Effective Date: November 20, 2019
The Ghostery Plans and Products (“GPP”) are owned by Cliqz International GmbH (“Cliqz” or “Company”), which is headquartered at Arabellastrasse 23, 81925 Munich, Germany. The Company, as the responsible body under the German Data Protection Law, takes the protection of your personal data very seriously and will always offer you the GBE and its functionality with your privacy in mind.
We also recognize that the GPP are popular because people want to be informed and empowered. We share the belief that privacy, when done right, is empowering, and that is why privacy is central to the GPP and new functionality that we may add. Therefore, we only collect data to build our products for the benefit of our users and we believe that we as a company should never have any personal data (“Personal Data) about our users unless they affirmatively provide it to us.
The core functionality of the GPP is to inform users what third-party tracking technologies (“Trackers”) are tracking them on any given website or device application so individuals can exercise personal control over that activity by blocking them for a cleaner, faster, safer browsing experience and use of their own devices.
II. Basis to Collect and Use Personal Data
There is no obligation on your part to provide your Personal Data. However, if you do, we have a legitimate interest to collect and use it, namely so we can provide products or services, or complete a transaction with you.
III. Notion of Personal Data
Personal Data means any information concerning the personal or material circumstances of an identified or identifiable individual such as name and age. Non-personal data are all data that cannot be used to identify an individual, such as statistics about usage of a website.
IV. What Personal Data are collected
User Account: When you create a user account, we will collect the following Personal Data: name, email address.
Many GPP users had previously requested the ability to open accounts so they can receive product information and also take advantage of new functionality, certain Ghostery products, and higher tiers of service. You are not required to open a user account in order to use the Ghostery Product Extension (GBE) with the Basic plan service tier. If you choose to open a user account in this case, you can do so either when you download the GBE, or any other time through the GBE settings. At any time you can deactivate your user account, at which time you will no longer have access to the services that a user account offers.
IP-Address: We do not differentiate between static or dynamic IP addresses – that is driven at the user level – but please see the Security section below to learn more about the security measures we take to protect data – including your IP-address – that the GBE collects.
V. How Personal Data are used
The use of the GPP Personal Data that we collect when you open an account is used for: (i) syncing your GPP settings across browsers and devices, (ii) serving as your login credentials, and (iii) communicating directly to you through your email address in order to give you information about our products, services, updates and upgrades (in certain cases for a fee).
IP-addresses are solely collected for geolocation purposes but only on Zip Code level or above (for example city, county, continent) to improve the GBE. We never store IP addresses.
VI. Collection of Non-Personal Data
When you download the Ghostery Browser Extension and Ghostery Insights products, they collect on an ongoing basis the following data: web browser, operating systems, and opt-in settings to share Tracker information with the Company, when an installation, upgrade, or uninstallation occurs, and whether the extension is active or engaged by you.
The use of the aforementioned non-personal data is limited to: (i) communicating through the CMP (see VII.) – since we don’t have your name or email address – in order to share product information or updates and Company news, (ii) for internal analytical purposes such as accurately counting the number of browser extension downloads, (iii) providing the services of the Ghostery Start Tab, which may include sharing of the non-personal data with other Cliqz products you have installed, locally on your device, or (iv) surveying our users from time to time.
When using Ghostery Midnight, if errors occur within the Midnight application while in use, or if the application crashes or causes other applications to break or crash, non-personal data about the error(s) will be generated to help us identify the cause of the error so that we can fix it in a future update. These error reports (“crash logs” or “logs”) contain information such as the state of the application, operating system, and device at the time of the crash; other application names and data (depending on subscription plan); data about websites visited while Midnight is active (depending on subscription plan); and error information. No personal data is collected, and nothing in these logs can be used to personally identify the user. These logs are collected and saved locally on the user’s device, and, upon release of Midnight, are not automatically sent to Ghostery. If Ghostery will start collecting these logs, we will ask for your permission in doing so.
