This privacy statement was last updated on July 27, 2023 and applies to citizens and legal permanent residents of the European Economic Area and Switzerland.
In this privacy statement, we explain what we do with the data we obtain about you via https://chi.us. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:
- we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
- we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
- we first request your explicit consent to process your personal data in cases requiring your consent;
- we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
- we respect your right to access your personal data or have it corrected or deleted, at your request.
If you have any questions, or want to know exactly what data we keep of you, please contact us.
1. Purpose, data and retention period
We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)1.1 Contact - Through phone, mail, email and/or webforms
1.1 Contact - Through phone, mail, email and/or webforms
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- IP Address
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Geolocation data
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data upon termination of the service for the following number of months: 12
1.2 Payments
1.2 Payments
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- IP Address
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Geolocation data
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data upon termination of the service for the following number of months: 12
1.3 Registering an account
1.3 Registering an account
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- IP Address
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Geolocation data
- Date of birth
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data until the service is terminated.
1.4 Newsletters
1.4 Newsletters
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Date of birth
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data upon termination of the service for the following number of months: 12
1.5 To support services or products that a customer wants to buy or has purchased
1.5 To support services or products that a customer wants to buy or has purchased
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- IP Address
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Geolocation data
- Date of birth
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data until the service is terminated.
1.6 To be able to comply with legal obligations
1.6 To be able to comply with legal obligations
For this purpose we use the following data:
- A first and last name
- Account name or alias
- A home or other physical address, including street name and name of a city or town
- An email address
- A telephone number
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We retain this data upon termination of the service for the following number of months: 12
1.7 Compiling and analyzing statistics for website improvement.
1.7 Compiling and analyzing statistics for website improvement.
For this purpose we use the following data:
- IP Address
- Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
- Geolocation data
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
Upon termination of the service we retain this data for the following period: 3 Years.
2. Cookies
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions. For more information about these technologies and partners, please refer to our Cookie Policy.
3. Disclosure practices
We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.
If our website or organisation is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.
CHI Institute participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. It uses the Consent Management Platform with the identification number 332.
We have concluded a data Processing Agreement with Google.
Google may not use the data for any other Google services.
The inclusion of full IP addresses is blocked by us.
4. Security
We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorized access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.
The security measures we use consist of:
- Login Security
- DKIM, SPF, DMARC and other specific DNS settings
- (START)TLS / SSL / DANE Encryption
- Website Hardening/Security Features
- Security measures of hardware that contain, or process personal data.
- ISO27001/27002 Certification
- HTTP Strict Transport Security and related Security Headers and Browser Policies
5. Third-party websites
This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.
6. Amendments to this privacy statement
We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.
7. Accessing and modifying your data
If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:
- You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
- Right of access: You have the right to access your personal data that is known to us.
- Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
- If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
- Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
- Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.
Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.
8. Submitting a complaint
If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Data Protection Authority.
9. Contact details
CHI Institute
1160 Selmi Dr Ste 140
Reno, NV 89512
United States
Website: https://chi.us
Email: privacy@chi.us
Phone number: (800) 682-7061
10. Data Requests
For the most frequently submitted requests, we also offer you the possibility to use our data request form
Annex
We collect information about you during the checkout process on our store.
What we collect and store
While you visit our site, we’ll track:
- Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
- Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
- Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!
We’ll also use cookies to keep track of cart contents while you’re browsing our site.
When you purchase from us, we’ll ask you to provide information including your name, billing address, shipping address, email address, phone number, credit card/payment details and optional account information like username and password. We’ll use this information for purposes, such as, to:
- Send you information about your account and order
- Respond to your requests, including refunds and complaints
- Process payments and prevent fraud
- Set up your account for our store
- Comply with any legal obligations we have, such as calculating taxes
- Improve our store offerings
- Send you marketing messages, if you choose to receive them
If you create an account, we will store your name, address, email and phone number, which will be used to populate the checkout for future orders.
We generally store information about you for as long as we need the information for the purposes for which we collect and use it, and we are not legally required to continue to keep it. For example, we will store order information for XXX years for tax and accounting purposes. This includes your name, email address and billing and shipping addresses.
We will also store comments or reviews, if you choose to leave them.
Who on our team has access
Members of our team have access to the information you provide us. For example, both Administrators and Shop Managers can access:
- Order information like what was purchased, when it was purchased and where it should be sent, and
- Customer information like your name, email address, and billing and shipping information.
Our team members have access to this information to help fulfill orders, process refunds and support you.
What we share with others
In short, we only share information with the following third parties.
We only share and disclose your information with the following third parties. We have categorized each party so that you may more easily understand the purpose of our data collection and processing practices. If we have processed your data based on your consent and you wish to revoke your consent please click here.
Advertising, Direct Marketing and Lead Generation Google AdSense. Third party vendors, including Google, use cookies to serve ads based on a user's prior visits to your website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to your users based on their visit to your sites and/or other sites on the Internet. Users may opt out of personalized advertising by visiting Ads Settings. (Alternatively, you can opt out of a third-party vendor's use of cookies for personalized advertising by visiting www.aboutads.info.) Please see the Googles Privacy Policy for more details.
