Sleep Assist Privacy Policy
Version Date: July 20, 2026
This Sleep Assist Privacy Policy (hereinafter referred to as the "Privacy Policy") applies to users (hereinafter referred to as "you") who register and log in to the products and APP services (hereinafter referred to as "our products and services") of Keeson Technology Corporation Limited (hereinafter referred to as "we," "us," or "our").
We are committed to protecting and respecting your privacy. This Privacy Policy details how we collect, use, share, and process the personal information of users and other individuals in connection with activities related to our various services. For information on how we collect, use, share, and process consumer health data pursuant to the Washington State "My Health, My Data" Act and other similar state laws, please refer to the "Consumer Health Data Privacy Policy."
This Privacy Policy applies to users of our products and services worldwide, including users in the United States and users in the European Economic Area ("EEA") and the United Kingdom ("UK"). If you are located in the EEA or the UK, the supplemental provisions in Section 9 of this Privacy Policy also apply to you. If you are located in the United States, the supplemental provisions in Section 10 of this Privacy Policy also apply to you.
You should carefully read and fully understand this Privacy Policy before using our products and/or services. If you do not agree with the content of this Privacy Policy, our products and/or services may not function properly, or may not achieve the service results we intend to achieve, and you should immediately cease accessing/using our products and/or services. Your use or continued use of the products and/or services we provide constitutes your full understanding of and agreement to the entire content of this Privacy Policy (including any updated versions).
As the provider of Keeson Technology Corporation Limited's products and the publisher of the APP, we highly value your opinions and suggestions regarding our services. Our contact information is as follows:
Company Name: Keeson Technology Corporation Limited
Address: No. 1508 Xiushui Avenue, Wangjiangjing Town, Xiuzhou District, Jiaxing City, Zhejiang Province, China
Entity Code: 91330411780498339G
Email: heqy@keeson.com
Phone: 573-82283307
For personal data protection matters, please contact our Data Protection Officer. Contact information is as follows:
Name: Qunyue He
Email: heqy@keeson.com
Phone: 15372308976
Address: No. 1508 Xiushui Avenue, Wangjiangjing Town, Xiuzhou District, Jiaxing City, Zhejiang Province, China
For EU personal data protection matters, please contact our EU Representative. Contact details are as follows:
Company Name: Ergomotion Unipessoal, Lda
Address: Rua Projectada à Matinha, Prédio B, 5º A, 1950-327 Lisbon, Portugal
Entity Code: PT516906453
Email: nfigueiredo@ergomotion.com
Tel: +351 917 270 446
The Sleep Assist Privacy Policy will help you understand the following information:
1. Scope of Application of this Privacy Policy
2. How We Collect and Use Your Personal Information
3. How We Share, Transfer, and Disclose Your Personal Information
4. Your Rights Regarding Personal Information
5. How We Store and Protect Your Personal Information
6. Protection of Minors
7. Updates to this Privacy Policy
8. Miscellaneous
9. Supplemental Provisions for Users in the EEA and the UK
10. Supplemental Provisions for Users in the United States
1. Scope of Application of this Privacy Policy
This Privacy Policy is a general document uniformly applicable to all of our products and/or services. When you use any of our products and/or services, this Privacy Policy applies, regardless of whether such product and/or service has a separate privacy policy, and regardless of whether you are a browsing user (visitor) or a registered and logged-in user. However, please note that this Privacy Policy does not apply to the following situations:
Our products and/or services may contain or link to information and/or third-party services provided by third parties (including any third-party applications, websites, products, services, etc.). Such information and/or services are operated by third parties, and your use of such information and/or services is unrelated to us. This Privacy Policy applies to the personal information we collect from you and does not apply to the collection of your personal information by any third party, nor to the services provided by any third party or the information use rules of any third party. We shall not bear any responsibility, to the extent permitted by law, for the collection, storage, and use of your personal information by any third party.
2. How We Collect and Process Your Personal Data
When you use our products and/or services, we may need to collect and use your personal information. There are two types:
Type 1: Information necessary for the basic functions of our products and/or services. Such information is essential for the normal operation of our products and/or services. You must authorize us to collect and use it. If you refuse to provide it, you will not be able to use our products and/or services normally.
Type 2: Information necessary for the additional functions of our products and/or services. Such information is not essential for the normal operation of our products and/or services. You may choose to separately consent or not consent to our collection and use of such information.
The specific functional scenarios we provide include:
2.1 Account Creation Service
To create an account for identifying and storing your personal information, to send you relevant reports generated from your use of our products and/or services, and to contact you or send necessary notifications, we need to collect and use your email address, password, or your authorized third-party account information. If you refuse to provide this information, we will be unable to identify you as a user and provide the corresponding products and/or services, nor will we be able to send notifications to you. In order to provide the home page service and better distinguish your personal information from that of other users, we need to collect your name (nickname). You may enter any name , which does not necessarily need to be your real name. If you refuse to provide this, it will not affect your ability to use our products and/or services.
