1 BACKGROUND AND PURPOSE
2 SCOPE
3 DURATION
4 CONTROLLER’S OBLIGATIONS
5 PROCESSOR’S OBLIGATIONS
6 COMPENSATION
7 USE OF ANOTHER PROCESSOR
8 DATA EXPORT
9 AMENDMENTS
10 LIMITATIONS OF LIABILITY
11 DISPUTES AND CHOICE OF LAW
GENERAL INFORMATION
We attach great importance to the protection and handling of your personal data in accordance with the applicable law, in particular in accordance with the General Data Protection Regulation of 27 April 2016 ("GDPR"). Our goal is to provide you with full information and control regarding the processing of your data and the availability of tools that allow you to take advantage of the rights arising from the law.
Below we present information on which personal data we process about you, how we process your personal data and the legal basis under which we process your personal data. You can also read about your rights as a data subject, how we care for the security of your data and who we share it with. If you have additional questions about how we use your personal data, write to us at the following email address: fm@iot4all.co.
WHO IS THE CONTROLLER FOR THE PROCESSING OF YOUR DATA?
IOT4ALL ApS, company reg.no. 39085666 , Aabenraa 4, 1124 Copenhagen K, Denmark CVR ("Easy Home","we", "us" or "our"), is the controller for the processing of your personal data.
HOW CAN YOU CONTACT US?
You can send an email to: fm@iot4all.co or by regular mail to: Easy Home Smart Systems ApS, Hyskenstræde 12, 1207 Copenhagen K, Denmark
WHEN DO WE PROCESS YOUR DATA?
We process personal data about you in the following situations:
We focus on the transparency of processing your personal data. If you have any question about the process or rules of processing, please contact us.
We process your data in accordance with applicable law, ensuring that it remains current and correct. Therefore, from time to time we will remind you about the need to update the data by sending a message to the e-mail address provided by you.
Your personal data will not be processed for automated decision making without your consent.
WHICH PERSONAL DATA DO WE PROCESS AND FOR WHAT PURPOSES DO WE PROCESS THE DATA?
You have set up an account on the Platform
When you set up an account on the Platform, whether directly via a Easy Home app, the Easy Home home page or via an administrator or other third party, we will process personal data about your e-mail, telephone number, house nickname, activity logs, data generated by the data, data collected by the installed devices (e.g. data from electronic door locks og on electrical consumption), list of installed devices, push notification devices enabled, geo-location of the house based on the gateway location (IP).
We will process your personal data for the following purposes:
The legal basis for processing your data will be to fulfil the contract concluded with you (GDPR article 6(1)(b)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our legitimate interest (GDPR article 6(1)(f)).
It is up to you to decide whether and what data you provide us with on the Platform, but remember that when setting up an account on the Platform, providing certain data will be mandatory to provide you the service, because without them you will not be able to login to your secure account, have access to the functionalities of the Platform, manage and control your integrated devices and/or receive notifications from the devices.
You have sent us a Ticket
When you set sent us a Ticket we will process personal data about your name, address, e-mail, phone number, data collected by your devices installed on the Platform.
We will process your personal data for the following purposes:
We use Zoho Desk (https://desk.zoho.eu/) and Zoho CRM (https://crm.zoho.eu/) to process the Ticket and the data associated with it.
The legal basis for processing your data will be to fulfil the contract concluded with you (GDPR article 6(1)(b)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our legitimate interest (GDPR article 6(1)(f)).
You have applied for a job with us
When you apply for a job with us we will process personal data about your name, address, e-mail, telephone, information included in your CV, application and LinkedIn profile.
We will process your personal data for the following purposes:
We use BambooHR (https://www.bamboohr.com) for holding this data.
The legal basis for processing your data will be to enter into a contract with you (GDPR article 6(1)(b)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our legitimate interest (GDPR article 6(1)(f)).
