|Last updated||11th March 2021|
Galaxkey Global Holding Limited, Jersey (registered number 125867), whose registered office is at Galaxkey Global Holdings Limited, Unit 10a Commercial Suites Castle Quay St Helier Jersey JE2 3WF know that you care how information about you is used and shared and we appreciate your trust in us to do that carefully and sensibly.
If you are a Galaxkey customer or subscriber, or just visiting our website, this policy applies to you.
- The data that you give to us
- The data that we may collect from you
- How we collect your data
- How we may use your data
- How we may share your data, with whom and why
- Where we may store, process and transfer your data
- How we secure your data
- Your responsibilities and your rights relating to your privacy
- How Galaxkey defines your data
|Your Galaxkey Account Data
|means the personal data about you that you provide to Galaxkey in connection with the following:
· Creation or administration of your account. This personal data may include name, usernames, email address, phone number, physical address, company name, payment details
· Information that you provide when you contact us
· Information that you provide when you access our products and services
· Information that you provide through consents and preference updates
|Your Data Content||means the data content that you protect using the Galaxkey product and or services. This may include data, text, audio, video or images. Galaxkey does not have access to your data content. Your data content does not include account data. The Galaxkey Terms of Service and Licence Agreement apply to customer/user data content.|
- Galaxkey’s role in your privacy
We know it is important to protect your personal data under the EU Regulation 2016/679 General Data Protection Regulation (GDPR) and we are committed to giving you a personalised service that meets your needs in a way that also protects your privacy.
Galaxkey as a data controller
If you are a registered Galaxkey user/customer or a visitor to our website we act as the data controller of personal data. This means that we decide how and why we process your data.
Galaxkey as a data processor
- When and how we collect data
From the first time you interact with Galaxkey, we may collect data. This includes you giving us your data directly and us collecting data from you or third-party sources which may be collected automatically.
|You provide us with your data for us to do this|
|We call you (only if you opt-in)|
|We send you emails (only if you opt-in)|
|We send you marketing materials (only if you opt-in)|
|We collect data from you to do this|
|When you browse our website, we may collect anonymous data relating to how you use our website. We use this to maintain and improve our website and the service we provide to you.|
|We use data that you provide to us and data we collect from you to do this|
|When you agree to take a service or product from us: through purchasing, registering, logging into, authenticating or accessing your account. We use this data to fulfil the service to you.|
|You fill in a form on our website (contact us, buy, request a demo etc.) We use this data to respond to your requests.|
- Providing us with information about others
- Types of data that we collect
This may include your first name, last name, telephone numbers (mobile or landline), email address, company details.
Data that identifies you
Your IP address (mostly anonymised), browser type and version, time zone setting, browser plug-in types, geolocation data (your location in the world), email address, operating system and version.
Data on how you use Galaxkey
Your URL clickstreams (the path you take through our website), pages viewed, page response times, website errors, download errors, the time that you spend on our website, how you navigate our website and use it, how often you use it.
Galaxkey is a business service directed at adults and for use in business. We do not target children and we do not knowingly collect any personal data from children, any person under 16 years of age. If you are not 16 years of age or above, you may not use our service or software. If our algorithms or staff validate your age to be below 16 years, we will disable your account.
- How and why, we use your data
The GDPR describes how we can use your data and the legal basis to do so. This is how and why we use your data:
Legal basis is defined as follows:
- Contract: this is necessary to fulfil the contract that you have with us or necessary to fulfil the procedures prior to entering the contract.
- Consent: you have given consent for us to process your data for that specific purpose.
- Legitimate interest: this is necessary for our legitimate interests or legitimate interests of a third party. These may include to gain insights from your conduct on our website, to provide our service and products to you, to improve and develop our services, communication and support, to determine the effectiveness of our marketing, to enhance our data security.
To maintain Galaxkey functioning properly and compliantly
- To help us to identify you when you contact us
- To help us to identify accounts, services and/or products which you use from us or selected partners
- To manage your requests, to provide the product and service to you
- To fulfil contractual obligations or pre-contractual obligation
- To administer and manage your account and our relationship with you
- To meet your data protection rights (preferences, keep your data accurate etc.)
