Privacy policy

Last updated: 26.11.2024

At MISTO, we want to give you the best possible experience to ensure that you enjoy our Services. Your privacy and the security of your personal data is, and will always be, enormously important to us. So, we want to transparently explain how and why we gather, store, share and use your personal data - as well as outline the controls and choices you have around when and how you choose to share your personal data. That is our objective, and this Privacy Policy (“Policy”) will explain exactly what we mean in further detail below.

This privacy policy applies to mobile app MISTO for residents and visitors with access to urban information (“MISTO”, “we,” “our,” “us”). The terms used in this Privacy Policy shall have the same meaning as in the Terms of Use, unless noted otherwise.

If you are interested in learning how we collect, use, and disclose information through our corporate Website, and learning how to exercise applicable privacy rights related to such information, please click here.

We respect your privacy and are committed to protecting it through our compliance with this policy. Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it.

If you do not agree with our policies and practices, do not register with, access, or use the MISTO. By registering with, accessing, or using MISTO, you agree to this Privacy Policy. This policy may change from time to time. Your continued use of or access to the MISTO after we make changes is deemed to be acceptance of those changes, so please check this.

ABOUT THIS POLICY

This Policy sets out the essential details relating to your personal data relationship with Rock IT, LLC, business code: 41717846.

The Policy applies to the features of app MISTO and any associated services (referred to as the “MISTO Services”). The terms governing your use of the MISTO app are defined in our Terms and Conditions of Use (the “Terms and Conditions of Use”).

From time to time, we may develop new or offer additional services. If the introduction of these new or additional services results in any material change to the way we collect or process your personal data we will provide you with more information or additional terms or policies. Unless stated otherwise when we introduce these new or additional services, they will be subject to this Policy.

The aim of this Policy is to:

We hope this helps you to understand our privacy commitments to you. Alternatively, if you do not agree with the content of this Policy, then please remember it is your choice whether you want to use the MISTO.

YOUR RIGHTS

If You are a citizen or resident of Ukraine, You have the following rights under the Law of Ukraine “On Personal Data Protection”:

  1. to know about the sources of collection, location of your personal data, the purpose of their processing, location or place of residence (stay) of the personal data owner or manager, or give an appropriate order to receive this information to persons authorized by him, except in cases established by law;
  2. to receive information about the conditions for granting access to personal data, in particular, information about third parties to whom your personal data is transferred;
  3. access to your personal data;
  4. not later than thirty calendar days from the date of request receipt, except in cases provided for by law, receive a response on whether your personal data is being processed, as well as receive the content of such personal data;
  5. подати вмотивовану вимогу власнику персональних даних із запереченням проти обробки своїх персональних даних;
  6. to submit a reasoned request to the personal data owner with an objection to the processing of your personal data;
  7. to submit a reasoned request for modification or destruction of your personal data by any personal data owner and manager, if this data is processed illegally or is unreliable;
  8. to protect your personal data from illegal processing and accidental loss, destruction, damage due to deliberate concealment, failure to provide data or its untimely provision;
  9. to submit complaints about your personal data processing to the Authorised Representative or to the court;
  10. to make reservations regarding the restriction of the right to process your personal data when providing consent;
  11. to withdraw consent to the personal data processing;
  12. be protected from an automated solution that has legal consequences for you.
  13. Other rights according to the Ukrainian legislation.

If You are a citizen or resident of the the European Economic Area or European Union, you have the rights under the General Data Protection Regulation (GDPR).

The General Data Protection Regulation or "GDPR" gives certain rights to individuals in relation to their personal data. Accordingly, we are happy to offer transparency and access controls to help users take advantage of those rights. As available and except as limited under applicable law, the rights afforded to individuals are:

If you have any questions about your privacy, your rights, or how to exercise them, please contact us r using the “Contact Us” form. If you have concerns around our processing of your personal data, we hope you will continue to work with us to resolve them. However, you can also contact and have the right to lodge a complaint with your local data protection authority.

Additional privacy rights under the California Consumer Privacy Act (CCPA) can be found in our supplemental policy “For California residents”, which contains supplemental disclosures relating to the processing of your personal data.

