Last updated: 3rd November 2023
This Privacy Notice describes how yuMuuv OÜ (a company incorporated under Estonian law with registry code 14636730 and registered address at Savi 4C, 50405 Tartu, Estonia; “YuMuuv” or “we”) collects, uses or otherwise processes and safeguards data relating to individuals (“data subjects” or “you”) who use our website accessible at www.yumuuv.com and our mobile application (jointly hereinafter - “YuMuuv Platform”), and with whom we otherwise interact, including in the course of providing our services via the YuMuuv Platform. The controller of your personal data is YuMuuv. You can contact us by e-mail at firstname.lastname@example.org
YuMuuv is responsible for ensuring that your personal data is processed in accordance with this Privacy Notice and applicable data protection laws, in particular with the General Data Processing Regulation (EU) 2016/679.
1. PERSONAL DATA WE COLLECT AND HOW WE USE IT
Personal data means any information relating to an identified or identifiable natural person. We usually collect personal data directly from data subjects when data subjects interact with the YuMuuv Platform. We may also collect personal data through integrations with third-party applications and wearable devices such as Google Fit, Apple Health, Garmin, Fitbit, Suunto, Polar, if the data subject has allowed such integrations.
1.1. Registering an account to access our services
To register an account to access our wellness-related services via the YuMuuv Platform, we request you to enter your e-mail address and select a password. If you decide to register an account through a third-party service provider, we may collect personal data that is associated with your third-party service provider’s account, such as your name, e-mail address, language preference and profile picture.
The legal basis for the processing of your personal data for these purposes is our legitimate interest to create your unique account and to provide you with access to the YuMuuv Platform.
1.2. Using our wellness-related services and other features
For the purposes of providing you our wellness-related services and other features, such as to track your personal progress and issue activity reports, enable you to organise challenges and participate in them, interact with other users using chat functionalities, we process your personal data which are required to provide the service or functionality requested by you. These data may include your name, e-mail address, age, gender, language preference, weight and height, data about your physical activity (including type, date and duration of activity, steps, distance, burned calories, activity reports), challenges you organise and where you participate, company or organisation you are a part of, and any other data you provide while using the YuMuuv Platform. The legal basis for the processing of your personal data for these purposes is the performance of the contract with you or our legitimate interest to perform the contract with the legal entity you represent.
Some of the data processed for this purpose may constitute special categories of personal data (particularly, data concerning your health). The legal basis for the processing of such data is your explicit consent. You may withdraw your consent at any time. Also, if you decide to use our services by integrating other wellness applications and wearable devices with the YuMuuv Platform, we may collect certain personal data that is associated with these applications and devices on the basis of your consent. You may terminate such integrations by withdrawing your consent at any time via the YuMuuv Platform or under the settings of the used application or device.
Please note that when you participate in challenges, your certain activity data may be disclosed to other users that have entered the same challenge. Your health data or other special categories of data will not be disclosed to other users for this purpose.
1.3. Inquiries and responses
If you submit an inquiry to us via the YuMuuv Platform, including to book a demo of our offered services, we collect some of your personal data depending on the content of the submitted inquiry. For these purposes, we may process your personal data, such as your name, e-mail address, the entity you represent, means of the proposed meeting, details on additional participants and other content of the inquiry (if applicable).
The legal basis for the processing of your personal data is the implementation of pre-contractual measures prior to the conclusion of the contract with you (or the entity you represent on the basis of our legitimate interest), or our legitimate interest to respond to inquiries about us and our services in general. If your request relates to our contractual relationship, the processing of your personal data is based on our obligation to perform our contractual obligations.
1.4. Improving and developing the YuMuuv Platform, including for security purposes
The legal basis for the processing of your personal data for this purpose is our legitimate interest in improving our understanding of our partners’ and users’ needs and preferences in order to constantly enhance the functioning of the YuMuuv Platform, including by conducting analytics and ensuring the technical availability and security of the YuMuuv Platform.
1.5. Management of contractual and business relationships
For the purposes of managing our contractual and business relationships, including databases of our partners, we may process your personal data on the basis of our legitimate interest in maintaining such legal relationships. Primarily, this processing concerns the name and contact details of our business partners’ representatives, as well as our correspondence with them. For this purpose, we may also process information about our business customer’s payments and transactions, such as type of subscription, used payment method, details of used bank account. These types of information may, to a limited extent, contain personal data.
1.6. Compliance with our legal obligations
For compliance purposes which derive from applicable law, for example, accounting and tax laws, we may process your personal data on the basis of the respective legal provision obliging us to process the relevant data. This also applies to the processing of your personal data regarding payments and transactions.
1.7. Direct marketing
If you opt in to receive our push notifications and/or e-mail communication from us on the YuMuuv Platform, and you consent to receive such communications, we may send you push notifications and/or use your e-mail address for the purpose of sending you updates, offers and other marketing material.
The legal basis to provide you with direct marketing is your consent. You may withdraw your consent at any time to stop receiving such communications.