In addition, in order to provide higher quality services, we need to process operational record information related to your APP usage (including but not limited to authorization records, product connection and usage records, log records generated from using services, application settings, and system update records). If you refuse to provide this, you will not be able to use our products and/or services.
2.2 Sleep Daily/Weekly/Monthly/Annual Report Service
To provide you with sleep daily/weekly/monthly/annual report services, we need to collect and use your sleep onset time, wake-up time, total sleep duration, deep sleep duration, light sleep duration, awake time, REM (rapid eye movement) sleep duration, sleep efficiency, average respiratory rate, average heart rate, average heart rate variability (HRV), restorative sleep duration, number of body movements, number of snoring events, snoring duration, and snoring intervention trigger records, and generate reports for your sleep time periods. Among these, snoring duration, number of snoring events, and snoring intervention trigger records will only be processed by us when you enable the snoring intervention function. If you disable the snoring intervention function, we will not process such information. You can enable or disable data uploading through the data toggle in the APP under "Settings - Bed Settings - Sleep Data Tracking." If you disable the data toggle or delete data, we will no longer generate sleep reports, and we will no longer process your above-mentioned information. You may still use the snoring intervention function, but we will not be able to calibrate the execution of snoring intervention and will not be able to perform troubleshooting. Among these, snoring intervention information will only be processed by us when you enable the "Snoring Intervention Sensitivity" function. If you disable the "Snoring Intervention Sensitivity" function, we will not process such information. You can find this toggle in the APP under "Settings - Bed Settings - Snoring Intervention Sensitivity." You can delete sleep reports in the APP under "Settings - Account & Security - Date & Sharing Settings - Delete Sleep Date."
To make your sleep report data more accurate, we need to collect and use your gender, date of birth, height, weight, and mattress thickness. You can edit this information in the APP under "Settings - Account & Security - Personal Information." If you wish us to stop processing the aforementioned information, you may contact us to delete the data through our manual customer service or by using the methods described in this Privacy Policy. If you refuse to provide the aforementioned information, it will not affect your ability to use our products and/or services.
2.3 Sleep Goals
To provide you with sleep management services, we will collect your sleep goal duration, sleep schedule rhythm, and primary sleep improvement goal. You can edit your data under "Settings - Sleep Goal" in the APP and deselect selected tags by tapping them. After you deselect, we will no longer process the aforementioned information. If you refuse to provide the aforementioned information, it will not affect your ability to use our products and/or services.
2.4 Sleep Schedule Service (Including Alarm Service)
To provide you with sleep management services, we need to process your alarm setting information, alarm execution time, and alarm cycle time information. If you have set a sleep goal, we will remind you to adjust your alarm settings based on your sleep goal. You can create, edit, and delete alarms in the APP under "Home - Quick Actions - Sleep Schedule." If you delete your alarms, you will not be able to use the sleep schedule function.
2.5 AI Sleep Assistant
(1) To provide you with the "Sleep Assistant" intelligent Q&A service, as well as accurate function guidance and troubleshooting suggestions, we need to collect and use the text you input during your interactions with the Sleep Assistant, and your basic device information (such as bed type, unit system, and time format preference). We will analyze and compute the content you input to better understand your questions and contextual background, thereby providing you with more relevant information. If you refuse to provide text information, you will not be able to interact with the Sleep Assistant, but this will not affect your normal use of other functions. If you refuse to provide basic device information, you will not be able to use the AI Sleep Assistant service, but this will not affect your normal use of other APP services.
(2) To provide you with personalized sleep health analysis and more accurate sleep recommendations, and to display AI insight content on the APP home page and sleep report pages, we need to collect and use your aggregated sleep data (such as sleep score, sleep duration, average HRV, etc.) and the sleep tags you have selected (such as your sleep concerns, lifestyle habits, or personal preferences).
You may refuse to provide aggregated sleep data to the AI Sleep Assistant by disabling the data toggle or deleting sleep reports. If you refuse to provide the aforementioned information, the AI Sleep Assistant will not provide health analysis and sleep recommendations, nor will AI insight content appear, but this will not affect your normal use of other functions.
You can deselect selected tags in the APP under "Settings - Sleep Tags." After deselecting, we will no longer process such data. If you do not select sleep tags, this may affect the accuracy of sleep health analysis and sleep recommendations, but it will not affect your ability to use the service.
2.6 Sharing Personal Health Information with Third-Party Health Platforms
To provide you with comprehensive health management services, this App provides the "Health Integration" feature, which is entirely initiated and authorized by you. Through this feature, you can actively synchronize your health data to the third-party health data platforms you designate (Apple Health, Samsung Health, Health Connect).
