Last Updated: October 15, 2019
Thank you for choosing HeyTap!
BRAVO UNICORN PTE LTD is a "data controller" within the meaning of EU General Data Protection Regulation n°2016/679 of 27 April 2016 (GDPR). This means that we are responsible for deciding how we hold and use your personal data, as well as complying with the provisions of GDPR in doing so.
This policy will help you understand the following:
II. How We Collect and Use Your Personal Data
III. How Long We Keep Your Personal Data
IV. How We Disclose Your Personal Data
V. How We Protect Your Personal Data
VI. Your Rights with Regards to Your Personal Data
VII. How We Process Children's Personal Data
VIII. Third-Party Service Providers and Their Services
IX. How Your Personal Data Is Transferred Globally
XI. Contact Us
"Affiliated Company" refers to a company that is related to us due to joint ownership or control.
"Third Parties" refer to companies or persons who do not have a related relationship arising out of joint ownership or control with us (i.e., a non-affiliated company) or other non-related persons. Third parties can be financial or non-financial companies, or persons other than you and us.
"Personal Data" refers to any information relating to an identified or identifiable natural person.
We collect data for efficient operations and to provide you with the best product experience. Our channels for collecting personal data include: (1) you provide us your data directly, (2) we record certain data about how you interact with our products, and/or (3) we obtain certain data about you from third parties.
The data we collect depends on the environment in which you interact with us, the choices you make, including your privacy settings and the products and features you use.
1. Personal Data We Collect
(1) Information directly provided by you
The services we provide require you to provide certain personal data directly to us. For instance:
Registering a HeyTap Account requires you to complete a personal profile where you would provide personal data such as name, date of birth, mobile number, email address, username and password , photos, emergency contact person, their contact information, etc.
We may ask you to provide personal data and collect it under other circumstances, these circumstances include participating in prize draws or competitions, participating in promotional or marketing activities organized by us or our business partners, completing questionnaires, participating in user forums or blogs hosted by us or our business partners. The information you provide helps us design and improve the products, personalize your shopping experience, and provide purchase suggestions. We may match your information with third-party data to better understand your needs.
(2) Service Usage Information
In addition to the information you provide, we may also collect information about your use of our services through software on your device and other means. For example, we may collect:
a. Device information — such as device name, device model, region and language settings, device identification number (IMEI number, etc.), device hardware information and status, usage habits, IP address, operating system version, and settings of the device used to access the service.
b. Log information —such as when and how long the service is used, search terms entered through the service, and error log information of your device. The Android system is designed in such a way that your error or crash logs will include the overall information when the events occur, which may sometimes include your personal data such as phone number, email address, Facebook account, etc. However, we have implemented security measures to ensure such information will only be used for error log analysis and not for personal identification or other purposes. We clear such data on a regular basis, usually within 30 days after collection.
c. Location information —such as the GPS signal of the device or information about Wi-Fi access points.
We may also collect other information about your use of our services — such as the version of the application being used, the website visited, and how you interact with the content provided through our services.
Please note that we may cooperate with third-party service providers to implement or improve our service functions above. These third parties may not use this information for any other purpose.
(3) Obtaining Data from a Third Party
To the extent permitted by law, we may obtain data about you from public or commercial sources and may combine it with other information received or relevant to you.
2. How We Use Your Personal Data
(1) We may process your personal data on the following legal basis:
a. with your prior explicit consent which can be withdrawn at any time at your request;
b. so that we can perform or carry out a contract with you in relation to our products and/or services;
c. for compliance with a legal obligation to which we are a subject; or
d. when necessary for the purposes of the legitimate interests pursued by us or a third party to whom it may be necessary to disclose information. Where we process your information in reliance on such grounds, we will only do so where we have appropriately balanced such interests against your right to privacy.
Examples of related usages are as follows:
•Provide and Improve Services. The personal data we collect will be used to provide you with our products and services, process your orders or fulfil the contract between you and us to ensure the functionality and safety of our products and services, to verify your identity, to prevent and investigate fraud or other improper use.
•Customer Support. We use data to diagnose product issues, and provide other customer care and support services. We also use this information to improve our products and analyze the efficiency of our business operations. However, we will not use this information to track your location.
•Commercial Promotion Activities. If you participate in prize draws, contests or similar promotional activities held by us, we will use the personal data you provide to manage such activities.
Our retention period for personal data is the minimum time necessary to realize the purpose of collection unless a longer retention period is required by law. Beyond the above retention period, we will delete or anonymize your personal data.
1.At times we may make certain personal information available to affiliated companies and other third parties that work with us to provide products and services. Your information will not be shared with third parties for their own independent marketing or commercial purposes.
(2) Sharing with third parties: to realize the purposes stated in this Policy, some of our services will be provided by our authorized partners. We may share some personal data with our partners to provide better services and user experience. Third-party service providers are also used to provide you with customer service.
2．We will only share your personal data for lawful, legitimate, necessary, specific and clear purposes, and only personal data necessary for service provision will be shared. Our partners are not allowed to use the shared personal data for any other purposes.
We may also disclose your personal data if it is compulsorily required by laws, such as to comply with a subpoena or other legal proceedings, legal actions or government agencies, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.
1. We have taken reasonably practical and technical measures to protect the collected information related to the service. However, please note that although we have taken reasonable measures to protect your information, no websites, Internet transmissions, computer systems or wireless connections are absolutely secure.
2. We have taken safeguarding measures in accordance with industry standards to protect the personal data you provided and prevent data from unauthorized access, public disclosure, use, modification, damage or loss. We take all reasonably practical measures to protect your personal data. In particular:
(1) We de-identify your personal data to mitigate the risk that other organizations or individuals may identify you on the basis of that personal information. We use SSL to encrypt many services. We periodically review practices regarding information collection, storage and possessing (including physical security measures), to prevent various systems from unauthorized access.
