Sociogram’s Privacy Policy
At Sociogram, we respect your privacy and want to give you the best possible experience to ensure that you enjoy our Service. Your privacy and the security of your Personal Data are, and will always be, enormously important to us. So, we want to transparently explain how and why we collect, store, share and use your Personal Data - as well as outlining the rights, controls and choices you have in respect of Personal Data we hold about you.
Capitalised terms used in this Privacy Policy have the meanings given to them in the Definitions section below. Unless specifically defined, any capitalized term used throughout this Privacy Policy (but not defined herein) shall have the same meaning attributed to it in Sociogram’s General Terms and Conditions.
Please read this Privacy Policy carefully before using the Platform or submitting any information to us. This Privacy Policy will be binding upon you when you accept the Privacy Policy by clicking on the “agree” button on the Platform. We may, from time to time, amend this Privacy Policy or parts of it in accordance with clause 1.2 below. If you do not agree to any part of this Privacy Policy, you must immediately cease accessing our Platform or using any of our Services.
Sociogram Technologies (company number 1061675) is incorporated in the Dubai Economic Department. Sociogram will act as the Controller for the purposes of the applicable laws (including the DIFC Data Protection Law No 5 of 2020, as may be amended) and can be contacted as indicated in the “How to Contact Us” section in clause 14 below.
Definitions:
- “Account Data” has the meaning attributed to it in clause 2.1.g.
- “Commissioner” means the person appointed by the President of the DIFC pursuant to Article 43(1) of the Data Protection Law 2020, Law No. 5 of 2020 as may be amended.
- “comply with a legal or regulatory obligation” means processing your Personal Data where it is necessary for us to comply with a legal or regulatory obligation.
- “Contact Data” has the meaning attributed to it in clause 2.1.b.
- “Contacts Data” has the meaning attributed to it in clause 2.1.j.
- “Controller” means Sociogram, which alone or jointly with others determines the purposes and means of the processing of Personal Data.
- “Controller” means Sociogram, which alone or jointly with others determines the purposes and means of the processing of Personal Data.
- “Data” means personal and non-personal User’s data that is submitted, generated, featured and displayed through the Platform, collected from the use of the Service and stored on Sociogram’s servers.
- “Financial Data” has the meaning attributed to it in clause 2.1.e.
- “Geolocation Data” has the meaning attributed to it in clause 2.1.d.
- “Identifiable Natural Person” means a natural living person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to his biological, physical, biometric, physiological, mental, genetic, economic, cultural or social identity.
- “Identity Data” has the meaning attributed to it in clause 2.1.a.
- “Performance of our Services” means processing your Data where it is necessary for the performance of our Services
- “Personal Data” means any information referring to an identified or Identifiable Natural Person.
- “Platform” means any online tool provided, processed and/or maintained by Sociogram (including, but not limited to, all subpages and subdomains, all Content, Services, and products available at or through Sociogram’s mobile application, website located at www.sociogram.com and/or any other related domain offering access to, or facilitating the provision of, the Services);
- “Privacy Policy” means all of the privacy policies, practices and notices contained or referenced in this document (as amended from time to time) and all other Sociogram rules and policies in relation to our data practices that may be published from time to time on the Platform.
- “process”, “processed”, “processes” and “processing” (and other variants) collectively mean any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage and archiving, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, transfer or otherwise making available, alignment or combination, restricting (meaning the marking of stored Personal Data with the aim of limiting Processing of it in the future), erasure or destruction, but excluding operations or sets of operations performed on Personal Data by: (a) a natural person in the course of a purely personal or household activity that has no connection to a commercial purpose; or (b) law enforcement authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security.
- “Profile Data” has the meaning attributed to it in clause 2.1.c.
- “Services” means any online and/or offline services provided to Users by Sociogram as set out in Sociogram’s General Terms and Conditions.
- “Sociogram’s General Terms and Conditions” means Sociogram’s general terms and conditions, all of the terms, conditions and notices contained or referenced in those general terms and conditions and all other Sociogram rules and policies available at [x], as amended from time to time.
- “Technical Data” has the meaning attributed to it in clause 2.1.f.
- “Usage Data” has the meaning attributed to it in clause 2.1.h.
