Attorney Work Product

Privileged & Confidential

For Discussion Purposes Only

Blocklayer, Inc.

PRIVACY NOTICE

Effective Date: January, 28th 2021

This Privacy Notice explains how Blocklayer, Inc. (“Company”, “we”, “us” or “our”) collects, uses, discloses, and otherwise processes Personal Information (as defined below) in connection with our website, https://blocklayerhq.com (the “Site”), and the related content, platform, services, and other functionality offered on or through the online services (collectively, the “Services”). It does not address our privacy practices relating to job applicants, employees and other personnel.

Region-Specific Disclosures

We may choose or be required by law to provide different or additional disclosures, relating to the processing of Personal information (as defined below) about residents of certain countries, regions or states. Please refer below for disclosures that may be applicable to you:

Table of Contents

What is Personal Information?

Our Collection of Personal Information

Our Use of Personal Information

Our Disclosure of Personal Information

Children’s Personal Information

Links to Third-Party Websites or Services

Updates to This Privacy Notice

Contact Us

Privacy Disclosures for the European Economic Area, United Kingdom and Switzerland

ANNEX 1 – PERSONAL DATA YOU PROVIDE TO US

ANNEX 2 – PERSONAL DATA COLLECTED AUTOMATICALLY

ANNEX 3 – COOKIES

What is Personal Information?

When we use the term “Personal Information” in this Privacy Notice, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual. It does not include aggregated or deidentified information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual.

Our Collection of Personal Information

Sometimes we collect Personal Information automatically when an individual interacts with our Services and sometimes we collect Personal Information directly from an individual. At times, we may collect Personal Information about an individual from other sources and third parties, even before our first direct interaction.

Personal Information Collected from Site Visitors and Account Holders

We may collect the following Personal Information submitted to us by visitors to our Site and account holders:

Personal Information Automatically Collected

As is true of most digital platforms, we and our third-party providers may also collect Personal Information from an individual’s device, browsing actions and site usage patterns automatically when visiting or interacting with our Site, which may include log data (such as internet protocol (IP) address, operating system, browser type, browser id, the URL entered and the referring page/campaign, date/time of visit, the time spent on our Site and any errors that may occur during the visit to our Site), analytics data (such as the electronic path taken to our Site, through our Site and when exiting our Site, as well as usage and activity on our Site) and location data (such as general geographic location based on the log data we or our third-party providers collect).  

We and our third-party providers may use (i) cookies or small data files that are stored on an individual’s computer and (ii) other, related technologies, such as web beacons, pixels, embedded scripts, location-identifying technologies and logging technologies (collectively, “cookies”) to automatically collect this Personal Information. For example, our Site uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”), to collect and view reports about the traffic on our Site. More information about the use of Google Analytics for these analytical and non-advertising purposes can be obtained by visiting Google’s privacy policy here and Google’s currently available opt-out options are available here.

To manage cookies, an individual may change their browser settings to: (i) notify them when they receive a cookie, so the individual can choose whether or not to accept it; (ii) disable existing cookies; or (iii) automatically reject cookies.  Please note that doing so may negatively impact an individual’s experience using our Site, as some features and offerings may not work properly or at all.  Depending on an individual’s device and operating system, the individual may not be able to delete or block all cookies. In addition, if an individual wants to reject cookies across all browsers and devices, the individual will need to do so on each browser on each device they actively use. An individual may also set their email options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether they have accessed our email and performed certain functions with it.

For more information about these practices in relation to our European operations, please see the “Cookies and Similar Technologies Used on Our Site” section of the Privacy Disclosures for the European Economic Area, United Kingdom and Switzerland below.

Personal Information from Third Parties

We also obtain Personal Information from third parties; which we often combine with Personal Information we collect either automatically or directly from an individual.

We may receive the same categories of Personal Information as described above from the following third parties:

Our Use of Personal Information

We may use Personal Information we collect to:

Where an individual chooses to contact us, we may need additional information to fulfill the request or respond to inquiries. We may provide additional privacy disclosures where the scope of the inquiry/request and/or Personal Information we require fall outside the scope of this Privacy Notice. In that case, the additional privacy disclosures will govern how we may process the information provided at that time.

