DATA PRIVACY POLICY

UPDATED POLICY

We have updated the Policy to reflect changes in data protection laws.

This updated Policy gives you more control over your information and more clearly explains how we use it.

You can read the updated Policy below. You can access the policy that’s in effect until May 24, 2018 here https://badi.com/blog/en/privacy-policy-and-data-protection/

If you object to any changes, you may close your account by writing us at info@badi.com.

WHO IS THE DATA CONTROLLER?

BadiApp 2015 INC. Sucursal en España, a European Subsidiary of BADI APP 2015, INC

(“BADI”, “us” or “we”) is the data controller for personal data processed under this Data Privacy Policy and is as such responsible for ensuring that the processing is conducted in accordance with applicable legislation.

By registering a user account, the user (“you” or “User”) acknowledges BADI’s processing of your personal data in accordance with the provisions below. This policy constitutes an integral and inseparable part of the Terms & Conditions of Use https://badi.com/blog/en/general-conditions-use/ and the definitions set out in them govern the interpretation of this policy.

This Data Privacy Policy applies for all our Platforms, although we may process different types of personal data depending on what platform that you use.

WHAT DATA DO WE COLLECT?

We collect information, including personal information, in various ways when you use our Platform. As used in this policy, “personal information” means any information which, either alone or in combination with other information, identifies you as an individual, such as your name, physical address, IP address, and email address.

The use of personal data is necessary for us to provide our services to you. This means that you cannot object to us processing your personal data altogether and still require us to provide our services to you. However, you are entitled to object to certain use of your personal data, and to opt-out of some kinds of processing.

(a)   Information you provide to us: When you sign up for and use our Services—you need to provide data including your name, email address and/or mobile number, and a password—send us an email, post on our blog, or communicate with us in any way, you are voluntarily giving us information that we collect. That information may include either your or your user name, physical address, email address, IP address, phone number, billing information (if you use our Booking Services).

(b)   Information that is collected automatically: When you use the Services or browse one of our Websites or use our Application/s (the “Platform”), we may collect information about your visit, your usage of the Services, and your browsing. That information may include your IP address, date and time, your operating system, your browser information, your browsing activity, and other information about how you interacted with our Platform, such as actions you take while on our Platform. We may collect this information as a part of log files as well as through the use of cookies or other tracking technologies.

(c) Information from Cookies: We and our partners may use various technologies to collect and store information when you use our Services, and this may include using cookies and similar tracking technologies on our Platform, such as pixels and web beacons, to analyze trends, track users’ movements around the Platform, provide personalized advertisements, and gather demographic information about our user base.

Users can control the use of cookies at the individual browser level. We partner with third parties to display advertising on our website or to manage and serve our advertising on other sites. Our third-party partners may use cookies or similar tracking technologies in order to provide you advertising or other content based upon your browsing activities and interests.

If you wish to opt out of interest-based advertising click on  http://www.youronlinechoices.eu (you might continue to receive generic ads). Below you will find information about opting out.

(d)   Information from third parties: From time to time we may obtain information about you from third party sources, such as marketing and attribution platforms, social media platforms, and third-party data providers via Cookies.

We take steps to ensure that such third parties are legally permitted or required to disclose such information to us. Examples of the information we may receive from other sources include: demographic information, device information (such as IP addresses), location, and behavioral data (such as information about your use of social media websites, page view information and search results and links).

We currently use the following providers:

Mixpanel. Please read their privacy policy at https://mixpanel.com/legal/privacy-policy/

Adjust. Please read their privacy policy at https://www.adjust.com/privacy-policy/

Google Analytics, Tag Manager, Fabric, Crashalytics. Please read their privacy policy at https://policies.google.com/privacy/update

Firebase. Please read their privacy policy at https://firebase.google.com/support/privacy/

Sendgrid.  Please read their privacy policy at https://sendgrid.com/policies/privacy/

Nexmo.  Please read their privacy policy at https://www.nexmo.com/privacy-policy

Stripe.  Please read their privacy policy at https://stripe.com/privacy

HotJar. Please read their privacy policy at https://www.hotjar.com/legal/policies/privacy

Intercom. Please read their privacy policy at https://www.intercom.com/terms-and-policies#privacy

(e)   Information from our Apps: When you use our mobile apps, we may collect certain information in addition to information described elsewhere in this Policy. For example, we may collect information about the type of device and operating system you use. We may ask you if you want to receive push notifications about activity in your account or tou ask for your consent to and for particular items. If you have opted in to these notifications and no longer want to receive them, you may turn them off through your operating system.

Only if you authorize it expressly, we may access or track location-based information from your mobile device at any time while downloading or using our Mobile Apps or Services. We may use mobile analytics software (including Adjust, as seen above) to better understand how people use our Apps. We may collect information about how often you use the application and other performance data.

HOW DO WE USE YOUR DATA?

We use information that we collect about you or that you provide to us, including any personal information, for the following purposes and legitimate basis:

–        To provide the Services through our Platform to you (legitimate basis: the improving of our Platform and Services)

–        To manage contact requests from you (legitimate basis: your request and if applicable, registration with us)

–        To provide you with information, products or services that you request from us or customer support (same legitimate basis as the previous point, as well as compliying with our legal obligations pursuant to Customer Protection Laws).

–        To fulfill or manage any contractual obligations between you and BADI—before, during and after the contract (legitimate basis: performance of a contract)

–        To assist in any matters regarding billing or payment on our Platform via Stripe. Please read the applicable terms https://stripe.com/es/legal (same legitimate basis as the previous point)

–        To manage your participation in contests and one-off promotions (legitimate basis: your consent, if expressly given by signing up to any such promotions)

–        To enforce compliance with our Terms & Conditions of Use and applicable law. This may include developing tools and algorithms that help us prevent violations, such as the detection of inappropriate, abusive or fraudulent behavior or language on our blogs or your chats with other users (legitimate basis: fulfillment of our legal obligation).

–        To protect the rights and safety of our users, third parties’, and ours (legitimate basis: fulfillment of our legal obligation).

–        To meet legal requirements, including complying with court orders, valid disclosure requests, and other appropriate legal orders (legitimate basis: fulfillment of our legal obligation)

–        To provide information to representatives and advisors, including attorneys and accountants, to help us comply with legal, accounting, or security requirements (legitimate basis: fulfillment of our legal obligation).

–        To prosecute and defend a court, arbitration, or similar legal proceeding (legitimate basis: fulfillment of our legal obligation).

–        To respond to lawful requests by public authorities, including to meet national security or law enforcement requirements (legitimate basis: fulfillment of our legal obligation).

–        To transfer your information in the case of a sale, merger, consolidation, liquidation, reorganization, or acquisition. In that event, any acquirer will be subject to our obligations under this Privacy Policy, including your rights to access and choice. We will notify you of the change either by sending you an email or posting a notice on the Platform (legitimate basis: fulfillment of our legal obligation).

–        To combine your personal information with other information we collect or obtain about you (such as information we source from our own third party cookies or services) to serve you specifically, such as to deliver a product or service according to your preferences or restrictions, or for advertising or targeting purposes in accordance with this Privacy Policy (legitimate basis: your consent and, if applicable, the improving of our Platform and Services)

–        To fulfill any other purpose for which you provide consent (legitimate basis: your consent).

–        To notify you about changes to our Platform or any products or services we offer or provide through it (legitimate basis: your consent and, if applicable, the improving of our Platform and Services).

HOW DO WE PROTECT YOUR DATA?

BADI has implemented appropriate technical and organizational measures for the protection of your personal data to ensure that only authorized persons are given access to it.

BADI uses technical security systems, such as firewalls, encryption technologies, passwords and anti-virus programs, to prevent and avoid unauthorized use of personal data.

HOW LONG IS YOUR DATA STORED?

BADI will not store or process your personal data for any longer time than what is necessary to fulfill the purposes for the processing set out in this Personal Data Policy or according to any mandatory applicable law.Therefore, when the purpose has been fulfilled in relation to a specific type of personal data, BADI will delete or anonymize the relevant personal data as soon as reasonably possible.

When processing is based on consent, and notwithstanding legal obligations otherwise, any data stored upon that legitimate basis will be deleted, or anonymized (for statistical purposes).

Please note that BADI uses backup systems to ensure the correct functioning of the services offered through our Platform. In the case of definite user deactivation, access to the account and user content will be deactivated and the contents will be deleted, with the exception of the backups that can be retained to cover possible legal responsibilities that may derive from the relationship with the User. Access to this data will be blocked in accordance with the law.

