Trading education only, not investment advice. Trading carries a real risk of financial loss.

Legal information

Privacy policy

This English version is a translation of the Hebrew original. If there is any difference between them, the Hebrew version prevails.

Your privacy matters to us. This policy explains what personal information is collected on the website djrlab.com and in the DJR LAB courses, for what purposes, where it is stored, to whom it is transferred, and what your rights are under the Protection of Privacy Law, 5741-1981. Any gendered wording in this policy is for convenience only.

1. Who is responsible for the information

The controller of the database is [to be completed: business name], business registration number [to be completed], address [to be completed]. For privacy inquiries: email [email protected], phone [to be completed].

2. No legal obligation to provide information

You are not required by law to provide us with information. However, without a name and phone number we cannot get back to you, and without an email address we cannot register you for the course, send a payment confirmation or give you access to the student area.

3. What information is collected and why

Contact form

  • Full name, mobile phone number, email (optional) and the course you are interested in — to get back to you, schedule an intro call and answer questions.
  • Source of arrival: campaign parameters (UTM), the domain you came from and the landing page on the site — to know which channels work. We also store only the device type (mobile, tablet or computer), the form you sent, and the version of the home page shown to you, if a comparison test between versions was running.
  • Consent to marketing messages: if you ticked the consent box, the consent, the time it was given and the wording you agreed to are stored.

Purchase

  • Name, phone, email, the course or cohort, the amount, the transaction number, the payment status and your consent to the purchase terms (the time of consent, the wording of the terms you approved and the IP address from which you approved them) — for carrying out the transaction, bookkeeping, issuing a receipt, proving consent to the terms and fulfilling obligations under law.
  • We do not see or store your credit card details. The card number is typed only on the payment provider's secure payment page. The payment provider only tells us whether the payment went through or not.

Student area and course

  • Login email, one-time login codes (stored in encrypted form and expiring within minutes), the time of the last login, and, for security purposes, the IP address and browser details of active sessions.
  • Attendance at sessions, practice tasks you handed in (text and images; the images are deleted at the end of the cohort) and the feedback on them, quiz attempts, messages from the instructor, scheduling of Private course sessions and opening calls, and a completion certificate — to run the course and support you.
  • Reviews: if you gave a review and approved its publication, it will be shown on the site under your first name (or as you approved), with your city and cohort if you provided them.

Browsing the site

  • The site records page views and clicks on buttons (such as WhatsApp) without cookies, without an IP address, without browser details and without a personal identifier: only the page, the referring domain, the campaign source and the device type. This information does not identify you.
  • We may use Cloudflare Web Analytics, a statistics tool that does not use cookies and does not track users across sites.
  • To block malicious software and automated submissions, the forms are protected by Cloudflare Turnstile, and requests to the site are rate-limited by IP address. This data is kept for up to 24 hours.
  • YouTube videos on the site load only after a click, in YouTube's "privacy-enhanced" mode. From the moment of the click, Google's privacy policy applies to the viewing.

4. Cookies and browser storage

  • The site does not use advertising or tracking cookies.
  • One essential cookie is created only when you log in to the student area, to keep you logged in (for up to 30 days or until you log out).
  • While you browse, your source of arrival at the site is stored in your browser (and not with us), so that it can be attached to the form if you send it. This information is deleted when you close the tab.

5. Marketing messages and communications

We will send you updates and marketing content by WhatsApp, SMS or email only if you have given express consent to this, in accordance with section 30A of the Communications (Telecommunications and Broadcasting) Law. Consent is not a condition for receiving service. You can ask to be removed at any time — on the unsubscribe page, by replying "remove" to a message, or by contacting us — and removal will cost you nothing. Service messages relating to a course you purchased (such as a payment confirmation, a login code or a session reminder) are not marketing messages and will continue to be sent as long as you are registered.

6. To whom the information is transferred

We do not sell personal information and do not transfer it to others for advertising purposes. The information is transferred only to providers that operate the service for us, and only to the extent required:

  • Cloudflare — hosting of the site and the database, security, Turnstile and statistics. The servers may be outside Israel.
  • [to be completed: name of the payment provider] — processing the payment and issuing the receipt.
  • Resend (an American company; sending is done from servers in Ireland, in the European Union) — sending emails from the address [email protected]: login codes, payment confirmations and reminders. Your email address and the content of the message are provided to it.
  • Cloudflare Email Routing and Google's Gmail — email you send to [email protected], or a reply to an email you received from us, passes through Cloudflare and is forwarded to DJR LAB's business mailbox on Gmail, where it is stored. The servers may be outside Israel.
  • Google (Google Calendar) — session dates are synced to DJR's calendar to prevent conflicts. The calendar stores the course and cohort name, the date and time, and the Zoom link or location; for the Private course, the cohort name includes the student's name.
  • Zoom — the online sessions, in accordance with Zoom's privacy policy.
  • WhatsApp and Discord — if you join the community groups, group members will see the name and details you display on the platform.
  • [to be completed: the accountant / bookkeeping service] — transaction details for tax purposes.
  • Competent authorities — when the law requires it, or to protect our rights in legal proceedings.

7. Transfer of information abroad

Some of the providers store information on servers outside Israel, mainly in the United States and the European Union. The transfer is made in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001, to providers that undertake to apply security measures and to use the information only to provide the service to us. Providing your details constitutes consent to this transfer.

8. Information security

We take reasonable measures to secure the information, in accordance with the Protection of Privacy (Data Security) Regulations, 5777-2017: an encrypted connection (HTTPS), access to the admin interface only for authorized persons and with means of authentication, an activity log in the admin interface, storage of login codes and session identifiers in encrypted form (hash), browser security headers and request rate limiting. No system is completely immune; if a severe security incident occurs, we will act in accordance with the law, including reporting to the Privacy Protection Authority to the extent required.

9. How long the information is kept

  • Inquiries that did not lead to registration or purchase: up to 7 years from the last inquiry (the civil limitation period), after which they are deleted automatically.
  • Student and transaction details: as long as needed to run the course, and afterwards for the period required under tax and accounting law (usually 7 years).
  • The IP address stored with the approval of the purchase terms: together with the transaction if the purchase was completed; if it was not completed, it is deleted automatically after 30 days.
  • Records of consent to marketing messages and of removal from them: as long as marketing messages are sent, and for a reasonable period afterwards in order to prove the consent.
  • Browsing data without personal identification: up to 7 years, after which it is deleted automatically.

10. Your rights

  • Access: you are entitled to inspect the information about you held in our database (section 13 of the Law).
  • Correction and deletion: if the information is not correct, complete, clear or up to date, you may ask to correct or delete it (section 14 of the Law).
  • Removal from marketing messages: you may ask not to receive marketing communications and to be deleted from the mailing list (section 17F of the Law).
  • To make a request, contact us by email at [email protected] and state your name and phone number so that we can verify your identity. We will respond within 30 days.
  • If you are not satisfied with how your request was handled, you may contact the Privacy Protection Authority at the Ministry of Justice.

11. Minors

The site and the courses are intended for people aged 18 and over. We do not knowingly collect information about minors without a parent's consent. If you learn that a minor has provided us with information, contact us and we will delete it.

12. Changes to this policy

We may update this policy. The date of the last update appears at the bottom of the page. A material change in the way the information is used will be published on the site.

Last updated: 07.10.2026