Sorbet Agency
web designdigital marketingaboutcareerscontact
Sorbet Agency
web designdigital marketingaboutcareerscontact
Home › Privacy Policy

Privacy Policy

Last Updated: 9 July 2026

Sorbet Agency ("Sorbet", "we", "us", "our") is a digital marketing and web design agency based in Tel Aviv, Israel. This Privacy Policy explains how we collect, use, disclose, store, and protect information in connection with our website, our client dashboards and reporting platform, our integrations with third-party advertising, marketing, analytics, and business (CRM) systems, our website chatbot / AI sales-assistant services, and our other services (together, the "Services").

We work with clients located in Israel, the European Union / European Economic Area, the United Kingdom, the United States, and other jurisdictions. This Policy is drafted to meet our obligations under the Israeli Protection of Privacy Law, 5741-1981 and its regulations, including Amendment 13 ("Israeli Privacy Law"); the EU/UK General Data Protection Regulation ("GDPR"); and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where these laws differ, the section headed "Your Rights by Region" identifies which rules apply to you.

Sorbet acts in two different capacities, and your rights depend on which capacity applies:

  • Controller: for information Sorbet collects for its own purposes, such as data about visitors to sorbetagency.com, prospective clients who submit contact/onboarding forms, and Sorbet's own billing and account records, Sorbet determines the purposes and means of processing and is the "controller" (or, under Israeli law, the "database owner").
  • Processor / Service Provider: for data Sorbet accesses inside a client's connected advertising, analytics, CRM, or marketing accounts (for example, a client's Meta Ads account, Salesforce instance, or Brevo contact lists) in order to deliver dashboards, reporting, campaign management, or lead-sync services, Sorbet acts on the client's instructions as a "processor" (GDPR) or "service provider" (CCPA). The client remains the controller/business responsible for that underlying data, including for obtaining any consents needed from its own customers or leads.

Where Sorbet acts as a processor, a separate Data Processing Agreement ("DPA") with the client governs the terms of that processing and takes precedence over this Policy for that data. Clients are responsible for ensuring they have a valid legal basis and, where required, a DPA in place with Sorbet before connecting third-party accounts containing personal data.

1. Information We Collect

Each client is given access to a dedicated Sorbet platform (dashboard) that consolidates data from the client's connected advertising, marketing, CRM, and website systems. Operating this platform means Sorbet has visibility into a range of the client's own business and financial information, including revenue and sales figures, deal values, pipeline stage, and lead volumes, for the purpose of generating the client's reporting and running the client's campaigns. This information belongs to the client (or the client's own customers/leads); Sorbet processes it strictly as a processor/service provider on the client's instructions, as described throughout this Section 1 and in Section 10 (Confidentiality of Business & Financial Data).

1.1 Information You Provide Directly

Name, job title, company name, email address, phone number, billing and payment details, login credentials, and any other information you submit through contact forms, onboarding questionnaires, the "Book Online" scheduler, support requests, proposals, or other communications with us.

1.2 Job Applicant / Recruitment Information

Our website invites candidates to submit a CV/resume, together with a cover letter and any other information the candidate chooses to include (which may contain name, contact details, employment history, education, and, depending on what the candidate includes in their CV, special categories of data such as photo, age/date of birth, military service, or nationality), by email to [email protected] for open or prospective roles.

  • Purpose and legal basis: we use this information solely to evaluate candidates for current or future employment opportunities at Sorbet. Under GDPR, this is based on our legitimate interest in recruitment and steps taken at the candidate's request prior to entering a contract; under Israeli law it is processed in accordance with the Equal Employment Opportunities Law and standard recruitment practice.
  • Retention: CVs are retained for the duration of the relevant hiring process and for a limited period afterward (up to 24 months, consistent with Israeli employment-claim limitation periods) in case of a future suitable opening, unless the candidate asks us to delete their CV sooner or we are legally required to keep it longer (e.g., in connection with a discrimination claim).
  • Sharing: CV information is shared only internally with those involved in hiring decisions, and is not shared with clients or advertising/CRM platforms.

1.3 Information Collected Automatically from Our Website

When you visit sorbetagency.com, we (and our website platform, Wix, and analytics/advertising partners) may automatically collect device and usage information such as IP address, browser type, pages viewed, referring/exit pages, approximate location, and interaction data, using cookies and similar technologies described in Section 7 below.

1.4 Information from Connected Advertising & Marketing Platforms (Read and Write Access)

Our dashboard and campaign-management platform connect to clients' advertising and marketing accounts, including Meta (Facebook/Instagram) Ads and Pages, Google Ads, Google Analytics 4, Google Search Console, LinkedIn (including LinkedIn Ads and LinkedIn Lead Gen Forms), TikTok, and other advertising or marketing systems the client authorizes. We also connect to SEO/competitive-research tools such as Semrush and Ahrefs; these primarily return keyword, ranking, and site-audit data rather than personal data, but are listed here for completeness.

These connections are not limited to reporting. Depending on the service the client has engaged us for, our access may include:

  • Read access: retrieving campaign performance data, ad account structure, keywords, audiences, impressions, clicks, spend, conversions, lead form submissions, page/account insights, website analytics, and similar reporting metrics.
  • Write access: creating, editing, publishing, pausing, or deleting campaigns, ad sets, ads, audiences, budgets, creative assets, landing pages, or posts; and configuring pixels, conversion events, or lead-form integrations, on the client's behalf and under the client's instruction, in order to actually manage the client's advertising and marketing activity (not only to report on it).

We only request the specific permissions needed to provide the service the client has engaged us for, through each platform's own authorization/OAuth flow. The client controls and can revoke this access at any time directly within the relevant platform or by notifying us.

Data obtained from Meta and Google advertising accounts through these API connections is used solely for the stated function of that engagement - reporting, campaign management, and related dashboard functionality. This data is not combined with other personal information or PII datasets in a way that could identify an individual end user, and is not used for retargeting, profiling, or advertising purposes outside the stated function, except where the client has separately and explicitly authorized a specific retargeting or audience-building activity as part of the engaged service.

1.5 Information from Connected CRM & Business Systems

For clients who engage us to integrate, manage, or report on their customer relationship management (CRM) or business systems, including Salesforce, HubSpot, Klaviyo, and similar platforms, we may access business and financial information stored in those systems, such as:

  • Contact and lead records (names, emails, phone numbers, company affiliations, job titles);
  • Deal, pipeline, and sales-stage data;
  • Revenue and sales performance data, including the client's own total sales, deal/opportunity values, win/loss rates, and lead volumes, used to build the client's reporting and to measure campaign performance against actual business outcomes;
  • Business and account information (company size, industry, order/purchase history);
  • Financial data relevant to marketing and sales operations, such as deal values, invoice or quote references, subscription/plan tiers, and payment or billing status fields exposed by the CRM;
  • Email/SMS marketing data such as contact lists, segments, campaign engagement (opens, clicks, bounces, unsubscribes), and automation workflows.

We access CRM, business-system, and revenue/sales data only to the extent authorized by the client (for example, to sync leads, trigger campaigns, build audience segments, or generate unified reporting on revenue and pipeline outcomes) and only for that client's own account. We do not use one client's CRM, revenue, or financial data to benefit another client, and we do not use it to build independent profiles outside the scope of the engagement. See also Section 10 (Confidentiality of Business & Financial Data).

1.6 Website Chatbot / AI Sales-Assistant Data

For clients who engage us to deploy a chatbot on their website, Sorbet builds and operates the chat widget and its supporting server in-house; it is not a third-party chat SaaS product resold to clients. The chatbot is powered by the OpenAI API, which is used solely as the underlying LLM sub-processor that generates chat responses. We use OpenAI's zero-data-retention API tier, so OpenAI does not store or train on the content of chatbot conversations. Chat data itself is stored in Sorbet's own database. The chatbot is designed to answer visitor questions, qualify leads, and support the client's sales process.

Depending on what a visitor chooses to share in the conversation, the chatbot may collect:

  • Information voluntarily typed into the chat (questions, name, email, phone number, company, and the substance of the conversation);
  • Standard technical data about the visitor's session (IP address, device/browser type, page the chat was opened from), consistent with Section 7 (Cookies);
  • Where connected, the resulting lead/contact record may be pushed into the client's CRM or ad platform audiences, as described in Sections 1.4 and 1.5.

The chatbot is configured for lead-generation and customer-support purposes only and is not designed or intended to solicit payment card numbers, government ID numbers, or other special-category/sensitive data. For clients operating in regulated or sensitive sectors (for example, healthcare or clinical-trial-related services), the chatbot includes an active safeguard: it is configured to detect when a visitor begins sharing confidential, health, or clinical information, interrupt that part of the exchange, and avoid repeating the sensitive content back to the visitor or retaining it further. If a client's chat flow is later expanded to take orders or payments, this Policy and the underlying service agreement will need to be updated accordingly before that expansion goes live.

  • Role: as with connected ad and CRM platforms, Sorbet processes chatbot conversation data as a processor/service provider on the client's instructions. The client is the controller responsible for the website visitors it collects data from through the chatbot, including for the notices described below.
  • Automated processing: the chatbot may use automated logic to qualify or route a lead (e.g., based on the answers given). This does not currently involve fully automated decisions that produce legal or similarly significant effects on an individual (e.g., it does not autonomously approve/deny credit, pricing, or service eligibility). If that scope ever changes, GDPR Art. 22 disclosure and human-review rights would need to be built in.
  • Retention: chat transcripts are stored in Sorbet's own database and are retained for 12 months from the date of the visitor's last message, after which they are deleted or anonymized, unless the visitor became a customer, in which case ordinary CRM retention applies.

1.7 Cross-Platform Reporting

Where authorized, our platform combines data from multiple connected sources (e.g., Meta, Google, LinkedIn, Google Analytics, and a client's CRM) into unified dashboards so a client can compare advertising performance, lead generation, website traffic, and pipeline/revenue outcomes in one place. Cross-platform reporting is generated only within the authorized client's own account and is not combined with, or used for the benefit of, any other client.

2. API Access and Permissions

Many of our integrations are built directly on the APIs of the relevant platform (e.g., Meta Marketing API, Google Ads API, LinkedIn Marketing API, Salesforce API, Brevo API). When a client connects an account, the client authorizes Sorbet to access specified data and/or functionality through that platform's official permission or OAuth process.

On certain platforms, completing an API connection during onboarding is a mandatory prerequisite set by the platform itself - for example, some ad platforms require a live API integration to be established, and in some cases require the associated app or use case to be reviewed and approved by the platform, before full account access or certain permissions (such as Lead Ads access) are granted. In those cases, the API connection step is not optional; it is required by the third-party platform in order for the client's account to be approved for use with our services, and we will explain this to the client during onboarding.

We request only the scopes/permissions needed for the services engaged. Clients may disconnect any integration at any time; once disconnected, we stop syncing new data from that source, subject to the technical, legal, security, backup, and operational requirements described in Section 5.

3. How We Use Information

We use the information described above to:

  • Provide, operate, and improve our website, dashboards, and reporting platform;
  • Build, launch, and manage advertising, SEO, SEM, social, email, retargeting, and native-advertising campaigns on a client's behalf;
  • Sync leads between connected platforms and a client's CRM, and send notifications about new leads;
  • Generate cross-platform performance reports and analytics;
  • Communicate with clients and prospective clients, including scheduling and onboarding;
  • Process billing and payments;
  • Maintain the security, integrity, and proper functioning of our Services;
  • Comply with legal obligations and enforce our agreements.

Legal bases under GDPR: where GDPR applies, we (or the client, as controller) rely on one or more of the following legal bases: performance of a contract with the client, the client's or Sorbet's legitimate interests in providing/operating the Services, compliance with a legal obligation, and, where required (e.g., certain cookies or direct marketing to individuals), consent.

