HOTSTAR PRIVACY POLICY
Novi Digital Entertainment Private Limited, Star House, Urmi Estate, 95 Ganpatrao Kadam Marg, Lower Parel (West), Mumbai 400013, India and any of its successors and assigns ("we", "us", "our", "Novi") as the owner, operator, manager of the Hotstar UK Platform (“Platform” or the “Hotstar Service”) has appointed Star Advertising Sales Limited and any of its successors and assigns ("SASL" or “our distributor”) to distribute the Platform in the United Kingdom.
Novi values the trust placed by users of the Hotstar Service ("you", "your", "user", "subscriber") and therefore, we follow the highest standards to protect your Personal Information. Novi is the data controller of your Personal Information and is solely responsible for the use of your Personal Information, even though SASL as our distributor contracts with you to provide the Hotstar Service.
If you require any information or clarification regarding the use of your Personal Information or this Privacy Notice or if you require any general information or clarification or inquiry regarding the Platform please email us at uk@hotstar.com. Alternatively, you may contact our UK Representative: Star Advertising Sales Limited: 2nd Floor, Profile West, 950 Great West Road, Brentford, Middlesex, TW8 9ES, UK
This Privacy Notice ("Privacy Notice") explains how we collect, use and protect Personal Information of the users and / or subscribers of our Hotstar website or mobile application (“Platforms”) in United Kingdom ("UK"). In some cases, we may provide additional data privacy notices specific to certain features or services. Those notices are to be read in combination with this Privacy Notice. Where our Platforms contain links to other sites not owned or controlled by us, we are not responsible for the privacy practices of those sites and therefore we encourage you to be aware when you leave our Platforms and to read the privacy policies of other sites that may collect your Personal Information. We encourage you to read the applicable Terms of Use to understand the terms related to the use of the Platform and Hotstar Service in general.
Where we refer to 'Personal Information' we mean any information related to a particular individual who we identify (whether directly or indirectly). This includes direct identifiers such as your name, postal address, email address, and mobile number, and also includes other indirect identifiers, such as your location. Where we refer to “ID” we mean a list of numbers and/or letters (also known as a numeric or alphanumeric string) which we or our service providers may generate and which is used as a means to give you a unique customer or user identifier – it cannot directly identify you personally but it may be able to do so where other Personal Information is associated with it.
3.1 INFORMATION PROVIDED BY YOU
We may collect the following Personal Information when you (i) use or register for the Hotstar Service and create a subscription account, (ii) upload content to or via the Platform, (iii) use any of the features of the Platform (such as game play) or (iv) contact us directly:
o Name, Email Address, Phone number
o Age or date of birth, Gender, Language preferences, Content preferences, Account settings
o User-generated content including comments, photos or videos which you choose to upload or broadcast on the Platform, Game play data during game play events on our Platform
o Other profile information, such as social media account information and profile image (where feature is available)
o information to verify an account such as a form of identification (if requested)
o information in correspondence you send to us, including responses to surveys or other feedback
o information you share when you participate in marketing promotions, prize draws or competitions, and your opt-in choices and communication preferences.
We collect this information in a number of ways, including when you enter it while using our Platform, interact with our customer support, or participate in game play events on our Platform, surveys, or marketing promotions, prize draws or competitions. In some cases, where you access our Platform service available via mobile devices, Smart TVs or Internet connected TVs or Internet connected devices (“streaming devices”) your streaming device may store some of your Personal Information in their memory. These streaming devices are operated by third parties and these third parties will have their own privacy notices or other policies regarding the handling of Personal Information that they independently collect from such streaming devices. You should carefully read the privacy notice and policies of these streaming devices. We are not responsible for the privacy practices of these third parties, and the information practices of these third parties are not covered by this Privacy Notice.
3.2 INFORMATION WE COLLECT AUTOMATICALLY
We collect information about you and your use of our Platform, your interactions with us or our advertising or any direct marketing we have permission to send you, as well as information regarding your computer or other streaming device used to access our service.
