Privacy Policy

 
 

Last Updated: May 02 2022

Hello there! We’re glad to see that you're concerned about your privacy, because we are, too. ♥

We are TRU LUV Inc. (“TRU LUV”), and in this Privacy Policy, we provide you with explanations on how we collect, use or disclose your personal data, and how you can exercise your rights on your personal data. In this Privacy Policy, we cover:

  • Our website http://truluv.ai (our "website")

  • Our mobile application BreatheLUV (our "BreatheLUV App")

  • Our mobile application #SelfCare (our "#SelfCare App")

  • Any exchange you may have with us, including by e-mails, social media or otherwise.

  • Any other activities we may undertake which involve the collection and processing of personal data, such as internal research and development activities for our commercial products and services.

We use the term “Services and Activities” to refer to all of the above, and where there is no distinction to make between them. 

This Policy also explains how cookies and other tracking technologies are used on our website. 

This Policy is meant to apply to our Services and Activities generally. When we need to provide you with more specific information not covered in this Policy, we will do so in a separate notice or consent form presented to you before you engage in the service or activity in question. 

This Policy does not apply to the Careers section of our website. Click here to read our Privacy Policy regarding our Careers and Recruitment activities. 

This Policy does not apply to the processing of your personal data by websites, applications or other services provided by independent third parties. For example, if you click on a link on our website that leads to a third party’s website, this Policy does not apply to that third party’s processing of your personal data through their website. Third parties include our social media accounts on social networks such as Facebook and Soundcloud, as well as services referenced through our digital services. Please make sure to always review third-party policies and practices to make sure you’re aware of how they handle your personal data. It’s important to take few minutes to understand their practices. ♥ 

At TRU LUV, we refer to our Users as “Tenders” and will do so throughout this document.

Please refer to the sections below to quickly find the information you’re looking for.

  1. How can you contact us?

  2. Do we process personal data about children?

  3. What do we mean by “personal data”?

  4. What types of cookies do we use and why?

  5. How can you manage your cookie preferences?

  6. What personal data do we collect about you and why?

  7. Who do we share your personal data with?

  8. Where will your personal data be stored and processed?

  9. How do we ensure your personal data is safe?

  10. How long do we keep your personal data?

  11. Can you opt out of marketing communications and push notifications?

  12. Do you have any rights regarding your personal data?

  13. How can you exercise your rights?

  14. Can we change this policy?

1. How can you contact us?

Under European and British privacy laws, TRU LUV Inc. acts as data controller with respect to the personal data covered under this Privacy Policy. If you have any questions, comments, or concerns regarding this Policy, how we handle your personal data, or if you want to exercise your privacy rights, you can contact us or our Data Protection Officer by e-mail at: privacy@truluv.ai, or by mail:

Data Protection Officer
TRU LUV Inc.
186-720 King Street West
Toronto, Ontario, Canada
M5V 3S5
Canada

2. Do we process personal data about children? 

While we believe wellness is important for people of all ages, we may collect sensitive health data through your devices to allow you to engage with our Services and Activities, and therefore, we do not allow individuals under the age of 16 to engage with our Services and Activities, with or without parental consent. If you are under 16 years old, don’t worry – we’ll be happy to get to know you when you reach 16 years old! In the meantime, we prefer that you use services that are tailored for your age group. If we find out that you’ve been engaging with our Services and Activities and you are not 16 years old, we will delete your personal data to protect your privacy. 

3. What do we mean by “personal data”? 

The word data means stored information, signs or indications, and the word personal means that the identification of an individual is possible based on the available data. Data is personal if it allows us to identify you, directly or indirectly. Personal data includes online identifiers, such as your IP addresses, location data, and identification data such as your name, mobile phone numbers and e-mail address.  

Different jurisdictions may have different legal definition(s) of what constitutes personal data. We use a large definition for this Privacy Policy so that we can provide you with as much information as possible, but it is possible that the personal data covered in this Privacy Policy is not protected under the laws that apply to you. 

