- Organizing it into sections,
- Providing a series of examples that help illustrate how the policies may be implemented by Perifit and
- Defining and capitalizing a few terms that are used more than once for simplicity and brevity.
When we refer to “Perifit”, we mean the Perifit entity that acts as the controller and processor of your information.
Any third party data processors are obliged to comply with this policy when processing personal data on our behalf. Any breach of this policy by that third party may result in disciplinary action being taken against them.
- Who we are
We are Perifit SAS (“we/our/us”). We are a company registered in France.
For the purpose of General Data Protection Regulation (GDPR Regulation (EU) 2016/679) (“the GDPR Regulation”) we are a data controller and data processor of personal data and sensitive personal data provided by you to us through our Platforms.
- Our Mission
At Perifit SAS we are as committed to protecting your personal data as we are to creating cutting edge, smart technology for women. It is a top priority for us to build a relationship of trust with you as a user of our product. These steps include:
- Being completely transparent about how, when and why your personal data is controlled and processed by us.
- Allowing you control over the personal data we collect from you and how we process that personal data
- If you do choose to allow us to process your personal data, we will make as clear as possible the specific reasons why and how that data may be collected, used and transferred.
- What is personal data?
Personal data is information relating to an “identified” person or an “identifiable natural person”. An “identifiable natural person” is one who can be identified, directly or indirectly, in particular reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
Sensitive personal data includes, but is not limited to, personal data which reveals racial or ethnic origin, and data concerning health or sex life and sexual orientation.
Further detail as to the specific types of personal data and sensitive personal data we may control and process is set out below.
- Personal data we may control and process
We may collect and process various types of personal data, sensitive personal data and other information from you when you use our Platforms, and when you correspond with us by phone, email or otherwise. The type of data collected, and the manner in which such data is collected, will vary depending on how you use our Platforms and whether or not you have consented for us to collect certain types of data from you. Further details of the type of data we collect and the manner in which such data may be collected is set out below in paragraph under the heading “How we collect personal data”.
By using our Platforms, and/or using our product in conjunction with our Platforms, you are agreeing for us to collect and process the personal data provided as part of that process, for the purposes made clear to you at that time.
The personal data we collect from you may be held on paper or on a computer or other media, and is subject to certain legal safeguards specified in the GDPR Regulation and under certain applicable United States federal and state laws and regulations (collectively the "Legislation").
- How we collect personal data
Perifit may collect and receive personal data and other information in a variety of ways:
This is data we must collect in order to fulfil any order for Perifit product you place through the Platforms.
Necessary Data includes, but is not limited to, your name, email address, billing details such as credit card information, banking information and/or a billing address and delivery address.
Necessary data will be collected by us when you fill in and submit the relevant form through the Platforms which contains that data.
This data is passively collected by us in the course of you using our product, the Perifit device, in conjunction with the Perifit application (“User Data”).
User Data includes:
- User account data: your email address and password relating to the user account information in the Perifit application to enable you to access and use your account across multiple devices.
- Perifit device usage data:
- Data relating to your performance and workouts with the Perifit device.
- Log data: As with most technology services delivered over the Internet, our servers automatically collect information when you access or use our product and record it in log files.
- Device information: Perifit collects information about devices using Perifit product, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and crash data.
- Location information: Perifit collect location information from devices in accordance with the consent process provided by your device only to allow the connection of Perifit product with your Bluetooth device.
All User Data is anonymized, encrypted and stored in secured servers. We are unable to identify you as a user from viewing User Data. We do, however, have the ability to re-identify User Data where permitted by applicable law, and may do so in exceptional circumstances, for example, if there is a need for us to identify you for the purpose of product recall and to solve product / application issues.
This data is passively collected by us in the course of you using and browsing the Platforms (“Platform Data”).
Platform Data includes, but is not limited to, your device’s Internet Protocol (IP) address, web cookies, browser type and version, the pages of our Platforms you visit, the amount of time spent on each page of our Platforms, time zone settings, the time and date of your visit and the operating system or platform you use, information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our Platforms (including date and time), any products you have viewed or searched for, page response times, download errors, length of visits to certain pages within the Platforms, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page. Platform Data is collected by us when it is transmitted to us during or after your use of the Platforms. Such data may or may not be anonymised and will be used as further described below.
We receive Other Information when submitted to our website or if you participate in a focus group, contest, activity or event, apply for a job, request support, interact with our social media accounts or otherwise communicate with Perifit.
- How we use your personal data
Perifit uses personal data in furtherance of our legitimate interests in operating our product, website and business.
Perifit uses Necessary data:
- To fulfill an order or contract placed through our Platforms.
Perifit uses User data:
- To create your personal user account in order for you to monitor your workouts and performances and to be able to keep your data after changing phone or tablet.
- To use functionally the Perifit product in combination with the Perifit application.
- To communicate with you by responding to your requests, comments and questions. If you contact us, we may use your User data to respond.
- To investigate and help prevent security issues and abuse.
- To send emails and other communications. We may send you service, technical and other administrative emails, messages, surveys and other types of communications. We may also contact you to inform you about changes in our Perifit device or application.
All User Data will be anonymised when viewed by us and any other third parties. No individual user data is shared with third parties. The only exception will require you to provide us with explicit permission to access and assess your User Data in order to resolve a problem you are having with the product. We will not be able to do this without your permission.
