Measure Protocol Privacy Notice
This Privacy Notice was last reviewed in December 2018.
Welcome to Measure Protocol’s Privacy Notice. Measure Protocol respects your privacy and is committed to protecting your Personal Data. This Privacy Notice will inform you as to how we look after your Personal Data and tell you about your privacy rights and how the law protects you.
This Privacy Notice sets out:
1. IMPORTANT INFORMATION
- 1. Important information
- 2. Data controller contact details
- 3. Information we may collect from you
- 4. How your Personal Data is collected
- 5. How we may use the information collected from you
- 6. How long will Measure Protocol use or store your Personal Data for?
- 7. Information security
- 8. Your rights in relation to your information
- 9. Cookies
- 10. International transfers of your Personal Data
- 11. Changes to this privacy notice and third party links
This Privacy Notice, together with the Measure Protocol End User Terms and Conditions available at https://www.measureprotocol.com/end-user-terms (the "Terms") and any other documents referred to in it, sets out the basis on which we will process any Personal Data about you. This Privacy Notice also sets out how you can instruct us if you prefer to limit the use of that Personal Data, and the procedures that we have in place to safeguard your privacy.
By using the Measure Protocol mobile application (the "App") or visiting http://measureprotocol.com/ (our “Website”), which may include submitting information to us or completing data-generating tasks through the Website, the App or otherwise, you signify your consent to our collection, use and disclosure of your Personal Data in accordance with this Privacy Notice. If you do not agree with this Privacy Notice, you must not use the App, access our Website, use our services, or submit information to us. Please note that you must be sixteen (16) years or over to use our App and Website.
Please note that you can adjust your privacy settings for the App at any time by accessing the "Settings" section in our App.
2. DATA CONTROLLER CONTACT DETAILS
For the purpose of this Privacy Notice, Data Protection Legislation means: (i) the Data Protection Act 2018 (the “DPA”) as applicable, along with any applicable UK data protection legislation (together “UK Data Protection Laws”); and (ii) the General Data Protection Regulation 2016/679 (the “GDPR”) until it is replaced by UK Data Protection Laws. Under current Data Protection Legislation the data controller is Measure Protocol.
If you have any questions about this Privacy Notice, including any requests to exercise your legal rights (see section 9 below), please contact us using the details set out below:
Full name of legal entity: Measure Protocol Limited
Email address: email@example.com
Postal address: C/O Blick Rothenberg Limited, 7-10 Chandos Street, London, W1G 9DQ
You have the right to make a complaint at any time to the supervisory authority for data protection issues, the Information Commissioner’s Office of the United Kingdom (https://ico.org.uk/). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
3. INFORMATION WE MAY COLLECT FROM YOU
“Personal Data” means any information relating to an identified or identifiable natural person: an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to their physical, physiological, mental, economic, cultural or social identity. It does not include data where the identity has been removed.
“Special Categories of Personal Data” may include information about an individual’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition, or sexual life. In some instances, the Survey Data (as defined below) you choose to provide may constitute Special Categories of Personal Data (also known as “Sensitive Personal Data”). We will only process Special Categories of Personal Data belonging to you where we obtain your informed consent or it is otherwise required by law or this is necessary to perform a contract we have with you.
We may collect, use, store and transfer different kinds of Personal Data about you which we have grouped together as follows:
Information you give us through direct interactions:
- Survey Data that you make available to us or provide by filling in surveys and submitting information and includes the information and responses that you provide by filling in forms, completing data-generating tasks and submitting or making available information through the App or Website.
- Identity Data includes first name, last name, username or similar identifier, title, date of birth and gender.
- Contact Data includes billing address, email address and telephone numbers.
- Financial Data including your bank account number, your bank name on the bank account, bank sort code, or similar details from other payment providers to be able to transfer to you any applicable rewards arising from your participation in surveys or to perform other services under our contract with you.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
- Correspondence Data includes records of communications between you and us relating to our App, Website or services. For example, if you submit a query, a complaint, report a problem with our service, Website or App, or otherwise liaise with Measure Protocol, we may keep a record. Information we may automatically collect about you and your device:
- Device Data, including the type of device you use, a unique device identifier (for example, your device's IMEI number, the MAC address of the device's wireless network interface), your mobile operating system and time zone setting.
- Content Data stored on your mobile device, including contact information, login information (your e-mail address, forename and surname), photos, videos or other digital content, check-ins (collecting location information, including exif image data, of where an image was taken - if you have the GPS switched on), geofencing (collecting the list of stations that you are at with a timestamp).
- Log Data, such as the details of your use of our App or your visits to our Website including, but not limited to traffic data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise.
- Location Data. We use GPS technology, or a similar technology, to determine your current or past location. Some of our location-enabled services require your Personal Data for the feature to work.
