Your privacy is of the utmost important to us. We, at Sport Heroes (“SH”), have a few fundamental principles:
● We don’t ask you for personal information unless we truly need it.
● We don’t share your personal information with anyone except to comply with the law, develop our products and services, or protect our rights.
● We treat your personal information with the highest regard to privacy and security.
1. What is Sport Heroes and how does it work?
Sport Heroes offers a digital Service Platform aiming to encourage sport among its Users. The Platform is accessible from SH Sites and through SH Applications. These Services are developed by SH on their own behalf (Running Heroes, Cycling Heroes, Swimming Heroes and United Heroes) or on behalf of third parties (“Partners”).
SH guarantees continuity of access through all media to the Platform that we offer, both for SH Sites and for SH Applications. As such, SH is responsible for processing your Personal Data, its integrity, security and respect for your privacy in accordance with the Applicable Regulations.
Its contacts details are as follows:
18/20 rue du Faubourg du Temple, 75011 Paris – France
SH is committed to respecting your right to privacy and shares your concerns about the security of the data you transmit to us through the SH Sites, SH Applications and third-party Applications. This Policy sets out the guidelines established by SH to protect the information you provide to SH when you visit the Platform.
2. What information does Sport Heroes collect about me and how is it used?
In the context of the provision of Services, SH is required to collect personal data, within the meaning of Article 4 of the GDPR, concerning Visitors and Users (hereinafter referred to as “Personal Data”) under the conditions detailed below.
In particular, SH may collect the following Personal Data:
- About Visitors:
o Navigation data collected for the purpose of measuring audience and traffic under the conditions detailed in point 4 below regarding Cookies.
o Information constituting Personal Data voluntarily provided by the Visitor in the contact form and allowing them to contact SH in order to respond to their requests and ensure follow-up.
- About Users:
o Identification data that is provided by Users when creating their User Accounts, including, in particular, their last name, first name, e-mail address and password for the purpose of creating the account and managing SH’s relationship with Users, including in the context of evaluations of the Services by Users.
o Data which is voluntarily and optionally provided by the User on their User Account, such as gender, city and photograph, for the purpose of personalising the Services and Rewards.
o Data collected via third-party applications if the User chooses to connect them to the Platform, such as GPS and training data and navigation data collected under the conditions set out in point relating to Cookies, in order to provide the Services to Users.
None of the data collected by SH, nor information resulting from data processing, fall within the scope of health data as defined by the GDPR.
SH may aggregate this data in order to prevent identification of the persons concerned for statistical purposes and use it to improve the quality of its Services.
Finally, GPS data is stored pseudonymized to minimize as much as possible the potential impact on users privacy.
3. How long is data stored by SH?
SH keeps the Personal Data of Visitors and Users only for as long as is strictly necessary for the fulfilment of the above purposes, subject to compliance with its legal and regulatory obligations.
In particular, User Data is deleted immediately after a User Account is closed or after three years of inactivity.
4. What cookies does SH use?
Like most standard website servers, the Sites use log files built on the basis of Cookies. This includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, platform type, date/time stamp, and number of clicks to analyse trends, administer the Sites, track Visitors’ movement in the aggregate, and gather broad demographic information for aggregate use. SH may use your IP address to identify you, to administer the Site and the Applications to assist in diagnosing problems with SH’s server.
You can find a list of the cookies we use on our Sites and Applications below.
5. To whom, and how, does SH transfer my Personal Data?
5.1. Transfers outside the European Union
The data set is automatically backed-up every 12 hours and is securely stored by MongoDB Inc. in the US, a subscriber to Privacy Shield. Privacy Shield is a self-certification mechanism for companies established in the United States, which has been recognised by the European Commission as providing an adequate level of protection for personal data transferred by a European entity to companies established in the United States.
5.2. Transfer to third parties
A list of all third-parties to which we transfer a subset of data can be found in appendix.
In addition, in the context of certain Challenges, and subject to the User’s express consent, SH may transfer the User’s contact details to partner companies involved in the organisation of the Challenge. This partner company may then, in accordance with the consent given by the User, contact the User again for promotional and advertising purposes
Finally, in the context of a Partner Platform, the ownership of the data is shared between SH and the Partner. It is thus subject of a transfer to the aforementioned third party.
