Privacy Policy
Your trust and the protection of your data are fundamental to us.
Last updated: October 15, 2023
Welcome to the SilkBliss Privacy Policy. At Clear Investments OÜ ("SilkBliss", "we", "us", or "our"), we are committed to protecting and respecting your privacy. This policy explains how we collect, use, share, and protect your personal data when you visit our website silkbliss.com (the "Website") and use our exclusive event organization services (the "Services").
We recommend you read this policy carefully to understand our practices regarding your personal data and how we will treat it.
1. Data Controller
The controller of your personal data is:
Clear Investments OÜ
Keskpuiestee 44-49
43125 Kiviõli
Estonia
VAT ID: EE102345678 (Example, replace with actual VAT)
Contact email for privacy matters: contact form
If you have any questions about this privacy policy or how we handle your personal data, please do not hesitate to contact us.
2. What Personal Data We Collect
We collect personal data that you provide to us directly, data we collect automatically when you use our Services, and data we may obtain from third parties. The types of data we collect include:
- Identification and Contact Data: Pseudonym chosen for the event, age range, email address, phone number (optional), Telegram username (optional).
- Personal Characteristics Data: Height, weight, sexual orientation (provided with your consent).
- Data about Your Experience and Expectations: Information about your previous experience in similar events, your expectations for the event you are applying to join.
- Health Data (Special Categories of Data): Information regarding past or current sexually transmitted diseases (STDs), voluntarily and explicitly provided by you to ensure a safe environment for all attendees.
- Images: Photographs (full-body or partial, with or without a visible face, as per your choice) that you provide as part of your application to help us assess your suitability and for attendee profile management.
- Transaction and Reservation Data: Details related to your place request, type of place (single, couple), and information necessary to process the reservation payment (although sensitive financial details like full credit card numbers are managed directly by our secure payment processors and not stored by us).
- Browsing and Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, information about your visit to the Website (including the full URL clickstream to, through, and from our site), pages viewed, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs). This data is primarily collected through cookies and similar technologies (see our Cookie Policy for more details).
- Communications: Records of correspondence if you contact us (e.g., by email or through contact forms), including additional comments, suggestions, or clarifications you provide.
3. Purposes of Processing and Legal Basis
We process your personal data for the following purposes and on the following legal bases, in accordance with the General Data Protection Regulation (GDPR):
-
Management of Place Requests and Event Participation:
- Purpose: To evaluate your place request, verify your identity and age, manage your reservation, communicate with you about the event (confirmations, reminders, logistical information), and facilitate your participation.
- Base Legal:
- Performance of a contract (or pre-contractual measures) with you when you request a place (Article 6(1)(b) GDPR).
- Your explicit consent (Article 9(2)(a) GDPR) for the processing of special categories of personal data (health/STDs, sexual orientation, images) necessary for this purpose.
- Our legitimate interest (Article 6(1)(f) GDPR) in ensuring an appropriate selection process and maintaining the exclusivity and desired atmosphere of our events.
-
Ensuring a Safe and Appropriate Environment at Events:
- Purpose: To use information about STDs to implement preventive measures and ensure the health and safety of all attendees. To consider sexual orientation and other profile data to foster a harmonious and compatible environment among participants.
- Base Legal:
- Your explicit consent (Article 9(2)(a) GDPR) for the processing of health and sexual orientation data.
- Our legitimate interest (Article 6(1)(f) GDPR) in providing a safe, respectful, and trustworthy environment for all participants.
-
Communications With You:
- Purpose: To respond to your inquiries and requests for information, provide you with assistance, and send you operational communications about the services.
- Legal Basis: Our legitimate interest (Article 6(1)(f) GDPR) in addressing your requests and communicating effectively. If communications are for direct marketing, they will be based on your consent (Article 6(1)(a) GDPR) where required.
-
Improvement of Our Website and Services:
- Purpose: To analyze how users interact with our Website to improve its design, functionality, content, and overall user experience. To conduct optional satisfaction surveys.
- Legal Basis: Our legitimate interest (Article 6(1)(f) GDPR) in developing and improving our services. For the use of non-essential analytical cookies, we will rely on your consent (Article 6(1)(a) GDPR).
-
Compliance with Legal Obligations:
- Purpose: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests (e.g., tax and accounting obligations).
- Legal Basis: Compliance with a legal obligation (Article 6(1)(c) GDPR).
4. Consent for Sensitive Data
The nature of our events and the application process require the collection of data considered "special categories of personal data" or "sensitive data" under the GDPR, such as health information (STDs), sexual orientation, and personal images. We collect and process this data exclusively based on your explicit, free, specific, informed, and unambiguous consent.
This consent is clearly requested during the place application process, through specific checkboxes that you must actively tick. Without this consent, we cannot process this sensitive data, which might prevent us from evaluating your application or managing your participation adecuadamente.
You have the right to withdraw your consent for the processing of this sensitive data at any time. To do so, please contact us via our contact form. Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal. However, please note that withdrawal might mean we cannot continue to process your application or that you cannot participate in the event if such data is essential for it.
5. Sharing of Personal Data
At SilkBliss, confidentiality is paramount. We do not sell, rent, or trade your personal data. We only share your personal data with third parties in the following limited circumstances and always with appropriate safeguards:
- Service Providers: We engage third parties to perform functions on our behalf. This includes payment service providers to process reservations (e.g., Stripe, PayPal), web hosting providers, email services for communications, web analytics tools. These providers only have access to the personal data necessary to perform their functions and are contractually obliged to treat it in accordance with our instructions and the GDPR.
