OGen Family Office

Privacy & Information Security Policy

Ogen Capital Advisors | www.ogen.capital

Last updated: August 2026

1. Who we are, and why this document matters

Ogen Capital Advisors (“Ogen”, “we”) is the first firm in Israel, and so far the only one, to combine investment advisory in traditional capital markets with advisory on digital assets (crypto), balanced internally and under one roof. To be precise: we provide investment advice only, not investment management. We do not hold your funds, your securities, and under no scenario the private keys to your digital wallets. The decisions and the execution stay with you.

This document explains what information is collected on www.ogen.capital (the “Site”), what we do with it, what we expressly do not do with it, and what rights you have under the Protection of Privacy Law, 5741-1981, including Amendment No. 13 which came into force in August 2025 (the “Law”) and its regulations.

Using the Site constitutes agreement to this policy. If something here does not sit right with you, do not use the Site, or simply write to us. We are happy to answer.

2. The short version

We do not sell or trade your information. Not to third parties, not to “strategic partners”, not to anyone. Our business model is advisory, not data.

We collect only what is required to operate the Site and provide the service.

We will never ask you for a private key, seed phrase or password; not by email, not by phone and not on WhatsApp. Anyone who asks you for these is, by definition, an impostor.

You have rights of access, correction and deletion, and exercising them is simple and free. Details in section 10 below.

3. Information collected automatically (analytics)

While you browse the Site, technical and statistical information is collected: pages viewed, visit duration, referral source, browser and device type, and IP address. A reminder: since Amendment 13, an IP address and online identifiers are considered “personal information” for every purpose, and we treat them accordingly. The information is used for statistical analysis, site security and improving our services and content, and is processed in aggregate wherever possible so that it does not identify you personally.

4. Cookies and measurement tools

The Site uses cookies and measurement tools. Some are essential to its proper operation, and some depend on your consent. You can manage, block or delete cookies through your browser settings, although blocking essential cookies may impair how the Site works. And no, we will not pretend cookies exist purely “to improve your experience”: they also help us understand what works on the Site and what does not.

5. Information you give us, and the notice under section 11 of the Law

On contact forms and newsletter sign-up you will be invited to provide details such as your name, email address and phone number. Important to know: you are under no legal obligation to provide your contact details, and doing so is entirely voluntary. It is just that without them, we simply cannot get back to you. The information is stored in the company's databases and used solely for the purposes set out in this policy: answering enquiries, operating the Site and its services, mailing only to those who signed up, and complying with the law that applies to us.

6. Mailing list and newsletters

Signed up? You will receive updates, professional content and, from time to time, marketing content, all strictly in accordance with section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982. Three things worth knowing:

Sign-up is entirely voluntary and based on explicit prior consent (opt-in).

Every message carries an unsubscribe link. One click and you are out, with no questions and no persuasion.

Withdrawing consent is exactly as easy as giving it, as required by law following Amendment 13.

7. What we do with the information, and what we do not

We use the information to: provide and operate the Site and its services; respond to enquiries; send mail to those who subscribed; comply with the law applying to our investment advisory activity; and improve the Site, the services and the content.

We do not pass personal information to third parties, except in the following cases:

Essential service providers (cloud hosting, mailing systems, analytics tools), who are bound to us by data processing and confidentiality agreements and act solely on our instructions and for the purposes set out in this policy.

Only where the law requires it, including a lawful demand by a competent authority, such as the Israel Securities Authority or the Capital Market, Insurance and Savings Authority.

In the course of legal proceedings, or to protect our legal rights.

With your explicit consent.

8. Transfers of information outside Israel

Some of our service providers (such as cloud services and mailing systems) store information on servers outside Israel. Such transfers are made in accordance with the Protection of Privacy Regulations (Transfer of Information to Databases Abroad), 5761-2001, that is, to countries providing an adequate level of protection, or under appropriate contractual safeguards.

9. Information security: what we do, and what nobody can promise

We apply technological and organisational security measures in accordance with the Protection of Privacy Regulations (Information Security), 5777-2017, including encryption, access controls, monitoring and internal procedures, and we follow developments in information security on an ongoing basis.

Even so, professional integrity requires saying what every website knows but not every website writes: there is no such thing as absolute security. The internet is inherently exposed to risk, cyber attacks, malware, viruses, impersonation attempts, faults, outages, and exposure or alteration of information by unauthorised parties. Subject to provisions of law that cannot be contracted out of, the company, its shareholders, officers, employees and anyone acting on its behalf shall not be liable for damage, loss or expense caused to a user by or in connection with use of the Site, provided that we took the reasonable security measures required by law.

A serious security incident? We are prepared to act as the law requires: reporting to the Privacy Protection Authority within 72 hours of discovering a reportable incident, and informing affected users without delay where the incident is likely to create a high risk to their rights.

10. Your rights in the information

Under the Law you have, among others, the following rights:

Access (section 13): to receive a copy of the information we hold about you.

Correction and deletion (section 14): to demand correction or deletion of information that is incorrect, incomplete, unclear or out of date.

Removal from the direct mailing database (section 17F): to be erased from our mailing lists.

Withdrawal of consent: at any time, and as easily as it was given.

A request to exercise your rights will be answered within 30 days at most, as the regulations require. No lawyer, notarised form or registered letter is needed; a simple email does the job.

11. Identification and access credentials

If you are given identification or access credentials to dedicated areas of the Site, they are personal and confidential, and should be treated as such. You undertake to keep them confidential and not to disclose or transfer them to any third party. And a friendly tip: do not keep them in a file called “passwords.txt” on your desktop.

12. Phishing, impersonation and fraud: required reading for crypto investors

Clients of financial firms, and especially in digital assets, have always been a favoured target for fraud attempts. Phishing messages today look remarkably convincing: the right logo, urgent and trustworthy wording, and a link almost identical to the real address. So please commit these rules to memory:

Ogen will never ask you for a private key, seed phrase, password or verification code. Ever. If someone asked you for one, that means it was not us.

Ogen will never send you a wallet address to transfer funds or coins that belong to you. We are advisors; we do not touch your assets.

Always check that the address in your browser is exactly www.ogen.capital, not ogen-capital, not 0gen, and not any other creative variation.

“Digital hygiene” recommendations: enable two-factor authentication (preferably via an app or hardware key, not SMS); use a password manager and a unique password for every service; keep software and security tools up to date; and for crypto holders, consider a cold wallet for significant holdings.

If you suspect an unlawful action, an attempt to impersonate us, or a compromise of the identification mechanisms, please tell us immediately so that we can act as quickly as possible.

13. Minors

The Site and the services are not intended for anyone under 18, and we do not knowingly collect personal information about minors.

14. Privacy contact

For any privacy matter, a request for access, correction or removal from the mailing list, a report of incorrect details, a concern about a privacy breach, or simply a question, you can reach us by email at privacy@ogen.capital or by phone at +972 55 979 9433. We will handle and respond promptly, and no later than the times set by law.

15. Changes to this policy

We may update this policy from time to time. The binding version is the one published on the Site, and the date of the last update appears at the top of the document. A material change will be highlighted on the Site reasonably, as required by law. Continued use of the Site after an update constitutes agreement to the updated version; so if you do not agree with it, your sole remedy is to stop using the Site.