Privacy Policy

Last Updated: August 4, 2026  

This Privacy Policy describes Our policies and procedures regarding the collection, use, disclosure, storage, retention, protection, and processing of Your information when You use the Service. It also explains Your privacy rights and how applicable privacy laws protect You.

We use Your Personal Data to provide, maintain, secure, and improve the Service. By using the Service, You acknowledge that You have read and understood this Privacy Policy and agree to the collection and use of information in accordance with this Privacy Policy.

 

Interpretation and Definitions

Interpretation

The words for which the initial letter is capitalized have meanings defined under the following conditions. These definitions shall have the same meaning whether they appear in singular or plural form.

 

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for You to access Our Service or parts of Our Service.

Company (referred to as either “the Company”, “We”, “Us”, or “Our”) refers to HEQA Security, HaMa’ayan St 2, Modi’in.

Cookies means small text files placed on Your computer, mobile device, or any other device by a website. Cookies contain information regarding Your browsing activity and may be used for authentication, security, website functionality, analytics, and user preferences.

Country refers to Israel.

Device means any device capable of accessing the Service, including computers, smartphones, tablets, or similar devices.

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on Personal Data including collection, recording, storage, organization, use, disclosure, transfer, deletion, or destruction.

Service refers to the Website.

Service Provider means any third-party organization or individual engaged by the Company to support, operate, host, maintain, monitor, or improve the Service or to process Personal Data on behalf of the Company.

Usage Data means information collected automatically when using the Service or generated by the Service infrastructure itself.

Website refers to HEQA Security, accessible at:

https://heqa-sec.com

You means the individual accessing or using the Service, or the company or legal entity on whose behalf such individual accesses the Service.

 

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide certain personally identifiable information that may be used to contact or identify You.

Such information may include, but is not limited to:

  • First Name 
  • Last Name 
  • Email Address 
  • Telephone Number (where applicable) 
  • Company Name (where applicable) 
  • Job Title (where applicable) 
  • Information submitted through contact forms 
  • Information provided during communications with the Company 

Providing Personal Data is voluntary; however, certain information may be required in order to provide requested services or respond to inquiries.

 

Usage Data

Usage Data is collected automatically whenever You access or interact with the Service.

Usage Data may include:

  • Internet Protocol (IP) Address 
  • Browser Type 
  • Browser Version 
  • Operating System 
  • Device Information 
  • Pages Visited 
  • Date and Time of Visit 
  • Time Spent on Pages 
  • Referring Website 
  • Unique Device Identifiers 
  • Diagnostic Information 
  • Clickstream Information 
  • Error Logs 
  • Security Logs 

When accessing the Service from a mobile device, We may also collect:

  • Mobile Device Type 
  • Mobile Device Identifier 
  • Mobile Operating System 
  • Mobile Browser Type 
  • Mobile IP Address 
  • Mobile Device Diagnostic Information 

This information helps Us maintain the security, availability, functionality, and performance of the Service.

 

Tracking Technologies and Cookies

We use Cookies and similar technologies to improve website functionality, protect our systems, analyze website usage, and enhance the user experience.

Tracking technologies may include:

  • Browser Cookies 
  • Session Cookies 
  • Persistent Cookies 
  • Flash Cookies 
  • Web Beacons 
  • Pixels 
  • Scripts 
  • Local Storage Technologies 

These technologies assist Us in:

  • Maintaining website functionality 
  • Authenticating users 
  • Preventing fraud 
  • Detecting malicious activity 
  • Improving website performance 
  • Understanding visitor behavior 
  • Enhancing user experience 
  • Supporting website security 

 

Browser Cookies

A Cookie is a small text file stored on Your Device.

You may configure Your browser to:

  • Accept Cookies 
  • Reject Cookies 
  • Delete previously stored Cookies 
  • Notify You before Cookies are stored 

Please note that disabling certain Cookies may affect the availability or functionality of parts of the Service.

 

Flash Cookies

Certain features of the Service may use Flash Cookies (Local Shared Objects) to store user preferences or website functionality.

Flash Cookies are managed separately from standard browser cookies.

