Balance — Israel Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Israeli resident covered by this Annex; the Privacy Protection Officer ("PPO" — the Israeli statutory equivalent of a Data Protection Officer) under section 17B1 of the Protection of Privacy Law, 5741-1981 (the "PPL") as introduced by the Protection of Privacy Law (Amendment No. 13), 5784-2024 (the "Amendment 13") published in Reshumot (the Official Gazette of the State of Israel) on 14 August 2024 and in force in tranches with the principal substantive provisions in force from 14 August 2025, with business contact published as the publicly-accessible PPO contact required by PPL section 17B1(c) read with the Protection of Privacy Regulations (Data Security), 5777-2017 (the "Data Security Regulations") and the guidance documents issued by the Privacy Protection Authority (Reshut Hagana al HaPratiut, the "PPA") published at https://www.gov.il/en/departments/the_privacy_protection_authority; the designated contact point for the Privacy Protection Authority ("PPA"), the Israel Police – National Cyber Unit (Yahidat Saiber HaIsraeli — Lahav 433 and Yahalom), the National Cyber Directorate (Maarach HaSaiber HaLeumi), the Ministry of Welfare and Social Affairs (Misrad HaAvoda HaRevacha VeHaSherutim HaHevratim), and the Council for the Welfare of the Child (HaMoetza Le'Shlom HaYeled) under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Protection of Privacy Law, 5741-1981 (the "PPL") including the entry into force of any provision of Amendment No. 13 (5784-2024) that is not yet operationally in force at the Effective date (the principal substantive provisions are in force from 14 August 2025; a small set of provisions including specific enforcement-quantum elements and certain transitional database-registration rules have staggered commencement under the Amendment's commencement schedule — § 18 versioning protocol covers their commencement); (b) any amendment to the Protection of Privacy Regulations (Data Security), 5777-2017 in force from 8 May 2018; (c) any amendment to the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001 in force from 1 May 2001; (d) any amendment to the Protection of Privacy Regulations (Conditions for Holding and Maintaining a Database by Holders Thereof and Conditions for Transfer of Information Between Public Bodies), 5746-1986; (e) any Directive or Guidance Document issued by the PPA — including the PPA's Guidelines on the Transfer of Information to a Third Party, the Guidelines on Database Registration, the Guidelines on Direct Mailing under section 17F PPL, the Guidelines on Privacy Protection Officers under Amendment 13, the Guidelines on Notifications of Serious Security Incidents, the Guidelines on Privacy in Online Services, the Guidelines on the Use of Cameras in the Public Sphere (insofar as referenced by online-services interpretive practice), the Guidelines on Smart Cameras, the Guidelines on Children's Privacy (Hebrew: Hanchayat HaRashut: Pratiut HaYeladim), and the body of PPA Decisions and Position Papers published at https://www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page; (f) any decision of the Magistrate's Court, District Court, or Supreme Court of Israel sitting as a High Court of Justice (Bagatz) bearing on the PPL, the Basic Law: Human Dignity and Liberty section 7 right to privacy, or the Basic Law: Freedom of Occupation; (g) any amendment to the Penal Law, 5737-1977 (Israel), in particular Chapter 8 (sexual offences) sections 199 (procurement of minor for indecent acts), 200, 201, 202, 203A, 203B, 203C (incitement, solicitation, and trafficking for prostitution including child trafficking), section 214(b1) (publication of indecent material involving minor), section 214(b)–(c) (possession of indecent material involving minor), section 345 (rape), section 345A (sexual intercourse with a minor — Ones Statutori), section 346 (forbidden intercourse by consent), section 347 (sodomy), section 348 (indecent acts), section 351 (sexual offence in family or by persons in a position of authority), and section 199 read with the Penal Law (Amendment No. 118), 5774-2014 introducing the online-luring offence at section 199(a)(2) for solicitation of sexual intercourse with a minor by means of a computer; (h) any amendment to the Youth (Care and Supervision) Law, 5720-1960 (Hebrew: Chok HaNo'ar (Tipul VePikuach)); (i) any amendment to the Youth (Trial, Punishment and Modes of Treatment) Law, 5731-1971; (j) any amendment to the Computers Law, 5755-1995 (Hebrew: Chok HaMahshevim), the Criminal Procedure (Powers of Enforcement — Communications Data) Law, 5768-2007 (Hebrew: Chok Sidre HaDin HaPlili (Smahuyot Akhifa — Netunei Tikshoret), the "Communications Data Law"), the Wiretapping Law, 5739-1979 (Hebrew: Chok HaAza'na), or the Search in Computer Material Law sub-regime within the Criminal Procedure (Arrest and Search) Ordinance [New Version], 5729-1969; (k) any amendment to the Consumer Protection Law, 5741-1981 (Hebrew: Chok Hagana al HaTzarchan) or its regulations, the Consumer Protection Regulations (Transactions of Distance Selling), 5774-2014 (the principal distance-selling subordinate regulation), or the Standard Contracts Law, 5743-1982 (Hebrew: Chok HaChozim HaAchidim); (l) any amendment to the Communications Law (Telecommunications and Broadcasting), 5742-1982 section 30A (Israel's anti-spam provision in force since 1 December 2008); (m) any amendment to a sub-processor's Israeli data-handling posture under our sub-processor register; (n) any change to Israel's EU adequacy status under Commission Decision 2011/61/EU of 31 January 2011 on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data (the "Israel Adequacy Decision") — including any review or revocation by the European Commission under GDPR Article 45(4) (the first periodic review under Article 45 was completed by the Commission in January 2024 and confirmed the adequacy decision for Israel; any subsequent review may trigger reassessment); (o) the bringing into force of any post-Effective-date Israeli regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (p) the entry into force in Israel of the Second Additional Protocol to the Convention on Cybercrime (Budapest Convention, of which Israel has been a party since 9 May 2016 — Israel signed the Second Additional Protocol and ratification status is monitored under § 18).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Israel row).
- Children's Privacy Notice § 14 (Country annexes — Israel row).
- Child Safety Standards § 13 (Country annexes — Israel row).
- Terms of Service § 19 (Israel consumer-protection carve-out under the Consumer Protection Law 5741-1981 + the Consumer Protection Regulations (Transactions of Distance Selling) 5774-2014 + the Standard Contracts Law 5743-1982).
- Subscription Terms § 20 (Israel consumer-rights overlay — Consumer Protection Law 5741-1981 section 14C 14-day cooling-off + section 14E supplier-obligations + Standard Contracts Law 5743-1982 unfair-terms screen).
- Data Retention & Deletion Policy § 14 (Israel PPA complaint route).
- our breach-notification runbook § 9 (Israel mandatory serious-security-incident-notification route under PPL section 11D (introduced by Amendment 13) + Data Security Regulations regulation 11 — immediate PPA notification for serious security incidents at high-security databases; data-subject notification per the harm-likelihood analysis under PPA Guidance on Notifications).
- our international-transfer pack § 6 (PPL section 36 + Transfer of Data Abroad Regulations regulation 2 cross-border-transfer paperwork; Israel-side outbound transfer mechanism + EU Adequacy Decision inbound mechanism).
This Annex is the canonical Israeli-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Israeli resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Israeli resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The official languages of the State of Israel under section 82 of the Palestine Order in Council, 1922 (preserved in Israeli law) and the Use of the Hebrew Language Law in their interpretive sense are Hebrew (the principal and primary official language) and Arabic (with Arabic's status as an official language modified by the Basic Law: Israel — The Nation State of the Jewish People (5778-2018) which preserves Arabic's "special status"). Hebrew translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker, with the Hebrew version intended to be authoritative for the Israeli resident on its publication; Arabic translation is queued in the same Phase-2 rollout. No translation is statutorily required at the Effective date for the English-language privacy notice to an Israeli resident (the PPL does not mandate multilingual notification; the PPA's interpretive practice accepts notices in Hebrew, English, or Arabic provided the notice is intelligible to the data subject in light of the context).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the State of Israel — the unitary state organised into six administrative districts (Northern, Haifa, Centre, Tel Aviv, Jerusalem, Southern) + the Judea and Samaria Area civil administration (whose data-protection status is determined by application of the PPL by the Israeli authorities to data subjects within their jurisdiction as a matter of administrative practice). There is no district data-protection sub-layer; the PPL is uniform throughout the State of Israel.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Israel as the country of residence, this Annex applies, even if the other signals are non-Israeli. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The PPL has explicit extraterritorial reach under PPL section 36A (introduced by Amendment 13) — the PPL applies to processing of personal information of a data subject in Israel by a database controller or processor located outside Israel where the controller or processor (i) offers goods or services to data subjects in Israel, or (ii) monitors the conduct of data subjects in Israel. The PPA's Position Paper on the Extraterritorial Application of the PPL + the body of PPA guidance documents confirm that an entity outside Israel is subject to the PPL in respect of its processing of personal information of Israeli residents where the entity directs activities towards Israel. Balance squarely targets Israeli residents through Google Play Israel, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Israeli-resident parents and kids; the PPL applies in full.
