Terms of Use & Privacy Policy

Naxos.one Blog • Elad Naccache

Including paid content membership plans | Powered by Ghost (Pro)

This document combines the Terms of Use (Part A) and the Privacy Policy (Part B) of the blog at blog.naxos.one (the "Blog" and/or the "Site"), operated on the Ghost publishing platform. The Blog covers a range of subjects — cybersecurity and information security, privacy protection, technology, artificial intelligence, management, strategy, news, and additional content — and offers paid membership plans granting access to premium digital content.

Important notice regarding the Merchant of Record: The sale of membership plans, billing, and invoicing are carried out through an external payment provider acting as the Merchant of Record — currently Creem (Armitage Labs OÜ), registered in Estonia. Purchases are therefore also subject to the Buyer Terms and refund policy of the Merchant of Record, in addition to these Terms.

Browsing the Blog, registering, and purchasing a membership constitute full acceptance of this document, including the Privacy Policy. The Privacy Policy is drafted in accordance with the Israeli Protection of Privacy Law, 5741-1981, including Amendment No. 13 (effective 14 August 2025) and its regulations.

Last updated: August 2026


Part A - Terms of Use

1. General

  1. The Blog may amend these Terms from time to time at its discretion; changes take effect upon publication on the Site and do not apply retroactively to transactions concluded beforehand.
  2. These Terms apply to use of the Blog through any device and any communications network.
  3. Browsing is open to all ages; purchasing a membership is permitted only to persons with legal capacity over the age of 18. A purchase by a minor requires the consent of a parent or guardian.
  4. This document, including the Privacy Policy, constitutes the entire agreement between the parties. If any provision is found unenforceable or void, this shall not affect the validity of the remaining provisions.
  5. Failure to enforce any right shall not be deemed a waiver of it.

2. Nature of Content and User Declaration

The user declares, confirms, and agrees that they are aware:

  1. The content on the Blog — across all its subject areas — is general information and does not constitute a substitute for professional, legal, technological, managerial, financial, or security advice tailored to the individual, and should not be regarded as expert opinion or a recommendation to take any specific action.
  2. Any reliance on the content, and any decision or action taken as a result, are the sole responsibility of the user.
  3. The Blog does not warrant the accuracy, completeness, or timeliness of the content, including news and commentary, and shall not be liable for any error, inaccuracy, or damage resulting from reliance on it.
  4. Access to the member account is provided through passwordless authentication (a one-time verification link sent to the user's email — a "magic link"); the user is responsible for maintaining secure access to their email inbox, which secures their account.
  5. The Blog uses essential third-party services for its operation (the Ghost platform, the Merchant of Record for payment processing, and an email delivery provider), and shall not be liable for faults, delays, or changes originating from those services.
  6. The Blog is provided "AS IS," and its use is at the user's full and sole responsibility.

3. Browsing, Registration, and Account

  1. Browsing open content does not require registration. Access to the personal area and to premium content requires registration as a Member.
  2. Registration is completed by providing an email address (and, optionally, a name) and confirming via the verification link sent to your inbox. Providing incorrect details may prevent use of the service.
  3. Details will be used in accordance with the Privacy Policy in Part B of this document, which forms an integral part of these Terms.
  4. The user is responsible for all activity carried out under their account and for maintaining access to the email inbox used for authentication.
  5. The Blog may deny access to or block any user at its discretion, including in cases of providing false details, unlawful use, breach of these Terms, attempting to harm the Blog, or sharing member access with another party.

4. Paid Content Membership Plans

  1. The Blog offers membership plans (Tiers) granting immediate access to premium digital content — extended articles, guides, updates, and benefits, as detailed on the membership page.
  2. Membership is personal and intended for the member's use only; access credentials or content may not be transferred, shared, or made available to any other party.
  3. The Blog may change, add to, or remove membership plans, content, or benefits from time to time, subject to preserving the rights of existing members for any period paid in advance.
  4. Access to purchased content is granted immediately upon completion of registration and payment.

