<<

PRIVACY POLICY

Updated to May 25th, 2018

Our Commitment to Your Privacy:

This is the privacy policy ("the policy") of Superstar Holidays Limited, of Blackburn Road, Blackburn House, London NW6 IRZ "Superstar Holidays", a whole owned subsidiary of Airlines, Ltd., P.O.B. 41, Ben Gurion Airport, Israel 70100 ("the company," "EL AL" or "we")

EL AL and Superstar Holidays are committed to protecting personal information about you and to your privacy. As part of this commitment, we undertake to uphold the following principles:

 To act with transparency in all matters pertaining to collecting and using information about you:

It is important to us that at all times you have all the information you need at hand to make intelligent decisions about our use of personal information about you. To this end we will implement several techniques and means intended to make relevant information accessible to you about how information about you is being used, at the appropriate time and manner.

Our full privacy policy is intended to provide you with as broad a picture as possible about the types of personal information that we gather and how we use and protect it. Therefore, it is important that you read the policy at your first opportunity and then again from time to time.

In addition, where we find that you need specific information, we will provide it to you at the appropriate time and place.

Furthermore, we will answer any questions you have and provide you with any clarification needed, subject to legal limitations. To this end, you can contact our data protection officer as follows:

Adv. Hila Stern Atias Data Protection Officer, EL AL Israel Airlines, Ltd. Ben Gurion Airport, P.O. box 41, Israel 7015001 972-3-9716653 [email protected]  To use personal information about you only for the purpose detailed in the following privacy policy.

The purposes for which we use personal information about you include, inter alia, providing services or products that you order, improving your experience in using them and our service channels, providing you with service about your reservations, improving our services and products, protecting our interests and rights, conducting commercial and administrative activity that supports the provision of services and products to our customers, adhering to the legal injunctions that apply. For the full list of purposes for which EL AL and/or Superstar uses personal information about people, see Section 7 for our full privacy policy.

In addition, we will use personal information about you to learn about your needs and preferences and send you offers tailored to you. You have the right at any time to request that we cease to use personal information about you to send you personally tailored offers, as above, and we will respect your request accordingly.

 To invest extensive resources to respect your rights pertaining to personal information about you.

We are investing extensive resources to enable you to realize your rights as the object of the information. Therefore, at any time that you wish to examine, correct, delete or have us cease to use personal information about you for specific purposes or in general, or to transfer it to you or to another agent, you can contact us and we will respect your request at the very least to the extent that we are obligated by law;

 To securely protect personal information about you.

While we cannot ensure absolute protection of your personal information, we undertake to implement and continually utilize a broad range of means intended to ensure the security of your personal information.

Our Full Privacy Policy

What Is Covered by the Privacy Policy:

This policy describes the types of personal information the company gathers about people, how it collects, uses, shares it with third parties, retains and processes it, etc.

All references to "personal information" in this policy refer to all information about an identified or identifiable person; an identifiable person is one who can be identified directly or by combining additional data in our possession or that we can access.

Similarly, all references in this policy to "processing" personal information refer to any action pertaining to personal information, including, inter alia, its collection, retention, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, revelation, transmission, distribution, accessing, combining, integration, unification, arrangement, limitation, deletion and/or destruction.

1. Data Controller

The company:

The company serves as the Data Controller of personal information about you.

Joint Data Controllers

If you make a flight reservation through the company but part of it is carried out by another airline, that airline will serve as a separate "Data Controller." The manner in which that airline gathers, uses and processes personal information about you is part of that airline's privacy policy.

Moreover, the company is part of a group of companies that also includes Sun D'or International Airlines, Ltd., P.O.B. 41, Ben Gurion Airport, Israel, 70100, Superstar Holidays ltd, Blackburn Road, Blackburn House, London NW6 1RZ. ("EL AL Group")

Each of the companies in the Group performs specific activities that constitute part of the overall activity of the Group, which is aviation transport by means of aircraft or auxiliaries. In this activity, which as noted includes all of the above companies, the Group members share among them personal information about people for their internal needs.

Therefore, personal information about you that is gathered by the company may be shared with the other companies in the Group. The latter may use it only for their internal needs. Vice versa, personal information about you which other companies in the Group gather about you may be shared with the company, which will use it only for its internal needs.

