Privacy policy
Last updated: October 10, 2026
Tikli is a document-collection and case-workflow service for mortgage-advice offices. It messages the office's clients on WhatsApp on the office's behalf, requests documents, reads them and updates the advisor. This policy explains what we process, why, where it is stored and your rights. The Hebrew version prevails.
Who we are
Tikli is operated by Doron Nazaretsky, a licensed sole proprietor (Osek Murshe) in Israel, no. 209130368, 7 Rambam St., Tel Aviv-Yafo, Israel. Privacy contact: privacy@tikli.ai.
Our role
The office using Tikli is the controller of its clients' data. Tikli processes that data on the office's behalf, only on its instructions and under a data processing agreement.
Data we process
- Office clients: WhatsApp name and phone number, the messages exchanged with Tikli, and documents uploaded through the secure link (e.g. payslips, bank statements, credit reports, certificates). Some of these contain financial and sensitive data.
- Advisors and offices: name, email, office details and service settings.
- Website visitors: no cookies, tracking or advertising tools. Our hosting provider keeps technical access logs (such as IP addresses) for security.
How we use it
Only to provide the service to the office: requesting documents, reading and checking them, cross-checking them with what the client said, sending reminders, organising the case and reporting to the advisor. We do not sell data, use it for advertising, or use it to train AI models.
AI processing
Tikli uses Google Vertex AI, hosted in the European Union, to read documents and understand replies. The model provider does not use the data for training. Decisions on a case are always made by the advisor.
Where data is stored
Documents are stored in a dedicated folder in the office's own Google Drive. We do not keep a database of client documents. Sensitive documents are uploaded only through a secure link, never in the chat.
Data from Google APIs
Tikli accesses the office's Google Drive only to store and organise case documents, with access limited to files the service created or the office shared with it. Tikli's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This data is not used for advertising, is not sold, is not used to develop, improve or train generalised AI or ML models, and is not read by humans except with the office's consent, for security purposes, or where required by law.
Who we share data with
- Meta (WhatsApp Business Platform), to deliver messages.
- Google Cloud and Google Workspace, for document processing, service hosting and email.
- Authorities, only where required by law.
Some providers process data outside Israel (mainly in the EU), in line with Israeli regulations on transfers of data abroad.
Retention
Conversation content and operational data are kept only while needed for the case, and no longer than 30 days after the case is closed. Documents stay in the office's Drive under the office's own retention policy. When an office stops using the service, we delete its data within 30 days.
Security
Data is encrypted in transit and at rest. Access is limited to the minimum needed, protected by two-factor authentication and logged.
Your rights
Under Israel's Privacy Protection Law you may access, correct or ask us to delete your data. See data deletion, or write to privacy@tikli.ai.
Children
The service is not intended for anyone under 18.
Changes
We will update the date above when this policy changes, and notify offices in advance of material changes.