We at Yigal Arnon & Co. ("YA", "us", "we", or "our") recognize and respect the importance of maintaining the privacy of our clients. This Privacy Notice describes the types of information we collect from you when you visit our website ("Site") and in the course of our business ("Services"). This Privacy Notice also explains how we process, transfer, store and disclose the information collected, as well as your ability to control certain uses of the collected information. "You" means any user of the Site, any client of YA, job applicant, and/or any other individual whose data we collect or process.
If you are an individual located in the European Union ("EU Individual"), some additional terms and rights may apply to you, as detailed herein. Yigal Arnon & Co. is the data controller in respect of the processing activities outlined in this Privacy Notice. Our registered office is Azrieli Center, Derech Menachem Begin 132, Tel Aviv and our registration number is 513311175. When we process Personal Data in the context of providing Services to our clients, depending on the type of Services we provide and the type of processing, the applicable client may serve as a controller and we may serve as a processor on the client's behalf.
"Personal Data" means any information that refers, is related to, or is associated with an identified or identifiable individual or as otherwise may be defined by applicable law. This Privacy Notice details which Personal Data is collected by us in connection with provision of the Services.
The key points listed below are presented in further detail throughout this Privacy Notice. You can click on the headers in this section in order to find out more information about any topic. These key points do not substitute the full Privacy Notice.
Personal Data We Collect, Uses and Legal Basis. We collect certain Personal Data that you provide to us including contact information, information related to the provision of Services including information provided by our clients, and your resume, if you apply for a position in our firm. We also collect certain Personal Data automatically when you visit our Site. We use your Personal Data for various reasons, including to provide you with the Site and Services, improve our Services, and to contact you with marketing offers. These processing activities are based on different legal bases including performance of a contract, legitimate interests and your consent, as more fully detailed below.
Additional Uses. We may compile statistical information based on anonymous and aggregated data we collect in order to help us understand customer needs. In addition, we use certain Personal Data for direct marketing purposes.
Sharing the Personal Data We Collect. We share the Personal Data we collect with our service providers and subcontractors who assist us in the operation of the Site and provision of Services and process the information on our behalf and under our instructions. When we act as a processor on behalf of our clients, we will share your Personal Data with the applicable client. We may also share Personal Data with our business partners involved in hosting or organizing events.
International Transfer. Some of our service providers, subcontractors or business partners who have access to your Personal Data are located in countries other than your own. We will ensure that we have agreements in place with such parties that ensure the same level of privacy and data protection as set forth in this Privacy Notice.
Security. We implement measures aimed at protecting your Personal Data, but they do not provide absolute information security. Such measures include physical, electronic, and procedural safeguards (such as secure servers, firewalls, antivirus and SSL encryption), access control, and other internal security policies.
Your Rights - How to Access and Limit Our Use of Certain Personal Data. Subject to applicable law and in addition to other rights as set forth below, you may have a right to access, update, delete, and/or obtain a copy of the Personal Data we have collected about you. You also have the right to object at any time to processing your Personal Data for certain purposes, including marketing purposes.
Data Retention. We retain Personal Data for as long as necessary for the purposes set forth in this Privacy Notice. We consider several different factors when determining the appropriate retention periods.
Cookies and Similar Technologies. We use cookies and similar technologies to help personalize your experience by helping save your settings and customizations across visits. You can adjust your settings to determine which cookies are allowed. More information about our use of cookies can be found here.
Third-Party Applications and Services. All use of third-party applications or services is at your own risk and subject to such third party's privacy policies.
Communications. We may send you e-mail or other messages about us or our Services. You always have the opportunity to opt-out of receiving certain messages that are not service-related. Note that you may receive personal communications from individuals within our organization without having the opportunity to opt-out of such communications.
Children. We do not knowingly collect Personal Data from children under the age of sixteen (16).
Changes to the Privacy Notice. We may change this Privacy Notice from time to time and shall notify you of such changes by indicating on our Site the Privacy Notice has been amended by publishing an updated Privacy Notice on the Site.
Comments and Questions. If you have any comments or questions about this Privacy Notice, or if you wish to exercise your legal rights with respect to your Personal Data, please contact us at privacy@arnon.co.il.
***
1.1 YA Clients
1.1.1 Services – If you are a client, we collect certain Personal Data that you provide to us including your name, email address, the company for which you work, if relevant, and your role there, including attendance of business meetings, events and conferences related to YA. We also collect Personal Data provided to us by or on behalf of our clients or generated by us in the course of providing Services to them, which may include special categories and/or sensitive data as well as criminal data – which shall all be processed in accordance with any applicable law and/or the data subject's consent, as
applicable.
