Privacy policy
The privacy policy of AppYourself
.
AppYourself collects personal data from its users.
Provider and responsible party
.
AppYourself GmbH – Westfälische Straße 49 – 10711 Berlin – Germany
E-mail address of the provider: privacy@appyourself.net
Data protection officer: Dr. Nils Haag, intersoft consulting services AG
Types of data collected
.
Personal data that AppYourself processes independently or through third parties include: Cookie, Usage Data, Various Types of Data, Email, First Name, Last Name and Company Name.
Full details of each type of personal data processed are provided in the designated sections of this Privacy Policy or selectively through explanatory text displayed prior to data collection.
Personal data may be provided voluntarily by the user or, in the case of usage data, may be collected automatically when AppYourself is used.
Unless otherwise stated, the provision of all data requested by AppYourself is mandatory. If the user refuses to provide the data, this may result in AppYourself being unable to provide its services to the user. In cases where AppYourself expressly states that the provision of personal data is voluntary, users may choose not to provide such data without any consequences for the availability or functioning of the service.
Users who are unclear about which personal data is mandatory may contact the provider.
Any use of cookies – or other tracking tools – by AppYourself or third party service providers used by AppYourself is for the purpose of providing the service requested by the user and any other purposes described in this document and, if any, in the Cookie Policy.
Users are responsible for all third party personal data obtained, published or disclosed by AppYourself and confirm that they have obtained consent to the transfer of any third party personal data to AppYourself.
Type and place of data processing
.
Methods of processing
.
The Provider processes User Data in a proper manner and takes appropriate security measures to prevent unauthorised access and unauthorised transmission, modification or destruction of data.
Data processing is carried out by means of computers or IT-based systems in accordance with organisational procedures and practices that are specific to the stated purposes. In addition to the data controller, other parties may operate AppYourself internally (human resources, sales, marketing, legal, system administrators) or externally – and in that case, where necessary, designated by the data controller as processors (such as technical service providers, delivery companies, hosting providers, IT companies or communications agencies) – and may therefore have access to the data. An up-to-date list of these parties can be requested from the provider at any time.
Legal basis of processing
.
The provider may only process users’ personal data if one of the following applies:
-
- The users have given their consent for one or more specified purposes. Note: In some jurisdictions, the provider may be allowed to process personal data until the user objects to such processing (“opt-out”) without relying on consent or any other of the following legal bases. However, this does not apply if the processing of personal data is subject to European data protection law;
.
-
- the collection of data is necessary for the performance of a contract with the user and/or for pre-contractual measures arising therefrom;
.
-
- the processing is necessary for compliance with a legal obligation to which the provider is subject;
- the processing is related to a task carried out in the public interest or in the exercise of official authority vested in the provider;
- the processing is necessary for the purposes of the legitimate interests of the provider or a third party;
.
In any case, the provider will be happy to provide information on the specific legal basis on which the processing is based, in particular whether the provision of personal data is a legal or contractual obligation or a prerequisite for the conclusion of a contract.
Place
Data will be processed at the Provider’s office and at any other location where the entities involved in data processing are located.
Depending on the location of the users, data transfers may involve the transfer of the user’s data to a country other than their own. To find out more about where the transferred data is processed, users can consult the section detailing the processing of personal data.
Users also have the right to be informed about the legal basis of the transfer of data to a country outside the European Union or to an international organisation governed by international law or established by two or more countries, such as the UN, and about the security measures taken by the provider to protect their data.
If such a transfer takes place, the User can find out more by reviewing the relevant sections of this document or by contacting the Provider using the information provided in the contact section.
Storage period
.
Personal data will be processed and stored for as long as is necessary for the purpose for which it was collected.
Therefore:
-
- Personal data collected for the purpose of fulfilling a contract concluded between the provider and the user will be stored until the complete fulfilment of this contract.
.
- Personal data collected for the purpose of safeguarding the provider’s legitimate interests will be retained for as long as necessary to fulfil those purposes. Users can obtain more detailed information about the provider’s legitimate interests in the relevant sections of this document or by contacting the provider.
In addition, the provider is permitted to store personal data for a longer period of time if the user has consented to such processing, as long as the consent is not revoked. Furthermore, the provider may be obliged to retain personal data for a longer period of time if this is necessary to comply with a legal obligation or by order of an authority.