4. What types of cookies do we use and why? 

Cookies are little data files installed on your device (a computer tablet or mobile phone for instance) to fulfil several purposes. When we use the term “cookies” in this Policy, we also imply similar tracking technologies such as tracking pixels (or pixels tags), web beacons and browser fingerprinting. If you want to know more about cookies, you can consult this article on the website of the Office of the Privacy Commissioner of Canada, or this website for more general information. 

We use the cookies described below for the purposes indicated. Otherwise, we don’t use targeting or marketing cookies, not for interest-based advertising or otherwise. 

Essential Cookies (always active) 

Essential cookies are necessary for you to use our digital services. They allow navigation from one page to another, for example. The website cannot function properly without these cookies. Therefore, they cannot be disabled. 

For our European Tenders, we set these essential cookies on the basis of our legitimate interests, including the security of our website and making our digital services available. 

Analytical Cookies (optional) 

We use analytical cookies to help us gain better insight into how our Tenders interact with our website. The data displays key metrics such as the number of visitors to the website and our social media channels, peak traffic times, conversion rates, and the geolocation and preferences of our Tenders. This data helps us understand how our Tenders use our services in an anonymized way so that we can improve your experience. 

For our European Tenders, we set these cookies on the basis of your explicit consent. You may withdraw your consent at any time. 

  • Essential Cookies (always active)

    Name: crumb

    Purpose: Ensures visitor browsing security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor.

    Source: TRU LUV AI

    Duration: Session

    Name: test

    Purpose: Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website.

    Source: Squarespace

    Duration: Persistent

    Analytical Cookies (optional)

    Name: p.gif

    Purpose: Keeps track of special fonts used on the website for internal analysis. The cookie does not register any visitor data.

    Source: typekit.net

    Duration: Session

5. How can you manage your cookie preferences?

Browsers and devices have tools for controlling cookies; you can block them, be notified when they’re loaded, and control the ones already placed on your device or computer. However, if you block all cookies, you may not be able to access all the features of the service. 

Cookie control tools vary depending on the browser you use. To learn more, click on the link for your browser: 

6. What personal data do we collect about you and why?

We collect your personal data to provide you with our Services and Activities, including to allow you to use our BreatheLUV App and #SelfCare App, to conduct surveys, for our artificial intelligence algorithms to personalize our #SelfCare App experience based on your in-app actions, to manage our communities, to provide you with specific functionalities such as syncing with your heart rate, to manage our social media accounts, to subscribe you to our newsletters, to provide you with support and respond to your requests, inquiries, or other communications, and to understand and improve our Services and Activities. The personal data that we collect may include electronic data, health data, identification data, and any information you share with us from time to time.  

We collect personal data directly from you, or from our service providers who collect it directly from you. We do not buy any personal data from third parties and neither do we sell any. We do not use your personal data within the BreatheLUV App and the #SelfCare App to conduct interest-based marketing based on your behavior, and we do not allow third parties to do so either. 

When we process your personal data on the basis of your consent, you may withdraw that consent at any time by contacting us at privacy@truluv.ai. Some services may not be available without your consent to data processing. 

Health Data and other Sensitive Personal Data 

If you allow us, the BreatheLUV App can read your heart rate from the Apple Health App. We do not input your heart rate as a data source, so we only need read permission. You can provide us with this permission through your Apple devices by opting-in, and you can opt-out at any time. The BreatheLUV App is also available on Apple Watch. Our Tenders generally use the Apple Watch to input their heart rate into the Apple Health App, which allows us to read your heartbeat if you opted-in to let us do so. 

We use this information for the purpose of syncing the apps’ animations with your heart rate. If you opt-out, then we will not be able to read your health data, in which case the functionality which allows us to sync the animations with your heart rate will not be available to you, but you can still use the BreatheLUV App without this functionality.  You can consult this page from Apple for more information on how to manage your preferences regarding Apple Health data such as heart rates. 

We may also collect and process other types of sensitive data in the context in some of our other activities. When this is the case, we will inform you in a separate notice before or at the time of collection of the specific types of data in question and the specific purposes for which we wish to collect and process them.  

