Effective date: 25.07.2022
2.Who are we?
|Company Name||Shenzhen Mamba Digital Information Technology Co.|
|Unified Social Credit Code||
|Address||Building B 308, Huafeng Robot Industrial Park, Hangcheng Avenue, Xixiang, Baoan District, Shenzhen|
|Legal Representative||Liu Shuai|
We act as a personal data controller in the provision and delivery of services, partner portal services, platforms and partner portals, managing websites and social accounts, performing the day-to-day operations of the company, complying with legal requirements, etc.
When we receive and process personal data on behalf of our customers who use our services and platforms, we do so only in accordance with the terms set out in the data processing agreement ("DPA") we have entered into with our customers. In this case, we act as a processor of personal data of our customers as defined in Article 28 of the GDPR.
We also offer various integrations, i.e. technical solutions, such as plugins, that allow you to integrate our services into other platforms (e.g. e-commerce platforms, social networks, etc.). These integrations can help you analyze your customer flows (by providing anonymous statistics), etc. You can see a list of the integrations we offer here. For more information on how the providers of these integrations handle personal data, please refer to their own privacy policies.
When providing the Partner Portal Services, we act as a sub-processor of personal data and we only sub-process personal data on behalf of our clients in accordance with the agreements signed between Mambasms and the delegated clients using the Partner Portal Services, for example, to help their clients perform marketing campaigns on the Platform and manage their accounts. Again, in this case, we process personal data only on behalf of our client and strictly in accordance with the DPA we have signed with that client. Our representatives who are bound by the DPA may also log in to such Partner Portal Service accounts to help them solve problems they encounter while using the Partner Portal Service, adjust their account settings, etc. We assure you that such logins will not be conducted without prior notice or on a regular basis.
3.What personal data do we process?
3.1. when you provide us with personal data, for example, when you register and use the Platform, Partner Portal, Services, Partner Portal Services, contact us, subscribe to our newsletter, apply for a job offered by us, etc.
3.2. when we collect your personal data when you use our services, partner portal services, platforms, partner portals, websites, social accounts, such as usage history, your IP address, cookies, preferences, opened URL links, etc..
3.3. when we receive personal data from other parties, for example, when we receive information about payments made from public registries, state or local government agencies or institutions, our partners, other third parties (such as payment institutions).
3.4. when your personal data is provided to us by other people (including companies using our services) with your consent, for example, when these companies indicate your contact person, refer to you as an authorized person, etc.
|Purpose of processing personal data||Personal data being processed||Personal data processing period|
|Registration and use of the platform, user identification, provision of services||Name, email, phone number, user name, password, email or marketing automation software used, platform used for the online store, workplace and job information, job title, relationship to the legal entity represented, billing name and address, service and account usage history data, marketing campaign data, content related to the services and account information about the services subscribed to and used and changes made therein.||During the use of the account and for 5 years after the last login to the account. If the processing of personal data is based on consent during the validity of consent and in case of withdrawal of consent - until the expiration of consent.|
|Agent/freelancer registration and use of partner portal services, identification, provision of partner portal services||First name, last name, email, phone number, username, password, workplace and job information, data about partner customers, location data, partner portal service and account usage history, marketing campaign data, content related to services and accounts, other information about partners.||During the use of the account and for 5 years after the last login to the account. If the processing of personal data is based on consent during the validity of consent and in case of withdrawal of consent - until the expiration of consent.|
|Franchise partner registration and use of franchise management software, identification of franchise partners, maintenance of business relationships and communication with franchise partners||First name, last name, email, phone number, username, password, workplace and job information, job title, relationship to represented legal entity, proof of self-employment data, payment data, billing name and address, member link sharing data, member link analytics data, marketing campaign data, content associated with account.||During the use of the account and for 5 years after the last login to the account. If the processing of personal data is based on consent during the validity of consent and in case of withdrawal of consent - until the expiration of consent.|
|Sending news, conducting surveys, direct marketing, advertising campaigns||Name, email address, phone number, data requested in survey announcement/questionnaire, marketing, advertising campaign analysis.||The data will be processed for 5 years from the date of receipt of consent.|
|Platform, services, partner portal and partner portal services personalization and quality assurance, protection of our intellectual property and other rights||First name, last name, email, phone number, username, password, workplace and job information, job title, relationship to represented legal entity, platform, partner portal, partner portal services, and service usage data.||Data is stored for a maximum of 1 year from the date of collection.|
You have the right to refuse or withdraw your consent to the processing of your personal data at any time, provided that such data is processed in accordance with your consent.
