2. Information on the Types of Data Processed and Their Origin
3. Processing Purposes & Legal Bases
6. Information on Behavioural Advertising
7. Transfer to Countries Outside the EU or the EEA
8. How Long Will my Data be Stored?
9. Information on the Voluntary Nature of the Information Provided
10. Information About Your Rights
11. Information About Your Right of Objection
12. Information on Your Legal Rights Under the California Consumer Privacy Act (CCPA)
13. Amendment of the Privacy Statement
This Privacy Notice provides an overview of the processing of your personal data in the context of the use of the offers and online Services on our Website and the corresponding App (hereinafter referred to as the ‘Service’).
Furthermore, this Privacy Notice informs you about your rights and the possibilities you have to control your personal data and to protect your privacy.
We have always taken the protection of your personal data very seriously and continuously take appropriate organisational, contractual and technical measures to protect your data from unauthorised or unlawful processing and against accidental loss, destruction or damage.
The data controller is Ideawise Limited, Room 604, Alliance Building, 133 Connaught Road, Central Hong Kong, Hong Kong. Its representative is SmH ServiceCenter.de GmbH, Metzer Str. 13, 13595 Berlin/Germany. Please direct any general support requests to: [email protected]).
Ideawise Limited is also meant when the terms ‘we’ or ‘us’ are used below. Please note that we are a company based outside the European Economic Area (‘EEA’). As far as you use our Service and data is processed, these data are collected by a data controller located in a so-called ‘Third Country’. Nonetheless, we will respect standards under applicable European data protection laws. Details about international data transfers can be found in section 7 below. You can contact our data protection officer at: email@example.com (general support requests will not be processed by the data protection team, please direct these requests to [email protected]).
If we provide the Service for your use, we process personal data from various sources. This is data that we collect automatically - for example when you visit our Website - as well as other data that you have additionally provided to us.
When visiting our Website, you submit technical information to our servers. This happens regardless of whether you subsequently register an account with us to use the Service or not. In any case, the following data will be processed:
The so-called server log. This is a file which stores the following data: the time, the status of your Website visit (status means in this case whether the request of the Website was successful or not) as well as the request that your browser has made to the server to open the page, the amount of data transferred and the Website from which you came to the requested page (referrer), and the product and version information of the browser used (user agent).
If you create a profile on our Service, we will assign a so-called unique user ID to it. Besides your chosen profile name, the unchangeable Unique User ID allows us to uniquely identify your profile.
In addition to the data we receive from all Website visitors, we also process other data from registered users.
The exact amount of this data depends on how you use the Service.
Personal information that you publicly upload to your profile or other areas of the Service will be visible to other users (and searchable via the search feature within the Service). If you choose additional settings for the wider publication of your data, this information will also be accessible to users who are not logged in. These privacy settings can be determined by you in your profile settings.
The data you provide to us include:
To use the Service, you can create a user account (a ‘Profile’). When you create a Profile, you must provide some mandatory information to complete the registration.
● Email address
● City and postcode
● Date of birth
● Gender, with option of not specifying this
● Real name, with option of not specifying this
By use of the so-called Single-Sign-On procedure, when registering with a profile, a profile is also automatically created at the provider of the ‘Happiness Academy’ platform, Thinkific. More information about this in Section vi.
The use of the Service is possible only with the aforementioned information. However, you may also provide additional personal information in your Profile, such as your real name, profession, personal interests or detailed information about your political opinion or your religious ideological beliefs. If you want to, you can upload photos and videos to your Profile or to a secret gallery. The scope of this optional data can be determined by you via the respective input fields in your Profile settings.
When you register with our Service, we use your IP once to determine your approximate location. You can agree to this localisation when registering or change it if necessary. In the app your location will only be collected with your permission.
If you communicate with other users of our Service, we save your conversations so that the conversation history with your chat partners can be permanently displayed, and conduct checks on certain keywords for the prevention of criminal activity.
When you contact our Customer Service, written communications between you and the Service staff and notes on each transaction are stored so that you can always have a smooth Customer Service experience when the transaction is resumed by other Service staff.
To verify your profile, you need to upload an image that shows your face and your left or right hand.
If you grant the App access to your camera or photo album, we will only receive the data you actively provide, e.g. photos you upload to the Services and nothing beyond. The same applies to you consenting to the delivery of notifications and the way in which they are displayed. You can change these settings at any time in the device settings and revoke your consent there. Your list of contacts will never be accessed at any time.
