Privacy Policy

Mindspace Ltd Privacy and Data Protection Policy and Notice

Last Updated: October 24, 2018

 

Mindspace Ltd (including its wholly and partially owned subsidiaries) (“Mindspace“, “we“, “our” or the “Company“, and their cognates) respects the privacy of its customers, employees, candidates, members and followers, and is committed to protecting the personal information that its Users (as defined below) share with it. We are transparent about our practices regarding the information we may collect and use when you use the Services, apply for a position, are employed by us, visit our office sites, visit our websites, use our mobile application,  or otherwise engage with us, and describe our practices in this policy and notice.

Mindspace provides open work spaces, private offices and related services at its facility locations (the “Services“).

A User may be either an entity, for example an employer which has executed an agreement with Mindspace (“Customer “) or a Customer’s users, for example a Customer’s employees, of the Services (“End User(s)“) (Customer and End User and any others with respect to whom we collect personal data,  shall collectively be referred to as “Users” or “you” or “Data Subjects”).

This Policy (the “Privacy Policy“) explains the types of information we may collect from Users or that Users may provide when using the Services, and which may likewise be collected from site visitors, website visitors, employment candidates and others. This Policy also describes Mindspace’s practices for collecting, using, maintaining and processing information, including through the Mindspace Website and the Mindspace Mobile application.

Users who wish to use the Services may be asked to provide Mindspace, either directly or through their company administrator, with certain information including Personal Data and Sensitive Information as further detailed in this Privacy Policy (“Data“). Mindspace’s use of this Data in connection with the Services will be undertaken in accordance with this Privacy Policy.

Please read the following carefully to understand our practices regarding your personal data and how we will treat it.

For the purposes of European Economic Area data protection law, (the “Data Protection Law“), Mindspace will usually be a data controller (the “Controller“).

  1. WHICH INFORMATION MAY WE COLLECT?

Categories of information and data we may collect from our Users.

Data we collect about you from your use of the Service

One type of Data is non-identifiable and anonymous information (“Non-personal Information”). We also collects several categories of personal data (“Personal Data”). Personal Data which is being gathered consists of any details which are personally identifiable provided consciously and voluntarily by a Customer, End User or the Customer’s administrator or through your use of the Mindspace Mobile application and website (as described below). This may include your name (first and last), email address, phone numbers, picture, postal address, birthdate, gender, position and organization name, your bank account, credit card and other such payment and billing details , billing address, your Mindspace Mobile application account username and password and usage details, and other information User may choose to provide to Mindspace.

Additionally, we may obtain location data related to the geographic location of your laptop, mobile device or other digital device on which the Mindspace website or application is used.

If you are visiting a User at one of our facility locations, we may ask you for your name, email address, phone number and the name and position of the person you are visiting. We use this information to facilitate our legitimate interest of providing reception services to Users and in order to let the User know that you are on your way to them, as well as to ensure the safety and security of our Users and premises.

You do not have any legal obligation to provide any information to Mindspace, however, we require certain information in order to provide the Services. If you choose not to provide us with certain information we may not be able to provide you with some or all of the Services.

Mindspace may also collect the email addresses of people who communicate with Mindspace via email or via messenger services or other social media platform or create accounts and login credentials.

By registering on Mindspace’s general website, Mindspace will collect your name, company name, phone number and personal or company email you provided. Mindspace may use this information to offer Mindspace’s services and support.

You may create a Mindspace account by clicking on a ‘connect’ or ‘sign-in’ button that we may display on the Services for a designated third party website or service (each a “Third Party Account”), including but not limited to Google, LinkedIn, Facebook or Twitter. Doing so will enable you to link your Mindspace account and your Third Party Account. If you choose this option, then you will be required to approve the connection as well as the provision of information (which may include Personal Information, such as your profile picture, gender, birthdate, headline, summary, friends’ lists, previous positions and organizations), that we may obtain from your Third Party Account.

Mindspace also collects Personal Data through the use of CCTV cameras and members’ site access cards. This may consist of video images of you in the public spaces at Mindspace offices, as well as records of your entrances and exits of the Mindspace buildings and office floors.

