AUSWEIS Privacy Policy


 

Effective: May 25th, 2018


 

1. KEY INFORMATION

 

Technologies Improving the World AG is the data controller of your personal information.

 

We collect the personal information set out in the "Information We Collect" section of this Privacy Policy below, including identity verification data and information about your use of our Service.

 

We use your personal information for the purposes set out in the "How We Use the Information" section of this Privacy Policy below, including providing our Service to you, ensuring the security and performance of our Service, sharing information with other users and our partners, direct marketing and performing statistical analysis of the use of our Service.

 

We process your personal data as set out in this Privacy Policy on the basis of your consent. In situations where we obtain your personal data from a source other than you, we process your data on the basis of legitimate interests.

 

You have a number of rights that you can exercise in relation to our use of your personal information, as set out in the "Exercise of your rights" and “Your Choices” section of this Privacy Policy below.

 

2. GENERAL PURPOSE AND WHO WE ARE

The purpose of this Privacy Policy is to describe how Technologies Improving the World AG ("TIW," "us," "we," or "our") collects, uses and shares information about you through our online interfaces (e.g., mobile applications and websites) owned and controlled by us, including mobile applications AUSWEIS or website www.ausweis.io (collectively referred to herein as the "Service" or "AUSWEIS"). Please read this Privacy Policy carefully to understand what we do. If you do not understand any aspects of our Privacy Policy, please feel free to contact us at support@tiwinnovations.com. Your use of our Service is also governed by our Terms of Use.

Technologies Improving the World AG is a Swiss company with a principal place of business at Zugerstrasse 1, 6330 Cham, Switzerland. TIW is the data controller of all Personal data(as defined below) collected via the Service and of certain Personal datacollected from third parties, as set out in this Privacy Policy.

In general, we only collect information that allows us to provide you with our best Service. This includes, for example, simple tasks like allowing other users to see the name and picture you choose to show. It also helps us to keep our Service clear of fraud and spam, and it allows us to get a unique understanding of what additional services may be useful to you, and all other purposes set out in this policy below.

3. CONSENT

Before you start using or installing our Service, it’s important you understand that by using or installing our Service, you allow us to collect, use, share, transfer, disclose and retain your personal information and other information you provide us as described in this Privacy Policy. You can be sure that we will only use your information as described in this Privacy Policy.

By using the Service, you are also agreeing to our End-User License Agreement. Please make sure you read and agree with our End-User License Agreement if you want to use the Service.

If you do not consent to such processing or do not agree with this Privacy Policy or End-User License Agreement, then please do not further access or use any of our Service.

TIW reserves the right to modify this Privacy Policy. Your continued use of Service will signify your acceptance of the changes to this Privacy Policy.

4. AGE REQUIREMENT (CHILDREN’S PRIVACY)

If you are under the age of consent in your country to form a binding agreement, you should only use our Service if you are either an emancipated minor, or have the legal consent of your parent or guardian for your use of our Service. You should use our Service only if you are fully able to understand and enter into and comply with this Privacy Policy. Our Service is not intended for children under 16: if you are under 16, please wait until you turn 16 to use them.

By using our Service you confirm that you have reached 16 years or the statutory minimum age established by law of your country, which allows you to enter into legally binding agreements or to act without the consent of both parents or guardian.

5. INFORMATION WE COLLECT

We must receive or collect some information to operate, provide, improve, understand, customize, support, and market our Service, including when you install, access, or use our Service. The types of information we receive and collect depend on how you use our Service. We collect your personal data when you interact with our Service. The data that we collect includes the following:

(i) Account and Profile Information

When you create an account and profile on the Service, we collect your name, contact information, and other information you provide, such as phone number, profile picture or other similar information, which is the type of information that specifically identifies you personally and/or can be used alone to contact you online or offline. Your name, photo, and any other information that you choose to add to your profile will be available for viewing to users of the Service. Once you create a profile, other users will be able to see in your profile certain information about your activity on the Service, such as locks you have or you have been granted, your invitees, your addresses where your AUSWEIS controller is installed and your edits to your content. For more information about your choices for publicly displayed information, see the section below about Your Choices.

