This privacy policy ("Policy") explains when, why and how personal information is collected, used and disclosed by SpaceOS Limited (“SpaceOS”, “we”, “us”) including with respect to your access and use of the cloud-based portal application made available to you through the our website or via mobile application by SpaceOS in relation to any building or site for the purpose of facilitating access to programs and services (the "Platform").
In our provision of the Platform, SpaceOS processes your personal data on behalf of third parties. The controllers of your data is the third party as follows and we act as their data processor:
For the purposes of this Policy, "personal data" or "personal information" refers to personal data as defined by the Data Protection Laws (defined below), and includes any data that relates to you (such as your name, address, email address or device information that could identify you) and which is processed (i.e., stored, used, etc.) by SpaceOS, as described more particularly in the section entitled "What Personal Information Do We Collect?" below). We process personal data only in compliance with applicable data protection laws, including the UK Data Protection Act 2018, the Irish Data Protection Acts 1988 to 2018, the EU General Data Protection Regulation (2016/679) (the "GDPR") and any legislation that replaces or supersedes them (together, the "Data Protection Laws").
The legal basis for the processing of your personal data is the necessity to process them in order to perform our services or upon your consent or fulfilling our legal obligations or our legitimate interests (as applicable). Providing personal data is voluntary, but it is necessary to provide you with the services of our Platform.
The personal data we collect from you might include your:
Except as described in this Privacy Policy, we do not generally ask you to disclose any sensitive information (e.g., medical information, details of race, religious or political beliefs, data concerning sexual orientation or sex life or membership of a trade union, or genetic or biometric data) to us. If we do ask you to provide us with any sensitive information, we will normally ask for your explicit consent in order to process this information.
If you do not provide your personal data to us, we may be unable to provide services to you, and you may not be able to create an account and use the Platform.
Information that you provide to us
We collect personal information from you when you:
Information collected by automated means
We also obtain some of your personal information by automated means when you use the Platform, such as the IP address of the device you use, the geographical location of your device, the browser you are using, the URL you came from, the web pages you access, and your usage of the Platform. If you use the mobile application version of the Platform, we may collect location data to enable your 'digital access pass', location based weather and/or transit information services (where available), and/or other location-based services available via the Platform to which you have opted to use (such as location based parking access services, where available), even when the app is closed or not in use.
Cookies
We use cookies and similar technologies where this is necessary to operate our Platform and may also use these technologies to track your usage of our Platform. Cookies are small text files that are stored on your device (laptop, tablet, smartphone, etc.) when you use the Platform. For more information about how we use cookies and the list of cookies being used, please refer to our Cookie Policy at https://spaceos.io/privacy-policy/.
If you are a user of our Platform
If you use our Platform to request products, services or information (in this section, "Platform User" or "you"), we will use your personal information in the following ways.
Categories of data. In order it manage the relationship with you, provide you with services and enable communication with you, we collect and process the following categories of personal data: name, e-mail address, postal address (including postcode), telephone number (including mobile number), date of birth, image, payment information, IP address and other device information, geolocation.
Purposes of the processing. We process your personal data for the following purposes:
Legal basis for the processing. We process your personal data because:
Categories of data. To ensure security of our services we process the following data: name, e-mail address, payment information.
Purposes of the processing. We process your personal data for the following purposes:
Legal basis for the processing. We process your personal data because it is necessary in our legitimate interest to use your personal information for the purposes of ensuring security and protecting against illegal and fraudulent activity.
Categories of data. To make sure that our services meet your needs, we process information collected by our website automatically, and through cookies and other technologies, alone and in combination with the types of data described in this privacy policy.
Purposes of the processing. We process your personal data for the following in order to better understand you, your behaviour and your interests. We share this information with third party organisations in your building or site to help those organisations provide you with a more tailored service and improve their products and services generally. For example, this information is used to inform those organisations' product development choices and to send you tailored offers and promotions for products and services you are likely to be interested in. You have the right to opt out from these promotional messages at any time. For more information, see the section titled "Your right to withdraw consent to processing" below.
Legal basis for the processing. We process your personal data based on:
Categories of data. We process the following data: name, e-mail address, postal address (including postcode), telephone number (including mobile number), transaction history, IP address and other device information.
Purposes of the processing. We process your personal data for the following purposes:
You have the right to opt out from these promotional messages at any time. For more information, see the section titled "Your right to withdraw consent to processing" below.
Legal basis for the processing. We process your personal data based on:
Categories of data. We process the following data: name and e-mail address.
