MAY 4, 2021

Welcome to Tiny-Panda.com’s Privacy Policy

 

Tiny-Panda.com cares deeply about the privacy of its customers and is fully committed to protect their personally identifiable information PII and use it properly in compliance with data privacy laws. This policy describes how we may collect and use PII, and the rights and choices available to our customers regarding such information.      

 

1.  Privacy Statement

This Tiny-Panda.com Privacy Policy (“Privacy Policy”) describes how we (Tiny-Panda.com, together with its affiliated companies worldwide, including B2CPrint Ltd.’s Order a Print Service wix.orderaprint.com – “Tiny-Panda”, “we” or “us”) collect and use information pertaining to each of our unregistered visitors and registered customers, including customers with Paid Services (each, a “Visitor” or “Customer” (respectively), or “you”), in connection with their access to and use of Tiny-Panda’s website and related services (collectively, the “Services”).  

 

The purpose of this Privacy Policy is to provide you with a clear explanation of when, why and how we collect and use your PII, as well as an explanation of your statutory rights.  This Privacy Policy is not intended to override the terms of any contract you have with us, nor any rights you might have under applicable data privacy laws. ​

By reading and understanding this policy, you consent to us collecting and processing your PII as defined in this policy. You can withdraw consent to any part of this policy by notifying us, however we will maintain legitimate interests for processing required PII when you enter into a contract with us.

 

2.  Personal Information we Collect

1.     PII, namely information that identifies a living individual or may with reasonable efforts cause the identification of a living individual. The collected by us consists of contact details (e.g., e-mail address or phone number), billing details (name, physical billing address, payment method and transaction details), which are only collected from Customers with Paid Services.

2. Special Category Data includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We do not seek to collect or otherwise process your Special Category Data

 

3. How do we collect PII  

1.   We collect information which you provide us. For example, we collect the PII you provide us when you register to our Services; when you sign into our Services via third party services such as Facebook or Google; when you place purchases; when you submit or upload such PII as you use any of our Services; and/or when you contact us directly by any communication channel (e.g., Tiny-Panda’s telephone, email). 

 

2.   We also collect information from third party sources as described in Section 6 below.

 

4. Why do we collect such information? 

We collect such   PII for the following purposes:

We will only use your PII for the purposes set out in Section 4 where we are satisfied that:

1.    our use of your PII is necessary to perform a contract

2.    our use of your PII is necessary to comply with a relevant legal or regulatory obligation that we have, or

3.    our use of your PII is necessary to support legitimate interests that we have as a business (for example, to maintain and improve our Services by identifying Customer trends and the effectiveness of Tiny-Panda campaigns and identifying technical issues), provided it is conducted at all times in a way that is proportionate, and that respects your privacy rights. ​

5. Where do we store your PII? 

Tiny-Panda Visitors’, Tiny-Panda Customers’ Personal Information may be maintained, processed and stored by Tiny-Panda and our authorised affiliates and service providers in the United States of America, where data is stored at Wix.com Data centre (Tiny-Panda data storage provider), for the proper delivery of our Services and/or as may be required by law (as further explained below).

 

Tiny-Panda.com is based in the United Kingdom, (not from 1st Jan 2021 if there is a no deal trade Brexit – see section 11 Security) Tiny-Panda affiliates and service providers that store or process your PII on Tiny-Panda’s behalf are each contractually committed to keep it protected and secured, in accordance with industry standards and regardless of any lesser legal requirements which may apply in their jurisdiction. You only hold PII when they enter into a contract, so you will hold PII. You may request deletion or access to your PII by contacting us. We will respond to your request within the timeframe imposed by the UK GDPR 2018.

6. Sharing PII with third parties 

Tiny-Panda may share your Personal Information with third parties (or otherwise allow them access to it) only in the following manners and instances:

 

6.1. Third Party Services: 

Tiny-Panda has partnered with a number of selected service providers, whose services and solutions complement, facilitate and enhance our own. These include printing services, delivery services, event management services and picture framing services, billing and payment processing services, fraud detection and prevention services, web analytics, e-mail distribution and monitoring services, session recording and remote access services, performance measurement, data optimization and marketing services and content providers (collectively, “Third Party Service(s)”).  Such Third-Party Services will have access to our Customers’ PII only depending on each of their particular roles and purposes in facilitating and enhancing our Services and business and may only use it for such purposes. This Privacy Policy does not apply to linked third party websites.

