Privacy Policy — Shlomicom

Last updated: 20 September 2026 Version: 1.0 Applies to: the website shlomicom.com and all its pages

The Hebrew version of this policy is the binding one. This English version is provided for convenience and is substantively equivalent; in case of conflict, the Hebrew version prevails.


1. Who we are

shlomicom.com is operated by Shlomo Yona, an individual, trading as "Shlomicom" ("we", "us"). Shlomicom is not a registered company — it is a trading name, not a separate legal entity.

The site operator is the owner and holder of the database under Israel's Protection of Privacy Law, 5741-1981, and the Data Controller under the EU General Data Protection Regulation (GDPR).

Privacy contact: hello@shlomicom.com

The site is operated by an individual who keeps no premises open to the public, which is why this policy carries no postal address. Email is the full contact channel — every message sent to the address above is answered within the period stated in §7.3. If you need a postal address for service of legal process, ask by email and it will be provided.


2. The short version

We collect only what you type into our contact form, and only so that we can get back to you. No advertising trackers. No profiling. No data sales. Ever.


3. What we collect, why, and on what legal basis

3.1 Information you give us — the contact form

FieldRequired?Why we need itGDPR legal basis
NameYesTo address you properly and know who we're speaking withArt. 6(1)(b) — steps at your request prior to entering a contract
Email addressYesOur primary channel for replyingArt. 6(1)(b)
PhoneNo — optionalOnly if you would rather we call you back instead of emailingArt. 6(1)(a) — consent
Message contentYesTo understand what you needArt. 6(1)(b)

Email is our reply channel. A phone number you give us is used only for a phone call from us in reply to your enquiry — not for SMS, not for WhatsApp or any other messaging app, and not for marketing. If you would rather not be called, simply leave the field empty; your enquiry is handled exactly the same way.

Under Israeli law: you provide this information voluntarily and are under no legal obligation to do so. If you do not provide the required fields, we cannot reply to your enquiry. This notice is given pursuant to Section 11 of the Protection of Privacy Law.

Please do not send us sensitive data through this form. It is not intended for information of special sensitivity — health, political opinions, ethnic origin, biometric data, financial details, national ID numbers or payment card data. If such data reaches us anyway, we will delete it.

3.2 Technical information generated automatically

Standard traffic data is recorded by our hosting provider: IP address, browser and operating system, page requested, and time of access.

  • Purpose: site security, abuse and attack prevention, and correct operation.
  • GDPR basis: Art. 6(1)(f) — our legitimate interest in securing the service.
  • Retention: per our hosting provider's policy, on the order of a few weeks.

3.3 What we do not do

  • ❌ No Google Analytics or any user-identifying analytics tool
  • ❌ No Meta, Google or other advertising pixels
  • ❌ No user profiling
  • ❌ No automated decision-making producing legal or similarly significant effects
  • ❌ No selling, renting or trading of your data — to anyone, under any circumstances
  • ❌ No marketing email to people who merely used the contact form

4. How we use your information — and how we don't

We may use your information to:

  1. Reply to your enquiry and conduct the correspondence that follows from it
  2. Prepare a quote or preliminary scope, if you asked for one
  3. Keep a record of the enquiry for the defence of our legal rights
  4. Comply with a legal obligation — including bookkeeping rules, if and when they come to apply to us

We will not use your information for any other purpose without first asking for your separate consent.

Marketing

Submitting the contact form is not a newsletter signup. We will not send you commercial messages within the meaning of Section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982, unless you explicitly opted in via a separate, non-pre-ticked checkbox. Even then, every message carries a free and immediate unsubscribe option.


5. How long we keep your information

DataRetention periodThen
Enquiry that did not lead to an engagement24 months from last contactDeleted
Enquiry that led to an engagementDuration of the engagement + 7 years from its endDeleted or anonymised
Technical logsPer hosting provider — a few weeksAuto-deleted
Data needed for actual or anticipated legal proceedingsUntil proceedings and the limitation period endDeleted

Why these periods, specifically:

  • 24 months for an enquiry that went nowhere. An enquiry that did not become an engagement creates no statutory retention duty for us at all. The period rests on legitimate interests alone (GDPR Art. 6(1)(f)): recognising a returning enquirer, preventing abuse of the form, and being able to show that an enquiry was received and answered. Two years is reasonable for those purposes; holding the data longer would be disproportionate, so we do not.
  • 7 years for an engagement — on limitation, not on bookkeeping. The limitation period for a civil claim in Israel is seven years, under section 5 of the Limitation Law, 5718-1958. For as long as a claim arising from an engagement can still be brought, we have a recognised legitimate interest in keeping the records needed to defend against it.
  • What changed, and why. An earlier version of this policy justified the seven-year period by "statutory bookkeeping rules". The site operator is an individual who is not a registered dealer, so no bookkeeping duty currently applies to him — and that justification has been removed. If such a duty ever arises, for example if the operator registers as a dealer and issues invoices, it will be added to this policy explicitly.

A deletion request from you shortens these periods — see Section 7.


6. Who we share it with

We do not sell data and do not pass it to advertisers. Your information is disclosed only to the following, and only to the extent necessary:

RecipientWhat they receivePurposeLocationRole
Vercel Inc.Form contents in transit + technical logsHosting and running the siteUSA / global edge networkProcessor
Google Workspace (Google Ireland / LLC)The enquiry email delivered to our mailboxOur business emailEU / USAProcessor
Resend (resend.com)Name, email, phone and messageDelivering the enquiry from the site to our mailboxOutside Israel — see the note below the tableProcessor
Competent authoritiesAs requiredLegal obligation, court order, or defence of our rightsIsrael—
Whoever takes over the activityIf the activity is transferred to another, or incorporated as a legal entityContinuity in handling enquiries—New controller; you will be notified in advance and may ask for erasure before the transfer

Processing at each of these providers is governed by a Data Processing Agreement (DPA) forming part of that provider's terms of service, obliging them to process your data only on our documented instructions and to keep it secure.

The precise geographic region in which Resend processes the data is set in our account with the provider and may change. We do not state it here rather than assert a figure that is not stable — we will disclose it to anyone who asks by email, within the period stated in §7.3.

International transfers

Some providers store data in the United States. Such transfers rely on the EU Standard Contractual Clauses (SCCs) and/or recognised adequacy mechanisms, in accordance with Chapter V of the GDPR and Israel's Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001.


7. Your rights — and how to exercise them

7.1 Under Israeli law

  • Access (Section 13) — to know what information about you we hold
  • Correction (Section 14) — to have inaccurate, incomplete or outdated data corrected
  • Deletion — to have your data erased once we no longer have a lawful basis to keep it

7.2 Under the GDPR (if you are in the EU/EEA)

RightArticleMeaning
Access15Obtain a copy of your data
Rectification16Correct inaccurate data
Erasure ("right to be forgotten")17Have your data deleted
Restriction18Freeze processing of your data
Portability20Receive your data in a structured, machine-readable format
Objection21Object to processing based on legitimate interests
Withdraw consent7(3)Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal

7.3 How to ask — and how long it takes

Email hello@shlomicom.com and tell us which right you are exercising.

  • Response within 30 days of receipt. For genuinely complex requests we will tell you within those 30 days if we need up to 60 additional days.
  • Free of charge. If a request is manifestly unfounded or excessive, particularly because it is repetitive, we will say so before charging anything.
  • Identity verification: we will ask only for reasonable verification, so that we don't hand your data to someone else. We will not demand a copy of your ID document.

7.4 Right to complain

  • Israel: the Privacy Protection Authority, Ministry of Justice.
  • EU/EEA: the supervisory authority in your country of residence.
  • You may also apply to a competent court.

We'd appreciate the chance to fix things first — most issues are resolved in a single email.


8. Cookies and tracking

This site uses no tracking cookies and no advertising cookies.

The site is essentially static. It sets no profiling cookies, runs no identifying analytics, and shares nothing with ad networks. That is why you will not see a cookie consent banner here — there is nothing to consent to.

If we ever add analytics, measurement, or any non-essential cookie, we will:

  1. Update this policy before switching it on
  2. Present a genuine consent banner — nothing pre-ticked, refusing as easy as accepting
  3. Load no tracking script before consent is given

Note: if your browser autofills your name or email, that's your browser, not us.


9. Security

We apply reasonable technical and organisational measures, including:

  • Encryption in transit — the entire site is served over HTTPS (TLS) only, with HSTS enforced
  • Minimisation — the fewest possible fields; the phone field is optional
  • Secret separation — keys and passwords live in environment variables, never in source code
  • Log hygiene — enquiry content and contact details are never written to server logs
  • Access control — access limited to those who need it to answer your enquiry
  • Form hardening — server-side validation, rate limiting and input length limits

No system is perfectly secure and we cannot guarantee absolute security. We undertake to act in accordance with the law and with Israel's Protection of Privacy (Data Security) Regulations, 5777-2017.

Breach notification

In the event of a serious security incident affecting your data, we will act as the law requires: notify the Israeli Privacy Protection Authority, and notify you without undue delay where the law so requires. Under the GDPR, notification to the supervisory authority within 72 hours of becoming aware of the breach.


10. Registration, DPO, and minors

10.1 Amendment 13 to the Protection of Privacy Law

Amendment 13, in force since August 2025, abolished the blanket database registration requirement and limited it to narrow categories. Our assessment is that a small enquiries database, kept by an individual, whose main purpose is not the transfer of data to others and which holds no data of special sensitivity, is not subject to registration and does not trigger an obligation to appoint a Data Protection Officer.

The substantive duties apply to us in full regardless: data minimisation, the notice required by section 11 of the Israeli law, the rights of access and correction, the security obligations under the Protection of Privacy Regulations (Data Security), 5777-2017, and the duty to report a serious security incident. Being an individual rather than a company reduces none of them.

⚠️ This is a professional assessment, not legal advice. Obligations under Amendment 13 depend on database scale, data type and controller identity. This classification will be re-examined if our collection grows.

10.2 Minors

This site and our services are aimed at businesses and adults. We do not target minors and do not knowingly collect data from children under 16. If you believe a minor has given us information, contact hello@shlomicom.com and we will delete it.


11. Links to other sites

As at the date of this policy, the site contains no outbound links to any third-party site or service. Every link on the site points to a page within shlomicom.com, plus a single mailto: link that opens your own mail client. Browsing the site sends no request to any external domain.

If an outbound link is added in future — for example to a published project or to one of our apps in an app store — following it will take you off our site, and this policy will not apply to that service; each operates under its own policy, for which we are not responsible. This section will be updated before any such link goes live.


12. Changes to this policy

We may update this policy. The updated version will appear on this page with a new "last updated" date.

A material change — new categories of data, a new purpose, or a new recipient — will be highlighted on the site before it takes effect. Where a change requires consent, we will ask for it afresh rather than rely on consent previously given.


13. Contact

Privacy requests and rightshello@shlomicom.com
General enquirieshello@shlomicom.com
Response timeWithin 30 days

The site is operated by an individual who keeps no premises open to the public. Email is the full contact channel — every message sent to the address above is answered within the period stated. If you need a postal address for service of legal process, ask by email and it will be provided.


14. Governing law

This policy is governed by the laws of the State of Israel. For data subjects in the EU/EEA, the mandatory provisions of the GDPR apply in addition.