Privacy Policy

www.spotumedia.com

Type of website: Digital Marketing Agency
Effective date: 06/04/2024

www.spotumedia.com (the "Site") is owned and operated by Szymon Balcer.
Szymon Balcer is the data controller and can be contacted at: szymon@spotumedia.com

Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:

1. The personal data we will collect;
2. Use of collected data;
3. Who has access to the data collected;
4. The rights of Site users; and
5. The Site's cookie policy.

This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR
For users in the European Union. We adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.

Consent
By using our Site users agree that they consent to:
1. The conditions set out in this Privacy Policy.

When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.

You can withdraw your consent by: Contact Us: If you do not have an account or prefer not to use the account settings, you can also withdraw your consent by contacting us directly. Please reach out to szymon@spotumedia.com. Provide us with your name, contact information, and a clear statement that you wish to withdraw your consent for specific or all types of data processing.

Using the Opt-Out Links: For specific types of data processing, such as marketing communications, you can withdraw your consent by clicking the "unsubscribe" link found at the bottom of our emails. For web cookies and tracking technologies, you can manage your preferences through our [Cookie Settings] page or your browser settings to block or remove cookies.

Legal Basis for Processing

We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.
   
We rely on the following legal bases to collect and process the personal data of users in the EU:
1. Users have provided their consent to the processing of their data for one or more specific purposes;
2. Processing of user personal data is necessary for us or a third party to pursue a legitimate interest. Our
legitimate interest is not overridden by the interests or fundamental rights and freedoms of users. Our legitimate interests) are:
- To effectively manage and communicate with our clients and potential clients regarding our services and their inquiries. This includes using personal data to provide personalised service offerings and maintain an efficient client relationship management system.
- To inform current and prospective clients about our services and promotional offers that could benefit them. Direct marketing efforts are essential for our business growth and allow us to tailor our communication based on the interests and preferences of our audience, enhancing the relevance and effectiveness of our outreach.
- To analyse client interactions and feedback to continuously improve our services. This enables us to better meet our clients' needs, improve user experience, and develop new features or services that are closely aligned with what our clients value.
- To implement and maintain robust security measures to protect the personal data we process from unauthorised access, alteration, or destruction. This is crucial not only for complying with legal obligations regarding data protection but also for maintaining the trust of our clients and safeguarding their privacy.;
3. Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party.

If a user chooses not to provide their personal data, it may limit our ability to:
- Enter into a Contract: Without the necessary personal data, we may be unable to create an agreement or
contract for services with the individual, as we cannot fulfil our service commitments without processing this
data.
- Provide Personalised Services: Our ability to tailor our services to meet specific needs or preferences may
be compromised, potentially affecting the overall service quality and effectiveness of our marketing efforts.
- Communicate Effectively: Lacking essential contact information may hinder our ability to offer timely support,
updates, and critical information regarding our services or changes to our policies.
- Process Transactions: We may be unable to process payments or fulfil other transactional aspects of our
service delivery without relevant personal data.

We understand the importance of personal data privacy and ensure that all personal information is processed in compliance with applicable data protection laws and regulations. Our processing activities are conducted with the utmost respect for the privacy and security of our clients' personal data, and we implement robust measures to protect this data throughout our engagement.;

Processing of user personal data is necessary for us to comply with a legal obligation. If a user does not provide the personal data necessary for us to perform a legal obligation the consequences are as follows: In certain circumstances, we are legally required to collect and process specific personal data from our users. This may include, but is not limited to, compliance with tax laws, anti-money laundering regulations, and other statutory requirements relevant to our business operations. Processing this data is not only crucial for us to meet our legal obligations but also ensures the integrity and security of our services.

If a user chooses not to provide their personal data that is required for legal reasons, the following consequences may occur:

Inability to Provide Services: We may be unable to offer our services, as we cannot fulfil our contractual and legal obligations without processing the necessary personal data.

Compliance Issues: Failure to provide required data may result in non-compliance with legal obligations, which could have legal consequences for both the user and our agency, such as fines or other penalties.

Transaction Limitations: We may be unable to process transactions, including payments for our services, which are essential for executing contracts and maintaining our business operations.

We are committed to processing all personal data in accordance with applicable data protection laws and regulations, ensuring the highest standards of privacy and security. Our processing of personal data for legal reasons is conducted transparently, and we provide clear information to our users about the specific legal basis for processing, including any obligations to provide certain types of data.

We understand the importance of personal data and respect our users' rights and freedoms. We encourage users to contact us directly if they have concerns or questions about the necessity of providing personal data for legal or contractual purposes.;
1. Processing of user personal data is necessary to protect the life of the user or another natural person; and
2. Processing of user personal data is necessary to a task carried out in the public interest or in the exercise of
our official authority.

Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the datalis listed below without notifying you first.

Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:
1. IP address;
2. Location;
3. Hardware and software details;
4. Clicked links; and. Content viewed.
5. Data Collected in a Non-Automatic Way.
6. We may also collect the following data when you perform certain functions on our Site:
- First and last name; - Email address;
- Phone number; and - Auto fill data.

This data may be collected using the following methods:
1. Contact Form.

How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site.

We will not use your data beyond what we disclose in this Privacy Policy.
 
The data we collect automatically is used for the following purposes:
1. Optimising Website Performance;
2. Improving User Experience;
3. Analytics and Performance Monitoring;. Personalised Recommendations; and. Website Security and Fraud
Prevention.
4. The data we collect when the user performs certain functions may be used for the following purposes:
5. Communication; and
6. Direct Marketing.

Who We Share Personal Data With
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties
We may share user data with the following third parties:
1. Go High Level CRM.

