FIRE ANGEL WI-SAFE GATEWAY – PRODUCT PRIVACY NOTICE

Terms and Conditions for Install

We take your privacy very seriously. We ask that you read this privacy notice carefully. It sets out important information about the operation of your Fire Angel Wi-Safe Gateway product and about:

1.

who we are;
how and why we collect, store, use and share information about you (known as

“personal data”);
how long we will keep your personal data;
your rights in relation to your personal data;
how to contact us (and supervisory authorities) if you have a complaint.

WHO WE ARE

Fireangel Safety Technology Limited is a private limited company, registered under the laws of England and Wales, with company number 3641019 and whose registered address is Bridge House, 4 Borough Street, London Bridge, London, SE1 9QR.

We are the “controller” of personal data we collect from you or you provide to us. This means that when we collect and use your personal data, we are responsible for ensuring that your personal data is lawfully and properly processed and our conduct is regulated by data protection laws including the Data Protection Act 2018 and the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). Our registration number under the Data Protection Public Register is ZA059289.

When the following words with capital letters are used in this Privacy Notice, this is what they mean:

Contract Provider

Premises

Service

means the entity that installed the Product in the Premises.

means the premises at which the Product has been installed and in which it operates.

means the Fire Angel Wi-Safe Gateway product.

means the software that is embedded in the Product, which enables it to function.

means the Fire Angel Wi-Safe Connect service. means Fireangel Safety Technology Limited.

Product
Product Software

Service
“we” “us” and “our”

2. PERSONAL DATA WE MAY COLLECT FROM YOU

The following table explains what personal data we will or may collect about you and how it will be collected.

24514887.1

Category of personal data

What the personal data is and how it is collected

Information you give us (“Submitted information”)

The personal data you give us may include: your first and last names, address, e-mail address, telephone number, country of residence, enquiries you submit to us about the Product, the Product Software and/or the Service, information about problems/defects you are experiencing with the Product, the Product Software and/or the Service and/or details relating to why you are corresponding with/contacting us.

We may collect this personal data:

  • when you fill in and submit (i.e. via the Internet) forms we ask you to complete in relation to the Product, the Product Software and/or the Service;
  • if you register for an account with us we ask you to provide certain information in order for us set-up, provide and administer that account;
  • by corresponding or communicating with us, including by telephone, by letter or by email.

Information we collect via the installers

In certain circumstances, the installer of the Product may collect and enter personal data you provide, which includes some or all of the following types of information:

  • first and last name;
  • property address;
  • device location which may reference some of your personal data such as your name (for example “John’s Office”);
  • contact details where you are named as the point of contact for alerts relating to the Premises.

Information we collect via the Product, Product Software and the Service

(“Product Information” and “Operational Information”)

The personal data we collect may include:

  • technical information, comprising the type of Product you use, a unique product identifier (for example, the serial number and/or model number of the Product) the MAC address of the Product’s network interface, IP address, network information, time zone setting, Product Software version number (“Product Information”);
  • details about the operation of the Product and/or the Product Software, comprising the activation state of the Product (i.e. whether it is turned on, connected to our network and operating within normal parameters (which is determined solely by us)), the dates and times at which the alarm in the Product has been triggered (e.g. by smoke or

24514887.1

carbon monoxide) and if and when the alarm in the Product has been silenced subsequently, the dates and times at which the “test” button on the Product has been pressed, battery charge level and other diagnostic information about the Product, risk determination linked to the above information and its performance (“Operational Information”).

This personal data will be collected automatically during the normal operation of the Product (via the Product Software and the Service).

We need to collect the above personal data, so that the Product can perform its function and so that we can provide the Service. If you do not provide the above personal data to us, it may prevent the Product and Product Software from operating correctly and it may delay or prevent us from providing the Service.

3. HOW AND WHY WE USE YOUR PERSONAL DATA

Under data protection law, we can only use your personal data if we have a legal basis for doing so. The legal basis on which we use your personal data (as described in the table below (including its disclosure to third parties, as per numbered paragraph 4 below)) is necessary for the purposes of our legitimate interests (i.e. for the success, growth and protection of our business and safe functioning and further development of our products) and/or for the purposes of the legitimate interests of the owner of the Premises (i.e. for the operation of the Product and the safety of the Premises and for the safety of persons living at the Premises).

A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.

