Frameit Privacy Policy
Last Modified: 6 Jun 2023
Your privacy is important to us.
Jiahua Information Technology Ltd. (“we”, “us” or “our”) is dedicated to protecting the privacy of our users (“users” or “you”). This Privacy Policy (this “Policy”) is meant to explain our practices regarding how we collect, store, use, manage and protect your user information (including your personal information) as a controller and/or business under applicable data protection laws during your use of Frameit application including all its features (our “Services”).
This page is used to inform visitors regarding our policies regarding the collection, use, and disclosure of Personal Information if anyone decides to use our Service.
If you choose to use our Service, then you agree to the collection and use of information in relation to this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.
The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which are accessible at Frameit unless otherwise defined in this Privacy Policy. So, please make sure that you have read and understand our Terms of Service.
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at team@frameit.site.
INFORMATION COLLECTION AND USE
In order to provide and improve our Services, we will collect and process your personal information and user information in accordance with this Policy. If you do not provide this information, we may be unable to provide you with our products or Services. You should ensure that all personal information and user information submitted to us is complete, accurate, true and correct. Failure on your part to do so may result in our inability to provide you with all or some of our Services.
The app does use third-party Services that may collect information used to identify you.
Link to the privacy policy of third-party Service providers used by the app
Mobile Device Information
When you use our Services on your mobile device, we will collect information about your device, including its International Mobile Equipment Identity (“IMEI”), Unique Device Identifier (“UDID”) or Android ID, Universally Unique Identifier (“GUUID”), User ID (“UID”), Identifier for Advertising (“IDFA”) and Identifier for Vendor (“IDFV”), Open Anonymous Device Identifier (“OAID”), Integrated Circuit Card Identifier (“ICCID”), Media Access Control (“MAC”) address, the type of device you use, operating system version, a list of mobile applications installed on your device and resolution, which will be used by us for statistical and/or analytical reasons, including without limitation to improve our technical functionality, server load-balancing, analysis of technical data relating to your mobile device so as to optimize our Services and graphics adaptation.
As stated below in the “Location Information” section, we may collect your location-based information from your mobile device if you choose to share it with us. If you subsequently wish to stop sharing Location Information, you may do so at any time by editing the relevant setting on your mobile device.
Mobile Analytics
We use mobile analytics software to allow us to better understand and improve the functionality of our Services. Such software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from.
Network Information
When you use our Services, we will collect information about the network you use, including the name of the operator and the type of network, so as to understand the distribution of operators and networks used by our users. In addition, we will collect information such as the name of the WiFi network to which you connect, the location of the WiFi network, and the duration of your WiFi connection to understand the environment under which you prefer to use our Services.
Log Data
We want to inform you that whenever you use our Service, in a case of an error in the app we collect data and information (through third-party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.
Cookies
We use “cookies” that store and retrieve information of user’s usage from time to time to provide customized Services for each user. Cookies are small amounts of information that the server uses to operate the app/website, sends to the user’s device and are also stored on the hard disk in the user’s device. You may refuse the installation of cookies. Information collected may include information about your Internet Protocol (IP) address, browser type, Internet Service Provider (ISP), referring and exit pages, your operating system, dates and timestamps, and clickstream data.
Purpose of use of cookies: Cookies are used to provide information optimized for each user by identifying the visit and use type of each Service and website that the user has visited, popular search terms, secure access status, etc.
Installation, operation and refusal of cookies: A user may refuse the installation of cookies by sending an email to team@frameit.site
If a user refuses to store cookies, he or she may experience difficulties in using customized Services.
Advertising-Related Information
We and our third-party Service providers may include advertisements within our Services, and with your consent, we may collect and use information about you such as your Advertising ID, geographic location and IP address for the purpose of delivering and tracking these advertisements. If your device does not have Advertising ID, we may use other persistent identifiers. We may also access your App list and collect the application package names of the applications installed on your device. We use the above information to help us better count, track and provide advertisements based on suitability, language, geographic location and other details. If you wish to opt out of interest-based advertising, you may opt out by sending email to [team@frameit.site]. Please note you will continue to receive generic ads after you opt out of interest-based advertising.
