1. Who controls the information
GIMMI is a trading name of JOYFIELD INVESTMENTS LTD, Hebrew name שדה האושר השקעות בע״מ, Israeli company no. 517295903. The company controls personal information collected through this website.
Registered correspondence address: 4 Granit St, Caesarea 3088900, Israel. For access, correction, or any privacy request, email hello@gimmi.io.
There is no legal duty to provide details. Without your name, work email, business name, and a short description, we cannot assess or respond to the request. A phone number is optional.
2. Information we collect
Information you provide
- Your full name, business name, work email, optional phone number, and a description of the work you would like us to assess.
- The content of follow-up emails and other correspondence with the company.
- Scheduling, proposal, or engagement details only if the conversation reaches that stage.
Limited technical information
- IP address, browser type, request details, access time, and error codes that the hosting provider may process to operate and secure the site.
- A random inquiry ID, language, submission time, and privacy-notice version to prevent duplicates and record how a request was received.
- To rate-limit form submissions, the site converts the IP address into a keyed one-way identifier and stores it with attempt counts and recent inquiry IDs in server temporary storage. The limit window is active for 10 minutes, the limiter file does not store the raw IP address, and it is outside the website-file backup set.
- The main GIMMI pages serve fonts from the site itself. The separate DC demonstration page at /dc/ loads Google Fonts, so visiting it may send technical request information to Google. GIMMI does not send form content to Google.
Do not submit passwords, identity numbers, medical information, payment details, or sensitive personal information about another person. The site is not designed to collect information from children.
3. Why we use information
- To receive and assess the request, respond, and arrange a conversation.
- To prepare a proposal or take pre-contract steps you ask us to take.
- To secure the site, prevent abuse, resolve failures, and maintain service continuity.
- To meet binding legal, accounting, or regulatory duties.
- To protect the rights of the company or users in a dispute or security incident.
A consultation request does not add you to a marketing list. Promotional messages will require separate express consent if GIMMI offers that option later.
4. Who receives information
Information is provided only as needed for the purpose for which it was collected:
- Hostinger, for hosting the site, serving content, running the form endpoint, security, logs, and backups.
- Resend, for sending an accepted request directly to the company mailbox.
- The company mailbox provider approved before launch, for receiving and storing company messages. The provider will be named here before the public form is enabled.
- Google Fonts, for serving font files on the separate DC demonstration page at /dc/ and processing the associated technical request information.
- Professional advisers or authorities where required by law or necessary to protect a legal right.
These providers may process information outside Israel. GIMMI works to use appropriate providers and contractual arrangements that protect the information and restrict processing to the service purpose. Before a new provider, such as a scheduling or analytics service, is enabled, this policy and the relevant consent controls will be updated.
GIMMI does not sell personal information or provide consultation leads to third parties for their own marketing.
5. How long information is kept
The periods below are operational limits for copies controlled by GIMMI. Providers may retain limited security or billing records under their own independent legal duties.
| Information | Period | End of period |
|---|---|---|
| Form rate-limit record | Active 10-minute window | An expired record no longer limits requests and is removed on the next valid submission or during server temporary-storage cleanup. |
| Inquiry that does not become an engagement | 12 months after the last meaningful contact | Deleted or anonymized unless you ask us to continue handling the inquiry. |
| Proposal or negotiation without a contract | 24 months after last activity | Copies not needed for an active dispute are deleted. |
| Required client contracts, invoices, and records | 7 years or another period required by law | Secure deletion after the obligation ends. |
| Hosting access and error logs | Up to 7 days under the current setting | Removed through the provider's log cycle. A separate record of a material security incident may be kept for up to 90 days. |
| Request to exercise privacy rights | 24 months after closure | Deleted unless an active dispute creates a documented need. |
| Website backups at the hosting provider | The active cycle contains 7 daily and 6 weekly copies | Removed progressively through the provider's normal backup cycle. |
At least annually, GIMMI reviews whether it holds more information than needed and deletes or anonymizes information that is no longer necessary. A legal hold applies only to records related to an active dispute, investigation, or legal duty and is documented until it ends.
6. Your rights
Subject to applicable law, you may ask to access personal information about you and to correct information that is inaccurate, incomplete, unclear, or out of date. You may also request deletion or an end to processing where you have that right under applicable law, or withdraw consent for future processing that relies on it.
Email hello@gimmi.io. Include the email address used in the original request and a reasonable description of what you need. We will request only the information needed to verify identity and generally respond to an access request within 30 days, subject to law.
Israeli access and correction rights appear in sections 13 and 14 of the Protection of Privacy Law. General information is available from the Israel Privacy Protection Authority.
7. Security, children, and changes
We use encryption in transit, restricted access, account authentication, input validation, duplicate prevention, and error logging that excludes form content. No system is completely secure, so do not submit confidential or sensitive information that is unnecessary for the consultation.
The website and services are designed for businesses, not people under 18. If we learn that we collected information from a child without a need to do so, we will take steps to delete it.
We will update this policy when services, providers, or applicable law change. A material change will be marked with a new update date and, where necessary, a fresh request for consent.
Version: 2026-08-09. This policy describes how the website operates and does not limit any right that cannot lawfully be waived.