Skip to content

Search

Search pages, products, sectors, experts and legal documents

All legal documents

Privacy Notice — Client Portal

Effective date: 11 September 2026

1. Who we are

CRUNCH, a service of CIDAH (cidah.ai), operates the client portal at crunchdd.com/portal ("Portal"). For the personal data described below we act as controller for account and security data, and as processor on behalf of the client organisation for the content of uploaded documents.

2. What we collect

CategoryExamplesSource
Account datawork email address, organisation, role in the Portal (client / operator / reviewer)invitation by your organisation; you
Authentication dataone-time sign-in codes (transient), authenticator (TOTP) enrolment for staff, session tokensyou; our authentication provider
Activity datarequest created / submitted, file uploaded, message posted, deliverable released, download issued; timestamps; user idgenerated by the Portal
Technical dataIP address, browser type, request logs (short-lived)your device; hosting provider logs
Content datadocuments and messages you upload for a matter, which may contain personal data of third partiesyou, on behalf of your organisation

We do not use tracking cookies or advertising analytics anywhere on crunchdd.com or in the Portal. Cookies and local storage are limited to what the service needs to function:

NamePurposeTypeLifetime
Authentication cookies (Portal)keep you signed in and protect your sessionstrictly necessarysession / until sign-out
NEXT_LOCALEremember your interface language (Hebrew / English)functional preference, set only when you choose a language1 year
theme (local storage)remember your light / dark mode choicefunctional preference, set only when you use the toggleuntil cleared

Because no cookie is used for tracking, profiling or advertising, and preference cookies are set only on your explicit action, no consent banner is shown. You can clear these at any time through your browser settings.

3. Why we process it and on what basis

PurposeLegal basis (GDPR, where applicable)
Providing the Portal and delivering the engaged workperformance of a contract (Art. 6(1)(b))
Account security, malware scanning, audit traillegitimate interests (Art. 6(1)(f)) — security and integrity
Professional-conduct and record-keeping dutieslegal obligation (Art. 6(1)(c))
Processing document content for the client organisationon the organisation's documented instructions (Art. 28)

4. Who receives it (sub-processors)

ProviderRoleLocation
Supabasedatabase, authentication, private file storageEU (Frankfurt, eu-central-1)
Vercelapplication hostingglobal edge network; server functions in the EU (Frankfurt, fra1)
Resendtransactional email (sign-in codes only)EU (Ireland, eu-west-1)
Cloudmersivemalware scanning of uploaded files (file content transmitted for scanning; not retained by the provider per its terms)US (provider default API region)

No personal data is sold. We disclose data to authorities only where legally required.

5. International transfers

Primary storage is in the EU. Where a sub-processor processes data outside the EU/Israel, transfers rely on the provider's standard contractual clauses / adequacy (Israel holds an EU adequacy decision).

6. How long we keep it

See the Retention Policy. Summary: matter content and released deliverables — 7 years from matter close (GN decision 11/09/2026); quarantined files — deleted within 30 days; sign-in codes — 10 minutes; request/session logs — 30 days; account data — for the life of the engagement plus the retention period.

7. Security

Invite-only access; one-time email codes; mandatory authenticator (TOTP) for CRUNCH staff; row-level access controls per organisation; private storage with short-lived signed links; malware scanning of every upload before any staff access; full activity audit trail.

8. Your rights

Depending on applicable law you may request access, rectification, erasure, restriction, portability or object to processing, and complain to a supervisory authority (Israel: Privacy Protection Authority; EU: your local authority). Where we process document content as a processor, please address requests to your organisation; we will assist it.

9. Contact

Privacy requests and general questions: info@crunchdd.com (subject line "Privacy"). Responsible officer: Guy Ne'eman, Adv. (guyn@cidah.ai). No statutory DPO appointment is required at the current scale of processing; this is reviewed annually.

10. Changes

We will post the updated notice in the Portal and, for material changes, notify the organisation's administrator by email.


This document combines the firm's advanced AI system with experienced legal expertise, under the close supervision and approval of a senior attorney.