Privacy policy

Last updated 21 May 2018

 

  1. Policy outline

Galaxkey Limited (registered number 07338597), whose registered office is at 2 Falcon Gate Shire Park, Welwyn Garden City, AL7 1TW know that you care how information about you is used and shared and we appreciate your trust in us to do that carefully and sensibly.

Our privacy policy forms part of our website terms and conditions. You should read this policy in conjunction with our website terms.

By accepting our website terms or by visiting www.galaxkey.com you are accepting and consenting to the practices described in this privacy policy.

If you are a Galaxkey customer or subscriber, or just visiting our website, this policy applies to you.

This privacy policy explains:

  • The data that you give to us
  • The data that we may collect from you
  • How we collect your data
  • How we may use your data
  • How we may share your data, with whom and why
  • Where we may store, process and transfer your data
  • How we secure your data
  • Your responsibilities and your rights relating to your privacy
  1. How Galaxkey defines your data
Your Galaxkey Account Data

 

 

means the personal data about you that you provide to Galaxkey in connection with the following:

o   Creation or administration of your account. This personal data may include name, usernames, email address, phone number, physical address, company name, payment details

o   Information that you provide when you contact us

o   Information that you provide when you access our products and services

o   Information that you provide through consents and preference updates

Your Data Content

 

means the data content that you protect using the Galaxkey product and or services. This may include data, text, audio, video or images. Galaxkey does not have access to your data content. Your data content does not include account data. The Galaxkey Terms of Service and Licence Agreement apply to customer/user data content.

 

  1. Galaxkey’s role in your privacy

We know it is important to protect your personal data under the EU Regulation 2016/679 General Data Protection Regulation (GDPR) and we are committed to giving you a personalised service that meets your needs in a way that also protects your privacy.

Galaxkey as a data controller

If you are a registered Galaxkey user/customer or a visitor to our website we act as the data controller of personal data. This means that we decide how and why we process your data.

Galaxkey as a data processor

If you are agreeing a contract through Galaxkey, you should check the privacy policy of the Galaxkey customer who sent you the contract. This means that you are not the registered user and we act as the data processor of the Galaxkey customer who has sent you the contract. This means we only process your data to help us provide our service to our customer, or in accordance with our customer’s instructions, or as required by law. Our customer is responsible to ensure that your personal data is handled in accordance with the data protection laws, including how service providers (like Galaxkey), collect and use data on their behalf.

  1. When and how we collect data

From the first time you interact with Galaxkey, we may collect data. This includes you giving us your data directly and us collecting data from you or third-party sources which may be collected automatically.

You provide us with your data for us to do this
We call you (only if you opt-in)
We send you emails (only if you opt-in)
We send you marketing materials (only if you opt-in)

 

We collect data from you to do this
When you browse our website we may collect anonymous data relating to how you use our website. We use this to maintain and improve our website and the service we provide to you.

 

We use data that you provide  to us and data we collect from you to do this
When you agree to take a service or product from us: through purchasing, registering, logging into, authenticating or accessing your account. We use this data to fulfil the service to you.
You fill in a form on our website (contact us, buy, request a demo etc.) We use this data to respond to your requests.

 

  1. Providing us with information about others

If you provide information to us on behalf of someone else, you confirm that you have provided them with the information set out in this privacy policy and that they have not objected to such use of their personal data. You must make sure that you have the right and permission to use their information in this way. By providing the information you confirm that you have the permission and right to do so.

  1. Types of data that we collect

 Contact details

This may include your first name, last name, telephone numbers (mobile or landline), email address, company details…

Data that identifies you

Your IP address (mostly anonymised), browser type and version, time zone setting, browser plug-in types, geolocation data (your location in the world), operating system and version…

Data on how you use Galaxkey

Your URL clickstreams (the path you take through our website), pages viewed, page response times, website errors, download errors, the time that you spend on our website, how you navigate our website and use it, how often you use it…

Children’s data

Galaxkey is a business service directed at adults and for use in business. We do not target children and we do not knowingly collect any personal data from children, any person under 16 years of age. If you are not 16 years of age or above you may not use our service or software. If our algorithms or staff validate your age to be below 16 years we will disable your account.

  1. How and why we use your data

The GDPR describes how we can use your data and the legal basis to do so. This is how and why we use your data:

Legal basis is defined as follows:

  • Contract: this is necessary to fulfil the contract that you have with us or necessary to fulfil the procedures prior to entering the contract.
  • Consent: you have given consent for us to process your data for that specific purpose.
  • Legitimate interest: this is necessary for our legitimate interests or legitimate interests of a third party. These may include to gain insights from your conduct on our website, to provide our service and products to you, to improve and develop our services, communication and support, to determine the effectiveness of our marketing, to enhance our data security.

