Privacy Policy - Velolinx
Last updated date: 7/20/2026
Introduction
Welcome to Velolinx (hereinafter: "the Company", "we", "our") operating under Licensed Dealer 300312121. Our website, www.velolinx.co.il (hereinafter "the Website"), provides SEO services and sale of link packages. To provide the services we may collect, process, store and deliver personal information about customers and users.
This privacy policy details the conditions and rules in which we operate with the information, in accordance with the Privacy Protection Law, 1981 (hereinafter: "the Law") and Amendment 13 that entered into force on August 14, 2025.
Table of Contents:
1. Key Definitions
Below are definitions for the essence of the main terms:
- "Personal Information", any detail identifying a person or allowing their identification, by itself or in combination with other information, such as name, phone, email, address, website address, IP address and the like.
- "Sensitive Information / Sensitive Personal Information", personal information in a state where its publication or exposure may cause serious harm, such as medical information, political opinions, sexual orientation, belonging to associations, economic status, etc.
- "Processing / Information Processing", any action related to personal information, including collection, storage, organization, editing, use, transfer, disclosure, comparison, destruction and the like.
- "Database / Personal Information Database", a collection of personal information made accessible in an organized manner for continuous processing according to certain criteria, even if not physically stored in a single system.
- "Data Controller" (data controller / database owner), the body that determines the purposes of processing and the manner of use of the personal information.
- "Data Processor" (data processor / database holder), a body that performs processing on the information on behalf of the controller, according to its instructions.
- "Data Subject / Information Owner", the person to whom the personal information belongs.
- "Consent", a clear, accurate, free and explicit notice of the information owner that their personal information will be processed for a certain purpose.
- "Information Security Incident", exposure, theft, penetration, unauthorized storage or any event that may harm the integrity, confidentiality and availability of the personal information.
2. Application of the Law and Amendment 13
2.1 General Application
The Law applies to any "data controller" and "database holder" operating within Israel and processing personal information of residents in Israel, as well as, in some cases, to bodies from abroad that handle personal information of Israeli citizens.
Amendment 13 expands the application of the Law and brings important changes:
2.2 Main points of Amendment 13 and its Implications
- New terminology and expanded definitions, Amendment 13 refines and updates concepts like "data controller", "database holder", "processing", and expands the application of the Law to cases that were not previously under supervision.
- Cancellation of database registration obligation in most cases, Under the old law it was necessary to register databases in a central database. In Amendment 13 the registration obligation is reduced to cases where the main purpose of the database is selling information or when the database includes information on over 100,000 data subjects, or when it is a public body.
- Obligations to increase transparency, Obligation to inform data subjects about the processing of their information, processing purposes, different periods during which information will be kept, etc.
- Reporting on information security incidents, Obligation to report to the Privacy Protection Authority (and sometimes to victims) on any potential event that will harm privacy.
- Punishment and increased supervision obligations, The authority of the Privacy Protection Authority has increased, including fines, orders, investigations and additional sanctions.
- Obligation to appoint a Data Protection Officer (DPO), In cases where processing personal information constitutes a core activity or there is a high risk to privacy, the amendment requires appointment of an officer.
- Board responsibility and internal supervision, Internal checks and transparency, responsibility for compliance with privacy guidelines.
Important: In August 2025, this privacy policy is adapted to Amendment 13 to meet the requirements of the renewed law.
3. Principles of Information Processing
In accordance with the provisions of the Law and common privacy practices (and similar to GDPR principles), we are committed to acting according to the following principles:
- Purpose limitation, Processing will be done for clear, defined and permitted purposes only, and not for new purposes not specified.
- Data minimization, We will collect only the information necessary for the purpose of providing the service, and not excess information.
- Accuracy, We will ensure that information is as updated and correct as possible, and it can be corrected or deleted at your request.
- Storage limitation, We will not keep information beyond what is required; storage periods are defined according to the purpose.
- Integrity and confidentiality, We will take appropriate security measures to maintain the confidentiality and non-changeability of information.
- Accountability, We carry responsibility for compliance with this policy, internal procedures and documentation of actions.
- Privacy by default / privacy by design, The structure, development and authorizations are built in advance to protect privacy.
