfinity Global Ltd’s Privacy Policy in simple and accessible language. The summary does not replace the full Privacy Policy appearing later in this document. In any case of contradiction, ambiguity, or inconsistency between the summary and the provisions of the full Privacy Policy, the provisions of the full Policy shall prevail. It is recommended to read the policy in its entirety.
Who are we?
Nexfinity Global Ltd is an Israeli company operating a digital platform for the management, evaluation, and marketing of excess electronics component inventory, intended for business customers only (B2B).What personal data do we collect?
Limited information regarding contact persons and authorized users acting on behalf of the customer: name, job title, email, telephone, and company name. Additionally, basic identification details from the Google account used for login, and technical data required for the operation and security of the platform. We do not collect personal information of private consumers.Why do we use the data?
To operate the platform, provide access permissions, supply services, manage the business relationship, ensure data security, and comply with legal obligations.What is the legal basis for processing personal data?
Your express consent, given while using the platform. You may withdraw your consent at any time, subject to the provisions of the full Privacy Policy.Where is the data stored?
On Google Cloud Platform servers in the United States (Iowa), utilizing recognized protection mechanisms for transferring personal data outside the European Union (SCCs).With whom is the data shared?
Only with infrastructure, security, and identification providers necessary for the operation of the platform (such as Google Cloud, Cloudflare), as well as with professional advisors of the company. We do not transfer personal data to external marketing entities and do not use pixels or marketing tracking tools. The Company does not process personal data using AI-based systems.What about cookies?
The platform uses strictly necessary cookies only, required for user authentication and the proper functioning of the platform.What are your rights?
Under Israeli law – the right of access and correction. To the extent the GDPR applies to you – additional rights regarding personal data, including erasure, restriction of processing, objection, data portability, and withdrawal of consent.Does the platform make automated decisions regarding you?
No. We do not perform automated decision-making or profiling with significant effects regarding platform users.How to contact us regarding privacy matters?
Via the contact details appearing at the top of this document.
Owner: Nexfinity Global Ltd. (Company No. 516803522)
Telephone: +972-52-555-4103
Email: Info@nexfinity-global.com
Address: Tsela ha-Har St 47, Modi’in, Israel
The Platform: Website
This Privacy Policy details the manner in which Nexfinity Global Ltd. (hereinafter: “the Company”, “we”, or “us”) collects, uses, stores, and protects personal data provided within the framework of access to the Company’s digital platform, registration to it, use of the services offered therein, or contacting the Company through contact channels.
Use of the platform, including browsing, logging in, or providing personal details, constitutes express consent to this Privacy Policy.
The platform is intended for business customers only (B2B) and is designed to assist in the management, evaluation, and marketing of excess inventory of electronic components and related products. In accordance with the nature of the service, the personal data collected is limited and primarily includes the details of contact persons and authorized users acting on behalf of the customer for the purpose of accessing and operating the platform. The Company does not knowingly collect personal data from minors under the age of 18. If the Company becomes aware that personal data of a minor was collected without the consent of a parent or guardian, the Company will act to delete the data without delay. A parent or guardian who believes a minor under their responsibility has provided personal data to the Company is invited to contact the Company via the contact details at the top of this policy, and the Company will handle the request in accordance with the provisions of the law.
We respect the privacy of the users on the platform and are committed to protecting the personal data of our users. Accordingly, we have decided to publish a clear and transparent privacy policy, and we commit to acting in accordance with it.
The purpose of this document is to explain how we conduct ourselves regarding the privacy of users on the platform. Among other things, we will explain what data is collected, how we use it, for what period it is kept, with which entities it may be shared, and what rights are available to you regarding this data.
This Privacy Policy is adapted to the provisions of Section 11 of the Protection of Privacy Law, 5741-1981, and the regulations installed thereunder, as well as the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR), to the extent they apply to the processing of personal data by the Company.
This document is drafted in the masculine gender for convenience only but is intended for all genders.
We recommend reading the Privacy Policy carefully. Continued use of the platform constitutes confirmation that you have read, understood, and that you agree to this policy. If you do not wish for your data to be collected in accordance with this policy, please refrain from using the platform.
There is no legal obligation to provide your details, but please note that providing certain information is a necessary condition for registering for the platform, receiving access permissions, using the services, and maintaining the business relationship between the Company and the customer.
