Frilok Privacy Policy

Version: 1.1 (draft for legal review) Effective Date: [date of publication] Data Fiduciary (India): High Way Fresh Applicable Law: As specified in Clause 18 and the applicable Schedule
Language. This Privacy Policy is drawn up in English. Any translation is provided for convenience only; in the event of any inconsistency between the English text and a translation, the English text shall prevail.

Preamble

This document is an electronic record in terms of the Information Technology Act, 2000 and the rules made thereunder, as amended from time to time, and does not require any physical or digital signature. It is published in accordance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"), and in accordance with the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules") as and when their provisions come into force.

This Privacy Policy forms part of, and shall be read together with, the Frilok Terms of Use and End-User Licence Agreement (the "Terms"). Capitalised terms used but not defined in this Privacy Policy have the meanings given to them in the Terms.


1. Scope and Responsible Entity

1.1 Scope. This Privacy Policy describes how the Operator collects, uses, stores, discloses, transfers and otherwise processes the Personal Data of Users in connection with the Platform. It does not apply to any third-party service, website or application, including any App Store or map tile provider, which is governed by the privacy policy of its own provider.

1.2 Data Fiduciary. In respect of each Designated Territory, the Operator determines the purposes and means of processing Personal Data and is the "Data Fiduciary" within the meaning of the DPDP Act (and the "controller" under the laws referred to in Schedules B and C). In respect of India, the Data Fiduciary is High Way Fresh, a sole proprietorship concern having its principal place of business at [full registered address], Sonapur, Assam, India ("HWF").

1.3 HWF as Data Processor. Where the Operator of a Designated Territory is a person other than HWF, HWF operates the Platform's infrastructure and processes Personal Data solely on behalf of, and on the documented instructions of, that Operator, as its Data Processor, under a written contract.

1.4 Consent. Where processing is based on consent, the Operator shall obtain it through a separate notice presented in the App that describes the Personal Data concerned and the purpose of processing. Consent may be withdrawn at any time with the same ease with which it was given. Withdrawal shall not affect the lawfulness of processing carried out before withdrawal, and may result in the discontinuation of the feature concerned.


2. Definitions

In this Privacy Policy:

"Data Principal" means the individual to whom Personal Data relates.

"Data Processor" means any person who processes Personal Data on behalf of a Data Fiduciary.

"Location Data" has the meaning given in the Terms.

"Personal Data" means any data about an individual who is identifiable by or in relation to such data.

"Personal Data Breach" means any unauthorised processing of Personal Data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data that compromises its confidentiality, integrity or availability.

"Processing" means any wholly or partly automated operation performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, restriction, erasure or destruction.

"Service Provider" means a third party engaged by the Operator to process Personal Data on its behalf.

"Sensitive Personal Data or Information" has the meaning given in Rule 3 of the SPDI Rules.


3. Personal Data Collected

3.1 The Operator collects the following categories of Personal Data:

Category Personal Data Source
Account and identity Username, display name, profile photograph, biographical description; authentication credentials, which are stored only in protected (non-reversible) form The User
Contact and verification Mobile number and e-mail address; for Business Users, identity and business documents, licence and tax registration particulars, and verification status The User
One-time passwords and verification codes Codes sent to verify an e-mail address or telephone number, or to confirm the handover of an order Generated by the Operator and sent to the User
Location Data As described in Clause 4 The User's device
Communications Messages and attachments; call metadata (participants, time, direction, duration) The User and other Users
Transactions Requests, Offers and Counter-offers, orders, prices agreed, delivery, collection and meeting points, routes selected and followed for Tracked Orders, steps marked by the parties, ratings, reviews and disputes The User and other Users
Order payments and dues For each order: amount, currency, mode of payment (cash, UPI or other), the User who recorded it, date and time, whether the Seller confirmed it, any note, and any amount outstanding The Customer and the Seller of that order
Store For Sellers: Store Page particulars, including name, photographs, opening hours, contact particulars, licence and tax registration numbers, terms of sale and Shop Rules The Seller
Preferences The shops that the User has chosen to follow; notification and privacy settings The User
Content Listings, catalogues, photographs and other Content The User
Device and technical Device model, operating system and version, App version, IP address, push-notification tokens, and records of App state necessary for message delivery The User's device
Support and grievances Correspondence with the Operator and the Grievance Officer The User

3.2 Authentication credentials constitute Sensitive Personal Data or Information under the SPDI Rules and are collected with the User's consent solely for authentication. The Operator does not collect financial information such as bank account or payment card details; payments between Users are made outside the Platform.

