Effective date: April 20, 2023
This Policy governs our information-handling practices as applicable to residents in the United Kingdom ("UK"), European Union (“EU”), European Economic Area (“EEA”), and Switzerland (collectively, the “Data Subjects”) that are visiting our website, www.cyango.com, and the other websites under the cyango.com domain (collectively, the “Sites”), or are customers who use our SaaS product, virtual experiences, tools, and related services (together with the Sites, the “Service”).
This Policy explains how we collect, use, disclose, and protect Data Subjects’ information as part of the Service in accordance with data protection laws in the UK, EU, EEA, and Switzerland (collectively the “Data Protection Laws”). Any discussion of your use of the Service in this Policy is meant to include your visits and other interactions with the Sites and Services, whether or not you are a user of Cyango’s SaaS product.
In order for you to understand Cyango’s data protection obligations and your rights to your Personal Information under this Policy, it is important that you identify which relationship(s) you have with Cyango.
● A “User” is an individual providing personal data to us via our website or other services, products or platforms, such as by signing up for our newsletter or making an account and posting on the Forums. Cyango is in a “data controller” relationship with Users.
● A “Customer” is a specific type of User that has engaged us to act as an agent (or, as a “Data Processor”) by obtaining our Services. Cyango is in a “data processor” relationship with Customers.
● Cyango does not have a direct relationship with Customers’ End Users. A “Customer End User” is an individual that provides their Personal Information to our Customers. We do not control the purposes nor the means by which this Personal Information is collected, and we are not in a direct relationship with Customer End Users. For details about how Personal Information about Customer End Users is handled, please review our Customers’ Privacy Policies instead of this one, and contact us for further information.
Hereinafter we may refer to Customers and Users collectively as “you.”
As a data processor, Cyango is not able to provide notice to or obtain consent from Customer End Users. To the extent required by law, Cyango supports Customers’ data-protection compliance efforts, but it is up to the Customer to ensure the appropriate data-protection safeguards are in place before processing Personal Information from Customer End Users.
In general, we collect the following types of Personal Information:
● Registration data: full name, email address, and optional social media account information (e.g., if logging in through your Google account).
● Profile data: biographical information, avatar, portfolio of work, skills, and/or freelance availability.
● Financial data: bank account information, payment card information, transaction history, and/or company billing information.
● Transaction data: information about the transactions you make on our Services, such as the projects you complete when projects are published, the number of stories shared and viewed and/or timestamps of certain actions.
● Online identifiers: geolocation/tracking details, browser fingerprint, OS, browser name and version, and/or IP addresses.
● Interaction data: survey responses, forum or blog posts, authentication data, security questions, public social networking posts, user ID, click-stream data, and other data collected via cookies and similar technologies. Please read our Cookies Policy for more information.
Any information that is disclosed in the forums or our blog becomes public information. This means that your posts are available to the public and may appear in search engines or other publicly available platforms,and may be “crawled” or searched by third parties. Your public posts can also be read, collected, or used by others to send you unsolicited messages. Be careful when posting on public parts of our Services and do not post any information that you are not comfortable sharing publicly.
Under the Data Protection Laws, we are required to notify you about our purposes for processing your Personal Information, as well as the legal basis for such processing.
Unless otherwise permitted by law, we may process your Personal Information:
● If you consent to the processing;
● To satisfy our legal obligations;
● If it is necessary to carry out our obligations arising from any contracts we entered with you or to take steps at your request prior to entering into a contract with you;
● In the public interest;
● In your vital interests;
● For our legitimate interests, such as to protect our property, rights, or the safety of Cyango, our customers, or others.
We process your Personal Information to:
● Enhance the security of our Services;
● Combat spam or other malware or security risks;
● Monitor and verify identity or service access;
● To comply with applicable security laws and regulations.
Without processing your Personal Information, we may not be able to ensure the security of our Services.
We have Terms of Service and other policies that define how you can use our Services. To ensure that you and others are using our Services in accordance with such terms and policies, we may process your Personal Information to:
● Investigate, prevent and mitigate any potentially prohibited or illicit activities;
● Enforce our agreementswith third parties;
● Collect fees based onyour use of our Services.
We collect information about your account usage and monitor your interactions with our Services. We may use any of your Personal Information collected on our Services for these purposes. The consequence of not processing your Personal Information for such purposes is the termination of your account, as we cannot perform our Services in accordance with our terms.
We process your Personal Information to provide the Services. For example, when you subscribe to Cyango Cloud Studio, we collect registration, financial, transaction, and interaction data to send the bill to you and obtain payment. We cannot provide you with Services without such information.
