Oxygen Website and App Privacy Notice
This Privacy Notice explains how we use the personal information that Oxygen collects or generates both in relation to the Oxygen Website (www.oxygen.org), the Oxygen App and Oxygen products and services.
The list below sets out what is covered in this Privacy Notice and you can click on the headings below to go to a specific section.
- The products and services we provide
- The types of personal data we collect
- How we use your information
- Disclosure of your information to third parties
- International transfers of personal data
- How we safeguard your information
- How long we keep your personal data
- Your rights
- Children’s privacy
- Designated representative
- Questions and concerns
1.1 Oxygen.org AG with its registered office at Baarerstrasse 75, 6300 Zug, Switzerland, and other companies in the Oxygen group (“Oxygen”, “we” “us” and “our”) collect and use certain Personal Data in relation to you. Oxygen is responsible for ensuring that it uses that Personal Data in compliance with data protection laws, including (but not limited to) the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and any other national, implementing or supplementing Data Protection Legislation including but not limited to the Data Protection Act 2018.
1.2 At Oxygen we respect the privacy of our Users and we are committed to keeping all your Personal Data secure. This Privacy Notice governs the handling of Personal Data by Oxygen in the course of carrying on commercial activities.
1.3 We use the following definitions in this Privacy Notice:
|Cookie||means a small text file that includes a small quantity of information sent to the browser of website Users, by a web server, and stored on the hard disk drive of a computer for purposes of archiving, collecting navigation data for statistical analysis purposes, and offering Users services related to their interests or location.|
|User(s) or you||means the users of the Oxygen Website and Oxygen App.|
|Oxygen Website and Oxygen App||means the platforms consisting of the Oxygen software as a service and the Oxygen website (www.oxygen.org) with restricted access.|
|Personal Data||means any data which relates to a living individual who can be identified from that data or from that data and other information which is in the possession of, or is likely to come into the possession of, Oxygen (or its representatives or service providers). In addition to factual information, it includes any expression of opinion about an individual and any indication of the intentions of Oxygen or any other person in respect of an individual.|
|Privacy Notice||means this Oxygen Website and App Privacy Notice.|
2. THE PRODUCTS AND SERVICES WE PROVIDE
2.1 This Privacy Notice concerns the following information that we collect about you when providing products and services as part of the Oxygen Website:
- information we receive through the Oxygen Website and the Oxygen App;
- information we receive through our products and services which we provide to you ("Oxygen Products"); and
- information we receive through our support, mobile security solution or cloud-based services ("Oxygen Services").
3. THE TYPES OF PERSONAL DATA WE COLLECT
3.1 Many of the services offered by Oxygen require us to obtain Personal Data about you in order to perform the services we have been engaged to provide. Users may be unable to access and use the Oxygen Website and the Oxygen App if such Personal Data are not provided. In relation to each of the services described at Section 2.1 above, we will collect and process the following Personal Data about you:
- Information that you provide to Oxygen. This includes information about you that you provide to us. The nature of the services you are requesting will determine the kind of Personal Data we might ask for, though such information may include (for example) any information that you choose to share on the Oxygen Website and / or Oxygen App which may be considered Personal Data and might include your preferences, feedback and any survey responses.
- Information that we collect or generate about you. This
includes (by way of non-exhaustive list):
- transaction data such as the amount, date, time, recipient for each transaction on the Oxygen Website or Oxygen App;
- any information regarding the services purchased and/or used on the Oxygen Website or Oxygen App and our interactions with you. This might include your trade history undertaken through Oxygen;
- a file with your contact history to be used for enquiry purposes so that we may ensure that you are satisfied with the services which we have provided to you;
- technical data including internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access the services;
- through our cloud security services, traffic and security reports that include information on the internet usage of the organisation’s computer users (e.g. what websites were visited by each User, any documents downloaded, security incidents, prevention measures taken by the gateway, etc.); and
- activity data relating to the publication of content, the creation of targets or the use of protected documents on the Oxygen Website or Oxygen App, such as altering a document’s permissions and information regarding the individual that performed the activity.
- Information we obtain from other sources. This includes the Personal Data provided to us by third-party service providers, agencies or other publicly available sources where applicable.
- When you visit the Oxygen Website, cookies are used to collect technical information about the services that you use, and how you use them.
- For more information on the cookies used by Oxygen please see Section 10 of this Privacy Notice.
- Anonymised data
- Special category Personal Data
- We do not collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, genetic and biometric data).
- Information about criminal convictions
- When you register for an Oxygen account or otherwise use our services, we may receive information about your criminal convictions when we perform certain verification or compliance checks. We carry out these checks in order to detect or prevent any unlawful or fraudulent acts and to comply with our legal obligations.
4. HOW WE USE YOUR INFORMATION
4.1 Your Personal Data may be stored and processed by us in the following ways and for the following purposes:
- for ongoing review and improvement of the information provided on the Oxygen Website and Oxygen App to ensure they are user friendly and to prevent any potential disruptions or cyber attacks;
- to allow you to use and access the functionality provided by the Oxygen Products;
- to conduct analysis required to detect malicious data and understand how this may affect you;
- for statistical monitoring and analysis of current attacks on devices and systems and for the on-going adaptation of the solutions provided to secure devices and systems against current attacks;
- to understand feedback on Oxygen Products and to help provide more information on the use of those products and services quickly and easily;
- to communicate with you in order to provide you with services or information about Oxygen and Oxygen Products;
- for in-depth threat analysis;
- to understand your needs and interests;
- for the management and administration of our business;
- in order to comply with and in order to assess compliance with applicable laws, rules and regulations, and internal policies and procedures; or
- for the administration and maintenance of databases storing Personal Data.
4.2 However, where we use Personal Data we make sure that the usage complies with law and the law allows us and requires us to use Personal Data for a variety of reasons. These include:
- we need to do so in order to perform its contractual obligations with our customers and third-party providers;
- we have obtained your consent;
- we have legal and regulatory obligations that we have to discharge;
- we may need to do so in order to establish, exercise or defend our legal rights or for the purpose of legal proceedings;
- the use of your Personal Data as described is necessary for our legitimate
business interests, such as:
- allowing us to effectively and efficiently manage and administer the operation of our business;
- maintaining compliance with internal policies and procedures;
- monitoring the use of our copyrighted materials;
- enabling quick and easy access to information on Oxygen Products;
- offering optimal, up-to-date security solutions for mobile devices and IT systems; and
- obtaining further knowledge of current threats to network security in order to update our security solutions and provide these to the market.
4.3 We will take steps to ensure that the Personal Data is accessed only by employees of Oxygen that have a need to do so for the purposes described in this Privacy Notice.
5. DISCLOSURE OF YOUR INFORMATION TO THIRD PARTIES
5.1 We may share your Personal Data within the Oxygen group of companies for the purposes described above. We will take steps to ensure that access to Personal Data is restricted to Oxygen employees who have a legitimate interest in the purposes described in this Privacy Notice.
5.2 We may also share your Personal Data outside of the Oxygen group for the following purposes:
- with our business partners. For example, this could include our partners
from whom you or your company or your organisation purchased the Oxygen
Product(s) or Services(s). For instance, we may share your Personal Data
- Business partners - From time to time Oxygen may partner with other companies to allow you to transact with individuals that are customers of such partners and not Oxygen. In order to complete these transactions, we will need to share information regarding your Oxygen account with the applicable partner so that they can meet their legal and regulatory obligations. Your information will only be shared with such partners to the extent you actually transact or interact with customers of such partner.
- with third party agents and contractors for the purposes of providing
services to us (for example, Oxygen’s accountants, professional advisors, IT
and communications providers and debt collectors). For example, we may share
your Personal Data with:
- Verification service providers - In order to detect and/or prevent fraud and comply with our legal obligations, we will sometimes need to share your information with third party identity verification services. This lets us make sure you are who you say you are, by comparing the information you provide us to public records and other third party databases. This may include searches through electronic services such as credit bureaus, but we will not do so in a manner that would have an adverse impact on your credit or credit score.
- Operational service providers - In order to deliver the services to you, we will need to share your information with third parties who provide us with certain tools/services including data storage, customer service platforms, accounting and invoicing, IT, email and other communication tools, security and fraud detection.
- Other service providers - In order to improve Oxygen’s functionality, we will sometimes share your information with service providers that help us analyse how people are using the services in order for us to refine the product. We may also share your information with services providers who help us to deliver certain advertising/marketing campaigns in order to grow our business.
- to the extent required by law, for example if we are under a duty to disclose your Personal Data in order to comply with any legal obligation (including, without limitation, in order to comply with tax reporting requirements and disclosures to regulators), or to establish, exercise or defend its legal rights;
- if we sell our business or assets, in which case we may need to disclose your Personal Data to the prospective buyer for due diligence purposes; and
- if we are acquired by a third party, in which case the Personal Data held by us about you will be disclosed to the third-party buyer.
6. INTERNATIONAL TRANSFERS OF PERSONAL DATA
6.1 Oxygen is a global business. Our users and our operations are spread around the world. As a result, we collect and transfer Personal Data on a global basis. That means that we may transfer your Personal Data to locations outside of your country.
6.2 Where we transfer your Personal Data from within the EEA, United Kingdom, or Switzerland to outside the EEA, United Kingdom, or Switzerland, we will ensure that it is protected and transferred in a manner consistent with legal requirements. This may be done in one of the following ways:
- the country that we send the data to might be approved by the European Commission as offering an adequate level of protection for Personal Data;
- the recipient might have signed up to a contract based on “model contractual clauses” approved by the European Commission, obliging them to protect your Personal Data;
- the recipient may have adhered to binding corporate rules (only for intragroup transfers); or
- in other circumstances the law may permit us to otherwise transfer your Personal Data outside the EEA, United Kingdom, or Switzerland .
6.3 You can obtain more details of the protection given to your Personal Data when it is transferred outside the EEA, United Kingdom, or Switzerland (including a copy of the standard data protection clauses which we have entered into with recipients of your Personal Data) by contacting us as described in Section 14 below.
7. HOW WE SAFEGUARD YOUR INFORMATION
7.1 We have extensive controls in place to maintain the security of our information and information systems. Client files are protected with safeguards according to the sensitivity of the relevant information. Appropriate controls (such as restricted access) are placed on our computer systems. Physical access to areas where Personal Data is gathered, processed or stored is limited to authorised employees.
7.2 As a condition of employment, Oxygen employees are required to follow all applicable laws and regulations, including in relation to data protection law. Access to sensitive Personal Data is limited to those employees who need to it to perform their roles. Unauthorised use or disclosure of confidential client information by an Oxygen employee is prohibited and may result in disciplinary measures.
7.3 When you contact an Oxygen employee about your file, you may be asked for some Personal Data. This type of safeguard is designed to ensure that only you, or someone authorised by you, has access to your file.
8. HOW LONG WE KEEP YOUR PERSONAL DATA
8.1 How long we will hold your Personal Data for will vary and will be determined by the following cumulative criteria:
- the purpose for which we are using it – Oxygen will need to keep your Personal Data for as long as is necessary for that purpose; and
- legal obligations – laws or regulation may set a minimum period for which Oxygen has to keep your Personal Data.
9. YOUR RIGHTS
9.1 In all the above cases in which we collect, use or store your Personal Data, you may have the following rights which you can exercise free of charge. These rights include:
- the right to obtain information regarding the processing of your Personal Data and access to the Personal Data which we hold about you;
- the right to withdraw your consent to the processing of your Personal Data at any time. Please note, however, that we may still be entitled to process your Personal Data if we have another legitimate reason for doing so. For example, we may need to retain Personal Data to comply with a legal obligation;
- in some circumstances, the right to receive some Personal Data in a structured, commonly used and machine-readable format and/or request that we transmit those data to a third party where this is technically feasible. Please note that this right only applies to Personal Data which you have provided directly to Oxygen;
- the right to request that we rectify your Personal Data if it is inaccurate or incomplete;
- the right to request that we erase your Personal Data in certain circumstances. Please note that there may be circumstances where you ask us to erase your Personal Data, but we are legally entitled to retain it;
- the right to object to, or request that we restrict, our processing of your Personal Data in certain circumstances. Again, there may be circumstances where you object to, or ask us to restrict, our processing of your Personal Data but we are legally entitled to refuse that request; and
- the right to lodge a complaint with the relevant data protection regulator if you think that any of your rights have been infringed by us.
9.2 You can exercise your rights by contacting us using the details listed in Section 14 below.
9.3 Further information about your rights may be obtained by contacting the supervisory data protection authority located in your jurisdiction.
10.1 To the extent that we collect Personal Data with the help of Cookies we will process them in accordance with this Privacy Notice.
10.2 Types of cookies and purposes
Cookies used on the Oxygen Website are used to record information necessary for the proper functioning of the Oxygen Website and the Products and Services offered to you, audience measurement, use monitoring and security.
Cookies are placed by Oxygen and, if applicable, its business partners, third party agents and contractors (without Oxygen being held responsible for the placement of Cookies by its partners, third party agents and contractors).
Each time a User is identified on the Oxygen Website, a Cookie is placed allowing to identify the computer or hardware used and the User navigating the Oxygen Website. This Cookie allows services to be provided seamlessly and therefore without re-identification. This Cookie is invalidated when the browser is closed or after a period of inactivity on the Oxygen Website.
11.1 We may use your contact details to inform you of products, services and offers may be relevant for you – we call this “marketing”.
11.2 We will only market to you with your consent (where required by law) and you will be able to withdraw that consent.
12. CHILDREN’S PRIVACY
12.1 Unfortunately, if you’re under 18, you can’t use the services. We do not knowingly solicit or collect information from anyone under 18. If we become aware that a person under the age of 18 has provided us with personal information, we’ll delete it immediately.
13. DESIGNATED REPRESENTATIVE
13.1 Oxygen’s registered office may be contacted using the following contact information:
|Address:||Baarerstrasse 75, 6300 Zug, Switzerland|
14. QUESTIONS AND CONCERNS
14.1 For further information regarding the processing of your Personal Data by Oxygen, this Privacy Notice, questions relating to consent, or in order to exercise the rights mentioned above, please contact our data protection officer using the following contact details:
|Address:||Baarerstrasse 75, 6300 Zug, Switzerland|
14.2 We are usually able to resolve privacy questions or concerns promptly and effectively. If you are not satisfied with the response you receive from our data protection officer, you may escalate concerns to the applicable privacy regulator in your jurisdiction. Upon request, Oxygen’s data protection officer will provide you with the contact information for that regulator.