1. Introduction
SpatialChat Ltd. (“SpatialChat”, the “Company”, “we”, or “our”) operates the website https://spatial.chat (the “Website”) and provides certain services (the “Services”) via a software as a service-based platform accessible on the Website.
This Privacy Policy is an integral part of the Terms of Service and is intended to govern the collection, use and access to your data in connection with the use of the Website and/or our Services, including the organization, management and participation in online events.
At SpatialChat, we want to give you the best possible experience to ensure that you enjoy our service. Your privacy and the security of your personal data is, and will always be, of great importance for us. We want to transparently explain how and why we gather, store, share and use your personal data - as well as outline the controls and choices you have over your personal data.
Storage and access to cookies that are set in connection with the SpatialChat Services are governed by the SpatialChat Cookie Policy (“Cookie Policy”).
By visiting https://spatial.chat, setting up your account with us, or using SpatialChat Services, you are accepting the practices described in this Privacy Policy. We may modify this Privacy Policy from time to time. We will post any modified version of our Privacy Policy at [URL TO THE PRIVACY POLICY]. If such changes might materially affect the way we use or disclose your personal data, we will provide you with notice by email or other methods. We encourage you to look for updates and changes to this Privacy Policy by checking the date above when you access our Website. Your continued use of the Website and our Services after we have posted changes to this Privacy Policy or notified you, if applicable, is deemed to be your acceptance of those changes.
2. Key Definitions
- “Customer” means any user of the SpatialChat Services.
- “European Data Protection Law” means the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national legislation implementing the GDPR.
- “Personal data” refers to any information relating to an identified or identifiable individual in the meaning of:
a. The European Data Protection Law, for individuals (“Data Subjects”) in the European Economic Area (EEA) and the United Kingdom (UK) or when the European Data Protection Law otherwise applies;
b. For individuals residing in the State of California, the California Consumer Privacy Act 2018 (CCPA);
c. For individuals residing in other jurisdictions, the applicable legislation on personal data protection (e.g., LGPD - Lei Geral de Protecao de Dados in Brazil).
- “Privacy Policy” refers to this Privacy Policy.
- “SpatialChat”, “we”, “us” and/or “our” refers to SpatialChat.
- “Services” refers to our software as a service-based online video communication platform that enables you to host online events, online classes, conferences and even parties.
- “You” and “your” refers to the individual to whom personal data covered by this Privacy Policy relates.
3. Identifying the Data Controller and Data Processor
In general, Customer is the controller of customer data and SpatialChat is the processor of customer data.
4. Information we collect
We collect personal information that you voluntarily provide to us when you register on the Website, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Website (e.g., communication with our support team via chat bot on the Website).
We have set out in the table below the categories of personal data we collect and use about you and how we collect it:
Purpose
Data Collected
Legal basis
Retention period
1
Creation and management of your account with SpatialChat
Account Data: Name, Last Name, password, email address
Performance of the contract between SpatialChat and You (Article 6.1b of the GDPR)
Duration of the contract + 7 days of backup data
Invoicing: Name, Last Name, postal address and VAT number enabling a legal entity to be identified, email address of the person responsible for the finance at a legal entity
2
Account customization
Images of a natural person recorded during an online event (video); Avatar/image of a natural person in the profile; transient VOIP data (to enable communication deliver only)
Performance of the contract between SpatialChat and You (Article 6.1b of the GDPR)
Legitimate interest in analysing our services to provide you with the best possible user experience (Article 6.1f of the GDPR)
Duration of the contract + 7 days of backup data
3
Improvement of the Services (data may be collected automatically, please see more in our Cookies Policy)
Connection data: time, country, proxies, IP address, device ID, and your activities within the Services
Legitimate interest in analysing our services to provide you with the best possible user experience (Article 6.1f of the GDPR)
Anonymized data
4
Responses to requests from administrative and judicial authorities
Technical Data: IP address and user agent
The legal obligation of stakeholders (Article 6.1c of the GDPR)
One (1) year fromthe date of thecommunication ofthe Data + three (3)years in the event of the opening of legal proceedings (+ 7 days backup).