- Third Party Data is information we receive from other sources. We are working closely with third parties (including, for example, our business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers and credit reference agencies). We will notify you when we receive information about you from them and the purposes for which we intend to use that information;
- Unique Application Numbers. When you install or uninstall an App containing a unique application number or when such App searches for automatic updates, that number and information about your installation, for example, the type of operating system, may be sent to us.
Failure to provide Personal Data. Where we need to collect Personal Data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services you request). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
4. HOW YOUR PERSONAL DATA IS COLLECTED
We use different methods to collect data from and about you including through:
Direct interactions. You may give us your Identity Data, Contact Data, Financial Data, Profile Data, Marketing and Communications Data, Correspondence Data, and Survey Data by make in it available to use through the app and/or filling in forms or by corresponding with us by post, phone, email, InMail or otherwise. This includes Personal Data you provide when you:
- answer surveys or questions on our Website or App;
- participate in or engage with our Website or App surveys;
- completing data-generating tasks;
- claim or redeem survey rewards;
- apply for our products or services;
- subscribe to our service or publications;
- request marketing to be sent to you; or
- you make the information available to us through the App; or
- give us feedback or contact us by phone, email, InMail or any other means of communication.
Automated technologies or interactions. As you interact with our Website or our App, we may automatically collect Device Data, Content Data, Log Data, Location Data about your equipment, mobile operating system, device location, browsing actions and patterns.
Third parties or publicly available sources. We will receive Personal Data about you from various third parties, including search information providers such as Google. We may also receive your Contact, Financial and Transaction Data from providers of technical, payment and delivery, and your Identity and Contact Data from our business partners. We may check some of the information that you provide against third party databases to confirm that it is accurate. We have no access to your credit or debit card details, but we may have access to your billing address and payment history in order to assist with customer service enquiries. Under no circumstances are these details disclosed to any third parties other than those who need to know this information for the performance of the services requested by you.
5. HOW WE MAY USE THE INFORMATION COLLECTED FROM YOU
We will only use your Personal Data when the law allows us to. Most commonly, we will use your Personal Data in the following circumstances (each known as a “lawful basis”):
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where we need to provide you with assistance in relation to your queries.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation, for example we may process your Identity, Contact, and Financial Data to comply with laws on money
- laundering prevention and crime or financing terrorism processes.
- Where we have received your consent. You have the right to withdraw consent to marketing at any time by contacting us at firstname.lastname@example.org
We have set out below a description of all the ways we plan to use your Personal Data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your Personal Data for more than one lawful ground depending on the specific purpose.
We may process your Personal Data for the purpose of:
- Administering registration records (including reminders, e.g. to update your payment details).
Lawful Basis: performance of our contract with you or necessary for our legitimate interests;
- Providing and personalising our products or services. Lawful Basis: your consent, performance of our contract with you or necessary for our legitimate interests;
- Providing you with access to all parts or features of our services, the App or the Website. Lawful Basis: performance of our contract with you or necessary for our legitimate interests;
- Dealing with your enquiries and requests, including contacting you where necessary. Lawful Basis: performance of our contract with you or necessary for our legitimate interests or compliance with Laws & Regulations;
- Carrying out our obligations arising from any contracts entered into between you and us. Lawful Basis: performance of our contract with you or necessary for our legitimate interests;
- Processing your rewards for participating in a survey or otherwise. Lawful Basis: performance of our contract with you or necessary for our legitimate interests or compliance with Laws & Regulations;
- Contacting you for your views on our services and notifying you occasionally about important changes or developments to our services, the App or the Website. Lawful Basis: performance of our contract with you or necessary for our legitimate interests or compliance with Laws & Regulations;
- Notifying you about changes to our services. Lawful Basis: performance of our contract with you or necessary for our legitimate interests or compliance with Laws & Regulations;
- Carrying out market research campaigns. Lawful Basis: Your consent or necessary for our legitimate interests;
- Improving and developing our services, the App or the Website. Lawful Basis: Performance of our contract with you or necessary for our legitimate interests;
- Ensuring that content from our App or our Website is presented in the most effective manner for you and for your computer or mobile device. Lawful Basis: Performance of our contract with you or necessary for our legitimate interests; and
- Debt recovery or debt tracing, crime, fraud and money laundering compliance. Lawful Basis: Performance of our contract with you or necessary for our legitimate interests or compliance with laws and regulations.
Marketing and promotional offers. We may also use your Personal Data, or permit selected third parties to use your data, to provide you with information about goods and services which may be of interest to you and we or they may contact you about these by e-mail or text or push notification through our App. You will be entitled to opt out from this by contacting us or by clicking "unsubscribe" in the electronic communication you receive.
Your participation in third party surveys and related activities: we will request your consent before we share your Survey Data or other Personal Data with the survey organiser or otherwise you will be asked to accept their T&Cs and privacy notice before you are connected directly with the survey organiser for the purpose of the survey.
