Secret Little Agents Privacy and Cookie Policy

Effective date: 19 November 2020
Your privacy is important to us. This Privacy and Cookie Policy explains in detail how we collectpersonal data from you across our website, http://www.secretlittleagents.com, and the related services (the “Website” or “Secret Little Agents”).

About Secret Little Agents

Data controller
Secret Little Agents is owned and operated by Hugsy LTD having a registered office at Suite 6867 Level 1, 6 Johnsonville Road, Wellington, 6037, New Zealand, NZBN: 9429048774154 (“we”, “us”, or “our”). We act in the capacity of a data controller with regard to the personal data processed through Secret Little Agents. As a data controller, we are responsible for collecting your personal data through Secret Little Agents and making decisions about the purposes for which your personal data is used.

What is Secret Little Agents?
Secret Little Agents allows ordering educational subscription programs directed to children (the “Programs”).

Children’s privacy
Children’s privacy is of utmost importance to us. Although our educational programs are directed to children, in most instances, our website cannot be used by persons under the age of 18. Thus, we do not collect personal data directly from children. When you order the Programs, we will ask you to provide us with some minimal information about your child(ren) in order to personalise the Programs. Such information is specified in the section “Children’s Privacy Policy”.

Links
Our Website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

Changes
At our discretion, we may change our Privacy and Cookie Policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our Website. If you are a registered user, we will notify you using the contact details saved in your account.

Our third-party privacy promise
We review the privacy policies of all our third-party providers before enlisting their services to ensure their practices align with ours. We will never knowingly include third-party services that compromise or violate the privacy of our users.

What information do we collect and how do we use it?

When you use Secret Little Agents, we automatically collect certain technical informationregarding your usage patterns. If you use certain functionalities of Secret Little Agents will ask you to provide us with your personal data. In this section, we explain in detail what personal and non-personal data we collect from you and for what purposes we use such data.

We use your personal data for limited, specified and legitimate purposes explicitly mentioned in this Privacy and Cookie Policy. In short, we use it only for the purposes of enabling you to use Secret Little Agents, delivering you the Programs, maintaining and improving Secret Little Agents, analysing our business activities, replying to your enquiries, promoting our services, and pursuing our legitimate business interests.

Personal Data
When you use Secret Little Agents, we ask you to provide us with your personal data in the following instances:
• Orders. When you join Secret Little Agents, we collect your email address, first name, last name, physical shipping address, and phone number. We use such data to register and maintain your user account, enable your access to Secret Little Agents, process your orders, send you the Programs, contact you, if necessary, and maintain our business records. The legal
bases on which we rely are ‘performing a contract with you’ and ‘pursuing our legitimate business interests’ (i.e., analyse, grow, and administer our business).


• Payment data. When you make a payment for the Programs, we ask you to provide us with your credit card number, its expiration date, and security code. If the PayPal payment option is enabled and you choose to pay by PayPal, we will ask you for your PayPal details (e.g., email address). Please note that we do not directly process payments - it is done by one of our third-party payment processors. We use your payment data to process your payments and maintain our business records. The legal bases on which we rely are ‘performing a contract’ and ‘pursuing our legitimate business interests’ (i.e., administer our business).


• IP address. When you browse Secret Little Agents, we or our third-party analytics service providers collect your IP address. We use your IP address to analyse the technical aspects of your use of Secret Little Agents, prevent fraud and abuse of Secret Little Agents, and ensure the security of Secret Little Agents. The legal basis that we rely on when processing your IP address is ‘pursuing our legitimate business interests’ (i.e., to analyse and protect Secret Little Agents).
• Contact. When you contact us by email or the chat available on the Website, we collect your name, email address, and any information that you decide to include in your message. We use such data to respond to your enquiries. The legal bases on which we rely are ‘pursuing our legitimate business interests’ (i.e., to grow and promote our business) and ‘your consent’ (for optional personal data).

Log data
When you visit our Website, our servers may automatically log the standard data provided by your web browser. This data is considered “non-personal data”, as it does not personally identify you on its own. It may include your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details. We may also collect data about the device you are using to access our Website. This data may include the device type, operating system, unique device identifiers, device settings, and geo-location data. What we collect can depend on the individual settings of your device and software.

