We at Smart Travel Agent Ltd. ("Company" "us", "we", or "our") recognize and respect the importance of maintaining the privacy of our customers and their end users. The Company operates the website located at https://www.smtagent.com (the "Site") and provides the SmartAgent mobile applications (the "App" or "Apps"). We take your privacy seriously and are committed to protecting the information we collect. We refer to our Site visitors and App users as users ("users") of the SmartAgent service (together, our "Service/s"). This Privacy Notice also explains how we collect, process, transfer, store and disclose the information collected, as well as your ability to control certain uses of the collected information. If not otherwise defined herein, capitalized terms have the meaning given to them in the Terms of Service, available at https://smtagent.com/terms-conditions.html ("Terms"). "You" means any adult user of the Services, or any parent or guardian of any minor whom you allow to use the Services, and for whom you will be held strictly responsible.
Company is the data controller in respect of some of the processing activities outlined in this Privacy Notice. Our registered office is at Hakidma 7 st' Yoqneam Illit, Israel, and our registration number is 515866614. When we process information in the context of providing Services to our customers ("Customers") including with regard to each Customer's end users, the applicable Customer serves as a controller with respect to such Customer's end user Personal Data (as defined below).
"Personal Data" means any information that refers, is related to, or is associated with an identified or identifiable individual or as otherwise may be defined by applicable law.
Privacy Notice Key Points
The key points listed below are presented in further detail throughout this Privacy Notice. These key points do not substitute the full Privacy Notice.
Personal Data We Collect. When you register, we collect Personal Data provided by you or by your superiors on your behalf, such as your name, email address and phone number. This data is required in order to supply SmartAgent services. We also collect Personal Data when you use the Services, or contact us with questions or complaints. When you use our Services, we automatically collect your IP address, browser type, browser version, the pages of our site that you visit, the time and date of your visit, the time spent on those pages and other statistics and operating system and other information about your use of the Services
PNR data from GDS systems we collect and analyze GDS PNR data in order to supply our services. PNR data collection is restricted to registered agent privileges and its maintenance period is limited according to service requirements. PNR information includes: itinerary details, passenger details (name, type, quantity), passenger contact details (name, phone number, email address), agent details (name, phone number, email), price details, segment status change details, alternative pricing options details.
How We Use Your Personal Data. We use the information (including Personal Data) we collect and/or receive mainly to administer and provide the Services, contact you with administrative information, contact you with marketing offers (if you indicated your desire to receive them), and improve the Services. To deal with inquiries through our website or to provide you with information and access to resources that you have requested from us. For network security and administration; to investigate and prevent fraud, spam, malware, identity theft or other unlawful activity.
Basis for Processing Your Personal Data. Processing your Personal Data is necessary for the performance of the terms and the provision of the Services to you. Processing for the purposes of developing new and enhancing our products and Services, for the marketing of our products and services, for analytics and usage analysis, for fraud prevention and for security and for our record keeping and protection of our legal rights – are all necessary for the purposes of legitimate interests that we pursue.
Sharing the Personal Data We Collect. We share the Personal Data we collect with our service providers and subcontractors who assist us in the operation of the Services and process the information on our behalf and under our instructions, [as well as with our business partners and affiliates who may offer you products and services, based on your preferences (if you indicated your desire to receive these).]
International Transfer. We use service providers and/or subcontractors and/or cooperate with or have business partners and affiliates located in countries other than your own, and send them your Personal Data. We will ensure that we have agreements in place with such parties that ensure the same level of privacy and data protection as set forth in this Privacy Notice. You hereby consent to such international transfer.
Security. We implement industry standard measures aimed at reducing the risks of damage and unauthorized access or use of Personal Data, but they do not provide absolute information security. Such measures include physical, electronic, and procedural safeguards (such as secure servers, firewalls, antivirus and SSL encryption), access control, and other internal security policies.
