Privacy Policy

Effective date: February 19, 2023

Who we are:

This privacy policy applies to Ukrainian Scale Company registered at Ukraine, 61108, Kharkiv, street Academica Sinelnykova, bld 3., ap.17 (collectively, “USC” or “we“, “us“, “our“, “Company”). The User for the purposes of this Privacy Policy, we define the term as a person who has created their own account on our website or mobile application. The Visitor as an individual who visits our website or mobile application. If the information relates to both the Visitor and the User, for the purposes of this policy, we define the term “You”, and “Yours”. We respect and are committed to protecting your privacy. That is why we have adopted this privacy policy, which lets you know how your personal information is processed and used.

What we do:

When you choose to use our Services, you are entrusting us with your personal information. By referring to our "Services" we mean the USC Software Family, which includes USC Spirit Station, USC Spirit Owner, USC Spirit App for Drivers and Contractors, USC Spirit Monitor, our website, and any other services that we may offer in the future, including online services for various Devices. In this Privacy Policy, "Devices" refers to scales, video monitoring cameras, duplicating scoreboards, LED indications, and any other devices that we may offer as part of our Services. Ukrainian Scale Company provides state-of-the-art industrial scale products to its customers. These products may process personal data when the scales are used and subsequent to such use. With this Privacy Policy, we wish to inform you about how and why we process your Personal Data and which rights You have under the European General Data Protection Regulation («GDPR») and other local laws on Privacy and the Processing of Personal Data («Applicable Laws»).

Topics

1. Definitions
2. Our Principles
3. What data do we collect?
4. How will we use your data?
5. What are your data protection rights?
6. Retention of data
7. Compliance with general data protection
8. How do we collect and store your data?
9. Security of your data
10. Links to other Sites
11. Disclosure of Data
12. Children's Privacy
13. Changes to This Privacy Policy
14. How to contact the appropriate authority
15. How to contact us

1. Definitions

a. You will see defined terms in this Privacy Policy. On this page, and the pages that it links to, we have used some words and phrases, and these are explained below. If not defined within this Privacy Policy, these terms have the meaning provided for in the Applicable Laws:   • i. DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed.   • ii. DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.   • iii. DATA SUBJECT is any living individual who is the subject of Personal Data.   • iv. COOKIES are small files stored on your device (computer or mobile device).   • v. PERSONAL DATA means any information about a living, identifiable person. It can include names, addresses, telephone numbers, email addresses, etc, but it is wider than that and includes any other information relating to that person or a combination of information which, if put together, means that the person can be identified.   • vi. USAGE DATA is data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

2. Our principles

a. We adhere to the following principles in order to protect your privacy:
• principle of purposefulness - we process Personal Data fairly and transparently only, aiming to achieve determined and lawful objectives, and they shall not be processed in a manner not conforming to the objectives of data processing;
• principle of minimalism - we collect Personal Data only to the extent necessary to achieve determined purposes. We do not keep Personal Data if it is no longer needed;
• principle of restricted use - we use Personal Data for all other purposes only with the consent of the data subject or if permitted by a competent authority;
• principle of data quality - we always keep Personal Data up-to-date and complete in order to achieve the end purpose of the data processing more efficiently;
• principle of security - security measures shall be applied in order to protect Personal Data from unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures;
• principle of individual participation - our Users shall be notified of data collected in connection to them. They shall be granted access to their Personal Data and have the right to demand a correction of inaccurate or misleading data.

3. What data do we collect?

a. In principle, we process personal data only insofar as this is necessary to provide functioning Services for you. The processing of personal data takes place regularly to communicate with you, process your request, and provide Services on a legal basis with you. We will process your personal data on the performance of a contract with you in compliance with Article 6(1)(b) GDPR. An exception applies to cases in which prior consent can not be obtained for reasons of fact and the processing of the data is permitted by law.b. We collect several different types of information for various purposes to provide and improve our Service to you. The scope of the data depends on the application from USC Software Family you are using:
Name of application: USC Spirit Station / USC Spirit Station Core
Description of application:
“Station core" is the hardware and software part of the complex, to which scales, cameras, LED controller are connected by cable. A tablet with the Spirit Station application installed is connected to it via the network and performs input/output functions as a wireless remote control for scales. "Spirit Station Core", in turn, synchronizes all data to the cloud backend (hereinafter referred to as the "Spirit Cloud") located on AWS.