- Event Organizers and Key Personnel: A very limited number of SilkBliss internal staff and, potentially, specific event organizers or hosts may have access to certain data (such as pseudonyms, and in a very restricted and necessary manner, information relevant to safety or logistics) to ensure the smooth running of the event. Access to sensitive data is especially restricted.
- Legal Compliance and Protection: We may disclose your data if we believe in good faith that it is necessary to: (a) comply with a legal obligation or judicial process; (b) protect and defend our rights or property, or the safety of our users or the public; (c) prevent or investigate possible wrongdoing in connection with the Services; (d) enforce our terms and conditions.
- Business Transactions: In the event of a merger, acquisition, reorganization, bankruptcy, or other sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change and of the choices you may have regarding your data.
We ensure that any third party with whom we share your data complies with applicable data protection laws and guarantees an adequate level of protection.
Internal Confidentiality: Within Clear Investments OÜ, access to your personal data, especially sensitive data, is restricted to personnel who need to know such information for the described purposes. We maintain strict confidentiality protocols.
6. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA). However, some of our service providers may be located or process data outside the EEA. When we transfer your personal data outside the EEA to countries not deemed by the European Commission to provide an adequate level of data protection, we implement appropriate safeguards. These may include entering into Standard Contractual Clauses (SCCs) approved by the European Commission with the data importer, or ensuring the provider is certified under a recognized adequacy framework (where applicable).
For more information on the specific safeguards applied to international transfers of your data, you can contact us.
7. Data Retention
We will retain your personal data only for as long as strictly necessary to fulfill the purposes for which it was collected, as described in this policy, and to comply with our legal obligations, resolve disputes, and enforce our agreements.
-
Place Application Data:
- If your application is accepted and you participate in an event, we will retain relevant data for the duration of the event and for a period of up to 3 years thereafter, for relationship management, possible future inquiries, and compliance with legal obligations (e.g., accounting). Certain data, such as basic financial records, may be retained longer as per tax law (e.g., 7 years in Estonia).
- If your application is rejected, or if you withdraw it, we will retain your application data for a maximum period of 1 year to manage the selection process and address possible inquiries, unless you request its deletion earlier and we have no legal obligation to retain it.
- Sensitive Data (Health/STDs, Sexual Orientation, Images): This data, provided with your explicit consent for a specific event, will be securely deleted or anonymized within 6 months after the end of the event for which it was provided, unless you have given us explicit consent to retain it for future event opportunities or there is a legal basis justifying longer retention (which would be communicated to you).
- Communication Data: Correspondence with you will be retained for the time necessary to manage your inquiry and for a reasonable subsequent period, generally not exceeding 2 years.
- Browsing Data: Cookie and analytics data are retained according to the timelines specified in our Cookie Policy, generally between a few months and 2 years.
Once your personal data is no longer necessary for these purposes, we will securely delete or anonymize it.
8. Your Data Protection Rights
Under the GDPR, you have a number of rights regarding your personal data. We are committed to facilitating your exercise of these rights:
- Right of Access: You have the right to request a copy of the personal data we hold about you and details on how we are processing it.
- Right to Rectification: If you believe any personal data we hold about you is incorrect or incomplete, you have the right to request its correction.
- Right to Erasure (Right to be Forgotten): You can request that we delete your personal data when it is no longer necessary for the purposes for which it was collected, you have withdrawn your consent (and there is no other legal basis for processing), you have objected to the processing, or the processing is unlawful.
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances (e.g., while we verify the accuracy of your data if you contest it).
- Right to Data Portability: Where processing is based on your consent or a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller if technically feasible.
- Right to Object: You have the right to object to the processing of your personal data when it is based on our legitimate interests. You also have the absolute right to object to the processing of your data for direct marketing purposes.
- Right not to be subject to Automated Individual Decision-making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Currently, SilkBliss does not engage in such automated decision-making with significant legal effects.
- Right to Withdraw Consent: If we have requested your consent to process your personal data (especially sensitive data), you have the right to withdraw such consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us via our contact form. To protect your privacy and security, we may ask you to verify your identity before processing your request. We will try to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex or you have made a number of requests, in which case we will notify you and keep you updated.
If you are not satisfied with our response or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority. In Estonia, the authority is the Andmekaitse Inspektsioon (AKI) (www.aki.ee/en).
9. Data Security
At SilkBliss, we take the security of your personal data very seriously. We have implemented a set of appropriate technical and organizational measures to protect the personal data we collect and process against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures include, among others:
- Encryption of data in transit (using SSL/TLS) and at rest where appropriate.
- Strict access controls to limit who can access personal data, especially sensitive data.
- Secure password management procedures and multi-factor authentication where possible.
- Regular staff training on data protection and information security.
- Periodic risk and vulnerability assessments.
- Procedures for managing security incidents.
Despite our efforts, no data transmission over the Internet or electronic storage system can be guaranteed as 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please notify us immediately.
10. Children's Privacy
Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from children under 18. If you are under 18, please do not use our Services or provide us with any personal data. If we become aware that we have collected personal data from a child under 18 without verified parental consent, we will take steps to delete that information from our servers.
11. Links to Other Websites
Our Website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this policy. If the changes are significant, we will notify you in a more prominent manner (e.g., by posting a notice on our Website or sending you an email notification if we have your address and you have consented to such communications).
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
13. Contact
If you have any questions, comments, or concerns about this Privacy Policy or our data processing practices, or if you wish to exercise any of your rights, please contact us at:
Clear Investments OÜ
Attn: SilkBliss Privacy Officer
Keskpuiestee 44-49
43125 Kiviõli
Estonia
Email: contact form