Last updated: 29 January 2020
- What information we collect
- Information you provide
- Information collected automatically
- Information collected by Third Parties
- How we use your information
- Disclosure of your information
- How long we retain your information
- Information about children
- Direct Marketing
- Privacy Rights
- International Users
- Business Transfers
- How to contact us
- WHAT INFORMATION WE COLLECT
- INFORMATION YOU PROVIDE
You provide information to us through the following activities:
When You Use the Device or the App
When you use the Device or the App, we will collect certain Personal Information such as your name, mailing address, email address and physiological data, such as gender, age range and scan data, to provide you with the Service.
To the extent such Personal Information is subject to the European Union’s General Data Protection Regulation (“GDPR”) or similar regulations, we will obtain your explicit consent to collect and process your Personal Information. We will obtain your explicit consent prior to collecting your Personal Information, for example, when you create an iTOVi Account or when you agree to be scanned for the first time.
When you Create an iTOVi Account
When You Self-Report Information
You have the option to participate in contests, giveaways, surveys and questionnaires. Information gathered from these sources may be used to improve the Service. Participation in such self-reporting is strictly voluntary and not required for use of the Service.
When You Make Purchases from Our Store
We store your shipping address, billing address and purchase history to provide excellent service. We do not, however, view or store your credit card information. This is handled by our third-party payment processor. We also save shipping data so that we can provide customer service related to the purchase.
When You Contact Us
- INFORMATION COLLECTED AUTOMATICALLY
Access and Usage Information
We collect anonymized information about your usage of the Device and Service; for example, how often you use the device, how often you charge the device, when you connect or disconnect the Device over Bluetooth, which app screens you look at most often, which app features are used most often, and location data associated with your usage. This information is used to improve the product and service.
When you access the Service through the Site, regardless of whether you have an Account, we may collect certain information automatically and store it on our servers. This information may include internet protocol (IP) address or an anonymised shortened IP address for your device.
- PERSONAL INFORMATION COLLECTED BY THIRD PARTIES ON THE SITE AND THROUGH THE SERVICE
We, or third party service providers acting on our behalf, may use web beacons and pixel tags to help us analyze usage and improve our functionality. Web beacons and pixel tags are images embedded in a webpage or email for the purpose of measuring and analyzing usage and activity. In addition to allowing third-parties to collect information from you while using the Service, we may collect information regarding your use of third-party sites and services. Currently, we use pixel tags on Facebook and Twitter to help us understand how effective our marketing is on those sites.
- HOW WE USE YOUR INFORMATION
iTOVi will use and share your Personal Information with third parties only in the ways that are described in this Privacy Statement.
To provide you with Services and analyze and improve our Services
We use the information described above in Section 2 to operate, provide, analyze and improve our Services. These activities may include, among other things, using your information in a manner consistent with this Privacy Statement to:
provide you with the Service;
improve the Service and our other products and services;
customize the Service for you;
conduct research about your use of the Service;
better understand our users;
communicate with you about the Service and our other products and services that we think may interest you;
inform you about events;
invite you to participate in new initiatives or feature and product upgrades;
conduct surveys or polls, and obtain testimonials or for other promotional purposes;
perform quality control activities; and
diagnose and fix problems with the Service.
For individuals located in the European Economic Area (“EEA”), United Kingdom, or Switzerland (collectively the “Designated Countries”): We process your Personal Information in this way to provide our Services to you in accordance with our Terms of Service.
- DISCLOSURE OF YOUR INFORMATION
Third-party service providers
We may, from time to time, outsource some or all of the operations of our business to third-party service providers or partner with third parties for special projects or initiatives, including the development of new products or services (including, for example, companies that provide us with technical support and assistance with respect to the Site and the App, financial institutions who process payment for orders placed by you, our suppliers and other third parties who facilitate delivery of the products and services you have ordered, and third parties who assist us with research to help us improve the Site and the App and our product offerings). We may also share anonymised information with research partners solely for research purposes. We aim to provide such third parties with the minimum amount of Information needed for the purpose of accomplishing their tasks.
Legal Investigations and requests
Under certain circumstances your Personal Information may be subject to processing pursuant to laws, regulations, judicial or other government subpoenas, warrants, or orders. For example, we may be required to disclose Personal Information in coordination with regulatory authorities in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Protection of iTOVi and others
We may also share aggregated or anonymized information, which cannot be used to identify you, with third parties for purposes including marketing and research or to sell to interested parties.
- HOW LONG WE RETAIN INFORMATION
- INFORMATION ABOUT CHILDREN
iTOVi does not knowingly collect personal information from children under 16 without parental consent. If you are under 16 years of age, you should not use the Service or send information about yourself to us without parental consent. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have information from or about a child under 16, without parental consent, please contact us as described below.
- DIRECT MARKETING
We will obtain your consent where required to send you marketing communications using electronic means. You may withdraw your consent at any time within your Account Settings, clicking unsubscribe on the communication or by emailing firstname.lastname@example.org.
We will only share your Personal Information with third parties for marketing purposes with your explicit consent. If you do not want us to use your Personal Information in this way, please review and update your Account Settings as necessary or contact us at email@example.com. You may raise such objection with regard to initial or further processing for purposes of direct marketing at any time and free of charge. The withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
Other marketing activities will happen based on the legitimate interests of iTOVi. E.g., where we tailor marketing communications or send targeted marketing messages via post, phone or social media and other third party platforms; and in providing existing customers with information (via email or other channels) about similar products and services.
