Privacy policy

BRAINCARE — PRIVACY POLICY

Braincare Limited ("Braincare", "we", "our", or "us") is committed to protecting and respecting your privacy.

1.     OUR APPROACH TO PRIVACY

This privacy policy sets out how we collect, store, process, transfer, share and use data that identifies or is associated with you ("personal information") when you use any website operated by us (including https://yourheights.com), any services we provide or otherwise interact with us (together the "Services").

2.     ABOUT US

Braincare Limited (company no. 08403776) is the data controller of the personal information we hold about you.

Our registered and postal address is 27 Old Gloucester Street, London, England, WC1N 3AX.

We are registered as a data controller with the UK Information Commissioner's Office under data protection registration number ZA381385.

Our data protection officer, Joel Freeman, can be contacted at privacy@yourheights.com.

3.     PERSONAL INFORMATION WE COLLECT ABOUT YOU AND HOW WE USE IT

The table at Annex 1 sets out the categories of personal information we collect about you and how we use that information. The table also lists the legal basis which we rely on to process the personal information.

More generally, you may provide us with personal information when you:

(a)   sign up to the website and complete your profile;

(b)   are using our website; and

(c)   communicate with us (whether online or by email).

4.     DATA RETENTION

We will only retain your personal information for as long as reasonably necessary to fulfil the purposes for which we collected it. To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, as well as the applicable legal, regulatory, tax, accounting or other requirements.

5.     RECIPIENTS OF PERSONAL INFORMATION

We may share your personal information with the following (as required in accordance with the uses set out in Annex 1 or as otherwise described below):

(a)   Service providers: we may share your personal information with third parties and other service providers that perform services for us or on our behalf, which may include providing subscription services, data hosting, data centre and storage facilities, communications, surveys and chat facilities, user relationship management, email and SMS marketing communications, advertising, technical support, error reporting and fixing, analytics, verification services and/or fraud prevention.

(b)   Purchasers and third parties in connection with a business transaction: your personal information may be disclosed to third parties in connection with a transaction, such as a merger, sale of assets or shares, reorganisation, financing, change of control or acquisition of all or a portion of our business.

(c)   Law enforcement, regulators and other parties for legal reasons: we may share your personal information with third parties as required by law or if we reasonably believe that such action is necessary to (i) comply with the law and/or the reasonable requests of law enforcement; (ii) detect and investigate illegal activities and breaches of agreements; (iii) enforce our terms and/or (iv) exercise or protect the rights, property, or personal safety of Braincare, its users or others.

(d)   Other members of the Braincare group: where applicable, we may share your personal information with our affiliates (for example, where they provide services on our behalf) or where such sharing is otherwise necessary in accordance with the uses set out in Annex 1.

 

6.     MARKETING AND ADVERTISING

From time to time, we may contact you with information about the Services, including sending you marketing messages and asking for your feedback on our Services.

The marketing messages we send will be by email and/or text message. For some marketing messages, we may use personal information we collect about you to help us determine the most relevant marketing information to share with you.

We will only send you marketing messages if we have your consent or, if consent is not required under applicable law, you have not opted out of receiving messages from us. You can withdraw your consent, or opt out of receiving further communications at a later date, by clicking on the unsubscribe link at the bottom of our marketing emails or contacting our support team at support@yourheights.com, or, if you are logged in to the website, toggling your preferences within your account settings.

Unsubscribing from marketing messages will not unsubscribe you from system or legal notifications which we may need to send as part of the Service we provide. From time to time, we may need to contact you by emailtext or via our support team.

 

7.     STORING AND TRANSFERRING YOUR PERSONAL INFORMATION

Security. We implement appropriate technical and organisational measures, including encryption, to protect your personal information against accidental or unlawful access, destruction, loss, alteration, or damage. All personal information we collect will be stored on our secure servers. Where data processing is carried out on our behalf by a third party, we take steps to ensure that appropriate security measures are in place to prevent unauthorised disclosure of personal information.

Despite these precautions, however, we cannot guarantee the security of information transmitted over the internet or that unauthorised persons will not obtain access to personal information.

