Last updated on 16 January 2025
INTRODUCTION
Welcome to NeuroOlympus OÜ (“Company”, “Data controller”, “us” or “we”). We recognize the importance of safeguarding the privacy of our users and are committed to ensuring that your personal data is processed in a secure and transparent manner. This Privacy Notice ("Notice") outlines the principles and practices we adhere to in the collection, use, processing, and protection of your personal data in strict compliance with the EU General Data Protection Regulation ("GDPR").
Please read this Notice carefully, as it provides a detailed explanation of our practices and your rights concerning your personal data. By engaging with our services, you acknowledge that you have read and understood the terms of this Notice, and you agree to the collection and processing of your data as described herein. If you have any questions or require further clarification, we encourage you to contact us at the details provided below.
DATA CONTROLLER
Data controller responsible for the processing of your personal data under this
Notice is:
Company Name: NeuroOlympus OÜ
Registration Number: 17153162
Legal Address: Harju maakond, Tallinn, Kesklinna linnaosa, Jõe tn 5, 10151
Email: info@quickpixai.net
As the data controller, we are responsible for deciding how and why your personal data is processed, ensuring that all such activities are carried out in strict accordance with applicable data protection laws. Our responsibilities as the data controller include determining the purposes for which your personal data is collected, the means by which it is processed, and ensuring that all necessary measures are in place to protect your data throughout its lifecycle. We are committed to maintaining the highest standards of data security and to safeguarding your rights under the law.
Should you have any questions or require further clarification about how we process your personal data, please do not hesitate to contact us using the details provided above.
CATEGORIES OF PERSONAL DATA PROCESSED
We may collect, utilize and otherwise process the following categories of personal data:
(a) Contact Information: This includes your name, surname, phone number, email address, postal address, and other similar contact details necessary for communication purposes.
(b) Account Information: This comprises details such as your profile ID, login credentials, passwords, activity logs, account settings, user preferences, photos, avatars, and any other content you choose to share through your account.
(c) Identity Data: This includes your full name, date of birth, government-issued identification numbers, details of identification documents (e.g., passport, ID card), and other information necessary for authentication and identification purposes.
(d) User-Generated Content: Any data, including text, images, and other media, that you upload, post, or generate while using our services.
(e) Legal and Compliance Data: Information required for compliance with legal and regulatory obligations, including but not limited to anti-money laundering (AML), counter-terrorist financing (CFT), and know-your-customer (KYC) regulations.
(f) Transaction Data: This includes details about your orders, purchases, transaction history, payment amounts, billing information, your current account balance, and other similar information necessary for processing transactions and maintaining records.
(g) Payment Information: Information related to your payment history, payment status, and payment methods, including bank account details, credit or debit card information, and other financial details necessary for processing payments.
(h) Communication Logs: Records of communications between you and us, including phone call logs and records, chat transcripts, email exchanges, and any other correspondence, used to provide customer support and improve service quality.
(i) Marketing Data: Information related to your marketing preferences, participation in surveys, loyalty programs, and any other promotional activities, as well as your engagement with marketing communications and advertising.
(j) Technical Data: Information about the devices and technology you use to access our services, including IP addresses, device identifiers, operating systems, browser types, cookie data, and settings, as well as usage statistics and analytics.
(k) Customer Support Information: Details of any issues or inquiries you have raised with our customer support team, including the nature of the issue, resolution status, and any relevant correspondence or documentation.
If you have any questions or require further information about the types of data we collect and how we use it, please do not hesitate to contact us. We are committed to providing transparency and supporting your understanding of our data processing practices.
LEGAL GROUNDS AND PURPOSES OF PROCESSING PERSONAL DATA
We process your personal data for various purposes, each grounded in a specific legal basis as required by applicable law:
(a) Account Management: To establish and administer your user account, ensuring you have access to our services and can utilize them effectively. (Legal Basis: Performance of a contract)
(b) Provision of Services: To deliver the services you have requested, ensuring their efficiency and alignment with your needs. (Legal Basis: Performance of a contract)
(c) Identity Verification: To confirm your identity and secure your account, thereby safeguarding against fraud and unauthorized access. (Legal Basis: Compliance with a legal obligation, Legitimate interests)
(d) Legal Compliance: To ensure adherence to applicable laws and regulations, including those related to anti-money laundering (AML), counter-terrorist financing (CFT), know-your-customer (KYC), and other relevant legal requirements. (Legal Basis: Compliance with a legal obligation, Performance of a public task).