The information includes:
o Your activity on the Hotstar Platform such as pages/titles viewed, load times, watch times, content selection and watch history, search queries and platform features used. This information may include the platform or website that you just visited (whether this platform is on Hotstar Services or not), which platform or website you next visit.
o Device tokens for push notification (if you have enabled push notifications)
o Your interactions with our emails, communications, messages, advertisements on third party platforms and other channels
o Your interactions with our customer support such as the date, time and reason for contacting us, transcripts of any chat conversations, and if you call us, your phone number and call recordings;
o Information about your general location, including location based on your mobile phone SIM card and/or IP address. In the event IP detection fails, we will collect the last cached location as your current location;
o Device and software information such as device id, device model, platform, type of operating system, installed version, time zone setting, mobile carrier, screen resolution etc. and other unique identifiers. With your permission we may also collect information pertaining to the applications frequently used by you on your device;
o We capture information related to the performance of the mobile application and the Platform, such as crash logs, build analytics and other performance statistics generated when you use the Platform;
o With your permission where required, information collected by us or our service providers, partners or advertising networks via the use of cookies and other technologies (You can read more about how we use cookies in our https://www.hotstar.com/gb/cookie-policy).
3.3 INFORMATION WE COLLECT THROUGH THIRD PARTY SOURCES
We may obtain your Personal Information from other sources. If you choose to link, connect or login to our Platform using a social media platform like Facebook, Twitter, Instagram or Google the social media platform may send us your profile and social information such as Email ID and Name. We may also receive information about you from third parties but will only do so where we have assurances that you have given your permission. For example, we may obtain data related to you and your interests from i) publicly available sources such public or open government databases or ii) online and offline data providers (including advertising networks and analytics providers).
4. PURPOSES AND LAWFULNESS OF PROCESSING
We will only collect and process Personal Information about you where we have a lawful basis to do so. We need to collect certain information from you in order to deliver the services to you and allow access to the Platform. Where you do not provide the required information or payment details, we may not be able to provide you with the requested services.
We do not knowingly collect or process any “special category” data as defined in the data protection laws in delivering our services to you (for example information regarding racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation). We ask that you do not send us or upload any special category information to the Platform. If we do find that any special category data is being held on the Platform, we will remove it.
Our lawful basis for processing your Personal Information will vary depending on the context in which we collect and use it and the following section explains which basis we apply to the processing we undertake. Where we refer to ‘perform the contract’ we mean the subscription contract between you and our distributor. There are a number of lawful bases available under the data protection laws. The ones we use in relation to your Personal Information are: (i) performance of a contract with you, (ii) fulfilling a legal obligation with you, (iii) pursuing our legitimate interests, (in each case we will notify you of what these interests are,) and (iv) your consent. We have set out below when each of these lawful bases applies to the processing of your Personal Information.
We use your information where we need the Personal Information to perform the contract with you (for example, to provide the Platform or our services to you) so as to:
In other contexts, we use your Personal Information where the processing is in our legitimate interests and not overridden by your fundamental rights and freedoms such as to:
We will use your Personal Information with your consent as follows:
5 PAYMENT CARD AND BILLING INFORMATION
When you purchase a subscription package our payment gateway service provider, or any other online or mobile payment services provider we may use, the following payment information will be collected by them: your credit/debit card details (number, card expiry date, CVC code) or other bank account details along with the date, time and amount of the transaction payment. This payment information is stored by our payment processors and associated with a merchant name/ID and location which our payment processor gives to us, together with a unique customer ID which we share with them but this payment information is never stored or processed by us. Our payment processors use this payment information to process and facilitate the payment of your subscription fee in order that we may provide you with the service you have requested or to enter into a contract with you to access the Platform
So that we know you have paid your subscription fee, our payment processors will send us a unique transaction ID which we associate with your unique customer ID and which we keep for internal accounting purposes..
Our payment processors may use third party fraud detection software or providers which analyse your payment information in order to make automated decisions as to whether or not payment from you will be accepted. You have the right to contest any fraud decision made about you and to be given more information about why any such decision was made by contacting us.
Where you pay a third party for your subscription package (e.g. Apple iTunes) your payment information is directly collected and controlled by that third party. However, we receive invoice receipts from third parties for your subscription purchase and these receipts are stored by us for internal accounting and tax purposes.
Where our payment processors are providing payment processing services to us (as data processors) we put in place appropriate contracts to protect your personal information (see Section 6, below on Disclosure for more information) and, where your personal information is transferred internationally outside of the UK, we take steps to ensure any transfer is subject to appropriate safeguards in accordance with data protection laws (see Section 9, below, on Data Transfer, Storage & Processing Globally for more information).