Mindspace may not be aware of the nature of the information collected through the Services (for example, through CCTV), and such information may include sensitive or special categories of Personal Data, but we do not knowingly collect such data about our Users, members, site visitors etc (“Sensitive Information”).

Mindspace also collects data relating to employees. This is governed by a specific notice we have made available to our employees.

Mindspace also collects data relating to employment candidates. This includes CVs and the data contained therein, notes on meetings, standardized tests, reports, references, interviewer impressions and such industry standard data, as well as collecting data made publicly available or available to us on social networks. We collect such data based on the intention of the candidate to enter into an employment agreement with Mindspace.

  1. HOW DO WE COLLECT PERSONAL DATA ON USERS OF MINDSPACE FACILITIES AND SERVICES?

We collect Personal Data through your use of our Website and Application. In other words, when you are using the website or application, we are aware of it and may gather, collect and record the information relating to such usage, either independently or through the help of third-party services as detailed below. This may include technical information and behavioral information such as the User’s Internet protocol (IP) address used to connect your computer to the Internet, your uniform resource locators (URL), operating system, type of browser, browser plug-in types and versions, screen resolution, Flash version, time zone setting, the User’s ‘click-stream’ on the website, the period of time the User visited the website, methods used to browse away from a page, and any phone number used to call our customer service number. We likewise may place cookies on your browsing devices (see section ‘Cookies’ below).

We collect Personal Data required to provide the Services when you or the Customer’s administrator register and open an account. In addition, we collect your Personal Data, when you provide us such information by entering it manually or via a Customer, whether through our application, in site visits, in the course of preparing a contract, or otherwise in engaging with us. We also collect Personal Data entered voluntarily by a Customer administrator, and it is the responsibility of every Customer administrator to ensure that they are entitled to provide such personal data to us for use in line with this Privacy Policy.

We also collect Personal Data through our CCTV recordings and through our card reader software, which automatically collect information about your presence in the Mindspace facilities.

  1. WHAT ARE THE PURPOSES OF PERSONAL DATA WE COLLECT?

We will use Personal Data to provide and improve the Services and meet our contractual, ethical and legal obligations, including for example:

  • to enable us to meet our legal, contractual and business obligations as an employer and a potential employer for our employees and job applicants;
  • carrying out our obligations arising from any contracts entered into between you or your employer and Mindspace and/or any contracts entered into between a Customer and Mindspace and to provide you with the information, products and Services that you request from Mindspace;
  • administering your account with Mindspace including to identify and authenticate your access to the parts of the Services that you are authorized to access.
  • verifying and carry out financial transactions in relation to payments you make in connection with the Service;
  • notifying you about changes to our Service;
  • contacting you for the purpose of providing you with technical assistance and other related information about the Service;
  • replying to your queries, troubleshooting problems, detect and protect against error, fraud or other criminal activity;
  • contacting you to give you information about events or promotions or additional Services offered by Mindspace, including in other locations;
  • soliciting feedback in connection with your use of the Services;
  • tracking use of Mindspace facilities and services to enable us to optimize and improve our services;
  • contacting you to inform you of additional services and locations which may be of interest to you;
  • compliance and audit purposes, such as meeting our reporting obligations in our various jurisdictions, and for crime prevention and prosecution in so far as it relates to our staff, members, facilities etc;
  • for security purposes and to identify and authenticate your access to the parts of the Services and our application that you are authorized to access;
  • for the security and business confidentiality purposes of some of our clients, we may collect and transfer the full names of individuals who need to enter the floors of offices occupied by those clients in order to ensure that only pre-approved individuals can access those offices, with entry logs for such offices;
  • we may collect personal data of our clients’ personnel, our members, which will be used for for the purposes set out above.

 

  1. SHARING DATA WITH THIRD PARTIES

We may transfer Personal Data to:

Members of our Group: This includes any member of our group, which means our subsidiaries – whether wholly or partially owned by Mindspace, in the EU, in Israel, in the US and elsewhere, as well as our joint-venture partners who support our processing of personal data under this policy.

