Last updated: 30 March 2021
OUR COMMITMENT TO YOUR PRIVACY
Your privacy is our priority. We appreciate that you entrust us with your personal data and want you to know that we respect your privacy. Our privacy practices are based on these core principles:
- We design our platforms and services with your privacy in mind.
- We strive for transparency about how we process your personal data. We work hard to provide clear and straightforward descriptions of our privacy practices because we want you to understand them.
- We are dedicated to the protection of your personal data. We continually assess data security risks and test and monitor our security practices to protect against them.
To learn how you can exercise your privacy rights:
- For everyone else, please see “How Does UNiDAYS Honour Privacy Rights Requests?” below.
WHAT IS UNIDAYS?
UNiDAYS works with brands that want to advertise their products and services to our Members. We refer to these brands as our “Partners”. Through the Platform, Members have access to exclusive promotions, discounts, and other exciting offers from Partners (“Offers”). Members may also have access to available sweepstakes, contests, volunteer opportunities, polls, surveys, subscriptions, exclusive content, and other online and in-person opportunities and events.
WHAT INFORMATION DOES UNIDAYS COLLECT AND WHY?
We collect five main categories of personal data:
1. Personal data that you provide to UNiDAYS
A Member’s email address is required to create a UNiDAYS account. Other personal data collected through Member accounts or use the Platform are:
- Email Address (required)
- University/College/Academic Institution
- Enrollment Status
- Student ID Card
- Telephone number
- Birthday or Age
- Photographs of yourself, such as on your Student ID or when you allow UNiDAYS to access your photos through the App
- Customer service communications
- Preferences, opinions, and other details about yourself that you choose to share in your responses to surveys or during focus groups or discussions, such as through our online community known as “The Counsel” Some of the personal data you choose to share, such as your ethnicity or gender identity, are sensitive so we urge caution when publicly sharing these data.
- Personal data shared with other Members through the Platform
We collect these personal data for the following purposes:
- To verify identity and eligibility for membership
- To create Members’ accounts
- To send information about Offers that we think will interest Members. Some Offers presented to a Member are personalized based on the information associated with that Member’s account.
- To track rewards and points.
- To administer sweepstakes (also known as giveaways), contests, polls, surveys, and events in which Members choose to participate
- To respond to correspondence and requests, such as Member interactions with our Customer Service team
- To learn how Members interact with the Platform so that we can improve the Platform, develop new features, and identify which Partners’ Offers are most popular with Members
- To process a Member’s application to become a UNiDAYS blogger, influencer, or other content creator
- To present volunteer and internship opportunities for Members
- To obtain feedback and provide customer service about Offers, Partners, and the Platform in general
- To detect and protect against spam, fraud, or unauthorized use of the Platform
- To monitor and enforce compliance with our legal agreements
2. Automatically-collected Personal Data
Automatically-collected data include:
- Technical information: IP or MAC address, device make, model and operating system, mobile network information, internet service provider, unique device identification number, advertising ID, browser type and language, geographic location (e.g., country or city-level location or time zone);
- Log-in events (i.e., when you log into and for how long use the Platform) and "click stream" data, which are data about how your computer or mobile device interacts with the Platform; and
- Interactions with Offers, polls, surveys, and other content on the Platform.
Automatically-collected data help us understand how Members and visitors who are not Members use the Platform. Specifically, we use automatically-collected data:
- For analytics to enhance how Members use the Platform or a laptop;
- To evaluate the performance of Offers and other content, such as which Partners and types of Offers are most popular;
- To improve the quality and relevance of the Platform for Members, such as by showing or offering Members Platform content based on their preferences inferred from clickstream data (with consent where necessary);
- To present Offers and information that we believe are tailored to the interests of particular categories of Members;
- To help resolve technical issues and develop and update the Platform;
- To detect unauthorized use of the Platform and/or distribution of Platform content;
- For customer service; and
- For billing purposes, so that we can bill our Partners for the services that we provide.
3. Information Collected through the App
When you download, access, or otherwise use our App, the data that we collect depends on your device and your in-App and operating system settings.
The App must access certain data on your mobile device in order to function but the App’s settings enable you to check or change your status for certain data collection. If you do not wish the App to access data on your mobile device, then please uninstall the App. Also, if you change your settings, certain App features may not function properly.
When you agree, the App may collect the geo-location of your mobile device and access to photos stored on your mobile device. If you choose via the App settings, you can receive push notifications from UNiDAYS.
