Privacy Policy

[Last Updated: May 2023]

This Privacy Policy (“Privacy Policy”), describe how Panaya Ltd. and its affiliates (collectively, “Panaya” or “we”) collect, use and disclose certain information, including Personal Data (as defined below) and the rights granted with regards to your information.

Panaya provides subscription-based on-demand online services for testing and impact analysis of changes made to its Customers’ Systems (“Services”).

When you use the Services (“Customer“), when you apply for a job through our website (“Job Applicant”), or merely when you engage with our blogs, news room, register to a webinar, or other similar forums as available through our website: (“Prospect” and collectively and separately with the Customer, and the Job Applicant, shall be referred to herein as ”you”), you are trusting us with your information. This Privacy Policy is meant to help you understand what information we collect, why we collect it, how we safeguard it and how you can control it by exercising your rights.

In the event you are a California or Virginia resident – this Privacy Policy together with our CCPA Privacy Notice apply to the data collected by Panaya from you.

1) Policy Amendments:

We reserve the right to amend this Privacy Policy from time to time, at our sole discretion. The most recent version of this Privacy Policy will always be posted on the website and the update date will be reflected in the “Last Updated” heading. We will provide notice to you if these changes are material, and, where required by applicable law, we will obtain your consent. Any amendments to the Privacy Policy will become effective immediately, unless we notify otherwise. We recommend you review this Privacy Policy periodically to ensure that you understand our most updated privacy practices.

2) Contact Information and Data Controller Information

Panaya, a company incorporated under the laws of the state of Israel, is the Controller (as such term is defined under the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”) or equivalent privacy legislation).

For any question, inquiry or concern related to this Privacy Policy or the processing of your Personal Data, you may contact as follows:

DPO Contact Information:  

By E-mail: [email protected]

By Mail:

Panaya Ltd.

6 Haharash St. Hod Hasharon, Israel 4524079

3) Data Processed by Panaya

We may collect two types of information from you, depending on your interaction with us.

The first type of information is non-identifiable and anonymous information (“Non-Personal Data”). We are not aware of the identity of the individual from who we have collected the Non-Personal Data. Non-Personal Data which is being gathered consists of technical information, and may contain, among other things, the type of operating system and type of browser, type of device, your action in the website or Services (such as session duration).

The second type of information is individually identifiable information, namely information that identifies an individual or may with reasonable effort identify an individual (“Personal Data”).

For the avoidance of doubt, any Non-Personal Data connected or linked to Personal Data shall be deemed as Personal Data as long as such connection or linkage exists.

The table below details the types of Personal Data we process, the purpose, lawful basis, and our processing operations:

Type of DataPurposes of ProcessingLegal Basis under the GDPR
Website Interaction and Marketing: When you interact with our website, we may collect your online identifiers, such as Internet Protocol (IP) address, Cookie ID and other unique identifiers (“Online Identifiers”).   Further, we will collect your behavioral information, which is collected indirectly by our external marketing tools, or analytic tools. This information includes the referring URL (that is, the webpage directing you to our website, and other websites you visited in the session), your interests in our competitors, the web page you visited when you tapped/clicked on our ad, how you interact with our webpage, time, duration of use, pages you have viewed on our website (“Marketing Data”).First, Online Identifiers and cookies are used, in particular to operate the website and enable its proper functionality, for security and fraud prevention purposes, debugging purposes and to resolve technical problems. For example, in order to automatically recognize you by the next time you enter the website or to confirm you are a real person. Second, the Online Identifiers and the Marketing Data are indirectly processed by third-parties marketing and analytic tools, for analytic and remarketing purposes. We process this data to understand how Prospects use our website and to measure effectiveness of some ads we use in order to track conversions, build targeted audience, and remarket our Services to people who have taken some action on the website.Online Identifiers which are collected through cookies we implement, which are strictly necessary for the proper and basic operation of the website will be processed in our legitimate interest. Your Marketing Data which are collected through third-party cookies, including any targeting and marketing cookies, will be processed based on your consent which we will obtain through our cookie notice and consent management. You may withdraw consent at any time by using the cookie preference settings as available in the footer of the website, or by managing opt-out through your browser or device.
Contact Information: In the event you contact us with any inquiries, either through an online form available on the website (i.e., the contact us and support pages, the DSR form, etc.), by sending us an email or by any other means, you will be requested to provide us certain information such as your name, telephone number, email address (“Contact Information”).We will use your Contact Information solely for the purpose of responding to your inquiries. The correspondence and its contents with you may be processed and stored by us in order to improve our customer services and in the event we believe it is required to continue to store it, for example, in the event of any claims or in order to provide you with any further assistance (if applicable).We process Contact Information subject to our legitimate interest.  
Newsletter: In the event you sign up to receive our newsletter, blog updates or other marketing materials, you will be requested to provide your contact details, such as your email address. We use this information in order to send you the content you requested or other marketing materials. We will further store this information in order to include you in our marketing lists, as well as the “opt-out” list (solely the necessary information for such purpose), and to ensure we respect your choice and comply with applicable laws in this regard.We process such contact information subject to your consent. You may withdraw consent at any time through the “unsubscribe” link within the email.
Additional Features: In the event you choose to provide feedback, post on our website or social media pages, participate in our webinars or events we host, you may be required to provide us with certain additional information such as your role, country, company name, etc.We will use this information for the purpose of providing you with the services that you requested.We process this information subject to our legitimate interest.
Call Recordings: When we contact you through your work phone, we may, subject to applicable laws, record our call (“Call Recordings”).We use such Call recordings in order to enhance our sales efforts, and in the event we believe it is required to continue to store it, for example, in the event of any claims or in order to provide you with any further assistance (if applicable).  Subject to applicable laws, we will process our Call Recordings based on your consent.
Customer Account: In order to use our Services, you will be required to register and open an account. During the registration process you will be requested to provide us with certain information such as your name, company name, email address, role, and other similar contact information, and you will be able to create a user name and password. (Collectively “Account Registration Data”).   We use your Account Registration Data to create and designate your account, authentication and validate access, enable log-in, access and use of your account as well as to send you needed information related to our engagement (e.g., billing and invoicing). In addition, we use this information for direct marketing purposes, meaning, as our Customer, we may send you marketing related communications (by email or other contact details you have provided), materials and content regarding the Services you are currently using or any services we may offer in the future to keep you up to date, and for example, offers and content such as software updates, new capabilities and features, surveys, etc.We process your Account Registration Data for the purpose of performing our contract with you. Processing of this information for direct marketing purposes is made subject to our legitimate interest. You can opt-out at any time using the “unsubscribe” option within the body of the message. Please note that if you choose to unsubscribe from our direct marketing, we will still retain your contact details and send you service-related emails, such as invoices.
Customer Support: When you contact us for customer support, we will process your Contact Information.We will use the Contact Information to provide you with the customer support needed. We will retain such correspondence for as long as needed, and to evidence the support was provided.We process such information to provide the required support services and fulfill the contractual obligations.
Free Trial: In the event you choose to book a free trial you will be requested provide us with certain information such as your name, your company email address, work phone, working company, your role, country, etc. (“Free Trial Information”).We will use your Free Trial Information for the purpose of providing you with the free trial services as requested.We process your Free Trial Information in order to take pre-contractual steps as you requested.        
Usage Data: When you use our Services, information regarding such use is automatically generated and collected, which may include the click stream within the Services, the use of the Services (i.e., accessed or used by Customer) and the time spent on those pages or features, crash data and analytics, etc. We record how you interact with the Services. We log crashes, interaction with the Services, how often you use the Services, how long you are on the Services, etc. (Collectively “Usage Data”)We use your Usage Data to help us understand how you are using our Services, and how to better provide and improve our Services. This helps us to better understand our business, analyze our operations, maintain, improve, innovate, plan, design, and develop the Service and our new products. In addition, we process Usage Data for security, operation and debugging purposes, and for example, to resolve technical errors. Where we collect Usage Data for operation and security purposes, we process your data based on our legitimate interest. Where we collect Usage Data for analytic and marketing purposes, we process such data based on your consent which we will obtain through our cookie notice and consent management tool. You may withdraw consent at any time by using the cookie preference settings available in the footer of the website, or by managing opt-out through your browser or device.
Career: When you apply for a job at Panaya, we will process your CV (and the information included therein), as well as additional information such as your contact information (name, email address and phone number), information regarding your education and skills, employment history, and your photo (to the extent provided by you). Further, where required by law, we may process diversity and inclusion data regarding your candidacy, such as ethnicity, gender, or any disability. In addition, we may collect other information from public and online sources, referees, background checks where applicable, and former employers and combine such data with the data you provided us (collectively, “Recruitment Data”).We will use your Recruitment Data to process your job application and for our internal recruitment management purposes, for further recruitment steps (e.g., interview), and to enable Panaya to comply with corporate governance and legal and regulatory requirements. Following the completion of the recruitment process, we may further retain and store the Recruitment Data (including other interactions with us under such process) as part of our internal records keeping, including for legal defense from any future claim, as well as, and subject to applicable law requirements, to contact you in the future for other position we believe you qualify for. If you are hired, your Recruitment Information will be kept on our HR systems as part of your employment and our corporate management. We currently use Comeet which processes your Recruitment Information on our behalf based on their Privacy Notice available here, and pursuant with Comeet’s contractual commitments under this data processing agreement.We process Recruitment Data subject to our legitimate interest. In some cases, for example, where we will ask you to provide health related information or diversity and inclusion data, we will process such data based on our obligations in employment and the safeguarding of your fundamental rights.   Where you provided your consent, we will process your Recruitment Data in order to contact you with further job offers which we believe you might be interested in.  