Information regarding Flash Cookie management is available from Adobe’s official documentation.

 

Web Beacons

Certain sections of Our Website and electronic communications may contain Web Beacons (also referred to as pixel tags, clear GIFs, or single-pixel GIFs).

These technologies enable Us to:

  • Measure Website Usage 
  • Count Website Visitors 
  • Analyze Email Effectiveness 
  • Improve Website Performance 
  • Maintain Service Integrity 

 

Types of Cookies We Use

Essential Cookies

Purpose:

These Cookies are required for the Website to operate correctly.

They support:

  • Authentication 
  • Session Management 
  • Security Controls 
  • Fraud Prevention 
  • Website Functionality 

These Cookies cannot be disabled through the Website because they are necessary for the operation of the Service.

 

Functionality Cookies

These Cookies remember:

  • Language Preferences 
  • User Preferences 
  • Website Settings 
  • Other personalization options 

They improve the user experience by reducing the need to repeatedly configure preferences.

Use of Your Personal Data

The Company may use Personal Data for one or more of the following purposes:

To Provide and Maintain Our Service

To provide, operate, maintain, and improve the functionality, availability, security, and performance of our Website and Services, including monitoring the usage of our Service.

 

To Manage Your Account

To create, maintain, and administer Your Account and provide You with access to the functionality of the Service.

 

To Perform Contractual Obligations

To fulfill contractual obligations arising from agreements entered into between You and the Company, including providing cybersecurity consulting services, assessments, professional support, and related activities.

 

To Communicate With You

To communicate with You regarding:

  • Your inquiries 
  • Requested services 
  • Security notifications 
  • Technical updates 
  • Administrative notices 
  • Service announcements 
  • Changes affecting the Service 

Communications may be sent via email, telephone, SMS, or other electronic communication channels where appropriate.

 

To Respond to Requests

To receive, process, and respond to requests, questions, support inquiries, or other communications submitted by You.

 

To Improve Our Services

To evaluate and improve:

  • Website functionality 
  • User experience 
  • Service quality 
  • Customer support 
  • Website performance 
  • Security controls 

 

Website Analytics

To understand how visitors interact with our Website, including:

  • Website traffic 
  • Popular content 
  • Navigation patterns 
  • Performance metrics 
  • Technical issues 

Where possible, aggregated or anonymized information is used for analytical purposes.

 

Security and Fraud Prevention

We may process Personal Data in order to:

  • Detect unauthorized activity 
  • Prevent fraud 
  • Prevent abuse of our Services 
  • Detect cybersecurity threats 
  • Investigate security incidents 
  • Protect the confidentiality, integrity, and availability of our systems 
  • Comply with information security obligations 

 

Marketing Communications

Where permitted by applicable law, We may send newsletters, event invitations, security advisories, white papers, or information regarding products and services that may be of interest to You.

You may opt out of receiving marketing communications at any time by following the unsubscribe instructions included in such communications or by contacting Us directly.

 

Business Transactions

Your Personal Data may be processed in connection with:

  • Mergers 
  • Acquisitions 
  • Corporate restructuring 
  • Asset transfers 
  • Financing transactions 

If ownership of the Company changes, Personal Data may be transferred as part of that transaction, subject to applicable legal requirements.

 

Compliance With Legal Obligations

The Company may process Personal Data where necessary to:

  • Comply with applicable laws 
  • Respond to lawful requests 
  • Meet regulatory obligations 
  • Enforce contractual rights 
  • Protect legal interests 

 

Sharing and Disclosure of Personal Data

The Company may share Personal Data only where necessary and only for legitimate business or legal purposes.

Personal Data may be shared with:

Service Providers

Third-party providers supporting:

  • Website hosting 
  • Cloud infrastructure 
  • Security monitoring 
  • Analytics 
  • Email communications 
  • Technical support 
  • Professional services 

These providers process Personal Data only on behalf of the Company and only for authorized purposes.

 

Affiliates

Personal Data may be shared with affiliated entities under common ownership or control where necessary for legitimate business purposes and subject to this Privacy Policy.