Our Disclosure of Personal Information

We may disclose Personal Information in the following ways:

Children’s Personal Information

Our Services are not directed to, and we do not intend to, or knowingly, collect or solicit Personal Information from children under the age of 13. If an individual is under the age of 13, they should not use our Services or otherwise provide us with any Personal Information either directly or by other means. If a child under the age of 13 has provided Personal Information to us, we encourage the child’s parent or guardian to contact us to request that we remove the Personal Information from our systems. If we learn that any Personal Information we collect has been provided by a child under the age of 13, we will promptly delete that Personal Information.

Links to Third-Party Websites or Services

Our Site and Services may include links to third-party websites, plug-ins and applications. Except where we post, link to or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to, and we are not responsible for, any Personal Information practices of third-party websites and online services or the practices of other third parties. To learn about the Personal Information practices of third parties, please visit their respective privacy notices.

Updates to This Privacy Notice

We will update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify individuals by email to their registered email address, by prominent posting on this Site or our Services, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided.

Contact Us

If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please send an email to privacy@blocklayerhq.com.

Alternatively, inquiries may be addressed to:

Blocklayer, Inc.

Attn: Legal Department
548 Market St

PMB 23743

San Francisco, California 94104-5401 US


Privacy Disclosures for the European Economic Area, United Kingdom and Switzerland

This section contains disclosures on how we collect, store, process, transfer, share use data that identifies or is associated with residents of the European Economic Area (“EEA”), Switzerland, and the United Kingdom (“UK”) ("personal data") and information regarding our use of cookies and similar technologies (“EU Disclosures”). These EU Disclosures apply solely to residents of the EEA, Switzerland, and the UK (“you”). Please ensure that you have read and understood these EU Disclosures before accessing or using the Services. Unless otherwise expressly stated, all terms in this section have the same meaning as defined in our Privacy Policy or as otherwise defined in the General Data Protection Regulation (“GDPR”).


Blocklayer, Inc. is the controller of the personal data we hold about you in connection with your use of the Services. This means that we determine and are responsible for how your personal data is used.

Personal Data We Collect From You When You Use the Service and How We Use It. We collect personal data as set out in the “Our Collection of Personal Information” and “Our Use of Personal Information” sections of our Privacy Notice. We will indicate to you where the provision of certain personal data is mandatory. If you choose not to provide such personal data, we may not be able to provide those parts of the Services to you or respond to your other requests.

The table at Annex 1 sets out in detail the categories of personal data we collect about you and how we use that information when you use the Services, as well as the legal basis which we rely on to process the personal data and recipients of that personal data.

Information We Collect About You Automatically. We also automatically collect personal data indirectly about how you access and use the Services, and information about the device you use to access the Services, or otherwise engage with us. Please see the “Personal Information Automatically Collected” section of our Privacy Notice for more information about what data we collect and how we use it.


How Long Will We Store Your Personal Data. We will usually store the personal data we collect about you for no longer than necessary for the purposes set out in Annexes 1 and 2, including for the purposes of our legitimate business interests and satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and the applicable legal requirements.

Recipients of Personal Data. We may share your personal data with the recipients as set out in the “Our Disclosure of Personal Information” section of our Privacy Notice (as required in accordance with the purposes set out in Annexes 1 and 2).

Marketing and Advertising. From time to time we may contact you with information about our products and services, including sending you marketing messages and asking for your feedback on our products and services.

Storing and Transferring Your Personal Data.

In the event of such a transfer, we ensure that: (i) the personal data is transferred to countries recognized as offering an equivalent level of protection; or (ii) the transfer is made pursuant to appropriate safeguards, such as standard data protection clauses adopted by the European Commission.

If you wish to enquire further about these safeguards used, please contact us using the details set out at the end of these EU Disclosures.

Your Rights in Respect of Your Personal Data. In accordance with applicable privacy law, you have the following rights in respect of your personal data that we hold:

You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal data, and we will assess and inform you if that is the case.  You can object to marketing activities for any reason.

You also have the right to lodge a complaint to your local data protection authority. Information about how to contact your local data protection authority is available here.

If you wish to exercise one of these rights, please contact us using the contact details at the end of these EU Disclosures.