For the following aspects of the payment processing our payment processor is a data controller of your payment information (identified and listed above): providing the payment processing services to you at your request, monitoring, preventing and detecting fraudulent payment transactions, complying with legal or regulatory obligations which apply to the financial services sector and analysing, developing and improving their products and services. Our payment processors have their own privacy policies in place and we recommend you read those policies before you provide your payment information.
6. DISCLOSURE OF YOUR PERSONAL INFORMATION
• 6.1 SERVICE PROVIDERS
At times we may make your Personal Information available to our or our distributor’s service providers and affiliates (such as but not limited to: marketing, analytics, research, communication, advertisements, infrastructure and IT services, technology or software providers, payment processing and other service providers) that work with us or assist us to provide services to you or license us software which we include in our application(s). Personal Information will only be shared with our service providers to provide or improve the Hotstar Service and to enable us to analyse our marketing efforts. We do not authorize our service providers to use or disclose your Personal Information except in connection with providing their services. We conduct appropriate due diligence on such service providers to ensure they can process your Personal Information safely and we enter into contracts with them to ensure they process Personal Information in accordance with data protection laws.
• 6.2 BUSINESS OR PROMOTIONAL PARTNERS
We may offer joint promotions that, in order for you to participate and benefit from any promotional offer, will require us to share your Personal Information with third parties so that we co-ordinate and fulfil the incentive offered. These third parties are responsible for their own privacy practices as a controller or joint controller of your personal data. You should therefore ensure you have read the relevant party’s privacy policy regarding how they process your personal data.
• 6.3 BUSINESS TRANSFERS
We transfer some personal information to our group companies and affiliates for business analysis and reporting purposes. See section 9 below for details of the safeguards we have in place where such transfers are made internationally.
• 6.4 LEGAL
In the event of any requirement by court order, government or quasi-government agency to disclose our Personal Information, we will disclose information as may be legally required. We may also disclose Your Personal Information if we, in the good faith believe that such disclosure is reasonably necessary to respond to subpoenas, court orders, or other legal process.
In the event Novi is merged with or acquired by another company or in case of re-organization or re-structuring of business, we and our affiliates may share your Personal Information, wholly or in part, with another business entity.
7. YOUR CONTROLS AND CHOICES
We provide you with the ability to exercise certain controls and choices regarding our collection, use and sharing of your Personal Information. In certain circumstances, we may need to verify your identity before, for example, providing you with access to Personal Information that we hold to ensure that we are dealing with the correct person. In accordance with applicable law, your controls and choices may include:
• 7.1 MANAGING YOUR INFORMATION You can access some of your Personal Information through the 'My Account' section of the Platform post successful login. You are responsible for providing us with your accurate Personal Information and keeping your Personal Information up-to-date.
• 7.3 PUSH NOTIFICATIONS If you have enabled push notifications then you can disable (or enable) any time by going to your device “Settings” and clicking on “Notifications,” and then changing those settings for some or all of the apps on your device. (Different device configurations, or updates to devices, may affect or change how these settings work)
• 7.4 RECTIFICATION OF INACCURATE OR INCOMPLETE INFORMATION You can ask us to correct inaccurate or incomplete Personal Information concerning you by sending us an email to our support email address. In case you have made your subscription via Apple iTunes, then you will also have to rectify your subscription and / or personal data on the Apple iTunes platform as per their applicable processes.
• 7.5 DATA ACCESS AND PORTABILITY You can request copies of your Personal Information held by us. You may also be entitled to request copies of Personal Information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible). You can issue such a request by contacting us via the provided support email. In case you have made your subscription via Apple iTunes, then you will also have to request access to your subscription / personal data or portability of your subscription / personal data on the Apple iTunes platform as per their applicable processes.
• 7.6 DATA RETENTION AND ERASURE We retain your Personal Information as long as necessary for providing you the services in line with the lawful basis of processing and to comply with our legal obligations. In particular, when determining how long we retain personal data, we take into account how long we need it to:
o Maintain business records for analysis and/or audit purposes;
o Comply with record retention requirements under the law;
o Defend or bring any existing or potential legal claims; and
o Deal with any complaints regarding the Platform/any services provided on the Platform.
