Privacybeleid
Introduction
This privacy notice provides you with details of how we collect and process your personal data through your use of https://keycard.tech/, including any information you may provide through our site when you purchase the Keycard product.
By providing us with your personal data, you warrant that you are over 13 years of age or are at the minimum age of consent for us to process your personal data as applicable in your jurisdiction.
Status Research & Development Deutschland GmbH is the data controller and responsible for your personal data (referred to as “we”, “us”, “our”, or “Status” in this privacy notice).
Contact Details:
Status Research & Development Deutschland GmbH
Email: legal@status.im
Postal Address: ℅ Cormoran GmbH, Am Zirkus 2, 10117 Berlin, Germany
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the German supervisory authority for data protection. We would appreciate the chance to deal with your concerns before you approach the authority, so please contact us first.
It is very important that the information we hold about you is accurate and up to date. Please let us know if your personal information changes by emailing getkeycard@status.im.
What Personal Data Do We Collect About You?
Personal data means any information capable of identifying an individual. It does not include anonymised data.
We may process certain types of personal data about you as follows:
-
Identity Data: first name, last name, username, title
-
Contact Data: billing address, delivery address, email address, telephone numbers
-
Financial Data: bank account, VAT registration number, payment card details
-
Transaction Data: details about payments and purchases made by you
-
Technical Data: login data, IP addresses, browser type and version, browser plug-in types and versions, time zone setting and location, operating system and platform, and other technology on the devices you use to access this site
-
Profile Data: username and password, purchases or orders, interests, preferences, feedback, survey responses
-
Usage Data: information about how you use our website, products, and services
We may also process Aggregated Data from your personal data, but this data does not reveal your identity and as such is not personal data. If we link Aggregated Data with your personal data so that you can be identified, it is treated as personal data.
How We Collect Your Personal Data
We collect data about you through a variety of different methods, including:
-
Direct Interactions: You may provide us personal data by filling in forms on our site (or otherwise), such as when you order the Keycard product or create an account.
-
Automated Technologies or Interactions: As you use our site, we may automatically collect Technical Data about your equipment, browsing actions, and usage patterns. We collect this data by using cookies, server logs, and similar technologies. Please see our cookie policy for further details.
How We Use Your Personal Data
We will only use your personal data when legally permitted. The most common uses are:
-
Where we need to perform our obligations under the Terms of Service
-
Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
-
Where we need to comply with a legal or regulatory obligation
Generally, we do not rely on consent as a legal ground for processing your personal data.
Purposes for Processing Your Personal Data
Below is a description of the ways we intend to use your personal data and the legal grounds on which we process such data. We may process your personal data for more than one lawful ground, depending on the specific purpose.
|
Purpose/Activity |
Type of Data |
Lawful Basis for Processing |
|
To register you as a new customer |
Identity, Contact |
Performance of a contract with you |
|
To process and deliver your order (including managing payments, fees, charges, collecting and recovering money owed to us) |
Identity, Contact, Financial, Transaction |
Performance of a contract with you; Necessary for our legitimate interests (to recover debts owed to us) |
|
To manage our relationship with you (including notifying you about changes to our terms or privacy policy) |
Identity, Contact, Profile |
Performance of a contract with you; Necessary to comply with a legal obligation; Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
|
To administer and protect our business and our site (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and housing of data) |
Identity, Contact, Technical |
Necessary for our legitimate interests (for running our business, IT administration, network security, fraud prevention, business reorganisation or group restructuring); Necessary to comply with a legal obligation |
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal ground for processing.
We may process your personal data without your knowledge or consent where this is required or permitted by law.
Disclosures of Your Personal Data
We may have to share your personal data with the following parties for the purposes set out above:
-
Service providers who provide IT and system administration services
-
Professional advisers (lawyers, accountants, consultants)
-
Regulators and other authorities based in Germany and relevant jurisdictions who require reporting of processing activities in certain circumstances
-
Third parties to whom we may sell, transfer, or merge parts of our business or assets
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
BixGrow (Affiliate Programme)
We note that Keycard offers an affiliate programme to reward participants who refer visitors to this Website. The affiliate programme is managed and operated by a separate entity:
Controller: Status Research & Development GmbH, with address: c/o PST Consulting GmbH Baarerstrasse 10, 6300 Zug Switzerland.
Status Research & Development GmbH is the data controller for the personal data collected and processing activities related to the affiliate programme, including the use of affiliate-tracking cookies. To enable referral tracking and commission attribution, BixGrow affiliate-tracking cookies are set in your browser when you visit this website via an affiliate link. For more information about these cookies, please see the Cookies section below.
X (Twitter) (Advertising)
Keycard uses advertising & measurement technology in the store and makes use of a tracking pixel from X. When this pixel is enabled, X collects and receives certain information at our instruction. For more information about these cookies, please see the Cookies section below.
International Transfers
Countries outside of the European Economic Area (EEA) do not always offer the same levels of protection to your personal data, so European law has prohibited transfers of personal data outside of the EEA unless the transfer meets certain criteria.
It is not intended that Status will export your personal data from the website outside the EEA. However, if personal data is exported by Status outside the EEA, it will only be processed in countries or by parties that provide an adequate level of protection as determined by the European Commission. Transmission of personal data outside the EEA will always occur in conformity with privacy legislation.
If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time. Please email us at legal@status.im if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Data Security
Status takes data security seriously and we have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know such data. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, and applicable legal requirements.
By law, we have to keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for six years after they cease being customers for tax purposes.
