PRIVACY POLICY

Protecting your private information is our priority. This Statement of Privacy applies to https:// www.bossworkapp.com/ and the related Application “Boss App” (hereinafter “our platform”) and governs data collection and usage. For purpose of this Privacy Notice, the terms “we” and “our” refer to Boss, LLC (or any of its subsidiaries (collectively, and including “bossapp,” “Boss App,” “bossworkapp.com,” or “Boss,”). By using our platform(s), you consent to the data practices described in this statement.


We use this privacy notice to disclose the privacy practices of our platform in accordance with privacy regulations, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We aim to help you understand what personal data we collect, how we use it, and what control you have over it. This notice applies solely to data collected by our platform. This notice will define the following:

  1. What personal data is collected by the platform.

  2. How personal data is collected, used, shared, stored, and otherwise processed.

  3. The security procedures implemented to protect your data.

  4. Your choices and rights regarding the use of your data.

  5. How you can contact us for issues such as to correct inaccuracies of your data or to request the removal of your personal data.


Please read the following privacy notice to understand the processing, collection, sharing, protection, and your rights associated with your personal data.


DATA WE COLLECT

In order to better provide you with products and services offered to you, our platform may collect personally identifiable information. In short, we collect personal information that you provide to us. when you register on the platform, express an interest in obtaining information about us or our platform or other services, when you participate on, or engage with the platform, or otherwise when you contact us. In particular, we may collect and have collected in the past twelve (12) months, the following categories of personal information (as defined by the CCPA):


Category

Examples

Collecte d


A. Identifiers

Name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name (“username”), or other similar identifiers


YES

B. Personal information

categories listed in the California Customer Records statute

Name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit or debit card number, other financial information, medical information, health insurance information


YES

C. Protected classification

characteristics under California or federal law

Race, religion, sexual orientation, gender identity, gender expression, age


NO

D. Commercial information

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies


NO

E. Biometric information

Hair color, eye color, fingerprints, height, retina scans, facial recognition, voice, and other biometric data


NO

F. Internet or other similar network

activity

Browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement


NO


G. Geolocation data

Physical location or movements


YES

H. Audio, electronic, visual, thermal,

olfactory, or similar sensory information

Audio, electronic, visual, thermal, olfactory or similar information


NO

I. Professional or employment-related

information

Current or past job history or performance evaluations


NO


J. Education Information

Non-public education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records


NO

K. Inferences drawn from other personal

information

Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes


NO

L. Sensitive Personal Information

Account login information, debit or credit card numbers and precise geolocation


YES


Please keep in mind that if you directly disclose personally identifiable information or personally sensitive data through our platforms’ public message boards (e.g., comments on a blog post), this information may be collected and used by others.


We do not collect any personal information about you unless you voluntarily provide it to us. However, you may be required to provide certain personal information to us when you elect to purchase certain products or use certain services available on our platform. These may include:

(a) registering for an account on our platform; (b) entering a sweepstake or contest sponsored by us or one of our partners; (c) signing up for special offers from selected third parties; (d) sending us an email message; (e) submitting your credit card or other payment information when ordering and purchasing products and services on our platform. To wit, we will use your information for, but not limited to, communicating with you in relation to services and/or products you have requested from us. We also may gather additional personal or non-personal information in the future.


HOW WE USE YOUR DATA

Our platform collects and uses your personal information to operate our application and deliver the services and/or products you have requested. Our platform may also use your personally identifiable information to inform you of other products or services available from us and our affiliates. Accordingly, your personal data may be used for the following purposes:


Purpose

Categories Used

Customization of content and user experience.

A, G, L

Account set up and administration.

A

Conducting polls, surveys, and contests.

A

Internal research and development.

A

Legal obligations.

A, B, G, L

Internal audits.

A, B, G, L

Fulfillment of obligations outlined in any agreements with users.

A, B, G, L

Gathering feedback and opinions on our provided services.

A

Notification to users of changes to our services.

A

Respond to your requests and comments.

A

Process your transactions.

A, B, L

Detecting security incidents and debugging and providing security updates to our websites/applications

A, B, G, L


Legal Basis of Processing.


We process personal data for purposes of our own legitimate interests, granted that those interests do not override any of our users' own interests, rights, and freedoms. This legitimate interest includes processing for user customization, processing transactions (e.g., order processing and invoicing), marketing, research, and business development purposes.


More particularly, we process your personal information for a variety of reasons, depending on how you interact with our platform, including: (a) to facilitate account creation and authentication and otherwise manage your accounts; (b) to deliver and facilitate delivery of services to you; (c) to respond to user inquiries/offer support to you; (d) to send administrative information to you; (e) to fulfill and manage your orders; (f) to enable user-to-user communications; (g) to request and obtain feedback; (h) to send you marketing and promotional communications; (i) to deliver targeted advertising to you; (j) to protect our platform and keep our platform safe and secure, including fraud monitoring and prevention; (k) to evaluate and improve our platform, products, marketing, and your experience; (l) to determine the effectiveness of our marketing and promotional campaigns; (m) to comply with our legal obligations.


We also process personal data for other purposes with consent, but you have the right to withdraw consent to processing for specific purposes, as outlined below.


Specific Data Use

To fully access the platform, you, as a user, can voluntarily register for an account. Certain data is collected during this process, including your name and email address. This data is used to contact you, suggest appropriate products and services, and improve your user experience.

When necessary, with your consent or as otherwise permitted by applicable law, we process financial data, including credit card or debit information. We may collect data necessary to

process your payment if you make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is stored by stripe. You may find their privacy notice link(s) here: https://stripe.com/privacy.