5
Customer Support and Sales
Name, Last name, company’s name, position within company, email address, telephone number
Consent (Article 6.1a of the GDPR)
Description of why SpatialChat processes your personal data (‘processing purpose’)
Legal Basis for the processing purpose
Categories of personal data used by SpatialChat for the processing purpose
To provide the Services and related support, process transactions, manage your user account and respond to your requests
- Performance of a contract;
- Legitimate interest;
- Consent
- User data;
- Plan verification data;
- Voice data;
- Usage data;
- Payment and Purchase data
To understand, diagnose, troubleshoot, and fix issues with the SpatialChat Services
- Performance of a contract;
- Legitimate interest
To evaluate and develop new features, technologies, and improvements to the SpatialChat Services
- Legitimate interest;
- Consent
- User data;
- Voice data;
- Usage data
For marketing, promotion, and advertising purposes
- User data;
- Voice data;
- Usage data
Where reasonably necessary, we use your data to exercise our legal rights and prevent abuse of our service
- Performance of a contract;
- Legitimate interest;
- Compliance with legal obligations
- User data;
- Plan verification data;
- Voice data;
- Usage data;
- Payment and Purchase data
To comply with legal obligations and law enforcement requests
- Legitimate interest;
- Compliance with legal obligations
- User data;
- Plan verification data;
- Voice data;
- Usage data;
- Payment and Purchase data
To fulfill contractual obligations with third parties, for example licensing agreements and to take appropriate action with respect to reports of intellectual property infringement and inappropriate content
- User data;
- Usage data;
- Payment data
To establish, exercise, or defend legal claims
- User data;
- Plan verification data;
- Voice data;
- Usage data;
- Payment data
To process your payment
- Performance of a contract;
- Compliance with legal obligations
- User data;
- Plan verification data;
- Payment data
To post testimonials. We post testimonials on our Website that may contain personal data. Prior to posting a testimonial, we will obtain your consent to use your name and the content of testimonial
- Name;
- Company name (logo if allowed);
- Photo (if provided consent)
To request feedback. We may use your information to request feedback and to contact you about your use of our Services
- Consent
- Legitimate interest
Customer Support and sales. The data you provide to us when you report a problem, request our support services, request or complete a review, register for demo or/and data provided when you correspond with us
- Full name;
- Email address;
- Company name;
- Telephone number
6. How we share and disclose personal data
SpatialChat is not in the business of selling your personal data. We consider your personal data to be a vital part of our relationship with you. There are, however, certain circumstances in which we may share your information with certain third parties, as set forth below.
Your Instruction: We may transfer and disclose your personal data in accordance with your instructions and with appropriate consent, including any applicable terms in the agreement and your use of Services functionality and in compliance with applicable law and legal process.
Legal Requirements: We may disclose your personal data if required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, (ii) protect and defend the rights or property of SpatialChat or related companies, (iii) protect the personal safety of users of the Services or the public, or (iv) protect against legal liability.
Third-Party Service Providers and Partners: We may engage third-party companies or individuals as service providers or business partners to process Information and support our business. This includes helping us in hosting, maintenance, backup, storage, virtual infrastructure, payment processing, fraud detection, marketing, and analysis. Third-party service providers may have access to your information as reasonably necessary to perform these tasks on our behalf and are obligated not to disclose or use it for other purposes. All our service providers must meet our security and privacy standards before they gain access to any of your personal data.
Forums: Information you contribute to blogs, forums, and related discussion areas – along with your profile information – may be publicly available.
Business Transfers: As we develop our business, we might get involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, sale of all or a portion of our assets, or transition of a service to another provider. In the event of such a transaction or similar event, your information may be part of the transferred assets. You will be notified via email and/or a prominent notice on the Services if a transaction takes place, as well as any choices you may have regarding your personal data.
Aggregated or De-identified Data: We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you.
To enforce our rights, prevent fraud, and for safety: To protect and defend the rights, property or safety of SpatialChat, its users, or third parties, including enforcing its contracts or policies, or in connection with investigating and preventing illegal activity, fraud, or security issues, including to prevent death or imminent bodily harm.
Consent: We may share your personal data with third parties when we have your consent to do so.
6.1. Sharing of information with third-parties
We only share and disclose your information with the following third-parties. We have placed those third-parties into categories so that you may be easily understand the purpose of our data collection and processing activities.