In each of the above cases, the company and the other companies in the Group will be considered "joint data controllers" regarding personal information about you, and they will be responsible together and individually for adhering to the obligations to protect personal information about you.

If you have any questions about activities involving the processing of your personal information or would like to realize your rights about personal information, you are invited to contact the company, which will deal with your request even if it entails another member of the Group, at the registered address of the company above, or by sending email to: [email protected].

You can also contact one of the Group members that process personal information about you together with the company, as listed below:

Sun D'or International P.O.B. 41, Ben Gurion Airlines Ltd. Airport, Israel 70100

Superstar Holidays ltd Blackburn House Blackburn Road London NW6 1RZ

2. Data Protection Officer and Company Representative in the European Union

In matters pertaining to European laws for the protection of privacy, the company representative to the EU is as per ELAL and the company Data Protection Officer is.

3. When we gather personal information about you:

Personal information about you is collected or received from you: We gather personal information about you any time you use our services or products, our service channels, such as websites and applications that we operate, or contact us. In some cases, you actively submit information to us. In other cases we receive information by observing your uses of our services and products or our service channels.

Personal information about you that is collected or obtained from third parties: In some cases, we may receive information about you from third parties, such as when you make reservations for flight tickets or other company products or services through other airlines, travel agents, your employer or another person. Whenever you make a reservation as noted above for another person, you are obligated to draw his attention to the fact that you are going to submit information about him to the company, and to draw his attention to this policy.

We may also send you offers for services or products offered by third parties who are our commercial partners. These offers may include websites or applications operated by us through referrals that include pages or sites operated by third parties [for details see Section 17, Links to Third Party Websites, below], or referrals to you through our newsletters (insofar as you subscribe to them), through company representatives or in any other manner.

Whenever you purchase services or products from third parties that our commercial partners as noted above, we will receive details of your transactions with them and we will use these details to tailor offers sent to you in the future so that they are more relevant to you. For details about company use of information about your transactions with its commercial partners see Section 7 (Aims of Processing Personal Information and the Legal Bases for Processing Personal Information) below.

4. Not Submitting Personal Information to the Company and its Consequences:

You are not obligated to submit any personal information about yourself to us. However, in certain cases, not submitting personal information about yourself will result in our not being able to supply you with the service or product that you requested from us. Following are details about these cases:

Legal obligations applying to the company: Certain legislative directions that apply to the company require it to gather certain types of personal information as a condition for providing its service or product. In these cases, if you do not submit the information to us, we will be unable to provide you with the service or product that you requested.

For example, certain legislative instructions require the company to submit personal details about passengers to public authorities at the destination countries of its flights. As you are not obligated to submit any personal information to us, if you do not submit certain types of personal information we will be unable to carry out your reservation and meet our legal obligations. Therefore, your refusal to submit such personal information to us will result in our not being able to complete your reservation.

Contractual obligation of the company: At times the company has a contractual obligation that requires it to submit personal information about you. In these cases, even though you are not obligated to submit the information to us, not submitting it results in our not being able to meet our contractual obligation towards you and as a result, we cannot provide you with the product or service you requested.

Thus, for example, if you order a vacation package through the company that includes flight and hotel accommodations, the company will be required to submit personal information about you, which it will send to the third party that is providing tourism services, so that the latter can arrange your reservation with the relevant hotel.

Submitting information is required for contracting with you: In some cases, submitting personal information about yourself is a condition for contractual ties between you and the company. Thus, in these cases too, even though you are not obligated to submit any personal information to us, not submitting certain types of personal information to us prevents us from entering contractual agreements with you and as a result, we cannot provide you with the service or product you requested.

For example, in the flight ticket reservation procedure, we require you to submit to us your email address so that we can send you the electronic flight ticket you ordered. If as part of the flight reservation you do not submit your email address to us for sending the e-ticket, we cannot complete your reservation.

5. Types of Personal Information the Company Gathers:

Information gathered when reserving flight tickets, vacation packages and auxiliary products and services: This information includes, inter alia, name, date of birth, identity number, passport number, PNR (reservation number), email address, cellphone number, country of citizenship and/or residence, gender, family status, medical limitations and medical equipment required on the flight, preferred meals, details of accompanying passengers on the flight, seat on the flight, personal inflight preferences, cabin class on the flight, flight destination and dates and data about auxiliary services and products purchased for the flight (such as additional baggage in the hold, option of choosing a seat and upgrading seats on the flight). For passengers to certain destinations such as the US, information is also gathered about a liaison person and address at the destination. In addition, if your flight is reserved by a corporate customer, the company may store data about your place of work, occupation and position with the corporate customer.