4. Types of Information We Collect
In accordance with the purposes and activities of the Website, we may collect the following information:
4.1 Information provided directly by the user
- Contact details: full name, phone, email
- Business details: business name, website address, short description of the business (brief), area of activity
- Purchase details: link packages selected, price, payment details (depending on the payment system; usually the system is separate)
- Information related to instructions, questions, comments or support
4.2 Technical / Automatic information
- IP address
- Browser type, operating system, browser version
- Usage data: pages visited, inquiries, entrance and exit traffic
- Cookies and Web Analytics data (e.g., Google Analytics)
- Date and time of action
4.3 Secondary / Learned information
- Usage profile, preferences, selected links
- Information arising from campaigns or integration with marketing tools, if user consent was given.
Note: We avoid as much as possible the collection of sensitive information, unless we have received explicit written consent.
5. Legal Basis for Processing
To process personal information legally, we must rely on at least one of the following legal bases:
- User consent, Before any processing for a certain purpose (such as sending marketing mailings), we will ask for clear and explicit consent.
- Performance of a contract / implementation of a user request, For example, processing information necessary to perform a purchase transaction, provide a package you requested.
- Recognized interest of the Company, If necessary, in a reasonable dose, when there is no tangible harm to your rights (for example: internal security, fraud prevention).
- Fulfillment of a legal obligation, In cases where the law requires it (for example, reporting to the authority in case of an information security incident).
- Public interest or other authorization under law, In exceptional cases.
Please note: In the case of processing sensitive information, explicit consent must be strictly observed and only in cases permitted by law.
6. Processing Purposes and Usage Policy
Below is a detail of information uses and processing rationale:
| Processing Purpose | Relevant Information | Legal Basis | Note |
|---|---|---|---|
| Providing link packages and promotion | Business details, website address, brief | Performed at your request / agreement offer | Required to adapt the service |
| User account management | Personal details, purchase history | Performance of contract / agreement | Ongoing maintenance |
| Handling inquiries / support | All inquiry details | Implementation of request | For providing response |
| Direct marketing (mailing, offers) | Email, phone | User consent | Can be canceled at any time |
| Information security / fraud prevention | IP address, logs, browser | Recognized interest / legal obligation | Intended to protect the site and users |
| Statistical analysis / improvement | Anonymous / minimized usage data | Recognized interest | For improving service experience |
| Exercising legal rights | Relevant details | Legal obligation / legal interest | If required as part of proceedings |
We will ensure that the matching between the purpose and the processing is as close as possible and in the required scope only.
7. Receiving Information from Data Subjects / Delivery of Information to Third Parties
7.1 Receiving information from data subjects
Before we collect information, we will provide you with clear and detailed information on the purpose, types of information, processing ways, and your rights. If the information was not transferred by you, e.g., external sources, we will do so only if the law permits it and provided these sources act lawfully.
7.2 Delivery of information to third parties
We are authorized to deliver personal information of users to the following entities:
- Processors on our behalf, hosting providers, technological infrastructure companies, payment systems, marketing tools, analytics tools, email services and more, but only under a binding agreement that protects information confidentiality.
- Subcontractors / business partners, for the purpose of performing the main services, if required, in accordance with clear agreements.
- Competent authorities, in case the law requires us to deliver information (court order, legal authority requirement).
- In case of merger / acquisition / transfer of activity, it is required that the receiving party continues to maintain confidentiality agreements and policy conditions.
In any such case, the receiving party will be obligated to act according to our policy and without additional use that was not approved.
8. Information Security
Information security constitutes a cornerstone in this policy:
- Maintenance of secure infrastructures (servers, encryption, firewalls, SSL/TLS)
- Controlled access and authorizations according to minimal demand (least privilege)
- Regular security audits, Penetration Testing
- Encryption key management and rigid procedures
- Maintaining system operation logs
- Employee training and internal access procedures
- Risk management, Privacy Impact Assessments
- Sectioning sensitive information, risk reduction, encryption of information in transit and at rest
In cases where we identify a weakness or risk, we will act for immediate repair and reporting as required.
9. Information Storage and Deletion
- We will build an internal policy of periodic deletions: unnecessary information will be deleted or anonymized
- Storage periods for information will be determined according to its type and legal obligation
- In case of a deletion request by the user, we will delete or secure information in a non-identifiable way
- If part of the information must be kept (for accounting, legal matters, etc.), we will keep only minimal parts subject to the law
10. Rights of Data Subjects
According to the Law and Amendment 13, you have (as a user / information owner) the following rights:
- Right to review, ask to access any personal information we hold about you.