To maintain Galaxkey functioning properly and compliantly

  • To help us to identify you when you contact us
  • To help us to identify accounts, services and/or products which you use from us or selected partners
  • To manage your requests, to provide the product and service to you
  • To fulfil contractual obligations or pre-contractual obligation
  • To administer and manage your account and our relationship with you
  • To meet your data protection rights (preferences, keep your data accurate etc.)
  • To maintain and develop our products, services, platform and infrastructure and ensure they are functioning properly
  • To show you the appropriate website or portal
  • To manage risk, ensure security and proper functioning of our services and infrastructure and to detect and prevent criminal activity

Legal basis: contract and legitimate interest

 To maintain and improve Galaxkey

  • Interaction with forms available on our website or applications
  • To manage our website pages
  • Heat mapping our website
  • To optimise our site to provide a better experience for our visitors
  • Through analysing website traffic and data which is anonymous
  • To maintain and develop our brand and website

Legal basis: contract and legitimate interest

Customer support

  • To keep you updated with any changes to our products or services
  • Responding to and resolving issues and requests
  • To manage, track and develop our customer relationship with you
  • To agree payment methods
  • To alert you to any concerns or updates to the services
  • To provide technical and customer support and guidance relating to products and services provided by us or our partners
  • We may monitor and record communications for quality assurance and compliance purposes

Legal basis: contract

Marketing

  • Sending you emails about new features, products, services, promotional material, newsletters
  • For marketing analysis and research purposes
  • We only do this with your explicit consent and you can update your preferences at any time

Legal basis: consent

  1. Updating your consent preferences

You can change your consent preferences at any time. This means that you can give consent and withdraw consent whenever you want to. You can contact us at info@galaxkey.com or update your consent preferences at www.galaxkey.com.

  1. Your privacy choices

You can choose not to provide us with your personal data (you will still be able to visit our website however, we will not be able to provide you with our products and services).

You can disable cookies in your browser (you can continue to visit our website, however, the website may not work as effectively or optimally).

You can choose that we do not use your personal data for marketing purposes (we will ask you before we use your personal data for marketing purposes and you can always opt-in or opt-out by contacting us or by updating your preferences on our website).

  1. Your Privacy Rights

The GDPR sets out the following rights applicable to data subjects. You can exercise your rights by contacting us at info@galaxkey.com

The right to access

You have the right to access your personal data that we hold about you.

You can contact Galaxkey requesting this information via a subject access request (SAR) free of charge.

The subject access request should be made by email to info@galaxkey.com. Galaxkey will verify the individual making the subject access request before handing over the information.

Galaxkey will aim to respond to such a request in, usually, one month of receipt but this may be extended if the SAR is complex. We will keep you informed of the progress.

The right to be informed

We aim to keep you informed of how your information is collected, processed, transferred, and stored. This includes:

  • The purpose for collecting the information at the time of collection
  • Information collected for communication purposes, at the time of the first communication
  • Transfer of data to another party, before transfer or as soon as reasonably possible
  • Transfer of information to a third party located outside of the EEA

 The right to rectification

We aim to keep the personal data we hold about you accurate and up to date. If you tell us that we are holding any inaccurate personal data about you, we will delete it or correct it promptly. Please email us at info@galaxkey.com. Our systems enable our users to update their information if required.

The right to erasure (also known as the ‘right to be forgotten’)

You can request that your personal data that Galaxkey holds about you be erased. Galaxkey will erase personal data in accordance with the GDPR. Unless Galaxkey has reasonable grounds to refuse the erasure, all requests will be complied with.

The right to restrict processing

You can request that Galaxkey stops the processing of your data. Galaxkey will comply and will only retain the personal data (if any) necessary to ensure that the information is no longer processed by Galaxkey.

The right to data portability

Galaxkey ensures the portability of your data. To facilitate data portability Galaxkey will make the personal data available in a Galaxkey encrypted format that is securely transferable to you on request. This will be complied with in a timely manner.

The right to object

You can object to Galaxkey processing your personal data based on legitimate interests, direct marketing, processing for scientific and/or historical research and statistic purposes. Unless the law allows, Galaxkey will comply with your request and stop processing your information.

The Rights with respect to automated decision-making and profiling

Galaxkey does not use personal data for automated decision making and profiling.

  1. How we protect your data

We have organisational and technical measures in place to protect your data and secure the information that you provide and we collect. We take steps to ensure personal data collected, held, and processed is kept secure and protected from unauthorised or unlawful processing and against accidental loss, destruction or damage.

We protect the security of your information during transmission by using Secure Sockets Layer (SSL) or TLS (Transport Layer Security) and with Galaxkey software which encrypts information you input with your key. So, we don’t have access to your data that you secure using Galaxkey, only you do and those you give access to.

We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personal data.

Our security procedures mean that we may occasionally request proof of identity before we disclose personal data to you.

It is important for you to protect your Galaxkey account against unauthorised access to your password and to your computer. Be sure to sign off when you finish using a shared computer.

