Last Updated: September 22, 2020
Thank you for choosing HeyTap!
Orope Netherlands B.V. (hereinafter referred to as "we" or "us") is committed to protecting and respecting your privacy. Therefore, we developed a Privacy Notice that covers how we collect, use, disclose, transfer, and store your personal data while you register for and use HeyTap ID. Please read carefully and familiarize yourself with our privacy practices before using our products (or services) or providing your personal data.
Orope Netherlands B.V. is a “data controller” within the meaning of EU General Data Protection Regulation n°2016/698 of 27 April 2016 (GDPR). This means that we are responsible for deciding how we hold and use your personal data and to comply with the provisions of GDPR in doing so.
This policy will help you understand the following:
I. Definitions
II. How We Collect and Use Your Personal Data
III. How Long We Keep Your Personal Data
IV. How We Disclose Your Personal Data
V. How We Protect Your Personal Data
VI. Your Rights with Regards to Your Personal Data
VII. How We Process Children's Personal Data
VIII. Third-Party Service Providers and Their Services
IX. How Your Personal Data Is Transferred Globally
X. How This Privacy Policy Is Updated
XI. Contact Us
“Affiliated Company” refers to a company that is related to us due to joint ownership or control.
“Third Parties” refer to companies or persons who do not have a related relationship arising out of joint ownership or control with us (i.e., a non-affiliated company) or other non-related persons. Third parties can be financial or non-financial companies, or persons other than you and us.
“Personal Data” refers to any information relating to an identified or identifiable natural person.
We collect data for efficient operations and to provide you with the best product experience. Our channels for collecting personal data include: (1) you provide us your data directly, (2) we record certain data about how you interact with our products, and/or (3) we obtain certain data about you from third parties.
The data we collect depends on the environment in which you interact with us, the choices you make, including your privacy settings and the products and features you use.
1. Personal data we collect
(1) Information directly provided by you
The services we provide require you to provide certain personal data directly to us. For instance:
Registering a HeyTap ID requires you to create an account or to complete a personal profile where you would provide personal data such as name, date of birth, mobile number, email address, username and password created, photos, emergency contact person and their contact information etc.
We may ask you to provide personal data and collect it under other circumstances, these circumstances include participating in prize draws or competitions, participating in promotional or marketing activities organized by us or our business partners, completing questionnaires, participating in user forums or blogs hosted by us or our business partners. The information you provide helps us design and improve the products, personalize your shopping experience, and provide purchase suggestions. We may match your information with third-party data to better understand your needs.
(2) Service usage information
In addition to the information you provide, we may also collect information about your use of our services through software on your device and other means. For example, we may collect:
a. Device information — such as device name, device model, region and language settings, device identification number (IMEI number, etc.), device hardware information and status, usage habits, IP address, operating system version, and settings of the device used to access the service.
b. Log information —such as when and how long the service is used, search terms entered through the service, and error log information of your device. The Android system is designed in such a way that your error or crash logs will include the overall information when the events occur, which may sometimes include your personal data such as phone number, email address, Facebook account, etc. However, we have implemented security measures to ensure such information only to be used for error log analysis and not for personal identification or other purposes.
c. Location information —such as the GPS signal of the device or information about WiFi access points.
We may also collect other information about your use of our services — such as the version of the application being used, the website visited, and how you interact with the content provided through our services.
Please note that we may cooperate with third-party service providers to implement or improve our service functions above. These third parties may not use this information for any other purpose.
(3) Obtaining data from a third party
To the extent permitted by law, we may obtain data about you from public or commercial sources and may combine it with other information received or relevant to you.
2. How we use your personal data
(1) We may process your personal data for the purposes described in this Privacy Policy, to perform our obligations to you under our user agreement and/or service contract,
a. with your prior explicit consent which can be withdrawn at any time at your request;
b. so that we can perform or carry out a contract with you in relation to our products and/or services;
c. for compliance with a legal obligation to which we are a subject;
d. when necessary for the purposes of the legitimate interests pursued by us or a third party to whom it may be necessary to disclose information. Where we process your information in reliance on such grounds, we will only do so where we have appropriately balanced such interests against your right to privacy.
Examples of related usages are as follows:
• Provide and improve services. The personal data we collect will be used to provide you with our products and services, process your orders or fulfil the contract between you and us to ensure the functionality and safety of our products and services, to verify your identity, to prevent and investigate fraud or other improper use.
