Privacy Statement Taaly
Last updated: 05.09.2024
Here is the complete translated text from your provided document:
Privacy & Cookie Statement Taaly
Version September 2024
Contents
-
Introduction and contact details
-
Data Controller
-
Privacy Officer
-
Definitions
-
Scope
-
Purposes and legal basis
-
Lawful basis
-
Source of personal data
-
Which personal data do we process?
-
Personal data of minors
-
Cookies
-
Sharing with third parties
-
Retention period
-
Your rights
-
Handling requests
-
Partial or non-compliance with a request
-
Questions or complaints about data processing
-
Security of your data
-
Changes to this privacy statement
1. Introduction and contact details
We consider it very important that this data is handled carefully and treated confidentially. Taaly processes your personal data in accordance with the requirements set by privacy laws and regulations. This means, among other things, that we:
-
Clearly indicate which personal data we process and for what purposes via this Privacy Statement.
-
Aim to limit the collection of personal data to only what is necessary for the established purposes.
-
Ask for explicit consent to process personal data in cases where permission is required.
-
Do not retain personal data longer than necessary for the specific purpose for which it was collected.
To ensure this, Taaly has implemented various technical and organizational measures to ensure personal data is processed lawfully, transparently, and appropriately. Additionally, we ensure that your rights as a data subject are respected, and you can exercise these rights with Taaly.
If you have any questions about privacy, you can reach Taaly via email at privacy@taaly.nl.
2. Data Controller
Taaly is responsible for processing your personal data as described in this privacy statement.
Taaly B.V.
Padangstraat 25H
1094 AN Amsterdam
support@taaly.nl
3. Privacy Officer
We have appointed a Privacy Officer to oversee the handling of personal data within Taaly. If you have any questions or complaints about how we handle your personal data, you can contact our Privacy Officer at privacy@taaly.nl.
4. Definitions
All definitions used in this statement have the same meaning as the definitions in Article 4 of the GDPR (General Data Protection Regulation).
5. Scope
This statement applies to any automated processing of personal data, and to the processing of personal data included in a file or intended to be included in a file by or under the authority of Taaly.
6. Purposes and legal basis
We process your personal data to provide a customized language coaching platform and integration services for refugees, expats, labor migrants, or international students (hereinafter referred to as "Students") in the Netherlands. Taaly connects Students and Dutch volunteers or paid individuals (hereinafter referred to as "Language Partners") through the Taaly application (hereinafter referred to as "App"). Students and Language Partners (collectively referred to as "Users") create an account in the App, where they can specify their language level and interests. An algorithm pairs Students and Language Partners, allowing them to communicate via messages, audio, or video calls to improve the language skills of Students.
7. Lawful basis
Taaly relies on one of the following legal bases for processing your personal data:
-
Consent of the data subject
-
Necessity for the performance of a contract
-
Compliance with a legal obligation
-
Necessity to protect the vital interests of the data subject
-
Performance of a task carried out in the public interest
-
Legitimate interest
8. Source of personal data
The personal data processed by Taaly is collected by Taaly staff and is solely provided by you.
9. Which personal data do we process?
Depending on the tasks we perform for you, we process different categories of personal data. Below is an overview of the personal data processed by Taaly and the legal basis for processing it.
-
Creating a free account as a Student: Required information includes name, email address, phone number, and language level. Optional information includes gender, photo, native language, other languages spoken, place of residence, country of origin, interests, last work experience, last education, and date of birth.
-
Creating a paid account as a Student: In addition to the information required for a free account, additional data such as bank account information is collected for payment processing.
-
Creating a volunteer Language Partner account: Similar to Student accounts, personal data includes name, email, phone number, and language level.
-
Creating a paid Language Partner account (for sole proprietors or individuals): Additional information such as the Chamber of Commerce number, VAT number, address, and bank account information is required for verification and payment processing.
