Privacy Notice

August 1st 2020

This privacy notice has been adopted by ExtoLabs LLC  (“ExtoLabs ”) for processing of personal data relating to you as a (i) visitor of our websites or social media profiles/pages, (ii) customer buying our products online or such a potential customer, and to (iii) registered user of our services and products.

EXTOWALLET IS A HARDWARE WALLET AND DOES NOT PROVIDE EXTOLABS ANY ACCESS TO YOUR PRIVATE KEYS, RECOVERY PASSPHRASE, BIOMETRICS OR PIN DATA, ASSETS, BALANCES OR TRANSACTIONS. EXTOWALLET IS A HARDWARE WALLET THAT SECURES YOUR CRYPTO ASSETS AND ALL OF THE ABOVE DATA IS IN YOUR POSSESSION ONLY. YOU ARE RESPONSIBLE FOR MAINTAINING RECOVERY KEY PHRASE AND PINS FOR YOUR WALLETS. EXTOLABS CAN NOT RECOVER OR ACCESS ANY OF YOUR ASSETS. 

This privacy policy applies to personal information such as contact information or other personal information we collect on our website or through the iOS and Android App stores. 

This policy does not apply to information collected by:

•    Us offline or through or through any other means, including on any other website operated by ExtoLabs or any third party (including our affiliates and subsidiaries); or
•    Any third party (including our affiliates and subsidiaries), including through any application or content (including advertising) that may link to or be accessible from the Website

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our website, products, or services. By accessing or using this website, using our products or services, you agree to this privacy policy. This policy may change from time to time (see Changes to the Privacy Notice). Your continued use of this website, our products or services, after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates.


1.    Introduction

1.1    Your privacy is important to us and we strive for a high level of protection in all processing of personal data. Within the EU/EEA, the General Data Protection Regulation (GDPR) applies from 25 May 2018.

1.2    In accordance with applicable data protection legislation, ExtoLabs, otherwise specified at the end of this Privacy Notice, is the data controller and responsible for the processing of your personal data as set out below. If you have any questions about this information, or if you wish to exercise any of your rights as set out below, contact ExtoLabs via the contact information listed under Section 6 below.
1.3  This website and our products and services are not intended for children and we do not knowingly collect data relating to children.

2.    Processing of Personal Data
2.1    General 
2.1.1 The term 'personal data' refers to such information which, directly or indirectly, may refer to you as an individual. Examples of such data are name, email address, government-issued identification number, billing information, contact details, IP address, and user behavior. Personal data processing refers to any action that we or a third party that we have engaged take with the personal data, such as collection, registration, and storage. 
2.1.2Personal data may only be processed for specified and explicitly stated purposes and may not be subsequently processed for any purpose that goes beyond these stated purposes.


2.2     Websites and Social Media
2.2.1    We collect personal data such as name, e-mail address and other information which you voluntarily provide, e.g. when you choose to interact with ExtoLabs by signing up for updates such as newsletters, deals and offers, webinars, trade shows, events, etc. through email (which you can opt-out from via a link in each message sent through email). We also automatically receive and store information from your web browser, such as IP address, language preferences cookie information, and the pages you visit, to log files on our server. We use the information collected to respond to your requests regarding products and services, to improve the content on our websites and the services, to track and prevent abuse of our websites and services, and to develop anonymous usage statistics.
2.2.2    We also use personal data for direct marketing and advertising in accordance with applicable law and market practice. We use the information we collect with regard to how you, as a user, use the websites so that we can analyze search and usage behavior and be able to provide you with personalized content. Personal data may also be processed indirectly in connection with the development and administration of ExtoLabs 'sExtoLabs’ IT systems.
2.2.3    Legal ground: (i) performance of a contract where you request services/resources through the websites and (ii) legitimate interest for other processing activities, such as for the purpose of improving services and the content of the websites as well as for prevention of abuse and statistical purposes. In case your consent is required for any of the above purposes, we will obtain such consent before we process your personal data for such purpose (if you withdraw the consent, that will not affect the lawfulness of processing based on consent before its withdrawal). See also our Cookie Notice
2.2.4    We delete collected personal data when the purpose of the processing has been completed. Our Cookie Notice includes retention periods in respect of cookies that we use.


2.3    Customer buying our products online or such potential customers
2.3.1    When you are a customer buying products online, or a potential customer inquiring about our products and services, we may process the information you have volunteered, such as name, home and/or delivery address, telephone number, e-mail address, payment information, historical order information and product you bought. When you buy or inquire about, our products online via our Website, we also collect the information specified in Section 2.
2.3.2    Legal ground: (i) performance of a contract and legal obligation where you have bought a product online and (ii) legitimate interest for other processing activities, such as for the purpose of improving services and the content of the websites as well as for statistical purposes. In case your consent is required for any of the above purposes, we will obtain such consent before we process your personal data for such purpose (if you withdraw the consent, that will not affect the lawfulness of processing based on consent before its withdrawal). 
2.3.3    We delete collected personal data when the purpose of the processing has been completed. Some of this information is retained for the duration required by applicable bookkeeping legislation.