- “User”, “you” and “your” collectively mean the person that has visited or is using the Platform and/or the Service. A User may be, without limitation, a Creator, a Participant, both or neither.
- Important Information
- Purpose of This Privacy Policy:
This Privacy Policy aims to give you information on how Sociogram collects and processes your Personal Data through your use of the Platform, including any Data you may provide throughout the Platform when you install and sign up to Sociogram’s mobile application, register an Account, use any Service and/or sign up to our newsletter.
This Privacy Policy applies to your use of our Services and all information we collect through our Services. By clicking on the agree button on the Platform, you (i) agree irrevocably and without condition to this Privacy Policy, (ii) consent to your Personal Data being collected, processed, used and shared in accordance with this Privacy Policy, and (iii) agree that we may provide notices to you electronically on the terms and conditions set forth in this Privacy Policy and Sociogram’s General Terms and Conditions.
It is important that you read this Privacy Policy together with Sociogram’s General Terms and Conditions, and any fair processing notice we may provide on specific occasions when we are collecting or processing Personal Data about you so that you are fully aware of how and why we are using your Personal Data. This Privacy Policy supplements the other notices and is not intended to override them.
If you are a resident of the European Union, you may be protected by and enjoy additional rights under the European Union’s General Data Protection Regulation 2016/679, also known as GDPR.
- Changes to the Privacy Policy
You agree that Sociogram may amend this Privacy Policy from time to time, and in Sociogram’s sole discretion. Sociogram will, where possible, provide you with 7 days’ notice of any amendments to this Privacy Policy.
Sociogram will publish any amendment or change to this Privacy Policy or any part of it on the Platform and will specify the date on which such amendment becomes effective. Your continued use of the Platform and/or any Service after the stated effective date constitutes your acceptance of the relevant revised policy, amendment or change.
You agree and undertake to review our Privacy Policy each time you visit our Platform and/or prior to each use of our Services. If you do not agree to our Privacy Policy, as updated from time to time, you undertake to cease using our Platform and/or Services immediately.
- Your Duty to Inform Us of Any Changes in Your Personal Data
Please note that it is crucial to the Performance of our Services and correct working of the Platform that the Personal Data we hold about you is accurate and current. Please keep us informed and updated if your Personal Data changes during your relationship with us. You can review and update your Personal Data in your Account settings at any time by logging in to your Account.
- Scope of this Privacy Policy
This Privacy Policy does not apply to information that you have provided or made accessible to other Users (including Creators) or third parties. Each User is solely responsible for complying with all requirements of applicable privacy laws in connection with the information that they obtain and process for the purposes of managing their contacts or joining, organizing or communicating through Activities, Groups or Clans.
Our Platform may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share Data about you. We do not control these third-party websites, plug-ins and applications, whether or not they operate on top of the Platform or on an external website, and are not responsible for their privacy statements. When you engage such third-party website, plug-in or application, whether or not you have left our Platform, we encourage you to read the privacy policy of each website, plug-in or application you visit or engage.
- The Data We Collect About You
- Depending on which of our Services you use and how you interact with our Platform, we collect different kinds of information from or about you. We may collect, use, store and transfer different kinds of Personal Data about you which we have grouped together as follows:
- Identity Data includes first name, last name, nickname, gender, date of birth, photograph and nationality.
- Contact Data includes physical address, email address, mobile number, and WhatsApp number.
- Profile Data includes your hobbies, spoken languages, interests, preferred locations to perform activities, preferred timing to perform activities and favourite colours.
- Geolocation Data includes the location of your device each time you use our Platform based on your consent to the collection of this information, such as when you enable location services.
- Financial Data includes bank account details (such as name of bank, SWIFT code, branch name and branch address, account number, account name, type of account, IBAN number and currency). Sociogram does not store or maintain your bank account credentials (username and password).
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, model of your mobile phones and computers and their device identification number, operating system, hardware version, device settings and other technology identification on the devices used to access our Platform, file and software names and types, time zone setting, device locations such as through GPS, Bluetooth or WiFi signals, browser plug-in types and versions, connection information such as the name of your mobile operator or ISP, or language setting.
- Account Data includes User Account information such as Sociogram username, password, privacy setting and profile picture.
- Usage Data includes information about how you use our Platform, Services and how you use your devices to access our Platform, including the pages you visit and searches you make.