1.8. Establishing, exercising and defending any potential legal claims
If necessary, we may process your personal data in order to establish, exercise or defend legal claims arising out of or in relation to the legal relationship between us and you (or the entity you represent) on the basis of our legitimate interest.
2. DISCLOSURE AND TRANSFER OF PERSONAL DATA
We put our best efforts to keep your personal data safe and always require a high level of security and confidentiality from our employees and partners.
We may disclose and share certain categories of your personal data:
- with other users when you participate in the wellness-related challenges (including to organisers of such challenges);
- with our trusted services providers when they provide services to us or to you, on behalf of us and under our instructions (such as cloud-based and payment service providers, IT-support, legal and accounting service providers, etc.). We will control and shall remain responsible for the use of your personal data in such cases;
- with our partners, who provide us with tools for analytics (who may, in particular, process statistical browsing data, such as Google Analytics);
- to public authorities if we are required to disclose personal data by applicable law or to comply with a lawful request of authorities; and
- in relation to a merger, acquisition or sale of our business or its part(s).
We may transfer your personal data outside of the European Economic Area in limited cases. In such a case, we implement adequate safeguards to protect your personal data, such as the standard contractual clauses for transfers established by the European Commission. You can contact us to get more information about the transfers of your personal data, for this please use the contact details brought out in the beginning of this Privacy Notice.
3. RETENTION OF YOUR PERSONAL DATA
We process your personal data only for as long as necessary for the fulfilment of the original purposes of personal data processing described above. Most of your personal data will be kept until the end of the legal relationship with us, i.e. until your account on the YuMuuv Platform is active. However, we may keep some of your personal data for longer, if this is necessary to achieve our legitimate interests or where this is required to fulfil our obligations deriving from applicable law.
We determine the appropriate retention period for personal data on the basis of the amount, nature, and sensitivity of the personal data being processed, the potential risk of harm from unauthorised use or disclosure of the personal data, whether we can achieve the purposes of the processing through other means, and on the basis of applicable requirements deriving from applicable law.
When the retention of your personal data is no longer necessary to achieve the purposes of processing, your data will be permanently removed, unless you instruct us otherwise and we agree on the terms on longer storage of your data.
4. YOUR RIGHTS AS A DATA SUBJECT
By contacting us at the contact details provided in the beginning of this Privacy Notice, you may exercise your rights as the data subject to the extent permitted under applicable law, including the following rights:
- You may request access to your personal data;
- To the extent permitted under applicable law, you may request us to correct, update, change or erase your personal data. In some cases you may also have a right to object to processing of your personal data;
- If you request the erasure of your personal data, please note that certain personal data is strictly necessary in order to fulfil the purposes defined in this Privacy Notice and the processing of which may also be required by applicable law. If personal data is erased under your request, we will only retain such copies of the information as are necessary for us to protect our or third parties’ legitimate interests, comply with authorities’ orders, resolve disputes, troubleshoot problems, or enforce any agreement you have (or the entity you represent has) entered into with us. Therefore, such personal data may not be erased in full;
- You may withdraw your consent regarding the processing of your personal data, where the legal basis for processing is your consent. Please note that withdrawal of consent does not affect the lawfulness of the processing of personal data carried out on the basis of consent before withdrawal;
- You may use your right to data portability. In some cases we may limit or deny your request if we are required or permitted by applicable law to do so, e.g. if it is necessary for the purpose of our legitimate interest to protect our trade secrets or any other confidential information; and
- To the extent permitted under applicable law, you may request more information about our legitimate interest and why we think our legitimate interest overrides your rights and interests as a data subject. This applies where the legal basis for the processing of your personal data is our legitimate interest.
We will respond to your requests and to provide you with additional privacy-related information within the timeframes specified in applicable personal data protection law. Please note that we may ask you for additional information to adequately verify your identity before taking action on your request to exercise your rights as a data subject.
If you are not satisfied with our response or have a concern that your privacy rights have been infringed, you have the right to lodge a complaint with your local supervisory authority. List and contact details of European supervisory authorities can be found here.
5. SECURITY MEASURES
We implement reasonable technical and organisational measures (including physical, electronic and administrative) to protect your personal data from loss, destruction, misuse and unauthorised access or disclosure, including by implementing additional restrictions or measures for safeguarding special categories of personal data (in particular, health data) which are, for instance, retained separately from any other personal data.
Please note that no method of transmission over the Internet, or method of electronic storage, is fully secure. While we use all reasonable efforts to protect your personal data from loss, destruction, unauthorised access, misuse, or disclosure, we cannot fully guarantee the security of your personal data.
6. UPDATES TO THIS PRIVACY NOTICE
From time to time, we may update this Privacy Notice in order to adapt it to any updates that might arise. In case of making any substantial update, we will notify you via the e-mail that you have, or the company on behalf of whom you use our services has, communicated us. This Privacy Notice was last updated as of the “Last updated” date indicated above.