Location Information
We may collect your location-based information from your mobile device if you choose to share it with us.
This information will help us understand user distribution and usage scenarios and allow us to provide users with the correct version of our apps, the reappearance of the geo-location or the publishing of the real-time geo-location where you take any photos or shoot any videos, and improve our Services. Unless we obtain your consent, location data WILL NOT BE ACQUIRED or USED to identify you individually. Except as otherwise provided in this Policy, we will not share this Location Information with any third parties. If you no longer wish to allow us to collect or use such information, you may turn off your Internet access or GPS, or disable our access to information about your network, GPS and device. Please note that we may still continue to receive some Location Information, such as your Network Information, IP address and system time zone, as a result of you using our Services.
Image Information
By choosing to use the cloud editing feature of our Services, you understand and agree that we must upload your photos to our server for processing before returning processed photos to you for the purposes of providing such Service to you and continuous optimization and that we will also receive the EXIF data about your photos (EXIF data may contain GPS coordinates where photos were taken and processed, equipment type, ISO and information about the front and rear cameras and creation time, depending on the equipment manufacturer) for the purpose of further optimizing our Services, such as providing a better match of photo effects to your equipment.
Information Collected by Third Party Services
Our Services provided to you may contain our Service provider’s Application Programming Interfaces (APIs) or Software Development Kits (SDKs), which may have tracking tools of such Service providers. These third parties may use cookies, APIs and SDKs on our Services and collect and analyze user information. In addition, some third-party SDKs may allow advertisers to collect information in order to provide content that is more relevant to you. Third parties may access your information such as your device identifiers, region (defined as the location where a given language is used), location information and IP address under their respective privacy policies. If you want to know more about such third parties, you may send an email to team@frameit.site
Other Information
We may also collect other information which is not related to your identity. For example, we may collect information on the type and version number of your operating system to better understand system upgrades, we may collect information on your system language for the purpose of language adaptation, and we may collect your App list to understand user preferences. If we choose to collect such information, we will do so for the purpose of improving our Services provided to you.
HOW WE USE INFORMATION
In addition to the uses listed above, we collect and use your user information and personal information for the following purposes:
(i) Services. To provide, process, maintain, improve and develop our Services provided to you, including customer support, and other Services provided through our products.
(ii) Statistical analysis. To develop and analyze statistics on the use of our products and Services for the purpose of improving our products and our Services.
(iii) To create an account. The personal information that we collect when you use our Services to create an account will be used by us to create your account and profile.
(iv) To provide location-based Services. When you use our Services, we or third-party Service providers may take advantage of your location information to provide you with advertising, the correct version of our Services and help you gain good user experience.
(v) To improve user experience. Certain optional features such as user experience programs allow us to analyze data regarding the use of our products and our Services and improve user experience.
(vi) To provide push Services. Device information may be used by us to provide push Services to assess the performance of adverts and the success of software updates, or provide notifications on new product releases.
(vii) To verify your identity. Verifying your identity using a text message when you log in to your account helps prevent unauthorized logins to your account.
(viii) To collect feedback from you. Your feedback is of great value in helping us to improve our Services. To keep track of your feedback, we may use the personal information provided by you to contact you and retain the records.
(ix) Other purposes. We will collect, store, maintain and use information about you for purposes under the “The Information We Collect”, and for purposes of running our operations, pursuing our legitimate interests (e.g., research (including marketing research), network and information security, and fraud prevention), and satisfying our legal obligations.
