End User Privacy Notice
The Business in these Terms means Poki Maki by Mr. 7 ("Business").
Continued on next page
End User Privacy Notice
This Privacy Notice explains the types of information the Business collects when you use its
Services and how it processes, transfers, stores, and discloses the information collected, as well
as your ability to control certain uses of the collected information. If not otherwise defined herein,
capitalized terms have the meaning given to them in the Terms of Service, available
at https://legal.comosense.com/business-end-user-terms-of-service ("Terms"). "You" means any
user of the Services.
If you are an individual located in the European Union ("EU Individual"), some additional terms
and rights may apply to you, as detailed herein. The Business is the data controller in respect of
the processing activities outlined in this Privacy Notice.
Privacy Notice Key Points
The key points listed below are presented in further detail throughout this Privacy Notice. You
can click on the headers in this section in order to find out more information about any topic.
These key points do not substitute the full Privacy Notice.
1. Personal Data the Business Collects and How it is Used
2. Additional
3. Legal Basis (GDPR only)
4. Sharing the Personal Data
5. Security
6. International Transfer
7. Your Rights Under GDPR
8. Your Rights as a California Resident
9. Data Retention
10. Third-Party Applications and Services
11. Communications
12. Children
13. Changes to the Privacy Notice
14. Comments and Questions
***
1. Personal Data the Business Collects and How it is Used
1.1. Registration Information. When you submit a registration form or otherwise provide
information in order to register to the Business's loyalty or customer engagement
program, the Business will collect certain Personal Data about you, such as your name,
phone number, email address, and home address. Some fields may be mandatory, while
others may be optional. If you specifically opt-in to permit access and collection of
information from your social network account(s), then your basic Personal Data in your
social network account will be collected (such as your name, photo and email address)
as well as your social network user ID (but not your password). Please refer to the social
network's privacy policy for more details on how you can set the privacy preferences of
your account to control the information that may be accessed and retrieved. The
Business collects this information for the purpose of enabling your registration to the
Services and providing you with the Service's functionalities, features and services
(including, without limitation, personalized content) and to send you push notifications,
SMS text messages, commercial emails and/or other communications.
1.2. Personal Data Collected Automatically through the App. If you use the App offered as
part of the Services, the Business automatically collects the following information about
your mobile device: your mobile device identifier and/or account identifier (Android
UDID, iOS UUID; Advertising ID: IDFA for iOS devices and AAID for Android devices, or
their equivalent), the Internet protocol (IP) address of the device used to access the
Internet, device type and its operating system version. The Business collects this
information in order to enable you to use the Services and App and in order to analyze
your usage of the Services to improve its offerings.
1.3. Usage Information. The Business also collects information regarding the features,
content, services or websites accessed, clicked or interacted with through the App as
well as information regarding the interactions made with the Service's interface and
features such as logging info, tabs, banners, or pages that are clicked on or accessed, ads
and/or promotions viewed through the Services and receipt of notifications sent through
the Services. The Business uses this information in order to understand how participants
use its Services in order to improve them and develop new products and services.
1.4. Communication and Participation Information. If you are a member of the Business's
customer loyalty program, the Business collects information regarding (i) receipt of SMS
text messages or emails sent to you through the Services; (ii) your participation in, or use
of the loyalty features available to you (such as: scratch card, point accumulation plans,
punch card, coupons, gift card, cash back, "Pay with Budget" or their equivalents); and
(iii) details of purchases made online or offline by using the Services (e.g., time and date
of your purchase, place where purchase was made, the amount paid, information about
the items purchased and payment method information, including to allow automatic
identification). The Business collects this information in order to enable you to use the
Services and in order to analyze your usage of the Services to improve its offerings and
allow seamless identification and usage.
1.5. Location Information. Subject to your consent, the Business may collect your geo-
location information in order to provide you with location-based offerings and
promotions. Subject to your consent, location may be collected through various
methods, including beacons, which is a technology that use Bluetooth low energy signals
in order to measure your proximity to a physical beacon. In some cases, the Business
may place beacons in or nearby its premises in order to collect your approximate
location. Additionally, if you use the Services at the Business's premises, the Business
will have information about your physical location.