Information gathered during check-in: During pre-flight check-in, whether at the airport or through early check-in via our websites or applications, data will be gathered about you, such as your passport details and the weight of your baggage. In addition, as part of early check-in you may submit to us additional information about your inflight preferences and needs. Data gathered about Matmid Frequent Flyer Club Members: If you become a member of the Matmid Frequent Flyer Club, the company may receive and make use of additional information about you, such as your name, family status, email address, telephone, place of work and your position there, tier status in the club, passport details, country of citizenship, identifying number, date of birth, address, inflight preferences (such as beverages, magazines and preferred meals), additional data that you choose to include in your profile, type of FLY CARD in your possession (if you have a FLY CARD), points accrued in your club account and data about utilization of points in businesses that are commercial partners of the company. In addition, Matmid members have the option of opening a family ticket, by updating their personal data in their family account. The data uploaded by family members are: names of immediate family members, their dates of birth, relation to the club member, details of their passports and their family status.

Information gathered about customers subscribing to our application: When registering for our application, we gather information about you such as your name, email address, cellphone number, date of birth and ID number (only for customers with Israeli ID cards). Customers registered on our application have the option of scanning their passports. Passports are scanned using technology that transfers pictures to text and enables us to extract only the details we need to allow you to board the flight. In addition, customers registered on the application have the option of opening a family card, by updating their personal data in the family account (see above).

Information gathered during the process of ordering and using other products or services from the company: If you purchase products or services from the company that are not flight tickets or auxiliary flight products or services (such as duty free products, "Gift in the Sky" service, vacation packages and entry to company lounges in Israel and the world) or make use of them, the company will document and store details of the purchases or orders of these products or services, as well as data you submit as part of your order.

Information gathered when ordering products or services from third parties that are commercial partners of the company: If you purchase services or products from third parties that are our commercial partners as described in Section 4 (When We Gather Personal Information About You) above, we receive details of your transactions with them. These details include, inter alia, transaction dates, description of the purchased product or service, its price, etc.

Information gathered from payments using credit cards or PayPal: This information includes, inter alia, passenger's name, the name of the owner of the credit card used for payment, credit card details, payment conditions, PNR (reservation number), details of the flight reserved (, destination and dates), and ID number. In addition to this information, as part of payments made through our websites or applications, the following types of information are gathered: IP address of the device from which payment was made and details of the browser and internet supplier of the device used for payment.

Information gathered about your use of our websites or applications: This information includes, inter alia, the IP address or other device identifiers through which you surf our websites or applications, browser type, the device and operating systems through which you surfed our websites or applications, language preferences, the display and system of the device or browser through which you surfed our websites or applications, dates and times at which you accessed our websites or applications, which pages you surfed on the websites or applications, searches you carried out on the websites or applications, the pages from which you were referred to them and other surfing and use patterns on our websites and applications, reports of technical failures and additional technical information.

Information that will be transmitted as part of communication with you: If you make contact with the company and/or an agent acting on its behalf by sending an email, filling out a form on our website or application, chat, social networks or any other means, the information that you submit with each such contact – including complaints, requests, comments and ideas – will be stored. This is to clarify that if you contact the company and/or an agent on its behalf by telephone, customer service representatives may record and/or document the conversations in writing, inter alia, for monitoring the quality of service and for preventing fraud. In addition, if you subscribe to the company newsletter, the company will receive automatic updates each time you open the newsletter sent to you or click the link it includes.

Information from social networks: Subject to the privacy parameters that you define in your accounts on the various social networks, the company may obtain data from operators of social networks in which you have an account. Thus, for example, if you identify yourself on the company website or application through your Facebook account, we may obtain your account data, including information about your contacts and your areas of interest. In order to obtain details about which information we may obtain from various social network operators, and how to change privacy definitions for your social network accounts, it is important that you read the privacy policy of those networks.

Information submitted as part of customer surveys: The company may ask you to participate in customer surveys. Participation in such surveys is not obligatory but the data that you provide as part of those surveys will be stored by the company together with your identifying details and your contact data. Location data from your device: Solely as part of the use of the application, to the extent that this option is available as part of the privacy definitions of your device, we obtain data about the location of your device (details about how we use data about your location are available for viewing in the privacy policy for our applications). It is further clarified that IP addresses enable the company to produce general data about the location of your device (state and city).

