Flyttr Privacy Policy

This privacy policy explains how our organization uses the personal data we collect from you when you use our website.

This Privacy Policy is issued on behalf of the Flyttr Group. Oxitec Ltd is the controller responsible for this Website.

Important information and who we are

This Privacy Policy is issued on behalf of Flyttr Group, so when we mention Flyttr, we, our, or us in this Privacy Policy, we are referring to the relevant company responsible for processing your data. In some cases, we will specify the relevant Flyttr Group company.

This Privacy Policy gives you information about how Flyttr collects and uses your personal data when you interact with us, including when you:

  • visit our website (www.flyttr.com);
  • subscribe to receive newsletters and other information from us;
  • request information from us or provide information to us;
  • supply goods or services to us (or you work for an organization that does); and
  • contact us by any means.

This Privacy Policy also applies to Shareholder Data that we might process from time to time. It does not apply to the processing of personal data when you are using our platform (www.flyttr.com/dengue), or when you are applying to work for a Flyttr Group company. The Website is not intended for children and we do not knowingly collect data relating to children.

Controller

The Flyttr Group is made up of the following entities:

Oxitec Ltd — Company number 04512301

71 Innovation Drive, Milton Park, Abingdon, Oxfordshire, OX14 4RQ, United Kingdom · info@flyttr.com · +44 (0)1235 832393

Oxitec do Brasil Tecnologia de Insetos Ltda. — CNPJ 15.696.374/0001-60

Pierre Simon de Laplace Avenue, 965, Module B1 – Techno Park, Campinas – SP – 13.069.320, Brazil · contato@flyttr.com · WhatsApp +55 19 98967-5605

Oxitec UK Holdings Inc. — Company number 5796957

1881 Grove Avenue, Radford, VA 24141, USA · info@flyttr.com

Oxitec Australia Pty Ltd — Company number (15) 673 846 609

Brisbane City, QLD 4000, Australia · info@flyttr.com

Oxitec Ltd is the controller and responsible for the Website. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us using the information set out below.

What data we collect

Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data about you, grouped as follows:

  • Identity Data: name, surname, title / job title or professional affiliation, age, gender, username or similar identifier, and organization details.
  • Contact Data: email, telephone, address, postal code.
  • Transaction Data: payment or billing details.
  • Technical Data: IP address, login data, browser type and version, time zone and geolocation, browser plug-ins, operating system and platform, device type and device ID.
  • Profile Data: your username and password, interests, preferences, feedback and survey responses.
  • Usage Data: information about how you interact with and use the Website, products or services.
  • Marketing and Communications Data: your preferences in receiving marketing from us and your communication preferences.

We do not collect special category (sensitive) personal data about you except in very limited circumstances — for example, if you inform us of dietary or access requirements for an event we organize, in which case your provision of the information indicates your consent. We may also collect and share aggregated data (such as statistical or demographic data) which is not personal data, as it does not reveal your identity.

How is your personal data collected?

We use different methods to collect data from and about you, including:

  • Your interactions with us — when you fill in online forms or correspond with us by post, phone, email or otherwise.
  • Automated technologies or interactions — as you interact with the Website we automatically collect Technical Data using cookies and similar technologies (see our Cookie information below).
  • Third parties or publicly available sources — including the organization you represent, analytics and advertising providers, providers of technical services, and public sources such as Companies House and social media platforms.

How we use your personal data

The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following: performance of a contract; legitimate interests (where we balance any impact on you and your rights); legal obligation; and consent (only where you have actively agreed, for example to receive a newsletter).

We use your personal data to manage our relationship with you or your organization; to process and deliver our solutions, including managing payments and recovering money owed; to manage relationships with suppliers; to notify you of changes to our terms or this policy and deal with your requests; to enable you to complete surveys; to administer and protect our business and the Website; to deliver and measure relevant content and advertising; to use data analytics to improve our service; to send you relevant marketing communications; and to manage relationships with shareholders and investors.

Marketing

We may ask you to indicate your preferences for receiving direct marketing from us. We will not share your personal data with any third party for their own direct marketing purposes. You can ask us to stop sending marketing communications at any time by following the opt-out links in any marketing communication, or by contacting us. If you opt out, you will still receive service-related communications.

Sharing your data

We will share your personal data with other entities within the Flyttr Group, all of which are required to protect your information consistently with this notice and applicable law, under an intra-group data sharing agreement. We may also share your personal data with vendors and service providers who support our operations; professional advisors (lawyers, auditors, insurers and consultants); the organization you represent; parties to whom we may sell, transfer or merge parts of our business; shareholders and investors; and regulators, law enforcement or public authorities where necessary. We do not sell, rent or trade personal data.

International data transfers

Whenever we transfer your personal data out of the UK or EEA (for example to Brazil or any other country in which the Flyttr Group operates), we ensure a similar degree of protection by relying on adequacy decisions or approved contractual safeguards. Please contact us if you want further information on the specific mechanism used.

Data security

We have put in place appropriate physical, technical and organizational data security measures to safeguard your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. We limit access to those with a business need to know, and we have procedures to deal with any suspected breach and to notify you and any applicable regulator where legally required. However, due to the risks inherent in the digital environment, Flyttr provides no guarantees that your personal data will not be unlawfully accessed by unauthorized third parties.

Data retention

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including satisfying any legal, regulatory, tax, accounting or reporting requirements. In some circumstances we will anonymize your personal data for research or statistical purposes, in which case we may use this information indefinitely without further notice.

Your rights

UK / EU data protection laws. Where applicable, you have the right to request access to your personal data; request correction; request erasure; object to processing based on legitimate interests; request the transfer of your data; withdraw consent; and request restriction of processing. To exercise any of these rights, please contact us. You will not usually have to pay a fee, and we try to respond to all legitimate requests within one month.

Data protection rights in Brazil (LGPD). If you are located in Brazil or your data is processed by Oxitec do Brasil, you have rights under the LGPD (Law No. 13,709/2018), including confirmation of processing; access; correction; anonymization, blocking or deletion; portability; deletion of data processed with consent; information about data sharing; the right to refuse consent and be informed of the consequences; revocation of consent; and review of decisions made solely on the basis of automated processing.

Complaints

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection (www.ico.org.uk), or to your national data protection regulator if you are based in the EEA. In Brazil, please contact the Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd. We would, however, appreciate the chance to address your concerns first.

Links to other websites

The Website may include links to third-party sites and content not related to Flyttr. We do not control these websites and are not responsible for their privacy statements. When you leave the Website, we encourage you to read the privacy policy of every website you visit.

Changes to this Privacy Policy

The date of the latest update will be shown at the top of this policy, and we'll inform you of any changes. Updates become effective once posted. It is important that the personal data we hold about you is accurate and current — please keep us informed if your personal data changes.

Cookies

Our website uses functionality cookies (to recognize you and remember your preferences), advertising cookies, and analytics and performance cookies (to understand how visitors interact with the site). You can set your browser not to accept cookies, though some website features may not function as a result. The analytics cookies we use include ss_cid, ss_cvr, ss_cvisit, ss_cvt, ss_cpvisit and ss_cookieAllowed, which identify unique visitors and track sessions on the site.

Contact us

If you have any questions, requests or comments about this Privacy Policy or the use of your personal data, or if you wish to exercise any of your rights, please contact Flyttr at dataenquiries@flyttr.com or +44 (0)1235 832393.