• Customer Support. We use data to diagnose product issues, and provide other customer care and support services. We also use this information to improve our products and analyze the efficiency of our business operations. However, we will not use this information to track your location.
• Commercial Promotion Activities. If you participate in prize draws, contests or similar promotional activities held by us, we will use the personal data you provide to manage such activities.
(2) We will strictly abide by the terms of this Privacy Policy and any updates to it (which will be notified to you in advance) where it uses your personal data. Your personal data will only be used for the purposes determined at the time.
(3) When we want to use the information for other purposes not covered by this Privacy Policy, we will obtain your consent in advance. When we want to use information which was collected for a specific purpose for other purposes, we will obtain your consent in advance.
(4) We do not take any decisions involving the use of algorithms or profiling that significantly affects you. If certain of our services require us to do so in the future, we will inform you in advance and you can exercise your legal rights as set out in section VII.9 of this Privacy Policy.
Our retention period for personal data is the minimum time necessary to realize the purpose of collection unless a longer retention period is required by law. Beyond the above retention period, we will delete or anonymize your personal data.
1. At times we may make certain personal information available to affiliated companies and other third parties that work with us to provide products and services. Your information will not be shared with third parties for their own independent marketing or commercial purposes.
(1) Affiliated Companies: your personal data may be shared with our affiliated companies. We only share necessary personal data subject to the purposes stated in this Privacy Policy. If the affiliated companies wish to change the purpose of processing, they will ask for your authorization and consent again.
(2) Sharing with third parties: to realize the purposes stated in this Policy, some of our services will be provided by our authorized partners. We may share some personal data with our partners to provide better services and user experience. Third-party service providers are also used to provide you with customer service.
Where a merger, acquisition or bankruptcy liquidation takes place, if the transfer of personal data is involved, we will ask the new company or organization which obtains your personal data to be subject to this Privacy Policy, otherwise we will ask such company or organization to acquire your authorization and consent again.
We will only share your personal data for lawful, legitimate, necessary, specific and clear purposes, and only personal data necessary for service provision will be shared. Our partners are not allowed to use the shared personal data for any other purposes.
We may also disclose your personal data if it is compulsorily required by laws, such as to comply with a subpoena or other legal proceedings, legal actions or government agencies, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
1. We have taken reasonably practical and technical measures to protect the collected information related to the service. However, please note that although we have taken reasonable measures to protect your information, no websites, Internet transmissions, computer systems or wireless connections are absolutely secure.
2. We have taken safeguarding measures in accordance with industry standards to protect the personal data you provided and prevent data from unauthorized access, public disclosure, use, modification, damage or loss. We take all reasonably practical measures to protect your personal data. In particular:
(1) We de-identify your personal data to mitigate the risk that other organizations or individuals may identify you on the basis of that personal information. We use SSL to encrypt many services. We periodically review practices regarding information collection, storage and possessing (including physical security measures), to prevent various systems from unauthorized access.
(2) We only allow our employees and personnel of authorized service companies who need the personal data to process it to access such personal data, and they are subject to strict contractual confidentiality obligations. If they fail to perform these obligations, they may be held liable or their relationship with our may be terminated.
(3) The security of your information is extremely important for us. Therefore, we endeavor to ensure the security of your personal data and implement measures such as full security encryption during storage and transmission to prevent your information from unauthorized access, use, or disclosure. At the same time, no one can access the specific content of some encrypted data except the users themselves.
(4) When we transmit and store your special categories of personal data, we will use security measures such as encryption. When we store personal biometric information, we will treat it with technical measures before storage. For instance, storing only the digest of personal biometric information.
3. In case of personal data security incident, we will act, in accordance with the applicable law.
We will respect your legal rights to your personal data. Below are the rights that you have under law, and what we do to protect those rights. Please note that for the sake of security, we may ask you to verify your identity before processing your request.
1. The right to be informed: We are publishing this Privacy Policy to keep you informed as to what we do with your personal data. We strive to be transparent about how we use your data.
2. The right to access: If you wish to access your personal data, you can login to your account and access the information you provided when registering the HeyTap ID through “Settings - HeyTap IDs”. If you have any questions when exercising your right to access, please contact us at: https://brand.heytap.com/eu/privacy-feedback.html.