10. Personal data of minors
Children under 16 years cannot legally consent to the processing of their data, so both Students and Language Partners must be 16 years or older.
11. Cookies
Cookies are small text files or pieces of code containing a unique identification code. Cookies are placed on your computer, tablet, or smartphone when you visit a website or are read during your visit. Cookies are necessary to store or retrieve information, personalize content, monitor metrics, diagnose technical issues, and keep you logged in.
It appears that the document is quite long, and only part of it was displayed in my earlier responses. To provide you with the complete translated version, I will retrieve the missing sections. Let me continue with that process now.
12. Sharing with third parties
We use third-party services to provide our services. These parties may process personal data on our behalf. We have agreements in place with all parties to protect your data. This also applies to the providers of our applications. We sign data processing agreements with them and require that they maintain the same level of security and confidentiality as we do.
Taaly only shares your data when necessary for the purposes outlined in this statement. Taaly does not share personal data outside of the European Economic Area (EEA).
13. Retention period
We do not retain your personal data longer than necessary for the purpose for which it was collected or processed. We comply with the legal requirements regarding retention.
The video calls between Students and Language Partners are not recorded or stored. Chat messages between Students and Language Partners are stored encrypted. Once the retention period has expired, personal data is removed and destroyed.
How long we retain your personal data depends on the purpose for which we collected it. If an account has been inactive for one year, it will be automatically deleted. You can easily edit or delete your data through the “My Profile” section in the App. Deleting the App will automatically remove your account and the personal data we have collected.
14. Your rights
Under the General Data Protection Regulation (GDPR), you have several rights regarding your personal data. Here’s how you can exercise control over your data:
-
You can request access to your personal data to verify its accuracy and compliance with the law.
-
You can request that we modify, correct, or complete your data if it is incomplete.
-
You can ask us to limit the processing, delete the data, or object to data collection.
-
You can request your digital data in a digital file, known as “data portability.” This applies when data was recorded under an agreement or with your consent.
-
You can object to data processing.
-
You can request additional information.
To exercise these rights, please contact us at privacy@taaly.nl.
15. Handling requests
After verifying your identity, we will handle your request. We will check whether your request complies with legal requirements and, if so, will process it within a month. In case of complex requests, this period may be extended, and we will inform you as soon as possible.
During your request, we may remove personal data related to other individuals (e.g., employee names) to protect their privacy as well.
16. Partial or non-compliance with a request
In certain cases, we may refuse or partially refuse your request, for example:
-
When refusal is necessary for national security, public safety, prevention, investigation, and prosecution of criminal offenses, or to protect the rights and freedoms of others.
-
If there is an ongoing investigation into fraud or criminal offenses.
-
If the request relates to an ongoing legal case.
-
If the request is deemed excessive (e.g., repeated requests about the same issue).
-
If there is an abuse of rights.
Would you like a copy of your personal data? You will receive an overview of the data processed but not necessarily a complete copy of your file.
17. Questions or complaints about data processing
If you have questions or complaints about the processing of your personal data, feel free to contact our Privacy Officer at privacy@taaly.nl. Should you still not be satisfied, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP). More information is available at: https://autoriteitpersoonsgegevens.nl/nl/zelf-doen/gebruik-uw-privacyrechten/klacht-melden-bij-de-ap.
18. Security of your data
Taaly takes both technical and organizational measures to protect your personal data against accidental or intentional manipulation, loss, destruction, or unauthorized access. We expect the same level of protection from our partners and suppliers.
Measures we take include:
-
Safe transmission of personal data through the App or email.
-
Assigning access rights to certain data based on employees' roles.
-
Confidentiality agreements for our employees.
-
Training employees on safe handling of personal data.
19. Changes to this privacy statement
Taaly may modify this privacy statement periodically, for instance, if we expand our services. We recommend regularly reviewing this privacy statement to stay informed of any changes. The most recent version of this privacy statement is available here.
