Updated: 1st of October 2018
Printt (we) are committed to protecting and respecting your privacy.
SCOPE OF POLICY
This policy (together with our Terms of Service) applies to your use of:
· Printt mobile application (the App) once you have downloaded or streamed a copy of the App onto your mobile telephone or handheld device (Device).
· Any of the printing and print management and delivery services (Services) that are available on or accessible through the App or the related site www.printtapp.com (Site).
This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of applicable data protection legislation, the data controller is AIWIP Ltd of 1 St Katherine’s Way, London, E1W 1UN. You can contact our Data Protection Officer by writing to us at that address, or by email to firstname.lastname@example.org.
We collect a range of data about you, your device, and your location. The data is collected from you and from other sources. See INFORMATION WE COLLECT ABOUT YOU for more
We use that data to power and improve the Printt service and serve targeted ads on the App and on free prints based on a profile we build around your information (for more on how and why we build a profile about you, see the PROFILING section below). We also use your data to run our business. See USES MADE OF THE INFORMATION for more.
We will share your data with others in order to provide the Printt service and run our business. See DISCLOSURE OF YOUR INFORMATION for more.
If you use the App to opt-in to location-based push notifications regarding promotions, Clear Channel and its technology partner will obtain some limited data about your device, and share it with the advertiser who uses Clear Channel to generate a push notification to you. The data does not identify you in the ‘real world’. More detail in the BEACONS section below.
Some of our service providers (like Stripe, our payment processor) will process your data outside Europe, but we take care to ensure that appropriate safeguards are in place. See WHERE WE STORE YOUR PERSONAL DATA for more.
You have a range of rights regarding the processing of your personal data. See YOUR RIGHTS for more.
INFORMATION WE COLLECT FROM YOU
We will collect and process the following data about you:
· Information you give us (Submitted information): This is information you give us about you by filling in forms on the App or the Site, or by corresponding with us (for example, by e-mail or chat). It includes information you provide when you register to use the Printt service, order paid prints, use our Printt Delivery service, enter a promotion we are running, and when you report a problem with the App, our Services, or our Site. If you contact us, we will keep a record of that correspondence. The information you give us may include your full name, e-mail address, age, gender, password, and other registration information. If you place an order for Printt Delivery, we will also need your delivery address and telephone number.
· Information we collect about you and your device. Each time you use the App or our Site we will automatically collect the following information:
o technical information, including the type of mobile device you use, a unique device identifier (for example, your Device's Apple or Google Advertising ID) (Device Information);
o material you upload or print using the Services (Print Material);
o and information relating to Print Material – for example, if you print an airline boarding pass for Barcelona using the App, we scan the contents of the boarding pass (including the origin and destination airport, the time of the flight, etc), and use it to match against keywords. So, we might record the fact that you printed a document that matched against our keywords ‘flight’ and ‘Barcelona’ (Content Information);
o details of your use of any of our Apps or your visits to any of our Sites including, the documents you have printed, the location of a printer you used, the time you used it, the number of pages you’ve printed, and whether you chose ad-funded or paid prints (Usage Information).
· Location information. We also use GPS technology to determine your current location. Some of our location-enabled Services require your personal data for the feature to work. You will be asked to consent to your data being used for this purpose. You can remove this consent by uninstalling the App, or adjusting your phone settings.
· Information we receive from other sources (Third Party Information). We work with certain third party service providers to power our services . Some of these providers send us information which may reference you individually. Stripe - our payment processor – will notify us of the result of a payment transaction you have initiated in respect of a paid-for print.
· Logging in using Facebook. If you login to the App or the Site using a Facebook login, you are granting permission to Facebook to share your user details with us. This consists of your age, gender, email, first name, last name, and an application-specific Facebook id, , which will then be used to form a Printt identity for you. This will also allow us and Facebook to share your networks, user ID and any other information you choose to share according to your Facebook account settings. If you remove the Printt app from your Facebook settings, we will no longer have access to any further information, but we will still have the information that we received when you first signed up for a Printt account using Facebook.
