Privacy Policy

(Last modified March 17, 2021)

Welcome!

Welcome to HexMap. We hope that you will appreciate using our “Services”, which may be visiting or using our website at https://www.hexmap.io/ or any subdomain thereof (the “Website”), accessing or using the HexMap dashboard at https://dashboard.hexmap.io/ or any subdomain thereof (the “Dashboard”) or using our “Application”, which refers to the app for iOS or Android called HexMap that you may have downloaded onto your handheld device (the “Device”).

We want you to know we take your privacy and protection of personal data very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you use the Services or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully.

If you are an Application user, you will be referred to in this Policy as a “User”. As a User, you may have learned about and been asked to download the Application from one of our third-party partners (each, a “Partner”) and your use of the Application will be associated with that Partner, who will provide you with one or more study codes in order to have access to the full functionalities of the Application. Please note that it is possible for your use of the Application to be associated with more than one Partner at a time. Partners (and their employees, contractors and affiliates) are the primary users of the Dashboard, which is not accessible by Users. This Policy applies to Users, Partners and visitors to the Website. Where necessary, this Policy will clearly identify what parts of the Policy apply to you.

If you are a User, following the acceptance of this Policy (the details of which are set out below), you will be asked to accept the privacy policy and terms of use of the Partner that asked you to download the Application. A Partner’s use of your personal data is governed by that Partner’s privacy policy – HexMap has no control over any Partner’s privacy policy and if you are not comfortable with a Partner’s privacy policy, you should delete the Application right now.

Acceptance

By downloading the Application on your Device, by tapping an acceptance button upon your use of the Application for the first time or by creating an account to access the Dashboard, you hereby accept to be bound by the terms of the Policy. By submitting personal data to us through the Application, the Dashboard, the Website or otherwise, you consent to HexMap’s collection, use and disclosure of such personal data in accordance with this Policy (as amended from time to time) and as permitted or required by law. If you do not agree to all the provisions contained in the Policy, you are not authorized to use the Services. If you have downloaded the Application and do not agree to all the provisions of the Policy, you must delete the Application from your Device.

Key Elements of this Policy

Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.

Personal data we collect from you but only with your consent
Contact Information
Account Information
Personal data collected via your inputs to and your use of the Application
What we do with it
Communicate with you and manage our relationship, depending on your relationship with us
Manage your Dashboard account, and enable logging in to the Dashboard
Ensure the functional operation of the Application and improve the Services
Third parties we share it with
Companies that provide our communications services, such as Mailgun or Elastic Email
Companies that provide the infrastructure for the Services, such as OVHcloud and Backblaze
Partners; companies that provide the infrastructure for the Services, such as OVHcloud and Backblaze

Some Terms

Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.

Data Protection Laws” refers to the laws that are designed to protect your personal data and privacy in the place where you live. These include: (1) the “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council; and (2) “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada. HexMap is committed to adhering to all these applicable Data Protection laws.

Personal data” refers to information that we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA, the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information.

Other terms and definitions used in this Policy may be found in our Terms of Use and will have the same meaning in this Policy as they do there.

About Us and Contacting Us

HexMap Inc. is a duly-incorporated company under the laws of Canada. Where this Policy refers to “HexMap”, it may refer to HexMap Inc. and / or its shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns, depending on the context.

Under the GDPR, HexMap is a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; and the word “processing” is used in this Policy in that way. In the context of our relationship with Partners, HexMap is a “data processor”. That means we also process personal data as instructed by Partners and on their behalf.

If you want to ask us anything about what is in this policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can email:

HexMap Privacy Officer
privacy@hexmap.io

Or inquiries can be mailed to:

HexMap Privacy Officer
410-500 Saint-Jacques Street
Montréal, Québec H2Y 1S1
Canada

Your Rights

You have the following rights regarding your personal data held by HexMap, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. These rights may be exercised at no cost to you. Notwithstanding that, exercising certain of these rights may affect your ability to use some or all of the Services’ features.

  1. The right to withdraw your consent at any time for HexMap to process your personal data;
  2. The right to have your personal data erased from HexMap’s records;
  3. The right to access your personal data and any relevant information around its processing and use;
  4. The right to have a copy of your personal data given to you in an easy to read format so that you can transfer it to another data processor;
  5. The right to have your personal data corrected or updated if you believe it is inaccurate or out of date;
  6. The right to opt out of marketing communications we send you, at any time, and the right to refuse any marketing targeted at you by HexMap;
  7. The right to know whether HexMap shares your personal data (and if so, who gets it). Please refer to that information elsewhere in this Policy, though you can contact our Privacy Officer if you need additional information or clarifications;
  8. The right to demand that HexMap not sell your personal data; and
  9. The right to restrict the processing of your personal data if it is inaccurate or if our processing or use of it is against the law.

If you wish to exercise any of these rights, please contact our Privacy Officer at the contact information above or refer to certain relevant sections further in this Policy.

Personal Data Collected from You and What We Use It For

In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to HexMap.

Personal data category
Contact Information
Account Information
Personal data collected via your inputs to and your use of the Application
Personal data processed
Your name and email address
Your email address
Current location, home, work and study locations, trips between these three locations and others, type of occupation, age bracket, gender, email and any other personal data requested by a Partner that you input to the Application, which shall be specified in such Partner’s privacy policy
What we use it for(the “purpose” of processing)
To communicate with you and to manage our relationship, depending on your relationship with us
To create a Dashboard account for you and to provide you with regular access to the Dashboard
To ensure the functional operation of the Application, to improve the Services and to provide support to Users
Legal basis for processing under the GDPR
Your consent in giving us this information
Your explicit consent in giving us this information and the performance of a contract between you and us
Your explicit consent in giving us this information; the performance of a contract between you and us and the performance of a contract between you and a Partner

Where you have provided personal data further to the contract between you and us, if you fail to provide such data or withdraw your consent to use such data, we will no longer be able to provide certain features of the Services to you.

