Privacy Policy
Effective: September 2026
Document language: Hebrew & English (Hebrew governs)
๐ Table of Contents
1. Introduction
Maximizer AI Ltd. ('Company', 'we') operates the Maximizer AI Active Intelligence Layer platform for the Property & Casualty insurance industry. The Platform delivers real-time call analysis, claims management, and forensic intelligence to insurance carriers.
This Privacy Policy describes how we collect, process and protect Personal Information under the Israeli Privacy Protection Law, 5741-1981 (as amended), including Amendment No. 13 effective 14 August 2025, and the Privacy Protection (Data Security) Regulations, 5777-2017.
2. Identity & Contact Details
| Detail | Information |
|---|---|
| Company Name | Maximizer AI Ltd. |
| Domicile | Israel |
| US Marketing | Maximizer AI Inc. (US affiliate) |
| Website | https://maximizer.ai |
| Privacy Email | privacy@maximizer.ai |
| DPO | Data Protection Officer: privacy@maximizer.ai |
The Company is the 'Database Controller' under the Law for customer, platform-user, and website-user Personal Information. With respect to policyholder data provided by insurance carrier clients, the Company acts as a 'Database Holder' (data processor) on their behalf, and in the US as a 'Service Provider' under applicable state privacy laws.
The Platform is marketed in the US by Maximizer AI Inc. (affiliate). Data processing is performed by Maximizer AI Ltd.
3. Personal Information Collected
3.1 Information We Collect Directly
- Identity: name, email, phone, job title
- Account: username, encrypted password, access tier
- Platform usage: actions, logs, preferences
- Communications: support or privacy enquiries
3.2 Policyholder Data Processed on Behalf of Clients
When providing services to insurance carrier clients, we process policyholder Personal Information under their instructions, including:
- Call recordings and transcripts
- Claim details (claim number, event type, amounts)
- AI analysis outputs: risk scores, summaries, recommendations
Call recording is performed by the carrier client; the client is responsible for obtaining required consents to record.
3.3 Voice Processing & Biometric Information
The Platform transcribes voice recordings and analyzes the transcripts for business intelligence. We do not create, collect, or store voiceprints or biometric identifiers as defined under biometric privacy laws (such as BIPA or Texas CUBI). Voice analysis is text-based only, not speaker identification.
4. Legal Basis for Processing
Under the amended Privacy Protection Law, we rely on the following legal bases:
| Purpose | Legal Basis | Law Reference |
|---|---|---|
| Platform service delivery | Contract | Civil Law; Privacy Protection Law |
| User account management | Contract + Consent | Amendment 13 ยง5a |
| Fraud & risk detection | Legitimate interest of insurer | Insurance Law, 5741-1981 |
| Legal & regulatory compliance | Legal obligation | Privacy Protection Law; Data Security Regulations |
| Platform improvement | Consent + Legitimate interest | Amendment 13 |
5. Data Subject Rights
Amendment 13 strengthens data subject rights. The following rights apply to you:
| Right | Description |
|---|---|
| Right of Access | Receive a copy of Personal Information held about you |
| Right to Rectification | Request correction of inaccurate or incomplete data |
| Right to Erasure | Request deletion subject to legal conditions |
| Right to Object | Object to processing based on legitimate interest |
| Right to Restrict | Request restriction in defined circumstances |
| Compensation without Proof of Damage | Amendment 13 allows courts to award damages without proof of actual harm |
To exercise your rights, contact our DPO: privacy@maximizer.ai. We will respond within 30 days (extendable to 60 days for complex requests with prior notice).
6. Data Security, Hosting & Tenant Isolation
The Platform is classified at the highest security level under the Privacy Protection (Data Security) Regulations, 5777-2017, and operated under ISO/IEC 27001:2022 (IQC certificate #I33153). Security measures include:
- AES-256 encryption at rest; TLS 1.3 in transit
- Multi-factor authentication (MFA) for all platform users
- Role-based access control (RBAC) and principle of least privilege
- Cloud hosting: Amazon Web Services, Microsoft Azure, or Google Cloud Platform (infrastructure hosts for dedicated single-tenant customer environments)
- Immutable audit logs for all sensitive data access
- SOC 2 Type II: audit underway
6.1 Single-Tenant Isolation
Each customer runs in a dedicated single-tenant environment in a private VPC with no outbound internet access. Compute, storage and model weights are not shared across tenants. File ingest and results move via isolated Cloud Storage; the user interface sits behind Google Cloud Armor with regional and IP-based filtering.
6.2 No Training on Client Data
Client data is not used to train general or shared AI models. Where a customer requests per-tenant fine-tuning, the process runs only inside that customer's isolated environment, requires the customer's prior written consent, and is governed by a Data Processing Agreement. This commitment is contractual, not merely policy.
In the event of a data security incident that may harm data subjects, we will notify the Privacy Protection Authority and relevant data subjects as required by law.
8. International Data Transfers
The Platform is hosted in Israel and the EU (europe-west4 region). Transfers outside the EEA are protected by Standard Contractual Clauses (SCCs) and Israel's EU adequacy decision status.
9. Data Retention
| Data Type | Retention | Justification |
|---|---|---|
| Call recordings | Per carrier client instruction | Processor (client governs) |
| AI analysis outputs | ~7 years | Amendment 13 limitation period |
| User account data | ~3 years post-contract | Contractual & regulatory |
| Audit logs | ~7 years | ISO/IEC 27001:2022 and regulatory |
10. Data Protection Officer
Pursuant to Amendment 13, we have appointed a Data Protection Officer (DPO). The DPO is responsible for:
- Ensuring organisational compliance with privacy laws
- Handling data subject requests and enquiries
- Liaison with the Privacy Protection Authority
- Managing training programmes and internal controls
Contact the DPO: privacy@maximizer.ai
16. Policy Updates
We may update this Policy periodically. Material changes will be published 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the changes.
13. US State Privacy Rights
In addition to rights under Israeli Privacy Protection Law, residents of US states with dedicated privacy laws (such as California, Virginia, Colorado) may be entitled to additional rights under those laws.
We do not sell or share Personal Information for cross-context behavioral advertising. For US privacy rights enquiries, contact: privacy@maximizer.ai
14. Children
Our services are not directed to children under 13. We do not knowingly collect Personal Information from children under 13. If we become aware that we have collected such information, we will delete it promptly.
15. Complaints
If you believe your Personal Information has been handled unlawfully, you may contact:
- Company DPO: privacy@maximizer.ai
- Privacy Protection Authority: https://www.gov.il
The civil limitation period for claims under the Privacy Protection Law has been extended to 7 years by Amendment 13.
Privacy enquiries: privacy@maximizer.ai

