Last Updated: September 22, 2020
Thank you for choosing HeyTap!
Orope Netherlands B.V. (hereinafter referred to as "we" or "us") is committed to protecting and respecting your privacy. Therefore, we developed a Privacy Notice that covers how we collect, use, disclose, transfer, and store your personal data while you register for and use HeyTap ID. Please read carefully and familiarize yourself with our privacy practices before using our products (or services) or providing your personal data.
Orope Netherlands B.V. is a “data controller” within the meaning of EU General Data Protection Regulation n°2016/698 of 27 April 2016 (GDPR). This means that we are responsible for deciding how we hold and use your personal data and to comply with the provisions of GDPR in doing so.
This policy will help you understand the following:
II. How We Collect and Use Your Personal Data
III. How Long We Keep Your Personal Data
IV. How We Disclose Your Personal Data
V. How We Protect Your Personal Data
VI. Your Rights with Regards to Your Personal Data
VII. How We Process Children's Personal Data
VIII. Third-Party Service Providers and Their Services
IX. How Your Personal Data Is Transferred Globally
XI. Contact Us
"Affiliated Company" refers to a company that is related to us due to joint ownership or control.
"Third Parties" refer to companies or persons who do not have a related relationship arising out of joint ownership or control with us (i.e., a non-affiliated company) or other non-related persons. Third parties can be financial or non-financial companies, or persons other than you and us.
"Personal Data" refers to any information relating to an identified or identifiable natural person.
We collect data for efficient operations and to provide you with the best product experience. Our channels for collecting personal data include: (1) you provide us your data directly, (2) we record certain data about how you interact with our products, and/or (3) we obtain certain data about you from third parties.
The data we collect depends on the environment in which you interact with us, the choices you make, including your privacy settings and the products and features you use.
1. Personal data we collect
(1) Information directly provided by you
The services we provide require you to provide certain personal data directly to us. For instance:
Registering a HeyTap ID requires you to create an account or to complete a personal profile where you would provide personal data such as name, date of birth, mobile number, email address, username and password created, photos, emergency contact person and their contact information, region and country etc.
We may ask you to provide personal data and collect it under other circumstances, these circumstances include participating in prize draws or competitions, participating in promotional or marketing activities organized by us or our business partners, completing questionnaires, participating in user forums or blogs hosted by us or our business partners. The information you provide, such as your name, mobile phone and shipping address enable us to contact you and send you gifts and awards.
Legal basis: your consent which can be withdrawn at any time at your request; and to perform or carry out a contract with you in relation to our products and/or services;
(2) Service usage information
In addition to the information you provide, we may also collect information about your use of our services through software on your device and other means. For example, we may collect:
a. Device information — such as device name, device model, region and language settings, device identification number (IMEI number, etc.), device hardware information and status, usage habits, IP address, operating system version, and settings of the device used to access the service. We assign to each user an SSOID for internal identification purpose.
b. Log information —such as when and how long the service is used, search terms entered through the service, and error log information of your device. The Android system is designed in such a way that your error or crash logs will include the overall information when the events occur, which may sometimes include your personal data such as phone number, email address, Facebook account, etc. However, we have implemented security measures to ensure such information only to be used for error log analysis and not for personal identification or other purposes.
c. Location information —such as the GPS signal of the device or information about WiFi access points. If we detect abnormal login, for your account safety, we will ask you to verify your identity again.
We may also collect other information about your use of our services — such as the version of the application being used, the website visited, and how you interact with the content provided through our services.
Please note that we may cooperate with third-party service providers to implement or improve our service functions above. These third parties may not use this information for any other purpose.
Legal basis: to perform or carry out a contract with you in relation to our products and/or services; when necessary for the purposes of the legitimate interests pursued by us
Our retention period for personal data is the minimum time necessary to realize the purpose of collection unless a longer retention period is required by law. Beyond the above retention period, we will delete or anonymize your personal data.
1.1.At times we may make certain personal information available to affiliated companies and other third parties that work with us to provide products and services. Your information will not be shared with third parties for their own independent marketing or commercial purposes.
(2) Sharing with third parties: to realize the purposes stated in this Policy, email and mobile phone number verification service is provided by third party service providers. Your phone number and email address will be shared with our service providers for verification purpose.
We will only share your personal data for lawful, legitimate, necessary, specific and clear purposes, and only personal data necessary for service provision will be shared. Our partners are not allowed to use the shared personal data for any other purposes.
We may also disclose your personal data if it is compulsorily required by laws, such as to comply with a subpoena or other legal proceedings, legal actions or government agencies, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
1. We have taken reasonably practical and technical measures to protect the collected information related to the service. However, please note that although we have taken reasonable measures to protect your information, no websites, Internet transmissions, computer systems or wireless connections are absolutely secure.
2. We have taken safeguarding measures in accordance with industry standards to protect the personal data you provided and prevent data from unauthorized access, public disclosure, use, modification, damage or loss. We take all reasonably practical measures to protect your personal data. In particular:
(1) We de-identify your personal data to mitigate the risk that other organizations or individuals may identify you on the basis of that personal information. We use SSL to encrypt many services. We periodically review practices regarding information collection, storage and possessing (including physical security measures), to prevent various systems from unauthorized access.
