Product Fruits – Privacy policy

Last updated: March 26, 2024

Personal data controller: Product Fruits s.r.o., with registered office at Rozdělovská 1999/7, Břevnov, 169 00 Praha 6, ID number: 09552618, incorporated under the laws of the Czech Republic, registered at the Commercial Register at the Municipal Court in Prague under file no. C 338063 (“we”).

We are providers of Product Fruits platform (the “Platform”) through which we help you with user onboarding and provide you with other services according to the Terms of Service (the “Terms”) and concluded agreement. The privacy of your data is a big deal to us. We’ll only ever access your account to help you with a problem or squash a software bug. We’ll never open any uploaded files unless you ask us to. We log all access to all accounts by IP address, so we can always verify that no unauthorized access has happened for as long as the logs are kept.

The Platform is available on website: https://productfruits.com/ (the “Website”).

We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”).

Do not forget that we act in two ways – as personal data controller where we stipulate purposes and means of the processing which are described in this privacy policy and also as personal data processor. How we process personal data as personal data processor is described here.

A.PERSONAL DATA PROCESSED

To be as transparent as possible, we divided personal data that we process into these categories:

  • Identification information. This includes your name, surname, identification of organization on which behalf you are acting.
  • Contact details. E-mail and voluntarily you may provide us with phone number.
  • Payment data. Information about purchase, credit card (passed directly to the payment processor and does not go through our servers, we only store las 4 digits of the credit card number), billing address, payment information, chargebacks, information necessary to prevent frauds, information about persons stipulated on invoices, requests, statistical data, information about numbers of users that used the service.
  • Log information and other information about usage of the Platform. We will process technical information, such as logs of the users in the Platform, IP address of the account etc.
  • Data in connection with fulfilment of the agreement. Information about fulfilment of mutual agreement, range of provided services under the agreement if connected with specific natural person acting on behalf of the Customer.
  • Communication data. Personal data provided by contacting us through our Website, e-mail communication and any other information contained in communication.

We obtain personal data directly from you, or if you are user of services and your account was created by your employer/contractual party, we may obtain personal data from such employer/contractual party with which we are in contractual relationship.

B.PURPOSES OF THE PROCESSING OF PERSONAL DATA

We process your personal data as a data controller for the processing purposes set out below, on the basis of the legal bases set out here, for a limited period of time and only to the extent described here.

B.1Provision of services, identity & access

We primarily process personal data to provide you with our services, to provide you with the account in the Platform (and to provide access to your workers and other personnel) and requested services, in particular when you register in the Platform, create a user account, fill billing details and pay for our services, contact us for further information. As part of this, we may also send you messages about the conclusion and performance of a contract, new product and service releases, payment reminders, password resets and other essential information.

For this purpose, we process your Identification information, Contact details, Payment data, Log information and other information about usage of the Platform, Data in connection with fulfilment of the agreement and Communication data if the communication is related to a mutual contractual relationship.

Payments are made via payment provider which is described in separate list of recipients and sub-processors and as we mentioned above, we do not see your credit card information.

For this purpose, we also need information about number of users to correctly set up prices for services. Under this, encrypted information about users (to which the services are used) are processed.

The legal basis for this processing is the performance of the contract between you and us and the need to take steps at your request before entering into the contract or, where you are not directly party to the contract (if you are, for example, an employee of our customer or person acting on behalf of customer), our legitimate interest in the performance of any contract entered into.

The data are processed for the duration of the concluded contract and for the period necessary for the performance of the obligations under such contract. When you cancel your account, we'll ensure that nothing is stored on our servers past 30 days. Anything you delete on your account while it's active will also be purged within 30 days (up until then it's available in the trash can).

B.2Protection of rights and duties and protection against frauds and misuse

We may also process your data to protect us from unauthorized use of our Platform and services to ensure their safe use. Also, we may use personal information to protect our own claims or to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person or violations of our Terms of Service.

For this purpose, we process your Identification information, Contact details, Payment data, Log information and other information about usage of the Platform, Data in connection with fulfilment of the agreement and Communication data.

The legal basis for this processing is our legitimate interest in protecting our rights and duties and protection against frauds and misuse.

