Privacy Policy

At Dr Ivy, we take your privacy seriously and are committed to maintaining the security and confidentiality of your personal information. This Privacy Policy describes the types of information we collect, how we use it, and the safeguards we have in place to protect it. We encourage you to read this Policy carefully to understand our practices regarding your personal information and how we treat it.

Payment Information

When using our Services requiring payment, we may ask for your credit card or other payment account information. This information is exclusively used for securely processing your payments. To ensure your payment information is secure, we collaborate with third-party payment processors ("Payment Processors"). These processors conform to the most recent security standards managed by the PCI Security Standards Council, an initiative of leading payment brands including Visa, MasterCard, American Express, and Discover.

Sensitive and private data exchange occurs over a secure SSL communication channel, ensuring your information is encrypted and protected with digital signatures. We share your payment data with our Payment Processors only to the extent necessary for processing payments, handling refunds, and managing complaints or queries related to such payments and refunds.

Note that Payment Processors may collect certain Personal Information from you, such as your email address, physical address, credit card details, and bank account number, essential for processing your payments. For future or recurring payments, your financial information may be stored in an encrypted form on our Payment Processors' secure servers, subject to your prior consent. Their usage of your Personal Information is dictated by their respective privacy policies, which we recommend you review.

Automatic Collection of Information

Whenever you visit our Website or use our Mobile Application, our servers automatically record data sent by your browser or device. This data may include your device's IP address, location, browser name and version, operating system type and version, language preferences, the webpage you visited before our Services, the pages of our Services you visit, the time spent on those pages, the information you search for on our Services, access times and dates, and other relevant statistics.

This automatically collected information is used to identify potential abuse cases and establish statistical information regarding the usage and traffic of our Services. Please note, this statistical information is not aggregated in such a way that would identify any specific User.

Personal Information Collection

Using our Services doesn't require revealing any personal information that could identify you as a specific individual unless you opt to use certain features. For instance, if you decide to create an account, make a purchase, or fill out forms on the Services, we may ask you to provide certain personal information like your name and email address.

The information we collect from you may include account details (username, user ID, password), contact details (email address, phone number), basic personal information (name, country of residence), and other data relevant to our Services. In certain cases, we might also collect sensitive personal information or biometric information, but this will only be with your explicit consent and as required by our Services.

We collect information directly from you, but we may also gather personal information about you from other sources, such as social media platforms, public databases, third-party data providers, and our partners. This may include demographic and device information, geolocation data, and online behavioral data.

While you have the choice not to provide us with your personal information, doing so might prevent you from fully utilizing our Services. If you're unsure about what information is mandatory, please feel free to contact us.

Children's Privacy

We understand the importance of safeguarding children's privacy, particularly for those under the age of 13. Any personal information we may collect from children is subject to special precautions. To use the Services, we may require children to disclose some personal information, but we always aim to minimize the data we collect and never request more than necessary. We ensure this information is used strictly for the purposes it was collected and kept private by default, accessible only by the user who submitted it.

We urge parents and legal guardians to monitor their children's internet usage and help enforce this policy by instructing their children never to provide personal information through our Services without their permission. Please ensure that children understand the importance of not disclosing personal information online without consent. As part of this, we encourage parents to foster a safe and friendly online environment for their children.

Handling and Use of Collected Information

When dealing with personal information, we function both as a data controller and a data processor in line with the General Data Protection Regulation (GDPR), unless a data processing agreement is in place which stipulates different roles.

When we ask you to provide personal information necessary for accessing and using the Services, we act as a data controller. As such, we determine the purposes and means of processing personal information and adhere to the GDPR’s obligations for data controllers.

On the other hand, when you submit personal information through the Services, we act as a data processor. In these instances, we don't own, control, or decide on the submitted personal information, and we process this data strictly based on your instructions. Here, the user who provides the personal information acts as a data controller in terms of the GDPR.

In order to provide you with our services or to comply with a legal obligation, we might need to collect and use certain personal information. The information we collect is used to create and manage user accounts, deliver and improve our products and services, respond to inquiries, administer prize draws and competitions, enforce policies, and protect from malicious users, among others.

The processing of your personal information depends on how you interact with our services, where you're located, and whether any of the following applies: your consent, necessity for an agreement, compliance with a legal obligation, tasks carried out in public interest, and legitimate interests pursued by us or a third party. We may also combine your personal information to serve you better and improve our Services.

We base the collection and processing of your personal information on your consent and our legitimate interests, as defined in the GDPR.

Please note that under some legislations, we might be allowed to process information until you opt out. In any case, we are happy to clarify the specific legal basis for the processing.

Payment Processing

For services requiring payment, you may have to provide your credit card details or other payment account information, which will be used solely for processing payments. We use third-party payment processors (Payment Processors) to assist us in securely processing your payment information.

These Payment Processors adhere to the latest security standards, as managed by the PCI Security Standards Council. All sensitive and private data exchange occurs over an SSL secured communication channel, is encrypted, and protected with digital signatures. We share payment data with the Payment Processors only to the extent necessary for processing payments, refunds, and handling related complaints and queries.