We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us. We use your log data to:
• Gain gain insights into demographics of the users of Secret Little Agents;
• Examine the relevance, popularity, and engagement rate of Secret Little Agents;
• To investigate and help prevent security issues and abuse;
• To develop and provide additional features to Secret Little Agents; and
• To personalise Secret Little Agents for your specific technical needs (e.g., to adjust the design and resolution for your device).

Your feedback
If you contact us, we may keep records of any questions, complaints, recommendations, or compliments made by you and any subsequent responses. Where reasonably possible, we remove all personal data that is not necessary for keeping such records. We will use such data only for our internal business purposes (e.g., to improve the Programs). The legal basis on which we rely is ‘pursuing our legitimate business interests’.


Sensitive data
We do not collect or use any special categories of personal data (“sensitive data”) from you, unless you decide, at your own discretion, to provide such data to us. Sensitive data is information that relates to your health, religious and political beliefs, racial origins, membership of a professional or trade association, or sexual orientation. Refusal to provide personal data We collect information by fair and lawful means, with your knowledge. We also let you know why we’re collecting it and how it will be used. You are free to refuse our request for this information, with the understanding that we may be unable to provide you with some of your desired services without it.

Aggregated and de-identified data
If we combine your non-personal data with certain elements of your personal data and such a combination allows us to identify you as a natural person, we will handle such aggregated data as personal data. If your personal data is de-identified in a way that it can no longer be associated with a natural person, it will not be considered personal data and we may use it for any business
purpose.

Commercial communication
We may use your personal data to contact you with updates about the Programs and Secret Little Agents, along with promotional content that we believe may be of interest to you. If you wish to opt out of receiving promotional content, you can follow the “unsubscribe” instructions provided alongside any promotional correspondence from us. Please note that we will send you commercial communication only if you (i) have previously purchased the Programs, (ii) subscribed to our newsletter, or (iii) completed a quizz and agreed to receive personalised commercial communication.

How do we store and protect your personal data?

Storage
The personal information we collect is stored and processed in our servers, or where we or our partners, affiliates and third-party providers maintain facilities. We only transfer data within jurisdictions subject to data protection laws that reflect our commitment to protecting your privacy.

Storage period
We only retain your personal data for as long as necessary for the primary purposes of your personal data. If you request your personal data be deleted, or where your personal data becomes no longer necessary for its primary purposes, we will securely erase it from our system without undue delay.

Security measures
While we retain this data, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification. Our security measures include secured networks, SSL protocol; strong passwords, limited access to your personal data by our staff, and anonymisation of personal data (when possible). That said, we advise that no method of electronic transmission or storage is 100% secure, and cannot guarantee absolute data security.

How do we store and protect your personal data?

Disclosure to our data processors
From time to time, your personal data is disclosed to our service providers with whom we cooperate (our data processors). For example, we share your personal and non-personal data with entities that provide certain technical support services to us, such as hosting and email distribution services. We do not sell your personal data to third parties. Our data processors access your
personal data solely for the purpose of performing specific tasks on our behalf. We do not give them permission to disclose or use any of our data for any other purpose. The disclosure is limited
to the situations when your personal data is required for the following purposes:
• Ensuring the proper operation of Secret Little Agents;
• Ensuring the delivery of the Programs that you have purchased;
• Providing you with the requested information;
• Pursuing our legitimate business interests;
• Enforcing our rights, preventing fraud, and security purposes;
• Carrying out our contractual obligations; or
• If you provide your prior consent to such a disclosure.

List of our data processors
We use a limited number of data processors. We choose them only if they agree to ensure an adequate level of protection of your personal data that is consistent with this Privacy and Cookie Policy and the applicable data protection laws. The data processors that have access to your personal data are:
• Our hosting service provider Liquid Web (https://www.liquidweb.com) located in the US;
• Our checkout service provider Subbly (https://www.subbly.co) located in the UK;
• Our email marketing service provider ActiveCampaign (https://www.activecampaign.com)
located in the US;
• Our analytics service providers Google Analytics (https://analytics.google.com), Google Tag
Manager (https://tagmanager.google.com), Tidio (https://www.tidio.com), and Lucky Orange
(https://www.luckyorange.com) located in the US, and ProveSource (https://provesrc.com)
located in Israel;
• Our payment processing service provider Stripe (https://stripe.com) and PayPal
(https://www.paypal.com) located in the US; and
• Our shipping service provider McMannis Duplication & Fulfillment
(http://mcmannisduplication.com) located in the US.

