1. In General
1.1 Tapkey’s collection, administration and use of personal data complies with applicable data protection law by ensuring that each user is able to decide for themselves which personal information is viewable by other users.
1.2 The controller of the processing is Tapkey GmbH, Brucknerstraße 2/6, A-1040 Vienna, Austria. The data controller can be reached at firstname.lastname@example.org.
2. Categories of the personal data processed by Tapkey / Purposes of the processing
2.1 Tapkey collects personal data when a user registers on the Site and in connection with the use of Tapkey applications, including the web shop. The personally identifiable information Tapkey collects falls into the following categories:
- First and last name;
- Residential or other mailing address, including street and city name;
- Email address;
- Date of birth;
- Payment information, including but not limited to credit card information (credit card number, expiration date, CVV and portal), billing address (“Payment Information”);
- Tapkey hardware identification number;
- Access events and other events at Tapkey locking products (e.g., which user opened or closed which Tapkey locking product and when);
- Log data and error reports from apps and other Tapkey products;
- Owner data: Which user is the owner of which Tapkey locking products or which locking system (also “owner accounts”);
- Role management: which user is allowed to manage a locking system;
- Authorization data and corresponding relationships between users: which user is allowed to open or close which Tapkey locking products;
- Mobile devices: Which user logs in from which mobile device (incl. unique IDs for the respective devices); and
- NFC transponders: which user uses which NFC transponders.
- Online Store Purchases: Information about orders a user has placed through Tapkey’s online store.
- Website requests: information provided by a customer for a specific request or offer (information about the planned locking system).
- Support Requests: information in the context of support requests that a User has submitted via the support infrastructure provided by Tapkey.
2.2 Tapkey stores and uses personal data in order to
- enable the user to use the Tapkey website services in a secure, efficient and personalized manner
- enable the user to use Tapkey products in a secure, efficient and personalized manner
- respond to support and other communication requests
- develop new applications, improve existing ones, and customize them to meet users’ needs.
- perform reach measurement and similar analyses of our web traffic, provided that you consent to the use of your personal data for this purpose.
2.3 The legal basis of the processing when (i) using our website, (ii) communicating with you and (iii) further developing our applications are our legitimate interests, Art. 6 (1) lit. f GDPR. Our legitimate interests are (i) to ensure the stability and security of the website, (ii) to speed up and make efficient our communication with you, and (iii) to continuously improve the usability, security and efficiency of our products.
2.4 The legal basis of the processing when using Tapkey products is the performance of the contract that we or one of our partners have concluded with you for the use of our systems, Art. 6 (1) lit. b GDPR.
2.5 The legal basis for processing in the case of reach measurement is your consent to data processing, Art. 6 (1) lit. a GDPR. You can revoke your consent at any time without this affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
3. Use and disclosure of personal information to third parties
3.1 Tapkey does not disclose personal information to third parties unless required to do so by law or in response to one of the exceptions enumerated in this section. Tapkey takes all reasonable and necessary measures to ensure that unauthorized third parties cannot access stored data.
We may share your information with the following third parties:
3.2 The operation of our website requires the use of the service provider Shopify. We therefore share various usage data with the company Shopify Inc, 151 O’Connor Street, Ground floor, Ottawa, ON, K2P 2L8, Canada.
3.3 External Identity Providers. The registration and use of the User’s Tapkey IDs is carried out by a partner of Tapkey located outside the European Union, currently the USA. Furthermore, Tapkey uses methods for “delegation of authentication”, currently these are Google-ID and Apple-ID. The Tapkey platform uses the software modules Auth0 (more information at https://auth0.com/terms/ and https://auth0.com/privacy/) and Firebase for its login. For this purpose, the user’s email address and password are transmitted to Auth0 and Firebase, respectively.
3.4 Hosting. Tapkey currently uses the Windows Azure Cloud program (EU Data Space) for storing directly or indirectly personal data of the User. More information about Azure Cloud can be found at https://azure.microsoft.com/en-us/support/legal/.
3.5 Payment Information. In order to make payments in the Online Shop or via In-App Payments, the User must enter payment information. Payments are made in addition to Payments via Apple In-App Purchases via Recurly, Inc. a partner of Tapkey located outside the European Union, currently the USA. For the purposes of payment processing, Tapkey transmits payment information to Recurly. Various common payment options are offered for purchases in Tapkey’s online store (including Google Pay, Apple Pay, EPS, bank transfer, credit card; of which some transaction are consolidated via Shopify Payments).
3.6 To the extent that your personal data is transferred to Canada, we would like to point out that there is an adequacy decision of the European Commission for this country, according to which there is a level of data protection in this country equivalent to the EU.
4.1 Several areas of the Tapkey Platform use “cookies”, which are small text files that are stored on the computer, smartphone and/or browser. These are used by Tapkey to provide a more user-friendly, effective and secure service. Cookies also allow Tapkey to identify the browser used and to provide certain offers to the user. Cookies do not contain any information that can be individualized.
4.2 The User has the possibility at any time to refuse the setting of cookies, by selecting the appropriate option in the browser settings. However, it should be noted that disabling cookies may reduce the scope of the Services or negatively affect the use of the Services on the Tapkey Platform.
