This document informs you of Fanvestory policies regarding the collection, use and disclosure of personal data when you use our Services. Terms such as data processor, data controller, data processing shall be used as defined in the Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (the GDPR) which can be found HERE.
The data controller of your data is Fanvestory OÜ, a company incorporated in Estonia (registration code 14221756).
PERSONAL DATA COLLECTION AND USE
Personal data is any data and information directly or indirectly related to you which makes it possible for us or any other person having access to the data to identify you. Processing of personal data means any actions taken in connection with your personal data, including (but not limited to) collecting, organising, storing, combining or otherwise making use of your personal data.
We use your personal data for providing you the Fanvestory Services, including creating and managing your user account, managing your Fanvestments, providing you with technical and customer support. We may record and use your transaction history, in anonymised form, for analytical and statistical purposes. We may use your transaction history to provide you offers or products on our Website. In order to operate our platform and create fans’ community, we may make your profile picture, name and information about your use of Services, for example, your fan’s score, publicly available on the leader board(s) or in other sections of the Website.
When registering a user account and using our Services we may collect or ask you to provide certain information for the purposes of providing and developing our Services. Some information which could be associated with you is generated by our platform. The data we collect and process which can be associated with you includes:
- Data enabling us to identify you, such as your name, age (optional), date of birth;
- Contact details, such as email address, phone number (optional), country of residence;
- Profile picture (optional);
- Log-in data;
- Names of your Facebook friends who are also users of Fanvestory, if you use Facebook account to log into your account (optional, only if you allow it);
- Financial information, including data related to your purchases and data related to transactions, Information about your use of the Website, including performed tasks, earned points and badges,
- billing information, bank account number;
- Information about your computer or device, including browser type and settings, IP address and traffic data relating to your Internet connection; and
- information about how you use our products and Services, including your Fanvestments and transaction history on the Fanvestory Website.
Data which is referred above as optional may only be processed if you have provided it to us and only for the purpose for which was indicated to you beforehand.
We process your personal data only
- if it is necessary for fulfilling our legal obligations,
- to fulfil our contractual obligations,
- if you have explicitly given us your consents in connection with the processing activities, or
- if data processing is necessary for purposes of legitimate interests.
Legal obligations. We have certain legal obligations in connection to which we must also process your personal data, such as:
Accounting (including obligations related to taxation) - for which we may process data enabling us to identify you as well as financial data, data on your purchases and contact information. Due to accounting obligations, we must store the aforementioned data for 7 years as of the termination of our contractual relationship;
submission of data to state institutions – we may be obliged to transmit some personal data to state institutions (incl. Police and Border Guard Board, Tax Board etc). The user is notified of the communication of its data unless user’s notification is forbidden by law.
Contractual obligations. For fulfilling our obligations arising from the user terms and for providing assistance in relation with your Fanvestments, we process data enabling us to identify you, also your contact data, and your financial information. Should the terms and conditions of our Service change or should there be any basis for contacting you under the terms and conditions of Fanvestory, we may use your contact details to submit notifications.
Consent. Some data processing activities are only conducted under your respective consent. You may always change your mind in terms of giving the consent or deciding not to do it. We ask for your consent in relation with the following data processing activities (concerns mainly data marked as optional above):
using data of your birthday for sending you special offers for your birthday;
disclosing information about your Fanvestments, performed tasks, earned points and badges to public and/or other users;
using the names of your Facebook friends to allow you to see your friends who are also users of Fanvestory and vice versa;
using your contact details for sending direct marketing;
any other activities performed by us which are not based on legal grounds, which are not connected to the contractual obligations and rights of you and us nor are based under legitimate interests.
Legitimate interests. We may use certain data to provide you a better experience when using our Services.
We may use information about how you use our products and Services to assure the safety of our platform as well as to target any security issues or platform anomalies.
We may use personal data to protect our rights (e.g. if there is a breach of the terms of our Services).
We may use some ‘cookies’ to help us improve our Service and the Website. Certain cookies cannot be deactivated, because they are essential for the Services.
We may use your Facebook profile picture as your profile picture on our platform when you log in using Facebook credentials. You can amend these setting firstly when you sign in using Facebook and afterwards under the settings on our webpage. This will not be visible for other users unless you allow this in relation with your Fanvestments and achievements.