For our European Tenders, the lawful basis applicable for us to collect this data is your explicit and specific consent. 

Community Data 

At TRU LUV, we love #SelfCare, and this also means having support from and interacting with other kind humans. This is why we are creating communities on third-party platforms such as Discord and Mighty Networks. When you interact with us or others in this community, any content you share will be available to others (unless sent in private), along with your pseudonym. You have no obligation to participate in our communities. 

For our European Tenders, the lawful basis applicable to the collection of community data is your explicit and specific consent. 

Personal Data Relating to Your Communications and Interactions with Us  

If you inquire about our Services and Activities, if you fill a contact form on our website, interact with us on social media or whenever you exchange with us, we collect the personal data that you share with us. On social media, we will have access to your publicly available information when you interact with us. Except in the case of subscribing to our newsletters, when you interact with us, we use your data only to answer your lovely questions and to connect with you, and not for marketing purposes. 

When we respond to your inquiries, if you are located in Europe, we do so based on the performance of our contract with you.

Payment Data 

You may be offered in-app purchases through Apple Pay or Google Pay in the context of engaging with our Services and Activities. We don’t see or access the payment data you provide to Apple Pay or Google Pay – they collect your payments on our behalf. 

For our European Tenders, we only process payment data pursuant to the performance of a contract, or in some cases, for functionalities that are not necessary for our BreatheLUV and #SelfCare Apps, with your explicit and specific consent. 

In-App Game Data #SelfCare App 

Our #SelfCare app uses artificial intelligence to adapt the game to your choices. Our artificial intelligence uses scores that we generate as data inputs. These scores are based on the aggregation of your actions within the game, and through our artificial intelligence algorithms, this generates instructions on how the game interacts with you. This processing of your personal data is done entirely on your device, and not on our servers. 

For our European Tenders, we collect this data based on the Performance of a Contract. Our #SelfCare App is artificial intelligence driven and cannot be used without this function which determines how the game functions. Our Terms of Services and Privacy Policy are available in the Apple App Store or Google Play Store. If you download the #SelfCare App, you consent to the Terms of Services for the #SelfCare App which is the contract that you are part of, and which justifies our processing of your in-game data through artificial intelligence. 

Performance and Usage Data 

When you use our #SelfCare app, and if you opt in to join our research collective, you can choose to allow us to gather anonymized analytical data about your usage, such as when you start and stop the app, click buttons, open a screen, exit a screen, or read a document. We also collect your responses to our status surveys. We don’t use such data for advertising or to send you notifications. We only use it to understand how our Tenders like to use our App, to improve and to understand any security or performance issue. We don’t actually see your actions as an individual, as we are provided with aggregated data on performance which do not allow us to identify you individually. Instead, we use an IP address, a token associated with your device or a similar indirect identifier to associate these aggregated data with your use of the #SelfCare app. We use Matomo Analytics (learn more about Matomo here) for this purpose. We do not collect this data by default. You can opt-out of this data collection anytime within #SelfCare app by selecting the opt-out button on our standard menu, in which case, we will stop collecting any analytics or survey data from you.

Otherwise, we also use: 

  • Squarespace Analytics on our Website and as described above in the Cookies section above. Learn more about Squarespace Analytics here.

  • Google Play’s and Apple App Store’s native analytics to gain insight into how our apps are performing on these app stores, such as how many times our apps have been downloaded or redownloaded, or high-level statistics on in-app purchases. The information we see here is all aggregated and deidentified, so it doesn’t allow us to identify any individual in particular.

For our European Tenders, we collect this information based on the performance of our contract with you whenever it is necessary to deliver our Services and Activities. Otherwise, we collect it based on your specific and explicit consent, which you can withdraw at any time.

Automatically Collected Electronic Data 

When you visit our website, some electronic data about you is automatically collected, such as your IP address, browser type, the types of devices that you’re using and your language preferences. Your use of our BreatheLUV App and #SelfCare App may also automatically generate electronic data, such as whether you are using an iOS version of the apps, or an Android version. This personal data is used to secure our services, to manage the performance of our services and to provide you with digital services. 

