Privacy Notice

Last updated: 14 June 2024

Intro 

This privacy notice will inform you how we look after, collect, process, and use your personal data when you use our App and tell you about your legal rights.

About us

Webpeak OÜ (Ltd) is the controller and responsible for your data ("we", "us", or "our").

Company Name

Webpeak OÜ (Ltd)

Registry code

16904672

Legal Address

Harju maakond, Tallinn, Lasnamäe linnaosa, Valukoja tn 8/2, 11415

Email

finance@webpeakou.net  – for general questions

finance@webpeakou.net – for privacy questions

Please note! We do not knowingly process the personal data of users under the age of 16. If you are such a user or the legal representative of such a user, please contact us.

By accessing or registering the App, the user agrees to the privacy notice and consents to collecting, processing, transferring, and using your personal data.

Before using the App, you must read and accept this privacy notice. If you don’t accept and agree to this privacy notice, you must immediately stop using our App.

Sources of data

We receive your data when you visit the App and interact with it, depending on your actions.

You can change your personal data by exercising your right to rectification and contact us about it. Please note that the same lawful basis and storage terms apply to the changed data.

We may also receive data from third parties. It depends on your settings and the features you use.

Lawful bases

For processing your personal data, we rely on the following lawful bases:

Types of data we collect

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We collect (automatically or with your consent), use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

Reasons for Processing

Types of data

 Lawful bases

 To identify the user.

User data. Your name, email, apple ID.

Performance of a contract with you.

Your consent.

For marketing and analytical purposes. To provide, improve and develop the App.

Device Data.Includes model, OS version, language, and time zone. Unique device identifiers (IDFA).

Performance of a contract with you.

Your consent.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our app)

To customize content within the App. To use App functions, share location with other users (friends, relatives).

Location data.  User geolocation (GPS).

Performance of a contract with you.

Your consent.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our app).

For marketing and analytical purposes. To provide, improve and develop the App.

Location data. Іnternet protocol (IP) address, and location.

Performance of a contract with you.

Your consent.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our app).

For marketing and analytical purposes. To provide, improve and develop the App.

Information about how you use our app, user activity within the App.

Performance of a contract with you.

Your consent.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our app).

To use application functions. In order to install a photo in your account.

Files and folders are placed on your device. Access to the gallery, photos.

Performance of a contract with you.

Your consent.

To use App functions. In order to install a photo in your account.

Device functions. Includes your camera.

Performance of a contract with you.

Your consent.

To provide access to the App, identify the user, and track the subscription period.

Data on subscription fees.

Performance of a contract with you.

Your consent.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our app).

Necessary to comply with a legal obligation.

We don’t collect any Special Categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). We don't collect any information about criminal convictions and offenses.

We also undertake to collect only such amounts and types of personal data strictly required for the purposes mentioned in this privacy notice section (data minimization principle).

For any new purpose of processing, we will ask for your separate explicit consent. To the extent necessary for those purposes, we take all reasonable steps to ensure that personal data is reliable, accurate, complete, and current for its intended use.

Third-party services and disclosures of your data

We are sharing your personal data with our service providers, which is strictly limited to cases and purposes stipulated in this privacy notice.

We’ll not use the information gained through your use of our App and other frameworks for advertising or similar services or sell it to advertising platforms, data brokers, or information resellers.

We require all third parties to respect the security of your personal data and to treat it under the law. We do not allow our third-party service providers to use your personal data for their purposes and only permit them to process your personal data for specified purposes.

We will not process personal data in a way incompatible with the purposes for which it has been collected or subsequently authorized by you by Section "Types of data we collect" of this privacy notice or collect any personal data that is not required for the mentioned purposes.

We disclose potentially personally identifying information (i.e., personal data) among our employees, contractors, and affiliated or other third-party organizations that (i) need to know that information in order to process it on our behalf or to provide services available at Company, and (ii) that have agreed not to disclose it to others.

We share your data with the parties below for purposes listen in Section "Types of data we collect".

External Third Parties: Google LLC, Meta Platforms, Inc., Apple Inc., Amplitude Inc., Firebase, Inc., Namecheap, Inc, Velia.net Internetdienste GmbH, Hetzner Online GmbH, Appfigures, Inc., Cloudflare, Inc., Amazon Web Services, Inc.

These parties help us with the storage of Personal Data, analyze or keep your data, and show relevant information about the App to us when you use the App to understand how you use the App, engage with particular features, and what you like or dislike the most to generate statistical reports.

Cross-border transfer of personal data. 