VII. The Consumer Messaging Platform (“CMP”)
The CMP is used from time to time as a way for us to effectively and generically communicate to our users, while still honoring their privacy. The CMP is automatically turned on, but you can easily turn it off by going to the GBE options page and following the instructions provided. If you turn off the CMP, you can still use the GPP, but you won’t receive any generic communications from us.
Offers, also known as Ghostery Rewards, is turned on by default and allows companies to show relevant marketing offers to users based upon an algorithm we created that anonymously determines intent and therefore particular commercial offers that may be of interest to you. This new functionality does not rely upon collected Personal Data and you can opt out of it at any time.
IX. Human Web
We developed a technology called Human Web, which is turned on by default, and creates anonymous group models that power the private quick-search, anti-tracking and anti-phishing technologies featured in the Cliqz products and will be soon be featured in the GPP.
Data Collection: In order for Human Web to function we automatically collect non-private URLs, search queries along with search engine results pages, suspicious URLs that could potentially be phishing websites, information related to safe and unsafe trackers, and information related to the prevalence and performance of Trackers.
Data Use: The data that we collect so Human Web can work is anonymized, aggregated and transmitted through the Human Web Proxy Network and used to improve the search, anti-tracking and anti-phishing features in the Cliqz browser.
For further information please go to https://cliqz.com/whycliqz/human-web.
X. Virtual Private Network (“VPN”)
For the VPN technologies we provide, we use a trusted third party provider. This service is operated by FoxyProxy LLC. Note that FoxyProxy is legally obliged to NOT log any personal data – including explicit or implicit network identifiers. FoxyProxy’s services cannot read message content (as it is encrypted). No data is logged except bandwidth use. That information is collected in order manage network performance. We do not collect or store any IP address information.
XI. Data Processing Abroad
Although the Company is located in Germany, it partly operates out of the United States. The data we collect, personal or otherwise, are located on servers based in the United States. If you are accessing or using GPP from the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that you may be allowing the collection or transferring of your personal data in or to the U.S. However, we have a strong data privacy framework in place to ensure an adequate level of protection for your Personal Data.
XII. Data Retention
If you deactivate your user account, the Company retains the collected Personal Data if and for as long as it may be required by law (for example to fulfill retention periods prescribed by law) or judicial order. The Company will use this personal data only for those purposes and retains it only as long as prescribed by law. After that the Personal Data will be deleted.
XIII. Data Portability & Erasure
In compliance with the GDPR, the Company provides features available in the product menu that allow users to easily download and delete the Personal Data associated with their user accounts. If users choose to download their information, it will be downloaded as a machine-readable CSV file and will include their name, email address, and your account settings and preferences. If users choose to delete their account, all Personal Data associated with the account will be completely and permanently deleted from the Company servers.
The Company has reasonable and appropriate technical, physical and administrative safeguards in place for a company of our size and complexity to protect the data that is collected. Some of the specific security measures we take include instantly hashing the origination IP addresses using very strong encryption technology to protect your privacy, whereupon the collected IP addresses and user agent information is destroyed. In addition, to further preserve your security, the GPP do not collect any information on URLs beyond the path query string.
XV. Contacting the Company
At any time the user has the right to object any use of his personal data and can do so by writing to the Company at the physical address provided in the beginning of the document or by emailing the Company at email@example.com If you object will be necessary to prove that you are the owner of the account. The Company has the right to answer your inquiry electronically. Please contact for this and all other inquiries, comments or concerns about these practices by email at firstname.lastname@example.org.
XVII. Payments & Subscriptions
We are offering paid subscriptions to use the GPP with a variety of features. There are several subscriptions at different prices charged on a recurring monthly or yearly basis, depending your preference.
To calculate the appropriate regional VAT/GST/sales tax for each payment, we use the service Avalara. To calculate the applying taxes Avalara needs some personal data (country, postal code). This is the only information Avalara receives. Based on the postal code, Avalara determines how much tax should be charged and recorded via Stripe.