SERVICE PROVIDERS
We may employ third-party companies and individuals for the following reasons:
(i) Providing you with advertising;
(ii) Payment processing;
(iii) Providing customer Services;
(iv) Fulfilling subscription Services;
(v) Conducting research and analysis;
We will not share with or disclose to third parties (other than our Service providers) your personal information in whole or in part except for the purposes of:
(i) protecting the security of others or their property;
(ii) preventing or dealing with fraud;
(iii) safeguarding our legitimate rights and interests;
(iv) taking action in line with our purposes as described in the “The Information We Collect” or the “How We Use Information” sections;
(v) complying with laws, rules and regulations or requests by government departments, judicial authorities, law enforcement, or private parties, which are typically designed to uphold Internet security and the rights, property and safety of us, our users and third parties;
We want to inform users of this Service that these third parties have access to their Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.
BASES FOR USING YOUR INFORMATION
We will only collect and process personal information where we have lawful bases and we typically rely on one of the following four legal bases: -
(i) consent (where you have given consent);
(ii) contract (where processing is necessary for the performance of a contract with you, for example, to operate the site or deliver any Services you have requested);
(iii) legitimate interests (for example, we need to use your information to provide and improve our Services, including protecting your account, providing customer support). We rely on our legitimate interests as our lawful basis only where those interests are not overridden by the impact on you (unless we have your consent or our processing is otherwise required or permitted by law); and
(iv) legal obligations (to comply with the laws, rules and regulations or requests by government departments, judicial authorities or law enforcement).
If you have questions about the lawful base on how we process your personal information, please contact us at team@frameit.site
SECURITY
We value your trust in providing us with your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we can not guarantee its absolute security.
DATA RETENTION
Subject to applicable laws, rules and regulations and the fulfillment of our business or legal purposes, we will delete your information (including your personal information) promptly upon your termination of your account with us.If you have questions about it, please contact us at team@frameit.site
THIRD PARTY WEBSITES AND ServiceS
Our Services may contain links to other websites and Services. In addition, other websites and Services may reference or link to our Services. These other domains and websites are not controlled by us, and we do not endorse or make any representations about third party websites or Services. We encourage our users to read the privacy policies of each and every website and Service with which they interact. Visiting these other websites or Services is at your own risk.
INFORMATION SECURITY
We will take reasonable measures to prevent the loss, improper use of, unauthorized access to or disclosure of information. For example, some of our Services will use encryption techniques (such as SSL) to protect your personal information. However, you understand and accept that (in the Internet industry) even though we take reasonable security measures, we cannot always guarantee that your information is 100% secure. You understand and accept that we cannot ensure or warrant the security of any information you provide to us. We do not accept liability for unintentional disclosure. Further, you understand and accept that the system and communication network used by you to access our Services may fail due to factors beyond our control.
INFORMATION ACCESS AND CONTROL
We will take all reasonable and appropriate technical measures to ensure that you can access, update and correct your personal information or other personal information provided to us by you when using our Services. Before you access, update, correct or remove such personal information, we may verify your identity in order to protect the security of your account.
PRIVACY RIGHTS
In accordance with applicable law, you may have the right to: (i) request confirmation of whether we are processing your personal information; (ii) obtain access to or a copy of your personal information; (iii) receive an electronic copy of personal information that you have provided to us, or ask us to send that information to another company (right to data portability); (iv) object to or restrict our uses of your personal information; (v) seek correction or amendment of inaccurate, untrue, incomplete, or improperly processed personal information; (vi) withdraw your consent; and (vii) request erasure of personal information held about you by us, subject to certain exceptions prescribed by law.
If you wish to exercise your rights, you may send an email to team@frameit.site. We will process your request in line with applicable laws within a reasonable period of time after receiving your email or mail, and will cease collecting, using and disclosing your personal information thereafter, subject to certain exceptions prescribed by law. To protect your privacy, we will take steps to verify your identity before fulfilling your request. Please note that if you withdraw your consent or delete your personal information, your use of some of our Services may be affected.
INFORMATION ABOUT CHILDREN
We will not knowingly collect or request personal information from children under 16 (or any other age stipulated by law applicable to your region). If you are under 16, please do not send your personal information to us, including but not limited to your name, address, phone number or email address. If you believe we may have any information about children under 16, you may send an email to team@frameit.site. If we learn that we have collected personal information from children under 16 (or any other age stipulated by law applicable to your region), we will promptly take steps to delete such information and terminate the associated account.
