Toko Privacy Policy
Last updated January 2, 2025
Toko Health Ltd. (“Toko”) are deeply committed to protecting the privacy and security of our users’ data. This Privacy Policy is intended to describe our practices regarding the information we may collect from you when you use or access our Services, including information shared between you and your Session Partner, the ways in which we may use such information, and the choices and rights available to you. Capitalized terms which are not defined herein, shall have the meaning ascribed to them in our Terms of Use.
This Privacy Policy applies both to information of individuals visiting our website at toko.health (“Website”, and “Visitors”, respectively), and to information of individuals who have applied to establish an Account in the Toko Platform or that otherwise the Toko Platform and Services (“Users”). “You”, “your”, or similar terms refers collectively to Visitor and User.
1. Your Consent
PLEASE READ THIS PRIVACY POLICY BEFORE ACCESSING AND USING THE SERVICES. BY ACCESSING THE SERVICES, YOU AGREE TO THIS PRIVACY POLICY, INCLUDING TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION (AS DEFINED BELOW). IF YOU DISAGREE TO ANY TERM PROVIDED HEREIN, YOU MAY NOT ACCESS OR USE THE SERVICES.
Please note: You hereby acknowledge and agree that you are providing us with Personal Information at your own free will and that we may collect and use such Personal Information pursuant to this Privacy Policy and any applicable laws and regulations.
TO THE EXTENT THAT YOU PROVIDE US WITH ANY PERSONAL INFORMATION RELATED TO ANY THIRD PARTY OR ANY OTHER PERSON OR ENTITY WHICH IS NOT YOU, YOU ARE SOLELY RESPONSIBLE TO RECEIVE AND HEREBY REPRESENT THAT YOU HAVE AND UNDERTAKE THAT YOU SHALL HAVE AT ALL TIMES, MAINTAINED AND RECEIVED, THE CONSENT, AUTHORITY, PERMISSION AND APPROVAL OF SUCH PERSONS AND PROVIDED THEM WITH SUFFICIENT DISCLOSURES, TO ALLOW TOKO TO ACCESS, STORE, COLLECT, ANALYZE AND PROCESS SUCH PERSONAL INFORMATION AS DETAILED HEREIN.
2. What Types of Information We May Collect?
We divide the information we access and collect into two categories: Personal Information and Non-Personal Information. In this section, we describe each of the two categories of information which we may collect, and the applicable circumstances under which such collection is performed.
- Non-Personal Information: “Non-Personal Information” is information which may be made available to us or collected automatically via your use of the Services or the Website, that does not enable us to identify the person from whom it was collected, or to whom such data pertains. Non-Personal Information usually consists of technical, usage data, or aggregated usage information which is not linked to a specific individual.
- Personal Information:“Personal Information” is information that pertains or relates to a specific individual, where such individual is identified or may be identified with reasonable efforts or together with additional information, we have access to. Identification of an individual also includes the association of such an individual with a persistent identifier such as a name, an identification number, persistent cookie identifier, etc., i.e. an identifier that does not expire at the end of your session in our Services. Personal Information does not include information that has been anonymized or aggregated; provided that such information can no longer be used to identify a specific natural person.
Personal Information that is collected by us consists of the following types of information:
- Contact Data. We collect login credentials such as name, password, email address, and phone number in connection with your request to register for an Account within our Platform.
- Registration questionnaire Data.As part of our registration process for the Platform we collect certain Personal Information categories through a questionnaire, which includes your mental well-being measurement. The collection of these types of Personal Information is intended to enable Toko to assess its User’s resilience and mental well-being, aimed to facilitate a Match between the User and an appropriate Session Partner, improving the Services and reflecting progress within the Platform. Such data may also be used by Toko, to review any complaint that you may report about that Match with your Session Partner and to conduct, collaborate or participate in research studies with select universities/clinics, including the Sponsor (if applicable), provided that Toko will only use deidentified or aggregated information in such studies, and that any personal information will only be provided with the User’s consent.
- Session Data. The Services enables Users to access and communicate with their Session Partners through their use of the Platform. This information may be visible to and shared with the Session Partner and Toko, and may media files which may be stored and transcribed by Toko. Such information shall be kept confidential and protected, and we use this data in accordance with the terms and conditions of the Toko Terms of Use and the Privacy Policy.
YOU ARE SOLELY RESPONSIBLE FOR SHARING YOUR PERSONAL INFORMATION WITH THE SESSION PARTNER AND FOR THE INFORMATION YOU SHARE IN THE SCOPE OF THE TOKO SESSIONS YOU PARTICIPATE IN.