We collect logs and usage statistics from and about your mobile device. For example, we record when you open the App so that we can monitor when, how the App is used and if/when the App stops working to help us identify and fix the cause.
When you download the App from Apple's App Store or Google Play (each, an "App Platform"), you acknowledge and agree that:
- As between UNiDAYS and the App Platform, UNiDAYS is solely responsible for the App.
- The App Platform has no obligation to provide any maintenance and support services with respect to the App.
- If our App fails to conform to any applicable warranty: (i) you may notify the App Platform and the App Platform may refund the purchase price for the App (if applicable), (ii) to the maximum extent permitted by applicable law, the App Platform will have no other warranty obligation whatsoever with respect to the applications, and (iii) any other claims, losses, liabilities, damages, costs or expenses attributable to any failure to conform to any warranty is, as between UNiDAYS and the App Platform, UNiDAYS' responsibility.
- The App Platform is not responsible for addressing any claim you have relating to the App or your possession and use of the App.
- If a third party claims that the App infringes another party's intellectual property rights, as between the App Platform and UNiDAYS, UNiDAYS is responsible for the investigation, defense, settlement, and discharge of any such intellectual property infringement claim.
- You must also comply with all third-party terms applicable through the App Platform when using the App.
To learn more about the specific data collected by the App, please check your mobile device settings or review the disclosures on the App Platform (defined below) from which you downloaded the App. To stop the collection of all data through the App, please uninstall it.
4. Data from third parties
From time to time, we may receive personal data about you from Partners and other third-party data sources (including publicly available sources). We may receive data about your interactions with a Partner’s website or app when you click through an Offer to make a purchase. We use this data for billing purposes so that we can bill our Partners for the services that we provide. The data we receive from third parties also are used to learn more about our Members, to tailor Members’ experiences on the Platform, to recommend Partners and Offers that we think will interest particular Members, and to improve the quality of the Platform content. Regarding subscriptions, we may receive identifying information (e.g. session ID or customer ID) from Stripe (a payment processor) to confirm your eligibility to use the related services. These data also help us to monitor and analyze trends and Platform use so that we can better manage our technology infrastructure and detect and protect against fraud or unauthorized use of the Platform.
When we combine data from third-party data sources to enhance the data that we hold about you, we require that each third-party data source confirm that its sharing of personal data with UNiDAYS is transparent and lawful.
5. Data related to Targeted Advertising
We display and help our Partners display targeted advertising using data collected when Members and visitors interact with the Platform. Targeted ads (also sometimes referred to as personalized or interest-based ads) are displayed based on information generated by online activity, such as purchasing through the Platform, use of the Platform on more than one device, visiting sites that contain Partners’ content, ads, or cookies and the websites that you visit before and after you log on to the Platform. You can opt out of receiving UNiDAYS’ targeted ads on the Platform here. You will still see ads but they may not be personalized to you.
Some web browsers (including Safari, Internet Explorer, Firefox, and Chrome) incorporate a “Do Not Track” (“DNT”) or similar feature that signals to websites that a browser’s user does not want to have his or her online activity tracked. If a website that responds to a particular DNT signal receives the DNT signal, the browser can block that website from collecting certain information about the browser’s user. Not all browsers offer a DNT option and DNT signals are not yet uniform. For this reason, many website operators, including UNiDAYS, do not respond to DNT signals.
WE DO NOT KNOWINGLY COLLECT INFORMATION FROM CHILDREN UNDER AGE 16. The Platform is not intended for use by children under age 16. If you are under the age of 16, please do not use or attempt to use our Platform or provide any personal data to us. If you learn or suspect that anyone under age 16 has provided UNiDAYS with personal data, please notify email@example.com.
HOW DOES UNIDAYS SHARE PERSONAL DATA?
We share personal data with the following categories of recipients:
- Professional advisors, such as lawyers, accountants, and information security and forensics experts;
- Partners and other Platform advertisers as needed to process orders and payments;
- Marketing vendors that help UNiDAYS promote the Platform and from time to time supplement personal data that we already have. For example, Facebook receives and uses certain data related to use of the Platform to help us deliver personalized advertising and assess the effectiveness of our advertising;
- Our contractors and vendors to enable them to work for us, including without limitation those who perform data analytics and test, monitor, secure, and enable the Platform and services. For example:
- Iterable receives and uses our data to assist us with marketing email campaigns
- Kevel receives and uses our data to deliver personalized advertising to Members
- Competent law enforcement, government regulators, courts, or other third parties when we believe disclosure is necessary (i) to comply with law, (ii) to exercise, establish or defend our legal rights, or (iii) to protect the vital interests of Members, Partners or another third party;
- Our affiliates; and
- to any other third party with your permission.
