Privacy Policy

Last updated 31 May 2024 (06:30am UTC)

1. INTRODUCTION

This page sets out the privacy policy of Spoony Pty Ltd ABN 92 673 604 727 (referred to in this privacy policy as ‘we’, ‘us’, or ‘our’) and outlines how we comply with applicable privacy law in the jurisdictions we operate in, including but not limited to Australia, New Zealand, Europe and the United Kingdom. For the purposes of applicable data protection law, (in particular, the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and the UK Data Protection Act 2018), your data will be controlled by us. By providing personal information (including sensitive information) to us, you consent to our storage, maintenance, use and disclosing of personal information in accordance with this privacy policy. This privacy policy applies to our use of any and all data collected by us or provided by you in relation to your use of the website and the provision of our services to you.

We take our privacy obligations seriously and we’ve created this privacy policy to explain how we collect and treat your personal information in accordance with applicable privacy law. Personal information is any information which could identify you. 

2. TYPES OF PERSONAL INFORMATION WE COLLECT

The personal information we collect may include the following:

  1. name;
  2. mailing or street address;
  3. email address;
  4. social media information;
  5. telephone number and other contact details;
  6. age;
  7. date of birth;
  8. photographs;
  9. videos;
  10. audio;
  11. credit card or other payment information;
  12. sensitive information as set out below;
  13. information about your personal circumstances;
  14. information in connection with client surveys, questionnaires and promotions;
  15. when we use analytical cookies, your device identity and type, I.P. address, geo-location information, page view statistics, advertising data and standard web log information; 
  16. information about third parties; and
  17. any other information provided by you to us via this website or our mobile application, in the course of providing services to you, or otherwise required by us or provided by you.

3. HOW PERSONAL INFORMATION IS COLLECTED

We will collect your personal information in a lawful and fair way. We will only collect your personal information where you have consented to it, or otherwise in accordance with the law.

How we collect information from you

We may collect personal information where you: 

  1. contact us through our website;
  2. sign up for an account on our mobile application;
  3. receive goods or services from us;
  4. offer to provide, or provide, services to us;
  5. submit any of our online forms;
  6. communicate with us via email, telephone, SMS, social applications (such as LinkedIn, Facebook or Twitter) or otherwise;
  7. otherwise interact with our website, applications, services, content and advertising; and
  8. invest in our business or enquire as to a potential purchase in our business.

How you provide information for someone else

If you are providing personal and/or sensitive information on behalf of someone else, you must have the consent of that person to provide their personal and/or sensitive information to us to be collected, used, and disclosed in accordance with this privacy policy. We reserve the right to request evidence of this consent.

How we collect information from cookies

We may also collect personal information from you when you use or access our website or our social media pages. This may be done through use of web analytics tools, ‘cookies’ or other similar tracking technologies that allow us to track and analyse your website usage. Cookies are small files that store information on your computer, mobile phone or other device and enable and allow the creator of the cookie to identify when you visit different websites. If you do not wish information to be stored as a cookie, you can disable cookies in your web browser.

4. USE OF YOUR PERSONAL INFORMATION

We collect and use personal information for the following primary purposes:

  1. to provide goods, services or information (including our mobile application) to you;
  2. for record keeping and administrative purposes;
  3. to provide information about you to our contractors, employees, consultants, agents or other third parties for the purpose of providing goods or services to you;
  4. to improve and optimise our service offering and customer experience;
  5. to comply with our legal obligations, resolve disputes or enforce our agreements with third parties;
  6. to send you administrative messages, reminders, notices, updates, security alerts, and other information requested by you;
  7. to develop and carry out marketing activities and to conduct market research and analysis and develop statistics; and
  8. to consider an application of employment from you.

We may also use your personal information for:

  1. secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use;
  2. such purposes where we reasonably believe that use of your personal information is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety, and it is unreasonable or impracticable to obtain your consent; 
  3. any other purpose for which we receive consent from you; or
  4. any other purpose which is permitted or required under applicable privacy laws.

5. HOW WE DISCLOSE YOUR PERSONAL INFORMATION

We may disclose your personal information to:

  1. our professional advisors such as lawyers, accountants and auditors;
  2. our related entities; or
  3. any third parties you have consented personal information to be disclosed to.

We may also disclose personal information to third parties as required for us to provide our goods and services to you. 

Some examples of third parties we may disclose your personal information to are: 

  1. Amazon for moderation of user content; 
  2. OpenAI for moderation of user content; and
  3. Stream for important functionality such as chat and feeds. 

We take care to work with such third parties who we believe maintain an acceptable standard of data security and require them not to use your personal information for any purpose except for those activities we have asked them to perform on our behalf.

We will not otherwise disclose your personal information unless:

  1. you have consented to us disclosing your personal information for particular circumstances;
  2. as needed in an emergency or in investigation suspected criminal activity;
  3. we are required to disclose under a subpoena, court order or other mandatory reporting requirements;
  4. we reasonably believe that disclosure of your information is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety, and it is unreasonable or impracticable to obtain your consent;
  5. it is reasonably necessary for the establishment, exercise or defence of a legal claim; or
  6. it is otherwise authorised or required by law.

6. SENSITIVE INFORMATION

Collection of sensitive information

We may collect sensitive information about you during the course of providing you our goods and services. We will only collect this sensitive information where you consent to such collection and either directly provide us with this information or it is provided by a referring health care provider.

Types of sensitive information we collect

The sensitive information we collect may include the following:

  1. sexual preference or practice;
  2. health information (including but not limited to information about any illnesses or disabilities you share with us); and
  3. any other sensitive information provided by you or a third party to us via our website or platforms, or otherwise provided by you or a third party to us.

