NewU - End User Privacy Policy

Effective date: 01-01-2025

Overview

At NewU, the privacy and safety of your data are paramount. One of our core principles is transparency, and through this End User Privacy Policy, we seek to clearly explain how NewU collects, uses, and processes your data. If you have any questions regarding NewU, your privacy and data, or any other parts of our Service, you can contact us at any time via info@newu-app.com.

Definitions

For the purposes of this Privacy Policy, capitalized words shall have the following meaning and all definitions shall have the same meaning regardless of whether they are singular or plural:
"NewU", "we", "us" or "our" refers to RabbitQuest B.V. and its related companies. NewU is the brand name of RabbitQuest B.V..
"End-user" or "You" means an individual who uses NewU. An end user is often an employee of an organization. End users must be part of a Group to be able to use NewU.
"Group" means a unique account created for an organization. A Group can contain multiple End users.
"NewU" refers to RabbitQuest B.V., which is located at Buitenplein 67, 1181ZE, Amstelveen.
"Personal Data" is any information that relates to an identified or identifiable individual.
"Usage Data" refers to data collected automatically, either generated by using the Service or from the Service infrastructure itself (for example, the duration of a page visit).
"Service" refers to the use of the Website, Portal (www.newu.app) or Mobile application.
"Mobile application" refers to the NewU app that is available on the App Store and Play Store.
"Portal" refers to www.newu.app. Group Admins use the Portal to manage their Group.
"Website" refers to www.newu-app.io. The Website is used for marketing purposes.
"Wearable Partner" refers to the software partner that NewU collaborates with to access wearable data.

Data collection

This section of the Policy describes what types of data we collect. We have categorized the sources of your personal information as follows:

  • Data you provide us
  • Analytical data
  • Data from our wearable partner

Data you provide us

Login data: Your email and password User content: E.g. challenges, photos, comments and other material) that you post to the Service; Activity data: Data about habits, such as selection and completion of habits and challenges, tracking, activity, etc. Profile information: Profile information that you provide for your user profile.

Analytical data

Anonymized Analytical data: We collect information that your browser or phone sends whenever you use our Service. This log file information may include information such as your computer's or phone's Internet Protocol address, browser type, phone type and other statistics. We use this information to optimize NewU's interface.

Data from our Wearable Partner

Wearable activities: You can decide to connect your Wearable with NewU through our Wearable Partner. If you do so your Wearable activities will be synchronized with NewU so that you can complete challenges. Wearable activities will be automatically deleted after 2 days.

Data usage

This section explains how we use your data once we have collected it. Our primary goal is to aid you in achieving your health goals; your data plays a crucial role in achieving that objective. We handle your information responsibly and are committed to helping you understand how we use it. The following describes and categorizes how we use the data we have collected:

Usage categories

Service access: Remember information so you will not have to re-enter it during your visit or the next time you visit the Service;
Deliver services: to manage, supply, and uphold our service offerings;
Service enhancement: to refine, strengthen, and extend our service offerings;
Aid assistance: to offer assistance to you, and to diagnose or fix technology problems;
Product development: to create new products and services;
Generate insights: We generate insights by analyzing the data we've collected. These insights assist connected app developers in offering improved services or enhancing user experiences;
Investigating misuse and misbehaviour: we may examine any improper use of our services or developers' applications, including policy violations, illicit activities, or unauthorized service access;
Consent-based Usage: Only with your explicit approval may we use your information for other specified purposes or as you direct us.
Communication: We may use your information to contact you with push notifications, newsletters, marketing or promotional materials and other information that may interest you. You may opt out of receiving any or all communications from us.

Group access to your data

Challenges: When you engage in challenges, a post is created for every challenge that you complete.
Habits and other personalized content: Habits and other personalized content is not shared with anyone in your Group.
Anonymize your profile: You have the option to anonymize your profile. If you decide to do so all your information will be hidden from other users.
Group Insights: The Group Admin has access to anonymized and aggregated insights about the End Users of that Group. This data is not retractable to individual profiles.

