1.2 BDA is committed to protecting your privacy. This Policy describes what we do with your data and applies to all processing of data that identifies you or may be used to identify you with (“Personal information”) by BDA, such as but not limited to processing via the BDA Free VPN – Private Search Application (hereinafter: “BDAVPN”). BDA complies with the European General Data Protection Regulation (hereinafter: “GDPR”)
1.3 BDA may amend this Policy at any time. In case the Policy is amended, the amended Policy will be made available to you through publication of the amended Policy on the Website. Should you have any questions after reading this Policy, or would like to exercise the rights as entailed in this Policy, please contact BDA via the above stated details.
2 What Personal information do we process?
BDA is a data controller under the GDPR. This means that with regard to any Personal information referred to in this Policy, we are responsible for determining the purpose for which we process this data, and determine the means necessary for the processing of this data. As a data controller, we process the data set out in this section.
(i) Information related to your account (“personal information”)
This information is collected for the purpose of administering your BDAVPN subscription and includes your name, email address, and payment information, which you submit on our order page when you subscribe for the Services.
BDAVPN collects personal information that you provide to us directly through the Site. We require that you provide personal information, such as an email address and payment information, in order to establish an BDAVPN account, and so that we can email you, collect payments from you, and respond to support queries that you initiate. The specific information collected varies depending on the payment method you choose.
BDAVPN uses your email address for the following reasons:
- To send emails related to payment transactions.
- To provide links to our Site, including password reset emails.
- To send you updates and announcements.
- To communicate with you about your VPN services or respond to your communications.
- To send marketing information, such as BDAVPN offers, surveys, invitations, and content about other matters in connection with BDAVPN (“Marketing emails”). You may choose to not receive Marketing emails by following the opt-out procedure described in these emails.
(ii) Aggregate Apps and VPN connection summary statistics
BDAVPN collects minimal information about usage in order to maintain excellent customer support and quality of service. The section below specifies in detail what information we collect. These statistics never include anything about what the user did with the VPN: no data about the contents or destinations of VPN traffic, no DNS queries, and no IP addresses.
We ensure that we never log browsing history, traffic destination, data content, IP addresses, or DNS queries. Therefore:
- We do not know which user ever accessed a particular website or service.
- We do not know which user was connected to the VPN at a specific time or which VPN server IP addresses they used.
- We do not know the set of original IP addresses of a user’s computer.
Should anyone try to compel BDAVPN to release user information based on any of the above, we cannot supply this information because the data don’t exist.
In order to maintain excellent customer support and quality of service, BDAVPN collects the following information related to your VPN usage:
Apps and Apps versions
We collect information related to which Apps and Apps version(s) you have activated. Knowing your current version of the Apps allows our Support Team to troubleshoot technical issues with you.
We collect information about whether you have successfully established a VPN connection on a particular day (but not a specific time of the day), to which VPN location (but not your assigned outgoing IP address), and from which country/ISP (but not your source IP address). This minimal information assists us in providing technical support, such as identifying connection problems, providing country-specific advice about how to best use our Service, and to enable BDAVPN
engineers to identify and fix network issues.
Aggregate sum of data transferred (in MB)
We collect information regarding the total sum of data transferred by a given user. Although we provide unlimited data transfer, if we notice that a single user pushes more traffic than thousands of others combined, thereby affecting the quality of service for other BDAVPN users, we may contact that user for an explanation.
(iii) (User-controlled option): Anonymous app diagnostics, including crash reports
App diagnostic data, which include crash reports, usability diagnostics, and VPN connection diagnostics, are anonymized and cannot be tied back to individual BDAVPN users. This feature is similar to a “send bug report” option. Users can specify in the settings menu of any BDAVPN App whether to send these data to us.
3 For what purposes do we process Personal information?
3.1 Primary purposes for which we process your Personal information are to offer you the best services possible, to optimize our BDAVPN and services and to ensure continuity thereof. More specifically, your personal details can be used for the following purposes:
- To provide our services: this may seem rather obvious, but we may need certain information about you in order to be able to provide our services. However, as set out above, identifying you as a user is not our main intention. It is however unavoidable that we process certain data such as IP-address, device identifier and other automatically collected Personal information as set out above.