Your Rights. Subject to applicable law and additional rights as set forth below, you may have a right to access, update and/or delete your Personal Data and obtain a copy of the Personal Data we have collected about you. You can change your mind at any time about your election to receive marketing communications from us and/or having your Personal Data processed for direct marketing purposes. You also have the right to object at any time to processing your personal data for certain purposes, including marketing purposes. You have the right to withdraw your consent to processing, if provided, at any time by contacting us as detailed in this Privacy Notice.
Data Retention. We retain information for as long as necessary for the purposes set forth in this Privacy Notice. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether those purposes can be achieved through other means, as well as applicable legal requirements.
Children. We do not knowingly collect personally-identifiable information from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) has enrolled without parental permission, please advise us immediately.
Third-Party Applications and Services. All use of third-party applications or services is at your own risk and subject to such third party's privacy policies.
Communications. Subject to your consent and applicable law, we may send you e-mail or other messages about us or our Services. You can stop receiving future communications from us by following the UNSUBSCRIBE link located at the bottom of each communication, by emailing us at firstname.lastname@example.org.
Changes to the Privacy Notice. We may change this Privacy Notice from time. We encourage you to review it periodically. By continuing to access or use the Services after those changes become effective, you agree to be bound by the revised privacy notice.
Comments and Questions. We have appointed a data protection officer (DPO) who is responsible for overseeing our privacy practices. If you have any comments or questions about this privacy notice, or if you wish to exercise your legal rights with respect to your Personal Data, please contact us at email@example.com.
Personal Data We Collect
We collect information from you when you choose to use our Services. In order to use our Services, you will be required to register and provide us with certain Personal Data, such as your name and email address and phone number.
We also collect Personal Data when you make use of the Services, request information from us, sign up for newsletters or our email lists, complete online forms, or contact us for any other reason. Examples of the Personal Data that we collect from you when you engage in any of the activities detailed above, may include your name, phone number and e-mail address. Such Personal Data may be collected by us through the Services.
We also collect any materials including images and/or pictures and/or photos and/or documents you may upload to the App/Site/Platform.
In addition, when you use the Services, certain information may be automatically gathered about your computer or mobile device, such as IP address, browser type, browser version, the pages of our site that you visit, the time and date of your visit, the time spent on those pages and other statistics and operating system and other information about your use of the Services.
It is your voluntary decision whether to provide us with any such Personal Data, but if you refuse to provide such information we may not be able to register you to and/or provide you with the Services.
How We Use Your Personal Data
We and any of our trusted third-party subcontractors and service providers use the Personal Data we collect from and about you for any of the following purposes: (1) to provide you and our Customers with the Services; (2) to respond to your inquiries or requests, contact and communicate with you; (3) to develop new products or services and conduct analyses to improve our current content, products, and services; (4) to provide you with customized content, targeted offers, and advertising on the App/Platform/Site, on other third-party sites or apps you may visit, or via e-mail, [based upon [your shopping history and usage of products you have previously purchased/the content on our Site/Platform/App you have clicked on / your preferences]]; (5) to contact you with informational newsletters and promotional materials relating to our Services; (6) to review the usage and operations of our Services; (7) to use your data in an aggregated, non-specific format for analytical purposes (as detailed below); (8) to prevent fraud, protect the security of our Services, and address any problems with the Services and (9) to provide customer support. [Note: please add other uses if applicable]
By analyzing all the information we receive, including all information concerning users, we may compile statistical information across a variety of platforms and users ("Statistical Information"). Statistical Information helps understand trends and customer needs so that new products and services can be considered and so that existing products and services can be tailored to customer desires. Statistical Information is anonymous and aggregated and we will not link Statistical Information to any Personal Data. We may share such Statistical Information with our partners, without restriction, on commercial terms that we can determine in our sole discretion.
We may use your Personal Data as required or permitted by any applicable law.
Basis for Processing Your Personal Data
Processing your Personal Data is necessary for the performance of the Terms and the provision of the Services to you, including responding to your inquiries or requests, contacting and communicating with you and providing customer support. When you make a purchase, use our Services or engage in any other transaction with us, we may also process your Personal Data to perform that contract.