How we use this data: (1) To provide you with Services; to manage our relationships with our clients and business partners; (2) for conflict, reputational and financial checks, business, finance, administration, KYC- anti-money laundering regulations; and (3) for marketing purposes – to contact you with informational newsletters, legal updates, invites for events and conferences and other messages about us and/or our Services, including targeted offers based upon Services you have obtained from us in the past.
Legal Basis: (1) We process this Personal Data for the purpose of providing the Services to you, which is considered performance of a contract, including responding to your inquiries and requests. (2) When we process your Personal Data for the purposes of conflict, reputational and financial checks, business, finance, administration, or marketing purposes, such processing is based on our legitimate interests. (3) When we process your Personal Data for KYC-anti-money laundering regulations such processing is based on our regulatory obligation.
1.1.2. Data Processed on Behalf of Clients
1.1.2.1. In the course of providing Services to our clients, we may process information about our clients' employees, business partners, customers, investors, or parties involved in legal disputes with our clients.
How we use this data: We process this data: (1) to provide the relevant client with our Services, and (2) to fulfill our statutory obligations.
Legal Basis: We process this Personal Data based on: (1) performance of a contract for provision of Services to the relevant client, (2) our legitimate interests to provide and/or improve our Services and for research and development purposes, and (3) to fulfill a legal obligation regarding the retention of client documents and materials.
1.1.2.2. In the course of providing Services to our clients, we may process certain Personal Data they provide to us as a data processor. We serve as a processor for our clients in cases where: (i) the client gives us specific instructions regarding the processing of the Personal Data, (ii) we don't need to process the Personal Data outside of the client's instructions in order to provide our Services, and (iii) we don't need to process the Personal Data outside of the client's instructions to comply with any legal requirement. When we serve as a processor for our clients, we process Personal Data on their behalf and in accordance with their instructions.
1.2.1 Contact Information - When you request information from us, or contact us for any other reason, we will collect any data you provide, such as your name, email address, and the content of your inquiry. When you sign up for newsletters or email lists, we collect your name and email address.
How we use this data: To respond to your request or inquiry and to provide you with newsletters, legal updates and for retargeting purposes.
Legal Basis: We process this Personal Data based on performance of a contract when we respond to your inquiry and provide you with newsletters. Processing your Personal Data for retargeting purposes is based on your consent.
1.2.2 Recruitment Data – If you send us a job application or make an inquiry, you may provide us with Personal Data, including a copy of your CV and other relevant information.
How we use this data: For recruitment and hiring purposes.
Legal Basis: For our legitimate interest for recruitment and hiring purposes.
1.2.3 Automatically Collected Data - When you visit our Site, we automatically collect information about your computer or mobile device, including non-Personal Data such as your operating system, and Personal Data such as IP address, device ID, and your browsing history, search terms, traffic data and any information regarding your viewing our Site. For more information about the cookies and similar technologies we use and how to adjust your preferences, please see our Cookie Policy.
How we use this data: (1) To review usage and operations, including in an aggregated non-specific analytical manner, develop new products or services and improve current content, products, and Services; (2) to prevent fraud, protect the security of our Site, and address any problems with the Site; (3) to provide you with customized content, targeted offers, and advertising related to our products and Services such as invitations for events and conferences and other messages about us or our Services, including targeted offers based upon your interest based on your usage history on the Site, on other third-party sites or apps you may visit and/or use.
Legal Basis: We process this Personal Data for our legitimate interests to develop our products and Services, review usage, perform analytics, prevent fraud, for our recordkeeping and protection of our legal rights and to market our own products and Services. Additional information regarding direct marketing is provided below.
1.3 Event Participants – From time to time, we, and/or together with our partners, hold special events in which we may invite you to participate. If you receive an invitation, we may collect the following Personal Data from you:
1.3.1 Registration Data - when you register for and participate in an event, we collect Personal Data from you, such as your name, contact details, and any other information we may request.
How we use this data: We use this data to: (i) help us plan the event and for other logistical purposes as well as to contact you with reminders and updates about the event; (ii) ask for your feedback regarding the event in order to improve future events and/or our Services; and (iii) send you marketing information about future events and other YA updates.
Legal Basis: (i) When we process this Personal Data in the course of planning for and running the event, we do so based on the performance of a contract with you; (ii) when we process this Personal Data to improve our events and Services, we do so based on our legitimate interest to grow and improve our business and Services; (iii) when we process this Personal Data to send you marketing information, we do so based on your consent. You may withdraw your consent at any time by contacting us at privacy@arnon.co.il.
1.3.2 Event Pictures – We may hire photographers to cover certain events. Event participants may be photographed directly or may appear in the background of event photos.