Data sharing (Subprocessors)

We will not rent or sell your information to third parties outside NewU. This section of the Policy outlines the categories of third parties with whom we may share your information to give you a clear understanding of how your data may be disclosed to others. We may share your data with:
Google Cloud Platform: Cloud storage services (https://cloud.google.com/privacy/gdpr) providers that offer remote data storage solutions over the internet that allow us to store, manage, and/or access collected data in a secure and scalable environment;
Mailchimp: Email marketing provider, which we use to send a weekly Habit Newsletter with tips on how to form habits. You can opt out at any time.
Terra: the Partner that NewU collaborates with for accessing wearable data (https://tryterra.co/end-user-privacy). Terra does not store any data, but only functions as a pass-through mechanism for wearable data.

Data Storage

Data is stored on Google Cloud Platform in a Europe-West-3 cluster around Frankfurt.

Data protection rights

The following ensures that you are aware of your rights and how you can exercise them. Understanding your data protection rights enables you to make informed decisions about how your personal information is used and managed. We will honour the following rights, subject to limitations of the law. You may:
Request access to your personal data: Obtain confirmation if we process your personal data and request a copy of the data we have about you.
Request correction of inaccurate or incomplete data: Ask us to update any incorrect information or complete incomplete data by providing additional details.
Request erasure of your personal data: In certain cases, ask us to permanently delete or anonymize your personal data. Note, this may not always be possible due to legal or legitimate obligations.
Request restriction of processing: In specific situations, request that we limit the way we process your personal data.
Request data portability: Receive a structured, commonly used, and machine-readable copy of the data you provided us, or have it transferred to another service provider where technically feasible.
Object to data processing: Challenge processing of your personal data when based on our legitimate interests. This includes objecting to data processing for marketing purposes, which you can do by clicking "unsubscribe" in our emails or managing your preferences in your account settings.
Withdraw your consent: Cancel your permission for us to process your personal data at any time. Be aware that this may impact your ability to use some features of our services.
If you wish to exercise any of the above rights or have any questions, please contact us directly. We are committed to addressing your concerns promptly and transparently.

Data retention and data deletion practices

This section covers our retention and deletion practices, which are designed to reduce data retention periods to the minimum required time to deliver our services to our customers successfully.
Retention period: After two years of inactivity, you will receive an email with the request to sign in to NewU within a month. If you do not sign in within a month, all user data will be deleted. You will be notified by email that the data is deleted.
Wearable data: Wearable data is deleted after 2 days.

Data security

"We are secure", is one of the 6 core values of NewU. NewU is committed to protecting the security of your data. We use a variety of security technologies and procedures to help protect your data from unauthorized access, use, or disclosure.
Penetration testing: NewU performs regular penetration tests by ethical hacking companies to ensure that its security meets industry standards.
Information security management system: NewU has an ISMS based on the ISO-27001 security standard, which outlines the organization's security procedures.

Legal basis for processing data

In accordance with GDPR, NewU provides the following information regarding the lawfulness of processing personal data. The performance of the contract (Terms & Conditions) between you and NewU for the data processing relating to your use of the Services;
NewU's base for personal data processing, more specifically:
The User has given consent to the processing of personal data by accepting this Privacy Policy and/or the Terms and Conditions and Processing of the data of the User is necessary for the performance of the Service.

Automated decision-making and profiling

Health suggestions: We might use profiling and automated decision making to give the User adequate health and habit-formation suggestions. E.g. This may come in the form of tips, tricks, recipes, work-outs, notifications, habits and challenges.

Corporate Restructuring

If we sell or otherwise transfer part or the whole of NewU or our assets to another organization (e.g., during a transaction like a merger, acquisition, bankruptcy, dissolution, liquidation), your information such as name and email address, User Content and any other information collected through the Service may be among the items sold or transferred. You will continue to own your User Content. The buyer or transferee will have to honour the commitments we have made in this Privacy Policy.

Children's Privacy

Our Service does not address anyone under the age of 13 ("Children"). We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your Children have provided us with personal information, please contact us. If we become aware that we have collected personal information from a child under age 13 without verification of parental consent, we take steps to remove that information from our servers.

Modifications to End User Privacy Policy

This policy may change from time to time. If we update it, we will notify you.

Contact us

Feel free to contact us at any moment if you have any questions about this Privacy Policy. You can email us at info@newu-app.com.