PRIVACY POLICY
1. Identity of the Data Controller
This website https://www.tkoatmimim.com/ (the “Website”) is operated by the educational project Tomchei Tmimim.
Donations are processed through a registered Israeli non-profit organization (Amuta), which acts as the legal recipient of funds.
For GDPR purposes:
-
The Website acts as Data Controller for contact and communication data.
-
The Amuta acts as Data Controller for donation-related financial data.
Contact email: [insert official email]
Country of operation: Israel
2. Legal Basis for Processing (GDPR Art. 6)
We process personal data based on:
-
Consent (Art. 6(1)(a)) – newsletter, contact forms
-
Contractual necessity (Art. 6(1)(b)) – donation processing
-
Legal obligation (Art. 6(1)(c)) – financial compliance
-
Legitimate interest (Art. 6(1)(f)) – website security, fraud prevention
We do not sell personal data.
3. Categories of Personal Data
We may collect:
-
Full name
-
Email address
-
Phone number
-
Country of residence
-
Donation details (processed by third-party provider)
-
IP address and browser metadata
-
Cookies and analytics identifiers
We do not store credit card details.
Payment processing is performed by certified PCI-DSS compliant providers.
4. International Data Transfers
Because our audience is global, data may be processed:
-
In Israel
-
In the European Union
-
In the United States
Where required, transfers are protected by:
-
Standard Contractual Clauses (SCCs)
-
Adequacy decisions (where applicable)
-
Reputable infrastructure providers (e.g., Google, hosting providers)
-
5. Data Retention
We retain data only for:
-
The duration necessary for the stated purpose
-
Legal accounting requirements
-
Fraud prevention and security monitoring
After expiration, data is securely deleted or anonymized.
6. Your Rights Under GDPR
If you are located in the EU/EEA, you have the right to:
-
Access your data
-
Rectify inaccuracies
-
Request erasure (“right to be forgotten”)
-
Restrict processing
-
Data portability
-
Withdraw consent at any time
Requests may be sent to: [email]
We respond within 30 days.
7. Security Measures
We implement:
-
SSL/TLS encryption
-
Secure hosting infrastructure
-
Limited access controls
-
Fraud prevention mechanisms
-
Bot and spam mitigation systems
Security systems are used solely to protect users and the integrity of donations.
8. Automated Decision-Making
We do not perform automated profiling or automated decision-making that produces legal effects.
9. Updates
We may update this policy periodically. The latest version will always be available on this page.