Purposes of the processing. We process your personal data to ensure that we do not contact you if you have asked us not to. We understand that you may prefer for us not to contact you with details of our products, services or promotions or those offered by third parties. We keep records of your marketing preferences in order to do this.
Legal basis for the processing. It is necessary for us to keep records of your marketing preferences to comply with requirements of direct marketing laws to which we are subject.
Categories of data. We process the following categories of data: name, e-mail address, geolocation.
Purposes of the processing. We process the above data in order to share this information with third party organisations providing products or services to people in your building or site in order for those third party organisations to fulfil your requests for products or services.
Legal basis for the processing. Your personal information will be processed in this way where this is necessary to fulfil a contract with you or to take steps at your request prior to such a contract being concluded.
Categories of data. To enable contact between you and other Platform Users, we process the following categories of data: name, telephone number (including mobile number), image, other information you provide us with relating to your interests and skills.
Purposes of the processing. We process the above data to enable contact between you and other Platform Users. Where you have asked us to make this information available to other Platform Users (for example, to allow them to contact you about a product or service that you offer or events or other activities you are running in their building), we will make this information visible to other Platform Users via the Platform so that they can contact you with enquiries and requests relating to your products, services or events.
Legal basis for the processing. Your personal information will be processed in this way where this is necessary to fulfil a contract with you or to take steps at your request prior to such a contract being concluded.
Categories of data. We collect and process the following information you may provide about your visitors: name, email address, company, and their role, any other data which you provide.
Purposes of the processing. Where applicable to the property and/or your role, you may have access to book visitor appointments to the property using the visitor management functionality of the Platform. By using the visitor management functionality, you agree that the data of your visitors (as supplied by you), is stored on the Platform to facilitate visitor management to the property.
Legal basis for the processing. The personal data is processed based on our legitimate interest to ensure security of the building.
If you are a visitor (not a Platform User)
If you are a visitor (a "Visitor") to the property, but not otherwise a user of our Platform (you have not registered for an account), we may process your personal information as supplied by your host at the property (usually limited to name, email address, company, and your role, unless your host has included any other information), for the purpose of facilitating visitor management at the property. Visitor personal data is deleted or permanently anonymised 90 days following the date of the appointment at the property. The legal basis of the processing is our legitimate interest in ensuring security of the property.
Who Do We Share Your Information with?
We will not share the personal information we collect from you through our services with third parties, except as described in this Policy, or as required by law.
To the extent permitted by applicable law, we may disclose information to the following recipients or categories of recipients:
Where do we store your personal information?
The data we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"), in particular to Equiem Services Pty Limited in Australia and Equiem USA LLC in the USA. It may also be processed by staff operating outside the EEA who work for us or for one of our service providers. We will take all steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Policy and applicable data protection laws, including, where relevant, entering into EU standard contractual clauses (or equivalent measures) with the party outside the EEA receiving the personal information. You can request a copy of these standard contractual clauses by contacting us as set out in "How to Contact Us" below.
Links to Other Sites
Our Platform may contain links to other sites. Any personal information you provide on the linked pages is provided directly to that third party and is subject to that third party's privacy policy. This Policy does not apply to such linked sites, and we are not responsible for the content or privacy and security practices and policies of these sites or any other sites that are linked to from our Platform.
How Do We Store and Secure Personal Information?
We store personal information on computer databases and/or in hard copy and will take reasonable physical and technical security measures to protect your personal information in an effort to prevent loss, misuse and unauthorised access, disclosure, alteration and destruction.
Please be aware, however, that despite our efforts, no security measures are perfect or impenetrable and no method of data transmission can be guaranteed against any interception or other type of misuse.
We offer the use of a secure server. All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our Payment gateway providers database only to be accessible by those authorized with special access rights to such systems, and are required to keep the information confidential.
How long do we keep your personal information?
Your personal information is stored by us and/or our service providers and suppliers, only to the extent and for the time necessary to achieve the purposes for which the information is collected, in accordance with the Data Protection Laws. When we no longer need to use your information for these purposes, we will remove it from our systems and records and/or take steps to properly anonymise it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which we are subject).
Your Choices and Privacy Rights
You have the following rights in connection with our processing of your personal data. If you wish to exercise one or more of these rights, please contact us with your request at [email protected]
Your right to access the information we hold about you
You may request access to the personal data we hold about you. Our file of your information will usually be made available to you within 30 days, although occasionally we may not be able to give you access to all the personal data we hold about you. For example, we may not be able to give you access if the information we hold includes both your personal data and the personal data of others and disclosing their information to you would adversely affect their rights.
