Legal · Privacy

Privacy Policy

What we collect, why we hold it, how long it stays, and what you can ask us to do with it. Written to be read — not to be survived.

Last updated
27 July 2026
Version
1.0
Applies to
This website and the services offered through it
Reading time
About 8 minutes
Template — review required

Have a lawyer read this before you publish it

This is a carefully structured starting point, not a finished legal document. Privacy law changes with the country you operate in, the industry you serve and the exact data you touch. Before this page goes live under a company name, a qualified privacy lawyer has to go through every section, fill in the placeholders, and confirm that what it promises is what actually happens inside the business.

  • Fill in every placeholder — legal entity, registered address, contact points.
  • Check the legal bases and retention periods against your real processes.
  • Confirm the sub-processor list matches the vendors you genuinely use.
  • Verify local requirements — GDPR, the Israeli Privacy Protection Law, CCPA and any sector rules.

The short version

The full policy is below. If you only read one part, read this one.

  • We collect very little

    A name, an email, and whatever you choose to tell us. No hidden profiling, and nothing bought from a third party.

  • We never sell your data

    Not to advertisers, not to brokers, not to anyone. Data leaves our systems only to the providers that help us run them.

  • You stay in control

    Ask what we hold, correct it, take it with you, or have it deleted. One email, thirty days, no charge.

  • We treat it as ours to protect

    Encryption in transit and at rest, least-privilege access, separated environments, and monitoring that actually gets read.

01

Who we are

We are a software house. We design and build multi-tenant platforms, custom systems and API solutions — some of which run in production for clients today. This policy covers the personal data that reaches us through this site and the direct contact around it.

Where this policy says "we", it means the company named below — the entity that decides how and why your data is used on this site.

Our role here
Data controller for this website
Legal entity
Registered company details

Two hats, and it matters which one we are wearing

When we build and host a platform for a client, that client decides what data is collected and why — they are the controller, and we act only as their processor under a written agreement. In that situation the client's own privacy policy governs the end users, not this one. On this website we wear the other hat: here the decisions are ours, and so is the responsibility.

02

What we collect

Five categories, and nothing outside them. Each one exists because something on this site would not work without it.

  • Contact and project enquiries

    What you type into a contact form, or send us directly when you want to talk about a project.

    • Your name, email address, and phone number if you give one
    • Company name and role, where relevant to the enquiry
    • The content of your message and anything you attach to it
  • Chat conversations

    The support chat on this site keeps the conversation, so the next person who answers you does not start from zero.

    • The messages exchanged, with their timestamps
    • The language and the page the conversation started from
    • Contact details you volunteer inside the chat
  • Technical logs

    Standard server records, created automatically for every request. Nobody types these in — this is how a web server works.

    • IP address, browser and device type, operating system
    • Pages requested, response codes, timestamps and referrer
    • Security events — failed logins, rate-limit hits, blocked requests
  • Usage measurement

    Aggregated analytics that tell us which pages are useful and which ones quietly fail.

    • Page views, session length and navigation paths
    • Approximate location at city level, derived from the IP address
    • Device class and screen size, so the layout can be judged honestly
  • Client and supplier records

    If we end up working together, the paperwork a business relationship requires.

    • Contact details of the people we work with day to day
    • Contracts, invoices, payment records and correspondence
    • Access credentials for systems you ask us to work on — held under separate, stricter controls

What we do not collect

Stated plainly, so there is nothing left to infer.

  • No special-category data — health, biometrics, religion, political views or anything similar.
  • No data bought, scraped or enriched from third-party brokers.
  • No advertising profiles and no cross-site tracking.
  • No payment card numbers — billing runs through regulated providers who never pass us the full card.
03

Why we use it, and on what basis

Every use of personal data needs a lawful reason. Here is ours, purpose by purpose.

  • Answering your enquiry

    Data usedContact details and message content
    Legal basisSteps taken at your request before entering a contract
  • Delivering and supporting our services

    Data usedClient contact details, project and account records
    Legal basisPerformance of a contract
  • Keeping the site available and secure

    Data usedTechnical logs and security events
    Legal basisOur legitimate interest in protecting the service
  • Understanding how the site is used

    Data usedAggregated usage measurement
    Legal basisYour consent, where consent is required
  • Telling businesses what we build

    Data usedBusiness contact details
    Legal basisLegitimate interest, with an opt-out in every message
  • Meeting accounting and legal duties

    Data usedInvoices, contracts and tax records
    Legal basisLegal obligation
04

How long we keep it

Data that no longer has a job to do gets deleted. These are the periods we work to.

  • Enquiries and contact messages

    Counted from the last exchange, then deleted or anonymised

    24 months
  • Chat transcripts

    Longer only while a support matter is still open

    12 months
  • Server and security logs

    A rolling window — older entries rotate out automatically

    90 days
  • Usage measurement

    Aggregated, and not tied back to an identified person

    14 months
  • Contracts and billing records

    Required by tax and accounting law, not by us

    7 years
  • Opt-out records

    Held precisely so we never contact you again by mistake

    Kept indefinitely

One exception: if a legal claim, audit or investigation is open, the records it touches are held until the matter closes.

05

Who processes data on our behalf

We do not run every layer of the stack ourselves. These are the categories of provider that can touch personal data, and what each one actually sees.

  • Cloud hosting and databases

    The application and the data stored in it

    Processing regionEuropean Union
  • Email delivery

    Transactional and notification email

    Processing regionEU / United States
  • Usage analytics

    Aggregated measurement, no message content

    Processing regionEU / United States
  • Customer messaging

    Chat and messaging conversations

    Processing regionEU / United States
  • Billing and payments

    Invoices and payment records

    Processing regionEuropean Union
  • Error monitoring

    Diagnostic traces and crash reports

    Processing regionEuropean Union

What every one of them has to agree to

  • A written data processing agreement, signed before any data moves.
  • Processing strictly on our documented instructions, and nothing beyond them.
  • Confidentiality obligations that bind their staff personally.
  • Technical and organisational security measures, plus deletion or return when the engagement ends.

A current list naming each provider is available on request — write to the privacy address at the bottom of this page.

06

International transfers

Our primary infrastructure sits in the European Union. Some of the providers above operate globally, which means data may be processed outside your own country. We do not treat that as a technicality.

The safeguards we rely on

  • EU Standard Contractual Clauses with every provider outside the EEA.
  • Adequacy decisions, where the destination country has one.
  • Encryption in transit and at rest, so a transfer is never readable in the middle.
  • Data minimisation — a provider receives the least it can function on.

You can ask us which safeguard applies to a specific transfer, and we will tell you.

07

Your rights

These are yours by law, not by our goodwill. Using them costs nothing and changes nothing about how we treat you.

  • Access

    Get a copy of the personal data we hold about you, and a plain explanation of what we do with it.

  • Correction

    Have anything inaccurate fixed, and anything incomplete filled in.

  • Deletion

    Have data erased once we no longer have a lawful reason to keep it.

  • Restriction

    Freeze processing while a dispute about accuracy or grounds is being resolved.

  • Portability

    Receive the data you gave us in a structured, machine-readable format.

  • Objection

    Object to any processing we base on legitimate interest, including marketing.

  • Withdraw consent

    Where processing rests on consent, withdraw it at any time — future use stops immediately.

  • Complain

    Take the matter to your data protection authority, with or without talking to us first.

How to use them

Write to the privacy address at the bottom of this page and say what you want. We will confirm who you are — that step protects you, not us — and answer within 30 days. If a request is genuinely complex we may need longer, and we will tell you why before the 30 days are up.

No charge, no conditions

We do not charge for handling a request and we do not require a reason. The only exception is a request that is clearly excessive or repeated without purpose, and even then we will explain the decision rather than ignore it.

If your data lives inside a client's platform

When we host a system for a client, that client decides what happens to the data in it. Send your request to them. If it reaches us instead, we will forward it, tell you that we did, and help them answer it.

08

Cookies and similar technologies

Four categories, one of which we simply do not use.

  • Strictly necessary

    Always on

    Session handling, security, load balancing, and remembering your language and theme. The site cannot function without them.

  • Preferences

    Set only after you choose

    Small choices you make — layout, language, whether a panel is open — so the site behaves the same on your next visit.

  • Measurement

    Only with consent, where required

    Aggregated analytics about which pages get used and where people give up.

  • Advertising

    Not used

    We run no advertising cookies and no cross-site tracking pixels on this site. There is nothing here to opt out of.

Your control

Every browser lets you see, block and delete cookies, and you can change your mind about the optional categories at any time from the consent panel. Blocking the strictly necessary ones will break parts of the site — that is a limitation, not a punishment.

Browser opt-out signals

If your browser sends a recognised opt-out signal, we treat it as a withdrawal of consent for the optional categories, without asking you to click anything else.

09

How we protect it

Security is the part of this policy we can actually engineer, so we do.

  • TLS for everything in transit, and encryption at rest for stored data.
  • Least-privilege access, multi-factor authentication and named accounts — no shared logins.
  • Production, staging and development kept apart, with real data never copied downstream.
  • Logging and monitoring that are genuinely reviewed, with alerting on the events that matter.
  • Dependencies patched on a schedule, and vendors re-checked rather than trusted forever.

If something goes wrong

Nobody can promise a breach will never happen. We can promise how we will behave if it does: contain it, notify the supervisory authority within 72 hours where the law requires it, and tell the people affected directly and without spin.

10

Children

This is a business-to-business site. It is not designed for, marketed to, or intended to be used by children, and we do not knowingly collect data from anyone under 16.

If you believe a child has sent us personal data, write to us and we will delete it — no forms, no process, just tell us.

11

Changes to this policy

This policy will change as the business does. Every change updates the date at the top of the page, and that date always reflects the version you are reading.

When a change materially affects how your data is used, we will not rely on you noticing a date. We will say so directly — by email where we have an address, and prominently on the site where we do not. Earlier versions are kept and available on request.

12

Contact us about privacy

One address, read by a person. Questions, requests and complaints all go to the same place.

Privacy enquiries
[email protected]
General contact
[email protected]
Registered addressTo complete
To be completed before publication
Data protection officerTo complete
To be appointed, or confirmed as not required
Response time
Within 30 days

If we do not resolve it

You can complain to the data protection authority where you live or work, and you can do it without going through us first. We would rather you came to us — but the choice is yours, and using it will never count against you.

Beyond the fine print

Prefer to talk to a person?

Privacy questions, a security review, or a project you want to scope — the same conversation window handles all of it, and a human answers.

No form to fill in. The chat opens right here.