You can also use the ‘Login with Facebook’ feature to create your profile. When choosing this feature, you transmit your username on the social network at www.facebook.com (‘Facebook’), your email address with which you registered on Facebook, as well as your gender, first name and your profile picture. Your first name and profile picture are used to suggest a profile name and profile picture in our Service, you can reject or change both during the sign-up process. Please be aware: If you sign up to use the service, a strictly designated account will be created with our service provider Thinkific so that you may use our learning platform / academy feature. More information about Thinkific can be found in Section 4.
We process your data exclusively for the following defined
- To allow you and other users to use the Service and to ensure its functionality
- To provide you with additional Services that you have purchased
- To keep you up to date with relevant information about our Service and to send you system notifications to the e-mail address you have provided.
- To send our newsletter and other information about our Services to the provided e-mail address (such as for example about competitions/sweepstakes, discount campaigns, events, satisfaction surveys or other similar offerings of our online platforms)
- To adapt the provision of the Service to your needs
- To provide the happiness Academy together with Thinkific
- To display advertising tailored to your interests (including participation in sweepstakes)
- To continuously improve the Service offer and to correct errors
- To detect and prevent fraud attempts
- To ensure the protection of minors
- To enable the exchange with Customer Service in case of questions
- To check information published on your profile or shared by you through the Service
- To disclose your personal data to third parties if we are legally obliged to do so
- To assert legal claims and to defend against legal disputes
- To ensure IT security and smooth operation of IT systems
- To assist the competent authorities in discovering and prosecuting criminal offences including, but not limited to, offences causing bodily injury or death of the victims
In doing so, we rely on various legal bases in accordance with the so-called General Data Protection Regulation, a European Union legal framework for the standardisation of data protection law (‘GDPR’ for short). We refer in detail to the following legal bases:
When visiting the Website without registration, you agree to the cookie guidelines in the pop-up. If you have given us your consent to process personal data for specific purposes, this consent ensures the legality of the processing. By registering and creating your profile, you expressly agree to its use for the purposes described in detail in this Privacy Notice by ticking the box before submitting the registration form. So, if we process your data, it is because you have expressly allowed us to do so when you registered. Your consent is therefore the most important legal basis for the processing of your personal data by us. If you provide us with information about your sexual orientation or preferences, we will process this data exclusively on the basis of your consent.
At the same time, the processing of personal data takes place also for the provision of the Service and in the context of the performance of our contract with you. In many cases, the processing is not only justified by your consent, but also because it is necessary to fulfil our contract with you: In order to fulfil your claim to the Services described in more detail in our General Terms and Conditions, it may be necessary, for example, to process your personal data, for example, if you wish to pay for your PLUS membership the processing of your payment information is required.
We invoke this legal basis in narrowly defined case constellations (e.g. reported suicide announcements) where the processing is necessary for the protection of the vital interests of the data subject or another natural person.
By registering to use the Service, you consent to the processing of your data in accordance with this Privacy Notice. That is why we process your data in principle, because you have allowed us to do so. However, there are some cases in which we would be entitled to process your data without your consent because it is necessary to protect our legitimate interests (or the interests of third parties). In this respect, the purposes for which we process your data also represent legitimate interests. We pursue legitimate interests, for example, if we check images or texts for content relevant under applicable criminal law or if we take measures to secure our ‘virtual domiciliary rights’. In these cases, we will not ask you in advance whether you agree to this processing, since processing is otherwise permitted by law.
In addition, we are legally obliged to provide certain information to criminal prosecution, tax or other authorities in individual cases upon request, if such processing is necessary for safeguarding public interest. Additionally, commercial and tax law contain such obligations for processing in some cases.
We treat your personal data with care and confidentiality and will only pass them on to third parties and other recipients to the extent described below and not beyond.
As our Service is a platform for getting to know each other, it is in the nature of things that we forward your profile data as well as other data (e.g. messages you send and other communication you have with other users and the community) at your request and on your behalf to the corresponding users of the Service.
We transfer data to affiliated companies which form part of the same group of companies as us within the framework of strict protection requirements. This is the case, for example, when you make a Customer Service request. We will then forward this request to SmH ServiceCenter.de GmbH, a service company associated with us. In addition, our development company, TheNetCircle Network Co. Ltd. as well as the payment / debt collection partners Compay GmbH and Faircollect GmbH and the community management and marketing at Playamedia S.L. receive the necessary information to ensure the security and functionality of the Service and the handling of payments.