Third Parties. We transfer personal data to third parties in a variety of circumstances. We endeavor to ensure that these third parties use your information only to the extent necessary to perform their functions, and to have a contract in place with them to govern their processing on our behalf. These third parties may include business partners, suppliers, affiliates, agents and/or sub-contractors for the performance of any contract we enter into with you. They may assist us in providing the Services we offer, processing transactions, fulfilling requests for information, receiving and sending communications, analysing data, providing IT and other support services or in other tasks, from time to time. These third parties may also include analytics and search engine providers that assist us in the improvement and optimisation of our website, our application, and our marketing.

Some customers of Mindspace require for their data security and management to know the identity of anyone who accesses their office space, for example, the identity of vendors (such as delivery services, catering, IT support, contractors, cleaning etc) and their staff who are on site. For customers of ours who reasonably require it, we will transfer the names of any of staff, visitors, vendors, etc who have access to their office space.

We periodically add and remove third party providers. At present our third party providers to whom we may transfer personal data include also the following:

In addition, we may disclose your personal data to third parties: if all or substantially all of our assets are acquired by a third party including by way of a merger, share acquisition, asset purchase or any similar transaction, in which case personal data held by it about its customers will be one of the transferred assets. Likewise, we may transfer personal data to third parties if we are under a duty to disclose or share your personal data in order to comply with any legal or audit or compliance obligation, in the course of any legal or regulatory proceeding or investigation, or in order to enforce or apply our terms of supply terms and other agreements with you; or to protect the rights, property, or safety of Mindspace, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction and to prevent cybercrime.

For avoidance of doubt, Mindspace may transfer and disclose non-personal data to third parties at its own discretion.

  1. WHERE DO WE STORE YOUR DATA?

We may keep Personal Data in a database which will be owned or controlled by the Controller. We currently store data on servers controlled by Mindspace, in Israel, and in cloud servers dedicated to Mindspace, such as on Amazon Web Services servers in Germany and other AWS servers.

 

  1. INTERNATIONAL DATA TRANSFERS

Personal Data may be transferred to, and stored and used at, a destination outside the European Economic Area (EEA) that may not be subject to equivalent Data protection laws to those of the EU. Where your Data is transferred outside of the EEA, we will take all steps reasonably necessary to ensure that your Data is subject to appropriate safeguards, and that it is treated securely and in accordance with this privacy policy. Mindspace transfers data from its various locations and jurisdictions to other jurisdictions as follows:

  • To Israel. Mindspace headquarters are based in Israel. Israel is considered by the European Commission to offer an adequate level of protection for the personal information of EU Member State residents; we may transfer data to other countries with an adequacy ruling too; and
  • To the United States of America. Transfer to the US is done subject to the Privacy Shield program as detailed below; where that is not available, we will make such transfers subject to Standard Contractual Clauses; and
  • Within the EU.

We may transfer your personal data outside of the EEA, in order to:

  • Store or backup the information;
  • Enable us to provide you with the Services and fulfil our contract with you;
  • Fulfill any legal, audit or compliance obligations which require us to make that transfer;
  • Facilitate the operation of our group businesses, where it is in our legitimate interests and we have concluded these are not overridden by your rights;
  • To serve our customers across multiple jurisdictions; and
  • To operate parent company, subsidiaries and affiliates in an efficient and optimal manner.
  1. PRIVACY SHIELD

Mindspace Inc complies with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland transferred to the United States pursuant to Privacy Shield. Mindspace Inc. has certified that it adheres to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/

Mindspace Inc. acknowledges the individual’s right to access their personal data and will provide you access to the personal information we hold about you to the extent it is reasonably available, and allow you to correct inaccurate information or delete the personal data, as required and permitted by applicable law. If you’d like to access, correct or delete any personal information that we hold about you, please send your request to us at dpo@mindspace.me and we will respond within 30 days.

