Privacy Policy


Last updated: February 19, 2023


This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

The Platform (as defined below) is owned and operated by MyBubble Ltd, a company registered in England and Wales under company number 13470206. MyBubble Ltd is a data controller and responsible for your Personal Data.

Our data protection officer is Qasim Armstrong who can be contacted at info@mybubbleapp.co.uk. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact our data protection officer.

This policy has been updated to reflect the changes introduced by the Data Protection Act 2018 (“DPA”) and the General Data Protection Regulation (the “GDPR”) and any other relevant privacy legislation.

We respect your privacy and are committed to protecting your Personal Data. This privacy policy will inform you as to how we look after your Personal Data and sets out the basis on which any Personal Data we collect from you, or that you provide to us, will be processed by us. The policy also applies when you correspond with us in person, by letter, by phone, email or any other means. Please read the following carefully to understand our views and practices regarding your Personal Data and how we will treat it.

In this privacy policy we seek to abide by the letter and spirit of the guidelines laid out by

the ICO on their webpage on the ‘Right to be Informed’.


Interpretation and Definitions


Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:


Account means a unique account created for You to access our Service or parts of our Service.

Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.

Application means the software program provided by the Company downloaded by You on any electronic device, named MyBubble

Business, for the purpose of the CCPA (California Consumer Privacy Act), refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information, that does business in the State of California.

Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to MyBubble Ltd, The Bristol Office, 2nd Floor, 5 High Street, Westbury on Trym, Bristol, England, BS9 3BY - company registration number 13470206.

For the purpose of the GDPR, the Company is the Data Controller.

Consumer, for the purpose of the CCPA (California Consumer Privacy Act), means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose.

Country refers to: United Kingdom

Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.

Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.

Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.

Personal Data is any information that relates to an identified or identifiable individual.

For the purposes for GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.

For the purposes of the CCPA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.

Sale, for the purpose of the CCPA (California Consumer Privacy Act), means selling, renting, releasing, disclosing, disseminating, making available, transferring, or

otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information to another business or a third party for monetary or other valuable consideration.

Service refers to the Application.

Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Under GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.

Collecting and Using Your Personal Data


Types of Data Collected


Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

Email address

First name and last name Gender or Pronoun

Contact mobile numbers that you provide to invite other users into Your MyBubble support network or for account creation

Profile Data

Profile Data including your username and password will be collected in order to set up Your accounts for access to the MyBubble Application and services.

Usage Data

Usage Data is collected automatically when using the Service.


Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time

and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.

Health Data

The MyBubble Application is not a medical device or application. However, any information You input that could be considered General Health Data will be securely stored. This information may include entries, notes or integrations that You add as part of Your mood and health tracking, and also MyBubble ‘support plans’. This information will be stored by MyBubble Ltd so you can access it when using the Application’s services. You have the ability at all times to delete, amend or update your information through Your account in the Application. In addition, all of Your account data can be deleted via the Settings page within the Application.

This information will not be shared with third-parties or sold without Your prior, informed consent. This information will only be shared with third-parties for the purpose of enabling You to share Your health data or progress from the Application with Your medical professional or practitioner.

Location Data

The MyBubble Application may collect location data. This enables the Application to be able to provide language or currency information that is relevant to You. However, You have the Right at any time to opt-out of location data collection. You can do this by disabling Location Services on Your mobile device.

How We Will Collect Your Data

We use different methods to collect data from and about you including through:


Direct interactions. You may give us any of the categories of data identified above by filling in forms in our Application or by corresponding with us in person or by phone, e-mail or otherwise. This includes Personal Data you provide when you:

We use this information to provide features of Our Service, to improve and customize Our Service. The information may be uploaded to the Company's servers and/or a Service Provider's server or it may be simply stored on Your device.

You can enable or disable access to this information at any time, through Your Device settings. You also have the Right to Request all data that has been stored pertaining to You as well as delete, update or amend this data at all times via Your account within the Application.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:


To provide and maintain our Service, including to monitor the usage of our Service.

To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.

For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.

To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.

To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.

To manage Your requests: To attend and manage Your requests to Us.

For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.

For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.

We may share Your personal information in the following situations:



Security of Your Personal Data

The security of Your Personal Data is important to Us therefore, we have put in place security measures to prevent Your Personal Data from being used or accessed in an unauthorized way, altered or disclosed.

Anti-virus software and applications are kept up-to-date and security best practice protections have been implemented to prevent unauthorized access to our servers or devices, such as segregated environments and stringent access controls. In addition, access to servers where Personal Data is stored is only given to approved employees, agents or third parties who have a business requirement to do so. This access utilizes up-to-date security best practices to maintain the integrity and confidentiality of this access. Any data

processing will be in accordance with this Privacy Policy and is subject to a duty of confidentiality.

User data is stored separately from all other data types securely within a Virtual Private Cloud environment. Administrative access to servers or services within this environment is not possible directly from the internet. In addition, best practice procedures for authentication and authorization, including the principle of least privilege, Virtual Private Network encrypted tunnels and multi-factor authentication, are used to access the servers within the environment.

User data is encrypted between your device and this environment to ensure that it cannot be intercepted and subsequently read in plaintext.

However, no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.

We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. However, if You suspect that there has been a breach of data confidentiality then you have the right to complain to Your Local Supervisory Authority or to the Information

Commissioner’s Office.


Detailed Information on the Processing of Your Personal Data


The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.

Analytics

We may use third-party Service providers to monitor and analyze the use of our Service.


Google Analytics

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.

You may opt-out of certain Google Analytics features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Firebase

Firebase is an analytics service provided by Google Inc.

You may opt-out of certain Firebase features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy

We also encourage you to review the Google's policy for safeguarding your data: https://support.google.com/analytics/answer/6004245

For more information on what type of information Firebase collects, please visit the How Google uses data when you use our partners' sites or apps webpage: https://policies.google.com/technologies/partner-sites


Amplitude

Amplitude is an analytics service provided by Amplitude, Inc. This aggregates usage data of Our services for the purpose of analytics and insights into the popularity of certain features or functions within Our Application.

You may opt-out of certain Amplitude features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Amplitude in their Privacy Policy: https://amplitude.com/privacy

We also encourage you to review Amplitude’s terms of service:

https://amplitude.com/terms

Amplitude’s data processing addendum can also be found at: https://www.amplitude.com/terms/dpa

Payments

We may provide paid products and/or services within the Service. In that case, we may use third-party services for payment processing (e.g. payment processors).

We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processors whose use of Your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

Apple Store In-App Payments

Their Privacy Policy can be viewed at https://www.apple.com/legal/privacy/en-ww/

Google Play In-App Payments

Their Privacy Policy can be viewed at https://www.google.com/policies/privacy/


Behavioral Remarketing

The Company uses remarketing services to advertise to You after You accessed or visited our Service. We and Our third-party vendors use cookies and non-cookie technologies to help Us recognize Your Device and understand how You use our Service so that We can

improve our Service to reflect Your interests and serve You advertisements that are likely to be of more interest to You.

These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies and to enable Us to: