2. What kinds of information do we collect?
In general, we collect personal data directly from you in view of ensuring your control over the type of information you provide to us.
Please bear in mind that personal data is considered any data that could directly or indirectly identify you, as a person. Although a personal data such as your products/ services preferences collected through our cookies is not considered, per se, a personal data because it could not lead indirectly to your identification. For example, such data, only combined with other data (for example any data that you provide to us on social media) could eventually identify you.
Even so, you have nothing to worry about as we have in place all the security measures to protect any personal data that we collet through our website, www.z3.xyz
To easily identify the personal data we process, we have combined them in several categories according to the purpose of processing.
Z3 processes the users' personal data who visit the Platforms, as follows:
CATEGORY 1 - ENROLLMENT IN THE TOKHIT COMMUNITIES
Personal data - first and last name, phone number, and e-mail address;
The purpose of processing - the personal data are processed for the purpose of allowing you to enjoy all benefits as a member of the Z3 community;
The legal basis - art. 6 para. 1 letter a) of the GDPR Regulation, which allows us to process personal data based on your consent given to us.
The collection method - directly from you, when you access our website and fill out the forms to 'Join the Z3 community', 'Get Access to the App', and/ or 'Buy Tokens'
The retention period - as a rule we try to keep less data as possible, and in this case, we will be keeping your personal data as long as you are a member of Z3 community.
CATEGORY 2 - USING OUR WEBSITE
The purpose of processing - the personal data are processed for the purpose of providing you with personalized and tailored content based on the data that our cookies collected from you;
The legal basis - art. 6 para. 1 letter a) of the GDPR Regulation, which allows us to process personal data based on your consent given to us. The collection method - directly from you, when you access and use our website; The retention period - as a rule we try to keep less data as possible.
CATEGORY 3 - SOCIAL MEDIA PLATFORMS
Personal data - related to each user, such as: user's social media accounts; any other information users decide to provide us with when they contact us on the social media platforms; any other information users decide to provide us with when they contact us by e-mail; comments and/or posts on our profiles;
Given that the internet is not a safe space, please do not send us or limit, as much as possible, the personal data communicated through social platforms or e-mail.
The purpose of processing - the personal data mentioned above are processed for customer support purposes;
The legal basis: Art. 6 para. 1 letter b) of the GDPR Regulation, which allows us to process personal data when necessary, for performance of a contract or for the steps prior to its conclusion;
The collection method - personal data are collected directly from users when they decide to contact us;
The retention period - personal data are stored for the purpose of proving the fulfilment of contractual obligations between the parties for a period between 30 days and 1 year, depending on the nature of the request (complaint, request for guarantee, contractual request, general request, etc.);
Generally, personal data are kept for a limited period according to the purpose of the processing and the legal provisions applicable to each category of data.
TOKHIT ensures the proper deletion of personal data when such processing is no longer necessary.
3. Use of personal information
To provide our service we will use your personal information in the following ways:
- To comply with law;
- We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities;
- For compliance, fraud prevention, and safety;
We may use your personal information to protect, investigate, and deter against fraudulent, unauthorized, or illegal activity.
4. The disclosure of your personal to third parties
Throughout its normal course of business Z3 will not disclose or transfer, for direct marketing purposes, your personal data to third parties, regardless if such parties are located in Romania, in EU or outside EU.
Z3 employees having access to personal data have been trained to observe the security and confidentiality of the personal data they have access to in performing the business activity. Z3 employees' access to personal data is limited to the information required in performing their specific tasks.
We perform our daily activities at the highest standards thus sometimes we chose to cooperate with other companies in order to facilitate several technical or administrative processes such as: e-mail hosting services, storing data, sever hosting, legal services etc.
In case we decide to contract third parties for the supply of specific services, we will ensure that such third party complies with the provisions of GDPR and we will provide all information required for the proper performance of their services.
Your personal data may be communicated to governmental authorities and/or law enforcement agencies if required by the applicable law.
5. Which are your rights and how can you effectively exercise them?
Z3 as data controller, ensures technical and organizational measures to be sure that your rights (as a data subject) are observed:
Right of access
You have the right to obtain the confirmation as to whether or not personal data concerning you are being processed by us, and, where that is the case, access to your personal data and information on how they are processed.
Right to data portability
You have the right to receive some of your personal data, which you have provided to us, in a structured, commonly used and machine-readable format and you have also the right to transmit those data to another controller without hindrance from us, where technically feasible.
Right to object
You have the right to object to processing of your personal data, when processing is necessary for the performance of a task carried out in the public interest or for the purposes of the legitimate interests pursued by us. You have the right to object at any time if your personal data are being processed for direct marketing purposes.
Right to rectification
You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. The rectification shall be communicated to each recipient to whom the data was sent unless this proves impossible or involves disproportionate (demonstrable) efforts.
Right to erasure ('right to be forgotten')
You have the right to obtain from us the erasure of personal data concerning you without undue delay and we have the obligation to erase your personal data without undue delay where one of the following grounds applies: your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraws consent on which the processing is based and there is no other legal ground for the processing; you object to the processing and there are no overriding legitimate grounds for the processing; your personal data have been unlawfully processed; your personal data have to be erased for compliance with a legal obligation; your personal data have been collected in relation to the offer of information society services.
