Privacy Policy
Version 1.0 · Last updated: 25 August 2026
1. Who we are
תורג'מן גואטה הדר מזל, exempt dealer number 204174361, of נוקדים כפר אלדד 142, ישראל, operates the Lessio platform — a SaaS system for running private tutoring businesses and learning centres.
For the purposes of this policy, "the Company", "we" and "Lessio" refer to תורג'מן גואטה הדר מזל.
Privacy enquiries: support@getlessio.com
2. Definitions
- "The system" / "Lessio" — the software-as-a-service (SaaS) platform operated by the Company, including the management interface, the parent portal, the API and any accompanying service.
- "Business customer" — a private tutor, learning centre, art school, studio, or any other business or entity that registers and uses the system to run its own business.
- "End user" — any person whose personal information is entered into the system, including students, parents, guardians, teachers and employees — whether they interact with the system themselves or the information was entered by the business customer.
- "Personal information" — any information relating to an identified or identifiable person, as defined in the Israeli Protection of Privacy Law, 5741-1981.
- "Sensitive information" — information about a person concerning their religious beliefs, health, family circumstances, and any information the law classifies as particularly sensitive.
- "Third-party providers" — external companies and service providers the Company engages in order to operate the system and provide the service.
3. Lessio's role in relation to personal information
3.1 Information about business customers
In respect of information given to us by the business customer itself in order to manage its account, receive the service, be billed for the subscription, get technical support and receive marketing — the business customer is the data subject, and the Company acts as the party responsible for processing that information for those purposes.
3.2 Information a business customer enters about students, parents and others
When a business customer enters information about its students, their parents, its teachers, its employees and its customers — the business customer is primarily responsible for that information. Responsibility for legal compliance in respect of it — including establishing a lawful basis for collection, giving notice to data subjects and obtaining the required consents — rests first and foremost with the business customer.
Lessio processes this information in accordance with the business customer's instructions and for the purposes of operating the system, providing the service, securing information, giving technical support and meeting legal requirements. Lessio does not use this information for independent purposes unrelated to the service.
Although the business customer bears primary responsibility as described, Lessio undertakes to meet the obligations that apply to it by law in respect of all information held in the system.
4. What information we collect
4.1 Business customer account information
Full name and business name, email address, phone number, role in the business, billing details for the Lessio subscription, identifiers from the payment processor (payment instrument details are held only by the payment processor — see section 7), and information provided during onboarding and sales conversations.
4.2 Information about students, parents and contacts
Names of students and their parents/guardians, phone numbers and contact details, family relationships, age or date of birth where entered, and operational notes added by the business customer.
4.3 Lesson and schedule details
Lesson times, assigned teachers, availability and its updates, cancellations, attendance and absences, lesson status and lesson notes.
4.4 Charge and payment details
Charge amounts, charge dates, payment status, payment links created, charge and receipt history, and identifiers received from external payment and invoicing providers. Lessio is not a payment processor and does not store full card details — those are held only by the payment processors, in accordance with PCI-DSS.
4.5 Communications and messages
WhatsApp messages sent and/or received through the system, automatic reminders, system notifications, and records of support enquiries.
We also keep a record of messaging consent: its source (declared by the business, import, parent portal sign-in, booking form, or the parent messaging the business first), when it was given, which member of the business staff declared it, and when the one-time welcome notice was sent. An opt-out request ("stop" / "הסר") is likewise recorded with its timestamp and blocks all future business-initiated messages.
4.6 Technical information and logs
IP address, browser and device type, operating system, actions taken in the system, sign-in dates and times, error logs and API version information.
4.7 Cookies and tracking technologies
The website and the system use cookies and similar tracking technologies for the following purposes, through the tools listed:
- Google Analytics 4 (GA4) — analysing traffic and usage patterns on the website and in the system.
- Meta Pixel — tracking advertising conversions and improving campaigns.
- Microsoft Clarity — mapping the user experience on the marketing pages (heatmaps, session recordings). Loaded only after consent to analytics cookies.
- Lessio's own anonymous measurement — on the marketing pages we count visits ourselves, with no third party: which link the visit came from, which parts of the page were viewed, how long it lasted and which buttons were clicked. It relies on a random identifier stored in a cookie, does not store an IP address, a name, a phone number or the full address of the referring site, and is deleted after 180 days.
- Sentry — monitoring errors and detecting technical faults in real time.
5. Why we use the information
- Operating the system and providing the service — managing accounts, lessons, calendars, cancellations, reminders and the parent portal.
- Managing charges — creating payment requests, tracking statuses, connecting to payment and invoicing providers.
- Communicating with the customer — WhatsApp messages, lesson reminders, operational updates.
- Technical support and customer service — handling enquiries, diagnosing problems and controlled support access.
- Information security and control — detecting intrusion attempts, monitoring anomalies, retaining logs for investigation.