Communicate and Chat with Users Tawk.to, please see the Tawk.to Privacy Policy for more details; and Facebook Customer Chat, please see the Facebook Privacy Policy for more details. We use MailChimp to manage our subscriber list. Their privacy policy can be found here : https://mailchimp.com/legal/privacy/. Hustle is a pop-up plugin that by default captures the IP Address for each conversion and for each view only if the "tracking" functionality is enabled. Other personal data such as your name and email address may also be captured, depending on the form fields. When visitors or users submit a form or view a module, we capture the IP Address for analysis purposes. We also capture the email address and might capture other personal data included in the form fields for collection via Mailchimp.
Content Optimization Google Search Console & Analytics, please see the Googles Privacy Policy for more details. For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our plugin. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO. If your browser does not support web fonts, a standard font is used by your computer. Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google's privacy policy at https://www.google.com/policies/privacy/.
Data Backup & Security DropBox, please see the DropBox Privacy Policy for more details. We collect information about visitors who comment on Sites that use our Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter's IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address, and the comment itself). For more information review the Akismet Privacy Policy here.
Invoice & Billing We accept payments through PayPal & Stripe. When processing payments, some of your data will be passed to either PayPal or Stripe, including information required to process or support the payment, such as the purchase total and billing information. Please see the PayPal and/or Stripe Privacy Policy pages for more information.
Retargeting Platforms Google & Facebook Advertising. Third party vendors, including Facebook & Google, use cookies to serve ads based on a user's prior visits to your website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to your users based on their visit to your sites and/or other sites on the Internet. Please see the Googles Privacy Policy or the Facebook Privacy Policy for more details.
Social Media Sharing Facebook, Twitter, Instagram LinkedIn & YouTube Social Plugins. We do not share any data directly with social media services when sharing from links from our site. Please visit the respective social media services privacy policy for more information on their handling of your private data.
Youtube Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited. If you're logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO. Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.
WooCommerce
What we collect and store
While you visit our site, we’ll track:- Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
- Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
- Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!
- Send you information about your account and order
- Respond to your requests, including refunds and complaints
- Process payments and prevent fraud
- Set up your account for our store
- Comply with any legal obligations we have, such as calculating taxes
- Improve our store offerings
- Send you marketing messages, if you choose to receive them
Who on our team has access
Members of our team have access to the information you provide us. For example, both Administrators and Shop Managers can access:- Order information like what was purchased, when it was purchased and where it should be sent, and
- Customer information like your name, email address, and billing and shipping information.
What we share with others
In this section you should list who you’re sharing data with, and for what purpose. This could include, but may not be limited to, analytics, marketing, payment gateways, shipping providers, and third party embeds.
We share information with third parties who help us provide our orders and store services to you; for example --Payments
We accept payments through PayPal & Stripe. When processing payments, some of your data will be passed to PayPal, including information required to process or support the payment, such as the purchase total and billing information. Please see the PayPal Privacy Policy or Stripe Privacy Policy for more details.What personal data do we collect and why?
By default, Hustle captures the IP Address for each conversion and for each view only if the "tracking" functionality is enabled. Other personal data such as your name and email address may also be captured, depending on the form fields.
When visitors or users submit a form or view a module, we capture the IP Address for analyisis purposes. We also capture the email address and might capture other personal data included in the form fields.How long we retain your data
When visitors or users submit a form or view a module we retain the data for 30 days.Where we send your data
All collected data might be shown publicly and we send it to our workers or contractors to perform necessary actions based on the form submission.Third Parties
We use Mailchimp to manage our subscriber list. Their privacy policy can be found here : https://mailchimp.com/legal/privacy/. We use reCAPTCHA to protect your website from fraud and abuse. Their privacy policy can be found here : https://policies.google.com/privacy. We use SendGrid to manage our subscriber. Their privacy policy can be found here : https://sendgrid.com/policies/privacy/. We use SendinBlue to manage our subscriber. Their privacy policy can be found here : https://www.sendinblue.com/legal/privacypolicy/. We use Zapier to manage our integration data. Their privacy policy can be found here : https://zapier.com/privacy/.Cookies
By default Hustle uses cookies to count how many times each module is visualized. Cookies might be used to handle other features such as display settings, used when a module should not be displayed for a certain time, whether the user commented before, whether the user has subscribed, among others, if their related settings are enabled.
MailChimp for WooCommerce
When shopping, we keep a record of your email and the cart contents for up to 30 days on our server. This record is kept to repopulate the contents of your cart if you switch devices or needed to come back another day. Read our privacy policy here.Slider Revolution
YouTube
Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited. If you're logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO. Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.Google Web Fonts
For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our plugin. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO. If your browser does not support web fonts, a standard font is used by your computer. Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google's privacy policy at https://www.google.com/policies/privacy/.Akismet
We collect information about visitors who comment on Sites that use our Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter's IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address, and the comment itself).WordPress
Who we are
Our website address is: https://chi.us.What personal data we collect and why we collect it
Personal data is not just created by a user’s interactions with your site. Personal data is also generated from technical processes such as contact forms, comments, cookies, analytics, and third party embeds.
By default WordPress does not collect any personal data about visitors, and only collects the data shown on the User Profile screen from registered users. However some of your plugins may collect personal data. You should add the relevant information below.
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year. If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed. If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.Analytics
Who we share your data with
By default WordPress does not share any personal data with anyone. If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue. For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.Where we send your data
Visitor comments may be checked through an automated spam detection service. You may contact privacy@chi.us for any further privacy related questions.[gpdr-data-request]