 

6.2. Law Enforcement, Legal Requests and Duties: 

Where permitted by local data protection laws, Tiny-Panda may disclose or otherwise allow others access to your PII pursuant to a legal request, such as legal proceedings, search warrant or court order, or in compliance with applicable laws, if we have good faith belief that the law requires us to do so, with or without notice to you.

 

6.3. Protecting Rights and Safety: 

Tiny-Panda may share your PII with others if we believe in good faith that this will help protect the rights, property or personal safety of Tiny-Panda, any of our Customers or any member of the general public, with or without notice to you.

 

6.4. Social Media Features and Framed Pages:

Our Services include certain Social Media features such as the “Facebook Connect” or “Google Sign-in”, the “Facebook Like” button, the “Share this” button or other interactive mini-programs (“Social Media Features”). These Social Media Features may collect information such as your IP address or which page you are visiting on our Website and may set a cookie to enable them to function properly. Social Media Features are either hosted by a third party or hosted directly on our Services. Your interactions with these third parties’ Social Media Features are governed by their policies and not ours. In addition, our Services may enable you to share your PII with third parties directly, such as via page framing techniques to serve content to or from Third Party Services or other parties, while preserving the look and feel of our Website and Services (“Frames”). Please be aware that if you choose to interact or share any PII via such Frames, you are in fact providing it to these third parties and not to us, and such interactions and sharing too are governed by such third parties’ policies and not ours.

 

7. Use of cookies and other tracking technologies 

Tiny-Panda, together with its marketing, analytics and technology partners, use certain monitoring and tracking technologies namely:  cookies, beacons, pixels, tags scripts, clear gifs, Flash and HTML5, Behavioural Targeting/Re-Targeting, Customer Data Supplementation and “Do Not Track” Signals). These technologies are used in order to maintain, provide and improve our Services on an ongoing basis, and in order to provide our Visitors and our Customers with a better experience. For example, thanks to these technologies, we are able to maintain and keep track of our Visitor’s and Customers’ preferences and authenticated sessions, to better secure our Services, to identify technical issues, Customer trends and effectiveness of campaigns, and to monitor and improve the overall performance of our Services.  

 

Please note that Third Party Services placing cookies or utilizing other tracking technologies through our Services may have their own policies regarding how they collect and store information. Such practices are not covered by our Privacy Policy and we do not have any control over them.   

8. Communications from Tiny-Panda 

8.1. Promotional Messages: 

We may use your PII to send you promotional content and messages by e-mail, text messages, direct text messages, marketing calls and similar forms of communication from Tiny-Panda or our partners (acting on Tiny-Panda’s behalf) through such means. If you do not wish to receive such promotional messages or calls, you may notify Tiny-Panda at any time or follow the “unsubscribe” or STOP instructions contained in the promotional communications you receive.

 

8.2. Service and Billing Messages: 

Tiny-Panda may contact you with important information regarding our Services, or your use thereof. For example, we may send you a notice if a certain Service is temporarily suspended for maintenance; reply to your support ticket or e-mail; send you reminders or warnings regarding upcoming or late payments for your current or upcoming subscriptions; or notify you of material changes in our Services. It is important that you are always able to receive such messages. For this reason, you are not able to opt-out of receiving such Service and Billing Messages unless you are no longer a Tiny-Panda Customer (which can be done by deleting your PII).

 

9. Your rights in relation to your PII

This section explains that you have a number of rights in relation to your PII. There are circumstances in which your rights may not apply. You have the right to request that we:

  • provide you with a copy of the information we hold about you.

  • update any of your PII if it is inaccurate or out of date. 

  • delete the PII we hold about you - if we are providing services to you and you ask us to delete PII we hold about you then we may be unable to continue providing those services to you. 

