REACH Privacy Policy
Effective date: 6 March 2019
We respect your right to privacy. This privacy policy (the “Privacy Policy”) describes in detail how we collect, use and disclose your personal data, and what choices you have with respect to your personal data. Please read this Privacy Policy carefully. If, after reading the Privacy Policy, you still have any questions, please contact us so that we can address your concerns.
Table of Contents
- General Information
- WHAT PERSONAL DATA DO WE COLLECT?
- For What Purposes do we USE PERSONAL DATA?
- Non-personal data
- Marketing communication
- Retention Period
- How DO We Share And Disclose Data?
- Transfer of personal data outside the EU
- Security
- Age Limitations AND MINORS
- Your Rights REGARDING PERSONAL DATA
- AMENDMENTS
- Contact
1. General Information
1.1 Applicability of the Privacy Policy. This Privacy Policy governs the processing of personal data collected from individual users and organizations through the mobile applications “REACH” (the “Mobile App”) and the desktop application (the “Web App”) (collectively, “REACH”). This Privacy Policy does not apply to any third-party applications or software that integrate with REACH or any other third-party products, services or businesses.
1.2 About REACH. REACH is a business-to-business software-as-a-service platform comprising the Mobile App and the Web App, which allows companies to manage authorized sellers, including engaging, motivating, and training sellers, tracking sale transactions, promoting sales, submitting feedback, and providing motivational incentive schemes. The Mobile App is used by sellers in a showroom, office or other business premises to enter, manage, validate sale transactions, and participate in the motivational schemes, whereas the Desktop App is used by companies to manage sellers, track sale transactions, and provide motivational schemes.
1.3 Responsible entity (data controller). The entity that is responsible for the processing of personal data through REACH is ChannelPro FZ LLC having a registered place of business at Dubai Internet city, IN5 building, P.O. Box 73030, Dubai, the United Arab Emirates (“we”, “us”, and “our”).
1.4 Definitions. In this Privacy Policy, you will encounter recurrent terms. For your convenience, we would like to explain what such terms mean:
- “Consent” means a freely given, specific, informed and unambiguous agreement to the processing of personal data;
- “Data controller” means the entity that determines the purposes and means of the processing of personal data;
- “Data processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller;
- “Personal data” means any information relating to a natural person who can be identified, directly or indirectly, by using such information (e.g., name, address, email, phone number, and IP address); and
- “Processing” means the use of personal data in any manner, including, but not limited to, collection, storage, erasure, transfer, and disclosure of personal data.
- If we are required by law to do so;
- If we intend to collect other types of personal data that are not mentioned in this Privacy Policy;
- If we intend to use your personal data for the purposes that are not indicated in this Privacy Policy;
- If we would like to disclose or transfer your personal data to third parties that are not indicated in this Privacy Policy; or
- If we significantly amend this Privacy Policy.
1.5 Applicable laws. We process personal data in accordance with the applicable data protection laws, including, but not limited to, the EU General Data Protection Regulation (GDPR).
1.6 Term and termination. This Privacy Policy enters into force on the effective date indicated at the top of the Privacy Policy and remains valid until terminated or updated by us.
1.7 Your consent to the Privacy Policy. Your use of REACH is subject to this Privacy Policy. Before you start using REACH, we will ask you to review this Privacy Policy. We also encourage you to review the Privacy Policy before submitting any personal data through REACH. In some cases (where required by the applicable law), we may seek to obtain your consent for the processing of your personal data. For example, we may seek your prior consent for the following purposes:
1.8 Cookies. REACH does not use cookies. Any eventual use of cookies will be governed by the Cookie Policy made available on REACH.
2. WHAT PERSONAL DATA DO WE COLLECT?
2.1 Types of personal data. We comply with data minimization principles and we collect only a minimal amount of personal data that is necessary for ensuring your use of REACH:
- When you create your user account, we collect your: (i) first name; (ii) last name; (iii) mobile phone number; (iv) email address, and (v) the company you work for.
- When you contact us by email, we collect your (i) name, (ii) email address, and (iii) any information you decide to provide us.
- When you file a survey and submit feedback, we collect the information that you decide to provide us in the feedback.
- When you subscribe to our newsletter, we collect your email address.
2.2 Additional data. We may receive certain additional data when submitted REACH if you participate in a focus group, contest, activity or event, request support, interact with our social media accounts or otherwise communicate with us. Please note that the provision of such data is optional and you may choose what personal data you would like to share with us.
2.3 Sensitive Data. We DO NOT collect, under any circumstances, any special categories of personal data (“sensitive data”) from you, such as your health information, opinion about your religious and political beliefs, racial origins, membership of a professional or trade association, or information about your sexual orientation.
2.4 Failure to provide personal data. If you fail to provide us with the personal data when requested, we may not be able to perform the requested operation and you may not be able to use the full functionality of REACH, receive the services provided through REACH, or get our response.
2.5 Personal data obtained from third parties. When using REACH, you can choose to permit or restrict services, functionalities, and integrations provided by third parties (the “Third-Party Services”). Once enabled, the provider of the Third-Party Services may share certain information with us. You are strongly encouraged to check carefully the privacy settings and notices of the Third-Party Services to understand what information may be disclosed to us.
