UpperKey Privacy and Cookies Policies
Updated 14 December 2020

Table of contents
1. Introduction
2. Information We Collect
3. How Information is Collected
4. How We Use this Information
5. How this Information is Disclosed
6. Your Rights in Relation to Your Personal Information
7. Information Security and Privacy Incident Reporting
8. Interest-Based Advertising
9. Communication from UpperKey
10. UpperKey Career Applications
11. Opting Out of Collection of Information by Third Parties
12. Third-Party Links and Websites
13. Children’s Privacy
14. What Are Cookies
15. Do We Use Cookies
16. How Do We Use Cookies?
17. How You Can Control Cookies
18. “Do not track” Signals
19. Updates to this Policy
20. How to Contact Us

1. Introduction

Welcome to UpperKey’s Privacy and Cookies Policies. At UpperKey, being transparent about how we conduct our business is one of our core values. It is also important for us to be transparent with our site visitors about the way we use and collect data. This privacy policy (“Privacy Policy” or “Policy”) and cookies policy (“Cookie Policy” or “Policy”) were developed by UpperKey (“us” or “we” or “UpperKey) to allow you to understand how we, our affiliates and our subsidiaries collect, communicate, disclose and make use of personal information in connection with our website (“Site”), our blogs (“Blogs”) or other service (collectively “Services”, and each individually as “Service”). This Policy also provides information on your choices and rights with respect to your Personal Information, and how you may reach us should you have any questions or concerns. Additionally, it provides detailed information about when and how we use cookies. We encourage you to read the Policies carefully before you use any of our Services. These Policies apply to all of our Services and your continued use of our Services constitutes consent to the Policy. Should you have any concerns or questions, regarding this policy, please contact privacy@theupperkey.com.

2. Information We Collect

We collect two types of information regarding Users and Visitors:

1. Non-identifiable and un-identified information pertaining to an un-identified User or Visitor, which may be made available to us, or collected automatically via their use of the Services (“Non-personal Information”). Non-personal Information does not enable us to identify the User or Visitor from whom it was collected. The Non-personal Information collected consists mainly of aggregated and technical usage information, such as Users’ and Visitors’ browsing and click-stream activity on the Services, session scrolls and heatmaps, non-identifying information regarding the Visitor’s or User’s date/time stamps, device, internet browser, internet service provider, language and keyboard settings, operating system, referring/exit pages, screen resolution, etc.
2. Individually identifiable information, namely information that identifies an individual or may with reasonable efforts cause the identification of an individual, or may be of private or sensitive nature (“Personal Information”). The Personal Information collected consists mainly of contact details such as an email address or a phone number, billing details (cardholder name, physical billing address, payment method and transaction details), which are only collected from Users with Paid Services, details regarding a browsing or usage session (Geo-location, IP address, and/or device unique identifier), details regarding connected third party accounts such as the email or username for a connected Google, Facebook or PayPal account), scanned identification documents provided to us (such as driver’s license, an ID card, official company registration documents or passport), correspondences (including those made through or uploaded to our Services), and any other Personal Information provided to us by Users and/or Visitors through their access to and/or use of the Services. For the avoidance of doubt, any Non-personal Information that is linked or connected to any Personal Information (for example, in order to improve the Services we offer) is deemed and treated by us as Personal Information, as long as such a linkage or connection exists.

3. How Information is Collected

Information is collected in three main ways:
1. Through your use of the Services.
When you use or visit our Services, including when you browse the Website or any User Website, make an inquiry or a booking of a property or register a User Account, we are aware of it and will usually collect, gather and record such sessions, uses and related information, either independently or with the help of third-party services, including through the use of tracking technologies such as “cookies”.
2. Through the information which you provide to us voluntarily.
We collect the Personal Information you provide us when you register to our Services; when you sign in to our Services via third party services such as Google or Facebook; when you make bookings or inquiries for certain properties; when you upload or submit such Personal Information as you use any of our Services; and/or when you contact us directly by any communication channel such as email, form submissions or telephone.
3. From third party sources as described in Section 11 below.
Some information provided through the Services is collected and processed on our behalf by third parties. When you make an online reservation through the Services, we are required to collect your credit card information. This information is collected and processed through third-party payment processors. In the event that a credit report is required to use a Service, you may be asked to provide your Social Security number ("SSN"). When a SSN is required, we use technology to pass that information directly to the third-party providers who need the information to process the background check or credit report.

