This policy explains how we handle personal information across our website at netboardroom.com and our media monitoring service.
If you found this page because your name appeared in one of our monitoring reports, go to Section 3. It explains what we collect from public sources and how to ask us to remove it.
1. Who we are and which law applies
We are established in Israel and operate under the Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13.
Israel holds an adequacy decision from the European Commission, most recently reconfirmed in January 2024. Personal data may therefore be transferred from the EU and EEA to us without additional transfer safeguards. Where we serve clients or handle information relating to individuals in the EU or UK, we also apply the standards of the GDPR and UK GDPR.
2. Website visitors
Comments
When you leave a comment we collect the information in the comment form, together with your IP address and browser user agent string, to help detect spam. An anonymised hash of your email address may be sent to the Gravatar service to check whether you use it; their policy is at https://automattic.com/privacy/. Comments and their metadata are retained until you ask us to remove them.
Cookies
We use only cookies that are necessary for the site to function. If you leave a comment you may choose to have your name, email and website saved in a cookie for convenience; that cookie lasts one year. Logging in sets session cookies that expire within two days, or two weeks if you select “Remember me”.
We do not use analytics, advertising or tracking cookies. We do not run Google Analytics or any equivalent.
Embedded content
Articles may contain embedded content from other websites — videos, images, social posts. These behave as if you had visited the other site directly, and those sites may set their own cookies and track your interaction with that content. We have no control over this.
Uploaded images
If you upload an image, remove embedded location data (EXIF GPS) first. Visitors can extract that data from images published on the site.
3. Information collected from public sources
This section concerns people whose names or posts appear in the material we monitor. You are probably not our client and may never have heard of us.
3.1 What we collect
We collect publicly accessible content that mentions the organisations, brands and topics our clients ask us to monitor. That content sometimes contains personal information:
- Names of people quoted or discussed in news coverage
- Public usernames and post text from open discussion platforms
- Public review text and reviewer display names
- Titles and descriptions of public videos, and channel names
- Titles, links and snippets from public search results
We store the content itself — headline, link, short excerpt, publication name and date. We do not build profiles of individuals and we do not combine this content with information from other sources.
3.2 What we do not collect
- Anything behind a login, paywall or access restriction
- Private messages, closed groups or members-only forums
- Anything obtained by circumventing technical restrictions or misrepresenting identity
- Contact details, addresses or identifiers not present in the published content
We configure monitoring around organisations, brands and topics — not around individuals. We decline requests to monitor a named private individual.
3.3 Our sources
- GDELT — global news index
- Google News — public RSS output, by language and region
- Reddit — official API, public posts only
- YouTube — official Data API, public video metadata only
- RSS feeds — published openly by publishers
- Search engine results — through a third-party search API, where enabled for a client
This list is kept current and updated when it changes materially.
3.4 Why we do it
To let organisations know what is being said about them publicly, so they can identify reputational risk, correct inaccurate reporting, and respond to legitimate criticism. This is the same purpose served by press-clipping services long before the internet.
We rely on our legitimate interests, and those of our clients, in monitoring public discourse about their own organisations. We have carried out and documented an assessment weighing that interest against the rights of the individuals concerned. A summary is available on request.
We do not ask individuals for consent because we have no relationship with them and no practicable way to contact them before collection. In exchange, we hold ourselves to a higher standard on transparency and on honouring requests, which is what the rest of this section describes.
3.5 Sensitive information
Published content sometimes reveals political opinions, religious beliefs, health information, union membership or sexual orientation. We do not seek this information.
- Keyword configurations are reviewed at setup and terms intended to surface such information are rejected
- Sources that exist primarily to publish such information are not added to our source library
- Where it appears incidentally it is not indexed, tagged, scored or used as an analytical dimension
- Where a record consists mainly of sensitive information about an identifiable individual and is not necessary for monitoring, we delete it
3.6 Automated analysis
Content is assessed by automated systems, including AI models, which assign a sentiment value, a topic label and a risk level, and write a short summary.
This analysis is applied to content about an organisation or topic, not to individuals. It produces no decision about any individual and has no legal or similarly significant effect on anyone.
These systems make mistakes. If you believe an assessment attached to content mentioning you is wrong, write to us and we will review it.
3.7 How long we keep it
Collected content is deleted automatically [180] days after its publication date. Aggregate statistics containing no personal information may be kept longer.
3.8 Your rights
If your personal information appears in content we hold, you may ask us to:
- Stop processing it. We will do so unless we have compelling grounds that override your rights. In practice, a request from a private individual will normally be honoured.
- Tell you what we hold about you
- Correct anything inaccurate
- Delete it
Write to [EMAIL]. Include your name as it appears and, if possible, a link to the content. We respond within 30 days, free of charge. We will not ask you to justify your request.
One limitation. We collect content published by others. Removing a record from our systems does not remove the original article, post or review from the internet — for that you need to contact whoever published it.
4. Client information
For our monitoring clients we collect account details (name, business email, company, job title), billing information, service configuration (keywords, markets, notification preferences) and usage logs.
We use this to operate the service, bill for it, keep it secure and respond to enquiries. We keep it for the life of the subscription plus [180] days, except billing records which we keep for [7] years as required by tax law.
For this information our client is the controller and we act on their instructions. Clients receive a separate data processing agreement setting out these terms.
5. Who we share information with
We do not sell personal information and we do not share it for advertising.
| Provider | Purpose | Location |
|---|---|---|
| Hostkey | Hosting and storage | Germany |
| OpenAI / Anthropic | Automated content analysis | United States |
| Net Boardroom | Email delivery | Germany |
| Search result data, where enabled | United States |
Each is bound by a written agreement. Content sent for AI analysis is limited to a title and short excerpt, under terms prohibiting its use to train models.
Monitoring content is delivered only to the client who requested that monitoring. It is never shared with another client.
We disclose information where required by law, and will tell the affected party unless prohibited from doing so.
6. Security
We apply access controls with per-client data isolation, encryption in transit, restricted administrative access, logging of administrative actions, and daily backups. No client can access another client’s records.
No system is perfectly secure. If a breach occurs that is likely to create a risk to individuals, we will notify the Israeli Privacy Protection Authority and affected individuals as required by law.
7. Changes
Material changes will be posted here, and clients will be notified by email at least [30] days in advance.
8. Contact
HSU Ltd., support@netboardroom.com
If you are unhappy with how we have handled your information, you may complain to the Privacy Protection Authority at the Israeli Ministry of Justice. Individuals in the EU or UK may also complain to their national supervisory authority.