3.3 The Operator does not knowingly collect Personal Data of persons under eighteen (18) years of age (Clause 13).

3.4 No tracking. The App contains no third-party analytics, advertising or tracking software, and the Operator does not track Users across applications or websites of other persons. The Operator shall amend this Privacy Policy before introducing any such software, and shall seek consent where Applicable Law so requires.

3.5 Website. The websites at frilok.com provide information about the Platform, publish the Terms and this Privacy Policy, and enable a User to request the deletion of its Account. They use no advertising or analytics cookies. Personal Data furnished in a request for deletion (the mobile number or e-mail address registered with the Account) is used only to verify that the requester holds the Account and to give effect to the request. The Operator's hosting and network-protection provider receives the IP address and browser particulars of visitors in order to deliver and protect the websites.

3.6 Sharing to other applications. Where a User shares a Listing or store to another application through the device's share function, or follows a link or telephone number leading outside the Platform, the information concerned passes to that application or service, whose own terms and privacy policy apply. The Operator is not responsible for the processing of Personal Data by any such application or service.


4. Location Data

4.1 Purposes. The Operator processes Location Data only in the following circumstances:

Circumstance Period Recipients Basis
Display of the map and nearby places While the map is displayed None; processed on the device Use voluntarily initiated by the User (DPDP Act, s. 7(a))
Orders (Terms, Clause 6.3(a)): the point of delivery, collection, pick-up or meeting For the life of the order, then as set out in Clause 10.2 The parties to the order Use voluntarily initiated by the User for the specified purpose (DPDP Act, s. 7(a))
Tracked Orders, in which a party goes to, or accompanies, the other, such as a delivery, a collection, a visit or the carriage of a person or goods (Terms, Clause 6.3(b)–(c)): live positions, the route selected and the route followed From the time a party sets out to the completion or cancellation of the order; retained as set out in Clause 10.2 The other participants in that order; the Operator, for the performance of the order, safety, fraud prevention and dispute resolution Use voluntarily initiated by the User for the specified purpose (DPDP Act, s. 7(a))
Personal location sharing (Terms, Clause 6.4) While the User shares, for the duration selected Only Users with a mutual contact relationship who have accepted by sharing their own Location Data Consent (DPDP Act, s. 6)
Location Groups, being temporary groups whose members share their locations, whether or not any of them is moving (Terms, Clause 6.5) While the User is a member Members of the Location Group Consent (DPDP Act, s. 6)
Providers who receive Requests by their current position (Clause 4.4) While location sharing for work is enabled As set out in Clause 4.4 Use voluntarily initiated by the User (DPDP Act, s. 7(a))
Places, points, routes and areas that a User shares (Terms, Clause 6.8) Until the User or the recipient deletes them The Users with whom they are shared, and any person to whom those Users share them further Use voluntarily initiated by the User (DPDP Act, s. 7(a))

4.2 Mutual visibility. Location Data shared under Clause 4.1 is not published to a User's wider contacts, profile or the public, and may not be requested by other Users. The Operator's servers verify, upon every request for Location Data, that the requesting User is entitled to receive it. When either of two Users sharing with each other ceases to share, sharing ends for both.

4.3 Background processing. Location Data is processed while the App is in the background, closed or the device is locked only (a) during a Tracked Order, and (b) for personal location sharing, where the User has enabled background sharing. The device displays a persistent indication while such processing continues. Permission to access location "all the time" is requested only when the User enables background sharing, after an explanatory notice, and may be refused or withdrawn in the device settings at any time.

