Shape

Privacy Policy for the Use of Facelift Cloud

The data controller in terms of the General Data Protection Regulation (GDPR) is:

Facelift brand building technologies GmbH, Gerhofstr. 19, 20354 Hamburg, Germany

Any questions regarding the processing of your personal data may be directed to our data protection officer at: dataprivacy@facelift-bbt.com.

Collection and storage of personal data; type and purpose of use

Use of Facelift Cloud

The name, username, password, email address, and organizational affiliation of each user is stored so that the user can use Facelift Cloud (as well as via the Facelift Cloud Mobile and Facelift Cloud Social Share apps). It is not possible to use Facelift Cloud without providing such data. The purpose of processing the aforementioned data is to ensure the operational integrity and optimal use of Facelift Cloud, as well as to allow for the evaluation of said data for administrative purposes.

In order to ensure functional reliability and to be able to track changes, the company admin has the option to activate an activity log that stores change data on various objects from the administration area (such as users, teams, permission sets, logins etc.), and also changes of module-specific objects (e.g. campaigns, events, media objects), as a table for the last 30 days. Even if the activity log is deactivated and not displayed to the Company Admin, this data is saved to ensure the functional reliability of the Facelift Cloud.

Dashboard

Upon accessing the dashboard, the browser running on your terminal device will automatically send information to our server. This information will be temporarily stored in a log file, where it will remain saved until it is automatically deleted. This includes the IP address of the requesting computer with the date and time of the access, and the name and URL of the retrieved file, as well as the URL of the website from which the access takes place. Furthermore, the browser used, your computer’s operating system, as well as the name of the respective access provider, are all identified.

The purpose of processing the aforementioned data is to guarantee a seamless connection to the website for the optimum use of our online service, as well as for an analysis of system security and stability. The data is also used for administrative purposes.

Art. 6, Para. 1, Sent 1, lit. f of the GDPR is the legal basis for the processing of data. Our legitimate interest is based on the purposes listed above concerning data collection. Under no circumstances shall we use the collected data for the purpose of drawing any inferences about you personally.

Disclosure of data

Your personal data will not be disclosed to third parties for purposes other than those listed below.

We will only disclose your personal data to third parties if:

  • You have provided your express consent pursuant to Art. 6, Para. 1, Sent. 1, lit A of the GDPR,

  • This is legally permissible and necessary for the execution of the contractual relationships with you as per Art. 6, Para. 1, Sent. 1, lit. B of the GDPR,

  • There is a legal obligation to disclose your data pursuant to Art. 6, Para. 1, Sent. 1, lit. C of the GDPR,

  • The disclosure is done pursuant to Art. 6, Para. 1, Sent. 1, lit F of the GDPR and is necessary to assert, exercise or defend our legal rights, and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data.

Analysis tools, tracking tools

The tracking measures, which are described below and used by us, are used on the basis of our legitimate interests pursuant to Art. 6, Para. 1, Sent. 1, lit. f of the GD GDPR. On the one hand, these tracking measures are used to continuously optimize Facelift Cloud. On the other hand, these tracking measures are used for recording and analyzing statistics concerning the use of Facelift Cloud. This data is used to help optimize our service. The respective purposes for such data processing and the categories of data collected can be found through the corresponding tracking tools.

Hotjar

We use Hotjar: This tool enables us to analyze usage behavior in order to constantly improve the Facelift Cloud product. In addition, Hotjar makes it possible to record complete web sessions. https://www.hotjar.com/privacy. This data is used to optimize our service and to record and analyze statistics concerning the use of Facelift Cloud.

Hotjar Ltd. is a European company headquartered in Malta. Hotjar complies with the provisions of the Data Protection Act and Chapter 440 of the Laws of Malta, which transposes all relevant EU data protection directives.

Intercom

We use this tool to offer our customers our first-line of support in the form of a chat function and email. This tool enables us to track usage behavior, which allows us to optimize the way in which we send information to the customer. The following data is stored for this purpose: Last name, first name, username, user ID, customer, email address.

Intercom uses cookies, which are stored on the computer of the respective website visitor and enable an analysis of the use of the website. You can prevent these cookies from being saved at any time by making the appropriate settings in your internet browser. By blocking these cookies, however, there may be restrictions in the functions and user-friendliness of our offer.

This tool is related to a third country, so that the data collected may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called standard contractual clauses with the provider for compliance with data protection within the meaning of the GDPR. However, it cannot be ruled out that data transferred to the USA may be processed by US authorities for control and monitoring purposes without you possibly having the right to redress. Further information on Intercom's Privacy Policy can be found here: https://www.intercom.com/legal/privacy

Dropbox

Dropbox can be used to copy user files from a user’s Dropbox account to Facelift Cloud. Further information on Dropbox’s Privacy Policy can be found here: https://www.dropbox.com/privacy

This tool is related to a third country, so that the data collected may be transferred to another country outside the European Union and the European Economic Area. We have concluded so-called standard contractual clauses with the provider for compliance with data protection within the meaning of the GDPR. However, it cannot be ruled out that data transferred to the USA may be processed by US authorities for control and monitoring purposes without you possibly having the right to redress.

