Privacy
Policy
Who are
we and what do we do?
We are the
Plastic Soup Foundation (a foundation incorporated under Dutch law), also
trading under the name My Little Plastic Footprint (hereafter MLPF, we, us and our).
MLPF is a collaboration between Plastic Soup Foundation, Ocean Recovery Alliance , Shaping EA and Smäll. We have developed the App called
My Little Plastic Footprint (hereinafter, the App) in order to
disclose the problem of the plastic soup and to let you reduce your plastic
footprint (our Services). Our website www.mylittleplasticfootprint.org (the Website) and
App offer more information about us and our Service.
MLPF and
your Personal Data
MLPF cares
about your privacy and protecting your personal data. We process Personal Data
– i.e. all information by which a person can be
directly or indirectly identified – in line with the General Data Protection
Regulation (GDPR) and other relevant legislation regarding the
protection of Personal Data (collectively referred to as Relevant
Legislation). This Privacy Policy explains what kind of Personal Data we
process via our Website, App and Services. It also explains the purposes for
which Personal Data is used, how it is protected and the duration of its
storage.
Are you
younger than thirteen years old?
If you are
younger than thirteen years old, you are not allowed to use our Website, App
and Services without the permission of your parents or legal guardian.
Our role
as Data Controller
We process
Personal Data in the context of our Services. We determine the purposes and
means of these processing activities. This means we act as Data
Controller within the meaning of the Relevant Legislation.
What
Personal Data do we process and for what purposes do we use them?
Depending
on the relationship we have with a person, we process various Personal Data for
different purposes. Below is a breakdown of what Personal Data we process when
you use our App (Users) or visit our Website (Visitors) and make
use of our Services
Personal
Data we collect of Visitors:
(Personal) data: |
Purpose(s): |
Legal basis: |
User-account
information |
We use
these data to: |
We may
process these Personal Data in order to create an account, necessary for
providing the Service (executing the contract). |
Plastic
Mass Index (PMI) information |
We use
these data to: |
We may
process these Personal Data because it is necessary for providing the Service
(executing the contract). |
Technical
information |
We use
these data to: |
We use
these Personal Data because we have a legitimate interest to process these
data in order to provide a good functioning App. |
App
analytics |
We use
these data to: |
We use
these Personal Data because we have a legitimate interest to process these
data in order to provide a good functioning App. Furthermore
we have a legitimate interest to use these Personal Data, in particular the
data analyses, to develop new products and services regarding plastic
reducing behaviour. |
Personal Data we collect of Visitors:
(Personal) data: |
Purpose(s): |
Legal basis: |
Contact
information |
We use
these data to: |
We may
process these Personal Data, because we have a
legitimate interest to process these data. We need these data to contact
Visitor regarding its message. |
Donation
form First-
middle and last name and e-mail address. Donation
amount, payment method and bank information (IBAN). |
We use
these data to: ·
contact you regarding your donation; ·
register you as a PSF donor; ·
process your donation; ·
include in our financial administration; · share with the national tax
authorities (as far as necessary). |
We may
process this is necessary to perform our contract with you, i.e. to process your donation. We are
also legally obligated to process (some of) these data on behalf of the national
tax authorities. |
Technical
information |
We use
these data to: |
We use
these Personal Data because we have a legitimate interest to process these
data in order to provide a good functioning Website. |
Website
analytics |
We use
these data to: |
We use
these Personal Data because we have a legitimate interest to process these
data in order to provide a good functioning Website. |
Social
media data |
We use
these data to: |
We may
process these Personal Data, because we have a legitimate interest to process
these data and because the Visitor voluntarily made such information public. |
How long do we store the Personal Data?
It is our
policy to store and process only those Personal Data that are essential to
provide you with the best possible service. We will not process or store any
personal data that we do not need. We store Personal Data for as long as we
need it for the above purposes:
• Personal
Data of Users| This data is stored as long as the User has an MLPF account
and until two (2) years after the last login. If an account is inactive, we
will send User a notification after two (2) years and remove the account and
Personal Data if an account remains inactive. In case User deletes its account,
we will also delete the Personal Data contained in it, unless we are legally
obliged to retain the Personal Data for longer or if we have a legitimate
interest.
• Other Personal Data | We store other Personal Data,
including Personal Data of Visitors, only for as long as it is necessary for
the purposes. These Personal Data will be deleted as soon as it is no longer
necessary for the purposes for which we processed it, unless
we are legally obliged to retain the Personal Data for longer.