USES MADE OF THE INFORMATION
We are required to tell you what uses we make of your information, and the legal basis for our doing so. References in this section to the basis of processing (e.g. "Basis: Legitimate Interest”) are a reference to basis specified in General Data Protection Regulation under which we undertake the processing in question, as follows:
Legitimate Interest: means the interest of our business in conducting and managing our business to enable us to give you the best service and the best and most secure Printt experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us at email@example.com.
Performance of Contract: means processing your data where it is necessary for the performance of a contract between us and you (including the Printt terms of service) or to take steps at your request before entering into such a contract.
Legal Obligation: means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
Consent: means your affirmative consent, which you can withdraw at any time by adjusting the settings on your device or contacting us at firstname.lastname@example.org.
We use information held about you in the following ways:
· Submitted Information: to provide the Services to you, and to improve our services generally. We use your telephone number to help you track order for Printt Delivery. Basis: Legitimate Interest, Performance of Contract.
· Device information: to provide the Services to you, and to improve our services generally. Basis: Legitimate Interest, Performance of Contract.
· Print Material: we will use the material you upload in order to provide the printing service to you. We will also scan it to derive keywords, which we use to build a profile of you to help us serve ads to you more effectively (see Content Information below). Basis: Legitimate Interest, Performance of Contract.
· Content Information: we use the keywords we derive from the Print Material for the purposes of building a profile to help us serve targeted ads to you in the App and on your ad-funded prints (see Online Behavioural Advertising, below). For example, if we detect that you have printed an airline boarding pass to Edinburgh, we’ll add keywords to your profile that may result in you being shown ads relating to restaurants and experiences in Edinburgh. We will also use this on an anonymised aggregated basis to help improve our services, and to provide analytics and reports to our advertisers and business partners. We do not store details of which Print Material generated which keyword in your profile. We do not review the Print Material for any purpose other than deriving keywords. We do not share that profile (or any data personally identifying you) with any advertiser. Basis: Legitimate Interest.
· Usage information: we use this to calculate how many pages you have printed, and to provide you with the Services generally. We will also use information regarding which printers you have used to add to your profile (see Content Information). Basis: Legitimate Interest, Performance of Contract.
· Location information: we use this for the purposes of building your profile for advertising purposes – for example, we will add ‘London’ and ‘University’ as keywords to your profile if you use a printer in a student building in London. We also use it to show you which printers are closest to you. We may also use it to determine whether you should be served with ads for a particular campaign we are running – for example, if you are in a particular university’s premises, we may serve you an ad we have agreed with an advertiser to conduct within those premises. If you consent to receiving ‘push’ notifications based on your location, we will use this to notify you of offers from our advertiser partners which are dependent on your location. Basis: Consent, Legitimate Interest, Performance of Contract.
· Third Party Information: if you have selected paid Services, we use this to establish that you have paid for the Services. Basis: Performance of Contract, Legitimate Interests.
· Login data from Facebook: we use this data as specified in the INFORMATION WE COLLECT FROM YOU section.
We do not disclose any information about identifiable individuals to our advertisers, but we may provide them with anonymous aggregate information about our users (for example, we may inform them that 500 people aged under 25 have made prints bearing that advertiser’s ads in a 24-hour period). We may also use such aggregate information to help advertisers reach the kind of audience they want to target (for example, male students in Birmingham, who are over 25).
We will retain information we hold about you as follows:
Submitted Information: 3 years following the last active use of the service
Device Information: 3 years following the last active use of the service
Print Material: 3 years following the upload (or, if earlier, as soon as you notify us by contacting us at email@example.com that you wish it to be deleted).