- Improving the product and analysing usage — understanding usage patterns to improve the user experience, generally on the basis of aggregated information.
- Marketing updates — to business customers only, with consent and with an opt-out.
- Legal and regulatory compliance — accounting, complying with court orders and responding to competent authorities.
6. Is providing information mandatory?
Providing personal information to Lessio is not a legal obligation. However, certain information is necessary in order to open an account and operate the service:
- Without basic account details (name, email, phone) — an account cannot be opened.
- Without student and lesson details — a calendar cannot be managed, reminders cannot be sent and charges cannot be handled.
- Without payment details for the subscription account — the paid version cannot continue to be used.
Some accounting information may be required by legal obligation (for example, retaining accounting documents under the law). In such cases we will say so explicitly at the point of collection wherever possible.
7. Sharing information with third parties
We do not sell personal information to third parties.
Information may be passed to the following parties solely in order to operate the service:
- Infrastructure and hosting — Supabase (database, authentication and file storage, on Amazon Web Services infrastructure) and Vercel (application hosting and processing of incoming WhatsApp messages).
- Communications — WhatsApp Business / Meta for sending and receiving messages and reminders; Resend for system emails; SMS providers where used.
- AI assistant (optional) — where a business customer enables the AI assistant, message content is sent for processing to the AI provider the customer selected (OpenAI or Anthropic), using the customer’s own API key.
- Google services (optional) — where a business customer connects their Google account, emails may be sent through Gmail under the customer’s own account, and availability (free/busy) may be read from their Google Calendar. Nothing is written to the calendar.
- Payments and processing — payment providers the business customer chose to connect (such as Cardcom, PayPlus, Bit, PayBox).
- Invoicing — invoicing providers the business customer connected (such as Green Invoice, iCount); and Sumit for billing Lessio’s own SaaS subscriptions.
- Monitoring and support — providers of monitoring, logging and error-diagnosis tools (such as Sentry) and product analytics tools.
- Professional advisers — lawyers and accountants, to a defined extent and under professional privilege.
- Competent bodies under the law — enforcement authorities, courts and regulators, where there is a legal obligation or a court order.
All third-party providers are obliged to safeguard the information and to comply with the law that applies to them.
7.1 Integrations the business customer connects
Some of the providers listed above (payment, invoicing, Google and AI providers) are not engaged by Lessio but are connected by the business customer, using the customer’s own account and credentials. Once connected, Lessio transfers to such a provider only the information required for the specific action the customer initiated (for example, the name and amount on an invoice, or the recipient and body of an email). The provider processes that information under its own terms of service and privacy policy, and the business customer is responsible for the choice of provider and for its use. The customer can disconnect an integration at any time from the system settings, after which no further information is transferred to that provider.
7.2 Google user data (Gmail and Google Calendar connections)
A business customer may, at their option, connect their Google account to the system. When connecting, Lessio receives only limited access, through Google's authorisation mechanism (OAuth):
- Gmail connection — permission to send emails only (the gmail.send scope) and the email address of the connected account. Lessio does not read, store or access the contents of the mailbox, the contacts, or any other information in the account.
- Google Calendar connection — read-only access to availability (free/busy) data from the calendar, in order to display availability and prevent scheduling conflicts. Lessio does not create, modify or delete calendar events.
Use: these permissions are used solely for actions the business customer initiates from within the system — sending emails in the customer's name and from the customer's account (for example payment requests and updates to their clients) and reading calendar availability. Google user data is not used for advertising, is not sold, is not transferred to third parties, and is not read by humans — except with the user's consent, for security purposes, or as required by law.
Storage: the access tokens received from Google are stored encrypted and are used solely to perform the actions described above.
Disconnection and deletion: the Google account can be disconnected at any time from the system settings — upon disconnection the access tokens are deleted. Lessio's access can also be revoked directly in Google's security settings at myaccount.google.com/permissions.
Lessio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Transfers of information outside Israel
Information may be stored and processed outside Israel, including within the European Union (mainly AWS and Supabase regions in Europe), and in the countries where the various service providers are located.
When personal information is transferred outside Israel, we work to ensure it is done:
- to countries determined to provide an adequate level of privacy protection;
- under contractual agreements that include undertakings to protect the information;
- in accordance with any direction issued by the Privacy Protection Authority under Amendment 13 to the law.
9. Retention and deletion
We retain personal information for as long as it is needed to operate the account, provide the service, meet legal and regulatory obligations, resolve disputes, secure information and manage backups.
| Type of information | Retention period |
|---|---|
| Operational data (lessons, students, charges) | 3 years from the end of the engagement |
| System and security logs | 12 months |
| Backups | 90 days |
| Accounting documents | No less than 7 years (under tax law) |
When the engagement ends, the customer may request an export of its data in a reasonable format. Immediate deletion from every backup system is not always possible — information may remain in backups until the regular backup cycle completes, and will not be accessible for active use.
