Privacy Policy

This “Privacy Policy” is a legal agreement made between the individual or organization (“you”, “User” or “Customer”) using the Services provided by “Lokot” owned by PhishAR Ltd (“us”, “we”, “our”, “Lokot”, or “PhishAR”). PhishAR is the data controller in all situations defined in this Privacy Policy.

This Privacy Policy details our commitment to protecting the privacy of individuals who share their personal data with us. It explains how the data is collected, what is stored, how and for how long, the purpose of storing and processing of such data, as well as individual rights in relation to such data.

Please read it carefully before accessing any of our service. If you have any questions about this Privacy Policy, please email us at lokot@phishar.com.

1. Definitions

  1. “Personal data” means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  2. “Service”, “Account” are in detail described in the binding Terms of Services, article 1 “Definitions” section.
  3. “Lokot Mobile Application” and “Lokot Backup” are in detail described in the binding Terms of Services, article 3 “Services” section.
  4. “2FA Accounts” are your personal accounts created in our Application used for authentication

2. Regulatory frame

We processes personal data in accordance with the provisions of the EU General Data Protection Regulation (GDPR) and other applicable data privacy regulations.

3. Legitimate interests

If not expressly mentioned otherwise, collecting and processing of data is based on our legitimate interest, considering always that your fundamental rights and freedoms are not overridden by the interests of our communication with you.

4. Use of Lokot Mobile Application

By using our Lokot Mobile Application you grant us the right to track and store information about your usage of the application. We collect information in order to better understand, improve and enhance the experience of using the Services we provide to you. Information that we collect is, including but not limited to, how often do you use our services, how much time do you spend using our service, what information and app screens you visit the most, and how you interact with our service. All data acquired in the process is anonymous. We do not hold any personal data in any way until Lokot Backup is enabled which is described in Article 5 of the Privacy Policy.

We may collect and use images and videos taken with your device camera through the app. This information is only used to test and improve the quality of our Service. Such information might be stored on a device storage and sent to the Service servers when your device is connected to a Wi-Fi network. Using a WiFi network might incur additional charges.

This processing of such information is based on our legitimate interest to improve your experience while using the mobile application as well as to optimize our services.

We do not sell, lease or rent personal data relating to any of our users to third parties.

5. Use of Lokot Backup

By enabling Lokot Backup, you grant us the right to store your Personal data, specifically your email address and your 2FA Accounts.

We ensure the highest possible security standards in order to protect your Personal data. The provided information is essential for the functioning of our service and so by enabling Lokot Backup you implicitly grant us the right to process and store data.

In case of withdrawing your consent, we cannot provide you with our Lokot Backup service. In such case, your only recourse is to continue using our Lokot Mobile Application without backup or to exercise your right to cancel your Account and fully discontinue the use of our service.

6. Other sources of data acquisition

If you choose to contact us either by email or post, regarding any matter not previously mentioned, including but not limited to, complaint, feedback, inquiry, general interest or unrelated, we reserve the right to store any information relevant to your inquiry, including but not limited to your first and last name, e-mail address, phone number, city, country of residence, IP address, in order to reply to your request, optimize our services and inform you about PhishAR’s offerings.

7. 3rd party services

Firebase Analytics and Crashlytics

Lokot Mobile Application uses Crashlytics analysis services offered by Google Inc. Crashlytics provides information on unforeseen system crashes and other malfunctions, thus helping us to constantly improve the Lokot Mobile Application.

Amplitude

Lokot Mobile Application uses Amplitude services offered by Amplitude Inc. Amplitude provides us with information on usage of various functionalities implemented and offered as the core services of the Lokot Mobile Application.

8. Future services

In order to enhance your user experience and optimize services and offerings, we may add additional tools or introduce new third-party providers. We will strive to notify of such changes by updating our Privacy Policy in due time. Any data collected through the channels described above might be shared with such third parties. You can contact us at any time to get additional information about such data sharing.

In addition, we may disclose information to third parties in an aggregate format that does not constitute Personal data and does not allow the identification of individual users.

9. Profiling and custom content

We do not automatically process, nor use techniques for profiling our users. Furthemore, Lokot Mobile Application does not serve nor limit content based on Personal data.

10. Security measures

We implement an information security management system to ensure the confidentiality, availability and integrity of assets from threats and vulnerabilities.