External consultants
We may, from time to time, allow limited access to our data by external consultants and agencies for the purpose of analysis and service improvement. This access is only permitted for as long as necessary to perform a specific function. We only work with external agencies whose privacy policies align with ours.

International transfers
Some of our data processors are located outside the country in which you reside. Therefore, we may need to transfer your personal data to other countries. In case it is necessary to make such a transfer, we will make sure that the jurisdiction in which the recipient third party is located guarantees an adequate level of protection for your personal data or we conclude a data processing agreement with the respective third party that ensures such protection. We will not transfer your personal data internationally if no appropriate level of protection can be granted. 

Disclosure of technical (non-personal) data
Your technical (non-personal) data may be disclosed to third parties for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving Secret Little Agents, planning the Programs, responding to lawful requests from public authorities or developing new products and services.

Legal requests
We will refuse government and law enforcement requests for data if we believe a request is too broad or unrelated to its stated purpose. However, we may cooperate if we believe the requested information is necessary and appropriate to comply with legal process, to protect our own rights and property, to protect the safety of the public and any person, to prevent a crime, or to prevent what we reasonably believe to be illegal, legally actionable, or unethical activity.

Successors
In case Secret Little Agents is sold partly or fully, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in line with this Privacy and Cookie Policy. We will notify you of any changes of the data controller.

Selling personal data
We do not directly sell your personal data to third parties. However, some of your personal data, including online identifiers (e.g., cookie-generated data and IP addresses) may be used for advertising, marketing, and monetisation purposes (e.g., programmatic advertising, retargeting, third-party marketing, profiling, or cross-device tracking). To make sure that you have full transparency and control over your personal data, we provide you with a possibility to manage your personal data used for such purposes as described in this notice below.

How can you manage your personal data?

You have certain rights to control how we process your personal data. You can exercise your rights listed below, unless, in very limited cases, the applicable law provides otherwise:
• Right of access: you can get a copy of your personal data that we store in our systems and a list of purposes for which your personal data is processed;
• Right to rectification: you can rectify inaccurate personal data that we hold about you;
• Right to erasure (‘right to be forgotten’): you can ask us to erase your personal data from our systems;
• Right to restriction: you can ask us to restrict the processing of your personal data;
• Right to data portability: you can ask us to provide you with a copy of your personal data in a structured, commonly used and machine-readable format and move that personal data to another processor;
• Right to object: you can ask us to stop processing your personal data;
• Right to withdraw consent: you have the right to withdraw your consent, if you have provided one; or
• Right to complaint: you can submit your complaint regarding our processing of your personal data.

To exercise your rights, please contact us by email at agent-support@secretlittleagents.com and explain your request in detail. In order to verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information that allows us to identify you in our system. We will answer your request within a reasonable time frame but no later than 2 weeks.

Filing a formal complaint
If you would like to launch a complaint about the way in which we process your personal data, we kindly ask you to contact us first and express your concerns. If we receive your complaint, we will investigate it and provide you with our response as soon as possible. If you are not satisfied with the outcome of your complaint, you have the right to lodge a complaint with your local data protection authority.

Non-discrimination
We do not discriminate against you if you decide to exercise your rights. It means that we will not
(i) deny any goods and services, (ii) charge you different prices, (iii) deny any discounts or benefits,
(iv) impose penalties, or (v) provide you with a lower quality service.

Cookie policy

We use “cookies” to collect information about you and your activity across our Website. A cookie is a small piece of data that our Website stores on your computer, and accesses each time you visit, so we can understand how you use our Website. This helps us serve you content based on preferences you have specified.

What is a cookie?
A cookie is a small piece of data that a website stores on your device when you visit, typically containing information about the website itself, a unique identifier that allows the website to recognise your web browser when you return, additional data that serves the purpose of the cookie, and the lifespan of the cookie itself. Cookies are used to enable certain features (eg. logging in), to track site usage (eg. analytics), to store your user settings (eg. timezone, notification preferences), and to personalise your content (eg. advertising, language). Cookies set by the website you are visiting are normally referred to as “first-party cookies”, and typically only track your activity on that particular site. Cookies set by other sites and companies (ie. third parties) are called “third-party cookies”, and can be used to track you on other websites that use the same third-party service.

Disabling cookies
If you don’t wish to accept cookies from us, you should instruct your browser to refuse cookies from our Website, with the understanding that we may be unable to provide you with some of your desired content and services.

Cookie consent
When you visit our Website for the first time, we may ask you to provide us with your consent to our use of all cookies via a cookie consent banner (e.g., if you are based in the EU). If you do not provide your consent, we serve you our essential technical cookies only. Please note that we may not be able to provide you with the best possible user experience if not all cookies are enabled.

Types of cookies and how we use them
• Essential cookies. Essential cookies are crucial to your experience of a website, enabling core features like user logins, account management, shopping carts and payment processing. We use essential cookies to enable certain functions on our Website.

• Performance cookies. Performance cookies are used in the tracking of how you use a website during your visit, without collecting personal information about you.  Typically, this information is anonymous and aggregated with information tracked across all site users, to help companies understand visitor usage patterns, identify and diagnose problems or errors their users may encounter, and make better strategic decisions in improving their audience’s overall website experience. These cookies may be set by the website you’re visiting (first-party) or by third- party services. We use performance cookies on our site.

• Functionality cookies. Functionality cookies are used in collecting information about your device and any settings you may configure on the website you’re visiting (like language and timezone settings). With this information, websites can provide you with customised, enhanced or optimised content and services. These cookies may be set by the website you’re visiting (first-party) or by third-party service. We use functionality cookies for selected features on our site.

• Targeting/advertising cookies. Targeting / advertising cookies are used in determining what promotional content is more relevant and appropriate to you and your interests. Websites may use them to deliver targeted advertising or to limit the number of times you see an advertisement. This helps companies improve the effectiveness of their campaigns and the quality of content presented to you. These cookies may be set by the website you’re visiting (first-party) or by third-party services. Targeting / advertising cookies set by third-parties may be used to track you on other websites that use the same third-party service. We use targeting / advertising cookies on our site.

• Third-party cookies on our Website. We may employ third-party companies and individuals on our Website—for example, analytics providers and content partners. We grant these third parties access to selected information to perform specific tasks on our behalf. They may also set third-party cookies in order to deliver the services they are providing. Third-party cookies can be used to track you on other websites that use the same third-party service. As we have no control over third-party cookies, they are not covered by Secret Little Agents's cookie policy.

List of our cookies
Below, you can find a list of cookies that we use on the Website, including their purpose and expiration time:
Statistics cookies
Name
Type
Provider
(location)

Expiration
Purpose
(location)
First-party HTTP cookie
secretlittleagents.com
(NZ)
2 years
This cookie is used to collect information on the visitor's behavior. This information will be stored for internal use on the website – internal analytics is used to optimize the websites or to register if the visitor has subscribed to a newsletter.
__kla_id
First-party HTTP cookie
secretlittleagents.com
(NZ)
2 years
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
   
First-party HTTP cookie
secretlittleagents.com
(NZ)
1 day
Used by Google Analytics to throttle request rate
(NZ)
First-party HTTP cookie
secretlittleagents.com
(NZ)
End of Session
Unclassified
_ga
First-party HTTP cookie
secretlittleagents.com
(NZ)
1 day
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
_gat
First-party HTTP cookie
secretlittleagents.com
(NZ)
3 months
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
(NZ)
Third-party Pixel cookie
google.com
(US)
End of session
Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor's online behaviour across websites.
_gd#
Third-party Pixel cookie
Third-party HTTP cookie
3 months
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
  
Third-party HTTP cookie
doubleclick.net (US)
1 year
Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.
(NZ)
Third-party Pixel cookie
google.com
(US)
End of session
Tracks if the user has shown interest in specific products or events across multiple websites and detects how the user navigates between sites. This is used for measurement of advertisement efforts and facilitates payment of referral-fees between websites.
_gid
First-party HTML cookie
secretlittleagents.com
(NZ)
Persistent
Tracks the conversion rate between the user and the advertisement banners on the website. This serves to optimise the relevance of the advertisements on the website.
(NZ)
First-party HTML cookie
secretlittleagents.com
(NZ)
Persistent
Registers a unique ID that identifies the user's device during return visits. Used for conversion tracking and to measure the efficacy of online ads.
Marketing cookies
First-party HTML cookie
secretlittleagents.com
(NZ)
3329 days
Collects information on user preferences and/or interaction with web-campaign content. This is used on CRM-campaign-platform used by website owners for promoting events or products.
(location)
Third-party HTTP cookie
facebook.com
(US)
End of session
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
_fbp
Third-party HTTP cookie
youtube.com
(US)
179 days
Tries to estimate the users' bandwidth on pages with integrated YouTube videos.
(NZ)
Third-party HTML cookie
youtube.com
(US)
End of session
Registers a unique ID to keep statistics of what videos from YouTube the user has seen.
ads/ga-audiences
Third-party HTML cookie
youtube.com
(US
Persistent
Stores the user's video player preferences using embedded YouTube video.
    