Also, BADI APP informs you that part of the systems, data and services of the Platform are hosted or used, among others, and for the purposes of Amazon Web Services (“AWS”): This is a set of cloud-based computer services offered by Amazon. BADI APP determines the regions in which the data on your platform is stored. The data on the platform is generally stored in countries subject to European data protection legislation. In the case of BADI APP, host content in AWS and these must be stored for any reason on servers located in the U.S. (outside the territory of the European Union), these are covered by the agreement reached by the US Government and the European Commission called the “EU-US privacy shield”. For more information: https://aws.amazon.com/es/compliance/data-privacy-faq/

ANONYMIZED DATA

We may create anonymous data records from your personal data by excluding information that makes the data personally identifiable to you. We use this anonymous data to analyze request and usage patterns so that we may enhance the content of our Services and improve the Platform. We reserve the right to use anonymous data for any purpose and disclose anonymous data to third parties in our sole discretion.

HOW DO WE SHARE AND DISCLOSE INFORMATION TO THIRD PARTIES?

Only in those instances we have your consent will BADI communicate your data to third companies outside our company. However, we may share and disclose information (including Personal Information) about our customers to with third party vendors, consultants and other service providers who we employ to perform tasks on our behalf necessary for the functioning of the Platform.

On the other hand, third parties located outside the European Union may access your personal data for the sole purpose of providing services that are necessary to manage and offer our users our services and products. In this regard, we inform you that we only select service providers that offer adequate guarantees of protection of your data, and which are adhere to

the EU-U.S. Privacy Shield: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en.

WHAT CHOICES DO YOU HAVE REGARDING THE USE OF YOUR DATA?

We have created mechanisms to provide you with the following control over your information:

(a)   tracking technologies and advertising. You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of the Platform may then be inaccessible or not function properly.

(b)   Opt-out. You may “opt out” of receiving marketing or promotional emails from us by following the instructions in those emails. If you opt out, we may still send you non-promotional emails, such as emails about your accounts or our ongoing business relations. Also, you will still receive—as your operating system allows—non-marketing push notifications about matters regarding the use of the platform, such as patch updates or changes to the platform.

WHAT ARE YOUR RIGHTS REGARDING PERSONAL DATA?

Right to access and rectification

You have the right to obtain information on what personal data BADI processes regarding you, the source of the data, for what purposes the data has been used, and the identity of parties to whom the data has been provided. If a request is manifestly unfounded or excessive, in particular because of its repetitive character, BADI may also refuse to act on the request.

You have also the right to, at any time, request a correction of any inaccurate or incomplete personal data.

Right to erasure (‘right to be forgotten’)

You may request that your personal data be erased in specific circumstance, for example, if you have deleted your user profile, the personal data is no longer necessary in relation to the purposes for which is was collected if there is no lawful reason for continuation of processing, the processing is unlawful, or the personal data has to be erased or anonymized to comply with a legal obligation in the European Union. This list is not exhaustive. Please contact BADI to receive further information on erasure of your personal data.

Right to object

You are entitled to object to processing of personal data that we base on our legitimate interest on grounds relating to your particular situation. If you lodge an objection, and the processing is based on a legitimate interest, we will no longer process your personal data unless we can demonstrate compelling and legitimate reasons for such processing that overrides your privacy interest.

However, please note that even if you object to certain processing, BADI may continue such processing if it is based on another legitimate basis, for example to provide services to you (should you still want to receive them) or to fulfil legal obligations.

Right to restriction

You can request that processing of your personal data is restricted if the personal data may not be correct, if you consider the processing to be unlawful, if BADI is basing its processing on a legitimate interest or if you believe that BADI does no longer need the personal data for providing you its services or products.

Right to withdraw consent

If you at any time have provided a consent to BADI for processing of personal data, you can always withdraw such consent for any future processing that is reliant on such consent.

Right to data portability

You have the right to receive the personal data concerning you, which you have provided to us, and that we process based on consent or to perform our agreement with you in a structured, commonly used and machine-readable format. You may also ask us to transmit such data directly to another controller where technically feasible.

You can make use of some of your rights, for example the right to opt-out from marketing based on your usage, by signing in to your account. When you are signed in, you can also make changes to certain personal data which we have stored about you.