Global User Data:(By "Global User Data", we mean that such a unique user authorized with his/her phone number. Authorization with a phone number gives the user access to data in which he or she is directly involved or which data is directly related to this phone number)
   • Phone number (Authentication flow is processed by phone number with SMS code verification.)   • Full name   • Date of birth

Local User Data (Weighing operators, Administrators, Service Engineer):(By "Local user", we mean that such a user only affects a specific Spirit Station. Such a user does not have direct access to the data stored in the "Spirit Cloud" or other applications of the "USC Spirit" family. The local user's data is synchronized with the "Spirit Cloud" in the form of data belonging to a specific Spirit Station, and only for the purpose of providing the Backup and restore functions)
Weighing operators:   • username   • password   • Date of birth   • Full name
Administrators:   • username   • password   • Full name
Service Engineer   • username   • password   • Full name
Weighing data:(Weighing data is entered directly by the local user or by automated algorithms. Once saved, the weighing data is included in the weighing log and synchronized with the Spirit Cloud. The weighing data is available in the Spirit Station and Spirit Owner applications (only for the Spirit Station owner)
   • Photo of weighing   • Vehicle number   • Type of weighing           • Receipt           • Shipment           • Transfer           • Paid   • Recipient   • Sender   • Load point (Warehouse of Sender)   • Unload point (Warehouse of Receiver)

Reference data:The data in the reference books is created by the local user, during the weighing process, or through the "Reference books" section. All reference data is synchronized with the Spirit Cloud. Initially, reference data is available only for the Spirit Station on which it was created. After synchronization with the "Spirit Cloud", this data is added to the shared directory database but is hidden for all Spirit Stations in the system. If any Spirit Station tries to create a directory entry that is in the hidden shared directory, the entry will be automatically filled from the shared directory, and on this Spirit Station, it will be marked as taken from the USC Spirit Database and cannot be edited.
Counterparties directory data:   • Registration code or Taxpayer Identification Number   • Full name of the counterparty   • Address
Data from the Company directory:   • Registration code or Taxpayer Identification Number   • Full name of the counterparty   • Address
Drivers' information:   • Driver's license series and number   • Full name   • Phone number
Vehicle directory data:   • Vehicle number   • Name   • Notarized weight   • Vehicle type (Trailer, Truck)
Warehouse directory data:   • Warehouse ID (unique company name or serial number)   • Name   • Address
Data in the Goods reference guide:   • Name   • Internal identifier (SKU, unique name, serial number, etc.)

Service data:Service data is collected exclusively for service purposes and to ensure the reliable operation of the balance and the entire system. All service data is synchronized with the "Spirit Cloud", in the form of data belonging to a specific Spirit Station. Some service data can be entered or changed from the "Spirit Cloud" or from the "Spirit Owner" application.
Data "Verification":   • History of verification   • Date of verification   • Executive body   • Executor   • Verification documents (Certificate of conformity, etc.)
Feedback data:   • Date and time of the message   • ID of the local user who made the request   • Settings of photo/video recording cameras   • Default vehicle type

Other data that can be collected in the background:This kind of data is necessary to ensure stable operation of the application, implementation of improvements, and usability for the end user. Such data can be partially synchronized with the "Spirit Cloud" Measurement log (created in the background, regardless of the main "Weighing" process):
   • Photo   • Data from surveillance cameras:           • Photo fixation of the scales in the loaded state           • Video recording for archiving in the Video Surveillance mode   • Log of automatic recognition of vehicle license plates

Name of application: USC Spirit Owner
Description:
The application connects directly and synchronizes data with the Spirit Cloud. The application implements a data caching mechanism to ensure performance in the absence of a network.
User Account Credentials:
Authorization is performed using a Phone Number and a confirmation code via SMS. The phone number is a unique user identifier and is used to determine the ownership of Spirit Station.
   • Phone number   • Full name   • Company name.
Spirit Station data:
The application gets access to the data of the "Spirit Station", only if the "Owner" matches the user's phone number. Authorization by number is required to access this data.The user can be the owner of several "Spirit Stations". All available "Spirit Stations" are displayed in the application. Below are described the "Spirit Station" data that are available in the application for each "Spirit Station" that is available to the user:
   • Weighing log   • Log of measurements   • Error and message log   • General data about "Spirit Station"   • Access to video surveillance cameras