Third-party HTML cookie
youtube.com
(US
Persistent
Stores the user's video player preferences using embedded YouTube video.
(US)
Third-party HTML cookie
youtube.com
(US
End of session
Stores the user's video player preferences using embedded YouTube video.
How you can control or opt out of cookies
If you do not wish to accept cookies from us, you can instruct your browser to refuse cookies from our Website. Most browsers are configured to accept cookies by default, but you can update these settings to either refuse cookies altogether, or to notify you when a website is trying to set or update a cookie. If you browse websites from multiple devices, you may need to update your settings on each individual device. Although some cookies can be blocked with little impact on your experience of a website, blocking all cookies may mean you are unable to access certain features and content across the sites you visit. For more information, you can consult the cookie management instructions of your browser:

Children's privacy policy
We are committed to protecting the privacy of children who use the Programs. This children’s privacy policy is part of our approach to privacy, and covers the way we collect, store and manage information provided by children under the age of 13, in accordance with the US Children’s Online Privacy Protection Act (COPPA). We encourage parents to engage with us in protecting their children’s privacy, ensuring a safe and enjoyable online experience. Please note that we do not collect personal data directly from children through the Website - the use of the Website is reserved for persons above the age of 18. However, from time to time, we may invite you to participate in our online Programs together with your child or ask you to provide certain information about your children to customise the Programs and analyse our business (e.g., the number of children that you have, their age, name, and preferences). You have the option not to provide your child’s personal data. 

Collecting information from children
At times, we may require information from children to enable participation in the Programs. When collecting non-personal information, we encourage children never to provide any details that may personally identify them or reveal their location. We do not require children to provide more information than is necessary to participate in an activity.

We do not use children’s contact details (if we have them) for marketing purposes, though we may use them for our internal marketing and research in order to improve the quality of products and services offered across our site.

Parental consent
In accordance with COPPA, if an activity does require children’s personal information (such as first name, last name, or email address), we will provide notice to and seek consent from a parent or guardian prior to collecting the information. We only retain collected information for as long as necessary to enable participation in the requested activity

In the event we discover we have collected personal information in a manner non-compliant with COPPA, we will either delete the information or seek parental consent.
As a parent/guardian, if you believe your child is participating in an activity that collects personal information, and you have not received a notification or request for consent, please feel free to get in touch with us. 

Safeguarding children’s privacy
We take security seriously, and do what we can within commercially acceptable means to protect your child’s personal information from loss or theft, as well as unauthorised access, disclosure, copying, use or modification. That said, we advise that no method of electronic transmission or storage is 100% secure, and cannot guarantee absolute data security.

Information abuse and community misconduct
We do not tolerate doxing (publishing of private or personal information about an individual without their consent), cyberbullying, or other forms of information abuse on Secret Little Agents. If we discover that a child’s personal information has been disclosed on Secret Little Agents without the express consent of their parent/guardian, we will remove the content in question as quickly as possible and effect disciplinary measures (a warning, suspension or ban) on the offending account.

Third-party access to information
We do not knowingly disclose any personally identifying information or personal information provided by children to third parties. We may, however, disclose anonymised and aggregated versions of this information (analytics and statistics) for business, marketing or public relations purposes.

Parental controls and intervention
As a parent/guardian, you may at any time refuse to let us collect further information from your children for a particular activity or account by contacting us.Please be aware that the removal of certain information may result in the termination of the associated account, or withdrawal from the associated activity.

How to contact us?

If you have any questions about our data protection practices, please contact us by:
Mailing address: Hugsy LTD, Suite 6867m Level 1, 6 Johnsonville Road, Wellington, 6037, New Zealand