• EnglishEnglish
Confidentiality

Confidentiality & Data Handling

This page explains how Zahavi Digital Clarity generally handles confidential business information, diagnostic materials, personal information and account access during a written website, lead and customer journey diagnostic.

Last updated: July 22, 2026

A written Digital Clarity Diagnostic may involve non-public business information, analytics, website weaknesses, traffic information, customer journey details, internal processes and other project-specific materials.

This page describes Zahavi Digital Clarity's general approach to confidentiality, data minimisation, account access, third-party services, retention and information security.

It is not, by itself, a separately negotiated or signed Non-Disclosure Agreement, Data Processing Agreement, information-security agreement or other project-specific contract.

Where a formal NDA, DPA or special vendor agreement is required, it should be discussed and agreed before the relevant restricted information or access is provided.

1. Purpose of this page

Zahavi Digital Clarity provides written website, lead and customer journey diagnostic services.

Depending on the agreed scope, a client may provide information relating to:

  • the website and digital offer;
  • traffic sources and audience quality;
  • analytics and measurement;
  • SEO, indexing and organic visibility;
  • advertising context;
  • forms, buttons and lead-capture paths;
  • WhatsApp, phone, email, booking or checkout journeys;
  • lead handling and response processes;
  • customer journey and follow-up processes;
  • available conversion or customer-value information;
  • internal business processes;
  • other information reasonably relevant to the diagnostic.

The purpose of this page is to explain the general handling approach and help clients avoid sharing information that is not reasonably required.

2. This page is not a signed NDA or DPA

This page provides general information and forms part of the wider website policies.

It is not, by itself, a customised or separately signed:

  • Non-Disclosure Agreement;
  • Data Processing Agreement;
  • vendor security agreement;
  • information-security schedule;
  • cross-border data-transfer agreement;
  • other project-specific legal contract.

A separate agreement may be appropriate where a project involves:

  • highly confidential commercial information;
  • large datasets containing personal information;
  • customer, employee or lead databases;
  • CRM exports containing identifiable individuals;
  • regulated or especially sensitive information;
  • special security or data-location requirements;
  • information subject to third-party contractual restrictions.

Any requirement for a formal agreement should be raised and agreed before the relevant information is shared.

Default rule:

do not send passwords, payment-card information, unrestricted administrator access, government identification numbers, full customer databases or other high-risk information through the initial request form, regular email or WhatsApp.

3. Legal roles depend on the project

The legal role of each party in relation to personal information depends on the actual circumstances, purposes, instructions, systems and information involved.

This general page does not automatically determine that Zahavi Digital Clarity is acting as:

  • a controller or database owner;
  • a processor, holder or service provider;
  • a joint controller;
  • another legally defined data-handling role.

Where the project requires a formal allocation of privacy, security, processing or international-transfer responsibilities, that allocation should be documented in a separate written agreement.

Until such an agreement is in place, clients should avoid providing restricted datasets or unnecessary third-party personal information.

4. Confidential business information

Confidential business information may include non-public information supplied specifically for the diagnostic.

Depending on the project, this may include:

  • business strategy and internal priorities;
  • traffic and analytics reports;
  • SEO and indexing information;
  • advertising information;
  • website weaknesses and technical observations;
  • lead-flow and customer journey information;
  • form, booking or enquiry paths;
  • lead-handling and follow-up processes;
  • CRM or customer-data context;
  • sales or service processes;
  • commercial or financial context;
  • internal documents and screenshots;
  • diagnostic findings and working materials;
  • other information identified as confidential or reasonably understood to be confidential.

Sharing information for a diagnostic does not transfer ownership of the client's pre-existing information or business materials to Zahavi Digital Clarity.

5. General confidentiality approach

Zahavi Digital Clarity will use reasonable care when handling confidential business information.

Confidential information should be used only to the extent reasonably necessary to:

  • review the request;
  • define the proposed scope;
  • provide the agreed written diagnostic;
  • prepare findings and deliverables;
  • communicate with the client;
  • maintain reasonable project records;
  • protect systems and legal rights;
  • meet applicable legal obligations.

Zahavi Digital Clarity will not intentionally disclose confidential business information except where disclosure is:

  • authorised or requested by the client;
  • reasonably necessary to provide the agreed service;
  • made to a relevant service provider subject to appropriate obligations;
  • required by applicable law or lawful authority;
  • reasonably necessary to establish or protect legal rights;
  • reasonably necessary to investigate fraud, abuse or a security incident;
  • reasonably necessary to prevent serious harm.