Data about your location in airports: Some airports from which our flights depart employ technologies through which airport representatives can scan the barcode printed on boarding passes to the plane as passengers arrive at a defined number of points during the boarding stages at the airport. Airlines operating at these airports (among them the company) have access to data scanned from the flight tickets of passengers on their flights and thus can monitor the current stage of their passengers' boarding process. Passengers on flights leaving from these airports are given the option of rejecting the use of this type of technology.

Information gathered from your use of inflight entertainment systems: During flights operated by the company, you can use the entertainment systems, which vary according to aircraft type (for additional details about these systems enter: https://www.elal.com/he/PassengersInfo/OnBoard/In-flight- Entertainment/Pages/default.aspx. The systems include entertainment systems installed on aircraft, inflight WiFi connections and streaming systems on company flights. When you use these entertainment systems, the company gathers information about your use of the systems. Therefore, before using these systems you should read the privacy policy documents attached to these systems.

Information gathered during your participation in company bids and competitions: If you participate in bidding to purchase reduced-price flight tickets (Bid2Fly) or to upgrade flight tickets (EL AL Upgrade), the company registers the amounts of the bids you submit and your winnings in the bids. You will also be asked to submit details about means of payment for the flight ticket or upgrade. These details will be used only in cases that your bid wins.

Information gathered when applying for a position in the company: If you wish to apply for a position through our website, you will be asked to submit personal details about yourself, such as name, ID number, telephone number, email address, date of birth, gender, date of , citizenship, driver's licenses in your possession, health fund (kupat cholim) membership, home address, CV documents and references appended to your application, data about your education and experience, languages spoken, military service, where you obtained the employment application, and relatives working in the company. If you apply for a position as a pilot in the company, you will also be required to provide details about your flight hours, piloting licenses and a medical certificate.

6. Purposes of and Legal Bases for Processing Personal Information

The company processes personal information for one or more of the purposes detailed below.

In addition, the company will not make any use of personal information about you unless there is a legal basis for such use. The legal bases on which the company may be able to process information about you are as follows:

a. You consent to the company's processing of personal information about you for one or more specific purposes. EXAMPLE: To the extent that you consent, the company will send you newsletters with updates and benefits In cases where the legal basis for processing personal information about you is your consent, you have the right at any time to withdraw the consent you gave to process personal information about you by sending an email to the following email address: [email protected]

It is hereby clarified that if you withdraw your consent as noted, it is possible that we will not be able to provide you with some of the services you ordered or to provide them in the manner you intended, and for this you will have no recourse to any suit and/or demand and/or claim as a result.

b. Processing the information is required for implementing a contract to which you are a party or in order to take steps at your request before entering a contract. EXAMPLE; (1) We must process your reservation data to complete your reservation; (2) We require data about your means of payment in order to collect payment for products or services that you ordered c. Processing the information is necessary in order to fulfill a legal obligation that applies to the company. EXAMPLE: (1) If you order a flight to specific destinations (including but not limited to countries of the EU and the USA), as precondition for completing your reservation, we are required to gather information about you and transfer it to the relevant authorities at those destinations; (2) The company is required, by certain legislative injunctions, to inform at least one person included in each flight reservation about updates and changes that apply to the reserved flight, and therefore, as a condition for completing the flight reservation the company gathers contact details of at least one person included in the reservation d. Processing the information is required for the public good or for exercising official authority imposed on the company. EXAMPLE: The company is required to complete certain actions in processing passengers' personal information in order to safeguard passengers' security e. Processing the information is required for fulfilling legitimate interests of the company or a third party. EXAMPLE: (1) The company retains historical information about its customers' reservations to defend itself in cases of legal procedures; (2) The company gathers data about use of its websites and applications in order to identify and prevent their abuse; (3) The company records conversations with customers calling the Customer Service Center in order to monitor and improve service quality provided by the Center

It is hereby clarified that the legal bases detailed above are the legal bases for actions to process personal information, carried out by the company as empowered by the European information protection laws. It is hereby clarified that if the processing of personal information about you is subject to other legal systems, then the legal basis for processing this information may differ according to those laws.

