International Version | Greater China Version

Privacy Policy

Last Updated: 6 January 2022

At TopHatch, we take your privacy seriously. Please read the following to learn how we treat personal information that we collect about you when you use or access TopHatch Services.

Remember that your use of TopHatch Services is at all times subject to our Terms of Use. Any capitalized terms we use in this Policy without defining them have the definitions given to them in the Terms of Use.

What this Privacy Policy Covers

This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services. “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations. This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage. This Privacy Policy also does not cover Personal Data that we handle on behalf of our enterprise customers as a processor; we handle such data in accordance with our applicable customer agreements.

Sources of Personal Data

We collect Personal Data about you from:

Categories of Personal Data We Collect

The following chart details the categories of Personal Data that we collect and have collected over the past twelve (12) months. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal DataPersonal Data CollectedSource
A.Personal identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number or other similar identifiers.
Email address (optional)
Name (optional)
Unique personal identifier
Telephone number (optional)
You
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Examples: Name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number or any other financial information, medical information or health insurance information.
Name (optional)
Telephone number (optional)
You
C.Protected classification characteristics under state or federal law
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status or genetic information (including familial genetic information).
We do not collect this category of Personal Data.
D.Commercial information
Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Purchase information is sent to us via billing partners (for example, Apple, Google) when you make a purchase of a feature of one of our applications via their store.Affiliates and business partners
E.Biometric information
Examples: Genetic, physiological, behavioral, and biological characteristics or identifying activity patterns, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health or exercise data.
We do not collect this category of Personal Data.
F.Internet or other similar network activity information
Examples: Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.
Interaction with our applications to monitor application performance and stability. Optionally, you may provide details to us about the categories of your use for our applications when creating an account with us. For example, Architecture, Product Design etc.You
G.Geolocation data
Examples: Physical location or movements.
We do not collect this category of Personal Data.
H.Sensory data
Examples: Audio, electronic, visual, thermal, olfactory or similar information.
We do not collect this category of Personal Data.
I.Professional or employment related information
Examples: Current or past job history or performance evaluations.
We do not collect this category of Personal Data.
J.Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99))
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information or student disciplinary records.
We do not collect this category of Personal Data.
K.Inferences drawn from other personal information
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
We do not collect this category of Personal Data.
L.Age or date of birth
We do not collect this category of Personal Data.
M.Special categories of data under the EU General Data Protection Regulation
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data or biometric data processed for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person’s sex life or sexual orientation.
We do not collect this category of Personal Data.
N.Personal Data about children under the age of 16
This includes any type of Personal Data that relates to someone under the age of 16.
We do not knowingly collect this category of Personal Data; however, some users of the education version of our services may be children under the age of 16. With respect to users of the education version, we collect all of the foregoing categories information, but only as authorized by the applicable educational institution. See below section Personal Data of Children for more information about how we collect and treat children’s Personal Data.You

The following sections provide additional information about how we collect your Personal Data.

Information Collected Automatically

The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs, and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser and tell us how and when you visit and use our Services, to analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone, or similar device when you use that device to visit our Services.

We use the following types of Cookies:

You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your computer. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some Services and functionalities may not work. Some browsers have incorporated Do Not Track (“DNT”) preferences. We make efforts to respond to DNT signals, although as there is not yet a uniform industry standard for handling DNT signals from website browsers, we cannot guarantee our response to DNT signals.

To explore what Cookie setting are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit https://ico.org.uk/for-the-public/online/cookies/ or https://www.allaboutcookies.org/.

How We Use Your Personal Data

We process Personal Data to operate, improve, understand and personalize our Services. We use Personal Data for the following purposes:

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.

As noted in the list above, we may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may send you promotional email offers or email you about your use of the Services. Also, we may receive a confirmation when you open an email from us, which helps us improve our services. Where necessary under applicable law, we will obtain your consent before using your Personal Data for these purposes. If you do not want to receive marketing-related emails from us at any time, you can follow the unsubscribe link that is present in each of these emails or indicate your preference by emailing us at privacy@concepts.app. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages, from which you cannot opt out.

How We Share Your Personal Data

Disclosures of Personal Data for a Business Purpose

We disclose your Personal Data to service providers and other parties for the following business purposes:

The following chart details the categories of Personal Data that we disclose and have disclosed over the past twelve (12) months.

