Privacy Policy

Effective as of 4th of May 2022

Introduction

This Privacy Policy uses the same terminology and abbreviations as defined in our Terms and Conditions document. This Privacy Policy governs the collection, use and storage of information about Users collected using the Services.

The information on Users is divided into personally identifiable and non-personally identifiable information depending on whether information can identify the User as a specific person. Personally identifiable information shall be referred to as “personal data”.

Brom doo with its registered headquarters at Koste Sokice 1, 21000 Novi Sad, Serbia is responsible for compliance with the principles relating to processing of personal data. You can contact us for any question regarding your privacy through our email address privacy@mcdeck.com.

In addition to the definitions provided for in the Terms, the following words and abbreviations shall have the meaning provided herein:

• “personal data” means any information relating to an identified or identifiable natural person (‘User’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

• “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

• “processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of McDeck.

• “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Personal data that we process

During your interaction with the Services or with us directly we may process the following personal data:

• First and last name
• E-mail address
• IP address
• Payment information
• Other information you choose to provide

We may collect personal data when you interact with the Site, when you purchase or use the Services or when you contact us.

Purposes for processing of personal data

We process your personal data for the following purposes:

• to provide you with an access to our Services and our Site,
• to provide you with the Services you requested,
• to provide you with the customer support,
• to send you information about the Services,
• to send you marketing emails,
• to comply with our legal obligations.

Legal basis for data processing

Depending on the type of personal data and the purpose for which it is processed, we process the personal data on the following legal basis:

• You have given us the consent for data processing for the specific purpose,
• Processing is necessary for the performance of our obligations under the Agreement
• Processing is necessary for compliance with legal obligations,
• Processing is necessary for the purpose of our legitimate interest.

We may process your email address to send you information about changes to the Services, introduction of the new Services or general news about our Services. We have a legitimate interest in keeping you informed about the Services you purchased and to promote our new Services which we believe you might be interested in. You can unsubscribe from these emails at any time by following the unsubscribe link in the email. We will not use legitimate interest to send you advertising emails for any Third-Party services. If you have provided us your consent for the receipt of the marketing emails, we will rely on that consent instead of our legitimate interest.

We may process you IP address automatically when you access the Site. We have a legitimate interest in ensuring the safety and integrity of our Site, and by collecting your IP address we can scan IP address and ban IP addresses that show malicious signs such as too many password failures, seeking exploits and similar. We will not use your IP address under our legitimate interest for any other purpose. If we need your IP address for other purpose, we will rely on other legal grounds or explain the new legitimate interest prior to commencing the processing.

General provisions

Some Services will not be available to you if you do not provide requested personal data, for example, if you do not provide your name and email you cannot purchase the Services. Different Services may require additional information which will be request at the time of requesting the specific Service.

We may keep records of any questions, complaints or compliments made by you and the response if any. Whenever you contact us, we shall collect any information which you chose to provide. We shall store and use this information only for the purpose of responding to your inquiries. Information contained within the inquiry, free from any personally identifiable information, will be stored on our servers for the purpose of improving our Services and providing the best customer support possible.

We do not sell or rent personal information to any Third-Party. We use collected information for our internal and marketing purposes, as necessary by the nature of the Services, and only in accordance with this Privacy Policy. In some instances, we are obliged to comply with court orders and government requests and provide information or parts of it to authorized bodies.

We have implemented security procedures and measures to ensure appropriate protection of the personal data we process, against any misuse, unauthorized access, disclosure, or modification.

We acknowledge that the safety of your personal data is one of the highest priorities and therefore only authorized processors have access to your information. Although we take all appropriate measures in respect to keeping your personal data secure, you understand that no data security measures in the world can offer 100% protection. If we ever find or suspect a personal data breach we will without delay, within seventy-two (72) hours after becoming aware of it, notify the appropriate supervisory authority about the breach and Users where necessary.

Children privacy

The services are intended for a general audience and are not targeted at children. We take children’s online safety very seriously, and if we ever learn that the personal data collected belongs to a child, we will immediately remove any such personal data. If you are younger than 18 you are not allowed to purchase or use the Services.

Collection and Use of Non-Personally Identifiable Information

The Site collects a series of general data and information when a User or automated system calls up the Site. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time of access to the internet site, (6) the internet service provider of the accessing system, and (7) any other similar data and information that may be used in the event of attacks on our information technology systems.

We collect this information for breach investigation purposes. When using this information, we do not draw any conclusions about the User. Rather, this information is needed to (1) deliver the content of our Site correctly, (2) optimize the content of our Site as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. The anonymous data of the server log files are stored separately from all personal data provided by a User.

Storage and transfer of personal data

Personal data will be stored on secure servers controlled and maintained in accordance with sufficient privacy safeguards. We may store or transfer information on Users to processors located outside of European Union, provided that such processors implement appropriate and suitable safeguards regarding the security of personal information.

We may keep your personal data for up to 10 years after your purchase of the Services in our backup in order to maintain the integrity of our backup storage data as well as in order to address any appeals or requests pursuant to your purchases and to comply with statutory tax obligations. Duration of storage is determined by the usual statue of limitation for the claims pertaining to the tax filings and returns. If you want us to delete your personal data prior to the expiry of the storage limitation you will need to release us from any liability that may arise from our provision of Services, in which case we will no longer have a legitimate interest in holding your personal data.

All payments on the Site are conducted through third party service provider PayPal Inc. You hereby understand that by making purchase through our Site your personal information is being processed and handled in accordance with respective Third-Party’s policies. PayPal’s privacy policy is available here:
https://www.paypal.com/en/webapps/mpp/ua/privacy-full

User’s Rights

We will process all personal data in line with Users’ rights, in particular their right, in certain circumstances, to:

• Request access to any data held about them by McDeck in a commonly used and machine-readable format.

• Transmit their personal data to another data controller (free of charge), where such personal data is processed on the basis of consent or contractual performance, unless in doing so, it would adversely affect the rights or freedoms of other Users or others e.g. including trade secrets or intellectual property.

• Prevent the processing of their personal data or withdraw their consent at any time in certain circumstances.

• Ask to have inaccurate personal data amended.

• Erasure of their personal data where data is no longer required for the original purpose or where the User has withdrawn their consent and no other lawful processing grounds apply.

• Object to the processing of their personal data in certain circumstances.

• Be notified where their personal data is subject to automated decision making i.e. profiling, including the logic involved, as well as the significance and the envisaged consequence of such processing for the data subject and object to such profiling in certain circumstances.


You may exercise these rights by contacting us through our email privacy@mcdeck.com.

Where we are required to provide a copy of personal data this will be free of charge, however, any further copies requested may be subject to reasonable fee based on administration costs.

Where we stop processing personal data or delete User’s personal data, it will possibly mean that that particular User is unable to continue using or contributing to the provision of some of our Services, and they shall be notified accordingly.

Where a User requests to rectify or erase (except data required by any legal obligations) their personal data or restrict any processing of such personal data, we may be required to notify, certain Third-Parties to whom such personal data has been disclosed of such request.

Users may without prejudice to any other administrative or judicial remedy, lodge a complaint with supervisory authority, in particular in the EU member country of their habitual residence or place of the alleged infringement if the User considers that the processing of personal data relating to them infringes the GDPR.

Changes to the Privacy Policy

We reserve the right to change our Privacy Policy at any time. The current version of Privacy Policy is available on the Site. You are encouraged to periodically check our Privacy Policy.