AWG Reachify is committed to protecting the privacy and data-protection rights of our users under the UK GDPR, the EU GDPR and the Data Protection Act 2018.
This GDPR Compliance Notice forms part of our Terms of Service and complements our Privacy Policy. It explains how we comply with our data-protection obligations and how you can exercise your rights under the Data Protection Legislation.
Be told how, why and for how long your personal data is used, through this policy and privacy notices at the point of collection.
Request a copy of the personal data we hold about you and information about how we process it (a Subject Access Request).
Have inaccurate or incomplete personal data corrected without undue delay.
Request deletion of your personal data in certain circumstances (the 'right to be forgotten').
Ask us to limit how we use your data, for example while a rectification request is being handled.
Receive personal data you provided in a structured, commonly used, machine-readable format and reuse it elsewhere.
Object to processing based on legitimate interests or carried out for direct marketing at any time.
Not be subject to solely automated decisions with legal or similarly significant effects, and to obtain human intervention.
This GDPR Compliance Notice explains how AWG Reachify ("Company", "we", "us" or "our") complies with its obligations under the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended) and any other applicable data-protection legislation (collectively, the "Data Protection Legislation") when providing our digital business card, bio-link, analytics, near-field communication ("NFC") product ordering and related software-as-a-service platform (the "Service"). This Notice forms part of, and is incorporated into, our Terms of Service and should be read together with our Privacy Policy and Cookie Policy. It is intended to give you a clear, detailed understanding of your data-protection rights and how we uphold them. Capitalised terms used but not defined here have the meanings given to them in the Terms of Service or the Privacy Policy.
AWG Reachify acts as a data controller in respect of the personal data we process to provide, operate, secure and improve the Service. As a data controller, we are responsible for determining the purposes and means of processing your personal data and for complying with the data-protection principles set out in Article 5 of the UK GDPR and the EU GDPR. Where you use the Service to create and publish Business Cards or Bio Links that collect personal data of third parties (such as visitors who scan your card or save your contact details), you act as a separate data controller in respect of that data, and we act as a data processor on your behalf. In such cases, you are responsible for complying with the Data Protection Legislation in respect of that data, including providing privacy notices and obtaining any necessary consents from those individuals. Where we act as a data processor for business Users, we process personal data only on the documented instructions of the controller, under a contract that meets the requirements of Article 28 of the UK GDPR and the EU GDPR.
We comply with the data-protection principles, which require that personal data is: (a) processed lawfully, fairly and in a transparent manner; (b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes; (c) adequate, relevant and limited to what is necessary for those purposes (data minimisation); (d) accurate and, where necessary, kept up to date, with inaccurate data corrected without undue delay; (e) kept in a form which permits identification of data subjects for no longer than is necessary (storage limitation); and (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage (integrity and confidentiality). We are accountable for, and able to demonstrate compliance with, these principles.
We process personal data only where we have a lawful basis under Article 6 of the UK GDPR and the EU GDPR. The lawful bases we rely on are: (a) Performance of a contract (Article 6(1)(b)): to provide the Service you have requested, including creating and managing your Account, processing payments, delivering NFC products and providing analytics. (b) Compliance with a legal obligation (Article 6(1)(c)): to meet obligations under accounting, tax, anti-money-laundering and other applicable law. (c) Legitimate interests (Article 6(1)(f)): for our legitimate interests in operating, securing, monitoring, improving and developing the Service, including fraud prevention, service reliability and Account communications, provided those interests are not overridden by your rights and freedoms. We have carried out legitimate-interests assessments and balancing tests. (d) Consent (Article 6(1)(a)): for certain marketing communications and non-essential cookies, where you have given clear affirmative consent. You may withdraw consent at any time. Where we process special category data (which we do not actively collect), we would rely on an Article 9 condition in addition to an Article 6 basis. We do not process criminal-offence data.
The categories of personal data we process are described in detail in our Privacy Policy and include: Account data (name, email, role, profile details); payment and billing data (processed via Stripe); Content data (material you upload or publish); usage and analytics data (views, scans, taps, clicks, device, browser, IP address for approximate location and currency detection); technical and log data; NFC order data (shipping details); and team data (invited members' emails and roles). We do not knowingly collect special category data. If you voluntarily include such data in your Content, you remain responsible for the lawfulness of that processing.
We process personal data for the purposes described in our Privacy Policy, including: providing and managing the Service and your Account; processing payments and subscriptions; fulfilling NFC orders; providing analytics and enabling export; detecting and preventing fraud and abuse; communicating with you about your Account and the Service; sending marketing communications where lawful; maintaining records for legal and regulatory compliance; and operating, securing, improving and developing the Service. We do not use your personal data for any purpose that is incompatible with the purpose for which it was originally collected, unless we have identified a new compatible purpose and informed you of it in accordance with Article 6(4) of the UK GDPR and the EU GDPR.
