(Date last updated: 23 May 2018)
The data controller of your Personal Information is Touchcast, LLC, a Delaware limited liability company with its principal offices located at 603 Greenwich Street, Suite 101, New York, NY 10014. (“Touchcast”, “we”, “us” or “our”). Our Data Protection Officer is Darin Grant – email@example.com.
1. Personal Data We Collect From You
“Personal Information” means any information about an individual from which that person can be identified, whether indirectly or directly. It does not include data where the identity of that individual has been removed or anonymised.
Personal information you give us. This is information about you that you give us by creating and authenticating a Touchcast account (“Account”) through any of the Services, by filling in the “Contact Us” form on the Site or by corresponding with us by phone, email or otherwise.
This Personal Information may include your name and email address age and individual preferences. It may include the zip/postal code and GPS location that you provide to the third party payment processors that collect and manage payment on our behalf (We will not, however, collect store or handle any of your payment information. This information will be transmitted directly to the payment processors (currently Chargebee and Stripe). You will have a direct relationship with such payment processors and they will process your Personal Information (as data controllers in accordance with their respective privacy policies).
Personal Information that we collect automatically about you. With regard to each of your visits to any of the Services we may automatically collect the following information, which may be Personal Information as it may (particularly when combined) enable you to be identified:
- Technical information (or ‘log data’), including the Internet protocol (IP) address used to connect your computer or other device to the Internet, browser type and version, time zone setting, browser plug-in types and versions, user preferences, operating system and platform; and
- Information about your use of the Services, including the dates and times you use any of the Services, the website you were visiting before you came to the Site, pages visited, length of visits to pages on the Site (or within the application), page interaction data (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, searches you make on the Site and any phone number used to call the contact phone numbers we provide.
Special categories of data: The Services is not designed to collect any special categories of Personal Information about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). To the extent that you provide any content to us that comprises any such special categories of data, you explicitly consent or confirm that you have explicit consent from the relevant individual to our collecting such data and processing it (including transfer) in accordance with this Policy.
vApp Content: If you create a video application (a “vApp”) using the Touchcast Services, the images, videos, PDF, and other media contained in the vApp (“vApp Media”) is stored locally on your device’s “app sandbox” while the vApp Media is in use. Therefore, any vApp Media includes any Personal Information, then it will be stored locally in the “app sandbox” during use and shall immediately be removed upon exit from the product. We do not generally access vApps or any information contained therein but reserve the right to do so in furtherance of our obligations under our agreement, including, for example, where necessary to deliver functionality troubleshooting and/or to provide support services.
2. How We Use Your Personal Information
We will only use your Personal Information when the law allows us to do so. Most commonly, we will use your Personal Information in the following circumstances:
- Where we need to, to perform the contract we are about to enter into or have entered into with you and/or the organization which employs or engages you, including the Terms of Service; or
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests; or
- Where we need to comply with a legal or regulatory obligation.
Generally we do not rely on consent as a legal basis for processing your Personal Information other than in relation to sending party direct marketing communications to you via email. We will get your express opt-in consent before we send you any marketing communications.
You can ask us to stop sending you marketing messages at any time by contacting us at firstname.lastname@example.org or following the unsubscribe options contained within marketing emails.
Specifically, we use Personal Information held about you in the following ways:
Personal information you give to us. We will use this Personal Information:
- to set up an Account for you;
- for integration with other approved applications approved by Touchcast;
- to respond to any enquiry you should make;
- to provide the Services;
- to complete any transactions you seek to enter in with us; and
- to better understand how the Services are used and improve the Services; and
- to notify you about any changes to the Services.
It is important that the Personal Information we hold about you is accurate and current. Please keep us informed if your Personal Information changes during your relationship with us.
Personal information we automatically collect about you. We will use this Personal Information:
- to deliver the Services effectively and for internal operations, including technical administration, troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to provide you with a better experience, to improve the quality, value, functionality and general user friendliness of the Services, and to analyze and understand how the Services are used;
- as part of our efforts to keep the Services safe and secure;
- to serve you with advertisements and other information appropriate to your interests, including making suggestions and recommendations to you about services we offer that may interest you; and
- to serve any aspect of the Services to you according to your preferences or restrictions.
3. Disclosure Of Your Personal Information
We may disclose your Personal Information, as follows.