In addition, we transmit data to external service providers who enable us to provide the Service to you. These include hosting providers, delivery service providers, payment service providers and providers of analytics platforms. We require each of these service providers to comply with strict rules about the security of your personal information when processing personal information on our behalf. Such processing operations are therefore principally based on your explicit consent as well as contractual agreements guaranteeing an adequate level of protection for your data.
We use the following affiliate systems to attract new customers to our community. In doing so we measure success on the basis of registrations and revenue.
- Google Adwords: We also use Google Adwords in conjunction with the Google Tag Manager to promote our site in Google search results and on third-party sites. Google (location USA, Privacy Shield certified) uses a remarketing cookie that contains a pseudonymous cookie ID and information about the use of our Website. This way, displayed ads are tailored towards your interests. We also use Google AdSense, which places a Doubleclick Cookie. This cookie is placed when clicking on an Ad on a partner website. Information on opt-out options
This hosting service (processing in USA and Europe, Privacy Shield certified) is used by us to store and deliver videos and images.
Jira and Confluence are products of the company Atlassian (location USA, Privacy Shield certified) that we use for error prevention, trouble shooting and for project management. In principle, no personal data is transmitted, in rare circumstances, however, a username may be mentioned in a so-called ‘ticket’ in order to enable us to quickly resolve technical issues.
We transmit data to authorities in the event of a legal obligation based on a request for information from the respective authority.
Our subsidiary Compay GmbH (located in Germany, adequate level of data protection) is our payment collection partner. When purchasing a membership or points via the website or mobile website, the billing information is passed directly to Compay. Here you can see what data is involved. For information about payments via the App, please see point 5.
We use Facebook (location USA, Privacy Shield certified) for the feature ‘Log in with Facebook’. The data required for registration (e-mail address, date of birth, first name, profile photo) is transferred from Facebook to us. In addition, we use the Facebook Tracking Pixel without Advanced Matching, for this type of processing we are joint-controllers together with Facebook. The purpose of its use is the optimisation of advertising campaigns. The tracking process allows the user to be identified across multiple web pages. In our case this comprises in particular:
Information on opt-out options for the Facebook Tracking Pixel can be found here.
Google LLC is a Privacy Shield certified provider from the USA. Google Analytics is used to analyse the behavior of users of our Services. With the help of Google Captcha, we can determine whether a visitor is a human being or a machine for certain actions. YouTube videos are embedded in our Service in ‘advanced privacy mode’. While no Youtube cookies are set due to this particularly data protection-friendly method of embedding, calling up the pages nevertheless leads to a connection being established with YouTube and the DoubleClick network. A click on the video can trigger further data processing operations over which we have no control. We use Google Maps to show members in the regional search on a map. We do not use the actual location of the user, but a location stored by us based on the zip code provided by the user. Information on opt-out options
Kayako (location UK) is our system for dealing with customer queries. With each request the e-mail address, your preview profile picture and the username will be transmitted.
We use Thinkific (location Canada, adequate level of data protection) for the provision of the Happiness Academy on our Service. When you register, we transmit your user name and a pseudonymised email address to Thinkific. The pseudonymised email forwards incoming emails to your email address stored in our system. Thinkific processes this data as our processor solely for the purpose of operating our service. If you also register for a course or another activity on our service, your username, the pseudonymised e-mail address and your last log-in date will be disclosed to the respective course teacher via the Thinkific backend.
With this survey feature (location Spain, adequate level of data protection) we improve and entertain our community through a permanent feedback survey, as well as regular via quizzes, other surveys and evaluations. It depends on each survey which information is passed on to Typeform, furthermore you decide yourself what you enter here. Among other things, the nickname, sex, payment class, information about the device (operating system, model, manufacturer and mobile phone provider) as well as the location stored in the profile can be transmitted.
Vendo (location Switzerland, adequate level of data protection) is an alternative payment provider for payments outside of Germany, Austria and Switzerland. When purchasing a membership or points, the User ID will be forwarded directly to Vendo.
