Privacy policy

Privacy policy for SEOH websites, tools, and services

This policy explains how Menashe Avramov, trading as SEOH, handles personal data across the public website, PWA and mobile shell, forms, planning and sharing tools, client portal, service delivery, support, analytics, automation, and communication channels.

Privacy policy

Privacy policy for SEOH websites, tools, and services

Purpose-limited collection

SEOH collects the contact, business, service, account, content, preference, security, and technical data needed for a requested interaction, an engagement, site operation, or a consented feature.

Consent and channel control

Non-essential analytics require the visitor's choice. Accepting these terms or sending a service enquiry is not consent to optional marketing, SMS, WhatsApp, push, or social-media distribution.

Controlled access and lifecycle

Access is limited to authorized people and configured providers. Data is retained by purpose, subject to deletion, security, legal-hold, suppression, and backup rules described below.

Privacy policy

Privacy policy

This policy explains how Menashe Avramov, trading as SEOH, handles personal data across the public website, PWA and mobile shell, forms, planning and sharing tools, client portal, service delivery, support, analytics, automation, and communication channels.

Who is responsible and what this policy covers

Menashe Avramov, trading as SEOH, is the controller for the public website and SEOH's own business administration. The contact address is 5 HaGefen Street, Ramla 7251205, IL and the privacy email is [email protected]. For client campaigns, white-label work, or systems operated under a client's instructions, the signed scope or data-processing agreement may instead make the client the controller and SEOH its processor. This policy covers the public and localized pages, forms and gated actions, pricing and resource pages, calculators and funnel-planning tools, shared-plan links, portfolio and partner links, PWA and mobile shell, client portal, support and cancellation flows, APIs and MCP or agent interfaces, lawful 18+ service areas, and work delivered under an SEOH engagement.

Data you provide directly

Depending on the interaction, SEOH may receive your name, email address, telephone or messaging number, organization, role, website, market, service area, preferred language, enquiry source, requested service, budget or planning range, timing, compliance and accessibility needs, consent and communication choices, support or cancellation request, and the contents of messages. If work proceeds, data may also include proposal and contract details, billing and payment-reconciliation information, project instructions, audience and campaign material, access details provided through an approved secure channel, files, images, audio, video, documents, prompts, feedback, approvals, deliverables, and correspondence. Do not send passwords, special-category data, private customer lists, or regulated material unless the agreed service requires it and SEOH has approved a suitable transfer method.

Website, device, security, and attribution data

The website and its infrastructure may process IP and network metadata, approximate location or bot and abuse signals derived from IP, date and time, requested URL, locale, referrer, campaign and partner parameters, browser, device, operating system, app surface, rate-limit and security events, server and application logs, error details, and response status. Essential browser storage can remember the consent decision and lawful 18+ gate, hold a short-lived PWA share receipt, mark a granted push-subscription synchronization attempt for the browser session, and cache localized public pages and assets for offline use. Optional preference storage can remember theme, persona, audience, scope, draft, planner, and game-display choices only after preference consent. Analytics session, visit, attribution, QA, and provider identifiers are available only after analytics consent, except that development-only QA tooling is not a public analytics purpose. Supabase can set provider-generated authentication cookies when an account or portal feature is enabled. The synchronized Cookie Policy names these items, their purposes, and their known lifecycles. Public partner or referral links may carry attribution parameters so SEOH can understand the source of a visit or engagement. Essential security and request processing do not depend on analytics consent.

Calculators, plans, shares, resources, and content

Calculators and planning tools may process the answers and business assumptions entered to generate an estimate, plan, report, download, or shareable link. A shared link can be opened by anyone who receives it, so it must not contain secrets or sensitive personal data. Shared-plan records use private application storage, but a fixed automatic expiry and self-service revocation path are not yet guaranteed; contact SEOH to request removal. Resource downloads, blog, portfolio, pricing, and comparison pages may create ordinary request logs and, after consent, analytics events. Generated plans and estimates are informational and are not a binding proposal.

Portal, accounts, documents, and application records

If portal or account features are enabled for you, SEOH may process authentication and account identifiers, authorized organization and role, sessions, sign-in and security events, project and service records, documents, approvals, notification preferences, and audit history. Supabase-backed application domains use access controls and row-level authorization where implemented. You are responsible for protecting credentials and for limiting portal access to authorized users. Some product domains, including a broader WhatsApp workspace, exist in the application model but do not by themselves mean that provider delivery or every modeled data field is active.

Enquiries, CRM recovery, and internal automation

A form or gated-action submission may be stored in a private recovery receipt so the request can be retried, deduplicated, audited, or recovered if a downstream service is temporarily unavailable. Guarded orchestration paths may route an approved data subset to a configured CRM and consent or suppression system. A particular connector is not an active recipient unless it is deployed for that interaction. Recovery, CRM, and project records are retained only for the configured operational or legal purpose and are then deleted, anonymized, or restricted subject to applicable accounting, dispute, security, and legal duties. Internal automation can classify or route a request, but SEOH does not use this site to make legal or similarly significant decisions about a person solely by automated means.

