USLY App Privacy Policy
1. GENERAL INFORMATION
This Privacy Policy sets out the rules for the processing of personal data of users of the USLY mobile application (hereinafter: “the App”).
USLY ensures procedures for the protection of Users’ personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 and in accordance with the implemented Privacy Policy.
The data controller is PUGUA Sp. z o.o., with its registered office at Byszewska 37R, 92-770 Łódź, Tax Identification Number (NIP): 7282900556, National Business Registry Number (KRS): 0001175035 (hereinafter: “the Controller”).
To obtain information or assistance regarding personal data, the User may contact us at: kontakt@uslyapp.pl.
Definitions
Controller – the entity that owns and operates the Application and determines the purposes and means of processing Users’ personal data.
Application – the USLY mobile application, enabling Users to make contacts, meet new people and participate in social interactions.
Personal Data – any information relating to an identified or identifiable natural person.
Account – a User’s individual profile created within the App.
Location – geographical data regarding the location of the User’s Device, obtained with the User’s consent.
Personal data breach – any incident leading to the accidental or unlawful destruction, loss, alteration or disclosure of personal data.
Privacy Policy – this document.
Profile – a set of information provided by the User as part of their Account.
Processing – operations performed on personal data, such as collection, recording, storage, organisation, modification, disclosure or erasure.
Terms and Conditions – a document setting out the rules for using the Application.
Device – an electronic device, in particular a smartphone or tablet.
Service – services provided electronically by the Controller via the Application.
User – a natural person using the App.
Events or Interactions – actions undertaken by a User within the Application or between Users.
The Controller processes personal data in accordance with:
a) Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
b) the Personal Data Protection Act,
c) the Act on the Provision of Electronic Services.
2. SCOPE OF DATA PROCESSED
The Controller may process the following personal data:
2.1 Personal data provided by the user:
email address,
telephone number
first name, surname
age, date of birth,
town, general location,
nationality,
gender (optional),
profile photos (optional),
2.2 Data relating to the use of the App:
account ID / username,
login and activity history (when you register for an account, create or edit your profile, set your preferences),
interactions within the App (chats, event registrations, participation in groups),
subscription information (plan, payment status),
description of your personal profile and interests (insofar as this may allow for the direct or indirect identification of a natural person),
information regarding the use of social media platforms, including access to your friends list, as well as aggregated non-personal analytical data (only if you have linked our services to your social media accounts),
other data that you provide via the App.
2.3 Technical data:
IP address,
device type,
operating system,
device identifiers (e.g. IDFA/AAID – in accordance with your settings)*,
other technical data about the devices you use to access the App *Advertising identifiers (IDFA/AAID) may only be used if the user consents to this in their device’s system settings and in accordance with Google Play / App Store policies.
2.4 Special categories of personal data: The Controller does not require you to provide sensitive data, i.e. racial or ethnic origin, philosophical, religious or political beliefs, trade union membership, or information about your health. This and other information, if voluntarily disclosed by you in your Profile, is subject to special protection under EU law.
2.5. Use of geolocation: The Controller processes location-related information, e.g. your current location, place of residence, places you visit, and places and people near you, in order to provide, personalise and improve our services within the App. The location is approximate and does not indicate an exact address. In order to provide features related to the User’s location, the App may use geolocation services and APIs provided by third-party partners. Location data is processed solely to the extent necessary to perform the App’s functions, such as determining the User’s location, displaying maps, interacting with other Users, searching for people and events in a given area, or presenting location-based content. The Controller has implemented appropriate technical and organisational measures to protect location data against unauthorised access, loss, alteration or disclosure. In particular, access to location services is provided via secure APIs, using API keys subject to security restrictions that prevent their unauthorised use outside the Application environment. Location data is used exclusively in real time, to the extent necessary for the functioning of the Application’s features, and may be disabled by the User in the device settings.
3. PURPOSES OF DATA PROCESSING
The Controller processes personal data in accordance with applicable legal provisions, in order to provide access to services within the Application.
The types of information collected depend on how the User utilises the services within the Application.
