PRIVACY POLICY

A story a day AB
PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING OUR SERVICE
1.    INTRODUCTION

1.1. Your privacy is of importance to A story a day AB, org. no. 559381-7850, Laursen Rävstigen 20 A, 433 50 Öjersjö, Sweden (‘ASAD’, ‘us’, ’we’, or ’our’). This privacy policy aims to inform you about how we collect, use, disclose and store information (“Processing”) that may identify you as an individual (‘Personal Data’) when you use our application, website [INSERT], or platform (‘Service’).

1.2. By accepting our terms, this privacy policy, our cookie policy and other supplemental terms and conditions which may govern your usage of our Services you will be granted access to A story a day’s internet based digital subscription of audiobooks, e-books and other literary works via our website or application.

1.3. The purpose of our Processing of your Personal Data is to fulfill our contractual relationship with you and to give you a better user experience when you use our Service.

1.4. We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. If you are now comfortable with the content in this privacy policy, you may always refrain from using the Service.

2.  WHO IS RESPONSIBLE?

2.1. Anyone who processes Personal Data (person or entity) is either a data controller or a data processor.

2.2. A data controller is any person or entity that determines the purposes and means of the processing. A data processor is any person or entity that processes personal data on behalf of a data controller.

2.3. In the case you are entering into an agreement with us or using our Service, we, A story a day AB, is the data controller. Information on how to contact us is found under section 14 below. In case we provide services or products that are not developed or provided by us, the third party providing such services or products is responsible for your Personal Data. We assume no responsibility for such third-party services or products. We do recommend that you take part of respective third party’s general terms, confidentiality undertakings and privacy policies.

3. LAWFULNESS

3.1. Our Process of your Personal Data is i.e., necessary to fulfil i) our obligation under contract entered into with you, and/or ii), if it may be necessary for one or more legitimate interests of ours, such as, after a weighing of interests or with your consent,

3.2. In the event we base or Processing of your Personal Data with a legitimate interest of ours, we evaluate the impact of such activities on your rights and freedoms and only proceed with the activities if our assessment shows that your interest is not outweighing ours. We undertake to continuously evaluate the effect of the Processing and will only Process your Personal Data provided that your interest (your freedoms and rights) does not outweigh ours.

3.3. For certain specific use-cases, we will base our use on your consent, which you give freely and may revoke at any time. In the event that you revoke your consent, we will cease our Processing of your Personal Data which is Processed on the basis such consent.

3.4. There may also be situations requiring us to collect personal data to comply with law.

4. COLLECTION OF PERSONAL DATA

4.1. While using our Service, we ask you to provide us with Personal Data. The Personal Data can be provided directly from you or indirectly and is Personal Data, such as;

- information you choose to send to us or provide us with, for example when you create an account and a profile with information such as e-mail, name and any other information you enter when you, for example, link the Service to your Facebook account or other similar third-party services,

- information about your family members if you choose to pride us with such information. Note that you are responsible for collecting you family members
consent prior to providing us with such information,

- your devices IP address, your saved areas,

- when you use and for what you use our Services for, such as log activity, password and pages you visit,

- the kind of phone / tablet and operating system you are using, the city, language settings and country where you are located when using our Services, what version of Services you are using, what version of the terms you have approved, if you have approved push notifications and newsletters.

- your payment details such as your credit card type and expiration date details of such card if you choose to subscribe to the paid Service as well as information you provide to our payment service provider to enable such paid Service.

4.2. When you use the Service, or visit our website, for example, we also collect information of your activity and choices through our own or third-party cookies and other tracking technologies, such as beacons, tags, and pixels. This is done, for instance, to make it easier for you to log in, to remember your preferred settings, to give you marketing that is especially relevant to you, and for us to assess how effective advertising is. Our cookie policy is available on our website and provides additional information regarding our usage of cookies.

5. USE OF PERSONAL DATA

5.1. We will use collected Personal Data to

- administer our Service and for internal operations, including troubleshooting, data analysis, testing statistical and survey purposes,
- to improve our Service to present content in the most efficient manner for you,
- for trend monitoring, marketing and advertising,
- for proposes made clear to you when submitting Personal Data.
- as part of our efforts to keep our Service secure.
- provide customer support for you and other users.

5.2. You may opt out of receiving any marketing or advertising information from us by following the unsubscribe link or instructions provided in any email we send or by contacting us at support@astoryaday.com.

6. SHARING OF DATA TO THIRD PARTIES

6.1. We use external partners to provide the Service, for example for cloud service for storing data. We may share your Personal Data with third party vendors, consultants and other service providers. These companies include for example website analytics companies (i.e., Google Analytics), payment processing providers.

6.2. Your Personal Data will be disclosed to the following actors who are personally responsible for their processing of your Personal Data:
- Google LLC and its affiliates. Read more about Google Analytics and Google's processing of your personal data here https://policies.google.com/privacy
- Apple Inc and its affiliates. Read more about Apple Inc and Apple Inc's processing of your personal data here https://www.apple.com/legal/privacy/en-ww/

6.3. Should A story a day AB change ownership, or sell its business to a third party, we may transfer the Personal Data to the new owner within the new company structure.