5. Pricing, Payment Processing, Taxes, and the Merchant of Record

  1. Prices displayed on the Blog are clear and visible, and the Blog may update them from time to time (updates do not apply to a period already paid in advance).
  2. Payment processing, billing, and invoicing are handled by the Merchant of Record (currently Creem / Armitage Labs OÜ), which acts as the merchant of record for the membership. The Merchant of Record is responsible for collecting applicable taxes (VAT/sales tax) and remitting them to the relevant authorities in accordance with applicable law.
  3. Completing a purchase is also subject to the Buyer Terms and refund policy of the Merchant of Record, in addition to these Terms.
  4. Credit card details are provided to and processed directly by the Merchant of Record in accordance with the PCI-DSS standard; the Blog does not collect or store credit card details in its systems.
  5. The Blog may change its payment provider / Merchant of Record from time to time, at its discretion, without derogating from members' rights.

6. Automatic Subscription Renewal

Membership plans in subscription format renew automatically at the end of each billing cycle (monthly or annual), and billing continues until the member cancels the subscription in accordance with Section 7. Upon joining, the member is shown the billing frequency, the amount, and the method of cancellation, as required by law.

7. Cancellation, Right of Withdrawal, and Refund Policy

It is clarified and emphasized that membership plans grant immediate access to digital content that constitutes "information" as defined in the Israeli Computers Law, 5755-1995. This Section is drafted in accordance with the Israeli Consumer Protection Law, 5741-1981 and its regulations, and subject to the terms of the Merchant of Record:

7.1 No Refund for Consumed Digital Content Pursuant to Section 14C(d)(3) of the Consumer Protection Law, the right of cancellation (withdrawal) in a distance sale transaction does not apply to information as defined in the Computers Law. Accordingly, since a membership plan grants immediate access to digital content consumed upon registration, the Blog does not provide any monetary refund, pro-rata refund, or credit for content that has been made available or consumed, including for a billing period that has already commenced or been paid.

7.2 Explicit Consent and Prior Disclosure At the time of purchase, the member is required to explicitly confirm that they wish to obtain immediate access to the content and that they understand that, upon access being granted, no right of cancellation or refund will apply as stated in Section 7.1. This confirmation is a condition for completing the purchase and constitutes prior disclosure as required by law.

7.3 Merchant of Record Discretion Notwithstanding Section 7.1, it is clarified that the Merchant of Record reserves the right, at its sole discretion, to issue a refund within 60 days of purchase — including in order to prevent payment disputes (chargebacks). The customer also retains the ability to contact their credit card provider to initiate a chargeback. The Merchant of Record's policy prevails on this matter over the Blog's policy.

7.4 Right to Cancel a Continuous Subscription (Going Forward) As a renewing subscription constitutes a "continuous transaction" under Section 13C of the law, the member may cancel the subscription at any time and without providing a reason — directly through the Merchant of Record's Customer Portal, or by notice to the support email. Such cancellation stops future billing, and the membership remains in effect until the end of the billing period already paid, subject to Sections 7.1–7.3.

7.5 Defect or Non-Conformity Nothing in the above derogates from rights granted to the consumer by law in the event of a defect, material non-conformity, or failure to provide the service as promised; in such cases the matter will be handled in accordance with the law.

8. User Content and Comments

To the extent the Blog permits comments or user-generated content, the user is responsible for the content they post and undertakes not to post content that is offensive, infringing, unlawful, or misleading. The Blog may remove or edit such content at its discretion and without prior notice, and receives a non-exclusive, worldwide, irrevocable license to display the content within the Blog.

9. Intellectual Property

All intellectual property rights in the Blog and its content — including articles, guides, texts, excerpts from Elad Naccache's book "Diary of a CISO — Starting the Journey," design, code, and trademarks — belong to the Blog or those acting on its behalf. No part of the content may be copied, reproduced, distributed, published, sold, or used commercially, in whole or in part, without prior written consent.