2. Statutory framework — what applies
The Israeli personal-data-protection regime is dominated by the Protection of Privacy Law, 5741-1981 ("PPL") as substantively modernised by the Protection of Privacy Law (Amendment No. 13), 5784-2024 (the "Amendment 13") with most provisions in force from 14 August 2025, supplemented by the Protection of Privacy Regulations (Data Security), 5777-2017 (in force from 8 May 2018), the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001 (in force from 1 May 2001), and the PPA's binding guidance documents. Adjacent layers: the Basic Law: Human Dignity and Liberty (5752-1992) section 7 (constitutional right to privacy); the Youth (Care and Supervision) Law, 5720-1960; the Youth (Trial, Punishment and Modes of Treatment) Law, 5731-1971; the Penal Law, 5737-1977 (sexual-offences and online-child-exploitation provisions); the Computers Law, 5755-1995 (cybercrime); the Wiretapping Law, 5739-1979; the Criminal Procedure (Powers of Enforcement — Communications Data) Law, 5768-2007; the Criminal Procedure (Arrest and Search) Ordinance [New Version], 5729-1969; the Consumer Protection Law, 5741-1981; the Consumer Protection Regulations (Transactions of Distance Selling), 5774-2014; the Standard Contracts Law, 5743-1982; the Communications Law (Telecommunications and Broadcasting), 5742-1982 section 30A (anti-spam); the Counsel for Children Law, 5728-1968.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Basic Law: Human Dignity and Liberty (5752-1992) | Basic Law (HDL) — passed by the Knesset 17 March 1992; entrenched constitutional-rank statute under Israeli constitutional doctrine (Bagatz 6821/93 United Mizrahi Bank v Migdal Cooperative Village). Section 2 (preservation of life, body, and dignity); Section 4 (protection of life, body, and dignity); Section 5 (personal liberty); Section 6 (departing and entering Israel); Section 7 — "All persons have the right to privacy and to intimacy. There shall be no entry into the private premises of a person who has not consented thereto. No search shall be conducted on the private premises of a person, nor in the body or personal effects. There shall be no violation of the confidentiality of conversation, or of the writings or records of a person." — the constitutional anchor for the right to privacy in Israeli law. Read with Basic Law (HDL) section 8 (the limitation clause — limitations on the rights must be by a law that befits the values of the State of Israel, is enacted for a proper purpose, and is to an extent no greater than required) and the doctrine of constitutional review developed by the Supreme Court sitting as a High Court of Justice. | The constitutional anchor. The right to privacy in Israel is constitutional (Basic Law (HDL) section 7) AND statutory (PPL + civil-wrongs framework). | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Protection of Privacy Law, 5741-1981 (Israel) | PPL — published in Sefer HaChukkim 1011 of 11 March 1981, in force 23 February 1982; as substantively modernised by the Protection of Privacy Law (Amendment No. 13), 5784-2024 published in Sefer HaChukkim 3071 of 14 August 2024 with most substantive provisions in force from 14 August 2025. Chapter A (Infringement of Privacy — substantive tort) — section 1 (the prohibition on infringement of privacy); section 2 (definitions of infringement including subsection (1) spying or trailing, subsection (2) wire-tapping prohibited by law, subsection (3) photographing a person while in a private domain, subsection (7) publication of private information including health and sexuality information, subsection (8) publication of an image, subsection (9) use of information about a person other than for the purpose for which it was given, subsection (10) holding or storing information about a person other than for the original purpose for which it was given); section 3 (knowledge defence); section 4 (consent defence); section 5–13 (criminal infringement, civil wrongs, exemptions, presumptions). Chapter B (Database Protection — the core data-protection provisions) — section 7 (definitions including "information" as data about a person's personality, personal status, intimate matters, state of health, financial standing, professional training, opinions, and beliefs; "sensitive information" as further defined in section 7 + Amendment 13 expanded definition; "database" as a collection of data, maintained by magnetic or optical means and intended for computer processing); section 8 (mandatory database registration with the PPA Database Registrar for databases meeting registration triggers — Amendment 13 narrowed the registration triggers significantly so that smaller databases are exempt; high-risk databases including databases of children's data remain registration-eligible, but the PPA's interpretive practice for foreign controllers without permanent Israeli establishment is documented in § 8.3 below); section 9 (registration application + Registrar's discretion); section 10 (refusal and conditions of registration); section 11 (notification obligation to data subject — when a controller requests information from a data subject, the controller must notify the data subject of: (a) whether the data subject is under a legal obligation to provide the information or it is by his consent; (b) the purpose for which the information is requested; (c) to whom the information will be transmitted and the purposes of the transmission); section 11A (accuracy and correction obligation); section 11B (security obligation — the controller must take reasonable security measures); section 11C (mandatory Privacy Protection Officer / PPO for certain database controllers including controllers processing children's data as a core activity — introduced by Amendment 13 with effect from 14 August 2025); section 11D (mandatory serious-security-incident notification — introduced by Amendment 13 — controllers of high-security databases must notify the PPA immediately of a serious security incident); section 13 (data-subject right of access — every person is entitled to receive from a controller, in writing in Hebrew or in another language understood by him, all the information about him that is held in the database); section 13A (right of access by the data subject's representative); section 14 (right of correction — if a person finds that information about him in a database is incorrect, incomplete, unclear, or out of date, he may apply to the controller to correct it); section 15 (notification of correction to recipients); section 16 (confidentiality duty — every controller, processor, holder, or worker who has access to a database is bound by professional secrecy); section 17 (regulations on data security); section 17A (database management responsibility); section 17B (database holder's obligations); section 17B1 (Privacy Protection Officer (PPO) — the Israeli statutory equivalent of GDPR DPO — introduced by Amendment 13 — mandatory PPO designation for: (i) controllers of public-sector databases; (ii) controllers whose principal business is the holding of personal data for others; (iii) controllers processing sensitive personal information at high volume as defined in regulations; (iv) controllers processing children's personal information as a core processing activity; the PPO must be readily accessible, must be reachable by data subjects and the PPA, and the PPO's contact details must be publicly available); section 17F (direct mailing rules — opt-out + identification + unsubscribe + Direct Mail Registry); section 17F(d) (right to be removed from a direct-mailing database); section 24 (transfer of information between public bodies — not engaged for Balance as a private controller); section 25 (data subject's right to request deletion of personal information held by direct-mailing controller); section 31 (right of action — civil wrong — infringement of privacy is a civil wrong, the substantive cause of action carrying damages without proof of harm up to NIS 50,000 at the date of Amendment 13's enhancement; Amendment 13 raised the cap to NIS 75,000 effective 14 August 2025 in line with the strengthened enforcement framework); section 31A (criminal infringement of privacy — wilful infringement is an offence punishable by up to 5 years' imprisonment); section 34 (judicial remedy by injunction); section 35–36 (Database Registrar + PPA's enforcement powers); section 36 (international data transfer — the Minister of Justice may make regulations on the transfer of information abroad; the operative regulations are the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001); section 36A (extraterritorial scope — introduced by Amendment 13 — the PPL applies to processing of personal information of data subjects in Israel by a controller or processor outside Israel that (i) offers goods or services to data subjects in Israel; (ii) monitors the conduct of data subjects in Israel); section 37–48 (PPA — the Privacy Protection Authority, its powers including investigations, administrative orders, administrative financial sanctions up to NIS 3.2 million OR 5% of annual turnover in significant cases under Amendment 13's enforcement-modernisation regime, and judicial appeal). | The principal statute. Applies in full to Balance as a controller located outside Israel offering services to Israeli residents (per PPL section 36A + Amendment 13's extraterritorial scope). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Protection of Privacy Regulations (Data Security), 5777-2017 | Data Security Regulations — promulgated by the Minister of Justice under PPL section 17(b), in force from 8 May 2018. Regulation 1 (definitions including database security level — basic, medium, high — determined by the database's size, sensitivity, and risk profile); Regulation 2 (Database Definition Document — every controller must maintain a Mismach Hagdarat HaMaagar describing the database's purposes, the types of information, the sources, recipients, retention periods, locations, and risks); Regulation 3 (mapping and risk assessment); Regulation 4 (organisational measures including written policies, training, role-based access); Regulation 5 (physical security); Regulation 6 (access control — least privilege, named accounts, identification and authentication, at high-security level: two-factor authentication); Regulation 7 (logging and monitoring); Regulation 8 (communications security); Regulation 9 (incident management); Regulation 10 (annual audit and penetration testing at high-security level); Regulation 11 (notification of serious security incidents to the PPA + on PPA Direction, to affected data subjects — the principal pre-Amendment-13 breach-notification rule, which Amendment 13 supplements with PPL section 11D); Regulation 13 (record-keeping); Regulation 14 (review and update obligations). | Applies in full. Balance's posture: as the database is processing children's personal information at scale, the database is treated at high-security level; the controls in Regulations 3–11 are implemented; the Database Definition Document is maintained internally; the annual audit + penetration testing are carried out per Regulation 10. Treatment in § 11 below. | |
| Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001 | Transfer Regulations — promulgated by the Minister of Justice under PPL section 36, in force from 1 May 2001. Regulation 1 (definitions); Regulation 2 — the operative rule — the controller of a database may transfer information from the database to abroad only if the receiving country provides a level of protection equivalent to or better than that provided under the laws of the State of Israel, or if one of the seven Regulation 2(c) exceptions applies, including (i) consent of the data subject; (ii) transfer necessary for the performance of a contract between the controller and the data subject; (iii) transfer to a corporation under the controller's control (intra-group); (iv) transfer pursuant to the country having an adequacy decision by the European Commission (the receiving country is one of the countries that has been declared as having an adequate level of protection under GDPR Article 45); (v) transfer to a country that has acceded to the Council of Europe Convention 108 (and successor instruments — the operative practice extends to Convention 108+ ratifying states); (vi) transfer pursuant to PPA approval; (vii) other narrowly drawn exceptions; Regulation 2(d) — even where one of the Regulation 2(c) exceptions applies, the receiving entity must give a written undertaking to maintain the conditions for holding and using the information as required of an Israeli holder of a database under Israeli law. | The principal Israel-to-abroad transfer rule. Applies in full. Treatment in § 8 below. | |
| PPA Guidance Documents | The body of PPA guidance documents published by the Privacy Protection Authority at https://www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page — including the Guidelines on the Transfer of Information to a Third Party, the Guidelines on Database Registration, the Guidelines on Direct Mailing under section 17F PPL, the Guidelines on Privacy Protection Officers under Amendment 13 (issued in 2024/2025), the Guidelines on Notifications of Serious Security Incidents, the Guidelines on Privacy in Online Services, the Guidelines on Children's Privacy (Hebrew: Hanchayat HaRashut: Pratiut HaYeladim), the Position Paper on the Extraterritorial Application of the PPL under Amendment 13, and the body of PPA Decisions and Position Papers. |
Applies as the PPA's binding interpretive layer on the PPL. The Children's Privacy Guidance and the PPO Guidance under Amendment 13 are particularly relevant. | |
| Youth (Care and Supervision) Law, 5720-1960 | Youth (Care and Supervision) Law — published in Sefer HaChukkim 312 of 15 July 1960. Definitions section 1 ("minor" — under 18); the framework for protection of minors at risk; mandatory reporting of harm to minors by professional reporters (section 7 — medavchei chova); the Welfare Officer (Pakid Saad) regime; District Welfare Officer (Pakid Saad Mahozi); the Children at Risk framework. | The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below. | |
| Youth (Trial, Punishment and Modes of Treatment) Law, 5731-1971 | Youth Trial Law — published in Sefer HaChukkim 619 of 12 March 1971. The framework for criminal proceedings against minors (under-18) — special-needs proceedings, juvenile courts, modes of punishment and treatment, and presumption of immaturity for under-12 (section 14 — gilei achra'iut plili). | The principal juvenile-justice statute. Applies as a context-setting fact. | |
| Penal Law, 5737-1977 (Israel) | Penal Law — published in Sefer HaChukkim 864 of 4 August 1977. Chapter 8 (Sexual Offences); section 199 (procurement of minor for sexual purposes — Sirsur Lemaaaseh Z'nut; including the online-luring offence at section 199(a)(2) introduced by Penal Law (Amendment No. 118), 5774-2014 for solicitation by means of a computer or telecommunications); section 200 (engaging in prostitution); section 201 (importing for prostitution); section 202 (premises for prostitution); section 203A (trafficking in minors for prostitution); section 203B (procurement for child trafficking); section 203C (continuing trafficking); section 214 (indecent publications including involving minors — section 214(b) holding indecent publications involving minors / section 214(b1) publishing indecent material involving minors / section 214(b3) distributing indecent material involving minors; the CSAM-criminalisation provisions); section 345 (rape); section 345A (statutory rape of minor under 14 — Ones Statutori); section 346 (forbidden intercourse by consent — sexual intercourse with a minor between 14 and 16 by an adult is a criminal offence); section 347 (sodomy); section 348 (indecent acts); section 351 (sexual offences in family or by persons in a position of authority — Avirei Min BeMishpacha O Be'al Sm'kha). The general age of sexual consent is 16 (section 346); statutory rape of an under-14 minor is an absolute offence regardless of consent (section 345A). | The principal Israeli sexual-offences statute relevant to child-online-safety. Applies. Treatment in § 14 below. | |
| Computers Law, 5755-1995 (Israel) | Computers Law — published in Sefer HaChukkim 1531 of 6 April 1995. Section 2 (definitions); section 3 (unlawful disruption of a computer); section 4 (unlawful access to a computer — penal); section 5 (act in relation to false information); section 6 (computer virus); section 7 (computer trespass with intent to commit another offence). | The principal cybercrime statute. Applies. Treatment in § 13 below. | |
| Wiretapping Law, 5739-1979 (Israel) | Wiretapping Law — Chok HaAza'na. The principal interception statute. Wire-tapping is prohibited; lawful interception is by judicial order under enumerated conditions (for offences enumerated in the schedule). | Applies. Treatment in § 13 below — relevant to E2EE posture and lawful-access framework. | |
| Criminal Procedure (Powers of Enforcement — Communications Data) Law, 5768-2007 | Communications Data Law — Chok Sidre HaDin HaPlili (Smahuyot Akhifa — Netunei Tikshoret). Governs law-enforcement access to communications data (metadata, subscriber data, location data) held by telecommunications and internet services. Section 3 judicial order; section 4 de minimis access by police; section 7 expedited orders. | Applies. Treatment in § 13 below. | |
| Criminal Procedure (Arrest and Search) Ordinance [New Version], 5729-1969 — "Search in Computer Material" sub-regime | Search in Computer Material — within the Criminal Procedure Ordinance. Sections 23A + 23B (judicial search warrant for computer material); section 32 (presumption regarding interception of computer material). | Applies. Treatment in § 13 below. | |
| Consumer Protection Law, 5741-1981 (Israel) | Consumer Protection Law — Chok Hagana al HaTzarchan — published in Sefer HaChukkim 1023 of 1 April 1981. Section 2 (prohibition of deception); section 3 (prohibition of undue influence); section 4 (disclosure obligations); section 13D (information on cooling-off rights); section 14C (14-day cooling-off period for distance selling — the consumer may cancel a distance-selling transaction within 14 days of receipt of the goods or of the conclusion of the contract for services); section 14E (supplier obligations in distance-selling transactions); section 17C (cooling-off for continuing transactions); section 31 (unfair-terms screen + civil action); section 41 (Director General of the Consumer Protection and Fair Trade Authority — Reshut Hagana al HaTzarchan VeSahar Hogen); enforced by the Consumer Protection and Fair Trade Authority (RaHTSAH). | The principal Israeli consumer-protection statute. Applies in full. Treatment in § 16 below. | |
| Consumer Protection Regulations (Transactions of Distance Selling), 5774-2014 | Distance Selling Regulations — promulgated under section 14C of the Consumer Protection Law, in force from 1 October 2014. Operationalises the section 14C cooling-off right and the section 14E supplier-obligations regime for distance-selling transactions including online subscription services. | Applies. Treatment in § 16 below. | |
| Standard Contracts Law, 5743-1982 (Israel) | Standard Contracts Law — Chok HaChozim HaAchidim — published in Sefer HaChukkim 1057 of 26 August 1982. Section 3 (prohibition of a depriving condition in a standard contract); section 4 (presumption of depriving conditions — a list of 12 categories of clauses presumed depriving including jurisdiction-displacement clauses, choice-of-law clauses that deprive the consumer of mandatory protection, exemption clauses, automatic-renewal-without-notice clauses); section 19 (judicial relief — court may rescind or modify a depriving condition); Standard Contracts Tribunal (Beit Din LeChozim Achidim). | Applies to Balance's Terms of Service and Subscription Terms in respect of Israeli consumers. Treatment in § 16 below. | |
| Communications Law (Telecommunications and Broadcasting), 5742-1982 — section 30A | Section 30A Anti-Spam — introduced by Communications Law (Amendment No. 40), 5768-2008, in force from 1 December 2008. Prohibits advertising message sent by fax, automatic telephone dialer, text message (SMS), or electronic mail without the recipient's prior express consent; requires identification of sender + clear marking as advertising + opt-out mechanism; civil cause of action with damages up to NIS 1,000 per message without proof of damage. | Applies. Balance does not send commercial-marketing electronic messages to Israeli residents. Treatment in § 12 below. | |