We use the information we collect about you (i.e. Submitted Information, Product Information and Operational Information) in the following ways:

Category of personal data

How and why we use your personal data

Submitted Information Product Information Operational Information

Used by us, so that we can:

  • identify the Product on our network (and distinguish it from other products on our network);
  • monitor the Product and its operation and use in connection with the Service. We will use the information gathered on an aggregated and anonymised basis to ascertain behaviour patterns in respect of the use made of and/or interaction with the Product from time to time (i.e. when our “Predict” service is in use). For example, the Product Software will tell us the number of times the alarm in the Product is triggered and subsequently silenced over

24514887.1

a period of time and we will use the information we gather to understand the frequency of risk patterns where fire/temperature/CO risk is identified;

  • in the event that the alarm in the Product is triggered, send automated notifications to you (including “push” notifications, where you have indicated you would like to receive them (i.e. by ticking the push notification’s check box in your device settings)) via a mobile software application (if you have downloaded and installed the same on a mobile device) and/or to a third party email address (nominated by you);
  • analyse faults with the Product that are reported to us via the Service and to provide customer assistance in respect of such faults in accordance with any applicable warranty in respect of the Product;
  • develop and/or improve the technical operation and/or quality of our products/services and/or any software used in connection with our products/services;
  • provide you with customer service and support in relation to the Product, the Product Software and/or the Service, if and when you contact us and ask us to do so;
  • monitor the quality of our products, their operation and/or our products’ compliance with applicable laws and regulations;
  • contact the Premises owner or the installer of the Product about issues/faults with/the performance of the Product, the Product Software and/or the Service.

We may also use the information you provide to us in an aggregated and anonymous form for research purposes and to help us make development, marketing, sales and/or other business decisions.

We may associate/combine any category of information with any other category of information (for example, we may associate/combine Submitted Information with Operational Information) and will treat the combined information as personal data in accordance with this Privacy Notice for as long as it is combined.

4. DISCLOSURE OF YOUR INFORMATION

At any time during which the Product, the Product Software and/or the Service are in use, we may disclose some or all of the data we collect about you to the following third parties:

Category of data

Recipient

Product Information

The owner of the Premises: We will disclose this data to the

24514887.1

Operational Information

owner of the Premises via the Service, which will allow the owner of the Premises to access, process, analyse and/or store the data for the purposes of enabling them to:

  • monitor the operational status and usage of the Product;
  • receive alerts about faults that have arisen with the Product;
  • receive alerts about the dates and times at which the alarm in the Product has been triggered;
  • monitor the dates and times at which the “test” button on the Product has been tested.The said data may also be disclosed to the owner of the Premises in circumstances where the owner of the Premises has linked the Service to an Amazon Alexa enabled device (see below in relation to data we may disclose to Amazon).This is so that the owner of the Premises can:
    • notify you if the Product is not connected to our network;
    • notify you if the Product has developed a fault;
    • notify you to remind you to test the Product.

Product Information Operational Information

Contract Service Provider: We will disclose this data to the Contract Service Provider via our FireAngel Connect software, which will allow the Contract Service Provider to access, process, analyse and/or store the data for the purposes of enabling them to perform any contract they have entered into with the owner of the Premises and to:

  • monitor the operational status and usage of the Product;
  • receive alerts about faults that have arisen with the Product;
  • receive alerts about the dates and times at which the alarm in the Product has been triggered;
  • monitor the dates and times at which the “test” button on the Product has been tested.This is so that the Contract Service Provider can notify the owner of the Premises:
    • if the Product is not connected to our network;
    • if the Product has developed a fault;
    • about the dates and times at which the alarm in the Product has been triggered;
    • with reminders to test the Product.

Product Information

The entity from whom the Contract Service Provider purchased the Product (“Distributor”): we will disclose this data to the

24514887.1

Operational Information

Distributor, so that they can:

  • provide customer service and support in relation to the Product, the Product Software and/or the Service, if and when you contact us/them and ask us/them to do so;
  • communicate/correspond with us about customer service and support issues, faults and/or maintenance issues you are experiencing / have experienced in respect of the Product, the Product Software and/or the Service.

Operational Information

Amazon: If (and only if) the owner of the Premises has linked the Service with Amazon’s Alexa service, so that he/she can submit questions to the Service via Alexa about the status of the Product, your data may be disclosed to Amazon.

When the owner of the Premises submits questions to the Service via Alexa about the status of the Product, the Service (and not Amazon) will automatically review the data held on our cloud servers to find the answer to the question asked of it. The Service will create a text instruction (i.e. the answer to the question, which may contain Operational Information) and send it to Amazon for Alexa to read out (e.g. “221b Baker St alarm was last activated on 6 January 2018”). Other than the text instructions that are created when questions are submitted to the Service via Alexa, we will not send any other data to Amazon.

Amazon will control, store, process and transfer the data it receives from us in accordance with their Privacy Policy https://www.amazon.co.uk/gp/help/customer/display.html?node Id=201909010 . For information about the data controllers who form part of Amazon and about how those data controllers will store, process and transfer your data, please read Amazon’s Privacy Policy

https://www.amazon.co.uk/gp/help/customer/display.html?node Id=201909010.