- To maintain and develop our products, services, platform and infrastructure and ensure they are functioning properly
- To show you the appropriate website or portal
- To manage risk, ensure security and proper functioning of our services and infrastructure and to detect and prevent criminal activity
Legal basis: contract and legitimate interest
To maintain and improve Galaxkey
- Interaction with forms available on our website or applications
- To manage our website pages
- Heat mapping our website
- To optimise our site to provide a better experience for our visitors
- Through analysing website traffic and data which is anonymous
- To maintain and develop our brand and website
Legal basis: contract and legitimate interest
- To keep you updated with any changes to our products or services
- Responding to and resolving issues and requests
- To manage, track and develop our customer relationship with you
- To agree payment methods
- To alert you to any concerns or updates to the services
- To provide technical and customer support and guidance relating to products and services provided by us or our partners
- We may monitor and record communications for quality assurance and compliance purposes
Legal basis: contract
- Sending you emails about new features, products, services, promotional material, newsletters
- For marketing analysis and research purposes
- We only do this with your explicit consent, and you can update your preferences at any time
Legal basis: consent
- Updating your consent preferences
You can change your consent preferences at any time. This means that you can give consent and withdraw consent whenever you want to. You can contact us at firstname.lastname@example.org or update your consent preferences from the Galaxkey Manager Portal under Profile
- Your privacy choices
You can choose not to provide us with your personal data (you will still be able to visit our website however, we will not be able to provide you with our products and services).
You can disable cookies in your browser (you can continue to visit our website; however, the website may not work as effectively or optimally).
You can choose that we do not use your personal data for marketing purposes (we will ask you before we use your personal data for marketing purposes, and you can always opt-in or opt-out by contacting us or by updating your preferences on our website).
- Your Privacy Rights
The GDPR sets out the following rights applicable to data subjects. You can exercise your rights by contacting us at email@example.com
The right to access
You have the right to access your personal data that we hold about you.
You can contact Galaxkey requesting this information via a subject access request (SAR) free of charge.
The subject access request should be made by email to firstname.lastname@example.org. Galaxkey will verify the individual making the subject access request before handing over the information.
Galaxkey will aim to respond to such a request in, usually, one month of receipt but this may be extended if the SAR is complex. We will keep you informed of the progress.
The right to be informed
We aim to keep you informed of how your information is collected, processed, transferred, and stored. This includes:
- The purpose for collecting the information at the time of collection
- Information collected for communication purposes, at the time of the first communication
- Transfer of data to another party, before transfer or as soon as reasonably possible
- Transfer of information to a third party located outside of the EEA
The right to rectification
We aim to keep the personal data we hold about you accurate and up to date. If you tell us that we are holding any inaccurate personal data about you, we will delete it or correct it promptly. Please email us at email@example.com. Our systems enable our users to update their information if required.
The right to erasure (also known as the ‘right to be forgotten’)
You can request that your personal data that Galaxkey holds about you be erased. Galaxkey will erase personal data in accordance with the GDPR. Unless Galaxkey has reasonable grounds to refuse the erasure, all requests will be complied with.
The right to restrict processing
You can request that Galaxkey stops the processing of your data. Galaxkey will comply and will only retain the personal data (if any) necessary to ensure that the information is no longer processed by Galaxkey.
The right to data portability
Galaxkey ensures the portability of your data. To facilitate data portability Galaxkey will make the personal data available in a Galaxkey encrypted format that is securely transferable to you on request. This will be complied with in a timely manner.
The right to object
You can object to Galaxkey processing your personal data based on legitimate interests, direct marketing, processing for scientific and/or historical research and statistic purposes. Unless the law allows, Galaxkey will comply with your request and stop processing your information.
The Rights with respect to automated decision-making and profiling
Galaxkey does not use personal data for automated decision making and profiling.
- How we protect your data
We have organisational and technical measures in place to protect your data and secure the information that you provide, and we collect. We take steps to ensure personal data collected, held, and processed is kept secure and protected from unauthorised or unlawful processing and against accidental loss, destruction or damage.