The processing of personal information to fulfill the legitimate interests of the company or a third party is undertaken only after it is determined that the interests or basic rights and freedoms of the people to whom the personal information refers do not outweigh the legitimate interests of the company or of any third party.

In all cases in which personal information about you is processed on this legal basis, you may request at any time to receive details about the examination we conducted that led to our determination that specific personal information can be processed on this legal basis.

8. Your right to object to the processing of your personal data information based on the public good, official authority given to the company or legitimate interests In every event in which the legal basis for processing personal data about you is a mission or missions for the public good, exercising official authority given to the company or fulfilling legitimate interests of the company or a third party (for details about the legal bases for processing personal information, see section 7 above (Purposes of and Legal Bases for Personal Information Processing). At any time you can object to the processing of your information for these purposes, including the creation of a personal profile for the same purposes, and your request will be examined according to your special circumstances.

For more information, see chapter 11 (Your Rights Regarding Personal Data) below.

10. Your Right to Object to the Use of Your Personal Data for Direct Marketing Purposes The company aspires to provide customers or potential customers with content and offers that may be personally relevant to them, based on their personal preferences and needs. For this purpose, the company uses tools and techniques that automatically analyze personal information in a way that enables the company to draw conclusions about its customers or potential customers in a variety of aspects.

The resulting analyses and conclusions can enable us to present you with what we consider relevant content for you. For example, your uses of our websites and applications (searches, the pages you surf and so forth) can provide us with indications about which flight destinations or vacation packages may interest you. Based on these indications and on other personal data we have gathered about you from your visits to our sites or applications, we can send you offers for the types of flights or vacation packages in which you have shown an interest.

In addition, insofar as you consent to receive marketing offers from us, we can utilize these same analyses and conclusions to tailor our offers to you. For example, if you reserve a flight to a specific destination, we might send you offers to attractions at that destination. Likewise, the more our analyses indicate that you prefer to fly to a specific destination and in specific seasons, the more likely we are to send you offers for flights to the same destination during the same seasons.

You are entitled, at any time, to refuse to allow us to use your personal data for the purpose of personally tailoring marketing offers, including analyses and operational conclusions concerning you, by sending a message to our customer service center at [email protected].

Additionally, you are entitled, at any time and at no cost, to request that personal information about you not be used for advertisement mailings, as above, by sending an email with the subject “removal” to the following email address: [email protected]. If you choose this option, the company will continue to save personal data about yourself (including your contact details) but will not use them for the purpose of sending advertising material.

Please note that operational announcements are not sent to you for marketing purposes and they will continue to be sent to you even if you refuse to receive marketing messages from the company.

10. Forwarding Personal Information to Third Parties As mentioned in section 2 (Data Controller) above, the company shares personal information about people with other companies in the EL AL Group for the purpose of supporting the general activity of the EL AL Group and for the internal needs of other companies in the Group.

In addition, we are likely to forward personal information about you to the following third parties:

A. Third parties that facilitate your reservations. Such parties include, inter alia, other airlines that carry out continuation flights, various airport authorities and additional organizations that deal with your travel arrangements;

B. Providers and suppliers whose services assist us in providing services and products to our customers. Examples of such service providers and suppliers are IT services, legal advisers, accountants, suppliers of payment services etc.;

C. Service providers and suppliers in cases of disputes, claims, lawsuits, demands or legal procedures to which the company is party or any other case in which sharing their information would be essential for maintaining the rights or possession of the company and/or any third party;

D. Global distribution companies for tourism services (GDS), which provide suppliers of tourism services around the world (including the company) with distribution services for their customers. All flight ticket details of reservations made through every one of our service channels are automatically transferred electronically to one of the global distribution companies, mainly Amadeus IT Group, Sabre GLBL Inc. and LP Travelport;

E. Public authorities in various countries for the purpose of fulfilling legal obligations. For example, if you reserve flights to specific destinations (including countries in the European Union or the USA), the company is required by law to transfer reservation data about your flight ticket to public authorities at these destinations;

F. Public authorities in various countries for the purpose of upholding legal injunctions. These public authorities may include, inter alia, security, and immigration authorities.

G. The company’s business partners. In order to make accessible a wide variety of solutions of possible interest to you, we may offer you products and services of third parties that are the company’s business partners, either as part of our websites or applications or in any other way. If you express any interest in these offers, we may send personal information about you to those third parties.