We may share the following user data with third parties:
1. Personal Details.

We may share user data with third parties for the following purposes:
1. Streamline Lead Management;
2. Enhance Customer Experience; and
3. Optimise Our Services.

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:
1. If the law requires it;
2. If it is required for any legal proceeding;
3. To prove or protect our legal rights; and
4. To buyers or potential buyers of this company in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved. You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data
At SpotUmedia, the security of our users' personal data is of utmost importance. We employ a comprehensive approach to data protection that integrates advanced security measures provided by our platform providers with our own stringent data security practices. Here's how we ensure the safety of your data:
     
Through Our Platform Providers:
Webflow: Our website is built on Webflow, which utilises Amazon Web Services (AWS) for hosting, benefiting from AWS's extensive network and application security measures. Webflow provides automatic SSL encryption for all websites, ensuring that data transmitted between the user and the website is secure. Regular platform updates and patches are applied to maintain high security and address vulnerabilities.

GoDaddy: Our domain is registered through GoDaddy, which offers domain privacy and protection features to prevent unauthorised domain transfers and hide domain registration details from the public WHOIS database. GoDaddy also provides options for SSL certificates, further encrypting data transmitted to and from our website.

Our Internal Security Practices:
Data Encryption: We implement strong encryption for data in transit and at rest, safeguarding personal information against interception and unauthorised access.

Access Control: Access to personal data is strictly limited to authorised personnel who have a legitimate business need to handle such information. We enforce robust authentication and access management procedures to ensure data integrity and confidentiality.

Secure Infrastructure: We regularly review and update our web infrastructure for vulnerabilities and ensure that our website and data storage solutions are hosted on secure servers, protected by the latest firewall and intrusion prevention technologies.

Data Minimization and Retention: We adhere to the principles of data minimization and retention, ensuring that we collect only the information necessary for our business purposes and retain it only for as long as needed.

Incident Response: We have established an incident response plan to quickly address any potential data breaches or security incidents, minimising impact and taking appropriate measures to protect affected users.

Partnerships and Third-Party Security:
We carefully select third-party service providers and ensure they adhere to high data protection and security standards. Our collaboration with Webflow and GoDaddy is a testament to our commitment to leveraging secure, reliable platforms for our business operations.

We are dedicated to continuously improving our security measures and practices to protect against new threats and ensure the highest level of data protection for our users.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

International Data Transfers
We transfer user personal data to the following countries:
1. USA.

When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.

If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:
1. The country your personal data is being transferred to has been deemed to have adequate data protection
by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations.
2. We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.

Your Rights as a User
Under the GDPR, you have the following rights:
1. Right to be informed;
2. Right of access;.
3. Right to rectification.
4. Right to erasure.
5. Right to restrict processing;
6. Right to data portability; and.
7. Right to object.

Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.

How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here:
Szymon Balcer
szymon@spotumedia.com

Do Not Track Notice
Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We respond to browser-initiated DNT signals. If we receive a DNT signal that indicates a user does not wish to be tracked, we will not track that user. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.

How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:
1. Behavioral Advertising and Tracking: Users can opt-out of the collection and use of information for ad targeting, a practice also known as behavioural advertising. This includes opting out of cookies and tracking technologies that monitor online activities across websites to deliver personalised advertising.
Third-Party Data Sharing for Marketing: If personal data is shared with third parties for marketing purposes other than essential service provision (like lead management with Go High Level), users have the right to opt-out of such sharing.

Marketing Communications: Users can choose not to receive marketing emails or other communications from us by opting out. Users can opt-out by adjusting their browser settings to refuse cookies or to alert them when cookies are being sent. Tools and detailed instructions for managing cookies can typically be found in the browser's help file or through such services as the Network Advertising Initiative or the Digital Advertising Alliance in the USA, Your Online Choices in the EU, etc. To directly opt-out of our use of tracking technologies for advertising purposes, users can use the opt-out links provided in our Cookie Policy or directly on the marketing communication itself (e.g., an unsubscribe link in emails).

For Third-Party Data Sharing:
Users wishing to opt-out of their data being shared with third parties for marketing purposes can contact us directly at szymon@spotumedia.com, specifying their opt-out preferences.

For Marketing Communications:
Users can opt-out of receiving marketing emails by clicking the "unsubscribe" link at the bottom of our emails. For other types of marketing communications, detailed opt-out instructions are provided within the communication itself or users can contact us directly.

Assistance with Opting Out:
If users have any difficulties or questions about how to exercise their opt-out rights, they are encouraged to contact us for assistance at szymon@spotumedia.com.

Cookie Policy.
A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.
We use the following types of cookies on our Site:

1. Functional cookies
Functional cookies are used to remember the selections you make on our Site so that your selections are
saved for your next visits;
2. Analytical cookies
Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you
access our Site, for example data on the content you access, how long you stay on our Site, etc;
3. Targeting cookies
Targeting cookies collect data on how you use the Site and your preferences. This allows us to personalise
the information you see on our Site for you; and
4. Third-Party Cookies
Third-party cookies are created by a website other than ours. We may use third-party cookies to achieve the following purposes:
- Analytics: Tracking website usage and visitor behaviour.;
- Advertising: Delivering targeted ads based on browsing history.;
- Social Media Integration: Enabling sharing and liking content directly on social media platforms.;
- Content Personalization: Customising website content to user preferences.; and.
- Performance Optimization: Improving website functionality and speed.

Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.
       
Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Data Protection Commission.

Contact Information
If you have any questions, concerns or complaints, you can contact our privacy officer, Szymon Balcer, at:
szymon@spotumedia.com

©2023-2024 spotUmedia®
Full Name *