4. Data Sharing and Sub-Processors

We do not sell personal information, marketing data, lead data, CRM data, or other third-party platform data.

We may share limited information with trusted service providers who help us operate our website, dashboards, platform, hosting/infrastructure, analytics, customer support, email delivery, payment processing, chatbot/AI functionality, and security ("sub-processors"). These providers may include, for example, our website/hosting provider (Wix), cloud infrastructure providers, our chatbot/AI platform provider (and, if applicable, the underlying LLM provider it relies on to generate responses), and the advertising/CRM platforms themselves as necessary to deliver the connected service. Sub-processors are contractually restricted to using information only to provide services to us and may not use it for their own independent purposes.

We may also disclose information where required by law, to protect our rights or the rights of others, to investigate fraud or security issues, or in connection with a merger, acquisition, or sale of assets (subject to confidentiality protections).

5. Data Retention

As a general principle, we retain information only for as long as needed for the purpose it was collected for and delete or anonymize it once that purpose no longer applies, subject to the legal, accounting, and security needs described below. Approximate retention criteria by category:

  • Website visitor/analytics data: consistent with the retention settings of the underlying analytics/cookie tool (typically 14-26 months), see Section 7.
  • Contact form / prospective client inquiries: for the duration of the sales conversation, and for a reasonable follow-up period afterward if no engagement results (no longer than necessary for that purpose), then deleted.
  • Client account, billing, and invoicing records: for the duration of the engagement and up to 7 years afterward, to meet Israeli bookkeeping/tax recordkeeping obligations.
  • Ad platform, CRM, and chatbot data accessed through the Service: for the duration of the engagement, per the client's own retention settings in the connected platform; deleted from our own systems within a reasonable period following the client disconnecting the integration or ending the engagement (no longer than necessary for transition, backup, or legal purposes), except for backups (see below).
  • Job applicant/CV data: as described in Section 1.2 (up to 24 months).

Clients (and, where applicable, individuals) may request deletion of their data by contacting us using the details in Section 14. Some information may be retained after such a request where required by law, security, accounting, backup, or legitimate business needs, in which case it will be securely isolated and/or anonymized where feasible.

Under the Israeli Protection of Privacy Law and its regulations, including Amendment 13, personal data may not be retained for longer than necessary to fulfil the purpose for which it was collected. Consistent with this, we align retention with the categories above. Billing, invoicing, and related financial records are kept for 7 years to comply with recordkeeping obligations under the Israeli Tax Ordinance and Companies Law.

Under the GDPR/UK GDPR storage-limitation principle (Art. 5(1)(e)), we do not keep personal data in identifiable form for longer than necessary for the purposes set out in this section. Where you ask us to delete your data and no legal or accounting exception applies, we will do so within the timeframe required by applicable law.

Consistent with CCPA/CPRA disclosure requirements, the categories and retention criteria above describe how long we keep each category of personal information, or the criteria used to determine that period, where a fixed period cannot be given (for example, because retention depends on the length of the client engagement).

6. Data Security and Breach Notification

We take reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, disclosure, alteration, or destruction, including access controls, encryption in transit, and limiting integration permissions to what is necessary for the service.

You should never share passwords, API keys, access tokens, or login credentials with anyone, including Sorbet staff outside authorized account-setup processes.

Access to the Sorbet client dashboard/platform is secured with two-factor authentication (2FA). Account holders primarily authenticate using a one-time verification code sent to their email address, or via a third-party authenticator app (e.g., Google Authenticator or Authy) using the TOTP standard. Where enabled for a specific account, a verification code may also be sent via WhatsApp to the phone number on file as an additional option. This use of WhatsApp is limited to delivering account-security verification codes; it is not used to send marketing or promotional messages and is a separate function from the client-facing chatbot described in Section 1.6.