3. FOR WHAT Purposes DO WE USE PERSONAL DATA?
We respect strictest data protection principles. Thus, we process your personal data only for specified and legitimate purposes explicitly mentioned in this Privacy Policy. In short, we will use personal data only for the purposes of enabling you to use REACH, maintaining REACH, conducting research about our business activities, administrative purposes, and replying to your enquiries. The detailed description of the purposes and legal basis for processing of your personal data is provided below.
Personal data
When you create a user account:
- First name
- Last name
- Mobile phone number
- Work Email address
- The company you work for.
Purpose
- To create and maintain your user account
- To enable you to use the full functionality of REACH
- To tailor REACH to your particular location
- To provide you with the requested services
- To contact you, if necessary
- To analyze, improve, and evaluate our business activities
Legal Basis
- Performing a contract with you
- Your consent (for optional personal data)
- Pursuing our legitimate business interests (to analyze and improve our business activities)
Personal data
When you contact us by email:
- Name
- Email address
- Any information you decide to provide us in your message
Purpose
- To respond to your enquiries
- To provide you with the requested information
Legal Basis
- Pursuing our legitimate business interests (to grow and promote our business)
- Your consent (for optional personal data)
Personal data
When you sign up for a newsletter:
Email address
Purpose
To deliver you the newsletter
Legal Basis
Your consent
Personal data
When you use REACH
- IP address
- Geo-location information
Purpose
- To analyze, improve, and evaluate our business activities
- To customize REACH for your location
Legal Basis
- Pursuing our legitimate business interests (to analyze and improve our business activities)
- Your consent (for geo-location information)
4. Non-personal data
4.1 Types of non-personal data. When you use REACH, we may automatically collect certain non-personal data about your use of REACH. Such non-personal data does not allow us to identify you in any manner. The non-personal data collected by us includes information about: (i) the type of your device; (ii) operating systems and browsers used by you; (iii) your browsing patterns; (iv) URL addresses of websites clicked to and from REACH; (v) crash report data; and (vi) your other online behavior data. Please note that de-identified personal data is also considered to be non-personal data.
4.2 Your feedback. If you contact us, we may keep records of any questions, complaints or compliments made by you and the response, if any. Where possible, we will de-identify your personal data. Please note that de-identified personal data is also considered to be non-personal data.
4.3 Purposes of non-personal data. We will use non-personal data in furtherance of our legitimate interests in operating REACH, conducting our business activities, and developing new products. More specifically, we collect the non-personal data for the following purposes:
- To analyze what kind of users visit and use REACH;
- To identify the channels through which REACH is accessed and used;
- To examine the relevance, popularity, and engagement rate of the content available on REACH;
- To investigate and help prevent security issues and abuse;
- To develop and provide search, learning, and productivity tools and additional features to REACH; and
- To personalize REACH for your specific needs.
4.4 Aggregated data. In case your non-personal data is combined with certain elements of your personal data in a way that allows us to identify you, we will handle such aggregated data as personal data. If your personal data is aggregated or de-identified in a way that it can no longer be associated with an identified or identifiable natural person, it will not be considered personal data and we may use it for any business purpose.
5. Marketing communication
5.1 Marketing messages. To keep you up-to-date with REACH, and based on your consent, we may send you marketing messages, such as newsletters, brochures, promotions and advertisements, informing you about our new services or new features of REACH. If you would like to stop receiving such marketing messages, please click on the “unsubscribe” link provided in each of the message.
5.2 Informational notices. From time to time, we may send you informational notices, such as service-related, technical or administrative emails, information about REACH, your privacy and security, and other important matters. Please note that we will send such notices on an “if-needed” basis and they do not fall within the scope of direct marketing communication that requires your consent.
6. Retention Period
6.1 Retention of personal data. We will store your personal data in our systems only for as long as such personal data is required for the purposes described in this Privacy Policy, you request us to delete your personal data, or until you stop using REACH and deactivate your account - whichever comes first. After your personal data is no longer necessary for its purposes and there is no other legal basis for storing it (e.g., we are not obliged by law to store your personal data), we will immediately delete your personal data from our systems.
6.2 Retention of non-personal data. We may retain non-personal data pertaining to you for as long as necessary for the purposes described in this Privacy Policy. This may include keeping non-personal data after you have deactivated your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
6.3 Retention as required by law. Please note that, in some cases, we may be obliged by law to store your personal data for a certain period of time. In such cases, we will store your personal data for the time period stipulated by the applicable law and delete the personal data as soon as the required retention period expires.
7. How DO We Share And Disclose Data?
7.1 Sharing of personal data. In some circumstances, we disclose your personal data to the service providers with whom we cooperate (data processors) and other third parties. For example, we may share your personal and non-personal data with entities that provide certain technical support services to us, such as web analytics, data processing, advertising, email distribution, and developing services, or if you explicitly request us to disclose the personal data. The disclosure of your personal data is limited to the situations when such data is required for the following purposes:
- Ensuring the operation of REACH;
- Ensuring the delivery of the services requested by you;
- Providing you with the requested information;
- Pursuing our legitimate business interests;
- Enforcing our rights, preventing fraud, and security purposes;
- Carrying out our contractual obligations;
- Law enforcement purposes; or
- If you provide your prior consent to such a disclosure.
