The privacy of our customers personal data is important to Bluebrain Digital. This Policy describes the rules according to which Bluebrain Digital processes the personal data of any person using the Bluebrain Digital’s website https://bluebrain.digital, mobile apps and any services offered by Bluebrain Digital.
- General DefinitionsBluebrain Digital
Service provider who needs to process customer’s personal data for the provision of service. Depending of the service the service providers are the following:
- Bluebrain Digital OÜ (registry code 14961625, address Sepapaja 6, Tallinn, 15551, Estonia)
- Affiliate of the forenamed service provider whose company information is provided in the respective
Any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
Personal Data processed by Bluebrain Digital is described under Section 3ProcessingAny operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destructionController
A person who alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
Depending of the service the Controller of the Customer’s Personal Data is:
- Bluebrain Digital OÜ
A person who Processes Personal Data on behalf of the Controller
In the course of provision of Service, Bluebrain Digital may act as Processor by Processing Personal Data on behalf of its Customer or Customer’s legal entity. However, this Policy shall not regulate the Bluebrain Digital’s actions as ProcessorServiceAny services provided by Bluebrain Digital via website https://bluebrain.digital and Bluebrain Digital mobile apps.
- Policy ApplicabilityThis Policy applies to Personal Data Processing where Bluebrain Digital acts as a Controller. Any personal data Processing conducted on behalf of the Customer or his legal entity is subject to an additional data processing agreement signed between Bluebrain Digital and the legal person controlled by the Customer.
- Personal Data being collectedBluebrain Digital Processes the following Personal Data about the Customer:
- Personal Details – full name (surname and given name), gender, personal identification code, date of birth, nationality, contact postal address, e-mail address, mobile phone number, bank where the personal bank account exists;
- Identification Data – data retrieved from the copy of a passport, such as document number, issue date, expiry date and issuing entity, photo, URL of a Portfolio or LinkedIn profile;
- Verification Data – data which Bluebrain Digital collects for the purpose of conducting Customer due diligence under applicable anti-money laundering laws.
- Background Data – data Bluebrain Digital collects and Processes for the purpose of conducting Customer adverse media checks via open sources;
- Profile Data – Customer’s Google profile data, such as name, e-mail address, language preference and profile picture;
- Payment Data – data concerning payments for Bluebrain Digital’s Service, such as account number (IBAN), account holder name, bank name, transaction details, If the Customer chooses to pay for the Service by credit card or by PayPal, his/her payment details are not stored by Bluebrain Digital and therefore cannot be accessed by Bluebrain Digital.
- Device Data – information regarding the device on which the Customer is using the Bluebrain Digital’s website/app, including the device’s model, name or any other identifier and the IP address;
- Preference Data – Customer’s preferences in the Bluebrain Digital’s website/app;
- Customer Support Data – communication between Bluebrain Digital and the Customer (inquiries submitted via the website, email, social media or chat);
- Usage Data – data about Customer’s interaction in Bluebrain Digital’s website/app.
- Sources of Personal Data collectionMajority of Customer’s Personal Data Processed by Bluebrain Digital is collected directly from the Customer. However, Bluebrain Digital may collect Customer’s Personal Data also from third party sources, such as databases of financial sanctions and people subject to international financial sanctions and databases of politically exposed people. Some of these databases are publicly available and some of them are not.
- Purposes for collecting and Processing Customer’s Personal DataPersonal Data collected by Bluebrain Digital is Processed for the purposes established in the law or as described herein, including but limited for the following purposes:
- Contractual Purpose – Bluebrain Digital needs to Process Customer’s Personal Data in order to enter into service agreement with the Customer and to provide Service to Customer;
- Compliance Purpose – Bluebrain Digital needs to Process Customer’s Personal Data in order to perform obligations under applicable laws, such as to comply with anti-money laundering requirements, and combat fraud, ensure the fulfilment of international financial sanctions, comply with the lawful inquiries and orders of public authorities with whom Bluebrain Digital is obligated to cooperate;
- Analytical Purpose – Bluebrain Digital needs to Process Customer’s Personal Data in order to manage, analyse and improve the Service, website and app;
- Marketing Purpose – Bluebrain Digital needs to Process Customer’s Personal Data in order to send relevant promotional information to the Customer about Bluebrain Digital services and the related offerings by third parties we work with, if the Customer has granted an explicit consent to use his/her Personal Data for this purpose;
- Personalization Purpose – Bluebrain Digital needs to Process Customer’s Personal Data in order to personalize the Service and the content provided to the Customer;
- Communication Purpose – to contact the Customer for administrative purposes such as customer service, address technical or legal issues related to the Service provided, or share updates and notifications about the Service;
Bluebrain Digital shall not use Customer’s Personal Data for any other purpose incompatible with the purposes outlined above or required, permitted or authorized by law.