- To customize our services: you have the option to customize the BDAVPN experience to your needs. In order to be able to remember your customizations, we may process Personal information about you, such as a unique ID and your IP address.
- To improve our services: our BDAVPN and services are constantly involving, and we are constantly working on improving your user experience and adding new functionality to our BDAVPN. Processing among others analytics data (in an aggregated form) is essential to this.
- To secure our services: in order to be able to provide your with the best user experience possible, it is necessary to keep out ‘the bad guys’, such as hackers, automated bots or other threats. We are therefore constantly monitoring our services and the use of our services. When we identify a possible threat, we may take immediate action in order to avoid disruption or wrongful or fraudulent use of our services.
- To communicate with you: when you contact us, we process your contact details such as name and email address and any other Personal information you may provide to us in order to be able adequately revert to you on your enquiry.
- For marketing purposes: data on your visit to our BDAVPN may be used by our advertisement partners in order to serve you with advertisements about our services elsewhere. As indicated, we do not use any behavioural targeting or profiling techniques.
- To exercise and safeguard our rights: though we trust you will use our BDAVPN and services in accordance with the law and our terms of service, we may need to exercise our legal rights among others in case you infringe our intellectual property, engage in fraudulent acts or act in violation of this Policy or our terms of service.
- Compensation of our partners: as we show and run advertisements certain Personal information may be needed in order to calculate the compensation to be paid to or received by or from our partners.
- To comply with a legal obligation: we may be required by law or by a court order to process (and/or transfer) certain Personal information.
3.2 We have multiple legal grounds for the processing of your Personal information. Applicable legal grounds are listed below:.
- Execution of a contract with you: most processing activities are carried out in order to provide you with our services. We provide our services on the basis of our terms of service, a contract entered into with you when using our services.
- Your consent: should certain processing activities not be related to our contract with you, we may process your Personal information on the basis of your consent.
- Compliance with a legal obligation: we may under certain circumstances be legally required to process your Personal information.
- Our legitimate interests: your Personal information may be processed by us for purposes of our legitimate interests, such as our commercial interests. This may be the case with among others (re)marketing and compensation of our partners.
4 Who may receive your Personal information?
4.1 BDA may transfer your personal inform to third parties, being:
- Group companies: we may provide Personal information to other companies within the BDA group of companies, if this is necessary for compliance, internal reporting, auditing or security purposes.
- Advertisement partners: Information on your BDAVPN visit may be provided to advertisement partners in order to serve you with (relevant) advertisements on our BDAVPN and elsewhere, and to measure effectiveness of advertisements.
- Law enforcement agencies: we may be under an obligation to provide your information to law enforcement, regulators, courts or other public authorities in relation to an official (court) order. In addition we may provide your data to law enforcement agencies, regulators, courts or otherwise in order to exercise our rights.
- Fraud prevention: we may engage third parties in order to investigate or prevent any fraudulent acts or to protect our assets and/or rights.
5 How long do we store your Personal information?
5.1 We retain your Personal information for as long as necessary in order to fulfil the associated purpose as set out above. After that, we may retain your Personal information if this is required or necessary in order to comply with applicable law or in order to be able satisfy any legal, reporting or audit requirements. Where possible we anonymize or pseudo-anonymize your Personal information or retain it in an aggregated form only.
6 How do we secure your Personal information?
6.1 We highly value the security of your Personal information. Therefore we have implemented technical and organizational measures to protect your Personal information against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. To keep your Personal information safe, the following measures are implemented:
- Encrypt the transfers of data via the BDAVPN;
- Protect the servers on which your Personal information is stored with passwords and appropriate security measures;
7 Cookies and Mobile Identifiers
What is a cookie?
A cookie is a small text file used to store information about your visit to the Site. Cookies let BDAVPN optimize and improve the user experience of the Site by helping us deliver certain functionalities, such as website login and language settings. The cookies we use may vary over time as we continuously update and improve our Site.
You are free to change your cookie preferences at any time. You can do this in the settings panel for your browser. Depending on which browser and device you use, you may be able to control which cookies you allow, which cookies you want to block in the future, and delete cookies. For more information about these settings, please refer to the “help” section of your browser. Note that BDA’s Site may not work as intended if you choose to disable cookies.