We process the data for the period during which limitation periods or any other time limits for the assertion of claims may run. This period may be changed according to the current state and according to the specific findings and caused frauds.

B.3Fulfilling legal obligations

We may also process your personal data in order to comply with our legal obligations, particularly in the area of taxes, accounting and other areas that are applied to us. At the same time, we need to be prepared to provide cooperation to state authorities if we are required to do so by law.

For this purpose, we process your Payment data, Log information and other information about usage of the Platform, Data in connection with fulfilment of the agreement.

The legal basis for this processing is the fulfilment of our legal obligations. Those data are processed for the period required by law. This is generally the period in which supervisory authorities may conclude check or start proceeding which is up to 10 years or similar.

B.4Surveys and other communication

We may process the data you provide when we communicate together, e.g., in connection with future reference, answering your questions, ensuring communication, providing you with surveys.

For this purpose, we process your Contact details you provide us and Communication data.

The legal basis for this processing is our legitimate interest in supporting and promoting our products and services. The data are processed for reasonable period required for mutual communication or conducting survey.

B.5Newsletters and commercial communication

From time to time, we may send you commercial communication. However, we will only do it if you are our customer and you provide us with your e-mail or you subscribe to the newsletter list via our Website.

For this purpose, we will process your e-mail address and your Identification information.

The legal basis for this processing is divided into two separate parts:

  • If you create your account and register, we conclude contract together and customer relationship is made. Thus, personal data are processed under our legitimate interest (direct marketing).
  • If you subscribe to our newsletter list, you are giving us consent for such processing by subscribing or accepting relevant check-box.

If you are our customer, in addition to objecting to the processing of data for this purpose, you may opt out of receiving any newsletter at any time by using the unsubscribe links provided in the footer of each message sent. Also, you may withdraw your consent at any time which has the same meaning as opt out described above.

Processing in connection with cookies on the Website and in the PlatformB.6Website/Platform operation and security (necessity)

We process your personal data for the operation of the Platform and its security, i.e., for the internal functioning of the Platform, your identification as a registered user when browsing and repeated visits to the Platform, and for ensuring your security.

For this purpose, we process technical data such as IP address and cookies data categorized as necessary.

The legal basis for this processing is our legitimate interest in the proper functioning and safe operation of our Platform. Data are processed, as a rule, for the duration of your visit to the Platform, for a maximum of 1 year from the date of collection.

B.7Analysis of Website/Platform traffic (analytics)

We process your personal data to understand how visitors use our Website. As part of this, we can monitor traffic to our Website, optimize it and generally make your visit to the Website smoother and more user-friendly.

For this purpose, we process cookies data categorized as analytical provided by us or third-parties when you provide us with your consent. The personal data is processed until a maximum of 1 year after your visit to the Website or the Platform or until you withdraw your consent.

B.8Web support and promotion (re-marketing)

We process your personal data to obtain information about your personal preferences and to display relevant advertising. In doing so, we may promote and offer products and services on the site and show you marketing communications relating to the services you have enquired about and promote our brand online.

For this purpose, we process cookies data categorized as marketing/re-marketing provided by us or third-parties when you provide us with your consent. The personal data is processed until a maximum of 1 year after your visit to the Website or the Platform or until you withdraw your consent.

C.SHARING OF PERSONAL DATA

At the same time, we may share personal information with third parties who help us provide our products and services to you. Also, in some cases, we may be obliged to share personal data with third parties. All of other third parties are according to the GDPR called recipients of personal data.

List of recipients is available in the separate list of recipients and sub-processors that is available here.

In addition to this, we may share your personal data with certain third parties as data controllers for the purpose of "Fulfilling legal obligations" where we are obliged to do so under applicable legislation (in particular, administrative authorities, police authorities and judicial authorities). Similarly, we may be obliged to share your data with persons who claim to have been harmed by your conduct.

Where we share your personal data with controllers and processors in third countries (outside the EEA), we only do so where there is a decision by the European Commission that a particular country outside the EEA provides an adequate level of data protection, including where controllers or processors have adopted additional data protection measures such as Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs).

