Privacy policy
The Spaceflow transforms physical buildings into a human experience, making amenities, services and community life available right in the palm of your hand. The Spaceflow changes the way people connect with the spaces around them and with each other – making life more convenient and enjoyable.
Definitions
GDPR means General Data Protection Regulation (EU) No. 2016/679; Personal data means any information relating to an identified or identifiable natural person; All definitions used in the Terms of Use are also used in these Privacy terms unless is stated something explicitly different.What data are collected?
Minimal viewed data | Basic data for App (or its services) to work for any user: | Optional data (voluntarily inserted) | Social Content |
Name/Surname | Name (Name of the Merchant), Surname | Bio (“description” in case of the Merchant) | Reservations, communications etc. by a particular User |
Telephone (in case of the User) | |||
Telephone (compulsory in case of the Merchant, in case of the User compulsory for verification while registering the Account unless Facebook login used) | Image (in case of the User) | ||
Phone operating system & brand | Employer | ||
Facebook credentials (ID user and Email stored in the phone) | |||
Phone language | |||
Privacy settings | |||
Notification token | |||
Geolocation (not stored) | |||
Password (not access to it) / access code to the building | |||
Image (in case of the Merchant) | |||
History of purchased Events (date, Event name, Price) | |||
History of purchased Amenities (date, duration, Amenity name, Price) |
The data specified above is jointly referred to as the "User data". The App does not allow performing any personalized analysis of your behavior or profiling based on the User data.
Other specific data are processed for web admin page and fozr online payment mechanism within the App:
Experience data (Appcues platform) |
PD I : Any User profile data passed to Appcues by the Spaceflow, using the `Appcues.identify()` SDK function Browser information that is collected by default in the Appcues SDK (e.g., OS, device type, browser language, user agent); |
PD II: End-user Appcues data This data pertains to how Users are interacting with Appcues content; This category usually does not contain Personal data; |
PD III: Spaceflow’s data is collected by the Appcues dashboard, for example the name and email address of each of a Spaceflow’s team members who are authorized to use the Appcues platform. This category contains Personal data; |
PD IV: Spaceflow’s aggregate data includes its-wide statistics such as active User count, number of Appcues flows shown, how many Appcues flows are published at a time, etc. This data does not contain Personal data. |
Payment data (Adyen payment service) |
Cardholder data (like Credit Card Numbers, CVC codes, expiry dates etc.). The Spaceflow does not have access to such data (except for the last 4 digits of the card number, expiry data and Cardholder name) and they are securely processed by a payment platform which acts as a sub-processor – Adyen. |
Facebook SDK data (SDK data) |
Explicit events, Implicit events, Automatically logged events, Facebook app ID, Mobile advertiser ID, Metadata from the requests, the following device related metrics: time zone, device OS, device model, carrier, screen size, processor cores, total disk space, remaining disk space. The SDK data is described more in detail here . |
Who can see my profile?
If your Account is in private regime, the Optional data and your Account is not seen within a particular Profile by anyone except the SF Manager and the Spaceflow through the web admin page to the extent of your Minimal viewed data and if you post anything, your post is visible to anyone in the particular Profile. The Merchant cannot see in the web admin page anything about you except its published information (e.g. advertisements).
If your Account is in public regime, your Account can be viewed also by other Users connected to the same Profile and in such Profile to the extent of your Minimal viewed data, the Optional data and the Social content you published.
Who is controller and processor?
The Spaceflow provides some of the data above to the SF Manager who processes this data for its own purposes. Please find below an overview of who is controller for which processing activities:
Personal data | Controller | Processor |
Basic data (user inserts the data) | Spaceflow | |
Basic data (except of history of purchased Events and history of purchased Amenities) Optional data Social content (user inserts the data) | Spaceflow | |
History of purchased Services (Events, Amenities) | SF Manager / Merchant | Spaceflow |
Minimal viewed data Optional data Social content (if applicable) (the SF Manager receives through the App) | SF Manager | Spaceflow |
Optional data (Inserted by the User himself about another user) | User (if applicable) | Spaceflow |
Payment data | Spaceflow | Spaceflow |
Experience data | Spaceflow |
What the Spaceflow does with the User data and Optional data, Experience data and Payment data
1. App functionality
We, the Spaceflow, use the User Data in the App in order to make the App work under the Terms of Use, i.e. to provide all Users of the App their connection with their Account and to join the Profiles, and to connect the Users, the Merchants and the SF Managers in social environment of the Profiles. Thus, processing the User Data for this purpose is necessary in order to perform a contract with you. For this purpose, your data will be stored until the Account is deactivated.2. Improvement of the App and SF Managers’ experience
In addition to the purpose described above, we, the Spaceflow, may use the User Data (which are for these purposes used in anonymized form and therefore not considered to be personal data under the GDPR) on the basis of our legitimate interest in further development of the App, more specifically:- to improve, test, and monitor the effectiveness of the App with respect to the current functionalities in the Profiles (e.g. workload of hardware if certain amount traffic is reached, modify user experience in order to provide more comfort and intuitive use of the App, change of the App’s configuration if any);
- to develop and test new features (including their improvement, e.g. future internal market, different method of sharing economy implemented within the building profile, incentivize a cooperation of building users,) of the App;
- to monitor metrics such as total number of visitors, traffic (e.g. how much users sign into the App during day, what are the main activities they do in the app, the workload of the App during the day);