2.4    Registered users of our services and products
2.4.1    We collect personal data such as name, address, phone number, e-mail address, payment information, designation, and other information that you voluntarily provide. When you use our services via our Website, we also collect the information specified in Section 2.2. We use the information collected to provide you with the services/products, to respond to your requests and handle support cases regarding products and services, to improve the support/services, and to develop anonymous usage statistics.
2.4.2    Legal ground: (i) performance of a contract where you request services/resources through the website and (ii) legitimate interest for other processing activities, such as for the purpose of improving the services, support, and content of the websites as well as for statistical purposes. In case your consent is required for any of the above purposes, we will obtain such consent before we process your personal data for such purpose (if you withdraw the consent, that will not affect the lawfulness of processing based on consent before its withdrawal). See also our Cookie Notice.
2.3.3    We delete collected personal data when the purpose of the processing has been completed.


3.    Security for the protection of personal data
We protect your personal data against unauthorized or unlawful processing and against accidental loss, destruction or damage, by implementing appropriate technical and organizational security measures.
We also limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. 
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.


4.    Restrictions on the Disclosure of Personal Data
4.1    We may appoint external partners to perform tasks on our behalfs, such as providing IT services or helping with marketing and recruitment, administration of press releases, data analysis, or statistics. The performance of these services may mean that our partners, both within and outside the EU/EEA, are able to gain access to your personal data. Companies that process personal data on our behalf must always sign an agreement with us so that we are able to ensure a high level of protection of your personal data even with our partners.
4.2    Special safeguards are taken with regard to partners outside the EU/EEA, such as signing agreements that include the standardized model clauses for data transfers adopted by the EU Commission and which are available on the EU Commission's website.
4.3    We may also disclose your personal data to third parties, for example, the police or other government or public authorities, if it concerns criminal investigations or if we are otherwise required to disclose such data by law, government or public authority decision. We will not disclose your personal data to any extent other than described in this section.
4.4    We may also disclose aggregated or de-identified information about our users, and information that does not identify any individual, without restriction. 


5.    Your Legal Rights
5.1    Under certain circumstances, you have rights under data protection laws in relation to your personal data. Please review the agreement to find out more about these rights:

  • Request access to your personal data.

  • Request the correction of your personal data.

  • Request erasure of your personal data.

  • Object to processing of your personal data.

  • Request restriction of processing your personal data.

  • Request the transfer of your personal data.

  • The right to withdraw consent.

You have the right to:

Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

  • If you want us to establish the data's accuracy.

  • Where our use of the data is unlawful but you do not want us to erase it.

  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.

  • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

6.    Your Rights and the Right to File a Complaint

Under applicable data protection legislation, you are entitled, at any time, to request access to the personal data that is processed about you, to have erroneous personal data corrected, to request that we shall stop processing and delete your personal data, to request that the processing of your personal data is restricted, to exercise your right to data portability, to withdraw consent to particular processing (where such consent has been obtained) and to object to the processing of your personal data. In such an event, contact ExtoLabs via the contact details listed below. You are also entitled, at any time, to file a complaint with the relevant supervisory authority, the Swedish Data Protection Authority, if you consider that your personal data has been processed in contravention of applicable data protection legislation. We would, however, appreciate the chance to deal with your concerns before you approach the Swedish Data Protection Authority, so please contact us in the first instance.


7.    Data Controller and Contact Details
7.1    Data Controller
ExtoLabs is the data controller in respect of the different processing activities covered by this Privacy Notice:
7.2    Contact Details
If you have any questions on how we process your personal data or want information about further contact details for the data controllers above, please contact us at support@ExtoLabs.com 


8.    External Links
Our websites may sometimes contain links to external websites or services that we do not control. If you follow a link to an external website, you are encouraged to review the principles for processing of personal data and information about cookies that apply to the website or service in question.


9.    Person’s Under the Age of 18
9.1    Our website, products, and services are not intended for anyone under the age of 18 . No one under age 18 may provide any personal data to us. We do not knowingly collect personal information from anyone under the age of 18. If you are under 18, do not use or provide any information on this website, make any purchases through the Website, or provide any information about yourself to us, including your name, address, telephone number, or email address. 


10.    California Privacy Rights
10.1    If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. 

10.2    California's "Shine the Light" law (Civil Code Section § 1798.83) permits users of our App that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to info@extolab.com.


11.    Changes to the Privacy Notice
Occasionally we may, in our discretion, make changes to this Privacy Notice e.g. by making new versions available on our website or provide you with prominent notice as appropriate under the circumstances. You are encouraged to, therefore, visit our website from time to time to learn of any updates and make sure you read any such notice carefully.