Sample Privacy Policy

 

Welcome to [INSERT NAME OF VENUE] (the “Venue”, “we”, “us” or “our”). In providing our services to you we work with our vendor Roller Networks Pty LTD (“Roller”), a company that, together with its operating subsidiaries in the US (Roller Networks USA Inc.) and the UK (Roller Networks Limited), offers leisure and entertainment venues like ours an all-in-one cloud based platform (the “Roller Platform”) that helps us to deliver a better experience to our guests. These guests are individuals and families like you who interact with our domains, networks, applications, websites, kiosks or other devices we operate with or through the Roller Platform.

These interactions include purchasing Venue tickets or gift cards, attending Venue events, signing participation waivers, making reservations, completing Venue surveys, consuming goods or services that we offer, submitting an inquiry or posting on our page on social networks such as Facebook, LinkedIn or Twitter. We collectively refer to these as “Interactions”.

This Privacy Policy (the “Policy“) describes how we, the Venue, handle the personal data of our guests while using the Platform powered by Roller. It also describes the rights and options available to you with respect to your information.

 

CONTROLLER AND PROCESSOR

The Venue is the controller of the personal data described in this Policy.

 

Roller is merely the processor who processes the data on behalf of the Venue. It performs and operates the activities described in this Policy for us and on our behalf

Venue is the controller of your personal data described in this Policy. It determines the purposes and means of processing your personal data.

Roller is the data processor of your personal data on the Platform, processing the data on behalf of the Venue.

In the context of how we collect, process, transfer and keep your personal data secure as described in this Policy, Roller performs and operates these activities for us and on our behalf.

 

PERSONAL DATA WE PROCESS

We collect and process your contact information and address when you engage in Interactions with us.

When you interact with us, depending on the nature of the Interaction, we will process information such as your name, email address, phone number, residential address. If you interact with us for the benefit of friends or family members, we will process their information as well, where relevant.

We refer to this type of data as “Contact Information”.

We collect and process information about the substance and content of your Interactions with us, such as what you’ve purchased, events you attended and the content of your inquiries to us.

When you engage in Interactions with us, we process information about the nature and substance of the Interaction, such as tickets or gift cards you purchased or used, Venue events you attended, participation waivers you signed, reservations you made, Venue surveys you completed, goods or services you consumed, and the substance of the inquiry you sent us.

We refer to this data as “Engagement Information”.

You do not have a legal obligation to provide us your Contact Information or Engagement Information. However, if you choose to not share this information with us, we may not be able to sell you tickets, let you participate in Venue event, or respond to your inquiry.

We also collect analytics information and logs about how visitors use the Platform.

When you interact with the Platform through our domains, networks, applications, websites, kiosks or other devices we operate with or through the Roller Platform, we record and collect certain information about your interaction, including the IP address from which you access the Platform, time and date of access, type of browser used, language used, links clicked, and actions taken while using the Platform.

We refer to this data as "Analytics".

HOW WE PROCESS YOUR PERSONAL DATA

To operate, provide and maintain our Venue

We process Analytics and survey responses to provide, maintain and improve your user experience at our Venue, and to troubleshoot problems. We also will use the Analytics and survey responses for quality assurance and for development and enhancement of the Venue’s our domains, networks, applications, websites, kiosks, and other devices, as well as Roller’s and its Roller Platform.

To fulfill your requests and orders

We process your Contact Information and Engagement Information to administer your Interactions and fulfill your requests such as ticket purchase, participation in events, providing the goods or services you ordered from us, or responding to your inquiry.

We process your Contact Information and Engagement Information to communicate with you regarding your Interactions, including by sending you announcements, technical notices, updates, security alerts, support and administrative messages and responding to your inquiry.

We also will use your Contact Information to send your marketing communications about us and our offerings, if you asked to receive them.

To comply with applicable law and judicial orders and enforce our contractual engagement with you

We will process your information to prevent fraud, handle and resolve disputes, assist with any investigations, and enforce this Privacy Policy and our contractual engagement with you.

WHO PROCESSES YOUR PERSONAL DATA

We will not share your information with third parties, except in the events listed below or when you provide us your explicit and informed consent.