CROSS-BORDER DATA TRANSFERS
You understand and agree that all information collected via or by us may be transferred, processed, and stored anywhere in the world, including but not limited to, Singapore, China, the United States, the European Union, in the cloud, on our servers, on the servers of our affiliates, or the servers of our Service providers in order to provide our Services.
FOR USERS IN JAPAN
Right to data disclosure, correction, erasure or suspension of use
If you are in Japan, as a data subject, you have the right to request the disclosure, correction, erasure or suspension of use of your personal information, and we are obliged to meet your request without undue delay. You may send your request by email to team@frameit.site.
FOR USERS IN SOUTH KOREA
International Data Transfers
We process the personal information of users only within the scope specified under HOW WE USE INFORMATION, and in principle, will not provide personal information of users to a third party. However, with your consent, for purposes of providing our Services described under INFORMATION SHARING AND DISCLOSURE to you, we may collect your personal information from, transfer it to, and store and process it elsewhere.
Also, we may transfer your personal information to the following third parties located outside of South Korea:
Name of the person providing personal information |
Purpose of the use of personal information |
Particulars of personal information to be collected
|
Period for retaining and using personal information |
Apple Inc. https://www.apple.com/legal/privacy/en-ww/ |
Subscription payment Services
|
IDFA, IP User’s UID, location
|
For such period as stated in the privacy policy of the relevant third party platform |
Google LLC https://policies.google.com/privacy?hl=en-US |
IDFA, GAID, Android ID, IP User’s UID, location |
||
Meta Platforms, Inc. https://www.facebook.com/policy.php/ |
IDFA, GAID, Android ID, IP User’s UID, location |
Whenever we share information outside of where you live, we ensure that the transfer complies with your local law so that your personal information is adequately protected.
If you do not wish to have your personal information transferred outside of South Korea, we will be unable to provide you with our products or Services.
Also, we may receive your personal information from the following third parties:
Name of the person providing personal information |
Purpose of the use of personal information |
Particulars of personal information to be collected |
Period for retaining and using personal information |
Apple Inc. https://www.apple.com/legal/privacy/en-ww/ |
Subscription payment Services |
IDFA, IP User’s UID, location |
For such period as stated in the privacy policy of the relevant third party platform |
Google LLC https://policies.google.com/privacy?hl=en-US |
IDFA, GAID, Android ID, IP User’s UID, location |
||
Meta Platforms, Inc. https://www.facebook.com/policy.php/ |
IDFA, GAID, Android ID, IP User’s UID, location |
Data Retention
Subject to applicable laws, rules and regulations and the fulfillment of our business or legal purposes, we will delete your information (including your personal information) promptly upon your termination of your account with us. We will destroy your personal information according to the following procedures and methods.
1.Procedures for Destruction: We select personal information subject to destruction and destroy them with approval of our data protection officer.
2.Method of Destruction: We will destroy personal information stored and filed electronically in a way that can be deleted by using a means that renders the record irrecoverable as far as possible.
Contact Us
Email: team@frameit.site
FOR USERS IN THE UNITED STATES OF AMERICA
In accordance with applicable law, you may have the right to:
If you would like to exercise any of your rights under the applicable privacy laws, please contact our Data Protection Officer via email at team@frameit.site . We will process such requests in accordance with applicable laws.
If you are a Virginia resident and would like to appeal our decision with respect to your request, you may do so by informing us of this and providing us with information supporting your appeal.
The following paragraphs only apply to our processing of your personal information that is subject to the California Consumer Privacy Act (as amended from time to time) (“CCPA”).