10. Prohibited Uses

The user undertakes not to:

  • Extract data (scraping/crawling) or create databases from the content.
  • Bypass, disrupt, or interfere with the security mechanisms of the Blog or the Ghost platform.
  • Impersonate others or use another person's account.
  • Copy, distribute, share, or sell the content or membership access.
  • Use the Blog to compete with the business, or for any unlawful, harmful, or improper purpose.
  • Upload or distribute viruses or malicious code.

11. Limitation of Liability

  1. Information on the Blog does not constitute a guarantee of results. The Blog shall not be liable for any direct or indirect damage arising from reliance on the content or on links to third parties.
  2. The Blog shall not be liable for any damage, loss, or distress caused by reliance on content, advertisements, or services appearing on the Blog.
  3. The Blog's liability, to the extent it applies, shall be limited to the amount paid by the user for the membership in the twelve months preceding the event giving rise to the claim. Nothing herein derogates from mandatory rights granted to consumers by law.

12. Indemnification

The user undertakes to indemnify the Blog for any damage, loss, or expense (including legal fees) incurred as a result of the user's breach of these Terms or of the law.

13. Governing Law and Jurisdiction

This document is governed by the laws of the State of Israel. Exclusive jurisdiction over any dispute lies with the competent courts of the Tel Aviv District, subject to mandatory rights granted to the consumer under the laws of their place of residence and to the terms of the Merchant of Record.


Part B - Privacy Policy

This Privacy Policy forms an integral part of the Terms. Providing details on the Blog constitutes acceptance of its terms.

1. Definitions

  • "Personal Information" — any data relating to an identified individual or an individual who can be identified, directly or indirectly (name, email, phone, online identifier, IP address, location data), as defined in Amendment No. 13 to the law.
  • "Information of Special Sensitivity" — as defined in Amendment No. 13. The Blog does not request or knowingly collect such information.
  • "Database Controller" — the Site operator, Elad Naccache, who determines the purposes and means of processing the information.
  • "Holder / Processor" — an external party that processes information on behalf of the Controller (for example, the Ghost platform, the Merchant of Record, and the email delivery provider).

2. What Information Is Collected (Based on the Ghost Members System)

2.1 Member Data Upon registration and purchase of a membership, the following fields are collected and stored on the Ghost platform: email address (required), name (optional), membership status (free/paid/complimentary), the customer identifier held by the payment provider, membership tier, newsletter preferences, labels, sign-up date, and login/verification-link activity records.

2.2 Passwordless Authentication The Blog does not collect or store passwords. Authentication is based on a one-time verification link sent by email, secured using JWT.

2.3 Payment Details (Merchant of Record) Membership purchases are processed directly by the Merchant of Record (currently Creem / Armitage Labs OÜ) in accordance with the PCI-DSS standard. The Blog does not see or store credit card details; only the customer identifier is retained for subscription management.

2.4 Technical Information and Analytics Ghost includes built-in, privacy-friendly analytics that do not use tracking cookies by default. Technical data (IP address, browser and device type, access times, pages viewed) may be collected for operational, statistical, and security purposes.

Information is processed on one or more of the following bases: your consent; performance of the membership contract; a legal obligation applicable to the Controller; and a legitimate interest (system security and fraud prevention). The purposes are:

  1. Providing access to content and managing the member account and membership plans.
  2. Payment processing, billing, subscription renewals, invoicing, and accounting (via the Merchant of Record).
  3. Responding to inquiries, support, and service.
  4. Sending updates, newsletters, and marketing content — subject to your consent and your right to opt out.
  5. Improving the Blog, analyzing usage data, information security, and preventing misuse.
  6. Compliance with legal requirements and directives of competent authorities.

4. Cookies

  1. Essential cookies: The Ghost platform on which the Blog operates does not set non-essential cookies by default. Essential cookies necessary for operating the Site and maintaining the member session (login and authentication) do not require consent.
  2. Non-essential cookies: If third-party tools that use non-essential cookies are activated on the Blog (for example, analytics, advertising pixels, or affiliate services), a cookie consent banner will be displayed, allowing you to accept, reject, or customize their use by category before loading.
  3. Management: You may delete or block cookies through your browser settings, though this may impair some functionality.