6. What does SH do to protect the data I transmit to SH?
The Sites use industry standard Transport Layer Security (TLS) technology to allow for the encryption of personal information such as your name and address. The Sites are also registered with site identification authorities so that your browser can confirm SH’s identity before any Personal Data is sent.
7. What can I do to help make sure the security works correctly?
To help ensure that these measures are effective in preventing unauthorized access to your private information, we invite you to familiarise yourself with the security features available to you through your browser. You should use a security-enabled browser to submit your personal information at the Sites.
Please note: if you do not use an SSL-capable browser, you are at risk of having data intercepted by unauthorised third parties. SH will not be responsible for any compromise of data that is intercepted due to your use of an unsecured browser.
Most browsers have the ability to notify you if you change between secure and insecure communications, receive invalid site identification information for the site you are communicating with, or send information over an unsecured connection. SH recommends that you enable these browser functions to help ensure that your communications are secure. You can also monitor the URL of the site you are visiting (secure URLs begin with https:// rather than the normal http://), along with the security symbol of your browser (a green or red padlock in Google Chrome for example) to help identify when you are communicating with a secure server. You can also view the details of the security certificate of the site to which you are connected. SHG encourages you to use this to check the validity of any site you connect to using secure communications.
8. Does SH offer opt-out or opt-in services?
Yes. If you no longer wish to receive emails from SH, please:
• follow the unsubscribe instructions available in every e-mail; or
• send an email to: firstname.lastname@example.org
If you do so, SH will not provide or share its mailing lists or other information about you with any other company or service for promotional purposes.
9. What are my rights?
In accordance with the Applicable Regulations, you have the right to access, rectify, modify, delete (right to forget), limit processing, object to and, where applicable, limit processing and portability (in JSON format) of personal data concerning you at any time and at no cost, subject to the rights and freedoms of third parties and the obligations incumbent on SH.
You also have the right to define directives regarding what should happen to your Personal Data after your death.
Where processing is based on consent, the Client may, at any time, notify their withdrawal of that consent, it being specified that any processing carried out prior to the withdrawal remains lawful.
Clients may exercise their rights:
• By sending an email to the following address: email@example.com; or
• By writing to the postal address: Sport Heroes Group 18/20 rue du Faubourg du Temple, 75011 Paris – France;
• Regarding the rights of rectification, modification and deletion, by configuring or updating their profile in “Edit your profile” from their Sport Heroes User Account.
If you believe that SHG has failed to comply with its legal obligations under the Applicable Regulations, you, or an organisation mandated for this purpose, may file a complaint with the CNIL or the supervisory authority of the European Union Member State in which you are ordinarily resident.
SH may change this Policy at any time, and you are therefore requested to review it regularly on the SH Sites and/or SH Applications you visit or use. In the event of a substantial change in the Policy concerning your rights, SH will inform you as soon as possible.
11. How to contact SH
SH welcomes your questions and comments. Send us your questions or comments by e-mail to the following address: firstname.lastname@example.org or contact our Data Protection Officer at the following e-mail address: email@example.com
● first name - public
● last name - public
● Email - private
● Gender - private
● Birthday - private
● Motto - public
● Language - public
● Picture - public
● Facebook - private
○ access token
● Google - private
○ access token
● Locations - public
○ Time zone
● Apps - public
○ profile id
○ profile URL
○ access token
● Company - private
● Business unit - private
● Bib number - private
● Phone number - private
● Postal address - private
● Shoe size - private
● T-shirt size - private 2. 2. Activities - public or private (user choice)
● Start date
● Time zone
● Active time
List of all third party providers to which we transfer data:
● AWS - Cloud Computing Services
● Algolia – Search service
● Braze – CRM
● MongoDB - Cloud hosted databases
● CloudAMQP - Cloud hosted databases
● Mailjet - Email as a Service
● Typeform – Online form
● Zendesk – Support service
● Adjust – Mobile marketing measurement
● Facebook, Twitter, Instagram and Google (in the context of marketing campaigns for consumer platforms, or after a contact with Sport Heroes on one of those providers website)
● Mixpanel – Product and User Behavioral Analytics for Mobile & Web
● Stream – Feed and Chat as a service
© 2019 United Heroes (Sport Heroes)