← Back to PE filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
for a discussion of our increased expenses as a result of being a public company.
If we lose our foreign private issuer status
under U.S. federal securities laws, we would incur additional expenses and reporting and other requirements associated with compliance
with the U.S. securities laws applicable to U.S. domestic issuers.
We are a foreign private issuer, as such term is defined under
U.S. federal securities laws, and, therefore, we are not required to comply with all of the periodic disclosure and current reporting
requirements applicable to U.S. domestic issuers. In June 2025 the SEC issued a concept release soliciting public comment on potential
changes to the definition of a foreign private issuer. This release is the first review of the foreign private issuer framework since
2008, and the SEC is considering revisions that could significantly impact which foreign companies qualify for the more-relaxed U.S. reporting
requirements afforded to foreign private issuers. This early concept release outlines several potential approaches to revising the foreign
private issuer definition, including updating existing eligibility criteria, adding foreign trading volume requirements, and incorporating
an assessment of foreign regulation. If we lose our foreign private issuer status, we would be required to comply with the reporting and
other requirements applicable to U.S. domestic issuers, which are more extensive than the requirements for foreign private issuers and
more expensive to comply with.
24
There can be no assurances that we will not
be a passive foreign investment company (“PFIC”) for any taxable year, which could subject U.S. Shareholders to significant
adverse U.S. federal income tax consequences.
In general, a non-U.S. corporation is a PFIC for any taxable year
in which (i) 75% or more of its gross income consists of passive income or (ii) 50% or more of the value of its assets (generally determined
on an average quarterly basis) consists of assets that produce, or are held for the production of, passive income. For purposes of the
above calculations, a non-U.S. corporation that owns (or is treated as owning for U.S. federal income tax purposes), directly or indirectly,
at least 25% by value of the shares or equity interests of another corporation is treated as if it held its proportionate share of the
assets of the other corporation and received directly its proportionate share of the income of the other corporation. Passive income generally
includes dividends, interest, rents, royalties and certain gains. Cash and marketable securities are generally passive assets for these
purposes. Goodwill and other intangible assets are generally characterized as non-passive or passive assets based on the nature of the
income produced in the activity to which the goodwill and other intangible assets relate.
Because we hold a substantial amount of cash and other passive
assets, our PFIC status for any taxable year generally will depend on the average value of our goodwill and other intangible assets (as
well as the value of our other active assets). If the value of our assets were determined by reference to the sum of our market
capitalization and liabilities, we would likely be a PFIC for 2025 due to the low average value of our market capitalization during 2025.
However, based on external advice, we believe that market capitalization plus liabilities does not fairly reflect the gross value of our
total assets, and that alternative valuation methods are appropriate. Specifically, we believe that if our assets were valued based on
the discounted cash flows or revenue multiples methods, our enterprise value for 2025 would be significantly larger than the value derived
from using the market capitalization method.
Accordingly, we believe that we were likely not a PFIC for 2025.
However, our position is not binding on the U.S. Internal Revenue Service and there can be no assurance that it will agree with our valuation
approach.
In addition, we may also be a PFIC for any future taxable year
if the portion of our financial income out of our gross income were to increase to 75% or more for any taxable year. Our PFIC status for
any taxable year is an annual factual determination that can be made only after the end of that taxable year and will depend on the composition
of our income and assets and the value of our assets from time to time (including the value of our goodwill and other intangible assets).
For the reasons described above, we cannot express any expectation regarding our PFIC status for the current or any future taxable year.
If we are a PFIC for any taxable year during which a U.S. investor
owns our ordinary shares, we will generally continue to be a PFIC with respect to that investor for all succeeding taxable years, even
if we cease to meet the threshold requirements for PFIC status, unless certain elections are timely made by the investor. In addition,
a U.S. investor could be subject to adverse U.S. federal income tax consequences and reporting obligations with respect to its ownership
of PFIC stock. See “Taxation – U.S. Federal Income Tax Considerations – Passive Foreign Investment Company Rules.”
Our business could be negatively affected as
a result of actions of activist shareholders, and such activism could impact the trading value of our securities.
In recent years, certain issuers listed on U.S. exchanges, including
our Company, have faced governance-related and other demands from activist shareholders, as well as unsolicited tender offers and proxy
contests. For example, in April 2025, following a decline in the market price of our ordinary shares, our board of directors adopted a
shareholder rights plan. Shortly thereafter, we received an open letter from Value Base Fund Limited Partnership, a shareholder of the
Company and then a significant shareholder, demanding the immediate rescission of the rights plan or its submission to a shareholder vote,
alleging, among other things, that the plan was adopted in violation of law and our articles of association. We rejected these allegations
and asserted that they were without merit. In July 2025, our board of director approved the early termination of the rights plan after
determining that the circumstances that led to its adoption no longer warranted its continuation. Additionally, we received a demand letter
from Phoenix Financial Ltd., one of our then significant shareholders, requiring us to submit for shareholder approval an amendment to
our articles of association relating to the future adoption of shareholder rights plans. Such proposal was not approved by our shareholders.
However, we may face similar or other demands in the future, Such activities could interfere with our ability to execute our strategic
plans. Although as a foreign private issuer we are not subject to U.S. proxy rules, responding to these types of actions by activist shareholders
could be costly and time-consuming, disrupting our operations and diverting the attention of management and our employees. In addition,
a proxy contest for the election of directors at our annual meeting would require us to incur significant legal fees and proxy solicitation
expenses and require significant time and attention by management and our board of directors. The perceived uncertainties due to these
potential actions of activist shareholders also could adversely affect the market price and volatility of our securities.
25
The rights and responsibilities of our shareholders
are governed by Israeli law and differ in several key respects from the rights and responsibilities of shareholders under U.S. laws, including
the duty to act in good faith and the lack of extensive case law.
We are incorporated in accordance with the Israeli Companies Law.
The rights and responsibilities of holders of our ordinary shares are governed by our memorandum of association, articles of association
and by applicable Israeli law. These rights and responsibilities differ in several key respects from the rights and responsibilities of
shareholders of typical U.S. corporations. In particular, a shareholder of an Israeli company has a duty to act in good faith in exercising
his or her rights and fulfilling his or her obligations toward a company and the other shareholders, and to refrain from abusing his or
her power in the company, including, among other things, in voting at the general meeting of shareholders on certain matters. This duty
to act in good faith is a significant difference from U.S. law. Israeli law provides that these duties are applicable in shareholder votes
at the general meeting with respect to, among other things, amendments to a company’s articles of association, increases in a company’s
authorized share capital, mergers and actions and transactions involving interests of officers, directors or other interested parties
which require shareholders’ approval. Another key difference is that there is little case law available to assist in understanding
the implications of these provisions that govern shareholder behavior, making the interpretation of these duties less predictable compared
to U.S. law.
As a foreign private issuer, whose shares are
listed on Nasdaq, we follow certain home country corporate governance practices instead of certain Nasdaq requirements.
As a foreign private issuer (as such term is defined in Rule 3b-4
under the Exchange Act), whose shares are listed on Nasdaq, we are permitted to follow certain home country corporate governance practices
instead of certain requirements contained in the Nasdaq Listing Rules. We follow the requirements of the Companies Law in Israel, rather
than comply with the Nasdaq requirements, in certain matters, including with respect to the quorum for shareholder meetings, sending annual
reports to shareholders, and shareholder approval with respect to certain issuances of securities. See Item 16.G. “Corporate Governance”
in this Annual Report on Form 20-F for a more complete discussion of the Nasdaq Listing Rules and the home country practices we follow.
As a foreign private issuer listed on Nasdaq, we may also elect in the future to follow home country practice with regard to other matters
as well. Accordingly, our shareholders may not be afforded the same protection as provided under Nasdaq’s corporate governance rules
to the shareholders of U.S. domestic companies.
Provisions of our articles of association and
Israeli law may delay, prevent or make an acquisition of our Company difficult, which could prevent a change of control and, therefore,
depress the price of our shares.
Israeli corporate law regulates mergers, requires tender offers
for acquisitions of shares above specified thresholds, requires special approvals for transactions involving directors, officers or significant
shareholders and regulates other matters that may be relevant to these types of transactions. In addition, our articles of association
contain provisions that may make it more difficult to acquire our Company, such as provisions establishing a staggered board. Furthermore,
Israeli tax considerations may make potential transactions unappealing to us or to some of our shareholders. See Exhibit 2.1 to this annual
report on Form 20-F, which is incorporated by reference into this annual report on Form 20-F, and Item 10.E. “Taxation—Israeli
Taxation” for additional discussion about some anti-takeover effects of Israeli law.
These provisions of Israeli law may delay, prevent or make difficult
an acquisition of our Company, which could prevent a change of control and therefore depress the price of our shares.
We must meet the Nasdaq Global Select Market’s
continued listing requirements and comply with the other Nasdaq rules, or we may risk delisting. Delisting could negatively affect the
price of our ordinary shares, which could make it more difficult for us to sell securities in a financing and for you to sell your ordinary
shares.
We are required to meet the continued listing requirements of the
Nasdaq Global Select Market and comply with the other Nasdaq rules, including those regarding minimum shareholders’ equity, minimum
share price, and certain other corporate governance requirements. Delisting of our ordinary shares from the Nasdaq Global Select Market
would cause us to pursue eligibility for trading on other markets or exchanges, or on the pink sheets. In such case, our shareholders’
ability to trade, or obtain quotations of the market value of, our ordinary shares would be severely limited because of lower trading
volumes and transaction delays. These factors could contribute to lower prices and larger spreads in the bid and ask prices for our securities.