- Our hosting partner Amazon Web Services;
7.2 Third parties with whom we share personal data. We will share your personal data only with the third parties that agree to ensure an adequate level of protection of personal data that is consistent with this Privacy Policy and the applicable data protection laws. The third parties (data processors) that may have access to your personal data include, but are not limited, to:
7.3 Sharing of non-personal data. We may disclose or use non-personal data and de-identified data for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving REACH, responding to lawful requests from public authorities or developing new products and services.
7.4 Legal requests. If necessary, we will to disclose information about the users of REACH to the extent necessary for pursuing a public interest objective, such as national security or law enforcement.
7.5 Successors. In case our business is sold partly or fully, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in line with this Privacy Policy.
8. Transfer of personal data outside the EU
We and some of the third parties listed in Section 7 of this Privacy Policy are located outside the European Union (EU) and, if you reside in the EU, we may need to transfer your personal data to jurisdictions outside the EU. In case it is necessary to make such a transfer, we will make sure that the jurisdiction in which the recipient third party is located guarantees an adequate level of protection for your personal data (e.g., the country in which the recipient is located is white-listed by the European Commission or the recipient is a Privacy-Shield certified entity) or we conclude an agreement with the respective third party that ensures such protection (e.g., a data processing agreement based on the Standard Contractual Clauses provided by the European Commission).
9. Security
9.1 Our security measures. We put our best efforts to keep your personal data safe and secure. We implement organizational and technical information security measures to protect your personal data from loss, misuse, unauthorized access, and disclosure. The security measures taken by us include secured networks, limited access to your personal data by our staff, and anonymization of personal data (when possible). In order to ensure the security of your personal data, we kindly ask you to use REACH through a secure network only.
9.2 Handling security breaches. Although we put our best efforts to protect your personal data, given the nature of communications and information processing technology and the Internet, we cannot be liable for any unlawful destruction, loss, use, copying, modification, leakage, and falsification of your personal data caused by circumstances that are beyond our reasonable control. In case a personal data breach occurs, we will inform our local data protection authority without undue delay and immediately take reasonable measures to mitigate the breach, as required by the applicable law. Our liability for any security breaches will be limited to the highest extent permitted by the applicable law.
10. Age Limitations AND MINORS
To the extent prohibited by applicable law, we do not allow anyone younger than 18 years old to use REACH. Thus, we do not knowingly collect personal data of persons below the age of 18. If you learn that anyone younger than 18 has unlawfully provided us with personal data and you are a parent or legal guardian of that person, please contact us and we will take immediate steps to delete such personal data.
11. Your Rights REGARDING PERSONAL DATA
11.1 What rights do you have? Individuals located in certain countries, including the EU, have certain statutory rights in relation to their personal data. Subject to any exemptions provided by law, you may ask us to:
- Get a copy of your personal data that we store;
- Get a list of purposes for which your personal data is processed;
- Rectify inaccurate personal data;
- Move your personal data to another processor;
- Delete your personal data from our systems;
- Object and restrict processing of your personal data;
- Withdraw your consent; or
- Process your complaint regarding your personal data.
11.2 How to exercise your rights? If you would like to exercise your rights listed above, please contact us by email at info@channelpro.co and explain in detail your request. In order verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information, so that we would be able to identify you in our system. We will answer your request within a reasonable timeframe but no later than 2 weeks. Your requests can be submitted free of charge once per calendar year. If you submit your requests more than once per year, we reserve the right to charge a small administrative fee for providing the requested information.
11.3 How to launch a complaint? If you would like to launch a complaint about the way in which we handle your personal data, we kindly ask you to contact us first and express your concerns. After you contact us, we will investigate your complaint and provide you with our response as soon as possible. If you are a resident of the EU and you are not satisfied with the outcome of your complaint, you have the right to lodge a complaint with your local data protection authority.
12. AMENDMENTS
The Privacy Policy may be changed from time to time to address the changes in laws, regulations, and industry standards. The amended version of the Privacy Policy will be posted on this page and, if we have your email address, we will send you a notice about all the changes implemented by us. We encourage you to review our Privacy Policy to stay informed. For significant material changes in the Privacy Policy or, where required by the applicable law, we may seek your consent. If you disagree with the changes to the Privacy Policy, you should cease using REACH. The Privacy Policy was last amended on 6th of March 2019.
13. Contact
Please feel free to contact us if you have any questions about the Privacy Policy, our privacy and security practices, or would like to exercise your rights listed in Section 11 of the Privacy Policy. You may contact us by using the following contact details:
Email: info@channelpro.co
Post address: ChannelPro FZ LLC
Dubai Internet city, IN5 building
P.O. Box 73030 Dubai
The United Arab Emirates