Mixpanel

Facelift Cloud uses the Mixpanel analytics service, a service of Mixpanel Inc. to constantly improve the Facelift Cloud product. The Mixpanel service logs page views and page activity. To make this possible, log data is transferred to Mixpanel. All data is exclusively stored and processed within the EU.

Rights of the data subject

If you are affected by the processing of data that takes place as part of our online service, you have the following rights:

  • Pursuant to Art. 15 of the GDPR, you have the right to request information about your personal data processed by us. In particular, you can request information about the purposes of processing your data, the categories of personal data processed, the categories of recipients to whom your data has been disclosed or will be disclosed, the planned retention periods, your right to rectification, to erasure, to limiting the processing of data, or to object to the processing of data, your right to lodge a complaint, the source of the data, if it is not collected by us, as well as automated decision-making, including profiling, and, if applicable, meaningful information concerning automated decision-making;

  • Pursuant to Art. 16 of the GDPR, you have the right to request that any incorrect or incomplete personal data belonging to you and stored by us be rectified without delay;

  • Pursuant to Art. 17 of the GDPR, you have the right to request that personal data belonging to you and stored by us be erased insofar as the processing of said data is not required for exercising the right to the freedom of expression of opinion and information, for fulfilling a legal requirement, for reasons of public interest, or for the purposes of asserting, exercising, or defending legal claims;

  • Pursuant to Art. 18 of the GDPR, you have the right to request that the processing of your personal data be restricted insofar as you dispute the correctness of the data or the processing of said data is unlawful, but, at the same time, you do not wish for the data to be erased; and the data is no longer required by us but would be required by you for the purposes of asserting, exercising, or defending against legal claims, or for objecting to the processing of said data in accordance with Art. 21 of the GDPR;

  • Pursuant to Art. 20 of the GDPR, you have the right to request that your personal data that has been provided to us be made available to you or another data controller in a structured, standardized, and machine-readable format;

  • Pursuant to Art. 7, Para. 3 of the GDPR, you have the right to revoke the consent that you previously provided to us, at any time. This means that we will not be permitted to continue processing the data for which consent was given; and

  • Pursuant to Art. 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. Generally speaking, for this purpose you can contact the supervisory authority at your usual place of residence or work, or that of our company’s main office.

Right to object

Insofar as your personal data is processed based on our legitimate interests as defined under Art. 6 Para. 1, Sent. 1, lit. f of the GDPR, you have the right – in accordance with Art. 21 of the GDPR – to object to your personal data being processed, provided that there are grounds pertaining to your particular circumstances that require this or you are objecting to direct advertising. In the latter case, you have a general right of objection, which we will enforce without providing any indication of any particular circumstances.

If you wish to exercise your right of revocation or objection, please email us at: dataprivacy@facelift-bbt.com.

Data security

We operate an information security management system in accordance with ISO 27001, and we are certified accordingly. We continually upgrade these security measures in line with advancements in technology. We employ suitable technical and organizational security measures in order to protect your data from accidental or intentional manipulation, partial or complete loss, destruction, or access by unauthorized third parties.

Finally, we would like to point out that when transferring data online, it cannot be guaranteed that this data will be fully protected against third-party access. We do not accept any liability for damage or any losses sustained that were caused by such security vulnerabilities, or for claims for injunctive relief.

Facelift Cloud Third Party Services

In order to work with Facelift Cloud, users are able to connect social networks via "Client APIs" to Facelift Cloud in self-service. By using Facelift Cloud customers and users agree on the below linked Terms of Service and Privacy Policies of these services.

Facebook

Terms of Service: https://www.facebook.com/terms.php
Privacy Policy: https://www.facebook.com/policy.php

Google Business

Terms of Service: https://policies.google.com/terms
Privacy Policy: https://policies.google.com/privacy

Instagram

Terms of Service: https://help.instagram.com/581066165581870
Privacy Policy: https://help.instagram.com/519522125107875

LinkedIn

Terms of Service: https://legal.linkedin.com/service-specific-terms
Privacy Policy: https://www.linkedin.com/legal/privacy-policy

Pinterest

Terms of Service: https://policy.pinterest.com/en/terms-of-service
Privacy Policy: https://policy.pinterest.com/en/privacy-policy

Twitter

Terms of Service: https://twitter.com/tos
Privacy Policy: https://twitter.com/privacy

WhatsApp

Terms of Service: https://www.whatsapp.com/legal/
Privacy Policy: https://www.whatsapp.com/privacy

XING

Terms of Service: https://www.xing.com/terms
Privacy Policy: https://privacy.xing.com/en

YouTube, incl. YouTube API Services

Terms of Service: https://www.youtube.com/t/terms
Privacy Policy: https://policies.google.com/privacy
Facelift Cloud’s access to the user’s or customer’s data available via the YouTube API can be retracted via Google Security Settings at https://security.google.com/settings/security/permissions.

TikTok

Terms of Service: https://www.tiktok.com/legal/page/eea/terms-of-service/en (EEA/UK/CH version)
Privacy Policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en (EEA/UK/CH version)