There can be no assurance that our ordinary shares, if delisted from the Nasdaq Global Select Market in the future, would be listed on
a national securities exchange or quoted on a national quotation service, the OTCQB or OTC Pink. Delisting from the Nasdaq, or even the
issuance of a notice of potential delisting, would also result in negative publicity, make it more difficult for us to raise additional
capital, adversely affect the market liquidity of our ordinary shares, reduce security analysts’ coverage of us and diminish investor,
supplier and employee confidence. In addition, as a consequence of any such delisting, our share price could be negatively affected and
our shareholders would likely find it more difficult to sell, or to obtain accurate quotations as to the prices of, our ordinary shares.
26
Our ordinary shares are traded on more than
one market, and this may result in price variations.
Our ordinary shares are traded on both the Nasdaq Global Select
Market and on TASE. Trading in our ordinary shares on these markets is affected in different currencies (U.S. dollars on Nasdaq and NIS
on TASE) and at different times (resulting from different time zones and different public holidays in the United States and Israel). In
January 2026, TASE changed its trading week from Sunday–Thursday to Monday–Friday, which has affected, and may continue to
affect trading volumes, liquidity, price discovery, and arbitrage opportunities between the markets. Consequently, the trading prices
of our ordinary shares on these two markets often differ, resulting from the factors described above as well as differences in exchange
rates and from political events and economic conditions in the United States and Israel. Any decrease in the trading price of our ordinary
shares on one of these markets could cause a decrease in the trading price of our ordinary shares on the other market.
Increasing scrutiny from investors, customers
and other market participants with respect to our Environmental, Social and Governance (“ESG”), policies could negatively
affect the price of our shares or impose additional costs on us.
In recent years, increasing attention has been given to ESG policies
of corporations across industries, including with respect to climate change and diversity, equity and inclusion matters. Growing public
concern about climate change has resulted in increased focus of local, state, regional, national and international regulatory bodies on
greenhouse gas, or GHG, emissions and climate change issues. We may incur additional expenses, such as costs related to data collection,
reporting, auditing, and compliance systems, as U.S. and international regulators require additional disclosures regarding GHG emissions
or climate-related risks. Compliance with such regulations and the associated potential cost is complicated by the fact that various countries
and regions are following different approaches to the regulation of climate change. These differing approaches can include variations
in emission reduction targets, reporting requirements, timelines for implementation, and enforcement mechanisms. The current presidential
administration in the United States in particular has been taking steps to roll back restrictions on greenhouse gas emissions and regulations
targeting climate change and is expected to continue to do so. Additionally, in the U.S., there is an increasing number of state-level
initiatives aimed at discouraging or penalizing the adoption of ESG or sustainability policies. This lack of uniformity can increase complexity
and cost as we navigate and comply with a patchwork of regulations. We could fail to achieve, or be perceived to fail to achieve, evolving,
expectations, standards, or regulations on ESG matters, or be perceived by investors, customers and other market participants as having
not responded appropriately to growing ESG concerns. As a result, we may experience reputational damage and our business, financial condition
and the price of our shares could be materially and adversely affected.
Our cash, cash equivalents, Marketable Securities
and short-term deposits are subject to risks that may cause losses and affect the liquidity of these investments.
As of December 31, 2025, we had $312.9 million in cash, cash equivalents,
marketable securities and short-term deposits. We regularly maintain cash, cash equivalent, marketable securities and short-term deposits
at third-party financial institutions. We maintain and invest our cash and cash equivalents based on an investment policy approved by
our Investment Committee of the board and by our board of directors. Our investment policy set various principles for managing our cash,
including the rating level of third-party financial institutions in which we keep our cash, diversified portfolio and diversified countries
of incorporation of the relevant financial institutions. These deposits and investments are subject to general credit, liquidity, market
and interest rate risks. Further, we may be adversely affected by a crisis in the banking industry. If banks and financial institutions
enter receivership or become insolvent in the future and a portion of our cash, cash equivalents, marketable securities or short-term
deposits is held in such banks and financial institutions, our ability to access our existing cash, cash equivalents and investments may
be impacted and could have a material adverse effect on our business and financial condition.
Risks Related to our Technological Environment
Our business and financial performance may be
materially adversely affected by information technology issues, data breaches, cyber-attacks and other similar incidents, as well as insufficient
cybersecurity and other business disruptions.
We rely on information technology systems and networks to operate
and manage our business and to collect, use, maintain and otherwise process information, including information related to our business,
customers, partners, and personnel. This information is stored and managed within our internal information technology infrastructure or,
in certain instances, on platforms maintained by third-party service providers, suppliers and vendors. These systems and networks, whether
operated internally or externally, may be subject to information technology issues, data breaches, cyber-attacks and other similar incidents.
Our business is constantly challenged and may be impacted by information technology issues, data breaches, cyber-attacks and other similar
incidents, as well as insufficient cybersecurity and other business disruptions experienced by us or our third-party service providers,
suppliers and vendors. Data breaches, cyber-attacks, and other similar incidents in particular are a growing and evolving risk and often
are difficult or impossible to detect for long periods of time or to successfully defend against. Such incidents may include, but are
not limited to software bugs, server malfunctions, software or hardware failure, service outages, malicious software or activity, computer
viruses, ransomware attacks, denial-of-service attacks, social engineering, domain name spoofing, fraud, phishing attacks, worms/trojan
horses, insider threats, human error, attempts to gain unauthorized access to data, and other cybersecurity breaches that could lead to
disruptions in systems and networks, denial of services, remote code execution, unauthorized access to or release of sensitive, proprietary,
confidential, personal or otherwise protected information corruption of data, telecommunications failures, terrorist attacks, natural
disasters, power loss, war, physical security breaches, or other events that may harm our systems and networks, or those of our third-party
service providers, suppliers and vendors. Moreover, the increasing integration of AI technology within our platform introduces new attack
vectors, such as prompt injection, data poisoning and adversarial attacks, which could compromise the integrity and security of our platform
and technology and the data processed thereon. At the same time, growing sophistication and accessibility of AI tools empower malicious
actors, potentially lowering the barrier to complex cyber-attacks and increasing their frequency and impact. All of the foregoing incidents
are increasing in frequency, levels of persistence, sophistication and intensity, are evolving in nature, and are conducted by organized
groups and individuals with a wide range of motives and expertise, including organized criminal groups, “hacktivists,” terrorists,
nation states, nation state-supported actors, and others, any of whom may see their effectiveness enhanced by the use of AI. Unidentified
groups continuously target numerous internet websites and servers, including our own, for various reasons, political, commercial and other.
High-profile data breaches, cyber-attacks and other similar incidents at other companies and government agencies have increased in frequency
and sophistication in recent years. Moreover, geopolitical tensions, particularly the Hamas-Israel, Iran-Israel and the Russia-Ukraine
conflicts, have contributed to a surge in cyber-attacks targeting Israeli companies, individuals and products globally, posing a threat
to critical infrastructure. Any data breach, cyber-attack or other similar incident impacting us or our third-party service providers,
suppliers and vendors, or any failure to make adequate or timely disclosures to the public, regulators, or law enforcement agencies following
any such incident, could subject us to substantial system downtimes, operational delays, other detrimental impacts on our operations or
ability to provide products and services to our customers, the compromising of sensitive, proprietary, confidential, personal or otherwise
protected information, the destruction or corruption of data, other manipulation or improper use of our systems and networks, violations
of applicable data protection, data privacy and cybersecurity laws and regulations or notification obligations, violation of contracts,
legal claims, regulatory scrutiny or enforcement actions, investigations, financial losses from remedial actions, loss of business or
potential liability, and/or damage to our reputation, any of which could have a material adverse effect on our cash flows, competitive
position, financial condition and results of operations.
27
Given the unpredictability of the timing, nature and scope of such
incidents, and because techniques used to obtain unauthorized access to or sabotage systems and networks change frequently and generally
are not identified until they are launched against a target, there can be no assurance that such incidents can be prevented, that such
incidents are not occurring currently without our knowledge, or that any such incidents will not have a material adverse effect on us
in the future. Additionally, the rapid evolution of AI technology may also cause new vulnerabilities and attack methods to emerge faster
than our ability to develop countermeasures, creating a persistent and escalating challenge to our cybersecurity defenses.
As cybersecurity threats continue to evolve, we expect to continue
to expend significant additional resources to continue to maintain, modify or enhance our protective measures or to investigate or remediate
any information technology issues, business interruptions, data breaches, cyber-attacks or other similar incidents. However, we may not
be able to anticipate such incidents, and such measures, as well as our response process, may not be adequate, may fail to detect or react
to such incidents in a timely manner, may fail to identify or accurately assess the severity of an incident, may not respond quickly enough,
or may fail to sufficiently remediate an incident. As a result, we may suffer significant legal, reputational, or financial exposure,
which could harm our business, financial condition, and operating results.
With respect to our third-party risk management processes, while
we generally seek to impose certain cybersecurity requirements on critical third parties with whom we do business, for example, by employing
due diligence and onboarding procedures, our ability to monitor such practices is limited, we do not control their cyber risk management
and there can be no assurance that we will detect, prevent, mitigate, or remediate the risk of any weakness, compromise, or failure in
the systems, networks, and information owned or controlled by such third parties. Due to applicable laws and regulations or contractual
obligations, we may be held responsible for business interruptions, data breaches, cyber-attacks or other similar incidents attributed
to such third parties as they relate to the information we share with them. In addition, if we suffer a highly publicized business interruption,
data breach, cyber-attack or other similar incident, even if our platform and solutions perform effectively, such an incident could have
an adverse effect and cause us to suffer reputational harm, lose existing commercial relationships and customers or deter existing customers
from purchasing additional solutions and prevent new customers from purchasing our solutions.