Under the Data Protection Legislation, you have the following rights, summarised in the grid above and detailed here: (a) The right to be informed (Articles 13 and 14): we inform you about how we use your data through this Notice, our Privacy Policy and privacy notices at the point of collection. (b) The right of access (Article 15): you may request confirmation of whether we process your personal data and a copy of it, together with certain supplementary information. (c) The right to rectification (Article 16): you may request that inaccurate data be corrected or incomplete data be completed. (d) The right to erasure (Article 17): in certain circumstances you may request that we delete your personal data, for example where the data is no longer necessary, you withdraw consent, or you object and there are no overriding grounds. (e) The right to restrict processing (Article 18): you may request that we limit our processing, for example while a rectification or objection request is being considered. (f) The right to data portability (Article 20): for personal data you provided to us, processed by automated means on the basis of consent or contract, you may receive it in a structured, commonly used, machine-readable format and transmit it to another controller. (g) The right to object (Article 21): you may object to processing based on legitimate interests or for direct marketing. We will stop processing for direct marketing upon objection without exception. (h) Rights relating to automated decision-making and profiling (Article 22): you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such solely automated decision-making. These rights are not absolute and may be subject to exceptions, conditions and exemptions set out in the Data Protection Legislation, including the need to balance your rights against the rights and freedoms of others.
To exercise any of your rights, contact us using the details in Section 14. You do not need to use a particular form, but identifying your request clearly helps us handle it promptly. We will respond to your request without undue delay and in any event within one month of receipt. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will inform you of the extension and the reasons within the first month. We will take reasonable steps to verify your identity before disclosing personal data or acting on a request, and we may request information necessary to confirm your identity and locate the relevant data. We will not charge a fee for most requests, but we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, particularly if repeated. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) or your local data-protection supervisory authority. You may also seek a judicial remedy against us.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, tax or regulatory requirements. Our retention approach is described in our Privacy Policy and includes: Account data retained while your Account is active and for a reasonable period after closure; billing and transaction records retained for the period required by accounting and tax law; analytics and log data retained for a limited operational period then aggregated or deleted; and NFC order data retained for the period necessary to fulfil the order and meet consumer-law record-keeping. When you close your Account, we will delete or anonymise your personal data in accordance with this approach, except where retention is required for legal, regulatory or legitimate security purposes. You may request erasure at any time, subject to the exceptions in Article 17 of the UK GDPR and the EU GDPR.
The Service is operated from England. Some of our service providers and sub-processors may process personal data outside the United Kingdom or the European Economic Area. Where personal data is transferred outside the United Kingdom, we rely on an adequacy decision where one applies, or on appropriate safeguards such as the International Data Transfer Agreement issued by the Information Commissioner's Office, standard contractual clauses adopted under Article 46 of the EU GDPR, or another lawful transfer mechanism recognised under the Data Protection Legislation. We take reasonable steps to ensure that transfers are limited to what is necessary and that recipients are bound by obligations consistent with the Data Protection Legislation. Where you publish a Business Card or Bio Link, the data you choose to make public may be accessible globally, and you are responsible for considering any cross-border implications.
We implement appropriate technical and organisational measures to secure personal data, including encryption in transit and at rest, access controls, authentication, regular security review and monitoring for suspicious activity, as described in our Privacy Policy. In the event of a personal data breach, we will assess the risk to individuals and, where a breach is likely to result in a risk to your rights and freedoms, notify the relevant supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of it, in accordance with Article 33 of the UK GDPR and the EU GDPR. Where a breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay in accordance with Article 34, unless an exception applies.
We do not carry out solely automated decision-making that produces legal or similarly significant effects. We may use automated processing for operational purposes such as fraud detection, approximate currency detection based on IP address, and service reliability, but such processing does not result in automated decisions that significantly affect you without human involvement. We do not carry out profiling that produces legal or similarly significant effects. Any analytics or segmentation we perform is for operational and improvement purposes only and does not result in automated decisions about you.
The Service is not directed at, and is not intended for use by, individuals under the age of eighteen (18) years. We do not knowingly collect personal data from children. Where we rely on consent for any processing, in the United Kingdom we apply the age threshold set out in the Data Protection Act 2018, and in the European Union we apply Article 8 of the EU GDPR. If you believe that a child has provided us with personal data, please contact us using the details in Section 14, and we will take steps to delete that data.
For any data-protection enquiry, to exercise any of your rights, or to make a complaint about our handling of your personal data, please contact us as follows: Email: hello@awgreachify.com For the attention of: Legal / Data Protection We aim to respond to all enquiries within thirty (30) days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) or your local data-protection supervisory authority. We would appreciate the opportunity to address your concerns directly before you approach a supervisory authority, but you are not required to do so. By using the Service, you confirm that you have read and understood this GDPR Compliance Notice and our Privacy Policy, and that you understand your rights under the Data Protection Legislation.