| Counsel for Children Law, 5728-1968 (Israel) | Counsel for Children Law — the framework for child-representation in legal proceedings, applied by Israeli courts in matters concerning minors. | Applies as a context-setting fact for any matter where a minor's interests are litigated under the PPL or the civil-wrongs framework. | |
| EU adequacy decision | Commission Decision 2011/61/EU of 31 January 2011 on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data — published in OJ L27/39 of 1 February 2011. Israel has an EU adequacy decision under GDPR Article 45 (originally under Directive 95/46/EC Article 25(6), continued post-GDPR-entry-into-force per Article 45(9) GDPR until the Commission's first periodic review under Article 45(4)). The Commission's first periodic review under Article 45(4) was completed in January 2024 and confirmed Israel's adequacy status. The adequacy decision covers transfers of personal data from EU/EEA Member States to Israeli controllers and processors subject to the PPL; it does NOT cover transfers from Israel to third countries (which remain subject to PPL section 36 + the Transfer of Data Abroad Regulations 5761-2001). | Cross-reference in EU / EEA annex § 8. | The EU adequacy decision is a context-setting fact that facilitates inbound EU→Israel data flow (Balance does not host any personal data in Israel, so the inbound EU→Israel route is not engaged for Balance's data architecture). The Israel→US outbound transfer that Balance does engage in is separately governed by PPL section 36 + Transfer Regulations Regulation 2 — see § 8 below. |
| Convention 108 / Convention 108+ | The State of Israel acceded to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108, Strasbourg 28 January 1981) on 1 September 2007 (entered into force for Israel on 1 January 2008). Israel signed the Protocol amending the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+, Strasbourg 10 October 2018) on 10 October 2018; ratification status monitored under § 18. | Applies. The Convention 108 framework reinforces the substantive equivalence of the PPL to the European data-protection acquis, which is the doctrinal foundation of the EU adequacy decision. Cross-reference in § 8 below. | |
| Budapest Convention on Cybercrime | The State of Israel signed the Convention on Cybercrime (Budapest, 23 November 2001) on 9 November 2010 and ratified on 9 May 2016, with the Convention entering into force for Israel on 1 September 2016. Israel signed the Second Additional Protocol on Enhanced Co-operation and Disclosure of Electronic Evidence (Strasbourg, 12 May 2022); ratification status monitored under § 18. | Applies. Treatment in § 13 below — substantive overlay on the lawful-access framework, including the 24/7 point-of-contact regime and the mutual-assistance arrangements. |
(Any prospective Israeli regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PPA guidance document in that area, the Israel Innovation Authority's voluntary innovation-policy papers, the Ministry of Justice's voluntary policy paper on responsible AI in the public sector (October 2023), any future Israeli AI Bill or AI-Law amendment before the Knesset, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal information using techniques within the scope of any such Israeli regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 PPA — Privacy Protection Authority
The principal supervisory authority is the Privacy Protection Authority (Hebrew: Reshut Hagana al HaPratiut, the "PPA"), an authority within the Ministry of Justice (Misrad HaMishpatim). The PPA was reorganised from the predecessor Israeli Law, Information and Technology Authority (ILITA) in 2017 and operates under PPL Chapter B + sections 37–48 + the Privacy Protection Authority Statute approved by the Government of Israel. The PPA has investigative, administrative-order, financial-sanction, and recommendation powers. The PPA's decisions are appealable to the Magistrate's Court under PPL section 48A (administrative-affairs jurisdiction under the Administrative Courts Law, 5760-2000) and onwards to the District Court sitting as a Court for Administrative Affairs; certain matters are amenable to Bagatz petition.
| Field | Value |
|---|---|
| Name | Privacy Protection Authority (PPA) — Reshut Hagana al HaPratiut |
| Parent ministry | Ministry of Justice (Misrad HaMishpatim) |
| Headquarters | 39 Yermiyahu Street, Jerusalem 9446722, Israel — Ministry of Justice building |
| Website | https://www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page (Hebrew) / https://www.gov.il/en/departments/the_privacy_protection_authority (English) |
| Complaint channel | PPA online complaint portal at the PPA gov.il page; email ppa@justice.gov.il |
| Phone | +972 73 3927700 |
| Mandatory-Serious-Security-Incident-Notification channel | PPA online Serious Security Incident Notification portal per PPL section 11D + Data Security Regulations Regulation 11 — immediate notification upon the controller's knowledge of a serious security incident at a high-security-level database |
| Head of Authority | At the Effective date — published at https://www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page |
The PPA is the first-line forum for any PPL-grounded complaint from any Israeli resident. An Israeli resident may petition the PPA after first raising the matter with Balance (the PPA's published practice + the PPA's Guidelines on Complaints Procedure is to attempt resolution with the controller first, but the PPA also accepts direct complaints). We accept all data-subject access / privacy enquiries at (named individual: , in his capacity as the PPO under PPL section 17B1 + the PPA's Guidelines on Privacy Protection Officers under Amendment 13) and respond within the PPL timelines (see § 6 below).
An Israeli resident may also pursue private remedies via (i) the PPL section 31 civil-wrong cause of action for infringement of privacy, with statutory damages without proof of harm up to NIS 75,000 (post-Amendment-13 cap effective from 14 August 2025); (ii) the Basic Law (HDL) section 7 constitutional-rights cause of action read with civil-wrongs doctrine; (iii) the PPL section 34 judicial injunction; (iv) the PPL section 31A criminal-infringement complaint to the police for wilful infringements; (v) the Bagatz petition in matters of public-law privacy concern.
3.2 Ministry of Justice — Privacy Protection Authority parent ministry
The Ministry of Justice (Misrad HaMishpatim) is the parent ministry of the PPA. The Minister of Justice is the responsible minister for the PPL and for the promulgation of regulations under PPL section 36 (transfer abroad), section 17 (data security), and section 8 (database registration).
| Field | Value |
|---|---|
| Name | Ministry of Justice (Misrad HaMishpatim) |
| Headquarters | 39 Yermiyahu Street, Jerusalem 9446722, Israel |
| Website | https://www.gov.il/en/departments/ministry_of_justice |
| Phone | +972 2 6466666 |
3.3 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| National Cyber Directorate (NCD) — Maarach HaSaiber HaLeumi | Cybersecurity national strategy; CERT-IL (national CERT) for incident-coordination; sector-specific cyber-protection | https://www.gov.il/en/departments/israel_national_cyber_directorate |
| Israel Police — National Cyber Unit — Yahidat HaSaiber HaLeumi BaMishtara | Cybercrime investigation under the Computers Law, the Wiretapping Law, and the Communications Data Law | https://www.police.gov.il/ |
| Israel Police — Lahav 433 (National Crime Investigation Headquarters) — Sigma (Cybercrime Investigation Unit) + Yahalom (Cybercrime Coordination Unit) | Cybercrime investigation and intelligence | https://www.police.gov.il/ |
| Ministry of Welfare and Social Affairs — Misrad HaAvoda HaRevacha VeHaSherutim HaHevratim | Youth Law (Care and Supervision) — child welfare and protection | https://www.gov.il/en/departments/ministry_of_welfare_and_social_affairs |
| Council for the Welfare of the Child — HaMoetza Le'Shlom HaYeled | Independent child-welfare advocacy body | https://www.children.org.il/ |
| State Attorney's Office — Praklitut HaMedina | Prosecutorial body — Cyber Department and Children/Youth Department | https://www.gov.il/en/departments/the_state_attorneys_office |
| Consumer Protection and Fair Trade Authority — Reshut Hagana al HaTzarchan VeSahar Hogen (RaHTSAH) | Consumer Protection Law enforcement; distance-selling rules | https://www.gov.il/en/departments/consumer_protection_and_fair_trade_authority |
| Public Defender for Children's Rights — HaSnegoria HaTziburit LeMoetzet HaYeladim (where engaged in family-court matters) | Child advocacy in court | via Public Defender's office |
| Standard Contracts Tribunal — Beit Din LeChozim Achidim | Adjudication of standard-contract depriving-condition disputes | https://www.gov.il/en/departments/units/tribunal_for_standard_contracts |
| ELEM — Youth in Distress — ELEM — Noar BeMatzav Sikun | NGO for youth in distress; online-help services | https://www.elem.org.il/ |
| ERAN — Mental Health First Aid | 24/7 mental health crisis helpline | https://www.eran.org.il/ — 1201 |
| 105 — Israeli National Hotline for the Protection of Children and Youth Online | The principal Israeli child-online-safety hotline operated by the Israel Police + National Cyber Directorate | https://www.gov.il/he/departments/general/police-105 — dial 105 |
| Saviv — Saviv Center for the Protection of Children and Youth Online | NGO partner of 105 | via 105 |
| The Israeli Internet Association — Agudat HaInternet HaIsraelit (ISOC-IL) | Internet-policy NGO | https://www.isoc.org.il/ |
3.4 The PPO
PPL section 17B1 (introduced by Amendment 13) + the PPA's Guidelines on Privacy Protection Officers under Amendment 13 require every controller falling within the section 17B1 criteria to designate a Privacy Protection Officer (PPO). The criteria include (iv) controllers processing children's personal information as a core processing activity — which is Balance's case. The PPO must be readily accessible, must be reachable by data subjects and the PPA, and the PPO's contact details must be publicly available.
The Balance PPO is:
- , Director, BabaYaga Program, TOO —
.
The PPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PPL section 17B1(c) + the PPA's Guidelines on Privacy Protection Officers under Amendment 13. The PPO is the contact point for the PPA on any regulatory matter and for data subjects on rights-exercise matters. The PPO need not be a citizen or resident of Israel but must be readily accessible during regular Israeli business hours.
4. Lawful bases — PPL section 11 notification + Amendment 13 consent regime + section 17F direct-mailing carve-out
The PPL is a notification-and-purpose-limitation regime modulated by the consent obligation at PPL sections 2(9) + 2(10) (use of information about a person other than for the purpose for which it was given is an infringement of privacy) and the Amendment 13 enhanced-consent framework which aligns the Israeli consent doctrine more closely with the GDPR Article 4(11) consent doctrine. Balance processes personal information of Israeli residents on the following PPL mapping:
| Processing purpose | PPL basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | PPL section 11 notification + parent's express consent at sign-up (under PPL section 4 consent + Amendment 13 enhanced-consent framework — informed, specific, freely given, unambiguous) + performance-of-contract necessity (recognised by PPA interpretive practice and PPA Position Papers as a discrete category of legitimate processing) + PPL section 2(9) purpose limitation observed | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal information | PPL section 4 consent of the parent (given on behalf of the kid under the Capacity and Guardianship Law, 5722-1962 sections 14–18 parental guardianship + the Civil Wrongs Ordinance [New Version], 5728-1968 parental-responsibility framework) + the most-protective reading of the PPL transparency + proportionality + the PPA Guidelines on Children's Privacy (Hebrew: Hanchayat HaRashut: Pratiut HaYeladim) | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | PPL section 11 notification + section 4 consent (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | PPL section 11B security obligation read with PPL sections 17–17B + Data Security Regulations Regulation 9 (incident management) + Regulation 11 (notification) + the PPA's interpretive practice on legitimate-security processing | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | PPL section 2 carve-out for processing required by law + section 7(b) general carve-outs | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's information | PPL section 4 consent — collection of the parent's personal information for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription information | performance-of-contract necessity — necessary for the performance of the subscription contract; Consumer Protection Law sections 14C + 14E + Standard Contracts Law sections 3 + 4 consumer-protection overlay in § 16 below | H4; § 16 below |
Balance does not process sensitive information under PPL section 7 (post-Amendment-13 definition) in respect of any Israeli resident (no medical or psychiatric information, no genetic data, no biometric data, no political views, no sexual-orientation information, no religious-belief information, no past-criminal-conviction information).
Balance does not collect any Israeli national identification number — neither the Teudat Zehut number (the Israeli ID-card number issued under the Identification Law, 5755-1995) nor the Passport number (issued under the Passports Law, 5712-1952) nor the driver's licence number. The PPA's Guidelines on the Collection of Identification Numbers impose strict purpose-limitation on the collection of such numbers; Balance's posture aligns: none collected.
5. Children's rights overlay
Israel does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PPL + Amendment 13 + the PPA's binding Guidelines on Children's Privacy (Hebrew: Hanchayat HaRashut: Pratiut HaYeladim); (ii) the Basic Law: Human Dignity and Liberty section 7; (iii) the Youth (Care and Supervision) Law, 5720-1960; (iv) the Capacity and Guardianship Law, 5722-1962 sections 14–18 (parental guardianship and the duty to act in the minor's best interest); (v) the Penal Law, 5737-1977 sexual-offences chapter (age of consent 16, statutory rape of under-14 absolute); (vi) the UN Convention on the Rights of the Child (Israel acceded 3 October 1991).
5.1 Definitions
For the purposes of this Annex:
- Minor (under Israeli statutory framework — Katan): a person below the age of 18 years (Capacity and Guardianship Law section 3).
- Child / Youth (under the Youth (Care and Supervision) Law and the Youth (Trial, Punishment and Modes of Treatment) Law): a person below the age of 18 years; further classified into yeled (under-12) and na'ar (12 to under-18) for certain operational provisions.
- Age of sexual consent (per Penal Law section 346): 16 years. Statutory rape of an under-14 minor is an absolute offence (section 345A).
- Age of digital consent under PPL: the PPL does not set a numerical age of digital consent. The PPA's Guidelines on Children's Privacy treat persons below 18 as requiring parental consent for the processing of their personal information for online services directed at minors, subject to maturity-based exceptions for older adolescents capable of understanding the processing. Balance applies the most-protective reading and obtains parental consent regardless of the child's age.
5.2 Verifiable Parental Consent (VPC) for Israeli kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Israeli kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Israeli residents itemises the categories of personal information being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PPL + Basic Law (HDL) section 7 + the civil-wrongs framework.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PPL + the Capacity and Guardianship Law sections 14–18 + the PPA Guidelines on Children's Privacy + the Youth (Care and Supervision) Law.
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PPA's interpretive position on advertising to children; (ii) the Consumer Protection Law section 7C (restrictions on advertising directed at minors); (iii) the Council for Cable and Satellite Broadcasting Rules on advertising to children (insofar as applied by interpretive analogy to online services); (iv) the Communications Law section 30A anti-spam framework. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Israeli child-protection bodies are: (i) the Israel Police — National Cyber Unit + Lahav 433 Sigma + Yahalom; (ii) the Ministry of Welfare and Social Affairs — Pakid Saad (district welfare officer); (iii) the 105 Hotline for the Protection of Children and Youth Online — the principal child-online-safety hotline; (iv) the Council for the Welfare of the Child — HaMoetza Le'Shlom HaYeled — independent advocacy NGO; (v) the National Cyber Directorate (NCD) — Maarach HaSaiber HaLeumi — CERT-IL coordination; (vi) the ELEM — Youth in Distress NGO; (vii) the ERAN — Mental Health First Aid — 24/7 crisis helpline at 1201; (viii) the Sahar — Sahar.org.il online emotional-support service; (ix) the State Attorney's Office — Cyber Department + Children/Youth Department; (x) the Saviv Center for the Protection of Children and Youth Online — partner organisation of 105. Balance cooperates with each on incidents involving Israeli kids — see § 14 below.
6. PPL rights catalogue
6.1 The rights catalogue
An Israeli resident has the following rights under the PPL + Amendment 13 + the PPA's binding guidance as in force at the Effective date.
- PPL section 11 — Right to be informed. When a controller requests information from a data subject, the controller must inform the data subject of (a) whether there is a legal obligation to provide the information or it is by his consent; (b) the purpose for which the information is requested; (c) to whom the information will be transmitted and the purposes of the transmission. Honored at
and in-app at the privacy notice screen. - PPL section 13 — Right of access. Every person is entitled to receive from a controller, in writing in Hebrew or in another language understood by him, all the information about him that is held in the database. Honored in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary; Hebrew summary queued for Phase-2 locale rollout.
- PPL section 13A — Right of access by representative. Where the data subject is unable to exercise the right of access in person, a representative may exercise the right on the data subject's behalf with appropriate proof of authority.
- PPL section 14 — Right of correction. Where the data subject finds that information about him in a database is incorrect, incomplete, unclear, or out of date, he may apply to the controller to correct it. Honored in-app at Settings → Account → Edit and at
. - PPL section 14(b) — Right to add a note. Where the controller refuses to correct the information, the data subject is entitled to have a note recorded in the database indicating his objection to the information, alongside the information itself.
- PPL Amendment 13 expanded right of erasure / blocking. Amendment 13 strengthens the data subject's right to request erasure or blocking of personal information where the information is no longer necessary for the purposes for which it was collected, where the data subject has withdrawn consent, where the processing is unlawful, or where the information is incorrect / inaccurate / outdated. The Israeli erasure right tracks the GDPR Article 17 erasure right substantively (within the framework of the PPL's existing remedies).
- PPL section 17F(d) — Right to be removed from direct-mailing database (n/a — Balance does not use a direct-mailing database).
- PPL section 25 — Right to request deletion (in the direct-mailing context — n/a as above).
- PPL section 31 — Right of civil action. Infringement of privacy is a civil wrong; the data subject may file a civil action in the Magistrate's Court or the District Court depending on the value of the claim. Statutory damages without proof of harm up to NIS 75,000 (post-Amendment-13 cap effective from 14 August 2025).
- PPL section 34 — Right of judicial injunction. The court may grant an injunction against an ongoing infringement of privacy.
- PPL section 31A — Right to file a criminal complaint for wilful infringement of privacy under the criminal limb of the PPL (offence punishable by up to 5 years' imprisonment).
- PPA complaint right. The data subject may file a complaint with the PPA at the PPA's online complaint portal or by email at
ppa@justice.gov.il. The PPA may open an investigation, issue administrative orders, and impose administrative financial sanctions. - Basic Law (HDL) section 7 constitutional remedy. The data subject may petition the Supreme Court sitting as a Bagatz in matters of public-law privacy concern.
6.2 Timeline
- PPL section 13 access: the PPA's interpretive practice and PPA Position Papers benchmark the controller's response window at 30 days from receipt of the access request, extendible with notice to the data subject. Balance adheres to a 30-day target.