(2) We only allow our employees and personnel of authorized service companies who need the personal data to process it to access such personal data, and they are subject to strict contractual confidentiality obligations. If they fail to perform these obligations, they may be held liable or their relationship with our may be terminated.
(3) The security of your information is extremely important for us. Therefore, we endeavor to ensure the security of your personal data and implement measures such as full security encryption during storage and transmission to prevent your information from unauthorized access, use, or disclosure. At the same time, no one can access the specific content of some encrypted data except the users themselves.
(4) When we transmit and store your special categories of personal data, we will use security measures such as encryption. When we store personal biometric information, we will treat it with technical measures before storage. For instance, storing only the digest of personal biometric information.
(5) We will prudently select business partners and service providers and implement the requirements for personal data protection to the business contracts or audits and assessments between both parties.
(6) We conduct security and privacy protection training, testing and other activities to enhance employees’ awareness and proficiency of personal data protection.
(7) We use international and industry-recognized standards to protect your personal data and actively pass relevant security and privacy protection certifications.
3. In case of personal data security incident, we will act, in accordance with the applicable law.
We will respect your legal rights to your personal data. Below are the rights that you have under law, and what we do to protect those rights. Please note that for the sake of security, we may ask you to verify your identity before processing your request.
2. The right to access: If you wish to access your personal data, you can login to your account and access the information you provided when registering the HeyTap Account through "Settings - Account". If you have any questions when exercising your right to access, please contact our Data Protection Officer: email@example.com.
3. The right to rectification: If you find that your personal data we process about you is inaccurate or incomplete, you are entitled to ask us to make rectifications. You can rectify your information via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: firstname.lastname@example.org.
4. The right to erasure: You can submit a request to us to delete personal data if we do not have a legal reason to continue to process and hold it. You can delete your information via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: email@example.com.
5. The right to restriction of processing: You have the right to ask us to restrict how we process your personal data. We will keep just enough or process those data necessary for us to make sure we respect your restriction request in the future. You can realize your right to restriction of processing via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: firstname.lastname@example.org.
6. The right to data portability: To the extent permitted by laws and regulations, you have the right to obtain a copy of your personal data in a structured, commonly used and machine-readable format. For example, if you decide to switch to a new provider, this enables you to move copy or transfer your personal data easily between our IT systems and theirs safely and securely, without affecting its usage. You can exercise your right to data portability via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: email@example.com.
7. The right to object: You have the right to object to us processing your data even if it is based on our legitimate interests, the exercise of official authority, direct marketing (including data aggregation), and processing for statistical purposes. You can object us processing your data via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: firstname.lastname@example.org.
8. The right to withdraw consent: If you have given us your consent to process your personal data but change your mind later, you have the right to withdraw your consent at any time, and we must stop processing your data. You can withdraw your consent via the https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: email@example.com.
9. The right to object automated individual decision-making: You have right not to be subject to a decision based solely on automated processing, including profiling. If these decisions significantly affect your lawful rights, you are entitled to ask for an explanation via https://id.heytap.com/static/userdata_index.html or contacting our Data Protection Officer: firstname.lastname@example.org, which we will respond to and take appropriate measures to resolve, as necessary.
10. The right to lodge a complaint: You have the right to lodge a complaint about the way we handle or process your personal data with your national data protection authority.
We will respond and reply to your above requests as soon as possible, and generally no later than one month upon receipt of your request. (If necessary and as permitted by law, we may extend it by an additional two months. We will inform you the reason for the extension within the aforementioned one month, for example, if the request is complex or involves a large volume of data). If you are not satisfied with the response you received, you can refer the complaint to the relevant regulatory authority in your jurisdiction.
1. Our products, applications and services are mainly adult-oriented. A child should not create his/her own user account. We treat anyone under 18 years old (or equivalent minimum age for full legal capacity in relevant jurisdiction) as a child.
2. When we find that a child’s personal data is collected, we will delete the relevant data as soon as possible.
1.Our websites, applications, and services may contain links to third-party websites, products, and services. You can choose whether to access websites, products and services provided by third parties or not.
1.In principle, the personal data collected and generated within the territory of European Union is stored within the territory of the European Union.
2.We provide products and services based on our resources and servers around the world and we have established data centers in China, France, Singapore, India, Indonesia, etc., which means to ensure the uniqueness of your account so that it can be used globally without duplication, after acquiring your authorization and consent, your personal data (i.e. IMEI, mobile number, email address, and user name information) might be transmitted to a jurisdiction or accessed from jurisdictions outside of the country/region where you use the products or services after de-identification.
3. In case your personal data is transferred by us to countries located outside of the European Economic Area (EEA), we will ensure that appropriate safeguards are taken, such as:
(1) the recipient of the personal data is located within a country that benefits from a full "adequacy" decision of the European Commission;
(2) the recipient may have adhered to binding corporate rules (only for intragroup transfers);
(3) the recipient has signed a contract based on "model contractual clauses" approved by the European Commission, obliging them to protect your personal data; or
(4) where the recipient is located in the US, it is a certified member of the EU-US Privacy Shield.
In the absence of the above appropriate safeguards, we will ask you for your explicit consent for cross-border transmission of your personal data. In the meantime, security measures such as encryption or de-identification will be adopted for the safety of your personal data.
For more information about the safeguards relating to personal data transfers outside of the EEA, please contact our Data Protection Officer: email@example.com.
NO.18 Haibin Road, Wusha, Chang'an, Dongguan, Guangdong, PRC China
Our EU representative:
OROPE Germany GmbH
Address: Graf-Adolf-Platz 15, 40213 Düsseldorf, Germany
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.