H. In the event of the insolvency of Superstar Holidays, we or any appointed practitioner, may disclose your personal information to the CAA, and or ABTA so that they can assess the status of your booking and advise you on the appropriate course of action under any scheme of financial protection. The CAA’s General Privacy Notice is at https://www.caa.co.uk/Our-work/About-us/General-privacy-notice /ABTA’s Privacy Notice is at https://www.abta.com/privacy-noticePersonal information about you will be sent at the first date that the company is requested to or needs to forward such personal information.

Please note that where personal information about you is also retained by your travel agent, this policy does not apply to personal information held by the agent and the company is not responsible for the travel agent's actions pertaining to personal information.

In addition, if a third party offers to purchase the company or another company belonging to the EL AL Group or the assets of one of them (all or some) , personal information about you is likely to be exposed to that party.

11. Your Rights Relating to Personal Information About You

You are entitled to the following rights with regard to personal information about you:

The right to examine – Should you request it, you are entitled to receive confirmation from the company whether or not the company retains personal information about you, and if so, you may receive a copy of the said personal information as well as information about (1) the purposes for which personal information about you is processed, (2) the various categories of personal information about you, (3) who received or will receive (or categories of recipients) personal information about you, in particular existing or future recipients of aforesaid information in countries other than the European Union or international organizations, (4) to the extent possible, the duration of time that the personal information about you will be retained or if this is not possible, the criteria for determining the aforesaid duration of time, (5) your rights regarding personal information about you and its processing by the company, (6) your right to submit a complaint to the empowered authorities, (7) if the personal information about you held by the company was not obtained from you – information about the source of the information and (8) in the event that the personal information about you is transferred to a country outside of the European economic zone (namely countries that are not members of the European Union and are not Iceland, Lichtenstein or Norway) or to international organizations – the measures taken by the company in order to protect the information that is forwarded to those countries or organizations.

The company may require identifying details or additional information from you about your request, inter alia, to ascertain that it is not transmitting personal information about you to third parties.

Requests to examine personal information should be sent to the following email address: [email protected].

All additional requests for examination, beyond the first request, may entail payment for the expenses entailed in acceding to such a request. It is hereby clarified that your right to receive a copy of personal information about you as stated above is subject to the rights of others besides you. Therefore, if transmitting a copy of personal information about you may harm the rights of other parties as stated, the company may not accede to your request to receive a copy of personal information about you (in whole or in part) or may do so to a limited extent.

Right to correct personal information about you – If personal information about you that is processed by the company is not accurate, you have the right to request that the company make corrections in said personal information. Likewise, if the personal information about you is incomplete, you have the right to request that the company supplement said personal information and in light of the purposes of processing the personal information, the company will accede to your request.

Requests to correct and/or supplement personal information about you should be sent to the following email address: [email protected].

Right to delete personal information about you – You have the right to request that personal information about you in the hands of the company be deleted if (1) the personal information about you is not needed for the purposes for which it was gathered and/or processed, (2) the processing of information was done based on your consent and you cancel your consent to process the personal information about you, as long as there are no other legal bases justifying the processing of information about you, (3) you object to the processing of personal information about you, for your own reasons, if the legal basis for its processing is performance of a task or tasks for the public good, implementing official authority given to the company or fulfilling the legitimate interests of the company and/or a third party, including creating a profile about you by virtue of the above legal bases, and there are no decisive legitimate reasons for processing personal information about you that outweigh your interests, rights and freedoms (for further details, see the continuation of this section, "The Right to Object to Processing Personal Information about You"), (4) you object to processing the personal information about you for the purpose of direct marketing (for further details see Section 10 9 "Your Right to Object to the Use of Personal Information About You for Purposes of Direct Marketing" above, (5) the personal information about you was obtained and/or processed illegally, (6) the personal information about you must be deleted because of legal obligations imposed on the company, or (7) the personal information was collected in the context of offering services to a minor.

Requests to delete personal information about you should be sent to the following email address: [email protected].

This right of yours does not apply where the company has an obligation to process personal information about you imposed by laws applying to the company, fulfilling commitments stemming from the public interest or implementing official authority of the company, for public health interests, or for protection from legal suits.

