Privacy Policy
Last Updated: 11/14/2024
1. Introduction
Worm Reads (“we,” “us,” or “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.WormReads.com (“the Website”). It also outlines your rights under the General Data Protection Regulation (GDPR) if you are accessing the Website from the European Economic Area (EEA).
2. Data Controller
For the purposes of GDPR, Worm Reads is the data controller of your personal information. If you have any questions about this Privacy Policy or our data practices, please contact us at:
- Email: support@wormreads.com
3. Information We Collect
Personal Data
We may collect the following personal data:
- Identity Information: Full name, gender.
- Contact Information: Email address, physical address, other contact details.
- Account Information: Username, password, profile preferences.
- Usage Data: IP address, browser type, browsing actions, and patterns on our Website.
- Technical Data: Login data, time zone setting, and other technology on the devices you use to access the Website.
Special Categories of Personal Data
We do not intentionally collect any special categories of personal data (e.g., health information, religious beliefs) about you.
4. How We Collect Your Data
- Direct Interactions: When you register for an account, fill out forms, or communicate with us.
- Automated Technologies: Through cookies and similar technologies as you interact with our Website.
- Third Parties: From payment processors like PayPal, WooCommerce, and Stripe when you make transactions.
5. Legal Basis for Processing Personal Data (EEA Users)
We process your personal data based on the following legal grounds:
- Consent (Article 6(1)(a) GDPR): When you have given clear consent for us to process your personal data for specific purposes.
- Contractual Necessity (Article 6(1)(b) GDPR): To perform the contract we are about to enter into or have entered into with you.
- Legal Obligation (Article 6(1)(c) GDPR): When processing is necessary for compliance with a legal obligation.
- Legitimate Interests (Article 6(1)(f) GDPR): For our legitimate interests, provided your interests and fundamental rights do not override those interests.
6. How We Use Your Information
We use your personal data for the following purposes:
- To Provide Services: Facilitate your use of the Website and deliver content.
- Account Management: Manage your account and provide customer support.
- Communication: Send notifications, updates, and respond to inquiries.
- Personalization: Customize content and advertisements.
- Analytics: Analyze Website usage to improve our services.
- Compliance: Comply with legal obligations and protect our legal rights.
7. Cookies and Similar Technologies
Use of Cookies
We use cookies to:
- Remember your preferences and settings.
- Authenticate and identify you on our Website.
- Provide personalized content and recommendations.
- Analyze Website traffic and usage.
Types of Cookies Used
- Essential Cookies: Necessary for the Website to function properly.
- Analytical/Performance Cookies: Help us understand how users interact with the Website.
- Functionality Cookies: Remember your preferences.
- Targeting/Advertising Cookies: Deliver relevant advertisements.
Consent and Control
- Cookie Consent Banner: We provide a cookie consent banner for EEA users, allowing you to accept or reject non-essential cookies.
- Browser Settings: You can control cookies through your browser settings.
8. Disclosure of Your Information
We may share your personal data with:
- Service Providers: Third parties who perform services on our behalf (e.g., payment processors, hosting providers).
- Legal Authorities: If required to comply with legal obligations or protect our rights.
- Business Transfers: In the event of a merger, acquisition, or sale of assets.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
9. International Data Transfers
Your personal data may be transferred to and processed in countries outside the EEA, including the United States. We ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses: We use contractual clauses approved by the European Commission.
- Privacy Shield Framework (where applicable): Though invalidated, some entities may still adhere to its principles.
By using our services, you consent to the transfer of your information to the United States and other countries.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption: Data is encrypted during transmission.
- Secure Servers: Data is stored on secure servers with limited access.
- Access Controls: Strict access controls and authentication measures.
11. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including:
- Account Information: Retained until you delete your account or request deletion.
- Transaction Records: Retained as required for accounting and tax purposes.
- Usage Data: Retained for internal analysis purposes.
12. Your Rights Under GDPR
If you are in the EEA, you have the following rights regarding your personal data:
- Right to Access: Request access to your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data under certain conditions.
- Right to Restrict Processing: Request to limit the processing of your data.
- Right to Data Portability: Receive your personal data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data.
To exercise these rights, please contact us at support@wormreads.com.
13. Children’s Privacy
We do not knowingly collect personal data from children under the age of 16 without parental consent. If we become aware that a child under 16 has provided us with personal data without verification of parental consent, we will take steps to remove that information.
14. Data Breach Notification
In the event of a data breach, we will notify the relevant supervisory authority within 72 hours if it poses a risk to your rights and freedoms. We will also inform you without undue delay if there is a high risk to your rights and freedoms.
15. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these websites and encourage you to read their privacy policies.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting a notice on our Website.
- Sending a notification to your account.
- Emailing you directly.
Your continued use of the Website after such changes signifies your acceptance of the updated policy.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer (DPO):
- Email: support@wormreads.com