You are our contact person with our suppliers, customers or any other third party
When you are our contact person with our suppliers, customers or any other third party we will process personal data about your name, e-mail, telephone number(s), title, company you work for. In this context, we use Zoho CRM (https://zoho.com/crm/) for data storage, Zoho Projects (https://projects.zoho.eu/) for project management and Zoho Sign (https://sign.zoho.eu/) for signing legal documents.
We will process your personal data for the following purposes:
The legal basis for processing your data will be to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our legitimate interest (GDPR article 6(1)(f)).
You have requested a demo
When you request an Easy Home demo, we will process personal data about your name, address, region, e-mail, telephone, company, company size and your title.
We will process your personal data for the following purposes:
We use Zoho tools (https://www.zoho.com/gdpr.html) such as Zoho Forms, Zoho CRM for handling this data.
The legal basis for processing your data will be to enter into a contract with you (GDPR article 6(1)(b)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our legitimate interest (GDPR article 6(1)(f)).
You have agreed to receive commercial information
When you agree to receive commercial information, we will process personal data about your name and e-mail address.
We will process your personal data for the following purposes:
The legal basis for processing your data will be to your consent (GDPR article 6(1)(a)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our or our partners legitimate interest (GDPR article 6(1)(f)).
You are not required to give your consent to receive commercial information. If you give your consent, you will be able to withdraw it at any time by contacting the above data or clicking on the link that we send in each e-mail containing commercial information. Withdrawal of consent does not affect the correctness of data processing in the period before its withdrawal.
You have decided to make purchases in our Store
When you make a purchase in our Store, we will process personal data about your name, billing address, delivery address, email, phone number.
We will process your personal data for the following purposes:
The legal basis for processing your data will be to fulfil the contract concluded with you (GDPR article 6(1)(b)); to comply with a legal obligation (GDPR article 6(1)(c)); or to fulfil our or our partner’s legitimate interest (GDPR article 6(1)(f)).
We will process data from you only to the extent necessary to fulfil the purposes described above. It is up to you to decide whether and what data you provide us with, but remember that when making purchases in the Store, providing certain data will be mandatory to perform the contract of sale, because without them we will not be able to process your order. Failure to provide the data we require results in failure to place an order.
WHO WILL WE DISCLOSE OR SHARE YOUR PERSONAL DATA WITH?
Depending on the personal data involved and the purpose of the processing and the context in which personal data is included, we may disclose your personal data to third parties (as independent data controllers). We may also share personal data with our suppliers when necessary for the purpose of the cooperation (as data processors).
You have set up an account on the Platform
Our Platform and Apps are using: Amazon Web Services (AWS), Push notification services (Firebase Cloud Messaging), Google Play Store, Apple App Store, Google Analytics and Firebase Crashlytics.
You have sent us a Ticket
We use Zoho Forms (https://forms.zoho.eu/) and Zoho Desk (https://desk.zoho.eu/) for support to our customers via NorthQ’s website. The information that you provide us while placing the ticket is processed in Zoho Desk by our Support Team. Please see Zoho’s Privacy Policy here: https://www.zoho.com/privacy.html.
You have applied for a job with us
We use BambooHR (Privacy Policy: https://www.bamboohr.com/privacy.php) to collect the job applications. If you applied directly or via a career portal such as Graduateland, we will save your application on the company’s Google Drive for relevant parties to have access to it.
You have sent us a message via Contact Form on the website
We use Zoho CRM as the Customer Relationship Management System (Privacy Policy: https://www.zoho.com/privacy.html), so that the information provided via the contact form on www.easy-home.app is sent to us via Zoho Desk, using Zoho Forms.
You are our contact person with our suppliers, customers or any other third party
We use Zoho CRM (https://crm.zoho.eu/) as our Customer Relationship Management system. Please see the Zoho Privacy Policy here: https://www.zoho.com/privacy.html.
You have agreed to receive commercial information
We will share your information with the entities providing on our request with the service of sending commercial information, such as:
You have decided to make purchases in our Store
We will pass your data to entities that cooperate with us in the performance of the contract for the sale of goods purchased by you.
