1. APPLICATION
This subpage (“Subpage”) applies if you reside outside the United States and supplements our Privacy Policy. It contains important information we are required by the General Data Protection Regulation (“GDPR”) to disclose, including (i) the controller(s) of your personal information; (ii) legal bases, (iii) your legal rights, (iv) safeguards we rely on for transferring your personal information outside the EEA; and (v) the contact details of the controller and Data Protection Officer. This page also contains important information about the Payments Controller (defined below) and the information processed in connection with the Payments Services. Please read this page carefully. If you have any questions, you can contact us at the details below.
2. WHO CONTROLS MY PERSONAL INFORMATION
2.1 Controller
Where this Subpage mentions “ExploringNotBoring,” “we,” “us,” or “our,” it refers to the ExploringNotBoring company that is responsible for your information under this Privacy Policy (the “Controller”).
2.2 Payments Controller
The Privacy Policy also applies to the Payment Services provided to you by ExploringNotBoring pursuant to the Payments Terms of Service (“Payments Terms”).
2.3 Contact Us
To contact the Controller or the Data Protection Officer (DPO) for ExploringNotBoring, click here for contact details.
3. PROCESSING OF PAYMENTS INFORMATION
3.1 Information Necessary For Use of Payment Services
The Controller needs to collect the following information necessary for the adequate performance of the contract with you and to comply with applicable law (such as anti-money laundering regulations). Without it, you will not be able to use Payment Services:
- Payment Information. When you use the Payment Services, the Controller requires certain financial information (such as your bank account or credit card information.) in order to process payments and comply with applicable law.
- Identity Verification and Other Information. The Controller may require identity verification information (such as images of your government issued ID document(s), passport, national ID card, tax ID or driving license) or other authentication information (such as your date of birth, your address, email address, phone number) and other information in order to verify your identity, provide the Payment Services to you, and to comply with applicable law.
3.2 How the Payments Controller Uses Personal Information Collected
We may use the personal information as a part of Payment Services to:
- Enable or authorise third parties to use the Payment Services
- Detect and prevent money laundering, fraud, abuse, security incidents
- Conduct security investigations and risk assessments
- Comply with legal obligations (such as anti-money laundering regulations)
- Enforce the Payment Terms and other payment policies
- With your consent, send you promotional messages, marketing, advertising, and other information that may be of interest to you based on your preferences
- Provide and improve the Payment Services
4. LEGAL BASES FOR PROCESSING PERSONAL INFORMATION
We process personal information for the purposes described in the Privacy Policy in line with the lawful bases set out below. For more information on the processing activities, please refer to the relevant section of the Privacy Policy.
4.1 Processing of Payments Information (Section 3, this Subpage)
SUB-SECTION | LEGAL BASES |
How the Payments Controller uses the personal information collected | The Payments Controller processes this personal information given its legitimate interest in improving the Payment Services and its users’ experience with it, and where it is necessary for the adequate performance of the contract with you and to comply with applicable laws. |
4.2 How We Use Information We Collect (Section 3)
SUB-SECTION | LEGAL BASES |
Provide, improve, and develop ExploringNotBoring. | We process this personal information for these purposes given our legitimate interest in improving ExploringNotBoring and our users’ experience with it, and where it is necessary for the adequate performance of the contract with you. |
Create and maintain a trusted and safer environment. | We process this personal information for these purposes given our legitimate interest in protecting ExploringNotBoring and our users, to measure the adequate performance of our contract with you, to comply with applicable laws, for the protection of your or another person’s vital interests, and for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health. |
Provide, personalize, measure, and improve our advertising and marketing. | We will process this personal information with your consent or based on our legitimate interest in undertaking marketing activities to offer you products or services that may be of interest to you. |
How the Payments Controller uses the personal information collected | The Payments Controller processes this personal information given its legitimate interest in improving the Payment Services and its users’ experience with it, and where it is necessary for the adequate performance of the contract with you and to comply with applicable laws. |
4.3 Complying with Law, Responding to Legal Requests, Preventing Harm and Protecting our Rights (Section 4.5)
SUB-SECTION | LEGAL BASES |
Complying with Law, Responding to Legal Requests, Preventing Harm and Protecting our Rights. | These disclosures may be necessary to comply with our legal obligations, for the protection of a person’s vital interests, for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health, for reasons of substantial public interest, or for the purposes of ExploringNotBoring’s or a third party’s legitimate interest in keeping ExploringNotBoring secure, preventing a breach of the law, harm or crime, enforcing or defending legal rights, claims, or obligations, facilitating the collection of taxes and prevention of tax fraud or preventing loss or damage. |
4.4 Other important information (Section 5)
SUB-SECTION | LEGAL BASES |
Analyzing your communications. | These activities are carried out based on ExploringNotBoring’s legitimate interest in ensuring compliance with applicable laws and our Terms, preventing fraud, promoting safety, and improving and ensuring the adequate performance of our services. |
Linking third party accounts, Third Party Partners & Integrations | We process personal information from linked third party accounts, third party partners, and integrations to the extent necessary to ensure the adequate performance of our contract with you, or to ensure that we comply with applicable laws, or with your consent. |
5. YOUR RIGHTS
If ExploringNotBoring is the Payments Controller, or pursuant to applicable law, you benefit from a number of rights. While some of these rights apply generally, certain rights apply only in certain limited cases. Please note that we may ask you to verify your identity and request before taking further action on your request. See here for information on data subject rights requests and how to submit a request.