Customer is not subject to statutory obligation which obligates Customer to provide Personal Data described herein to Bluebrain Digital. The collection of certain Personal Data referred herein may be required under the law and/or inevitably necessary for the provision of service to the Customers (such as data necessary for the verification of the Customer). Failure to provide data may result in adverse consequences, such as, Bluebrain Digital’s inability to comply with our obligations under law. The Customer is welcome to ask for clarifications regarding the obligation to submit any specific Personal Data and also about possible consequences arising from the failure to provide the Personal Data.
- Automated decision makingBluebrain Digital provides various online Service’s for the Customers active in the certain field of activities. Not all fields of activities are supported by Bluebrain Digital’s services. Bluebrain Digital is using automated decision making in the pre-contractual Processing in order to establish sufficiently whether the Customer is eligible to use Bluebrain Digital’s services.Automated decision making refers to a decision which is taken solely on the basis of automated Processing of Customer’s Personal Data. This means Processing using, for example, software code or an algorithm, which does not require human intervention.
- Legal grounds for ProcessingBluebrain Digital is relying on the following legal grounds when Processing Customer’s Personal Data:
- Processing is necessary for the performance or entry into a contract between Customer and Bluebrain Digital (GDPR article 6 (1) (b)), Bluebrain Digital is Processing Personal Data for Contractual Purpose under contract entered into between Bluebrain Digital and Customer;
- Processing is necessary for compliance with a legal obligation to which Bluebrain Digital is subject (GDPR article 6 (1) (c)). Bluebrain Digital is Processing Personal Data for Compliance Purpose under legal obligations to which Bluebrain Digital is subject to;
- Processing is necessary for the purposes of the legitimate interests pursued by Bluebrain Digital (GDPR article 6 (1) (f)). Bluebrain Digital is Processing Personal Data for Analytical or Personalization Purpose under legitimate interest;
- Customer has granted a consent to the Processing of his Personal Data (GDPR article 6 (1) (a)). Bluebrain Digital is Processing Personal Data for Marketing Purpose under Customer’s consent.
- Transfer of the Personal DataBluebrain Digital may transfer Customer’s Personal Data to third parties, such as:
- legal and regulatory authorities (e.g. commercial register) whom Bluebrain Digital is obligated to disclose Customer’s Personal Data under the law;
- server hosts who host Bluebrain Digital’s servers;
- identification service providers who help Bluebrain Digital verify Customer’s identity and acquire Verification Data;
- communication service providers who facilitate e-mails, calls, SMS messages and other communication between Bluebrain Digital and the Customer;
- customer support and customer management service providers;
- marketing service provider;
- Bluebrain Digital’s partner bank who providing banking services to the Customer or to the legal entity controlled by the Customer or any other financial service provider;
- Bluebrain Digital’s affiliate. i.e. any company that directly or indirectly controls Bluebrain Digital; any company that is directly or indirectly controlled by Bluebrain Digital; or any company that is controlled, directly or indirectly, by the ultimate parent company of Bluebrain Digital. Control shall mean owning more than fifty percent of the voting rights in a company or otherwise having the power to govern the financial and the operating policies or to appoint the management of a company;
- other parties involved with the provision of Bluebrain Digital’s Service (accountants, auditors, lawyers, IT systems suppliers and support, or any other outsourcing providers).
Bluebrain Digital has taken steps to ensure that these data recipients protect the confidentiality and security of Personal Data, and to ensure that Personal Data is Processed only for the provision of Service and in compliance with applicable law.
Such third parties may be located in countries outside of the European Economic Area (“EEA”) whose privacy regulations may differ and which are not subject to adequacy decisions of the European Commission. In those countries the security of the Personal Data (inc. protection against misuse, unauthorized access, disclosure, alteration or destruction) may not be ensured as it is secured in the European Union, due to the lack of adequate data protection level.
For example, Bluebrain Digital may transfer Customer’s Personal Data to the US, in which case Bluebrain Digital shall ensure that the recipient of the Personal Data is certified in accordance to the EU-US Privacy Shield entered by and between the US Department of Commerce and the European Commission. To learn more about the Privacy Shield program, please visit https://www.privacyshield.gov/
When transferring collected Personal Data outside of the EEA, Bluebrain Digital shall ensure the application of the appropriate safeguards. If the Customer wishes to receive a copy, please contact us as instructed below.
- SecurityBluebrain Digital will take appropriate legal, organisational, and technical measures to protect Personal Data consistent with applicable privacy and data security laws. Security measures shall be applied in order to protect Personal Data from involuntary or unauthorized Processing, disclosure or destruction.Upon transferring Personal Data to third parties, Bluebrain Digital will apply the following safeguards:
- Bluebrain Digital enters into a data processing agreement with the relevant third party;
- Bluebrain Digital makes sure that such third party undertakes to implement appropriate technical and organizational measures ensuring the Processing of Customer’s Personal Data in accordance with this Policy and applicable law;
- Bluebrain Digital makes sure that (a) the third party is established in a jurisdiction which the European Commission has recognized as ensuring an adequate level of personal data protection, or (b) the Processing of Customer’s Personal Data is subject to other appropriate safeguards stipulated in the GDPR.
- Integrity and retention of the Personal DataBluebrain Digital will retain Personal Data for the period required or permitted by applicable law, but no longer than it is reasonably necessary in order to achieve the purposes for which the Personal Data was collected.Bluebrain Digital takes reasonable steps to ensure that the Personal Data we Process is reliable for its intended use, accurate, and complete as necessary to carry out the purposes described herein.
- Customer’s rights in regarding to the collection of Personal DataCustomer has the following rights in relation to the Processing of his Personal Data:
- Request information – Bluebrain Digital has provided all information which the Customer has right to receive in this Policy. The valid version of the Policy is available in Bluebrain Digital’s website at any time.
- Right to access – Customer has the right to ask Bluebrain Digital to provide a copy of Customer’s Personal Data which Bluebrain Digital Process.
- Right to Rectification – Customer has the right to ask Bluebrain Digital to rectify Personal Data in case the data is incorrect or incomplete.
- Right to Erasure – Customer has the right to ask Bluebrain Digital to erase Personal Data, unless Bluebrain Digital is obliged to continue Processing Customer’s Personal Data under law or under a contract between the Customer and Bluebrain Digital, or in case Bluebrain Digital has other lawful grounds for the continued Processing of Personal Data.
- Right to Restriction – Customer has the right to ask Bluebrain Digital to restrict the Processing of his Personal Data in case the data is incorrect or incomplete or in case his Personal Data is Processed unlawfully.
- Right to Data Portability – Customer has the right to ask Bluebrain Digital to provide the Customer or, in case it is technically feasible, a third party, his Personal Data, which the Customer has provided to Bluebrain Digital and which is Processed in accordance with Customer’s consent or a contract between the Customer and Bluebrain Digital.
- Right to Object – Customer has the right to object to Processing his Personal Data in case there is a reason to believe that Bluebrain Digital has no lawful grounds for Processing the Personal Data.
- Right to withdraw Consent for the Processing of Personal Data – Customer is entitled to withdraw the consent granted for the Processing of Personal Data et any time. Withdrawal does not affect the lawfulness of the Processing conducted before the withdrawal.
- Right to File Complaints – Customer has the right to file complaints regarding Processing of his Personal Data.
In order to exercise any rights referred herein the Customer is required to submit a written application to Bluebrain Digital (Bluebrain Digital’s contact details can be find under Section 16). Bluebrain Digital has the right to decline this application by justifying the reasons for the refusal.
According to the article 12(3) of GDPR, Bluebrain Digital is obligated to respond to the application within 1 month. However, Bluebrain Digital will make its best efforts to respond to Customer’s request within 1 week.
