This policy explains what personal data Sibonix collects, why, and what you can do about it. It covers this website, sibonix.com, and personal data we handle while providing marketing services to clients.

Who we are

Sibonix is a marketing services company operating from Israel. For any privacy question, or to exercise any right described below, contact yoav@sibonix.com. We are the data controller for the data described in this policy, except where we act as a processor on behalf of a client.

What this website collects

This website is a set of static pages. It has no accounts, no login, no comment system, and no forms that submit data to us.

  • No analytics. We do not run Google Analytics or any other analytics or advertising tracker on this website.
  • No cookies set by us. We do not set cookies for tracking, advertising, or personalisation.
  • Server logs. Our hosting provider, Cloudflare, records standard request data such as IP address, user agent, requested URL, and timestamp. This is used to serve the site, block abuse, and keep the service available. Cloudflare may also set a security cookie for that purpose. See the Cloudflare privacy policy.

If we later add a contact form or analytics to this website, this policy will be updated before that happens.

If you contact us

If you email us, we receive your email address, your name if you give it, and whatever you write. We use it to reply to you and to discuss possible work. We keep business correspondence for as long as it is commercially relevant, and delete it on request unless we are required to keep it.

Client data we handle as a service provider

When a client engages us, we are usually given access to their marketing and analytics systems. Examples include advertising accounts, web analytics, e-commerce platforms, and email marketing tools. Some of that data is personal data belonging to the client's own customers.

  • In that relationship, the client is the data controller and Sibonix acts as a processor.
  • We access this data only to perform the agreed services.
  • We do not sell it, and we do not use it to build our own marketing lists.
  • We return or delete it, and our access is revoked, at the end of the engagement or on the client's instruction.
  • Where required, this is governed by the written agreement between us and the client, which takes precedence over this policy for that data.

Third parties

We use established service providers to run our business, including hosting, email, cloud infrastructure, and the advertising and analytics platforms our clients already use. They process data on our instructions or under their own published terms. We do not sell personal data to anyone.

Legal basis

Where the GDPR applies, we rely on legitimate interests to operate and secure this website and to respond to business enquiries, on contract to deliver services to a client, and on the client's own legal basis where we act as a processor.

Your rights

Subject to applicable law, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict or object to our use of it, or provide it in a portable format. Write to yoav@sibonix.com and we will respond within 30 days. If we hold your data on behalf of a client, we will forward your request to that client.

Security

Access to client systems is limited to the people who need it, protected by multi-factor authentication where the platform supports it, and revoked when an engagement ends. Credentials are held in a dedicated secrets manager, not in documents or email.

Children

This website is not directed at children and we do not knowingly collect data from anyone under 16.

International transfers

Our providers operate globally, so data may be processed outside your country, including in the United States and the European Union. We use providers that offer recognised transfer safeguards.

Changes

We update this policy when our practices change. The date at the top always reflects the current version.

Contact

Sibonix
yoav@sibonix.com