 

(ii) Your Content

 

We collect and store the information and content that you post to the Service, including your addresses where the AUSWEIS controller is installed. Unless you have posted certain content anonymously, Your Content, date and time stamps, and all associated comments are viewable on the Service to some audience you choose, along with your name. For more information about what you can change, see the below section on Your Choices.

 

(iii) Communications

 

When you communicate with us (via email, phone, through the Service, or otherwise), we may maintain a record of your communication.

 

(iv) Information that may be collected automatically

 

When you visit or use our Service, we may also automatically receive and track certain data about your computer or mobile device when you visit our sites or apps, including, but not limited to, your device type, IP address, software and language preference, browser, type of operating system, date and time of viewing, use of our features and purchasing history or preferences, and your taps and interests. IP addresses may be collected, along with information about the actual web pages that you visit on our websites or at any services. If you arrive at the websites via a link from another website, the URL of the linking website and the URL of any website that you link to next will also be collected.

 

We may also ask you to access to your mobile phone (including but not limited to mobile phone memory, address book of your mobile device) while using our Service, as well as to your location with the aim to provide additional features and functionality. Your device’s settings may provide you with such permissions settings. The default settings may vary from device to device and are subject to your specific device’s functionality.

 

(v) Information that may be provided directly by third party sites

 

If you elect to sign up into your AUSWEIS account through your email or social networking sites (i.e. Facebook or Google) (the Linked Network), we receive certain profile and account information about you from the Linked Network. You agree to give us with a continued access to all of your personal data listed on such a Linked Network (e.g., your email address, birthday, country of residence, your friends list). We can receive certain information about you from Linked Network depending on your settings on these sites.

 

You may also elect to connect and make and receive payments to and from use through third party payment service providers ("PSP"). Whenever you buy something from our websites or Service, the information that you provide to the PSP is subject to their privacy policies, not ours. You explicitly consent that TIW may provide personal information collected from you to a PSP for the purpose of the offering of the payment-transaction service whenever you buy something from the Website(s) or Service and that such PSP may use such data for (statistical) analysis of payment transactions. TIW shall be allowed to notify a PSP regarding a user that engages in (or who a party believes has engaged in) any activity that is illegal, that violates any person's rights, or that led to such user's suspension or termination of use of the Websites.

 

(vi) Automatically Collected Information About Your Activity

 

We use cookies, log files, pixel tags, local storage objects, and other tracking technologies to automatically collect information about your activities, such as your searches, page views, date and time of your visit, and other information about your use of the Service. We also collect and may store information that your computer or mobile device provides to us in connection with your use of the Service such as your browser type, type of computer or mobile device, browser language, IP address, mobile carrier, unique device identifier, location, and requested and referring URLs. We also receive information when you view content on or otherwise interact with the Service, even if you have not created an account. For more information, see our Cookies Policy.

 

(vii) Information from other sources

 

We may use ad-network providers to help present advertisements on our Service. These ad-network providers use cookies, web beacons, or similar technologies to help the presenting, better targeting, and measuring of the effectiveness of advertisements, using data gathered over time and across their networks of web pages to determine or predict the characteristics and preferences of their audiences. We may offer some services in connection with other websites. Personal data that you provide to those websites may be sent to TIW in order to deliver these services. TIW processes such information in accordance with the Cookies Policy.

 

(viii) Other Data

 

We are trying to do our best and provide you our services with a good quality, in which regard we may upgrade our Service and establish new partnership relations in the future, which would result in obtaining further additional data. If we start collecting new types of personal data or significantly alter the processing of your data, then relevant amendments will be incorporated into this Privacy Policy and we will notify you of such amendments.

 

6. WHY DO WE COLLECT INFORMATION

 

We use your personal data and other information to maintain the general and personified content and functionality of our Service. In addition, we use your information to make it possible to accommodate your requests, and so that we are able to provide you with service when using (one of) our Services and for the purposes set out elsewhere in this Privacy Policy.