Third parties also may access certain personal data using OAuth and other similar protocols when you choose to log into the Platform using your log-in information from other services or when you receive a third party’s notification or ‘prompt’. We can use OAuth and similar protocols to share our data about you without sharing your security credentials.
WHAT ARE UNIDAYS’ LAWFUL BASES FOR PROCESSING PERSONAL DATA?
Under EU data protection law, UNiDAYS may collect and process your personal data only when UNiDAYS follows the lawful bases specified in EU data protection law and informs you of the specific lawful bases on which UNiDAYS relies.
The lawful bases on which UNiDAYS relies are:
- Consent: we process your personal data when you provide your consent
- Performance of a contract: UNiDAYS operates the Platform and related services on the basis of a contract with you, which are our Terms of Service.
- Our legitimate interests: UNiDAYS may base the processing of personal data on our legitimate business interest in operating the Platform and related services and analyzing how they are used and improving and creating new services and products, which benefit our Members and Partners, and promoting UNiDAYS. Other legitimate interests are to prevent and detect fraud, to retain evidence of our compliance with law and to defend UNiDAYS against legal claims or fraud. When we rely on our legitimate interests as our basis for processing personal data, we balance our interests with strong privacy protections designed to minimize the risks to our Members, visitors, and others.
- Compliance with a legal obligation.
If we ask you to provide personal data to comply with a legal obligation or to perform a contract with you, we may not be able to comply with our legal obligation or enter into or perform the contract if you do not provide that personal data. For example, when we ask you to provide your email address, we need that data to verify that you are eligible to use the Platform. We will advise you whether providing your personal data is mandatory and the possible consequences if you do not provide your personal data.
If another legal basis or legitimate interest is relevant to particular personal data processing, we will make that clear when we collect that personal data. If you have questions or need further information concerning the legal basis on which we process your personal data, please contact us using the contact details provided under the “How Do I Contact UNiDAYS?” heading below.
- If you are located in the European Economic Area or the U.K., the data controller for the personal data that UNiDAYS collects is MyUnidays Ltd of 2 Castle Boulevard, Nottingham, United Kingdom NG7 1FB. The ICO registration number is Z2692580
- If you are located in the U.S. or Canada, the legal entity responsible for personal data processing is UNiDAYS, Inc., 434 W 33rd St., Suite 830, New York, NY 10001-2601, United States
- For all other jurisdictions, the legal entity responsible for personal data processing is MyUnidays Limited of 2 Castle Boulevard, Nottingham, NG7 1FB.
Our Data Protection Officer is available via firstname.lastname@example.org. Our EU representative is available at email@example.com.
EU residents: If you have a complaint related to UNiDAYS processing of your personal data, you may submit a complaint to the Supervisory Authority of the EU Member State of residence or where the issue that is the subject of the complaint occurred. We hope you will allow us to address your concerns before you approach a Supervisory Authority, but otherwise the contact details of the EU Supervisory Authorities are available at https://edpb.europa.eu/about-edpb/board/members_en.
HOW DOES UNIDAYS HONOUR PRIVACY RIGHTS REQUESTS?
For personal data for which we are the data controller, we honour the following privacy rights in accordance with applicable law:
- If you wish to review, correct, update, suppress, restrict or delete your personal data:
- You can object to the processing of your personal data, request restrictions on the processing of your personal data, or request portability of your personal data. To exercise these rights, please contact us using the contact details provided under the “How Do I Contact UNiDAYS?” heading below.
- You can opt-out of (or unsubscribe from) UNiDAYS’ email marketing communications by clicking the “unsubscribe” or “opt-out” link in one of our marketing emails or through your account settings. Please note that you cannot unsubscribe from certain communications, such as messages relating to your account transactions, non-promotional messages, business relationships, or system updates or system issues.
- If we process your personal data based on your consent, then you can withdraw your consent at any time by contacting us using the contact details provided under the “How Do I Contact UNiDAYS?” heading below. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal data conducted in reliance on lawful basis other than consent.
- If we process your personal data based on our legitimate interests, you have the right to object to that processing, subject to certain exceptions, by contacting us using the contact details provided under the “How Do I Contact UNiDAYS?” heading below.