Due to the confidential nature of data processing we may ask you to provide proof of identity when exercising the above rights. This can be done by providing a scanned copy of a valid identity document or a signed photocopy of a valid identity document.

Cookies and Similar Technologies Used on Our Site. Our Site use cookies and similar technologies such as pixels and Local Storage Objects (LSOs) like HTML5 (together cookies”) to distinguish you from other users of our Site. This helps us to provide you with a good experience when you browse our Site and also allows us to monitor and analyze how you use and interact with our Site so that we can continue to improve our Site. It also helps us and our advertising partners to determine products and services that may be of interest to you, in order to serve you targeted advertisements.


We use the following types of cookies:

  1. Strictly necessary cookies. These are cookies that are required for the operation of our Site. They include, for example, cookies that enable you to log into secure areas of our Site or make use of e-billing services.

  1. Analytical/performance cookies. They allow us to recognize and count the number of visitors and to see how visitors move around our Site when they are using it. This helps us to improve the way our Site works, for example, by ensuring that users are finding what they are looking for easily.

  1. Functionality cookies. These are used to recognize you when you return to our Site. This enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

  1. Targeting cookies. These cookies record your visit to our Site, the pages you have visited and the links you have followed. We will use this information to make our Site and the marketing messages we send to you more relevant to your interests. We may also share this information with third parties who provide a service to us for this purpose.

  1. Third party cookies. Please be aware that advertisers and other third parties may use their own cookies tags when you click on an advertisement or link on our Site. These third parties are responsible for setting out their own cookie and privacy policies.

Please see Annex 3 for more information about the cookies we use on the Site and please see our Privacy Notice for more information about cookies.

Our Policy Towards Children. The Services is not directed at persons under 16. We do not knowingly collect or solicit personal data from any persons under the age of 16. In the event that we learn that we have inadvertently collected personal data from a child under age 13, we will delete that information as quickly as possible.  If you believe that we might have any information from a child under 13, please contact us using the details at the end of these EU Disclosures.

Changes to These EU Disclosures. We may update these EU Disclosures from time to time and so you should review this page periodically. When we change these EU Disclosures in a material way, we will update the "Effective Date" above. Changes to these EU Disclosures are effective when they are posted on this page.

Contact Us. Please contact privacy@blocklayerhq.com if you have any questions, comments and requests regarding these EU Disclosures.


ANNEX 1 – PERSONAL DATA YOU PROVIDE TO US

Category of Personal Data

How We May Use the Personal Data

Legal Bases for Processing

Recipients of Personal Data

Contact information, such as your first name, last name, email address and phone number.

We may use this information to set up and authenticate your account on the Services.

The processing is necessary for the performance of a contract with you and to take steps prior to entering into a contract with you, namely our Terms of Use.

We may share this information with Stripe Payments Europe, Ltd in order to identify you so that you can make and receive payments through the Services.

We may also share your personal data with Sendgrid.

We may use this information to communicate with you, including sending service-related communications.

The processing is necessary for the performance of a contract with you, namely our Terms of Use.

We may use this information to deal with enquiries and complaints made by or about you relating to the Services.

The processing is necessary for our legitimate interests, namely administering the Services, and for communicating with you effectively to respond to your queries or complaints.

We may use this information to send you unsolicited marketing communications in accordance with your preferences.

We will only use your personal data in this way to the extent you have given us consent to do so.

Profile and log-in information. This is information you choose to put in your profile such as username, phone number, photo and mailing address.

We use this information to allow you to populate your profile with relevant information.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Use.

We use this information to provide to you the features and functionality of the Services.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Use.

Payment and transaction information, such as your credit/debit card, payment authentication code, billing address, and other information such as date and time of your transaction.

We may use this information to process the payments you make or receive through the Services.

The processing is necessary for the performance of a contract, namely our Terms of Use.

We may share this information with Stripe Payments Europe, Ltd in order to identify you so that you can make and receive payments through the Services.

We may use this information to verify your identity in connection with the detection and prevention of fraud or financial crime.

The processing is necessary for our and third partiers' legitimate interests, namely the detection and prevention of fraud and financial crime.

Information about your activity on the Services, such as information about any products and services you have purchased.