- Payment Data. To the extent that we collect your payment information, this information may include, without limitation, bank account numbers, credit card or debit card numbers, account details, and similar data. Such Information will be collected and processed by our third-party payment vendors pursuant to their privacy policies and terms of use.
- Usage Data.Including: IP address, UDID (Unique Device Identifier) or other persistent user and/or mobile device token, advertising ID, device type, browser and keyboard language, the User’s or Visitors’ “click-stream” and activities on the Services, the period of time the Visitor or User used the Website and/or Platform, and/or related time stamps.
- Cookies Data.Information that we collect from Users or Visitors through their use of and access to the Website, includes using “cookie” technology. To learn more about how we use cookies, please review our Cookie Policy, if available.
We do not collect any Personal Information from you or related to you without your approval, which is obtained, inter alia, through your acceptance of this Privacy Policy.
3. How Do You Collect Information From Me?
- We collect information through your use of the Service. In other words, we are aware of your usage of the Service and may gather, collect and record the information relating to such usage, including by using “cookies” and other tracking technologies, as further detailed below.
- We collect information which you provide us voluntarily. For example, we collect Personal information that you voluntarily provide when you request to register as a User and provide us with your login credentials, or information you provide us when you request to contact Toko.
4. Why Do You Collect and Process My Information?
We may use the personal information that we collect about you for the following purposes:
- To provide, operate, and improve the Services, Website and/or Platform for our Users and to manage your Account and provide you with customer support services.
- To send you updates, notices, notifications, and announcements related to the Services as well as newsletters, commercial offers and additional communications regarding our Services.
- To verify your eligibility for our Services.
- To enable us to improve and enhance our Services, to provide our Users with a better user experience with more relevant and accurate information, features and functionalities.
- To prevent, detect, mitigate, and investigate fraud, security breaches or other potentially prohibited or illegal activities.
- To charge fees for our Services.
- To comply with any applicable rule or regulation, to protect our legal interests and/or respond to or defend against (actual or potential) legal proceedings against us or our affiliates.
- To engage with our Session Partners and related third parties in order to perform certain operations on behalf of Toko.
- To verify to relevant Sponsors that sponsor your use of the Services, that such sponsorship was attributed to the intended person.
5. What Are Your Legal Grounds for Collecting My Personal Information?
- In performing an agreement with you: We collect and process your personal information in order to provide you with the Platform and the Services, following your acceptance of this Privacy Policy and pursuant to the Terms of Use.
- With your consent: We ask for your agreement to collect and process your information for specific purposes and you have the right to withdraw your consent at any time.
- Legitimate interest: We process your information for our legitimate interests while applying appropriate safeguards that protect your privacy. This means that we process your information for things like detecting, preventing, or otherwise addressing fraud, abuse, security, usability, functionality or technical issues with our services, protecting against harm to the rights, property or safety of our properties, or our users, or the public as required or permitted by law; enforcing legal claims, including investigation of potential violations of this Privacy Policy; in order to comply and/or fulfil our obligation under applicable laws, regulation, guidelines, industry standards and contractual requirements, legal process, subpoena or governmental request, as well as our Terms of Use.
6. Who Do You Share My Information With and Why?
We may share information with third parties (or otherwise allow them access to it) only in the following manners and instances:
- Internally– We may share information with our affiliates, as well as our employees, for the purposes described in this Privacy Policy. In addition, should Toko or any of its affiliates undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your information may be shared with the parties involved in such event under strict security conditions, for the purpose of evaluating such event and in accordance with the terms of this Privacy Policy. If we believe that such change in control might materially affect your Personal Information then stored with us, we will notify you of this event and the choices you may have, through prominent notice on our Services.
- Protecting Our Rights and Safety– We may share your information to enforce this Privacy Policy and/or the Terms of Use, including investigation of potential violations thereof; to detect, prevent, or otherwise address fraud, security or technical issues; or otherwise if we believe in good faith that this will help protect the rights, property or personal safety of any of our Users, or any member of the general public.
- Third Parties– We may share your information with a number of selected service providers, whose services and solutions are required or otherwise facilitate achievement of the purposes of processing set forth under Section 4 above. These third parties serve in facilitating and enhancing our Services and related services, including such third-party services required to allow platform analytics (e.g. Google analytics), payments processing, storing data (e.g Amazon AWS), website functionality as well as our business, legal, and financial advisors, and other essential third party services (collectively, “Third Party Service Providers”).
