Data subject rights

Last uploaded: 05 May 2020

Exposebox Ltd. (“Exposebox”, “We”, “Our”, “Us”) values privacy rights of its customers, partners and users (“You”). As required under applicable privacy legislation and data protection laws, individuals have certain rights regarding the processing of their personal data. This Data Subject Rights Overview is prepared by Us in order for You to be aware of your rights under the EU General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act of 2018 (“CCPA” or “Act”) which shall apply to you in the event you are a “California Resident”, as defined under the CCPA.

Right to be Informed

This right enables You to be informed how do we use personal information provided by You or collected through using of Our Services. Please review our Privacy Policy for such information.

Right of Access

This right enables You to receive a copy of the Personal Data we hold about You and to check that we are lawfully processing it. You may also have the right to ask for a copy of your personal data in portable or machine-readable form.  The GDPR and CCPA provide different protections, the GDPR enables access to all Personal Data processed by the controller, however the CCPA “Access Right” applies only to Personal Information collected in the 12 months prior to the request.

Right to Rectification

This right enables You to have any incomplete or inaccurate information we hold about You corrected. You may also be able to have incomplete Personal Data completed – although this will depend on the purposes for the processing.

Right for Erasure (“Right to be Forgotten”)

This right enables You to ask Us to delete or remove personal information where there is no reason for Us continuing to process it. You also have the right to ask Us to delete or remove your personal information where You have exercised your right to object processing (see below). Please note that the right for erasure is not absolute. We are required to comply with Your request and delete the requested data if: (i) the Personal Data is no longer necessary for the purposes for which it was collected or processed; (ii) You withdraw the consent on which the processing is based under the applicable legislation and there is no other legal ground for processing; (iii) You have exercised your right to object the processing of the data provided by You, and there are no overriding legitimate grounds to process the data; (iv) the Personal Data was processed unlawfully; or (v) otherwise, the erasure of Your Personal Data is necessary to comply with applicable law. Please note, that we are entitled to reject your request in the event that (subject to applicable law) we must or need to retain such information to comply with Our obligations or for another specific purpose.

Right to Restrict Processing

This right enables You to ask Us to suspend the processing of personal information about You in certain circumstances, for example is You want Us to establish its accuracy or the reason for processing it.

Right to Data Portability

This right enables You to receive Personal Data You provided Us, when we act as a controller, in a structured, commonly used and machine-readable format. It also gives You the right to request transmitting this data directly to another controller. Please note, that this right only applies when: (i) Our lawful basis for processing this information is consent or for the performance of a contract; and (ii) We are carrying out the processing by automated means (i.e. excluding paper files).

Right to Object

This right enables You to object to the processing of Your Personal Data where We are relying on a legitimate interest (or those of a third party) and there is something about Your particular situation which makes You want to object to processing on this ground. There is also right to object the processing of your Personal Data for direct marketing. Please note, that even if We receive Your objection, we will be permitted to continue processing the Personal Data in the event that (subject to applicable law): (i) Our legitimate interests for processing override Your rights, interests and freedoms; or (ii) the processing of such Personal Data is necessary to establish, exercise or defend a legal claim or right, etc.

Right of Non-Discrimination

Under the CCPA, you must not be discriminated for exercising any of your rights, including by denied goods or services, charging you with different fees for goods or services, including through the use of discounts or other benefits or imposing penalties; suggested you will receive a different price or rate for goods or services.

Notwithstanding the above it is allowed to set up schemes for providing financial incentives and you can opt-in to become part of them.

Response Timing and Format

We endeavor to respond to a verifiable consumer request with undue delay and according to applicable law (for example, within 30 days from the receipt of the request subject to GDPR and between 10-45 days from receipt of a request subject to CCPA). If we require more time, we will inform you of the reason and extension period in writing. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Data that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

Further, note, under the CCPA your rights only apply to the Personal Information collected 12 months prior to the request and you are not entitled to submit more than 2 requests in a 12 months period.

This Policy applies solely to your rights concerning Personal Data / Personal Information (as defined under the applicable law) processed by us.