Privacy policy
Last updated March 8, 2024
Welcome to Apptree! Thank you for choosing to use our services. Please read this Privacy Policy carefully.
This Privacy Policy describes how we collect, use, process, and disclose your information, including personal information, in conjunction with your access to and use of the Apptree Services.
Apptree is alternatively a data processor or a data controller when it processes data directly or indirectly based on the order of its Users. Apptree is headquartered at Rue d'Arenberg 44, 1000 Brussels (Belgium, Europe), and is registered at the Belgian Registre du Commerce under number BE0538.711.472.
Definitions
- Access codes
- Username and password and any credentials (including but not limited to passwords, usernames, 2FA and OTP) used by the User or the Customer together or separately to identify oneself and access the Services. The access codes are part of the User Account.
- Adequacy Decision
- A decision adopted by the European Commission on the basis of Article 45 of the GDPR, which establishes that a third country (i.e. a country not bound by the GDPR) or international organisation ensures an adequate level of protection of personal data.
- App stores
- Any type of digital shop provided by Platforms or Third Parties on mobile devices, computers, or any other digital devices to download applications made available to the public by developers.
- Application(s) or Service(s)
- Any type of interface allowing the User to deliver to its End-Users any type of content through the use of Apptree’s BackOffice. An "Application" is a mobile or desktop application created by the User through Apptree infrastructure and made available to the public for download or to access from a third-party platform or a web browser, through PWA or on any mobile device.
- BackOffice
- The embedded web app allowing the User to create, review, personalise, modify, delete, and send to Apptree, and finally to Platforms, its finalised Application.
- Binding Corporate Rules (BCR)
- A legal tool used by multinational companies to ensure an adequate level of protection for intra-group transfers of personal data from a country in the EU or the European Economic Area (EEA) to a third country.
- Cookie
- A small piece of text file implemented on your computer or mobile device to allow a website to remember your choices and personalisation requests for a limited time, in accordance with law and regulation.
- Customer Service
- The service that assists the Customer or the User with technical issues, invoice issues, payment or subscription fees, or any assistance regarding how the BackOffice works or can be used.
- Data Protection Law
- All data protection and privacy laws applicable to the processing of personal data.
- Data Controller
- Any entity that determines the purposes and means of the processing of personal data.
- Data Protection Officer (DPO)
- The physical person, entity, or Sub-processor in charge of compliance with EU Regulation (GDPR Section 4, articles 37, 38, and 39) and national regulation regarding the treatment and processing of personal data.
- Data importer
- The processor who agrees to receive from the data exporter personal data intended for processing on their behalf.
- Data exporter
- The controller who transfers the personal data.
- End User
- Any person or entity who actually uses our Service(s). This can include users, visitors, and customers of our User’s Application.
- European Union Data Protection Law
- Since 25 May 2018, Regulation 2016/679 (GDPR) and Directive 2002/58/EC as modified by Directive 2009/136/EC, concerning the processing of personal data and the protection of privacy in the electronic communications sector, and its national implementations.
- Guest
- Any person invited by a User of the Service to provide or drop comments, or publish as an Author, under the Client’s responsibility.
- iBeacon or beacon
- A miniaturised network device using Bluetooth Low Energy (BLE / Bluetooth 4.0) that acts as a relay to detect or track a smartphone or mobile device within a set range, and can send push notifications to that device.
- Order
- An online subscription of our Service(s).
- Personal Data or Personal Information
- Any information relating to an identified or identifiable natural person, in accordance with Article 4.1 GDPR.
- Platform
- Any third-party entity, including but not limited to Apple Inc. and Google LLC, providing a hosting service that, at the request of a recipient of the service, stores and disseminates to the public information, applications, or services (Digital Services Act, 15/12/2020).
- Progressive Web App (PWA)
- A web app that behaves and acts as if it were a mobile app on a mobile device.
- Push notification
- A notification sent to a mobile device to communicate information to the User regarding the use of a service.
- Service or Services
- Access to our sites, including but not limited to www.apptree.so and its regional subdomains, as well as your subscription to and any Order of our services, products, tools, and features, provided by Apptree together with its affiliates, officers, directors, employees, agents, and subsidiaries ("Apptree", "we", "our", or "us").