In exceptional cases (e.g. suspected fraudulent use, reporting via other users etc.) we use the following platforms for checking uploaded images and for the performance of a fake check by uploading the image to the following services:
- Google Search by Google LLC (location USA)
- Tineye (location Canada, adequate level of data protection)
- Bing by Microsoft Corporation (location USA)
- Yandex (location Switzerland, adequate level of data protection)
- Baidu (location China, no adequate level of data protection)
Adjust (location Germany, adequate level of data protection) provides usage evaluation and analysis of marketing activities. When opening the App, Adjust collects installation and event data. We use this information to understand how our users interact with our App and to analyse mobile ad campaigns. For such an analysis Adjust uses your anonymised IDFA (iOS) or GAID (Android) as well as your anonymised IP address. It is not possible to identify you individually.
We use Apple (location USA) and its Apple Push Notification Service (APNS) to send push notifications to iOS users that may contain personally identifiable information.
The Facebook SDK (location USA) included in our App helps us to increase the success of Facebook advertising campaigns by, for example, avoiding the display of ads on devices on which this App is already installed. In addition, the Facebook SDK allows for various evaluations of the installation of the App and of the success of the advertising campaign. In addition, individual activities (events) of the user within the App can be analysed in order to better define the target group for advertising campaigns, for example. For this purpose, we send Facebook pseudonymous data, such as the time, model name of the device, IP address, name of the App, a unique Ad-ID created by Facebook, and the information that the App has been launched. The Advertising ID provided by the operating system of the terminal device serves as the pseudonym. The latter occurs regardless of whether the user uses Facebook or not. Facebook uses this information to create a profile for the Ad-ID along with other information and uses this profile for promotional purposes.
We work with ‘Sentry’ from Functional Software, Inc. (location USA) to detect and eliminate errors that occur in our backend. In the event of a crash or other unexpected errors, information such as the version of the operating system and some technical data about the cause of the error is sent to Sentry. However, this information does not contain any personal data. We merely use the data to increase the stability of our App.
Google Fabric (incl. Crashlytics and Answers) and Google Firebase (both: USA) help us to monitor the performance of our App, identify crashes and analyse user behavior. We use Google Firebase and its Firebase Cloud Messaging (FCM) service to send push notifications to Android and iOS users that may contain personally identifiable information. Google AdMob (location: USA) enables us to deliver relevant ads in our app and is powered by ads from Google Ads and other Third Party Ad Buyers on Google's Ad Exchange. More information on how Google manages data in its ads products.
When using our App, our ad networks and affiliates may use so-called device identifiers to create an anonymous profile of your click behavior for mobile advertising. In our App we work with various mobile advertising partners beyond Google Admob, including the following companies:
You can disable personalised advertising via the settings of your device:
On Android, this option can be found in the Google Preferences App. Depending on the device, this is called ‘Google Settings’ or only ‘Settings’. Under the menu item ‘Google’ > ‘Ads’ you will find the option ‘Deactivate Interest Based Advertising’ or ‘Deactivate Personalised Advertising’ depending on the device. The selection can be used to deactivate personalised advertising.
On iOS, this option is located in the "Settings" app. Under the menu item "Privacy" > "Tracking" you will find the option "Allow apps to request to track". Personalised advertising can be deactivated with the deactivated selection.
‘Behavioral advertising’ means the use of tracking measures to determine the potential interest of users in advertisements on our Website and in our App and to display them according to their interests. For this we use the following features: Gender, membership type, interest in membership, and number of logins. Members with a PLUS membership have the possibility to turn off advertising.
All servers of the Service are located in the European Economic Area (‘EEA’), so your data do not leave the EEA from a technical perspective, instead the technical provision and processing of the data for the operation of the Service takes place in the EEA.
However, when you submit information to us, it is legally collected by a data controller located in a country outside the EEA because we are based in Hong Kong (P.R. China). In addition, our development company is also based in China, from where it has technical access to the servers in the EEA in certain situations.
According to the GDPR, there are special requirements for transfers of data to so-called ‘Third Countries’ not guaranteeing an adequate level of data protection, without applicable adequacy decisions and without specific guarantees to compensate for this deficit. This means that, from a European perspective, personal data and data subjects enjoy less protection and rights there.
Where no adequate level of protection for personal data can be guaranteed in a specific country, this means that it is possible that government bodies such as criminal prosecution services and intelligence agencies might be able to access data under less strict requirements than within the territory of the EEA (including secret disclosures without any pre-notification to you). Further, it is likely that you will have no effective remedy to challenge such access to your personal data in or out of court. While you might find this acceptable, we strongly urge you to cautiously assess the level of protection you deem appropriate for the personal data we process when providing the Service to you.