After the retention period has expired, personal data will be deleted. Therefore, the right of access, the right of deletion, the right of rectification and the right of data portability cannot be exercised after the retention period has expired.
Purposes of processing
.
Personal data about the user is collected to enable the provider to deliver the services. In addition, data is collected for the following purposes: Heat mapping and session recording, interacting with online survey platforms, managing user databases, handling payments, analytics, tag management, interacting with external social networks and platforms, remarketing and behavioural targeting, interacting with data collection platforms and other third parties, contacting the user, interacting with live chat platforms, managing contacts and sending messages, testing the performance of content and features (A/B testing) and monitoring infrastructure.
Users can find more detailed information about these processing purposes and the personal data used for each purpose in the relevant sections of this document.
Detailed information on the processing of personal data
.
Personal data is collected for the following purposes using the following services:
The rights of users
.
Users may exercise certain rights in relation to their data processed by the Provider.
In particular, users have the right to do the following:
-
- Revoke consent at any time. If the user has previously consented to the processing of personal data, they may revoke their own consent at any time.
- Object to the processing of their data. The user has the right to object to the processing of their data if the processing is based on a legal basis other than consent. Further information on this is provided below.
- Receive information regarding their data. The user has the right to know whether the data is being processed by the provider, to receive information about individual aspects of the processing and to obtain a copy of the data.
- Review and rectify. The user has the right to check the accuracy of his or her data and request that it be updated or rectified.
- Request restriction of the processing of their data. Users have the right to restrict the processing of their data in certain circumstances. In this case, the provider will not process the data for any purpose other than storage.
- Request erasure or other removal of personal data. Users have the right, in certain circumstances, to request that the provider erase their data.
- Receive their data and have it transferred to another controller. Users have the right to receive their data in a structured, commonly used and machine-readable format and, if technically possible, have it transferred to another controller without hindrance. This provision applies where the data are processed by automated means and the processing is based on the user’s consent, on a contract to which the user is party or on pre-contractual obligations.
.
- Submit a complaint. Users have the right to submit a complaint to the competent supervisory authority.
Details on the right to object regarding processing
.
Where personal data are processed in the public interest, in the exercise of a public authority conferred on the provider or for the purposes of the provider’s legitimate interests, the user may object to such processing by providing a justification relating to his or her particular situation.
Users are informed that they may object to the processing of personal data for direct marketing at any time without giving reasons. Users can find out whether the provider processes personal data for direct marketing purposes in the relevant sections of this document.
How the rights can be exercised
.
All requests to exercise User Rights may be made to the Provider via the contact details provided in this document. Requests may be exercised free of charge and will be dealt with by the Provider as soon as possible and within one month at the latest.
Cookie Policy
.
AppYourself uses cookies. To learn more and get a more detailed knowledge about cookies, users can read the specific document here: Cookie Policy.
More information about data collection and processing
Legal measures
.
The User’s personal data may be processed by the Provider for law enforcement purposes within or in preparation of legal proceedings arising from the improper use of AppYourself or its associated services.
The user declares to be aware that the provider may be obliged by the authorities to hand over personal data.
Further information about the user’s personal data
.
In addition to the information set out in this Privacy Policy, AppYourself may provide the User, upon request, with further contextual information relating to specific services or to the collection and processing of personal data.
System Logs and Maintenance
.
AppYourself and third-party services may collect files that record interaction taking place through AppYourself (system logs) or use other personal data (e.g. IP address) for operational and maintenance purposes.
Information not included in this privacy statement
.
Further information about the collection or processing of personal data can be requested from the provider at any time via the contact details listed.
How “Do Not Track” requests are handled
.
AppYourself does not support do-not-track requests (“Do Not Track”) by web browsers.
For information on whether integrated third-party services support the Do Not Track protocol, users should refer to the privacy policy of the relevant service.
Changes to this privacy policy
.
The Provider reserves the right to make changes to this Privacy Policy at any time by notifying its users accordingly on this page and, where applicable, via AppYourself and/or, where technically and legally possible, by sending a notice to users via one of the contact details available to the Provider. Users are therefore advised to visit this page regularly and to check the date of the last change indicated at the bottom of the page.
Where changes affect a data use based on the user’s consent, the provider will obtain new consent where necessary.