Who we are.
Shapes101 has determined responsibilities for compliance with the obligations under applicable privacy legislation for processing your personal data. This policy describes how we collect, use and look after your personal data. It also describes the rights you have and control you can exercise in relation to your personal data.
This policy is addressed to individuals outside Shapes101 with whom we interact, including individual clients, representatives, directors, direct or indirect shareholders, beneficial owners and other stakeholders of client organisations, visitors to our website, other users of our services and suppliers.
The types of personal data we collect and process.
We may collect and process the following categories of personal information:
- Name, Surname and other identifying information
For example, we may collect your name, title, gender, country of residence and position, role to a company or organization.
- Your contact details
Your contact details may include your company or organization address, telephone number and email address.
- Financial Information
Billing address, payment method, bank account number, accountholder name, invoice records, payment records, SWIFT details, IBAN details, payment amount, payment date.
- Business Information
Data identifying you in relation to matters on which you instruct us or in which you are involved. Identification and background information provided by you or collected by us as part of our business acceptance processes, anti-money laundering and compliance obligations.
- Attendance Records
How we collect your data.
We collect the aforementioned categories of personal data in the following ways:
- We collect data you directly provide to us.
- We receive your personal data from your personal assistants or employees that you authorize to provide your personal data to us.
For which purposes we use your data.
The main purposes for which we use your personal information are:
- To communicate with you.
- To provide our services to you.
Disclosing or sharing your personal data with third parties.
- General: we may disclose or share your personal data with our correspondent lawyers worldwide including their lawyers and staff in order to provide legal advice and other services.
- To trusted third parties: we may share your personal information with certain trusted third parties which provide services to Shapes101, such as our professional advisers and accountants, suppliers and processors to whom we outsource certain support services, IT service providers, software providers, communication suppliers. We shall take measures to protect the confidentiality and security of the personal data in such circumstances.
- Third parties which provide professional services to your company or organization provided we are requested by you or your company or organization to do so.
Security and retention.
- Shapes101 will take appropriate technical and organizational measures to protect your personal data against loss or unlawful use.
- Personal data may be kept on our personal IT systems, those of our contractors or in paper files.
International transfer of your data.
- Shapes101 may transfer your personal data to countries other than your country of residence or company’s country (including countries outside the European Economic Area). This is often necessary to provide our services to you. The laws of these countries may not afford the same level of protection to your personal data.
- We may also be required to disclose your personal data to foreign companies or organisations or institutions to provide our services to you and if applicable law outside EEA requires disclosure.
You may contact our Office (please see below) to exercise any of the rights you are granted under applicable data protection laws, which includes (1) the right to access your data, (2) to rectify them, (3) to erase them, (4) to restrict the processing of your data, (5) the right to data portability and (6) the right to object to processing.
1. Right to access
You may ask us whether we process any of your personal data and, if so, receive access to that data in the form of a copy. When complying with an access request, we will also provide you with additional information, such as the purposes of the processing, the categories of personal data concerned as well as any other information necessary for you to exercise the essence of this right.
2. Right to rectification
You have the right to have your data rectified in case of inaccuracy or incompleteness. Upon request, we will correct inaccurate personal data about you and, taking into account the purposes of the processing, complete incomplete personal data, which may include the provision of a supplementary statement.
3. Right to erasure
You also have the right to have your personal data erased, which means the deletion of your data by us and, where possible, any other controller to whom your data has previously been transfered by us. Erasure of your personal data only finds place in certain cases, prescribed by law and listed under article 17 of the General Data Protection Regulation (GDPR). This includes situations where your personal data are no longer necessary in relation to the initial purposes for which they were processed as well as situations where they were processed unlawfully. Due to the way we maintain certain services, it may take some time before backup copies are erased.
4. Right to restriction of processing
You have the right to obtain the restriction of the processing of your personal data, which means that we suspend the processing of your data for a certain period of time. Circumstances which may give rise to this right include situations where the accuracy of your personal data was contested but some time is needed for us to verify their (in)accuracy. This right does not prevent us from continuing to store your personal data. We will inform you before the restriction is lifted.
5. Right to data portability
Your right to data portability entails that you may request us to provide you with your personal data in a structured, commonly used and machine-readable format and to have such data transmitted directly to another controller, where technically feasible. Upon request and where this is technically feasible we will transmit your personal data directly to the other controller.
6. Right to object
You also have the right to object to the processing of your personal data, which means you may request us to no longer process your personal data.
- You may withdraw your consent at any time.
- When you would like to exercise your rights, all you have to do is send your request to firstname.lastname@example.org with title “Data Privacy Manager” of Shapes101.
How we look after this policy.