- to diagnose or fix problems with the use of the App (e.g. if the App does not work properly with a specific device operating system, if it crashes due to noncompliance with other technical parameters of the device);
- to automatically update the App on your device (if the Spaceflow comes with any new functionality of feature we do so through the App update);
3. Operation of payment mechanism
Between the Spaceflow and customer who possess a SF Manager role is based on agreement and the Terms enabled possibility to pay through online mechanism in the web admin page. Therefore, the Spaceflow processes the Payment data on the basis of a legal obligation. The Spaceflow does not have any access to this Payment data (unless stated above) which are processed securely by below stated processor in compliance with the best industry practices.4. Recipients
Spaceflow uses the following processors:- Google Ireland Limited (Cloud Service Provider, providing “platform as a service” services e.g. environment, computing capabilities, for more information see: https://cloud.google.com/terms/ ), the App runs on the Google Cloud Platform;
- Message Systems, Inc. d/b/a SparkPost, Delaware, US, (email service – Sparkpost, sending the email from the App), for more information see: https://www.sparkpost.com/policies/DPA/, the App uses API of the Sparkpost to send: 1) Addressing, message, 2) email address of the addressee 3) content of email. Message Systems, Inc. d/b/a SparkPost is certified under the EU-U.S. Privacy Shield Framework;
- Adyen N.V., The Netherlands (payment processing payment transactions in the web admin page), for more information see: https://www.adyen.com/policies-and-disclaimer/privacy-policy , the App uses Adyen services to operate on-line payment mechanism in a web admin page and for the Users – in case of the Services);
- Appcues, Inc., Boston, the U.S.A. (experience platform which provides deeper experience for the App-Users), for more information see: https://www.appcues.com/privacy . Appcues is certified under the EU-U.S. Privacy Shield Framework.
- In case privacy mode is off: App-User joined in same Profile as the User, application portfolio manager, building managers;
- Courts, Legal representatives and Notaries.
What the SF manager does with the Minimal viewed data, the Optional data, the history of purchased Services and the Social content
1. Purpose, legal basis and duration of processing
If you are connected to the particular Profile the SF Manager is a controller of the Personal data in your Profile, namely your Minimal viewed data, the Optional data and the Social content (see above). Your profile can be viewed by the SF Manager through the web admin page of the App. SF Manager is entitled to observe and manage the Profile environment to the extend you see. Through web admin page the SF Manager is entitled to see your Minimal viewed data. SF Manager uses the web admin page to:- regulate access control and management of users of the Profile for a particular building;
- react to various requests/demands and feelings from You;
- communicate with You directly through various communication activities (questionnaires, posts and notifications regarding functionalities, facilities, etc.);
- improve the service of buildings operated by the SF Manager; and
- provide social place for You to meet and to make the building life more vibrant.
2. Recipients
SF Manager uses the following processors:- IT-Service provider Spaceflow s.r.o. (for the purpose of ensuring the technical functionality and for providing all users of the App their connection with their Account and to join the Profiles);
- Property-manager (in case they are admins of the particular Profile, if the SF manager provides access to the Profile of the facility/asset);
- Company’s affiliates (for the purpose of internal audits);
- In case privacy mode is off: Users joined in same Profile as you, application portfolio manager, building managers, service providers, admin of Spaceflow (the latter only in case You load data about the building);
- Courts, Legal Representatives and Notaries.
What are the security measures in place?
The App and the web admin page use in communication with all users of the App a Transport Layer Security (TLS) encryption technology to encrypt personal information (including geolocation) and maintains by-design security. If you make a reservation within particular Profile in the App for a certain service, you will decide whether the App will have access to your calendar application in order to record such reservation. The Spaceflow guarantees that information in the App may not be accessed, disclosed, altered, or destroyed without authorized access. Data logs from the App are saved for the purposes of security events and are erased from the App after 7 days. The Experience data is secured by highest level encryption i) in external traffic in transit ( HTTPS/TLS ) and ii) at rest (using AES-256 and an automated key rotation system). The Experience data is retained for an indefinite period of time and they can be erased in seven days following the receipt of an individual request at support@appcues.com . The Payment data is retained by the payment processor for 10 years, this requires Dutch law under which the payment processor operates. If there is a serious suspicion that the particular user breached the Terms of use or committed a fraud and other illegal activity, such log can be accessed, processed and retained for an extended time period when it is the subject of a legal request or obligation, governmental investigation, or investigations concerning possible violations of the Terms of Use, or otherwise to prevent harm. The Spaceflow, the SF Manager and the Merchant can access the App through web admin page. We do not use any plugins of third parties in our web admin page and the App web admin environment. The Spaceflow uses its own analytics tools to monitor metrics and usage trends in the App and such tools collect information sent by your device but are anonymized. The Spaceflow works within the App only with anonymized logs of such statistics and then provide results to the SF Manager in the web admin page. If Information is anonymized (e.g. used anonymized for statistics) so it is no longer reasonably associated with an identified or identifiable natural person, the Spaceflow and the SF Manager may use it for any business purpose.What are your rights and your obligations?
The GDPR grants you a number of rights we will honor:- to request access to your Personal data;
- to request rectification or erasure your Personal data;
- to request restriction of the processing of your Personal data;
- to object to the processing of your Personal data;
- to receive your Personal data, as it was provided by you (data portability).