How we use this data: We may post event pictures, including on social media, to notify or update the public that the event took place. We may tag individuals in specific photos. We may also use the photos in other marketing materials.
Legal Basis: When we collect event pictures, we do so on the basis of our legitimate interest to market future events and our Services.
2.1 Statistical Information and Analytics - We and/or our service providers use analytics tools, including "Google Analytics" to collect and analyze information about the use of the Site, such as how often users visit the Site, what pages they visit when they do so, and what other sites and mobile applications they used prior to visiting the Site. By analyzing the information we receive, we may compile statistical information across a variety of platforms and users, which helps us improve our Site, understand trends and customer needs and consider new products and services, and tailor existing products and services to customer desires. The information we collect is anonymous and aggregated and we will not link it to any Personal Data. We may share such anonymous information with our partners, without restriction, on commercial terms that we can
determine in our sole discretion. You can find more information about how Google collects information and how you can control such use at https://policies.google.com/technologies/partner-sites.
2.2 Direct Marketing - As described above, we may use Personal Data to let you know about our products and Services that we believe will be of interest to you. We may contact you by email, post, or telephone or through other communication channels such as through social media platforms. In all cases, we will respect your preferences for how you would like us to manage marketing activity with respect to you. To protect privacy rights and to ensure you have control over how we manage marketing with you:
2.2.1 We will take steps to limit direct marketing to a reasonable and proportionate level and only send you communications which we believe may be of interest or relevance to you.
2.2.2 You can ask us to stop sending email marketing by following the "unsubscribe" link you will find on all the email marketing messages we send you. Alternatively, you can contact us, Here.
2.2.3 You can change the way your browser manages cookies, which may be used to deliver online advertising, by following the settings on your browser as explained in our Cookie Policy. If our marketing activities are based upon your consent, you may withdraw this consent at any time.
2.3 We recommend that you routinely review the privacy notices and preference settings that are available to you on any social media platforms.
3.1 Service Providers, Subcontractors and Business Partners. We also disclose information, including Personal Data we collect from and/or about you, to our trusted service providers and subcontractors, who have
agreed to confidentiality restrictions and who use such information solely on our behalf in order to: (1) help us provide you with the Site and/or Services; (2) aid in their understanding of how users are using our Site;
(3) for the purpose of direct marketing (see above for more details); or (4) assist us in (co-) hosting a particular event or conference. Any business partners involved in organizing events in which you participate are
independent and separate controllers of your Personal Data and may contact you with offers (such as events, lectures, etc.) that such party determines may be relevant to your interests.
Such service providers and subcontractors provide us with IT and system administration services, data backup, security, storage, and management services, data analysis, ERP systems, email distribution, social media services, and help us serve advertisements and other marketing to our clients and may assist us in (co-) hosting a particular event or conference.
3.2 Data Controllers. When you use our Site, we also disclose your Personal Data to additional third parties, such as business partners, which act as independent, separate controllers with respect to the collection of your
Personal Data. The details and contact information of such controllers are as set forth below.
Facebook, Inc. |
Privacy Operations, 1601 Willow Road, Menlo Park, CA 94025, USA |
3.3 Business Transfers. Your Personal Data may be disclosed as part of, or during negotiations of, any merger, sale of company assets or acquisition (including in cases of liquidation) in such case, your Personal Data
shall continue being subject to the provisions of this Privacy Notice.
3.4 Law Enforcement Related Disclosure. We may share your Personal Data with third parties (i) if we believe in good faith that disclosure is appropriate to protect our or a third party's rights, property or safety
(including the enforcement of the Terms and this Privacy Notice); (ii) when required by law, regulation subpoena, court order or other law enforcement related issues, agencies and/or authorities; or (iii) as is necessary
to comply with any legal and/or regulatory obligation.
3.5 Legal Uses. We may use your Personal Data as required or permitted by any applicable law, for example, to comply with audit and other legal requirements.
4.1 We use subcontractors and service providers and have business partners who are located in countries other than your own, such as Ireland, Israel, and the US and send them information we receive (including Personal
Data). We conduct such international transfers for the purposes described above. We will ensure that these third parties will be subject to written agreements ensuring the same level of privacy and data protection as set forth in this Privacy Notice, including appropriate remedies in the event of the violation of your data protection rights in such third country.
4.2 Whenever we transfer your Personal Data to third parties based outside of the European Economic Area ("EEA"), we ensure a similar degree of protection is afforded to it by ensuring at least one of the following
safeguards is implemented:
4.2.1. We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the European Commission.
4.2.2. Where we use certain service providers, not located in countries with an adequate level of protection as determined by the European Commission we may use specific contracts approved by the European
Commission which give Personal Data the same protection it has in the EEA.