Some employees, contractors, and affiliated or third-party organizations may be located within or outside the USA, EU, or the European Economic Area (EEA). By using our App, you consent to transfer such information to them.

Changes to the privacy notice

We reserve the right to and may change this privacy notice occasionally. If we make any material changes, we will notify you through our App or email or by presenting you with a new version of this privacy notice for you to accept if we, for example, add new processing activities or collect additional personal data from you.

Your continued use of the App after the effective date of an updated version of the privacy notice will indicate your acceptance of the privacy notice as modified.

Opt-out options.

You can withdraw your consent or opt-out, whatever applies in your case, from sharing your Personal Data under this subsection anytime by using one of the following options:

Obtaining data from third parties

When a user buys a subscription, we receive transaction data, ID subscriptions, subscription terms, and App statistics from the Apple App Store.

The collection, processing, and transmission of data on purchase via the Apple App Store are further regulated by the Apple App Store data processing policy.

Banking information

When you pay for a subscription to our App, you share your banking information with the Apple App Store. This relationship is further regulated between the user and privacy notices in the Apple App Store.

We do not collect or process your bank information when buying a subscription.

Data security

We have implemented appropriate security measures to prevent your data from being accidentally lost, used, or accessed unauthorizedly, altered, or disclosed. In addition, we limit access to your data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your data based on our instructions and are subject to a duty of confidentiality.

We have implemented procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

We also use technical data encryption tools such as the technology listed below.

HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP, the protocol used for transmitting data over the Internet. HTTPS employs TLS (Transport Layer Security) or its predecessor SSL (Secure Sockets Layer) to encrypt the communication between a client (e.g., a web browser) and a server (e.g., a web server). This encryption helps protect sensitive data, such as login credentials, credit card information, and other personal information, from being intercepted by unauthorized parties.

TLS (Transport Layer Security): TLS is a cryptographic protocol that provides end-to-end encryption and authentication for data transmitted over computer networks. It is the successor to SSL and is widely used to secure various types of communication, including web browsing, email, file transfers, and remote desktop connections.

SSH (Secure Shell): SSH is a cryptographic network protocol that allows secure remote login and command-line access to computers over an unsecured network. It provides encryption and authentication capabilities, protecting the transmitted data from eavesdropping, data tampering, and other security threats.

SFTP (Secure File Transfer Protocol): SFTP is a network protocol that provides file access, file transfer, and file management functionality over a secure, encrypted connection. It is an extension of the SSH protocol and is commonly used for securely transferring files between computers over an unsecured network.

OpenVPN: OpenVPN is an open-source virtual private network (VPN) software that implements secure point-to-point or site-to-site connections using SSL/TLS protocols. It allows users to securely access remote resources over an unsecured network by creating an encrypted tunnel between the client and the VPN server.

LDAP over SSL (LDAPS): LDAP (Lightweight Directory Access Protocol) is a protocol used for accessing and maintaining distributed directory information services. LDAPS refers to the use of LDAP over an encrypted SSL/TLS connection, ensuring that the communication between the LDAP client and server is secure and protected from unauthorized access or eavesdropping.

Data retention

How long will you use my personal data?

We will only retain your data for as long as necessary to fulfill the purposes for which we collected it, including satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your data, the purposes for which we process your data, and whether we can achieve those purposes through other means, and the applicable legal requirements.

We store your data while you use our App.

In some circumstances, you can ask us to delete your data. To send an email to our address: finance@webpeakou.net. 

In some circumstances, we may anonymize your data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

We require all third parties to respect the security of your personal data and treat it under the law. We do not allow our third-party services providers to use your personal data for their purposes and only permit them to process your personal data for specified purposes and under our instructions.

We do not use user data for sale (or any other commercial activity) to other companies. User data is used solely to ensure the App's functionality.

Your legal rights

European Economic Area residents

As a data subject, you have the right to interact with its data directly or through a request to us. This section describes these rights and how you can exercise them:

Right

Description

Right to access

You can request an explanation of how your personal data is processed.

Right to rectification

You can change the data if it is inaccurate or incomplete.

Right to erasure

You can send us a request to delete your personal data from our systems. We will remove them unless otherwise provided by law.

Right to restrict the processing

You may partially or completely prohibit us from processing your personal data.

Right to data portability

You can request all the data you provided to us and request to transfer data to another controller.

Right to object

You may object to the processing of your personal data.

Right to withdraw consent

You can withdraw your consent at any time.

Right to file a complaint

If your request was not satisfied, you could file a complaint to the regulatory body.

