Effective Date: May 25, 2018
Your privacy is important to EMOTIV, Inc., and its affiliates, Emotiv Research Pty Ltd (Australia), Emotiv Limited (UK), Emotiv Vietnam (Vietnam), and Emotiv Technology Vietnam (Vietnam) (collectively, EMOTIV). EMOTIV is committed to being a good steward of your information, handling it in a responsible manner, and securing it with administrative, technical, and physical safeguards by design.
EMOTIV follows three guiding principles when it comes to your privacy:
- Transparency. We work hard to be transparent about what information we collect and process.
- Simplicity. We try to use easy-to-understand language to describe our privacy practices to help you make informed choices.
- Control. We give you control over the information you provide to us, and how it is used, shared, and retained.
References to "we," "us," "our," and other similar references mean EMOTIV, and "you" and "your" and other similar references mean any user of the Services.
Please contact us if you have any questions or comments about our privacy practices. You can reach us online at firstname.lastname@example.org, by telephone at +1 415 801 0400, or by mail at EMOTIV, Inc., 490 Post St., San Francisco, CA 94102 USA.
Types of Information We Collect
EMOTIV collects Personal Information about you (i) when you provide it directly to us, (ii) when third parties such as our business partners and service providers provide us with Personal Information about you, or (iii) when Personal Information about you is automatically collected in connection with your use of the Service. We collect the following Personal Information from you in connection with the Service:
- Contact Information: information we collect to identify or contact you, we collect typical "business card information" such as your first and last name, physical address, email address, or telephone number. For example, this is the basic information that we collect when you register for the Service.
- Financial Account Information: information that you provide in connection with your purchase of the Services (or a purchase made through the Service), including credit card number, credit card expiration date, credit card verification code, bank account number, bank account title, bank name, branch location, and routing number. You must only provide us with Financial Account Information for accounts and credit cards that you have the lawful right to access.
- EEG Data: electrical biosignals collected using EMOTIV devices and any related monitoring equipment, motion sensor outputs, associated data such as event timing markers, mouse, touchscreen, gestural, and keyboard events, eye movements, survey responses, choices, and preferences, tactile, audio, visual, and other sensory stimuli, reaction times, self-assessment, and cognitive performance. It also includes information that may be inferred from the foregoing sources, either alone or in any combination.
- User Account Information: information that identifies you to the Service, such as your user name, email address, password, and IP address. For example, we use this information to authenticate you when you log in to the Service, and use the IP address to help maintain your web session security while using the Service.
- User Content: to the extent that you choose to input Personal Information as part of such content, images, comments, and other content, information, and materials that you post to or through the Service.
- Partner Information: information that our business partners, such as our content-providing partners, share with us. For example, if you use their services to purchase, preview, and/or otherwise use their content when using the Service.
- Log Data: information automatically recorded by the Services about how you use the Services, such as IP addresses, cookies, device and browser type, web beacons, operating system, the pages or features of the Services to which a user browsed, the time spent on those pages or features, the frequency with which the Services is used by a user, search terms used by a user, the links on the Services that a user clicked on or used, and other statistics.
We sometimes collect usage and performance information that is not Personal Information. We also sometimes associate data that is not Personal Information, such as our intellectual property, with Personal Information.
How We Collect Personal Information
We collect Personal Information when a user (i) creates an account with EMOTIV (a "User Account"); (ii) logs into the Service; (iii) interacts with the Services (such as by submitting EEG Data); (iv) uploads or generates User Content, such as by third-party social media platforms; (v) communicates with us; and (vi) responds to a communication or interaction from us.
How We Use Personal Information
We use Personal Information to: (i) provide, administer, and improve the Services; (ii) better understand your needs and interests; (iii) fulfill requests you make; (iv) personalize your experience, such as to provide you with information regarding your overall cognitive performance relative to other users of similar age or other characteristics; (v) provide announcements; (vi) provide you with information and offers from EMOTIV; (vii) protect, investigate, and deter against fraudulent, harmful, unauthorized, or illegal activity; and (viii) comply with legal obligations.
Pseudonymization of EEG Data
We use unique identifiers, such as your user ID, to process your EEG Data so that it cannot be attributed to you without the use of your unique identifier. By design, we keep the unique identifier separate from your EEG Data and subject to technical and organizational measures to ensure that your EEG Data is not and cannot be attributed to you.
Lawful Basis for Processing
We will only process your Personal Information if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity, and our "legitimate interests" or the legitimate interest of others, as further described below.
- Contractual Necessity: We process Personal Information because we need to process the data to perform our contract(s) with you, which enables us to provide you with the Service. When we process data due to contractual necessity, failure to provide such Personal Information will result in your inability to use some or all portions of the Services that require such data.
- Legitimate Interest: We process some categories of Personal Information when we believe doing so furthers the legitimate interest of us or third parties. Examples of these legitimate interests include: (i) operating and improving our business, products, and services; (ii) marketing of our products and services; (iii) providing customer support; (iv) protecting from fraud or security threats; (v) complying with legal obligations; and (vi) completing corporate transactions.
- Consent: In some cases, we process Personal Information based on the consent you expressly grant to us.
- Other Processing Grounds: From time to time, we may also need to process Personal Information to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
How and With Whom We Share Information
We share Personal Information with vendors, third-party service providers, and agents who work on our behalf and provide us with services related to the Service. These parties include: (i) third parties who act for us or provide services for us, such as billing and credit card payment processing, maintenance, sales, marketing, administration, support, data enrichment, hosting, and database management services; and (ii) outside professional advisors (such as lawyers and accountants) for purposes related to the operation of our business such as auditing, compliance, and corporate governance.