2. Additional Uses.
2.1. Aggregate and Anonymous Information. Through the Services, the Business may collect
aggregated and anonymous information, which cannot identify you. The Business may
aggregate this information with information about other individuals and may use this
information without restriction, including for statistical and analytical purposes.
2.2. Direct Marketing. As described above, the Business may use Personal Data to let you
know about products and Services that it believes will be of interest to you. It may
contact you by email, post, text, or telephone or through other communication channels.
In all cases, the Business will respect your preferences for how you would like it to
manage marketing activity with respect to you. To protect privacy rights and to ensure
you have control over how the Business manages marketing with you:
2.2.1. The Business will take steps to limit direct marketing to a reasonable and
proportionate level and only send you communications which it believes may be of
interest or relevance to you.
2.2.2. You may ask us to stop sending email marketing by following the "unsubscribe" link
you will find on all the email marketing messages or follow the unsubscribe
instructions for other messages. Alternatively, you can contact the Business directly.
2.2.3. No Share of SMS opt-in. The Business will not sell your SMS opt-in to third parties,
nor will it share it with third parties to allow such third parties or affiliates to use it
for their own marketing purposes.
3. Legal Basis (GDPR only). If you are an EU Individual, please note the following legal bases
under the GDPR on which the Business relies for collection and processing of your Personal
Data:
3.1. When the Business uses the Personal Data collected in order to provide you with the
Services or manage the administrative and operational aspects of the Services, it does so
based on performance of a contract with you, namely the Terms you have entered with
the Business.
3.2. When the Business uses the Personal Data collected to review usage and operations,
including in an aggregated non-specific analytical manner, develop new products or
services and improve current offerings, products, and Services, it does so based on its
legitimate interest.
3.3. When the Businesses uses your geo-location, it does so based on your consent.
3.4. If the Business uses the Personal Data collected in order to enforce the Terms and this
Privacy or to prevent unlawful activities and misuse of the Services, it does so based on
its legitimate interest or for compliance with applicable laws.
3.5. If the Business uses the Personal Data collected in order to comply with applicable law
or assist law enforcement agencies, which it will do when it has a good faith belief that
its cooperation with them meets the applicable legal standards, it does so for the
purpose of compliance with laws.
4. Sharing the Personal Data. The Business shares your information, including Personal Data, as
follows:
4.1. Affiliates. The Business may share information, including your Personal Data, with its
affiliated companies, where this is necessary to provide you with Products and Services,
and for the purpose of management of its business.
4.2. Service Providers, and Subcontractors. The Business discloses information, including
Personal Data it collects from and/or about you, to its trusted service providers and
subcontractors and who use such information solely on its behalf in order to: (1) help it
provide you with the Services; (2) aid in its understanding of how users are using its
Services; (3) for the purpose of direct marketing (see above for more details).
Such service providers and subcontractors provide the Business with IT and system
administration services, hosting, data backup, security, and storage services, data
analysis, assist with online ordering, ecommerce services, games, payments,
communications, plugins or APIs, help the Business serve advertisements and provide
other marketing services.
4.3. Business Transfers. Your Personal Data may be disclosed as part of, or during
negotiations of any merger, sale of company assets or acquisition (including in cases of
liquidation). In such case, your Personal Data shall continue being subject to the
provisions of this Privacy Notice .
4.4. Law Enforcement Related Disclosure. The Business may share your Personal Data with
third parties: (i) if it believes in good faith that disclosure is appropriate to protect its or
a third party's rights, property or safety (including the enforcement of the Terms and this
Privacy Notice); (ii) when required by law, regulation subpoena, court order or other law
enforcement related issues, agencies and/or authorities; or (iii) as is necessary to comply
with any legal and/or regulatory obligation.
4.5. Legal Uses. The Business may use your Personal Data as required or permitted by any
applicable law, for example, to comply with audit and other legal requirements.