6. Information that may not be confidential

Confidentiality generally does not apply to information that:

  • is already publicly available;
  • becomes public through no breach by Zahavi Digital Clarity;
  • was lawfully known before disclosure by the client;
  • is independently developed without using the client's confidential information;
  • is lawfully obtained from another source without confidentiality restrictions;
  • is released with the client's authorisation;
  • must be disclosed under applicable law or lawful authority.

Where legally permitted and reasonably practical, Zahavi Digital Clarity may notify the affected client before making a compulsory disclosure.

7. Data minimisation

Zahavi Digital Clarity aims to use only information reasonably relevant to the agreed diagnostic purpose.

Before sharing a document, screenshot, report or export, clients are encouraged to:

  • remove irrelevant columns or records;
  • blur names, email addresses and phone numbers;
  • redact private messages;
  • replace identifiable examples with summaries;
  • share aggregated information where sufficient;
  • limit the date range or scope of an export;
  • remove payment and identity information;
  • provide only the portion required for the diagnostic.

A typical written diagnostic usually does not require:

  • a complete customer or lead database;
  • a full CRM export;
  • full payment information;
  • bank information;
  • government identification numbers;
  • medical information;
  • children's personal information;
  • private conversations unrelated to the scope;
  • information about individuals who are not relevant to the diagnostic.

8. Information clients should not send

Clients should not send unnecessary sensitive or high-risk information through the website, regular email, WhatsApp or an unsecured link.

Avoid sending:

  • account passwords;
  • shared administrator credentials;
  • payment-card information;
  • bank or billing credentials;
  • government identification numbers;
  • medical or health information;
  • children's personal information;
  • complete customer, employee or lead databases;
  • private personal conversations unrelated to the project;
  • information that is not reasonably required for the agreed scope.
The safest default is:

share the minimum information reasonably needed to understand and diagnose the relevant business problem.

9. Account access and credentials

No account access, password, billing credential or administrator permission is required when submitting the initial request.

If access is reasonably required later, the platform, purpose, role and expected access period should be discussed separately.

Where technically available, the preferred access method is:

  • a provider-generated user invitation;
  • read-only access;
  • a limited user role;
  • temporary project-specific access;
  • access that the client can independently revoke.

Clients should avoid:

  • sharing a main administrator password;
  • sharing the account of another employee or contractor;
  • providing access to billing or payment functions;
  • granting permissions unrelated to the diagnostic;
  • leaving temporary access active after it is no longer required.

Multi-factor authentication should remain enabled where it is available and practical.

Clients are encouraged to review permissions and revoke temporary access after delivery.

10. Personal information about other people

Zahavi Digital Clarity does not request unnecessary personal information about customers, employees, leads, contractors or other individuals.

Where possible, screenshots, reports and examples should be:

  • anonymised;
  • redacted;
  • blurred;
  • aggregated;
  • summarised;
  • limited to information relevant to the scope.

If a client provides information about another person, the client remains responsible for having an appropriate right, permission or legal basis to provide it for the agreed purpose.

Zahavi Digital Clarity may:

  • ask for unnecessary personal information to be removed;
  • decline to receive an excessive dataset;
  • request a redacted or aggregated version;
  • pause analysis until an appropriate arrangement is agreed.

11. Third-party tools and service providers

Zahavi Digital Clarity may use professional tools and third-party providers to operate the website and support the diagnostic workflow.

Depending on actual use, provider categories may include:

  • website hosting and domain providers;
  • WordPress and relevant plugins;
  • form and email-delivery services;
  • email and communication providers;
  • video-call services where an optional walkthrough or project meeting is agreed;
  • analytics and tag-management providers;
  • SEO, testing and QA tools;
  • document, storage and productivity services;
  • payment or invoicing services where used;
  • professional advisers where reasonably required.

Providers may process information according to their own:

  • terms;
  • privacy policies;
  • security practices;
  • technical infrastructure;
  • contractual arrangements.

Information should be shared only to the extent reasonably required for the relevant purpose.

Where a client requires:

  • an approved-provider list;
  • specific vendor restrictions;
  • special data-location restrictions;
  • a formal DPA;
  • additional security terms;

those requirements should be agreed before restricted information is provided.

12. International processing and data locations

Some hosting, analytics, communication, cloud, document or professional-service providers may process or store information outside Israel or outside the client's country.

This may occur because a provider uses:

  • international infrastructure;
  • regional or global data centres;
  • international support teams;
  • cross-border subcontractors or service providers.

Where information is transferred internationally, Zahavi Digital Clarity aims to:

  • limit the transferred information to what is reasonably required;
  • use appropriate providers and contractual arrangements;
  • consider applicable privacy and transfer requirements;
  • avoid transferring unnecessary sensitive information.

Privacy and security standards may differ between countries.

Clients with specific cross-border requirements should raise them before sharing restricted information.

13. No sale of client information

Zahavi Digital Clarity does not sell client business information, customer or lead data, diagnostic materials, website information or confidential business information as a commercial data product.

Information may be used only for the purposes described in this page, the Privacy Policy, the Terms of Service, the agreed project scope and other lawful purposes applicable to the circumstances.

14. Reasonable security measures

Zahavi Digital Clarity aims to use reasonable, proportionate and practical measures intended to reduce the risk of:

  • unauthorised access;
  • unnecessary disclosure;
  • loss or misuse;
  • unauthorised alteration;
  • unauthorised destruction.

Depending on the circumstances, measures may include:

  • limiting information to what is reasonably needed;
  • limiting account, folder and document access;
  • preferring invitation-based and read-only permissions;
  • using available multi-factor authentication;
  • using provider security controls;
  • avoiding shared passwords;
  • limiting information sent to third-party tools;
  • reviewing and revoking temporary access;
  • deleting or anonymising unnecessary materials where appropriate;
  • maintaining relevant website systems and plugins.

No website, hosting provider, email system, messaging platform, cloud service, form tool or internet transmission can be guaranteed completely secure.

Zahavi Digital Clarity does not promise absolute security.

The commitment is to reasonable, proportionate and careful handling appropriate to the service and information involved.

15. Retention and deletion

Information and diagnostic materials may be retained only for as long as reasonably necessary for purposes such as:

  • reviewing and responding to requests;
  • providing the agreed written diagnostic;
  • maintaining project and communication records;
  • documenting the agreed scope and deliverables;
  • maintaining payment, accounting or tax records;
  • protecting systems and preventing abuse;
  • resolving disputes;
  • establishing or protecting legal rights;
  • meeting applicable legal obligations.

Different categories of information may be retained for different periods.

Information that is no longer reasonably required may be:

  • deleted;
  • anonymised;
  • redacted;
  • securely archived.

Accounting, transaction, legal or dispute-related records may need to be retained after other project materials can be removed.

Backup systems may retain limited copies until ordinary backup cycles are completed.

16. Return or deletion requests

A client may request the return, deletion or restriction of project materials held by Zahavi Digital Clarity.

A request will be considered subject to:

  • reasonable identity verification;
  • the agreed project scope;
  • applicable privacy and contractual requirements;
  • legitimate accounting or legal retention needs;
  • dispute or security records;
  • technical feasibility;
  • ordinary backup cycles;
  • the rights and information of other people.

Deleting a working copy does not necessarily require deletion of a record that must be retained for accounting, legal, security or dispute-resolution purposes.

Requests may be sent to:

hello@zahavidigitalclarity.com

17. Security incidents

If Zahavi Digital Clarity becomes aware of a suspected security incident involving information under its responsibility, reasonable steps may be taken to:

  • understand what occurred;
  • limit continuing exposure where reasonably possible;
  • secure affected accounts, documents or access;
  • work with relevant service providers;
  • preserve relevant records;
  • assess the type of information involved;
  • take reasonable corrective action;
  • notify an authority or affected person where legally required.

Clients should promptly report any suspected issue involving:

  • access granted for the diagnostic;
  • information shared for the project;
  • a lost or compromised account;
  • an unintended disclosure;
  • a suspicious message or access request.

Zahavi Digital Clarity is not responsible for an incident caused solely by:

  • the client's own systems;
  • a compromised client account;
  • unsafe password sharing by the client;
  • access granted by the client to another party;
  • a third-party platform outside reasonable control;
  • information sent through an unsafe method against clear instructions.

Nothing in this section excludes responsibility that cannot legally be excluded.

18. Case studies, examples and testimonials

Zahavi Digital Clarity will not publish:

  • the client's name;
  • the client's logo;
  • an identifiable testimonial;
  • exact confidential information;
  • an identifiable case study;

without the client's prior written permission.

Anonymised or generalised lessons may be used only where they do not reasonably:

  • identify the client;
  • reveal confidential information;
  • disclose unnecessary personal information;
  • misrepresent the work or outcome.

Anonymisation may include:

  • removing the business name;
  • describing only the general industry;
  • removing exact figures;
  • generalising technical details;
  • removing identifying circumstances.
The purpose of a case study is to explain the nature of the work without exposing information that should reasonably remain private.