We cannot ensure that any indemnification or limitation of liability
provisions in our agreements with customers, service providers, suppliers, vendors and other third parties with which we do business would
be enforceable or adequate or would otherwise protect us from any liabilities or damages with respect to any particular claim in connection
with a business interruption, data breach, cyber-attack or other similar incident. Additionally, we cannot be certain that our insurance
coverage will be adequate for cybersecurity liabilities actually incurred, that insurance will continue to be available to us on economically
reasonable terms, or at all, or that our insurer will not deny coverage as to any future claim.
We have contractual, legal and regulatory obligations to notify
relevant stakeholders of certain data breaches, cyber-attacks or similar incidents, as defined in the relevant laws, regulations or respective
contracts. Most jurisdictions have enacted laws and regulations requiring companies to notify individuals, regulatory authorities and
others of data breaches, cyber-attacks or similar incidents involving certain types of data. In addition, our agreements with certain
customers and third-party partners may require us to notify them in the event of a data breach, cyber-attack or similar incident. Such
mandatory disclosures are costly, could lead to negative publicity and may cause our customers to lose confidence in the effectiveness
of our security measures. If we fail to make such notification within the mandatory time frames, we may be subject to penalties and legal
actions.
28
Although we have implemented administrative, technical and organizational
safeguards to comply with applicable data protection, data privacy and cybersecurity laws and regulations in connection with the collection,
use, retention, disclosure and other processing of personal information, if a significant failure of such safeguards were to occur, our
business and reputation could be materially adversely affected. A business interruption, data breach, cyber-attack or other similar incident
could lead to claims by our customers, data subjects or other relevant parties that we have failed to comply with applicable laws, regulations
or contractual obligations to implement specified security measures. As a result, we could be subject to legal action or our customers,
data providers or other relevant parties could end their relationships with us.
Data protection, data privacy and cybersecurity laws and regulations
in certain jurisdictions may require us to notify individuals and government or regulatory authorities of data breaches, cyber-attacks
or other similar incidents involving certain types of personal data. Pursuant to certain data protection, data privacy and cybersecurity
laws and regulations, including certain U.S. states’ privacy laws, such as the California Consumer Privacy Act (as amended by the
California Privacy Rights Act, the “CCPA”), and the Israeli Privacy Protection Law, 1981 and the regulations thereunder (“Israeli
Privacy Law”), if we experience a data breach, cyber-attack or other similar incident, affected individuals could, under certain
circumstances relating to such incidents, bring a private action claiming the breach was the result of our violation of the duty to implement
and maintain reasonable security procedures and practices and recover civil damages, which could be costly, impact the operation of our
business and cause reputational harm. Similarly, there is a risk of class actions in the United Kingdom (the “U.K.”), Europe,
Israel as well as other countries. In Canada, there has been an increase in tort claims and related civil litigation. Data breaches, cyber-attacks
or other similar incidents could also result in enforcement actions, including significant penalties and fines, by government or regulatory
authorities alleging that we have violated applicable laws or regulations that require us to maintain reasonable security measures and
comply with mandatory disclosure requirements. In the coming years, we expect further regulation regarding data protection, data privacy
and cybersecurity in the U.S., Canada and other countries that will likely apply to our business. These laws, regulations and other obligations
may create additional regulatory, liability, and reputational risks and may increase financial costs to mitigate such risks. For more
information, see the Risk Factor titled – “Our business depends on our ability to collect,
use, maintain and otherwise process data, including personal data, to help our clients deliver advertisements, and to disclose data relating
to the performance of advertisements. Any limitation imposed on our collection, use, maintenance or other processing of this data could
significantly diminish the value of our solution and cause us to lose sellers, buyers, and revenue. Regulations, legislation or
self-regulation relating to data protection, data privacy, cybersecurity, AI, e-commerce and internet advertising and uncertainties regarding
the application or interpretation of existing or newly adopted laws and regulations threaten our ability to collect, use, maintain and
otherwise process this data, could harm our business and subject us to significant costs and legal liability for non-compliance.”
If we fail to detect or prevent fraudulent,
suspicious or other invalid traffic or engagement with our ads, or otherwise prevent against malware intrusions, we could lose the confidence
of our advertisers, damage our reputation and be responsible to make-good or refund demands, which would cause our business to suffer.
Our business relies on delivering positive results to our advertisers
and their consumers. We are exposed to the risk of fraudulent, suspicious or other invalid traffic, impressions, clicks, conversions,
or other ad engagements that advertisers may perceive as undesirable. Such fraudulent, suspicious or other invalid activities may occur
when a software program, usually known as a bot, spider or crawler, intentionally simulates user activity causing impressions, ad engagements
or clicks to be counted as real users. Such malicious software programs can run on a single machine or on tens of thousands of machines,
making them difficult to detect and filter.
We implement and use proprietary and third-party technologies designed
to identify fraudulent, suspicious or other invalid traffic, impressions, clicks, conversions or other ad engagements. Despite our efforts,
it can be difficult to detect fraudulent, suspicious or other invalid activity for different reasons. If we are unable to detect and prevent
fraudulent, suspicious or other invalid activity, the affected advertisers may experience or perceive a reduced return on their investment.
High levels of fraudulent, suspicious or other invalid activity could lead to dissatisfaction with our advertising services, refusals
to pay, refund or make-good demands or withdrawal of future business. Any of these occurrences could damage our brand and lead to a loss
of revenue.
We may not be able to enhance our platform,
technology and solutions to keep pace with technological and market developments in our evolving industry.
To keep pace with technological developments, satisfy increasing
developer requirements, maintain the attractiveness and competitiveness of our advertising solutions offered by our platform, and
ensure compatibility with evolving industry standards, we will need to regularly enhance our platform, technology and solutions as well
as develop and introduce new services on a timely basis, including on our platform. The success of our platform relies on our ability
to further develop and enhance our platform’s AI infrastructure and our AI-agent.
We also must update our software to reflect changes in advertising
networks’ application programming interfaces (“APIs”), technological integration, data protection, data privacy, cybersecurity
and terms of use. The success of any enhancement or new solution depends on several factors, including timely completion, adequate quality
testing, appropriate introduction and market acceptance. Our inability, for technological, business or other reasons, to timely enhance,
develop, introduce and deliver compelling advertising services and AI capabilities in response to changing market conditions and technologies
or evolving expectations of advertisers or consumers could hurt our ability to grow our advertising business and adversely impact our
business. For additional information see also the Risk Factors titled – “If the demand for
digital advertising does not continue to grow or customers do not embrace our solutions including our Perion One platform, it could have
a material adverse effect on our business and results of operation.”
29
Our products operate in a variety of computer
and device configurations and could contain undetected errors, failures or defects that could result in product failures, lost revenue,
and loss of market share.
Our software and advertising products may contain undetected errors,
failures or defects, especially when the products are first introduced or when new versions are released. Our customers’ computer
and other device environments are often characterized by a wide variety of standard and non-standard configurations that make pre-release
testing for programming or compatibility errors very difficult and time-consuming. As a result, there could be errors, failures or defects
in our products or our platform. In addition, despite testing, errors, failures or defects may not be found in our products and new versions
of our products and platform. In the past, we have discovered software errors, failures and defects in certain of our product offerings
after their full introduction and have experienced delayed or lost revenue during the period required to correct these errors, failures
and defects.
Errors, failures or defects in our products and platform could
result in negative publicity, make-goods, refunds, loss of or delay in market acceptance of our products, loss of competitive position
or claims by customers. Alleviating any of these problems could require significant expense and resources and could cause interruptions
to our products.
We depend on third-party service
providers, suppliers and vendors, such as Internet, telecommunication, data centers, cloud computing and hosting providers as
well as data providers, to operate our platform, websites and services. Temporary failure of these services, including catastrophic or
technological interruptions, would materially reduce our revenue and damage our reputation, and securing alternate sources for these services
could significantly increase our expenses and be difficult to obtain.
The availability of our products and services and fulfillment of
our customer contracts depend on the continuing operation of our information technology and communications systems and networks, and those
of our third-party service providers, suppliers and vendors. Our products and platform’s operation as well as our internal conduct
and daily management are supported by third-party internet, hosting, SaaS services, telecommunication providers as well as data providers
and others. We also rely on third-party AI infrastructure and service providers including large language model (LLM) providers, AI model
APIs, and machine learning platforms, to power and enhance our advertising technology and products. Such third-party service providers,
suppliers and vendors may experience disruptions, which would reduce our revenue and increase our costs.
We own servers located in Israel, Europe and the United States
and we also rent the services of thousands of servers located around the world. Our servers mainly include web servers, application servers,
data collection servers, data storage servers, data processing servers and database servers. While we believe that there are many alternative
providers of hosting and other communication services available to us, the costs associated with any transition to a new service provider,
supplier or vendor could be substantial.
Furthermore, although we maintain back-up systems and networks
for most aspects of our operations, and we could still experience deterioration in performance or interruption in our systems and networks,
delays, and loss of critical data and registered users and revenue. Our systems and networks, and those of our third-party service providers,
suppliers and vendors, are vulnerable to damage, interference, or interruption from modifications or upgrades, terrorist attacks, war,
natural disasters, fires, epidemics and pandemics, the effects of climate change (such as sea level rise, drought, flooding, wildfires,
and increased storm severity), power loss, telecommunications failures, cyber-attacks, computer viruses, ransomware attacks, denial-of-service
attacks, phishing schemes, break-ins, sabotage, intentional acts of vandalism, misconduct or similar events. Such events, a decision to
close third-party facilities on which we rely without adequate notice, or other unanticipated problems, could result in lengthy interruptions
to our services.