- Marketing and Communications Data includes your preferences in receiving marketing from us and your communication preferences.
- Contacts Data includes contact information that we collect from your contacts when you invite your contacts to use our Platform (e.g. when you invite your phonebook contacts). This includes your contacts’ Identity Data and Contact Data.
- Other Personal Data includes:
- any other data uploaded onto our Platform by you or shared with other Users of our Platform by you via our Platform;
- communications with us via social media platforms, email, electronic messages and other electronic and non-electronic communications;
- third party partner information related to how you use our third-party partners, such as your reviews of our partners or other service providers;
- your networks and connections made available to us, depending on the permissions you have granted, from your mobile and desktop devices, and social media channels such as WhatsApp, Facebook, Instagram and Twitter.
- We also collect, use and share aggregated Data such as statistical or demographic Data for any purpose. Aggregated Data may be derived from your Personal Data but is not considered Personal Data as this Data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of Users accessing a specific Platform feature.
- We are dedicated to providing a safe and secure Service. Therefore, before permitting you to use the Services, we may require and collect additional information from you which we can use to verify your identity or other information or to manage risk and compliance throughout our relationship.
- We may also collect additional information from or about you in other ways. For example, we may collect information related to your contact with our customer support team or store results when you respond to a survey or provide us with your feedback.
- We do not collect any Personal Data about racial or ethnic origin, communal origin, political affiliations or opinions, religious or philosophical beliefs, criminal record, trade-union membership, health, sex life or genetic data.
- Where we need to collect Personal Data by law, or under the terms of a contract we have with you and you fail to provide that Personal Data when requested, we may not be able to perform our Services. In this case, we may have to cancel the Service which you have with us. We will notify you if this is the case at any time.
- How Is Your Personal Data Collected?
We use different methods to collect Personal Data from and about you through the following categories of sources:
- When you communicate with us in writing, by telephone, fax, email or through the Platform or other forms of electronic communication or when you submit information to us or allow us to access information;
- Social media channels. If you register or log into your Account through a third-party social media service, we will have access to some of your third-party account information from that service, including identifiers, such as your name and other information in that account;
- User Content. We may receive Personal Data about you when you or another User uploads photos or posts other Content on the Platform
- Your devices and how you interact with our Services. This includes Personal Data you provide when you:
- enter data for installing or using any Sociogram powered application;
- open a Sociogram Account or provide Sociogram Account information;
- choose interests or fill out a form;
- look for, join, create, list, organize or manage Activities, Groups or Clans;
- chat or communicate with other Users through our Platform;
- use our Services;
- connect your device to our Platform, such as your camera roll, contact list or calendar information;
- subscribe to our publications;
- enter a competition, promotion or survey;
- correspond with us (online or offline including via email addresses and phone numbers), if you contact us;
- create or share Content on our Platform; or
- give us feedback and / or review our Services;
- Automated technologies. As you interact with our Platform, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this Personal Data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies;
- Information From Other Third-Party Sources. In order to provide you with more tailored recommendations, we may obtain information about you from publicly and commercially available sources, such as third-party publishers, advertising networks, and service providers that we may use to manage our ads on other sites, and other third parties as permitted by law.
- Our group companies or affiliates;
- Technical Data from the following parties:
- analytics providers such as Google;
- advertising networks/agencies;
- search information providers.
- How Do We Share Your Information?
- Information shared with everyone in the community: We may publicly share some of your Personal Data on the Platform depending on your privacy settings, such as your name, last name, username, nickname, gender, profile photo, interest, preferred locations to perform activities or preferred timing to perform activities. We provide as many options as possible for Users to consider and decide what information they would like to share with others. Some Personal Data, such as gender, interests or profile photo, is public by default, but can be hidden on our Platform. Some Personal Data, such as Group or Clan memberships, will always be visible to other members of that Group or Clan, and may be public, depending on the settings of that Group or Clan. For example, if a User chooses to remain anonymous, s/he may not be found in the search results on the Platform; however, when such User is connected to another User via friends list or an Activity Group, the photos, full name, age, location, interests, activity statistics, previous and future Activities, ratings and posts of such User can be seen by the other User. Similarly, when joining a Clan, some of such User’s Personal Data (such as full name, photo and ratings) will be seen by the other members of that Clan, irrespective of whether the User’s profile settings are set to private.
