Privacy Policy & Data Protection
At BrandMeWeb, data privacy, infrastructure security, and engineering integrity are foundational principles. This Privacy Policy details how we collect, process, safeguard, and govern information in full accordance with the Israeli Privacy Protection Law 5741-1981 (including Amendments 13 and 14), the Privacy Protection Regulations (Data Security) 5777-2017, the European Union General Data Protection Regulation (GDPR), and modern cybersecurity protocols.
1. Data Controller & Legal Jurisdiction
The data controller and database manager is BrandMeWeb (Ra'anana, Israel; Chief Architect & Founder: Ilya Sibiryakov).
The State of Israel is formally recognized by the European Commission as offering an adequate level of data protection (EU Adequacy Decision 2011/61/EU). This grants our clients European-grade legal protection for all personal data processed. For statutory inquiries or to contact our Data Protection Officer (DPO), email: info@brandmeweb.com.
2. Categories of Data Collected & Data Minimization
We strictly apply the principle of Data Minimization, capturing only records strictly essential to deliver our SEO, GEO, and engineering services:
• Account & Contact Information: Name, business email, contact phone number, or authorized messenger handle (WhatsApp / Telegram).
• Project Telemetry: Client domains registered for SEO/GEO auditing, target keyword corpuses, search visibility indices, and technical audit parameters.
• Payment & Billing Data: BrandMeWeb operates under a strict Zero-Server architecture regarding financial credentials. All subscription transactions and credit card processing are conducted exclusively by authorized PCI-DSS Level 1 certified gateway Morning (Green Invoice Ltd., Israel). Payment credentials never pass through our servers and are never stored in our databases.
3. Legal Grounds for Processing
All personal data processing is conducted strictly under verified lawful grounds:
• Contractual Performance: Delivering commissioned technical retainers, search intelligence software, and audit diagnostics (GDPR Art. 6(1)(b) and Israeli Law 5741-1981).
• Explicit Consent: Submitting contact forms, diagnostic requests, or registering tracking accounts (GDPR Art. 6(1)(a)).
• Legitimate Interests: System security, DDoS mitigation, malicious crawling prevention, and Core Web Vitals telemetry optimization (GDPR Art. 6(1)(f)).
• Statutory Compliance: Fulfilling statutory bookkeeping, invoicing, and tax obligations under applicable Israeli commercial law.
4. Engineering Safeguards: PostgreSQL RLS & Cryptography
Data protection is hardcoded into our engineering infrastructure:
• Row-Level Security (RLS): Our production PostgreSQL clusters managed by Supabase enforce strict RLS policies. Client datasets are cryptographically and logically isolated; users can access only domains and keywords mapped to their authenticated UID.
• Encryption in Transit: All client-server communications are encrypted via TLS 1.3 / HTTPS with mandatory HTTP Strict Transport Security (HSTS).
• Encryption at Rest: Production database volumes, cold storage backups, and telemetry tables are encrypted using AES-256.
• Zero-Server PII Sanitization: Proprietary sanitization layers ensure customer personal identifiers are never forwarded to external third-party LLM providers.
5. Sub-processors & International Data Transfers
To provide high uptime and scalable infrastructure, we rely on established sub-processors:
• Supabase Inc. – Managed PostgreSQL database infrastructure (AWS Frankfurt region, European Union).
• Vercel Inc. – Serverless Next.js edge runtime and global content delivery network (USA / EU / Global).
• Morning (Green Invoice Ltd.) – PCI-DSS Level 1 certified billing and invoice generation engine (Israel).
• Google LLC – Search Console and Google Analytics 4 telemetry with active IP anonymization (USA / Global).
Data transfers outside Israel or the European Economic Area (EEA) adhere strictly to European Standard Contractual Clauses (SCCs).
6. Cookies & Anonymous Performance Telemetry
We do not deploy invasive third-party advertising cookies or cross-site behavioral tracking pixels. The platform utilizes only:
• Essential Technical Cookies: Managing user authentication tokens, active language settings, and consent flags in browser localStorage.
• Anonymous Performance Telemetry: Vercel Speed Insights and Google Analytics 4 configured strictly for Core Web Vitals diagnostics and server error logging.
Users may inspect, restrict, or purge cookies at any time through their browser configuration or our interactive consent interface.
7. Data Subject Rights (Israeli Privacy Law & GDPR)
Under Israeli privacy statutes and global standards, you retain comprehensive statutory rights:
• Right of Inspection (Section 13 Israeli Privacy Law / GDPR Art. 15): The right to request written confirmation and a structured summary of personal records held.
• Right of Rectification (Section 14 Israeli Privacy Law / GDPR Art. 16): The right to update or correct inaccurate, incomplete, or outdated data.
• Right to Erasure ("Right to be Forgotten" / GDPR Art. 17): The right to demand permanent deletion of your profile, projects, and telemetry from all active databases.
• Right to Data Portability (GDPR Art. 20): The right to export keyword metrics and ranking archives in structured CSV/JSON formats.
To exercise these statutory rights, email: info@brandmeweb.com. We respond to all verified requests within 30 calendar days.
8. Data Retention & Permanent Deletion Protocols
Account configurations and search telemetry remain stored as long as your account or retainer is active. You may remove individual domain monitors directly via your dashboard at any time; this action executes an immediate row-level purge from our PostgreSQL cluster.
Upon receipt of a formal account erasure request, all associated personal and operational records are permanently deleted within 30 calendar days, preserving only tax-mandated billing records required by Israeli commercial law.