Effective Date: June 9, 2023
Who we are
If you have any questions or comments about our privacy practices, please contact us here. firstname.lastname@example.org
Why does EMOTIV care about privacy?
EMOTIV follows three guiding principles when it comes to your privacy:
(i) Transparency. We work to communicate to you what information we collect, when we collect, and how we will process or analyze your information.
(ii) Simplicity. We try to use easy-to-understand language to help you make informed choices.
(iii) Control. We give you control over the information you provide to us, and how it is used, shared, and retained.
Some helpful definitions
To help you understand the terms we use in this document, here are some definitions we use:
(iii) Services. This is the collective term for the product and services we provide to you including our hardware, our software, our cloud storage and applications, and our websites.
(iv) Data. This is information we collect from you that may include Personal Information, and other types of non-identifiable information such as EEG Data.
(v) Personal Information includes any information you provide that does or could identify you as an individual person.
(vi) Demographic Data is not considered to be Personal Information. Demographic Data which is relevant to brain science includes general information such as your age, gender, country of residence and birth, handedness, education, number of languages spoken, musical ability and other non-identifying characteristics.
(i) What kinds of information we collect;
(ii) When we collect information about you;
(iii) How we use Personal Information we collect about you;
(iv) The lawful basis for processing your Personal Information;
(v) What steps we take to protect your Personal Information;
(vi) How and with whom we share information;
(vii) Data retention;
(viii) Third-party services;
(ix) How you can correct information we collect about you;
(x) Social media features;
(xi) Closing your account;
(xii) California privacy rights;
(xiv) Prevention of Children using the Services; and
What kinds of information we collect
EMOTIV collects Personal Information about you (i) when you provide it directly to us, (ii) when third parties such as our business partners and service providers provide us with Personal Information about you, or (iii) when Personal Information about you is automatically collected in connection with your use of the Services.
(i) We collect personal information we directly ask you for:
- Contact Information. This is information we collect to identify or contact you, such as your first and last name, physical address, email address, or telephone number. For example, this is the basic information that we collect when you register for the Services.
- Financial Account Information. This is information that you provide to purchase Services, including credit card number, credit card expiration date, credit card verification code, bank account number, bank account title, bank name, branch location, and routing number. You must only provide us with financial account information for accounts and credit cards that you have the lawful right to access.
(ii) We collect Personal Information that third parties give to us:
- Partner Information. This is information that our business partners, such as our content-providing partners, share with us. For example, if you use their services to purchase, preview, and/or otherwise use their content when using the Services.
(iii) We collect Personal Information from you automatically when you use our Services:
- User Account Information. This is information that identifies you to the Services, such as your user name, email address, password, and IP address. For example, we use this information to authenticate you when you log in to the Services, and use the IP address to help maintain your web session security while using the Services.
- User Content. You may choose to input Personal Information as part of content, images, comments, information, and materials that you post to or through the Services.
- Log Data. This is information recorded about how you use the Services, such as IP addresses, cookies, device and browser type, geographic location, web beacons, operating system, the pages, features, products or services you browsed, the time spent viewing those pages, features, products or services, the products or services you added to your cart or purchased, the frequency with which you used the Services, search terms you used, the links on the Services that your clicked on or used, and other statistics. If you enable your browser’s Do Not Track feature, EMOTIV will not be able to collect certain Log Data regarding your online activities.
EMOTIV also collects information from you that is not Personal Information such as:
- Experiment Data. This is information collected from you during your voluntary participation in research and other experiments, studies or programs or your use of the Services, such as your EEG Data, Demographic Data, performance data, responses to experiment questions, and any data collected from related monitoring equipment, associated data such as event timing markers, mouse, touchscreen, gestural, and keyboard events, eye movements, survey responses, choices and preferences, tactile, audio, visual, and other sensory stimuli, reaction times, self-assessment, and cognitive performance. Experiment Data, on its own, is not Personal Information because it does not and cannot identify you.
When do we collect information about you?
We collect Personal Information when you:
(i) create an account with EMOTIV (a “User Account”);
(ii) log into the Services;
(iii) interact with the Services (such as by submitting EEG Data);
(iv) upload or generate User Content, such as by third-party social media platforms;
(v) communicate with us or respond to a communication or interaction from us; and
(vi) decide to participate in research and other experiments, studies or programs (collectively, “Experiments”).
How do we use Personal Information we collect about you?
