How we respect privacy when we deal with personal information
The keyforhearts.com site ("Site") is supplied by Love Amb Inc LP, 146 Drumcondra Rd Lower Drumcondra Dublin 9 D09 YR83 Ireland, UK, email: email@example.com telephone: +447937418571 ("Company").
("You") means the individual about whom we are collecting Information.
("General Data Protection Regulation") and ("GDPR") mean Regulation (EU) 2016/679 of The European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 9S/46/EC.
("International Organization") means an organization and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.
("Third Party Country") means a country that is not a member of the European Union.
("Personal Data") means any information relating to an identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person and includes Special Category Personal Data.
("Processing") means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
("Purposes") means the Primary and Secondary purposes.
("Special Category Personal Data") means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, Your criminal record, genetic and biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning Your sex life or sexual orientation.
("Third Party") means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
("Related Site") means any other website owned, operated or controlled by Company.
("Collection") means the acquisition of Your Personal Data.
Site is owned and operated by Company ("we", "our", "us").
Company is committed to protecting user privacy. We understand that visitors and users of the Site are concerned about their privacy, and the confidentiality and security of any Personal Data that is provided.
1.2 Your consent
Due to the nature of the services provided by Company it is impractical for us to deal with You without knowing Your full name. When You register for our services You are required to use truthful and accurate information and You will not have the option to use a pseudonym.
3. Collection of data
3.1 All users
Whenever users (including non-member users) visit the Site, our servers automatically record information for statistical purposes about Your usage of the Site such as:
(a) the type of browser used;
(b) the referring URL;
(c) the IP address;
(d) the number and type of pages viewed;
(e) the date and time of visits; and
(f) the exit URL.
This information we collect about You is not Personal Data and, in any event, remains anonymous. We do not link the anonymous information to any other Personal Data unless You have either registered as a member or logged on as a member at the time of use. Accordingly, if You have not identified Yourself on the Site, such as by registering as a member or logging on as a member, we will not link a record of Your usage of our Site to You personally.
3.2 Active Members
Upon Your registration as a member we collect information about You in order to provide You with the full benefits of membership. We collect non-identifying information as well as Personal Data from You directly when You first register, and also from time to time thereafter if You provide us with additional information.
Personal Data which may be collected by Company includes:
(a) Your full name;
(b) Your email address;
(c) Your residential address;
(d) A photograph of You;
(e) Your age;
(f) Your occupation;
(g) A description of Your appearance;
Information which we may also collect and which may be deemed as constituting Special Category Personal Data includes, without limitation:
(a) Your racial or ethnic origin;
A ‘cookie’ consists of information downloaded on to your computer when you visit a Site. Cookies are widely used and can do a number of things, eg remembering your preferences, recording what you have put in your shopping basket, and counting the number of people looking at a Site.
3.4 Third parties and social media
We may allow third parties, including authorized service providers, advertising companies, data management platforms, and ad networks to serve advertisements on our sites. These companies may use tracking technologies to collect information about users who view or interact with their advertisements. Any information that these third-parties collect via cookies is completely anonymous and is non-identifiable.
4. Purposes of collecting, holding, using and disclosing Personal Data
4.1 Collect from You only
Where it is reasonable or practical to do so, we will endeavor to only collect Personal Data about You from You.
4.2 Purposes of collecting Personal Data
We will only collect Personal Data that is reasonably necessary for:
(a) enabling us to process Your application for membership and enabling us to provide services to You (including creating Your publicly viewable profile, allowing members to search for suitable members, and providing mechanisms for communication between members);
(b) our internal research and statistical purposes;
(c) enabling us to forward to You other information or material which we believe may be of interest to You;
(d) enabling a payment processor to process the payment of subscription fees;
(e) any other purpose specified in our Site Terms.
4.3 Holding of Personal Data
We will take reasonable steps to protect Personal Data that we hold from:
(a) misuse, interference and loss; and
(b) unauthorized access, modification or disclosure.
In the unlikely event that there is a serious data breach that is likely to result in a risk to Your rights and freedoms we shall, without undue delay, notify the appropriate supervisory authority. Where there is a high risk that a serious data breach will impact upon Your rights and freedoms, we will also notify You without undue delay of such a breach.
4.4 Destruction of Personal Data
We will keep Your information only for as long as we need it for legitimate business purposes and as permitted by applicable legal requirements. If:
(a) we hold Personal Data about You; and
(b) we no longer need the Personal Data for any purpose for which the information may be processed or disclosed by us under this Policy, the GDPR or Privacy Act 1988 (Cth) or other applicable law; and
(c) we are not required by or under a law of the European Union, an Australian law, this Policy, other applicable law, or a court/tribunal order, to retain the information,
4.5 Use and disclosure of Personal Data
We will only use or disclose Personal Data for the Primary Purpose where it is reasonably necessary. Use of Personal Data for the Primary Purpose will include the use of Personal Data in automated decision making processes.
We will only use or disclose Personal Data about You for a purpose other than the Primary Purpose (the "Secondary Purpose") where the following apply:
(a) the Secondary Purpose is related to the Primary Purpose and, if the Personal Data is Special Category Personal Data, the Secondary Purpose is directly related to the Primary Purpose; and
(b) You would reasonably expect us to use or disclose the Personal Data for the Secondary Purpose; or
(c) You have consented to the use or disclosure for the Secondary Purpose; or
(d) the use or disclosure of the Personal Data is required or authorized under the GDPR, an Australian law, other applicable law or a court/tribunal order.
You may withdraw Your consent to our use of Your Personal Data for the Primary and Secondary Purposes at any time by contacting us using the contact information contained in clause 1 of this Policy. However, this may affect or limit Your ability to use the Site and Company’s services.
4.6 Disclosure to Third Party Country recipients and International Organizations
Any profile information that You have provided to us will be publicly viewable on Your profile, irrespective of the location of the viewer. By creating a profile You acknowledge that overseas recipients will be able to view Your profile.
In order to provide customer support, perform back office functions, perform fraud prevention tasks, or provide services to You we may need to allow our staff or suppliers (who may be located or whose resources may be located other than Your country of residence) to access Your profile information, billing information or other Personal Data that You have supplied.
We have implemented security measures to protect the security of Your Personal Data. However, as with any transfer of data, there are still risks of data breaches. There may be instances where Your Personal Data is transferred to Third Party Countries and International Organizations, which have not been the subject of an adequacy decision by the General Data Protection Regulation Commission. Such transfers are necessary in order for us to perform our obligations set out in the Company Site Terms.
By providing Your Personal Data and Special Category Personal Data You are explicitly consenting to the international transfer and processing of such data in accordance with this Policy, in full and informed knowledge of the risks associated with such transfers and processing.
You may withdraw Your consent at any time by contacting us using the contact information contained in clause 1 of this Policy. However, this may affect or limit Your ability to use the Site and Company's services.
In all other circumstances we will only disclose Personal Data to a Third Party Country recipient or International Organization if the disclosure of the information is required or authorized by or under a law of the EU, an Australian law, other applicable law or a court/tribunal order.
4.7 Unsolicited information
If we collect Personal Data which we have not sought or requested, and if we determine that we are otherwise permitted to collect that information in compliance with the GDPR, the Privacy Act 1988 (Cth) or other applicable law, that information will be dealt with in accordance with the terms of this Policy. If, however, we determine that the collection of Your Personal Data is not permitted under the terms of the GDPR, the Privacy Act 1988 (Cth) or other applicable law, then we will destroy or de-identify that information as soon as practicable, where it is lawful and reasonable to do so.
4.8 Information not confidential
We reserve the right to send electronic mail to You regarding recommended matches, notification alerts of activity such as interest alerts or message alerts, promotions or offers, changes or additions to our services, or any products and services of our affiliated businesses. Where You are a member You may manage Your email preferences by using the settings on the “Notifications” page to customize what type of email communications You wish to receive.
5. Access, correction and portability
5.1 Access to Personal Data
We will provide You with access upon request to the Personal Data held by us in relation to You except to the extent that:
(a) giving access would be unlawful; or
(b) denying access is required or authorized by or under a law of the European Union, an Australian law, other applicable law or a court/tribunal order.
5.2 Requests for access
To request access to the Personal Data held by us about You, You must contact us using the contact details provided in clause 1. Following Your request we will contact You within a reasonable time and by no later than within one (1) month from the date of receipt of Your request. We will either provide You with the requested Personal Data or notify You when we will provide You with the Personal Data. In any event, the Personal Data requested will be provided within one month of our receipt of Your request, unless we decide not to provide You with access to the Personal Data. Where we have decided not to provide You with access to the Personal Data, we will advise You of the reasons for our decision.
5.3 Data portability
Insofar as it does not adversely affect the rights and freedoms of others and where You have communicated a request to us using the contact information in clause 1:
(a) where we have employed an automated means to process Your Personal Data after receiving Your written request, we will provide You with such Personal Data that we have collected in a structured, commonly used and machine-readable format.
(b) after receiving Your request, where technically feasible, we will transmit Your personal data directly to another data holder.
5.4 Commercially sensitive information
Where providing You access to Your Personal Data would reveal evaluative information generated by us in connection with a commercially sensitive decision-making process we will give You an explanation for the commercially sensitive decision rather than direct access to the Personal Data.
5.5 Use of intermediaries
Where we are not required to provide You with access to the Personal Data then we will, if it is reasonable to do so, give consideration to whether the use of mutually agreed intermediaries would allow sufficient access to meet our respective needs.
5.6 Correction and erasure of Personal Data
It is Your responsibility to ensure that the information You provide to us is accurate and to update Your Personal Data as necessary.
If for any reason You are unable to correct any Personal Data held by us, please contact us using the contact details provided in clause 1 and we will take reasonable steps to correct Your Personal Data.
If we elect not to correct Your information, we will notify You within one month of the reason of our refusal and the mechanisms available to You to object to our refusal.
If we correct or erase Personal Data about You that we previously disclosed to another entity we will take reasonable steps in the circumstances to give that notification, unless it is impracticable or unlawful to do so.
5.7 Refusal to correct or erase
If at any time we refuse or deny You access to Your Personal Data, or refuse to correct or erase Your Personal Data, we will provide You with reasons for such denial or refusal.
5.8 Restriction of processing
You may request that we limit or restrict the manner in which we deal with and process Your Personal Data. Where we are satisfied grounds for restriction exist, we will only process Your Personal Data: with Your consent; for the establishment, exercise or defense of legal claims against Us; or for the protection of the rights of another natural or legal person.
Access to, erasure and rectification of Your Personal Data, including any communications related thereto, will generally be provided free of charge. Where Your requests are manifestly unfounded or excessive in nature (particularly due to repetitiveness) we may elect to charge You a reasonable fee taking into account the administrative costs of providing the information or communication, or taking the action requested. Where Your requests are manifestly unfounded or excessive in nature we may also refuse Your request.
5.10 Specific objection rights
If it becomes necessary for us to process Your Personal Data without Your consent for reasons of:
(a) performing a task in the public interest;
(b) the exercise of an official authority that has been vested in us; or
(c) where it is in our legitimate interests or the legitimate interests of a third party to do so;
You will have the right to object to such use.
If You object to certain uses of Your Personal Data, we will refrain from processing Your Personal Data unless compelling legitimate grounds exist for the processing which otherwise override Your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.
6.1 Making a complaint
If You believe that we have used or disclosed Your Personal Data in a manner which is contrary to this Policy or otherwise breaches an applicable law, then You should email us at firstname.lastname@example.org.
6.2 Our response
Within 30 days of receipt of Your complaint we will notify You in writing as to what action we propose to take in relation to Your complaint and will provide You with details of what further action You can take if You are not satisfied with our response.
Last updated: 22 May 2018