4.4 Providers who receive Requests by their current position. Where a Provider without a fixed store, such as a delivery person, a mobile vendor or a Provider who carries persons or goods, enables location sharing for work in order to receive Requests near it (Terms, Clause 6.2):

Matter Position
Personal Data processed Geographical position, accuracy, speed, direction of travel and time
Purposes Before an order is agreed, only to determine whether the Provider is within the distance each Customer selected for a Request; during a Tracked Order, to enable the participants to see one another until its completion or cancellation, and for safety, fraud prevention and dispute resolution
Recipients Before an order is agreed, the Operator's servers only; Customers are not shown the Provider's position. During a Tracked Order, the participants in that order and the Operator
Nature of storage The current position is held in server memory while sharing is enabled and is not retained as a location history
Effect of disabling sharing The Provider ceases to receive new Requests by its current position; the last known position is retained for not more than two (2) hours and then deleted; Requests may continue to be shown by reference to any store or base location recorded in its profile; if a Tracked Order is in progress, Clause 6.3 of the Terms applies
Retention As set out in Clause 10.2
Safeguards Transmission over encrypted connections; server-side verification of every request; notifications contain no coordinates of any User's position; access to Location Data is logged

4.5 Other Location Data.

(a) Routing requests are processed to compute a route. A route selected for a Tracked Order, and the route followed in performing it, are stored with the order as provided in Clause 4.1 and Clause 10.2. Other routing requests are not retained.

(b) Places saved by a User (for example "Home" or "Work") are stored on the Operator's servers and are visible only to that User, unless the User shares them. A place, point, route or area that a User shares with other Users is visible to them, may be shared further by them, and remains with them until they delete it; the Operator is not responsible for such further sharing.

(c) A Request published without display on the map is notified only to Providers within the distance selected by the Customer, and is not displayed on any map.

4.6 The Operator does not sell Location Data, does not disclose it to advertisers or other third parties for their own purposes, and does not use it to build profiles of Users. The App may show a User stores near the User's current position or along a route that the User is following, including promotions paid for by their Sellers, which are labelled "Sponsored" (Terms, Clause 3.7). Such stores are selected at that moment by place, route and category only; the Location Data used to select them is not stored for that purpose, is not disclosed to the Sellers concerned, and is not used to profile the User.


5. Communications, Calls and Content

5.1 Messages. Messages are transmitted over encrypted connections. The Operator retains a server-side archive of messages, in accordance with the User's message-history setting, to enable synchronisation across devices and restoration on a new device.

5.2 Calls. The content of voice and video calls is transmitted directly between devices or, where a direct connection is not possible, through relay servers, and is encrypted in transit by means of DTLS-SRTP. The Operator does not record calls and relay servers cannot access their content. A User's telephone number, device identifiers and mobile carrier are not disclosed to the other party to a call. Call logs are stored on the User's device. Relay servers retain limited technical records (session times and IP addresses) solely for rate limiting, the prevention of abuse and attacks, and compliance with Applicable Law.

5.3 Media. Photographs and attachments are uploaded to access-controlled storage. Device and location metadata embedded in photographs is removed on the device before upload.

5.4 Public information. A User's profile, Store Page (including its Shop Rules), Listings, reviews and photographs uploaded to public place records are visible to other Users.

5.5 Notifications. In order to inform a User of messages, calls, Offers and orders while the App is not open, the Operator sends notifications through Google Firebase Cloud Messaging (on Android devices) and the Apple Push Notification service (on Apple devices). A notification may contain the display name of the other User, a short description of the event and an amount, and may be displayed by the device on its lock screen. A notification may state that a User has started or stopped sharing its location, or has sent a place, and may include the name of a place or a meeting point chosen by the sender; notifications do not contain the coordinates of any User's position. A User may conceal the content of notifications on the lock screen, or disable notifications, in the settings of the device.

5.6 Order Records. Payments recorded in an Order Record, and any amount outstanding, are displayed only to the Customer and the Seller of the order concerned, and may be communicated to both of them as messages in the conversation relating to that order. The Operator processes them solely to maintain the Order Record and to handle any problem report concerning the order. The Operator does not use them to assess the creditworthiness of any User, and does not disclose them to any credit information company, lender or advertiser.


6. Device Permissions

6.1 The App requests access to the following device functions only when a feature requiring it is first used, and access may be withdrawn at any time in the device settings:

Permission Purpose
Location The purposes in Clause 4; access "all the time" only as provided in Clause 4.3
Microphone Voice and video calls
Camera Video calls and photographs taken by the User
Photographs and files Selection of items through the device's own picker; the App does not access the User's entire library
Notifications Alerts for messages, calls, orders and location-sharing requests
Background services Persistent notification during background location sharing; incoming-call display when the App is closed

6.2 The microphone and camera are used only while the User makes, answers or participates in a call or takes a photograph.


