Home / Privacy Policy
LegalPrivacy Policy.
What we collect, why we use it, who receives it, how long we keep it, and the choices available to you.
We collect only the information needed to answer enquiries, deliver our work, assess applications, operate this website and meet our legal obligations. We do not sell personal information or use enquiry, client or candidate data for advertising.
Who is responsible
Eshay Ltd., trading as Eshay Advisory, is responsible for the personal information described in this policy when it decides why and how that information is processed.
- Company: Eshay Ltd.
- Registered office: Aba Even 10, Jerusalem, Israel
- Company registration number: to be completed
- Privacy contact: privacy@eshay-advisory.com
Eshay Ltd. processes personal information in accordance with applicable Israeli privacy law, including the Israeli Privacy Protection Law, 5741-1981 and applicable regulations made under it.
Where the EU General Data Protection Regulation or another local privacy law applies to a specific activity, we also process the information in accordance with that law.
Scope of this policy
This policy applies to personal information processed through this website and in our relationships with prospects, clients, partners, suppliers, candidates and other professional contacts.
It does not replace the terms of a client contract, data processing agreement or other specific notice provided for a particular service or engagement.
Where we process personal information only on the documented instructions of a client, that client remains responsible for the purposes and means of the processing and the relevant contractual terms apply.
Information we collect
Information you provide
When you contact us, we may collect your name, organisation, role, professional contact details and the contents of your message or correspondence.
When you apply for a role, we may also collect your CV, professional history, portfolio, references, work samples and any other information you choose to provide.
Information collected automatically
Our systems may record technical information needed to deliver and secure the website, including:
- IP address;
- browser and device information;
- date and time of a request;
- page or resource requested;
- referring page;
- response status and technical diagnostics.
Where you consent to analytics, Google Analytics may also collect information about pages viewed, navigation, broad traffic source, device type and technical performance.
Google reCAPTCHA may collect technical and interaction signals to assess whether a form submission is likely to be legitimate.
Information from professional relationships
During a client, supplier or partner relationship, we may process business contact details, communications, contract information, invoices, project records and information needed to manage the relationship.
Information we do not seek
We do not buy enriched contact databases, create advertising profiles or collect personal information from data brokers for use through this website.
Why we use personal information
We may use personal information to:
- respond to enquiries and assess whether we can assist;
- prepare proposals, contracts and statements of work;
- deliver advisory, assurance, engineering and product services;
- manage client, partner and supplier relationships;
- assess applications and conduct recruitment processes;
- operate, maintain, protect and improve the website;
- prevent spam, fraud, abuse and security incidents;
- maintain records, issue invoices and meet tax, accounting and legal obligations;
- establish, exercise or defend legal claims.
Depending on the context and the law that applies, we rely on one or more of the following grounds:
- your consent;
- steps taken at your request before entering a contract;
- performance of a contract;
- compliance with a legal obligation;
- our legitimate interests in operating and protecting our business, responding to professional enquiries and maintaining professional relationships;
- another lawful basis recognised by applicable law.
We do not use enquiry, client or candidate information for unrelated advertising, and we do not make decisions producing legal or similarly significant effects solely through automated processing.
Personal information in client engagements
During an audit, penetration test, monitoring assignment or engineering engagement, we may encounter personal information held by or on behalf of a client. This can include employee identifiers, system logs, account information or credentials.
Our role depends on the engagement. In many cases, the client determines why and how the information is processed and Eshay Ltd. acts only on its documented instructions under the applicable contract or data processing agreement.
We limit access to those who need it, minimise what we copy or retain, use the information only for the engagement, and return or securely delete it in accordance with the agreed terms.
Findings identifying individuals are shared only with authorised client contacts unless disclosure is legally required. Client data is not reused as marketing material or for unrelated product development.
Who receives personal information
Internally, access is limited to personnel who need the information for the relevant purpose and who are subject to confidentiality and security obligations.
We may also share information with service providers used to operate our business and website, such as:
- hosting and infrastructure providers;
- email and communication providers;
- business, accounting and document-management services;
- Google Analytics, where analytics consent has been given;
- Google reCAPTCHA, for contact-form abuse prevention;
- professional advisers, auditors or insurers where necessary.