 

Business Partners

Information may be shared with trusted business partners solely to provide products, services, or events requested by You.

 

Legal Authorities

Personal Data may be disclosed where required:

  • By law 
  • Court order 
  • Government authority 
  • Regulatory investigation 
  • Law enforcement request 

 

Corporate Transactions

Personal Data may be transferred during:

  • Mergers 
  • Acquisitions 
  • Business sales 
  • Bankruptcy proceedings 
  • Corporate restructuring 

Affected individuals will be notified where required by applicable law.

 

With Your Consent

The Company may disclose Personal Data for any additional purpose with Your explicit consent.

 

No Sale of Personal Data

The Company does not sell Personal Data to third parties.

 

Cookies Policy

Our Website uses Cookies and similar technologies to improve functionality, enhance security, analyze website usage, and improve the overall user experience.

Cookies may be categorized as:

Essential Cookies

These Cookies are required for:

  • Website operation 
  • User authentication 
  • Session management 
  • Security functionality 

Without these Cookies, portions of the Website may not function properly.

 

Functional Cookies

These Cookies remember:

  • User preferences 
  • Language settings 
  • Display preferences 
  • Website customization 

Analytics Cookies

Analytics Cookies help us understand:

  • Website performance 
  • Visitor behavior 
  • Website traffic 
  • Popular content 
  • User interaction 

This information is generally collected in an aggregated form.

 

Security Cookies

Security Cookies assist in:

  • Fraud prevention 
  • Attack detection 
  • Session protection 
  • Security monitoring 

 

Managing Cookies

Users may configure their browsers to:

  • Accept Cookies 
  • Reject Cookies 
  • Delete existing Cookies 
  • Receive notifications before Cookies are stored 

Disabling certain Cookies may reduce Website functionality.

Instructions for managing Cookies are available within your browser’s documentation.

 

Third-Party Cookies

The Website may use trusted third-party technologies for:

  • Website analytics 
  • Website performance 
  • Embedded content 
  • Security services 

These third parties operate under their own privacy policies.

Users are encouraged to review the privacy policies of those third-party providers.

 

Do Not Track (DNT)

Some web browsers provide a Do Not Track (“DNT”) feature that allows users to indicate their privacy preferences.

At present, there is no universally accepted standard governing how websites should respond to Do Not Track browser signals.

Accordingly, the Website does not currently respond differently to browser Do Not Track requests.

If an industry-standard mechanism becomes available in the future, this Privacy Policy may be updated accordingly.

Retention of Your Personal Data

The Company retains Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including providing Services, maintaining business operations, complying with legal obligations, resolving disputes, enforcing agreements, and protecting the legitimate interests of the Company.

The length of time Personal Data is retained depends on several factors, including:

  • The nature of the Personal Data. 
  • The purpose for which it was collected. 
  • Applicable legal or regulatory retention requirements. 
  • Contractual obligations. 
  • Legitimate business needs. 

Usage Data is generally retained for a shorter period unless it is required to:

  • Improve the security of the Service. 
  • Detect or investigate security incidents. 
  • Comply with legal obligations. 
  • Resolve technical issues. 
  • Protect against fraud or abuse. 

When Personal Data is no longer required, it will be securely deleted, anonymized, or otherwise disposed of using commercially reasonable methods designed to prevent unauthorized access or recovery.

 

Transfer of Your Personal Data

Your information, including Personal Data, may be processed at the Company’s offices and by authorized Service Providers located in different jurisdictions.

This means that Personal Data may be transferred to and maintained on systems located outside Your country of residence where data protection laws may differ from those applicable in Your jurisdiction.

Where Personal Data is transferred internationally, the Company will take commercially reasonable measures to ensure that appropriate safeguards are implemented to protect Personal Data in accordance with applicable privacy laws.

Such safeguards may include:

  • Contractual confidentiality obligations. 
  • Security controls. 
  • Access restrictions. 
  • Secure transmission methods. 
  • Other lawful transfer mechanisms where applicable. 

Your submission of Personal Data and continued use of the Service constitutes Your acknowledgment that such transfers may occur where necessary for the operation of the Service.