Perifit uses Platform Data:
To understand how our customers’ behave in order for us to develop or optimise:
- How the Platform works for you;
- The information and services provided to you through our Platforms; and
- The effectiveness of our online advertising and branding.
Perifit uses Other Information:
- To send emails and other communications. We may send you emails about new product features, promotional communications or other news about Perifit product. These are marketing messages so you can unsubscribe anytime.
All personal data we collect and process is stored on our secure servers in accordance with reasonable security practices as required by applicable law, legal process or regulation.
Where you have chosen (or where we have given you) a password which enables you to access to your account in Perifit application, you are responsible for keeping this password confidential. We ask you not to share this password with anyone and to change it if you suspect someone has gained access to it.
- Your rights and our obligations
We may also process your personal data with your consent for some technical issues purposes, or for the purpose of ensuring electronic information security.
If we are controlling and processing your personal data on the sole basis of having your consent to do so, we must gain separate consents from you in respect of each distinct type of processing operation.
Where we are processing your personal data on the basis of you having given us your consent to do so, you do have the right to withdraw that consent at any time, but this will not affect the lawfulness of processing prior to the withdrawal of such consent. You can exercise your right to withdraw consent to processing at any time by contacting us via firstname.lastname@example.org
Data Retention, Erasure and Rectification
The personal data we collect from you will be stored and retained by us for the length of time that you maintain a user account with us in respect of the Platforms. We may also retain such data for a time of 1 year following deactivation of your user account for the purpose of enabling you to reactive your user account more easily.
You also benefit from the right to erasure (also known as the ‘right to be forgotten’). This means that you have the right to request us to erase personal data we hold about you.
You also benefit from the right to rectify inaccurate personal data we hold which relates to you (also known as the “right to rectification”). This means that, taking into account the subject of the processing, you shall have the right to have incomplete personal data completed.
You can exercise your right to erasure and rectification by contacting us via email@example.com.
You also have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format. You have the right to transmit such data to other data controllers without hindrance from us where we are processing that data on the basis of having your consent to do so, or where it is necessary for the performance of a contract, and the processing is carried out by automated means.
Subject Access Requests
You as a data subject are entitled to make a formal request for information we hold about you. We must provide you with a copy of this information, the reasons it is being processed and whether it will be given to any other organisations or people provided that you make this request in writing.
- Children’s privacy
The product provided through our Platforms is not marketed to, and should not be used by, anybody under the age of 16.
We do not knowingly collect personal data from children under the age of 16. In the event that we discover that a child under the age of 16 has provided us with personal data, we will delete such data from our servers unless consent is given or authorised by the holder of parental responsibility over the child.
- Sharing and transferring personal data
We use industry standard encryption for transmission of data to our systems. Although we cannot guarantee the absolute safety of transmission of data via the internet, we adhere to industry standards to give your data the most appropriate protection possible.
Sharing of Personal Data:
We may share personal data we hold to third parties, with your consent, or on the basis of us an otherwise lawful reason for doing so under the Legislation. For example:
- in order to facilitate, provide and improve the product we provide to you through our Platforms;
- in order to analyse the manner in which our services are used by product users;
- if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with the data subject or other agreements; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Use of Third Party Platforms:
Our Platforms use Google Analytics, a web analytics service offered by Google Inc. Google Analytics will make use of small pieces of data, known as cookies, which can be used to track and analyze the manner in which you use and operate our Platforms. Such data will be transferred to, and stored on, a server in the USA operated by Google, Inc. Google, Inc. may i) transfer this data to third parties where required by law, or other third party processors used by Google, Inc. You may prevent cookies from being stored in relation to your visit to, and use of, our Platforms but do please be aware that this may negatively impact upon the way in which the Platforms work.
We may also use Facebook’s advertising service known as “Facebook lookalike audiences” if you have informed Facebook of the fact that you use our Platforms. Facebook lookalike will allow us to identify new potential consumers and users of our Platforms and products on the basis that those new potential users share similar characteristics with you on Facebook – for example, on the basis that both users have “liked” the same Facebook pages. We may, therefore, share your email address and name with Facebook if you have logged into the Platforms via your Facebook account, or have downloaded our Platforms onto your device through a Facebook advertisement. More information about Facebook lookalike audiences is here.
Transfers outside the EEA:
We may also transfer any personal data we hold to a country outside the European Economic Area (EEA), provided that one of the following conditions applies:
- the country to which the personal data is transferred ensures an adequate level of protection for the data subjects' rights and freedoms;
- you have given your consent;
- the transfer is necessary for one of the reasons set out in the GDPR Regulation, including the protection of your vital interests;
- the transfer is legally required on important public interest grounds or for the establishment, exercise or defence of legal claims; or
- the transfer is authorised by the relevant data protection authority where we have adduced adequate safeguards with respect to the protection of the data subjects' privacy, their fundamental rights and freedoms, and the exercise of their rights.
- California Consumer Rights
Under California Civil Code Section 1798.83, California residents have the right to obtain: (a) a list of all third parties that we may have disclosed your personal information to within the past year for direct marketing purposes; and (b) a description of the categories of personal information disclosed. To obtain such information, please email your request to firstname.lastname@example.org.
- Changes to this policy
We reserve the right to change this policy at any time. Where appropriate, we will notify you, as a data subject, of those changes by email.
- Concerns or complaints
If you have any concerns or complaints relating to this policy, its subject matter, or the manner in which we collect, control and/or process your personal data, please do let us know by sending an email to email@example.com.