- People who access our podcasts through an embedded player on a web browser
- People who access our podcasts through our app either when logged in or not
- People who access our podcasts through a third party media player on a web browser or a third party app
1. The personal data we process and why
In this section, you can read about when and why we process your personal data, the categories of personal data concerned, our legal basis for processing and the time period during which the data is stored. As outlined below, what personal data we process about you depends on how you access our podcasts and for what purpose we need to process your data. Our legal basis for the processing also varies depending on why we need to process your data.
2. How we collect your personal data
We collect the personal data that you provide to us, e.g. when you choose to sign up in the Acast app, contact us, download a podcast through an app or the internet. If you log in with a user name and password through Acast’s app we collect name, email address, year of birth, gender and your interests for different categories of podcasts.
Through our website you can choose to register for Acast’s newsletter.
If you choose to do so we will collect your name and email address.
Regardless of the way you log in to our services, Acast will collect certain information from your technical equipment such as your IP address, User Agent, language, country settings and Advertising ID.If you use our service without logging in, we only collect your public IP address and the User Agent from your technical equipment.
From Third parties
If you log in to our services through your Facebook or Google Account, Acast will collect information from your public profile, such as your Facebook ID/Google Plus ID, profile picture, name or nick name, email address, gender, age and interests for different podcast subjects.
3. Who we share your data with
To fulfil the purposes for our processing of your personal data we share your personal data with companies that provide services to Acast. These companies are only allowed to use your personal information in line with our instructions and may not use your personal data for their own purposes. They are also obliged to protect your personal data. We share your personal data with the following companies:
- Microsoft who provides hosting services through Azure.
- Amazon who provides hosting services through AWS.
- IBM who provides storing services through compose.io.
- Hetzner who provides hosting services and logging services.
- AdsWizz who provides a service for advertising.
- ID5 for advertising profiling test purposes.
- Zendesk who provides us with a support tool.
- Intercom who provides us with a support tool.
- Google who provides us with a mail server for support.
- Mailchimp who provides us a service for sending newsletters.
- Hubspot who provides us with a service to empower our blog.
- Certain Media House partners (Nova, Australia).
We may also share your personal data with other companies in the Acast group and our partners within the marketing analysis field. The personal data will in such cases not be used for purposes that are incompatible with the purposes for which it was originally collected.
We may be obliged to share your data with public authorities at their request in accordance with applicable legislation or a decision by a competent authority.
4. Where we process your personal data
Some of our suppliers may be located in a country outside the European Union or European Economic Area. When we share your data with such suppliers in order to provide our services to you we will always perform necessary security measures in order to make certain that the data we share is handled in accordance with applicable legislation.Some of our suppliers are located in the USA and in order to protect your personal data we ensure that our suppliers in the USA are certified under the Privacy Shield. Consequently, transfers of personal data to such suppliers are based on a decision by the European Commission that an adequate level of protection of the personal data is ensured in accordance with GDPR article 45.1
5. Your rights
Right to be informed
Right of access
You can submit an access request regarding your personal data in our mobile app user settings. If we receive an access request we may contact you for further information regarding your request and to establish your identity. We will answer your access requests without delay within one month.
Right to rectification
We have a responsibility to ensure that your personal data is accurate. However, you may provide us with additional data if our data is incomplete or require rectification if you have identified that your personal data is incorrect. When your data is being corrected we will inform any recipients we have disclosed the data to, about the rectification, unless this proves impossible or involves disproportionate effort. We will also, at your request, inform you about which recipients have been informed of the rectification.
Right to erasure
You have the right to have your personal data erased if:
- the personal data is no longer is necessary for the purpose which we originally collected or processed it for
- we are relying on consent as our lawful basis for processing the data, and you withdraw your consent
- we are relying on legitimate interests as our basis for processing, you object to the processing of your data, and there is no overriding legitimate interest to continue the processing
- we are processing the personal data for direct marketing purposes and you object to that processing
- we have processed the personal data unlawfully
- we have to do it to comply with a legal obligation
If your data is erased, we will inform any recipients of your data that this erasure has been undertaken unless this proves impossible or involves disproportionate effort.
Right to restrict processing
You have the right to request that we restrict the processing of your personal data in the following circumstances:
- you contest the accuracy of your personal data during a period when we are verifying the accuracy of the data;
- the data has been unlawfully processed and you oppose erasure and request restriction instead;
- we no longer need the personal data but you need us to keep it in order to establish, exercise or defend a legal claim; or
- you have objected to us processing your data, and we are considering whether our legitimate grounds override your grounds.
If we have restricted the processing of your personal data temporarily, we will inform any recipients of your personal data of such restriction unless this proves impossible or involves disproportionate effort.
Right to data portability
You may under certain circumstances have a right to data portability. This means the right to obtain and reuse your personal data for your own purposes across different services. It allows you to move, copy or transfer your personal data easily from one IT environment to another. The right to data portability only applies:
- to personal data you have provided to us as controller;
- where the processing is based on your consent or for the performance of a contract; and
- when the processing is carried out by automated means.
Right to object to processing based on legitimate interests
You have a right to object to the processing of your personal data based on our legitimate interests. If you choose to object, please specify which processing the objection refers to. We are obliged to stop processing your personal data based on our legitimate interests unless:
- we can demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms, or
- the processing is for the establishment, exercise or defence of legal claims.
Right to object to processing for direct marketing purposes
You have a right to object to our processing of your personal data for direct marketing purposes at any time by unsubscribing from future messages. This is done by clicking on a link named “unsubscribe” in the email you have received from us. Your personal data will thereafter no longer be processed for direct marketing purposes.
Right to withdraw consent
When we process your personal data based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent shall however not affect the lawfulness of processing based on your consent before its withdrawal. You can withdraw your consent through changing your user settings in the Acast mobile app.
Right to lodge a complaint with the Data Supervisory Authority
If you believe your personal data is not processed in accordance with applicable legislation, please contact us, see contact information below. You can also lodge a complaint with the Data Supervisory Authority (Datainspektionen).
7. How to contact us
Acast AB (publ)
Kungsgatan 12 Stockholm 111 35 Sweden