The CCPA provides California residents with the right to know what categories of personal information we have collected about them, and whether we disclosed that personal information for a business purpose (e.g., to a service provider) in the preceding twelve months. California residents can find this information below:
Category of Personal Information Collected |
Category of Third Parties to Whom Personal Information is Disclosed to for a Business Purpose |
Identifiers |
· Service providers |
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) |
· Service providers |
Protected classification characteristics under California or federal law |
· Service providers |
Commercial information |
· Service providers
|
Biometric information |
N/A
|
Internet or other electronic network activity |
· Service providers
|
Geolocation data |
· Service providers
|
Sensory data |
N/A
|
Professional or employment-related information |
N/A |
Non-public education information (per the Family Education Rights and Privacy Act (20 U.S.C. Sec. 1232g, 34 C.F.R. Part 99)) |
N/A |
Inferences drawn from other personal information to create a profile about a consumer |
· Service providers
|
Personal information that reveals a consumer’s social security, driver’s license, state identification card, or passport number |
N/A |
Personal information that reveals a consumer’s account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account |
· Service providers
|
Personal information that reveals a consumer’s precise geolocation |
· Service providers
|
Personal information that reveals a consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership |
N/A
|
Personal information that reveals the contents of a consumer’s mail, email, and text messages unless Figma is the intended recipient of the communication |
N/A
|
Personal information that reveals consumer’s genetic data |
N/A |
Biometric information that is processed for the purpose of uniquely identifying a consumer |
N/A |
Personal information collected and analyzed concerning a consumer’s health |
N/A |
Personal information collected and analyzed concerning a consumer’s sex life or sexual orientation |
N/A |
The categories of sources from which we collect Personal Information and our business and commercial purposes for using and disclosing Personal Information are set forth in “The Information We Collect”, “How We Use Information”, and “Information Sharing and Disclosure” above, respectively. We will retain personal information in accordance with the time periods set forth in “Data Retention” above.
In the preceding twelve months, we have not “sold” any personal information (as defined by the CCPA), nor do we have actual knowledge of any “sale” of personal information of minors under 16 years of age.
In the preceding twelve months, we have not “shared” any personal information for “cross-context behavioral advertising” (as such terms are defined in the CCPA), nor do we have actual knowledge of any “sharing” of personal information of minors under 16 years of age for “cross-context behavioral advertising”
We only use and disclose sensitive personal information for the following purposes:
California residents have the right not to receive discriminatory treatment by us for the exercise of their rights conferred by the CCPA.
To protect your privacy, we will take steps to reasonably verify your identity before fulfilling requests submitted under the CCPA. These steps may involve asking you to provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative. Examples of our verification process may include asking you to provide the email address or phone number we have associated with you and providing a verification code that is sent to your email address or phone number.
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. To authorize an agent, provide written authorization signed by you and your designated agent and contact us using the information in “Privacy Rights” above for additional instructions.
We do not “sell” personal information or “share” personal information for “cross-context behavioral advertising” so we do not respond to opt-out preference signals.
If you are a Nevada resident, we do not “sell” your personal information.
GDPR NOTICE
Categories of personal data processed |
Personal data included in the categories |
Sources of the data |
Obligation of the data subject to provide the data |
Storage duration |
Protocol Data |
Protocol data which accrue when using the Services to provide content from the server of our applications. The data accruing during use is defined by the network protocol for transferring information between your terminal device and the applications’ server. This includes IP address, type and version of the mobile operating system used, the content accessed, the content previously accessed, date and time of access. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. If the data is not provided, we cannot provide the content of our applications requested by you. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Subscription Data
|
Information on current and/or past subscriptions.
