Privacy Policy

Introduction and Scope

This Privacy Policy is designed to clarify how Meitarim – Find Your Compass Ltd. processes personal information of users, customers, and visitors to our websites and other communication channels. The policy applies to the main website thecompass.arninakashtan.com. Information processing is carried out in accordance with the Privacy Protection Law, 5741-1981, Privacy Protection Regulations (Information Security), 5777-2017 and Amendment 13 to the Law, the Communications Law (Bezeq and Broadcasts), 5742-1982 (Section 30a – “Spam Law”), and in accordance with the EU GDPR where applicable.

Business Details and Data Controller

Data Controller: Meitarim – Find Your Compass Ltd.
Contact Person: Hen.
Email for privacy inquiries: henn.natan@meitarim.co.il
Phone: +972547433713
Website addresses: thecompass.arninakashtan.com.

Target Audience and Minors

The services are intended for an adult audience. We do not knowingly target minors under the age of 18 and do not intentionally collect information from them without parental/guardian consent, as required by law. If we become aware that information has been collected from a minor without appropriate consent, we will act to delete it as soon as possible.

Types of Information Collected

We may process the following categories of personal information: full name; phone number; email address; residential/delivery address; payment details (including credit/debit card details as provided for clearing through the clearing provider); IP address and approximate location data; technical and usage information collected from websites (such as device/browser identifiers, cookies, referral pages, access times).

Sources and Means of Collection

Information is collected through forms and our WordPress sites at the specified addresses, the “Rav Messer” mailing system, proactive inquiries from you via email and WhatsApp, and as part of online purchase and clearing processes through the clearing provider. In addition, technical information may be collected automatically during browsing (including server logs, IP address, and cookies).

Purposes of Processing and Legal Grounds

We process personal information for the following purposes, in accordance with the appropriate legal grounds:

  • Providing services, managing customer accounts, support and customer service, contacting existing customers and inquirers – contract performance and legitimate interest.
  • Performing online purchases and clearing, handling orders, issuing receipts and invoices – contract performance and legal obligation (reporting and accounting ledger).
  • Sending updates, newsletters, and marketing content subject to law – consent and legitimate interest, and in accordance with the Communications Law (Section 30a).
  • System security, fraud monitoring and prevention, log retention – legitimate interest and legal obligation.
  • Compliance with legal requirements, responding to authority inquiries and enforcement – legal obligation.
 When the basis is consent 

you can withdraw consent at any time, provided that this does not affect processing already lawfully performed before the withdrawal of consent.

Direct Marketing

We send advertisements in accordance with the Communications Law (Section 30a). Consent is given, among other things, by checking a box/approval button in registration interfaces and messages, and we will act according to applicable law and request consent where required. Every marketing message will include the sender’s identification details (Meitarim – Find Your Compass Ltd.) and an option to unsubscribe. You can remove yourself at any time by clicking on an unsubscribe link/button in the message or by physical request/email. Removal will be performed free of charge and within a reasonable timeframe.

Cookies and Similar Technologies

We use cookies and similar technologies for website operation, security, measurement and analysis of use, and improvement of user experience. Cookie types include essential operational cookies, performance/analytics cookies, and functional cookies. Preferences can be managed through browser settings or any cookie management mechanism available on the site, and existing cookies can be deleted; blocking essential cookies may impair some website functions.

Disclosure of Information to Third Parties

We share personal information with service providers acting as processors on our behalf for the purpose of providing services (such as cloud storage, website maintenance, mailing, clearing), subject to appropriate agreements and data protection provisions. Information may also be disclosed to law enforcement authorities, regulators, and courts where required by law or for the exercise of legal rights, and as part of lawful corporate structural changes. In clearing transactions, card details are processed by the authorized clearing provider; where possible, we do not store full card details ourselves but rely on the provider’s tokenization mechanisms.

Information Transfers Outside of Israel 

Some of the providers and infrastructures may be located outside of Israel, including outside the EEA/UK. When transferring international information, we will implement appropriate protection mechanisms, such as standard contractual clauses (SCCs) of the European Union, due diligence, and additional contractual protections, and in accordance with applicable Israeli law on international data transfer.

Retention and Deletion

We will retain personal information only for the period required for the purposes for which it was collected, and according to legitimate business need or legal obligation (including retaining accounting records and tax documents for periods required by law). When the basis for processing expires or at your request, we will act to delete or anonymize the information, subject to our data retention obligations. Requests for removal from marketing processing will be honored within a reasonable time.

Data Subject Rights

In accordance with the Privacy Protection Law and GDPR (where applicable), you have the following rights: the right to review information, receive a copy, correct incomplete/outdated information, delete information in appropriate cases (“right to be forgotten”), restrict processing, object to processing based on legitimate interest (including objection to direct marketing), and data portability where applicable. When processing is based on consent – you can withdraw it at any time. To exercise your rights, contact us by email henn.natan@meitarim.co.il or by phone +972547433713; we may request identity verification. We will respond within the timeframes stipulated by law. If you are not satisfied, you can file a complaint with the Privacy Protection Authority in Israel, and for data subjects in the EU/UK – also with a local supervisory authority.

Information Security and Security Incidents

We implement information security measures that comply with legal requirements, including: role-based and need-based access controls (“Least Privilege”), use of HTTPS protocol for traffic encryption, two-factor authentication for administrative accounts and supporting systems, and periodic backups. In addition, we use encryption at rest and in transit where appropriate, permission management, anomaly monitoring, ongoing security updates, and log controls. In the event of a security incident that may create a real risk to privacy, we will act in accordance with the law and regulations, including conducting an investigation, taking mitigation steps, and reporting to authorities and data subjects as needed and by law (including under GDPR, Sections 33-34, where applicable).

Use of Artificial Intelligence (AI)

We may use artificial intelligence tools to support service processes, analyze trends, and improve internal processes. We do not make automated decisions that create legal implications or similar material impact on you without human involvement. When external tools are used, we will adhere to principles of data minimization, avoidance of entering identifying data when not necessary, and subject processing to appropriate agreements and security protections.

Controller vs. Processor

For the purpose of the processing described in this policy, the company acts as a data controller. Our service providers act as processors and process personal information for us solely according to our instructions, for the purposes set, and in accordance with appropriate data processing agreements and confidentiality and security commitments.

Updates to the Policy

We may update this policy from time to time to reflect changes in law or services. We will update the “Last Updated Date” below and publish the updated version on the website. Your continued use of the services after a change constitutes acceptance of the updated version, subject to law.

Appendix – List of Systems and Service Providers

Google Cloud – cloud storage, server infrastructure, and backups

Cardcom – payment clearing and credit card charging

Rav Messer – email marketing, list management, and automation processes

WordPress – website management, forms, and content

Last Updated Date: October 29, 2025

Subscribe to Our Newsletter.