Processing the information for third-party marketing purposes is based upon your consent. When using the Services, you shall be asked to accept the terms of this Privacy Notice, including the processing of your Personal Data for marketing purposes. You may withdraw your consent to receive marketing communications from us and/or having your Personal Data processed for direct marketing purposes at any time by contacting us as detailed in this Privacy Notice. We will process your request as soon as reasonably possible, however it may take a few days for us to update our records before any opt out is effective.
Processing for the purposes of developing new and enhancing our products and Services, for analytics and usage analysis, for the marketing of our products and services, for fraud prevention and security and for our recordkeeping and protection of our legal rights – are all necessary for the purposes of legitimate interests that we pursue. In conducting such processing activities, we balance these legitimate interests against the rights and interests of our users. If you would like more information regarding how we make such determinations, please contact us through the contact information specified below.
Please note that we may process your Personal Data for more than one legal basis depending on the specific purpose for which we are using your Personal Data. Please contact us if you would like details about the specific legal ground we are relying on to process your Personal Data.
Sharing the Personal Data We Collect
We share your information, including Personal Data, as follows:
Business Partners, Service Providers, Affiliates, and Subcontractors
We disclose information, including Personal Data we collect from and/or about you, to our trusted service providers, business partners, affiliates, subcontractors, who use such information to: (1) help us provide you with the Services; (2) aid in their understanding of how users are using our Services. (3) when you have consented to such disclosure, provide to you targeted offers and advertising on both our Services, as well as on other apps/platform/sites you choose to visit, based upon [your purchase history and usage of products you have previously purchased/the content on our Services you have clicked on / your preferences] .
Service providers and sub-processors based globally, which provide applications/functionality, data processing, marketing or IT services, such as a server and application hosting Cloud Platform, identity management service, website hosting and management, data analysis service, crash analysis service, data back-up service, email service, security and storage services.
We may transfer our databases containing your Personal Data if we sell our business or part of it, including in cases of liquidation. Information about our users, including Personal Data, may be disclosed as part of, or during negotiations of, any merger, sale of company assets or acquisition and shall continue being subject to the provisions of this Privacy Notice.
Law Enforcement Related Disclosure
We will fully cooperate with any law enforcement authorities or court order requesting or directing us to disclose the identity, behavior or (digital) content and information of or related to an individual, including in the event of any user suspected to have engaged in illegal or infringing behavior. We may also share your Personal Data with third parties: (i) if we believe in good faith that disclosure is appropriate to protect our rights, property or safety (including the enforcement of the Terms and this Privacy Notice); (ii) to protect the rights, property or safety of third parties; (iii) when required by law, regulation subpoena, court order or other law enforcement related issues; or (iv) as is necessary to comply with any legal and/or regulatory obligation. You can request such Personal Data as specified herein by emailing us at firstname.lastname@example.org.
We use subcontractors and service providers and have business partners and affiliates who are located in countries other than your own, as set forth above and send them information we receive (including Personal Data). We conduct such international transfers in order to receive development services and application support services. We will ensure that these third parties will be subject to written agreements ensuring the same level of privacy and data protection as set forth in this Privacy Notice, including appropriate remedies in the event of the violation of your data protection rights in such third country.
Whenever we transfer your Personal Data to third parties based outside of the European Economic Area (EEA), we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the European Commission.
Where we use certain service providers, we may use specific contracts approved by the European Commission which give Personal Data the same protection it has in the EEA.
Where we use providers based in the US, we may transfer data to them if they have been certified by the EU-US Privacy Shield which requires them to provide similar protection to Personal Data shared between the Europe and the US or any other arrangement which has been approved by the European Commission.
Please contact us the contact information listed below if you would like further information on the specific mechanism used by us when transferring your Personal Data out of the EEA.
You hereby consent to such international transfer described above.
We make efforts to follow generally accepted industry standards to protect the Personal Data submitted to and collected by us, both during transmission and once we receive it, including by implementing the below:
Safeguards - The physical, electronic, and procedural safeguard we employ to protect your data include secure servers, firewalls, antivirus and SSL encryption of data.