- PRIVACY RIGHTS
You can exercise your privacy rights by following the instructions below. We will handle your request under applicable law. When you make a request, we may verify your identity to protect your privacy and security.
Right to Access and Rectification
You can view and update the content and accuracy of your Registration Information or Personal Information at any time. Certain information is editable through the app or the web portal, other information is editable by contacting us at firstname.lastname@example.org.
Right to withdraw consent
To the extent iTOVi requests and you provide your consent to the processing of your Personal Information, you can withdraw your consent at any time. Your withdrawal will not affect the lawfulness of our processing based on consent before your withdrawal. You may withdraw your consent for marketing communication through user settings in the app or the web portal. Please contact Customer Support at support@iTOVi.com for any other concerns.
Right to be forgotten
You can delete your Personal Information by contacting Customer Support at support@iTOVi.com. When you do, your Personal Information will be removed from the Service. Backup copies of this data will be removed from our server based upon an automated schedule, which means it may persist in our archive for a short period. iTOVi may continue to use your anonymized data.
Right to data portability
If we process your Personal Information based on a contract with you or based on your consent, or the processing is carried out by automated means, you may request your Personal Information in a structured, commonly used and machine-readable format. You may also request the transfer of your Personal Information directly to another controller, where technically feasible, unless choosing to exercise this right adversely affects the rights and freedoms of others. A “controller” is a natural or legal person, public authority, agency or other body which alone or jointly with others, determines the purposes and means of the processing of your Personal Information.
Right to restriction of our processing
You can restrict our processing of your Personal Information where one of the following applies: (a) you dispute the accuracy of Personal Information processed by iTOVi (for a period enabling us to verify its accuracy); (b) the processing is unlawful and you oppose the erasure of the Personal Information and request the restriction of its use instead; (c) iTOVi no longer needs the Personal Information for the purposes of the processing, but it is required by you for the establishment, exercise or defense of legal claims; and (d) you have objected to certain processing relying on legitimate interest, pending the verification whether iTOVi’s legitimate grounds override your rights. Restricted Personal Information shall only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest. We will notify you if the restriction is lifted.
We acknowledge consumers rights under the California Consumer Privacy Act to opt out of the sale of personal information to third parties. iTOVi does not engage in the sale of personal information.
iTOVi takes seriously the trust you place in us. We implement appropriate security measures, including physical, technological and procedural measures to protect your Information. We have implemented measures designed to protect against the unauthorized access, interception, loss, misuse and or alteration of the Information under our control.
Please recognize that protecting your Personal Information is also your responsibility. We ask you to be responsible for safeguarding your password and other authentication information you use to access the Service. You should not disclose your authentication information to any third party and should immediately notify iTOVi of any unauthorized use of your password. iTOVi cannot secure Personal Information that you release on your own or that you request us to release.
- INTERNATIONAL USERS
iTOVi is located in the United States and the Service is hosted and operated entirely in the United States. If you reside outside the U.S., your Information will be stored and processed in the United States. By voluntarily sharing your Personal Information with us, you understand that your Personal Information will be stored and processed in the United States.
With respect to Information received under the Privacy Shield Framework, iTOVi is subject to the investigatory and enforcement authority of the U.S. Federal Trade Commission. Under certain circumstances, we may be required to disclose Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Under the Privacy Shield Framework, iTOVi will offer an individual the opportunity to choose (opt-out) whether Information about them will be disclosed to a third party or used for a purpose incompatible with the purpose for which it was originally collected or subsequently authorized by them, unless such choice is not required by law.
Where a complaint relates to Information transferred or received pursuant to the Privacy Shield Framework, you should first contact iTOVi using the contact information provided below. We will investigate and attempt to resolve any questions or complaints you may have within 30 days of receipt. If iTOVi is unable to resolve your complaint through its internal processes or you are dissatisfied with the response, you may file a complaint with JAMS, our U.S.- based third party dispute resolution provider, at no cost to you. Please visit https://www.jamsadr.com/file-an-eu-us-privacy-shield-claim for more information or to file a complaint.
Under certain circumstances, EEA individuals may invoke binding arbitration to resolve a Privacy Shield related dispute. In order to invoke arbitration, you must take the following steps prior to initiating an arbitration claim: (1) raise your complaint directly with iTOVi and provide us the opportunity to resolve the issue; (2) make use of the independent dispute resolution mechanism, in this case JAMS; and (3) raise the issue through your relevant data protection authority and allow the U.S. Department of Commerce an opportunity to resolve the complaint at no cost to you. For more information on binding arbitration, see the U.S. Department of Commerce’s Privacy Shield Framework: Annex I (Binding Arbitration).
Individuals in the EEA have certain data subject rights which may be subject to limitations and/or restrictions. These rights include the right to: (i) request access to and rectification or erasure of their Information; (ii) obtain restriction of processing or to object to processing of their Information; and (iii) ask for a copy of their Information to be provided to them, or a third party, in a digital format, as well as how that data has been used. If you wish to exercise one of the above-mentioned rights, please send us your request to the contact details set out below. Individuals also have the right to lodge a complaint about the processing of their Information with their local data protection authority.
California Civil Code Section § 1798.83 permits users of our Services that are California residents to request certain information regarding our disclosure of Information to third parties for their direct marketing purposes. To make such a request, you may contact us as described below.
- BUSINESS TRANSFERS
- CONTACT US
email@example.com or by mail to the following address:
355 South 520 West
Lindon, UT 84042