We protect the security of your information during transmission by using TLS (Transport Layer Security) and with Galaxkey software which encrypts information you input with your key. So, we don’t have access to your data that you secure using Galaxkey, only you do and those you give access to.
We maintain physical, electronic and procedural safeguards in connection with the collection, storage and disclosure of personal data.
Our security procedures mean that we may occasionally request proof of identity before we disclose personal data to you.
It is important for you to protect your Galaxkey account against unauthorised access to your password and to your computer. Be sure to sign off when you finish using a shared computer.
We also provide free 2 Factor and or Multifactor authentication which we recommend you always use to protect your account and thus your protected data secured using Galaxkey. You may not share your password or credentials with anyone, doing so is against our terms of service and will lead to account closure.
It is important to remember that the information you provide on our website is your choice and no transmission is 100% guaranteed secure, especially as it traverses a public network which we have no control over.
Please remember that communications over the internet, such as emails and webmail (messages sent through a website), are not secure unless they have been encrypted. Your communications may go through a number of countries before they are delivered – this is the nature of the internet. We cannot accept responsibility for any unauthorised access or loss of personal data that is beyond our control.
You are solely responsible for your credentials, your username and password. Do not share these details and keep them private and secure
- Where we process, store and transfer your data
The personal data that we collect is mainly processed in our offices in London and in any data processing facilities operated by third parties identified in this policy.
We may employ third parties to perform functions on our behalf and may share your personal data to these parties to fulfil our function and contract including: for fulfilling orders, delivering packages, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links (including paid listings and links) and providing customer service.
We may transfer your encrypted data if we, or substantially all of our assets, are acquired or are in the process of being acquired by a third party, in which case personal data held by us, about our customers, will be one of the transferred assets.
We may transfer your data if applicable by law. If we have been legitimately asked to provide information for legal or regulatory purposes or as part of legal proceedings or prospective legal proceedings.
To operate effectively we may need to transfer data to third parties outside the EEA. By submitting your personal data, you agree to this transfer, storing and processing by us. If we transfer or store your data outside of the EEA, we will ensure that the transfer is subject to appropriate safeguards so that your security and privacy is maintained.
- How long we keep your data for
Galaxkey will only keep personal data for the amount of time that it is needed for the original processing purpose. If it is no longer needed, Galaxkey will take reasonable steps to securely remove the information.
To ensure that personal data is kept for no longer than is necessary, Galaxkey has a data retention period of 12 months if the user is not active or after the expiration of the subscription. Unless agreed otherwise with you in a separate contract. We remove information securely by digital shredding.
- Third parties may process your data
We may need to share your data with these third parties to fulfil our function and contract with you. We only do this is if it is necessary and when we do we have safeguards in place to protect your data and your privacy as outlined in this policy. Below are our main third-party processing partners and links to their privacy policies. These partners do not have access to any of the data content you have protected with Galaxkey software.
Please be aware that the Galaxkey website may link to other websites that may be accessed by you through our site. We are not responsible for their data security and privacy policies, content or security of these linked websites. We do not have any control over how these linked third parties may use your data when you when you choose to purchase products or services or otherwise to contact them via our site.
We do not provide any personal data to these third-party websites.
We exclude all liability for loss that you may incur when using these third-party websites.
- How to complain
If you have any complaints or questions relating to your privacy or this policy please contact us at firstname.lastname@example.org.
- Updating this policy
We may update this policy from time to time so please check back on a regular basis. If we make any significant changes we will notify you through our software or by email. If you have any questions relating to your privacy or this policy, please contact us at email@example.com.
- Governing Law
This policy is governed by the laws of Jersey. These terms and all of the subject matter are solely governed by Jersey Law and not for the country in which the Galaxkey licensed services, software, services and web infrastructure is purchased, installed and used.
Any dispute will be handled exclusively in the jurisdiction of the courts of Jersey.
- Additional information
Any use of our systems for illegal activities will result in immediate suspension of your account.