- Standard Contractual Clauses (SCC)
- Legal tools that provide adequate safeguards for data transfers from the EU or EEA to third countries.
- Stripe
- A third-party digital solution allowing digital payments and transactions via credit cards or other digital payment methods. Apptree has no affiliation with Stripe and has no liability regarding its operations.
- Subscription
- Any paid access proposed by Apptree allowing, upon due payment, the User to access features, add-ons, or options within the BackOffice.
- Sub-processor
- Any processor engaged by the data importer, or by any other sub-processor of the data importer, who agrees to receive personal data exclusively intended for processing activities.
- User Content
- Any content uploaded by you (the User), including but not limited to designs, images, animations, videos, audio files, fonts, logos, illustrations, compositions, artworks, interfaces, text, drawings, literary works, and other materials.
- User
- Any person or entity having an account allowing access to our Services.
- Website User
- Any person visiting one of our websites.
At Apptree we are convinced that data privacy is a fundamental right that must be respected at any time when you use our Services or Application. This is why Apptree treats all data related to an identified or identifiable individual as personal data, without consideration of that individual's area of residency.
1. Information and data we collect
The data collected by Apptree depends on how you use and interact with our website, Services, and Application. When you create an account or register on one of our websites, we can collect any of the following:
- Account information, including a unique account ID
- Device, mobile device, or computer information and details
- Contact information: name, surname, phone number, email address, physical address
- Localisation data
- Company name, address, and contact details
- Consent to receive newsletters and other promotional or marketing messages
- Payment method (for instance, credit card hash, PayPal account information)
- Age and gender
- Social media profile and third-party account details, if provided (including but not limited to Google, Apple, Facebook, Twitter, Instagram, YouTube, LinkedIn)
- IP address, connection logs and data, browser type, and computer-related information
- UDIDs for Android and iPhone, IDFA, IMEIs
- Navigator information, including metadata
- Connection logs, crash logs, diagnostic or performance data
- Advertising data
- Login credentials (hashed)
- Subscriber name and contact information
- Financial or other transaction information, other than banking details (hashed)
- Any other personal data voluntarily given by the User to Apptree or a third party
It is not mandatory for Users to provide this information. However, choosing not to share it may limit Apptree's functionality and our ability to provide comprehensive Customer Service or DPO assistance.
When you use our mobile apps, we may collect information about your device and operating system, and ask whether you want to receive push notifications or share location-based information. You can turn either off at any time through your operating system settings. We may also use mobile analytics software to better understand how people use our applications.
2. Personal data collected by the User from the End-User via Apptree's Services
The User might collect Personal Data about the End-User during the use of a Service created through Apptree's BackOffice. As you use our Services, you may import Personal Information you have collected from your End Users into our system. We have no direct relationship with your End Users, and you are responsible for making sure you have the appropriate permission for us to collect and process information about those individuals.
Our Users who have created an Application using Apptree are responsible for what they do with the personal data they collect, directly or through Apptree, about their End Users. The User acts as Data Controller for that data; Apptree acts as Data Processor.
If you are an End User and no longer want to be contacted by one of our Users, please contact that User directly. If you contact us instead, we may remove or update your information within a reasonable time, generally no longer than one month, and up to three months in case of further investigation.
You are solely responsible for complying with any laws and regulations that apply to your collection and use of your End Users' information. You must publish your own privacy policy, DPA, terms and conditions, and cookie policy, and comply with them. Apptree is not liable for your relationship with your End Users or how you collect and use personal information about them.
3. Your privacy rights at Apptree
Apptree complies with and strongly respects, as required by the GDPR and other regulations, your right to access, consult, correct, erase, transfer, and limit the processing of your data, where applicable.
If you are a User: you can access, update, change, or delete personal information (or that of your End Users) directly in your account, or by contacting us at dpo@apptree.so.
If you are an End User: when using an Application made by one of our Users, you should reach out directly to that User (the Data Controller) to manage, delete, access, restrict, or withdraw consent for your data. If you cannot find that User, contact us at dpo@apptree.so and we will try to help.