If, as a data controller, we transfer data to a third country, we generally guarantee an adequate level of data protection. This applies regardless of whether it is a transfer to an affiliated company or to another recipient (such as an external service provider acting as a data processor). In these cases, we will ensure that the transfer is either based on approved standard contractual clauses (as well as the prerequisite additional safeguards required under the Articles 44 and following of the GDPR), that there is an adequacy decision for the respective country, or that other appropriate safeguards such as binding corporate rules have been provided to guarantee an adequate level of data protection.
However, please be reminded: When justifying the transfer of personal data to third countries we, first and foremost, rely on the informed explicit consent you have freely given to us when signing up for our Service (as per Article 49 (1) lit. a GDPR). Specifically, you consent to the transfer of the data mentioned in this Privacy Statement to the US, the UK as well as China. If you would like to suspend the third-country transfer of your personal data, you are free to not sign up for our Service or to close the account you have opened with us.
We process and store your personal data for as long as it is necessary for the fulfilment of our contractual or legal obligations. Thus, we store the data in principle only as long as our contractual relationship with you exists and also after termination only as far as the laws of the Federal Republic of Germany and the People's Republic of China require this. If the data are no longer necessary for the fulfilment of such obligations, they shall be deleted regularly and without delay, unless their further processing is necessary for the protection of legitimate interests or for the preservation of evidence within the framework of statutes of limitations. In this sense, in particular the storage of age and profile verification photos and videos is carried out expressly for the entire duration of the contract, since we hold this data in particular for the ongoing guarantee of the protection of minors and the prevention of fraud attempts.
The data collected under 2.a are stored for 90 days. This storage period serves our protection against attacks on the systems of our Service, e.g. by so-called Distributed Denial of Service attacks, in which the systems are deliberately overloaded by a large number of accesses to our Service in order to interrupt the provision of our Service.
You are not legally obliged to provide us with the above data. In principle, the contractual relationship that you have entered into with us by agreeing to our General Terms and Conditions does not result in any obligation to provide this personal data. However, the transmission of the compulsory data is a basic requirement for a conclusion of a contract with us. In addition, if you do not provide us with certain information or if you object to its use, you may not be able to use the Service, or only to a limited extent. This is because the Service essentially only becomes ‘alive’ through the content posted by the users.
You can assert the following rights:
Your right to information according to article 15 GDPR,
Your right to rectification according to article 16 GDPR,
Your right to erasure according to article 17 GDPR,
Your right to restriction of processing according to Article 18 GDPR as well as
Your right to data portability according to Article 20 GDPR.
If you have any questions in this regard, please contact customer service at [email protected].com.
You can revoke your consent to the processing of personal data at any time.
In addition, you have the right to lodge a complaint with the responsible data protection supervisory authority.
In addition to the rights already mentioned, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data relating to you on the basis of Art. 6 (1) lit. e GDPR (‘public interest grounds’) or of Art. 6 (1) lit. f GDPR (‘legitimate interests’). If you object, we will no longer process your personal data unless we can prove compelling reasons for processing worthy of protection which outweigh your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims.
You also have the right to object at any time to the processing of your personal data for the purpose of direct marketing. If you object, we will no longer process your personal data.
The objection can be made in each case form-free and should be addressed to [email protected] if possible.
Please note: We do not sell personal data. This means we will not transmit data to any third party except for the recipients mentioned in this Privacy Statement, for the stated purposes. The relevant recipients have agreed to contractual limitations as to their retention, use, and disclosure of personal data.
California law grants state residents certain rights, including the rights to access specific types of personal data, to learn how we process personal data, to request deletion of personal data, and not to be denied goods or services for exercising these rights. If you are a California resident under the age of 18 and have registered for an account with us, you may also ask us to remove content or information that you have posted to our Services. For information on how to exercise your rights under the CCPA, please refer to Section 10 above.
As a data controller under GDPR and a business regulated under CCPA, we ensure that your rights are respected in all jurisdictions. If you are an authorized agent wishing to exercise rights on behalf of a California resident, please contact our privacy team and provide us with a copy of the consumer’s written authorization designating you as their agent.
We may need to verify your identity and place of residence before completing your CCPA rights request.