If you no longer want us to use your information, then you can request that we erase your Personal Information and close your Platform account. Erasure of your information from the Platform will result in your subscription being terminated without any refunds.
Please note that if you make a request for the erasure of your Personal Information;
o We may retain some of your Personal Information as necessary for our legitimate business interests, such as fraud detection and prevention and enhancing safety. For example, if we suspend a Platform account for fraud or safety reasons, we may retain certain information from that account to prevent that user from opening a new account in the future.
o We may retain and use your Personal Information to the extent necessary to comply with our legal obligations. For example, we may keep some of your information for tax, legal reporting and auditing obligations.
• 7.7 WITHDRAWING CONSENT
For Personal Information that we collect and process based on your consent, you may withdraw your consent at any time, by selecting preferences available in the app or by sending us an e-mail to uk@hotstar.com. Withdrawal of your consent will not affect the validity of processing undertaken before such withdrawal was made.
• 7.8 RESTRICTION OF AND/OR OBJECTION TO PROCESSING
You have the right to restrict our processing of your Personal Information in certain circumstances or to object to the use of your Personal Information with respect to processing on the basis of legitimate interests, including processing for direct marketing and profiling. You can object by changing your preferences, disabling cookies as set out in our Cookies Policy or by contacting us (see Contact Information).
8. CHILDREN'S PRIVACY
We do not knowingly permit any person who is under 18 years of age to register for the Platform. Please do not use or register with us if you are below 18 years of age. If we become aware that persons less than 18 years of age have registered for the Platform without verified parental consent, then we will take the appropriate steps to delete any such information. Should a parent or guardian have any reason to believe that a minor has provided us with Personal Information without their prior consent, please contact us (see Contact Information below).
9. DATA TRANSFER, STORAGE & PROCESSING GLOBALLY
We operate globally and may transfer your Personal Information to Novi affiliated companies or service providers in locations around the world for the purposes described in this Privacy Notice. Wherever your Personal Information is transferred, stored or processed by us or our affiliates or service providers, we will take reasonable steps to safeguard the privacy of your Personal Information. Additionally, when using or disclosing Personal Information transferred from the UK, we use standard contractual clauses approved by the UK Government, or adopt other approved methods for ensuring adequate safeguards under applicable data protection laws. If you would like to review a copy of these clauses (which may be partially redacted for business confidentiality reasons), please contact us (See Contact Information below).
10. SECURITY
We are continuously implementing and updating administrative, technical, and physical security measures to help protect your Personal Information against unauthorized access, loss, destruction, or alteration. Some of the safeguards we use to protect your information are firewalls and data encryption, and information access controls. These measures are designed to provide a level of security appropriate to the risks of processing your Personal Information. If you know or have reason to believe that your account credentials have been lost, stolen, altered, or otherwise compromised or in case of any actual or suspected unauthorized use of your account, please (See Contact Information below)
11. PROFILING
We use the information we collect in order to profile you and deliver appropriate content and recommendations to you. Such information includes inferences drawn from other personal information identified from you to create a profile based on your account and activities, that reflect your preferences, characteristics, behaviour, and searches related to your use of the Platform.
We do not use any automated decision making which has legal or other similarly significant direct consequences on an individual.
12. CHANGE IN PRIVACY NOTICE
This Privacy Notice is subject to change from time to time. We reserve the right, at our sole discretion, to modify the terms of this Privacy Notice from time to time in order to ensure compliance with applicable laws or in response to changing regulatory or operational requirements ("Updated Terms"). The Updated Terms shall be effective immediately (unless we state otherwise) and shall supersede the terms of this Privacy Notice. We will notify you of any changes to this Privacy Notice if the changes significantly affect your rights or as may be required by law. If you do not agree to the updates we make to the way in which we process your Personal Information, you should stop using the Service and cancel your subscription.
13. COMPLAINTS
We ask that you make any comments or complaints regarding the way in which we handle your Personal Information directly to us using the contact information provided so that we may address your concerns in the first instance. However, if you’re not satisfied with our response to any complaint or believe our processing of your information does not comply with data protection law, you can also make a complaint to the Information Commissioner’s Office (ICO) using the following details:
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone number: 0303 123 1113
Website: www.ico.org.uk