 

7. HOW WE USE THE INFORMATION

 

We do not sell your personal data – such as your name and contact information – to third parties to use for their own marketing purposes. We use the information we collect for the following purposes:

 

(i) Provide our Services: We use your personal data provided by you with the aim to (i) register you in our Services and create your user account; (ii) create your profile and make it visible; (iii) provide support, provide you with information about your user account, and respond to your requests; (iv) provide an individual approach by providing content (for example, information from other services) within the Service, including targeted advertisement of our Service and partner services, which we believe may be of most interest to you; (v) provide you with access to the Service and provide the requested information, products and services. If you deactivate your account in Service, this will result in the immediate deletion of your details from our servers without the possibility of recovery. In all other cases, we store information about your contacts while you use the Service to ensure the functionality of all its functions.

(ii) Technical support and security: We may use your personal data to provide technical support to you, where required, and to ensure the security of our Service.

(iii) Updates: We use your personal data collected when you sign-up to send you the messages in connection with the Service or news related to it. We may also archive this information and/or use it for future communications with you, where we are legally entitled to do so.

(iv) Communications with or from us: When you send us an email message or otherwise contact us, we may use the information provided by you to respond to your communication and/or as described in this Privacy Policy. We may also archive this information and/or use it for future communications with you where we are legally entitled to do so. Where we send you emails, we may track the way that you interact with these emails (such as when you open an email or click on a link inside an email). We use this information for the purposes of optimizing and better tailoring our communications to you.

(v) Communications with our Business Partners, Advertising: We may share your information with our business partners so that such partners may share information about their products and services that may be of interest to you where they are legally entitled to do so.

(vi) Disclosure of Information to TIW Group of Companies: We may provide the information we collect about you, including your personal data, within the TIW group of companies, including our subsidiaries and affiliates for with the aim to provide our Services properly, the proper implementation of our obligations, as well as to comply with the requirements of the law.

(vii) Disclosure to application providers and other third parties: We have the right to disclose your information, including your persona data, to service providers and other third parties under contract who help us providing you and to other users with our Service on our behalf, or other services provided by third parties through our Service (including but not limited to investigation of fraud and spam activities, site analytics, provision of special partnerships opportunities with our Service - either without identification of users, or using a unique identifier, not tied to the identity of the user). This is necessary to protect the data they receive.

(viii) Disclosure to our Operations and Maintenance Contractors: We use various service providers, vendors and contractors (collectively, "Contractors") to assist us in providing our products and services to you. Our Contractors may have limited access to your information in the course of providing their products or services to us, so that we in turn can provide our products and services to you. These Contractors may include vendors and suppliers that provide us with technology, services, and/or content related to the operation and maintenance of our Service. Access to your information by these Contractors is limited to the information reasonably necessary for the Contractor to perform its limited function for us.

(ix) Government Authorities, Legal Rights and Actions: We may share your information with various government authorities in response to subpoenas, court orders, or other legal process; to establish or exercise our legal rights or to protect our property; to defend against legal claims; or as otherwise required by law. In such cases we reserve the right to raise or waive any legal objection or right available to us. We also may share your information when we believe it is appropriate to investigate, prevent, or take action regarding illegal or suspected illegal activities; to protect and defend the rights, property, or safety of TIW, the Service, our users, customers, or others; and in connection with our Terms of Use and other agreements.

(x) Disclosure to Acquirers: TIW may disclose and/or transfer your information to an acquirer, assignee or other successor entity in connection with a sale, merger, or reorganization of all or substantially all of the equity, business or assets of TIW to which your information relates.

8. Data Retention

Unless otherwise specified, we retain information as long as it is necessary and relevant for us to achieve the purposes referred to above or to enable us to comply with our legal data protection retention obligations. Upon deactivation of your account or revoking your consent on processing your data, we will minimize the personal data we keep about you only to such data which we are required to keep to comply with laws, or other legal reasons. We may keep activity data on a non-identifiable basis to improve our services. Your posts on public accounts and communities may remain available if you do not delete them.

