Israel Defense TechFounders Club

Privacy

What we hold, and why.

The club exists because people trust it with things they would not post publicly. This page is written plainly rather than defensively, so you can see exactly what that means in practice.

Last updated 7 August 2026.

Who we are

The Israel Defense Tech Founders Club, contactable at club@isr-defense.tech. We are the controller of the information described here.

What we collect

When you apply for membership

DataWhy
Full nameTo know who is in the room.
Email addressVerification, and the only channel we use for decisions.
WhatsApp numberVerification, and adding you to the group if approved.
LinkedIn profileSo a human can confirm you are who you say you are.
Company, website, company LinkedIn, role, stageTo judge which circle fits, and whether the application is genuine.
What you are building, and why it belongs hereRead by the reviewer. This is the part that decides it.
Who referred you, how you heard of usTo understand how the club grows.
Country and network of your connectionMembership is for Israeli citizens; this is one advisory signal among several, never an automatic rejection.

When you RSVP to an event

DataWhy
Your answer, and any access or dietary noteCatering and headcount.
ID or passport numberOptional. Building security requires a name list in advance. See below.
Whether you were checked inDoor management on the night.

When you message the concierge

Messages you send to the club WhatsApp number are stored so a human can act on them - an introduction request, an RSVP, a question. Reply stop at any time to switch off announcements while staying a member.

If you enquire about partnership

Your organisation, name, role, email, phone and whatever you tell us about budget and objectives. Kept separately from member records.

ID numbers, specifically

This is the most sensitive thing we ask for, so it gets its own section.

What we never do

Who processes it for us

ServiceWhat it handles
CloudflareHosting, the database, and bot protection. Data is stored in Cloudflare's infrastructure.
ResendSends our email. It sees your address and the message.
Meta (WhatsApp)Delivers WhatsApp messages and codes. Meta's own terms apply to that transport.
Google / MicrosoftOnly if you choose to sign in with them. They confirm your address; they receive no member data from us.
Google AnalyticsMeasures traffic on the public pages. It sets cookies and can associate your visit with other sites you use. It is not present on any member-only or staff page.

Analytics run on the public pages only: Cloudflare Web Analytics, which is cookieless, and Google Analytics, which does set cookies and is Google's own cross-site product. Neither runs on a member-only or staff page - not your members area, not the RSVP, not the door list, not the admin console. What you do inside the club is not measured, by us or by anyone else.

How long we keep it

ID / passport numbersDeleted automatically 7 days after the event.
Member recordsWhile you are a member, and for a short period afterwards so we do not re-approach you by mistake.
Applications we declinedKept so a repeat application is handled consistently. Ask and we will erase it.
Audit log of decisionsRetained - it is how we can show who was admitted and on what basis.

Your rights, and how to delete your data

You can ask to see everything we hold about you, correct it, or have it erased. Two ways:

We will act within 30 days and confirm in writing when it is done. Deleting your data ends your membership and removes you from the groups - we cannot keep you in a verified room while holding nothing that verifies you.

One exception: entries in the audit log recording that a decision was made, and records we are required to keep by law, are retained. They contain the decision, not your application.

Legal basis

We process this information on the basis of your consent, given when you submit an application, and our legitimate interest in running a verified private community. You can withdraw consent at any time by asking us to delete your data. We operate under Israel's Privacy Protection Law; if you are in the EEA or UK, we honour the equivalent rights under the GDPR.

Security

Verification links are single-use and expire. Sessions are signed and short-lived. The admin console requires a password plus a code sent to a separate channel, and locks out after repeated failures. Nothing about members is exposed by any public endpoint. If you believe you have found a flaw, please write to club@isr-defense.tech - we would much rather hear it from you.

Changes

If we change this in a way that affects what we do with your data, we will tell members directly rather than quietly updating this page.

Questions: club@isr-defense.tech