Access Control - We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after employee termination.
Internal Policies - We maintain and regularly review and update our privacy related and information security policies.
Personnel - We require new employees to sign non-disclosure agreements according to applicable law and industry customary practice.
Encryption - We encrypt the data in transit using secure SSL protocols.
Database Backup – Our databases are backed up on a periodic basis for certain data and which are verified regularly. Backups are and stored within the production environment to preserve their confidentiality and integrity and are accessed only by authorized personnel.
However, no method of transmission over the Internet, or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
It should be mentioned that in order to provide efficient services including push notifications to you we are using auto login function in such way that you stay login in web and mobile apps as long as you didn't perform logout. We expect that you will implement strong security controls on endpoint devices to prevent unauthorized access to the devices and the web and mobile apps.
Your Rights - How to Access and Limit Our Use of Certain Information
You have certain rights in relation to the Personal Data that we hold about you, as detailed below. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information and/or comply with any of your requests, as detailed below:
Right of Access and Data Portability. You have a right to know what Personal Data we collect about you and, in some cases, to have the information communicated to you. Subject to the limitations in applicable law, you may be entitled to obtain from us a copy of the Personal Data you provided to us (excluding information that we obtained from other sources) in a structured, commonly-used, and machine-readable format, and you may have the right to (request that we) transmit such Personal Data to another party. If you wish to exercise this right please contact us letting us know what information in particular you would like to receive and/or transmit. Subject to applicable law, we may charge you with a fee. Please note that we may not be able to provide you with all the information you request, for instance, if the information includes Personal Data about another person. Where we are not able to provide you with information that you have asked for, we will endeavor to explain to you why. We will try to respond to any request for a right of access as soon as possible.
Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, correct or delete inaccurate or outdated Personal Data and/or that we suspend the use of Personal Data, the accuracy of which you may contest, while we verify the status of that Personal Data. We will correct your Personal Data within a reasonable time from the receipt of your written request thereof.
Deletion of Personal Data ("Right to Be Forgotten"). In certain circumstances you have a right to have Personal Data that we hold about you deleted. Should you wish to have any Personal Data about you deleted, please contact us, using the contact information specified in this Privacy Notice. Subject to applicable law, we will delete Personal Data provided to us by a user within a reasonable time from the receipt of a written (including via email) request by such user to delete such collected Personal Data. We cannot restore information once it has been deleted. Please note that to ensure that we do not collect any further Personal Data, you should also delete our App from your mobile devices and terminate your account with us and clear our cookies from any device where you have used our App. We may retain certain Personal Data (including following your request to delete) for audit and record-keeping purposes, as well as other purposes, all as permissible and/or required under applicable law. We may also retain your information in an anonymized form.
Account Deactivation. You can ask us to deactivate your account by contacting us using the information below. In order to deactivate your account, we may ask you for additional information.
Direct Marketing Opt Out. You can change your mind at any time about your election to receive marketing communications from us and/or having your Personal Data processed for direct marketing purposes. If you do, please notify us by contacting us as detailed in this Privacy Notice. We will process your request as soon as reasonably possible, however it may take a few days for us to update our records before any opt out is effective.
Right to Object. Subject to applicable law, you may have the right to object to processing of your Personal Data including for the purpose of direct marketing.
Supervisory Authority. If you are a European Citizen, you may have the right to submit a complaint to the relevant supervisory data protection authority.
Subject to applicable law, we retain information as necessary for the purposes set forth above. We may delete information from our systems, without notice to you, once we deem it is no longer necessary for the purposes set forth in this Privacy Notice. We may also retain your information in an anonymized form. In addition, retention by any of our processors may vary, in accordance with the processor's retention policy.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether those purposes can be achieved through other means, as well as applicable legal requirements.
Please contact us through the contact information listed below if you would like details regarding the retention periods for different types of your Personal Data. We retain this information for such period for audit and record keeping purposes.
