2. Data Controller (or Owner)
2.2. We are also registered with the Information Commissioner under registration number: ZA219393.
2.3. You may contact us at: email@example.com
3. Data Processor
3.1.Amazon Web Services (AWS). AWS is appointed Data Processor by Oval. AWS provides the processing service of the Data collected through the use of the App. The processing of Data is carried out in respect of AWS Security Standards at all times. The information collected by AWS may be transferred to, or stored at, a location outside the European Economic Area (‘EEA’). To this end, AWS has enacted Model Clauses that allow the transfer of Data outside the EEA in compliance with European Data Protection law (Directive 95/46/CE) and with the General Data Protection Regulation (Reg. 679/2016).
3.2. Additionally, the Data may be accessible to certain types of persons in charge, involved with the operation of the site (administration, sales, marketing, legal, system administration) or external parties (such as third party technical service providers, mail carriers, hosting providers, IT companies, communications agencies). The updated list of these parties may be requested from the Data Controller at any time.
4. Personal Data you give us
4.1. Oval collects, by itself or through third parties, Personal Data that includes: Full Name; Email; Mobile Phone number; Date of Birth; Country of Residence and Address; Nationality; Bank Account; copies of Personal Identification Documents (such as your Passport, ID, Driver License). The primary purposes in collecting information are to provide and improve our Service, to administer your use of the Service and to enable you to enjoy it.
4.3 Failure to provide Personal Data may make it impossible for the App to provide its Service.
5. Information we collect from other sources
5.1. When you use our App we may receive or collect your IP address, URL, Browser information, operating system and platform as well as your login information. We may collect and store information about your location by converting your IP address into a rough geolocation or by accessing your mobile device’s GPS coordinates or coarse location if you enable location services on your device. This information may be used to improve and personalize our service.
. In cases where, in order to provide our service, personal data are to be collected from third parties who can be considered as autonomous data controllers, such as, for instance, likes on Facebook, Instagram or Twitter put by the Users, we guarantee to process these data exclusively for the fulfilment of contractual obligations related to our service.
6. Bank Account and Financial Details.
6.1. The Service requires the processing in read only mode of your bank account details and financial data such as the history of your transaction and balance. To ensure the maximum level of protection of your Data, Oval collaborates with the following service providers that store and process User’s Data:
6.2. Salt Edge Inc. is an account aggregation service that allows the User to store its credit card and bank accounts’ credentials. Oval has sign up for the Bank Integration Program offered by Salt Edge Inc. and to use the App you shall link your bank account(s) to the App by using Salt Edge’s platform service. Salt Edge will allow you to connect with your bank account(s) using your online login credentials and will store them s through a bank-level security system. Oval will never receive nor store User’s personal online login credentials and will receive from Salt Edge only the information required to provide the service.
7. Other uses of the Data collected
The Data we collect from Users are also used for the following purposes:
- Registrazion. Through User registration or authentication, you give Oval your consent to be identified and to access the App’s services.
- Facebook Authentication (Facebook, Inc.). Facebook Authentication is a registration and authentication service provided by Facebook, Inc., related to the social network Facebook.
- Collected Data: Public Profile, Email, Friends, Date of Birth, Events, Location, likes and pictures
- Instagram Authentication (Instagram Inc.).. o Instagram Authentication is a registration and authentication service provided by Instagram, Inc.
- Collected Data: Shared Data: Public Profile, Email, User’s Friends, Date of Birth, Events, Location, likes and pictures
- Analytics. The services described in this section allow the Data Controller to control and analyze traffic data. The services also allow the tracking of the User’s behavior.
- Email and Contact Management. These services allow the managing of email contacts and other contacts used to communicate with the User. The services may also allow the collection of Data concerning the date and time of display of the message by the User.
- Mailchimp, Mailchimp is an email management and storage service provided by Mailchimp Inc. Data collected: Email.
- Intercom is a communication platform developed by Intercom Inc. focused on the profiling of the Users
- Newsletter By registering to the newsletter service, the User’s email address is inserted in a mailing list. They will receive emails containing information, also of commercial and promotional nature, regarding Oval. Data collected: Email and Name.
- This type of services allows User Data to be utilized for advertising communication purposes displayed in the form of banners and other advertisements on this Application, possibly based on User interests.
8. Mode and Place of Processing the Data
8.1. Security Measures
8.1.1 Oval processes Users’ Personal Data in a proper manner and shall adopt appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. Even where all precautions are adopted we cannot guarantee complete security in all events.
8.1.2. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated.
8.2. Place of processing
8.2.1. The Data is processed at the Data Controller's operating offices and where the Data Processor’s operating offices or other parties involved with the processing are located.
8.3. Retention time
8.3.2 The User may always request that the Data Controller suspend or remove the Data.
9. Data Transfer
9.1. The User consents to the transfer of the collected Data through the Service in the event of rearrangement, merger, sale, joint venture, transfer or any other arrangement method of the whole or part of the Company, of its goods and shares.
10. Legal Action
10.1. Your Personal Data may be used for legal purposes by the Data Controller, in Court or in the stages leading to possible legal action arising from improper use of this App or related services.
10.2. You acknowledge to be aware that the Data Controller may be required to reveal personal data upon request of public authorities.
11 Rights of UsersYou have the right, at any time, to:
11.1. Know whether your Personal Data has been stored and may consult the Data Controller to learn about their contents and origin (right of access);
11.2. Verify your Personal Data accuracy or ask for them to be supplemented, updated or corrected (right to rectification);
11.3. Request the erasure of your Personal Data or their transformation into anonymous format (right to erasure);
11.4. Request the restriction of processing of your Personal Data for any and all legitimate reasons (right to restriction of processing);
11.5. Receive your Personal Data in a structured, commonly used and machine-readable format and to transmit those data to another controller from the controller (right to data portability);
11.6. Withdraw the consent to the processing of your Personal Data at any time, without prejudice to the lawfulness of the processing based on consent before its withdrawal;
11.7. Object to the direct marketing activities carried out by Oval Money, including any segmentation for marketing purposes.
Requests should be sent to the Data Controller at: firstname.lastname@example.org
Personal Data (or Data)
Any information regarding a natural person, which is, or may be, identified or identifiable, even indirectly, by reference to any other information, including a personal identification number.
Information collected automatically from this App (or Third Party services employed in this App), which may include: IP addresses or domain names of the computers used by the Users, URI addresses (Uniform Resource Identifier), time of the request, method of request submission to the server, size of the file received in response, numerical code indicating the status of the server's answer (successful outcome, error, etc.), Country of origin, features of the browser and the operating system utilized by the User, various time details per visit (e.g., time spent on each page within the App) and details about the process followed within the App, specifically the visited pages sequence and other parameters about the device operating system and/or the User's IT environment..
Data Controller (or Owner)
The natural person, legal person, public administration or any other body, association or organization, also jointly with another Data Controller, having the right to make decisions regarding the purposes and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this App. The Data Controller, unless otherwise specified, is the Owner of this App.
The individual using this App, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refer.