In social accounts, we can share information about ourselves, our content, events, news, surveys, and information about the employees we are looking for. Social account users are also subject to the privacy policies of social network owners. When you contact us through a social account, depending on the privacy settings you choose, we may see certain user account information such as profile first name, last name, image, gender, email address, location, etc. (this list is not exhaustive). If a user posts information by communicating with us on our social accounts (e.g., by posting a comment in the comments section of our social accounts or by posting a message on our social account profiles), depending on the privacy settings selected, the posted information may be posted publicly (e.g., visible to other users on our social accounts).
In some cases, we may use the contact data you provide to send messages related to the subscription or provision of our services or partner platform services, for example, to notify you of order confirmations, expiration dates for subscribed services, temporary or permanent changes to the services, including but not limited to planned outages, new features offered, version updates, point releases, major releases, abuse warnings, and changes to our terms, privacy policies and other documents and agreements. Such communications are necessary for the proper provision of our contractual obligations and services and are not considered marketing communications.
You have the right to change and update the information you provide to us by making changes on the Platform or by contacting us. In some cases, we need to obtain accurate and up-to-date information about you, so we may ask you to periodically confirm that the information we hold about you is correct.
We assure you that Mambasms will not share, sell, rent or trade any personal data with third parties for marketing or commercial purposes.
When providing our services or partner portal services, in some cases we may apply automated data decision making, such as to clarify your needs and compliance with requirements. Automated decision-making refers to the use of, for example, software code or algorithms that do not require human intervention to process personal data. We regularly review the standards and models used in automated decision making to ensure their integrity, efficiency and fairness. We do not use analytics-based automated decision-making processes that may have legal consequences or similarly have a significant impact on the rights or freedoms of data subjects. Notwithstanding, you have the right to request human intervention to express your opinion or object to the results of automated decision-making, and in order to protect the rights of children, we do not knowingly collect any personal data from data subjects under the age of eighteen (18) that can be used to clearly identify them, and we do not allow data subjects under the age of eighteen (18) to use any of Mambasms' services. If you believe that we may have any information from or about underage children, Please pass firstname.lastname@example.org Contact us.
4.How do we use your personal data and what principles do we follow?
4.1. we comply with the requirements of existing and applicable laws, including the GDPR and TCPA, as well as national laws.
4.2. we process your personal data in a lawful, fair and transparent manner.
4.3. we collect your personal data for specific, explicit and legitimate purposes and do not process it in a manner inconsistent with those purposes, except as permitted by law
4.4. we take all reasonable steps to ensure that personal data that is inaccurate or incomplete in accordance with the purposes for which it is processed will be immediately corrected, supplemented, suspended or destroyed
4.5. that we keep them in such a form that your identity is not established for longer than is necessary for the purposes for which the personal data are processed
4.7. we ensure that your personal data is processed securely, that we ensure technical and organizational security measures and that we provide access to personal data only to those employees who require such access for their job functions.
5.Who do we transfer your personal data to and when?
5.2. other third parties, such as payment institutions
5.3. if necessary, to companies that intend to purchase or will purchase our business or will engage in joint activities with us or will otherwise cooperate.
6.What rights do you have?