Please note that the actual processing operation per each purpose of use and lawful basis detailed in the table above may differ. Such processing operation usually includes a set of operations made by automated means, such as collection, storage, use, disclosure by transmission, erasure, or destruction. The transfer of Personal Data to third-party countries, as further detailed in the Data Transfer section below, is based on the same lawful basis as stipulated in the table above.

In addition, we may use certain Personal Data to prevent potentially prohibited or illegal activities, fraud, misappropriation, infringements, identity thefts, and any other misuse of our Services, and to enforce our terms of use and other policies, as well as to protect the security or integrity of our databases all systems, and to take precautions against legal liability. Such processing is based on our legitimate interests.

4) How We Collect Information

Depending on the nature of your interaction with Panaya, we may collect information as follows:

  • Automatically– we may use cookies (as elaborated below) or similar tracking technologies to gather some information automatically when you interact with our website.
  • Provided by you voluntarily– we will collect information if and when you choose to provide us with the information, such as when you apply for a job, contact us communications, account registration, etc.
  • Provided by third parties – such as third parties listed on your CV for professional reference, etc.

5) Cookies and Tracking Technologies

We use “cookies” (or similar tracking technologies) when you interact with our website. The use of cookies is a standard industry-wide practice. A “cookie” is a small piece of information that a website assigns and stores on your computer while you are viewing a website. Cookies can be used for various purposes, including allowing you to navigate between pages efficiently, for statistical purposes, as well as for advertising purposes.

You can find more information about cookies here:

Please see our cookies list page as available through our website footer, which details the cookies we use on our website, as well as our cookie setting tool made available on our website, enabling you to change your settings and preferences ant any time 

Also note that, most browsers will allow you to erase cookies from your computer’s hard drive, block acceptance of cookies, or receive a warning before a cookie is stored. You may set your browser to block all cookies, including cookies associated with our website, or to indicate when a cookie is being used by us, by adjusting the privacy and security settings of your web browser. Please refer to the support page of your browser to learn more about how you can adjust your privacy and security settings. Please note that once you choose to opt out or disable cookies, some features of our website may not operate properly and your online experience may be limited. In addition, even if you do opt-out, you may still receive some content and advertising, however, it will not be targeted content or advertising.

Where we use third-party advertising cookies, such third-party may independently collect, through the use of such tracking technologies, some or all types of Personal Data detailed above, as well as additional data sets, including to combine such information with other information they have independently collected relating to your online activities across their network of websites, for the purpose of enhanced targeting functionality and delivering personalized ads, as well as providing aggregated analytics related to the performance of our advertising campaign you interacted with. These third parties collect and use this information under their own privacy policies, and are responsible for their practices.

6) Sharing Personal Data

We share your Personal Data with third parties, including our partners or service providers that help us provide our Services. You can find in the table below information about the categories of such third-party recipients.

Category of RecipientData That Will Be SharedPurpose of Sharing
Service providers    All types of Personal Data We employ other companies and individuals to perform functions on our behalf. Examples include: outsource consultants, sending communications, processing payments, analyzing data, providing marketing and sales assistance (including advertising and event management), identifying errors and crashes, conducting customer relationship management, and providing training. These third-party service providers have access to Personal Data needed to perform their functions, but they are prohibited, through contractual obligations, from using your Personal Data for any purposes other than providing us with requested services.
Affiliated CompaniesAll types of Personal DataWe may share your Personal Data with our affiliated companies including our parent company, for sales and marketing purposes, providing customer relationship services, etc.   
Any acquirer of our businessAll types of Personal DataWe may share Personal Data, in the event of a corporate transaction (e.g., sale of a substantial part of our business, merger, consolidation or asset sale). In the event of the above, our affiliated companies or acquiring company will assume the rights and obligations as described in this Privacy Policy.
governmental agencies, law enforcements or authorized third partiesAll types of dataWe may disclose Personal Data to enforce our policies and agreements, as well as defend our rights, including the investigation of potential violations thereof, alleged illegal activity or any other activity that may expose us, you, or other users to legal liability, and solely to the extent required. In addition, we may disclose Personal Data to detect, prevent, or otherwise address fraud, security, or technical issues, solely to the extent required. We may also share certain data when we believe it is appropriate to do so in order to comply with the law enforcement, or protect the rights, property, or security of Panaya, our Customers or others.