Name of application: USC Spirit App
Description:
The application connects directly and synchronizes data with the Spirit Cloud. The application implements a data caching mechanism to ensure performance in the absence of a network.
User credentials:
Authorization is performed using a phone number and a confirmation by SMS. The phone number is a unique identifier of the user, and is used to personalize the data stored on Spirit Cloud.
Driver
   • Phone number   • Full name   • Date of birth
Company representative
   • Phone number   • Full name   • Date of birth   • Name of the organization   • Registration code
List of weighing stations:A list of all available weighing stations, for the possibility to lay Navigation route to each of them
Geoposition:
Determines the current coordinates of the user's location are enabled only when using the menu "Map of weighing stations" or in the GPS Tracker mode, and only with the prior permission of the user, through a standard request of the Operating System. The user can at any time can block access to geolocation data in the system settings of the device at any time. The coordinates are synchronized to Spirit Cloud only in the "GPS Tracker" mode.
   • Location log   • Coordinates   • Date/Time
Name of application: USC Spirit Monitor
Description:
The application connects directly and synchronizes data with Spirit Cloud.The application implements a data caching mechanism to ensure performance in the absence of a network.
User credentials:
Authorization takes place using a phone number and a confirmation by SMS. The phone number is a unique identifier of the user and is used to personalize the data stored on Spirit Cloud. The phone number determines the membership in the group, which determines the accessibility of data for the user. User access levels:
   • Developers - has access to the data of all Spirit Stations   • Distributor - has access to Spirit Station data that has been sold and installed through the distributor   • Installer - has access to Spirit Station data that was sold and installed through him/her   • Service Engineer - has access to the Spirit Station data allowed by "Installer"
   • Phone number   • Date of birth   • Full name
Spirit Station list:
Data of weighing stations available to a specific user
   • Name   • Address   • Owners   • The scales   • Spirit Station configuration:           • Setting up photo/video recording cameras           • Reference guides:                  - Contractors                  - Companies                  - Drivers                  - Vehicles                  - Sensor data           • Log of ADC and weight codes for each sensor           • Verification log data           • Local user data           • IP address for remote access of the support service.
Messages received through the feedback form:
   • Date/Time   • Spirit Station   • Sender - the name of the Local user

USC Spirit Cloud
Description:
All data described in the applications above is synchronized and stored in the Spirit Cloud. Only USC Spirit Software developers have direct access to Spirit Cloud data. Spirit Cloud serves as a backup storage and data synchronization between applications. All data exchange between applications and Spirit Cloud is encrypted and has an additional authentication system for a secure synchronization channel.

4. How will we use your data?

1. At Ukrainian Scale Company, we value your privacy and are committed to protecting your personal data. When processing the personal data of our Users and Visitors, as a Data Controller, we rely on our legitimate interest, the performance of a contract with you. This includes improving our mobile applications and website, keeping you informed about our business activities, events, and new services, and communicating with you. We also process your personal data to manage and run our business efficiently, provide quality services, support our website, develop and improve our products, and determine who may be interested in them.
2. When you purchase and use our devices (for instance scale) with connected software, you may be considered a Controller of personal data under the GDPR, depending on the circumstances. It is your responsibility to ensure that the processing of personal data is done in compliance with GDPR requirements. As the developer of the software, Ukrainian Scale Company is considered a Processor of personal data under the GDPR. We will process personal data on your behalf and ensure that such processing is done in compliance with GDPR requirements. To ensure compliance and transparency, we will enter into a data processing agreement with you that outlines respective roles and responsibilities.
3. For marketing purposes, including newsletters, we rely on the performance of a contract with you to process your personal data. You will receive marketing communications from us if you have explicitly requested information from us or purchased services from us. In addition, we may also send you marketing communications if we believe that our products or services would be of interest to you, based on your interactions with us, such as visiting our website or attending our events.
4. We respect your privacy and understand that you may not want to receive marketing communications from us. Therefore, you have the option to opt out of receiving such communications at any time. We will promptly update our records to reflect your preferences.
5. As you interact with our website, we will automatically collect technical data about your equipment, browsing actions and patterns. We collect this Personal Data by using cookies, server logs and other similar technologies. We aim to obtain your explicit consent to process your personal data, such as by asking you to agree to the use of cookies.
6. You can control the use of Cookies at the individual browser level. If you reject Cookies, you may still use our Services, but your ability to use some features or areas of our website or mobile application may be limited. To learn more and for a detailed Cookie notice, You may refer to our Cookie Policy.