- Right to correction / completion, ask to correct wrong information or complete missing information.
- Right to erasure ("The right to be forgotten"), ask to delete information if there is no legal need to keep it anymore.
- Right to restrict processing, ask to reduce processing in certain cases.
- Right to data portability, receive information processed by us in a readable structure and transfer it to another entity.
- Right to object to processing, especially for direct marketing purposes.
- Right to withdraw consent, at any time you can withdraw consents you granted, which will stop future processing for these purposes.
- Right to compensation / appeal to the authority, if you were harmed due to a violation of the policy or the law, you can appeal to the authority or courts.
Every request for exercising rights will be handled within a reasonable time and according to law.
11. Coping with Information Security Incidents
According to Amendment 13 there is an obligation to report on an information security incident:
- After incident identification, we will perform mapping immediately, assessment of the damage type and penetration scope
- If the incident is likely to cause "material harm to privacy", we will send an update to the Privacy Protection Authority within the period set in the law
- If required, we will also inform the affected data subjects, in the required details
- We will maintain an internal record of the incident, actions taken and repairs performed
- We will perform a root cause analysis and implementation of preventive steps
The Company's management will carry responsibility for supervising the reporting and handling procedure.
12. Appointment of an Officer (DPO) and Internal Organizational Obligations
According to Amendment 13, it is mandatory to appoint a Data Protection Officer in cases where:
- Processing personal information constitutes a core activity
- There is a high risk to privacy
- According to the instructions of the Privacy Protection Authority
The officer will act as a contact point with the Authority and data subjects, supervise compliance with the policy, conduct internal audits and training, and be responsible for risk mapping.
In addition, the organizational requirement includes:
- Website management and board are responsible for compliance with the privacy policy
- Internal supervision and enforcement of procedures
- Documentation of actions, procedures and updates
- Training of Company employees on privacy and information security issues
13. Trans-border Data Flows (Information Transfers from Abroad)
If information is transferred from the State of Israel to a foreign country (for example, foreign cloud storage or external service in another country), we must ensure:
- That the foreign country provides good enough protection
- Use of secured means (transfer agreements, encryption, binding standards, etc.)
- In appropriate cases, clear notice to the data subject and obtaining their consent before transfer
14. Cookies and Similar Tools
- We use cookies for proper operation of the website, user identification, traffic data analysis and personalization
- Types of cookies: essential, performance, marketing
- Upon entering the site, a notice about cookie use is shown, with a link to this policy. You can control and block cookies via your browser settings
- Blocking cookies may affect the website usage experience
Third-party analytics and marketing tools: The site uses third-party analytics and advertising services, including:
- Google Analytics (GA4) and Google Ads, for traffic analysis, conversion measurement and remarketing.
- Google Ads Enhanced Conversions, when you make a purchase, contact details you provided (email and phone number) are sent to Google in hashed (encrypted) form only, to more accurately attribute conversions. Google does not receive these details in plain text.
- Meta Pixel by Meta (Facebook/Instagram), for ad performance measurement and remarketing.
These services may set cookies and collect identifiers for advertising and measurement, subject to those providers' privacy policies. You can block these cookies via your browser settings.
15. Changes to the Policy
- We reserve the right to update this policy from time to time
- Any material change will be published prominently on the website in advance, and will enter into force accordingly (usually within 7 days)
- A valid version will include an update date
16. Contact Details and Further Information
If you wish to exercise your rights, ask a question or raise a request related to privacy, contact us:
Company Name: Velolinx
Licensed Dealer: 300312121
Website: www.velolinx.co.il
Email: velolinx.seo@gmail.com
Phone: 050-7418449
Option for inquiry also through the "Contact Us" form on the Website
Data Protection Officer (if appointed): details will be published on the Website
Company Declaration
Velolinx undertakes to act in full transparency, respect the privacy rights of all its users and comply with all legal requirements, including Amendment 13 to the Privacy Protection Law. We see the protection of our customers' privacy as a top value and invest many resources in information security and ongoing updating of our security systems.
This policy was written in a professional and legal manner in order to protect the rights of the Company and the customers alike. We highly recommend reading this policy carefully and contacting us with any question, doubt or request.
Update Date: 7/20/2026
Based on: Privacy Protection Law, 1981 including Amendment 13 of 2021 that entered into force in August 2025
