Effective Date: April 1, 2024
Thank you for using Vidual’s products for creating, distributing, and updating work instructions, SOPs, and routine action instructions. The protection and confidentiality of your personal data is of particular importance for us.
With this policy, we aim to inform you about the processing of personal data that we collect from our users and customers of our software products hereinafter referred to as the Products.
Personal data covers all information related to an identified or identifiable individual. This includes information such as name, address, email, display name or profile picture. Information that is not directly related to your identity, for example, the number of users of our Products or other usage statistics do not fall within this category.
We respect the privacy of all users, customers, and business contacts. When we refer to you or user, we mean someone who uses any of our Products or our Website (https://www.vidual.io/). When we refer to controller, we mean the person or entity that determines what personal information is collected from or about you and how that personal information is used and protected.
This Privacy Policy describes the ways and conditions under which we process and use your personal data. We recommend that you read this Privacy Policy to get more information about the processing of your personal data.
Governing law applicable to this Privacy Policy is the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (‘General Data Protection Regulation’ or ‘GDPR’), and the U.S. Privacy Laws (namely the California Consumer Privacy Act, the California Privacy Rights Act, the Colorado Privacy Act, the Connecticut's Act Concerning Personal Data Privacy and Online Monitoring, the Utah Consumer Privacy Act, the Virginia Consumer Data Protection Act and similar laws enacted from time to time in other U.S. states, each as amended, repealed, consolidated, or replaced from time to time).
We provide additional information for residents of the United States of America below in Section 14.
The data controller in the sense of the GDPR as well as other applicable privacy laws is:
"Vidual" EOOD, UIC 207571092, a limited liability company incorporated under the laws of Republic of Bulgaria, hereinafter referred to as Vidual, The Company or We
Address: 239b Aleksandar Stamboliyski Blvd., floor 2, 1309 Sofia, Bulgaria.
Email: privacy@vidual.io
In certain cases, Vidual acts in the capacity of personal data processor operating under the instructions of our business client (another company) who acts as personal data controller and is responsible for the personal data of individuals. For additional information regarding this, please see Section 4 below.
If you have any questions and / or requests related to your personal data that the Company processes, you can contact us at: 239b Aleksandar Stamboliyski Blvd., floor 2, 1309 Sofia, Bulgaria.
You can send us an email at: privacy@vidual.io. Please note that to ensure safety and to abide by applicable privacy laws, we may need to verify your identity and geographic residency before fulfilling your request. We will comply with your request as soon as reasonably practicable within the statutory period for answering your request as per applicable privacy laws.
Vidual respects the privacy of your personal information. The protection of your personal information, as well as the security of all data processed by the Company, is an important issue for us. We process personally identifiable information collected while you use our Products in accordance with applicable privacy laws.
Vidual develops software Products for easy creation and distribution of visual guides using smartphones. Our Products are focused on enabling small and medium sized businesses to create, distribute and update work instructions, SOPs, and routine action instructions.
Our Products are strictly professional and are not aimed at children under 18 years old and we will not deliberately collect, use, provide or process in any other form any personal information of children under the age of 18. We therefore also ask you, if you are under 18 years old, please do not provide us with your personal information (for example, your name and email address). If we learn that we have collected personal data through our Products from a child under 18 without the consent of the child’s parent or guardian as required by law, we will delete it.
Vidual is a personal data controller as per the GDPR when our immediate client is an individual. Our products are open, and any individual may download them, subscribe, and create an account. In those cases, we determine what personal data is collected and how it is used, making us the responsible entity for ensuring personal data protection.
As explained in Section 3 above Vidual’s Products are predominantly focused on small and medium sized businesses and providing them tools to create, update and distribute work instructions among their employees. When our immediate client is a small or medium sized business (or any type of business/legal entity for that matter), we may process personal data about our client’s employees, business partners or other affiliates who must have accounts in our Products to be able to use and update the work instructions, SOPs, and routine action instructions. In those cases, Vidual acts as a personal data processor on behalf of its client and this Privacy Policy is not directly applicable to those cases. When Vidual acts as personal data processor we have executed a Data Processing Agreement (DPA) with our clients to regulate the personal data processing. Usually, this would be our own template DPA, unless we have negotiated a custom DPA.
Regardless of our capacity (personal data controller or personal data processor) Vidual declares that we have implemented all technical and organizational measures to protect the personal data of individuals prescribed by applicable privacy laws.
This Privacy Policy aims to provide you with comprehensive information in a clear and understandable language about what actions are taken with the personal data you provide to us, including:
Any information and data by which an individual can be identified falls directly or indirectly under the definition of “personal data”.
For example, indirect identification is your IP address. Direct identification is achieved when you provide a unique identifier such as passport number, driver’s license number etc. Generally Vidual does not process unique direct identifiers (unless the chosen display name or email matches your actual names).
