Effective Date: 11th September 2024
1. Introduction
Hurree Inc. is committed to protecting your privacy and ensuring the security of the personal data we collect, store, and process. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our services, in accordance with the UK General Data Protection Regulation (GDPR) and ISO 27001 standards.
By using our services, you agree to the terms of this Privacy Policy.
2. Data Controller Information
Data Controller: Hurree Inc.
Address: Hurree Inc, Pilots View, 18 Heron Road, Belfast BT3 9DE
Contact Information: dpo@hurree.co
Data Protection Officer (DPO): Rachel McMullin
3. What Data We Collect
We collect and process the following categories of personal data:
Personal Identification Information: Name, email address, phone number, and postal address.
Financial Data: Payment information such as credit card details (processed securely through third-party providers).
Technical Data: IP addresses, device information, browser type, session activity.
Behavioral Data: Interaction data, usage patterns, and preferences (collected via tools like Google Analytics, LogRocket, etc.).
Marketing Data: Preferences, subscription information, browsing behavior, and advertising engagement (collected via platforms like Google Ads, Facebook, LinkedIn, Instagram, and others).
Support Data: Customer support conversations and related data collected via tools like ZenDesk and Intercom.
4. How We Use Your Data
We use personal data for the following purposes:
Purpose
Legal Basis
5. International Data Transfers
Some of the tools we use may transfer personal data outside the UK or European Economic Area (EEA), including to the United States. We ensure that adequate safeguards, such as Standard Contractual Clauses (SCCs), are in place for such transfers to comply with GDPR.
6. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods may vary based on the type of data and applicable legal requirements:
Financial Data: Retained in compliance with financial regulations (via Stripe).
Marketing Data: Retained for as long as the individual remains subscribed or engaged.
Customer Support Data: Retained for the duration of customer interaction or until the data is no longer needed (via ZenDesk, Intercom).
Analytics Data: Retained as configured in the respective analytics tools (Google Analytics, Microsoft Clarity).
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data in line with ISO 27001 standards. These include:
Encryption of data in transit.
Access Control ensuring that only authorized personnel have access to personal data.
Incident Management: Procedures in place to detect, respond to, and report any data breaches.
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
Access: Request a copy of the data we hold about you.
Rectification: Ask us to correct inaccurate or incomplete data.
Erasure: Request deletion of your data when it is no longer necessary for the purposes for which it was collected.
Restriction: Ask us to restrict the processing of your data in certain circumstances.
Data Portability: Request a copy of your data in a structured, commonly used format.
Objection: Object to the processing of your data for marketing purposes.
Withdrawal of Consent: If processing is based on consent, you can withdraw your consent at any time.
To exercise your rights, please fill in this form: Data Subject Request Form.
9. Data Sharing with Third Parties
We may share your personal data with the following third parties:
HubSpot
Google Ads
Buzzsprout
Arcade
SEM Rush
Convert Calculator
G2
LogRocket
Microsoft Clarity
Google Analytics
Acast
SendGrid
ZenDesk
Pendo
Stripe
LiveStorm
Jiminny
Notion
Azure
Cognism
Intercom
Google Workspace APIs