- PPL section 14 correction: as soon as practicable, in any event within 30 days.
- PPL Amendment 13 erasure / blocking: Balance gives effect to an erasure / blocking request within 30 days, consistent with the PPA's interpretive practice.
- Direct-mailing removal (section 17F(d) / section 25): n/a (Balance does not use a direct-mailing database).
- PPA complaint: the PPA's published target is to conduct an initial assessment within 30 days + an in-depth investigation thereafter; complex matters may take longer.
Where the access carve-outs at PPL section 13(c) apply (national security, public safety, prevention/investigation/prosecution of criminal offences, regulatory enforcement, certain professional confidentialities), Balance may decline to provide access and explain the reasons.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.
6.4 Fees
Under PPL section 13(d) + the regulations made thereunder, a controller may charge a reasonable fee for processing an access request, provided the fee is not excessive. Balance does not charge for access in practice.
6.5 Language
A request may be submitted in Hebrew, English, or Arabic. The PPA accepts complaints in Hebrew, English, and Arabic.
7. Children's information — PPL + Amendment 13 + Capacity and Guardianship Law + Youth Care Law
Balance processes personal information of Israeli kids under the following layered framework:
- PPL section 4 consent + Amendment 13 enhanced-consent framework read with the PPA's binding Guidelines on Children's Privacy — for any minor under 18, the controller should obtain consent from the parent or guardian exercising parental responsibility under the Capacity and Guardianship Law sections 14–18.
- Capacity and Guardianship Law, 5722-1962 sections 14–18 — joint parental guardianship of mother and father (sections 14 + 15); in case of divorce or separation, custodial parent's authority allocated by court order (sections 16 + 17); guardian's duty to act in the minor's best interest (section 17); minor's capacity is graduated by age and maturity (section 6 for the under-7 absolute incapacity; sections 4 + 5 for the graduated capacity of 7+ minors with parental ratification).
- Youth (Care and Supervision) Law, 5720-1960 — child-protection framework including the mandatory-reporting regime at section 7 (medavchei chova).
- Penal Law, 5737-1977 Chapter 8 — sexual offences against minors + online-luring offence at section 199(a)(2).
- Civil Wrongs Ordinance [New Version], 5728-1968 — parental-responsibility tort framework.
- UN Convention on the Rights of the Child (Israel acceded 3 October 1991) — internalised through Israel's child-welfare statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Hebrew queued for Phase 2 locale rollout; Arabic queued in the same Phase 2 rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Israel — PPL section 36 + Transfer of Data Abroad Regulations 5761-2001
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Israeli resident's personal information leaves Israel at the point of being uploaded to the Balance backend.
8.1 The Israel-to-US transfer mechanism — PPL section 36 + Transfer Regulations Regulation 2
PPL section 36 authorises the Minister of Justice to make regulations on the transfer of information from a database to abroad. The operative regulations are the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001 (the "Transfer Regulations") in force from 1 May 2001.
Transfer Regulations Regulation 2 is the operative cross-border-transfer rule. The controller may transfer information from the database abroad only if the receiving country provides a level of protection equivalent to or better than that provided by Israeli law, or if one of the Regulation 2(c) exceptions applies: - (1) the data subject has consented to the transfer; - (2) the consent of the data subject cannot be obtained and the transfer is essential for the protection of the public health or for the protection of the data subject's health; - (3) the transfer is made to a corporation under the controller's control, provided that the corporation has undertaken to maintain the conditions for holding and using the information as required of an Israeli holder of a database; - (4) the transfer is made to a country that has agreed with the State of Israel to receive information from Israel (none currently engaged operationally for Balance); - (5) the information is transferred to a controller in a country that is a party to a treaty under which the State of Israel is bound to transfer the information (none currently engaged operationally for Balance); - (6) the information is transferred to a country that has received an EU adequacy decision (note: the receiving country must be EU-adequate; the EU adequacy decision for Israel itself is for the outbound from EU to Israel direction, separate from Israel's outbound to third country rules); - (7) other narrowly drawn exceptions including transfer pursuant to PPA approval + transfer for compliance with Israeli law.
Transfer Regulations Regulation 2(d) is the operative compounding rule. Even where one of the Regulation 2(c) exceptions applies, the receiving entity must give a written undertaking to maintain the conditions for holding and using the information as required of an Israeli holder of a database under Israeli law. This Regulation 2(d) written-undertaking requirement is the operational anchor of the Israeli international-transfer regime.
Balance relies on the following stack to satisfy PPL section 36 + Transfer Regulations Regulation 2 for the Israel → US transfer:
- Regulation 2(c)(1) consent overlay. The parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the US recipient has given a Regulation 2(d) written undertaking to maintain the conditions for holding and using the information as required of an Israeli holder of a database, identifies the country of destination and the categories of recipients, and informs the parent of any risk arising from the transfer.
- Regulation 2(d) written undertaking. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that includes a binding undertaking to maintain the conditions for holding and using the information as required of an Israeli holder of a database under Israeli law. The full transfer pack is in our international-transfer pack § 6. The contractual safeguards are reinforced by EU SCC substance + UK IDTA substance + APP-aligned substance + Quebec-Private-Sector-Act-aligned substance as substantive overlays.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Israeli-resident personal information to a third country outside the section 36 + Transfer Regulations framework without the controller's prior written authorisation.
8.2 The Israel-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Israel-KZ axis is covered by the Regulation 2(d) written undertaking + Regulation 2(c)(1) consent routes — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
8.3 PPA database registration
PPL section 8 + the Protection of Privacy Regulations (Conditions for Holding and Maintaining a Database by Holders Thereof and Conditions for Transfer of Information Between Public Bodies), 5746-1986 + Amendment 13's narrowed registration triggers require the controller of a database meeting the registration triggers to register the database with the PPA Database Registrar. Under Amendment 13, registration is required where the database (a) contains information about more than 100,000 persons; or (b) contains sensitive information (post-Amendment-13 expanded definition); or (c) is held by a public body. Balance's database does not contain sensitive information in the section 7 expanded sense (no health / genetic / biometric / political / religious / sexual-orientation / past-criminal-conviction information). The PPA's interpretive practice for foreign controllers without permanent Israeli establishment under PPL section 36A is documented in the PPA's Position Paper on the Extraterritorial Application of the PPL under Amendment 13: foreign controllers are not required to register their databases with the PPA Database Registrar but remain subject to the PPL's substantive obligations including the data-security, transparency, access-and-correction, and PPO obligations. Balance accordingly does not register its database with the PPA Database Registrar at the Effective date and tracks this in the placeholder tracker. Should the PPA's interpretive practice change or should Balance pass a threshold that engages registration, registration will follow via the PPA portal.
8.4 EU adequacy — inbound direction (context-setting only)
Israel holds an EU adequacy decision under GDPR Article 45 by virtue of Commission Decision 2011/61/EU of 31 January 2011 (most recently reviewed by the Commission in January 2024 with the adequacy decision confirmed). The Israel adequacy decision facilitates inbound EU→Israel transfers. Balance's data architecture does not host any personal data in Israel (the backend is in the US — see § 9 below), so the inbound EU→Israel direction is not operationally engaged for Balance. The outbound Israel→US transfer that Balance does engage in is governed separately by PPL section 36 + Transfer Regulations Regulation 2 (treated in § 8.1 above).
9. Data residency for Israeli residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Israeli resident's personal information held in Israel? | No. Every Israeli resident's personal information is held in the United States. The PPL section 36 + Transfer Regulations Regulation 2 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there an Israeli establishment? | No. Balance has no permanent establishment in Israel. The PPL's extraterritorial reach (section 36A + Amendment 13 + the PPA's Position Paper on the Extraterritorial Application of the PPL) is the basis for Balance's PPL compliance. |
| Where is the supervisory authority? | Israel — PPA + Ministry of Justice + the regulatory bodies in § 3.3 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Israel does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bank of Israel directives on outsourcing by Israeli banks — not applicable to Balance) and certain Defence Establishment regulations (not applicable to Balance).