We may also collect and store social media login data. We may provide you with the option to register with us using your existing social media account details, like your Facebook, Twitter, or other social media account. If you choose to register in this way, we will collect this information consistent with our policies described herein.


As part of using our platform, if you use our application(s), we may collect the following information if you choose to provide us with access or permission:

Please note your request may only go back 12 months from the date of your request.


Right to Delete. You have a right to request that we delete your personal information, subject to certain exceptions such as if the information is necessary to complete the transaction for which the information was collected, detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, identify and repair errors and for various other reasons available under California law.


Right of Non-Discrimination. We will not discriminate against you in any way if you choose to exercise your rights under this section or applicable California law.


Submit a Request. To submit a request to know or delete, you may contact us via the contact information provided in this Notice.


Verification. In order to protect your personal information and prevent against fraud, we may verify your identity before responding to your request by matching the information provided in your request with the information we have on file about you, and depending on the sensitivity of information requested utilizing more stringent verification methods, including but not limited to requesting additional information from you and/or requiring you to sign a declaration under penalty of perjury.


Notice of Collection and Disclosure for a Business Purpose. The categories of personal information we have collected over the last twelve months, including, from where we collect it, the purpose for collection, and with whom we share it is outlined in this Notice.


VIRGINIA DISCLOSURES

Pursuant to Virginia law, some Virginia residents have specific rights regarding their personal data as described below. These rights are subject to certain exceptions.

When legally required, we will respond to most requests without undue delay, within 45 days of receipt of the request, unless it is reasonably necessary for us to extend our response time.

Right to Confirm and Access. You have the right to request confirmation from us as to whether or not we are processing your personal data and to access such personal data. If you submit a valid and authenticated request and we confirm your identity and/or authority to make the request, we will confirm for you whether or not we are processing your personal data and/or grant you access to your data.

Right to Request Correction of Inaccuracies. You have the right to request that we correct any inaccuracies in any of your personal information, which is under our control, taking into account the nature of the data and the purposes of processing that data. If you submit a valid and authenticated request and we confirm your identity and/or authority to make the request, we will correct the personal information.

Right to Request Deletion of Personal Data. You have the right to request that we delete any of your personal data that we collected from or about you and retained. If you submit a valid and authenticated request and we can confirm your identity and/or authority to make the request, we will delete your personal data from our records and direct our service providers to do the same, if no exceptions or retention conditions apply.

Right to Request Disclosure of Information. You have the right to request a copy of your personal data previously provided to us in a portable and, to the extent technically feasible, readily usable format, thereby permitting you the ability to transmit the data without hindrance.

Right to Opt-Out of Processing. As a Virginia resident, you have the right to direct a business that processes your personal data for the purposes of targeted advertising, sale, and/or profiling, in furtherance of decisions that produce legal or similarly significant effects concerning you, not to process for these purposes. This right is referred to as “the right to opt-out.” If you submit a valid and authenticated request and we confirm your identity and/or authority to make the request, we will cease processing your personal data for the limited purposes of targeted advertising, sale, and/or profiling. Because we are not selling your personal data for monetary compensation, we do not provide an opt-out for these activities. Since we may engage in targeted advertising and/or profiling, we provide you with the option to opt-out of such processing for these purposes. To do so, contact us using the contact information provided in this Notice.

Submit a Request. To exercise your rights described above, please contact us using the contact information provided in this Notice. You may make an authenticated consumer request no more than twice within a 12-month period. The authenticated request must:

Verification. In order to safeguard the personal data in our possession, if we cannot verify your identity or authority to act on another’s behalf using commercially reasonable efforts, we will be unable to comply with your request and may request additional information from you. We will only use personal data you provide when submitting an authenticated request to confirm your identity or authority, or to fulfill your request.

Right to Appeal. If we refuse to act on your request, you have the right to appeal our decision within a reasonable period of time after receipt of our initial decision. We will inform you in writing, within 60 days of receipt of an appeal, of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. To exercise your right to appeal, please submit an authenticated consumer appeal request to us using the contact information provided in this Notice.

If your appeal is denied, you may contact the Attorney General to submit a complaint by visiting the Office of the Attorney General’s website to complete an Online Consumer Complaint

Form or by calling the Consumer Protection Hotline at 1-800-552-9963 (within Virginia) or 804-786-2042 (outside Virginia).

Right to Non-Discrimination. You may exercise your rights under the CDPA without discrimination. For example, unless the CDPA provides an exception, we will not: (a) deny you goods or services; (b) charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; or (c) provide you a different level or quality of goods or services.


CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and mobile applications include a Do- Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.


E-MAIL COMMUNICATIONS

From time to time, we may contact you via email for the purpose of providing announcements, promotional offers, alerts, confirmations, surveys, and/or other general communication.

If you would like to stop receiving marketing or promotional communications via email from us, you may opt out of such communications by contacting us using the contact information provided in this Notice.


CHANGES TO THIS NOTICE

We reserve the right to change this Privacy Notice from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account, by placing a prominent notice on our platform, and/or by updating any privacy information on our platform. Your continued use of our platform and/or any related services available through our platform after such modifications will constitute your:

(a) acknowledgment of the modified Privacy Notice; and (b) agreement to abide and be bound by that Policy.


CONTACT INFORMATION

We welcome your questions or comments regarding this Privacy Notice. If you believe that we have not adhered to this Notice, please contact us at:


Email:

aj@bossworkapp.com privacy@bossworkapp.com


Post:

Boss App

1023 9th St. Apt 2

Hull, IA 51239

United States


This Privacy Notice was last updated on: December 15, 2023