4.6. Advertisers. When you click on an ad, the relevant advertiser will be alerted that
someone has visited the page on which the relevant advertisement was displayed and
may be able to identify that it was you by using certain mechanisms, like cookies.
4.7. Other Uses or Transfer of Your Personal Data. If you use the Services with or through a
third-party service, site and/or mobile application, we may receive information
(including Personal Data) about you from those third parties. Please note that when you
use third parties outside of our Services, their own terms and privacy policies will govern
your use of those services.
5. Security. The Business make efforts to follow generally accepted industry standards to protect
the Personal Data it collects, both during transmission and once it is received. However, no
method of transmission over the Internet or method of electronic storage is 100% secure.
Therefore, while the Business strive to use commercially acceptable means to protect your
Personal Data, its absolute security is not guaranteed. As the security of information depends
in part on the security of the computer you use to communicate with the Business and the
security you use to protect user IDs and passwords, please take appropriate measures to
protect this information.
6. International Transfer. The Business may use subcontractors and service providers who are
located in countries other than your own and send them information it receives (including
Personal Data). The Business conducts such international transfers for the purposes described
above.
7. Your Rights Under GDPR. Depending on which laws apply, you have certain legal rights over
your data. Below is some general information about rights that may apply to you. It is
recommended that you check the law or consult with a lawyer to understand what applies in
your specific case. To exercise your rights, please contact the Business. The Business may ask
for reasonable evidence to verify your identity before it can comply with any request.
7.1. Right of Access. You may have a right to know what Personal Data the Business collects
about you. The Business may charge you with a fee to provide you with this information,
if permitted by law. If the Business is unable to provide you with all the information you
request, it will do its best to explain why. See Article 15 of the GDPR for more details, if
your Personal Data is subject to GDPR.
7.2. Right to Correct Personal Data. You may have the request that the Business update,
complete, correct or delete inaccurate, incomplete, or outdated Personal Data. See
Article 16 of the GDPR for more details, if your Personal Data is subject to GDPR.
7.3. Deletion of Personal Data ("Right to Be Forgotten"). If you are an EU Individual, you may
have the right to request that the Business delete your Personal Data. Note that the
Business cannot restore information once it has been deleted. Even after you ask the
Business to delete your Personal Data, it may be allowed to keep certain data for specific
purposes under applicable law. See Article 17 of the GDPR for more details, if your
Personal Data is subject to GDPR.
7.4. Right to Restrict Processing. If you are an EU Individual, you may have the right to ask
the Business to stop processing your Personal Data. See Article 18 of the GDPR for more
details, if your Personal Data is subject to GDPR.
7.5. Right to Data Portability. If you are an EU Individual, you may have the right to request
that the Business provide you with a copy of the Personal Data you provided to it in a
structured, commonly used, and machine-readable format. See Article 20 of the GDPR
for more details, if your Personal Data is subject to GDPR.
7.6. Right to Object. If you are an EU Individual, you may have the right object to certain
processing activities. See Article 21 of the GDPR for more details, if your Personal Data
is subject to GDPR.
7.7. Withdrawal of Consent. If the Business's activities are processing your data based on
your consent, you are always free to withdraw your consent, however, this won't affect
processing the Business have done from before you withdrew your consent.
7.8. Right to Lodge a Complaint with Your Local Data Protection Authority. If you are an EU
Individual, you have the right to submit a complaint to the relevant data protection
authority if you have any concerns about how the Business are processing your Personal
Data, though the Business asks that as a courtesy you please attempt to resolve any
issues with it first.
8. Your Rights as a California Resident. If you are a resident of the State of California, depending
on the applicability of certain laws and exemptions, you may have certain rights over your
data. Below is some general information about rights that may apply to you. It is
recommended that you check the law or consult with a lawyer to understand what applies in
your specific case. To exercise your rights, please contact the Business. The Business may ask
for reasonable evidence to verify your identity or to verify that you have been authorized to
act on behalf of the relevant individual. You may only request to exercise your right of access
twice within a 12-month period.