We use Personal Information to:
(i) provide, administer, and improve the Services;
(ii) better understand your needs and interests;
(iii) fulfill requests you make;
(iv) personalize your experience, such as to provide you with information regarding your overall cognitive performance relative to other users of similar age or other characteristics;
(v) conduct Experiments you have decided to participate in;
(vi) provide you with announcements, information and offers from EMOTIV;
(vii) protect, investigate, and deter against fraudulent, harmful, unauthorized, or illegal activity; and
(viii) comply with legal obligations.
Lawful basis for processing your Personal Information
We will only process your Personal Information if we have a lawful basis for doing so. Lawful bases for processing includes consent, contractual necessity, legitimate interests, or other legitimate processing grounds, as further described below.
(i) Consent. In some cases, we process Personal Information based on the consent you give to us.
(ii) Contractual Necessity. We process Personal Information because we need to process the information to perform our contracts with you, which allows us to provide you with the Services. When we process Personal Information due to contractual necessity, failure to provide such Personal Information will result in your inability to use some or all portions of the Services that require such Personal Information.
(iii) Legitimate Interest. We process some categories of Personal Information when we believe doing so furthers the legitimate interest of us or third parties. Examples of these legitimate interests include:
- operating and improving our business, products, and services;
- marketing of our products and services;
- providing customer support;
- protecting from fraud or security threats;
- complying with legal obligations; and
- completing corporate transactions.
(iv) Other Processing Grounds. From time to time, we may also need to process Personal Information to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
What steps do we take to protect your Personal Information?
Information like your name or birthdate are considered Personal Information. EEG Data is information we collect from your brain and, on its own, does not and cannot identify you. We recognize that access to BOTH your Personal Information and your EEG Data or Experiment Data should only be available to you, the owner of the data, and to a limited number of EMOTIV staff for the exclusive purpose of maintaining security and providing the Services.
We take the following steps to protect your Personal Information:
(i) Password Protected User Account. In order to use our Services and to access your EEG Data and Experiment Data, you must create and log in to a password-protected User Account. Your User Account contains your User Name (“EmotivID”), email address, license information and other relevant Personal Information relating to your personal use of the Services. Apart from financial transactions, correspondence and delivery records, none of your Personal Information is stored in any other location.
(ii) Security. Personal Information we collect about you is stored only in your User Account, managed through limited access servers located in the United States and other countries where EMOTIV has facilities. We use commercially reasonable security measures to protect against the loss, misuse, and alteration of your information under our control based on the type of Personal Information and applicable processing activity, such as pseudonymization, aggregation, data encryption in transit, and data encryption at rest.
(iii) Pseudonymization. When you create a User Account, we also create an anonymous, unique identification number (“OwnerID”) which is associated with your EEG Data and Experiment Data. Your User Account is the only place where both your Personal Information (associated with your EmotivID) and your EEG Data and Experiment Data (associated with your OwnerID) are linked, so that you can log into your account and access your own personal data. Unless you are logged in to your User Account, it is not possible to discover or deduce your personal identity from information stored or accessed when reading your EEG Data and Experiment Data.
(iv) Your Responsibility. By accepting the EMOTIV End User License Agreement, you agree not to add any Personal Information to your EEG Data or Experiment Data.
(v) Data Sharing: EMOTIV Applications. EMOTIV collects EEG Data when any application based on the EMOTIV platform is used by anyone who is logged in to an EMOTIV User Account. By accepting the EMOTIV End User License Agreement, you accept that your non-identifiable EEG Data collected during the use of any EMOTIV-enabled application will be available to EMOTIV for the purpose of providing the Services and for scientific and historical research purposes and to improve the Services. Unless your Personal Information is explicitly required when using your EEG Data in order to provide you with the Services, pseudonymized data will be used and your Personal Information will not be accessed. Some EMOTIV applications allow you to opt out of data sharing. If you opt out of data sharing, the Services we offer will be restricted.
(vi) Data Sharing: Third Party Applications. Some third party applications which utilize the Services may wish to collect EEG Data. Where such data is to be shared with the third party, the application must ask for your explicit consent to allow access to that non-identifiable EEG Data specifically related to the use of the application. With your explicit consent the third party will be provided with a de-identified copy of the EEG Data collected only during your use of the application. You can withdraw permission at any time by deleting the application or by contacting EMOTIV.