5. What are your data protection rights?

1. We would like to make sure you are fully aware of all of your data protection rights. Every user and visitor is entitled to the following:   • The right to access – You have the right to request Our Company for copies of your personal data.   • The right to rectification – You have the right to request that Our Company correct any information you believe is inaccurate. You also have the right to request Our Company to complete the information you believe is incomplete.   • The right to erasure – You have the right to request that Our Company erase your personal data, under certain conditions.   • The right to restrict processing – You have the right to request that Our Company restrict the processing of your personal data, under certain conditions.   • The right to object to processing – You have the right to object to Our Company’s processing of your personal data, under certain conditions.   • The right to data portability – You have the right to request that Our Company transfer the data that we have collected to another organization, or directly to you, under certain conditions.2. If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at our email: moc.dlrow-csu%40troppus3. Please note that you are entitled to the rights specified herein only in the scope of GDPR. Rules applicable to personal data processing in third countries may significantly differ and the person may not be entitled to rights equivalent to those established by GDPR or such rights may be limited.4. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please email us. We will acknowledge their request within seventy-two (72) hours and handle it promptly and as required by law.5. Please note that we may ask you to verify your identity before responding to such requests. We may not be able to provide Service without some necessary data.6. In any case, the maximum time limit for an answer and information that must be provided to you is one month.

6. Retention of data

1. We will retain your Usage Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Usage Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
2. We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
3. If you are no longer a User of the website or mobile application, we will keep your Usage Data for the minimum length of time required to comply with the purposes set out in this Privacy Policy and relevant legal or regulatory obligations, but not more than twenty-four (24) months. Usage Data collected and processed with your consent shall be retained as long as we have your consent.

7. Compliance with general data protection

1. For Visitors, Users located in the European Economic Area (EEA) privacy rights are granted and all processing of Personal Data is performed in accordance with regulations and rules of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).
2. For Visitors and Users located in the US all processing of Personal Data is performed in accordance with regulations and rules following the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”)
3. For Visitors and Users located in Ukraine of Personal Data is performed in accordance with regulations and rules following the Law of Ukraine On Personal Data Protection (Official Bulletin of the Verkhovna Rada of Ukraine (BVR), 2010, No. 34, Art. 481)
4. For Visitors and Users located in the United Kingdom, of Personal Data is performed in accordance with regulations and rules following the UK General Data Protection Regulation. It is a UK law that came into effect on 01 January 2021.
5. Our Privacy Policy is compliant with the laws of every country or legal jurisdiction within which we aim to do business. If you think it fails to satisfy the law of your jurisdiction, we should like to hear from you. However, ultimately it is your choice whether you wish to use our Services.
6. We would, however, appreciate the chance to deal with your concerns before you approach the official authority, so please contact us in the first instance.