8.1. Right to Know. You may the right to request that the Business discloses to you any or all
of the following, subject to applicable law:
8.1.1. The categories of Personal Data it has collected about you.
8.1.2. The categories of sources from which it has collected the Personal Data about
you.
8.1.3. Its business or commercial purpose(s) for collecting, selling, or sharing your
Personal Data.
8.1.4. The specific pieces Personal Data it has collected about you.
8.1.5. The categories of third parties to whom it discloses Personal Data about you.
8.1.6. The categories of Personal Data about you it has sold or shared and the
categories of third parties to whom it has sold or with whom it has shared such
Personal Data, by category or categories of Personal Data for each category of
third parties to whom the Personal Data was sold or shared.
8.1.7. The categories of Personal Data about you it has disclosed for a business
purpose and the categories of third parties to whom it has disclosed such
Personal Data.
8.2. Right to Delete. Subject to certain exceptions, you have the right to request that the
Business and any of its service providers delete your Personal Data.
8.3. Right to Correct. You have the right to request that the Business corrects any inaccurate
Personal Data it maintains about you, considering the nature of the Personal Data and
the purposes of the processing of the Personal Data.
8.4. Right to Opt-Out of the Sale or Sharing of Personal Data. If you are 16 years of age or
older or have consented to the sale of your Personal Data, you have the right to direct
that the Business not to sell or share your Personal Data at any time. You may change
your mind and opt back into the sale of your Personal Data at any time by contacting the
Business. The Business may deny any request to opt-out of the sale of Personal Data that
its deem in its good-faith, reasonable and documented belief is fraudulent.
8.5. Right to Limit Use and Disclosure of Sensitive Personal Data. You have the right to direct
us to limit the Business's use of your sensitive Personal Data, to that use which is
necessary to perform the services or provide the goods reasonably expected by an
average consumer who requests those goods or services and as otherwise permitted by
applicable law.
8.6. Right to Non-Discrimination for Exercising your Consumer Privacy Rights. You have the
right not to be discriminated against for exercising any of your consumer privacy rights,
such as, not being denied any goods or services or charged different prices or rates.
9. Data Retention
9.1. Please contact the Business if you would like details regarding the retention periods for
different types of your Personal Data. Note that the Business may delete information
from its systems without notice to you once the Business deem it is no longer necessary
for the purposes described above. Retention by any of its processors may vary in
accordance with the processor's retention policy.
9.2. In some circumstances, the Business may store your Personal Data where it is required
to do so in accordance with legal, regulatory, tax, audit, accounting requirements and so
that the Business has an accurate record of your dealings with it in the event of any
complaints or challenges, or if the Business reasonably believes there is a prospect of
litigation relating to your Personal Data or dealings.
9.3. Please note that deletion of the App from your device does not cause deletion or
anonymization of the information you voluntarily provided or information that the
Business collected in accordance with this Privacy Notice. You should contact us if you
would like your data to be deleted.
10. Third-Party Applications and Services. All use of third-party applications or services is at your
own risk and subject to such third party's terms and privacy policies.
11. Communications. The Business reserves the right to send you service-related
communications, including service announcements and administrative messages, without
offering you the opportunity to opt out of receiving them. Should you not wish to receive such
communications, you may terminate the Services.
12. Children. The Business does not knowingly collect Personal Data from children under the age
of sixteen (16). In the event that you become aware that an individual under the age of sixteen
(16) has enrolled in the Services without parental permission, please advise the Business
immediately.
13. Changes to the Privacy Notice. The Business may update this Privacy Notice from time to time
to keep it up to date with legal requirements and the way the Business operates its business,
and the Business will place any updates on this webpage. Please come back to this page every
now and then to make sure you are familiar with the latest version. If the Business makes
material changes to this Privacy Notice, it will seek to inform you by notice on its website,
App, or via email.
14. Comments and Questions. If you have any comments or questions about this Privacy Notice
or if you wish to exercise any of your legal rights as set out herein, please contact the Business.
Last update: January 2024