Privacy Policy

Hiface OÜ (“Hiface”, “we”, “us” or “our”) is a company registered in the Estonia with company number EE102567166 and a registered address at Harju maakond , Kesklinna linnaosa, Viru väljak  2, 3. korrus Tallinn 10111 Estonia. We develop and publish applications for mobile devices.We are a data controller and are responsible for the collection, use, disclosure, retention and protection of your “personal data” (which has the meaning as set out in the General Data Protection Regulation (the “Data Protection Laws”)).

When you use Hiface’s “PureFace – Face Yoga Exercise” or other apps or our corporate websites available at and at (each being, our “Platform”, collectively, the “Platforms”), we may collect, store and process some data, including personal data. This privacy policy (“Privacy Policy”) sets out the main principles on which the data collected from you, or that you provide to us, will be processed by us.

This Privacy Policy also aims to remind you about your rights and to provide you with all the elements you need to exercise them. For data protection laws in Estonia, we are the controller of your personal data.If you have any questions related to this Privacy Policy or our practices around privacy and data protection in general, please don’t hesitate to contact us.

BY USING THE PLATFORMS, YOU PROMISE US THAT YOU HAVE READ, UNDERSTAND AND AGREE TO THIS PRIVACY POLICY. If you do not agree, or are unable to make this promise, you must not use the Platforms. In such case, you must (a) delete your account using the functionality found in “Settings” in the App, or contact us and request deletion of your data; (b) cancel any subscriptions using the functionality provided by Apple (if you are using iOS) or Google (if you are using Android); and (c) delete the App from your devices.


When you visit our Platform, you may provide us with the following types of data, and we may collect and process such data in accordance with his Privacy Policy, as follows:

Contact Data

This may include your name and your email address. This information will be collected by us if you communicate with us, for example if you use the links on our Platforms to communicate with us via email.

Account Data

If you create an account on our Platforms (including the creation of a Gismart ID) to benefit from our Platforms, you may need to provide your name, email address, phone number and your photograph. If you use Facebook or Google to login to our Platforms, Facebook [or Google] will share data with us including but not limited to your profile data, language, location and publicly available information about you and your friends.

Physical Data

This may include your gender identity, weight, age, date, place and time of birth, zodiac sign, photos (palm, face, etc.), sleep time.

Social Data

This includes relationship status, duration of relationship (if any).

Correspondence Data

This includes the information you provide when you request support through our Platform, contact us via the email address provided in this Privacy Policy and elsewhere on our website and your views, opinions and feedback which you choose to provide in relation to the Platform and our services, including any comment facilities and message boards.

Session Data

This includes your IP address, your device’s unique identifier details, browser details including version, device operating system, geo-location, time zone setting and time/date of access requests, the amount of data transmitted and the requesting provider. We may also capture other information about visits to our Platform such as pages viewed and traffic patterns.

Cookie Data

Cookies are small files which are downloaded to your device when accessing our platform. Most web browsers automatically accept cookies. Please refer to paragraph 4 below for further details about our use of cookies.

Preference Data

This includes any information you choose to provide us.

Payment Data

Our Platforms include purchases directly in the application (including subscriptions) and/or purchases directly through our website. If you want to make a purchase in the application, you may do this with the help of payment system provided by Google Play (managed by Google) or AppStore (managed by Apple) and integrated into the apps. The in-app payment system is managed by the Google Play/AppStore administration or its authorized partner. Under no circumstances do we collect or process any information related to your payment instruments, such as bank card number, its validity term or your name as written on it. When you purchase directly through our website, including subscription, you authorize us to have our payment processor collect this information. We do not store such information on our servers.


In order to make possible for you to use certain functions of “PureFace – Face Yoga Exercise” app, we will process data obtained from your device (iOS devices with a front-facing TrueDepth camera) through the use of the Apple Software (through TrueDepth API technologies (ARKit Framework) that will provide us information about such human faces’ position, orientation and their topology. Information related to human faces obtained through the use of the Apple Software (ARKit) are the “Face Data”. The Face Data shall be considered the personal data.Notwithstanding anything to the contrary in other Sections of this Privacy Policy in relation to the personal data, we do not:

  • collect, store, share or transfer the Face Data off the User devices;
  • use the Face Data to identify any particular individual user;
  • use the Face Data for authentication, advertising, or marketing purposes, or to otherwise target a user in a similar manner;
  • use the Face Data to build a user profile, or otherwise attempt, facilitate, or encourage third parties to identify anonymous users or reconstruct user profiles based on the Face Data;
  • transfer, share, sell, or otherwise provide the Face Data to advertising platforms, analytics providers, data brokers, information resellers or other such parties.

You hereby express your informed written consent on processing of your Face Data as described in this Section 2 of the Privacy Policy.


When you use our Platforms, we can collect and process some of your data for different legitimate purposes. You will find below explanations regarding the reasons why we may collect data and the legal bases we rely on in each case.