5. Google Analytics
5.1 The Tapkey Platform uses Google Analytics, a network analysis service provided by Google Inc (“Google”). Google Analytics uses “cookies” (see point 4, above). The information regarding the visit of a website or app, including the IP address, is collected by the cookie and usually transmitted to a Google server in the USA and stored there. If a website has IP anonymization enabled, Google first shortens IP addresses from member states of the European Union and EEA states. The full IP address is then, only as an exception, transmitted to the Google server in the USA and only shortened there. Google uses the information collected on behalf of the website provider to analyze the use of the Tapkey platform, to compile reports on website activity and to provide additional services to Tapkey regarding the Tapkey platform and the use of the internet. Under no circumstances will Google link the IP address transmitted by the browser as part of Google Analytics with other Google data.
5.2 When accessing the Website, the User can prevent Google’s recording and processing of information regarding the use of the Tapkey Platform, including the IP address, by downloading and installing the following browser plugin: https://tools.google.com/dlpage/gaoptout?hl=en/.
6. Google Ads
Tapkey uses the Google Ads Conversion tool to advertise Tapkey’s product offerings on websites operated by third parties. Based on these tools, we can measure the success of individual advertising campaigns. This allows us to take your interests into account when displaying advertising offers and to optimize our online presence for your customer experience. Advertisements are served by Google via their ad server infrastructure. For this purpose, ad server cookies are used to measure the effectiveness of displayed ads (display and user interaction). When you click on an ad, Google Ads stores a cookie on your terminal device. These cookies are not intended to be used for personal identification and expire after a certain period of time (usually 30 days). A cookie can store several pieces of information, such as the last time the ad was displayed, the number of impressions and a unique cookie ID as well as any opt-out settings (made by the user). We do not receive any personal profile data from Google (we cannot identify you personally) but only statistical information that is intended to continuously improve our advertising campaigns.
7. LinkedIn Insight
We use the conversion tool “LinkedIn Insight Tag” of the company LinkedIn Ireland on our website. By using it, a cookie is created in your web browser, which enables the collection of the following data, among others: IP address, device details and browser info, as well as page events (e.g. number of page views). The collected data is encrypted and anonymized within seven days. LinkedIn does not share any personal information with us, but only enables reports on website target groups and display performance in anonymous form. Based on this cookie, targeted advertising can be displayed outside of Tapkey websites without personal identification of the website visitor. More information about data protection on the LinkedIn platform can be found in the LinkedIn Privacy Terms.
8. Facebook Pixel
Tapkey uses the Facebook Pixel tool. A cookie is stored on your device by Facebook Pixel for this purpose. Data collected via Facebook Pixel is processed by Facebook and is not directly accessible to Tapkey. The use of Facebook Pixel allows us to play ads on the Facebook platform based on your browsing behavior and to measure and continuously optimize the success of ad placements for statistical purposes. You can individually configure the display of advertisements on the Facebook platform with the corresponding settings provided.
9.1 Tapkey uses Zendesk, a product of Zendesk Inc, 410 Townsend St, San Francisco CA, 94107, USA (“Zendesk”), for processing support and customer requests as well as the help center (https://support.tapkey.com and https://tapkeyb2b.zendesk.com).
9.2 The data required for this purpose is transferred to a Zendesk server and stored there. The following personal data is collected and transmitted: Name, e-mail address and telephone number.
10.1 Tapkey uses CleverReach, a product of CleverReach GmbH & Co. KG, Schafjueckenweg 2, 26180 Rastede, Germany (“CleverReach”) to send newsletters and analyze the behavior of newsletter recipients, such as their open and click-through rates. Further information on data analysis by CleverReach newsletters is available at: https://www.cleverreach.com/en/features/reporting-tracking/.
10.2 In order to sign up for the Tapkey newsletter, a User must enter and confirm his/her email address (double opt-in). This data is forwarded to CleverReach and stored on its server.
10.3 The user can revoke the consent at any time by unsubscribing from the newsletter. For this purpose, we provide a corresponding link in each newsletter message. The user data will be deleted from the CleverReach servers. However, the legality of the data processing operations that have already taken place remains unaffected by the revocation. Further information on the data protection provisions of CleverReach can be found at https://www.cleverreach.com/en/privacy-policy/.
12. Rights of the Data Subject
To exercise your rights below, please contact us using the contact details provided. According to the General Data Protection Regulation, you have the right to:
- Access regarding your data stored by us and its processing (Art. 15 GDPR),
- Rectification of incorrect personal data (Art. 16 GDPR),
- Erasure of your data stored by us (Art. 17 GDPR),
- Restriction of data processing if we are not yet allowed to delete your data due to legal obligations or if a more detailed examination must take place beforehand (Art. 18 GDPR),
- object to the processing of your data according to Art. 21 GDPR and
- Data portability, provided that you have consented to the data processing or have concluded a contract with us (Art. 20 GDPR).
In the event of violations of the GDPR, you also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the suspected violation. The right of appeal is without prejudice to other administrative or judicial remedies.
13. Obligations regarding the provision of personal data
The provision of the personal data is neither contractually nor legally required. However, failure to provide the (correct) data may result in the use of Tapkey products and our website being impaired.
14. Retention Period
Your personal data will only be stored by us for as long as is necessary to fulfill the purposes named above in respect to the respective data.