Size Stream is committed to protecting the privacy of personal data that it processes.
In all other cases, Size Stream is acting as the “controller” of personal information (such as when we collect information from users of our mobile apps that are provided to the general public).
2. PRIVACY SHIELD PARTICIPATION
With respect to personal information received or transferred pursuant to the Privacy Shield Framework, Size Stream is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (“FTC”).
3. NOTICE OF INFORMATION COLLECTED AND USED
We will inform you when we need information that personally identifies you or allows us to contact you or provide you with the Services. Generally, this information is requested when you register for or use our Services, or when you fill out our contact form on our Public Site requesting additional information about our Services. Personal information collected during registration or when you request information from us may include, without limitation, your name and email address.
For certain Services, you will be requested to undergo a 3D body scan which uses infrared sensors, and/or other technologies to map out the shape and contours of your body (“body data”). If you use our mobile apps to conduct a 3D body scan, then we may also collect personal information about you in the form of photographs taken by the mobile app and process those photographs to create the body data. We may also request additional information about you, including your gender. The body data and other data relating to you may be processed for the purpose of supplying goods or services to you, keeping proper records of those transactions and assisting us in the development, debugging and testing of our mobile app and our Services.The legal basis for this processing is the performance of a contract between you and us (or between you and one of our Customers), taking steps (at your request) to enter into such a contract and/or your specific consent to use such information for these purposes.
When performing Services for Customers where Size Stream is the processor, Size Stream may receive body data without any other personally identifying information. In these cases, Size Stream has no ability to identify the individual associated with the body data.Size Stream may use pixel tags, web beacons, and other similar technologies to record information about how individuals access our Services. This information is typically not personally identifiable and may include internet protocol (IP) addresses (or the DNS name associated with it) of the individual’s computer, the web site from which the individual linked to our Services, and the browser software the individual is using to access our Services. This information is used in the aggregate to administer computer systems and to make improvements to our Services.
If you supply any other person’s personal data to Size Stream, you must do so only if you have the authority of such person to do so and you must comply with any obligations imposed upon you under applicable laws and regulations.
If you contact our technical support team for questions about our Services, Size Stream will obtain information about you in order to confirm that you are a lawful user of our Services with a right to receive support, and in order to provide the requested support.
If/when registration for our Services is available, you may choose not to register or provide personal information. You can still use the Public Site. But you will not be able to access Services that require registration.
If/when registration is available, you may register to select the kinds of information you want to receive from us by subscribing to various services and communications.
5. WHAT WE DO WITH THE INFORMATION YOU SHARE
We will use and disclose your personal information to provide the Services, which may include delivery of body data and other personal information to a supplier of clothing or other products, or to a gym or fitness trainer, or other Customers, as requested by you through the Services, or as part of fulfilling Services to Customers with whom you have a relationship. In such cases, we will exclude any photographs created by our mobile apps from the body data provided to the Business Customers unless you specifically direct us to provide such information. This also includes handling customer support and other direct contact requests
We may provide your personal information to Customers when providing Services for those Customers to fulfill our contractual obligations.
We may provide personal information to companies that assist us in providing Services, such as a hosting provider or a customer service provider. These companies are authorized to use your personal information only as necessary to provide these Services and to assist with supporting our users.
We may share your information in response to subpoenas, court orders, and other legal processes or governmental requests, or to establish or exercise our legal rights or defend against legal claims.
We may use your personal information to improve the quality of our Services (and the products and services of our affiliates) and for the research and development of new
We may use and share aggregated, statistical data for our general business and marketing purposes.
Subject to your right to opt-out of marketing messages, we may provide personal information to you about additional Size Stream or Size Stream business partner products that we believe may be of interest to you.
6. ACCESS AND CONTROL OF YOUR DATA
You have certain rights relating to your personal information, subject to applicable laws. Depending on the applicable laws and, in particular, if you are located in the European Economic Area, these rights may include:
To access your personal information held by us (right to access)
To rectify inaccurate personal information and, taking into account the purpose of processing the personal information, ensure it is complete (right to rectification)
To erase/delete your personal information, to the extent permitted by applicable data protection laws (right to erasure; right to be forgotten). In some instances, we may not be able to delete some or all your information in order to comply with applicable laws. We may retain de-identified data.
To restrict our processing of your personal information, to the extent permitted by law (right to restriction of processing)
To transfer your personal information to another controller, to the extent possible (right to data portability)
To object to any processing of your personal information carried out on the basis of our legitimate interests (right to object). Where we process your personal information for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection.