- Cookies and tracking technologiesBluebrain Digital is using automatically collected information and other information collected within its website through cookies and similar technologies.Cookies are small text files that a website or its service provider transfers to the Customer’s computer hard drive through his website browser (if Customer allows) that enables the website’s or service provider’s systems to recognize Customer’s browser and capture and remember certain information. For example, cookies may help a website remember certain preferences the Customer has selected on the website, such as language preferences.
- Within the website Bluebrain Digital is using the following types of cookies:
- first-party cookies, which are stored to the Customer’s device by Bluebrain Digital. These cookies allow website owners to collect analytics data, remember language settings, and perform other useful functions that provide a good user experience;
- third-party cookies, which are stored to the Customer’s device by other service providers on Bluebrain Digital’s website. Bluebrain Digital may use third-party analytics tools (such as Google Analytics), to help us measure traffic and usage trends for the Bluebrain Digital’s Service. Web analytic service providers analyse the usage of the Bluebrain Digital website and services so that Bluebrain Digital could improve and amend our website/app and function thereof.
- Cookies are being used to serve the following purposes:
- to store authentication information and protect Personal Data from third parties;
- to personalize our Service, help remember Customer’s choices within the website, understand and save Customer’s preferences for future visits;
- to provide customized advertisements, content and information;
- to track Customer’s entries, submissions, and status in any promotional or other activities on the Service;
- to monitor and analyse the effectiveness of the Service;
- to compile aggregate data about site traffic and site interactions in order to offer better site experiences and tools in the future.
The Customer can delete or block cookies through his browser settings at any time. However, some cookies might be necessary for the functionality of the Bluebrain Digital Services and usage of the website. Therefore, the Customer understands that when blocking or deleting the cookies some features within the website might not function correctly. For more general information about cookies please see http://www.allaboutcookies.org
- Within the website Bluebrain Digital is using the following types of cookies:
- Google Analytics and adsBluebrain Digital have implemented the following Google Analytics features:
- Google Display Network Impression Reporting;
- Demographics and Interests Reporting.
Bluebrain Digital along with third-party vendors, such as Google, use first-party cookies (such as the Google Analytics cookies) and third-party cookies or other third-party identifiers together to compile data regarding Customer interactions with ad impressions, and other ad service functions as they relate to our website.
Customers can set preferences for how Google advertises to them using the Google Ad Settings page. Alternatively, the Customer can opt out by visiting the Network Advertising initiative opt out page or permanently using the Google Analytics Opt Out Browser add on.
Bluebrain Digital is using Google Analytics to measure and evaluate access to and traffic on the public area of our website and create user navigation reports for our website administrators.
Bluebrain Digital takes measures to protect the technical information collected by the use of Google Analytics. The data collected will only be used on a need to know basis to resolve technical issues, administer the website and identify visitor preferences.
- Commercial CommunicationIf a Customer receives commercial emails from us, he may unsubscribe at any time by following the instructions contained within the email or by sending an email to info(at)bluebrain(dot)digitalThe Customer is able to view and modify settings relating to the nature and frequency of promotional communications that they receive from us by accessing the “Settings” section in the restricted area of the website.
The Customer has to be aware that if he opts-out of receiving commercial emails from us or otherwise modify the nature or frequency of promotional communications he receives from us, it may take up to five (5) business days for us to Process the request. Additionally, even after he/she opts-out from receiving commercial messages from us, he/she will continue to receive administrative messages from us regarding the Service.
- Right to amend this PolicyBluebrain Digital is entitled to unilaterally amend this Policy from time to time. Upon amending the Policy, Bluebrain Digital will notify the Customer about the terms by e-mail. In case the new terms refer to Processing of Customer’s Personal Data for any new purpose, which requires Customer’s consent, then Bluebrain Digital will not Process Personal Data for such new purpose, before it has received respective consent.
- Contact InformationShould the Customers have any questions regarding this Policy or Processing of Personal Data, they are welcome to contact Bluebrain Digital with requests, inquiries or any complaints via email: info(at)bluebrain(dot)digital
- ConfirmationBy accepting this Policy, the Customer confirms that he has familiarized himself with this Policy, understood it and agree to its terms.Last updated: August 13, 2020