If we become aware of a security incident affecting personal data we control or process, we will notify affected clients and take the following steps depending on where the affected individuals or the incident are located:

  • Under the Privacy Protection Regulations (Data Security), 5777-2017, and Amendment 13, we will notify the Israeli Privacy Protection Authority without undue delay in the event of a severe security incident and will notify affected individuals where the incident is likely to adversely affect them, in accordance with the Authority's guidance.
  • Under the GDPR/UK GDPR, where a breach is likely to result in a risk to the rights and freedoms of individuals, we (or the client, as controller, where Sorbet is the processor) will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33). Where a breach is likely to result in a high risk to individuals, affected individuals will also be notified without undue delay (Art. 34).
  • US breach-notification obligations are set primarily at the state level and timelines vary; the general standard is notification to affected individuals "without unreasonable delay," with some states imposing fixed maximum timeframes and/or requiring notice to a state Attorney General or regulator. We will follow the notification requirements of the states where affected individuals reside.

7. Cookies and Tracking Technologies

Our website and platform use cookies, pixels, tags, and similar technologies for the following purposes:

  • Strictly necessary: required for the website/platform to function (e.g., login sessions, security);
  • Analytics/performance: to understand how visitors use our site (e.g., Google Analytics);
  • Marketing/advertising: to measure and support our own marketing (e.g., Meta Pixel, LinkedIn Insight Tag, Google Ads tags), and, on client sites where we implement retargeting, similar tags configured for the client.

Where required by applicable law (including GDPR/ePrivacy rules and evolving Israeli guidance), we will obtain consent before setting non-essential cookies via a cookie consent banner, and allow you to change your preferences at any time. You can also control cookies through your browser settings; disabling cookies may affect site functionality.

8. International Data Transfers

Sorbet is based in Israel and may use service providers and platforms located in other countries (including the United States and EU). As a result, information may be processed or stored outside your country of residence.

  • From the EU/EEA/UK: Israel benefits from an EU adequacy decision (and a corresponding UK adequacy finding), so transfers of personal data from the EEA/UK to Israel are permitted without additional safeguards on that basis. Where Sorbet or its sub-processors transfer EU/UK personal data onward to countries without an adequacy decision (e.g., certain U.S. sub-processors), we rely on appropriate safeguards such as the EU Standard Contractual Clauses / UK IDTA, as applicable.
  • From Israel/elsewhere: we take reasonable contractual and technical steps to ensure a comparable level of protection when data is processed abroad.
  • Chatbot hosting: the server supporting the website chatbot described in Section 1.6 is hosted in the UK/EU (DigitalOcean, London region), specifically so that UK and EU visitor chat data is not transferred to a third country in the course of ordinary chatbot operation.

9. Your Rights by Region

9.1 Israel

Under the Israeli Protection of Privacy Law, 5741-1981 (as amended by Amendment 13), individuals may request to inspect the personal information held about them in a database, request correction of inaccurate information, and object to certain uses (such as direct mailing). Where Sorbet or a client's database is subject to registration requirements, we will maintain such registration as required. You also have the right to lodge a complaint with the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות) if you believe your rights under this law have been violated. To exercise these rights with Sorbet, contact us at [email protected].

9.2 European Union / EEA / United Kingdom (GDPR / UK GDPR)

If GDPR or UK GDPR applies to you, you have the right to request access to, rectification or erasure of, restriction of or objection to processing of, and portability of your personal data, and the right to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at [email protected].

9.3 United States (including California - CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we have collected about you, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information (as those terms are defined by the CCPA/CPRA) and to be free from discrimination for exercising these rights.

If you are a resident of another U.S. state with a comprehensive privacy law in effect, including, among others, Virginia, Colorado, Connecticut, Utah, and other states that have since enacted similar legislation, you have broadly similar rights: to confirm and access the personal information we hold about you, to correct or delete it, and to opt out of its use for targeted advertising, sale, or (in some states) certain profiling. Where the applicable state law requires it (for example, Colorado and Connecticut), you also have the right to appeal a denied request; instructions for doing so will be provided in our response if we deny a request.