Please note – in certain cases such Services Providers may collect and process personal information, in a scope which is broader than the scope of collection and processing required for the purposes set forth above. This means that sometimes these Services Providers have access to more of your personal information than we do. In such cases all such excess collection and processing is performed pursuant to and under a direct contractual relationship you have with such Service Providers, and any rights you may have with respect to such information, collected by such Services Providers, shall be governed by such contractual relationship. Otherwise the terms of this Privacy Policy shall fully apply.
For example, we use Google, Facebook, and LinkedIn’s functionality of re-marketing tracking cookies and pixel-based retargeting. Please visit the Social Ad Platforms’ individual privacy policy to find out how they use such information:
- Google: https://policies.google.com/privacy
- Facebook: https://www.facebook.com/about/privacy/
- LinkedIn: https://www.linkedin.com/legal/cookie-policy
If you wish to opt-out of such re-targeting and tracking functionality of the Social Ad Platforms, you may do so at the following links:
- Google: https://myadcenter.google.co.il/controls
- Facebook: https://www.facebook.com/settings/?tab=ads
- LinkedIn: https://www.linkedin.com/help/linkedin/answer/62931
By choosing not to opt-out, you agree that any processing of your personal information by such third parties shall be done pursuant to your acceptance and agreement to their terms of use and privacy policies as specified in their relevant properties.
- Sponsors– Where users’ use of the Services is sponsored by Sponsors, we may share certain personal information of such users with the relevant Sponsors, as required to verify that the sponsorship is attributed to the right user.
- Law Enforcement– We may cooperate with government and law enforcement officials to enforce and comply with the law. We may therefore disclose any information to government or law enforcement officials as we believe necessary or appropriate to respond to claims and legal process (including but not limited to subpoenas), to protect our or a third party’s property and legal rights, to protect the safety of the public or any person, or to prevent or stop any activity we may consider to be, or to pose a risk of being, illegal, unethical, inappropriate or legally actionable.
For avoidance of doubt, we will NOT sell (as “sell” is traditionally defined) your personal data. That is, we will not provide your name and email or other personally identifiable information to third parties in exchange for money. We may share anonymized or de-identified information with any other third party, at our sole discretion. However, under California law, certain cases of sharing information, such as for advertising purposes, may be considered a “sale” of personal information. However, to the extent applicable, including if a supervisory authority determines that our practices include the selling and/or sharing of your personal information (as such terms are defined under applicable US State Privacy Laws including the CCPA), and you would like to opt out of the “sale” or “sharing” of your personal information, please contact us at support@toko.health.
7. Where Do You Transfer or Store My Information?
Your information may be transferred to, maintained, processed and stored by us and our authorized affiliates and service providers in the United States, EU and Israel. Please note that the data protection laws in the above jurisdictions may not be as comprehensive as those in your country of residence. Residents of certain countries may be subject to additional protections, as set forth below.
GDPR (EEA Users):This section applies only to natural persons residing in the European Union, EFTA States, or the United Kingdom. It is the Company’s policy to comply with the EEA’s General Data Protection Regulation (“GDPR”) and the UK GDPR. In accordance with the GDPR, we may transfer your Personal Information from your home country to the U.S. and/or other countries, provided that the transferee has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Specifically, we may cause such transfer if we ensured that at least one of the following applies:
- The country to which Personal Information has been transferred, has been determined by the EU Commission to be a country providing adequate protection to the privacy rights of EU residents.
- Application of Standard Contractual Clauses where appropriate.
8. What Are My Rights?
Under certain laws, including the EU, UK GDPR or US-state data protection laws individuals have rights regarding their personal data. You can exercise your rights at any time by contacting us at support@toko.health. Those rights may include, but are not limited to, the following:
- Right of access. You may have a right to know what information we hold about you and, in some cases, to have the information communicated to you. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information.
- Right to correct Personal Information. We endeavor to keep the information that we hold about you accurate and up to date. Should you realize that any of the information that we hold about you is incorrect, please let us know and we will correct it as soon as we can.
- Data deletion. In some circumstances, you have a right to request that some portions of the Personal Information that we hold about you be deleted or otherwise anonymized.
- Data portability. In some circumstances, you may have the right to request that we will provide you with the Personal Information you have made available to us, so you can transfer it to another party.
- Restriction of processing. In some cases, you may have the right to request restriction of the processing of your Personal Information, such as when you are disputing the accuracy of your information held by us.
Please note that these rights are reliant upon the data protection and privacy laws that are applicable in your jurisdiction. Toko may refuse requests to exercise data subject rights if there is a legitimate reason, such as if we cannot authenticate your identity, if the request could violate the rights of a third party or applicable law, or prevent us from delivering a service you requested.