(vii) Data Sharing: Experiment Data - EMOTIV Online Games. Games are provided exclusively by EMOTIV on our online platform. By accepting the EMOTIV End User License Agreement, you accept that your Experiment Data collected when playing Games will be available to EMOTIV for the purpose of providing the Services and for scientific and historical research purposes and to improve the Services.
(viii) Data Sharing: Experiment Data - EMOTIV and Third Party Experiments. EMOTIV offers services which allow EMOTIV and third parties to design and deploy browser-based Experiments for remote and local participants. Participation is voluntary, and in many cases EMOTIV or the third party researcher may offer payment for your participation. You must be logged in to a valid User Account to participate in Experiments. Your Personal Information may be used by EMOTIV for valid reasons such as to effect payments for participation, but otherwise will not be used by EMOTIV, and will not be provided to the third party. You will be informed of the purpose of the Experiment and the intended use of your data, and you must explicitly consent to sharing your data each time you participate in an Experiment. With your explicit consent, the third party will be provided with a de-identified copy of the EEG Data collected only during the course of the Experiment.
(ix) Access to your Personal Information. Your password-protected User Account contains all of the Personal Information that we store on your behalf, other than commercial and logistic information related to purchase transactions, correspondence and deliveries. Many of the available fields can be accessed and edited through the application used to log into your account or through EMOTIV applications which may also record your usage history. You can contact EMOTIV at email@example.com for a full list of the Personal Information that we hold on your behalf, and ask us to edit or delete any or all of it.
(x) Withdrawal of Consent and Deletion of Personal Information. You may contact us at firstname.lastname@example.org if you wish to withdraw permission for data sharing or to delete your Personal Information in its entirety by deleting your User Account. Your User Account contains all of the Personal Information that we store on your behalf, other than commercial transactions, correspondence and deliveries. Your User Account contains the only link between your identity (your Personal Information, linked to your EmotivID) and your OwnerID, an anonymous number associated with your EEG Data and Experiment Data. If you choose to delete your User Account, all of your Personal Information will be removed and the link between your identity and the pseudonymized EEG Data and Experiment Data collected from you will be destroyed, and we will no longer be able to provide Services based on associating that data with you. Deletion of your User Account is final and we will not be able to restore access to your previous EEG Data and Experiment Data.
(xi) Aggregation. We may aggregate your EEG Data and Experiment Data with the EEG Data and Experiment Data of others. Since aggregated EEG Data and aggregated Experiment Data does not and cannot identify you, it is not Personal Information.
(xii) PCI-Compliant Service Providers. If the Services require you to provide any Financial Account Information, such as when you purchase subscriptions to the Services, that information will be collected and processed by third-party PCI-compliant service providers. EMOTIV will not retain or store any sensitive financial information such as credit card numbers other than at arm’s length through those service providers.
Although EMOTIV uses administrative, technical, and physical safeguards to protect your Personal Information, no security measures are 100% effective and we cannot guarantee the security of your Personal Information. We will notify you of any data breach where your Personal Information has been obtained by unauthorized third parties, as required by law.
How and with whom we share information
We share Personal Information with vendors, third-party service providers, and agents who work on our behalf to help us provide the Services. These include: (i) third parties who act for us or provide services for us, such as billing and credit card payment processing, maintenance, sales, marketing, administration, support, data enrichment, hosting, and database management services; and (ii) outside professional advisors (such as lawyers and accountants) for purposes related to the operation of our business such as auditing, compliance, and corporate governance.
We may share pseudonymized EEG Data and pseudonymized Experiment Data with third parties, with your explicit, case by case consent, in connection with your voluntary participation in an Experiment. We may also share aggregated EEG Data and aggregated Experiment Data with third parties for scientific and historical research purposes and to improve the Services. As mentioned earlier, pseudonymized or aggregated EEG Data and pseudonymized or aggregated Experiment Data is not Personal Information because it does not and cannot identify you.
We will not share your Personal Information with third parties without ensuring appropriate safeguards and effective and enforceable rights and remedies are in place, as required by law.
We retain Personal Information about you for as long as you have an open account with us or as otherwise necessary to provide you with the Services, and thereafter as set forth in any applicable agreement with you, or as set forth below. In some cases, we retain Personal Information for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule, or regulation. We may retain your pseudonymized and/or aggregated EEG Data and Experiment Data, which is not Personal Information, for scientific or historical research purposes and to improve the Services.
How can you control the information we collect about you?
You have certain rights with respect to your Personal Information, and we want to help you review and update your information to ensure it is accurate and up to date.
Subject to certain limitations as set forth below or otherwise provided by law, you may email us at email@example.com for any of the following:
(i) Access. You can request more information about the Personal Information we hold about you and request a copy of such Personal Information.
(ii) Correction. If you believe that any Personal Information we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data.
(iii) Removal. You can request that we remove some or all of your Personal Information from our systems. Please note that if you request the removal of information required to provide the Service to you, your User Account will be de-activated and you will lose access to the Services.
(iv) Portability. You can ask for a copy of your Personal Information in a machine-readable format. You can also request that we transmit the Personal Information to another controller where technically feasible.
(v) Withdrawal of Consent. If we are processing your Personal Information based on your consent, you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may thereafter have to provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Information, if such use or disclosure is necessary to enable you to utilize some or all of the Services. Any use of your Personal Information that has already been performed prior to our receipt of your request will not be reversed, undone, or withdrawn. If you withdraw your consent, your pseudonymized and/or aggregated EEG Data and Experiment Data, which is not Personal Information, may still be used by us and shared with our third-party service providers to provide and improve the Services and for scientific or historical research purposes.
(vi) Objection. You can contact us to let us know that you object to the further use or disclosure of your Personal Information for certain purposes, such as for marketing purposes.
(vii) Restriction of Processing. You can ask us to restrict further processing of your Personal Information.
We will give you the ability to opt-out of marketing-related emails by contacting us at firstname.lastname@example.org, or clicking on a link at the bottom of each such email. You cannot opt-out of receiving certain non-marketing emails regarding the Services.
If you want to disable cookies, check with your browser provider to learn how.
Once EMOTIV provides pseudonymized Experiment Data to a third-party conducting an Experiment in which you have volunteered to participate , EMOTIV will be unable to delete such data from the third party’s possession.
We may limit or reject your request in certain cases, such as if it is frivolous or extremely impractical, if it jeopardizes our rights or the rights of others, if it is not required by law, or if the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question. In some cases, we may also need you to provide us with additional information, which may include Personal Information, to verify your identity and the nature of your request. We will take reasonable steps to respond to all requests within 30 days.
You also have the right to lodge a complaint about EMOTIV’s practices with respect to your Personal Information with the supervisory authority of your country or EU Member State.
Social media features
In general, Personal Information, once shared or disclosed, can be difficult to contain or retrieve. EMOTIV will have no responsibility or liability for any consequences that may result because you have released or shared Personal Information with others.
Closing your account
You may close an account, and upon termination of your user account, we will take reasonable steps to provide, modify, or delete your Personal Information as soon as is practicable. However, EMOTIV may nevertheless retain your Personal Information to protect the business interests of EMOTIV, and some information may remain in archived/backup copies for our records or as otherwise required by law. Those interests include without limitation the completion of transactions, maintaining records for financial reporting purposes, complying with our legal obligations, resolving disputes, and enforcing agreements. We will retain pseudonymized or aggregated EEG Data and pseudonymized or aggregated Experiment Data, which is not Personal Information, for scientific or historical research purposes and to improve the Services.
California privacy rights
Under Section 1798.83 of the California Civil Code, residents of California can obtain certain information about the types of Personal Information that companies with whom they have an established business relationship have shared with third parties for direct marketing purposes during the preceding calendar year. The law requires companies to inform consumers about the categories of Personal Information that have been shared with third parties, the names and addresses of those third parties, and examples of the types of services or products marketed by those third parties. To request a copy of the information disclosure provided by EMOTIV pursuant to Section 1798.83 of the California Civil Code, please contact us as set forth above.
The Services are not intended for children under the age of 16, and therefore, EMOTIV does not knowingly acquire or receive Personal Information from children under the age of 16. If we later learn that any user of the Services is under the age of 16, we will take appropriate steps to remove that user’s information from our account database and will restrict that individual from future access to the Services. Please contact email@example.com if you are a parent or guardian of a child under 16 whom you believe has provided us with any Personal Information.
If you have any questions or concerns regarding privacy related to the Services, please contact us by mail, telephone, or email using the contact information set forth below, and we will try to resolve your concerns.
Telephone +1:(415) 801-0400
Address: EMOTIV, Inc., Attn: Data Protection Officer, 490 Post Street, Suite 824, San Francisco, CA 94102, USA