We also provide free 2 Factor and or Multifactor authentication which we recommend you always use to protect your account and thus your protected Galaxkeyed data. You may not share your password or credentials with anyone, doing so is against our terms of service and will lead to account closure.

It is important to remember that the information you provide on our website is your choice and no transmission is 100% guaranteed secure, especially as it traverses a public network which we have no control over.

Please remember that communications over the internet, such as emails and webmails (messages sent through a website), are not secure unless they have been encrypted. Your communications may go through a number of countries before they are delivered – this is the nature of the internet. We cannot accept responsibility for any unauthorised access or loss of personal data that is beyond our control. If you require better security please use Galaxkey.

You are solely responsible for your credentials, your username and password. Do not share these details and keep them private and secure

If you believe your privacy has been breached, let us know by contacting us immediately at info@galaxkey.com.

  1. Where we process, store and transfer your data

The personal data that we collect is mainly processed in our offices in London and in any data processing facilities operated by third parties identified in this policy.

We  may employ third-parties to perform functions on our behalf and may share your personal data to these parties to fulfil our function and contract including: for fulfilling orders, delivering packages, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links (including paid listings and links) and providing customer service.

Those parties are bound by strict contractual provisions with us and only have access to personal data needed to perform their functions and may not use it for other purposes. Further, they must process the personal data in accordance with this Privacy Policy and as permitted by the data protection regulation

We may transfer your encrypted data if we, or substantially all of our assets, are acquired or are in the process of being acquired by a third party, in which case personal data held by us, about our customers, will be one of the transferred assets.

We may transfer your data if applicable by law. If we have been legitimately asked to provide information for legal or regulatory purposes or as part of legal proceedings or prospective legal proceedings.

To operate effectively we may need to transfer data to third parties outside the EEA. By submitting your personal data, you agree to this transfer, storing and processing by us. If we transfer or store your data outside of the EEA, we will ensure that the transfer is subject to appropriate safeguards so that your security and privacy is maintained.

  1. How long we keep your data for

Galaxkey will only keep personal data for the amount of time that it is needed for the original processing purpose. If it is no longer needed, Galaxkey will take reasonable steps to securely remove the information.

To ensure that personal data is kept for no longer than is necessary, Galaxkey has a data retention period of 12 months if the user is not active or after the expiration of the subscription. Unless agreed otherwise with you in a separate contract. We remove information securely by digital shredding.

  1. Third parties may process your data

We sometimes use third parties to help us provide the Galaxkey products and services to you. The third parties that we partner with are chosen by us, they adhere to the data protection regulation and this privacy policy.

We may need to share your data with these third parties to fulfil our function and contract with you. We only do this is if it is necessary and when we do we have safeguards in place to protect your data and your privacy as outlined in this policy. Below are our main third-party processing partners and links to their privacy policies. These partners do not have access to any of the data content you have protected with Galaxkey software.

 

Third party

 

Purpose

 

Data collected or shared

 

Privacy Policy

Amazon Web Services Infrastructure Storing of your encrypted data if you are not a paying subscriber or if you have not elected to use a Galaxkey on premise appliance or service Privacy policy
HubSpot Customer relationship management Contact details that you give to us for us to contact you Privacy policy
Smartlook Website analytics Anonymous data to improve our website Privacy policy
Zendesk Customer support Contact details and information that you provide to us for us to support you Privacy policy

 

  1. Cookies

We use cookies on our website. Our cookies are used to improve your website experience. You can choose to disable the cookies in your browser. Please see our Cookie Policy for further details.

  1. Links

 Please be aware that the Galaxkey website may link to other websites that may be accessed by you through our site. We are not responsible for their data security and privacy policies, content or security of these linked websites. We do not have any control over how these linked third parties may use your data when you when you choose to purchase products or services or otherwise to contact them via our site.

We do not provide any personal data to these third-party websites.

We exclude all liability for loss that you may incur when using these third-party websites.

  1. How to complain

 If you have any complaints or questions relating to your privacy or this policy please contact us at info@galaxkey.com.

  1. Updating this policy

We may update this policy from time to time so please check back on a regular basis. If we make any significant changes we will notify you through our software or by email. If you have any questions relating to your privacy or this policy please contact us at info@galaxkey.com.

  1. Governing Law

This policy is governed by the law of the UK, English law. These terms and all of the subject matter are solely governed by English Law and not for the country in which the Galaxkey licensed services, software, services and web infrastructure is purchased, installed and used.

Any dispute will be handled exclusively in the jurisdiction of the courts of England.

  1. Additional information

 If you would like any more information or you have any comments about our privacy policy, please either write to us at Data Protection Manager, Galaxkey Limited, 2 Falcon Gate Shire Park, Welwyn Garden City, AL7 1TW or email us at info@galaxkey.com.

You can ask us for a copy of this privacy policy and of any amended privacy policy by writing to the above address or by emailing us at info@galaxkey.com.

Any use of our systems for illegal activities will result in immediate suspension of your account.