6.1. to know (be informed) about the processing of your personal data (right to information)
6.2. to access your personal data and how it is processed (right of access)
6.3. to request the correction or supplementation of incomplete personal data in accordance with the purposes for which the personal data were processed (right to correction)
6.4. to request the deletion of your personal data or the suspension of your personal data processing activities (excluding storage) (right to erasure and right to "be forgotten")
6.5. to request that we restrict the processing of personal data for one of the legitimate reasons (right to restriction).
6.6. the right to transfer the data (right to transfer). This right may only be exercised if there are grounds for exercising it and if appropriate technical measures are taken to ensure that the transfer of the requested personal data does not pose a risk of a security breach to the data of other data subjects.
6.7. the right to object to the processing of your personal data when we process the personal data on the basis of the legitimate interests of the company or third parties (including analysis). If you object, we will only be able to further process your personal data for compelling legitimate reasons that override your interests, rights and freedoms, or to bring, enforce or defend legal claims.
6.8. withdraw your consent to the processing of your personal data when it is processed or intended to be processed for direct marketing purposes, including analysis for such direct marketing purposes (which may be carried out based on the personal data you have provided) for direct marketing purposes, to provide you with individually tailored solutions and recommendations. You may withdraw your consent to the processing of personal data, or object to it, at any time through automated processing (including analysis).
7.Do we send you news?
7.1. notify us of your opt-out in the manner specified in the message provided (for example, by clicking on the "unsubscribe" link in the newsletter, etc.).
8.How do we protect your personal data?
9.How we process personal data when we act as data processors
9.1. process personal data in accordance with the DPA and only to the extent necessary for the performance of the agreement and the provision of the services thereunder.
9.2. to inform the customer immediately if we are unable to process personal data for any reason.
9.3. to entrust the processing of personal data only to authorized persons who have assumed the obligation of confidentiality to the extent necessary
9.4. to transmit to the customer, upon receipt of a request from a data subject, supervisory authority or any other person to provide the processed personal data
9.5. not to use personal data for purposes other than the performance of the Agreement and the DPA, taking measures to prevent accidental or unlawful destruction, alteration, disclosure of personal data and any other unlawful processing
9.6. to take appropriate technical and organizational security measures to protect personal data in accordance with the GDPR and the TCPA
9.7. take into account the nature of the personal data provided, the manner in which it is provided, in order to enable the Client to access, correct, delete, limit and transfer the personal data processed by us
9.8. take into account the nature of the personal data processed, the manner in which it is provided and the technical and organizational measures applied at the request of the Client to assist in
9.8.1. the fulfilment of the Client's obligation to respond to requests for the exercise of the rights of the data subject, taking into account the services provided and the conditions under which the personal data are processed
9.8.2. the fulfillment of specific obligations applicable to the Client in accordance with the GDPR and TCPA or other laws regulating the protection of personal data, such as reporting personal data breaches, providing information in the context of data protection impact assessments and prior consultation.
9.9. The Customer ensures that the personal data submitted to us for processing are collected and processed lawfully for lawful purposes and reasons and that the Customer has all necessary consents and rights to the transfer of personal data. The customer undertakes to duly inform the data subject about the processing of his personal data and the information transferred to us. The customer shall be liable for all damages suffered by the data subject as a result of improper processing of personal data by the customer.
9.10. we do not individually verify the legality of such data transfers. If anyone indicates that personal data transmitted to us has been collected or processed unlawfully, we will immediately suspend the processing of such personal data until the customer denies these circumstances. The customer bears all costs and negative consequences associated with such denial, including delays in the provision of services. We shall not be liable for such consequences.
9.11. the Client undertakes to provide, in a timely and appropriate manner, the necessary and lawful instructions regarding the processing of personal data, as well as all information and documentation required for the processing of personal data. The instructions are provided in writing, including by e-mail or by filling out a form prepared by us.
When we act as a data processor in the DPA, you can learn more about how we process personal data.