The cookies set by BDAVPN enable us to set your language preference, attribute visitors to a marketing channel, and, once you log in, securely show you information that is specific to your account. The cookies contain a user identifier, but no directly personally identifying information such as your name or email address, and do not track any activity outside of BDA domains.
BDAVPN uses third-party services such as Google Analytics and Adwords. Cookies from such services are used to collect data for statistical reports. For example, we may generate reports regarding the amount of time users spend on the Site and the number of users who visit a particular page.
BDAVPN uses Google AdWords remarketing to show advertisements on third-party websites (including Google) to users who have visited our Site. We may show such users advertisements on a Google search results page, or on a site in the Google Display Network.
A mobile identifier is an identifier provided by an Android or iOS device. It does not contain your name or email address. BDAVPN uses mobile identifiers to generate statistics related to the marketing channels and advertising partners through which users learned about and signed up for BDAVPN mobile apps.
Disabling or resetting mobile identifiers
Users may disable or reset the mobile identifiers associated with their devices at any time. For instructions, see Apple’s page on Advertising & Privacy on iOS devices and Google’s page on Managing your Google Settings on your Android device.
The Site may contain links to external websites that do not fall under BDAVPN’s domain. BDAVPN is not responsible for the privacy practices or content of such external websites.
8 What are your rights?
8.1 Applicable data protection laws and regulations guarantee you certain rights:
- Objection: Depending on the situation, you have the right to consent or object to the processing of your Personal information and the conditions under which this processing takes place.
- Access: You have the right to request from us, without constraint, at reasonable intervals and without excessive delay or expense, i) a confirmation as to whether or not Personal information regarding you is being processed, ii) information on the purposes for which Personal information is processed, iii) the categories of Personal information concerned, and iv) the recipients or categories of recipients to whom the Personal information is disclosed. You have the right to receive, in an intelligible form, a communication of the Personal information being processed and of any available information as to the source(s). Furthermore, you have the right to knowledge of the underlying logic of the automated processing of Personal information relating to you.
- Rectification, erasure, blocking or deletion: You, where appropriate, have the right to rectification, erasure, blocking or deletion of your Personal information that is not processed in compliance with data protection laws and regulations, in particular when the nature of the data is incomplete or inaccurate.
- Notification: You have the right to a notification to third parties to whom your Personal information has been disclosed, when you have been granted any rectification, erasure, blocking or deletion as stated above, unless such notification proves to be impossible or requires a disproportionate effort from us.
- Withdraw consent: where we are processing Personal information relating to you on the basis of your prior consent to that processing, you may withdraw your consent at any time.
- Complaint with relevant authority. You have the right to file a complaint with the relevant data protection authorities, e.g. the Autoriteit Persoonsgegevens in the Netherlands.
8.2 In order to fulfil your possible requests pursuant to the rights as stated above, we may request specific additional information from you to identify you with or we may ask you for information to identify you with. We only collect and process such specific data with the purpose of executing your above stated rights insofar this is requested by you.
9 What are your choices?
9.1 As indicated, you may choose to withhold your consent to certain processing activities, such as the processing of your personal information by our advertisement partners. The easiest way to do so is by opting out through among others these sites:
- Your Online Choices
- Network Advertising Initiative
- Digital Advertising Alliance
9.2 As an alternative to the above, you may set your web browser or mobile device settings in such a way that certain technologies, such as third party cookies, are blocked as a general rule. For more information on how to do this, we refer to the help-section of your web browser or mobile device.
10 What else is there to know?
10.1 This Policy is effective until terminated by BDA. If you no longer agree to be bound by this Policy, you must cease your use of the Websites and can no longer use the BDAVPN.
10.2 The laws of the Netherlands exclusively apply to this Policy and all agreements and legal relationships between you and BDA. Any disputes relating to or arising from this Policy and the use of Websites will only be submitted to the competent court in the district of Overijssel, location Almelo, the Netherlands, unless there is another competent court on the basis of mandatory law.
10.3 Should you have any questions after reading this Policy, or would want to exercise any right as stated in this Policy, please do not hesitate to contact us: firstname.lastname@example.org