We may need to share your personal data with other third parties:
• where disclosure of the information is in our legitimate interests (i.e. for the success,

growth and protection of our business), including:

o with prospective sellers or buyers of businesses or assets, if we plan to sell or buy any business or assets, but we will only do so after the prospective seller or buyer has entered into an agreement with us to protect the confidentiality and security of your personal data;

o if Fireangel Safety Technology Limited or substantially all of its assets are acquired by a third party, in which case personal data held by it about users of the Product/Product Software/Service will be one of the transferred assets;

24514887.1

o in order to enforce or apply the End User Licence Agreement and/or any other agreements or to investigate potential breaches and/or to protect the rights, property or safety of Fireangel Safety Technology Limited, our customers, or others.

• where disclosure of the information is necessary for compliance with a legal obligation to which we are subject, including:

o if we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or request, in which case we may have to disclose your personal data to law enforcement agencies and regulatory authorities.

We may allow other IT service providers to handle your personal data if we are satisfied that we have a legal basis to share the same with them and they take appropriate measures to protect your personal data.

5. WHERE WE STORE YOUR PERSONAL DATA

Personal data you provide to us by corresponding with us by telephone, email or otherwise howsoever will be filed and stored at our offices (at Fireangel Safety Technology Limited, Vanguard Centre, Coventry, CV4 7EZ).

Information which we collect from and about you (including Submitted Information, Product Information and Operational Information) will also be stored using the Amazon Cloud service, via an account which we control and administer. The information stored using the Amazon Cloud service is a distributed cloud platform, and therefore the information we collect is not stored at one specific address. Nevertheless, all the information you provide to us and which we collect will be stored at a destination within the European Economic Area (“EEA”).

6. HOW LONG WE WILL KEEP YOUR PERSONAL DATA

Unless otherwise required by law or a regulatory authority, we will hold your personal data for the following duration:

  • Submitted Information: For as long as the owner of the Premises’ subscription for the FireAngel Connect system (i.e. the Service) remains active, plus 3 years;
  • Product Information: For as long as the owner of the Premises’ subscription for the FireAngel Connect system (i.e. the Service) remains active, plus 3 years;
  • Operational Information: For as long as the owner of the Premises’ subscription for the FireAngel Connect system (i.e. the Service) remains active, plus 3 years.We will not retain and process your personal data other than for the purposes set out in this Privacy Notice.When it is no longer necessary to retain your personal data, we will delete or anonymise it.

7. YOUR RIGHTS

You have the following rights in respect of your Personal Data, which you can exercise free of charge (unless your request is manifestly unfounded or excessive, in which case we may charge you a reasonable fee or refuse to act on the request):

24514887.1

Right

Description

Access

The right to be provided with a copy of your personal data.

Rectification

The right to require us to correct any mistakes in your personal data.

To be forgotten

The right to require us to delete your personal data – in certain situations.

Restriction of processing

The right to require us to restrict processing of your personal data — in certain circumstances (e.g. if you contest the accuracy of the personal data).

Data portability

The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party — in certain situations.

To object

The right to object:

  • at any time to your personal data being processed for direct marketing (including profiling);
  • in certain other situations to our continued processing of your personal data (e.g. processing carried out for the purpose of our legitimate interests).

Not to be subject to automated individual decision-making

The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you.

For further information on each of those rights, including the circumstances in which they apply, please contact us or consult the guidance issued by the UK Information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation.

If you would like to exercise any of those rights, please:

  • email, or write to us (see below: ‘How to contact us’);
  • let us have enough information to identify you (e.g. your full name, address andclient or matter reference number);
  • let us have proof of your identity and address (a copy of your driving licence orpassport and a recent utility or credit card bill); and
  • let us know what right you want to exercise and the information to which yourrequest relates.

8. KEEPING YOUR PERSONAL DATA SECURE

24514887.1

We have appropriate security measures to prevent your personal data from being accidentally lost, or used or accessed unlawfully. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

9. HOW TO COMPLAIN

We hope we can resolve any query or concern you may raise about our use of your personal data (see below ‘How to contact us’).

The General Data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioners Office, who may be contacted at https://ico.org.uk/concerns or telephone: 0303 123 1113.

10. CHANGES TO THIS PRIVACY NOTICE

This Privacy Notice was published in April 2020.

We may change this Privacy Notice from time to time. Any changes we may make to our Privacy Notice in the future will be posted on our website (at www.fireangeltech.com) and, where appropriate, notified to you by e-mail. Please check our website frequently to see any updates or changes to this Privacy Notice.

11. HOW TO CONTACT US

Please contact us by post, email or telephone if you have any questions about this privacy notice or the personal data we hold about you. Our contact details are as follows:

Post: Fireangel Safety Technology Limited, Vanguard Centre, Coventry, CV4 7EZ Email: technicalsupport@fireangeltech.com
Telephone: +44 2477 717 700

24514887.1