7. Purposes and Lawful Bases of Processing

7.1 The Operator processes Personal Data for the following purposes and on the following bases:

Purpose Basis under the DPDP Act Basis under the GDPR (Schedules B and C)
Registration and administration of the Account; authentication s. 7(a) Art. 6(1)(b)
Delivery of messages, calls and notifications s. 7(a) Art. 6(1)(b)
Location Data for orders, Tracked Orders and Providers who receive Requests by their current position s. 7(a) Art. 6(1)(b)
Personal location sharing, Location Groups, background sharing and location history s. 6 (consent) Art. 6(1)(a)
Display of Listings and Requests s. 7(a) Art. 6(1)(b)
Offers, orders and Order Records, including recorded payments and amounts outstanding s. 7(a) Art. 6(1)(b)
Promotional messages from stores that the User follows s. 6 (consent, given by following the store) Art. 6(1)(a)
Security, fraud prevention and enforcement of the Terms s. 7(a) Art. 6(1)(f)
Compliance with Applicable Law and orders of authorities s. 7(d) and (e) Art. 6(1)(c)
Response to a medical emergency or threat to life s. 7(f) Art. 6(1)(d)
Grievance redressal and dispute resolution s. 7(a), (d) and (e) Art. 6(1)(c) and (f)
Service messages concerning the Account s. 7(a) Art. 6(1)(b)
Promotional communications s. 6 (consent) Art. 6(1)(a)

7.2 The Operator may use data that has been anonymised so that it no longer identifies any individual, such as aggregated demand by area, to operate and improve the Platform.


8. Disclosure of Personal Data

8.1 The Operator does not sell, rent or trade Personal Data, does not disclose Personal Data for behavioural advertising, and does not disclose Personal Data to any credit information company or lender.

8.2 The Operator discloses Personal Data only to:

(a) other Users, to the extent necessary for a Transaction (including the pickup point, contact handle, display name, the Order Record and, during the Transaction, Location Data), for mutual location sharing, and as described in Clauses 5.4 and 8.3;

(b) HWF, where it is not the Operator, as Data Processor under Clause 1.3;

(c) Service Providers engaged under written contracts, being cloud hosting (Amazon Web Services), network protection and object storage (Cloudflare), and push-notification delivery (Google Firebase Cloud Messaging and Apple Push Notification service);

(d) map tile providers (OpenFreeMap and Esri), which receive the IP address of the device and the identity of the map tiles requested, but no account information or Location Data from the device's positioning system;

(e) courts, tribunals, government, law-enforcement and other competent authorities, as provided in Clause 14 of the Terms;

(f) professional advisers, auditors and insurers, under duties of confidentiality; and

(g) a successor to, or assignee of, the operation of the Platform (including a company formed by HWF or a licensed operator, as contemplated by Clause 24.2 of the Terms), which shall be bound by this Privacy Policy.

8.3 Personal Data received by Business Users. When a User places an order with, or accepts an Offer from, a Business User, that Business User receives the Personal Data needed to fulfil the order: the User's display name (unless the User has chosen to withhold it from a Request, until an order is made), the delivery or pick-up point, the telephone number if the User has furnished it, the order and its Order Record. The Business User may use such Personal Data only for the purposes permitted by Clause 9.11 of the Terms, and is responsible under Applicable Law for its use. A User who believes that a Business User has misused its Personal Data may report the matter to the Grievance Officer.

8.4 Following a store. A User who follows a store may receive promotional messages from that store through the Platform. The Seller does not thereby receive any further Personal Data of the User. The User may stop following the store at any time, whereupon such messages shall cease.


9. Transfer of Personal Data Outside India

9.1 Personal Data is stored principally on servers located in India. Certain Service Providers, including those providing push-notification delivery, network protection and object storage, may process Personal Data outside India.

9.2 Any transfer of Personal Data outside India shall be made in accordance with Applicable Law, including any restriction notified by the Central Government under Section 16 of the DPDP Act, and subject to contractual obligations requiring the recipient to protect the Personal Data.


10. Retention and Deletion

10.1 General principle. Personal Data is retained only for as long as necessary for the purpose for which it was collected or as required by Applicable Law, and is thereafter erased. Account data and active Listings are retained for so long as the Account remains active. One-time passwords are deleted within fifteen (15) minutes, and transient matching data within twenty-four (24) hours.