Cookies, analytics, replay, and browser tracking

PostHog Cloud EU is the active non-essential analytics processor only when its deployment flags are enabled and the visitor accepts analytics. It may receive page and route events, referrers, campaign parameters, consented interaction and form metadata, clicks, dead clicks, scroll and heatmap behavior, Web Vitals, performance attribution, browser errors, device signals, and masked session replay. IP anonymization is enabled; text and inputs are masked; images are blocked; and canvas capture, console-log capture, and request or response headers and bodies are disabled in the current client configuration. Auth-token query parameters are redacted, and SEOH's manual marketing-event bridge strips direct email, phone, company, and message-body values. The current configuration creates PostHog person or device profiles from consented identifiers. Analytics events are retained for 12 months and replay for 30 days. Browser identifiers may remain until cleared or expired; withdrawing analytics consent stops future site capture but does not promise immediate deletion of every identifier already held in browser or provider storage. Google Analytics 4 is reserved but not active unless SEOH later enables its consent-gated tag and updates the disclosure where required. Google advertising-storage, advertising-user-data, and advertising-personalization signals remain denied even when a visitor accepts the site's current optional categories. Mautic browser tracking is inactive unless SEOH separately enables both its technical flag and its privacy-approval flag and the visitor accepts marketing storage; enabling browser tracking would not by itself authorize a Mautic campaign send.

Service messages, optional marketing, and suppression

SEOH may use the contact route you choose to reply to an enquiry, administer a contract, send a requested document, handle security or service notices, and process support, cancellation, or rights requests. Optional marketing requires the consent or other lawful permission applicable to the channel and region, and an opt-out does not prevent necessary service messages. Consent records, objections, and suppression entries may be retained after other data is deleted so SEOH can continue honoring the choice. Accepting the Terms of Service is never treated as marketing consent.

Email, SMS, WhatsApp, push, and social-channel status

The infrastructure includes guarded or prepared paths for Mautic browser tracking and campaigns, Novu notifications, WhatsApp Cloud, WAHA, Twilio SMS, Postal email delivery, browser push, and Postiz social publishing. Those systems are not all active data recipients or delivery channels. Mautic browser tracking requires separate technical enablement, privacy approval, and visitor marketing consent; automated Mautic sends require a further operational authorization and are not currently authorized. The current operating boundary also does not authorize Novu external fan-out, WhatsApp provider sends, SMS delivery, Postal delivery, or Postiz publication or scheduling. A WhatsApp, social, email, or telephone link you choose to open is handled by that external provider under its own terms. Browser-push subscriptions, where the feature is explicitly enabled and permission is granted, can include the push endpoint and encryption keys, locale, route, source, user agent, and timestamps. A provider-expired endpoint can be removed, and you may request deletion, but no universal self-service subscription deletion or fixed age-based expiry is promised until that lifecycle control is implemented.

AI, synthetic media, APIs, and agent interfaces

SEOH may use AI-assisted tools to draft, translate, audit, classify, summarize, research, generate synthetic media, or support an approved client workflow. Inputs can include project instructions and content supplied for that purpose. SEOH applies human review to public claims and consequential deliverables and does not permit AI assistance to create fake evidence, impersonation, unlawful likeness use, or hidden instructions. API and MCP or agent interfaces can process credentials, requests, tool inputs, outputs, rate-limit data, and audit events. The specific model or external provider, data-use setting, retention, and transfer terms must be approved for an engagement before confidential or personal data is sent to it.

Purposes and legal bases

SEOH processes data to provide requested information and take steps before a contract; perform and administer an engagement; operate, secure, troubleshoot, and improve the site and services; preserve consent and suppression choices; prevent fraud and abuse; keep business, tax, and accounting records; establish or defend legal claims; and comply with law. Depending on the data, location, and interaction, the basis is the requested pre-contract step or contract, consent, a legal obligation, or SEOH's legitimate interests in secure service operation and business administration where those interests are not overridden by individual rights. Optional analytics, replay, push permission, and optional marketing use consent where required. You may withdraw consent prospectively without affecting earlier lawful processing.

Recipients, processors, and disclosures

Access may be given to authorized SEOH personnel, advisers, and providers that need the data for the stated purpose. Technical recipient categories that may apply to current features include Vercel hosting and private Blob storage, Cloudflare edge and security transport as configured, PostHog Cloud EU analytics, and Supabase application database and authentication where portal features are used. Guarded Activepieces and ERPNext integration paths exist, but neither is represented as a recipient for a particular submission unless the deployed workflow, payload, and retention settings have been verified for that use. Banks, accountants, lawyers, regulators, courts, fraud-prevention services, or a successor business may receive limited data when necessary and lawful. Dormant or default-off marketing providers are not treated as active recipients merely because connector code or credentials exist. SEOH does not authorize the current infrastructure to sell personal data, distribute contact lists, or run cross-context behavioral advertising; a material change requires a fresh purpose, provider review, consent control, and policy update where applicable.