Our systems and networks are also not fully redundant, and our
disaster recovery planning may not be sufficient for all eventualities. In addition, we may have inadequate insurance coverage to compensate
us for losses from a major interruption. Furthermore, interruptions in the services of our providers or their inability to provide us
the services or data or meet the service capacity we require, could result in interruptions in the availability or functionality of our
solutions or materially impede our ability to attract and onboard new customers to services and to maintain relationships with current
customers. Difficulties of this kind could damage our reputation, be expensive to remedy, curtail our growth and materially adversely
impact our business operations. For more information, see the Risk Factor titled – “Our business
and financial performance may be materially adversely affected by information technology issues, data breaches, cyber-attacks and other
similar incidents, as well as insufficient cybersecurity and other business disruptions.”
Additionally, should some of our third-party service providers,
suppliers and vendors terminate their relationship with us, our ability to continue the development of some of our products could be adversely
affected, until such time that we find adequate replacement for these vendors, or until such time that we can continue the development
on our own. Any of the foregoing could materially adversely affect our business, financial condition, and operating results.
30
The introduction of new browsers and other popular
software products may materially adversely affect user engagement with our search services.
Users typically install new software and update their existing
software as new or updated software is introduced online by third-party developers. In addition, when a user purchases a new computing
device or installs a new internet browser, it generally uses the internet search services that are typically pre-installed on the new
device or internet browser. Our products are distributed online and are usually not pre-installed on computing devices. Further, as many
software vendors that distribute their solutions online also offer search services alongside their primary software product, users often
replace our search services with those provided by these vendors while installing new software or updating existing software. Furthermore,
the migration of users to new browsers, and particularly to AI-powered browsers, render our search services not relevant to such users.
After users have installed search solutions offered by us, any
event that results in a significant number of our users changing or upgrading their internet browsers could result in the failure to generate
the revenue that we anticipate from our users and result in a decline in our user base. Should we not be able to timely respond to such
changes or in the event that the search solutions offered by vendors would offer better user experience than the one offered by us, this
could have an adverse effect on our business, financial condition and our results of operations.
Finally, although we constantly monitor the compatibility of our
internet search services and related solutions with such new versions and upgrades, we may not be able to make the required adjustments
to ensure constant availability and compatibility of such solutions.
Risks Related to Data Protection, Data Privacy
and Cybersecurity Laws and Regulations
Our business depends on our ability to collect,
use, maintain and otherwise process data, including personal data, to help our clients deliver advertisements and to disclose data relating
to the performance of advertisements. Any limitation imposed on our collection, use, maintenance or other processing of this data could
significantly diminish the value of our solution and cause us to lose sellers, buyers, and revenue. Regulations, legislation or self-regulation
relating to data protection, data privacy, cybersecurity, AI, e-commerce and internet advertising and uncertainties regarding the application
or interpretation of existing or newly adopted laws and regulations threaten our ability to collect, use, maintain and otherwise process
this data, could harm our business and subject us to significant costs and legal liability for non-compliance.
Our business is conducted through the internet and therefore, among
other things, we are subject to the laws and regulations that apply to e-commerce and online businesses around the world. These laws and
regulations are becoming more prevalent in the United States, Europe, Israel, Canada and elsewhere and may impede the growth of the internet
or otherwise adversely impact our business. These laws and regulations cover data protection, data privacy, data protection, cybersecurity,
e-commerce, content, use of “cookies,” pricing, advertising, distribution of “spam,” copyright and other intellectual
property, libel, marketing, distribution of products, protection of minors, consumer protection, accessibility, taxation, online payment
services, and the use of AI to process data or for automated decision-making . Many areas of laws and regulations affecting the
internet remain largely unsettled, even in areas where there has been some legislative or regulatory action.
We collect, use, maintain and otherwise process certain data, including
personal data, about our customers (including, without limitation, customers’ clients or users), partners, candidates and employees,
consultants, leads and consumers. Our ability to collect, use, maintain or otherwise process personal data has been, and could be further,
restricted by existing and new laws and regulations relating to data protection, data privacy and cybersecurity, including the EU
General Data Protection Regulation 2016/679 (the “GDPR”), the U.K.’s General Data Protection Regulation (“U.K.
GDPR”), the rules and regulations promulgated under the authority of the FTC, the CCPA and privacy laws of various U.S. states,
the Israeli Privacy Law, Canada’s federal Personal Information Protection and Electronic Documents Act (the “PIPEDA”),
the Quebec Privacy Act and other laws such as Quebec’s new Privacy Legislation Modernization Act (“Quebec’s Law 25”
and together with the PIPEDA and the Quebec Privacy Act, “Canadian Privacy Law”),
and the EU ePrivacy Directive (“ePD”). These laws and regulations generally define personal data to include location data
and online identifiers, which are commonly used and collected parameters in digital advertising and, among other things, impose stringent
user consent requirements and permit data subjects to request that we discontinue using certain data. The obligations imposed under data
protection, data privacy and cybersecurity laws and regulations could increase our potential liability and adversely affect our business.
In the European Economic Area (“EEA”), the U.K. and
Canada, we are subject to the GDPR, the U.K. GDPR and Canadian Privacy Law, respectively, which, among other things, impose requirements
to provide detailed and transparent disclosures about how personal data is collected and processed, grant rights for data subjects to
access, delete or object to the processing of their personal data, provide for a mandatory breach notification to supervisory authorities
(and in certain cases, affected individuals) of certain data breaches, set limitations on the retention of personal data and outline significant
documentary requirements to demonstrate compliance through policies, procedures, training and audits. In the EEA and the U.K., failure
to comply with the GDPR and the U.K. GDPR can result in significant fines and other liability under applicable law. In particular, under
the GDPR, fines of up to EUR 20 million (or GBP 17.5 million under the U.K. GDPR) or up to 4% of the annual global revenue of the noncompliant
company, whichever is greater, could be imposed for violations of certain of the GDPR’s requirements. European data protection authorities
have already imposed fines for GDPR violations, in some cases, of hundreds of millions of euros.
31
In Canada, the data privacy landscape is made up of different provincial
data privacy laws (including the Quebec Privacy Act and Quebec’s Law 25), Canadian federal data privacy laws as well as sector-specific
data privacy laws. In 2021, Quebec passed Quebec’s Law 25 overhauling the Quebec Privacy Act. Quebec’s Law 25 imposes strict
controller requirements, such as privacy policies; enhanced consent requirements when collecting, using or disclosing personal data; risk
assessments and data breach notification. Quebec’s Law 25 also granted individuals certain data privacy rights including a right
to erasure, right to restrict processing and, as of September 22, 2024, a right to data portability. Also under Quebec’s Law 25,
organizations must provide, by default, the parameters ensuring the highest level of confidentiality of a technological product or service
offered to the public. Canadian Privacy Law applies not only to third-party transactions, but also to transfers of information between
us and our subsidiaries, and under Quebec’s Law 25, personal data would include employee information. Failure to comply with Canadian
Privacy Law and other data privacy laws within Canada may expose us to administrative fines, litigation or enforcement actions brought
by data subjects and regulatory authorities, class actions and even punitive damages. Canadian federal data privacy law is currently being
overhauled and we expect that data privacy legislation across Canada will continue to evolve in the coming months and years.
In the U.S., both federal and state laws and regulations govern
the collection, use, maintenance and other processing of personal data, and the advertising industry has been subject to review by the
FTC, U.S. Congress, and individual states. For example, at the U.S. federal level, we are subject to the rules and regulations promulgated
under the authority of the FTC, which regulates unfair or deceptive acts or practices, including with respect to data protection, data
privacy and cybersecurity, and has taken an increasingly active approach to enforcing such regulations against companies that handle personal
data that is considered by the FTC a sensitive data for advertising purposes, including location data brokers and companies that process
health-related data. These enforcement actions by the FTC signal an increased regulatory scrutiny of advertising practices that involve
such data processing activities, which could adversely impact our ads business. In recent years, U.S. Congress has regularly considered
proposals for new data privacy and security laws to which we may become subject if enacted. Additionally, at the U.S. state level, we
are subject to, among other things, state privacy laws, such as the CCPA which provides data privacy rights for California residents and
operational requirements for covered companies. Among other things, companies covered by the CCPA must provide certain disclosures to
California residents and afford such residents the ability to opt-out of certain sales of personal data. The CCPA provides for civil penalties
for violations, as well as a private right of action for certain data breaches that is expected to increase data breach litigation. In
addition, the California Privacy Rights Act, which took effect in January 2023, has expanded the rights granted under the CCPA and imposed
additional notice and opt out-obligations, including an obligation to provide California residents with the ability to opt-out of the
processing of personal data for purposes of behavioral advertising and restrictions on the “sale” or “share” of
personal data (which it defines broadly under the CCPA), with significant enforcement penalties for non-compliance. Many other U.S. states
also have implemented, or are in the process of implementing, similar new laws or regulations, reflecting a trend toward more stringent
U.S. federal and state data privacy legislation, which could increase our potential liability and adversely affect our business. These
laws and regulations often make it easier for certain individuals to opt-out of having their personal data processed and disclosed to
third parties through various opt-out mechanisms, and this could result in an increase to our operational costs to ensure compliance with
such legal and regulatory changes and a decrease in personalized advertising leading to a decrease in revenues. Further, laws in all 50
states, under certain circumstances, require businesses to provide notice to consumers whose certain types of personal data has been disclosed
as a result of a data breach. Additionally, tracking technology litigation—including lawsuits brought under the California Invasion
of Privacy Act (“CIPA”) and the Electronic Communications Privacy Act continues
to create risk for organizations, prompting many companies to adopt an opt-in approach to placement of tracking technologies, such as
cookies, on their websites. Such litigation can be brought against any website using tracking technologies, advertisers placing such cookies
tracking technologies on publishers’ websites or other intermediaries placing tracking technologies on advertisers or publishers’
websites or platforms. We may be named in such litigaiton or other legal proceedings regarding evolving interpretations of privacy laws,
including CIPA, which could result in substantial damages and legal costs, civil damages, impact the operation of our business and cause
us reputational harm. The U.S. Department of Justice has issued rules restricting the transfer of certain personal data to countries of
concerns, i.e., China, Russia, Iran, North Korea, Cuba and Venezuela, as well as to individuals or organizations associated with these
countries. These restrictions may limit our ability to share such data and could subject us to liability in case of noncompliance.