You can also always contact us by phone (‭+34 933 023 673‬) or email at info@badi.com if you want to make use of your rights.

WHAT TO DO IF YOU HAVE ANY COMPLAINTS

If you have any complaints on how we use your personal data, or would like further information, we would ask you to first contact our Data Protection Officer at bcn@microlabhard.es (please Cc info@badi.com).

However, you can also always make a complaint about how we process your personal data with the relevant public supervisory authority, specifically the authority where you live, work or where the alleged infringement has occurred.

The relevant authority in Spain is:

Agencia Española de Protección de Datos

C/ Jorge Juan 6. 28001 – Madrid

Any claims may be submitted to http://www.agpd.es/portalwebAGPD/CanalDelCiudadano/derechos/principales_derchos)

Without prejudice to your rights to make complaints, where you consider that your rights under this Data Privacy Policy have been infringed as a result of the processing of your personal data in non-compliance with the applicable laws, you may also bring proceedings before the competent courts, including the courts of the EU member state where you have your habitual residence.

CHILDREN

BADI’s services will only be provided to those of the legal age or legally emancipated minors. Notwithstanding the foregoing, BADI APP shall not be liable in any case for any damages and losses that may arise in those cases in which the minor, at the time of registration, had not provided truthful information about their status.

Without prejudice to the foregoing, the access of minors to the contents included in the platform is the responsibility of their legal guardians, who are obliged to exert adequate control on the activity of their children or minors in their charge or to install some of the tools of control of the use of the Internet in order to avoid:

–        Access to content that is not suitable for children;

–        Any type of payment information (ex: Bank cards or virtual payment service accounts)

–        The sending of personal data without the prior authorization of their legal guardians.

If you believe we hold a minor’s personal data, especially under the age of 13, please contact us at info@badi.com.

 COOKIE POLICY

If you do not want BADI APP to deploy cookies in your browser, you can configure it to reject cookies or to inform you when a website tries to place a cookie in the browser software.

Most browsers allow you to configure cookie handling in the following 3 ways:

  •      Reject all cookies
  •      Accept all cookies; and
  •      Opt-in to accept or reject certain cookies.

The browser can also allow you to better specify which cookies have to be accepted and which ones do not. In particular, the user can normally accept one of the following options:

  •      Reject cookies from certain domains; Reject third party cookies;
  •      Accept cookies as non-persistent (removed when broswer closes);
  •      Allow the server to create cookies for a different domain.

BADI uses the following cookies:

Essential Technical Cookies (Always on)

These cookies are strictly necessary to provide you with services available through our platforms and to use some of its features, such as such as identifying the session, access secure areas, performing the process of purchasing an order, or sharing content. Because these cookies are strictly necessary to deliver our services, you cannot refuse them without impacting how our websites function. However, you can block or delete them by changing your browser settings, as described in our Cookie Policy.

Personalization and Advertising Cookies (Opt-in or Opt-out)

These cookies are used to make advertising messages more relevant to you and your interests. The collection and processing of information about your use of this service to subsequently personalize advertising and/or content for you in other contexts, such as on other websites or apps, over time. Typically, the content of the site or app is used to make inferences about your interests, which inform future selection of advertising and/or content. These cookies also allow you to determine certain Website options (language, visualization, bookmarks, browser type, etc.).

Analytical Cookies (Opt-in or Opt-out)

These cookies collect information that is used either in aggregate form to help us understand how our websites are being used or how effective our marketing campaigns are, or to help us customize our websites and application for you in order to enhance your experience.

To allow, know, restrict, block, or delete cookies or any other Web page, please see the configuration options of your browser:

BADI uses the following cookie-based providers

Mixpanel. Please read their privacy policy at https://mixpanel.com/legal/privacy-policy/

Google Analytics, Tag Manager, Fabric, Crashalytics. Please read their privacy policy at https://policies.google.com/privacy/update

Stripe.  Please read their privacy policy at https://stripe.com/privacy

HotJar. Please read their privacy policy at https://www.hotjar.com/legal/policies/privacy

Intercom. Please read their privacy policy at https://www.intercom.com/terms-and-policies#privacy

This Data Privacy Policy is translated from English into other languages for your convenience and for information purposes exclusively. Regarding any discrepancies between any such versions and the English original, the latter will prevail. The translated versions shall therefore be understood to be non-binding.