Privacy Policy
of Dinamic5 Business
We take your privacy seriously. This document explains how we collect, use, and protect your personal information.
Last updated: May 2026
1. Overview — Controller Identity
Dinamic5 (the "Company", "we") operates the business.dinamic5.com website and the CRM platform with WhatsApp Business Cloud API integration from Meta (the "Service"). This privacy policy applies to all users of the website and the Service.
Use of the Service constitutes acceptance of this privacy policy. If you do not agree, please refrain from using the Service.
Privacy contact:
- Email: privacy@dinamic5.com
- Phone: +972-53-380-6759
2. Information We Collect
2.1 Account registration data
- First and last name
- Email address (used for login)
- Phone number
- Company name (optional)
- Country (used to set language, time zone, currency, and phone prefix)
2.2 CRM content you enter
- Business records: leads, contacts, accounts, deals, quotes, invoices, sales orders, projects, tasks, tickets
- Files and documents you upload
- Automation configurations and execution logs
2.3 WhatsApp Business Cloud API communications data
- Messages: full message content, recipient phone numbers, timestamps, delivery statuses (sent / delivered / read), media files (images, video, documents) — routed via Meta's official Cloud API infrastructure
- Message templates: templates you create, template content, Meta approval status
- Conversation metadata: Meta Conversation IDs, conversation type (Marketing / Utility / Authentication / Service)
- Call recordings (Virtual PBX, optional): phone numbers, call duration, timestamps, recording URLs stored with the telephony provider
- Email: if you've configured an inbox sync — incoming and outgoing email content
2.4 Login and security data
- Login history: IP address and timestamp on each session
- Change tracking (audit trail): record modification history
2.5 Automatically collected website data
- IP address, browser type, operating system (server logs only)
- Access timestamp
2.6 Billing data
- Payment details are processed directly by payment providers — we do not store credit card numbers
- Billing cycle, plan, subscription IDs, transaction history
3. Purposes & Legal Basis
We use the information collected for the following purposes:
- Contract performance: operating the Service, granting platform access, account administration, technical support
- Contract performance: processing payments and managing subscriptions
- Legitimate interest: service improvement, new feature development, performance monitoring, security
- Legitimate interest: fraud prevention and unauthorized access protection
- Legal obligation: compliance with law, regulation, and tax reporting
- Consent: sending updates and marketing communications (revocable at any time)
We do not sell, rent, or transfer your personal data to third parties for marketing purposes.
4. Controller vs. Processor
Dinamic5 acts in different capacities depending on the data type:
- Data Controller: for account registration, billing, and platform-usage data.
- Data Processor: for CRM content and WhatsApp message content entered by our customers (contacts, leads, deals, messages, documents, call recordings). Customers are the Controllers of that content.
Customers are responsible for ensuring they have a lawful basis to process the personal data of their own end customers through the platform — including obtaining recipient consent for WhatsApp messages in line with Meta's policies.
5. Third-Party Sharing
We share data with third parties only in the following cases:
- Meta Platforms, Inc.: message content, metadata, and templates are transmitted to Meta via the WhatsApp Business Cloud API for delivery to WhatsApp. Subject to Meta Business Tools Terms and WhatsApp Business Policy.
- Transactional email providers: for account activation and password reset emails
- Cloud telephony providers (optional): for call routing, recording, and virtual numbers
- Payment processors: for subscription billing — Israeli and international providers
- Infrastructure provider: servers hosted in Germany (European Union)
- DNS and email provider: DNS management and email forwarding
- Integrations you configure: services you connect (Google, Facebook, etc.) — per your settings only
- Legal requirement: when required by law, court order, or legal process
Current list of sub-processors is available on request at privacy@dinamic5.com.
6. Security
We use modern security controls to protect your information:
- TLS 1.3 encryption in transit
- Encryption at rest (Data at Rest)
- Per-customer isolated database (Row-Level Security)
- Daily automated encrypted backups
- Secured servers with 24/7 monitoring
- Role-based access control (RBAC)
- Comprehensive audit logging
While we make every reasonable effort to protect your data, no system can guarantee 100% security. We commit to notifying you without undue delay in the event of a security incident that may affect your privacy.
7. Data Retention & Deletion
- Customer CRM content: upon account closure, all CRM data (database + files) is deleted within 30 days. Backups are deleted within 90 days.
- Account registration data: name, email — retained up to 12 months after account closure for legal and audit purposes.
- Billing data: retained per legal requirements (up to 7 years for tax purposes).
- Call recordings: retained per the telephony provider's policy and customer settings.
- WhatsApp Business message content: retained as long as the account is active and deleted upon account closure. Metadata stored by Meta is subject to Meta's retention policies.
For specific deletion requests, see the Data Deletion page.
8. Cookies
This site uses only essential cookies:
- Session cookie (PHPSESSID): required for authentication and login — essential for system function
We do not use tracking cookies, analytics cookies, or advertising cookies. No third-party scripts install cookies on this site.
9. International Data Transfers
Our servers are located in Germany (European Union). Your data may be transferred to:
- Israel: recognized by the European Union as offering an adequate level of protection (Adequacy Decision 2011/61/EU).
- United States: Meta Platforms and certain sub-processors (email, telephony, DNS) are US-based. Transfers occur under Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
- United Kingdom: an international payment processor is UK-based — covered by the European Union adequacy decision for the UK.
10. Your Rights
Under the Israeli Privacy Protection Law 5741-1981 and the GDPR (for EU residents), you have the following rights:
- Access: view the personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data (subject to legal requirements)
- Restriction: restrict how your data is used in certain circumstances
- Object: object to processing based on legitimate interest
- Portability: receive a copy of your data in a structured format
- Unsubscribe: opt out of mailing lists at any time
- Withdraw consent: revoke any consent previously given
To exercise your rights, contact us at privacy@dinamic5.com or +972-53-380-6759.
Right to lodge a complaint:
- Israeli users may lodge a complaint with the Privacy Protection Authority — www.gov.il
- EU users may lodge a complaint with their national data protection supervisory authority
11. Automated Decision-Making
We do not perform automated decision-making or profiling with legal or similarly significant effects on you.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this site and registered users will be notified. Continued use of the Service after an update constitutes acceptance of the updated policy.
13. Contact
For questions or requests about this privacy policy:
- Email: privacy@dinamic5.com
- Phone: +972-53-380-6759
14. Governing Law & Jurisdiction
This privacy policy is governed by Israeli law. Exclusive jurisdiction for any matter relating to this policy lies with the competent courts of the Tel Aviv district.