  • restrict the way in which we process your PII. 

  • stop processing your data if you have valid objections to such processing; and

  • transfer your PII to a third party. 

 

For more information on your rights and how to use them, or if you would like to make any of the requests set out above, please contact us. We will respond to all such requests within the time period required by law. Occasionally it may take us longer, if your request is particularly complex, you have made a number of requests or you have not supplied the information we need to respond to you. In this case, we will notify you and keep you updated.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that PII is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. 

Even if you consented to the processing of your PII for marketing purposes (by ticking the relevant box or by requesting information about services), you have the right to ask us to stop processing your PII for such purposes. You can exercise this right at any time by unsubscribing from the relevant communication channel, changing your preferences or by contacting us.

You will not have to pay a fee to access your PII (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

10. Data Retention

We may retain your PII for as long as your Customer database entry is active, as indicated in this Privacy Policy or as otherwise needed to provide you with our Services.

 

We may continue to retain such PII even after you cease to use any particular Service, as reasonably necessary to comply with our legal obligations, to resolve disputes regarding our Customers or to prevent fraud and abuse, enforce our agreements and/or protect our legitimate interests.

 

We maintain a data retention policy which we apply to information in our care. Where your PII is no longer required we will ensure it is securely deleted.

 

11. Security

Tiny-Panda has implemented security measures designed to protect the PII you share with us, including physical, electronic and procedural measures. Among other things, we offer HTTPS secure access to most areas on our Services; the transmission of payment information (such as a credit card number) through our designated purchase provider is protected by an industry standard SSL/TLS encrypted connection; and our provider regularly maintains a PCI DSS (Payment Card Industry Data Security Standards) certification. We also regularly monitor our systems for possible vulnerabilities and attacks, and regularly seek new ways and Third-Party Services for further enhancing the security of our Services and protection of our Visitors’ and Customers’ privacy.

 

Regardless of the measures and efforts taken by Tiny-Panda, we cannot and do not guarantee the absolute protection and security of your PII, or any Content you upload, publish or otherwise share with Tiny-Panda or anyone else. Furthermore, because certain areas on our Services are less secure than others (for example, since e-mail and instant messaging are not recognized as secure forms of communications, we request and encourage you not to share any PII on any of these areas or via any of these methods. If you have any questions regarding the security of our Services, you are welcome to contact us at privacy@Tiny-Panda.com.

 

The information that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA). When we transfer and store your PII outside of the EEA we will ensure that it is adequately protected by using appropriate safeguards as further detailed below.

Suppliers operating outside the EEA, may process the information. Such suppliers may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services;

Where your PII is transferred from the UK to a recipient outside the EEA in a country not recognised by the European Commission as providing an adequate level of protection for PII, such transfer shall be covered by a framework recognised by the relevant authorities or courts as providing an adequate level of protection for PII including but not limited to:

 

Standard Contractual Clauses (the agreement in the form annexed to the European Commission's decision of 5 February 2010 on Standard Contractual Clauses for the transfer of PII to processors established in third countries which can be found here); or

The EU-US Privacy Shield Framework. 

Unfortunately, the transmission of your PII via the internet is not completely secure and although we do our best to protect your PII, we cannot guarantee the security of your data transmitted to us over the internet and you acknowledge that any transmission is at your own risk. 

 

12. Updates and interpretation

We may update this Privacy Policy as required by applicable law, and to reflect changes to our information collection, usage and storage practices. If we make any changes that we deem as “material” (in our sole good faith discretion), we will notify you prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices. Unless stated otherwise, our most current Privacy Policy applies to all information that we have about you, with respect to our Website and Services.

 

This Privacy Policy was written in English and may be translated into other languages for your convenience. You may access and view other language versions by changing your Tiny-Panda Website language settings. If a translated (non-English) version of this Privacy Policy conflicts in any way with its English version, the provisions of the English version shall prevail.

 

13. Contacting us

If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact the Data Protection Office at tiny.panda@tiny-panda.com. We will attempt to respond to questions regarding the use of your PII in accordance with this Privacy Policy.

Privacy Policy