We may reach out to you to send you administrative or account-related information to keep you in the loop about our Services, alert you of relevant security issues or updates, or provide other transaction-related information to you. While we generally use your registration data for this purpose, we may send personalized Service communications to you based on other Personal Information, such as interaction, payment, or transaction data. Without such communication, you may miss out on important developments relating to your account that may affect how you can use our Services.
We process your Personal Information for quality control and staff training to make sure we continue to provide you with accurate information. Without our quality-control measures, you may experience issues while using the Services. For example, you may not be able to share your creations or you may encounter interruptions in our Services.
When you contact our customer service channel, we process your Personal Information to respond to your questions, disputes, feedback, or issues with our Services. We may process your Personal Information in response to another customer’s request, as relevant. Without processing your Personal Information for such purposes, we cannot respond to your requests.
We process your Personal Information to provide a personalized experience with our Services and to implement your feedback or the preferences you request. For example, you may share parts of your social media account information with us for authentication. Without such processing of your Personal Information, we may not be able to ensure your continued enjoyment of part or all of our Services.
We process your Personal Information to better understand you and the way you use and interact with our Services. For example, interaction data can provide helpful insights that assist us with measuring, customizing, or improving current Services. In addition, such information can help us develop new Services for your enjoyment. Without such processing, we cannot ensure your continued enjoyment of our Services.
We may process any of your Personal Information as necessary in the context of acquisitions, mergers, or other business transactions. We will try to notify you in advance if we intend to process your Personal Information for this purpose. You will have the option of terminating your account if you do not wish to have your Personal Information processed for such purposes.
We may send you marketing communications from time to time. Such marketing communications may contain information about our events, partner events, or promotional offers. We may use your interaction and/or transaction data to provide you with targeted marketing communications. You can opt out of our marketing communications at any time and free of charge.
We will only use your Personal Information for the purposes above or for compatible purposes.
Cyango conducts the majority of data processing activities required to provide you with the Services. However, we do engage third-party service providers to assist with supporting our Services, including vendors in the following areas:
● Credit card or payment processors;
● Cloud storage providers;
● Customer support tools;
● Product development tools;
● IT and security service providers;
● Marketing or analytics tools.
Each service provider is vetted and bound by contractual obligations that are equivalent to the provision of this Policy or more stringent. See the “Accountability for Onward Transfers” section below for more information about our agreements with third parties.
We are committed to keeping your Personal Information secure on our Services. We limit our storage of your Personal Information to the amount of time necessary to fulfil the purposes for which we collected the Personal Information, including for the purposes of satisfying any legal, accounting, or reporting obligations, or resolving disputes. Although retention laws and requirements vary by jurisdiction, we have some standard retention periods for parts of your Personal Information which are described below:
● Contact information collected for marketing purposes, such as your name and email address, is retained on an ongoing basis until you unsubscribe from our marketing communications. Thereafter we will add your contact information to our suppression list indefinitely to respect your unsubscribe request.
● Browser interaction data, such as cookies and trackers, is kept for a period of up to one year from the expiry of the cookie or date of collection.
● Product analytics data is kept for up to 5 years and automatically deleted on an ongoing basis.
If you have questions about retention periods that apply to any other data, please contact us at firstname.lastname@example.org.
Direct marketing includes any communications to you that are only based on advertising or promoting products and services. Transactional communications about your account or our Services are not considered “direct marketing” communications.
We will only contact Customers by electronic means (including email) based on our legitimate interests or the Customer’s consent. When we rely on legitimate interest, we will only send you information about our Services that are similar to those which were the subject of a previous sale or negotiations of a sale to you.
If you do not want us to use your Personal Information in this way, or to pass your Personal Information on to third parties for marketing purposes, please go to the email settings for your account to opt-out, click an unsubscribe link in your emails, or contact us at email@example.com. You can object to direct marketing at any time and free of charge.
You have the rights to your Personal Information that are described below. You can exercise your rights by contacting us at firstname.lastname@example.org so that we may consider your request under applicable law. When we receive an individual rights request via email, we may take steps to verify your identity before complying with the request to protect your privacy and security.
● Right to withdraw consent. When we rely on your consent for the processing of your Personal Information, you have the right to withdraw your consent at any time. However, the withdrawal of your consent will not affect the lawfulness of Cyango’s processing based on consent before your withdrawal.
