Rock Gym Pro – EU/UK/Switzerland Supplemental Privacy Notice

 

Effective Date
January 1, 2023

This EU/UK/Switzerland Supplemental Privacy Notice (“Privacy Notice”) describes how Rock Gym Pro, LLC and its affiliates (“Company,” “we,” “us,” “our”) collect and process “personal data” under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection. This Notice applies to personal data collected through our websites and mobile applications (collectively, the “Site”) and supplements our main Website Privacy Policy.


Scope and Relationship to Website Privacy Policy
This Privacy Notice applies only to individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland. It supplements our standard Website Privacy Policy and should be read together with that policy.


1. Data Controller
For purposes of applicable data protection laws, the Company is the data controller of your personal data. In certain cases, when we provide services to our customers, we may act as a data processor and our customer will be the data controller. This Privacy Notice does not apply to personal data that we process on behalf of our customers.


2. Contact Details
If you have any questions or concerns about this Privacy Notice or our data practices, you may contact us at:
Email: legal@togetherwork.com


3. Categories of Personal Data Collected
We may collect the following categories of personal data from or about you:

  • First name

  • Last name

  • Address

  • Email address

  • Phone number

  • Organization/company name

  • Organization/company website

  • Account credentials (username and password)

  • Financial information


4. Purposes of Processing
We process your personal data for the following purposes:

  • To provide the Site to you and to improve the Site

  • To provide, operate, improve, and personalize our Services and to give each user a more consistent and personalized experience when interacting with us

  • To register your account

  • To determine trends in consumption of our Services and determine where our Services may be in demand

  • To provide you with information about our Services that we think may be of interest to you

  • To provide you with updates about our Services and with transactional information

  • For customer service and/or support, security (including for authentication purposes), to detect fraud or illegal activity, and for other legal obligations and activities


5. Legal Basis for Processing
We rely on the following legal bases for processing your personal data:

  • Performance of Contract
    We may use your information to perform our contractual services or prior to entering into an agreement with you. If you use the Site or contact us to request the Services, we use your information to provide to you the features and functionality of the Site and the Services, including for customer service.

  • Legitimate Interest
    We may use your information for our legitimate interests, except where such interests are overridden by your interests or fundamental rights and freedoms. For example, we may use your personal data to contact you and respond to your requests and inquiries, to administer our business including by creating statistical analyses, to identify, prevent, and detect fraud, or to pursue or defend ourselves against legal claims.

  • Consent
    We may use your information with your consent. In these instances, we will ask you to grant us consent to use your information. You are free to grant or deny permission. If you deny permission, we will not be able to process your information to conduct the activity to which the consent relates. For example, we will not be able to send you marketing materials that you request. You are also free to withdraw your consent at any time. A withdrawal of consent will not affect processing that has been completed during the time in which the consent was valid. If you have granted us consent to use your information, we will use it only for the purposes specified when we request your consent. This includes use for our marketing campaigns.


6. Marketing Communication Consent
By submitting your phone number online, you agree to our Website Privacy Policy and this Privacy Notice and authorize us to deliver sales and marketing calls, texts, and pre-recorded voicemails. You are not required to agree as a condition of purchasing Services. Message and data rates may apply. You may opt out of marketing emails and text messages at any time using the instructions provided in those communications. Please note that opting out of marketing messages does not impact transactional or account-related communications.


7. Categories of Recipients
We may share your personal data with the following categories of recipients:

  • With Third-Party Service Providers Performing Services on Our Behalf
    We may share your personal information with our service providers to perform the functions for which we engage them. For example, we may use third parties to host the Site or assist us in providing functionality on the Site, provide analytics on the Site, provide a chat function on the Site, provide marketing and advertising services for us, to send out emails on our behalf, or to process payments.

  • With Affiliates and Subsidiaries
    We may share your information with our family of brands and corporate affiliates (e.g., parent company, sister companies, subsidiaries, joint ventures, or companies under common control) for our internal business purposes. However, if we do so, the use and disclosure of your personal data will be subject to this Privacy Notice.

  • For Legal Purposes
    We may disclose your personal data if required to do so by law or in response to a subpoena or other legal process, such as to law enforcement or regulatory agencies, to protect the rights, safety, and property of Rock Gym Pro, our customers, or others, or to exercise or defend legal claims.

  • In Connection with Corporate Transactions
    We may transfer your personal data in the event of a corporate transaction, such as a divestiture, merger, consolidation, asset sale, or in the unlikely event of bankruptcy.


8. Rights Under Data Protection Law
If you are a resident of the EEA, UK, or Switzerland, you have the following rights under applicable data protection law:

  • Right to access your personal data

  • Right to rectify inaccurate personal data

  • Right to have your personal data erased

  • Right to restrict processing of your personal data

  • Right to object to processing of your personal data

  • Right to data portability

  • Right to lodge a complaint with a supervisory authority

To exercise any of these rights, email legal@togetherwork.com and include “GDPR Request” in the subject and body of your message.


9. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, to enforce our policies, and to ensure security.


10. International Data Transfers
Your personal data may be transferred to and processed in countries outside of the EEA, UK, and Switzerland. When we transfer personal data internationally, we implement safeguards such as Standard Contractual Clauses or rely on adequacy decisions to protect your data.


11. Security and Access Suspension
We take reasonable administrative, technical, and physical measures to protect your personal data. We may suspend access to the Site without notice if a security issue is suspected. Access to password-protected areas of the Site is restricted to authorized users only.


12. Changes to this Privacy Notice
We may update this Privacy Notice from time to time. The “Effective Date” at the top of this page indicates when this Privacy Notice was last revised. Your continued use of the Site following the posting of changes constitutes your acceptance of those changes.


13. Contact and Complaints
For questions, concerns, or to exercise your data protection rights, contact us at:
Email: legal@togetherwork.com
Please include “GDPR Request” in the subject and body if applicable.