10.2 Location Data.

Personal Data Retention period On expiry
Position during personal location sharing or in a Location Group While sharing continues Deleted
Location history of personal sharing, only where the User has enabled "Save my location history" (disabled by default) Not more than thirty (30) days; visible only to the User Deleted; the User may erase it at any time
Record of a share (parties, start and end time, without coordinates) Ninety (90) days Deleted
Live positions, route selected and route followed for a Tracked Order Until completion or cancellation, and thirty (30) days thereafter Deleted, save where a dispute, safety incident or request of an authority concerning the Transaction is pending, in which case until its conclusion
Provider's current position While location sharing for work is enabled Continuously replaced; not retained as history
Provider's last known position after going offline Not more than two (2) hours Deleted
Transaction records, including Order Records and recorded payments (parties, amounts, dates; without route) The period prescribed by tax and accounting law Deleted
Anonymised aggregated data Indefinitely Not Personal Data

10.3 Deletion of Account. Upon a request under Clause 16 of the Terms:

(a) the User's profile, contacts, server-side messages, Location Data, settings and uploaded media shall be erased within thirty (30) days of the request;

(b) where a Transaction is in progress or a dispute is pending, erasure shall be completed upon its completion (subject to a maximum of thirty (30) days for a Transaction) or resolution, as provided in the Terms;

(c) transaction and payment records shall be retained for the period prescribed by tax and accounting law (in India, up to eight (8) years), and basic account information for one hundred and eighty (180) days after closure where required under the IT Rules, and shall be used only for those purposes;

(d) records preserved at the request of a competent authority shall be retained as provided in Clause 14.4 of the Terms; and

(e) public place records contributed by the User may remain on the Platform but shall be dissociated from the User.

10.4 A request for deletion may be made in the App (Me → Privacy & Safety → Delete account) or by e-mail to privacy@frilok.com from the e-mail address or telephone number registered with the Account.


11. Rights of Data Principals

11.1 Subject to Applicable Law, a User has the right to:

(a) obtain a summary of the Personal Data processed and the processing activities undertaken, and the identities of the persons with whom it has been shared;

(b) the correction, completion, updating and erasure of Personal Data;

(c) withdraw consent at any time;

(d) nominate another individual to exercise these rights in the event of the User's death or incapacity; and

(e) have grievances redressed in accordance with Clause 17.

11.2 Requests may be made through the App or by e-mail to privacy@frilok.com. The Operator may take reasonable steps to verify the identity of the person making a request, and shall respond within the period prescribed by Applicable Law, being not more than ninety (90) days under the DPDP Rules.

11.3 Additional rights applicable in other Designated Territories are set out in the relevant Schedule.


12. Privacy Controls

12.1 The App provides the following controls under Me → Privacy & Safety:

(a) a privacy check-up displaying, and permitting the User to change, the persons who may view the User's Location Data, pending invitations and requests, background sharing and location-history settings, profile visibility, message-history settings, blocked Users and device permissions;

(b) "Keep sharing in the background", disabled by default;

(c) "Save my location history", disabled by default; and

(d) "Erase Location Data", which deletes the Location Data associated with the User.


13. Children

13.1 The Platform is not directed to persons under eighteen (18) years of age, and the Operator does not knowingly process their Personal Data. Upon becoming aware that an Account belongs to such a person, the Operator shall delete it. Any person who believes that a child has registered an Account may notify privacy@frilok.com.


14. Security Safeguards

14.1 The Operator implements reasonable security practices and procedures, and technical and organisational measures appropriate to the nature of the Personal Data, as required by Section 43A of the Information Technology Act, 2000, the SPDI Rules and Section 8(5) of the DPDP Act, including:

(a) encryption of data in transit, and of call content by DTLS-SRTP;

(b) storage of authentication credentials only in protected, non-reversible form;

(c) restriction of internal services to private networks, and access controls limiting access to Personal Data to authorised personnel on a need-to-know basis;

(d) storage of authentication tokens on devices in the platform's hardware-backed secure storage; and

(e) logging of access to Location Data.

14.2 No method of transmission or storage is completely secure, and the Operator cannot guarantee absolute security.


15. Personal Data Breach

15.1 In the event of a Personal Data Breach, the Operator shall, as required by Applicable Law, intimate each affected User without delay, describing in clear and plain language the nature and extent of the breach, its likely consequences, the measures taken or proposed to mitigate the risk, the safety measures the User may take, and the contact details of a person able to respond to queries, and shall report the breach to the Data Protection Board of India and any other competent authority within the prescribed period.


