Privacy Policy

Effective: September 2026

Document language: Hebrew & English (Hebrew governs)

๐Ÿ“‹ Table of Contents

1. Introduction

Maximizer AI Ltd. ('Company', 'we') operates the Maximizer AI Active Intelligence Layer platform for the Property & Casualty insurance industry. The Platform delivers real-time call analysis, claims management, and forensic intelligence to insurance carriers.

This Privacy Policy describes how we collect, process and protect Personal Information under the Israeli Privacy Protection Law, 5741-1981 (as amended), including Amendment No. 13 effective 14 August 2025, and the Privacy Protection (Data Security) Regulations, 5777-2017.

2. Identity & Contact Details

DetailInformation
Company NameMaximizer AI Ltd.
DomicileIsrael
US MarketingMaximizer AI Inc. (US affiliate)
Websitehttps://maximizer.ai
Privacy Emailprivacy@maximizer.ai
DPOData Protection Officer: privacy@maximizer.ai

The Company is the 'Database Controller' under the Law for customer, platform-user, and website-user Personal Information. With respect to policyholder data provided by insurance carrier clients, the Company acts as a 'Database Holder' (data processor) on their behalf, and in the US as a 'Service Provider' under applicable state privacy laws.

The Platform is marketed in the US by Maximizer AI Inc. (affiliate). Data processing is performed by Maximizer AI Ltd.

3. Personal Information Collected

3.1 Information We Collect Directly

  • Identity: name, email, phone, job title
  • Account: username, encrypted password, access tier
  • Platform usage: actions, logs, preferences
  • Communications: support or privacy enquiries

3.2 Policyholder Data Processed on Behalf of Clients

When providing services to insurance carrier clients, we process policyholder Personal Information under their instructions, including:

  • Call recordings and transcripts
  • Claim details (claim number, event type, amounts)
  • AI analysis outputs: risk scores, summaries, recommendations

Call recording is performed by the carrier client; the client is responsible for obtaining required consents to record.

3.3 Voice Processing & Biometric Information

The Platform transcribes voice recordings and analyzes the transcripts for business intelligence. We do not create, collect, or store voiceprints or biometric identifiers as defined under biometric privacy laws (such as BIPA or Texas CUBI). Voice analysis is text-based only, not speaker identification.

5. Data Subject Rights

Amendment 13 strengthens data subject rights. The following rights apply to you:

RightDescription
Right of AccessReceive a copy of Personal Information held about you
Right to RectificationRequest correction of inaccurate or incomplete data
Right to ErasureRequest deletion subject to legal conditions
Right to ObjectObject to processing based on legitimate interest
Right to RestrictRequest restriction in defined circumstances
Compensation without Proof of DamageAmendment 13 allows courts to award damages without proof of actual harm

To exercise your rights, contact our DPO: privacy@maximizer.ai. We will respond within 30 days (extendable to 60 days for complex requests with prior notice).

6. Data Security, Hosting & Tenant Isolation

The Platform is classified at the highest security level under the Privacy Protection (Data Security) Regulations, 5777-2017, and operated under ISO/IEC 27001:2022 (IQC certificate #I33153). Security measures include:

  • AES-256 encryption at rest; TLS 1.3 in transit
  • Multi-factor authentication (MFA) for all platform users
  • Role-based access control (RBAC) and principle of least privilege
  • Cloud hosting: Amazon Web Services, Microsoft Azure, or Google Cloud Platform (infrastructure hosts for dedicated single-tenant customer environments)
  • Immutable audit logs for all sensitive data access
  • SOC 2 Type II: audit underway

6.1 Single-Tenant Isolation

Each customer runs in a dedicated single-tenant environment in a private VPC with no outbound internet access. Compute, storage and model weights are not shared across tenants. File ingest and results move via isolated Cloud Storage; the user interface sits behind Google Cloud Armor with regional and IP-based filtering.

6.2 No Training on Client Data

Client data is not used to train general or shared AI models. Where a customer requests per-tenant fine-tuning, the process runs only inside that customer's isolated environment, requires the customer's prior written consent, and is governed by a Data Processing Agreement. This commitment is contractual, not merely policy.

In the event of a data security incident that may harm data subjects, we will notify the Privacy Protection Authority and relevant data subjects as required by law.

7. Data Sharing with Third Parties

We do not sell or share Personal Information for cross-context behavioral advertising. We may share data with:

  • Authorised access holders: employees and contractors with a business need to know
  • Affiliates: Maximizer AI Inc. (US affiliate)
  • Cloud infrastructure providers: Amazon Web Services, Microsoft Azure, or Google Cloud Platform (hosting dedicated single-tenant customer environments; not AI vendors)
  • Regulators and law enforcement: only under legal obligation
  • Insurance carrier clients: analysis outputs relating to their policyholders

All AI processing (speech-to-text and language-model inference) runs inside the customer's dedicated single-tenant cloud environment. No customer data is sent to external model services.

Operational infrastructure providers (monitoring, support) do not receive access to Platform policyholder data.

All sub-processors are bound by Data Processing Agreements (DPAs) compliant with the Privacy Protection Law, including the UK IDTA or EU Standard Contractual Clauses where applicable. An up-to-date sub-processor list is available on the website's Security / Trust page.

8. International Data Transfers

The Platform is hosted in Israel and the EU (europe-west4 region). Transfers outside the EEA are protected by Standard Contractual Clauses (SCCs) and Israel's EU adequacy decision status.

9. Data Retention

Data TypeRetentionJustification
Call recordingsPer carrier client instructionProcessor (client governs)
AI analysis outputs~7 yearsAmendment 13 limitation period
User account data~3 years post-contractContractual & regulatory
Audit logs~7 yearsISO/IEC 27001:2022 and regulatory

10. Data Protection Officer

Pursuant to Amendment 13, we have appointed a Data Protection Officer (DPO). The DPO is responsible for:

  • Ensuring organisational compliance with privacy laws
  • Handling data subject requests and enquiries
  • Liaison with the Privacy Protection Authority
  • Managing training programmes and internal controls

Contact the DPO: privacy@maximizer.ai

11. Cookies and Similar Technologies (Public Website Only)

This section applies to the public marketing website maximizer.ai only. Platform customer/policyholder processing does not rely on marketing-site cookies.

  • Essential/functionality cookies (language, session): required for the site to work
  • Website monitoring/analytics on public marketing site only (not advertising; separate from Platform)
  • No advertising or cross-site marketing cookies on maximizer.ai

You may control non-essential cookies via the banner or your browser. Blocking essential cookies may break basic site features.

16. Policy Updates

We may update this Policy periodically. Material changes will be published 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the changes.

13. US State Privacy Rights

In addition to rights under Israeli Privacy Protection Law, residents of US states with dedicated privacy laws (such as California, Virginia, Colorado) may be entitled to additional rights under those laws.

We do not sell or share Personal Information for cross-context behavioral advertising. For US privacy rights enquiries, contact: privacy@maximizer.ai

14. Children

Our services are not directed to children under 13. We do not knowingly collect Personal Information from children under 13. If we become aware that we have collected such information, we will delete it promptly.

15. Complaints

If you believe your Personal Information has been handled unlawfully, you may contact:

  • Company DPO: privacy@maximizer.ai
  • Privacy Protection Authority: https://www.gov.il

The civil limitation period for claims under the Privacy Protection Law has been extended to 7 years by Amendment 13.