- Cloud Computing Services: AWS servers;
- Communication with you: Zendesk;
- Invoice and Billing: Odoo, Stripe;
- Web Analytics: For EU(!) – plausible.io (hosted in EU), usefathom.com (the traffic is routed via EU-owned infrastructure); for non-EU countries – Google Analytics; For all – Amplitude;
- Advertising, Direct Marketing, and Lead Generation: Amplitude
- Website hosting:
- Website Performance Monitoring: Sentry
6.1.1. Integrations
For better experience with us, and in order to provide our Services, SpatialChat may once enabled share certain information with the following service providers integrated into our Service:
A. Slack (https://slack.com/trust/privacy/privacy-policy)
Purpose: This integration provides to you the best experience of working with SpatialChat. By using this you may have such useful features like:
- Notifications about new users that entered the room
- Provide a special Slack status if the user is inside SpatialChat
- Make a connection with your team in Slack and in SpatialChat
Functionality:
- Synchronization of team accounts. Connecting and Disconnecting
- Synchronization customer accounts. Connecting and Disconnecting
- Setting notifications from space
- Synchronization of user accounts. Connecting and Disconnecting
- Status display
- Changing statuses via Spatial chat
Data shared:
- public channels name, id
- slack user id,
- user access token: authed_user.access_token
- bot token
B. Sentry.io (https://sentry.io/privacy/)
Purpose: JavaScript Sentry’s SDK that will automatically report errors and exceptions in SpatialChat. Help and improve the feedback from SpatialChat support team in solving customer’s issues.
Functionality:
- The user clicks the button;
- A popup window opens up where the user describes the problem, he/she is facing now and sends a request to SpatialChat support team;
- At this point we collect technical information through Sentry JavaScript library. This is essentially a snapshot of a text file with debugging information from the user’s browser (no personal data), solely browser logs for debugging errors.
- https://docs.sentry.io/platforms/javascript/
Data shared:
C. Google OAuth 2.0 (https://policies.google.com/privacy?hl=en-US)
Purpose: Enabling our users with the possibility to create an account or log into SpatialChat by using third-party services, such as Google. The information we receive when you authenticate through a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in the relevant third-party services to understand what data may be disclosed to us or shared with our service.
Functionality: We use the information collected from you to provide and improve our service, including to:
- Authenticate your Google account to provide you access to our service
- Use Google APIs to perform tasks on your behalf, such as accessing Google Drive files
- Personalize your experience on our service based on your preferences and activity
- Communicate with you about our service and updates
Data shared:
- Your Google account information, including your name and email address
- Information necessary to access and use Google APIs, such as an access token and refresh token
- Information about how you use our service, such as your activity and preferences
7. Data Retention and Deletion
We keep your personal data only as long as necessary to provide you with the SpatialChat Services and for legitimate and essential business purposes, such as maintaining the performance of the SpatialChat Services, making data-driven business decisions about new features and offerings, complying with our legal obligations, and resolving disputes. We may retain logs of automatically collected information (for internal analytics and security purposes).
If you request, we will delete or anonymize your personal data so that it no longer identifies you, unless we are legally allowed or required to maintain certain personal data, including situations such as the following:
- If there is an unresolved issue relating to your account, such as an outstanding credit on your account or an unresolved claim or dispute we will retain the necessary personal data until the issue is resolved;
- Where we need to retain the personal data for our legal, tax, audit, and accounting obligations, we will retain the necessary personal data for the period required by applicable law; and/or,
- Where necessary for our legitimate business interests such as fraud prevention or to maintain the security of our users.
8. Data Transfers
We may share your personal data globally in order to carry out the activities specified in this Privacy Policy. For instance, some of the third parties to whom we may subcontract processing to, or share your personal data with, are based in other countries that may have laws that are different, and potentially not as protective, as the laws of your country of residence.
When we share personal data of our users with such third parties, we shall ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, we use of European Commission-approved Standard Contractual Data Protection Clauses, or other appropriate legal mechanisms to safeguard the transfer.
For further details of the security measures, we use to protect your personal data, please see Section 9 below ‘Security’.