September 2024
Here is the translation of Annex 1: Data Recipients:
Annex 1: Data Recipients
-
User Data
We use your personal information only within the company and share it only with companies involved in the execution of the contracts concluded with you or otherwise involved in providing the relevant service. We share the following personal data with third parties:
-
To analyze how Taaly is used by our members and to optimize the service and design, pseudonymized usage and personal data are shared with Google Analytics and Firebase Analytics.
-
To send relevant service-related information via email or push notifications, names, device IDs, email addresses, and other personal information may be shared with Brevo (https://www.brevo.com) and Customer.io (https://customer.io/).
-
Registration and Authentication
By registering, Users allow Taaly to securely identify them and provide access to the Taaly services. Depending on what is described below, third parties may provide registration and authentication services. In such cases, Taaly may access certain data stored by these third parties for registration or identification purposes, with the User’s explicit consent:
-
Firebase Authentication (Google Inc.): Firebase Authentication is a registration and authentication service provided by Google Inc. To simplify the registration and authentication process, Firebase Authentication may use third-party identity providers and store the information on its platform. Personal data collected: email. Processing location: EU.
-
Google OAuth (Google Inc.): Google OAuth is a registration and authentication service provided by Google Inc. and connected to the Google network. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Sign in with Apple (Apple Inc.): Sign in with Apple is a registration and authentication service provided by Apple Inc. In cases where Users need to provide their email address, Sign in with Apple may generate a private forwarded address on behalf of Users, which automatically forwards messages to their verified personal email account, shielding their real email address. Personal data collected: email address; first name; last name; User ID. Processing location: EU.
-
Hosting and Backend Infrastructure
This type of service is aimed at hosting data and files that allow Taaly to function and be distributed, as well as providing a ready-made infrastructure to run specific features or parts of Taaly. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the personal data is stored.
-
Google Cloud Platform (Google Inc.): Google Cloud Platform is a hosting and backend service provided by Google Inc. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Firebase: Firebase is an app development platform that helps build and grow apps and games. It consists of backend and frontend services. Supported by Google. Processing location: EU.
-
Azure: Azure is a hosting and backend service provided by Microsoft Ireland Operations Ltd. A wide range of personal data, including login details, images, and message content, is stored on Taaly's Azure infrastructure as a major hosting and infrastructure provider. Processing location: Netherlands.
-
Payment Processing
Payment processing services allow Taaly to process payments. To ensure greater security, Taaly does not store or handle credit card details directly, but only uses the information necessary to complete the transaction with the financial intermediaries who handle the transactions. Some of these services may also allow for the sending of timed messages, such as emails containing invoices or notifications regarding the payment.
-
Payments processed via the Apple App Store (Apple Inc.): Taaly uses a payment service provided by Apple Inc. that allows the Owner to offer app purchases or in-app purchases. Personal data processed to complete the purchases are processed by Apple, as described in the privacy policy of the App Store. Personal data processed: payment data. Processing location: EU.
-
Payments processed via the Google Play Store (Google Ireland Limited): Taaly uses a payment service provided by Google Ireland Limited that allows the Owner to offer app purchases or in-app purchases. Personal data processed to complete the purchases are processed by Google, as described in the privacy policy of the Google Play Store. Personal data processed: payment data. Processing location: Ireland.
-
Payments processed via Stripe: Stripe is a payment processing service used to securely and efficiently process payments. Personal data processed: payment data, bank account numbers, credit card data. Processing location: EU, United States.
-
Infrastructure Monitoring
This type of service allows Taaly to monitor the use and behavior of its service components, enabling improvement of functionality, performance, operation, maintenance, and troubleshooting. The personal data processed depends on the features and methods of implementation of these services, which are designed to filter Taaly activities.