Personal data is processed for the purpose of pursuing a so-called legitimate interest, understood as a fully lawful purpose of data processing that is consistent with the User’s rights, including, amongst others:
1) the provision of electronic services (maintaining an account in the App),
2) authorising access and verifying the User’s data (including age and identity),
3) enabling communication between Users,
4) enabling participation in Interactions and the management of Events,
5) processing subscriptions and payments,
6) providing marketing information (including personalised content),
7) improving the quality and modifying the Application,
8) notifying Users of changes to the Services,
9) ensuring security and preventing abuse,
10) handling complaints and reports of breaches,
10) fulfilling the Controller’s legal obligations.
4. LEGAL BASIS FOR PROCESSING
Personal data is processed on the basis of:
Article 6(1)(b) of the GDPR – performance of a contract,
Article 6(1)(c) of the GDPR – a legal obligation,
Article 6(1)(f) of the GDPR – the Controller’s legitimate interests,
5. DISCLOSURE OF PERSONAL DATA
5.1 In order to provide the Services properly, it may be necessary to transfer certain collected information and data to third parties assisting the Controller in maintaining the technical infrastructure of the Application, in particular to hosting, analytics or cloud service providers responsible for providing technical support. The Controller shares information with third parties that help it to operate, deliver, improve, integrate, customise, support and market its services, including business, marketing and analytics partners, as well as IT and payment service providers. The Controller ensures that all relationships involving the processing of personal data are governed by a documented data processing agreement containing the specific information and conditions required by the GDPR. Personal data may be transferred to:
a) IT and hosting service providers,
b) payment operators (Apple, Google and others),
c) providers of analytical tools (e.g. app statistics),
d) administrative and law enforcement authorities, where justified by law,
d) other Users of the App to the extent specified in the App’s Terms of Use. The data provided by the User in their Profile is visible to other Users of the Application, to the extent permitted by the Profile owner. Other App Users (natural persons) may view content uploaded by the User, as well as actions taken by the User within the App’s services, participation in events, interactions, etc.
e) Public authorities: Where required by law, the Controller may disclose the User’s data and information about their interactions to the Police or other authorised public authorities (including, but not limited to: first name, surname, telephone number, email address, IP address, as well as data concerning suspicious behaviour such as unlawful use of a given Service, reasonable suspicion of a criminal offence, threats against another User). We may share your personal data with the following organisations:
The police, law enforcement agencies, regulatory bodies, including tax and other authorities;
Fraud prevention agencies;
Identity verification agencies,
Third parties who have your consent to share your data with them;
Third parties with whom we have lawful and binding data processing agreements, to the extent necessary for the provision and development of our services, including those arising from payment services regulations and banking law.
5.2 Communication between users: The app enables users to communicate and interact with one another. The controller may process the content of communications to ensure user safety, prevent abuse, and respond to reports of breaches of the terms and conditions. The Administrator does not monitor private conversations on an ongoing basis, but may analyse reported content in the event of a suspected breach of the App’s terms of use.
5.3. Marketing Consents: Where we have the appropriate consent, and in accordance with the law and the User’s preferences, some personal data may be processed by our external marketing partners to enable us to communicate with all our customers (e.g. by telephone, email, push notifications). This may include providers of email and SMS messaging platforms, providers of rewards or gifts, etc. This is always carried out on the basis of data processing agreements that comply with legal requirements and effectively protect your rights and interests regarding access to personal data. Our marketing communications will include instructions on how to opt out of receiving a specific type of communication or to withdraw/amend the scope of your marketing consents. It may take up to 48 hours for your request to be fully processed.
5.4. We do not share Users’ personal data with unaffiliated third parties for the purpose of selling it.
5.5. The Controller may profile personal data, which means that it may use the information collected to tailor communications addressed to the User directly to their needs. The Controller does not use profiling data to make automated decisions that could affect the User’s legal situation. The Controller does not use algorithms to make decisions that would affect individual rights arising from the contract for the use of the Application.