Certain U.S. states (including Vermont, California, Texas, and
Oregon) have enacted data broker laws and regulations imposing certain requirements on data brokers, including, without limitation, requirements
relating to registration, consent, disclosure, and/or cybersecurity. California also amended its data broker law to impose additional
requirements applicable to companies that are registered there as data brokers (such as our subsidiary Hivestack Technologies Inc.), effective
on August 1, 2026, to honor requests by California residents to delete such residents’ personal information submitted through a
universal deletion mechanism. Furthermore, on June 20, 2025, the Texas governor signed two bills amending the Texas Data Broker Act. These
bills, among others, broaden the definition of “data broker”, alter certain applicability thresholds, and provide enhanced
notice and registration statement requirements. In addition, the FTC has increasingly issued orders restricting data brokers from selling
certain location data obtained by tracking individuals’ mobile devices. Other countries and jurisdictions have enacted and may further
enact similar or related laws or regulations, and/or their authorities may reach similar decisions. These laws, regulations, and decisions
and any additional laws, regulations and decisions that may be enacted or issued in the future, may result in significantly larger numbers
of consumers opting out of having their personal data used for targeted advertising purposes relative to historical averages. In addition,
consent requirements in the EU under the GDPR have become complex due to the CJEU ruling regarding the IAB Transparency and Consent Framework
(TCF). Further, due to ruling of the Belgian Market Court, there may be ambiguity around the lawfulness of informed consent obtained via
the TCF in the EEA and UK. If our implementation of these current or future laws, regulations, and decisions, including of the TCF or
other practices are found to be deficient by EU supervisory or other authorities, this could result in fines and enforcement actions,
reduced access to consumer’s personal data, impacting performance of our services or resulting in loss of business, and may require
us to develop complex and expensive compliance tools and procedures. Moreover, there has been an increase in laws and regulation for data
privacy in specific sectors. For example, laws and regulations specific to consumer health data have been enacted in certain U.S. states,
with an expectation that more states will follow. Such laws and regulations include Washington’s My Health My Data Act which imposes
certain requirements and obligations regarding the collection, sharing and sale of “consumer health data” – broadly
defined as personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present,
or future physical or mental health status. The Washington My Health My Data Act provides a private right of action and, together with
the broad definition and scope, is likely to trigger a wave of related litigation. As such, we may be limited with the advertising services
we can provide to customers in certain sectors in jurisdictions with such data privacy laws and regulations.
32
The Israeli Privacy Law and its regulations, including but
not limited to the Israeli Privacy Protection Regulations (Data Security) 2017 and the guidelines issued by the Israeli Privacy Protection
Authority (“PPA”), impose obligations regarding the collection, use, processing, transferring and securing of personal data.
In addition, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area),
2023 were enacted and consequently provide, in certain cases, additional rights to data subjects from the EEA or other data subjects whose
personal data is stored in the same database. A material amendment to the Israeli Privacy Law took effect in August 2025 (“Amendment
13”) which sets forth additional obligations regarding the processing of personal data and, among other things, expands the PPA’s
investigative authority and monetary sanctions that can be imposed for breach of the Israeli Privacy Law, to substantial amounts that
may reach in certain cases millions of NIS. Amendment 13 also imposes more extensive obligations on data brokers and grants the PPA authority
issued guidance regarding required consents and transparency, reflecting the PPA's legal interpretation for purposes of exercising its
authorities. Therefore, significant changes to the Israeli Privacy Law may necessitate adjustments to our data protection and security
practices. Lack of compliance with the Israeli Privacy Law could result in enforcement actions, litigation (including class actions),
fines and penalties and, in certain cases, criminal liability.
Most of our products and services are provided without direct relationships
with users/consumers, therefore, we rely on our data providers, customers or publishers to establish a legal basis required under the
applicable data protection and data privacy laws and regulations (for example, to obtain the consent from the user) on our behalf to process
their data and to implement any notice or choice mechanisms required under applicable data protection and data privacy laws and regulations.
However, if our data providers, customers, or publishers fail to follow this process, or to adapt their practices as the legal requirements
in this area continue to evolve, we could be exposed to legal liability and experience a reduction in the volume of data we receive, which
could adversely affect our business and results of operations.
The uncertainty created by these laws and regulations can be compounded
when services hosted in one jurisdiction are directed at users in another jurisdiction. For instance, certain data protection and data
privacy laws (including the GDPR, CCPA and Canadian Privacy Law) have an extra-territorial scope causing such laws to potentially govern
activities conducted by organizations established in jurisdictions outside of, in the case of the GDPR, the EEA, in the case of the CCPA,
California, and, in the case of PIPEDA and Quebec’s Law 25, Canada and Quebec, respectively. These laws contain significant penalties
for non-compliance. Additionally, under the GDPR, supervisory authorities in the EU member states have some flexibility when implementing
European Directives and certain aspects of the GDPR, which can lead to diverging national rules. In addition, following the withdrawal
of the U.K. from the EU, we are subject to the U.K. GDPR. While the U.K. GDPR currently imposes substantially the same obligations as
the GDPR, the U.K. GDPR does not automatically incorporate changes to the GDPR (which would need to be specifically incorporated by the
U.K. government). Moreover, the U.K. government has amended the U.K. GDPR through the Data (Use and Access) Act 2025 and may further reform
the U.K. GDPR in ways that, if formalized, are likely to deviate from the GDPR, all of which exposes us to two parallel regimes (GDPR
and U.K. GDPR), each of which authorizes similar fines and may subject us to increased compliance risk based on differing, and potentially
inconsistent or conflicting, interpretation and enforcement by regulators and authorities (particularly, if the laws are amended in the
future in divergent ways). The European Commission’s Digital Omnibus Proposal, published in November 2025, includes proposed amendments
to the GDPR and other EU laws and regulations, but it remains at an early stage of the EU legislative process.
Additionally, some countries are considering or have enacted legislation
requiring local storage and processing of data or otherwise restricting cross-border transfers of personal data that could increase the
cost and complexity of delivering our services. For example, as of September 22, 2023, Quebec’s Law 25 requires organizations
to conduct a privacy impact assessment (“PIA”) in certain circumstances, such as when transferring personal data from Quebec
to other jurisdictions (including to other provinces in Canada) as well as when acquiring, developing, or overhauling an information system
or electronic service delivery system that involves the collection, use, release, keeping, or destruction of personal data. Such PIAs
can be time consuming and costly and may impact our ability to attract/retain customers and service providers. Additionally, the GDPR
and the U.K. GDPR generally prohibit the transfer of personal data from the EEA and the U.K. to the United States and third countries,
unless the transfer is to a country deemed to provide adequate protection (such as Israel or Canada), the recipient is certified under
the EU-U.S. Data Privacy Framework (“DPF”), or the parties to the transfer have implemented specific safeguards to protect
the transferred personal data. The GDPR and the U.K. GDPR requirements apply not only to third-party transactions, but also to transfers
of information between us and our subsidiaries, including employee information.
33
Where we transfer personal data outside the EEA or the U.K. to
a country that is not deemed to be “adequate,” we rely on transfer mechanisms available under the relevant laws and regulations,
such as DPF certification or the EU Standard Contractual Clauses and their UK Addendum, and the efficacy and longevity of such mechanisms
remains uncertain. In some jurisdictions like the EU, U.K., Canada and Israel, the law and guidance on data transfers is rapidly developing
and recent developments will require us to review and may require us to amend or supplement the legal mechanisms by which we make and/or
receive personal data transfers. Additional costs may need to be incurred in order to implement necessary safeguards to comply with the
GDPR and the U.K. GDPR and potential new rules and restrictions on cross-border transfers of personal data could increase the cost and
complexity of conducting business in some markets. If our policies and practices, or those of third parties who process personal data
on our behalf, are, or are perceived to be, insufficient, or if individuals have concerns regarding the transfer of personal data from
the EEA or the U.K. to the U.S., we could be subject to enforcement actions or investigations by individual EU or U.K. data protection
authorities or lawsuits by private parties.
European supervisory authorities have also been very active in
terms of enforcing data protection rules. EU national laws that implement the ePD, which concerns the processing of personal data
and the protection of privacy in the electronic communications sector, continue to be subject to uncertainty in light of the European
Commission’s withdrawal of the ePrivacy Regulation, which was expected to alter rules on cookies and other tracking technologies,
impose burdensome requirements surrounding obtaining consent and significantly increase fines for non-compliance in February 2025. A European
court decision, regulatory guidance, and campaigns by privacy activists are continuing to draw attention to cookies and other tracking
technologies under existing laws and regulations. Increased regulation of cookies and similar technologies in the EEA and the U.K., in
addition to certain other jurisdictions such as Canada and the U.S., and any decline of cookies or similar online tracking technologies
as a means to identify and potentially target individuals, may lead to broader restrictions and impairments on our business activities
and negatively impact our efforts to understand users. Industry participants in the advertising technology ecosystem have taken or may
take action to eliminate or restrict the use of cookies and other identifiers. For example, Google had at one point announced plans to
fully eliminate support for third-party cookies in the Chrome browser but cancelled such plans instead opting to allow users to choose
whether to retain third-party cookies rather than completely removing them, and Apple implemented further restrictions on the use of mobile
identifiers on its devices. If such industry changes are pursued, we may need to take adaptive measures, which may include substantial
development and commercial changes. While we are taking measures to shift away from third-party cookies-based solutions, for example,
by using our proprietary cookieless solution, SORT®, which enables advertisers to reach their audience in real time without storing
any personally identifiable data, we generally rely on third-party cookies-based solutions. If the use of cookies is substantially limited
or if regulators start to enforce an increasingly strict approach, this could lead to substantial costs, require significant systems changes,
limit the effectiveness of our solutions and services, divert the attention of our personnel, adversely affect our business, and subject
us to additional liabilities.
The increase in attention to and regulation of data protection,
data privacy and cybersecurity across the globe in recent years will require us to further devote resources and incur additional costs
associated with compliance, as well as impose additional restrictions on our and our partners’ operations. Although we strive to
comply with applicable laws and regulations regarding data protection, data privacy and cybersecurity and to inform our customers of our
business practices prior to any installations of our product and use of our services, it is possible that these laws and regulations may
be interpreted and applied in a manner that is inconsistent with our data collection, use, maintenance and other processing practices
or that it may be argued that our practices do not comply with certain countries’ data protection, data privacy and cybersecurity
laws and regulations. Due to rapid changes in technology and the inconsistent interpretations of privacy and data collection and protection
laws and regulations, we may be required to materially change the way we do business. The challenges imposed by the ongoing need to remain
compliant with such laws and regulations, as well as the need to implement any changes due to newly introduced laws and regulations, may
slow our growth, and if we are not able to cope with these challenges as effectively as other companies, we will be competitively disadvantaged.
Any limitation on our ability to collect and utilize data, including personal data, would make it more difficult for us to be able to
optimize ad placement for the benefit of our advertisers and publishers, which could render our solutions less valuable and potentially
result in loss of clients and a decline in revenue. For example, we may need to adapt our advertising solutions that rely on third-party
cookies to a “cookie-less” environment and introduce alternative solutions which may not provide the targeting capabilities
provided by cookies, or adapt due to restrictions imposed on data brokers — for example with respect to geolocation data. In addition,
we may be required to implement physical, administrative and technological security measures that differ from those we have now, such
as different data access controls or encryption technology. Further, we use cloud-based computing, which is not without substantial risk,
particularly at a time when businesses of almost every kind are finding themselves subject to an ever-expanding range of privacy, data
collection and processing and cybersecurity laws and regulations, document retention requirements, and other standards of accountability.
Compliance with such existing and new laws and regulations can be costly and can delay or impede the development of new products.
In November 2022, the EU’s Digital Services Act (the “DSA”)
came into force in the EEA, and the majority of its substantive provisions took effect on February 17, 2024. The DSA imposes new content
moderation obligations, notice obligations, advertising restrictions and other requirements on online intermediaries and platforms, including
providers of intermediary services, hosting services and social media services. Additionally, the DSA may indirectly impact additional
players in the advertising technology industry by subjecting them to the DSA’s transparency requirements concerning online advertising.
Although we do not expect the DSA to have a material impact on our operations, there could be indirect consequences that adversely affect
the advertising technology industry and our business.
34
Any failure or perceived failure to comply with the foregoing
laws and regulations could result in negative publicity, increase our operating costs, require significant management time and attention
and subject us to inquiries or investigations, litigation (including class actions), claims, or other remedies, including penalties, fines,
sanctions and criminal and civil liabilities, or demands or orders that we modify or cease existing business practices, each of which
could materially adversely affect our operating results and our business. Further, any failure or perceived failure to comply with our
public privacy policies and other public statements about privacy and cybersecurity could potentially subject us to regulatory investigations,
enforcement or legal actions, and harm to our reputation and, if such policies or statements are found to be deceptive, unfair or misrepresentative
of our actual practices, fines, monetary or other penalties, and other damage to our business, financial condition and results of operations.
Moreover, concerns about our collection, use, maintenance and other processing of personal data or other data protection-, data privacy-
or cybersecurity-related matters, even if unfounded, could harm our reputation and operating results. For more information regarding government
regulations to which we are subject, see Item 4.B. “Business Overview— Government Regulation.”
If one or more states or countries determine
that we are required to collect sales, use, or other taxes on the services that we sell, this may result in liability to pay sales, use,
and other taxes (plus interest and penalties) on prior sales and a decrease in our future sales revenue.
While in some states we are subject to sales tax, in general, the
digital advertising business has not traditionally paid sales tax. However, a successful assertion by one or more cities, states or countries
that digital advertising services should be subject to such taxes or that we are not providing digital advertising services but other
services, and should collect sales, use, or other taxes on the sale of our services, or that we have failed to do so where required in
the past, could result in a decrease in future sales and/or substantial tax liabilities for past sales. Each state and country has different
rules and regulations governing sales, use, and other taxes, and these rules and regulations are subject to varying interpretations that
may change over time.
Following a U.S. Supreme Court decision regarding the rights of
individual states to tax out-of-state suppliers, certain states have adapted their statutes to expand taxation on out-of-state suppliers
of goods and services. Some states are also pursuing legislative expansion of the scope of goods and services that are subject to sales
and similar taxes as well as the circumstances in which a vendor of goods and services must collect such taxes. Furthermore, legislative
proposals have been introduced in Congress that would provide states with additional authority to impose such taxes. Accordingly, it is
possible that either federal or state legislative changes may require us to collect additional sales and similar taxes from our clients
in the future which could impact our future sales, and therefore could result in a material adverse effect on our revenue.
For example, the State of Maryland and the State of Washington
have enacted legislation to tax digital advertising revenues. Maryland's tax has been subject to ongoing judicial review, Washington’s
tax, which became effective in October 2025, is also facing legal challenges. Similar bills have been introduced in several other states.
Under current Israeli, U.S., Canada,
U.K., French and Ukrainian law, as well as other laws, we may not be able to enforce non-competition
and non-solicitation covenants and, therefore, we may be unable to prevent our competitors from benefiting from the expertise of some
of our former employees and/or vendors, whether current or former.
We have entered into non-competition and non-solicitation agreements
with many of our employees and vendors. These agreements prohibit our employees and vendors, if they terminate their relationship with
us, from competing directly with us, working for our competitors, or soliciting current employees away from us for a limited period. Under
current Israeli, U.S., U.K., French, and Ukrainian law, as well as other laws, and further under proposed legislation such as Senate Bill
S4641A in New York, we may be unable to enforce these agreements, in whole or in part, and it may be difficult for us to restrict our
competitors from gaining the expertise that our former employees gained while working for us. For example, Israeli courts have required
employers seeking to enforce non-compete undertakings of a former employee to demonstrate that the competitive activities of the former
employee will harm one of a limited number of material interests of the employer which have been recognized by the courts, such as the
secrecy of a company’s confidential commercial information or its intellectual property. If we cannot demonstrate that such harm
would be caused to us, we may be unable to prevent our competitors from benefiting from the expertise of our former employees.
Risks Related to our Intellectual Property
Our proprietary information, technology and
other intellectual property may not be adequately protected and thus our intellectual property may be unlawfully copied by or disclosed
to other third parties.
We regard the protection of our proprietary information, technology,
and other intellectual property as critical to our success. We strive to protect our intellectual property rights by relying on contractual
restrictions, trade secret, trademark, copyright and patent laws and other common law rights, as well as federal and international intellectual
property registrations and the laws on which these registrations are based. However, the technology we use and incorporate into our offerings
may not be adequately protected by these means.
35
We generally enter into confidentiality and invention assignment
agreements with our employees and contractors, and confidentiality agreements with parties with whom we conduct business, in order to
limit access to, and the disclosure and use of, our proprietary information, technology and other intellectual property. However, we may
not be successful in executing these agreements with every party who has access to our confidential information or contributes to the
development of our intellectual property. In addition, those agreements that we do execute may be breached, and we may not have adequate
remedies for any such breach. Further, these contractual arrangements do not prevent or deter independent development of similar intellectual
property by others.
In addition, there is no assurance that any existing or future
trade secrets, patents, copyrights or trademarks will afford adequate protection against competitors and similar technologies. Our intellectual
property rights may be misappropriated, infringed, reverse-engineered, circumvented, or otherwise violated by others, or challenged and
invalidated through administrative processes or litigation. Effective trade secret, trademark and patent protections are expensive to
develop and maintain, as are the costs of defending or enforcing our rights. Further, we cannot provide any assurances that competitors
will not challenge, invalidate, misappropriate, infringe, reverse-engineer, circumvent or otherwise violate our intellectual property
rights, or that we will have adequate resources to defend or enforce our rights. In addition, the laws of some countries do not
provide the same level of intellectual property protection as U.S. or Israeli laws and courts.
Claims of misappropriation, infringement
or other violation of third-party intellectual property rights or other third-party claims
against us could require us to redesign our products, seek licenses, or engage in costly intellectual property litigation, which could
adversely affect our financial position and our ability to execute our business strategy.
Given the competitive and technology-driven nature of the digital
advertising industry, companies within our industry often design and use similar products and services, which may lead to claims of third-party
intellectual property misappropriation, infringement, or other violation and subsequent litigation. We have been, and in the future may
be, the subject of claims that our solutions and underlying technology misappropriate, infringe or otherwise violate the intellectual
property rights of others. Regardless of whether such claims have any merit, they are time-consuming and costly to evaluate and defend,
and the outcome of any litigation is inherently uncertain. Our business may suffer if we are unable to resolve claims of third-party intellectual
property misappropriation infringement or other violation without major financial expenditures or adverse consequences.