4.3 Please contact us at privacy@arnon.co.il if you would like further information on the specific mechanism used by us when transferring your Personal Data out of the EEA.
5.1 Safeguards – The physical, electronic, and procedural safeguards we employ to protect your Personal Data include secure servers, firewalls, antivirus, and SSL encryption of data.5.2 Access Control – We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after employee termination.
5.3 Internal Policies – We maintain and regularly review and update our privacy related and information security policies.
5.4 Personnel – We require new employees to sign non-disclosure agreements according to applicable law and industry customary practice.
5.5 Encryption – We encrypt the data in transit using secure SSL protocols.
5.6 Database Backup – Our databases are backed up on a periodic basis for certain data and are verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality
and integrity, are tested regularly to ensure availability, and are accessible only by authorized personnel.
5.7 However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Data, we cannot
guarantee its absolute security.
5.8 As the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect user IDs and passwords, please take appropriate measures to
protect this information.
6.1 Right of Access. You have a right to know what Personal Data we collect about you and, in some cases, to have such Personal Data communicated to you. Subject to applicable law, we may charge you with a fee.
Please note that we may not be able to provide you with all the information you request and in such case, we will endeavor to explain to you why.
6.2 Right to Data Portability. If the processing is based on your consent or performance of a contract with you and processing is being carried out by automated means, you may be entitled to (request that we) provide
you or another party with a copy of the Personal Data you provided to us in a structured, commonly-used, and machine-readable format.
6.3 Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, complete, correct or delete inaccurate, incomplete, or outdated Personal Data.
6.4 Deletion of Personal Data ("Right to Be Forgotten"). If you are an EU Individual, you have a right to request that we delete your Personal Data if either: (i) it is no longer needed for the purpose for which it was
collected, (ii) our processing was based on your consent and you have withdrawn your consent, (iii) you have successfully exercised your Right to Object (see below), (iv) processing was unlawful, or (iv) we are
required to erase it for compliance with a legal obligation. We cannot restore information once it has been deleted. Please note that to ensure that we do not collect any further Personal Data, you should clear our
cookies from any device where you have visited our Site. We may retain certain Personal Data (including following your request to delete) for audit and record-keeping purposes, or as otherwise permitted and/or
required under applicable law.
6.5 Right to Restrict Processing. If you are an EU Individual, you can ask us to limit the processing of your Personal Data if either: (i) you have contested its accuracy and wish us to limit processing until this is verified;
(ii) the processing is unlawful, but you do not wish us to erase the Personal Data; (iii) it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise, or defend of a legal
claim; (iv) you have exercised your Right to Object (below) and we are in the process of verifying our legitimate grounds for processing. We may continue to use your Personal Data after a restriction request under
certain circumstances.
6.6 Direct Marketing Opt-Out. You can change your mind at any time about your election to receive marketing communications from us and/or having your Personal Data processed for direct marketing purposes. If you
do, please notify us by contacting us at privacy@arnon.co.il. We will process your request as soon as reasonably possible, however it may take a few days for us to update our records before any opt out is effective.
6.7 Right to Object. If you are an EU Individual, you can object to any processing of your Personal Data which has our legitimate interests as its legal basis, if you believe your fundamental rights and freedoms outweigh
our legitimate interests. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
6.8 Withdrawal of Consent. You may withdraw your consent in connection with any processing of your Personal Data based on a previously granted consent. This will not affect the lawfulness of any processing prior to
such withdrawal.
6.9 Right to Lodge a Complaint with Your Local Supervisory Authority. If you are an EU Individual, you may have the right to submit a complaint to the relevant supervisory data protection authority if you have any
concerns about how we are processing your Personal Data, though we ask that as a courtesy you please attempt to resolve any issues with us first.
7.1 Subject to applicable law and our (regulatory) obligations we retain Personal Data as necessary for the purposes set forth above. We may maintain records of the Personal Data we collect for our recordkeeping and
for protection of our legal rights.
7.2 We may delete information from our systems without notice to you once we deem it is no longer necessary for these purposes. Retention by any of our processors may vary in accordance with the processor's
retention policy.
7.3 In some circumstances, we may store your Personal Data for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, audit, accounting requirements and so that we
have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings. To determine the
appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we
process your Personal Data, and whether those purposes can be achieved through other means, as well as applicable legal requirements.
7.4 When processing Data on behalf of our clients, due to regulatory requirements, we may be obligated to retain such Data beyond the term of the provision of Services to the applicable client.
7.5 Please contact us at privacy@arnon.co.il if you would like details regarding the retention periods for different types of your Personal Data.