THIS POLICY WAS LAST UPDATED ON: 3rdJanuary 2023
We are HyperJar Limited (“we, “us” or “our”) and we arecommitted to protecting your personal data.
This policy applies to your use of our website at HyperJar.com(“Site”), the HyperJar digital wallet application (“App”) and any of our services that are accessible through the Site or the App(collectively referred to as our “Services”). It sets out thebasis on which any personal data we collect about you, or you provideto us, will be processed and used by us.
We recommend you print a copy of this policy for future reference.
1. IMPORTANT INFORMATION AND WHO WE ARE
PURPOSE OF THIS PRIVACY NOTICE
For the purpose of the relevant data protection regulations, HyperJar Limited is the “data controller” of your personal data. Thismeans that we decide on the purpose for which your personal data isprocessed.
We have appointed a data privacy manager who is responsible foroverseeing questions in relation to this policy. If you have anyquestions, including any requests to exercise your legal rights,please contact the data privacy manager using the details set outbelow.
CONTACT DETAILS AND COMPLAINTS
Email address: firstname.lastname@example.org
Postal address: HyperJar, 71-75 Shelton Street, Covent Garden,London, United Kingdom, WC2H 9JQ.
You have the right to make a complaint at any time to the InformationCommissioner’s Office (ICO), the UK supervisory authority for dataprotection issues (www.ico.org.uk). Our registration number with theICO is ZA286245. We would, however, appreciate the chance to dealwith your concerns before you approach the ICO, so please contact usin the first instance.
CHANGES TO THE PRIVACY NOTICE
We may update this policy from time to time. If we do so, the changeswill be made available on our Site and in the App and, whereappropriate, we will provide notification of the changes and where the latest version can be accessed. The new policy may bedisplayed on-screen and you may be required to accept the changes tocontinue using the App or the Services.
Please check back regularly to see any updates or changes.
Our Site and the App may include links to third-party sites, plug-insand applications. Clicking on those links or enabling thoseconnections may allow third parties to collect or share data aboutyou or your Sub-account Users. We do not control these third-partysites and are not responsible for their privacy policies or any datathat may be collected or used through those sites. Please check theirpolicies before you or your Sub-account Users submit any informationto them.
NOTICE TO PARENTS THAT OPEN A SUB-ACCOUNT AND TO SUB-ACCOUNT USERS
As a parent orguardian who opens a Sub-account you are giving us permission tocollect, use, store, share and transfer your child’s personal datain the ways specified in this policy. We encourage you to explain toyour child how their information will be used, as set out in thispolicy. For a child friendly summary see our Child Sub-accountPrivacy Notice [include hyperlink].
If you havepermitted your child to use the App to access their Sub-account youare explicitly giving us your permission to communicate with yourchild by sending them the following communications:
The registered accountholder that has opened your Sub-account, whichwill be your parent or guardian if you are a child, willhave full visibilityof all activity on your Sub-account. That means they will be able tosee all activity and use of your Sub-account and HyperJar card. Thiswill include your Transaction Data, Contact Data, Profile Data, UsageData, Marketing Data, HyperJar card details and your Sub-account ID(see section 2 below for more details on what these terms mean).
2. THE DATA WE COLLECT
Personal data, or personal information, means any information aboutan individual from which that person can be identified. It does notinclude data where the identity has been removed (anonymous data).
We may collect, use, store, share and transfer different kinds ofpersonal data about you (and your Sub-account Users) which we havegrouped together as follows:
We also collect, use and share “Aggregated Data” such asstatistical or demographic data. Aggregated Data may be derived fromyour (or your Sub-account User’s) personal data but is notconsidered personal data in law as this data does not directly orindirectly reveal your (or your Sub-account User’s) identity. Forexample, we may aggregate Usage Data to calculate the percentage ofusers accessing a specific App feature.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
We use different methods to collect data from and about you (and yourSub-account Users), including through the interactions outlinedbelow.
You (and your Sub-account Users) may give us Identity, Contact,Transaction or Financial Data by completing online forms or bycorresponding with us by using our Services. This includes personaldata you provide when you register to use the App, create an accountor a Sub-account, you or your Sub-account User enter any transactionusing our Services (such as making an advance payment to a merchantfeatured on the App), complete a survey, enter a promotion, report aproblem with the Services or sign-up to receive marketingcommunications from us.
You may allow us to access your (and your Sub-account Users ifpermitted by you) Content Data to identify contacts that are Appaccountholders or to send them a gift or a referral link. TheServices may periodically re-collect this information to stay up todate.
You (and your Sub-account Users if permitted by you) may also provideus with personal data about others when you or they use parts of ourServices, such as when you open a Sub-account, add otheraccountholders to share a jar, make a payment to a third party’s UKbank account, authorise us to receive details of contacts or referfriends. In doing so, you confirm that you have obtained consent fromsuch person to the disclosure of the information to us (whetherdisclosed by you or by your Sub-account Users), and to ourcollection, use and disclosure of the information in accordance withthis policy.