10. Data subject rights
Under the Israeli Protection of Privacy Law, 5741-1981 and its amendments (including Amendment 13), a person is entitled to make a request to:
- Access information — to receive information about the personal information held about them in Lessio’s databases.
- Correct information — to request correction of information that is inaccurate, incomplete, unclear or out of date.
- Delete or restrict — to request deletion of information or restriction of its processing, subject to legal retention obligations and the needs of dispute resolution.
Making a request: write to support@getlessio.com setting out: full name, contact details, a description of the information the request concerns and the type of request. We may need to verify the requester's identity before responding. Detailed instructions for requesting data deletion are available on the data deletion instructions page.
Where the information was entered by a business customer: Lessio may refer the requester to that business customer, since it is the party that collected the information and is responsible for it, or handle the request in coordination with it.
You may also contact the Privacy Protection Authority at the Israeli Ministry of Justice on any matter concerning rights under the law.
11. Information about minors
The system is intended for use by adult business customers and may include information about students who are minors, entered by the business customer or by the parent/guardian.
- Lessio does not allow minors to register and use the system independently without the consent of a parent or guardian, or appropriate authorisation from the business customer.
- The business customer is responsible for ensuring it is entitled to enter information about minors into the system, including obtaining parent/guardian consent where the law requires it.
- Lessio handles information about minors carefully and in accordance with the law, and does not use it beyond what is needed to operate the service.
- If we learn that information about a minor was collected without appropriate authorisation, we will act to delete it.
12. Information security
The Company acts in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017, and applies accepted security measures appropriate to the nature of the information held, including:
- Access controls — access to information is limited to those authorised by their role.
- Role-based permissions — Lessio staff access information only to the extent their role requires.
- Encryption — information is transmitted over encrypted channels (TLS/HTTPS); sensitive information is also encrypted at rest.
- Customer separation — each business customer is held in an environment logically isolated from other customers.
- Backups — information is backed up regularly.
- Monitoring and logging — ongoing monitoring is in place to detect anomalies and security events.
- Security incident procedures — procedures exist for handling security events, including assessment, damage limitation and reporting.
We cannot guarantee absolute security. We work to reduce security risks to the reasonable minimum.
13. Security incidents
If a security incident is suspected that could harm the privacy of data subjects, Lessio will act immediately to investigate it, limit its damage and restore operation.
Notice will be given to the relevant parties in accordance with the applicable law and the circumstances — including notice to affected business customers and, where required, to the Privacy Protection Authority.
Where a business customer is required to notify data subjects about an incident affecting information it entered, Lessio will cooperate with it reasonably and provide the information available to it for that purpose.
14. Cookies and tracking technologies
The Lessio website and/or system may use cookies and similar tracking technologies:
- Essential cookies — required to operate the system and manage the sign-in session. These cannot be disabled.
- Anonymous measurement cookie — a random visitor identifier set by Lessio itself, used to count visits to the marketing pages and to link a signup to the source it came from. It does not identify a person, is not shared with any third party, and operates regardless of the choice made in the banner.
- Analytics cookies — Google Analytics 4 for usage analysis and product improvement; Microsoft Clarity for mapping the user experience. Loaded only after consent.
- Marketing cookies — Meta Pixel for tracking advertising conversions. Loaded only after consent.
- Error-monitoring cookies — Sentry for detecting and recording technical faults.
Third-party analytics and marketing cookies are chosen in the banner shown on your first visit: you can reject all of them, accept analytics only, or accept everything, and none of them load before you choose. To change an earlier choice, clear this site's cookies in your browser and the banner is shown again. Using the website and the system after registering constitutes consent to essential cookies.
15. Marketing and communications
Operational messages: messages necessary to operate the service (system updates, registration confirmations, changes to the terms of service, security alerts) are sent without an opt-out, since they are an inseparable part of the service.
Lessio marketing messages: updates, tips and offers are sent to business customers in accordance with Israeli law, with consent and with an opt-out in every message.
Messages a business customer sends to its own customers: Lessio is the technical infrastructure for sending WhatsApp messages and reminders on the business customer's behalf. The business customer is responsible for obtaining consent and complying with the law in respect of those messages.
16. Changes to this privacy policy
We may update this policy from time to time. The date of the last update is shown at the top of the document.
In the case of a material change, we will notify business customers in a way we consider appropriate (email, an in-system notice, and so on). Continued use of the system after the change is published constitutes acceptance of the updated terms.
17. Contact
For any question, request or enquiry regarding privacy:
תורג'מן גואטה הדר מזל
Privacy contact: תורג'מן גואטה הדר מזל
Email: support@getlessio.com
Phone: 050-434-3547
Address: נוקדים כפר אלדד 142, ישראל
We aim to respond to privacy enquiries within 30 days.