4. How We Use this Information

The information collected is used to:

• Provide you with our Services as an registered or unregistered user of the Site, process transactions and send related information such as confirmations and invoices;
• Send administrative messages, security alerts, support, technical notices and updates;
• Provide customer service by responding to your questions and requests;
• Improve and manage the performance of our Services and products;
• Communicate about events, offers, products, promotions, rewards and services offered by UpperKey and others, and provide information and news we think may be of interest to you;
• For reporting and auditing purposes;
• Investigate, detect and prevent fraudulent transactions and other illegal activities and protect the property and rights of UpperKey, as well as that of our employees, agents or others, and in order to comply with applicable law and government requests;
• Deliver and provide the Services, process transactions and send related information such as confirmations and invoices;
• Analyze and monitor trends, activities and usage in connection with our Services;
• Revise, update or modify existing Services and develop new Services;
• Carry out any other purposes described to you at the time that the information was collected.
We only collect personal information that is required for us to collect by our legal obligations or that is necessary in order to fulfill the Services.

5. How this Information is Disclosed

In the following circumstances, Personal Information may be disclosed to the following parties:

• Other companies belonging to or directly affiliated with UpperKey and always in accordance with this policy. Note that sharing of Personal Information from UpperKey affiliated companies and subsidiaries in the European Union with UpperKey’s United States subsidiary, adheres to the EU-US Privacy Shield frameworks.
• Certain service providers perform a number of services on our behalf, such as analytics, email service providers, payment processing, web hosting, etc. In order to do so, we are sometimes required to share your personal information with them for the purposes described above. These service providers are located all around the world. Therefore, the personal data that we collect may be transferred to and stored in countries outside of your jurisdiction. Any international transfer of your personal information is made by following the appropriate transfer safeguards.
• Certain third-parties when required by law, and when necessary to provide, and to protect Our Services.
• Certain third-party partners, after receiving your explicit consent. We will request your consent to share personal information about you with third parties so that they may provide you with promotional materials, special offers and any other materials that may be of interest to you.
• Aggregated information that does not identify specific individuals.
To clarify, UpperKey may share your Personal Information in manners other than as described above, pursuant to your explicit approval, or if and when we are legally obligated to do so.

6. Your Rights in Relation to Your Personal Information

It is essential that you have control over your Personal Information. This is why we are taking steps to allow you to access, amend, delete, limit the use of, receive a copy of or update the use of your Personal Information. Individuals located in specific countries, including the European Economic Area, have certain statutory rights in relation to their personal data. Such individuals have the following rights:

• Right of access: you have the right to obtain confirmation that your personal data is processed, and in the case of processing, information regarding the purposes of your data processing, the retention period (and the criteria used to determine this period) of the data, the recipients to whom your personal data has been or will be disclosed, and a copy of your personal data that we maintain.
• Right to data portability: you have the right to receive your personal data that you have provided to us, in a structured, commonly used and machine-readable format.
• Right to rectification: you have the right to obtain rectification of any inaccurate or incomplete personal data that we maintain about you.
• Right to erasure (right to be forgotten): you have the right, in some circumstances, to obtain the erasure of the personal data that we maintain about you. The right to be forgotten is not unreservedly guaranteed. It is limited especially when colliding with the right of freedom of expression and information. Other exceptions are if the processing of data which is subject to an erasure request is necessary to comply with legal obligations, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes or for the defence of legal claims.
• Right to restriction of processing: you have the right, in some circumstances, to obtain restriction of processing to the personal data that we maintain about you.
• Right to object: you have the right to object to any processing of your personal data that we maintain, but there may be compelling reasons for continuing this processing from our side. In any case we will assess your request and respond to you accordingly. Marketing activities are not included in the aforementioned compelling reasons.
Before we disclose the requested records of Personal Information that we keep of you, you may be asked for additional information in order to confirm your identity for security purposes. We reserve the right to charge a fee where permitted by law in the case of an unfounded or excessive request. While we recommend that you contact us first, you do have the right to file a complaint with your local supervisory authority for data. In case you wish to exercise one of these rights, please contact us at privacy@theupperkey.com. We will make all reasonable efforts to promptly honour your request, unless we require further information from you in order to fulfill your request, subject to legal and other permissible considerations.

7. Information Security and Privacy Incident Reporting

We are taking all reasonable technical and organizational measures in order to safeguard your personal data against accidental or unlawful change, damage, destruction or loss. That being said, no security program is 100% foolproof and thus we cannot guarantee the absolute security of your personal or other information. In order to minimize the consequences and handle any potential data privacy incident, we have implemented a relevant procedure. Upon the occurrence of a data privacy breach, you will be informed as soon as the incident is taken into consideration. The relevant Data Protection Authority will also be informed within 72 hours after the breach has been noticed.

8. Interest-based advertising

When you use the Services, we or third party advertisers or service providers may use cookies (we provide to them or that they collect) or other similar technologies in order to collect information about your use of the Services (including on mobile applications) or your online activities over time and across different websites and devices due to our practices of interest-based advertising. The collected information may include the content you view, the date and time that you view this content, and the website that referred you to the Services. This information may be associated with your unique browser, device identifier, or Internet Protocol (IP) address. Such practices help tailor advertisements that are useful and relevant to you. These tailored advertisements may appear on the Services or on other applications, properties or websites. In addition, if you have provided your email address to us, we may use an unreadable, scrambled form (a hash), of your email address to deliver tailored advertisements to you on the Services or on other websites. We do not collect or access any of the contents of your email messages in providing interest-based advertising. Our use of the information received from Gmail APIs will adhere to Google’s Limited Use Requirements Policies.

9. Communication from UpperKey
Your Personal Information may be used to send you messages and promotional email, text messages, direct text messages, marketing calls and similar forms of communication. Should you not wish to receive such communications, you may notify us at any time or follow the “unsubscribe” link. We take measures to limit the content that is sent to you to a reasonable and proportionate level. We aim to send you information which we believe may be of relevance or interest to you, based on your information. We may also contact you with important information regarding our Services or your use thereof. We may send you billing information, replies to your support tickets or emails, send reminders or warnings regarding upcoming or late payments or notify you of material changes in our Services. It is important that you are always able to receive such messages. For this reason, it is not possible to opt-out of receiving such Service and Billing Messages unless you are no longer a UpperKey Visitor or User.

10. UpperKey Career Applications

All qualified Applicants to are welcome to apply to any of the open positions published on www.theUpperKey.com by sending us their curriculum vitae and contact details (“Applicants’ Information”) via form submissions, email or any other means. We understand that discreetness and privacy and are essential to our Applicants, and we are committed to keep Applicants’ Information private and confidential, using it solely for UpperKey’s internal recruitment purposes (including for identifying Applicants, evaluating their applications, contacting Applicants by phone or in writing and making hiring and employment decisions).

UpperKey may retain Applicants’ Information submitted for no longer than two years after the applied position has been filled or closed. In this way, we can re-consider Applicants for other positions and opportunities at UpperKey as they arise. We can also use their Applicants Information as a reference for future applications submitted by them. If the Applicant is hired, the information may be used for additional employment and business purposes related to their work at UpperKey. If you previously submitted your Applicants’ Information to UpperKey and now wish to update it, access it or have it deleted from UpperKey’s systems, please contact privacy@theupperkey.com.

11. Opting Out of Collection of Information by Third Parties

UpperKey's ad network providers, third-party ad servers and third-party advertisers may provide you with advertisements that you may see on the Services or on other affiliated websites. In order to improve their relevancy and help to measure the effectiveness of their advertisements, the UpperKey Ad Providers may use cookies, clear gifs, web beacons or other similar technologies. Such cookies are used to record users' activity, including the pages visited, in order to learn what types of information are most pertinent to the users.