For the avoidance of doubt, we may transfer and disclose or otherwise use Non-Personal Data or information which is linked to anonymous random identifiers or information that is aggregated in a non-identifiable way, at its own discretion.

7) Your Rights Related to Your Personal Data

We acknowledge that different people have different privacy concerns and preferences. Our goal is to be clear about what information we collect so that you can make meaningful choices about how it is used. We allow you to exercise certain choices, rights, and controls in connection with your information. Depending on your relationship with us, your jurisdiction and the applicable data protection laws that apply to you, you have the right to control and request certain limitations or rights to be executed.

For California and Virginia residents, please see our CCPA Privacy Notice.

For detailed information on your rights and how to exercise your rights, please see the Data Subject Request Form (“DSR”) form available here and send it to our privacy team at: [email protected]

Certain rights can be easily executed independently by you without the need to fill out the DSR form, and for example:

  • If you are our Customer, you can correct certain data provided under your Customer account (such as contact information) through the account settings;
  • You can you can opt-out from receiving our marketing emails by clicking “unsubscribe” link;
  • You can use the cookie settings tool available on the footer of the website to change your preferences.

In the event you are a Customer – note that termination of the engagement or closing your account does not automatically resolved in deletion of data. If you wish to delete the data, please ensure to contact us with such request.

8) Data Retention

We retain Personal Data we collect as long as it remains necessary for the purposes set forth above, all in accordance with applicable laws, or until an individual expresses a preference to opt-out.

Other circumstances in which we will retain your Personal Data for longer periods of time include: (i) where we are required to do so in accordance with legal, regulatory, tax, or accounting requirements; (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges; or (iii) if we reasonably believe there is a prospect of litigation relating to your Personal Data. Please note that except as required by applicable law, we may at our sole discretion, delete or amend information from our systems, without notice to you, once we deem it is no longer necessary for such purposes.

9) Security

At Panaya, security is our highest priority. We design our systems with your security and privacy in mind. We have implemented physical, technical, and administrative security measures for the Services that comply with applicable laws and industry standards.

Note that we cannot be held responsible for unauthorized or unintended access beyond our control, and we make no warranty, express, implied, or otherwise, that we will always be able to prevent such access.

Please contact us at: [email protected], if you feel that your privacy was not dealt with properly, in a way that was in breach of our Privacy Policy, or if you become aware of a third party’s attempt to gain unauthorized access to any of your Personal Data. We will make a reasonable effort to notify you and the appropriate authorities (if required by applicable law) in the event that we discover a security incident related to your Personal Data.

10) Data Transfer

We may store or process your Personal Data in the EU, the United States or in other countries. Thus, any information you provide us may be transferred to and processed in countries other than the country from which you accessed our Services. We will take appropriate measures to ensure that your Personal Data receives an adequate level of data protection upon its transfer. When Personal Data that was collected within the EEA is transferred outside the EEA, we will take necessary steps in order to ensure that sufficient safeguards are provided during the transferring of such Personal Data, such as pursuant with the EU standard contractual clauses as approved by the European Union (SCCs).

Additionally, following the withdrawal of the United Kingdom (UK) from the European Union on January 31, 2020, the UK is no longer considered to be a part of the EEA and therefore, the transferring of Personal Data from the EEA to the UK will also be subject to the SCCs or other contractual clauses that will ensure the security of the Personal Data (pending an adequacy decision from the European Commission). Further, the transfer of Personal Data collected within the UK to countries outside the UK, will be provided with sufficient safeguards as required under applicable laws, including pursuant with the UK standard contractual clauses (UK SCCs) as approved by the UK Information Commissioner Office (ICO).

11) Children

Our website and Services are not intended for use by children and we do not knowingly collect or maintain information about anyone under the age of 16. Please contact us at: [email protected], if you have reason to believe that a child has shared any information with us.