8. How do we collect and store your data?

1. You directly provide Our Company with most of the data we collect. We collect data and process data when you:   • Register online or place an order for any of our products or services.   • Register an account via our mobile applications   • Voluntarily complete a customer survey or provide feedback on any of our message boards or via email moc.dlrow-csu%40troppus   • Use or view our website via your browser’s cookies.2. We work with third-party service providers who provide Service, application development, hosting, maintenance, and other services for us. They may be located outside of the EEA. These contractors may have access to, or process Personal Data on behalf of us as part of providing those services for us. We limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions.3. All data transfers are performed in accordance with the highest security regulations. Transfer of Personal Data to countries outside the European Economic Area may be possible only in the case, when we have obtained your consent for it. Your information, including Personal Data, may be transferred to – and maintained on – computers outside your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.4. Our Company securely stores your data at Amazon AWS (Europe). Data access: only authorized personnel within our Company have access to the data stored on Amazon AWS. Personal Data collected: Usage Data. Place of processing: AWS– Privacy Policy.5. We use Firebase Analytics for collecting usage information. Clearly state what types of data you are collecting from users through Firebase Analytics, such as device information, in-app actions, and location data. Data use: Explain how the data is being used, such as to provide insights on user behavior, improve app functionality, and personalize user experiences. Data sharing: Disclose any third-party service providers that the data may be shared with, such as advertisers and analytics companies, in order to deliver targeted advertising and measure the effectiveness of advertising campaigns. We use of Firebase Analytics is in compliance with the Firebase Analytics terms of service and the Google Privacy Policy.6. LLC Ukrainian Scale Company will take all the steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information

9. Security of data

1. We care to ensure the security of your Personal Data. We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain technical, physical, and administrative security measures to provide reasonable protection for your Personal Data. When our contractors or we process your information, we also make sure that your information is protected from unauthorized access, loss, manipulation, falsification, destruction or unauthorized disclosure. This is done through appropriate administrative, technical and physical measures.
2. We always use pseudonymization as a method of securing Personal Data we process as the Processor. We never process any kind of sensitive data and/or criminal offence data. Also, we never undertake profiling of Personal Data.
3. The security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

10. Links to Other Sites

1. Our Service may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third-party's site. We strongly advise you to review the Privacy Policy of every site you visit.
2. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
3. We assume that all Visitors and Users have carefully read this document, understand its contents and agree to the terms and conditions stated in the Privacy Policy. If one disagrees with this Privacy Policy, they should refrain from using our Service.

11. Disclosure of data

1. Corporate transactions: We may disclose your information as part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets.
2. Legal and law enforcement: We will access, disclose, and preserve your information when we believe that doing so is necessary to comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies.
3. Safety, security, and protecting rights. We will also disclose your information if we believe it is necessary to:
o Protect our customers and others; for example, to prevent spam or attempts to commit fraud, or to help prevent the loss of life or serious injury of anyone.
o Operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks.
o Protect the rights or property of ourselves or others, including enforcing our agreements, terms, and policies.

12. Children's Privacy

1. Our Services are not intended for use by children under the age of 18 (“Child” or “Children”). We do not knowingly collect or retain personally identifiable information about persons under 18 years of age. Any person who provides their personal information to us via the Service represents that they are 18 years of age or older. Users or Visitors declare themselves to be adults according to their applicable legislation.
2. We collect data about all Users and Visitors regardless of age. We do anticipate that some of those users will be children.
3. We strongly recommend that parents regularly monitor and supervise their children's online activities.
4. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

13. How to contact the appropriate authority

1. Should you wish to report a complaint or if you feel that Our Company has not addressed your concern in a satisfactory manner, you have the right to complain to a Data Protection Authority about our collection and use of your Personal Data:
2. If Users or Visitors are domiciled in the EU and they think their privacy rights were breached, they may lodge a complaint with the data protection authority of the country of their domicile. They may find the list and contact details of EU data protection authorities here http://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=50061.
3. If Users or Visitors are from California, they have the right to lodge a complaint with a supervisory authority if they think that we violate their rights. You could contact The California Department of Justice (Department) via their Service (https://www.oag.ca.gov/privacy/caloppa/complaint-form/privacy-notice).
4. When we receive any request to access, edit or delete personally identifiable information, we shall first take reasonable steps to verify Users' or Visitors' identity before granting them access or otherwise taking any action. This is important to safeguard their information.

14. Changes to This Privacy Policy

1. We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
2. We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective, and update “effective date” at the top of this Privacy Policy.
3. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on the page.

15. How to contact us

If you have any questions about Our Company’s privacy policy, the data we hold on you, or if you would like to exercise one of your data protection rights, please do not hesitate to contact us. Email us at: moc.dlrow-csu%40troppus