 

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, financing, restructuring, or sale of assets, Personal Data may be transferred as part of that transaction.

Where required by applicable law, affected individuals will be notified before Personal Data becomes subject to a different Privacy Policy.

 

Legal Requirements

The Company may disclose Personal Data when required to do so by law or in response to valid requests from public authorities, regulatory agencies, courts, or law enforcement authorities.

 

Protection of Rights

The Company may disclose Personal Data where necessary to:

  • Comply with legal obligations. 
  • Protect and defend the rights or property of the Company. 
  • Investigate suspected fraud or unlawful activity. 
  • Detect or respond to cybersecurity incidents. 
  • Protect the safety of users or the public. 
  • Protect against legal liability. 

 

Security of Your Personal Data

The Company is committed to protecting Personal Data through the implementation of commercially reasonable administrative, technical, and organizational security measures designed to reduce the risk of unauthorized access, disclosure, alteration, loss, misuse, or destruction.

Depending on the nature of the information processed, security measures may include:

  • Role-based access controls. 
  • User authentication mechanisms. 
  • Encryption of data during transmission where appropriate. 
  • Secure hosting environments. 
  • Security monitoring and logging. 
  • Regular software updates. 
  • Vulnerability management. 
  • Backup and recovery procedures. 
  • Incident response processes. 
  • Employee awareness and confidentiality obligations. 

While the Company continuously works to protect Personal Data using industry-accepted security practices, no method of electronic transmission or storage can be guaranteed to be completely secure.

Accordingly, the Company cannot guarantee the absolute security of Personal Data.

Your Privacy Rights

Depending on Your location and applicable law, You may have certain rights regarding Your Personal Data.

These rights may include:

Right of Access

You may request confirmation regarding whether the Company processes Your Personal Data and request access to such information.

 

Right to Rectification

You may request correction of inaccurate or incomplete Personal Data.

 

Right to Erasure

Where permitted by law, You may request deletion of Your Personal Data.

Certain legal obligations may require the Company to retain specific information.

 

Right to Restrict Processing

You may request that processing of Your Personal Data be restricted under certain circumstances.

 

Right to Object

Where applicable, You may object to the processing of Personal Data based on legitimate interests.

 

Right to Withdraw Consent

Where processing is based upon consent, You may withdraw that consent at any time.

Withdrawal of consent does not affect processing carried out before consent was withdrawn.

 

Right to Data Portability

Where applicable, You may request a copy of Your Personal Data in a structured, commonly used, and machine-readable format.

 

Right to Lodge a Complaint

If You believe that the Company has not handled Your Personal Data appropriately, You may lodge a complaint with the applicable supervisory authority in Your jurisdiction.

 

Exercising Your Rights

Requests regarding Personal Data may be submitted using the contact information provided at the end of this Privacy Policy.

The Company may request additional information to verify Your identity before responding to a request.



Children’s Privacy

The Service is not intended for individuals under the age of 13, and the Company does not knowingly collect Personal Data from children under the age of 13.

If the Company becomes aware that Personal Data has been collected from a child without appropriate authorization where required by law, reasonable steps will be taken to delete such information as soon as practicable.

Parents or legal guardians who believe that their child has provided Personal Data should contact the Company immediately.

 

Links to Other Websites

The Website may contain links to third-party websites that are not operated or controlled by the Company.

The Company is not responsible for the privacy practices, security, or content of third-party websites.

Users are encouraged to review the privacy policies of any external websites they visit.

 

Changes to this Privacy Policy

The Company may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, technologies, or services.

When material changes are made, the updated Privacy Policy will be published on this page together with the revised “Last Updated” date.

Where required by applicable law, additional notice may be provided through the Website or other appropriate communication channels.

Users are encouraged to review this Privacy Policy periodically.

 

Contact Us

If You have any questions regarding this Privacy Policy or wish to exercise any of Your privacy rights, You may contact the Company using one of the following methods:

HEQA Security

HaMa’ayan St 2, Modi’in, Israel

Website

https://heqa-sec.com

Contact Page

https://heqa-sec.com/contact/