Privacy Policy

2. Compliance with the applicable law
2.1
For Customers and Users located in the United Kingdom all processing of Personal Data is performed in accordance with regulations and rules following the Data Protection Act 2018.
2.2
For Customers and Users located in the European Economic Area (EEA) privacy rights are granted and all processing of Personal Data is performed in accordance with  regulations and rules following the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).
2.3
For Customers and Users located in California all processing of Personal Data is performed in accordance with  regulations and rules following the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”)
2.4
For Customers and Users located in Brazilia, all processing of Personal Data is performed in accordance with regulations and rules following the Lei Geral de Proteção de Dados (“LGPD”).
2.5
We may need to share your Personal Data with the third parties that provide the Services. Where your Personal Data is transferred outside of the European Economic Area (‘EEA’), we require that appropriate safeguards are in place.
2.6
We guarantee that we have Data Processing Agreements in place with our service providers, ensuring compliance with the GDPR and our contracts with them, requiring us to maintain the confidentiality of Personal Data. All data transfers inside and outside of the EEA are being done in accordance with these Data Processing Agreements. All data transfers are performed in accordance with the strictest security regulations.
2.7
For more detailed information about the international information transfers to our business partners, service providers and developers outside of the EU/EEA, please contact us at privacy@uppwellbeing.com.
4. Data retention
4.1
We will retain Personal Data for as long as You use our Website, or continue to communicate with our support team. Your information will be deleted if You did not communicate with the support team for more than 12 months.
4.2
When deciding what the correct time is to keep the data for we look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.
4.3
For tax purposes the law requires us to keep basic information about You (including contact, identity, financial and transaction data) for 12 months after You stop being Customers.
4.4
In some circumstances we may anonymise Your Personal Data for research or statistical purposes in which case we may use this information indefinitely without further notice to You.
4.5
Any data collected for the purpose of analytics will be deleted in 12 months after being collected.
5. Information security
5.1
We care to ensure the security of Personal Data. We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain technical, physical, and administrative security measures to provide reasonable protection for Your Personal Data. When we or our Service Providers process Your information, we also make sure that Your information is protected from unauthorized access, loss, manipulation, falsification, destruction or unauthorized disclosure. This is done through appropriate administrative, technical and physical measures.
5.2
There is no 100% secure method of transmission over the Internet or method of electronic storage. Therefore, we cannot guarantee its absolute security. But we make our best efforts to make the transmission as secure as possible.
5.3
We never process any kind of sensitive data and criminal offence data not as a Controller nor as a Processor. Also we never undertake profiling of Personal Data.
6. Service providers
6.1
We may employ third party companies and individuals to facilitate our Service (‘Service Providers’), to provide the Service on our behalf, to perform Service-related services or to assist us in analysing how our Service is used.
6.2
These third parties have access to Your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
6.3
Analytics. We may use third-party Service Providers to monitor and analyse the use of our Website.
6.3.1
Google Analytics. Google Analytics is a web analytics service offered by Google that tracks and reports Website traffic. Google uses the data collected to track and monitor the use of our Website. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network. You can opt-out of having made Your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en. Your data will be stored in Google's network of data centres. Google maintains a number of geographically distributed data centres.
6.3.2
Google AdWords. Google AdWords remarketing service is provided by Google Inc. You can opt-out of Google Analytics for Display Advertising and customise the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads. Google also recommends installing the Google Analytics Opt-out Browser Add-on - https://tools.google.com/dlpage/gaoptout - for Your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en. Your data will be stored in Google's network of data centres. Google maintains a number of geographically distributed data centres
6.3.3
Facebook pixel. We use Facebook pixel to monitor and analyse web traffic. Facebook pixel is a web analysis service provided by Facebook Ireland Ltd ("Facebook"). Facebook utilises the Data collected to track and examine the use of our Website, to prepare reports on its activities and share them with other Facebook services. Facebook may use the Personal Data collected to contextualise and personalise the ads of its own advertising network. Personal Data collected: Cookies and Usage Data. Place of processing: the Republic of Ireland – Privacy PolicyOpt Out. Privacy Shield participant.