Not to be subject to a decision based solely on automated processing, including profiling,which produces legal effects (“Automated Decision-Making”). Automated Decision-Making currently does not take place through our Services.
To the extent we base the collection, processing, and sharing of your personal information on your consent, to withdraw your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.
To exercise your rights, please contact us using the information in the Contact Information section of this policy. We try to respond to all legitimate requests within one month and will contact you if we need additional information from you in order to honor your request.
As described above, we may also process personal information for a Customer in the role of a processor. If your data has been submitted to us by or obtained by us on behalf of a Customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with the applicable Customer directly, as they are the “controller” of the personal information. Because we may only access data upon instruction from that Customer, if you wish to make your request directly to us, please provide us with the name of the Customer who submitted your data to us. We will refer your request to that Customer and will support them as needed in responding to your request within a reasonable time-frame.
7. ONWARD TRANSFER OF INFORMATION
Except for transfers to Customers and as otherwise expressly set forth herein, which we have described above, Size Stream will not disclose any personal information to a third party who is not a Size Stream contractor or agent (“Agent”). For third parties acting as Size Stream’s Agent, Size Stream will use best commercial efforts to determine that the third party subscribes to the Privacy Shield principles, is subject to the EU Data Protection Directive, or has entered into an agreement with Size Stream that is consistent with the Privacy Shield principles.
In the context of an onward transfer, Size Stream has responsibility for the processing of personal information it receives under the Privacy Shield and subsequently transfers to an Agent on its behalf. Size Stream shall remain liable under the Privacy Shield principles if its Agent processes such personal information in a manner inconsistent with such principles, unless Size Stream proves that it is not responsible for the event giving rise to the damage.
Size Stream takes reasonable technical, administrative and physical measures to protect the security of your personal information from unauthorized use, disclosure and alteration.
Size Stream provides information and training to all employees who have access to personally identifiable data maintained by Size Stream, and Size Stream employees are responsible for the internal security of such information.
Size Stream will not process personally identifiable information in any way that is incompatible or inconsistent with the purpose for which such information was collected.
You also have a significant role in protecting your information. No one can see or edit your personal information associated with your account without knowing your user name and password, so do not share these with others.
9. CHILDREN’S PRIVACY
Size Stream does not knowingly collect or maintain information acquired through the Public Site from persons under 13 years of age, and no part of the Public Site is directed to persons under 13 years of age. Any user under 13 years of age should not use or access the Public Site at anytime or in any manner. If Size Stream learns that personally identifiable information of persons less than 13 years of age has been collected from our website without verified parental consent, then Size Stream will take the appropriate steps to delete this information.
10. DISPUTE RESOLUTION
In compliance with the Privacy Shield Principles, Size Stream, LLC commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Size Stream,LLC at:
Size Stream, LLC
223 Commonwealth Ct.
Cary, NC 27511
Size Stream, LLC has further committed to refer unresolved Privacy Shield complaints to PrivacyTrust, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.privacytrust.com/about/contact.php for more information or to file a complaint. The services of PrivacyTrust are provided at no cost to you.
Any questions or concerns regarding the use or disclosure of personal information should be directed to Size Stream pursuant to the contact information below. Size Stream will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with the principles contained in this Policy. Size Stream has a policy of responding to individuals within 60 days of an inquiry or complaint.
Size Stream has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) regarding unresolved Privacy Shield complaints concerning human resources data transferred from the EU and Switzerland in the context of the employment relationship. Under certain conditions, more fully described on the Privacy Shield website, individuals may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
11. NOTICE CONCERNING DO NOT TRACK
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. You may contact us regarding your choices related to our processing of your personal information. However, we do not currently recognize or respond to browser-initiated DNT signals.
12. MERGER, SALE OR BANKRUPTCY
If all or part of Size Stream is acquired by or merged with a third-party entity, Size Stream may transfer or assign the personal information held by Size Stream as part of such merger, acquisition, or other change of control. In the unlikely event of Size Stream’s bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the
application of laws or equitable principles affecting creditors’ rights generally, Size Stream may not be able to control how personal information is treated, transferred, or used.
14. CONTACT INFORMATION
Size Stream, LLC
223 Commonwealth Ct.
Cary, NC 27511
Phone: (919) 650-2525
Last Updated: November 3, 2020