(2) We only allow our employees and personnel of authorized service companies who need the personal data to process it to access such personal data, and they are subject to strict contractual confidentiality obligations. If they fail to perform these obligations, they may be held liable or their relationship with our may be terminated.
(3) The security of your information is extremely important for us. Therefore, we endeavor to ensure the security of your personal data and implement measures such as full security encryption during storage and transmission to prevent your information from unauthorized access, use, or disclosure. At the same time, no one can access the specific content of some encrypted data except the users themselves.
(4) When we transmit and store your special categories of personal data, we will use security measures such as encryption. When we store personal biometric information, we will treat it with technical measures before storage. For instance, storing only the digest of personal biometric information.
3. In case of personal data security incident, we will act, in accordance with the applicable law.
We will respect your legal rights to your personal data. Below are the rights that you have under law, and what we do to protect those rights. Please note that for the sake of security, we may ask you to verify your identity before processing your request.
2. The right to access: If you wish to access your personal data, you can login to your account and access the information you provided when registering the HeyTap ID through “Settings - HeyTap IDs”. If you have any questions when exercising your right to access, please contact us at: https://www.heytap.com/eu/privacy-feedback.html.
3. The right to rectification: If you find that your personal data we process about you is inaccurate or incomplete, you are entitled to ask us to make rectifications. You can rectify your information via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
4. The right to erasure: You can submit a request to us to delete personal data if we do not have a legal reason to continue to process and hold it. You can delete your information via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
5. The right to restriction of processing: You have the right to ask us to restrict how we process your personal data. We will keep just enough or process those data necessary for us to make sure we respect your restriction request in the future. You can realize your right to restriction of processing via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
6. The right to data portability: To the extent permitted by laws and regulations, you have the right to obtain a copy of your personal data in a structured, commonly used and machine-readable format. For example, if you decide to switch to a new provider, this enables you to move copy or transfer your personal data easily between our IT systems and theirs safely and securely, without affecting its usage. You can exercise your right to the restriction of processing via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
7. The right to object: You have the right to object to us processing your data even if it is based on our legitimate interests, the exercise of official authority, direct marketing (including data aggregation), and processing for the purpose of statistics. You can object us processing your data via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
8. The right to withdraw consent: If you have given us your consent to process your personal data but change your mind later, you have the right to withdraw your consent at any time, and we must stop processing your data. You can withdraw your consent via the https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html.
9. The right to object automated individual decision-making: You have right not to be subject to a decision based solely on automated processing, including profiling. If these decisions significantly affect your lawful rights, you are entitled to ask for an explanation via https://id.heytap.com/static/userdata_index.html or contacting us at: https://www.heytap.com/eu/privacy-feedback.html, which we will respond to and take appropriate measures to resolve, as necessary.
10. The right to lodge a complaint: You can the right to lodge a complaint about the way we handle or process your personal data with your national data protection authority.
We will respond and reply to your above requests as soon as possible, and generally no later than one month upon receipt of your request. (If necessary and as permitted by law, we may extend it by an additional two months. We will inform you the reason for the extension within the aforementioned one month, for example, if the request is complex or involves a large volume of data). If you are not satisfied with a response you received, you can refer the complaint to the relevant regulatory authority in your jurisdiction.
1. Our products, applications and services are mainly adult-oriented. A child should not create his/her own user account. We treat anyone under 18 years old (or equivalent minimum age for full legal capacity in relevant jurisdiction) as a child.
2. When we find that a child’s personal data is collected, we will delete the relevant data as soon as possible.
1.Our websites, applications, and services may contain links to third-party websites, products, and services. You can choose whether to access websites, products and services provided by third parties or not.
1.In principle, the personal data collected and produced within the territory of European Union is stored within the territory of the European Union. Based on your consent, after acquiring your consent, your personal data (mobile phone number, email address, Nickname, and Avatar) will be transferred to the People’s Republic of China for the purpose of uniqueness verification in order to ensure the account can be used globally without duplication and for data management purpose.
2.In case your personal data is transferred by us to countries located outside of the European Economic Area (EEA), we will ensure that appropriate safeguards are taken, such as:
(1) the recipient of the personal data is located within a country that benefits from a full “adequacy” decision of the European Commission;
(2) the recipient has signed a contract based on “model contractual clauses” approved by the European Commission, obliging them to protect your personal data;
(3) or in the absence of the above appropriate safeguards, we will ask you for your explicit consent for cross-border transmission of your personal data. In the meantime, security measures such as encryption or de-identification will be adopted for the safety of your personal data.
For more information about the safeguards relating to personal data transfers outside of the EEA, please contact us at: https://www.heytap.com/eu/privacy-feedback.html.
Orope Netherlands B.V.
Address: Florijinstraat 1, 2988CL Ridderkerk
Zip code: 2988 CL
Our EU Data Protection Officer: Collegium Auditores GmbH Datenschutz OROPE Wilhelmstrasse 74, 53721 Siegburg, Germany
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.