If you are not satisfied with our answer regarding how your personal data is managed, you can send a complaint directly to the Belgian Data Protection Authority (APD) via their mediation request page, or to the CNIL in France via cnil.fr or by post at CNIL - Service des Plaintes, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
4. Apptree's use of personal data
Apptree uses personal data to enable our Services to work technically, and to handle commercial, marketing, and financial transactions, including through third parties such as Stripe, PayPal, Apple Pay, Google Pay, and Mercado Pago. This can include:
- Billing, to bill and collect money owed to us, including invoices, receipts, and payment notices
- Advertising, to promote our Services to you and others
- Newsletters and notices, to inform you of changes, outages, new features, or policy updates
- Customer support, to communicate with Users about their account
- Compliance, to enforce our Terms of Use and applicable law
- Third-party protection, to protect the rights and safety of our Users and third parties
- Legal requirements, including responding to court orders and lawful requests by public authorities
- User and End-User support, to provide, support, and improve the Services
Apptree's legal basis for data collection is, depending on the case, consent, contractual obligation, legal requirement, or legitimate interest, in accordance with Article 6(a), (b), (c), and (f) GDPR.
5. Apptree's sharing of personal data
Apptree may share personal data with Sub-Processors, third parties, or affiliated companies that work with Apptree in relation to our activities, including:
| Entity | Corporate location |
|---|---|
| Amazon Inc. (AWS) | Washington, USA; London, United Kingdom; Ireland, Stockholm, Frankfurt, Paris, Milan, Europe |
| Apple Inc. | California, USA |
| Google LLC | California, USA |
| Google Ireland Limited | Ireland, Europe |
| Slack Technologies | California, USA |
| OVH | France, Europe |
| Twilio | California, USA |
| Stripe Inc. | California, USA |
| HubSpot Inc. | California, USA |
6. Protection of data at Apptree
Apptree implements state-of-the-art administrative, technical, and physical measures to meet and respect applicable legislation, including the GDPR, and trains its employees accordingly. Apptree requires its Sub-Processors and third parties to do the same. We maintain safeguards intended to protect against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and misuse of personal information, including firewalls, network redundancy, and vulnerability testing.
7. Transfer of personal data between countries
Apptree delivers its Services within the European Union and around the world, so your personal data might be transferred to or accessed by third parties located inside or outside the European Economic Area (EEA). Apptree complies with applicable law regarding such transfers, including any Adequacy Decision issued by the European Commission under Article 45 GDPR, and puts in place Binding Corporate Rules (BCR) and Standard Contractual Clauses (SCC) where an Adequacy Decision does not exist.
8. Public information and third parties
Blog: comments you post on our public blogs may be read, collected, and used by anyone. Contact dpo@apptree.so if you want a comment removed.
Social media platforms and widgets: our websites include social media features that may collect information about your IP address and the pages you visit, and may set their own cookies. We also maintain presences on platforms such as Facebook, LinkedIn, YouTube, and Instagram; interactions there are governed by those platforms' own policies.
Links to third-party websites: our websites include links to other websites whose privacy practices may differ from ours. We encourage you to read their policies before submitting personal information.
Service providers: we share information with third-party Service Providers who help us provide and support our Services, under contracts requiring them to handle it consistently with this policy.
Advertising partners: we may partner with third-party advertising networks and share personal data with them for that purpose, using cookies and similar technologies to provide targeted advertising.
9. Changes to this privacy policy
Apptree may update this privacy policy at any time. When we do, we revise the date at the top of this page. We encourage Users and End-Users to check this page periodically to stay informed of any changes.
10. Your acceptance of these terms
By using our Services or accessing our websites, you signify your acceptance of this policy. If you do not agree, please do not use our Services, and notify us at dpo@apptree.so. Continued use of the Services after changes are posted will be deemed acceptance of those changes.
11. Contacting us - Data Protection Officer (DPO)
Apptree has designated a Data Protection Officer as required by the GDPR, located at Rue d'Arenberg 44, 1000 Brussels, Belgium. For any question about this Privacy Policy, contact our DPO at dpo@apptree.so.
All legal notices to Apptree should be sent to: Apptree, Rue d'Arenberg 44, 1000 Brussels, Belgium.