Last updated: 2018.04.24
The Optimalprint Service is provided by Gelato AS, who is committed to protecting the personal data of those individuals who visit our websites and register to use our products and services. This policy describes our data protection practices and how we use and collect the Personal Data that you share with us when browsing our Websites and/or registering for our products. Our processing of your Personal Data is needed for us to deliver the service to you and/or is based on your consent. We may also process your Personal Data in order to comply with our legal obligations as explained below or due to our legitimate interests.
1. PERSONAL DATA WE COLLECT
We will collect Personal Data from you in the following circumstances:
When you create an account and place an Order: We will collect your first and last name, E-mail address, postal address, phone number, password, birthdate and/or age, payment information, such as your credit card or PayPal account information, drafts of product designs that you save under your Account, content that you choose to save under your Account, communications and correspondence sent to and from your Account, information about purchasing habits and preferences, order histories, and/or Account histories.
When you create or design Products: We may collect any images, text, logos or other content that you upload or submit, including information related to or included within such content, such as the names, birthdates, ages and gender of individuals to whom the content is related.
When interacting with Social media sites:
You may be able to register and create an Account to use the Services using your Facebook, Google or other social media accounts. If you choose to use this option, where available, we will access your social media account profile information, such as your name and e-mail address.
The Services may give you the option to upload a photo from your social media account, such as Facebook and Instagram, and from your account with cloud storage services, such as Dropbox. If you choose to use this functionality, we will access your social media account profile information, including your profile photo and all photos that you have saved within your social media account.
You can stop sharing your social media account profile information with us at any time by removing Gelato’s access to that account. Any information that we collect from your Facebook or other social media account may depend on the privacy settings you have with that social media, so please consult the social media’s own privacy and data practices.
2. PURPOSE AND USE OF PERSONAL DATA
We use your Personal Data, including your Content, for the following purposes:
· To provide you with the services and to evaluate, modify and enhance the services
· To enable you to set up your account, to create and design Products, process and fulfill your order
· To process your payment, facilitate billing and issue invoices, as applicable
· To communicate with you and to respond to your requests
· To provide you with customer service and support
- For corporate account management purposes
· To help keep our website safe and secure and to improve the website
We will create anonymous data records from Personal Data by excluding information (such as your name) that makes the data personally identifiable to you. We use such Anonymous Data records to analyze request and usage patterns so that we may enhance the content of the Services and improve Website navigation.
3. HOW WE SHARE YOUR PERSONAL DATA
We disclose your Personal Data as described below. Personal Data provided by you or that we may obtain automatically by your use of the Website, is not and will not be sold, rented, or shared by us with any third party without your prior consent.
Transfer and Storage of Personal Data
Your Personal Data will be transmitted, uploaded, transferred, stored, or backed up at Gelato’s servers with our GDPR compliant cloud providers in the United States, Europe and China.
Third Party Service Providers
We will share your Personal Data with third party companies and individuals that perform Services on our behalf to help us provide the Website and Services to you. In Order to fulfill your print Order in the most environmentally friendly way, we let the printer closest to the address of delivery print your products. This may mean a transfer of your personal data out of EU. Other examples of Services that may be provided by Third Party Service Providers may include, but are not limited to: processing credit card payments with our payment provider in EU, providing customer service by our suppliers in EU and the Philippines, and maintaining our customer lists by our service providers in EU. Third Party Service Providers acting on our behalf are only provided with such Personal Data reasonably required to provide the particular service for which they are retained. Our Third-Party Service Providers are obligated to keep all of your Personal Data confidential and to collect, use and disclose your Personal Data only to the extent necessary to provide the Services on our behalf. They are fully compliant to the EU GDPR regulation and have signed a Data Processing Agreement with Gelato.
Advertisers and Third-Party Marketing
Third Party Payment Processor
For online payments, we use the payment services of Adyen B.V. Gelato does not process, record or maintain your credit card or bank account information. Gelato records the payment method you have chosen. For Optimalprint Premium members, for Native app customers and customers who prefer, Adyen will store the applicable payment data provided by you in order to charge the periodic fee. This is also optional for all Optimalprint customers.
Compliance with Law, Court Order, and Other Disclosures
Third Party Sites
The Website may contain links to third party websites, or third party websites may otherwise be associated with the Website. These companies are GDPR compliant and Gelato has signed a Data Processing Agreement with them. Gelato is not responsible for the policies and practices employed by the owners of such third party websites, including but not limited to their collection, use and disclosure of your Personal Data, nor does Gelato offer any (and expressly disclaims any) guarantee, representation, warranty, or covenant of any kind with respect to the collection, use or disclosure of your Personal Data by any third party site that is linked from (or is otherwise associated with) the Website. Please consult the terms and conditions and privacy policies of any third party websites prior to use.
Security of Your Personal Data
We employ security safeguards to protect your Personal Data against loss or
theft, as well as against unauthorized access, disclosure, copying, use, or
modification. When we transmit highly confidential information over the
Internet, we protect it through the use of encryption technology, such as
the Secure Socket Layer (SSL) protocol. We also protect your stored
password through the use of encryption technology.
4. YOUR RIGHTS REGARDING YOUR PERSONAL DATA
Consent for Marketing Communication
You can choose to receive marketing communications by e-mail or sms by ticking the respective boxes for receiving marketing material when you register as a customer. You can also unsubscribe to this kind of communication in your customer Account or at any time by following the unsubscribe instructions in communication sent to you or by contacting us. Despite your indicated opt-out preferences, we may continue to send you administrative and transaction related communications. By registering for an account or purchasing products, you consent to receiving administrative and transaction-related communications.
Changing, Transferring or Deleting Your Personal Data
We delete Your Personal Date once no longer necessary in relation to the purposes for which they were collected or otherwise processed. You may access, review, update, correct or delete the Personal Data in your Account by contacting us directly using the contact information provided below. You may also access or modify your Personal Data by editing your Account via the Service. If you would like to have your Personal Data transferred to someone else, please e-mail us to firstname.lastname@example.org and we will provide you with a file of your Person Data. If you completely delete all of your Personal Data, then your Account may become deactivated. If you rather want us to delete your data, please contact us and we will fulfill your request.
6. DATA PROTECTION OFFICER AND CONTACT INFORMATION
Our contact details:
1360 Fornebu, Norway
Our Data Protection Officer: email@example.com
If you believe that Gelato does not fulfill its obligations according to the EU GDPR regulation or other applicable privacy legislation, you also have the right to lodge a complaint with a supervisory authority.