Legal
Privacy policy
What we collect, what we do with it, and what we won't do. Written to comply with the Israeli Privacy Protection Law (1981), the Israeli Privacy Authority's 2017 Consent Decree, EU GDPR (Regulation 2016/679), and the ePrivacy Directive (2002/58/EC).
01Operator
This site is operated by דמיטרי צ׳ולקין (Dmitriy Chulkin), Osek Patur (Exempt Dealer), Israel. Contact: contact@aikraft.com. Postal address available upon written request. The operator is the data controller within the meaning of GDPR Art. 4(7) and the equivalent under Israeli law.
02What we collect
Reading this site (anyone).
- Server logs — IP address, user-agent, request URL, timestamp, referrer. Retained by Netlify (our CDN host) for up to 30 days under their standard log policy. Used solely to operate the site, debug, and detect abuse.
- Google Analytics (G-457L9MJ5QY) — page views, session duration, country-level location, anonymised. Only loaded after you click "Accept" on the cookie banner. If you decline (or never decide), no Google Analytics script is loaded and no GA cookies are set. IP anonymisation is enabled. Google Signals and ad personalisation are disabled.
- Local storage — your cookie-consent decision (a single string: "accept" or "decline"). No other localStorage usage.
Subscribing to a banner slot.
- PayPal data — when you click Subscribe, you are redirected to PayPal. Payment processing is performed entirely by PayPal under their privacy policy. We receive only: your PayPal subscription ID, the amount, the start date, and the slot identifier you bought. We never see your card data.
- Banner content you send us — the image / HTML / destination URL you email us for installation. Stored in our content management for as long as the banner is live, plus a 12-month archive for accounting.
- Email correspondence — the email address and content of any message you send to contact@aikraft.com. Retained for as long as needed to fulfil the request, then archived for accounting.
Suggesting a pain-point (the form on the home page).
- Suggestion text — what you write in the "what's the pain?" field. Stored by our form processor (Netlify Forms) for review. Used only to inform what we research next; never published with attribution.
- Email address (optional) — only if you provide it. Used solely to notify you once if and when the suggested page goes live, after which it is deleted. Never shared, never added to any marketing list, never used for any purpose other than that single notification.
- If you submit no email, we have no way to identify or contact you in connection with the suggestion. The submission is, in effect, anonymous.
Sharing a page on social media. Each painpoint page has a share bar at the end of section 01. The buttons are plain links to the share-compose pages of LinkedIn, X, WhatsApp, Telegram, or your email client. No third-party scripts and no tracking pixels are loaded by these buttons. The platforms only learn anything about you if you click — at which point you are interacting with them directly under their own privacy policies. We add UTM parameters (`utm_source=share&utm_medium=<platform>`) to outbound share URLs so we can see in our own analytics which platform brought a visitor back; UTM tags contain no personal data.
Listing-management contact (email).
- The contents of any email you send to contact@aikraft.com regarding a listing on bizpain.org — including your name, company name, the page slug, and the change you are requesting — are used solely to action your removal or correction and to reply to you. Email retained as long as the thread is active; deleted on resolution unless an active legal-retention obligation applies.
- We do not contact listed companies first; we respond to mail you initiate.
We do not collect: names, addresses, phone numbers, demographics, behavioural profiles, cross-site tracking, location finer than country, or any data you have not deliberately submitted.
03Lawful basis for processing
Under GDPR Art. 6(1):
- Server logs: legitimate interest (Art. 6(1)(f)) — operating and securing the site.
- Google Analytics: consent (Art. 6(1)(a)) — only loaded after you click Accept.
- Subscription data & banner content: performance of contract (Art. 6(1)(b)) — fulfilling your subscription.
- Accounting archive: legal obligation (Art. 6(1)(c)) — Israeli tax law requires retention of transaction records.
Equivalent grounds apply under Israeli Privacy Protection Law §11.
04Sharing
We share data only with:
- Netlify (USA) — hosting, CDN, and form-submission storage (the suggest-a-pain-point form). Standard server logs + form data sent through Netlify Forms.
- Google (USA / Ireland) — only if you accept analytics. Subject to Google's privacy policy.
- PayPal (Luxembourg / USA) — payment processing. Subject to PayPal's privacy policy.
- Israeli tax authorities — only as required by Israeli tax law for accounting records.
We do not sell, rent, share, or otherwise transfer personal data for marketing purposes. We do not use any data for cross-site tracking.
05Cross-border transfers
Some processors are based outside Israel and the EU/EEA (notably Netlify and Google in the USA). Where applicable, transfers rely on the EU-US Data Privacy Framework or the Standard Contractual Clauses (Commission Decision 2021/914) plus supplementary measures the operator deems adequate.
06Your rights
Under Israeli Privacy Protection Law §13–14B and GDPR Art. 12–22, you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion (subject to legal retention obligations)
- Restrict or object to processing
- Data portability (where the legal basis is consent or contract)
- Withdraw consent at any time (this will not affect lawful processing already performed)
- Lodge a complaint with the Israeli Privacy Protection Authority or your local EU supervisory authority
To exercise any of these, email contact@aikraft.com. We respond within 30 days (Israeli §13B) or sooner under GDPR.
07Cookies
This site uses one piece of localStorage (your cookie-consent decision) and, only if you accept analytics, the following Google Analytics cookies:
_ga — distinguishes anonymous users (2-year expiry)
_ga_457L9MJ5QY — Google Analytics 4 session state (2-year expiry)
That is the entire cookie inventory. No advertising cookies, no third-party tracking pixels, no fingerprinting. To revoke consent, click "Cookie settings" in the footer of any page.
08Outbound communications
bizpain.org does not send unsolicited commercial messages by email, SMS, contact form, messenger, or any other channel. We will only contact you in response to a message you initiate (e.g. a subscription you placed, an email you sent). This complies with Israeli Communications Law (1982) Amendment 40 and EU ePrivacy Directive Art. 13.
09Changes
We may update this policy. Material changes will be flagged on this page; the version date below is updated whenever the text changes.
Version: 2026-04-27 · v2.0