(e) Order Fulfillment: To process and complete your orders, including the efficient handling of payments and delivery of goods or services. (Legal Basis: Performance of a contract)
(f) Transaction Management: To manage and facilitate transactions, ensuring their accuracy, security, and compliance with applicable standards. (Legal Basis: Performance of a contract, Legitimate interests)
(g) Risk Management: To assess, monitor, and manage business risks, ensuring the continued smooth operation of our services. (Legal Basis: Performance of a contract, Compliance with a legal obligation, Legitimate interests)
(h) Customer Communication: To engage with you regarding your account, provide customer support, and address any inquiries or issues you may have. (Legal Basis: Performance of a contract, Legitimate interests)
(i) Marketing: To send you marketing communications and personalized content tailored to your preferences, subject to your consent. (Legal Basis: Consent, Legitimate interests)
(j) Fraud Prevention: To detect, prevent, and respond to fraud and other unlawful activities, thereby protecting both our services and your data. (Legal Basis: Compliance with a legal obligation, Legitimate interests)
(k) Security: To safeguard our information systems and assets from unauthorized access, ensuring the integrity and confidentiality of data. (Legal Basis: Performance of a contract, Compliance with a legal obligation, Legitimate interests)
(l) Technical Support: To diagnose and resolve technical issues, maintaining the functionality, stability, and reliability of our services. (Legal Basis: Performance of a contract)
(m) Service Improvement: To enhance, refine, and develop our services based on user feedback, behavior, and usage patterns, ensuring they continue to meet your evolving needs. (Legal Basis: Legitimate interests)
(n) Dispute Resolution: To manage and resolve any legal claims or disputes, protecting our legal interests and ensuring compliance with our legal obligations. (Legal Basis: Performance of a contract, Compliance with a legal obligation, Legitimate interests)
OBLIGATORY AND OPTIONAL DATA PROVISION
To provide our services effectively, certain personal data is essential. This core data, clearly marked during collection, is required for you to access and use specific features and functionalities. Without this mandatory data, we cannot deliver the full scope of our services. In contrast, optional data is not critical to service delivery and does not impact your ability to use our core services. Providing this information is entirely up to you and can be managed or updated through your account settings at any time. If you have any questions about which data is obligatory or optional, or if you need assistance managing your information, please do not hesitate to contact us.
METHODS OF DATA COLLECTION
We collect personal data through various methods, including but not limited to:
(a) Direct Collection: Data you provide directly to us when applying for our services, registering an account, communicating with us, or engaging with us in any other manner.
(b) Automated Collection: Data collected automatically when you interact with our website through cookies and similar tracking technologies. Please see our Cookie Notice published on our website for more information about our cookie practices.
(c) Third-Party Sources: Data obtained from third-party sources, such as service providers (e.g., payment processors), state authorities, or publicly available sources.
DATA SHARING
Your personal data may be disclosed to service providers who assist us, such as payment processors, IT support, and marketing agencies, all of whom must adhere to our data protection standards. We may also share your data with regulatory or legal authorities as required by law. We do not sell your personal data to third parties, and any data sharing is conducted in compliance with legal requirements and safeguarded appropriately.
INTERNATIONAL DATA TRANSFERS
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) and the European Union (EU). These transfers are essential for providing our services and may involve your data being handled in jurisdictions that do not offer the same level of data protection as within the EEA and EU. To ensure your personal data is adequately protected during these transfers, we implement stringent safeguards, such as the European Commission's Standard Contractual Clauses, binding corporate rules, or other legally recognized mechanisms. In cases where the European Commission has issued an adequacy decision, recognizing that a non-EU/EEA country provides an adequate level of data protection, transfers to that country will be conducted under such a decision. These measures are designed to ensure that your data receives a level of protection equivalent to that provided within the EEA and EU, regardless of where it is processed.
DATA RETENTION
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The retention periods for different categories of data may vary. For example, data needed to comply with legal obligations is usually retained for a period of five years, with possible extensions if required by law. Data that may be relevant to potential legal claims is typically kept until the expiration of the statutory limitation period, which generally does not exceed ten years. After the relevant retention period has passed, we securely delete or anonymize your data to protect your privacy. If you have any questions about our data retention practices, please do not hesitate to contact us. We are committed to transparency and to ensuring that your privacy is fully safeguarded.
DATA SECURITY
We prioritize the security and confidentiality of your personal data by implementing a comprehensive range of technical and organizational measures designed to protect it from unauthorized access, alteration, disclosure, or destruction. Our security framework includes the following key elements:
· Encryption: We use advanced encryption technologies to safeguard your personal data both during transmission and storage, ensuring that it remains secure and inaccessible to unauthorized parties.
· Access Controls: We maintain strict access control protocols, allowing only authorized personnel to access your data based on their role and necessity. This minimizes the risk of data breaches and ensures that your information is handled responsibly.
· Regular Security Assessments: We conduct regular security audits and assessments to identify and mitigate potential vulnerabilities. Our systems and practices are continually updated to keep pace with evolving security threats and industry best practices.
· Secure Data Storage: Your personal data is stored in secure environments with multiple layers of protection, including firewalls, intrusion detection systems, and secure data centers that comply with industry standards.
· Trusted Partners: We only work with partners and service providers who adhere to the highest security standards, including the Payment Card Industry Data Security Standard (PCI DSS) for the secure handling of payment information. These partners are thoroughly vetted to ensure they maintain robust security measures and data protection practices in line with our own stringent requirements.
While we take extensive measures to protect your personal data, you also play a crucial role in ensuring its security. Here are some steps you can take:
· Use Strong Passwords: Create strong, unique passwords for your accounts and change them regularly. Avoid using easily guessable information such as birthdays or common words.