Anonymised statistical data. We may also gather information and statistics for the purposes of monitoring the usage of the App or the Website and our services, and may provide such anonymised aggregated information (“Aggregated Data”) to third parties. While Aggregated Data could be derived from Personal Data, it is not considered “Personal Data” under Data Protection Legislation as this data will not reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of our users accessing a specific survey on our App. If we combine or connect Aggregated Data to your Personal Data in such a way that it can identify you, we will protect the combined data in accordance with this Privacy Notice.
6. HOW LONG WILL MEASURE PROTOCOL USE OR STORE YOUR PERSONAL DATA FOR?
If you stop using our services, the App or our Website or your permission to use the App, the Website or our services is terminated, we may continue to use and disclose your Personal Data in accordance with this Privacy Notice (as amended from time to time) and as permitted by law.
We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
However, if you wish us to stop e-mailing you with information in connection with the App, the Website or our services, please see Marketing and promotional offers above.
7. INFORMATION SECURITY
The Internet is not a secure medium. However, we have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents or contractors on a need to know basis. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality. We may also share your personal data with other third parties when you have consented to It. We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator if we are required to do so.
Where relevant, with respect to online payments, all payment details will be processed using encryption. All information you provide to us is stored on our secured servers. Any payment transactions carried out by us or our chosen third-party provider of payment processing services will be encrypted using Secured Sockets Layer technology blockchain or other suitable encryption technology.
To Whom Will Your Information Be Disclosed?
- Your Account. Where you have been allocated a user admin area (an "Account"), this area is protected by your user name and password, which you should never divulge to anyone else. You are responsible for keeping this password confidential. We ask you not to share a password with anyone. We cannot accept responsibility for any unauthorised access or loss of Personal Data that is beyond our control.
- Disclosure to Government Authorities. We ensure that your information will not be disclosed to government institutions or authorities except if required by law or when requested to by regulatory bodies or law enforcement organisations.
- Social Networking. Certain of our services include social networking, chat room or forum features. When using these features please ensure that you do not submit any Personal Data that you do not want to be seen, collected or used by other users.
Your information may, for the purposes set out in this Privacy Notice, be disclosed for processing to:
8. YOUR RIGHTS IN RELATION TO YOUR INFORMATION
- Our employees;
- Our affiliates;
- Successors in title to our business;
- Third party consultants, contractors or other service providers who may access your Personal Data when providing services (including but not limited to IT support services) to us;
- Government bodies and law enforcement agencies and in response to other legal and regulatory requests, if we are under a duty to disclose or share your Personal Data in order to comply with any legal or regulatory obligation or request;
- Auditors or other advisers auditing, assisting with or advising on any of our business purposes or processes;
- To any third party where you consent, or in certain limited cases where such disclosure is required in order to enforce or apply our Terms, Website Terms and/or other agreements; or to protect the rights, property, or safety of our company, our customers, or others; and
- Subject to the limitations set out in the MARKETING AND PROMOTIONAL OFFERS section of this notice, to carefully selected third parties that may contact you about products and services which may be of interest to you.
Under certain circumstances, you have rights under data protection laws in relation to your Personal Data. If you wish to exercise any of your legal rights, please contact us using the contact details set out in this Privacy Notice.
You have the right to:
- Request access to your Personal Data. This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
- Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
- Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in the following scenarios: (a) If you want us to establish the data’s accuracy; (b) Where our use of the data is unlawful but you do not want us to erase it; (c) Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; and (d) You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
No fee usually required. You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We will notify you if this is the case at the time
What we may need from you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it.
Time limit to respond. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Exceptions. It may not be possible for us to delete your Personal Data if we are required to keep it by law or if we hold it in connection with a contract with you. Similarly, access to your Personal Data may be refused if making the information available would reveal Personal Data about another person or if we are legally prevented from such disclosure.
10. INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA
Measure Protocol is headquartered in the United Kingdom, but from time to time may conduct business in various locations around the world. Accordingly, the data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). We will take all steps reasonably necessary to ensure that your Personal Data is treated securely and in accordance with this Privacy Notice. By way of example, we may implement one of the following safeguards for Personal Data transfers outside the EEA:
- (a) Only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data by the European Commission;
- (b) Where we use certain service providers, we may use specific contracts approved by the European Commission which give Personal Data the same protection it has in Europe;
- (c) Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to Personal Data shared between the Europe and the US.
11. CHANGES TO THIS PRIVACY NOTICE AND THIRD PARTY LINKS
Changes to this Privacy Notice. In the event the purposes for which we process Personal Data changes, then we will contact you as soon as practicable and seek your consent, where such notification relates to a new additional purpose for processing which is not compatible or similar to the originally specified purposes.
Third Party Links. We are not responsible for the privacy notices and practices of other apps or websites even if you accessed the third party app using links from our App, our Website or by means of our services. This includes any survey organiser (or similar third parties) we put you in touch with after you consent to it. We recommend that you check the policy of each website or app you visit and contact the owner or operator of such app or website if you have concerns or questions.