User Content. Once you become a registered Touchcast user, the general public will be able to view your user profile as well as your comments, likes, and any other posts you make on the Site or Applications relating to videos and other materials (“Content”) posted or distributed by other Touchcast users. Any Content that you create via the Services and voluntarily disclose for posting to any of the Services becomes available to the public, as controlled by any applicable privacy settings that you set. You can change your privacy settings on the Service by changing your profile settings. Once you have shared Content or made it public, that Content may be re-shared by other users. If you remove Content that you posted to the any of the Services, copies may remain viewable in cached and archived pages of those Services, or if other users or third parties have copied or saved that information.
Aggregated data. We may share aggregated information that does not include Personal Information (including technical information, and information about your use of the Services, as set out above) with third parties for industry analysis, demographic profiling, and other purposes. Any aggregated information shared in these contexts will not enable you to be identified personally, either directly or indirectly.
Service Providers. We may employ third party companies and individuals to facilitate our Services, to provide the Services on our behalf, to perform website and application-related services, including, without limitation, maintenance services, database management, payment processors, web analytics and improvement of the website’s and application’s features, or to assist us in analyzing how our Services. These third parties may have access to your Personal Information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. Where we appoint such third parties, we implement contractual or other safeguards to ensure that such service providers are bound by similar obligations in relation to your Personal Information and agree to abide by all applicable privacy and data protection laws.
Compliance with Laws and Law Enforcement. Touchcast cooperates with government and law enforcement officials and private parties to enforce and comply with the law. We will disclose any information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary or appropriate to respond to claims and legal process (including but not limited to subpoenas), to protect the property and rights of Touchcast or a third party, to protect the safety of the public or any person, or to prevent or stop activity we may consider to be, or to pose a risk of being, illegal, unethical, or legally actionable activity.
Business Transfers. Touchcast may sell, transfer, or otherwise share some or all of its assets, including your Personal Information, in connection with a merger, acquisition, reorganization or sale of assets or in the event of bankruptcy.
First and third party cookies. We set cookies (first party cookies) on web pages on the Services, however, where we require additional Personal Information or services, we also allow other companies to host cookies on our web pages (third party cookies). These partner companies have been carefully selected by us and are required to meet contractual obligations they have with us.
- Strictly Necessary cookies. These cookies are used for technical reasons and are necessary to enable the Services to operate efficiently so that you can navigate the Services with ease and use specific features. These include, for example, cookies that help us to debug any errors. If these cookies are blocked or disabled, some of the Services may not operate effectively.
- Performance cookies. These cookies are used to obtain statistics about the number of users of the Services and how such users interact with the Services. These cookies collect Personal Information that is aggregated and therefore cannot be used to ascertain an individual’s identity. Such Personal Information allows us to continuously improve the Services to provide users with a better online experience.
- Functionality cookies. These cookies are used to improve the functionality of the Services and make it easier to use. They help us to identify you as a repeat user of the Services and help us remember your preferences (for example, your choice of language or region), improving your user experience.
- Analytical. These cookies record your visit to our Services, the pages you have visited and the links you have followed and are used to generate usage statistics and help us to understand user preferences and how improve delivery of the Services.
We may share Personal Information that we collected through cookies, in aggregated form, with carefully selected third parties for the purposes set out above, unless you disable or block cookies as set out below.
How do I control my cookie settings on my computer or device? Please be aware that if you decide to disable or block cookies, parts of the Site may not function correctly, or at all.
Should you choose however to disable or block our cookies on your computer or other device you will need to do this through your browser. Click on the ‘Help’ menu on your particular browser to learn how to manage your cookie preferences. Alternatively, you can visit www.aboutcookies.org or www.youronlinechoices.eu (EU specific) for comprehensive Personal Information on how to manage cookies.
Google Analytics. We use Google Analytics to collect information about how users use the Site. The information generated by the cookie about your use of the Site will be transmitted to and stored by Google on servers in the United States.
5. Where we store your personal data.
The data that we collect from you will be transferred to, and stored in the US. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy. All Personal Information you provide to us is stored on our secure servers.
Unfortunately, the transmission of Personal Information via the internet is not completely secure. While we do our best to protect your Personal Information, we cannot guarantee the security of your data transmitted to us over the email, or through the ‘Contact Us’ form on the Site; any transmission is at your own risk. Once we have received your Personal Information, we will use strict procedures and security features to try to prevent unauthorised access.
Your Personal Information may be transferred to, and maintained on, computers located outside of your state, province, country or other jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. We will implement adequate safeguards to protect your Personal Information prior to any such transfers.
6. Your rights (all registered users)
As a registered user, you may review, update, correct or delete the Personal Information linked to your Account by contacting us. If you completely delete all such information, then your Account may become deactivated. If you request to terminate your Account, we will retain the Personal Information in case you would like to reactivate your Account in the future. If you would like us to delete your Personal Information in our system, please contact us at email@example.com with a request that we delete your Personal Information from our database. We will use commercially reasonable efforts to honor your request. We may retain an archived copy of your records as required by law or for legitimate business purposes.
7. Your rights (EEA Users Only)
You have a number of rights in relation to how we process your Personal Information. These include:
- The right to access the Personal Information that we may hold about you;
- The right to rectify any inaccurate Personal Information that we may hold about you;
- The right to have your Personal Information erased in certain circumstances, for example, where it is no longer necessary for us to process your Personal Information to fulfill our processing purposes; or where you have exercised your right to object to the processing;
- The right to restrict the processing of your Personal Information where, for example, the information is inaccurate or it is no longer necessary for us to process such information or where you have exercised your right to object to our processing;
- The right to object to the processing of your Personal Information which may be exercised in certain circumstances, for example, where we are processing your Personal Information for direct marketing purposes, or where your own legitimate interests outweigh ours; and
- The right to have your data ported to a new service provider if you no longer wish to use the Services.
You can exercise any of these rights any time by contacting us at firstname.lastname@example.org.
Users in other jurisdictions may have similar rights, which shall be exercisable by contacting us.
No fee usually required.
You will not have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
What we may need from you.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal Information (or to exercise any of your other rights). This is a security measure to ensure that personal Information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
We will only retain your personal Information for as long as necessary to fulfill the purposes we collected it for, as set out in this Policy.
To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the personal Information, the potential risk of harm from unauthorized use or disclosure of your personal Information, the purposes for which we process your personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.
For further information on retention periods, please contact us using the details provided at the end of this Policy.
Touchcast uses commercially reasonable safeguards to help keep the information collected through the Service secure and Touchcast reasonable steps (such as requesting a unique password) to verify your identity before granting you access to your account.
We will make any legally required disclosures of any breach of the security, confidentiality, or integrity of your Personal Information to you via email or conspicuous posting on the Site or via the application in the most expedient time possible and without undue delay. Where permitted, we may delay making such a notification in: (i) to meet the legitimate needs of law enforcement or (ii) to impose any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
10. Other Websites
Our Services may contain links to other websites. If you choose to visit an advertiser by clicking on a banner ad or other type of advertisement, or click on another third party link, you will be directed to that third party’s website. The fact that we link to a website or present a banner ad or other type of advertisement is not an endorsement, authorization, or representation of our affiliation with that third party, nor is it an endorsement of their privacy or information security policies or practices. We do not exercise control over third party websites. Those third party websites may place their own cookies or other files on your computer, collect data, or solicit Personal Information from you. Other sites follow different rules regarding the use or disclosure of the Personal Information you submit to them. We encourage you to read the privacy policies or statements of the other websites you visit.
The Services are not directed to persons under 13. We do not knowingly collect Personal Information from children under 13. If a parent or guardian becomes aware that his or her child has provided us with Personal Information without his or her consent, he or she should contact us at: email@example.com. If we become aware that a child under 13 has provided us with Personal Information, we will delete such information from our files.
12. Third Party Data Processors
Please note that in some cases, described below, you will need to interact with a third party data processor (“Third Party Data Processor”) in order to sign up or use the product. In each of these cases outlined below, you are dealing directly with the Third Party Data Processor and it alone is responsible for the data that you provide. In each case, Touchcast does not receive any of the information processed, with the exception of: (i) the name or email address needed to identify or authenticate you as a user, and (ii) your relationship to the transaction. In these cases, you will be notified when you are no longer dealing directly with Touchcast, such as:
- Product Payment. Payment information is processed directly by Stripe or Chargebee. Touchcast does not process or store any of this information, and only receives the necessary information in return (such as your name, and a confirmation that payment has been made at the current time).
- Authentication. Authentication via a third party login service, such as Google, Microsoft, LinkedIn, or Facebook, is conducted directly through our SSO provider, Okta. TouchCast does not process or store any of this information, with the exception of your name and email address, and only receives the necessary information in return (such as your name, email address, and a confirmation that you have been authenticated at the current time).
Changes To Our Policy
Any changes we make to our Policy in the future will be posted on this page and, where you continue to hold an account with us, notified to you by email. Please check back frequently to see any updates or changes to our Policy.
Questions, comments and requests regarding this Policy should be addressed to firstname.lastname@example.org.
EEA Users only: Should you have cause to complain about how we handle your Personal Information, please contact us in the first instance. We will do our best to resolve your concern. Alternatively, you may prefer to submit a complaint directly to your national data protection supervisory authority.