· Enable Two-Factor Authentication (2FA): Where available, enable two-factor authentication to add an extra layer of security to your account. This ensures that even if your password is compromised, your account remains protected.
· Be Cautious with Public Wi-Fi: Avoid accessing your accounts or providing personal information when connected to public Wi-Fi networks, as they may not be secure and could expose your data to unauthorized access.
· Keep Your Software Updated: Regularly update your software, applications, and devices to protect against the latest security vulnerabilities.
· Monitor Your Accounts: Regularly review your account activity for any suspicious transactions or changes. Report any unauthorized activity to us immediately.
· Beware of Phishing: Be vigilant about phishing attempts. Phishing is a fraudulent attempt to obtain sensitive information by pretending to be a trustworthy entity in electronic communications. Always verify the authenticity of emails, messages, or phone calls requesting personal information, and avoid clicking on suspicious links.
If you have any concerns or need further guidance on protecting your data, please contact us. Together, we can maintain the highest level of data security.
YOUR DATA SUBJECT RIGHTS
As a data subject under the data protection laws, you are entitled to exercise the following rights concerning your personal data:
(a) Right of Access: You have the right to request access to your personal data and obtain a copy of the information we hold about you.
(b) Right to Rectification: You are entitled to request the correction of any inaccurate or incomplete personal data we hold about you.
(c) Right to Erasure: You may request the deletion of your personal data, subject to certain legal obligations and limitations.
(d) Right to Restrict Processing: Under specific circumstances, you may request that we restrict the processing of your personal data.
(e) Right to Object: You have the right to object to the processing of your personal data where it is based on our legitimate interests or is used for direct marketing purposes.
(f) Right to Data Portability: You may request to receive your personal data in a structured, commonly used, and machine-readable format, and you may also request that we transfer this data to another data controller where technically feasible.
(g) Right to Withdraw Consent: Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us using the contact details provided in this document. Upon receiving your request, we will inform you of any such limitations and the outcome of your request. Additionally, we may require you to provide sufficient information to verify your identity before we can process your request to ensure the security of your data.
AUTOMATED DECISION-MAKING AND PROFILING
We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
COMPLAINTS
If you have concerns regarding the way we handle your personal data, we welcome the opportunity to address them directly and encourage you to contact us first. However, if for any reason it is not feasible to reach out to us, or if you prefer, you may also lodge a complaint with the supervisory authority in your jurisdiction. In Estonia the relevant authority is Data Protection Inspectorate. Contact details:
Data Protection Inspectorate (Andmekaitse Inspektsioon)
Website: https://www.aki.ee/en
Adress: Tatari 39, Tallinn 10134
Email: info@aki.ee
Tel: +372 627 4135
UPDATES TO THIS NOTICE
We may update this Privacy Notice from time to time to reflect changes in our data processing practices or to comply with legal requirements. The most recent version of this Notice will always be available on our website, and any significant changes will be communicated to you through appropriate channels. We encourage you to periodically review this Notice to stay informed about how we are protecting your personal data and to ensure you are aware of any updates or modifications.
DATA OF MINORS
Our services and website are not intended for use by individuals under the age of 18. We do not knowingly collect, process, or store personal data from minors. In the event that we become aware of the inadvertent collection of personal data from a minor, we will take prompt and appropriate measures to delete such data from our records. If you are a parent or guardian and have reason to believe that your child under the age of 18 has provided us with personal data, we urge you to contact us immediately so that we can address the issue and ensure the removal of any such data from our systems.
USER-GENERATED CONTENT AND SENSITIVE DATA
When utilizing our services, you may choose to upload various types of information, including data that is sensitive in nature. To safeguard your privacy and ensure the secure handling of your data, we urge you to adhere to the following guidelines:
(a) Exercise Discretion: Carefully evaluate the sensitivity of the information you choose to share. Upload only data that is both necessary for your interaction with our services and that you are comfortable disclosing.
(b) Handle Sensitive Data with Caution: Take extra precautions when submitting sensitive information, which may include personal, confidential, or otherwise protected data. Sensitive data demands a higher degree of care and discretion to prevent unauthorized access or misuse.
(c) Limit Disclosure to Necessity: Share only the information that is directly relevant and required for the specific purpose at hand. Avoid disclosing excessive or unnecessary details to mitigate potential risks to your privacy.
(d) Acknowledge Your Responsibility: You bear the responsibility for the content and nature of the information you choose to disclose. It is imperative that you understand the potential consequences of sharing sensitive data and make informed decisions regarding the information you upload.
By engaging with our services and uploading any form of data, you affirm that you comprehend these considerations and agree to assume full responsibility for the information you disclose. While we are committed to implementing robust measures to protect your data, the ultimate responsibility for the information provided lies with you. Should you have any questions or concerns about the type of data you are sharing, we encourage you to contact us for further guidance.
CONTACT US
If you have any questions or concerns regarding this Privacy Notice or our data processing practices, please contact us at: info@quickpixai.net.