- When our processing of your personal data results in automated decisions, such as which ads or content to show you, we do not intend that these decisions legally affect or significantly affect you. By automated decision, we mean that a decision concerning you is made automatically on the basis of computer algorithms without our human review. If we make an automated decision about you that legally affects or otherwise significantly affects you, you have the right to ask us to review the decision and to require a human review of the decision. You can learn about and exercise this right by contacting us using the contact details provided under the “How Do I Contact UNiDAYS?” heading below.
We will review your request as soon as reasonably practicable and respond within the time periods required by applicable law. In any request you submit to us, please make clear the personal data that are the subject of your request.
We respond to all requests we receive from individuals wishing to exercise their privacy rights in accordance with applicable data protection laws. Please know that the rights described above are not automatic rights and may not apply in all circumstances. When this occurs, we will notify you in our response to you.
For your protection, if you are a Member, we only fulfil requests for the personal data associated with the email address in your account and, if you are not a Member, we only fulfil requests for the personal data associated with the email address that you use to send us your request. We may need to request information from you to help us confirm your identity and ensure your right to access personal data. When we make these requests for more information, we do so as a security measure to ensure that your personal data are not disclosed to someone who has no right to receive your personal data. We also may contact you to ask you for further information in relation to your request to speed up our response.
Keeping your personal data – particularly your email address – accurate and current is important. Please update your account and/or contact us if your personal data changes during your relationship with us.
Please note that we may need to retain certain personal data for recordkeeping purposes and/or to complete a transaction that you began prior to requesting a change or deletion, such as fulfilling a prize in a sweepstakes. Our databases and other records may have residual personal data which we cannot and will not remove. We also may not allow you to review certain personal data for legal, security, or other similar reasons.
Generally, no fee is associated with exercising your privacy rights but UNiDAYS may charge a reasonable fee if your request is unfounded, repetitive, or excessive.
WHERE DOES UNIDAYS PROCESS PERSONAL DATA?
Your personal data may be transferred to and processed someplace other than where you live. These other jurisdictions may have privacy laws that are different from the laws of where you reside (and, in some cases, not as protective).
Our servers are primarily located in Ireland but we store and replicate your personal data on servers in other places in order to provide speed of access, robustness, and protection against server failure. The other primary jurisdictions where personal data are processed by or on behalf of UNiDAYS are the United States of America and the United Kingdom.
HOW DOES UNIDAYS PROTECT PERSONAL DATA?
Like any other organization, UNiDAYS cannot fully eliminate security risks associated with the processing of personal data but UNiDAYS uses technical, physical, and administrative safeguards intended to protect the personal data that we process. Our safeguards are designed to provide a level of security appropriate to the risk of processing your personal data and include (as applicable) measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and a procedure for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing of personal data.
You are responsible for maintaining the security of your account credentials. UNiDAYS will treat access to the Platform through your account credentials as authorized by you.
We may suspend your use of all or part of the Platform without notice if we suspect or detect any breach of security. If you believe that information you provided to UNiDAYS or your account is no longer secure, please notify us immediately at firstname.lastname@example.org.
If we become aware of a breach that affects the security of your personal data, we will provide you with notice as required by applicable law. When permitted by applicable law, UNiDAYS will provide this notice to you through the email address associated with your account.
UNAUTHORIZED ACCESS TO PERSONAL DATA AND THE PLATFORM – INCLUDING SCRAPING – IS PROHIBITED AND MAY LEAD TO CRIMINAL PROSECUTION.
FOR HOW LONG WILL UNIDAYS RETAIN PERSONAL DATA?
UNiDAYS will only retain your personal data for as long as we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements or to protect against fraud). We may retain your personal data for a longer period to address a complaint or if we reasonably believe that litigation in respect to our relationship with you is possible.
When we have no ongoing legitimate business need to process personal data, we will either delete or anonymize that personal data. If you are a Member, UNiDAYS’ policy is to delete or anonymize your personal data three (3) years after your membership expires.
If we are not able to delete or anonymize certain personal data (for example, because your data are stored in backup archives or due to a legal requirement), then we will securely store the personal data and isolate the data from any further processing until deletion or anonymization is feasible.
HOW DO I CONTACT UNIDAYS?
- By Email: email@example.com or firstname.lastname@example.org
- By Post: MyUnidays Ltd, ℅ DPO, 2 Castle Boulevard, Nottingham, United Kingdom NG7 1FB
Our European Representative is Planit Legal.
- By Email: email@example.com
- By Post: Jungfernstieg 1 20095 Hamburg.