3. The right to rectification: If you find that your personal data we process about you is inaccurate or incomplete, you are entitled to ask us to make rectifications. You can rectify your information via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
4. The right to erasure: You can submit a request to us to delete personal data if we do not have a legal reason to continue to process and hold it. You can delete your information via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
5. The right to restriction of processing: You have the right to ask us to restrict how we process your personal data. We will keep just enough or process those data necessary for us to make sure we respect your restriction request in the future. You can realize your right to restriction of processing via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
6. The right to data portability: To the extent permitted by laws and regulations, you have the right to obtain a copy of your personal data in a structured, commonly used and machine-readable format. For example, if you decide to switch to a new provider, this enables you to move copy or transfer your personal data easily between our IT systems and theirs safely and securely, without affecting its usage. You can exercise your right to the restriction of processing via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
7. The right to object: You have the right to object to us processing your data even if it is based on our legitimate interests, the exercise of official authority, direct marketing (including data aggregation), and processing for the purpose of statistics. You can object us processing your data via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
8. The right to withdraw consent: If you have given us your consent to process your personal data but change your mind later, you have the right to withdraw your consent at any time, and we must stop processing your data. You can withdraw your consent via the https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html.
9. The right to object automated individual decision-making: You have right not to be subject to a decision based solely on automated processing, including profiling. If these decisions significantly affect your lawful rights, you are entitled to ask for an explanation via https://id.heytap.com/static/userdata_index.html or contacting us at: https://brand.heytap.com/eu/privacy-feedback.html, which we will respond to and take appropriate measures to resolve, as necessary.
10. The right to lodge a complaint: You can the right to lodge a complaint about the way we handle or process your personal data with your national data protection authority.
We will respond and reply to your above requests as soon as possible, and generally no later than one month upon receipt of your request. (If necessary and as permitted by law, we may extend it by an additional two months. We will inform you the reason for the extension within the aforementioned one month, for example, if the request is complex or involves a large volume of data). If you are not satisfied with a response you received, you can refer the complaint to the relevant regulatory authority in your jurisdiction.
1. Our products, applications and services are mainly adult-oriented. A child should not create his/her own user account. We treat anyone under 18 years old (or equivalent minimum age for full legal capacity in relevant jurisdiction) as a child.
2. When we find that a child’s personal data is collected, we will delete the relevant data as soon as possible.
1. Our websites, applications, and services may contain links to third-party websites, products, and services. You can choose whether to access websites, products and services provided by third parties or not.
2. We have no control over third-party privacy and data protection policies and such third parties are not bound by this Privacy Policy. Before submitting personal data to third parties, please refer to the privacy protection privacy of such third-parties.
1. In principle, the personal data collected and produced within the territory of European Union is stored within the territory of the European Union. Based on your consent, after acquiring your consent, your personal data (mobile phone number, email address, Nickname, and Avatar) will be transferred to the People’s Republic of China for the purpose of uniqueness verification in order to ensure the account can be used globally without duplication.
2. In case your personal data is transferred by us to countries located outside of the European Economic Area (EEA), we will ensure that appropriate safeguards are taken, such as:
(1) the recipient of the personal data is located within a country that benefits from a full “adequacy” decision of the European Commission;
(2) the recipient has signed a contract based on “model contractual clauses” approved by the European Commission, obliging them to protect your personal data;
(3) or in the absence of the above appropriate safeguards, we will ask you for your explicit consent for cross-border transmission of your personal data. In the meantime, security measures such as encryption or de-identification will be adopted for the safety of your personal data.
For more information about the safeguards relating to personal data transfers outside of the EEA, please contact us at: https://brand.heytap.com/eu/privacy-feedback.html.
We reserve the right to update or modify this Privacy Policy from time to time. We will send you notifications of update of this Privacy Policy in a form we deem appropriate. If you have provided us an email address, we will notify you updates (and seek your consent on such updates if you are an Indonesian resident) via email before such updates take effect. If we don’t have an email address of yours, we will post a notice on our website or send push notifications to you through our devices about the aforesaid updates.
If you have questions or concerns regarding our Privacy Policy or practices, please contact us at the following address:
Orope Netherlands B.V.
Address: Florijinstraat 1, 2988CL Ridderkerk
Our EU Data Protection Officer:
Collegium Auditores GmbH
Wilhelmstrasse 74, 53721 Siegburg, Germany
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.