The Federal Trade Commission has jurisdiction over Mindspace Inc.’s compliance with the Privacy Shield. Under the Privacy Shield, Mindspace Inc. may remain liable if its third party service providers process your personal information in a manner inconsistent with the Privacy Shield Principles, unless we prove that we are not responsible for the event giving rise to the damage.

In compliance with the Privacy Shield Principles, Mindspace Inc. commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union and Swiss individuals with Privacy Shield inquiries or complaints should first contact Mindspace Inc. at: dpo@Mindspace.me

Mindspace Inc. has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers  for more information and to file a complaint. This service is provided free of charge to you.

If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms.  See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction

  1. DATA RETENTION

Mindspace will retain personal data it processes only for as long as required in our view, to provide the Service and as necessary to comply with our legal obligations, to resolve disputes and to enforce agreements. We will also retain personal data to meet any audit, compliance and business best-practices.

Data that is no longer retained may be anonymized or deleted. Likewise, some metadata and statistical information concerning the use of the Service are not subject to the deletion procedures in this policy and may be retained by Mindspace. We will not be able to identify you from this data. Some data may also be retained on our third-party service providers’ servers until deleted in accordance with their privacy policy and their retention policy.

  1. WEBSITE DATA COLLECTION AND COOKIES

When you access or use the Service, Mindspace may use industry standard technologies such as Cookies, pixels and similar technologies, which store certain information on your computer or browsing device and which will allow us to identify the computer or device with the user, and to enable automatic activation of certain features, and make your Service experience much more convenient and effortless. We use different types of Cookies: some cookies are strictly necessary, they are required for the operation of our Site and under our terms with you; this includes for example, cookies that enable you to log into secure areas of our Service. We also use analytical and performance monitoring cookies, which allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. Finally, we use functionality cookies which are used to recognise you when you return to our Site. This enables us, subject to personalise content to your preferences, including for example, your choice of language or region.

Different cookies are kept for different periods. Session cookies are used to keep track of your activities online in a given browsing session; these cookies generally expire when the browser is closed but may be retained for a period on your device. Permanent cookies remain in operation even when you have closed the browser; they are used to remember your login details and password. Third-party cookies are installed by third parties with the aim of collecting certain information to research behaviour, demographics. Third party cookies on our site include, for example, Google Analytics. Likewise, pixels from Facebook and others enable integration of third party service providers (eg Facebook, Twitter) on our site. Third party cookies will be retained according to the terms of those third parties, and you can control those cookies in your browser settings.

We use Cookies and other technologies on the basis that they are necessary for the performance of a contract with you, or because using them is in our legitimate interests of improving, optimizing and personalizing our services, and these are not overridden by your rights.

Most browsers will allow you to erase cookies from your computer’s hard drive, block acceptance of cookies, or receive a warning before a cookie is stored. However, if you block or erase cookies your online experience on our website will be limited.

How to disable cookies: The effect of disabling cookies depends on which cookies you disable but, in general, the website and some services delivered through it may not operate properly, may not recognize your device, may not remember your preferences and so on, if cookies are disabled or removed. However, allowing or disabling cookies is your choice and in your control. If you want to disable cookies on our site, you need to change your browser settings to reject cookies. How you can do this will depend on the browser you use. Further details on how to disable cookies can be found here:

 

Our websites may, from time to time, contain links to external sites. We are not responsible for the operation, privacy policies or the content of such sites.

  1. SECURITY AND STORAGE OF INFORMATION

We take a great care in implementing, enforcing and maintaining the security of the personal data we process. Mindspace implements, enforces and maintains security measures, technologies and policies to prevent the unauthorized or accidental access to or destruction, loss, modification, use or disclosure of personal data. We likewise take steps to monitor compliance of such policies on an ongoing basis. Where we deem it necessary in light of the nature of the data in question and the risks to data subjects, we may encrypt data. Likewise, we take industry standard steps to ensure our website and application are safe.

Note however, that no data security measures are perfect or impenetrable, and we cannot guarantee that unauthorized access, leaks, viruses and other data security breaches will never occur.

Within Mindspace, we limit access to personal data to those of our personnel who: (i) require access in order for Mindspace to fulfil its obligations under this Privacy Policy and its agreements and (ii) have been appropriately and periodically trained on the requirements applicable to the processing, care and handling of the Personal Data (iii) are under confidentiality obligations as required under applicable law. Mindspace takes steps to ensure that its staff who have access to personal data are honest, reliable, competent and trained.

Mindspace shall act in accordance with its policies to promptly notify the relevant authorities and data subjects in the event that any personal data processed by Mindspace is lost, stolen, or where there has been any unauthorized access to it, all in accordance with applicable law and on the instructions of qualified authority. Mindspace shall promptly take reasonable remedial measures.

  1. DATA SUBJECT RIGHTS

Data subjects have rights under GDPR and local laws, including, in different circumstances, rights to data portability, rights to access data, rectify data, object to processing, and erase data. It is clarified for the removal of doubt, that where personal data is provided by a customer being the data subject’s employer, such data subject rights will have to be effected through that customer. In addition, data subject rights cannot be exercised in a manner inconsistent with the rights of Mindspace employees and staff, with Mindspace proprietary rights, and third party rights. As such, job references, reviews, internal notes and assessments, documents and notes including proprietary information or forms of intellectual property, cannot be accessed or erased or rectified. In addition, these rights may not be exercisable where they relate to data that is not in a structured form, for example emails, or where other exemptions apply. If processing occurs based on consent, data subjects may have a right to withdraw their consent.

If, for any reason, a data subject wishes to modify, delete or retrieve their Personal Data, they may do so by contacting Mindspace (DPO@mindspace.me). Note that Mindspace may have to undertake a process to identify a data subject exercising their rights. Mindspace may keep details of such rights exercised for its own compliance and audit requirements. Please note that Personal Data may be either deleted or retained in an aggregated manner without being linked to any identifiers or Personal Data, depending on technical commercial capability. Such information may continue to be used by Mindspace.

Data subjects have the right to lodge a complaint, principally with the Romanian National Supervisory Authority for Personal Data Processing (anspdcp@dataprotection.ro). If the supervisory authority fails to deal with a complaint or inform you within the time frame set under applicable law, you may have the right to an effective judicial remedy.

  1. GENERAL

Mindspace aims to process only adequate, accurate and relevant data limited to the needs and purposes for which it is gathered. It also aims to store data for the time period necessary to fulfill the purpose for which the data is gathered. Mindspace only collects data in connection with a specific legitimate purpose and only processes data in accordance with this Privacy Policy.

Minors. We do not knowingly collect or solicit information or data from children under the age of 16 or knowingly allow children under the age of 16 to register for Mindspace services. If you are under 16, do not register or attempt to register for any of the Mindspace Service or send any information about yourself to us. If we learn that we have collected or have been sent Personal Data or from a child under the age of 16, we will delete that Personal Data as soon as reasonably practicable without any liability to Mindspace. If you believe that we might have collected or been sent information from a minor under the age of 16, please contact us at: dpo@Mindspace.me, as soon as possible.

Changes to this Privacy Policy. The terms of this Privacy Policy will govern the use of the services, websites and application, and any information collected in connection with them. Mindspace may amend or update this Privacy Policy from time to time. The most current version of this Privacy Policy will be available at: https://www.Mindspace.me/privacy/. We will endeavor to provide notice of material changes to this policy on the homepage of the website or by other means. Material changes will take effect seven (7) days after such notice was provided. Otherwise, all other changes to this Privacy Policy are effective as of the stated “Last Revised” date and your continued use of Services will constitute your active acceptance of, and agreement to be bound by, the changes to the Privacy Policy.

If you have any questions or comments concerning this Privacy Policy, you are welcome to send us an email or otherwise contact us at dpo@Mindspace.me and we will make an effort to reply within a reasonable timeframe.

Mindspace contact details:

54 Ahad Haam St., Tel Aviv, Israel, 652021, Israel
dpo@mindspace.met
+972-77-2203567

*             *             *             *             *