Skip to content
Legal

Privacy Policy

OctoMonic (Tom Levi), Licensed Dealer (עוסק מורשה) no. 302148911
Version 2.0 · Effective: 20 August 2026

The Hebrew version is the binding version. This English translation is complete, carries
identical numbering, and confers the same rights.

This Policy is drafted to the Protection of Privacy Law, 5741-1981, including Amendment No. 13, in force since 14 August 2025; the Protection of Privacy (Data Security) Regulations, 5777-2017; the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001; and the Communications (Telecommunications and Broadcasts) Law, 5742-1982.

This Policy forms an integral part of the Website Terms. Section 14 of the Terms contains a self-contained, complete version of its substance; in any conflict, the text more favourable to the data subject applies.

1. Who we are — the controller

Pursuant to section 11(2a) of the Law, the controller of personal data collected on this Website is:

NameOctoMonic (Tom Levi)
StatusLicensed dealer (עוסק מורשה) — a sole proprietor, not a company
Business number302148911
AddressAminadav 2, Tel Aviv-Yafo, Israel
Telephone054-502-5008 · +972-54-502-5008
Email for privacy requeststom@octomonic.com

OctoMonic is not required to appoint a Data Protection Officer under section 17B1 of the Law, as it falls within none of the four categories listed there. Privacy requests are handled directly by Tom Levi.

2. Providing data is voluntary — and what happens if you don't

Pursuant to section 11(1) of the Law:

You are under no legal obligation to provide us with any personal data. Providing it depends entirely on your will and consent.

The consequence of not consenting:

  • If you do not provide a name, email and phone number in the contact form — we cannot get back to you.
  • If you do not provide details in the booking form — we cannot schedule a session.
  • If you do not provide billing and identifying details on the payment page — we cannot process the payment, cannot issue the invoice the law requires, and cannot supply the service.
  • If you do not consent to non-essential cookies — the Website will function fully, but we cannot measure usage or tailor content.
  • If you do not consent to marketing — we will not send you marketing. This does not affect your ability to purchase.

3. What data we collect

3.1. Data you provide

  • Contact and booking forms: full name, email address, telephone number, business name, role, and the free-text content of your message.
  • Order and payment: full name, identity or company/business number, billing address, email, telephone, the declared buyer type (private individual / business) and the declaration given, the service purchased and the amount. The full card number is supplied directly to the payment provider, is not stored on OctoMonic's servers and is not disclosed to us. We do not operate a card-vault (stored-card) facility with the payment provider.
  • During service delivery: business, technical and operational information you provide for the specification or development work, including process descriptions, sample data and system access credentials. Please do not provide sensitive data that is not necessary for the service.
  • Correspondence: the content of emails, WhatsApp messages and other correspondence you initiate with us.

3.2. Data collected automatically

  • IP address, browser type and operating system, device type, interface language.
  • Pages viewed, entry and exit times, referral source.
  • Online identifiers stored in cookies and similar local storage.
  • Terms-acceptance record: timestamp (server clock, Israel local time and UTC), IP address, user agent, the version of the Terms and of the Privacy Policy accepted, interface language and the declared buyer type.

Following Amendment 13, an online identifier and an IP address are "personal data" where a person can be identified by them with reasonable effort, and this Policy applies to them.

3.3. What we do not collect

We do not knowingly collect data of special sensitivity — medical, genetic, biometric, ethnic origin, political opinions or religious beliefs, criminal record, or precise location data. We do not knowingly collect data about persons under 18.

4. Purposes of use

Pursuant to sections 8(b) and 11(2) of the Law, data is used solely for:

  • 1. Responding to enquiries and scheduling calls and meetings.
  • 2. Preparing quotations and entering into transactions.
  • 3. Delivering the services purchased — consulting, specification, development, setup, workshops and maintenance.
  • 4. Processing payment and issuing invoices and receipts, and meeting reporting duties to the Israel Tax Authority.
  • 5. Customer relationship management and post-delivery support.
  • 6. Securing the data and the Website, detecting faults, and preventing fraud and misuse.
  • 7. Improving the Website and services on the basis of aggregate usage data.
  • 8. Sending marketing communications — only to those who have given express, separate, prior consent.
  • 9. Complying with legal obligations, responding to requests from a competent authority, and defending our legal rights in legal or pre-litigation proceedings.

We make no other use of the data. We do not sell personal data, do not rent it, and do not transfer it to third parties for their own marketing purposes.

5. Legal basis for processing

  • Consent — for most collection and processing; providing data in our forms and accepting the Terms on the payment page constitutes informed, express consent. Consent to uses not directly derived from the service — in particular direct marketing — is collected as separate, active opt-in.
  • Performance of the transaction — processing necessary to supply the service ordered.
  • Legal obligation — issuing invoices and retaining accounting records under the VAT Law and the Income Tax (Bookkeeping) Instructions.
  • Legitimate protected interest — data security, fraud prevention and legal defence.

6. Who we share data with

Pursuant to section 11(3) of the Law:

RecipientWhat is transferredPurposeProcessing location
Grow (Meitav) / Green Invoice (Morning)Name, ID or company number, email, phone, billing address, transaction details and amountPayment processing, issuing tax invoice-receipts, tax reportingIsrael
Card companies and the acquirerCharge detailsExecuting the charge, managing credits and cancellationsIsrael
Google LLC / Google Workspace (Gmail, Calendar, Drive, Meet)Correspondence content, contact details, working documents, meeting schedulingEmail, calendar, file storage, video callsUSA and EU
Google Firebase / Firebase HostingSubmitted form content, technical usage dataWebsite hosting and enquiry storageUSA and EU
Vercel Inc.Request data and technical logs, IP addressesHosting and running web applicationsUSA
Meta Platforms (WhatsApp)Name, phone number and message contentOngoing customer communication and schedulingUSA and Ireland
Google Analytics (where enabled, subject to your cookie consent)Cookie identifier, truncated IP address, browsing dataWebsite usage measurement onlyUSA and EU
Meta Platforms Ireland (advertising pixel, where enabled and subject to your cookie consent)Cookie identifier, ad click identifier, IP address, browsing and booking-request eventsMeasuring advertising effectiveness and building advertising audiencesUSA and Ireland
Email delivery provider (for subscribers)Name and email addressSending marketing to those who consentedUSA / EU
Accountant / bookkeeper and professional advisersAccounting documents and transaction detailsBookkeeping, tax filings, adviceIsrael
Competent authoritiesAs requiredLegal obligation, court order or lawful demandIsrael

An up-to-date list of processors, and the list of each provider's material sub-processors so far as it is available from that provider, will be supplied on request at tom@octomonic.com.

7. Transfers of data outside Israel

7.1. Some of our service providers store and process data on servers located outside Israel — principally in the United States, Ireland and the European Union, as set out in section 6.

7.2. Transfers are made under the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001, and rely, in this order, on:

  • Regulation 2(4) — the primary basis: a contractual undertaking by the recipient to comply, mutatis mutandis, with the conditions for holding and using data applicable to a database in Israel (data processing agreements);
  • Regulation 2(8) — for EU Member States, states whose level of protection is not lower than that required in Israel;
  • Regulation 2(1) — your consent to the transfer, as a secondary and supplementary basis only. Withdrawal of consent does not remove the Regulation 2(4) basis.

7.3. Where a processor makes data processing terms (a DPA) available, we rely on the terms that provider offers — typically containing an undertaking to take sufficient security measures to protect data subjects' privacy, to restrict use of the data to supplying the service, and to engage sub-processors only under equivalent undertakings. We work to obtain and file, from each recipient that offers one, a written undertaking under Regulation 3 of those Regulations. We make no representation that such an undertaking has been obtained from every recipient. Each provider's list of material sub-processors is available from that provider and will be supplied on request.

7.4. If you do not wish your data to be transferred outside Israel, contact us — but note that without the ability to use these infrastructure providers we will in most cases be unable to supply the service.

8. Retention periods

DataRetentionBasis
Invoices, receipts and accounting records7 years from the end of the tax year, or 6 years from the filing of the return for that year — whichever is laterSection 25 of the Income Tax (Bookkeeping) Instructions, 5733-1973
Agreements, orders and contractual correspondence7 years from the end of the engagementLimitation period and legal-defence need
Work product and project documents3 years from the end of the engagement, unless earlier deletion is requestedOperational need and post-delivery support
Enquiries that did not become transactions (leads)24 months from last contactCustomer relationship management
Marketing listUntil consent is withdrawn; thereafter a minimal identifier only on a suppression listCommunications Law
Technical and security logs12 monthsData security and incident logging
Record of Terms acceptance (timestamp, IP, version, buyer type)7 yearsThe burden of proof borne by the Provider

At the end of the period, data is deleted or anonymised. A deletion request will not apply to data we are legally obliged to retain — in particular accounting documents.

We review, at least annually and no later than 31 December, the scope of data held, and delete data no longer needed for the purposes for which it was collected.

9. Your rights

9.1. Right of access (section 13)

You are entitled to inspect, yourself or through a person authorised in writing or a guardian, the personal data we hold about you. Inspection is available in Hebrew, Arabic or English, at your choice. The manner and conditions are set out in the Protection of Privacy (Conditions for Inspection of Data and Appeal Procedure on Refusal of an Inspection Request) Regulations, 5741-1981; a fee may apply under those Regulations. We will respond within 30 days.

9.2. Right to correction or deletion (section 14)

If you find that data about you is incorrect, incomplete, unclear or out of date, you may request its correction or deletion. If we agree, we will make the change and notify everyone to whom the data was transferred. If we refuse, we will notify you of the refusal and its reasons, and you may appeal to the Magistrates' Court.

For the avoidance of doubt: Israeli law does not recognise a general "right to be forgotten". The deletion right under section 14 arises where data is incorrect, incomplete, unclear or out of date. As a matter of policy, however, we will delete on request any personal data we are not required to retain by law or for legal defence, and we will tell you what was deleted, what remains and why.

9.3. Right to be removed from a marketing list (section 17F(b) of the Law and section 30A(d) of the Communications Law)

You may demand at any time, free of charge, to be removed from our marketing list and to have your details deleted from it. See section 10.

9.4. Right to withdraw consent

You may withdraw your consent to processing at any time. Withdrawal does not affect the lawfulness of processing already carried out, and does not apply to processing required to meet a legal obligation, for data security, or to protect our legal rights.

9.5. How to exercise your rights

Write to tom@octomonic.com, or by post to Aminadav 2, Tel Aviv-Yafo, Israel, stating your full name, the contact details we hold, and the substance of the request. We will acknowledge within 3 business days and substantively respond within 30 days. We will ask for one reasonable identifying detail to verify identity; we will not demand documents beyond what is necessary.

9.6. Right to complain

If we do not meet your request, or you believe your rights have been infringed, you may apply to the Israeli Privacy Protection Authority at the Ministry of Justice:

  • Website: gov.il/privacy-protection-authority
  • Online complaint form: on the "Contact" page of the Authority's website
  • By post: Privacy Protection Authority, Ministry of Justice, Jerusalem

10. Direct marketing and advertising

10.1. We will send you advertising only if you have given express prior consent, via a dedicated, separate checkbox that is not pre-ticked and is not a condition of purchase. Accepting the Terms or making a purchase does not constitute consent to marketing.

10.2. Notice at the point of collection (section 30A(c)(1) of the Communications Law): if you provide your details in the course of purchasing a service or in the course of negotiations for a purchase, we may use them to send you advertising about services of a similar kind. This notice is given to you at the moment you provide your details, and you may refuse immediately and at any time.

10.3. Every advertising message we send will state, prominently and clearly: the word "פרסומת" / "Advertisement" at the start of the message and in the email subject line; our name, address and contact details; and your right to send a refusal notice at any time, together with a simple, reasonable means of doing so and a valid internet address for that purpose.

10.4. A refusal notice may be given at any time, free of charge, in writing or by the same channel through which the message reached you — at your choice: by clicking the unsubscribe link at the foot of the message, by replying to the email address tom@octomonic.com, or by telephone on 054-502-5008. We will stop immediately and in any event within 3 business days.

10.5. Operational messages — order confirmations, invoices, meeting scheduling, project status updates and service notices — are not advertising and will continue while the engagement is in force.

11. Cookies and similar technologies

11.1. We use cookies and similar local storage. Since Amendment 13, an online identifier may constitute personal data, so the use of non-essential cookies requires consent.

11.2. Cookie categories:

CategoryDescriptionConsent required
Strictly necessaryEnable basic Website operation — session management, security, remembering your language and cookie preferencesNo. Always active; the Website cannot function without them
Performance and statisticsAggregate usage measurement — which pages were viewed, for how long, and where visitors came fromYes
Marketing and personalisationMeasuring campaign effectiveness and tailoring contentYes

11.3. On your first visit you will be shown a cookie notice allowing you to accept or reject non-essential cookies. Rejecting is as simple and accessible as accepting. Your choice is stored for 12 months and can be changed at any time via the "Cookie Settings" link in the footer of every page.

11.4. You may also block or delete cookies in your browser settings. Blocking strictly necessary cookies may impair the Website.

11.5. We do not currently respond to "Do Not Track" signals, as no uniform standard for interpreting them has been established.

12. Data security

12.1. We take reasonable and accepted measures to secure data, including: encryption of traffic (HTTPS/TLS); two-factor authentication on the administrative accounts under our control; restricting access to a small number of authorised users on a need-to-know basis; using infrastructure and payment providers that meet accepted security standards; and logging security incidents in accordance with Regulation 11(a) of the Protection of Privacy (Data Security) Regulations, 5777-2017.

12.2. The full card number is never stored by us and is processed directly by a licensed payment provider. We do not operate a card-vault (stored-card) facility with the payment provider.

12.3. We maintain an internal database definitions document under Regulation 2 of the Data Security Regulations — covering the description of collection and use operations, the purposes of use, the categories of data, details of transfers outside Israel, processing performed via a holder, the principal security risks and how they are handled, and the names of the relevant office-holders — and update it at least annually, by 31 December. The document is internal and is not published.

12.4. For the avoidance of doubt: no system is entirely immune. If a security incident affects your personal data, we will act to contain and remediate it, and we will notify you where notification is required by law or where we determine notification is necessary to enable you to protect yourself.

13. Database registration

Following Amendment 13, the duty to register a database in the Databases Register was significantly narrowed and now applies principally to public bodies and to databases whose primary purpose is collecting data for transfer to others as a business or for consideration and which hold data on more than 10,000 people (section 8A(a)). OctoMonic is not in these categories and is not required to register. Transparency, notice, security and data-subject-rights obligations apply to us in full regardless of registration, and we comply with them.

14. Changes to this Policy and renewed consent

14.1. We may update this Policy from time to time. The updated version will be published on the Website with an effective date and version number.

14.2. Where there is a material change in the purposes of use or the manner of processing, consent previously given will not be treated as covering the change, and we will seek your consent afresh. Material changes affecting existing customers will be notified by email in advance.

14.3. Previous versions are retained and available on request.

15. Privacy contact

OctoMonic (Tom Levi), licensed dealer no. 302148911
Aminadav 2, Tel Aviv-Yafo, Israel · 054-502-5008 · tom@octomonic.com

The Hebrew version of this Policy is the binding version. A complete and parallel English version exists, with identical numbering, conferring no lesser rights.

Privacy Policy version 2.0 · Effective 20 August 2026

Terms of Service

Cookies on this website

We use cookies and similar local storage. Strictly necessary cookies (session management, security, remembering your language and cookie preference) are always active and require no consent. Performance/statistics cookies and marketing/personalisation cookies require consent. Rejecting is as simple and accessible as accepting. Your choice is stored for 12 months and can be changed at any time via the "Cookie Settings" link in the footer of every page.

Privacy Policy