We recommend that you check your privacy settings and what information will be available to others before using our Services to ensure that you are happy with the information that is visible to others. Depending on your privacy settings, your Personal Data may be visible to all Users on the Platform and may be seen by anyone on the internet, whether or not they have a Sociogram Account. Public information may also be seen, accessed, or used through third-party services that integrate with our Services. - Information shared with other Sociogram Users: We may share Personal Data with the Users that you interact with through the Platform. When you register for an Activity, join a Group or Clan, sign up for communications, enter a contest, or otherwise input your Personal Data or use chat feature to communicate with other Users or participate in an Activity, other Users may receive your Personal Data. For instance, if you wish to participate in an Activity, the Creator of that Activity will receive some of your Personal Data (such as your full name, profile photo and profile ratings) depending on your privacy settings.
Creators may share your Personal Data with the Service Providers that provide services to the Creators and Participants in relation to an Activity for the creation, performance and/or delivery of that Activity. We are not responsible for the actions of other Users, Service Providers or third parties with respect to your Personal Data. - Information shared with our affiliates and group companies: We may share your Personal Data with our affiliates and group companies to understand how you engage with Sociogram, to improve our Services, and to help us build Services tailored to your preferences.
4.4 Information shared with our service providers: We may share your Personal Data with:
- Third party service providers that assist us in providing our Services to you (for example, email transmission, conducting surveys or contests, data hosting, customer support);
- Our professional advisers where it is necessary for us to obtain their advice or assistance, including lawyers, accountants, IT or public relations advisers;
- Service providers that help us run our marketing and advertising campaigns, special offers, or other events or activities;
- Other third parties with your consent or at your direction to do so, including if you authorize an account connection with a third-party account or platform. For the purposes of this Privacy Policy, an "account connection" with such a third party is a connection you authorize or enable between your Sociogram Account and a non-Sociogram account or platform that you lawfully control or own. When you authorize such a connection, we may receive information from the third-party service about you and your use of the third-party’s service and share your Personal Data and other information in accordance with such third party’s privacy policy. Examples of account connections include, without limitation, linking your Sociogram account to a social media account or social messaging service. Information that we share with a third-party based on an account connection will be used and disclosed in accordance with the third-party’s privacy practices. Before authorizing an account connection, you should review the privacy notice of any third-party that will gain access to your Personal Data as part of the account connection.
- Business Transfer: In the event that Sociogram is involved in a merger, acquisition, reorganization, sale of assets or bankruptcy, your information may be transferred as part of that transaction. The promises in this Privacy Policy will apply to your information as transferred to the new owner or entity.
- Protection of Sociogram and Others: We may release Personal Data when we believe that disclosure is reasonably necessary (i) to comply with any applicable law, regulation, legal process or governmental request; (ii) to exercise or defend our legal rights; (iii) to enforce or comply with Sociogram’s General Terms and Conditions or other applicable agreements or policies; (iv) to protect our or our customers’ or the public rights or property, or the security or integrity of our Services from harm, fraud, or potentially prohibited or illegal activities or otherwise; or (v) for an investigation of suspected or actual illegal activity.
- Aggregated and Anonymized Information: We may share aggregated and anonymized information that does not specifically identify you or any User of our Services with service providers or other third parties.
- How We Use Your Personal Data
We may collect, use and share your Personal Data for the following reasons:
- Performance of our Services: We process your Personal Data because it is necessary for the Performance of our Services. In this respect, we use your Personal Data for the following:
- To verify your identity;
- To enable you to set up a Sociogram Account;
- To determine whether our Services are available in your country;
- To connect you with other Users;
- To display information about you (for instance, your list of interests, which may be visible on your profile);
- To provide you with Sociogram features and Services;
- To identify and fix errors that impair how our Services function;
- To answer any question you may have;
- To deal with any complaints you may have;
- To send you surveys and collect any feedback you may have or to send you information we think you may find useful or which you have requested from us about our Services. For avoidance of doubt, you agree that we may communicate with you in a number of ways for the purpose of collecting your feedback, including through the Platform, by email, telephone, WhatsApp or through other digital channels. Please contact us at hello@sociogram.com if you wish to withdraw your consent to receive communications from us seeking feedback;
- To provide, maintain, improve, personalize and facilitate our Services, Content and features;
- To develop new products and services (such as machine learning based tools) to better serve you;
- To track and analyse usage in connection with your use or the performance of our Services; and
- To issue reports/analytics on a no name basis for business and marketing purposes.