1. Data We Collect on the Platform and Purposes of Collection and Use
1.1 Contact Person and Authorized User Details:
Details of contact persons and authorized users acting on behalf of the customer, such as full name, job title, email address, telephone number, company name, and company address, are used for creating a business contact, managing the business relationship with the customer, allocating access permissions to the platform, verifying user identity, responding to inquiries, professional support, providing services on the platform, documenting activity, enforcing terms of use, and sending operational, service, and system-related messages.1.2 Data Collected via Google Account Login:
Logging into the platform is performed via Google’s OAuth protocol. As part of the login, we receive basic identifying data about the user from Google, usually including the email address used for login, full name, and a unique account identifier. This data is used to verify the user’s identity, provide access to the personal area on the platform, manage permissions, and prevent unauthorized access.1.3 Data Provided via Correspondence or Communication with the Company:
Data you provide within the framework of inquiries, correspondence, or other communication with the Company (including via email, telephone, or other channels) is used to handle your inquiry, provide a response, clarify complaints or requests, document conduct with you, improve service, and protect our rights and manage disputes, as required.1.4 Usage Data and Technical Data:
During the use of the platform, technical data and usage data are automatically collected, including IP address, browser type and operating system, device identifiers, login and logout timestamps, actions performed on the platform, files uploaded or downloaded, and referrals between pages. This data is used for the proper operation of the platform, data security, identification and prevention of unauthorized use or irregular activity, fault diagnosis, aggregate statistical analysis, maintaining system integrity, and improving platform performance.1.5 Business Information on Inventory and Components:
Within the framework of using the platform, the customer uploads business information regarding excess inventory and components, including part numbers (MPNs), quantities, requested prices, and commercial preferences. It is clarified that this information is the customer’s business information and does not constitute personal data under the Protection of Privacy Law or the GDPR. However, to the extent that it actually includes any personal data (for example, if names of contact persons appear in the uploaded files), it will be subject to the same level of protection as the rest of the personal data processed by the Company, in accordance with this policy.1.6 Cookies:
The platform uses strictly necessary cookies only, required for its proper functioning, user authentication, maintaining a login session, and protection against attacks. There is no use of marketing cookies or tracking pixels of advertising networks (such as Meta Pixel, Google Ads) on the platform. Further details regarding the types of cookies appear in Section 8 of this policy.2. Legal Basis for Processing Personal Data
The processing of personal data by the Company is carried out based on the user’s express consent, in accordance with the provisions of the Protection of Privacy Law, -1981. By accessing the platform, registering for it, logging in via a Google account, uploading information, or other use of the services, the user confirms that he has read this Privacy Policy, understood it, and agrees to the collection of personal data about him, its processing, storage, and use for the purposes detailed in this policy. The user may withdraw his consent at any time, without affecting the lawfulness of processing carried out based on consent prior to its withdrawal. Withdrawal of consent may harm the user’s ability to use the platform or some of the services offered therein, and will be handled in accordance with the provisions of the applicable law.3. Data Collection and Storage Location
The personal data collected on the platform, including content the user uploads or creates therein, is stored on servers operated on the Google Cloud Platform (GCP) cloud infrastructure located in the United States (Iowa). Google Cloud is a US company subject to its terms of service and US law. The user of the platform declares that he agrees to the storage of data on these servers.Transfer of Personal Data Outside the European Union:
Since the servers are located in the United States, the processing of personal data involves the transfer of data outside the borders of the European Economic Area (EEA). To the extent that the Privacy Policy applies to a user to whom the GDPR applies, it is clarified that the transfer of personal data is carried out in accordance with the provisions of Chapter V of the GDPR. The Company acts to ensure an appropriate level of protection by relying on recognized protection mechanisms, including Standard Contractual Clauses (SCCs) adopted by the European Commission, as well as technical and organizational protection mechanisms provided by Google Cloud Platform (including encryption at rest and in transit). A user interested in receiving a copy of the relevant protection measures may contact the Company in accordance with the contact details at the top of this document.4. Contacting the User
The Company wishes to update platform users regarding system updates, operational changes, service announcements, and other relevant matters related to the platform and services. To ensure continuous and up-to-date communication, the Company may send users operational, service, and system-related messages via email or through the platform itself. These messages are an integral part of the service, and it is not possible to opt out of them as long as the user is active on the platform. To the extent that in the future the Company wishes to send you marketing or advertising information, this will be done only subject to receiving your express consent and in accordance with the provisions of the applicable law, including Section 30A of the Communications Law (Telecommunications and Broadcasting), 5742-1982. You may revoke your consent and stop receiving marketing messages at any time.5. Disclosure of Personal Data to Third Parties
The Company will not transfer your personal details and data collected about your activity on the platform to third parties, except in the cases detailed below:- Infrastructure, storage, and data security providers on behalf of the Company, specifically cloud service providers (Google Cloud Platform) and protection service providers (such as Cloudflare). These providers supply their services subject to legal agreements ensuring an appropriate level of data protection;
- Identification and authentication service providers, specifically Google in the context of logging in via a Google account (OAuth);
- AI and data processing service providers used by the Company for component analysis, market evaluations, and report generation. It is clarified that the Company does not transfer personal data to these providers, but rather business data on components and inventory only;
- Professional advisors of the Company, including lawyers, accountants, and other consultants, to the extent required for the provision of their professional services to the Company, and subject to a duty of confidentiality;
- In the event of a legal dispute between you and the Company that requires the disclosure of your details;
- If you perform actions on the platform that are contrary to the law or the provisions of the Terms of Use;
- If a judicial order or a requirement from a competent authority is received ordering the disclosure of your details or data about you to a third party;
- Business ownership transfers, mergers, etc.: In the event of a merger, acquisition, or transfer of the Company’s assets or activity, your personal data may be transferred to a third party as part of the transaction, provided that the transferee assumes the provisions of this Privacy Policy.