Right to limit the use of personal information about you – You have the right to demand that limitations be imposed on the use of personal information about you by the company (1) insofar as you think that the personal information about you held by the company is not accurate – for a sufficient period of time that will allow the company to ascertain the correctness of the personal information about you, (2) if processing personal information about you is illegal and you request to limit its use instead of its deletion, (3) if the company has no further need or use for the personal information about you, but you need it to open, conduct or defend yourself against legal proceedings, or (4) if you object for reasons of your own to processing personal information about you where the legal basis for its processing is conducting a task or tasks for the public good, implementing official authority given to the company or fulfilling legitimate interests of the company and/or of a third part, including creating a profile of you based on the authority of the above legal bases – and until it is determined whether the company has decisive legitimate reasons for processing the personal information about you that outweigh your interests, rights and freedoms, or for basing, applying or defending against legal suits.

Requests to impose limitations of the use of personal information about you should be sent to the following email address: [email protected].

Right to object to the use of personal information about you – You have the right at any time to object, for your own reasons, to processing personal information about you, if the legal basis for its processing is performing a task or tasks for the public good, implementing official authority given to the company or fulfilling the legitimate interests of the company and/or a third party, including creating a profile of you by virtue of any of the above legal bases, unless the company proves the existence of decisive legitimate reasons for processing personal information about you that outweigh your interests, rights and freedoms, or for basing, implementing or protecting oneself from legal suits.

Likewise, you have the right at any time to object to personal information about you being processed for direct marketing purposes, including creating a profile of you for this purpose, and in the said case the company will cease processing personal information about you for direct marketing purposes (for further details see Section 9, "Your Right to Object to The Use of Personal Information About You for Direct Marketing Purposes").

Objections to the use of personal information about you as detailed above should be sent to the following email address: [email protected].

Right to mobility of personal information about you – You have the right to receive the personal information about you that you submitted to the company in a structured, acceptable format that is readable on a device and to transfer said information to another data controller. If it is technically possible, you have the right to request that the personal information about you be transferred directly by the company to the other data controller.

It is to be emphasized that your right to receive the personal information about you or to transfer it to another data controller applies only to personal information about you that was processed based on your consent or based on the need to implement a contract to which you are a party or to take steps at your request before signing a contract.

It is also emphasized that it is not sufficient to impinge on the company's right to retain a copy of the personal information about you as determined by European legislation regarding the protection of privacy.

Requests to receive and/or transfer personal information about you should be sent to the following email address: [email protected].

Right to cancel consent – You have the right at any time to cancel your consent allowing the company to use personal information about you based on your consent, from this moment onward; this does not detract from the legality of the use made of personal information about you before cancelation of said consent.

Requests to cancel consent should be sent to the following email address: [email protected].

Right to submit a complaint – If you have a complaint pertaining to personal information about you and/or this policy, you have the right to contact the Data Protection Officer for the company's protection of privacy, with the following details:

Adv. Hila Stern Atias Data Protection Officer, EL AL Israel Airlines, Ltd. Ben Gurion Airport, P.O. box 41, Israel 7015001 972-3-9716653 [email protected]

If you are dissatisfied with how your complaint is handled, you have the right to submit a complaint the Data Protection Authorities in the EU, mainly the Data Protection Authority located in your area of residence, place of work or place in which the violation occurred of your rights pertaining to personal information about you according to the European laws for the protection of privacy.

The company will respond to your request to fulfill each of your above rights in this section in relation to the company without delay and in any case within one month of receiving your request. The period of time may be extended by two additional months where necessary, taking into consideration the complexity and number of the requests; the company will inform you, within a month of receiving the request, about the above extension together with reasons for it. The response to your request to implement each of your said rights in this section vs the company is without charge. At the same time, if it becomes clear that your requests have no basis or are exaggerated, the company has the right to levy a fee for responding to or refusing requests.

12. Minors

Insofar as personal information about you may be gathered based on your consent, you must be above age 16 (or above age 13 if this is what the law in your country has determined). If you do not meet these age requirements, you are required to obtain the consent of your parent or guardian to process information in accordance with this policy; lacking such consent, the company will not supply you with its services. The company has the right to demand information and proof from you about your age, at the company's discretion.