We use this information to provide to you the features and functionality of the Services.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Use.

Chat, comments and opinions. When you contact us directly, e.g. by email or phone we will record your comments and opinions.

We may use this information to address your questions, issues and concerns.

The processing is necessary for our legitimate interests, namely communicating with you and responding to queries, complaints and concerns.

We may share any information you provide to us when you contact us with Zendesk the provider of our customer support platform, in order to process any customer support queries you might submit to us.

We may use this information to improve the Services.

The processing is necessary for our legitimate interests (to develop and improve our service).

Information received from third party social networks, such as Instagram and Facebook. If you interact with the Services through a social network or link your Blocklayer account with certain social networks such as Facebook, Instagram or Twitter, we may receive information from the social network such as your name, age, photos, email address, phone number, location, workplace, friends list, and any other information you permit the social network to share with third parties. The data we receive is dependent on your privacy settings with the social network.

We use this information to promote and market our Services and increase user engagement with our products and Services.

The processing is necessary for our legitimate interests, namely promoting our products and services and increasing user engagement with our products and services.

Your preferences, such as preferences set for notifications, marketing communications, how the Services is displayed and the active functionalities on the Services.

We use this information to provide notifications, send news, alerts and marketing communications and provide the Services in accordance with your choices.

The processing is necessary for our legitimate interest, namely ensuring the user receives the correct marketing and other communications, and that this is displayed in accordance with the user's preferences.

We use this information to ensure that we comply with our legal obligation to send only those marketing communications to which you have consented.

The processing is necessary for compliance with a legal obligation to which we are subject.

All personal data set out above.

We may use all the personal data we collect to operate, maintain and provide to you the features and functionality of the Services, to communicate with you, to monitor and improve the Services and business, and to help us develop new products and services.

The processing is necessary for our legitimate interests, namely, to administer and improve the Services.


ANNEX 2 – PERSONAL DATA COLLECTED AUTOMATICALLY

Category of Personal Data

How We May Use It

Legal Basis for the Processing

Recipients of Personal Data

Approximate location information. Other than information you choose to provide to us, we do not collect information about your precise location. Your device’s IP address may however help us determine an approximate location.

We may use information you provide to us about your location to monitor and detect fraud or suspicious activity in relation to your account.

The processing is necessary for our legitimate interests, namely, to protect our business and your account from fraud and other illegal activities.

We may share this information with the following:

  • Amazon Cognito
  • Segment
  • Amplitude

We may use this information to tailor how the Services is displayed to you (such as the language in which it is provided to you).

The processing is necessary for our legitimate interest, namely tailoring our service so that it is more relevant to our users.

Information about how you access and use the Services. For example, how frequently you access the Services, the time you access the Services and how long you use it for, the approximate location that you access the Services from, the site from which you came and the site to which you are going when you leave our Site, the website pages you visit, the links you click, [whether you open emails or click the links contained in emails], whether you access the Services from multiple devices, and other actions you take on the Services.

We may use information about how you use and connect to the Services to present the Services to you on your device.

The processing is necessary for our legitimate interests, namely, to tailor the Services to the user.

We may use this information to determine products and services that may be of interest to you for marketing purposes.

The processing is necessary for our legitimate interests, namely, to inform our direct marketing.

We may use this information to monitor and improve the Services and business, resolve issues and to inform the development of new products and services.

The processing is necessary for our legitimate interests, namely, to monitor and resolve issues with the Services and to improve the Services generally.

Log files and information about your device. We also collect information about the tablet, smartphone or other electronic device you use to connect to the Services. This information can include details about the type of device, unique device identifying numbers, operating systems, browsers and applications connected to the Services through the device, your mobile network, your IP address and your device’s telephone number (if it has one).

We may use information about how you use and connect to the Services to present the Services to you on your device.

The processing is necessary for our legitimate interests, namely, to tailor the Services to the user.

We may use this information to monitor and improve the Services and business, resolve issues and to inform the development of new products and services.

The processing is necessary for our legitimate interests, namely, to monitor and resolve issues with the Services and to improve the Services generally.


ANNEX 3 – COOKIES

Cookie Name

Type of cookie

When is the cookie set?

How long does the cookie stay on my device?

Purpose of the cookie