5. Marketing and Communications

  1. Newsletters and marketing communications will be sent only with your consent, in accordance with Section 30A of the Israeli Communications Law (Telecommunications and Broadcasting), 5742-1982.
  2. Simple and immediate opt-out: Every newsletter includes a built-in unsubscribe link at the bottom of the message, and you may also manage your communication preferences or opt out at any time directly through the Ghost member Portal — without needing to submit a separate request.

6. Disclosure of Information to Third Parties / Subprocessors

The Blog does not sell personal information. Information is shared only with the following essential subprocessors, which are contractually bound to data protection:

SubprocessorRoleProcessing Location
Ghost FoundationSite hosting and members systemEuropean Union
Creem (Armitage Labs OÜ)Payment processing, billing, invoicing, subscription managementEstonia / European Union
Email delivery providerEmail and newsletter deliverySubject to adequate safeguards

The Blog is hosted on Ghost Pro, under which Ghost Foundation acts as a processor pursuant to a Data Processing Agreement (DPA), and site data is stored on servers in the European Union.

In addition, the Blog may disclose information (excluding credit card details and ID numbers) to a third party pursuant to a legal obligation or court order, to protect its rights, in a legal dispute with you, to prevent serious harm, or upon transfer of the Blog's operations to a party that undertakes to comply with this Policy.

7. Transfer of Information Outside Israel

Site data is stored on the Ghost platform on servers in the European Union, and the Merchant of Record operates from Estonia (European Union). To the extent information is processed outside Israel, the transfer will be carried out in accordance with the Protection of Privacy Regulations (Transfer of Information to Databases Abroad) and while taking reasonable measures to ensure an adequate level of protection.

8. Data Retention Period

Information will be retained for the duration of the membership relationship and thereafter as required for legal, accounting, and regulatory purposes (for example, retention of invoices under tax law). At the end of the retention period, the information will be deleted or rendered non-identifiable, subject to applicable law.

9. Information Security

The Blog takes reasonable and customary measures in accordance with the Protection of Privacy Regulations (Information Security), 5777-2017: encryption (TLS/HTTPS), passwordless authentication, access controls, backups, and monitoring. However, absolute immunity from intrusion cannot be guaranteed, and the Blog does not warrant complete immunity.

10. Data Subject Rights

In accordance with the Protection of Privacy Law and Amendment No. 13, you have the following rights:

  1. Right of access to the information held about you.
  2. Right to rectification of incorrect, inaccurate, or incomplete information.
  3. Right to erasure of the information, subject to exceptions under the law.
  4. Right to withdraw consent and to opt out of marketing communications at any time.

To the extent additional law applies to you granting further rights regarding your information, we will honor them in accordance with that law. Requests should be submitted to the support email in Section 13 and will be handled within 30 days, subject to verification of your identity and applicable law.

11. Data Security Incident

In the event of a serious security incident affecting personal information, the Blog will act without delay and in accordance with the reporting obligations set out in the Information Security Regulations and the guidance of the Israeli Privacy Protection Authority, including notifying the Authority and affected individuals as required.

12. Children's Privacy

The Blog is not intended for minors under the age of 18 and does not knowingly collect information about them. Purchasing a membership is permitted only to persons with legal capacity over the age of 18.

13. Contact and Support

For any question, request to cancel a membership, exercise of a right, or privacy-related inquiry, you may contact the Blog's support email: Support email: marrow.violist_0c@proton.me (For matters relating to billing, invoicing, or refunds, you may also contact the Merchant of Record at support@creem.io.)

14. Changes to This Policy

The Blog may update this Policy from time to time. A material change will be brought to users' attention through a prominent notice on the Site, and to the extent it relates to information already collected, your consent will be requested as required by law.


Last updated: August 2026 © Elad Naccache - All rights reserved