To prevent unauthorized access or disclosure and to maintain data accuracy, as well as to ensure the appropriate use of such data, we utilize all reasonable technical and organizational measures to protect your personal data, including but not limited to minimizing the processing of personal data, pseudonymization, and anonymization of personal data as soon as possible, transparency with regard to the functions and processing of personal data, enabling each individual to have knowledge of the ways and reasons for data processing. All personal data is encrypted while in transit and in storage. Additionally, PhishAR continuously undertakes and upgrades different measures to ensure the highest standards for data privacy. We design all our processes with special emphasis on protecting personal and confidential data.

Although we take best industry practice in keeping the data safely stored, we do not warrant that the undertaken safety, technical and organizational measures will be sufficient to fully protect your personal data against potential unauthorized access and use of your personal data.

Moreover, to the maximum extent permitted by applicable law, we cannot guarantee the full safety of your information. However, if such an attempt is detected, we will notify you as soon as reasonably possible of a potential breach of the security measures either directly to your contact address, if disclosed, or via an notification on our website and other appropriate channels.

11. Affiliated companies

We may share information with its affiliates and subsidiaries. Provisions of this Privacy Policy apply to PhishAR affiliated companies PhishAR d.o.o ID: HR 33026948132, Trg Petra Svačića 5, 10 000 Zagreb, Croatia. Depending on which company you contacted and for what reason, such a company shall be considered a data controller in a particular case.

We may also share information with its subsequent owner, co-owner, or operator of the services and their advisors in connection with a corporate merger, consolidation, restructuring, or the sale of substantially all of our stock and/or assets, or in connection with bankruptcy proceedings, or other corporate reorganization, in accordance with this Privacy Policy.

12. Data transfer

The Internet is a global environment. Using the Internet to collect and process personal data necessarily involves the transmission of data on an international basis. Any such transfer is made in accordance with regulatory requirements that ensure such transfer and/or country maintains the same level of personal data protection. PhishAR opted for industry-approved storage providers with the highest privacy and data security standards.

13. Data retention period

We may retain your personal data as long as it is required to complete the purpose of collection or as long as the applicable law requires.

The data that is not required to be kept by applicable law, shall be kept up to ten years from receipt.

If we collect the personal data on the basis of consent, the data shall be stored for as long as such consent is not withdrawn.

14. Your rights

Each individual has a right to know what data PhishAR holds about any such person. The rights every individual has in relation to personal data shared with us are:

  1. the right to be informed,
  2. the right of access,
  3. the right to rectification,
  4. the right to erasure,
  5. the right to restrict processing,
  6. the right to data portability,
  7. the right to object to processing,
  8. the right to withdraw consent, and
  9. the right not to receive discriminatory treatment by PhishAR for the exercise of an individual’s rights conferred by the applicable data protection laws.

For any questions and requests for access or deletion, please email us at lokot@phishar.com. It is necessary to clearly state on which basis and through which channel you shared your personal data with us so we could easily fulfil your request.

Please note that we may ask for additional information in order to determine if you are authorized to submit a particular request. If you have a complaint about our handling of your data, you can contact the supervisory authority to find out more information.

15. Children data

We do not knowingly collect information from persons who are considered children by their local law. We encourage parents and guardians to take an active role in their children’s online and mobile activities and interests.

By accepting our Terms of Service Agreement you warrant that you are of legal age, and have the authority to bind the User to the Agreement and the Privacy Policy.

If you have reason to believe that a child below the minimum age has provided personal data to Phishar through using any of the above-stated services without the necessary consent, please contact us at lokot@phishar.com and we will use commercially reasonable efforts to delete that data.

16. Changes to the Privacy Policy

We are likely to make changes to the services in the future and as a consequence will need to revise this Policy to reflect those changes. You can tell when changes have been made to the Privacy Policy by referring to the “Latest update” legend at the top of this page. When the Policy is revised, we will post the new Privacy Policy on the Lokot website (www.lokot.app), so you should review the page periodically. We encourage you to review the Privacy Policy whenever you access the services to stay informed about our privacy practices. Please do not use our Services if you do not agree with any of the stipulations contained herein.

17. Questions or concerns

Should you have any questions regarding this Privacy Policy, your privacy as it relates to the use of the services, or the protection of the personal data we hold about you, please contact us via e-mail at lokot@phishar.com.

You can reach our Data Protection Officer at the same email address for any questions or concerns relating to your data shared with PhishAR.