9. Do You Use Cookies or Similar Tracking Technologies?
We may use certain monitoring and tracking technologies, including ones offered by third party service providers. These technologies are used in order to maintain, provide and improve our Services on an ongoing basis, and in order to provide a better experience to our users. For example, these technologies enable us to: (i) keep track of our Users’ preferences and authenticated sessions, (ii) secure our Services by detecting abnormal behaviors, (iii) identify technical issues and improve the overall performance of our Services, and (iv) create and monitor analytics.
We may use cookies in connection with our Services. A “Cookie” is a small data file that is downloaded and stored on your computer or mobile device when you visit our Services.
To learn more about our use of Cookies and other tracking technologies, please see our Cookie Policy, if available.
10. How Do You Keep My Information Secure?
We have implemented administrative, technical, and physical safeguards to help prevent unauthorized access, use, or disclosure of your Personal Information. We limit access of your information only to those employees, Third Party Service Providers or partners on a “need to know” basis, and strictly in order to enable us to perform the agreement between you and us.
Despite these measures, Toko cannot provide absolute information security or eliminate all risks associated with Personal Information, and security breaches may happen. If there are any questions about security, please contact us at support@toko.health.
11. How Long Will You Retain My Information?
We will retain your Personal Information only for as long as necessary to achieve the purposes for collection and processing set forth above. If you withdraw your consent to our processing your Personal Information, we will delete your Personal Information from our systems (except to the extent retaining such data in whole or in part is necessary to comply with any applicable rule or regulation and/or to respond to or defend against legal proceedings brought against us or our affiliates).
12. Candidates
We welcome qualified candidates (“Candidate(s)”) to apply to any of the open positions posted on our properties by sending us your contact details and CV or resume (“Candidate Information”). Since privacy and discreetness are very important to our Candidates, we are committed to keeping Candidate Information private and will use it solely for our internal recruitment purposes.
Please note that we may retain Candidate Information submitted to us even after the applied position has been filled or closed. This is done so we can re-consider Candidates for other suitable positions and opportunities at the Company, use the Candidate Information as a reference for future applications, and, in case the Candidate is hired, for additional employment and business purposes related to their employment with us. If you previously submitted your Candidate Information to us, and now wish to access it, update it or have it deleted from our systems, please contact us.
13. How Do You Protect the Privacy of Children?
To use our Services, Users must be over the age of eighteen (18). Therefore, we do not knowingly collect Personal Information from individuals under the age of eighteen and do not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that individuals under the age of eighteen are not using the Services. If you believe that we might have any information from or about an individual under the age of eighteen, please contact us at support@toko.health.
14. Intellectual Property Rights
We respect other people’s rights, and expect the same of you. You may not post any content or take any action on our Website or Platform that infringes or violates any other party’s rights or the law. We can remove any content or information you post on the Website if we believe that it violates this Privacy Policy or the Terms of Use. You may not use any of our copyrights or any similar marks, without our written permission.
Also, the Website may contain links to third-party websites. We do not endorse or sponsor such third-party sites and we are not responsible for their privacy practices. Please refer to the privacy policies of those Third-Party Sites for more information.
15. Updates to This Privacy Policy
This Privacy Policy is subject to changes from time to time at our sole discretion. The most current version will always be posted on our Services. You are advised to check for updates regularly. By continuing to access and use our Services after any updates become effective, you accept and agree to be bound by the updated Privacy Policy.
16. Direct Marketing
You hereby agree that we may use your contact details provided during registration to inform you regarding updates and offers related to our Services that may interest you and other related marketing materials. You may withdraw your consent via sending a written notice to Toko by email to the following address: support@toko.health or by clicking the “Unsubscribe” button displayed in the email you received. In addition, we may use your phone number in order to send you recurring marketing messages and promotions. You are able to opt-out from such recurring text messages at any time by replying to the text message we sent you, click the link in the text message, or otherwise, whichever is available to you. Once you opted-out, you may receive one SMS confirming you have successfully opted-out. After that you will receive no further messages unless you opt-in again.
17. General Information
This Privacy Policy, its interpretation, and any claims and disputes related hereto, shall be governed by the laws of the State of Israel, without respect to its conflict of law principles. Any and all such claims and disputes shall be brought in, and you hereby consent to them being litigated in and decided exclusively by a court of competent jurisdiction located in Tel Aviv, Israel.
18. How Can I Contact You?
If you wish to exercise any of the aforementioned rights or receive more information, please email us at support@toko.health.
Toko may provide you with notices concerning this Privacy Policy by using the e-mail address you provide in connection with your account registration on the Services.