6.3.4
ActiveCampaign LLC is a marketing automation platform and email marketing service.  It is heavily focused on GDPR, SOC 2, and HIPAA compliance. We constantly improve our security to go above and beyond compliance standards. You can learn more about this service from by visiting this page. For more information on the privacy practices of ActiveCampaign, please visit its Privacy Policy.  ActiveCampaign uses data centres worldwide. View this page for more information on it's data centres.
6.4
Form constructors and hosting providers
6.4.1
JotForm. JotForm is provided by JotForm Inc. This is an online form builder that helps You in creating forms, surveys, order forms, etc. Creating a form using JotForm is easy with its intuitive drag and drop method. You can learn more about this service from JotForm by visiting this page: https://www.jotform.com/help/. For more information on the privacy practices of JotForm, please visit JotForm's Privacy Policy: https://www.jotform.com/privacy/. JotForm servers are co-located in a cloud based architecture with Google Cloud and Amazon Web Services (AWS). Google Cloud data centres are hosted in Iowa (US). AWS data centres are located both in Germany, Frankfurt (EU) and US, Virginia (US).
6.4.2
Cultrix. Cultrix cloud is provided by Cultrix LTD. Cultrix hosted virtual desktops provide a completely comprehensible cloud computing service, such as desktops and data availability from anywhere, maintenance, support, backups and the latest version of Microsoft Office, software consistency. You can learn more about this service from Cultrix LTD by visiting this page: https://www.cultrix.co.uk/.  For more information on the privacy practices of Cultrix cloud, please visit their Cultrix Privacy Policy page. The servers of Cultrix are hosted and operated in various countries around the world in which it conducts business. Thus, Your Personal Data associated with Cultrix may be transferred to and/or processed in a country other than that from which it was collected. If You are a resident of the EU, any such transfers will be made in accordance with applicable laws.
6.4.2
Webflow. Webflow is provided by Webflow, Inc., a Delaware corporation.  Webflow empowers to build professional, custom websites in a completely visual canvas with no code. You can learn more about this service from Webflow by visiting this page: https://webflow.com/legal/terms. For more information on the privacy practices of Webflow, please visit Privacy Policy: https://webflow.com/legal/privacy.
6.5
Payments. We use third-party services for payment processing (e.g. payment processors). We will not store or collect Your payment card details. That information is provided directly to our third-party payment processors whose use of Your Personal Data is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
6.6
The payment processors we work or sometimes work with are:
6.6.1
Shopify Payments
6.6.2
Stripe. Their Privacy Policy can be viewed at https://stripe.com/privacy.
6.6.3
Paypal. Their Privacy Statements can be found here.
6.6.4
Google Pay. Their Privacy notice can be viewed on the google payments site.
6.7
For a complete list of Service Providers - contact us.
7. Applicability
7.1
This Privacy Policy is applicable to our Website. Our Website contains links to other Websites. Once redirected to another Website, this Policy is no longer applicable.
8. Permitted Disclosure
8.1
We may have to share Your Personal Data with the parties set out below:
  • Other companies in our group who provide services to us.
  • Service Providers who provide IT and system administration services.
  • Professional advisers including lawyers, bankers, auditors and insurers
  • Government bodies that require us to report processing activities.
  • Third parties to whom we sell, transfer, or merge parts of our business or our assets.
8.2
We require all third parties to whom we transfer Your data to respect the security of Your Personal Data and to treat it in accordance with the law. We only allow such third parties to process Your Personal Data for specified purposes and in accordance with our instructions.
9. Changes
9.1
From time to time, we may update this Privacy Policy. We will notify You about material changes by prominently posting a notice on our Service. We encourage You to periodically check back and review this Policy so that You always will know what information we collect, how we use it, and with whom we share it.
Last updated July, 2021