We will share your data necessary for the delivery of goods to LEMAN International System Transport A/S (Leman’s Privacy and Cookie Policy: http://leman.dk/cookies) who will share your data with one of the following entities, depending on your choosing how to deliver the goods:
Depending on your choice of payment method for purchased goods, we will share your data necessary for collection or payment for purchased goods to the following entities:
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. For more insight, you may also want to read Wix’s Terms of Service (https://www.wix.com/about/terms-of-use), Privacy Statement (https://www.wix.com/about/privacy) and Wix’s Billing Services and PCI Compliance (https://support.wix.com/en/article/security-of-wixs-billing-services-and-pci-compliance).
TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES
We will seek to keep all personal data within the European Union or EEA; it is not our intention to export data.
HOW LONG WILL WE PROCESS YOUR PERSONAL DATA?
The personal data provided by you will be processed for the time necessary to fulfil the purposes described in this privacy policy. e.g.:
HOW ARE WE PROTECTING YOUR DATA?
We will ensure the confidentiality, integrity and availability of the personal data that we process through technical and organisational security measures.
We use a range of IT and organizational security measures aimed at minimizing the risk of data leakage, their destruction and disintegration, such as: firewall system, cyber security good practices, internal access procedures, data processing and emergency recovery, as well as a multi-level backup system.
All third party services are trusted platforms with big communities. NorthQ is using latest security standards in order to use, build on top off and/or integrate with those services.
Our Store operates on a platform with a very high level of security and we use a high level of encryption HTTPS/SSL connection in accordance with accepted best practices.
Remember that using the internet always brings with it the risk of certain security incidents, but we assure you that thanks to the implemented regular procedures, reviews of information systems and their updates, and active monitoring of critical points of the system, we want to reduce this risk as much as possible.
WHAT RIGHTS DO YOU HAVE IN RELATION TO THE PROCESSING OF YOUR PERSONAL DATA BY US?
According to the GDPR, you have a number of rights in connection with providing your personal data to us, such as:
If you would like to exercise any of your rights please contact us on our email: fm@iot4all.co.
HOW LONG TIME WILL IT TAKE FOR YOU TO GET THE ANSWER FROM US?
We try to complete your requests as quickly as possible and answer your questions about your data. In any case, you should receive a message from us not later than within 30 days of receiving your request. During this period we will give you an answer or inform you about the extension of the deadline and explain the reasons. If we have doubts as to whether you are making a specific request, we may ask a few more questions to verify your identity.
INFORMATION ON THE COMPETENT AUTHORITY
If you feel that we are processing your personal data unlawfully, you can also file a complaint with Data Protection Agency in Denmark (https://www.datatilsynet.dk/).
If you have any questions related to the processing of your personal data by us or you want to use the rights resulting from the GDPR, please use the contact form or write directly to our Data Protection Officer: fm@iot4all.co.
UPDATES TO THIS PRIVACY POLICY
From time to time, we may need to update this privacy policy. We regularly review our privacy policy to ensure that it is updated, accurate and in accordance with applicable laws and principles for processing of personal data.
INFORMATION ON THE USE OF "COOKIES"
DEFINITIONS
TYPES OF COOKIES USED
a) SESSION COOKIES: they are stored on the User's Device and remain there until the session of the given browser ends. The saved information is then permanently removed from the Device's memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from the User's Device,
b) PERMANENT COOKIES: they are stored on the User's Device and remain there until they are deleted. Ending the session of a given browser or turning off the Device does not delete them from the User's Device. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the User's Device.
The User has the ability to limit or disable the access of cookies to his Device. If you use this option, the use of the Website will be possible, in addition to functions that, by their nature, require cookies.
THE PURPOSES FOR WHICH COOKIES ARE USED
THE POSSIBILITY OF DETERMINING THE CONDITIONS FOR STORING OR ACCESSING COOKIES
Last revision on 27.02.2022
Copyright © 2022 IOT4ALL Aps