We share individualized and aggregated EEG Data with third parties for scientific, medical, and historical research purposes.
We will not share your Personal Information to third parties without ensuring appropriate safeguards and effective and enforceable rights and remedies are in place, as required by law.
We believe the security of your information is important and we are committed to protecting the information we receive from you. The Personal Information we collect about you is stored in limited access servers located in the United States and other countries where EMOTIV has facilities. We use commercially reasonable security measures to protect against the loss, misuse, and alteration of your information under our control based on the type of Personal Information and applicable processing activity, such as pseudonymization, data encryption in transit, and data encryption at rest.
To the extent the Services require you to provide any Financial Account Information, such as when you purchase subscriptions to the Service, that information will be collected and processed by third-party PCI-compliant service providers.
No security measures are 100% effective, however, and we cannot guarantee the security of your Personal Information. We will notify you of any data breach where your Personal Information has been obtained by unauthorized third parties, as required by law.
We retain Personal Information about you for as long as you have an open account with us or as otherwise necessary to provide you with the Service, and thereafter as set forth in any applicable agreement with you, or as set forth below. In some cases, we retain Personal Information for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule, or regulation. We retain your EEG Data for scientific, medical, or historical research purposes.
Your Privacy Choices
You have certain rights with respect to your Personal Information, and we want to help you review and update your information to ensure it is accurate and up-to-date.
We may limit or reject your request in certain cases, such as if the Personal Information is used for scientific, medical, or historical research purposes, if it is frivolous or extremely impractical, if it jeopardizes our rights or the rights of others, if it is not required by law, or if the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question. In some cases, we may also need you to provide us with additional information, which may include Personal Information, to verify your identity and the nature of your request. We will take reasonable steps to respond to all requests within 30 days.
Subject to certain limitations as set forth above or otherwise provided by law, you may email us at email@example.com for any of the following:
- Access: You can request more information about the Personal Information we hold about you and request a copy of such Personal Information.
- Rectification: If you believe that any Personal Information we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data.
- Erasure: With the exception of your EEG Data, you can request that we erase some or all of your Personal Information from our systems. We retain your EEG Data for scientific, medical, or historical research purposes. Please note that if you request the deletion of information required to provide the Services to you, your User Account will be de-activated and you will lose access to the Service.
- Portability: You can ask for a copy of your Personal Information in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
- Withdrawal of Consent: If we are processing your Personal Information based on your consent, you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Information, if such use or disclosure is necessary to enable you to utilize some or all of the Service. Any use of your data that has already been performed prior to our receipt of your request will not be reversed, undone, or withdrawn. If you withdraw your consent, your EEG Data may still be used by us and shared with our third-party service providers to provide and improve our Services and shared as aggregate information that does not identify you as an individual.
- Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Information for certain purposes, such as for marketing purposes.
- Restriction of Processing: You can ask us to restrict further processing of your Personal Information.
We will give you the ability to opt-out of marketing-related emails by contacting us at firstname.lastname@example.org, or clicking on a link at the bottom of each such email. You cannot opt-out of receiving certain non-marketing emails regarding the Service.
If you want to disable cookies, check with your browser provider to learn how.
You also have the right to lodge a complaint about EMOTIV's practices with respect to your Personal Information with the supervisory authority of your country or EU Member State.
Social Media Features
In general, Personal Information, once shared or disclosed, can be difficult to contain or retrieve. EMOTIV will have no responsibility or liability for any consequences that may result because you have released or shared Personal Information with others.
Closing Your Account
You may close an account, and upon termination of your User Account, we will take reasonable steps to provide, modify, or delete your Personal Information as soon as is practicable. However, EMOTIV may nevertheless retain your Personal Information to protect the business interests of EMOTIV, and some information may remain in archived/backup copies for our records or as otherwise required by law. Those interests include without limitation the completion of transactions, maintaining records for financial reporting purposes, complying with our legal obligations, resolving disputes, and enforcing agreements. We will retain your EEG Data for scientific, medical, or historical research purposes.
California Privacy Rights
Pursuant to Section 1798.83 of the California Civil Code, residents of California can obtain certain information about the types of Personal Information that companies with whom they have an established business relationship have shared with third parties for direct marketing purposes during the proceeding calendar year. In particular, the law provides that companies must inform consumers about the categories of Personal Information that have been shared with third parties, the names and addresses of those third parties, and examples of the types of services or products marketed by those third parties. To request a copy of the information disclosure provided by EMOTIV pursuant to Section 1798.83 of the California Civil Code, please contact as set forth above.
EMOTIV does not collect personal information about your online activities over time and across third party websites or online services, and therefore it does not respond to your browser's Do Not Track signals. No third parties conduct online tracking on the Websites.
The Services are not intended for children under the age of 16, and therefore, EMOTIV does not knowingly acquire or receive Personal Information from children under the age of 16. If we later learn that any user of the Services is under the age of 16, we will take appropriate steps to remove that user's information from our account database and will restrict that individual from future access to the Service. Please contact email@example.com if you are a parent or guardian of a child under 16 whom you believe has provided us with any Personal Information.
If you have any questions or concerns regarding privacy related to the Service, please contact us by mail, telephone, or email using the contact information set forth below, and we will try to resolve your concerns.
Telephone: +1 415 801 0400
Address: EMOTIV, Inc., Attn: Matthew Bosworth, Data Protection Officer, 490 Post St., San Francisco, CA 94102 USA