6. The Company’s Status as Data Controller
For the purposes of the GDPR, the Company acts as the Data Controller in relation to the personal data of the users and individuals registered on the platform, as detailed in this policy. This means that the Company is the one determining the purposes of processing and the means used for processing the personal data, and it is the one bearing primary responsibility for meeting the obligations applicable by law. In relation to business data of its customers (such as inventory lists, part numbers, etc.), the Company acts in accordance with the customer’s instructions and within the framework of the business relationship with them, and this is not personal data as defined by law.7. Automated Decision Making and Profiling
The platform uses algorithmic tools and AI tools for component analysis, market value assessment, inventory classification, and commercial recommendations. It is clarified that these mechanisms operate in relation to the customer’s business data (components, part numbers, prices, market data) and do not process personal data of users for the purpose of automated decision-making. Accordingly, the Company does not perform automated decision-making regarding platform users, including profiling, as defined in Article 22 of the GDPR, and there are no automated decision processes in the system that significantly affect the user’s rights, status, or access to the services offered on the platform.8. Cookies
A “Cookie” is a small text file used for authentication, tracking browsing data, and saving information about users. Each cookie is created by a server and transferred to the user’s browser; the browser is what saves the cookies in the memory of the computer or device. The platform uses cookies for its regular and proper operation, user authentication, maintaining a login session, and ensuring data security. Modern browsers include the option to avoid receiving cookies and to delete existing cookies. However, it is clarified that blocking necessary cookies may harm the proper functioning of the platform and even prevent its use. If you do not know how to do this, check the help file of the browser you are using. The following types of cookies are used on the platform:- Strictly Necessary Cookies: Essential for the proper functioning of the platform, including for user login, maintaining an active session, protection against CSRF attacks, and maintaining data security. These cookies do not require prior consent from the user according to European law, as they are technically required to provide the service the user requested.
- Analytical / Performance Cookies: To the extent they are activated in the future, they will be used to collect aggregate statistical information on how the platform is used for the purpose of improving it. Activation of these cookies will only be done after receiving the user’s consent.
- Marketing Cookies and Targeted Advertising: The platform does not use marketing cookies, marketing pixels, or third-party tracking tools for advertising purposes.
9. Data Retention
We will retain your personal data for as long as it is reasonably required for the purpose of providing the services, managing the business relationship with you, enforcing our rights, and protecting our legitimate interests. At the end of the engagement with the customer, the authorized user will be removed from the active side of the platform; however, historical records, including logs, documentary information, and metadata, may be kept for an additional period. In addition, we will retain personal data as long as there is a legal obligation or permission to keep it for a longer period, including for accounting purposes, transaction documentation, meeting regulatory requirements, clarifying claims, managing legal proceedings, and fulfilling reporting obligations. Generally, the duration of data retention is determined according to the type of data and the purpose for which it was collected, and will not exceed what is required for that purpose.10. Data Security
The Company implements comprehensive technical and organizational security measures to protect personal data, including:- Encryption of traffic via HTTPS and HSTS;
- User identification via Google OAuth;
- Limiting access to authenticated users only via an Identity-Aware Proxy (IAP) mechanism;
- Encryption of keys and secrets using Secret Manager;
- Encryption of databases at rest and in transit;
- Role-Based Access Control (RBAC) at the application and infrastructure level (IAM);
- Database access is limited and performed solely through Google’s Auth Proxy, without exposure to the public network;
- Infrastructure protection using Cloudflare services;
- Performance of daily data backups;
- Implementation of Content Security Policy (CSP) rules and secure cookies.