  1. By using our Platform, you consent for us to store your personal data in line with legal, regulatory, financial and good-practice requirements.
  2. The period for which we may retain your personal data will depend on the type of personal data collected, the purposes for which it was collected, applicable limitation periods for the exercise of legal rights and whether any legal or regulatory obligations require the retention of the personal data.


We use cookies and other software development kits (“SDKs”) and third-party libraries. Our Platform uses the following categories of cookies:

Strictly necessary cookies

These are cookies that are required for the operation of our Platform. They include, for example, cookies that enable you to load webpages.

Analytical/performance cookies

These cookies allow us to recognize and count the number of visitors to our Platform and to see how visitors move around our Platform. This helps us to improve the way our Platform works, for example, by ensuring that visitors are finding what they are looking for easily.

Functionality cookies

These are used to recognize you when you return to our Platform. This enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

Tracking ID

Every iOS and Google Android device has a unique Tracking ID, for iOS devices, called an Identifier for Advertising (IDFA) and for Android devices, called a Google Advertising ID (AAID). These Tracking IDs enable app providers and advertisers to track user activity and target ads at those users.

  1. Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control.
  2. You may block cookies by updating the relevant settings on your device or browser to allow you to refuse the setting of some or all types of cookies. However, if you use your browser settings to block all cookies (including strictly necessary cookies) you may not be able to access all or parts of our site.

Hiface does not share your personal data except as consented by you or as described herein.


  1. We will store your data in Europe where possible. We will do our best to keep this information secure. No information security system is perfect so please remember to be careful.
  2. Where will your data be stored? The information we hold will primarily be stored and processed in the EU, but there may be circumstances where we need to work with trusted third parties outside of the EU in order to provide the Services to you (e.g. where we run servers in the US). By submitting your personal data, you explicitly agree to such transfer, storing or processing of data outside the EU. We will take all steps reasonably necessary to ensure that this information is treated securely and in accordance with this Privacy Policy.
  3. All information we hold is stored on our secure servers (which we own or license from appropriate third parties). We use industry standard procedures and security standards to prevent unauthorised access to our servers, however no online service or website can be completely secure, so please protect the data in your possession as well.


Our Platform may contain links to third party websites. If you follow a link to a third-party website, please note that this Privacy Policy does not apply to those websites. We are not responsible or liable for the privacy policies or practices of those websites, so please check their policies before you submit any data to those websites.

  • We take data security seriously. We implement and maintain appropriate technical and organizational measures including resilient security systems and protocols to protect the personal data we store.
  • We have put procedures in place to deal with any suspected data security breach and will notify you and applicable regulator of a suspected breach where the breach may cause a risk to you.
  • Our security procedures mean that we may occasionally request proof of identity before we are able to disclose personal data to you.


As a result of us collecting and processing your personal data, you have the following legal rights:

  • To access personal data we hold on you;
  • To request us to make any changes to your personal data if it is inaccurate or incomplete;
  • To request your personal data is erased where we do not have a compelling reason to continue to process such personal data in certain circumstances;
  • To receive your personal data provided to us as a data controller in a structured, commonly used and machine-readable format where our processing of the personal data is based on:
  1. your consent;
  2. our necessity for performance of a contract to which you are a party to; or
  • steps taken at your request prior to entering into a contract with us and the processing is carried out by automated means;
  • To object to, or restrict, our processing of your personal data in certain circumstances;
  • If we use your personal data for direct marketing, you can ask us to stop and we will comply with your request;
  • If we use your personal data on the basis of having a legitimate interest, you can object to our use of it for those purposes, giving an explanation of your particular situation, and we will consider your objection;
  • To object to, and not be subject to a decision which is based solely on, automated processing (including profiling), which produces legal effects or could significantly affect you;
  • If we are processing your personal data with your consent, you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal data conducted pursuant to lawful processing grounds other than consent. You may do so by contacting us;
  • To lodge a complaint with a data protection supervisory body, which at present, is the Commissioner for Personal Data Protection.

To exercise your rights, please contact our data protection officer at or write to us at the address set forth in the “Contact” section.


Our Platform is not intended for children (under the age of 13 or such higher age as required by applicable law). We do not knowingly collect or solicit any personal data or target interest based advertising to children and we do not knowingly allow children to register for or use the Platform. Children should not use our Platform or send us any personal data about themselves at any time. In the event that we learn that we have inadvertently gathered personal data from children, we will take reasonable measures to promptly erase such information from our records. If you believe that we might have information from or about a child, please contact us


Hiface’s Data Protection Officer
You may contact Hiface’s Data Protection Officer at or the address below for further information.
Hiface OÜ
Harju maakond , Kesklinna linnaosa,

Viru väljak  2, 3. korrus Tallinn 10111



  1. Any changes we may make to this Privacy Policy in the future will be posted on this page and, where appropriate, notified to you via an electronic communications within our Apps. Please check back regularly to keep informed of updates or changes to this Privacy Policy.
  2. This Privacy Policy was last updated in March 5st, 2023.