Please be aware that the Payment Processors may collect some personal information from you to process payments. With your prior consent, necessary for processing recurring payments, your financial information may be stored in encrypted form on the secure servers of our Payment Processors. We suggest that you review their respective privacy policies, as they govern the use of your personal information.

Disclosure of Information

To provide the Services you requested or to complete any transaction, we may share your information with our trusted subsidiaries, joint venture partners, affiliates, contracted companies, and service providers (collectively, "Service Providers") that assist in the operation of the Services and abide by our privacy policies. We will not share information with unaffiliated third parties.

Service Providers can only use or disclose your information to perform services on our behalf or comply with legal requirements. We limit their access to necessary information and do not authorize them to use it for their marketing or other purposes. Categories of Service Providers we may share your information with include advertising networks, cloud computing services, data storage services, payment processors, social networks, and website hosting service providers, among others.

We may also disclose your personal information if required by law, during a business transition such as a merger or acquisition, or when necessary to protect our rights, your safety or the safety of others.

Retention of Information

We retain and use your Personal Information to comply with legal obligations, for as long as your user account is active, to enforce agreements, resolve disputes, or as long as required or permitted by law. After the retention period expires, the Personal Information will be deleted, and you will not be able to exercise rights to access, erasure, rectification, and data portability.

Transfer of Information

Depending on your location, transferring your information may involve storing it in a country other than your own. Transfers of Personal Information outside the European Union will occur only with your explicit consent or as provided by the GDPR. We will take appropriate measures to safeguard your information.

Data Protection Rights under the GDPR

If you are a resident of the European Economic Area (EEA), you have specific data protection rights. These include rights to withdraw consent, access your Personal Information, correct inaccurate data, object to processing, restrict processing, erase your Personal Information, receive your Personal Information in a structured format and have it transferred, and lodge a complaint with a data protection authority. Please contact us to exercise any of these rights.

California Privacy Rights

Under the California Consumer Privacy Act (“CCPA”), California residents are entitled to certain additional rights regarding their Personal Information. If you're a California resident, you can request information once a year about the specific pieces and categories of Personal Information we have collected and disclosed. Additionally, you have the right to request deletion of your Personal Information or opt-out of its sale. We will not discriminate against you if you exercise these rights.

How to Exercise Your Rights

To exercise any of your rights, you can contact us using the details provided in this document. We may ask you to verify your identity before responding to your requests. If your request is submitted by an authorized representative, we may need evidence of their authority to act on your behalf. Your request must include enough details for us to understand and respond appropriately.

Data Analytics

Our Services may use third-party analytics tools that use cookies or similar technologies to collect internet activity and usage information. We use this data to improve our Services by monitoring user activity.

Do Not Track Signals

Our Services currently do not respond to Do Not Track signals from your browser due to a lack of uniform communication methods. However, we do limit our use and collection of your Personal Information.

No Reverse Engineering

You agree not to copy, decompile, reverse engineer, disassemble, modify, or create derivative works of our software or any part thereof, except where such actions are prohibited by law.

Advertisements

We may work with third-party companies to deliver tailored advertising that we think may be of interest to users. These companies may use cookies and track user behavior.

Social Media Features

Our Services may include social media features such as the Facebook and Twitter buttons. These features may collect information such as your IP address and the pages you visit on our Services. Interactions with these features are governed by the privacy policies of the respective social media platforms.

Email Marketing

We offer voluntary electronic newsletters. We commit to keeping your email address confidential and will not disclose it to third parties except for email sending purposes. You can unsubscribe from our newsletters or marketing emails at any time, but you will continue to receive essential transactional emails. Our emails comply with the CAN-SPAM Act.

Affiliate Links

We engage in affiliate marketing, and affiliate links may be present on our Services. Clicking on these links will place a cookie on your browser to track sales for commission purposes.

Links to Other Resources

Our Services contain links to resources not owned or controlled by us. We are not responsible for their privacy practices, so we encourage you to read their privacy statements.

Information Security

We strive to protect your Personal Information by maintaining reasonable administrative, technical, and physical safeguards. However, due to the nature of internet, the security and privacy of your information can't be completely guaranteed.

Data Breach

If a data breach occurs, resulting in unauthorized access to Personal Information, we will take appropriate measures, including notifying affected individuals if there's a risk of harm or if required by law.

Changes and Amendments

We reserve the right to modify this Policy at any time. Changes will be effective immediately upon posting unless specified otherwise. By continuing to use the Services after changes are made, you consent to the revised Policy.

Acceptance of this Policy

By using our Services, you acknowledge you've read this Policy and agree to its terms. If you disagree, you're not authorized to use our Services.

Contacting Us

For questions regarding your data or to exercise your rights, contact us at hello@drivy.ai. We aim to resolve complaints and honor your rights promptly, within the timescales set by data protection laws.

This document was last updated on June 28th, 2023.