THIRD PARTY DISCLOSURE
We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information for other purpose than in relation to the Services. We may transfer your personal data to third parties if it is necessary for providing the Services (fulfilling contractual obligations) or required by law. We may use third party authorized processors to process your data, for example store the data in secure and encrypted servers hosted by third party cloud service providers or, to help improve our Service and secure the Website, use third party service providers that implement certain ‘cookies’ to our Website. Any such authorized processor shall be obliged to adhere to the terms set forth in this document and conditions set forth in the legislation.
The artists may make available some items for the fans on our Website (i.e. t-shirts, concert tickets, personal greetings from the artist) either within fan packages together with Fanvestments or separately. By making purchases from artists via our Website, you will enter into contractual relationship with the respective artist or their representative. Your personal data may then be transferred to the respective artist (or a person appointed by them, such as a representative or an accountant) for them to fulfil their contractual obligations and for accounting purposes.
For more information about the third-party service providers we use, please contact us.
Upon performing a task, making a purchase or Fanvestment via the Fanvestory Website, your name, profile picture and fan’s score shall be made available to the public and other users on the Fanvestory Website, unless you have indicated that you wish to stay anonymous before performing a task, making a purchase or Fanvestment. In the latter case you will remain anonymous to the other users.
We may also use tracking software to monitor customer traffic patterns and Website usage to help us develop the design and layout of the Website, and also to keep you informed of our activities.
Cookies are files with a small amount of data, which may include an anonymous unique identifier. Cookies are sent to your browser from a web site and stored on your computer's hard drive.
We use the following tracking cookies:
This cookie is used internally by the website’s owners, when uploading or renewing website content.
Remembers the option which registration form user used for authentication.
Asks user to accept cookies.
For more information about the cookies we use, please contact us.
DATA PROTECTION PRINCIPLES
We will process and protect your data in accordance with EU data protection regulations and any other applicable laws.
You may at any time request to see, update or remove the personal information collected from our systems.
We will retain your personal information until the closure of your user account. This period may be extended further, but it will be only for so long as it is reasonably necessary for us to have sufficient information to respond to any issues that may arise after the end of your relationship with us.
Some of the information about your Fanvestments and/or purchases via our Website (e.g. information about your transactions, contracts, financial information necessary for reconstructing the transaction) are to be retained for accounting purposes for the term specified in the Estonian Accounting Act (currently 7 years from the purchase or, in case of Fanvestments, 7 years from the expiry of the Fanvestment).
When your personal information is no longer required, we will destroy, delete or convert it into an anonymous form.
We may send you e-mails for marketing purposes which could be important to you without your explicit consent.
In case you wish to stop receiving e-mails for marketing purposes, please click unsubscribe button, which can be found at the end of such e-mails.
- You have the right to request access to your personal data processed by us. Most of the data is already available to you under the account information. However, please note that certain Services cannot be provided after you wish to remove your personal information.
- You have the right to withdraw your consent, if we use your consent for data processing.
- You have the right to request data correction. Should any of the information held by us in connection with you be incorrect or invalid, please let us know and we will make the required amendments.
- You have the right to request deletion of data stored by us, but only if there are no legal requirements for us to keep it for longer (e.g. to keep it for accounting, you still have some ongoing Fanvestments, there some unsolved issues). This may vary throughout different data categories. If we cannot delete certain data, we will let you know and explain.
- You have the right to restrict processing of your personal data by us, but only if you have submitted any of the following claims for the period allowing us to verify the existence of the respective issues: (i) you have challenged the accuracy of your data processed by us, (ii) you have claimed the processing of your data by us is unlawful.
- You have the right to submit objections to certain data processing activities which are conducted based on our legitimate interest (for more information, see section ‘Personal Data Collection and Use’). Unless there are compelling legitimate grounds for us to continue data processing activities and we can provide evidence about that, we will no longer process the personal data in the respective manner.
To exercise any of your rights listed above, you may send us a request to which we will answer as soon as practical but always within a month. If it takes us more time to provide you a detailed answer, GDPR allows us to prolong the given deadline by two months, but in the latter case, we will notify you about it beforehand.
For more information about your rights under the GDPR, please see Articles 15-22 of the GDPR or relevant explanations on the webpage of the supervision authority (Data Protection Inspectorate in Estonia).
Should you have any complaints towards us, you have the right to contact the relevant supervisory authority (Data Protection Inspectorate in Estonia) or submit a claim to the court. The information about how to submit complaints to the Estonian Data Protection Inspectorate is available on their webpage (also available in English).
If you have any questions related to this policy or in case of any suspected infringement of your privacy, please contact us at firstname.lastname@example.org or using the credentials below:
Parda 6, 4th floor, Tallinn, 10151, Estonia