10. Sub-processors touching Israeli-resident information
| Sub-processor | Role | Location of processing | Israeli transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Transfer Regulations Regulation 2(d) written undertaking with PPL-comparable-protection clauses + Regulation 2(c)(1) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Regulation 2(d) written undertaking (Google Cloud Data Processing Addendum) + Regulation 2(c)(1) consent; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Regulation 2(d) written undertaking (Google Cloud Data Processing Addendum) + Regulation 2(c)(1) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Israeli kid + parent devices | United States | Regulation 2(d) + Regulation 2(c)(1) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Regulation 2(d) + Regulation 2(c)(1) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Regulation 2(d) + Regulation 2(c)(1) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Israeli parent users | United States | Regulation 2(d) + Regulation 2(c)(1). |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PPL section 11B security obligation + Data Security Regulations Regulations 4–11. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — PPL section 11D (Amendment 13) + Data Security Regulations regulation 11
PPL section 11D (introduced by Amendment 13, in force from 14 August 2025) + Data Security Regulations Regulation 11 (in force from 8 May 2018) is the principal breach-notification regime. The Israeli regime requires immediate PPA notification on the controller's knowledge of a serious security incident at a high-security-level database:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| PPA | A serious security incident has occurred at a high-security-level database — defined by Data Security Regulations Regulation 11 + the PPA's Guidelines on Notifications of Serious Security Incidents + PPL section 11D as introduced by Amendment 13 as an incident that materially compromises the confidentiality, integrity, or availability of personal information held in the database, including unauthorised access, unauthorised use, accidental loss or destruction, or a deliberate attack. | Immediately upon the controller's knowledge of the serious security incident (the Israeli regime does not specify a numerical hours-window; the operative standard is "miyad" — immediately — with the PPA's interpretive practice and the PPA's published guidance treating this as as soon as practicable but no later than within 24 hours from initial discovery for a clearly notifiable serious security incident at a high-security-level database). Balance internal anchor: as soon as practicable but no later than 24 hours from initial discovery (Israel benchmark) + no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark for the broader notification-decision window). | PPA online Serious Security Incident Notification portal at https://www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page + by email to ppa@justice.gov.il |
| Affected individuals | A serious security incident as above where the PPA, exercising its powers under Data Security Regulations Regulation 11 + PPL section 11D, directs the controller to notify the affected individuals — OR where the controller, exercising its own judgement and the harm-likelihood analysis under PPA Guidance on Notifications, determines that affected-individual notification is warranted to allow the affected individuals to take protective measures. | As soon as practicable after PPA notification, subject to the PPA's direction and the carve-outs in the PPA Guidelines on Notifications of Serious Security Incidents (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be required). | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Hebrew version queued for the Phase-2 locale rollout. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | Israel Police National Cyber Unit + 105 Hotline + Pakid Saad. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under Data Security Regulations Regulation 11 + PPL section 11D completed within 24 hours of discovery for serious-security-incident escalation, PPA notification within the miyad (immediate) standard with the operational anchor at as soon as practicable but no later than 24 hours from initial discovery, affected-individual notification per the PPA's direction.
11.1 Minimum content of the PPA notification (Data Security Regulations Regulation 11(b) + PPA Guidelines on Notifications of Serious Security Incidents)
The PPA notification states:
- the nature of the serious security incident, the description of how the incident occurred, the personal information possibly involved, the chronology of the events leading up to the loss of control of the personal information;
- the number of data subjects involved (or the best estimate);
- the description of the likely consequences of the incident;
- the measures taken or proposed to be taken to address the incident (including measures to mitigate possible harm or negative consequences);
- the name and contact details of the PPO (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.
The English-language template lives in our breach-notification runbook § 8.1. A Hebrew version is queued for Phase 2 locale rollout.
11.2 Non-compliance — PPL sections 37–48 + Amendment 13 enforcement-modernisation
- PPL section 5 — concealment of an infringement of privacy is itself an offence.
- Amendment 13 administrative financial sanctions — administrative financial sanctions up to NIS 3.2 million OR 5% of annual turnover in significant cases, with the PPA's discretion guided by the proportionality + culpability factors in the Amendment 13 enforcement-modernisation regime.
- PPL section 31A criminal limb — wilful infringement of privacy including concealment of a serious security incident may attract criminal liability.
11.3 Annual security audit
Data Security Regulations Regulation 10 requires the controller of a high-security-level database to commission an annual external security audit and a periodic penetration-testing exercise. Balance complies via the annual audit + the periodic penetration-testing schedule documented in the Database Definition Document (internal).
12. Cookies, spam, and electronic direct marketing
Israel does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PPL section 11 notification + sections 2(9) + 2(10) purpose limitation for any cookie that processes personal information; (ii) the PPA's interpretive position on cookies in the Guidelines on Privacy in Online Services; (iii) the Communications Law section 30A anti-spam framework (in force 1 December 2008) for commercial electronic messages; (iv) PPL section 17F + 17F(d) for direct mailing under the PPL framework + the Direct Mail Registry.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages within the meaning of Communications Law section 30A to Israeli residents. The only email Balance sends to Israeli parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The Communications Law section 30A advertising message definition requires the message to promote the supply of goods or services for a commercial purpose; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with Communications Law section 30A: (i) prior express consent from the recipient (opt-in); (ii) clear marking of the message as advertising (pirsomet) in the subject line; (iii) clear identification of the sender; (iv) a clearly-identified opt-out mechanism in the body; (v) honour an opt-out request within a reasonable time.
12.4 No telemarketing and no Direct Mail Registry engagement
Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Israeli residents. Balance does not maintain a direct-mailing database within the meaning of PPL section 17F; the PPL section 17F + section 17F(d) + section 25 framework + the Direct Mail Registry (Mirsham HaDiyur HaYashir) are not operationally engaged.
13. Lawful-access requests and the encryption posture
Israeli authorities may serve a lawful-access request on Balance via:
- A judicial search warrant under the Criminal Procedure (Arrest and Search) Ordinance [New Version], 5729-1969 sections 23A + 23B (search in computer material) — the principal mechanism for compelling production of stored personal information in connection with a criminal investigation.
- A judicial order for communications data under the Criminal Procedure (Powers of Enforcement — Communications Data) Law, 5768-2007 (Communications Data Law) — for subscriber, traffic, and location data.
- A judicial interception order under the Wiretapping Law, 5739-1979 (Chok HaAza'na) — for the lawful interception of communications.
- An order under the Computers Law, 5755-1995 + the Search in Computer Material sub-regime within the Criminal Procedure Ordinance.
- A PPA administrative order or compliance notice under PPL sections 37–48 + Amendment 13's enforcement-modernisation regime (the PPA has investigative powers analogous to those of a regulator within the administrative-law framework).
- An ordinary civil-court production order or subpoena under the Civil Procedure Regulations, 5779-2018.
- A Mutual Legal Assistance Treaty (MLAT) request channelled through the State Attorney's Office under the International Legal Assistance Law, 5758-1998 (the "International Legal Assistance Law") or under a bilateral MLAT.
- A Budapest Convention request channelled via the 24/7 point-of-contact regime — Israel has been a party to the Budapest Convention since 1 September 2016.
- A Bagatz order in a matter of public-law concern.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media. PPL section 11B security obligation + Data Security Regulations Regulations 4–11 + the Wiretapping Law, 5739-1979 prohibition on unauthorised interception + the Computers Law, 5755-1995 section 4 prohibition on unauthorised access all reinforce the design choice.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Israeli counsel to assess the validity of the request and the appropriate response under PPL section 2 carve-outs + the relevant lawful-access statute + the Basic Law (HDL) section 7 proportionality screen; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the Israel Police National Cyber Unit, the State Attorney's Office Cyber Department, the 105 Hotline, and the Pakid Saad on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (PPL section 11 notification + Basic Law (HDL) section 7 + PPA interpretive practice). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the Communications Data Law or the Wiretapping Law), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Israel
An Israeli resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Israel Police — emergency 100 (Hebrew: Mishtara — Mukad 100); non-emergency Mokda 110 for the National Cyber Unit. The Israel Police National Cyber Unit is the principal law-enforcement node for cyber-CSAE.
- 105 — Israeli National Hotline for the Protection of Children and Youth Online — the principal Israeli child-online-safety hotline. Phone: dial 105 (24/7); online:
https://www.gov.il/he/departments/general/police-105. Operated by the Israel Police + the Ministry of Public Security + the National Cyber Directorate. - Ministry of Welfare and Social Affairs — Pakid Saad (district welfare officer) — district-level welfare officers operating under the Youth (Care and Supervision) Law section 7. Hotline 118 (Welfare Ministry general).
- Council for the Welfare of the Child — HaMoetza Le'Shlom HaYeled — phone: +972 2 6780606; online:
https://www.children.org.il/. - State Attorney's Office — Cyber Department + Children/Youth Department —
https://www.gov.il/en/departments/the_state_attorneys_office. - ELEM — Youth in Distress — NGO for youth in distress. Phone: 1800-444-005; online:
https://www.elem.org.il/. - ERAN — Mental Health First Aid — 24/7 crisis helpline. Phone: 1201 (Israel domestic); online:
https://www.eran.org.il/. - Sahar — Sahar.org.il — online emotional-support service. Online chat at
https://www.sahar.org.il/. - National Cyber Directorate (NCD) — CERT-IL —
https://www.gov.il/en/departments/units/national-cyber-security. CERT-IL coordinates national-level cyber-incident response; relevant where the CSAE incident has a broader cyber-security dimension. - Saviv Center for the Protection of Children and Youth Online — partner organisation of 105; via 105.