- Legitimate interests: We also process your Personal Data because it is necessary for our legitimate interests, or sometimes where it is necessary for the legitimate interests of another person. In this respect, we use your Personal Data for:
- The administration and management of our business;
- Seeking advice on our rights and obligations, such as where we require legal advice;
- Contacting you to resolve disputes;
- Investigating, detecting, preventing, recovering from, or reporting fraud, misrepresentations, security breaches or incidents, other potentially prohibited, malicious, or illegal activities, or to otherwise help protect your account;
- Protecting your, our, or our other Users' rights or property, or the security or integrity of our Services; and
- Verifying or maintaining the quality and safety of our Services.
- Legal obligations: We also process your Personal Data for our compliance with legal obligations which we are under. In this respect, we will use your Personal Data for the following:
- Meeting our compliance and regulatory obligations, enforcing any applicable laws, regulations, legal requirements, and industry standards and responding to lawful requests for information from the government or to legal process; and
- As required by tax authorities or any competent court or legal authority.
- Marketing: We may send you marketing about the Services we provide which may be of interest to you, as well as other information in the form of alerts, newsletters and invitations to the events or functions which we believe might be of interest to you or in order to update you with information (such as legal or commercial news) which we believe may be relevant to you. We may communicate this to you in a number of ways including through the Platform, telephone, SMS, email or other digital channels. You have the right to withdraw/unsubscribe your consent to marketing emails/newsletters at any time by contacting us at newsletter@sociogram.com.
- Promotional offers from us: We may use your Identity Data, Contact Data, Geolocation Data, Technical Data, Profile Data, Usage Data and Account Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which Services and offers may be relevant for you. You may receive promotional marketing communications from us if you have requested information from us or used our Services and, in each case, you have not opted out of receiving that promotional marketing communication.
- Other reasons: For any other reason for which you provide us with your Personal Data and/or we may tell you about from time to time.
- Our website uses web technologies such as cookies to distinguish you from other users of our site. This helps us to provide you with a good experience when you use our Platform. We use the following cookies:
- Strictly necessary cookies. These are cookies that are required for the operation of our Platform. They include, for example, cookies that enable you to log into secure areas of our Platform.
- Analytical/performance cookies. They allow us to recognise and count the number of Users and to see how Users move around our Platform when they are using it. This helps us to improve the way our Platform works, for example, by ensuring that Users are finding what they are looking for easily.
- Functionality cookies. These are used to recognise you when you return to our Platform. This enables us to personalise our content for you, greet you by your name and remember your preferences (for example, your choice of language or region).
- Targeting cookies. These cookies record your visit to our Platform, the pages you have visited and the links you have followed. We will use this information to make our Platform and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
- Protecting your, our, or our other Users' rights or property, or the security or integrity of our Services; and
- Verifying or maintaining the quality and safety of our Services.
- While we set some of these automated technologies ourselves, some of them are set by third parties who provide services to us. For example, we may use other companies’ web analytics services such as Google Analytics, which use automated technologies to help us evaluate how our Users use our Platform.
- You can set your browser to refuse all or some browser cookies or to alert you when our Platform sets or accesses cookies. If you use a mobile device, you can manage how your device and browser share certain device data by changing the privacy and security settings on your mobile device. If you disable or refuse cookies, please note that some parts of our Platform may become inaccessible or not function properly.
- Change of Purpose
We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your Personal Data without your knowledge or consent, in compliance with this Privacy Policy, where this is required or permitted by law.
Your data security is important to us, and we take reasonable steps to ensure that your Personal Data is treated securely and to minimize unauthorised access to, collection, use, disclosure of your Personal Data, or similar risks.
We have put in place suitable physical, electronic and managerial procedures to put our Users at ease and to safeguard and secure the information we collect. Notwithstanding Sociogram’s culture of transparency, in order to minimise the likelihood of security breaches we do not publicly disclose the nature of such security measures.