Providers receive only the information reasonably necessary for their role and are required to protect it under applicable contractual and legal obligations.
We may disclose information where required by law, court order or a competent authority, or where reasonably necessary to protect our rights, systems, clients or personnel.
We do not sell, rent or trade personal information.
International transfers
Eshay Ltd. is established in Israel and works with clients and service providers internationally. Personal information may therefore be processed in Israel, the European Economic Area and other jurisdictions in which our providers operate.
Israel is recognised by the European Commission as providing an adequate level of protection for personal data transferred from the European Economic Area, subject to the scope of that decision.
Where information is transferred to a jurisdiction not covered by an applicable adequacy decision, we use an appropriate legal mechanism where required, such as contractual safeguards, and consider whether additional technical or organisational measures are appropriate.
Google Analytics and Google reCAPTCHA may involve processing by Google entities and infrastructure outside the country from which you access the site. Further information appears in our Cookie Policy.
How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, accounting, security and evidential needs.
- General enquiries: for the duration of the exchange and normally up to three years after the last meaningful contact.
- Client and supplier records: for the relationship and the period required by applicable contractual, tax, accounting and limitation rules.
- Engagement working data: in accordance with the relevant contract, statement of work and data processing terms, then returned or securely deleted unless retention is required or agreed.
- Candidate information: for the recruitment process and normally up to two years after the last contact, unless a shorter period is required or you ask us to delete it sooner.
- Server and security logs: for a limited operational period, unless longer retention is necessary to investigate an incident or protect legal rights.
- Cookie and consent information: for the periods described in our Cookie Policy and for as long as necessary to demonstrate compliance.
We may retain a minimal record after deletion where necessary to record an objection, honour a suppression request or establish that information has been deleted.
Your rights
The rights available to you depend on the law that applies to the processing and may include the right to:
- request access to personal information about you;
- correct inaccurate or incomplete information;
- request deletion where the legal conditions are met;
- object to or restrict certain processing;
- receive certain information in a portable format;
- withdraw consent at any time;
- complain to the competent privacy authority.
To exercise a right, write to privacy@eshay-advisory.com .
We may request information needed to verify your identity and locate the relevant records. We use verification only where reasonably necessary to protect personal information from unauthorised disclosure.
Where the GDPR applies, we normally respond within one month, subject to any permitted extension for complex or numerous requests.
Where we process information only for a client, we may direct the request to that client and assist it in responding.
In Israel, complaints may be directed to the Israeli Privacy Protection Authority. Where EU or UK data protection law applies, you may also complain to the supervisory authority responsible for your place of residence, work or the alleged infringement.
How we protect personal information
We apply technical and organisational safeguards proportionate to the nature of the information and the risks involved. These may include:
- encryption in transit;
- role-based and need-to-know access controls;
- multi-factor authentication where appropriate;
- logging, monitoring and review;
- segregation of client engagement data;
- endpoint and infrastructure hardening;
- supplier and processor controls;
- documented incident response procedures.
No system can be guaranteed to be completely secure. We review our controls and adjust them as our services, risks and legal obligations evolve.
Where applicable law requires notification of a personal data breach, we notify the relevant authority and affected individuals within the required timeframe.
Security issues affecting Eshay Ltd., this website or our products can be reported to security@eshay-advisory.com under the disclosure terms in our Legal Notice.
Cookies and analytics
This website uses a limited number of cookies and similar technologies for security, consent management and audience measurement.
Google Analytics is activated only after the required consent has been given. Google reCAPTCHA is used on the contact page to protect the form against automated abuse.
We do not use advertising, remarketing or cross-site tracking technologies.
Full details, including cookie purposes, providers and retention periods, appear in our Cookie Policy.
Changes and contact
We may update this policy to reflect changes in our organisation, services, technologies or legal obligations.
Material changes are published on this page with an updated version number and date. Where required, we provide additional notice or request a new consent before a change takes effect.
The current version is 2.0, dated 2 July 2026.
Questions, concerns or requests relating to this policy may be sent to privacy@eshay-advisory.com .