For our European Tenders, the lawful basis for our processing of this personal data with respect to our website lies in our legitimate interest in monitoring and securing our services. Within our apps, the performance of a contract is the applicable lawful basis for collecting electronic data as we would not otherwise be able to provide you with our BreatheLUV App and #SelfCare App.  

Business Communications and Consent Preferences 

We collect electronic information (such as cookies) to remember your consent preferences, including for privacy purposes. 

For our European Tenders, we collect consent preferences to comply with a legal obligation and we collect your e-mail for business communication based on the performance of a contract or to comply with a legal obligation, depending on the situation. 

Marketing Communications and Newsletters 

With your explicit consent, we will use your e-mail address and sometimes your name to provide you with promotional content as well as other news, information and updates about our Services and Activities, such as in the form of newsletters. 

You can unsubscribe at any time from these communications using the unsubscribe option within them. 

Surveys about our Services and Activities 

We love to hear from you! ♥ 

For this reason, and with your explicit consent, we may collect personal data about you as part of our surveys. We use Microsoft Forms to prepare our surveys and collect your personal data. The personal data that we collect may include your answers to the questions and your identification data, such as name, e-mail, age range, location, personal habits and preferences when engaging with our Services and Activities, depending on the type and nature of the survey. Only a few members of the TRU LUV team will access your personal data. We collect this information to improve our Services and Activities, to make sure you’re satisfied, and to get feedback from you. 

For our European Tenders, we collect this data based on your specific and explicit consent.

7. Who do we share your personal data with?

We care about you, and we’re not in the business of selling your personal data to anyone. ♥ 

Within our organization, we apply access on a need-to-know basis as a principle. 

We do not share health data with third parties. 

We may share your personal data in the following exceptional situations: 

  • If required by law, subpoena, or a request from authorities that we believe we should respond to, or if the disclosure is made necessary by an urgent and justified medical situation. 

  • In connection with a merger, acquisition, corporate reorganization, or sale of some or all of our assets. 

We may also share your personal data when necessary to allow you to engage with our Services and Activities, to respond to your inquiries, and to obtain performance data about our Services and Activities. Under these circumstances, we may share your personal data with the following categories of third parties: 

Service Providers 

Service providers are used for such things as managing our website and to allow you to engage with the Services and Activities. They may include: 

  • Microsoft Forms, which is used to get your amazing feedback. Read Microsoft’s Privacy Policy; 

  • Mighty Networks to provide you with support groups. Read Mighty Networks's Privacy Policy; 

  • Discord to provide you with support networks. Read Discord's Privacy Policy here. 

  • MailChimp, to send you communications. Read MailChimp's Privacy Policy; 

  • Matomo, to provide our analytics service within the #SelfCare App. Read Matomo’s privacy policy.  

  • Squarespace as described above in the Cookies section above. Learn more about Squarespace Analytics here. 

  • Zoom, to conduct virtual meetings for some of our activities, such as our Rituals. Read Zoom’s Privacy Policy

  • Other Contractors and Subcontractors with whom we have Data Protection Agreements. By virtue of these agreements, these parties are restricted to collecting and processing your personal data only in alignment with the instructions we have given them, which do not conflict with the information provided in this General Privacy Policy. 

Performance Partners 

We also use performance partners to collect data about your use of our services and the performance of our services, such as which pages or functionalities are most popular, or whether there are bugs in our services so that we can improve them. 

8. Where will your personal data be stored and processed? 

When you use our BreatheLUV and #SelfCare Apps, these apps are hosted using edge computing. This means that your data is always processed at the edge of your network, where you are located, so it is not centrally located in any database. If you save your data on iCloud when you use our Apps, it will be hosted by Apple, in accordance with their Privacy Policy. Apple stores metadata – information that describes the files – and all the encryption keys on its own servers. Apple does not disclose where the data are hosted, and you should assume that they may not store your data in the country where you are located. iCloud is not part of our Services and Activities, but we provide you with this information so that you understand where your data may end up. 