Content Information: 3 years following the last active use of the service
Usage Information: 3 years following the last active use of the service
Location Information: 3 years following the last active use of the service
Third Party Information: 3 years following the last active use of the service
Printt Delivery address: 1 year following the last active use of the service
Facebook login data: 3 years following the last active use of the service
We use an advertising technique called profiling. Profiling is the technique we use to place in-app ads and ads on free-to-print documents via Printt. This allows us to deliver targeted advertising to users of our Services. It works by showing you adverts that are based on your printing patterns (including your location, and keywords derived from what you have previously printed), the way you have interacted with the App, whether you have been validated as a UK uni student, and some of the Submitted Information you provide us. For example, if you have been printing information about a particular type of car, you might be shown more ads for sales of that car in ad-funded prints and in the App. None of the profiling techniques used will use ‘real world’ identification or contact information such as your name, email address, postal address or phone number – they just use a unique identifier based on your device, in combination with the Location Information, Content Information and Usage Information and come of the Submitted Information we hold about you. If you would like more information regarding our use of profiling, email us at firstname.lastname@example.org. If you would like to opt out of OBA on Printt, please notify us at email@example.com and we will arrange for your account to be limited to paid prints only.
THE INFORMATION WE MAY COLLECT FROM YOU ABOUT OTHERS
DISCLOSURE OF YOUR INFORMATION
We will disclose the data we collect from you to the following third parties:
All data – we store all our data on servers provided by our hosting partner, Amazon Web Services so that they can store it and give us access to it.
B&H Printers is our printing services partner for our Printt Delivery service. We send them the material you wish to receive, your name, and address, so they can print your material and hand it to Royal Mail for delivery. B&H deletes your material and your name and address promptly on completing your printing.
Additionally, we will disclose your personal information to third parties:
· In the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets.
· If AIWIP Ltd or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
· If we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or request.
· In order to:
o protect the rights, property or safety of AIWIP Ltd, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
If you consent to the receipt of ‘push’ notifications based on your location, a piece of Clear Channel code in the App will notify and communicate with a Clear Channel ‘beacon’ when your Device is nearby the beacon at a time when the App is open. A beacon is an ad on a bus shelter or other piece of street furniture. No data that can identify you in the ‘real world’ is sent to or from the beacon. The beacon receives a number unique to your Device’s installation of the App (‘phone ID’) and uses it to count how many devices have been near the beacon, and how many devices have displayed an ad in Printt as a result of passing nearby. If you have consented to the receipt of ‘push’ notifications based on your location, the following information will be received by Clear Channel, their technology partner Eagle Eye, and the advertiser whose products and services are promoted by means of the notification: Phone ID; Android/iOS operating system number of your Device; and the make and model of your Device. That information is stored in the European Union.
WHERE WE STORE YOUR PERSONAL DATA
We store your data on Amazon Web Services servers in the UK and European Economic Area.
B&H Digital (our printing services partner) store your data in the UK and the European Economic Area.
Stripe’s services in Europe are provided by Stripe Payments Europe Ltd, an entity located in Ireland. In providing Stripe payment services, Stripe Payments Europe transfers personal data to Stripe, Inc. in the US. Stripe has agreed EU standard model contractual terms to provide an adequate level of data protection for the transfer of personal data to the US.
Also, Stripe is certified under the EU-U.S. and the Swiss-U.S. Privacy Shield Framework.
Mixpanel sends data obtained through its cookies to a Mixpanel server in the USA. Mixpanel’s processing of the data is subject to its EU-U.S. Privacy Shield certification.
For more details on the standard model clauses, see here - https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en
For more information on the EU-US Privacy Shield, see here - https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en
Under the General Data Protection Regulation you have a number of important rights free of charge. In summary, those include rights to:
• require us to correct any mistakes in your information which we hold
• require the erasure of personal information concerning you in certain situations
• receive the personal information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
• withdraw your consent to any processing we undertake on the basis of that consent (for example, sending you push notifications based on your location)
• object at any time to processing of personal information concerning you for direct marketing
• object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affecting you
• object in certain other situations to our continued processing of your personal information
• otherwise restrict our processing of your personal information in certain circumstances
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please:
• email us at firstname.lastname@example.org
• let us have enough information to identify you
• let us know the information to which your request relates, including any account or reference numbers, if you have them.
If you would like to unsubscribe from any promotional material we send you, you can also click on the ‘unsubscribe’ button at the bottom of the email.
If you make a complaint to us and think we have not dealt with it to your satisfaction, you may send your complaint to the Information Commissioner for investigation. For more information on the Information Commissioner, and how to make a complaint, please visit their website at www.ico.org.uk