Although we aim to create a safe and secure environment, we cannot guarantee absolute security of the transmission or storage of your information. To the extent permitted by applicable law, we expressly exclude any liability arising from any unauthorised access to your Personal Data.
Please contact us at report@sociogram.com immediately if you become aware of any unauthorised use of your Account by anyone else or any other breach of security.
- You May Change Your Personal Information
You may access, review, change, or correct information that you have provided by logging into your Sociogram Account (in your Account settings) at any time. We may require additional information to verify your identity before granting access or otherwise changing or correcting your information.
- You May Deactivate Your Account
If you wish to deactivate your account, you can do so via the general settings on the Platform. If you face any issue regarding deactivation, you can contact us as described under clause 13 below.
- You May Cease Our Collection of Location Information
In order to provide certain Services, we may need to access to your location information, including precise geolocation information collected from your device. We will collect information about your location, which we use to make better recommendations for Groups and Activities in your area, and to improve our Platform. If you do not consent to collection of this information, certain Services will not function properly and you will not be able to use those Services. You can stop our collection of location information at any time via the user settings on the Platform or via your phone’s location service settings. If you do so, some of our Services will no longer function.
- You May Opt Out of Promotional Notifications
You can opt out of receiving in-app and/or push notifications containing promotional information from us via the notification settings on the Platform or by clicking on the unsubscribe button provided at the bottom of each promotional notification sent. If you decide to opt out, we may still send you non-promotional communications via in-app or push notifications or via email and SMS, such as message notifications.
- Right to withdraw consent
You may withdraw your consent to us processing your Personal Data at any time if we process your Personal Data on the grounds of your consent. If you withdraw your consent to our processing of your Personal Data, Sociogram will respect your decision and will stop processing your Personal Data as soon as reasonably practicable. This will not affect the legality of our processing of your Personal Data up until the point at which you withdraw your consent.
If you withdraw your consent to our processing of your Personal Data however, our Services will not function properly and you will no longer be able to use our Services.
Please note that after your withdrawal of consent, we may still process and retain your Personal Data for a period of time that complies with applicable law or as we believe is reasonably necessary to comply with applicable law, regulation, legal process, or governmental request.
- Rights to access, rectification and erasure of Personal Data
- Upon request, you have the right to obtain from us without charge and within one (1) month of the request:
- confirmation in writing as to whether or not Personal Data relating to you is being processed and information at least as to the purposes of the processing, the categories of Personal Data concerned, and the recipients or categories of recipients to whom the Personal Data are disclosed;
- a copy of the Personal Data undergoing processing in electronic form and of any available information as to its source; and
- the rectification or erasure of Personal Data unless it is not technically feasible to do so.
- You may require us to erase your Personal Data if one of the following conditions applies (subject to exceptions the applicable law provides):
- the processing of the Personal Data is no longer necessary in relation to the purposes for which we have collected;
- you have withdrawn consent to the processing where consent was the lawful basis for processing and there is no other lawful basis;
- the processing is unlawful or the Personal Data is required to be deleted to comply with applicable law; or
- you object to the processing and there are no overriding legitimate grounds for us to continue with the processing.
- Please note that you may no longer be able to use our Services if you delete or request deletion of your Personal Data.
- If your request under clause 10.2.1 is particularly complex, or your requests are numerous, we may send notice to you, within one (1) month, to increase the period for compliance by a further two (2) months citing the reasons for the delay.
- Where your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may either:
- charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
- refuse to act on the request, providing written confirmation to you reasons for the refusal.
- If we have reasonable doubts as to your identity asserting a right under clause 10.2.1, we may require you to provide additional information sufficient to confirm your identity.
- We may also restrict, wholly or partly, the provision of information to you under clause 10.2.1 to the extent that and for so long as the restriction is, having regard to your fundamental rights and legitimate interests, a necessary and proportionate measure to:
- avoid obstructing an official or legal inquiry, investigation or procedure;
- avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties;
- protect public security;
- protect the rights of others.
- Right to object to Processing
- object at any time on reasonable grounds relating to your particular situation to processing of your Personal Data where such processing is carried out on the basis that: (i) it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in Sociogram; or (ii) it is necessary for the purposes of the legitimate interests, where applicable, of Sociogram or of a third party; and
- be informed before your Personal Data is disclosed for the first time to third parties or used on their behalf for the purposes of direct marketing, and to be expressly offered the right to object to such disclosures or uses, subject to any provision of applicable law that does not permit disclosure; and
- where Personal Data is processed for direct marketing purposes, object at any time to such processing.
- protect the rights of others.
- An objection under clause 10.3.1 may be deemed justified unless we demonstrate compelling grounds for such processing that overrides your interests and rights.
- Right to restriction of Processing
- You may have the right to require us to restrict processing to the extent that any of the following circumstances apply:
- the accuracy of the Personal Data is contested by you for a period allowing us to verify the accuracy of the Personal Data;
- the processing is unlawful and you oppose the erasure of the Personal Data and request the restriction of its use instead;
- we no longer need the Personal Data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
- you have objected to processing pursuant to clause 10.3 pending verification of whether the legitimate grounds of Sociogram overrides those of you.
- Where clause 10.4.1 applies, we may continue the following processing without your consent:
- storage of the Personal Data concerned;
- processing of the Personal Data for the establishment, exercise or defence of legal claims;
- processing for the protection of the rights of another person; and
- processing for reasons of substantial public interest.
- Right to data portability
You may have the right to receive Personal Data that you have provided to us in a structured, commonly used and machine-readable format where the processing is:
- based on your consent or the performance of a contract; and
- carried out by automated means.
- Right of Non-Discrimination
You have the right to not be discriminated against your exercise of these privacy rights. We will not discriminate against you, deny, charge different prices for, or provide a different quality of goods or services if you choose to exercise your rights under this Privacy Policy.
- Right to inquire about direct marketing
You have the right to inquire as to whether we disclose your Personal Data to third parties for their direct marketing purposes at any time. Sociogram currently do not disclose your Personal Data for others’ direct marketing purposes.
- Right to complain to the Commissioner
If you feel that we have processed your Personal Data unfairly or unlawfully, you have the right to complain about us to the Commissioner as per the DIFC laws and regulations. We would appreciate it if you would please contact us first so that we can try to put things right for you.
- Methods of exercising your rights
If you choose to exercise your rights under this Privacy Policy, you may do so online at www.sociogram.com/contact or by contacting us as indicated in the “How to Contact Us” section below. In order to help protect your privacy and maintain security, we take steps to verify your identity and will require you to be logged in to your account before granting you access to your personal information or complying with your request.
To the extent permitted by applicable law, we may charge a reasonable fee to comply with your request.
The Personal Data we collect from you may be transferred to, and stored at, a destination outside the DIFC as it may be processed by our affiliates and group companies, or by our service providers when they are located outside of the DIFC.
- Transfers within the Sociogram group
Where Personal Data is transferred between Sociogram’s affiliates and group companies to locations which the Commissioner has not deemed to have “adequate level of protection”, we have put in place contracts that include standard data protection clauses as adopted by the Commissioner.
- Transfers to third parties
Where required for certain matters, we may use service providers located outside the DIFC and transfer Personal Data to such service providers (for example, technology services).
Depending on the circumstances we may also need to transfer Personal Data to other kinds of third parties, for example regulators, government authorities as necessary.
Where the recipient is located in a jurisdiction which has not been deemed by the Commissioner to have adequate level of protection in place, we transfer the Personal Data using one of the following measures:
- Where we use certain service providers on a recurring basis, we will seek to put in place contracts that include standard data protection clauses as adopted by the Commissioner.
- Where the transfer is on an ad hoc basis, to a service provider which we do not regularly use or to a third party which is not a service provider, we will only transfer the Personal Data in accordance with applicable law.
We will only retain your Personal Data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances, we may anonymize your Personal Data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
If you have questions or concerns regarding this Privacy Policy, or any feedback pertaining to your privacy and the Services that you would like us to consider, please contact us at feedback@sociogram.com.
If you believe our privacy notice or applicable laws relating to the protection of your personal information have not been respected, you may file a complaint with our team as described above. If you file a complaint with our team, we will respond to let you know when you can expect a further response. We may request additional details from you regarding your concerns and may need to engage or consult with other parties in order to investigate and address your issue. We may keep records of your request and any resolution.
Effective as of 30th of May2022