13. Cookies files

Installation of Cookie Files When you visit the website a cookie file is installed in the device through which you access the site, and this device is assigned an identifying number in the company's systems. The company uses cookie files to monitor your activity patterns on the website, to improve and enhance the experience of visiting the website, and to offer you services and products of possible interest to you (based on information gathered through these files), and to provide you with support services insofar as you need them. At times the company allows third parties to install cookie files in your device, whether temporarily or permanently, and these serve the third parties in relation to their internet websites, products and/or services or what they offer. For further details, see the Website Cookies Policy

15. How Long Personal Information About You Is Retained

The company will retain personal information about you for the time required to attain the purposes for using the information detailed in this policy or for a longer period of time as required according to the instructions of the relevant laws.

For the most part, we will retain personal information about you according to the statutes of limitations in the relevant local law or according to the injunctions of regulations that apply to the company, insofar as they require it to retain information for longer periods.

In order to ensure that we do not retain personal information about you longer than required, we have developed technical means that systematically delete information according to predefined timetables. Beyond that, the company conducts periodic examinations at minimal frequency intended to ascertain that information about you is not retained beyond what is required, despite the technical means employed.

15. Transferring Personal Information to Other Countries and to International Organizations

Personal information about you may be transferred outside the borders of Israel, including to states whose laws assure a lower level of protection of personal information than the level determined in Israeli law. In such cases, the company will take steps to ensure a proper level of protection of personal information about you as detailed in this policy and as required by applicable law.

Personal information about you may be transferred beyond the EU zone (that is, to countries that are not members of the EU and are not Iceland, Lichtenstein or Norway) and to international organizations. In such cases, the company will take appropriate steps to ensure protection of the personal information about you as required by relevant applicable laws and at the very least will ascertain that at least one of the following conditions is met:

A. The information will be transferred to a country or international organization for which a valid decision has been made by the EU Council about the propriety of its protection of personal information transferred to that country or organization as noted (ordinance 45 of the general European ordinance for data protection 2016/679);

B. Transfer of information based on binding and valid agreements between public bodies and authorities (ordinance 46.2(a) of the general European ordinance for data protection 2016/679); C. Transfer of information according to contractual instructions approved by the EU Council and that imposes on those who received the information the obligation to protect the information at a level acceptable in the EU zone (ordinance 46.2(c) of the General Data Protection Regulation 2016/679);

The contractual orders that were adopted by the EU Council are available for viewing here: https://ec.europa.eu/info/law/law-topic/data- protection/data-transfers-outside-eu/model-contracts-transfer-personal- data-third-countries_en

You have the right at any time to receive details from the company about the steps it has taken to protect the information transferred outside the EU zone or to international organizations as noted above, by sending a message to the following address: [email protected].

16. How We Protect Personal Information About You

We use technical and organizational means to assure a high level of protection of personal information about you. In addition, at any time that we transfer or share personal information about you with third parties, we also obligate those third parties to take the technical and organizational steps necessary to prevent a decline in the level of protection of information. At the same time it is hereby clarified that at times we are required by legal and other obligations beyond our control to transfer personal information about you to third parties, such as public authorities. In these cases, we have limited control of the level of information protection taken by those parties.

Our websites and applications are secured by the accepted protocol: Secured Sockets Layer SSL 128. This protocol is intended to encrypt information on the internet. Despite the above, transferring information through the internet is not completely safe. Accordingly, the company cannot assure the security of the data transferred to our websites and applications, including the security of personal information about you that is transferred to the company.

17. Links to Third Party Websites

Our websites and applications sometimes include links to or from third party internet sites or sources to which you have access at your discretion. External websites as noted may look like our websites or applications and they may even include the company logo, but it is possible to identify them as such according to their URL address, which does not begin with www.sundor.co.il, www.elal.com, or www.flyup.co.il or through writing that indicates this explicitly. Please note that any such third party site or source may gather your personal data and use it differently from us. The company has no control over what is done with information collected on those sites and therefore it takes no responsibility whatsoever for how they gather or use data, share data with third parties or any other action they take with the data they have collected. Therefore, if you are referred to an external site, as noted, you are advised to carefully read the conditions of use and/or privacy policy of that site because this policy does not apply to them.

18. Changes in Privacy Policy

The company has the right to change the instructions of this policy from time to time. In any case in which changes are made in this policy, the company will announce these changes by publishing the updated policy on our websites or applications. Furthermore, in cases in which significant changes are made in the policy, we will make efforts to inform you of this through the channels of communication generally used in such circumstances and by publishing an open announcement about it on the websites and the applications. Unless stated otherwise, all changes will go into effect on the day of their publication on the specific website or application.