Cookies and Similar Technologies
What are Cookies?
A cookie is a small piece of text that is sent to a user's browser or device. The browser provides this piece of text to the device of the originating user when this visitor returns.
A "session cookie" is temporary and will remain on your device until you leave the Site.
A "persistent" cookie may be used to help save your settings and customizations across visits. It will remain on your device for much longer or until you delete it.
First-party cookies are placed by us, while third-party cookies may be placed by a third party. We use both first- and third-party cookies.
Information may also be collected through web beacons, which are small graphic images ("pixel tags"), which usually work together with cookies in order to identify users and user behavior. These may be shared with third parties.
We may use the terms "cookies" to refer to all technologies that we may use to store data in your browser or device or that collect information or help us identify you in the manner described above.
The specific names and types of the cookies, web beacons, and other similar technologies we use may change from time to time. However, the cookies we use generally fall into one of the following categories:
Why We Use These Cookies
These cookies are necessary in order to allow the Services to work correctly. They enable you to access the Services, move around, and access different services, features, and tools. Examples include remembering previous actions (e.g. entered text) when navigating back to a page in the same session. These cookies cannot be disabled.
These cookies remember your settings and preferences and the choices you make (such as language or regional preferences) in order to help us personalize your experience and offer you enhanced functionality and content.
These cookies can help us identify and prevent security risks. They may be used to store your session information to prevent others from changing your password without your login information.
These cookies can help us collect information to help us understand how you use our Services, such as whether you have viewed messages or specific pages and how long you spent on each page. This helps us improve the performance of our Services.
These cookies collect information regarding your activity on our Services to help us learn more about which features are popular with our users and how our Services can be improved.
These cookies are placed in order to deliver content, including ads relevant and meaningful to you and your interests. They may also be used to deliver targeted advertising or to limit the number of times you see an advertisement. This can help us track how efficient advertising campaigns are, both for our own Services and for other websites. Such cookies may track your browsing habits and activity when visiting both our Services and those of third-parties.
How to Adjust Your Preferences
Most Web browsers are initially configured to accept cookies, but you can change this setting so your browser either refuses all cookies or informs you when a cookie is being sent. In addition, you are free to delete any existing cookies at any time. Please note that some features of the Services may function improperly when cookies are disabled or removed.
By changing your device settings, you can prevent your device's ad identifier being used for interest-based advertising, or you can reset your device's ad identifier. Typically, you can find the ad identifier settings under "privacy" or "ads" in your device's settings, although settings may vary from device to device.
Adjusting your preferences as described in this section herein does not mean you will no longer receive advertisements, it only means the advertisement you do see will be less relevant to your interests.
Third-Party Applications and Services
Subject to your consent and applicable law, we may send you e-mail or other messages and/or a newsletter about us or our Services. You may remove your Personal Data from our mailing list and stop receiving future communication from us by following the UNSUBSCRIBE link located at the bottom of each communication or by emailing us at email@example.com. You will also be given the opportunity to unsubscribe from commercial messages in any such e-mail or message we send. Please note that we reserve the right to send you service-related communications, including service announcements and administrative messages relating to your account, without offering you the opportunity to opt out of receiving them. Should you not wish to receive such communications you may cancel your account.
We do not knowingly collect personally-identifiable information from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) has enrolled without parental permission, please advise us immediately.
Changes to the Privacy Notice
When visiting this Service, you shall be asked to accept the terms of this Privacy Notice. If you do not agree with the terms hereof, please do not use the Services. We may update this Privacy Notice from time to time – we encourage you to review it periodically. By continuing to access or use the Services after those changes become effective, you agree to be bound by the revised privacy notice. We will post the updated Privacy Notice on this page. Please come back to this page every now and then to make sure you are familiar with the latest version. Any new Privacy Notice will be effective from the date it is accepted by you.
Comments and Questions
If you have any comments or questions about this privacy notice, or if you wish for us to amend or delete your Personal Data, or exercise any other of your legal rights, please contact us at firstname.lastname@example.org.
Last updated: November 2019