We may seek to obtain licenses to third-party intellectual property
rights that we desire to use, which we would be allegedly misappropriating, infringing or otherwise violating or may misappropriate, infringe
or otherwise violate, without such licenses. Although holders of intellectual property rights often offer these licenses, we cannot provide
any assurances that such licenses will be offered on acceptable terms or at all. Our failure to obtain a license for key intellectual
property rights from a third party for technology, content, sound, or graphics we use could cause us to incur substantial liabilities
or to suspend the development or sale of our products. Alternatively, we could be required to expend significant resources to redesign
our products or develop non-infringing technology, content, sound, or graphics. If we are unable to redesign our products or develop non-infringing
technology, content, sound, or graphics, our revenue could decrease and we may not be able to execute our business strategy.
We may also become involved in litigation in connection with the
brand-name rights associated with our Company name or the names of our products. Third parties may claim that our Company name, our brand
names, or product names infringe their trademark rights. If we will need to change the name of our Company or any of our subsidiaries,
brands or products, we may experience a loss in goodwill associated with such name, customer confusion or a loss of sales. Any lawsuit
involving such a name, regardless of its merit, would likely be time-consuming, expensive to resolve, and divert our management’s
time and attention.
We may become subject to claims for remuneration
or royalties for assigned service invention rights by our employees, which could result in litigation and adversely affect our business.
A significant portion of our intellectual property has been developed
by our employees in the course of their employment for us. Under the Israeli Patent Law, 5727-1967 (the “Israeli Patent Law”),
inventions conceived by an employee in the course and as a result of, or arising from, his or her employment with a company are regarded
as “service inventions,” which belong to the employer, absent a specific agreement between the employee and employer giving
the employee service invention rights. The Israeli Patent Law also provides that if there is no such agreement between an employer and
an employee, the Israeli Compensation and Royalties Committee (the “Israeli Royalties Committee”), a body constituted under
the Israeli Patent Law, shall determine whether the employee is entitled to remuneration for his or her inventions. An employee may waive
the right to receive remuneration for “service inventions” and case law has held that in certain circumstances, such waiver
does not necessarily have to be explicit. The Israeli Royalties Committee will examine, on a case-by-case basis, the general contractual
framework between the parties in accordance with general Israeli contract law. Further, there is no specific formula for calculating this
remuneration. Under Canadian law, employees benefit from a presumption that they are entitled to ownership of a patent of any invention
they created in the course of their employment unless there is an express contract to the contrary or the employer can prove that the
employee was employed for the express purpose of inventing. Although we generally enter into invention assignment agreements with our
employees pursuant to which such individuals assign to us all rights to any inventions created in the scope of their employment or engagement
with us, we may still face claims demanding ownership rights or remuneration in consideration for such inventions. As a consequence of
such claims, we could be required to pay additional remuneration or royalties to our current and/or former employees, or be forced to
litigate such claims, which could negatively affect our business.
36
We use certain “open-source”
software tools that may be subject to intellectual property infringement claims or that may subject derivative works of such open-source
software to unintended consequences, which may impair our product development plans, interfere
with our ability to provide services to our clients, require us to allow access to the source code of our products or necessitate that
we pay licensing fees.
Certain of our products contain open-source code, and we may use
more open-source code in the future. In addition, certain third-party software embedded in our products contains open-source code. Open-source
code is computer code that is covered by a license agreement that permits the user to liberally use, copy, modify and distribute the software
without cost, provided that such users and modifiers abide by certain requirements. The original developers of the open-source code provide
no warranties on such code.
As a result of our use of open-source software, we could be subject
to suits by parties claiming ownership of what they believe to be their proprietary code or claims alleging non-compliance with, or seeking
to enforce, certain open-source code license terms. If we are not successful in defending against any such claims that may arise, we may
be subject to injunctions and/or monetary damages or be required to purchase a costly license or re-engineer our software products to
remove the open-source code from our products, which may be a costly and time-consuming process, and we may not be able to complete such
re-engineering process successfully. Such events could disrupt our operations and the sales of our products, which would negatively impact
our revenue and cash flow.
Moreover, under certain conditions, we may be obligated to make
derivative works of open-source code available to others at no cost. The circumstances under which our use of open-source code would compel
us to offer derivative code at no cost are subject to varying interpretations. If we are required to publicly disclose the source code
for such derivative products or to license our derivative products that use an open-source code license, our previously proprietary software
products may be made available to others at no charge. As a result, our customers and our competitors may have access to our products
at no cost to them which could harm our business. Certain open-source code licenses require, as a condition to use, modify and/or distribute
such open-source code, that proprietary software incorporated into, derived from or distributed with such open-source code be disclosed
or distributed in source-code form, be licensed for the purpose of making derivative works, or be redistributable at no charge. The foregoing
requirements may under certain conditions be interpreted to apply to our software, depending upon the use of the open-source code and
the interpretation of the applicable open-source code licenses. The terms of many open-source code licenses to which we may be subject
have not been interpreted by U.S. or foreign courts, and there is a risk that open-source code licenses could be construed in a manner
that imposes unanticipated conditions or restrictions on our ability to provide or distribute our products or services. The use of open-source
code may ultimately subject some of our products to unintended conditions so that we are required to take remedial action that may divert
resources away from our development efforts and have a material adverse effect on our business, financial condition and results of operation.
In addition, third-party software licensors generally do not provide
warranties or controls on the origin of software or other contractual protections regarding infringement claims or the quality of the
code with respect to the open-source components of their products and would not indemnify us in the event that we or our customers are
held liable for intellectual property infringement or other software-related claims in respect of the open-source components contained
in such third-party software. Further, some open-source code is known to have security risks and other vulnerabilities and architectural
instabilities or are otherwise subject to security breaches due to their wide availability, and are provided on an “as-is”
basis. There is typically no support available for open-source code, and we cannot ensure that the authors of such open-source code will
implement or push updates to address security risks or will not abandon further development and maintenance. Many of the risks associated
with the use of open-source code, such as the lack of warranties or assurances of title or performance, cannot be eliminated, and could,
if not properly addressed, have a material adverse effect on our business, financial condition and results of operation.
Risks Related to the Geographical Location
of our Operations
Our business relies significantly on the U.S.
market. Any material adverse change in that market could have a material adverse effect on our results of operations.
Our revenue has been concentrated within the U.S. market, accounting
for approximately 73% of our revenue in 2025. A recession that causes a reduction in advertising expenditures generally or other circumstances
that cause a decrease in our U.S. revenue could have a material adverse effect on our results of operations. Recent fluctuations in prevailing
interest rates due to higher-than-average inflation materially increase the likelihood of such circumstances and present significant potential
challenges to our U.S. business.
37
Our business may be materially affected by changes
to fiscal and tax policies. Potentially negative or unexpected tax consequences of these policies, or the uncertainty surrounding their
potential effects, could adversely affect our results of operations and share price.
We operate in a global market and are subject to tax in Israel
and other jurisdictions. Our tax expenses may be affected by changes in tax laws, international tax treaties, and international tax guidelines
(such as the Base Erosion and Profit Shifting project of the OECD’s Inclusive Framework (“BEPS”)).
The members of the OECD’s Inclusive Framework on BEPS have
agreed in October 2021 on certain recommendations, informally known as BEPS 2.0 or Pillar Two, which aim to modify international taxation
norms with the introduction of a 15% minimum tax applicable to in-scope multinational enterprises (with revenue in excess of Euro 750
million). The UK and the EU member countries as well as additional countries have already enacted legislation to implement the recommendations
which have come into effect gradually in 2024 and 2025. In January 2026, the OECD released a ‘Side-by-Side’ (SbS) relief package
and administrative guidance intended to coordinate the application of Pillar Two rules with existing tax regimes in jurisdictions like
the United States.
On December 31, 2025, Israel enacted the Law on the Minimum Corporate
Tax for Multinational Groups-2025, which is intended to align with the OECD Pillar Two framework and imposes a Qualified Domestic Minimum
Top-up Tax (QDMTT) at a rate of 15% effective for fiscal years beginning on or after January 1, 2026.
The application of the QDMTT law or other laws in other jurisdictions
enacted under the Pillar Two framework on us will depend on our consolidated global revenue and effective tax rate in future periods.
Our effective tax rate and cash tax payments could increase in
future years as a result of these changes. Further, the OECD’s Inclusive Framework on BEPS known as Pillar One which deals with
the allocation of taxing rights with respect to multinational enterprises with revenue in excess of Euro 20 billion and profitability
of more than 10%, focusing mostly on the digital economy, has made some progress - the OECD has released the text for a Multilateral
Convention (MLC) to implement these changes. However, as of early 2026, the MLC has not yet entered into force. The delay in ratification
may result in the continued imposition of unilateral digital services taxes by various jurisdictions, which could indirectly impact our
business and results of operations.
Certain of these changes could have a negative impact on our results
of operations and business. The impact of these changes is uncertain and may not become evident for some period of time. The uncertainty
surrounding the effect of the reforms on our financial results and business could also weaken confidence among investors in our financial
condition. This could, in turn, have a materially adverse effect on the price of our ordinary shares.
Our international operations involve special
risks that could increase our expenses, adversely affect our operating results and require increased time and attention of our management.