We will process information with our service providers helping us to operate Venue.

We will process personal information with the help of our service providers and Roller’s service providers who assist with our internal operations. These companies are authorized to use your personal information to provide these services to us and Roller, but not for their own promotional purposes.

We will share information with competent authorities, if you abuse your rights or violate any applicable law.

If you abused your rights, or violated any applicable law, we will share information with competent authorities and with third parties (such as legal counsels and advisors), for the purpose of handling of the violation or breach.

We will share your information if we are legally required.

We will share information if we are required to do so by a judicial, governmental, or regulatory authority.

We will share your information with third parties in any event of change in our structure.

If the operation of our company is organized within a different framework, or through another legal structure or entity (such as due to a merger or acquisition), we will share information as required to enable the structural change in the operation of our company.

SECURITY AND DATA RETENTION

We retain your information for as long as we need it for business purposes, and thereafter as needed for record-keeping matters.

We will retain your information for the duration needed to support our ordinary business activities in operating the Venue. Thereafter, we will still retain it as necessary to comply with our legal obligations, resolve disputes, establish, and defend legal claims and enforce our agreements.

We implement measures to secure your Information

We implement measures to reduce the risks of damage, loss of information and unauthorized access or use of information. These include encryption for data in transit and at rest. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure personal information, it is not guaranteed, and you cannot expect that the Website or Service will be immune from information security risks.

INTERNATIONAL DATA TRANSFERS

We will internationally transfer information in accordance with applicable data protection laws.

If we transfer your personal data for processing at locations outside your jurisdiction, we will abide by data transfer rules applicable to these situations.

ADDITIONAL INFORMATION FOR INDIVIDUALS IN THE EU OR UK

Legal basis under for processing your personal data.

The legal basis for processing Analytics and survey responses is our legitimate interest in maintaining, developing, and enhancing the Venue.

The legal basis for processing your Contact Information and Engagement Information for the purpose of administering your Interactions, fulfilling your requests and communicating with you regarding your Interaction, is our legitimate interests in fulfilling your requests and communicating with you.

The legal basis for processing your Contact Information for the purpose of sending your marketing communications is your consent.

The legal basis for processing your information for the purpose of handling instances of abusive use of the Website or the Service is our legitimate interests in defending and enforcing against violations and breaches that are harmful to our business.

The legal basis for processing your information where we are legally required to share it, is our legitimate interests in complying with mandatory legal requirements imposed on us.

The legal basis for processing your information in the event of a change in our corporate structure is our legitimate interests in our business continuity.

You have certain rights to access, update or delete information, obtain a copy of your information, and object or restrict certain data processing activities.

If you are in the EU or UK, you have the following rights under the GDPR regarding the information we process as a controller:

Right to Access your personal data and receive a copy of it.

Right to Rectify inaccurate personal data about you and to have incomplete personal data completed.

Right to withdraw consent, for our processing your Contact Information to send you marketing communications.

Right to Data Portability, that is, to receive the personal data that you provided to us, in a structured, commonly used, and machine-readable format. You have the right to transmit this data to another service provider. Where technically feasible, you have the right that your personal data be transmitted directly from us to the service provider you designate.

Right to Object, based on your particular situation, to use your personal data on the basis of our legitimate interest, including processing your information for marketing purposes. However, in cases other than processing your information for marketing purposes, we may override the objection if we demonstrate compelling legitimate grounds, or for the establishment, exercise of defense of legal claims. You may also object at any time to the use of your personal data for direct marketing purposes.

Right to Restrict the processing of your personal data (except for storing it) if: (i) you contest the accuracy of your personal data, for a period enabling us to verify its accuracy; (ii) you believe that the processing is unlawful and you oppose the erasure of the personal data and request instead to restrict its use; or (iii) we no longer need the personal data for the purposes outlined in this Privacy Policy, but you require them to establish, exercise or defense relating to legal claims, or if you object to processing, pending the verification whether our legitimate grounds for processing override yours.

Right to be Forgotten. Under certain circumstances, such as when you object to us processing your data and we have no compelling legitimate grounds to override your objection, you have the right to ask us to erase your personal data. However, we may still process your personal data if it is necessary to comply with a legal obligation, where we are subject to under laws in EU Member States or the UK, or for the establishment, exercise or defense of legal claims.