- Israeli Internet Association (ISOC-IL) —
https://www.isoc.org.il/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Israel coordination via Israel Police + INTERPOL Israel. - INHOPE — Israel does not currently have a domestic INHOPE-member hotline at the Effective date. Cross-border CSAM reports flow through 105 + Israel Police National Cyber Unit + INTERPOL Israel + the international INHOPE network.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
An Israeli resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Privacy Protection Authority (PPA) | PPL | 39 Yermiyahu Street, Jerusalem 9446722; https://www.gov.il/en/departments/the_privacy_protection_authority; +972 73 3927700; ppa@justice.gov.il |
| Ministry of Justice | PPL parent ministry | 39 Yermiyahu Street, Jerusalem 9446722; https://www.gov.il/en/departments/ministry_of_justice |
| Israel Police — National Cyber Unit | Cybercrime + CSAE | https://www.police.gov.il/; emergency 100; non-emergency 110 |
| 105 Hotline | Child-online-safety | https://www.gov.il/he/departments/general/police-105; dial 105 |
| Ministry of Welfare and Social Affairs | Youth (Care and Supervision) Law | https://www.gov.il/en/departments/ministry_of_welfare_and_social_affairs |
| Council for the Welfare of the Child | Independent child-welfare advocacy | https://www.children.org.il/; +972 2 6780606 |
| State Attorney's Office — Cyber + Children/Youth Departments | Cybercrime prosecution + child-protection prosecution | https://www.gov.il/en/departments/the_state_attorneys_office |
| Consumer Protection and Fair Trade Authority (RaHTSAH) | Consumer Protection Law + Distance-Selling Regulations | https://www.gov.il/en/departments/consumer_protection_and_fair_trade_authority |
| Standard Contracts Tribunal | Standard Contracts Law depriving-condition adjudication | https://www.gov.il/en/departments/units/tribunal_for_standard_contracts |
| Magistrate's Court | PPL section 31 civil-wrong action up to NIS 2.5 million; small-claims jurisdiction up to NIS 35,000; PPA appeal jurisdiction | via https://www.gov.il/en/departments/the_judicial_authority |
| District Court | PPL section 31 civil-wrong action above Magistrate's Court limits; PPA appeal jurisdiction (Court for Administrative Affairs) | via https://www.gov.il/en/departments/the_judicial_authority |
| Supreme Court of Israel | Bagatz petition + appellate review | https://supremedecisions.court.gov.il/ |
An Israeli resident may always first raise the matter with us at (data-subject access; named individual: , in his capacity as the PPO under PPL section 17B1 + Amendment 13). We will respond within the PPL timelines. The PPA's published policy is to attempt resolution with the controller first, but the PPA accepts direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate PPA action.
16. Consumer rights — the Consumer Protection Law + Distance-Selling Regulations + Standard Contracts Law overlay
The Consumer Protection Law, 5741-1981 (Hebrew: Chok Hagana al HaTzarchan), the Consumer Protection Regulations (Transactions of Distance Selling), 5774-2014 (in force from 1 October 2014), and the Standard Contracts Law, 5743-1982 (Hebrew: Chok HaChozim HaAchidim) apply to Balance's subscription flow as a consumer transaction. The parent is a consumer (tzarchan) within the Consumer Protection Law section 1 definition. Treatment is implemented in Subscription Terms § 20.
16.1 Prohibition of deception + undue influence (Consumer Protection Law sections 2 + 3)
Consumer Protection Law section 2 prohibits deception in a transaction with a consumer (false or misleading representations regarding the nature, characteristics, terms, price, or origin of consumer goods or services). Consumer Protection Law section 3 prohibits undue influence on a consumer's decision to enter into a transaction. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each section 2 / section 3 risk.
16.2 14-day cooling-off right (Consumer Protection Law section 14C + Distance-Selling Regulations)
- Consumer Protection Law section 14C(c) — for a distance-selling transaction (a transaction concluded without simultaneous physical presence of the consumer and the supplier, through telecommunications including internet or telephone), the consumer is entitled to cancel the transaction within 14 days of receipt of the goods or of the conclusion of the contract for services. For ongoing services (continuing transactions) the 14-day cooling-off applies, with the consumer entitled to a pro-rata refund for any unused portion.
- Distance-Selling Regulations, 5774-2014 operationalise the section 14C right (cancellation form template; pro-rata refund calculation; supplier's confirmation obligations; supplier's pre-contract disclosure obligations).
Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, which meets and (in practice, by being no-questions) exceeds the Consumer Protection Law section 14C cooling-off minimum.
16.3 Supplier disclosure obligations (Consumer Protection Law section 14E)
Consumer Protection Law section 14E + the Distance-Selling Regulations require the supplier in a distance-selling transaction to disclose: (i) the supplier's name + business address + means of contact; (ii) the principal characteristics of the goods or services; (iii) the price including taxes + the delivery and payment terms; (iv) the duration of the contract for continuing services; (v) the consumer's section 14C cancellation right with a description of the procedure for exercising it. Balance's pre-contract subscription screen + the in-app subscription terms + the Subscription Terms document (Subscription Terms) implement each disclosure.
16.4 Standard Contracts Law — depriving-condition screen
The Standard Contracts Law, 5743-1982 applies to Balance's Terms of Service and Subscription Terms as standard contracts (terms drafted by the supplier and offered to the consumer without individual negotiation). The Standard Contracts Law:
- Section 3 prohibits a depriving condition (Hebrew: tnai magbil) in a standard contract — a condition that, having regard to the contract as a whole, is unreasonable or unconscionable.
- Section 4 presumes 12 categories of conditions to be depriving, including (i) conditions that exclude or limit the supplier's liability; (ii) jurisdiction-displacement clauses depriving the consumer of mandatory protection; (iii) choice-of-law clauses depriving the consumer of mandatory protection; (iv) automatic-renewal clauses without adequate notice; (v) one-sided unilateral-modification clauses.
- Section 19 — judicial relief — the court may rescind or modify a depriving condition.
- Standard Contracts Tribunal — the Beit Din LeChozim Achidim may approve a standard contract in advance, in which case the approved contract is presumed not to contain depriving conditions.
Balance's Terms of Service and Subscription Terms are drafted to comply with the Standard Contracts Law. The consumer's domicile forum is preserved per Terms of Service § 19; choice-of-law clauses that would deprive the Israeli consumer of mandatory protection are subject to the Standard Contracts Law section 4 + the public policy doctrine.
16.5 Refunds and the Israeli subscription posture
Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, satisfying the Consumer Protection Law section 14C cooling-off period. The 14-day refund window is documented at Subscription Terms § 20.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — Regulation 2(d) written undertakings with PPL-comparable-protection clauses on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- New Zealand Country Annex: New Zealand annex (A-NZ).
- Singapore Country Annex: Singapore annex (A-SG).
- Philippines Country Annex: Philippines annex (A-PH).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the PPL (5741-1981) — including the bringing into force of any provision of Amendment No. 13 (5784-2024) that is not yet operationally in force at the Effective date — triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- A material amendment to the Protection of Privacy Regulations (Data Security), 5777-2017 triggers an off-cycle update to §§ 4, 8, and 11.
- A material amendment to the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001 triggers an off-cycle update to § 8.
- A new or amended PPA guidance document — including any revision to the Guidelines on Privacy Protection Officers under Amendment 13, the Guidelines on Notifications of Serious Security Incidents, the Guidelines on Children's Privacy (Hebrew: Hanchayat HaRashut: Pratiut HaYeladim), or the Position Paper on the Extraterritorial Application of the PPL under Amendment 13 — triggers an off-cycle update.
- A material amendment to the Penal Law, 5737-1977 (in particular sections 199, 200, 214, 345, 345A, 346, 348, 351), to the Youth (Care and Supervision) Law, 5720-1960, or to the Youth (Trial, Punishment and Modes of Treatment) Law, 5731-1971, triggers an off-cycle update to § 13 + § 14.
- A material amendment to the Computers Law, 5755-1995, to the Wiretapping Law, 5739-1979, or to the Criminal Procedure (Powers of Enforcement — Communications Data) Law, 5768-2007, triggers an off-cycle update to § 13.
- A material amendment to the Consumer Protection Law, 5741-1981, to the Consumer Protection Regulations (Transactions of Distance Selling), 5774-2014, or to the Standard Contracts Law, 5743-1982, triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to the Communications Law (Telecommunications and Broadcasting), 5742-1982 section 30A (anti-spam) triggers an off-cycle update to § 12.
- A material PPA Decision, a material judgment of the Magistrate's Court / District Court / Supreme Court bearing on the PPL, the Basic Law (HDL) section 7, or the civil-wrongs privacy framework, triggers an off-cycle update.
- A change to Israel's EU adequacy status under Commission Decision 2011/61/EU of 31 January 2011 — including any review or revocation by the European Commission under GDPR Article 45(4) — triggers an off-cycle update to § 2 + § 8.
- The entry into force in Israel of the Second Additional Protocol to the Budapest Convention (Israel has signed but ratification status is monitored) triggers an off-cycle update to § 13.
- A material change to a sub-processor's PPL-comparable-protection status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The PPO signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The Hebrew translation is queued for the Phase-2 locale rollout, with the Hebrew version intended to be authoritative for the Israeli resident on its publication; Arabic translation is queued in the same Phase-2 rollout, per our internal compliance tracker.
End of Israel Country Annex.