16. Amendments

16.1 The Operator may amend this Privacy Policy from time to time. The amended Privacy Policy shall bear a revised version number and effective date. Material amendments shall be notified to Users before they take effect, through the App, by notification to the User's device, by e-mail or by SMS, and consent shall be sought afresh where Applicable Law so requires.


17. Grievance Officer and Contact

17.1 Questions, requests and complaints concerning the processing of Personal Data may be addressed to the Grievance Officer:

Grievance Officer: [Name], [Designation], High Way Fresh
Address: [full postal address], Sonapur, Assam, India
E-mail: grievance@frilok.com (privacy requests: privacy@frilok.com)

17.2 The Grievance Officer shall acknowledge and dispose of complaints within the periods specified in Schedule A to the Terms. A User who is not satisfied with the resolution of a grievance relating to Personal Data may, upon exhausting this procedure, file a complaint with the Data Protection Board of India, whose decisions are appealable to the Telecom Disputes Settlement and Appellate Tribunal.


18. Applicable Law and Territorial Scope

18.1 The Platform is offered only in the Designated Territories specified in Clause 22.2 of the Terms, currently India. The processing of the Personal Data of a User is governed by the data protection law specified in the Schedule applicable to the Designated Territory in which the User is ordinarily resident.

18.2 Schedules B, C and D shall apply only upon the Platform being offered in the territories to which they relate. Before the Platform is offered in any other country or territory, the Operator shall add or complete the Schedule for it. The Platform is not directed to persons outside the Designated Territories; nothing in this Clause shall exclude any protection conferred by mandatory law.


Schedule A — India

A.1 Legislation. The Information Technology Act, 2000 and the SPDI Rules (which continue to apply until the commencement of the corresponding provisions of the DPDP Act); and the DPDP Act and the DPDP Rules, notified on 13–14 November 2025 and coming into force in phases, the substantive obligations of Data Fiduciaries applying from May 2027. The Operator applies the standards of the DPDP Act and the DPDP Rules from the effective date of this Privacy Policy.

A.2 Data Fiduciary. High Way Fresh, [full registered address], Sonapur, Assam, India.

A.3 Grievance Officer. As specified in Clause 17.1.

A.4 Data Protection Board. Complaints may be filed with the Data Protection Board of India through its online platform after exhausting the grievance procedure in Clause 17.


Schedule B — European Union and European Economic Area

(Applicable only upon the Platform being offered in the EU/EEA.)

B.1 The Operator shall act as controller under Regulation (EU) 2016/679 (the "GDPR") and shall designate a representative under Article 27 before the Platform is offered in the EU/EEA.

B.2 A User has the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects (Art. 22).

B.3 Transfers of Personal Data outside the EEA shall be made on the basis of an adequacy decision or the Standard Contractual Clauses adopted by the European Commission, together with supplementary measures where required.

B.4 A User may lodge a complaint with the supervisory authority of the Member State of habitual residence, place of work or place of the alleged infringement.


Schedule C — United Kingdom

(Applicable only upon the Platform being offered in the United Kingdom.)

C.1 The Operator shall act as controller under the UK GDPR and the Data Protection Act 2018 and shall designate a representative in the United Kingdom before the Platform is offered there.

C.2 A User has the rights described in paragraph B.2, under the UK GDPR.

C.3 Transfers of Personal Data outside the United Kingdom shall be made on the basis of adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the Standard Contractual Clauses.

C.4 A User may lodge a complaint with the Information Commissioner's Office.


Schedule D — United States

(Applicable only upon the Platform being offered in the United States.)

D.1 The Operator does not sell Personal Data or share it for cross-context behavioural advertising.

D.2 Precise geolocation is processed only to provide the features requested by the User (Clause 4) and is not used to infer characteristics about the User.

D.3 Residents of California and other States with comprehensive privacy legislation may exercise the rights to know, delete and correct Personal Data and to limit the use of sensitive personal information by e-mail to privacy@frilok.com, directly or through an authorised agent. The Operator shall not discriminate against any User for exercising such rights.


Privacy requests: privacy@frilok.com.