International Transfers of your Personal Information. The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where our affiliates and our third party service providers have operations. If you are located in the UK or European Economic Area ("EEA"), your personal information may be transferred outside of the UK and EEA respectively to a country which is not recognised by the UK or European Commission as ensuring an adequate level of protection for personal data. These international transfers of your personal information will be made pursuant to appropriate safeguards, such as standard contractual clauses adopted by the European Commission and UK government (as applicable). If you wish to enquire further about the safeguards used, please contact us using the details set out at the end of this privacy policy.

8.     YOUR RIGHTS IN RESPECT OF YOUR PERSONAL INFORMATION

In accordance with applicable privacy law, you have the following rights in respect of your personal information that we hold:

(a)   Right of access. You have the right to obtain access to your personal information.

(b)   Right of portability. You have the right, in certain circumstances, to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal information to another person.

(c)   Right to rectification. You have the right to obtain rectification of any inaccurate or incomplete personal information we hold about you without undue delay.

(d)   Right to erasure. You have the right, in some circumstances, to require us to erase your personal information without undue delay if the continued processing of that personal information is not justified.

(e)   Right to restriction. You have the right, in some circumstances, to require us to limit the purposes for which we process your personal information if the continued processing of the personal information in this way is not justified, such as where the accuracy of the personal information is contested by you.

(f)    Right to withdraw consent. If you have provided consent to any processing of your personal information, you have a right to withdraw that consent (without affecting the lawfulness of our processing prior to you having withdrawn your consent).

Right to object: you also have the right, in certain circumstances, to object to any processing based on our legitimate interests in certain circumstances. You can also object to our direct marketing activities for any reason by following the instructions for unsubscribing to marketing messages set out at section 6 above, or toggling your preferences in your account settings. See paragraph 6 for further details.

Please note that the above rights are not absolute, and we may be entitled to refuse requests, wholly or partly, where exceptions under the applicable law apply.

If you wish to exercise one of these rights, please contact us using the contact details at the end of this privacy policy. You may also review, remove and edit some of the personal information you have submitted to us by logging into your account on the website.

You also have the right to lodge a complaint to your national data protection authority. If you are in the UK, information on how to contact the Information Commissioner is available at www.ico.org.uk. If you are located in the EU, further information about how to contact your local data protection authority is available at: 

http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

9.     COOKIES AND SIMILAR TECHNOLOGIES

Our website uses cookies and similar technologies to distinguish you from other users of our Services. Please refer to our Cookies Policy for more information as to the way in which we use cookies on our website.

Analytics: This website uses Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google Analytics uses cookies. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, but please note that if you do this you may not be able to use the full functionality of this website. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

10.  INTEREST BASED ADVERTISING

We participate in interest-based advertising and use third party advertising companies to serve you targeted advertisements based on your online browsing history and your interests. To do this, we or our advertising partners may collect information about how you use or connect to our Services, or the types of other websites, social media services, content and ads that you (or others using your device) visit or view or connect to our Services so that we or our advertising partners may play or display ads on our Services you may use, and on other devices you may use.

Typically, but not always, this information is collected through cookies and similar tracking technologies. We and our third party partners use this information to make the advertisements you see online more relevant to your interests, as well as to provide advertising-related services such as reporting, attribution, analytics and market research.

To learn about interest-based advertising and how you may be able to opt-out of some of this advertising and to limit some third party advertising cookies, you may wish to visit:

      Your Online Choices ("YOC") (http://www.youronlinechoices.com/);

      Network Advertising Initiative ("NAI") (http://www.networkadvertising.org/); and

      Digital Advertising Alliance ("DAA") (http://www.aboutads.info/consumers).

Please note that opting-out of receiving interest-based advertising through the NAI and DAA or YOC online resources will only opt-out a user from receiving interest-based ads on that specific browser or device, but the user may still receive interest-based ads on their other devices. You must perform the opt-out on each browser or device you use.

