This Privacy Notice explains who we are, how we collect, share and use personal information about you, and how you can exercise your privacy rights.
1. WHAT PERSONAL INFORMATION DOES CHATLY COLLECT?
The personal information we may collect about you through the Services falls into the following general categories:
1.1. Information that you provide voluntarily
Certain parts of our Services may ask you to provide personal information voluntarily. For example, we may ask for certain information in order to register for an event or receive offers within WeChat once you follow the account and begin interacting with the brand, to subscribe or follow to marketing communications from the brand you would like to engage with, and/or to submit enquiries to, such as:
- Your name, email address, phone number and address
- The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be explained to you when we ask you to provide your personal information.
1.2 Information we collect automatically (provided by Weixin)
When you use our Services, we may also collect certain information automatically from you and/or your device via WeChat, which may be considered non- personal information under applicable data protection laws, such as:
- Your nick name, gender, province, country, wechatid, age, profile picture
- Data and analytics about your use of our Services (e.g. in-marketing adverts you may have viewed, in-event preferences or just follower preferences)
- Your device type and the operating system that you use
- General geographic location (e.g. country or city location) based on what WeChat provides us
- GPS location, with your consent
1.3 Information we obtain from third party sources
Information from integrated 3rd party platforms
Typical uses include data updates from POS, CRM and loyalty systems.
Special note about Chatly: Chatly uses WeChat standard API to connect with official accounts provided to clients. APIs are authenticated using official accounts credentials in order to process follower information
1.4 No special categories of information
We do not request or intend to collect any "special categories of information" such as any information on health, race, religion, political opinions or philosophical beliefs, sexual preferences or orientation. Please, be cautious when sharing this information about yourself (or others) in our forms or chat messages.
2. HOW WE USE YOUR PERSONAL INFORMATION
We use your personal information for the following purposes:
2.1 To provide and operate our Services:
- To create user accounts/profiles to enable you to interact and receive useful information from the brand you are following
- To enable you to communicate with the brand either via the automation setups or customer support channel
- To send you service-related communications broadcast, response messages or QR codes that enable local wi-fi access
2.2 To improve our Services and keep them secure:
- To respond to your customer support requests (e.g. if you write to us with a complaint)
- To detect and prevent illegal activities (e.g. hacking or cheating)
- To conduct optional user feedback surveys
- To understand you, your preferences and user traffic to enhance your experience and enjoyment using the brand you are following
- To conduct research
2.3 To personalize our Services:
- To remember you next time you visit one of our client services
- Communicate with you about promotions, rewards, upcoming events, and other news about products and services our clients offer
2.4 For promotional activities (including marketing and advertising)
- To provide you with in-app offers and rewards based on your in-app behaviors
- To serve you with relevant targeted advertisements
- To make you offers to purchase in-app items on discount based on your in-app activity and purchase history.
- To send you marketing communications and/or newsletters about rewards and promotions if you have subscribed to them
- To comply with our legal obligations
- To exercise, establish or defend our legal rights, or to protect your vital interests or those of any other person
- To prevent and/or detect fraud or fraudulent behavior
3.1. Our platform is used by our clients to send you information pertaining to the brand. The information sent to you either via broadcast messages or chat messages is specific to the brand that you are following.
3.2. Only the brand that you are following on WeChat is permitted to send you any material that will be in the form of broadcast messages, template messages, chat messages or QR codes and not exclusive of those, that will enable you to interact with the brand.
3.3. WeChat natively imposes multiple limitations in the ability of the brand to send you marketing content
- Limit the number of times you see broadcast messages per month
- Ensure that they cannot send you video, audio or text messages more than 48 hours of inactivity at your end
- To serve you with advertisements likely to be relevant to you based on your activity, your engagement with the brand and ads which is recorded using your WeChatID, and to use your general geographic area.
3.4 You can opt out of brand-based advertising on WeChat by unfollowing the account.
4. User tracking
Weixin uses open ID which is unique to your ID for the particular brand. We track your activity in WeChat using your Open ID or Union ID based on the group of accounts that you follow relating to a particular brand.
The Personal Data Processed for the WeChat Followers concern the following categories of data (please specify):
- First Name
- Last Name
- Email ID
- Phone Number
The Personal Data Processed will be subject to the following basic processing activities:
- The Personal Data will be associated with the WeChat follower ID (Open ID).
- PII form data will be tokenized and sent to Salesforce Marketing Cloud Data Extensions.