If You are outside the European Economic Area or European Union, California, or Ukraine your country may have other privacy laws that accord You different rights, but the GDPR is one of the most comprehensive privacy laws in the world, so You are pretty much covered here.

INFORMATION WE COLLECT AND HOW WE COLLECT IT

We collect information from and about users of MISTO:

The information we collect and how we collect it is described below:

OUR PRINCIPLES REGARDING USER PRIVACY AND DATA PROTECTION

Your privacy and security are of the utmost importance to us. We will always follow these principles.

Data we collect for our analytics

DATA WE COLLECT FROM OUR PARTNERS

We may collect limited data about you from various third parties such as public databases, marketing partners, social media platforms, and other outside sources. These third-party sources vary over time and include the following:

INFORMATION YOU PROVIDE TO US

When you register with, access, or use MISTO, we may ask you to provide information (a) by which you may be personally identified, such as name, mobile number, email address, or any other personal or personally identifiable information under applicable law (“personal information“), and/or (b) that is about you but individually does not identify you.

This information includes:

INFORMATION COLLECTION AND TRACKING TECHNOLOGIES

The technologies we use for automatic information collection may include:

We automatically collect certain information when you visit, use, or navigate the MISTOs. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use MISTO and other technical information. This information is primarily needed to maintain the security and operation of MISTOs, and for our internal analytics and reporting purposes.

Device information, such as your mobile device ID, model, and manufacturer, and information about the location of your device.

Additionally, we may use third-party software to serve ads on the MISTO, implement email marketing campaigns, and manage other interactive marketing initiatives. This third-party software may use tracking technology to help manage and optimize your online experience with us.

THIRD-PARTIES

When you use or access MISTO or its/their content, certain third parties may use automatic information collection technologies to collect information about you or your Device, or you may otherwise be accessing and using third-party platforms, software, and applications.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about a third party’s processing of your information, you should contact the responsible provider directly. You acknowledge and agree that your access and use of such third-party tools may be subject to their respective terms of use and privacy policies.

We may also partner with selected third-party vendors (processors) to allow tracking technologies and remarketing services on the MISTO to, among other things, analyze and track users’ use of the MISTO, determine the popularity of certain content or features and better understand online activity. By accessing the MISTO, you consent to the collection and use of your information by these third-party vendors. You are encouraged to review their privacy policy and contact them directly for responses to your questions. We do not transfer personal information to these third-party vendors.

Full list of third-party you can find here: "Disclosure of Your Personal Data".

WHY DO WE COLLECT YOUR DATA

When you use or interact with the MISTO, we use a variety of technologies to process the personal data we collect about you for various reasons. We have set out below the reasons why we process your personal data, the associated legal bases we rely upon to legally permit us to process your personal data, and the categories of personal data for these purposes:

We process your personal data for the following purposes:

DISCLOSURE OF YOUR PERSONAL DATA

We only share information with your consent, to comply with laws, to protect your rights, or to fulfill business obligations. We may disclose aggregated information about our users, and information that does not identify any individual or device, without restriction.

The following personal data will only be shared with the categories of recipients outlined in the table below if:

In addition, we may disclose personal information for following categories of recipients and for the following reasons:

Service providers: We work with service providers that work on our behalf which may need access to certain personal data in order to provide their services to us. These companies include those we've hired to provide customer service support, operate the technical infrastructure that we need to provide the Service, assist in protecting and securing our systems and services, and help market own products and services as well as partner products, services, events, and co-branded promotions in which we involved. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity.

Payment processors: We will share your personal data with our payment processors as necessary to enable them to process your payments, and for anti-fraud purposes.

Advertising partners: We work with advertising partners to enable us to customize the advertising content you may receive via MISTO. These partners help us deliver more relevant ads and promotional messages to you, which may include interest-based advertising (also known as online behavioral advertising), contextual advertising, and generic advertising on the MISTO. We and our advertising partners may process certain personal data to help MISTO understand your interests or preferences so that we can deliver advertisements that are more relevant to you.

Our partners: Depending on how you sign up for the MISTO (e.g. through a third-party service or a mobile provider), we share your username or other User Data as necessary to enable your account. We may also share personal data with that third party about your use of the MISTO, such as whether and to what extent you have used the offer, activated account, or actively used the Service.

Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy policy. Affiliates include our parent company and any subsidiaries, joint venture partners or other companies that we control or that are under common control with us.

Law enforcement and data protection authorities: We may share your personal data when we in good faith believe it is necessary for us to do so in order to comply with a legal obligation under applicable law, or respond to valid legal process, such as a search warrant, a court order, or a subpoena. We also may share your personal data where we in good faith believe that it is necessary for the purpose of our own, or a third party’s legitimate interest relating to national security, law enforcement, litigation, criminal investigation, protecting the safety of any person, or to prevent death or imminent bodily harm, provided that we deem that such interest is not overridden by your interests or fundamental rights and freedoms requiring the protection of your personal data.

Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

DATA SECURITY

We are committed to protecting our Users’ personal data. We implement appropriate technical and organisational measures to help protect the security of your personal data; however, please note that no system is ever completely secure. We have implemented various policies including pseudonymisation, encryption, access, and retention policies to guard against unauthorised access and unnecessary retention of personal data in our systems.

Your password protects your user account, so we encourage you to use a strong password that is unique to your MISTO account, never share your password with anyone, limit access to your device.

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process which included:

However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from MISTO is at your own risk. You should only access the services within a secure environment.

Unfortunately, the transmission of information via the internet and mobile platforms is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted through MISTO. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures we provide.

We are not responsible for the safety of any information that you share with third-party providers who advertise, but are not affiliated with MISTO.

Personal information will be pseudonymized and encrypted to ensure the user privacy. The collected information will be handled for standard cases of use described in this Privacy Policy.

INTERNATIONAL DATA TRANSFERS

MISTO uses servers provided by our partners within Ireland to store and process data. Also, for certain functions and purposes of MISTO, in particular for analytics, the servers of our partners, which are located around the world, may be used. In this case, the data stored and processed on such servers will be anonymized or depersonalized.

Personal data collected within the European Union and the European Economic Area or Switzerland may, for example, be transferred to and processed by third parties located outside of the European Union and the European Economic Area or Switzerland. In such instances MISTO shall ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organisational measures are in place such as the Standard Contractual Clauses approved by the EU Commission.

For further details of the security measures we use to protect your personal data, please see section “Data Security” of this Policy.

DATA RETENTION

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements).

We retain your data for as long as your Account is active or unless you request us to delete your data. Note that if you ask us to remove your personal data, we may retain your data as necessary to comply with our legal obligations.

If you request, we will delete or anonymise your personal data so that it no longer identifies you, unless we are legally allowed or required to maintain certain personal data, including situations such as the following:

CHANGES TO OUR PRIVACY POLICY

We may update our privacy policy from time to time. If we make material changes to how we treat your personal information, we will post the new privacy policy on this page, and we may also send a courtesy email to you to the email address we have on file for you, or displaying a prominent notice within the MISTO, if any. The date the privacy policy was last revised is identified at the top of the page. You are responsible for periodically visiting this privacy policy to check for any changes.

AGE LIMITS

We do not knowingly collect or solicit personal data about or direct or target interest-based advertising to anyone under the age of 18 or knowingly allow such persons to use or access the MISTO. If you are under 18, please do not send any data about yourself to us, including your name, address, or email address. No one under the age of 18 may provide any personal data. If we learn that we have collected personal data about a child under age 18, we will delete that data as quickly as possible. If you believe that we might have any data from or about a child under the age of 18, please contact us.

LINKS

We may display advertisements from third parties and other content that links to third-party websites. We cannot control or be held responsible for third parties’ privacy practices and content. If you click on a third-party advertisement or link, please understand that you are leaving the Service and any personal data you provide will not be covered by this Policy. Please read their privacy policies to find out how they collect and process your personal data.

CONTACT US

If you have any questions or suggestions regarding our Privacy Policy, please contact us at legal@mistodigital.com or through “Contact us”. If you are a resident in the European Economic Area, the “data controller”, or from California, “business” for your personal information is Rock IT, LLC, business code: 41717846, with the address at Ukraine, 01014, city of Kyiv, Zvirynetska Street, building 63, office 1.