● Right of access to and rectification of your Personal Information. You have a right to request a copy of your Personal Information stored with Cyango. We will provide a copy to you without undue delay subject to some fee associated with gathering the information (as permitted by law). We may limit or deny your request if providing you with a copy could adversely affect the rights and freedoms of others. You may also request us to correct or update any inaccurate Personal Information stored by us.
● Right to erasure (or, “The right to be forgotten”). You have the right to request the erasure of your Personal Information that: (a) is no longer necessary in relation to the purposes for which it was collected or otherwise processed; (b) was collected in relation to processing that you previously consented to, but no longer consent to; or (c) was collected in relation to processing activities to which you object, and there are no overriding legitimate grounds for our processing. Your right to erasure is subject to limitations by relevant Data Protection Laws.
● Right to data portability. If we process your Personal Information based on a contract with you or based on your consent, or the processing is carried out by automated means, you may request to receive your Personal Information in a structured, commonly used, and machine-readable format, and to have us transfer your Personal Information directly to another data controller, where technically feasible unless the exercise of this right adversely affects the rights and freedoms of others.
● Right to restriction of the processing. You have the right to restrict our processing of your Personal Information where one of the following applies:
1. You contest the accuracy of your Personal Information that we processed. In such instances, we will restrict processing during the period necessary for us to verify the accuracy of your Personal Information.
2. The processing is unlawful and you oppose the erasure of your Personal Information and request the restriction of its use instead.
3. We no longer need your Personal Information for the purposes of the processing, but it is required by you to establish, exercise, or defend legal claims.
4. You have objected to processing, pending the verification of whether the legitimate grounds of Cyango’s processing override your rights.
Restricted Personal Information shall only be processed with your consent or for the establishment, exercise, or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest. We will inform you if the restriction is lifted.
● Notification of erasure, rectification, and restriction. We will communicate any rectification or erasure of your Personal Information or restriction of processing to each recipient to whom your Personal Information has been disclosed unless this proves impossible or involves disproportionate effort. We will inform you about those recipients if you request this information. If we have made your Personal Information public and we are required to erase the Personal Information, we will, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other parties that are processing your Personal Information that you have requested the erasure of any links to, or copy or replication of your Personal Information.
● Right to object to processing. Where the processing of your Personal Information is based on consent, contract, or legitimate interests, you may restrict or object, at any time, to the processing of your Personal Information as permitted by applicable law. We can continue to process your Personal Information if it is necessary for the defence of legal claims, or for any other exceptions permitted by applicable law.
● Automated individual decision-making, including profiling. You have the right not to be subject to a decision based solely on the automated processing of your Personal Information, including profiling, which produces legal or similarly significant effects on you. There may be exceptions or limitations to this right as defined under relevant Data Protection Laws.
Your rights to your Personal Information are not without limits. Access may be denied when:
● Denial of access is required or authorized by law;
● Granting access would have a negative impact on other's privacy;
● Doing so protects our rights and properties;
● Where the request is frivolous or vexatious.
We will investigate and work expeditiously to resolve any complaints or disputes in accordance with this Policy. If you have an inquiry or complaint regarding our privacy policies or practices, please contact us first at email@example.com.
You have also a right to lodge a complaint with a competent supervisory authority.
We recognize that some Data Protection Laws vary based on the age of consent. Depending on the jurisdiction, the age of consent can be between 13 to 16 years old. We do not knowingly request to collect Personal Information from any Data Subject under the age of consent as defined by the jurisdiction in which the Data Subject resides. If we are aware of or suspect that a Data Subject is under the age of consent, we will require the Data Subject to terminate their account. We will also take steps to delete the information as soon as possible. Please notify us if you know of any individuals under the age of consent using our Services.
We may change this Policy at any time and the changes will apply to any Personal Information we already hold and to any new Personal Information collected after the change occurs. If we make any material changes to this Policy, we will endeavor to notify you by email or by posting a prominent notice on the Services prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of our Services after the effective date of this Policy constitutes an acceptance of the amended terms. You may refer to the “Last Updated” date of this Policy to determine if the Policy has changed since the date of your last visit.
If you have questions regarding this Policy or about the privacy practices of Cyango, please contact us by email at firstname.lastname@example.org, or at
Head of Privacy
Wishes and Intuition Unip. LDA
Rua Circular Norte do PITE, NERE, 7005-841 Évora, Portugal
Our local representative in the EEA is European Data Protection Office (EDPO) with a registered address at Rua Senhora da Saúde n14A 7005-372 Évora, Portugal
The EDPO can be contacted at email@example.com. If you are in the EEA, data subject request forms can be accessed at http://edpo.com/gdpr-data-request/.