19. Sharing delivered materials

The client may share the written diagnostic report, action plan and related deliverables with relevant:

  • employees;
  • developers;
  • designers;
  • marketers;
  • SEO or analytics specialists;
  • CRM specialists;
  • lawyers or accountants;
  • accessibility or cybersecurity specialists;
  • other relevant contractors or advisers.

The client should use reasonable care when sharing materials containing:

  • confidential business information;
  • analytics or screenshots;
  • lead or customer information;
  • access-related information;
  • sensitive operational context.

Zahavi Digital Clarity is not responsible for how another person:

  • interprets the materials;
  • changes or simplifies them;
  • removes relevant context;
  • discloses them to another party;
  • implements the recommendations.

20. Privacy and data-handling requests

Subject to applicable law and the circumstances, a person may contact Zahavi Digital Clarity regarding personal information relating to them.

This may include a request concerning:

  • access or review;
  • correction or updating;
  • deletion where applicable;
  • withdrawal of consent where processing depends on consent;
  • how information is used or shared;
  • a suspected security concern.

Requests may be subject to:

  • reasonable identity verification;
  • applicable legal requirements;
  • legitimate retention needs;
  • accounting, tax or legal obligations;
  • technical feasibility;
  • the privacy and rights of other people.

Requests may be sent to:

hello@zahavidigitalclarity.com

21. Relationship with other documents

This page should be read together with:

  • the Terms of Service;
  • the Privacy Policy;
  • the Refund & Cancellation Policy;
  • the Diagnostic Disclaimer;
  • the Cookie & Analytics Notice;
  • the agreed written scope for the project.

A project may also be subject to a:

  • proposal or scope confirmation;
  • separate NDA;
  • Data Processing Agreement;
  • vendor or security agreement;
  • other project-specific written agreement.

Where a project-specific agreement clearly conflicts with this general page, the more specific agreement may apply to that conflict, subject to mandatory applicable law.

22. Governing law and mandatory rights

This Confidentiality & Data Handling page is governed by the laws of the State of Israel, unless mandatory applicable law requires otherwise.

Nothing in this page is intended to remove, restrict or waive a mandatory privacy, confidentiality, data-protection or other legal right that cannot legally be excluded.

If a mandatory legal requirement conflicts with this page, the mandatory requirement applies to the extent required by law.

23. Language and translations

This page may be available in English, Russian and Hebrew for convenience and accessibility.

If different language versions conflict, the English version will generally apply, unless:

  • a project-specific written agreement states otherwise;
  • mandatory applicable law requires another result.

Clients should read the version they understand best before providing information, access or project materials.

24. Changes to this page

Zahavi Digital Clarity may update this page to reflect changes in:

  • services and business processes;
  • website functionality;
  • professional tools and providers;
  • security practices;
  • legal or regulatory requirements.

The date at the top of the page identifies the current version.

An updated website version does not automatically change an existing project-specific agreement or remove rights that arose under an earlier agreement.

25. Contact

For questions concerning:

  • confidentiality;
  • data handling;
  • account access;
  • NDA or DPA requirements;
  • privacy requests;
  • deletion or return requests;
  • security concerns;

please contact:

hello@zahavidigitalclarity.com

This page describes the general confidentiality and data-handling approach of Zahavi Digital Clarity. It does not replace individual legal advice or a separately agreed NDA, DPA or security agreement where one is required.

Zahavi Digital Clarity
Written Website & Customer Journey Diagnostic

Written diagnostic analysis connecting technical website health, SEO, functionality, analytics, offer clarity and lead handling — so business owners can understand where the digital journey weakens, what should be addressed first and what can wait.

Contact hello@zahavidigitalclarity.com

Pages

Home Digital Clarity Diagnostic How It Works Case Studies FAQ Glossary Request a Written Diagnostic

Legal

Terms of Service Privacy Policy Refund & Cancellation Policy Diagnostic Disclaimer Confidentiality & Data Handling Cookie & Analytics Notice
© 2026 Zahavi Digital Clarity. All rights reserved.
Contact: hello@zahavidigitalclarity.com
Accessibility Adjustments

Powered by OneTap

How long do you want to hide the toolbar?
Hide Toolbar Duration
Select your accessibility profile
Vision Impaired Mode
Enhances website's visuals
Seizure Safe Profile
Clear flashes & reduces color
ADHD Friendly Mode
Focused browsing, distraction-free
Blindness Mode
Reduces distractions, improves focus
Epilepsy Safe Mode
Dims colors and stops blinking
Content Modules
Font Size

Default

Line Height

Default

Color Modules
Orientation Modules