- PII data (i.e. First Name, Last Name, Phone Number and Email ID) collected after consent from WeChat followers will be stored on WeChatify servers in China.
5. LEGAL BASIS FOR PROCESSING PERSONAL INFORMATION
Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will normally collect personal information from you only where
- We need the personal information to perform a contract with you,
- The processing is in our legitimate interests and not superseded by your rights, or
- We have your consent to do so.
(a) Under our terms of service, “performance of contract” as a legal basis for processing your information refers to when we create an event for example and require your information in order to inform you of service-related changes and its progress.
(b) We process your personal data on the basis of our legitimate interests for example when you provide personal information to register for an event, when we need to serve interest based advertisements to you, carry out marketing within the prescribed limits, analyzing the users’ behavior across the account, and moderating chat discussion.
(e) If our clients ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
(f) Chatly shall inform THE CUSTOMER immediately if, in Chatly's reasonable opinion, Chatly believes that any instruction given by THE CUSTOMER infringes Data Protection Laws.
(g) Chatly's Processing of Personal Data shall comply with its obligations under Data Protection Laws and Chatly shall not perform the Services in a manner that causes THE CUSTOMER to violate Data Protection Laws.
If you have questions about, or require, further information concerning the legal basis for collecting and using your personal information, please contact us using the contact information provided in the "Contact Us" page.
6. HOW DOES CHATLY KEEP MY PERSONAL INFORMATION SECURE?
We use appropriate technical and organizational measures designed to protect the personal information that we collect about you and process. The measures we adopt are designed to provide a level of security appropriate for the degree of risk involved with processing your personal information. Specific measures include encrypting your personal information in transit and at rest.
7. CO-OPERATION WITH REGULATORS
Chatly shall provide THE CUSTOMER with such assistance and information as THE CUSTOMER may reasonably request in order for THE CUSTOMER to comply with any obligation to carry out a data protection impact assessment or consult with a Regulator, including the obligations under Articles 35 and 36 of GDPR.
8. INTERNATIONAL DATA TRANSFERS
Your personal information may be transferred to, and processed in, countries other than the country of which you are a resident. These countries may have data protection laws that are different from the laws of your country.
Specifically, our servers are currently located in the Hong kong, China and our business group members, third-party service providers and partners operate around the world. This means that when we collect your personal information we may process it in any of these countries. Personally Identifiable information(PII) like First name, Last Name, Mobile number and email address are stored within China. We ensure appropriate safeguards are in place so that your personal information will remain protected in accordance with this Privacy Notice. This includes complying with the European Commission’s Standard Contractual Clauses for transfers of personal information among companies in our business group and third-party service providers and partners, which require all members of our business group to protect the personal information they process from the EEA in accordance with European Union data protection law. It also includes the transfer of personal information to third-party service providers and partners that are certified under the EU-US Privacy Shield.
9. DATA RETENTION
We retain personal information we collect from you where we have an ongoing legitimate business need to do so. For example, to provide you with a Service you have requested, or to comply with applicable legal, tax or accounting requirements. For example, we periodically de-identify unused accounts and regularly review and de-identify unnecessary personal information.
When we have no ongoing legitimate business need to process your personal information, we will either delete or de-identify it, or, if this is not possible – for example, because your personal information has been stored on a backup server – then we will securely store your personal information and isolate it from any further processing until deletion.
10. YOUR DATA PROTECTION RIGHTS
You have the following data protection rights:
(a) To access, correct, update or request deletion of your personal information. You may do so in your account settings (via "Terms of Service and Privacy Notice") or by contacting us using the information in the "Contact Us" section below.
(b) To object to the processing of your personal information (which is processed on the grounds of legitimate interests), ask us to restrict processing of your personal information or request portability of your personal information. Again, you may do so by unfollowing the official account, or by contacting us using the information in the "Contact Us" section below so we can assist you in ensuring all of your personal information is removed from our servers.
(c) To opt out of marketing communications sent by our clients using our platform, at any time. You can exercise this right by clicking by unfollowing the official account.
(d) If we are processing your personal information with your consent, you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal information conducted pursuant to lawful processing grounds other than consent. You may do so by contacting us using the details at "Contact Us" heading below. We will respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
11. AGE LIMIT
12. UPDATES TO THIS PRIVACY NOTICE
We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, in accordance with the significance of the changes we make.
13. HOW TO CONTACT US
Data controller: Chatly Inc, New York, USA
You can exercise your right to access personal information, request the deletion of personal information or unfollow the official account