Locations and international transfers

SEOH operates from Israel and can serve clients internationally. Providers may store or access data in Israel, the European Economic Area, the United States, or another location configured for the service. PostHog is configured for its EU cloud. Before SEOH activates a processor or transfer for personal data, it verifies the provider entity, region, contract and data-processing terms, subprocessors, and any safeguard required by applicable law, such as an adequacy basis, standard contractual clauses, or another recognized mechanism. A processor's public availability in the codebase is not confirmation that a transfer is active.

Retention schedule and deletion criteria

PostHog analytics events are retained for 12 months and session replays for 30 days. Recovery-receipt and CRM periods follow the confirmed deployed settings and the purpose for which the record is used; application-code defaults are not treated as proof of the live period. Browser consent, preference, and adult-gate items use the periods shown in the cookie table or remain until cleared. Enquiry, CRM, portal, project, invoice, contract, support, consent, suppression, security, and audit records are retained for the active purpose and then for the period reasonably needed for accounting, warranty, dispute, fraud-prevention, legal, or opt-out duties. Shared plans and push subscriptions use the feature-specific limitations described in this policy. Logs are retained according to security and provider configuration. Files and account data are deleted, anonymized, or access-restricted when no longer needed, subject to legal holds and backup cycles. SEOH will update the policy or feature disclosure before relying on a materially different period.

Security, backups, and incident limits

SEOH uses measures appropriate to the context, including private storage for recovery data, access controls, environment-held secrets, data minimization, input and replay masking, rate limits, audit records, encrypted or restricted backups where configured, and isolated recovery checks. No website or transfer method is completely secure. Primary-system deletion may not immediately remove an access-restricted backup copy that must remain for continuity, security, legal, or dispute purposes; restored data is subject to the original deletion and suppression rules. If a breach creates a notification duty, SEOH will investigate and notify affected parties or authorities as required by applicable law.

Your rights and choices

Depending on applicable law, you may ask to know or access personal data, receive a copy, correct it, delete it, restrict or object to processing, withdraw consent, opt out of eligible marketing or sharing, or obtain portability. You can reject or withdraw non-essential analytics through the site's consent control and can clear browser storage. Account, document, shared-plan, push, communication, or service requests can be sent through the support or cancellation pages or to [email protected]. SEOH may need to verify identity and authority, clarify scope, preserve a minimal suppression or legal record, or refuse a request where the law permits. An authorized agent may be required to show authority. You may also complain to the competent privacy or data-protection authority in your location.

Children and lawful 18+ services

SEOH's services are directed to businesses and people able to enter a valid engagement, not to children. SEOH does not knowingly solicit personal data from a child through the service-intake paths. Adult-industry pages and services are restricted to lawful 18+ businesses and adults, and the browser adult gate is a preference and compliance control rather than verified identity or proof of age. Never provide content involving minors or any unlawful, non-consensual, exploitative, or unauthorized likeness. If you believe a child supplied data, contact SEOH for review and deletion.

Third-party sites and client-controlled processing

The site may link to search, social, messaging, payment, portfolio, partner, or other third-party services. When you choose an external link or account, that provider may collect data under its own policy, and SEOH does not control the provider's independent processing. Clients are responsible for the lawfulness, notices, permissions, and instructions for personal data they supply or ask SEOH to process. A signed data-processing agreement can allocate controller, processor, security, deletion, assistance, and subprocessor duties for a specific engagement.

Changes, questions, and effective date

This policy is effective from August 25, 2026. SEOH may revise it when services, processors, retention controls, laws, or operating practices change. Material changes will be posted on this page and additional notice or renewed consent will be used where required. Questions, rights requests, or complaints can be sent to [email protected] or by post to 5 HaGefen Street, Ramla 7251205, IL. The policy describes the current verified operating boundary; a signed client agreement or data-processing agreement may add stricter project-specific commitments.

PWA and mobile app metadata

When the SEOH PWA or native mobile shell is used, the site may process install state, app surface parameters, notification permission state, device/browser metadata, crash or error context, and external-link handoff signals needed to operate the app experience.

Client portal, Supabase auth, and storage

The client portal uses invite-only Supabase magic-link authentication. Supabase may process email addresses, session cookies, authentication events, project rows, status records, intake history, shared documents, and storage metadata under Row Level Security controls.

Notification permission

The PWA can ask for browser notification permission only after a user action and only when the notification prompt flag is enabled. Permission can be denied or changed in browser or device settings.

Professional 18+ compliance sections

Adult-industry pages and app sections remain professional, non-explicit, age-rated, and focused on lawful compliance, consent, platform policy, payment policy, reputation, and brand-safe operations.

Privacy choices and deletion path

Support, cancellation, account access removal, document deletion, and data-deletion requests can be sent by WhatsApp or email. SEOH reviews each request against account authority, service status, legal retention, security, and contractual duties.

Founder email: [email protected] - WhatsApp: +972-54-582-1664

Review agent action

Check the action and details below. Continue only if this matches your request.