5.1 Data Access and Portability
You have the right to request certain copies of your personal information held by us. In certain instances, you also have the right to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
5.2 Rectification
You have the right to ask us to correct inaccurate or incomplete personal information about you (and which you cannot update yourself within your ExploringNotBoring account).
5.3 Erasure
We generally retain your personal information for as long as is necessary for the performance of the contract between you and us, to comply with our legal obligations, and as permitted by applicable law.
You have the right to ask us to delete your personal information, subject to certain limitations and restrictions. Please note that if you request the erasure of your personal information:
- We may retain your personal information as necessary for our legitimate business interests, such as prevention of money laundering, fraud detection and prevention and enhancing safety. For example, if we suspend an ExploringNotBoring account for fraud or safety reasons, we may retain information from that ExploringNotBoring account to prevent that Member from opening a new ExploringNotBoring account in the future.
- We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, ExploringNotBoring may keep your information for tax, legal reporting and auditing obligations.
- Information you have shared with others (e.g., Reviews, forum postings) will continue to be publicly visible on ExploringNotBoring, even after your ExploringNotBoring account is cancelled. However, attribution of such information to you will be removed.
- Some copies of your information (e.g., log records) will remain in our database, but are disassociated from personal identifiers.
- Because we maintain ExploringNotBoring to protect from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
5.4 Withdrawing Consent
If we are processing your personal information based on your consent you can withdraw your consent at any time by changing your account settings or by sending a communication to ExploringNotBoring specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal.
5.5 Restriction of Processing
You have the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information; (ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the personal information for the establishment, exercise or defense of legal claims; or (iv) you have objected to the processing pursuant to Section 5.6 (below) and pending the verification whether the legitimate grounds of ExploringNotBoring override your own.
5.6 Objection to Processing
You have the right to object to the processing of your personal information based on grounds specific to your situation if such processing is for direct marketing or is for a purpose based on a legitimate interest or public interest. If you object to processing based on legitimate or public interests we will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or where the processing is otherwise required for the establishment, exercise or defense of legal claims.
Where your personal information is processed for direct marketing purposes, you may, at any time ask ExploringNotBoring to cease processing your data for these direct marketing purposes by sending an e-mail to opt-out@exploringnotboring.com.
5.7 Lodging Complaints
You have the right to lodge complaints about our data processing activities by filing a complaint with our Data Protection Officer who can be reached by the “Contact Us” section above or with a supervisory authority, either your local supervisory authority or our lead supervisory authority, the US Federal Trade Commission (FTC).
6. RETENTION
We retain personal information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law. The criteria used to determine our retention periods include:
- the length of time we have an ongoing relationship with you and provide ExploringNotBoring to you (for example, for as long as you have an account with us or keep using ExploringNotBoring);
- whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); and/or
- whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).
7. OPERATING GLOBALLY & INTERNATIONAL TRANSFERS
To facilitate our global operations ExploringNotBoring may transfer, store, and process your information within our family of companies, partners, and service providers based in Europe, India, Asia Pacific and North and South America. Laws in these countries may differ from the laws applicable to your country of residence. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in these other countries may be entitled to access your personal information.
Some of these countries are subject to a European Commission adequacy decision. For other countries, measures have been taken pursuant to applicable data protection law, such as standard contractual clauses within ExploringNotBoring or with the relevant third party to protect this personal data.
7.1 Other Means to Ensure an Adequate Level of Data Protection
If ExploringNotBoring is the Controller and your information is shared with corporate affiliates or third party service providers outside the EEA, we have (prior to sharing your information with such corporate affiliate or third party service provider) established the necessary means to ensure an adequate level of data protection. This may be an adequacy decision of the European Commission confirming an adequate level of data protection in the respective non-EEA country or an agreement on the basis of the EU Model Clauses (a set of clauses issued by the European Commission). We will provide further information on the means to ensure an adequate level of data protection, such as a copy of the EU Model Clauses, on request.