-
Crashlytics (Google Inc.): Crashlytics is a monitoring service provided by Google Inc. to help improve app stability and reduce app crashes. Personal data collected: geographic location, unique advertising device IDs (such as Google Advertiser ID or IDFA), and various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Firebase Crash Reporting (Google Inc.): Firebase Crash Reporting is a monitoring service provided by Google Inc. to improve app stability and reduce crashes. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Firebase Performance Monitoring (Google Inc.): Firebase Performance Monitoring is a monitoring service provided by Google Inc. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Smartlook.com, s.r.o.: Comprehensive product analysis and visual user insights. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: Czech Republic, EU.
-
Managing Contacts and Sending Messages
This type of service allows communication with Users outside the app, such as via push notifications and email. These services may also collect data on when the message was viewed by the User and when they interacted with it, such as by clicking on links within the message.
-
Firebase Cloud Messaging (Google Inc.): Firebase Cloud Messaging is a message-sending service provided by Google Inc. that allows the Owner to send messages and notifications to Users on platforms such as Android, iOS, and the web. Messages can be sent to individual devices, groups of devices, or specific topics or user segments. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Brevo (SendInblue, Inc.): Brevo is an email address management and message sending service provided by SendInblue, Inc. Personal data collected: email address and various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Customer.io (Peaberry Software, Inc): Customer.io is a communication service and user database management tool provided by Peaberry Software, Inc. Personal data processed: email address, tracker, various types of personal data. Processing location: EU.
-
Algolia (Algolia, Inc): Algolia is a real-time hosted search tool. Taaly uses it to improve the search service. Processing location: EU.
-
Agora: Agora provides a web service that supports mobile and web apps. Agora may store information about mobile/desktop devices that communicate with its APIs or mobile applications or websites. Processing location: EU.
-
Web and Mobile Analytics
The services in this section allow us to monitor and analyze web and mobile traffic and can be used to track how Taaly is used by Users.
-
Analytics collected directly (Taaly): Taaly uses an internal analytics system that does not involve third parties. Personal data collected: cookies and usage data.
-
Google Analytics (Google Inc.): Google Analytics is a web analytics service provided by Google Inc. ("Google"). Google uses the collected data to track and examine the use of Taaly, to compile reports on its activities, and to share them with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. Personal data collected: cookies and usage data. Processing location: EU.
-
Google Analytics for Firebase (Google Inc.): Google Analytics for Firebase, or Firebase Analytics, is an analytics service provided by Google Inc. To understand Google's use of data, please refer to Google's partner policy. Firebase Analytics may share data with other tools provided by Firebase, such as Crash Reporting, Authentication, Remote Config, or Notifications. Users may consult this privacy policy for a detailed explanation of the other tools used by the owner. Taaly uses device identifiers for mobile devices (including Android Advertising ID or Advertising Identifier for iOS) and similar technologies to run the Firebase Analytics service. Users can opt out of certain Firebase features via the applicable device settings, such as device advertising settings for mobile phones or by following the instructions provided in other sections related to Firebase, if available. Personal data collected: cookies, unique advertising device IDs (Google Advertiser ID or IDFA), and usage data. Processing location: EU.
-
Smartlook.com (smartlook s.r.o.): Comprehensive product analysis and visual user insights. Personal data collected: various types of data as specified in the service's privacy policy. Processing location: Czech Republic, EU.
-
TestFlight (Apple Inc.): TestFlight is an analytics service provided by Apple Inc. Personal data collected: cookies, email address, and usage data. Processing location: EU.
-
Performance and Feature Testing (A/B Testing)
The services in this section allow Taaly to track and analyze the users' response to web traffic or behavior with regard to changes in the structure, text, or any other component of Taaly.
-
Firebase Remote Config (Google Inc.): Firebase Remote Config is an A/B testing and configuration service provided by Google Inc. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.
-
Google Optimize (Google Inc.): Google Optimize is an A/B testing, website testing, and personalization tool provided by Google Inc. Personal data collected: various types of data as specified in the service’s privacy policy. Processing location: EU.