A large portion of our operations are performed from outside the
United States. In addition, we derive and expect to continue to derive a portion of our revenue from customers and users outside the United
States. Our international operations and sales are subject to a number of inherent risks, including risks with respect to:
• potential loss of proprietary information, technology and other intellectual property due to piracy, misappropriation, infringement, or other violation or laws that may be less protective of our intellectual property rights than those of the United States;
• costs and delays associated with translating and supporting our products in multiple languages;
• foreign exchange rate fluctuations and economic instability, such as higher interest rates and inflation, which could make our products more expensive in those countries;
• costs of compliance with a variety of laws and regulations;
• restrictive governmental actions such as trade restrictions or retaliatory trade measures, including trade wars;
• limitations on the transfer and repatriation of funds and foreign currency exchange restrictions;
• compliance with different consumer, data protection, data privacy and cybersecurity laws and regulations, and restrictions on pricing or discounts;
• lower levels of adoption or use of the internet and other technologies vital to our business and the lack of appropriate infrastructure to support widespread internet usage;
• lower levels of consumer spending on a per capita basis and fewer opportunities for growth in certain foreign market segments compared to the United States;
• lower levels of credit card usage and increased payment risk;
• changes in domestic and international tax regulations; and
• geopolitical events, including war and terrorism.
Political, economic and military instability
in the Middle East and specifically in Israel, including Israel’s war with Hamas and conflict with other parties in the region,
may adversely affect our operations and limit our ability to market our products, which would lead to a decrease in revenues.
We are incorporated under Israeli law, and many of our employees,
including our Chief Executive Officer, our Chief Financial Officer, and other senior members of our management team, operate from our
headquarters located in Israel. In addition, many of our officers and directors are residents of Israel. Accordingly, our business and
operations are directly affected by economic, political, geopolitical, and military conditions in Israel.
38
Since the establishment of the State of Israel in 1948, the region
has experienced ongoing, armed conflicts and hostilities. These events have included conflicts between Israel and neighboring countries
as well as terrorist organizations. Such conflicts have involved various forms of aggression, including missile strikes, hostile infiltrations,
and terrorism against civilian targets.
Following the October 7, 2023 attacks by Hamas, Israel declared
that it is in war against Hamas, leading to military conflicts with Hamas, Hezbollah and Iran (both directly and through proxies). Despite
some ceasefire agreements, military activity and hostilities continue varying levels of intensity. At the same time, in June 2025, Israel
launched a major military strike against Iran, resulting in a twelve-day armed conflict (the “Twelve-Day War”) that also involved
direct U.S. airstrikes on Iranian nuclear facilities. A ceasefire was reached on June 24, 2025. On February 28, 2026, Israel and the United
States launched a second, larger-scale offensive against Iran. Iran has retaliated with sustained attacks across the Middle East and was
joined by renewed Hezbollah attacks on Israel. As of the date of this filing, the conflict is ongoing with no ceasefire in place and the
situation remains volatile, with the potential for escalation into a broader regional conflict involving additional terrorist organizations
and possibly other countries.
While our facilities have not been damaged during the current conflicts,
ongoing hostilities have caused and may continue to cause damage to private and public facilities, infrastructure, utilities, and telecommunication
networks, and potentially disrupting our operations and supply chains. In addition, Israeli organizations, government agencies and companies
have been subject to extensive cyber-attacks. These factors could lead to increased costs, risks to employee safety, and challenges to
business continuity, with potential financial losses.
The continuation of the conflict has led to a deterioration of
certain indicators of Israel’s economic standing, for instance, credit rating actions or outlook changes by international rating
agencies.
The ongoing conflict has resulted in the drafting of a significant
number of Israeli military reservists for active duty, with expectations of continued reserve service in the coming years. While only
a few of our employees are called to active military duty, the absence of our employees due to military service in current or future conflicts
may materially adversely affect our ability to conduct our operations.
Our commercial insurance does not cover losses that may occur
as a result of events associated with war and terrorism. Although the Israeli government currently covers the reinstatement value of certain
direct physical damages caused by terrorist attacks or acts of war in Israel, we cannot assure you that such government coverage will
be maintained or that it will sufficiently cover our potential damages. Any losses or damages incurred by us could have a material adverse
effect on our business.
The global perception of Israel and Israeli companies, influenced
by international judicial bodies and geopolitical events, may lead to increased sanctions and other negative measures against Israel,
as well as Israeli companies and academic institutions. There is also a growing movement among countries, activists, and organizations
to boycott Israeli goods, services and academic research or restrict business with Israel, which could affect business operations. If
these efforts become widespread, along with any future rulings from international tribunals against Israel, they could significantly and
negatively impact business operations.
Prior to the October 2023 war, the Israeli government pursued changes
to Israel’s judicial system and has recently renewed its efforts to effect such changes. As of early 2026, several pieces of legislation
aimed at restructuring the judicial selection committee and re-regulating the civil service have advanced in the Knesset. These developments
have raised concerns that such proposed changes may negatively impact the business environment in Israel and could lead to political instability
or civil unrest. If such changes are pursued and approved, this may have an adverse effect on our business, results of operations, and
ability to raise additional funds. In addition, Israel’s election cycle (or the possibility of early elections) may contribute to
governmental inconsistency, policy uncertainty and civil unrest, any of which could adversely affect our operations and the Israeli business
environment.
We are exposed to the risk of natural disasters,
political events, war, terrorism, and pandemics, each of which could disrupt our business and adversely affect our results of operations.
Events beyond our control could have an adverse effect on our business,
financial condition, results of operations and cash flows. Disruption to our business resulting from natural disasters, political events,
war, terrorism, pandemics or other reasons could impair our ability to continue to provide uninterrupted service to our advertisers and
partners. For example, tensions between Russia and Ukraine, resulting in Russia’s invasion of Ukraine, and the possibility of retaliatory
measures taken by the United States and NATO have created global security concerns that could have a lasting adverse impact on regional
and global economies, and in turn, may lead to reduced spending on advertising and adversely affect our results of operations. Similarly,
the escalating military conflict between Israel, the United States, and Iran, including Israel’s Twelve-Day War against Iran in
June 2025 and the joint U.S.-Israel strikes on Iran that commenced in February 2026, has created significant instability across
the Middle East. Given that our headquarters and many of our operations are located in Israel, this conflict presents heightened and direct
risks to our business. Similarly, disruptions in the operations of our key third-parties, such as data centers, servers or other technology
providers, could have a material adverse effect on our business.
39
While we have disaster recovery and wartime resilience plan for
power and communication continuity arrangements in place, they have not been tested under actual disasters or similar events and may not
effectively permit us to continue to provide our services. If any of these events were to occur, our business, results of operations,
or financial condition could be materially adversely affected.
Investors and our shareholders generally may
have difficulties enforcing a U.S. judgment against us, our executive officers or our directors or asserting U.S. securities laws claims
in Israel.
We are incorporated under the laws of the State of Israel. Service
of process on us, our Israeli subsidiaries, our directors and officers and the Israeli experts, if any, named in this Annual Report on
Form 20-F, substantially all of whom reside outside of the United States, may be difficult to obtain within the United States.
Furthermore, because a significant portion of our assets and investments,
and most of our directors, officers and Israeli external experts are located outside the United States, any judgment obtained in the United
States against us or any of them may be difficult to collect within the United States.
We have been informed by our legal counsel in Israel that it may
also be difficult to assert U.S. securities laws claims in original actions instituted in Israel. Israeli courts may refuse to hear a
claim based on an alleged violation of U.S. securities laws reasoning that Israel is not the most appropriate forum to bring such a claim.
In addition, even if an Israeli court agrees to hear a claim, it may determine that Israeli law and not U.S. law is applicable to the
claim. There is little binding case law in Israel addressing these matters. If U.S. law is found to be applicable, the content of applicable
U.S. law must be proved as a fact, which can be a time-consuming and costly process. Certain matters of procedure will also be governed
by Israeli law.
Subject to specified time limitations and legal procedures, under
the rules of private international law currently prevailing in Israel, Israeli courts may enforce a U.S. judgment in a civil matter, including
a judgment based upon the civil liability provisions of the U.S. securities laws, as well as a monetary or compensatory judgment in a
non-civil matter, provided that the following key conditions are met:
• subject to limited exceptions, the judgment is final and non-appealable;
• the judgment was given by a court competent under the laws of the state of the court and is otherwise enforceable in such state;
• the judgment was rendered by a court competent under the rules of private international law applicable in Israel;
• the laws of the state in which the judgment was given provide for the enforcement of judgments of Israeli courts;
• adequate service of process has been effected and the defendant has had a reasonable opportunity to present his arguments and evidence;
• the judgment and its enforcement are not contrary to the law, public policy, security or sovereignty of the State of Israel;
• the judgment was not obtained by fraud and does not conflict with any other valid judgment in the same matter between the same parties; and
• an action between the same parties in the same matter was not pending in any Israeli court at the time the lawsuit was instituted in the U.S. court.
The tax benefits available to us for activities
in Israel and in other jurisdictions in which we operate require us to meet several conditions and may be terminated or reduced in the
future, which would increase our costs and taxes.
We have benefited and currently benefit from a variety of government
programs and tax benefits with regards to our operations, that generally carry conditions that we must meet in order to be eligible to
obtain any benefit. Our tax expenses and the resulting effective tax rate reflected in our financial statements may increase over time
as a result of changes in corporate income tax rates, tax incentive regimes or other changes in the tax laws of the countries in which
we operate, non-deductible expenses, loss and timing differences, or changes in the mix of countries, where we generate profit.
If we fail to meet the conditions upon which certain favorable
tax treatment is based, we would not be able to claim future tax benefits and could be required to refund tax benefits already received
including interest, and linkage. Any of the following could have a material effect on our overall effective tax rate:
• we may be unable to meet the requirements for continuing to qualify for some programs;
• these programs and tax benefits may be unavailable at their current levels; or
• we may be required to refund previously recognized tax benefits if we are found to be in violation of the stipulated conditions.
Additional details are provided in Item 5.A “Operating Results”
under the caption “Taxes on Income”, in Item 10.E. “Taxation” under the caption “Israeli Taxation”
and in Note 15 to our Financial Statements.
40