Sensitive Personal Data

We do not collect any of what the GDPR considers sensitive personal data from you, unless you voluntarily submit it on the “Contact us” page of the Website, which we encourage you not to do.

Who We Transfer Your Personal Data To

We routinely share some of your personal data with certain types of third parties who are identified in the table below, along with what they do with it. Some of those third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area — please see the “Transfer of Your Personal Data Outside of the European Economic Area” further down in this Policy for more information including on how we safeguard your personal data when this occurs.

We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of HexMap’s Terms of Use or other contract that governs your relationship with us; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Services infrastructure or the internet in general (such as voluminous spamming or denial of service attacks).

We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with HexMap (in which case we will require such entities to honour this Policy); (2) if HexMap merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).

We will never share your personal data with other third parties except under these circumstances. We do not sell your personal data to any third party for direct marketing purposes or any other purpose.

Personal data category
Contact Information
Account Information
Personal data collected via your inputs to and your use of the Application
Analytics identifiers(including IP addresses and device identifiers)
Who we transfer it to
Companies that provide email services, specifically Mailgun or Elastic Email, as detailed more fully in the Email Communications section below
Companies providing technical infrastructure for the Services, specifically OVHcloud and Backblaze
Partners; companies providing technical infrastructure for the Services, specifically OVHcloud and Backblaze
Companies that provide data analytics, specifically Sentry.io and Firebase
What they do with it
Send you emails
Control your logging in to the Dashboard so that it can be provided to you, and for record-keeping
Conduct their own research and analysis, which they will inform you about in separate communications with you
Provide us with analytics as to how the Services are used and to trace fraudulent activities

Aggregated Information

In addition to the information collected by the analytics identifiers described in the previous section, we may also generate, use and disclose aggregated and / or anonymized information and statistics about Users for operational, strategic and research purposes. However, no User will be individually identifiable from these aggregated and / or anonymized information and statistics.

Tracking Technology (“Cookies” and Related Technologies)

HexMap uses tracking technology (“cookies” and related technology, such as tokens, tags, pixels and web beacons) in connection with the Services and by interacting with the Services, you agree to their use. Cookies are small text files placed on your computer or Device when you visit a website or use an online application or service, in order to track use of the site, application or service and to improve the user experience by storing certain data on your computer or Device.

Specifically, we may use cookies and related technologies for the following functions:

Your browser can be set to refuse cookies or delete them after they have been stored. Please note that deleting or blocking certain cookies may reduce your user experience by requiring you to re-enter certain information, including information required to use the Services.

Email Communications and Compliance with Anti-Spam Laws

HexMap uses Elastic Email to manage the “Contact us” page on the Website, and MailGun to send out emails related to the Dashboard (Elastic Email and MailGun, collectively the “Email Service Providers”). Personal data is transferred to the Email Service Providers in order to manage our communications with you and for the emails to be sent out properly. Your Contact Information is only used to send out emails; the Email Service Providers do not use this Personal Information for any other purpose, and will not transfer or sell your Personal Information to any other third party. For more information, please refer to Elastic Email's Privacy Policy and MailGun's Privacy Policy.

HexMap’s practices with respect to its email are designed to be compliant with anti-spam laws, specifically the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23). If you believe you have received email in violation of these laws, please contact us using the contact information further up in this Policy.

How the Application Accesses Your Device

The following is a complete listing and description of what functions on your Device that were developed by third parties are accessed and / or modified by the Application. Unless otherwise specified, these permissions apply to both the iOS and Android versions of the Application. Where noted, these will function with explicit user permission only. You acknowledge that denying explicit permission may affect or reduce your user experience with the Application.

Uninstall of the Application

You may uninstall the Application; uninstall methods may vary depending on your Device or iOS or Android version. HexMap has no control over the uninstall function and denies any responsibility for your use thereof, and any data or personal data sent to third parties as a result of such activity.

How We Protect Your Personal Data

We have implemented very strict technical and organisational procedures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws require us to do so, and within the time frame required by the applicable Data Protection Law.

HexMap uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use OVHcloud and Backblaze, leaders in secure data, as hosting partners to provide the necessary networking, storage, and related technology required to operate the Services, and both OVHcloud and Backblaze were selected for their high standards of security, both electronic and physical.

Finally, all information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check HexMap’s valid SSL security certificate. Additionally, all of our backups are stored encrypted with AES-256 ciphers.

Transfer of Your Personal Data Outside of the European Economic Area (EEA)

For our European users, we endeavour to keep your personal data inside the EEA. However, certain of our data processors (and HexMap) are in other countries where your personal data may be transferred.

However, these countries are limited to countries with particular circumstances that protect your data, specifically:

That’s it! You have the right, however, to refuse to have your data transferred outside the EEA. Please contact our Privacy Officer to make that request. Please note that making this request may prevent you from being able to use certain features of the Services.

Supervisory Authorities and Complaints

If you are in the EEA, under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about HexMap’s data practises, we invite you to contact the supervisory authority in your country. If you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.

‍The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.

Data Retention

Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your Account Information for as long as you have an account with us.

Automated Decision-Making

HexMap does not use any automated decision-making processes in providing the Services.

Children’s Privacy Statement

The Services are not intended for children under the age of 16. We do not knowingly collect any personal data from a child under 16. If we become aware that we have inadvertently received personal data from a person under the age of 16 through the Services, we will delete such information from our records.

Changes to This Privacy Policy

The date at the top of this page indicates when this Policy was last updated. Every now and then, we will have to update this Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL or in the Application, and we will always post a notice on the Services if we make significant changes.

© HexMap Inc., 2021