Privacy policy

This policy describes what this service actually collects, where it is sent and how long it is kept. It was written by reading our own code, not from a template.

Last updated: July 27, 2026

1. Who controls the data

  • Controller of the database: Dr. Digital, a sole licensed dealer (not an incorporated company)
  • Licensed dealer (Israel) No.: 209546571
  • Contact for privacy matters: aelgani.mhmd@gmail.com (email is our contact channel; the business has no premises open to the public)
  • Phone / WhatsApp: 052-444-6528

2. What we collect, and why

DataWhenPurpose
The website address you ask us to auditWhen you start an audit, a comparison or a monitorTo run the audit and to produce and store the report
Your name, email address and (optionally) phone numberWhen you unlock a full report or send the consultation formTo deliver the report you asked for and to reply to your enquiry
The message and preferred contact methodConsultation form onlyTo answer the enquiry
The email address for monitoringWhen you set up recurring monitoringTo send the scheduled result and score-change alerts
Your IP addressEvery audit requestRate limiting and abuse prevention (five audits per hour)
Your language choiceWhen you switch languageTo show the site and the report in that language
Your accessibility and cookie preferencesWhen you set themTo keep the site the way you configured it

We do not run advertising pixels, session recording, or profiling of any kind. We do not buy or sell personal data. We do measure traffic, but only with our own cookieless first-party analytics, described in section 12.

3. Who else processes the data

  • Supabase — database and backend hosting. All audits, leads, consultation requests and monitors are stored there.
  • Resend — transactional email delivery. Receives your email address and the contents of the report or alert email.
  • Google PageSpeed Insights API — performance measurement. The address of the website you audit is transmitted to Google, which then fetches and renders that website in order to measure it. If you would rather Google did not see the address, do not audit it here.
  • Cloudflare — serves the application itself; connection metadata such as your IP address is processed to route and protect the request.

4. Legal bases (GDPR)

  • Performance of a contract — delivering the audit report, the comparison or the monitoring result you requested.
  • Legitimate interest — rate limiting, abuse prevention and the security of the service; we keep your IP address only for as long as that purpose requires.
  • Consent — sending you marketing or follow-up email beyond the report you asked for, and storing any non-essential preference. You may withdraw consent at any time; withdrawal does not affect processing carried out before you withdrew.

5. How long we keep it

  • Audit reports and their findings: retained indefinitely, so that the permanent report link you were given keeps working and so that monitoring can compare against history. Ask us and we will delete a specific report.
  • Lead and consultation details: retained while there is an active business relationship, and deleted on request.
  • Monitoring records: retained until you unsubscribe, using the one-click link in every monitoring email; the record is then deactivated and deleted on request.
  • IP addresses attached to audits: retained with the audit record. They are used only for the rolling one-hour rate-limit window.

Honest note: today the system has no automatic deletion job. Reports and the IP address stored with them stay until deleted on request. If you would prefer a fixed retention period with automatic deletion, tell us and we will implement it.

6. Your rights

You may ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, or withdraw a consent you gave. Write to aelgani.mhmd@gmail.com and we will respond within 30 days. You may also lodge a complaint with your supervisory authority.

7. Israeli privacy law — Amendment 13

Under the Protection of Privacy Law and Amendment 13 to it, in force since August 2025, we notify you of the following at the point of collection:

  • Purpose of collection: to run the audit you requested, to send you the resulting report and monitoring alerts, to reply to your enquiry, and to protect the service from abuse.
  • Identity of the controller of the database: Dr. Digital, licensed dealer (Israel) No. 209546571, contactable at aelgani.mhmd@gmail.com or 052-444-6528.
  • Right of access: you have the right to inspect the information held about you and to demand its correction or deletion.
  • Consequence of refusing to provide the information: you are under no legal obligation to give us any of it. If you do not provide the website address we cannot run an audit; if you do not provide an email address we cannot send you the report or monitoring alerts, and you can still read the report at its link on screen; if you do not provide a name or phone number we simply cannot contact you back. No other consequence follows from refusing.

8. International transfers

Our processors — Supabase, Resend, Google and Cloudflare — may store or process data outside Israel and outside the European Economic Area, including in the United States. Those transfers rely on the processors' standard contractual clauses and equivalent safeguards. Details of a specific processor's hosting region are available on request.

9. Cookies and local storage

This site sets no cookies for advertising, and our analytics uses no cookies or storage at all. It stores a small number of values in your browser's local storage in order to remember your language, your accessibility settings, your cookie choice and which reports you have unlocked. The cookie policy lists every one of them, with its purpose and its lifetime.

10. Security and changes

Data is held in an access-controlled database with row-level security; the personal fields on an audit record are not readable by the public report page. We may update this policy; the date below always reflects the current version, and a material change is announced in the cookie banner.

11. Marketing emails

Separately from the report itself, you may opt in to receive occasional practical tips on website speed, SEO and AI visibility. The checkbox is unticked by default and is never a condition of receiving your report or of booking a consultation — if you leave it unticked you still get everything you asked for.

  • Legal basis: your consent (GDPR Art. 6(1)(a)) and the prior explicit consent required by section 30A of the Israeli Communications Law.
  • What we record: whether you consented, the date and time, which form you used, and the exact wording you agreed to — that last item is what proves what was actually offered.
  • Withdrawing consent: every marketing email carries a one-click unsubscribe link, and one click is enough — no login, no reason required. You can also write to aelgani.mhmd@gmail.com. Withdrawal takes effect immediately and does not affect anything you asked for before.
  • If you did not consent, your details are still stored for the audit trail and so your report link keeps working, but you are excluded from every marketing list and export by default.

12. Analytics

We measure how this site is used with our own first-party, cookieless analytics. There is no Google Analytics, no third-party script and no data leaving to an advertising network. Nothing is written to your device: no cookie, no local storage, no session storage.

  • What is recorded per page view: the page path, a cleaned query string (anything resembling an email address or a token is discarded), the referring website's host name only — never the full referring URL, campaign tags (utm_source, utm_medium, utm_campaign) when present, your country as reported by our network provider, a coarse device type, browser and operating system derived from your browser's user-agent string, and the site language you were using.
  • What is not recorded: your IP address is never stored in the analytics tables, and neither is your full user-agent string, your name, your email address or any account identifier.
  • How visits are counted without tracking you: your IP address and user-agent are combined with a secret salt and hashed with SHA-256. The salt is regenerated every 24 hours and old salts are deleted, so the resulting value cannot be reversed to an IP address and the same visitor cannot be recognised on a later day. A visit ends after 30 minutes of inactivity.
  • Events: we also record which steps of the service were used — a scan started, a scan completed or failed, a report viewed or unlocked, a PDF exported, a comparison started, monitoring set up, a consultation booked, a language changed — attached to the same anonymous daily value, so we can see where people give up.
  • Bots: automated crawlers are recorded and flagged as such, and are excluded from our reports by default.
  • Legal basis: our legitimate interest (GDPR Art. 6(1)(f)) in understanding how our own service is used. Because no information is stored on or read from your device beyond what is strictly necessary to deliver the page, this measurement does not require consent under the ePrivacy rules on access to terminal equipment.
  • Retention: row-level analytics data is kept for 12 months. A scheduled job then aggregates it into daily totals — counts only, with no path, referrer, country or visitor value — and permanently deletes the underlying rows.

Because no persistent identifier exists, we cannot single you out in this data, and a request to access or erase your analytics records cannot be fulfilled by us — there is nothing in it that identifies you.