|
User of the Services |
The provision of the information marked as mandatory during the registration process is a requirement necessary to enter into a subscription contract. The provision of other data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. If the mandatory information is not provided, you cannot make full use of the Services. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Mobile Device Data |
Information about your mobile device, including its International Mobile Equipment Identity (IMEI), Unique Device Identifier (UDID) or Android ID, Universally Unique Identifier (GUUID), User ID (UID), Identifier for Advertising (IDFA) and Identifier for Vendor (IDFV), Open Anonymous Device Identifier (OAID), Integrated Circuit Card Identifier (ICCID), Media Access Control (MAC) address, Google Advertising ID (GAID), the type of device you use, operating system version, a list of mobile applications installed on your device and resolution. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. If the data is not provided, we cannot provide the content of our applications requested by you. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Mobile Analytics Data |
Information to better understand and improve the functionality of our Services. These include information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Network Data |
Name of the operator and the type of network, name of the WiFi network to which you connect, the location of the WiFi network, and the duration of your WiFi connection. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Location Data |
Country code, latitude and longitude, network location, IP address and the system country and system time zone recorded on your device. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Log Data |
Log Information may include (i) details on when and how often you use our Services, (ii) device statistics, including critical operation paths, errors, crashes, language and time zone. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Image Data |
Photo/video of the data subject; EXIF data stored in the image file (EXIF data may contain GPS coordinates where photos were taken and processed, equipment type, ISO and information about the front and rear cameras and creation time, depending on the equipment manufacturer). |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. If the data is not provided, you cannot make full use of the Services. |
The data are stored in server log files for a maximum period of 21 days. |
Advertisement Data |
Advertising ID (including IMEI, Android ID, OAID, IMSI, ICCID, GAID, MEID, mac addr, IDFV, IDFA), geographic location and IP address. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data. If you do not provide this data we are not able to provide you with interest-based advertising. |
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Third Party Tracking Data
|
Device identifiers, region (defined as the location where a given language is used), location information, IP address. To the extent such personal data is stored in cookies, you can find more detailed information in Section III below. |
User of the Services |
The provision of the data is not a statutory or contractual requirement, or a requirement necessary to enter into a contract. There is no obligation of the data subject to provide the data.
|
The data you provide will remain stored in your account for as long as your account exists until you delete it yourself. You can delete your account at any time. |
Purpose of processing the personal data |
Categories of personal data processed |
Automated decision-making |
Legal basis and, where applicable, legitimate interests |
Recipient |
Provision of the Services |
Protocol Data Registration Data Subscription Data Network Data Location Data Image Data |
No automated decision-making takes place. |
For processing activities relating to the app user: Art. 6 (1) (b) GDPR (performance of a contract to which the data subject is party or taking steps at the request of the data subject prior to entering into a contract) For processing of Location Data: Art. 6 (1) (a) GDPR (consent) For processing activities relating to data subjects different from the device owner: Art. 6 (1) (f) GDPR (pursuing legitimate interests under balancing of interests): Our legitimate interest is the provision of our services |
Apple Inc. Google LLC Meta Platform, Inc.
|
Statistical analysis (develop and analyse statistics on the use of our products and Services for the purpose of improving our products and Services)
|
Protocol Data Mobile Device Data Mobile Analytics Data Network Data Location Data Log Data Cookie Data
|
No automated decision-making takes place. |
Art. 6 (1) (a) GDPR (consent) |
Apple Inc. Google LLC Meta Platform, Inc.
|
Providing location-based services (for providing user with advertising, the correct version of our Services and help user gaining good user experience) |
Protocol Data Location Data |
No automated decision-making takes place. |
Art. 6 (1) (a) GDPR (consent) |
Apple Inc. Google LLC
|
Improving user experience (optional features such as user experience programs allow us to analyse data regarding the use of our products and our Services and improve user experience) |
Protocol Data Mobile Device Data Mobile Analytics Data Network Data Location Data Log Data Image Data Cookie Data Third Party Tracking Data |
No automated decision-making takes place. |
Art. 6 (1) (a) GDPR (consent)
|
Apple Inc. Google LLC Meta Platform, Inc,
|
Verifying user’s identity |
Protocol Data
|
No automated decision-making takes place. |
Art. 6 (1) (f) GDPR (pursuing legitimate interests under balancing of interests): In this case, our legitimate interest is verifying your identity to be able to provide the Services to you. |
Apple Inc. Google LLC Meta Platform, Inc. |
Collecting feedback from user (to help us improve our Services)
|
Protocol Data |
No automated decision-making takes place. |
Art. 6 (1) (a) GDPR (consent) |
Apple Inc. Google LLC Meta Platform, Inc.
|
Complying with any applicable rules, laws and regulations, codes of practice or guidelines or to assist in law enforcement and investigations by relevant authorities |
Protocol Data Subscription Data
|
No automated decision-making takes place. |
Art. 6 (1) (c) GDPR (necessary for compliance with a legal obligation to which the controller is subject) |
Public authorities
|
Processing of requests (customer service) |
Protocol Data Subscription Data |
No automated decision-making takes place. |
If your request concerns a contract to which you are party or the performance of pre-contractual measures: Art. 6 (1) (b) GDPR (performance of a contract to which the data subject is party or taking steps at the request of the data subject prior to entering into a contract). Otherwise: Art. 6 (1) (f) GDPR (pursuing legitimate interests under balancing of interests): In this case, our legitimate interest is the processing of your request. |
|
Recipient |
Recipient’s role |
Transfers to third countries and/or international organisations |
Adequacy decision or appropriate or suitable safeguards for transfers to third countries and/or international organisations |
|
Apple Inc. |
Processor |
United States
|
There is no adequacy decision of the EU Commission for the USA. We have secured your data by concluding so-called standard data protection clauses pursuant to Art. 46(2)(c) GDPR with the recipient. You can obtain a copy of this agreement from our contact address stated above. |
|
Google LLC |
Processor |
United States
|
There is no adequacy decision of the EU Commission for the USA. We have secured your data by concluding so-called standard data protection clauses pursuant to Art. 46(2)(c) GDPR with the recipient. You can obtain a copy of this agreement from our contact address stated above. |
|
Meta Platform, Inc. |
Processor |
United States
|
There is no adequacy decision of the EU Commission for the USA. We have secured your data by concluding so-called standard data protection clauses pursuant to Art. 46(2)(c) GDPR with the recipient. You can obtain a copy of this agreement from our contact address stated above. |
|
As a data subject, you have the following rights with regard to the processing of your personal data:
You may contact us for the purpose of exercising these rights using the contact information in Section I.
Where applicable, you find information on any specific modalities and mechanisms which facilitate the exercise of your rights, in particular the exercise of your rights to data portability and to object, in the information on the processing of personal data in Section II of this GDPR Notice.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
Below you find more detailed information on your rights with regard to the processing of your personal data:
As a data subject, you have a right to obtain access and information under the conditions provided in Art. 15 GDPR.
This means in particular that you have the right to obtain confirmation from us as to whether we are processing your personal data. If so, you also have the right to obtain access to the personal data and the information listed in Art. 15 (1) GDPR. This includes information regarding the purposes of the processing, the categories of personal data that are being processed and the recipients or categories of recipients to whom the personal data have been or will be disclosed (Art. 15 (1) (a), (b) and (c) GDPR).
You can find the full extent of your right to access and information in Art. 15 GDPR.
As a data subject, you have the right to rectification under the conditions provided in Art. 16 GDPR.
This means in particular that you have the right to receive from us without undue delay the rectification of inaccuracies in your personal data and completion of incomplete personal data.
You can find the full extent of your right to rectification in Art. 16 GDPR.
As a data subject, you have a right to erasure (“right to be forgotten”) under the conditions provided in Art. 17 GDPR.
This means that you have the right to obtain from us the erasure of your personal data and we are obliged to erase your personal data without undue delay when one of the reasons listed in Art. 17 (1) GDPR applies. This can be the case, for example, if personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed (Art. 17 (1) (a) GDPR).
If we have made the personal data public and are obliged to erase it, we are also obliged, taking account of available technology and the cost of implementation, to take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of those personal data (Art. 17 (2) GDPR).
The right to erasure (“right to be forgotten”) does not apply if the processing is necessary for one of the reasons listed in Art. 17 (3) GDPR. This can be the case, for example, if the processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims (Art. 17 (3) (b) and (e) GDPR).
You can find the full extent of your right to erasure (“right to be forgotten”) in Art. 17 GDPR.
As a data subject, you have a right to restriction of processing under the conditions provided in Art. 18 GDPR.