In some circumstances, you can ask us to delete your data (see below for further information). In some cases, we may anonymise your personal data for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:
-
Ask us to correct or update your personal data (where possible)
-
Ask us to remove your personal data from our systems
-
Ask us for a copy of your personal data, which may also be transferred to another data controller at your request
-
Withdraw your consent to process your personal data (only if consent was asked for a processing activity)
-
Object to the processing of your personal data
-
Ask that we restrict the processing of your personal data
If you wish to exercise any of these rights, please email us at legal@status.im.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Third-Party Links
This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, you will be bound by the privacy notice of those third parties.
Cookies
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see the information below.
What Are Cookies?
A cookie is a file that is downloaded to your computer when you access certain web pages. Cookies allow a website to store and retrieve information about the browsing habits of a user or their device and, depending on the information they contain and how they use their device, can be used to recognize the user. The user’s browser retains cookies on the hard disk only during the current session, occupying minimal memory space and not harming the computer. Cookies do not contain any specific personal information, and most are deleted at the end of the browser session (session cookies). Most browsers accept cookies as standard and, regardless of the cookies, allow or prevent temporary or retained cookies in the security settings. Without your express consent (by activating cookies in your browser), Status will not link in the cookies the data stored with your personal data provided at the time of registration or purchase.
What Cookies We Use on This Website
-
Technical Cookies: Allow navigation through the website and use of different options or services, such as controlling traffic, identifying sessions, accessing restricted parts, remembering order elements, processing purchases, using security features, storing content for videos or sound, or sharing content through social networks.
-
Personalization Cookies: Allow access to the service with predefined characteristics, such as language, browser type, or regional settings.
-
Analysis Cookies: Allow us (or third parties) to quantify users and analyze the use of the offered service, helping us improve our products or services.
-
Advertising Cookies: Allow us (or third parties) to manage advertising spaces effectively, adapting ad content to the requested service or user’s browsing profile.
In addition to the above, we note the use of cookies utilised for the affiliate programme as follows:
BixGrow (Affiliate Programme)
As mentioned above, Keycard offers an affiliate programme that is administered and facilitated by Status Research & Development GmbH.
Purpose and legal basis: These cookies are used exclusively for tracking referrals and attributing commissions to affiliates, based on the legitimate interests of Status Research & Development GmbH in performance-based marketing (Art. 6(1)(f) GDPR). Where required by law, affiliate-tracking cookies are only set with your consent, which is obtained via our cookie banner.
International transfers: BixGrow may process cookie data on Amazon Web Services (AWS) servers located in the European Union (Dublin) or the United States. International data transfers are protected by Standard Contractual Clauses and AWS’s EU-US Data Privacy Framework certification.
Opt-out: You can refuse or withdraw consent for BixGrow cookies at any time via our cookie banner.
BixGrow Cookies Used
|
Cookie Name |
Provider |
Purpose |
Lifespan |
Category |
|
bgaffiliate_id |
BixGrow |
Stores the referring affiliate’s ID for commission tracking |
30 days (merchant-configurable, max 10 years) |
Marketing / Affiliate |
|
bgclick_id |
BixGrow |
Records unique click-event ID for affiliate attribution |
30 days (merchant-configurable, max 10 years) |
Marketing / Affiliate |
|
bgexpire_time |
BixGrow |
Unix timestamp indicating cookie expiry |
30 days (merchant-configurable, max 10 years) |
Marketing / Affiliate |
|
bglast_click |
BixGrow |
Unix timestamp of most recent affiliate click |
30 days (merchant-configurable, max 10 years) |
Marketing / Affiliate |
|
bgvisitor_id |
BixGrow |
Anonymized visitor ID for de-duplicating repeat visits |
30 days (merchant-configurable, max 10 years) |
Marketing / Affiliate |
X (Twitter) (Advertising)
As mentioned above, Keycard uses the X (Twitter) pixel to measure advertising performance and to show ads that are more relevant to you. When enabled, it sends device and event data to X and may send hashed identifiers (e.g. email/phone) for matching. X processes this data collected via its pixel and in accordance with our instructions. Where required by law, we only activate this pixel after you consent to Marketing cookies. You can manage your choices any time via our cookie settings and also control ad personalisation directly with X or via industry tools (DAA/NAI).
X (Twitter) Cookies Used
|
Cookie Name |
Provider |
Purpose |
Lifespan |
Category |
|
personalization_id |
X (Twitter) |
Ad targeting & content personalization |
2 years |
Marketing / Advertising |
|
guest_id / guest_id_ads |
X (Twitter) |
Distinguish browsers for ads & analytics |
2 years |
Marketing / Advertising |
|
mus_ads |
X (Twitter) |
Advertising / fraud-prevention |
2 years |
Marketing / Advertising |
|
_twitter_sess |
X (Twitter) |
Login / pixel session management |
Session |
Marketing / Advertising |
|
ct0 |
X (Twitter) |
CSRF token for requests |
6 hours |
Marketing / Advertising |
|
external_referer |
X (Twitter) |
Ad-click attribution |
3 minutes |
Marketing / Advertising |
How We Authorise and Consent the Use of Cookies
By using this website, you expressly accept the processing of information collected in the manner and for the purposes mentioned above. You may refuse the processing of such data or information by refusing the use of cookies via your browser settings. Blocking cookies may not allow full use of all website functionality.
How You Can Deactivate or Disable the Use of Cookies
You can allow, block, or delete cookies installed on your computer by configuring your browser options. Here are instructions for common browsers:
-
Internet Explorer: Tools → Internet Options → Privacy → Settings
-
Firefox: Tools → Options → Privacy → History → Custom Settings
-
Chrome: Settings → Show advanced options → Privacy → Content settings
-
Safari: Preferences → Security
Contact Us
If you have questions about this Privacy Policy, you can contact Status at legal@status.im.