APP PRIVACY POLICY

We're Heart Brands UK Limited, with registered office at Orion Gate, Guildford Road, Woking, Surrey GU22 7NJ. We are registered with the ICO with registration number ZA392588.

We’ve worked hard to create a privacy policy for our App that’s easy to read, and clear. Our Web Application privacy policy is available here. But if you have any questions, feel we’ve overlooked something or missed an important perspective, we’d love to hear from you. Please get in touch with us by emailing us at privacy@heartstyles.com 

This policy was last updated on 12 May 2023.

How do you use my data?

When you download and use our App using your Heartstyles credentials or via single sign on,  we collect personal information provided by you while journaling or creating tasks, actions and goals, your reflections and other data you choose to add to the App. We only process your personal data via our App if you have given us your consent to do so. We use your personal data to create and store your profile preferences and provide you with tailored information about your personal development reports and daily reflections.

To create customised reports for you, we may combine this personal data with other information received about you from others, such as Heartstyles indicator feedback provided by your colleagues. The results of your Heartstyles indicator and the feedback/commentary about you from others will never be shared with your employer.

We use a provider called Mixpanel to understand how users use our App. The data we obtain from using Mixpanel doesn't directly identify you – it helps us understand how far through the Heartstyles journey you are, and enables us to anonymously report back to your employer how their employees are progressing through their Heartstyles journey.

Who do you share my data with?

Regulators, Authorities and Enforcement Agencies if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of our clients or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.

Where do you store my data?

We store your data on Amazon Web Services servers, located in Dublin, Ireland.

When working with third parties we may need to transfer your personal data outside of the UK and / or EU. Whenever we transfer your personal information outside of the UK and the EU, we ensure it receives additional protection as required by law. To keep this policy as short and easy to understand as possible, we haven’t set out the specific circumstances when each of these protection measures are used. You can contact us at privacy@heartstyles.com for more detail on this.

How long do you keep my data for?

We will only retain your personal data for as long as we need it unless we are required to keep it for longer to comply with our legal, accounting or regulatory requirements.

You can ask us to delete your data at any time by contacting us at privacy@heartstyles.com. We delete your personal data 6 years after you last logged into the platform and completed your Heartstyles indicator with us. If your employer notifies us that you’re no longer an employee, we will also delete your data shortly after we're notified.

In some circumstances we may carefully anonymise your personal data such as your feedback related to the profiles of other individuals, so that it can no longer be associated with you, and we may use this anonymised information indefinitely without notifying you. We use this anonymised information to improve our business, and understand trends and statistics.

What are my rights under data protection law?

You have various other rights under applicable data protection laws, including the right to:

Please keep in mind that privacy law is complicated, and these rights will not always be available to you all of the time.

You also have the right to lodge a complaint with us or the Information Commissioner's Office, the supervisory authority for data protection issues in England and Wales. If you are based in the EU you can find your relevant supervisory authority here.