EU Privacy Notice
Last Updated: December 1, 2023
Data Controller
KoreLock, Inc.
7100 E. Belleview Ave., Ste. 203
Greenwood Village, CO 80111 USA
303.681.5785
email: info@korelock.com
This European Privacy Notice for EEA, UK, and Swiss residents (“European Privacy Notice” supplements the information contained in the Privacy Policy of KoreLock, Inc. (“KoreLock,” “we,” or “us”), which is incorporated in this European Privacy Notice by this reference. This European Privacy Notice applies to EEA, UK, and Swiss residents from whom we collect information relating to you and, directly or indirectly, identifying you (“Personal Data”) or market to while such residents are in the EEA, UK, and Switzerland (“consumers” or “you”). Any terms that are capitalized but undefined in this European Privacy Notice have the meanings ascribed to them in the Privacy Notice.
Information We Collect About You and How We Collect It
Personal Data: What data is collected?
Source: How was the data collected?
Purpose/Legal Basis: Why was the data collected? *Please see the numbered list below for the numerical value key*
-
Personal Data: Contact information, such as name, E-mail address, mailing address, and phone number. Source: Online; From Third Parties. Purpose/Legal Basis: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10
-
Personal Data: Demographic information, such as information that is about you individually but does not specifically identify you. Source: Online; From Third Parties. Purpose/Legal Basis: 2, 3, 6, 7, 8, 9, 10
-
Personal Data: Login information, such as username and password. Source: Online. Purpose/Legal Basis: 2, 3, 4, 5, 8, 9, 10
-
Personal Data: Payment and financial information, such as credit card number and billing address, which are processed and maintained by third-party payment processors. Source: Online; From Third Parties. Purpose/Legal Basis: 1, 9, 10
-
Personal Data: Communication information, such as information provided to us through e-mail or through chat. Source: Online. Purpose/Legal Basis: 1, 2, 3, 4
-
Personal Data: Information about the devices you use to access the Sites (such as the IP address and the type of the device, operating system, and web browser). Source: Online; From Third Parties. Purpose/Legal Basis: 7, 8, 12
Purpose and Legal Basis of Processing.
Our legal basis for processing and collecting Personal Data varies based on the context for which it is collected. The following are the legal grounds by which we can use your Personal Data:
-
To allow us to provide our services, e.g., to process orders you place and complete other transactions you have requested using the services, and provide you with products and services you request (legal basis: processing is necessary for the performance of an agreement with the user and/or for any pre-contractual obligations thereof);
-
To respond to your questions and comments and provide customer support (legal basis: processing is necessary for the performance of an agreement with the user and/or for any pre-contractual obligations thereof);
-
To comply with legal obligations (legal basis: processing is necessary for compliance with a legal obligation to which we are subject);
-
For our legitimate interests in enforcing our Terms of Service and other agreements in Court or in the stages leading to possible legal action arising from improper use of the Sites or the related services (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
To respond to enforcement requests (legal basis: processing is necessary for compliance with a legal obligation to which we are subject);
-
For our legitimate interests to operate, evaluate, and improve our business and the products and services we offer (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
To communicate with you about our products, services, offers, and promotions, and to analyze and enhance our marketing communications and strategies (legal basis: your consent or, if related to similar products or services as those already purchased, processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
For our legitimate interests to analyze trends and statistics regarding use of the services and transactions conducted using the services (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
For our legitimate interests to detect and protect against any malicious or fraudulent activity, unauthorized transactions, claims, and other liabilities, and manage risk exposure, including by identifying potential hackers and other unauthorized users (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
For our legitimate interests to maintain a record of your payments to user and other transactions using the services (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party);
-
For our legitimate interests in traffic optimization and distribution, interaction with live chat platforms, displaying content from external platforms and tag management (legal basis: processing is necessary for the purposes of the legitimate interests pursued by us or by a third party); and
-
For our legitimate interests in improved operation and maintenance purposes, the Sites and any third-party services may collect files that record interaction with the Sites (System logs) or use other Personal Data (such as the IP Address) for this purpose (legal basis: processing is necessary for the purposes of the legitimate interests pursued by the Sites or by a third party).
We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Transfers of Data.
We are based out of the United States and thus may transfer your Personal Data across borders. We have taken appropriate safeguards to ensure your Personal Data is protected in accordance with this European Privacy Notice through implementing additional safeguards, such as the European Commission’s Standard Contractual Clauses.
Retention of Data.
We will only retain Personal Data for as long as it is required to provide you the Services you have requested, or as otherwise required by applicable law.
Your Rights.
Under certain circumstances, by law, you have the right to:
-
Request access to your Personal Data (known as a “data subject access request”). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it;
-
Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate information we have about you corrected;
-
Request the erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data when there is not a good reason for us to continue to process it. You also have the right to ask us to stop processing Personal Data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground;
-
Request the restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of Personal Data about you, for example, if you want us to establish its accuracy or the reason for processing it;
-
Withdraw your consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your Personal Data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Where we are providing you with marketing information, you can also change your marketing preferences by using the unsubscribe instructions in the communications sent to you. Once we have received notification that you have withdrawn your consent, we will no longer process your Personal Data for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so;
-
Complain to your local data protection authority regarding our collection and use of Personal Data. For more information, please contact your local data protection authority. Contact information may be found here; and
-
Request the transfer of your Personal Data to another party. If you want to review, verify, correct or request erasure of your Personal Data, object to the processing of your Personal Data, or request that we transfer a copy of your Personal Data to another party, please contact us in writing at info@korelock.com.
You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is unfounded or excessive. Alternatively, applicable law may require or permit us to decline your request. However, if we do so, we will inform you of the reason unless otherwise prohibited by law.
Details About the Right to Object to Processing.
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in KoreLock or for the purposes of the legitimate interests pursued by KoreLock, you may object to such processing by providing an explanation related to your particular situation to justify the objection.
You must know that should your Personal Data be processed for direct marketing purposes, you can object to that processing at any time, free of charge and without providing any justification. Where you object to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes.