Critical Territory & Product Classification Update
- UK Market Product Definition: Our device is marketed, sold and certified as a consumer sound amplification device only in the United Kingdom, NOT classified as a medical hearing aid. Audio and test data are processed for sound tuning purposes only, not for medical diagnosis, treatment or clinical hearing intervention.
- Data Storage Isolation Rule: UK resident user personal data is independently stored, managed and operated on dedicated Microsoft Azure United Kingdom local servers, fully segregated from global user data, with no cross-border outflow out of UK territory.
- Third-party Data Source Confirmation: We do NOT receive any personal data from distributors, dealers or external third-party platforms.
This revised notice complies with standalone UK GDPR + Data Protection Act 2018, California CCPA, and the Swiss Federal Data Protection Act. EU GDPR compliance clauses are reserved for a future EEA service launch only.
If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact our Data Protection Officer at [email protected].
Summary of Key Points (Updated UK GDPR Compliance)
This summary provides key updated compliance amendments aligned with confirmed internal UK business facts:
- Special Category Data Clarified: We process user hearing test results as health special category personal data under UK GDPR Article 9, collected only upon standalone user consent, solely for device sound amplification tuning, with no marketing usage.
- Dedicated Data Protection Officer: DPO Contact: [email protected]
- Data Retention Fixed Rule: Account usage data is retained during the valid account period; system operation logs are retained for 6 months; users may delete their account and associated data at any time.
- UK Permission Compliance Confirmed: For UK users, microphone, Bluetooth and storage permissions adopt standalone separate pop-up consent; no pre-ticked consent, no one-click bulk permission approval.
- User Portrait Marketing Ban: All audio tuning data and user preference profiling data will never be used for commercial advertising, third-party marketing or cross-scenario recommendation.
- Cloud Vendor Confirmation: Microsoft Azure (UK node) is the only appointed third-party data processor for UK services; no other subcontractor data processors are involved.
- EU Representative Status: Not required currently, as we have no EEA user business or data processing activities for now.
- Local Audio Cache Rule: Currently our App does not collect, cache or store user raw audio files on user local mobile devices.
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect personal information that you voluntarily provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
- Personal Information Provided by You: email addresses.
Special Category Health Data
We process user-submitted hearing test results and audiogram data uploaded/generated within the App. This is classified as health-related special category personal data under UK GDPR.
Processing Rule: Such health data is collected only via standalone opt-in consent, collected exclusively for consumer sound amplifier algorithm adaptation and personal audio tuning, and is prohibited for marketing, user profiling for commercial promotion, or third-party data sharing.
Application Permission & Device Data
For UK users: Bluetooth, microphone and local storage access adopt independent separate pop-up consent, with no bundled consent and no default-enabled permission.
Notice: Our App has no local raw audio collection and no local audio cache logic at present.
Information automatically collected
Automatically collected metadata: IP address, device model, OS version, language setting, service interaction timestamp, feature usage log. All auto-collected data follows the UK GDPR data minimization principle.
2. How Do We Process Your Information & UK GDPR Lawful Bases?
Mandatory Legal Bases for UK Users
- Performance of Contract: Execute the user service agreement, provide account service, sound amplifier function delivery, and device connection service.
- Explicit Standalone Consent: For microphone access, hearing health test data collection, and personalized audio tuning; users may withdraw consent at any time without service penalty.
- Legitimate Interest: Limited, balanced business interest for product iteration, anti-fraud, and service security, which will not override users' fundamental privacy rights.
- Legal Compliance: Comply with UK Data Protection Act 2018 and UK GDPR regulatory obligations.
Processing Purposes: Account management, device connection & audio tuning, service troubleshooting, product optimization, risk prevention, and regulatory compliance, with no commercial marketing profiling usage.
3. When and With Whom Do We Share Your Personal Information?
Exclusive Third-Party Processor: Microsoft Azure Cloud (UK)
We appoint Microsoft Azure as the only cloud service provider; no other third-party data processor is involved in UK user data processing.
UK User Data Rule: Stored on Microsoft Azure UK local servers, with no outbound cross-border transfer out of UK territory. A UK SCC cross-border transfer agreement is not required for UK resident data.
Microsoft complies with the ISO 27018 cloud privacy standard and UK GDPR obligations, and provides a data government request defense mechanism. Full privacy details: https://www.microsoft.com/en-us/trust-center/privacy
Other Sharing Scenarios
- Legal mandatory disclosure: Respond to a valid official legal authority request raised by the UK ICO or UK judicial departments.
- Business transfer: Data transferred as a business asset in a merger, acquisition or bankruptcy arrangement.
- Consent-based sharing: Additional third-party sharing is only permitted with the user's explicit consent.
We will never sell UK user personal data, health test data or device usage data for commercial marketing purposes.
4. How Long Do We Keep Your Information?
Aligned with our internally confirmed retention standard, in compliance with the ICO retention principle:
- Account & Usage Personal Data: Retained during the validity period of the user account; users may delete their account at any time, and all bound usage data will be erased upon account deletion.
- System Log & Operation Diagnostic Data: Automatically purged 6 months after generation, on a fixed retention cycle, with no prolonged storage.
- Hearing test / audiogram health data: Reserved synchronously with the user account; deleted together when the user cancels the account or deletes the test record actively.
- Backup Data: Isolated backup data will be purged within 30 calendar days after a user account deletion request is confirmed.
5. How Do We Keep Your Information Safe?
Technical & organizational security measures updated for UK GDPR compliance:
- End-to-end protection: TLS transmission encryption and AES-256 at-rest encryption adopted by the Microsoft Azure UK cloud server.
- UK user data logical isolation: The UK user dataset is independently partitioned on the UK Azure node, fully separated from the overseas user database.
- Staff access control: Internal role-based data access permission, with regular UK GDPR privacy training for internal staff.
We implement reasonable technical safeguards; however, no internet data transmission can be 100% secure, and we cannot absolutely guarantee no unauthorized access, breach or modification.
6. What Are Your Privacy Rights (UK GDPR Statutory Rights)?
Full Statutory Data Subject Rights for UK Users
UK users own the below UK GDPR statutory rights:
- Right to access: Obtain a copy of stored personal data and health test data.
- Right to rectification: Modify inaccurate account or test data.
- Right to erasure ("right to be forgotten"): Delete account, health record and usage data freely.
- Right to restriction of processing: Suspend data processing upon valid application.
- Right to data portability: Export personal hearing test data in a readable format.
- Right to object: Object to legitimate-interest-based processing.
- Right to withdraw consent: Revoke microphone/health data collection consent at any time, with no adverse service impact.
Supervisory Authority Complaint Channel
UK Users: Lodge a complaint directly with the ICO (UK Information Commissioner's Office).
GDPR Request Response Timeline: We reply to all valid user privacy requests within 1 calendar month, extending by a maximum of 2 additional months for complex requests per UK GDPR rules.
7. Controls for Do-Not-Track Features
Unchanged: We do not respond to DNT browser signals currently, and will update this notice if a unified industry standard is issued in the future.
8. Do We Make Updates to This Notice?
Updated Rule: Material changes affecting UK users' UK GDPR rights will be notified via in-app notice at least 30 days prior to the effective date.
9. How Can You Contact Us About This Notice?
Core Privacy Contact
- Data Protection Officer Email: [email protected]
Company Postal Address
ELEHEAR Intelligence Co., Ltd.
7/F, Block 12B, Shenzhen Bay Tech-Eco Park, Nanshan Dist., Shenzhen, Guangdong, China, 518054
10. How Can You Review, Update, or Delete the Data We Collect From You?
Users may submit a data access, correction, deletion or consent withdrawal request via the DPO email [email protected], or modify account data inside the App account settings page.