We do not sell personal information for money. To the extent any use of cookies/pixels for advertising purposes could be considered "sharing" under CPRA, we provide a mechanism to opt out as described in Section 7.

9.4 Exercising Your Rights

To exercise any of the above rights, contact us using the details in Section 14. We may need to verify your identity before fulfilling a request. We will respond within the timeframe required by applicable law.

10. Confidentiality of Business & Financial Data

Because our platform gives Sorbet visibility into a client's own revenue, sales, deal-value, lead, and other business/financial data (Section 1.5), Sorbet treats this information as confidential. We:

  • Use it only to deliver the services the client has engaged us for (reporting, campaign management, lead sync, and similar purposes), not for any other purpose;
  • Do not disclose it to other clients, and do not use it to benchmark, profile, or advantage any other client's account;
  • Do not sell it or share it with third parties for their own marketing or other independent purposes;
  • Limit internal access to staff who need it to service that client's account;
  • Apply the same security measures described in Section 6 to this data as to all other personal data we process.

This confidentiality commitment is in addition to, and does not replace, any separate confidentiality or non-disclosure terms in the client's services agreement or Terms & Conditions with Sorbet.

11. Client Responsibilities

Each client is responsible for ensuring it has the proper rights, permissions, and (where applicable) legal basis or consents to connect its advertising, analytics, CRM, or lead-generation accounts to our platform, and to authorize Sorbet's read and/or write access to those accounts. Clients using CRM or email-marketing systems remain responsible for the accuracy of, and their own legal basis for holding, the contact and lead data in those systems.

Where Sorbet sends or helps send marketing communications (email, SMS, or similar) on a client's behalf using the client's own contact lists, the client is responsible for ensuring it holds valid opt-in consent for such messages and provides a working unsubscribe/opt-out mechanism, as required under the Israeli Communications Law (Telecommunications and Broadcasting), 5742-1982, Section 30A (the "Anti-Spam Law"), and, where applicable, equivalent laws such as GDPR/ePrivacy rules, the U.S. CAN-SPAM Act, and Canada's CASL. Sorbet does not verify the consent basis of client-supplied contact lists and relies on the client's warranty that valid consent exists. This does not apply to Sorbet's own transactional use of email or WhatsApp to deliver two-factor authentication codes to dashboard account holders (Section 6), which is a security function, not a marketing communication.

12. Children's Privacy

Our Services are directed to businesses and are not intended for individuals under 16 (or the relevant age of digital consent in your jurisdiction). We do not knowingly collect personal information from children through our website.

13. Third-Party Websites and Social Media Pages

Our website and platform may link to or integrate with third-party websites, platforms, or applications (including the advertising, analytics, and CRM platforms described above). We are not responsible for the privacy or security practices of those third parties, and your use of them is subject to their own terms and privacy policies.

Our website links to Sorbet's own pages on Instagram, Facebook, and X (Twitter). If you click through to and interact with these pages (for example, by following, messaging, commenting, or liking), that platform collects and processes your information under its own privacy policy and terms, and Sorbet has no control over that processing. As the operator of these pages, Sorbet may, in some cases, act as a joint controller with the platform for aggregated page insights/analytics (e.g., follower demographics, post engagement statistics) that the platform makes available to page administrators; Sorbet does not itself receive individual message content or profile data beyond what the platform's page-admin tools expose. We recommend reviewing Instagram's, Facebook's (Meta's), and X's own privacy policies before interacting with our pages.

14. Contact Us

Sorbet Agency
Midtown Tower, Menachem Begin 144, Tel Aviv, Israel
Email: [email protected]
DPO contact: [email protected]

15. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Where changes are material, we will provide additional notice as required by applicable law. Continued use of our website or Services after changes are posted constitutes acceptance of the updated Policy.

home web design digital marketing about contact book a meeting

Contact us

By submitting this form, you agree to our Privacy Policy.

Wix Partner Legend Google Partner Wix Studio Certified Web Designer Expert
Sorbet Agency

[email protected]

© 2025 by Sorbet Agency. Privacy Policy T&C