Please note, we can store certain data of deactivated accounts in order to comply with legal requirements, prevent fraud, assist with investigations, resolve disputes, analyzes or troubleshoot programs, and with the aim to enforce SERVICE Terms of Use or undertake other actions provided by law. Likewise, if your account has been closed or temporarily disabled, we can save some information to prevent your re-registration.

 

9. Confidentiality and Security

We consider the confidentiality and security of your information to be of the utmost importance. We will use industry standard physical, technical and administrative security measures to keep your personal data confidential and secure and will not share it with third parties, except as otherwise provided in this Privacy Policy, or unless such disclosure is necessary in special cases, such as a physical threat to you or others, as permitted by applicable law. Because the Internet is not a 100% secure environment we cannot guarantee the security of your intimation, and there is some risk that an unauthorized third party may find a way to circumvent our security systems or that transmission of your information over the Internet will be intercepted. It is your responsibility to protect the security of your login information. Please note that e-mails communications are typically not encrypted and should not be considered secure.

10. Technical, organizational and other measures

TIW endeavor to ensure that the data disclosed by you are as secure as possible. To that end we constantly strive to improve and introduce new number of technical and organizational measures which protect your Personal datafrom unauthorized or unlawful processing and from unintentional loss, destruction or damage.

TIW aim at minimizing the processing of Personally Identifiable Information. We only process information which is indispensable or information which you provide us with your consent beyond the scope of the necessary processing.

As mentioned above in this Privacy Policy, we disclose your personal data to third persons in certain cases in which we have an obligation to do so. In such cases we choose trustworthy partners of whom we can be sure they are going to apply personal data protection standards that offer at least the same level of security as those adopted by TIW.

When personal data are transferred to state administration bodies, we use the most suitable and the most secure options offered by the given body.

11. Exercise of your rights

Right to information

We respect the principle of transparency of personal data processing. In accordance with this principle we will provide information to you on the manner in which your personal data are processed.

If you wish to know in general which of your Personal datawe process, you may submit your request via support@tiwinnovations.com and specify the Service name via of which the data is processed.

If you wish to find out concrete personal data which are processed directly for you, you can submit your request via support@tiwinnovations.com and specify which concrete piece of information you require and the Service name, via of which the data is processed. The information to which you are entitled is described in Articles 13 and 14 of the GDPR. If you do not submit specific requirements, your request will be viewed as a general request under the previous paragraph.

We need to point out that if we are not able to verify your identity electronically or if there is reasonable doubt as to your identity, we may ask you to submit proof of identity at the office of TIW. Only in this way we can rule out the possibility that your personal data are disclosed to a person who only pretends to be you.

Your request will be handled in as short time as possible. But keep in mind that often this is a very complicated process which may take several weeks.

Right to Accessing, Reviewing, and Rectification Your Personally Identifiable Information

As a registered member, you can access, review and change your personal data and confirm that it remains correct and up-to-date or choose whether or not you wish to receive material from us or some of our partners by logging into the App and visiting your user account. Please be sure to update your personal information promptly if it changes or becomes inaccurate.

If you reside or are located in the EEA, you have the right to request that we:

- provide access to any personal data we hold about you;

- prevent the processing of your personal data for direct-marketing purposes;

- update any Personal data which is out of date or incorrect;

- delete any Personal data which we are holding about you;

- restrict the way that we process your Personally Identifiable Information;

- provide your Personal data to a third party provider of services; or

- provide you with a copy of any Personal data which we hold about you.

 

If you would like further information in relation to your rights or would like to exercise any of them, you may also contact us via support@tiwinnovations.com.

 

In certain cases we cannot rectify your Personally Identifiable Information. This includes cases when your incorrect or outdated personal data are contained in documents which we have to archive by law.

 

Withdrawal of consent to personal data processing and right to be forgotten

 

If TIW process your Personal data on the basis of your consent with such processing, you can stop their further processing at any time. You only have to withdraw your consent to such processing.

 

You can also exercise your right to be forgotten. In such case TIW will destroy all your Personal data that we process. Exception is cases when the processing is performed on the basis of a statutory obligation or for a legitimate interest of TIW. Also in this case TIW may demand your identification before destroying the Personally Identifiable Information.

 

12. Your Choices

You may, of course, decline to submit information through our Service, in which case we may not be able to provide certain services to you. You may also control the types of notifications and communications we send, limit the information shared within our Service about you, and otherwise amend certain privacy settings. Here is some further information about some of your choices:

Your Content. You may edit or your information. If you wish to fully delete your information please contact us at support@tiwinnovations.com and specify your request and the Service name. Any deleted content will be removed from the Service. When you make edits to Your Content, we may see the history of those edits in your profile activity and on content edit logs.

Emails and Communications. From time to time, we can send you messages about the activities and operation of our Service (for example, changes in policies, technical issues, etc.). We may also send notifications about our or third parties offers, which in our opinion may be of interest to you. If you do not want to receive such notifications, you can unsubscribe them in the system settings or by writing to us at support@tiwinnovations.com.

Deleted or Deactivated Account. If you wish to delete your account please contact us at support@tiwinnovations.com and specify your request and the Service name. Please note, in such a case all of Your Content will be removed from the Service, and it may not be restored by us, even if you change your mind. If you choose Deactivate Your Account, then you will no longer receive any communications from us, and users will not be able to interact with you; however Your Content will remain on the Service. Once you deactivate your account, you can reactivate it any time by choosing to log in.

13. Transferring Your Data

TIW is headquartered in Switzerland, and has operations, entities and service providers throughout the world. As such, we and our service providers may transfer your personal information to, or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your personal information receives an adequate level of protection in the jurisdictions in which we process it.

14. Cookies and Tracking Technologies

When you visit our Service, we and our business partners may use cookies and other tracking technologies for a variety of purposes. To learn more visit our Cookies Policy.

15. California Privacy Rights

Under California’s "Shine the Light" law, California residents who provide personal information in obtaining products or services for personal, family or household use are entitled to request and obtain from us once a calendar year information about the customer information we shared, if any, with other businesses for their own direct marketing uses. If applicable, this information would include the categories of customer information and the names and addresses of those businesses with which we shared customer information for the immediately prior calendar year (e.g. requests made in 2018 will receive information regarding 2017 sharing activities).

To obtain this information, please send an email message to support@tiwinnovations.com with "Request for California Privacy Information" on the subject line and in the body of your message. We will provide the requested information to you at your e-mail address in response. Please be aware that not all information sharing is covered by the "Shine the Light" requirements and only information on covered sharing will be included in our response.

16. Questions, Suggestions and Complaints

If you have any privacy-related questions, suggestions, unresolved problems, or complaints you may contact us via support@tiwinnovations.com.

If you reside or are located in the EEA, our Data Protection Officer and Privacy Team may assist with all queries regarding our processing of Personal dataat support@tiwinnovations.com.

If you reside or are located in the EEA, you may also make a complaint to our supervisory body for data protection matters (namely the Czech Office for Personal Data Protection) or seek a remedy through local courts if you believe that your rights have been breached.


 

17. Changes to Our Privacy Policy

If we change our privacy policies and procedures, we will post those changes on this page. If we make any changes to this Privacy Policy that materially change how we treat your personal information, we will endeavor to provide you with reasonable notice of such changes, such as via prominent notice in the Service or to your email address of record, and where required by law, we will obtain your consent or give you the opportunity to opt out of such changes.

18. Representative in the EU

To comply with all its obligations arising under the GDPR TIW appoints as of 25 of May 2018 the Representative, who represents TIW in the EU with regard of data processing (Representative). The Representative’s task is to monitor compliance with the GDPR and in cooperation with the TIW’s employees the Representative is your contact in EU for your enquiries, comments, complaints and claims regarding personal data protection.

 

Representative contact data:

 

Technology Improves the World s.r.o.

Stodůlky, Nárožní 2787 / 7a, PSČ 158 00, Prague-5, Czech Republic

 

Enquiries, comments, complaints and claims relating to the protection of personal data may also be submitted via support@tiwinnovations.com.


 

In the event you read this policy in any language other than English, you agree that in the event of any discrepancies, the English version shall prevail.