We also use third party service providers, some of which store data on servers located in various countries, including the United States for which there is no current adequacy decision in effect pursuant to the European Union’s and the United Kingdom’s General Data Protection Regulations (GDPR). If you are in Europe, we are required to ensure that appropriate safeguards are in place prior to transferring your personal data out of Europe. Where there is no adequacy decision in place, we do so through standard contractual clauses or through other safeguards when they are available. If you would like more specific information about this, please contact us at privacy@truluv.ai.  

9. How do we ensure your personal data is safe? 

The security of your data is important to us, but please keep in mind that no method of transmission over the web or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. We’ve implemented reasonable security measures for the risks associated with your personal data. For instance, when we developed our website, we took into consideration HTML & CSS security best practices. Internally, we only allow access to your personal data on a need-to-know basis and with two factor authentication enabled. Please make sure that you also use safe network connections, and that you develop good practices when using your mobile device, such as enabling two factor authentication. We believe #SelfCare also means developing safe practices for your data. ♥ For more information about how we keep your personal data safe, please contact us at privacy@truluv.ai

10. How long do we keep your personal data? 

We keep your personal data for as long as necessary (a) for the purposes of the collection or (b) as required under applicable laws, whichever is longer. For instance, we keep your personal data that you transmit to us through surveys for a maximum period of one (1) year, which is how long we believe that the personal data can be useful to us. If we want to keep the data longer, we will de-identify prior to doing so. 

11. Can you opt out of marketing communications and push notifications? 

Yes, you can do so directly in the e-mails you receive by clicking the “unsubscribe” link. You can also contact us directly at the contact details provided at the beginning of this Policy or manage your preferences within our services where available. 

You can opt-out of push notifications through your mobile device, and you can also control our right to read heart data through your mobile device by opting out at any time.  

12. Do you have any rights regarding your personal data? 

You do. Your rights differ depending on where you are in the world. 

In most locations, you have the right to access the personal data we have about you and request that any incomplete or inaccurate such data be rectified. Furthermore, as stated above, when processing is based on your consent, you have the right to revoke your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You moreover have the right to request information about the use of any automated decision-making system we may be using and the impact it may have on you. 

For our European Tenders, you are entitled to additional rights, including: (i) the right to withdraw consent to processing where consent is the basis of processing; (ii) the right to object to unlawful data processing, under certain conditions; (iii) the right to erasure of Personal Information about you, under certain conditions; (iv) the right to demand that we restrict processing of your Personal Information, under certain conditions, if you believe we have exceeded the legitimate basis for processing, processing is no longer necessary, or believe your Personal Information is inaccurate; (v) the right to data portability of Personal Information concerning you that you provided us in a structured, commonly used, and machine-readable format, under certain conditions; (vi) the right to object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you, under certain conditions.  

You also always have the right to lodge a complaint with the relevant data protection authority. 

If you want to learn more about your rights under the GDPR, you can visit the European Commission's page on Data Protection.  

13. How can you exercise your rights? 

If you’re not satisfied with how we have handled your personal data, or if you want to exercise your rights, you can reach out to our Data Protection Officer at the contact details provided above and we will get back to you within 30 days. In some cases, we may need additional information to validate your identity, in which case we will use it only for this reason and delete it after.  

Note that we don’t charge fees for you to exercise your rights. However, we may charge reasonable fees for requests that are manifestly unfounded or excessive, in particular because of their repetitive character. We may also refuse to act on any such requests. 

If you disagree with how we handle your personal data, you are also always entitled to lodge a complaint with your competent data protection authority, such as the Office of the Privacy Commissioner of Canada. You can find more information on how to lodge a complaint with your competent authority on its respective website. 

14. Can we change this policy? 

Yes, we may need to modify this Privacy Policy to reflect new processing activities, adapt to new laws and regulations or reflect technological changes or corporate changes, such as a result of a merger and acquisition. We may also change this Privacy Policy at our sole discretion, such as to provide you with more details about how we handle your personal data. You can see our latest update date above. Please make sure to visit frequently. See you soon! ♥