Skip to content
alma studio

Privacy policy

Last updated 30 August 2026In effect since 30 August 2026

In one line. We collect a name and a phone number from anyone who wants us to get back to them. It goes to our inbox. We do not sell it to anyone and we delete it the moment you ask.

This document explains exactly what information is collected on the alma studio site, why it is collected, where it actually goes, how long it is kept and what you can ask for at any moment. It is written under the Protection of Privacy Law 1981 as amended by Amendment 13, which took effect on 14 August 2025, and follows the opinion of the Privacy Protection Authority on consent from February 2026. We wrote it to be understood, not to be long. Alongside it sit the terms and the accessibility statement.

1. Who is responsible for the information

The party in control of the information is alma studio, based in Eilat. Access to the information you give is limited to whoever needs it in order to handle your enquiry, and no further.

For anything to do with privacy. Phone and WhatsApp 050-294-0127. Email shaharlibshin@gmail.com. No special wording is needed and you do not have to explain why.

We have not appointed a privacy protection officer. The duty to appoint one under section 17B1 of the law applies to public bodies, to anyone whose main business is trading in information, and to anyone carrying out systematic monitoring on a significant scale. We do none of those. Privacy requests are handled here directly, with no call centre and no queue.

Our database does not require registration. Amendment 13 removed almost all of the registration duty in the private sector and left it mainly on those who trade in information. We do not trade in information.

2. What information is collected and from whom

We collect very little. This is the full list and it holds nothing that is not written here.

What is collectedFrom whereIs it requiredWhat happens if you do not give it
Name and phoneThe contact form on the siteNo legal duty. You give them voluntarily and with consentWe will not be able to get back to you. You can always call or write on WhatsApp instead
The free text of your messageThe same form. An optional fieldNot requiredWe will get back to you without knowing in advance what it is about
A site address or business nameThe AI visibility check formNot requiredWe will not be able to run the check
The consent tick and the time it was tickedRecorded automatically when the form is sentIt is a condition for sendingThe form will not be sent. That is what the law requires and not our choice
The marketing consent tick. Separate and optionalThe same formNever requiredYou will not get updates from us. It does not affect how your enquiry is handled
Your display preferencesSaved in your browser onlyNoYou will have to choose again on every visit

One request. The message field is free text, so please do not write sensitive information in it. Health conditions, ID numbers, card details or information about someone else. We do not need it in order to get back to you, and we would rather not hold it.

3. Where the information actually goes

This is the part most policies on the market keep vague. Here is the exact route an enquiry takes from the moment you press send.

The form is sent to the site server. From there an email alert goes to a business inbox of ours. The enquiry is kept in that inbox. As of the date this document was updated, the site runs in email only mode and does not store enquiries in a separate database.

If we switch on a database for managing enquiries in the future, we will update this document before we switch it on and not after. We update this document so that it describes reality, not so that it covers every theoretical possibility in advance.

A WhatsApp message or a phone call does not pass through the site at all. It reaches our device directly and is subject to the policy of the service provider you use.

4. What the information is used for

The law requires us to process information only for the purpose it was collected for. These are the purposes and there are no others.

The purposeWhich information it usesThe basis for processing
Getting back to you and handling your enquiryName, phone and the content of the messageThe consent you ticked in the form
Running the AI visibility check and giving you the resultThe site address and phoneThe consent you ticked in the form
Recording that consent was given and whenThe consent tick and its timeA duty under the law. It is the proof that we acted lawfully
Sending professional updatesName and phone or emailA separate and explicit consent that can be withdrawn at any moment
Managing the business relationship if we work togetherContact details and what was agreedThe engagement itself and bookkeeping duties
Understanding what works on the site and what to improveGeneral usage data that does not identify anyoneOnly if you approved measurement cookies

What we will never do. We will not sell, rent or pass your details to anyone else for their own use. We will not use them for a purpose outside this list. We will not buy lead lists from others and we will not harvest contact details from websites automatically. The last two break the law and are not merely bad manners.

5. Cookies and browser storage

On your first visit the site shows a notice with a real choice. Until you choose, no measurement tool is loaded. Carrying on browsing without choosing is not consent and we do not treat it as consent.

This is the full list of what is stored in your browser and what each item does.

NameTypeWhat it is forHow long
as-consent-v1Local storage. NecessaryRemembers your choice about cookies so we do not ask on every pageUntil you clear the site data in your browser
as-a11y-v1Local storage. NecessaryRemembers the preferences you chose in the accessibility menuUntil you clear the site data in your browser
Google measurement cookiesThird party. With consent onlyCounting visitors and understanding usage paths. Loaded only after approvalPer the provider policy. If you declined they are not loaded at all
as-adminServer cookie. NecessaryKeeps the connection to the admin panel. Created only on our side, never for visitorsUntil logout

You can change your choice at any moment. Clearing the site data in your browser brings the notice back and you can choose again. As of the date this document was updated no measurement id is configured on the site at all, so in practice no measurement cookies are loaded even for someone who approved them.

6. Who else sees the information. Our sub-processors

The law requires us to say who the information is given to and not to settle for a general phrase. These are all the parties the information passes through. Each one gets only what it needs in order to work and may not use it for its own purposes.

The providerWhat it doesWhat information reaches itLocation
VercelHosts the site and serves it to visitorsThe enquiry passes through it on the way to us and is not stored thereUnited States and Europe
ResendSends the email alert to usThe content of the enquiry including name and phoneUnited States
Google WorkspaceThe inbox where the enquiry is actually keptThe content of the enquiryUnited States and Europe
SupabaseDatabase. Technically ready but not active todayReceives no information at presentEurope
Google Tag ManagerLoads measurement tools. Only after cookie approvalGeneral usage data that does not identify anyoneUnited States
Meta / WhatsAppThe chat channel. Only if you chose to write to us thereThe message you wrote and your phone numberPer the provider policy

The AI visibility check is carried out by us by hand. We do not pass your details automatically to a language model provider. If that changes we will update this table in advance.

7. Transferring information outside Israel

Some of the providers in the list above run servers outside Israel, mainly in the United States and the European Union. That means the information may be stored or processed there.

That kind of transfer is governed by the Protection of Privacy Regulations on transferring information to databases outside the borders of the state. The default in those regulations is a prohibition, and a transfer happens only where one of the alternatives they set out applies. Our basis is your explicit consent to giving the details for the purpose they were given for, together with the contractual undertakings the providers give us to protect the information and not use it for their own purposes.

On top of any such alternative, the regulations require a written undertaking from the recipient to take sufficient measures to protect privacy and not to pass the information on. We are working with our providers to obtain and file those undertakings. If you want to know where things stand with a particular provider, ask and we will tell you exactly.

The European Union recognises Israel as a country with an adequate level of protection. That recognition was renewed in January 2024. It means that transferring information from Europe to Israel does not require any further mechanism.

8. How long we keep it

The law requires us to check once a year that we hold no information that is no longer needed. We do that and delete accordingly.

Type of informationHow longAnd then
An enquiry that did not turn into an engagementUp to two years from the enquiryDeleted. Sooner if you asked
An enquiry that led to working togetherFor as long as the business relationship lasts and subject to bookkeeping dutiesWhatever the law does not require us to keep is deleted
The consent recordAs long as the information it refers to is still held by usDeleted together with it
Details of a marketing list subscriberUntil a removal requestDeleted as soon as the removal is made
Accounting documentsFor the period the law requiresKept as required. That is a duty and not a choice

Asked us to delete sooner? We will delete right away and will not ask why. The only thing we will keep is what the law requires us to keep, and we will tell you exactly what that is.

9. How the information is secured

We classified the database under the Data Security Regulations and matched the measures to that classification. These are the measures in practice.

  • The site is served over an encrypted connection only. All traffic between your browser and the server is encrypted
  • The admin panel is protected by a password and a secure session cookie. Access to it is limited to a small set of permissions
  • Access to the inbox where enquiries are kept is protected by two step verification and given only to whoever needs it
  • We collect little information on purpose. What is not collected cannot leak
  • Input fields on the site are limited in length and handled as text only, to prevent code injection
  • Provider access keys are kept as encrypted environment variables and are not in the site code
  • We log every event that raises a concern of unauthorised access or of harm to the information. The regulations require that

An honest word. No system is completely immune, and anyone promising you absolute security is not being accurate. If a security event touching your information happens, we will tell you about it and act according to the reporting duties the law places on us. We are not promising here a reporting duty that does not apply to us, because a promise like that is worth less than nothing.