Category of Personal DataDisclosed to Which Categories of Third Parties
A.Personal identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number or other similar identifiers.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.
Other parties at your direction
Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Examples: Name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number or any other financial information, medical information or health insurance information.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.
Other parties at your direction
Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
C.Internet or other similar network activity information
Examples: Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.

In addition, we may disclose Personal Data to a third party if we undergo a merger, acquisition, bankruptcy, reorganization, or other disposition of all or any portion of our business, assets, or stock.

Sales of Personal Data

We do not “sell” Personal Data and have not “sold” Personal Data for purposes of the CCPA in the last 12 months. We have shared Personal Data with service providers over the last 12 months which did not constitute a sale under then-applicable law.

Under the CCPA, if a business sells Personal Data, it must allow California residents to opt out of the sale of their Personal Data, but we do not sell your Personal Data with a sale defined as-in the CCPA. For example, and without limiting the foregoing, we do not sell the Personal Data of minors under 16 years of age.

Data Security and Retention

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. The Services use industry standard Secure Sockets Layer (SSL) technology to allow for the encryption of sensitive Personal Data you provide to us. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account.

We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. Afterwards, we retain some information in a depersonalized or aggregated form but not in a way that would identify you personally.

Personal Data of Children

As noted in the Terms of Use, we do not knowingly collect or solicit Personal Data from children under 16 except if a child is using the education version of our services as authorized by an applicable educational institution; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at privacy@concepts.app.

The Children’s Online Privacy Protection Act (“COPPA”) requires that online service providers obtain parental consent before they knowingly collect personal information online from children who are under 13. We do not knowingly collect or solicit personally identifiable information from children under 13, as defined in 16 C.F.R. 312.2. If we learn we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us personal information, please contact us at privacy@concepts.app.

TopHatch is not an educational agency or institution as defined in 34 C.F.R. 99.3 and, therefore, is not subject to the Family Educational Rights and Privacy Act (“FERPA”).

California Resident Rights

If you are a California resident, you have the rights outlined in this section. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us by email at privacy@concepts.app.

Access

You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information:

If we have disclosed your Personal Data for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient.

Deletion

You have the right to request that we delete the Personal Data that we have collected from you. Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Exercising Your Rights

To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data, such as an email sent from the email address associated with your account and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify you and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request using the following methods:

We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA

You have the right to be free from unlawful discrimination for exercising your rights under the CCPA, and we will not engage in such discrimination. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA.

Authorized Agents

If you want to make a request as an authorized agent on behalf of a California resident, you may use the submission methods noted above. As part of our verification process, we may request that you provide, as applicable, proof concerning your status as an authorized agent, which also may include:

If you are making a request on behalf of a California resident and have not provided us with a power of attorney from the resident pursuant to Probate Code sections 4121-4130, we may also require the resident to:

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

European Union Data Subject Rights

EU Residents

If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway, or Iceland, you may have additional rights under the EU General Data Protection Regulation or the EU General Data Protection Regulation as transposed into the national law of the United Kingdom by the UK European Union (Withdrawal) Act 2018 and amended by the UK Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (collectively the “GDPR”) with respect to your Personal Data, as outlined below.

For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. TopHatch generally will be the controller of your Personal Data processed in connection with your use of the Services, unless we are handling your Personal Data as a processor on behalf of your organization.

If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at privacy@concepts.app.

Personal Data We Collect

The “Categories of Personal Data We Collect” section above details the Personal Data that we collect from you.

Personal Data Use and Processing Grounds

The “How We Use Your Personal Data” section above explains how we use your Personal Data.

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

Sharing Personal Data

The “How We Share Your Personal Data” section above details how we share your Personal Data with third parties.

EU Data Subject Rights

If you are an EU Data Subject, you have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email privacy@concepts.app. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.

Transfers of Personal Data

The Services are hosted and operated in the United States (“U.S.”) through Company and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Company in the U.S. and will be hosted on U.S. servers, and you authorize Company to transfer, store and process your information to and in the U.S., and possibly other countries.

Changes to this Privacy Policy

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well, but we will alert you to changes by placing a notice on the https://concepts.app website, by sending you an email, and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.

Contact Information:

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data, your choices and rights regarding such use, please do not hesitate to contact us at: