Privacy Policy

ELEHEAR Spark E1 – UK GDPR Compliance

Last Updated: July 2026
This privacy notice for ELEHEAR Intelligence Co., Ltd. (doing business as ELEHEAR) ("ELEHEAR," "we," "us," or "our") applies to all users accessing our mobile application and services globally, currently serving United Kingdom ("UK") users only.

Critical Territory & Product Classification Update

This revised notice complies with standalone UK GDPR + Data Protection Act 2018, California CCPA, and the Swiss Federal Data Protection Act. EU GDPR compliance clauses are reserved for a future EEA service launch only.

If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact our Data Protection Officer at [email protected].

Summary of Key Points (Updated UK GDPR Compliance)

This summary provides key updated compliance amendments aligned with confirmed internal UK business facts:

1. What Information Do We Collect?

Personal information you disclose to us

In Short: We collect personal information that you voluntarily provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Special Category Health Data

We process user-submitted hearing test results and audiogram data uploaded/generated within the App. This is classified as health-related special category personal data under UK GDPR.

Processing Rule: Such health data is collected only via standalone opt-in consent, collected exclusively for consumer sound amplifier algorithm adaptation and personal audio tuning, and is prohibited for marketing, user profiling for commercial promotion, or third-party data sharing.

Application Permission & Device Data

For UK users: Bluetooth, microphone and local storage access adopt independent separate pop-up consent, with no bundled consent and no default-enabled permission.

Notice: Our App has no local raw audio collection and no local audio cache logic at present.

Information automatically collected

Automatically collected metadata: IP address, device model, OS version, language setting, service interaction timestamp, feature usage log. All auto-collected data follows the UK GDPR data minimization principle.

2. How Do We Process Your Information & UK GDPR Lawful Bases?

Mandatory Legal Bases for UK Users

Processing Purposes: Account management, device connection & audio tuning, service troubleshooting, product optimization, risk prevention, and regulatory compliance, with no commercial marketing profiling usage.

3. When and With Whom Do We Share Your Personal Information?

Exclusive Third-Party Processor: Microsoft Azure Cloud (UK)

We appoint Microsoft Azure as the only cloud service provider; no other third-party data processor is involved in UK user data processing.

UK User Data Rule: Stored on Microsoft Azure UK local servers, with no outbound cross-border transfer out of UK territory. A UK SCC cross-border transfer agreement is not required for UK resident data.

Microsoft complies with the ISO 27018 cloud privacy standard and UK GDPR obligations, and provides a data government request defense mechanism. Full privacy details: https://www.microsoft.com/en-us/trust-center/privacy

Other Sharing Scenarios

We will never sell UK user personal data, health test data or device usage data for commercial marketing purposes.

4. How Long Do We Keep Your Information?

Aligned with our internally confirmed retention standard, in compliance with the ICO retention principle:

5. How Do We Keep Your Information Safe?

Technical & organizational security measures updated for UK GDPR compliance:

We implement reasonable technical safeguards; however, no internet data transmission can be 100% secure, and we cannot absolutely guarantee no unauthorized access, breach or modification.

6. What Are Your Privacy Rights (UK GDPR Statutory Rights)?

Full Statutory Data Subject Rights for UK Users

UK users own the below UK GDPR statutory rights:

Supervisory Authority Complaint Channel

UK Users: Lodge a complaint directly with the ICO (UK Information Commissioner's Office).

GDPR Request Response Timeline: We reply to all valid user privacy requests within 1 calendar month, extending by a maximum of 2 additional months for complex requests per UK GDPR rules.

7. Controls for Do-Not-Track Features

Unchanged: We do not respond to DNT browser signals currently, and will update this notice if a unified industry standard is issued in the future.

8. Do We Make Updates to This Notice?

Updated Rule: Material changes affecting UK users' UK GDPR rights will be notified via in-app notice at least 30 days prior to the effective date.

9. How Can You Contact Us About This Notice?

Core Privacy Contact

Company Postal Address

ELEHEAR Intelligence Co., Ltd.
7/F, Block 12B, Shenzhen Bay Tech-Eco Park, Nanshan Dist., Shenzhen, Guangdong, China, 518054

10. How Can You Review, Update, or Delete the Data We Collect From You?

Users may submit a data access, correction, deletion or consent withdrawal request via the DPO email [email protected], or modify account data inside the App account settings page.

If you are unsure about any clause, contact us before further use.