Right to restriction of processing
You have the right to obtain from us restriction of processing where one of the following applies: you contest the accuracy of your personal data, for a period enabling us to verify the accuracy of your personal data; the processing is unlawful and you oppose the erasure of your personal data and request the restriction of their use instead; we no longer need your personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims; you has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
Right not to be subject to a decision based solely on automated processing
You have the right not to be subject to a decision solely based on automated processing, including profiling, which produces legal effects concerning the data subject or similarly affects the data subject in a significant manner. Therefore, we hereby state that Z3 does not use applications, algorithms, artificial intelligence or automatic process to make automatic decisions (without human intervention) that produces legal effects.
To exercise your rights listed above you can send us your request (accompanied by your contact details) electronically to the e-mail address email@example.com.
6. What security precautions does Z3 takes to protect your personal data?
We have assumed the responsibility to implement proper technical and organizational measures regarding the protection of privacy and security of your personal data. We have taken all reasonable measures to protect your Personal Data from damage, loss, misuse, unauthorized access, alteration, destruction, or disclosure, as following:
- People who have access to our filing system are only those nominated by Z3. To accesses the system, they use individual accounts and passwords which are changed periodically.
- All our employees, collaborators and service providers who are in contact with personal data must act in accordance with the principles and policies regarding to the processing of personal data. They were informed and they have assumed to respect of the GDPR by signing the Data Processing Agreements or as an effect of the law.
- Our employees and collaborators access personal data for the performance of their professional duties and only in accordance with the stated purpose of data collection.
- Computers from which the filing system is accessed are passwordprotected and have antivirus, antispam and firewall security updates.
- Personal data is printed only by authorized users, if it is necessary to perform our activity or to fulfil our legal obligations. Please also select carefully what personal data do you choose to submit thinking that the internet or e-mails are not impenetrable spaces, and a technical error can cause an unhappy event anytime with respect to your personal data.
7. What is our legal basis for processing data?
We collect, use and share the data that we have in the ways described below:
- We collect, use and share the data that we have in the ways described below:
- as necessary to fulfill our Terms and Conditions; • consistent with your consent, which you may revoke at any time through;
- as necessary to comply with our legal obligations;
- to protect your vital interests, or those of others;
- as necessary in the public interest; and
- as necessary for our (or others') legitimate interests, including our interests in providing an innovative, personalized, safe, and profitable service to our users and partners, unless those interests are overridden by your interests or fundamental rights and freedoms that require protection of personal data.
8. How can you exercise your rights provided under the GDPR?
According to the GDPR regulation, considering the personal data processed by our platform, we (Z3) are considered data controller and our visitors and users are considered data subjects.
Z3 observes the confidentiality and security of the personal data constantly ensuring that all personal data are processed only for specific, explicit and legal purposes, according with the principles and provisions of the GDPR.
Under the General Data Protection Regulation, you have the right to access, rectify, port and erase your data. You also have the right to object to and restrict certain processing of your data.
Definitions according to the GDPR
NSAPDP represents The National Supervisory Authority for Personal Data Processing, the Romanian independent public authority responsible for the compliance with the protection of personal data requirements;
Personal data represents any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Processing represents any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Restriction of processing represents the marking of stored personal data with the aim of limiting their processing in the future;
Controller represents the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by the European Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
Processor represents a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Recipient represents a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether it is a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with the European Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
Third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
Data Breach represents a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. This means that a breach is more than just losing personal data.
9. How do we respond to legal requests or prevent harm?
We access, preserve and share your information with regulators, law enforcement or others:• In response to a legal request, if we have a good-faith belief that the law requires us to do so. We can also respond to legal requests when we have a good-faith belief that the response is required by law in that jurisdiction, affects users in that jurisdiction, and is consistent with internationally recognized standards. • When we have a good-faith belief it is necessary to: detect, prevent and address fraud, violations of our terms or policies, or other harmful or illegal activity; to protect ourselves, you or others, including as part of investigations or regulatory inquiries; or to prevent death or imminent bodily harm.
10. Links to other websites
On our app you may find links to other organizations. This Privacy Notice do not cover the personal data processed by them.
If you decide to access other organization's links, we encourage you to carefully read their Privacy Notices which should be found on their websites.
Believing that we are constantly developing our services, we are confident that our platform may soon have new functions, so our Privacy Notice will be updated accordingly.
In order to keep you informed, we always publish the latest version of the Privacy Notice on our app, without any specific notice in this respect.
We assure you that the way we collect and process your personal data is in accordance with the provisions of the GDPR Regulation.
12. Information concerning Data Protection Supervisory Authority
If you consider that your rights provided by Regulation no. 679/2016 have been violated, you can address directly to us or to our Data Protection Supervisory Authority: National Authority for the Supervision of the Processing of Personal Data (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal) 'ANSPDC' by submitting a complaint.
Contact details of the authority:
Link for compliances: https://www.dataprotection.ro/? page=Plangeri_pagina_principala
Contact link: https://www.dataprotection.ro/?page=contact&lang=ro
Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, cod postal 010336, Bucuresti, Romania
13. How to contact us with questions
If you have questions about this policy, you can contact us as described below:
TOKHIT APP SRL, located in Cluj Napoca, Cluj County
Street Mircea Eliade 2A, Floor P, Ap. 7