Please note that if you request a copy of your data using electronic means (such as email), then we will provide a copy of your information in electronic form unless you ask us to do otherwise.
Your right to have your information corrected
You have the right to have incomplete or inaccurate personal information that we process about you rectified. Note that you can always make certain adjustments to certain personal information directly through your online account.
Your right to have your information deleted
You have the right to request that we delete personal information that we process about you. This right applies only in certain circumstances. For example, we are not obligated to delete your data where we need to retain it in order to comply with our legal obligations or to establish, exercise or defend legal claims.
Your right to object to us processing your personal data
Where the legal justification for our processing of your personal information is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate grounds for the processing which override your interests and rights, or if we need to continue to process the data for the establishment, exercise or defence of a legal claim.
Your right to withdraw consent to processing
If you have consented to us processing your personal data for a particular purpose, you have the right to withdraw your consent at any time, free of charge, by contacting us. This includes cases where you wish to opt out from marketing messages that you receive from us (including marketing messages that we send on behalf of third party organisations). You can unsubscribe from marketing communications at any time by following the instructions in any individual message If you withdraw your consent to processing, we may still contact you in connection with your account, relationship, activities, transactions and communications with us.
Your right to have an electronic copy of your personal data transmitted (right to data portability)
Where we hold personal data about you with your consent or for the performance of a contract with you, you also have the right to ask us to provide you with the personal data we hold about you in a structured, commonly used and machine-readable format and, where technically feasible, to transmit that personal data to another organisation.
Your right to restrict processing of your data
You have the right to restrict our processing of your personal information where you believe such data to be inaccurate, our processing is unlawful or that we no longer need to process such data for a particular purpose, but where we are not able to delete the data due to a legal or other obligation or because you do not wish for us to delete it.
Your right to data portability
You have a right to receive the personal data you have provided us in a digital format of current use and automatic reading or to request the direct transmission of your personal data to another entity that becomes the new responsible for your personal data however only if technically possible.
Your right to object and ADM
When the processing of personal data, including the processing for the definition of profiles, is exclusively automatic (without human intervention) and may have effects in your legal sphere or significantly affect it, you shall have the right not to remain subject to any decision based on such automatic processing, except as otherwise provided by law and shall have the right that we take appropriate measures to safeguard its rights and freedoms and legitimate interests, including the right to have human intervention in decision making by us, the right to express its point of view or contest the decision taken on the basis of automated individual information processing.
Your right to lodge a complaint with the local data protection authority
You have the right to lodge a complaint with the local data protection authority if you believe that we have not complied with applicable data protection laws.
If you are based in the UK, the Information Commissioner's Office can be contacted as follows:
Telephone: +44 0303 123 1113
E-mail: [email protected]
Website: www.ico.org.uk
Web-form: www.ico.org.uk/concerns/
Address: Water Lane, Wycliffe House, Wilmslow, Cheshire, SK9 5AF
In Ireland, the Data Protection Commission can be contacted as follows:
Telephone: +353578684800
Website: https://dataprotection.ie/
Web-form: https://forms.dataprotection.ie/contact/
Postal Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
If you are based elsewhere in the European Economic Area (EEA), please use this link for a list of local data protection authorities in the EEA countries in which we operate: https://edpb.europa.eu/about-edpb/board/members_en .
Amendments to this Policy
This Policy may be modified from time-to-time. If we make changes to this Policy, we will notify you of these changes by email and post an alert on our Platform.
Terms and Conditions
Please also ensure you have read our Terms of Use at https://spaceos.io/terms-and-conditions/ before using our Platform.
Queries, Comments and Complaints about our Handling of Personal Information
If you have any questions, comments or complaints about our collection, use or disclosure of personal information, you wish to ask us to stop processing your personal information, you would like to request a copy of the personal information we hold about you, or if you believe that we have not complied with this Policy or the Data Protection Laws, please contact us by email at [email protected] or by writing to us at 14th Floor 33 Cavendish Square, London, England, W1G 0PW, United Kingdom.
We will take any privacy complaint seriously and any complaint will be assessed with the aim of resolving any issue in a timely and efficient manner. We request that you cooperate with us during this process and provide us with any relevant information that we may reasonably request.
You may also contact our data protection representative, using the contact details below.
Email: [email protected]
Phone: 0800 041 8132