D.YOUR RIGHTS IN PROCESSING AND THE POSSIBILITY OF EXERCISING THEM

You have the right to (i) request access to your personal data; (ii) withdraw your consent; (iii) request rectification of your personal data; (iv) request erasure of your personal data; (v) request restriction of the processing of your personal data; (vi) request portability of your personal data; (vii) object to the processing of your personal data; or (viii) lodge a complaint with the relevant supervisory authority.

In all matters related to the processing of your personal data, whether it is a question, the exercise of rights, sending a complaint to our hands, etc., you can contact us at privacy@productfruits.com.

Your request will be processed without undue delay, at most within 1 month. In exceptional cases, in particular due to the complexity of your request, we are entitled to extend this period by a further 2 months. We will, of course, always inform you of any such extension and the reason for it.

You also have the right to lodge a complaint with the supervisory authority as described below.

D.1Right of access

You have the right to obtain confirmation from us as to whether or not we are processing your personal data. If we process your personal data, you also have the right to request access to information about the purpose and scope of the processing, the recipients of the data, the duration of the processing, the right to rectification, erasure, restriction of processing and to object to the processing, the right to file a complaint with a supervisory authority and the sources of the personal data (this information is already provided in this document). You can also ask us for a copy of the personal data we process. We provide the first copy free of charge; further copies may be subject to a fee. The scope of the data provided may be limited so as not to interfere with the rights and freedoms of others.

D.2Right to withdraw consent

You have the right to withdraw your consent to the processing of personal data at any time. However, the withdrawal of consent does not affect the lawfulness of the processing prior to such consent, nor does it lead to the termination of the processing of personal data that has already been anonymized.

D.3Right to repair

You have the right to request us to correct inaccurate personal data concerning you. Depending on the purpose of the processing, you may also have the right to have incomplete personal data completed, including by providing an additional declaration.

D.4Right to erasure (right to be forgotten)

You have the right to request the deletion of your personal data in cases where:

  • we no longer need your personal data for the purposes for which it was collected or processed;
  • you withdraw the consent on the basis of which the personal data was processed and there is no further reason for processing it:
  • • you object to processing and there are no other overriding reasons for processing, or you object to processing for direct marketing purposes;
  • personal data are processed in violation of the law.

However, you cannot exercise this right where the processing is necessary for compliance with our legal obligations or tasks entrusted to us in the public interest or for the establishment, exercise, or defense of legal claims.

D.5Right to restriction of processing

You have the right to request restriction of the processing of your personal data in cases where:

  • you contest the accuracy of your personal data; in this case, you may request a restriction of processing until the accuracy of the personal data has been verified;
  • the processing is contrary to the law and instead of erasure, you request a restriction of the processing of personal data;
  • we no longer need your personal data for the purposes for which it was collected or processed, but you require it for the establishment, exercise, or defense of legal claims;
  • you have objected to the processing of your personal data; in this case, you may request a restriction of processing until it is verified that our legitimate interests prevail.
D.6Right to portability

You have the right to obtain a copy of your personal data that we process by automated means on the basis of your consent or for the performance of a contract. We will transmit this data in a commonly used and machine-readable format to you or to a controller designated by you, if technically feasible. The scope of the data provided may be limited so as not to interfere with the rights and freedoms of others.

D.7Right to object

You have the right to object to the processing of your personal data that we process on the basis of our legitimate interest. We will stop processing your data if there are no other overriding reasons for processing or if the processing is not necessary for the establishment, exercise, or defense of legal claims or if you object to processing for direct marketing purposes. Specific rule will apply when you object to newsletters. In this case, we stop with sending you such newsletters.

E.RIGHT TO FILE A COMPLAINT

In addition to the possibility of exercising your rights with our company, you can also file a complaint with the relevant supervisory authority, which is the Office for Personal Data Protection located at Pplk. Sochora 27, 170 00 Prague 7.

F.CHANGES TO THIS INFORMATION

We are entitled to change this processing information from time to time, so please check it regularly. We will post any changes to this document on our Website.

aicpa soc badgeiso 27001 badgehipaa badgegdpr badge
© Copyright 2024 Product Fruits. Made with ❤️ in Czech Republic, EU
youtubelinkedin