As you or your Sub-account Users navigate our Services, we may alsocollect Usage Data, Profile Data and Marketing Data as specified byyou or by them from time to time.
Automated technologies or interactions
As you or your Sub-account Users interact with our Services, we mayautomatically collect Technical Data about your or their equipment,browsing actions and patterns. We collect this by using cookies,server logs and other similar technologies. Our Services also useCookies to distinguish you and your Sub-account Users from otherusers. This helps us to provide users with a good experience and toimprove our Services. We may also receive Technical Data about you oryour Sub-account Users if you or they visit other sites employing ourcookies.
We may also use device-based data to determinethe current location of your, or your Sub-account User’s, devicewhen you or they are using the App to improve our messaging. If youallow the use of the Location Data feature in the permissions thatyou set for your account or for any Sub-account, you or yourSub-Account Users (if applicable) will be asked to consent to the useof your or their data for this purpose. You or they can withdrawconsent at any time by disabling Location Data in your App settings.
Third parties. In order to provide our Services to you,we may receive personal data about you and your Sub-account Usersfrom various third parties as set out below:
4. PURPOSES FOR WHICH WE WILL USE PERSONAL DATA
The table below describes the ways we plan to use your (and yourSub-account User’s) personal data, and which of the legal bases werely on to do so. You (and they) may obtain further information onthe legal ground relied on, or how we assess our legitimate interestsagainst any potential impact on you or them, by contacting usat email@example.com.
What is a legitimate interest?
This means our interest in conducting our business to enable us toprovide the best Services in an efficient and secure way. We do notuse your or your Sub-account User’s personal data for activitieswhere our interests are overridden by the impact on you or them(unless we have your consent or are otherwise required or permittedto by law).
What is Performance of a Contract?
This means processing your and your Sub-account User’s data whereit is necessary for us to be able to contract with you so that you(and they) can use our Services.
We will never sell your or your Sub-account Users personal data toany third-party company for marketing purposes.
You will receive in-App marketing communications from us if you have signed up to use our App, and your Sub-account Users will alsoreceive in-App marketing communications from us if you have permitted them to use the App to access their Sub-account.
We will only use your personal data to construct more relevantmarketing messages for you if you have consented to us doing so. Wewill not use the personal data of any account user, or Sub-accountUser, that is under the age of 16 to construct more relevantmarketing messages for them.
You or your Sub-account Users can ask us to stop using your personaldata to construct more relevant marketing messages at any time in theApp and adjusting your marketing preferences in the “profile” tabor by following the unsubscribe links on any marketing messages sentto you.
6. DISCLOSURES OF PERSONAL DATA
We may share your (and your Sub-account User’s) personal data withselected third parties to perform our Services and do the thingsoutlined in the table above including:
We require all third parties who use personal data in deliveringservices to us to respect the confidentiality and security of yourpersonal data and to treat it in accordance with the law.
If you would like further information about who we have shared youror your Sub-account User’s personal data with, and whether theywill be acting as a controller or processor of that data, pleasecontact us at firstname.lastname@example.org.
7. INTERNATIONAL TRANSFERS
The personal data that we collect may be transferred to, and storedat, a destination outside the UK. It may also be processed by staffoperating outside of the UK who work for us or one of our suppliers.Whenever we transfer your or your child’s personal data out of theUK, we ensure a similar degree of protection is afforded to it bytransferring to countries and organisations havebeen deemed to provide an adequate level of protection for personaldata or that we have agreed standard data protection clauseswith.
Please contact us at email@example.com if you wantfurther information on the specific mechanism used by us whentransferring your personal data out of the UK.
8. DATA SECURITY
All information you or your Sub-account Users provide to us is storedon our secure servers. Any payment transactions carried out by us orour chosen third-party provider of payment processing services willbe sent in encrypted form.
Transmission of information via the internet is not completelysecure. Although we do our best to protect your and your Sub-accountUser’s personal data, we cannot guarantee its security duringtransmission. Once we have received your and their information, wewill use strict procedures and security features to try to preventyour and your Sub-account User’s personal data from beingaccidentally lost, used or accessed in an unauthorised way.
We limit access to personal data to those employees, agents,contractors and other third parties who have a business need to knowthe information and are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personaldata breach and will notify you and any applicable regulator of abreach where we are legally required to do so.
9. DATA RETENTION
We only retain personal data for as long as necessary to fulfil thepurposes we collected it for, including for the purposes ofsatisfying any legal, accounting, or reporting requirements.
Details of retention periods for different aspects of your personaldata are available in our retention policy which you can request fromus by contacting us at firstname.lastname@example.org.
10. YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protectionlaws in relation to your (and your Sub-account Users) personal data.
You have the right:
Your Sub-account Users will also have these rights in relation to their personal data.