7. HOW LONG WE STORE YOUR PERSONAL DATA

7.1. We only process your Personal Data for as long as we, with legitimate interests, may process your Personal Data.

7.2. Other Personal Data, for example account information, might be retained for longer period of time based on the contract you have with us or if the Processing is based on our legitimate interest.

7.3. The time periods vary for the type of Personal Data we Process, for example:
- Some Personal Data is deleted on an ongoing basis.
- Some Personal Data, such as account information, may be retained for a longer period of time based on our contractual relationship.
- We Process certain Personal Data for a longer period of time against the background that we have a legitimate interest or to comply with current legislation. Such treatment refers to, for example, network improvement, fraud prevention and record keeping.

7.4. No Personal Data will be Processed longer than 24 months, unless you have given us your consent to continue the Processing;
1) after the end of your subscription period;
2) from the date you have contacted us to receive support or for other purposes we will store your personal data after resolving your latest support ticket (e.g. issues and requests) (i.e., support service);
3) or from the date any other service we may provide you has ended.

8. WHERE IS YOUR PERSONAL DATA STORED?

8.1. The Personal Data is stored at servers located at Laursen Rävstigen 20 A, 433 50 Öjersjö, Sweden.

9. DATA SECURITY

9.1. We use the level of security that is the industry standard when it comes to encryption, storage, firewalls, backups etc.

9.2. Note that no system is 100% secure and there is always a small risk that data will end up in the wrong hands. By using our Service, you accept this risk and will not hold us liable for any unauthorized entry or use, hardware or software failure or other factors that may compromise the security of Personal Data at any time.

9.3. If you believe that we incorrectly Process your personal information, you can file a complaint with the Data Protection Authority in your country (such as Swedish Authority for Privacy Protection, www.imy.se).

9.4. We encourage you to use a strong password so that no one can guess your login details.

10. YOUR PRIVACY RIGHTS

10.1. You own your Personal Data and therefore you have rights to understand how your
Personal Data is Processed.
The Processing might vary, depending on how the Personal Data is Processed.

10.2. You have the right to;

- get confirmation on whether or not we are Processing your Personal Data, information about such Personal Data, why we use it, how it is shared and for how long we store it. You can also get a copy of your Personal Data.

- in some cases, request that we delete your Personal Data. This is the case for example where the Personal Data is no longer necessary given the purposes it was collected for, or if you withdraw a consent, you have given, and we do not have any other legal reason to keep your Personal Data.

- object to our use of your Personal Data when our basis for using it is our legitimate interest or when we use it for marketing purposes. In some cases, we can continue to use your personal data even if you have objected to our use. This5can be if we show compelling legitimate reasons that outweigh your interests or if needed in relation to legal claims.

- correct or update any inaccurate Personal Data and ask us to have incomplete Personal Data completed. When possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.

- request that we restrict our use of your Personal Data. This could be the case when accuracy of your Personal Data is questioned by you, or the Processing is unlawful, but you do not wish it to be deleted and instead you want us to restrict our use of it.

- file a complaint with a supervisory authority. You can to this in the EU/EEA member state where you live. For us, the Swedish Authority for Privacy Protection (in Swedish Integritetsskyddsmyndigheten, or short, IMY) is the primary supervision authority. You also have to contact your national supervisory authority or seek remedy from a national court.

- at any time to withdraw any given consents to our use of your Personal Data.

10.3. Please note that we may ask you to verify your identity before responding to such requests in accordance with this section 9.

11. ACCOUNT DELETION

11.1. You can delete your A story a day account at any time by sending an e-mail to support@astoryaday.com. Please note that we will then delete things that you have registered, including photos. This data cannot be recreated.

12. LINKS TO OTHER SITES

12.1. Our Service may contain links to third party webpages not operated by us. If you click on a third-party link, you will be directed to that third party's site.

12.2. We strongly advise you to review the privacy policy of every site you visit.

12.3. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party webpages or services, including without limitation these third parties’ privacy policy’s and how such third parties process your Personal Data.

13. CHILDREN'S PRIVACY

13.1. We are committed to protecting the privacy of children who use our Service. We do not collect any personal information without verifiable parental consent, in compliance with  GDPR. All collected data is used solely to enhance the user experience and is securely stored.

13.2. We do not knowingly collect Personal Data from Children. If you are a Child, please do not attempt to register for our Services or send any of your Personal Data to us. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us.\

13.3. If we become aware that we have collected Personal Data from Children without verification of parental consent, we will delete such Personal Data from our servers as quickly as possible.

14. CHANGES TO THIS PRIVACY POLICY

14.1. From time to time, it may become necessary to make changes to this Privacy Policy. We will alert you by placing a notice on our website.

14.2. You can see when this Privacy Policy was last updated by checking the date at the top of this page.

14.3. You are responsible for periodically reviewing this Privacy Policy and keep up to date on any updates and / or changes.

15. CONTACT US

15.1. If you have any questions about this Privacy Policy, please contact us at support@astoryaday.com.

15.2. You have the right at any time contact or files complaints with the relevant data protection authority.