Privacy policy
In one line. We collect a name and a phone number from anyone who wants us to get back to them. It goes to our inbox. We do not sell it to anyone and we delete it the moment you ask.
This document explains exactly what information is collected on the alma studio site, why it is collected, where it actually goes, how long it is kept and what you can ask for at any moment. It is written under the Protection of Privacy Law 1981 as amended by Amendment 13, which took effect on 14 August 2025, and follows the opinion of the Privacy Protection Authority on consent from February 2026. We wrote it to be understood, not to be long. Alongside it sit the terms and the accessibility statement.
1. Who is responsible for the information
The party in control of the information is alma studio, based in Eilat. Access to the information you give is limited to whoever needs it in order to handle your enquiry, and no further.
For anything to do with privacy. Phone and WhatsApp 050-294-0127. Email shaharlibshin@gmail.com. No special wording is needed and you do not have to explain why.
We have not appointed a privacy protection officer. The duty to appoint one under section 17B1 of the law applies to public bodies, to anyone whose main business is trading in information, and to anyone carrying out systematic monitoring on a significant scale. We do none of those. Privacy requests are handled here directly, with no call centre and no queue.
Our database does not require registration. Amendment 13 removed almost all of the registration duty in the private sector and left it mainly on those who trade in information. We do not trade in information.
2. What information is collected and from whom
We collect very little. This is the full list and it holds nothing that is not written here.
| What is collected | From where | Is it required | What happens if you do not give it |
|---|---|---|---|
| Name and phone | The contact form on the site | No legal duty. You give them voluntarily and with consent | We will not be able to get back to you. You can always call or write on WhatsApp instead |
| The free text of your message | The same form. An optional field | Not required | We will get back to you without knowing in advance what it is about |
| A site address or business name | The AI visibility check form | Not required | We will not be able to run the check |
| The consent tick and the time it was ticked | Recorded automatically when the form is sent | It is a condition for sending | The form will not be sent. That is what the law requires and not our choice |
| The marketing consent tick. Separate and optional | The same form | Never required | You will not get updates from us. It does not affect how your enquiry is handled |
| Your display preferences | Saved in your browser only | No | You will have to choose again on every visit |
One request. The message field is free text, so please do not write sensitive information in it. Health conditions, ID numbers, card details or information about someone else. We do not need it in order to get back to you, and we would rather not hold it.
3. Where the information actually goes
This is the part most policies on the market keep vague. Here is the exact route an enquiry takes from the moment you press send.
The form is sent to the site server. From there an email alert goes to a business inbox of ours. The enquiry is kept in that inbox. As of the date this document was updated, the site runs in email only mode and does not store enquiries in a separate database.
If we switch on a database for managing enquiries in the future, we will update this document before we switch it on and not after. We update this document so that it describes reality, not so that it covers every theoretical possibility in advance.
A WhatsApp message or a phone call does not pass through the site at all. It reaches our device directly and is subject to the policy of the service provider you use.
4. What the information is used for
The law requires us to process information only for the purpose it was collected for. These are the purposes and there are no others.
| The purpose | Which information it uses | The basis for processing |
|---|---|---|
| Getting back to you and handling your enquiry | Name, phone and the content of the message | The consent you ticked in the form |
| Running the AI visibility check and giving you the result | The site address and phone | The consent you ticked in the form |
| Recording that consent was given and when | The consent tick and its time | A duty under the law. It is the proof that we acted lawfully |
| Sending professional updates | Name and phone or email | A separate and explicit consent that can be withdrawn at any moment |
| Managing the business relationship if we work together | Contact details and what was agreed | The engagement itself and bookkeeping duties |
| Understanding what works on the site and what to improve | General usage data that does not identify anyone | Only if you approved measurement cookies |
What we will never do. We will not sell, rent or pass your details to anyone else for their own use. We will not use them for a purpose outside this list. We will not buy lead lists from others and we will not harvest contact details from websites automatically. The last two break the law and are not merely bad manners.
6. Who else sees the information. Our sub-processors
The law requires us to say who the information is given to and not to settle for a general phrase. These are all the parties the information passes through. Each one gets only what it needs in order to work and may not use it for its own purposes.
| The provider | What it does | What information reaches it | Location |
|---|---|---|---|
| Vercel | Hosts the site and serves it to visitors | The enquiry passes through it on the way to us and is not stored there | United States and Europe |
| Resend | Sends the email alert to us | The content of the enquiry including name and phone | United States |
| Google Workspace | The inbox where the enquiry is actually kept | The content of the enquiry | United States and Europe |
| Supabase | Database. Technically ready but not active today | Receives no information at present | Europe |
| Google Tag Manager | Loads measurement tools. Only after cookie approval | General usage data that does not identify anyone | United States |
| Meta / WhatsApp | The chat channel. Only if you chose to write to us there | The message you wrote and your phone number | Per the provider policy |
The AI visibility check is carried out by us by hand. We do not pass your details automatically to a language model provider. If that changes we will update this table in advance.
7. Transferring information outside Israel
Some of the providers in the list above run servers outside Israel, mainly in the United States and the European Union. That means the information may be stored or processed there.
That kind of transfer is governed by the Protection of Privacy Regulations on transferring information to databases outside the borders of the state. The default in those regulations is a prohibition, and a transfer happens only where one of the alternatives they set out applies. Our basis is your explicit consent to giving the details for the purpose they were given for, together with the contractual undertakings the providers give us to protect the information and not use it for their own purposes.
On top of any such alternative, the regulations require a written undertaking from the recipient to take sufficient measures to protect privacy and not to pass the information on. We are working with our providers to obtain and file those undertakings. If you want to know where things stand with a particular provider, ask and we will tell you exactly.
The European Union recognises Israel as a country with an adequate level of protection. That recognition was renewed in January 2024. It means that transferring information from Europe to Israel does not require any further mechanism.
8. How long we keep it
The law requires us to check once a year that we hold no information that is no longer needed. We do that and delete accordingly.
| Type of information | How long | And then |
|---|---|---|
| An enquiry that did not turn into an engagement | Up to two years from the enquiry | Deleted. Sooner if you asked |
| An enquiry that led to working together | For as long as the business relationship lasts and subject to bookkeeping duties | Whatever the law does not require us to keep is deleted |
| The consent record | As long as the information it refers to is still held by us | Deleted together with it |
| Details of a marketing list subscriber | Until a removal request | Deleted as soon as the removal is made |
| Accounting documents | For the period the law requires | Kept as required. That is a duty and not a choice |
Asked us to delete sooner? We will delete right away and will not ask why. The only thing we will keep is what the law requires us to keep, and we will tell you exactly what that is.
9. How the information is secured
We classified the database under the Data Security Regulations and matched the measures to that classification. These are the measures in practice.
- The site is served over an encrypted connection only. All traffic between your browser and the server is encrypted
- The admin panel is protected by a password and a secure session cookie. Access to it is limited to a small set of permissions
- Access to the inbox where enquiries are kept is protected by two step verification and given only to whoever needs it
- We collect little information on purpose. What is not collected cannot leak
- Input fields on the site are limited in length and handled as text only, to prevent code injection
- Provider access keys are kept as encrypted environment variables and are not in the site code
- We log every event that raises a concern of unauthorised access or of harm to the information. The regulations require that
An honest word. No system is completely immune, and anyone promising you absolute security is not being accurate. If a security event touching your information happens, we will tell you about it and act according to the reporting duties the law places on us. We are not promising here a reporting duty that does not apply to us, because a promise like that is worth less than nothing.
10. Your rights and how to use them
These are rights the law gives you. Honouring them is not a favour we do you.
- To know whether we hold information about you and to review it. We will reply within thirty days of receiving the request, as the regulations set out
- To ask us to correct information that is incorrect, incomplete, unclear or out of date. Thirty days here too. If we correct it and had already passed the information to someone else, we will tell them about the correction as well
- To ask us to delete information that is no longer needed for the purpose it was given for
- To withdraw a consent you gave. Withdrawing marketing consent takes effect immediately
- To get an explanation for a refusal. If we refuse a request we will say so in writing and explain why. No answer counts as a refusal, and that can be challenged too
- To approach the Privacy Protection Authority at the Ministry of Justice if you think we did not handle things properly. Contacting us first is not a precondition
To use a right, just tell us what you want. WhatsApp or phone 050-294-0127, or email shaharlibshin@gmail.com. There is no form and no fee. We may ask to verify that you really are the person the information is about. That is meant to protect you and not to make it harder. We log every privacy request and the date it was answered.
11. Marketing messages and updates
Marketing consent is a separate tick box in the form. It is not ticked in advance and it is not a condition for getting an answer. That is deliberate.
Every marketing message we send will include three things. A clear mark that it is an advertisement. Our name and how to reach us. And a simple, clear way to remove yourself.
Removal takes effect immediately and without questions. You can reply to the email with the word remove, you can write on WhatsApp, and you can call. After removal you will get no more marketing messages from us.
Before we make an unsolicited marketing approach to a phone number, we check that it is not listed in the register for restricting marketing approaches run by the Consumer Protection Authority.
12. Client information that we handle
This section is meant for our clients and not for visitors to the site. When we build a site or run a system for a client, we sometimes access personal information about that client's own customers. Leads, mailing lists or data in the system.
In that situation we are a holder under the law and the information stays the client's. We process it only under their instructions and only for the service. We do not use it for our own purposes, we do not copy it and we do not keep copies beyond what is needed.
When the engagement ends we delete or return the information as the client chooses, and we revoke our own access permissions.
For a client who wants it, we sign a data processing addendum that sets all of this out in writing. For a client with users in the European Union we will add the parts the European regulation requires. Just ask.
13. Visitors from outside Israel
The site has an English version, so visitors from outside Israel reach it too.
alma studio is an Israeli business operating in Israel, and it does not direct marketing activity at the European or the American market. Even so, we already meet the main principles the European regulation requires. Full transparency about what is collected and why. Active consent before any measurement tool loads. Collecting as little as possible. Rights to review, correct and delete. And deletion within a set time.
A visitor from the European Union or from the United Kingdom who wants to use a right is welcome to contact us through exactly the same channels and will get exactly the same treatment.
14. Minors
The site is meant for business owners and managers. It does not address minors and does not offer them a service. We do not knowingly collect information about minors. If it turns out that such information was given to us, we will delete it immediately. A parent or guardian who believes information about their child was given to us is welcome to contact us and we will handle it the same day.
15. Automated decisions and profiling
We do not make automated decisions about you and we do not build profiles. There is no automatic lead ranking here, no scoring and no system that decides anything without a person. Every enquiry is read by a person.
16. Changes to this policy
This policy may be updated when something in reality changes. Switching on a database, adding a new provider, or a change in the law.
The current version will always appear on this page with the update date at the top. A material change will be marked at the top of the page for at least thirty days. We update the document before the change actually happens and not after it.
This document was updated on 30 August 2026 and replaces an earlier version of 14 August 2026. The main changes in this version. An exact description of the route the information actually takes, a full cookie table, a named list of providers, a retention timetable, and a correction to the storage description that did not reflect the situation on the ground.