Some of these opt-outs may not be effective unless your browser is set to accept cookies. If you delete cookies, change your browser settings, switch browsers or computers, or use another operating system, you will need to opt-out again.

11.  LINKS TO THIRD PARTY SITES

Our website(s) may, from time to time, contain links to and from third party websites, including those of our business partners, advertisers, news publications and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. Please check the individual policies before you submit any information to those websites.

12.  CHANGES TO THIS POLICY

We may update this privacy policy from time to time and so you should review this page periodically. When we change this privacy policy in a material way, we will update the "last modified" date at the end of this privacy policy. Changes to this privacy policy are effective when they are posted on this page.

13.  CHILDREN

You must not use our Services if you are under the age of 18. We do not knowingly collect personal information relating to anyone under this age.

14.  CONTACTING US

If you have any questions, comments and requests regarding this Privacy Policy, you can contact us:

By post:

Braincare Limited

27 Old Gloucester Street

London

WC1N 3AX

 

By email: privacy@yourheights.com

This privacy policy was last modified on 29 November 2024.


 

ANNEX 1 – PERSONAL INFORMATION WE COLLECT

Category of personal information

How we use it

Legal basis for processing

 

Contact details (username, email address, postal address and phone number)

 

Profile details (username, date of birth, and gender)

 

Order and subscription details (information necessary to fulfil your order, such as (i) payment information (processed securely by Shopify Payments, we do not store full credit card details), (ii) order details (products purchased, quantities, etc.), and (iii) subscription plan details and history)

To assist you in creating a profiling.

 

To register you with the Services.

 

To enable you to use our Services, including the purchasing of our products and having them delivered to your address.

 

To administer your account (including sending you information regarding your orders and delivery information, changes to our policies, other terms and other administrative information).

 

To provide and manage our subscription services to you.

 

Such processing is all necessary to perform our contract with you.

 

Contact details

To verify your identity via SMS or email

It is in our legitimate interests to verify the email address or phone number you have given during registration is yours to ensure the accuracy of the data and for security purposes.

Contact details

 

Marketing details (such as your marketing preferences)

Marketing and advertising (including sending you newsletters and measuring the effectiveness of our marketing).

 

Consent (if required by law)

 

Where consent is not required by law, it is in our legitimate interests to study how users use our Services and to grow and market our business.

Contact details

 

Profile details

 

Order details

To respond to queries and complaints and provide you with information and materials that you request from us.

 

To carry out surveys and/or ask for feedback with a view to improving our Services.

 

It is in our legitimate interests to respond to your queries and provide any information and materials requested in order for you to have a positive experience with us and to maintain good customer relations.

 

It is in our legitimate interests to understand how our users feel about our Service so we can take steps to improve this.

 

Contact details

 

Profile details

 

Marketing details

 

 

To enable you to partake in a prize draw or competition.

It is in our legitimate interests to study how users use our Services and to grow and market our business

Technical information (IP address, browser type, internet service provider, device identifier, your login information, time zone setting, browser plug-in types and versions, preferred language, activities, operating system, and platform)

 

Usage data (including clickstream to, through and from the Services, pages you viewed and searched for, page response times, length of visits to certain pages, referral source/exit pages, interaction information (such as scrolling, clicks, views and mouse-overs), date and time Services are accessed, and Services navigation and search terms used)

 

Analytics (such as analysing usage of the Services).

 

Improve the Services to ensure that content is presented in the most effective manner for you.

 

Marketing and advertising.

 

To ascertain your preferences.

Consent (if require by law).

 

Where consent is not required by law, it is in our legitimate interests to study how users use our Services and to grow and market our business.

 

 

 

Contact details

 

Profile details

 

Technical information and Usage data

To administer and protect our business and our Services (including troubleshooting, fraud prevention, IT security, data analysis, testing, system maintenance, support, reporting and hosting of data).

It is in our legitimate interests to monitor the Services and resolve errors to ensure that everything functions properly.

 

To comply with our legal and regulatory obligations under applicable law.

 

It is also in our legitimate interests to protect systems and data and to prevent and detect criminal activity that could be damaging for you and/or us.