5.6. Transfer of data outside the EEA: Data may be transferred outside the EU only to the extent permitted by the GDPR. By consenting to the transfer of your data to third parties, you also agree that such third parties may be located outside the EEA. Privacy laws in these countries may not provide the same level of protection as in your country or the EEA. The transfer of personal data outside the European Union will be carefully assessed prior to the transfer to ensure that it falls within the limits imposed by the GDPR. Intra-group international data transfers will be subject to legally binding agreements, known as Binding Corporate Rules (BCRs), which ensure full compliance with and enforcement of the rights of data subjects. If the Controller transfers data outside the EEA, it will rely on the EU Standard Contractual Clauses or other legal provisions that allow for a lawful transfer of data and ensure an adequate level of protection.
6. DATA RETENTION PERIOD
6.1 The Controller processes the User’s personal data only for as long as is necessary to achieve the purposes set out in this Privacy Policy, in accordance with the principles of data minimisation and storage limitation set out in the GDPR (Article 5(1)(e)). After this period, the Controller will delete or anonymise the data, depending on the type of data and legal requirements. In the case of anonymised data, the Controller securely stores the User’s data and isolates it from further processing until such time as its deletion is legally and technically possible.
6.2. Data is retained for the following periods: A. Data disclosed in the User Profile (the User’s personal data, information posted in the Profile) remains visible in the Profile for the duration of the User’s use of the application, until the User’s account is deleted. Upon deletion of the Account, the data is automatically anonymised and becomes invisible to other Users. After the User’s account is deleted, basic personal data remains visible only to the Administrator and is stored for the period necessary to pursue or defend against claims, ensure the security of the Application, and fulfil obligations arising from legal provisions. Anonymised data may be stored for up to 5 years or for the period required by law. B. Location data Location data is stored exclusively in real time, for the period necessary for the application’s functions to operate. Data relating to participation in events, published content, social activity and interactions within the Application is stored for the duration of the User’s Account or until it is deleted by the User, subject to situations where further storage is required by law. C. Payment data is stored for the period required by tax and accounting legislation, generally for 5 years from the end of the calendar year in which the tax liability arose; D. IP addresses, device information and data relating to the security of the Application are stored for a period of 24 months from the date of their recording, unless there is a need for longer storage for the purpose of establishing, pursuing or defending claims. E. Data processed for analytical and statistical purposes is retained for the period necessary to fulfil these purposes, but for no longer than 36 months from the date of collection, unless the data has been anonymised beforehand.
7. USER RIGHTS
7.1. Under the General Data Protection Regulation (GDPR), the User has the right to access their data, rectify it, transfer it or request its erasure. The User’s rights under the provisions of the GDPR include, among others:
The right to withdraw consent to data processing,
The right to receive information on how data is processed and for what purpose,
The right to access data and information about yourself, and to request a copy of your data (exclusively about you),
The right to rectify and complete incomplete data where your personal data is inaccurate,
The right to erasure – you may request the erasure of your personal data at any time, provided there are no legal requirements or overriding obligations to continue processing such data for a specified period. Legal obligations arising from specific regulations include pre-determined data retention periods.
Right to restriction of processing / right to object – in certain circumstances, you have the right to object or request the restriction of the processing of your personal data if the processing is based on consent or our legitimate interest, rather than legal requirements. However, if a specific set of data is subject to legal requirements binding on us, then despite your objection or request to restrict the processing of your data, we will still have to continue processing your data for a specified period,
Right to object to the manner of data processing, e.g. to the processing of data for marketing purposes,
Right to data portability – You have the right to request that your personal data be provided in a structured, commonly used and machine-readable format and to have that data transmitted to a third party. This applies to personal data processed on the basis of your consent and to data processed by automated means.
Rights relating to automated decision-making and profiling – the right to object to being subject to automated decision-making; where a decision has a significant impact on you, you may request human intervention where appropriate. You also have the right to express your point of view and the decisions taken. To exercise your rights, please contact the Controller.
7.2. The Controller may refuse to exercise certain User rights indicated above where the exercise of a given right would conflict with the legitimate purpose of data processing or the obligations imposed on the Controller by law. The Controller may refuse to delete your personal data for the period during which they are required to retain such data in accordance with legal provisions.
