Additional Disclosures for Data Subjects in Europe

Additional Disclosures for Data Subjects in Europe

These additional disclosures apply only to data subjects in Europe. For our full Privacy Policy, please visit https://company.eko.com/legal/privacy. 

1.1 Roles.

Data protection laws in Europe distinguish between organizations that process personal data for their own purposes (known as “controllers”) and organizations that process personal data on behalf of other organizations (known as “processors”). Eko acts as a controller with respect to personal data collected as you interact with our Services.

1.2 Lawful Basis for Processing.

Data protection laws in Europe require a “lawful basis” for processing personal data. Our lawful bases include where: (a) you have given consent to the processing for one or more specific purposes, either to us or to our service providers or business partners; (b) processing is necessary for the performance of a contract with you; (c) processing is necessary for compliance with a legal obligation, such as disclosure of information to authorities where we are obligated to do so; or (d) processing is necessary for the purposes of the legitimate interests pursued by us or a third party, where your interests and fundamental rights and freedoms do not override those interests. 

1.3 Data Transfer outside the EEA

The personal data collected from you by Eko, as detailed in the Privacy Policy, may be transferred to, and stored at, servers which may be located in countries outside the European Economic Area (EEA). We apply strict safeguards when transferring it outside of the EEA, which may include the following: 

  • Transferring your personal data to countries approved by the European Commission as having adequate data protection laws, such as Israel;
  • Entering into standard contracts that have been approved by the European Commission and which provide an adequate level of high quality protection, with the recipients of your personal data;
  • Transferring your personal data to U.S. organizations that are Privacy Shield certified, as approved by the European Commission.

1.4 Your Data Subject Rights.

You have the right to access, rectify, or erase any personal data we have collected about you. You also have the right to data portability and the right to restrict or object to our processing of personal data we have collected about you. In addition, you have the right to ask us not to process your personal data (or provide it to third parties to process) for marketing purposes or purposes materially different than for which it was originally collected or subsequently authorized by you. You may withdraw your consent at any time for any data processing we do based on consent you have provided to us. 

To exercise any of these rights, please submit a request through our Online Form. We will respond to your request within 30 days. We may require specific information from you to help us confirm your identity and process your request. 

Please note that we retain information as necessary to fulfil the purposes for which it was collected, and may continue to retain and use information even after a data subject request for purposes of our legitimate interests, including as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements. 

If you have any issues with our compliance, you may contact us at privacy@eko.com. You have the right to lodge a complaint with the data protection regulator in your jurisdiction.