To exercise your rights, contact us. If your request is not satisfied, you can submit a complaint to your local Data Protection Authority. You may find it here.

UK residents enjoy the same rights but may lodge a complaint at the other Authority in the UK – Information Commissioner’s Office.

You can contact them at 0303 123 1113 or go online at www.ico.org.uk/concerns.

United States residents

You, as data subjects, have some special privacy rights. To use them, please contact us at finance@webpeakou.net.

Please note! Depending on the state and legislative requirements, we have from 30 to 60 days to exercise your request, with the right to postpone it for 30 days more.

If your complaint is not satisfied, you can file a complaint with the Federal Trade Commission.

Your rights vary depending on the laws that apply to you but may include:

Right

Description

Area

Right to access

You can request an explanation of the processing of your personal data.

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Iowa;
  • Montana;
  • Tennessee;
  • Texas;
  • Utah;
  • Virginia.

Right to correct

You can change the data if it needs to be more accurate or complete.

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Montana;
  • Tennessee;
  • Texas;
  • Virginia.

Right to delete

You can request to delete your personal data from our systems.

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Iowa;
  • Montana;
  • Tennessee;
  • Texas;
  • Utah;
  • Virginia.

Right to portability

You can request all the data you provided to us and request to transfer data to another controller.

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Iowa;
  • Montana;
  • Tennessee;
  • Texas;
  • Utah;
  • Virginia.

Right to opt out of sales

The right to opt out of the sale of personal data to third parties.

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Iowa;
  • Montana;
  • Tennessee;
  • Texas;
  • Utah;
  • Virginia.

Right to opt out of certain purposes

The right to opt-out of processing for profiling/targeted advertising purposes.

  • Colorado;
  • Connecticut;
  • Indiana;
  • Montana;
  • Tennessee;
  • Texas;
  • Utah;
  • Virginia.

Right to opt out of the processing of sensitive data

The right to opt-out of processing of sensitive data.

  • California.

Right to opt in for sensitive data processing

The right to opt in before processing sensitive data.

  • Colorado;
  • Connecticut;
  • Indiana;
  • Montana;
  • Tennessee;
  • Texas;
  • Virginia.

Right against automated decision-making

A prohibition against a business making decisions about a consumer based solely on an automated process without human input

  • California;
  • Colorado;
  • Connecticut;
  • Indiana;
  • Iowa;
  • Montana;
  • Tennessee;
  • Texas;
  • Virginia.

Private right of action

The right to seek civil damages from a controller for statute violations.

  • Californi.

Please note! Some states do not have privacy laws. The rights of residents of such states are governed by U.S. federal law. If your state is missing from the list, please contact us.

Do not sell my personal information

California residents have the right under the California Consumer Privacy Act (“CCPA”) to opt out of the “sale” of their personal information by a company governed by the CCPA.

We do not sell your personal information to anyone nor use your data as a business model.

However, we support CCPA by allowing California residents to opt out of any future sale of their personal information. Please contact us if you would like to record your preference that we will not sell your data in the future.

Canada residents

As data subjects, you have privacy rights prescribed by Canada’s federal and provincial privacy laws.

If you want additional information, please contact us at finance@webpeakou.net.

If your complaint is not satisfied, you can file a complaint to the Office of the Privacy Commissioner of Canada.

Children's Online Privacy Protection Act

COPPA requires us to obtain verifiable parental or guardian consent before collecting, using, or disclosing personal information from children under 13.

Suppose your child is under 13, and you want them to use our App. In that case, you must provide verifiable parental consent.

Providing consent is a straightforward process. You can use your credit or debit card to make in-app purchases and subscriptions for your child.

When creating your child's account, you will be prompted to pay for one of our subscriptions through the Apple payment system.

This card transaction provides verifiable parental consent under COPPA.

Upon successful completion, you will be allowed to use our App.

You can revoke your consent at any time by contacting us at finance@webpeakou.net. We will delete your child's personal data upon revocation.

We prioritize your child's data protection. We will not collect more data than reasonably necessary, use it for any other purpose, or retain it longer than needed.

 

Glossary

In this notice, the following terms shall have the following meanings:

Lawful basis. Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

You can obtain further information about how we assess our legitimate interests against any potential impact on you regarding specific activities by contacting us at finance@webpeakou.net.

Performance of Contract. This means processing your data where necessary for the performance of a contract to which you are a party or taking steps at your request before entering into such a contract.

Complying with a legal or regulatory obligation. This means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.