We may also
process all aforementioned Personal Data when we have a good faith belief it is
necessary to detect, prevent and address fraud and other illegal activity.
Personal Data that we process to prevent fraud (or users who have committed
fraud), we store for five (5) years after the last login of User.
Personal Data we process of Users and Visitors may be accessed, processed and
retained for an extended period of time when it is the subject of a legal
request or obligation, governmental investigation, or investigations concerning
possible violations of our terms or policies, or otherwise to prevent harm.
Do we
share your Personal Data with others?
We use
third parties (Data Processors) for e-mail management, data storage, app
development and communications]. We only provide such Personal Data to third
party service providers which is necessary for them to execute the services
they provide to us. Our use of Processors is always in accordance with the
Relevant Legislation. We have established contractual agreements with all our
Data Processors in Data Processor Agreements in which - in line with this
Privacy Policy - it defines what these parties may do with your Personal Data,
how they must secure it and when it must be deleted. Apart from the above, we
will not share your Personal Data with third parties, unless we are legally
obliged to do so.
Export
of data outside the European Union (EU)
Depending
on the relationship we have with a person, we process various Personal Data for
different purposes. Below is a breakdown of what Personal Data we process when
you use our App (Users) or visit our Website (Visitors) and make
use of our Services
How do
we protect the Personal Data?
We make
every effort to protect the Personal Data we process from unauthorized and
unlawful access, change, disclosure, use or destruction. We take, among others
things, the following technical and organizational measures to protect the
Personal Data:
• applying encrypted transmission to limit access to the systems on which the
Personal Data are stored;
• limited access to the (Personal) Data for authorized employees on a
need-to-know basis;
• encryption through passwords;
• network connection with Secure Socket Layer (SSL) technology;
• [applying two-factor authentication internally for accessing the (Personal)
Data;]
• split of application and database servers.
Generic
(non-personal) data
We may
convert Personal Data into non-Personal Data and combine it with information
collected from other users and/or using another anonymization methods. This
means that the data will be fully and irreversibly anonymized: it will not
contain any Personal Data. We may share such generic aggregated data with our
clients and business partners for industry analysis, demographic profiling,
improvement of our services and other purposes.
Third-party
websites
Our Website contains (hyper)links to websites of partners,
suppliers, advertisers, sponsors, licensors or other third parties. We have no
control over the contents or links that appear on these websites
and we are not responsible for the practices of websites linked to or from our
Website. In addition, these websites and their contents and links can change
constantly. These websites may have their own privacy policies, user terms and
client policy. Browsing and interaction on any other website, including
websites linked to or from our Website, are subject to
the terms and policy of that website.
Amendments to this Privacy Policy
We aim to
constantly improve our Website, App and Services. This means, our Privacy
Policy could be amended from time to time. If this Privacy Policy is amended
significantly, then a notification is placed on our Website
along with the updated Privacy Policy
Your
rights and our contact details
As laid
down in the Relevant Legislation, you have the right to:
• request us to correct or update Personal Data;
• request Personal Data to be deleted from our database;
• request a copy of the Personal Data that we have processed. A copy of this
may also be submitted to another data controller at your request;
• withdraw consent for the processing of data. This does not affect the
validity of processing executed before the time that consent was withdrawn;
• lodge an objection to us processing data;
• submit a complaint to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), if
the data subject thinks we process data unlawfully.
To exercise the rights set out above, please contact us at the contact details
below, stating in your email:
• which
right you wish to exercise (i.e.: which of the above requests you are making);
• to which
personal data your request refers.
For example
letters for such a request, you can consult this website of the Dutch Data
Protection Authority. The use of such example letters is, of course, not obligatory. Upon
receipt of your request, we are committed to responding to such requests within
five (5) working days.
If you wish to
delete all personal data linked to your account yourself, you
can delete your account. You can do this by clicking on the "Edit
profile" button within your account and then on "Delete".
If you have
any questions, comments or concerns about how we handle Personal Data, you can
also contact us using the contact details below.
Contact Data
Stichting
Plastic Soup Foundation
Sumatrakade 1537
1019 RS Amsterdam
The Netherlands
E-mail address: mlpf@plasticsoupfoundation.org
Ch. Of Comm: 52072894
VAT: NL 8502 888 85 B01
Last updated in October 2021