11. Data Subject Rights under Israeli Law
11.1 Right of Access:
Under the Protection of Privacy Law, 5741-1981, every person is entitled to review data about them held in a database, either personally or through an authorized representative in writing or by a guardian.11.2 Right to Correction:
A person who reviewed data about them and found it to be incorrect, incomplete, unclear, or not up-to-date, may contact the Company with a request to correct or delete the data, all in accordance with the provisions of the law.11.3 Exercise of Rights:
Inquiries regarding rights should be directed to the Company via the contact methods listed at the top of this document. The Company will respond to inquiries within a reasonable period and in accordance with the provisions of the applicable law.12. Data Subject Rights under GDPR
To the extent that the GDPR applies to the processing of your personal data, the following rights are available to you:12.1 Right to Information and Access:
You are entitled to receive information regarding the processing of your personal data by the Company, as well as to receive a copy of the personal data we hold about you, in accordance with the provisions of Article 15 of the GDPR.12.2 Right to Rectification:
- You are entitled to request the correction of personal data we hold about you, to the extent the data is inaccurate or incomplete, in accordance with the provisions of Article 16 of the GDPR.
12.3 Right to Erasure (Right to be Forgotten):
In appropriate cases, you are entitled to request the deletion of personal data concerning you, for example, when the data is no longer necessary for the purposes for which it was collected, when you have withdrawn your consent and there is no other legal basis for processing, or when the processing was done unlawfully, in accordance with the provisions of Article 17 of the GDPR.12.4 Right to Restriction of Processing:
In certain cases, you are entitled to request to restrict the processing of your personal data, for example, when you contest the accuracy of the data, when the processing is unlawful but you do not wish to delete the data, or when the data is required for the clarification, exercise, or protection of legal rights, in accordance with the provisions of Article 18 of the GDPR.12.5 Right to Object to Processing:
Subject to the applicable law, you are entitled to object to the processing of personal data concerning you when the processing is based on our legitimate interest or that of a third party. In such a case, we will examine your request in accordance with the provisions of Article 21 of the GDPR.12.6 Right to Data Portability:
In appropriate cases and subject to the applicable law, you are entitled to request to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to request its transfer to a third party, to the extent technically possible, in accordance with the provisions of Article 20 of the GDPR.12.7 Withdrawal of Consent:
To the extent that the processing of your personal data is based on your consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out based on consent prior to its withdrawal. You may contact us at any time to withdraw consent via the contact details appearing at the top of this Privacy Policy.13. Reporting a Privacy Violation and Right to Lodge a Complaint with a Supervisory Authority
If you believe your privacy has been violated within the framework of or in connection with the platform’s activity, please contact the Company and detail the circumstances of the violation as you see it in your inquiry. Additionally, if you have questions or concerns regarding the processing of your personal data or if you wish to exercise your rights, the Company will respond within a reasonable time to your inquiries and provide you with the necessary information. You can contact the Company via the contact methods listed at the beginning of this document.Right to Lodge a Complaint with a Supervisory Authority:
To the extent you are a resident of Israel, you may lodge a complaint with the Privacy Protection Authority in the Ministry of Justice if you believe that the processing of your personal data violates the provisions of the Protection of Privacy Law. If you believe that the processing of your personal data violates the provisions of the GDPR to the extent they apply, you may lodge a complaint with the competent supervisory authority for data protection in the relevant country in the European Union, specifically in the country of your habitual residence, place of work, or the place where the alleged violation occurred.14. Changes to the Privacy Policy
We will regularly review and update our Privacy Policy to ensure it reflects our current data handling practices. All updates will be clearly provided to you, and we will obtain your consent as required by law. The updated version will be published on the platform and will take effect from the date of its publication. Privacy Policy updated: April 2026Appendix 1: Detailed Use of Cookies on the Site
| Cookie / Tool | Purpose | Category | Provider | Collected Data | Transfer to Third Parties | Retention Period |
|---|---|---|---|---|---|---|
| Google Analytics (GA4) | Analyze website traffic and usage | Analytics | Third party – Google | IP address (sometimes anonymized), pages viewed, time on site, traffic source, device and browser type | Yes – Google | Persistent |
| Sentry | Monitor errors and site performance | Necessary / Technical | Sentry (Functional Software) | Errors and performance tracking, technical browser and device data, IP address, session replay data | Yes – Sentry | Persistent |
| session-token | Ensure proper site operation and maintain user session | Necessary | Website (First party) | Encrypted session identifier | No | 7 days |
| company / companyId | Store user’s selected company | Necessary / Functional | Website (First party) | Company ID and company name | No | 7 days |
| impersonation | Allow admin to impersonate another user | Necessary | Website (First party) | Original user ID and authentication token | No | 24 hours |
| homepage | Redirect to appropriate homepage based on role | Functional | Website (First party) | Homepage URL | No | 7 days |
| nexfinity-global | Store UI preferences – dark/light mode, layout, colors | Functional | Website (First party) | User interface preferences (JSON) | No | Session |
| tour | Track completion of onboarding tours | Functional | Website (First party) | Tour completion status and date | No | Session |
| colorPref | Store color theme preference (light/dark) | Functional | Website (First party) | Light or dark value | No | Session |