How we use your sensitive information

Your sensitive information will only be used for the purpose of:

  1. providing you with our goods and services (including our mobile application);
  2. complying with our legal obligations, resolving disputes or enforcing our agreements with you; or
  3. any other purpose which is permitted or required under applicable privacy laws.

How we disclose your sensitive information

Your sensitive information will only be disclosed to third parties when required under applicable privacy laws.

How you can withdraw consent

If you wish to withdraw your consent to our collection, use or disclosure of your sensitive information, please contact us using the contact details set out below. We will deal with all such requests within a reasonable timeframe.

7. MARKETING

We may at times send you marketing communications which will be done in accordance with the Spam Act 2003 (Cth) (Spam Act).

If we do, we may use email, SMS, social media, or phone to send you direct marketing communications. 

Where consent is needed, we will ask you for your consent before sending you marketing communications, except where you:

  1. have explicitly opted-in to receiving email marketing from us in the past; or
  2. were given the option to opt-out of email marketing when you initially signed up for one of our platforms and you did not do so.

You can, at any time, opt out of receiving marketing materials from us by using the opt-out facility provided (e.g., an unsubscribe link on emails we send you) or by contacting us via the details provided at the end of this privacy policy. We will implement such a request as soon as possible, however, cannot guarantee that such a response will be immediate.

8. DE-IDENTIFIED INFORMATION

The information we collect may have analytical, educational, or commercial value to us. Where we have de-identified the information we have collected, we reserve the right to process and distribute the information such information. 

9. SECURITY

We take reasonable steps to ensure your personal information is secure and protected from misuse or unauthorised access. Our information technology systems are password protected, and we use a range of administrative and technical measures to protect these systems. However, we cannot guarantee the security of your personal information. If there is any inconsistency between this Privacy Policy and any Services Agreement that we provide you, the security processes in the Services Agreement will prevail.

10. LINKS

Our website may contain links to other websites. Those links are provided for convenience and may not remain current or be maintained. We are not responsible for the privacy practices of those linked websites and we suggest you review the privacy policies of those websites before using them.

11. YOUR RIGHTS

You have various rights with respect to our use of your personal information:

  1. Access: You have the right to obtain access to your information (if we’re processing it) and certain other information (similar to that provided in this privacy notice). This is so that you’re aware and can check that we’re using your information in accordance with data protection law.
  2. Be informed: You have the right to be provided with clear, transparent and easily understandable information about how we use your information and your rights. This is why we’re providing you with the information in this privacy policy.
  3. Rectification: We aim to keep your personal data accurate, current, and complete. We encourage you to contact us using our contact form to let us know if any of your personal data is not accurate or changes, so that we can keep your personal data up-to-date.
  4. Objecting: You also have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing.
  5. Restricting: You have the right to ‘block’ or suppress further use of your information. When processing is restricted, we can still store your information, but may not use it further.
  6. Erasure: You have the right to ask us to erase your personal data when the personal data is no longer necessary for the purposes for which it was collected, or when, among other things, your personal data have been unlawfully processed.
  7. Portability: You have the right to request that some of your personal data is provided to you, or to another data controller, in a commonly used, machine-readable format.
  8. Complaints: If you believe that your data protection rights may have been breached, you have the right to lodge a complaint with the applicable supervisory authority. In the UK, the supervisory authority is the Information Commissioner’s Office.
  9. Withdraw consent: If you have given your consent to anything we do with your personal information, you have the right to withdraw your consent at any time. This includes your right to withdraw consent to us using your personal information for marketing purposes.

You may, at any time, exercise any of the above rights, by contacting our email address provided below.

12. HOW LONG WE KEEP DATA

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. We will securely destroy your personal data in accordance with applicable laws and regulations.

If you would like further information about our specific retention periods for your personal information, please contact us using our email address provided below.

13. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA (‘EEA’)

To provide our services, we may transfer the personal information we collect to countries outside of the UK or EEA which do not provide the same level of data protection as the country in which you reside and are not recognised by the European Commission as providing an adequate level of data protection.

When we do this, we will make sure that it is protected to the same extent as in the EEA and UK as we will put in place appropriate safeguards to protect your personal information, which may include standard contractual clauses.

For more information, please contact us at our email address provided below.

14. Analytics and performance monitoring

Purpose of Data Collection
We use Amplitude, a third-party analytics service, to understand how our users interact with our services. This helps us improve your user experience, enhance our application’s functionality, and measure performance effectively.

Data Collected
Amplitude collects data related to your app usage such as the features you use, the buttons you click, and the frequency and duration of your visits. Amplitude does not collect personally identifying information unless explicitly provided by you.

Data Sharing and Third-Party Disclosure
The data collected through Amplitude is stored and processed by Amplitude, Inc. We do not share this data with other third parties except as necessary for processing or as required by law.

User Consent
By using our Services, you consent to the collection and use of this information by Amplitude as described in this policy. You may withdraw your consent at any time by adjusting your user settings or contacting us directly.

Data Security and Storage
The data collected by Amplitude is stored securely on servers in the United States. We and Amplitude implement strong security measures to protect your data from unauthorized access or alteration.

15. CONTACT US

For further information about our privacy policy or practices, or to access or correct your personal information, or make a complaint, please contact us at: support@spoony.app

We may change this privacy policy from time to time by posting an updated copy on our website and we encourage you to check our website regularly to ensure that you are aware of our most current privacy policy. Where we make any significant changes, we will endeavour to notify you by email.