PRIVACY POLICY
Last updated: June 2026
1. DATA CONTROLLER
DOMAINator is operated from Israel. For questions regarding your personal data, contact us at [email protected].
2. DATA WE COLLECT
Account Data
- Email address, display name, company name, industry, country
- Hashed passwords (bcrypt — we never store plaintext passwords)
- Two-factor authentication secrets (encrypted)
Scan Data
- VPN configuration files (encrypted at rest, deleted upon removal)
- Target IP addresses and domain names
- Scan results, findings, and generated reports
- Credentials discovered during authorized scans (encrypted)
Usage Data
- Login timestamps, IP addresses, session data
- Scan initiation and completion records
- Platform usage analytics
Payment Data
- Payments are processed by Grow Payments (Merchant of Record). We do NOT store credit card numbers. See Grow Payments's privacy policy for payment data handling.
3. PURPOSE OF PROCESSING
- Service delivery — executing scans, generating reports, managing accounts
- Security — authentication, fraud prevention, abuse detection
- Communication — transactional emails (scan completion, password resets)
- Legal compliance — audit logs, tax records
We do NOT sell personal data. We do NOT use your data for advertising. We do NOT send scan data to AI/LLM services.
4. DATA SECURITY
- All data encrypted in transit (TLS 1.3). Two-factor authentication secrets are encrypted at rest.
- VPN configs stored with restricted file permissions in isolated per-customer directories
- Scan environments isolated using Linux network namespaces
- Access controls and audit logging on all systems
- Regular security reviews and vulnerability assessments
5. DATA RETENTION
- Account data — deleted upon account closure, except where retention is required by law (see below)
- Scan results — the report is accessible for 24 hours (48 hours on the Emperor and CISO plans) after your scan completes. After that window the report and the sensitive scan contents (scan credentials, any credentials discovered, target IP/host, and raw scan output) are permanently deleted; only a non-sensitive summary (target domain, risk score, finding counts, dates) is kept for your history
- VPN configs — deleted when you remove them or when your account is deleted
- Audit logs — retained for as long as needed for security and account integrity purposes
- Financial records — retained for 7 years (Israeli tax law), independent of account deletion
6. YOUR RIGHTS
Under the Israeli Privacy Protection Law and GDPR (for EU residents), you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (subject to legal retention requirements)
- Data portability — receive your data in a structured format
- Object — object to processing of your data
- Withdraw consent — for marketing communications at any time
To exercise these rights, email [email protected]. We will respond within 30 days.
7. COOKIES
We use essential cookies for authentication and session management. These are strictly necessary and do not require consent. We do not use third-party tracking or advertising cookies.
We collect anonymous page-visit data (page path, timestamp) via our own servers to understand site usage. This is first-party data — it is not shared with or processed by any third-party analytics provider.
8. THIRD-PARTY SERVICES
- Grow Payments — payment processing
- Brevo (Sendinblue) — transactional email delivery
- Accessibility widget — built and hosted in-house, no third-party data sharing
Each service has its own privacy policy governing its handling of data.
9. DATA BREACH NOTIFICATION
In the event of a data breach that poses a risk to your rights, we will notify the Israeli Privacy Protection Authority and affected users without undue delay, in accordance with the Privacy Protection Regulations (Data Security).
10. INTERNATIONAL TRANSFERS
Your primary data is stored on servers located in Israel. Some data processing is handled by third-party sub-processors that may be located outside Israel — see the Third-Party Services section for the current list. Where a sub-processor is based in the EU, we rely on that provider's own GDPR compliance mechanisms.
11. CHILDREN
DOMAINator is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.
12. CHANGES
We may update this policy. Material changes will be communicated via email or platform notification. Continued use after changes constitutes acceptance.
13. CONTACT
Privacy inquiries: [email protected]
1. מפעיל המידע
DOMAINator מופעלת מישראל. לשאלות בנוגע למידע האישי שלכם, פנו אלינו בכתובת [email protected].
2. מידע שאנו אוספים
נתוני חשבון
- כתובת אימייל, שם תצוגה, שם חברה, תעשייה, מדינה
- סיסמאות מוצפנות (bcrypt — איננו שומרים סיסמאות בטקסט גלוי)
- סודות אימות דו-שלבי (מוצפנים)
נתוני סריקה
- קבצי תצורת VPN (מוצפנים בזמן אחסון, נמחקים עם הסרתם)
- כתובות IP ושמות דומיין של יעדים
- תוצאות סריקה, ממצאים ודוחות שנוצרו
- אישורים שהתגלו במהלך סריקות מורשות (מוצפנים)
נתוני שימוש
- חותמות זמן של כניסה, כתובות IP, נתוני הפעלה
- רשומות הפעלה והשלמת סריקות
- אנליטיקת שימוש בפלטפורמה
נתוני תשלום
- התשלומים מעובדים על ידי Grow Payments. איננו שומרים מספרי כרטיסי אשראי.