7.3. The User’s rights in relation to other Users: In order to ensure the safety of the Application’s users, the Administrator may take automatic actions following reports of irregularities by other Users, including the ability to block other users and moderate reported content. The Administrator reserves the right to suspend or delete an account that violates the terms of use of the Application.
7.4. Deleting your account: You can permanently delete your account in the App via the “Account Settings” tab or by contacting the Administrator: kontakt@uslyapp.pl If you delete your account, we will remove the content you have published, such as photos and information disclosed in your Profile. This information cannot be recovered later. Information about you shared by other people does not belong to your account and will not be deleted.
8. DATA SECURITY
8.1 The Controller employs appropriate technical and organisational measures to protect data. The Controller of personal data takes technical, physical and administrative measures to ensure adequate protection of Users’ personal data against loss, misuse, as well as unauthorised access, disclosure and alteration. To this end, appropriate security measures are in place, including firewalls, data encryption, physical access controls to databases and access authorisation controls.
8.2. Access to data is restricted to authorised persons and the Administrator’s partners. The Administrator shall not be liable for actions resulting from the User’s negligence (e.g. sharing a password).
8.3. User-generated content: The User bears full responsibility for content published on the Application and undertakes not to publish content:
that infringes the law,
that infringes the rights of others,
containing offensive, vulgar, discriminatory or violence-inciting content,
containing spam or advertising content without the Administrator’s consent. The Administrator reserves the right to remove content that breaches these Terms and Conditions.
8.4. Mechanism for reporting Users and violations: The App provides a mechanism for reporting users or content that breaches the rules of use of the App, the rights of other Users and third parties. Any User may report inappropriate behaviour by other users, content that breaches these Terms and Conditions, suspected abuse, or unlawful activities. The Administrator reviews reports and may take appropriate action, in particular: remove the reported content, issue a warning to the user, or block or delete the user’s account.
9. DATA OF MINORS
The App is intended for persons aged 18 or over. By registering on the App, the User declares that:
is at least 18 years of age,
has the capacity to use the services offered in the App in accordance with applicable law. The Controller does not knowingly process the personal data of persons under the age of 18. Should the Controller become aware that such data has been provided, the Controller will take steps to delete it immediately.
10. COOKIES AND SIMILAR TECHNOLOGIES
The Controller’s external partners, including marketing and analytics partners, use technologies to collect information, such as cookies and web beacons. The Controller uses cookies, web beacons and other technologies for the following purposes:
a) functional purposes,
to improve and customise the services within the Application;
to enhance the user experience – cookies remember selected options, such as language or search parameters;
to enable access to and use of the services without having to re-enter the User’s username or password, by remembering that the User is already logged in;
b) analytical
for performance and analytics – cookies and similar technologies collect information on how Users interact with the services,
The Controller uses Google Analytics cookies to better understand how users find our products and website, and how they browse them, to identify areas for improvement, such as navigation, user experience and marketing campaigns,
to display adverts relevant to your interests.
c) social media interactions: These cookies are used when you share information about your Profile on the App via the share button on other social media platforms, or when you link your Profile to other websites or social media platforms. You can manage your consents in your device settings. To opt out of the use of cookies, you can configure your web browser accordingly by changing its settings so that it no longer accepts cookies or displays a prompt before accepting cookies from the websites you visit. If you do not accept cookies, this may hinder or prevent you from using all aspects of the services within the App.
11. CHANGES TO THE PRIVACY POLICY
The Controller reserves the right to amend the Privacy Policy. The Controller publishes any changes to the Privacy Policy by adding a notice within the App. The Administrator retains previous versions of the Privacy Policy in an archive for reference. We encourage you to review the Privacy Policy each time you use the services to stay informed about our information practices and privacy protection measures. If you do not agree with the changes to this Privacy Policy, you will need to stop using the services and deactivate your account in the App. Continued use of the App constitutes acceptance of the changes.
12. CONTACT
For matters relating to the protection of personal data, please contact: kontakt@uslyapp.pl Sincerely, USLY Data Controller
Change history
1.1 — first public version of the document published for the USLY app.