Privacy Policy
1. Introduction – Who We Are
- Studio Naim ("we")
- Contact email: info@naim.org.il
- Phone: 035188998
Last updated: August 2025
This page complies with Amendment 13 to the Privacy Protection Law (5741–1981).
2. Personal Information We Collect
We may collect the following types of information:
- Identifying details such as: name, email, phone, age
- Digital identifiers such as: IP address, cookies
- Particularly sensitive information (e.g., health or personal status), but only when explicitly authorized
3. Purposes of Data Use
We use your information for the following purposes: operating the site and providing service; improving user experience and offering personalized content; statistical analysis (non-personal) for improvement and promotion; sending marketing communications — only after explicit opt-in; site security (including preventing intrusion and monitoring suspicious activity).
4. Consent and Use of Information
Some uses of information are necessary to provide the service itself or to comply with a legal obligation (for example, managing the membership, documenting payments, and retaining health declarations), and do not require separate consent. By contrast, uses that are not essential to providing the service, such as marketing communications and non-essential cookies, are carried out only after receiving your explicit consent, which you may withdraw at any time.
5. Cookies
When you enter the site, a notice is displayed requesting your consent to the use of cookies. Cookies are used for the proper operation of the site, saving preferences, analyzing usage, and improving the service. You can block or delete cookies at any time through your browser settings, although some parts of the site may not function properly without certain cookies.
6. Sharing with Third Parties (Processors)
Third-party sharing – Arbox (management system). We use the Arbox platform to manage clients, payments, and studio activity. This is done under a Data Processing Agreement (DPA) between Studio Naim and Arbox, which includes commitments to protect your personal data.
We may share information with third parties such as mailing services, CDN, analytics, or plugins. Any such sharing will only be done upon signing a Data Processing Agreement (DPA) and meeting security requirements. Where international data transfer is required, it will only take place to countries with an adequate level of protection.
7. Your Rights – Access / Correction / Deletion
You have the right to:
- Access the information held about you
- Correct inaccurate information
- Request deletion of information (where applicable) by contacting us by email
8. Information Security
- TLS protocol (HTTPS), backups, and regular system updates.
- Strict user permissions, secure passwords, and two-factor authentication (2FA)
- Where necessary — penetration testing (PenTest) and security scans
- DPO – michale@naim.org.il
9. Security Cameras (CCTV)
Closed-circuit television (CCTV) cameras are installed in the public areas of the studio and the gyms as part of our security measures. The purpose of the cameras is to protect the safety, security and property of trainees, staff and visitors, to prevent theft and incidents of violence, and to enforce the terms of use. Camera footage is retained for three days only, unless longer retention of a specific event is required for investigation, legal proceedings, or a request by a competent authority. Access to the footage is limited to authorized personnel only.
10. Data Retention Period
We retain personal information only as long as it is necessary for the purposes for which it was collected, such as: class management, service and support, statistics, consented mailing, payment processing and documentation (including accounting records).
If you request deletion of your data, we will delete or anonymize it from active systems without unreasonable delay and ensure that relevant data is not used. Copies in system backups without ongoing operational access will be deleted in the next backup cycle or within a reasonable timeframe in accordance with our backup cycles and technical capabilities ("beyond use").
11. Database Registration and Reporting to the Privacy Authority
After review, we determined that we do not meet the conditions for mandatory registration, and therefore there is no obligation to register. Reporting is also not required as we do not hold "particularly sensitive" information at the 100,000-person threshold.
12. Future Updates
This policy may be updated in accordance with changes in legislation or new directives from the Authority. We will make every effort to update this page in all relevant cases.