12. Third-party Links and Websites
Throughout the Services, we may link to the websites of other individuals and/or companies. UpperKey's Privacy Policy does not extend to these external websites and third parties who may collect information about users on those websites. Please refer directly to these websites and third parties regarding their own privacy policies.


13. Children’s Privacy

Our Services are addressed to individuals, aged 18 years old or more, unless specified otherwise. For individuals under the age of 18, we do not knowingly collect personal data without prior parental consent. Should you find out that your child has provided us with any personal data without your prior consent, please inform us accordingly so we may delete this information and terminate any account that the minor may have created with us.

14. What Are Cookies

In order for the website to work properly, we place small data files known as cookies on your device, as do most websites today. A cookie is a small text file that gets saved on your computer or mobile device when you visit a site, enabling the website to remember your preferences and actions. This includes things such as login, location, language, font size and other display preferences over a period of time. In this way you are not required to re-enter them each time you revisit the site or click from one page to another.

15. Do We Use Cookies

UpperKey uses cookies and other similar technologies like web beacons and single-pixel gifs. The cookies we use are a combination of both persistent cookies and session-based cookies. We set and access our own cookies on the domains operated by us. Additionally, we use third-party cookies such as Google Analytics.

16. How Do We Use Cookies
Some of the cookies used are associated with your personal information and account in order to remember that you are logged in and in which workspaces. Other cookies are unique and not specifically tied to your account, allowing us to carry out customization, analytics and other similar actions. More secifically, we implement cookies for the following usage purposes:

• Security. Cookies are used to support and enable our security features, helping us to detect malicious activity.
• Authentication. When logged in to our services, cookies help us to personalize your experience and show you the right information.
• Preferences. Cookies let us know which language you prefer, what your communication preferences are, provide customized features and content, show insights and help with filling in forms.
• Analytics, performance and research. With cookies, we are able to learn how well our services and website are performing. They are used to help us understand, research and improve new features, products and services. This includes creating record logs when you access our Sites and Services from different devices, such as your mobile phone or personal computer.
• Marketing. Cookies may be used to help us deliver and track marketing campaigns. In the same way, our partners may use these cookies to provide us with information about your interactions with their services. The use of those third-party cookies would be subject to the service provider’s own cookie policies.

17. How You Can Control Cookies
Certain users prefer not to allow cookies in their browser, which is why most browsers give users you the ability to manage their cookie settings. You can control and/or delete cookies as desired. For example, all of the cookies that are already stored in your computer can be deleted and most browsers can be set to prevent them from being placed. However, by doing this, you may have to manually adjust certain preferences each time you visit this website or other sites. Additionally, this may cause some services and functionalities not to function.
Some browsers allow you to set up rules to manage cookies on a site-by-site basis, allowing more granular control over your privacy by disallowing cookies from all websites except those you trust.

Most Browser providers offer help pages relating to cookie management. Information from some of the most popular browsers can be reviewed by clicking on the links listed here: Google Chrome, Internet Explorer, Mozilla Firefox, Safari (Desktop), Safari (Mobile), Android Browser. For other browsers not listed above, please consult the related documentation directly from your browser provider. For additional information regarding the EU Directive for Cookie Policy, please read here.

18. “Do Not Track” Signals
Please note that in regards to a “Do Not Track” signal in the HTTP header from a browser or mobile application, we do not change our practices.

19. Updates to this Policy
These UpperKey Privacy Policy and UpperKey Cookie Policy may be updated or changed occasionally in order to meet legal, operational and technological standards or requirements. We encourage you to frequently visit this policy in order to stay updated about changes. In case of any critical changes, these will be communicated to you prior to implementation. Any modifications will take effect on the day they are published.

20. How to Contact Us
If you have any concerns or questions about this Privacy Policy or Cookies Policy, or wish to exercise any of our rights, you may contact us at privacy@theupperkey.com. We will attempt to resolve any complaints regarding the use your Personal Information in accordance with these Privacy and Cookies Policies.
If you are based in the EU, and for the purposes of GDPR (Article 27) including Data Deletion, you may contact our EU head office at 231 rue Saint Honoré, 75001 Paris, France.