3. מטרת העיבוד
- מתן שירות — ביצוע סריקות, יצירת דוחות, ניהול חשבונות
- אבטחה — אימות, מניעת הונאות, זיהוי שימוש לרעה
- תקשורת — אימיילים עסקיים (השלמת סריקה, איפוס סיסמה)
- עמידה בחוק — רישומי ביקורת, רשומות מס
איננו מוכרים מידע אישי. איננו משתמשים במידע שלכם לפרסום. איננו שולחים נתוני סריקה לשירותי AI.
4. אבטחת מידע
- כל המידע מוצפן בזמן העברה (TLS 1.3). קודי אימות דו-שלבי מוצפנים גם באחסון.
- תצורות VPN מאוחסנות עם הרשאות קובץ מוגבלות בתיקיות מבודדות לכל לקוח
- סביבות סריקה מבודדות באמצעות Linux network namespaces
- בקרות גישה ורישום ביקורת בכל המערכות
5. שמירת מידע
- נתוני חשבון — נשמרים כל עוד החשבון פעיל + 90 יום לאחר מחיקה
- תוצאות סריקה — נשמרים בהתאם למשך הגישה לדוח של התוכנית שלכם
- תצורות VPN — נמחקות עם הסרתן או מחיקת החשבון
- רישומי ביקורת — נשמרים ל-24 חודשים
- רשומות כספיות — נשמרות ל-7 שנים (חוק המס הישראלי)
6. הזכויות שלכם
על פי חוק הגנת הפרטיות הישראלי ו-GDPR (לתושבי האיחוד האירופי), עומדת לכם הזכות:
- גישה — לבקש עותק של המידע האישי שלכם
- תיקון — לתקן מידע שגוי
- מחיקה — לבקש מחיקת המידע (בכפוף לדרישות שמירה חוקיות)
- ניידות מידע — לקבל את המידע בפורמט מובנה
- התנגדות — להתנגד לעיבוד המידע
- ביטול הסכמה — לתקשורת שיווקית בכל עת
למימוש זכויות אלה, שלחו אימייל ל-[email protected]. נגיב תוך 30 יום.
7. עוגיות
אנו משתמשים בעוגיות חיוניות לאימות וניהול הפעלות. אלו הכרחיות ואינן דורשות הסכמה. איננו משתמשים בעוגיות מעקב או פרסום של צדדים שלישיים.
אנו אוספים נתוני ביקור אנונימיים (נתיב עמוד, חותמת זמן) דרך השרתים שלנו כדי להבין את השימוש באתר. זהו מידע מהצד הראשון — הוא אינו משותף או מעובד על ידי כל ספק אנליטיקה של צד שלישי.
8. שירותי צד שלישי
- Grow Payments — עיבוד תשלומים
- Brevo (Sendinblue) — משלוח אימיילים עסקיים
- כלי נגישות — פותח ומאוחסן באופן פנימי, ללא שיתוף מידע עם צד שלישי
9. התראה על פריצת מידע
במקרה של פריצת מידע המהווה סיכון לזכויותיכם, נודיע לרשות להגנת הפרטיות ולמשתמשים המושפעים ללא דיחוי, בהתאם לתקנות הגנת הפרטיות (אבטחת מידע).
10. העברות בינלאומיות
המידע העיקרי שלכם מאוחסן בשרתים הממוקמים בישראל. חלק מעיבוד המידע מתבצע על ידי ספקי משנה שעשויים להיות ממוקמים מחוץ לישראל — ראו את סעיף שירותי צד שלישי לרשימה העדכנית. כאשר ספק משנה ממוקם באיחוד האירופי, אנו מסתמכים על מנגנוני הציות של אותו ספק ל-GDPR.
11. קטינים
DOMAINator אינה מיועדת לשימוש על ידי מי שמתחת לגיל 18. איננו אוספים ביודעין מידע מקטינים.
12. שינויים
אנו עשויים לעדכן מדיניות זו. שינויים מהותיים יועברו באימייל או בהתראה בפלטפורמה.
13. יצירת קשר
פניות פרטיות: [email protected]