This means that you have the right to obtain from us the restriction of processing if one of the conditions provided in Art. 18 (1) GDPR applies. This can be the case, for example, if you contest the accuracy of the personal data. In such a case, the restriction of processing lasts for a period that enables us to verify the accuracy of the personal data (Art. 18 (1) (a) GDPR).
Restriction means that stored personal data are marked with the goal of restricting their future processing (Art. 4 (3) GDPR).
You can find the full extent of your right to restriction of processing in Art. 18 GDPR.
As a data subject, you have a right to data portability under the conditions provided in Art. 20 GDPR.
This means that you generally have the right to receive your personal data with which you have provided us in a structured, commonly used and machine-readable format and to transmit those data to another controller without hindrance from us if the processing is based on consent pursuant to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the processing is carried out by automated means (Art. 20 (1) GDPR).
You can find information as to whether an instance of processing is based on consent pursuant to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR in the information regarding the legal basis of processing in Section II of this GDPR Notice.
In exercising your right to data portability, you also generally have the right to have your personal data transmitted directly from us to another controller if technically feasible (Art. 20 (2) GDPR).
You can find the full extent of your right to data portability in Art. 20 GDPR.
As a data subject, you have a right to object under the conditions provided in Art. 21 GDPR.
At the latest in our first communication with you, we expressly inform you of your right, as a data subject, to object.
More detailed information on this is given below:
Right to object on grounds relating to the particular situation of the data subject
As a data subject, you have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on Art. 6 (1) (e) or (f), including profiling based on those provisions.
You can find information as to whether an instance of processing is based on Art. 6 (1) (e) or (f) GDPR in the information regarding the legal basis of processing in Section II of this GDPR Notice.
In the event of an objection relating to your particular situation, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
You can find the full extent of your right to objection in Art. 21 GDPR.
Right to object to direct marketing
Where your personal data are processed for direct marketing purposes, you have the right to object at any time to processing of your personal data for such marketing, which includes profiling to the extent that it is related to such direct marketing.
You can find information as to whether and to what extent personal data are processed for direct marketing purposes in the information regarding the legal basis of processing in Section II of this GDPR Notice.
If you object to processing for direct marketing purposes, we no longer process your personal data for these purposes.
You can find the full extent of your right to objection in Art. 21 GDPR.
Where an instance of processing is based on consent pursuant to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR, as a data subject you have the right to withdraw your consent at any time pursuant to Art. 7 (3) GDPR. The withdrawal of your consent does not affect the legitimacy of the processing that occurred based on your consent until the withdrawal. We inform you of this before you grant your consent.
You can find information as to whether an instance of processing is based on Art. 6 (1) (a) or Art. 9 (2) (a) GDPR in the information regarding the legal basis of processing in Section II of this GDPR Notice.
As a data subject, you have a right to lodge a complaint with a supervisory authority under the conditions provided in Art. 77 GDPR.
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str 22, 20459 Hamburg
E-mail: mailbox@datenschutz.hamburg.de
Phone: +49 40 42854-4040
Information Commissioner’s Office
E-mail: dpo@ico.org.uk
Phone: 0303 123 1113
Information on the technical terms of the GDPR used in this GDPR Notice
The technical terms relating to data protection used in this GDPR Notice have the meaning used in the General Data Protection Regulation.
The full scope of the definitions of the General Data Protection Regulation can be found in Art. 4 GDPR.
You will find more detailed information on the most important technical terms of the General Data Protection Regulation used in this GDPR Notice below:
“Personal data” means any information relating to an identified or identifiable natural person (”data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
“Data subject” means the respective identified or identifiable natural person, to which the personal data refers to;
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
“Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
“Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
“International organisation” means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries; and
“Third country” means a country which is not a member state of the European Union (”EU”) or the European Economic Area (“EEA”) or the United Kingdom.
CHANGES TO THIS PRIVACY POLICY
We may update our Privacy Policy from time to time. Thus, you are advised to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page.
This policy is effective as of 2023-06-06
CONTACT US
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at team@frameit.site.