"Special categories of personal data" means for example data revealing racial or ethnic origin, political views, religious or philosophical beliefs or membership of trade unions, as well as the processing of genetic data, biometric data for the sole purpose of identifying an individual, health data or data about the sexual life or sexual orientation of the individual.
We collect personal data directly from you, for example when you create an account with us or contact us. We also collect personal data on behalf of our clients (see Section 4 above).
The personal data collected and processed by Vidual may include the following categories and types of data:
Categories & Types of Personal Data:
Vidual does not collect any special categories of personal data since such are not required for the use of our Products. If sensitive categories of personal data are provided by you during your interaction with our Products, it will be deleted as soon as possible after the processing of such data is established.
The processing of personal data includes the collection, storage, destruction, transfer, correction, updating, deletion, and all other activities carried out with your personal data.
Vidual processes personal data on the grounds of the performance of a contract with the customer (Article 6, paragraph 1, item "b" of the GDPR). We may also process personal data after obtaining clear, free, and unambiguous consent from you for the purposes of processing expressed through your voluntary registration or provision of optional personal data in our Products (Article 6, paragraph 1, item “a” of the GDPR). The consent you provide can always be withdrawn by contacting us or using the contact form available on our website.
Some of our processing activities are based on legitimate interest (Article 6, paragraph 1, item “f” of the GDPR), but only after we have carefully assessed that such interests do not concern the fundamental rights and freedoms of the data subject.
Lastly, in a very limited number of cases we process your personal data for compliance with a legal obligation to which Vidual is subject (Article 6, paragraph 1, item “c” of the GDPR).
The personal data provided by you shall be used for the following purposes, including but not limited to:
Your personal data is not subject to automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR.
When you use our Products, Vidual processes (collects) your personal information in the following ways:
Depending on the legal ground on which we process your personal data, the storage period of personal data may be different.
Your personal data is stored as long as we have valid legal grounds for processing it. After this period has expired and in case there is no legal ground to continue storing your personal data, your information shall be fully anonymized or deleted.
Vidual respects your privacy and keeps your data secured. Subject to statutory requirements or business needs, Vidual may disclose your personal data to the following categories of recipients:
In principle, Vidual is based in the European Union and stores and processes personal data predominantly in the European Union (“EU”).
Vidual may transfer personal information across borders only in case some of our service providers or cloud storage servers are located in a country outside of the EU.
If your personal information is transferred across borders by us or on our behalf, we use appropriate safeguards to protect your personal information in accordance with this Privacy Policy and applicable law. These safeguards include agreeing to standard contractual clauses or model contracts for transfers of personal information with our respective service providers located outside of the EU. When in place, these contracts require our service providers to protect personal information in accordance with applicable privacy laws.
Subject to European law (GDPR), you may have the following rights to your personal data processed by Vidual:
You can exercise any of the above rights by submitting a formal request to the following address: 239b Aleksandar Stamboliyski Blvd., floor 2, 1309 Sofia, Bulgaria, or email: privacy@vidual.io. To exercise your rights, it is mandatory to establish the identity of the claimant when submitting a request for exercising your rights.
You also have the right to file a complaint with the Bulgarian Commission for Protection of personal Data (https://www.cpdp.bg/en/index.php?p=home&aid=0), or the data protection authority where you live, work or where you think we have violated data protection laws, when the relevant prerequisites are in place.
Throughout this section for Residents of the United States, we use the following terms with the following meanings:
The controller for the personal information collected in connection with use of our Products in the United States is "Vidual" EOOD, UIC 207571092, a limited liability company incorporated under the laws of Republic of Bulgaria with registered address at: 239b Aleksandar Stamboliyski Blvd., floor 2, 1309 Sofia, Bulgaria. "Vidual" EOOD is hereinafter referred to in this section as Vidual or We.
This California Privacy Notice (California Privacy Notice) applies to Vidual’s processing of personal information of residents of the U.S. State of California (California Consumers) as required by the California Consumer Privacy Act of 2018, as amended (CCPA). This "Residents of California" section contains our Notice at Collection under CCPA.
If you are a California Consumer, this California Privacy Notice is designed to help you understand the categories of personal information that we collect about you, where we get that personal information, why we process it, who we share it with, and the rights you have to know and control your personal information. If this California Privacy Notice and any provision in the rest of our Privacy Policy conflict, then this California Privacy Notice applies for the processing of personal information of California Consumers. This California Privacy Notice does not apply to Vidual’s employees, contractors, contingent workers, job applicants, business partners and resellers residing and operating in the U.S. State of California.
In this "Residents of California" section, Business Purposes means providing our Products to California consumers; advertising and marketing; quality assurance; research and development; and other business purposes as may be defined in CCPA from time to time; and Service Providers means organizations that process personal information on behalf of Vidual and contractors and other organizations with which Vidual shares personal information pursuant to a contract for Business Purposes.
For CCPA purposes, Vidual generally acts as a “Business” with respect to your personal information, which means that Vidual determines how and why the personal information that Vidual collects from or about you is handled. (A “Business” is similar to a “controller” which is defined in the preamble to this Privacy Policy.)
This Notice at Collection of personal information describes our personal information collection practices when we are acting as the Business, including a list of the categories of personal information we collect, the purposes for which we collect personal information and the sources from which we collect personal information.
This Notice at Collection covers the twelve (12) months prior to the "Last Updated" date above. This Notice at Collection is updated at least once per year. If this Notice at Collection conflicts with the Privacy Policy, this Notice at Collection will govern as to California Consumers, unless expressly stated otherwise. If Vidual’s processing materially changes between updates to this Notice at Collection, Vidual will provide a supplemental notice when or before the changes apply.
Although we already explain what personal information we collect and why above in this Privacy Policy, the CCPA requires that we make certain disclosures using the categories of personal information used in the definition of personal information in the CCPA.
In the preceding 12 months, Vidual has collected the following categories of personal information:
Categories of Personal Data:
We do not collect precise geolocation information or other personal information that is “sensitive” under California law, Our use of this personal information is to provide you with a Product you have requested and is consistent with the permitted business purposes in California Civil Code § 1798.100 et seq. and implementing regulations. We will collect your consent for any other use.
Vidual does not collect:
We do not collect, share, process or sell any data of people below the age of 18.
Your California Consumer Privacy Rights
CCPA offers California Consumers the following key privacy rights:
Notice of Financial Incentive
We may offer discounts or other benefits to California Consumers enrolled in certain rewards or promotional programs.
Vidual does not generally assign monetary or other value to consumers’ personal information and our promotional activity changes continually. To the extent California law requires that a value be assigned to such programs, or the price or service differences they involve, Vidual values the personal information collected and used under each program as being equal to the value of the discounts or other financial incentives provided in each such program, based upon a practical and good-faith effort to assess on an aggregate basis for all collected information: (1) the type of personal information collected in each program (e.g., email address), (2) the use of such information by Vidual in connection with its marketing activities, (3) the range of discounts provided (which can depend on each consumer’s purchases under such offers), (4) the number of individuals enrolled in respective programs, and (5) the products for which the benefits (such as price difference) can apply. These values can change over time. Note that this description is without waiver of any proprietary or business confidential information, including trade secrets, and it does not constitute any representation with regard to generally accepted accounting principles or financial accounting standards.
A different California law permits California residents to request a notice disclosing the categories of Personal Information about you that we have shared with third parties for their direct marketing purposes during the preceding calendar year. Currently, Vidual does not share Personal Information with third parties for their direct marketing purposes.
The U.S. Privacy Laws offer Consumers certain rights with respect to their personal information. Vidual will honor these rights for any U.S. resident. They include:
To protect Consumers, if we are unable to verify a privacy rights request, we are unable to honor the request. We will use personal information provided in a verified privacy rights request only to verify identity or agent authority to make the privacy rights request and to track and document responses unless Vidual also received the personal information for another purpose.
You may use an authorized agent to make a privacy rights request for you. We may require that you directly confirm that you authorized the agent to submit requests on your behalf or request provision of evidence for the authorization. Please note that it may take additional time to verify and fulfill agent-submitted requests. Once confirmed, your authorized agent may exercise privacy rights on your behalf, subject to the requirements of applicable law.
You may appeal Vidual's decision regarding a request by email at privacy@vidual.io. Please use the same email address that you used to submit the initial privacy rights request when you submit your Request to Appeal and please add “Request to Appeal” in the subject line of the email. If you do not use the same email address, Vidual cannot link your Request to Appeal to your initial privacy rights request.
Some personal information that we maintain is insufficiently specific for us to be able to associate it with a verified Consumer (e.g., data tied only to a pseudonymous browser ID). We do not include that personal information in response to those requests. If we deny a request, in whole or in part, Vidual will explain the reasons in our response.
Vidual will make commercially reasonable efforts to identify personal information that we process to respond to a privacy rights request. In some cases, particularly with voluminous and/or typically irrelevant data, we may suggest you receive the most recent or a summary of your personal information and give you the opportunity to elect whether you want the rest. We reserve the right to direct you to where you may access and copy responsive personal information yourself. We will typically not charge a fee to fully respond to your requests; provided, however, that we may charge a reasonable fee or refuse to act upon a request, if your request is excessive, repetitive, unfounded, or overly burdensome. If we determine that the request warrants a fee or that we may refuse it, we will give you notice explaining why we made that decision. You will be provided with a cost estimate and the opportunity to accept such fees before we charge you for responding to your request.
We retain personal information about a Consumer for as long as the Consumer’s account is active and otherwise as long as necessary for the purposes described above. We also retain personal information as long as necessary to comply with legal obligations, resolve disputes and enforce our agreements. When determining the retention period, we consider various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you and mandatory retention periods under applicable law.