10. Your rights and how to use them

These are rights the law gives you. Honouring them is not a favour we do you.

  • To know whether we hold information about you and to review it. We will reply within thirty days of receiving the request, as the regulations set out
  • To ask us to correct information that is incorrect, incomplete, unclear or out of date. Thirty days here too. If we correct it and had already passed the information to someone else, we will tell them about the correction as well
  • To ask us to delete information that is no longer needed for the purpose it was given for
  • To withdraw a consent you gave. Withdrawing marketing consent takes effect immediately
  • To get an explanation for a refusal. If we refuse a request we will say so in writing and explain why. No answer counts as a refusal, and that can be challenged too
  • To approach the Privacy Protection Authority at the Ministry of Justice if you think we did not handle things properly. Contacting us first is not a precondition

To use a right, just tell us what you want. WhatsApp or phone 050-294-0127, or email shaharlibshin@gmail.com. There is no form and no fee. We may ask to verify that you really are the person the information is about. That is meant to protect you and not to make it harder. We log every privacy request and the date it was answered.

11. Marketing messages and updates

Marketing consent is a separate tick box in the form. It is not ticked in advance and it is not a condition for getting an answer. That is deliberate.

Every marketing message we send will include three things. A clear mark that it is an advertisement. Our name and how to reach us. And a simple, clear way to remove yourself.

Removal takes effect immediately and without questions. You can reply to the email with the word remove, you can write on WhatsApp, and you can call. After removal you will get no more marketing messages from us.

Before we make an unsolicited marketing approach to a phone number, we check that it is not listed in the register for restricting marketing approaches run by the Consumer Protection Authority.

12. Client information that we handle

This section is meant for our clients and not for visitors to the site. When we build a site or run a system for a client, we sometimes access personal information about that client's own customers. Leads, mailing lists or data in the system.

In that situation we are a holder under the law and the information stays the client's. We process it only under their instructions and only for the service. We do not use it for our own purposes, we do not copy it and we do not keep copies beyond what is needed.

When the engagement ends we delete or return the information as the client chooses, and we revoke our own access permissions.

For a client who wants it, we sign a data processing addendum that sets all of this out in writing. For a client with users in the European Union we will add the parts the European regulation requires. Just ask.

13. Visitors from outside Israel

The site has an English version, so visitors from outside Israel reach it too.

alma studio is an Israeli business operating in Israel, and it does not direct marketing activity at the European or the American market. Even so, we already meet the main principles the European regulation requires. Full transparency about what is collected and why. Active consent before any measurement tool loads. Collecting as little as possible. Rights to review, correct and delete. And deletion within a set time.

A visitor from the European Union or from the United Kingdom who wants to use a right is welcome to contact us through exactly the same channels and will get exactly the same treatment.

14. Minors

The site is meant for business owners and managers. It does not address minors and does not offer them a service. We do not knowingly collect information about minors. If it turns out that such information was given to us, we will delete it immediately. A parent or guardian who believes information about their child was given to us is welcome to contact us and we will handle it the same day.

15. Automated decisions and profiling

We do not make automated decisions about you and we do not build profiles. There is no automatic lead ranking here, no scoring and no system that decides anything without a person. Every enquiry is read by a person.

16. Changes to this policy

This policy may be updated when something in reality changes. Switching on a database, adding a new provider, or a change in the law.

The current version will always appear on this page with the update date at the top. A material change will be marked at the top of the page for at least thirty days. We update the document before the change actually happens and not after it.

This document was updated on 30 August 2026 and replaces an earlier version of 14 August 2026. The main changes in this version. An exact description of the route the information actually takes, a full cookie table, a named list of providers, a retention timetable, and a correction to the storage description that did not reflect the situation on the ground.

Back to top