We take reasonable steps to ensure that your personal data is accurate, complete, and up to date. Based on protection for your privacy，your have the following rights:
You have the right to contact us to know whether or not your personal data is being processed, and, where that is the case, access to the personal data and information, including but not limited to the purposes of the processing and the categories of personal data concerned.
To protect the privacy and the security of your personal data, we may request data from you to enable us to confirm your identity and right to access such data, as well as to search for and provide you with the personal data we maintain. There are instances where applicable laws or regulatory requirements allow or require us to refuse to provide or delete some or all of the personal data that we maintain.
You may contact us to exercise your rights. We will respond to your request within 30days.
Checking your details
How can I check my personal data
You can check your personal data via entering "My Account".
We make certain personal data available to strategic partners that work with us to provide our products and services or help us market to customers. Personal data will only be shared by us with these companies in order to provide or improve our products, services, and advertising; it will not be shared with third parties for their own marketing purposes without your prior express consent.
We share personal data with companies that provide services on behalf of us, such as website hosting, email services, marketing, sponsoring of sweepstakes, contests, and other promotions, auditing, fulfilling customer orders, data analytics, providing customer service, and conducting customer research and satisfaction surveys. These companies are obligated to protect your data and may be located wherever we operate.
1.1 Definition of personal data.
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data.Personal data does not include data that has been irreversibly anonymized or aggregated so that it can no longer enable us, whether in combination with other information or otherwise, to identify you.
Here is a description of the types of personal data we may collect and how we may use it:
What Personal Data We Collect
Depending on the products and services you choose, we collect different kinds of personal data from or about you.
Data you provide
We collect the personal data you provide when you create an account to use our products and services or otherwise interact with us, such as when you fill in account information, contact us, participate in an online survey, use our online help or online chat tool.
Data from your terminal equipments
Photos/ Media/ File
Our app can use files or data stored on your device.If you want to prevent our app from accessing to your phone data ,you can reset your permission on your phone. After obtaining your permission, Photos/Media/Files access may include the ability to:
Read the contents of your USB storage (such as SD card).
7.1 Third party’s previous authorization to us
Facebook, Twitter, Google, VK
The definition of Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
We provide products and service to customers around the world and your personal data may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed outside the EEA by staffs who work for Heather-lodge or one of our suppliers. Data protection laws vary among countries, with some providing more protection than others. Regardless of where your information is processed, we apply the same protections descried in this policy. We also sufficiently consider about certain legal frameworks relating the processing of data.
When we provide products and services to customers under assistance of our affiliates, business partners and service providers，your personal data may be processed out of EEA. In such circumstances, we will enter into model contractual clauses, or rely on alternative legal bases such as the Privacy Shield, where applicable, or binding corporate rules where our partners or service providers have adopted. Appropriate or suitable safeguards, for example, encryption technology, will be provided to ensure security of your information. Our customers have right to obtain copy of those data transferred to a third country. If you need to realize your rights, please contact us. As for details of data processing of the third parties that may reach your personal data, please read the following introduction of Third Party.
We use reasonable technical, administrative, and physical security measures designed to safeguard and help prevent unauthorized access to your data, and to correctly use the data we collect. For example, access to your personal data is strictly limited to our data controller, data processer, data protection officer who need access to such data to perform their assigned job duties. We have built up recovery system to prevent your data from destruction, loss, alteration, unauthorized disclosure caused by automatic technology.
It is important that you take precautions to protect against unauthorized access to your account credentials, and computer or other devices. “personal data breach”means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.If you notice such kind of personal data breach, please immediately contact us. We will investigate any complaint and notify the individual of the outcome of the investigation within a reasonable period. Heather-lodge has set up Data Protection Officer(DPO) to provide professional analysis about personal data processing. Whenever you need help directly from our DPO, you are free to inform us of your requirement. Please be aware that, despite our best efforts, no security system is impenetrable. In the event of a security breach, we will promptly notify you and the proper authorities if required by law.