If you wish to exercise any of these rights, please contact us through the channels listed on our website.

We reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you the information that you have asked for, we will explain the reason for this.

You have a right to submit a complaint to the relevant supervisory data protection authority.

Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, particularly in the Member State of your residence, place of work or place of an alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.

If you are in the UK, you can lodge a complaint to Information Commissioner’s Office (ICO) pursuant to the instructions provided here.

CCPA INFORMATION FOR CONSUMERS RESIDING IN CALIFORNIA

This is the personal information we have collected over the past 12 months when we operate as a “business” under the California Consumer Privacy Act (CCPA):

Categories of Personal Information

Specific Types of Personal Information Collected

Source of Information

Identifiers

You name, address, phone number

The consumer themselves or another household member or acquaintance on their behalf

Information that identifies, relates to, describes, or is capable of being associated with, a particular individual

The subject of your inquiry or Interaction with us

The consumer themselves or another household member or acquaintance on their behalf

Commercial information, including products or services purchased, obtained, or considered

The subject of your Interaction with us regarding our products or services

The consumer themselves or another household member or acquaintance on their behalf

Internet or other electronic network activity information

IP address from which you access the Platform, time and date of access, type of browser used, language used, links clicked, and actions taken while using the Platform

The consumer’s device

The following are the CCPA business or commercial purposes for which we use each category of personal information. Details about the information we collect for each category are provided in the table above. More details about the business or commercial purposes are provided in the privacy policy’s section titled ‘HOW WE PROCESS YOUR PERSONAL DATA’.

Please note that we do not sell your data and we have not done so in the preceding 12 months.

Categories of Personal Information

Business or commercial purposes pursuant to the CCPA

Identifiers

Providing customer service, processing, or fulfilling orders and transactions, verifying customer information

Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, prosecuting those responsible for that activity

Undertaking internal research for technology development and demonstration

Undertaking activities to verify or maintain the quality of the Service and to improve, upgrade or enhance the Service

Debugging to identify and repair errors

Commercial information, including products or services purchased, obtained, or considered

Information that identifies, relates to, describes, or is capable of being associated with, a particular individual

Internet or other electronic network activity information

Disclosure of Personal Information We Collect About You. You have the right to know:

·       The categories of personal information we have collected about you;

·       The categories of sources from which the personal information is collected;

·       Our business or commercial purpose for collecting personal information;

·       The categories of third parties with whom we share personal information, if any;

·       The specific pieces of personal information we have collected about you.

Right to Deletion. Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will:

·       Delete your personal information from our records; and

·       Direct any service providers to delete your personal information from their records.

Please note that we may not delete your personal information if it is necessary to:

·       Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us;

·       Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;

·       Debug to identify and repair errors that impair existing intended functionality;

·       Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;

·       Comply with the California Electronic Communications Privacy Act;

·       Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the achievement of such research, provided we have obtained your informed consent;

·       Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us;

·       Comply with an existing legal obligation; or

·       Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided the information.

Protection Against Discrimination. You have the right to not be discriminated against by us because you exercised any of your rights under the CCPA. This means we cannot, among other things:

·       Deny goods or services to you;

·       Charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;

·       Provide a different level or quality of goods or services to you; or

·       Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.

Designate an authorized agent to submit CCPA requests on your behalf. You may designate an authorized agent to make a request under the CCPA on your behalf. To do so, you need to provide the authorized agent written permission to do so and the agent will need to submit to us proof that they have been authorized by you. We will also require that you verify your own identity, as explained below.

If you would like to exercise any of your CCPA rights as described above, you should contact us through the channels listed on our website.

We may ask you for additional information to confirm your identity and for security purposes, before disclosing the personal data requested to you, by using a two or three points of data verification process, depending on the type of information you require.

CHANGES TO THIS PRIVACY POLICY

If we change this Privacy Policy, we will make efforts to proactively notify you of such changes.

From time to time, we may change this Privacy Policy. If we do so, we will make efforts to proactively notify you of such changes. In any event, the latest version of the Privacy Policy will always be accessible on the Platform.

Last Update: ___