9. Security
SpatialChat works hard to protect Personal Data you provide us from loss, misuse, and unauthorized access or disclosure. We implement appropriate technical and organizational measures to help protect the security of your personal data; we have implemented various policies including pseudonymization, encryption, access, and retention policies to guard against unauthorized access and unnecessary retention of personal data in our systems.
Despite these efforts, no information system can be fully secure or error free, so we cannot guarantee the absolute security of your personal dat. Users also play an important role in keeping their data safe. You should take special care when disclosing any information via the Internet. When you click a link to a third-party site, you will be leaving our site and we don’t control or endorse what is on third-party sites.
Your password protects your user account, so we encourage you to use a strong password that is unique to your SpatialChat account, never share your password with anyone, limit access to your computer and browser, and log out after having used the SpatialChat Services.
10. Your Data Rights and Choices
No matter where you are, we treat all our users equally, and so we are making the following options, as available and except as limited under applicable law, to control your data available to all users, regardless of their location.
As the data subject you have:
- the right of access – the right to be informed of, and request access to, the personal data we process about you;
- the right to rectification – the right to request that we amend or update your personal data where it is inaccurate or incomplete. If your personal data has been shared with others, we will tell them about the correction where possible;
- the right to erasure – the right to request that we delete your personal data. If we shared your data with others, we will alert them to the need for erasure where possible;
- the right to restriction of processing – the right to request that we temporarily or permanently stop processing all or some of your personal data. If we shared your personal data with others, we will tell them about the restriction where possible;
- the right to data portability – the right to request a copy of your personal data in electronic format and the right to transmit that personal data for use in another party’s service;
- the right to object – the right, at any time, to object to us processing your personal data on grounds relating to your particular situation; the right to object to your personal data being processed for direct marketing purposes;
- the right to withdraw consent – the right to withdraw your consent given to us for personal data processing at any time, but this will not affect any processing of your data that has already taken place;
- the right not be subject to automated decision-making – the right to not be subject to a decision based solely on automated decision making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect;
- the right to make a complaint with the data protection authority – the right to report to the data protection authority in case you have a concern about our privacy practices, including the way we handled your personal data.
At any time, you may exercise your rights as described here by sending an email to privacy@spatial.chat. In the email, please provide specific details about the right you are exercising. Once we receive the communication, we will respond as quickly as possible and without delay. Depending on the request, it might take us some time to respond, but we will endeavor to do so within 30 days of receiving your request.
11. Links to other websites
This Privacy Policy applies only to the Services. The Services may contain links to other websites not operated, controlled or owned by us (the “Third Party Sites”). The policies and procedures we described here do not apply to the Third Party Sites. The links from the Services do not imply that we endorse of have reviewed the Third Party Sites. We suggest contacting those sites directly for information on their privacy policies.
12. Children’s Privacy
We do not knowingly collect personal information from individuals who are under the minimum required ages specified herein. You must be at least 18 years old or the age of majority in your jurisdiction, whichever is greater, to use our Services. Individuals under the applicable age may use our Services only through a parent or legal guardians’ account with their involvement. If you are a parent or legal guardian who believes your child has provided personal information to SpatialChat without your consent, you ask us to delete such information by contacting us at privacy@spatial.chat
13. Changes to this Privacy Policy
We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time, but we will alert you to any such changes by placing a notice on the SpatialChat website, by sending you an email and/or by some other means. Please note that if you’ve opted out of receiving legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.
14. Data Protection Authority
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority of the Cypriot Data Protection Authority, which is SpatialChat’s lead supervisory authority in the European Union.
You may direct questions or complaints to our lead supervisory authority: The Office of the Commissioner for Personal Data Protection
Office address:
Iasonos 1, 1082 Nicosia, Cyprus
Postal address
P.O.Box 23378, 1682 Nicosia, Cyprus
Tel: +357 22818456
Fax: +357 22304565
Email: commissionerdataprotection.gov.cy
15. Contacting Us
If you have any questions, comments, or concerns relating to the SpatialChat Services or this Privacy Policy, please send an email to privacy@spatial.chat or write to us at:
SpatialChat Ltd.
224 Arch. Makariou III Avenue,
Achilleos Building, office 51,
3030 Limassol, Cyprus
Attention of Legal Counsel