Authorization Method: In the App under "Settings - Health Integration," select a third-party health platform (Apple Health Integration, Samsung Health Integration, Health Connect Integration). After entering the corresponding page, tap the "Enable Apple Health," "Enable Samsung Health," or "Enable Health Connect" toggle, and then follow the system dialog prompts to grant this App permission to write data types such as heart rate and sleep data (deep sleep duration, light sleep duration, awake time, REM sleep duration) to the third-party health platform. You may disable specific data synchronization or cancel the overall authorization at any time in the "Health Integration" settings. If you refuse to provide the aforementioned information to any platform, you will not be able to view the information collected by this App on the third-party platform, but this will not affect your normal use of other functions of our products and/or services. Due to the diversity of third-party platforms and differences in update frequency, there may be delays and not real-time synchronization. If you find any errors in data display, please contact us promptly.
We access, collect, use, and share data obtained through Apple Health (HealthKit), Health Connect, and Samsung Health only to provide the health data integration features described above at your request, and only after you have granted the corresponding platform permissions. We do not use data obtained from these platforms for any non-essential commercial purposes, such as advertising push, resale to unrelated third parties, or cross-context behavioral analysis, and we do not share such data with any third party except as described in this Privacy Policy. Data obtained through these platforms is retained and deleted in accordance with Section 5 of this Privacy Policy, and you may request its deletion at any time as described in Section 4.
2.7 Sharing Your Sleep Reports with Others
You may enter the recipient's email address on the APP's "Date & Sharing Settings - Sharing Settings - Share with Others" page to actively share your sleep reports (including sleep duration, deep sleep/light sleep duration, sleep onset/wake-up time, etc., as displayed within the App) with designated individuals. After confirming and sending, the recipient will receive an email invitation and must create or log in to a Sleep Assist account before they can view the data you have shared. You may remove shared contacts at any time on the "Share with Others" page, after which the recipient will no longer be able to access your data.
2.8 Manual Customer Service
To better assist you in resolving issues you encounter, we cooperate with our affiliate company, Ergomotion, Inc. (hereinafter referred to as "Ergo"), to provide you with manual customer service. When you use the manual customer service, we need to collect and use your device (mobile phone) and system information (including device identifier, application platform, operating system type, system version, App name, App version, device type, device model), network identity information (IP address), smart bed ID, bed model name, and all information you actively fill in or provide (your communication with us, communication/call records and related content (including but not limited to other information you provide to prove relevant facts, or your name, contact information, address, etc. that you leave)). Please be aware that we will share the above information with Ergo, and Ergo will process your above information based on our entrustment. If you use the manual customer service, it means you consent to our collection and use of your information in the manner described above. If you do not consent to our collection and use, you will not be able to use the manual customer service, but this will not affect your use of our products and other services. You may contact us to revoke your authorization through the methods described in this Privacy Policy.
2.9 Services Based on System Permissions
In providing you with the following products and/or services, we will enable system permissions to collect and use your personal information. If you do not agree to enable the relevant permissions, you will not be able to normally use our products and/or services.
You can check the status of the above permissions item by item in your device's "Settings" and decide at any time to enable or disable them.
Please note that enabling any permission means you authorize us to collect and use relevant personal information to provide you with the corresponding service. Once you disable any permission, it means you have revoked the authorization, and we will no longer continue to collect and use the relevant personal information based on that permission, nor will we be able to provide you with the service corresponding to that permission. However, your decision to disable a permission will not affect the information collection and use previously conducted based on your authorization.
Our application permission requests and usage are described as follows:
1. Bluetooth Permission: To bind your account with our smart bed product, you need to enable Bluetooth. If you do not enable this permission, you will not be able to use our products and services.
2. Camera Permission: If you choose to bind our smart bed product by scanning a QR code, you need to enable the camera permission. If you do not enable this permission, you may choose to bind our smart bed product through Bluetooth search; this permission is not mandatory.
3. Network Permission: To use any of our products and/or services, you need to use the network for data communication. If you do not enable this permission, you will not be able to use our products and services.
4. Location Permission: To ensure the normal functioning of Bluetooth so that our smart bed product can connect, you need to enable the location permission. If you do not enable this permission, you will not be able to use our products and services.
5. Storage Permission (Android only): To upgrade your Bluetooth box, you need to enable the storage permission. If you do not enable this permission, you will not be able to upgrade the Bluetooth box. However, if you do not need or choose not to upgrade the Bluetooth box, you do not need to enable this permission. If we recommend that you perform an upgrade and you do not do so, this may affect your use of our products and/or services.
2.10 Other Services
Basic Assurance Services:
To ensure that we can provide you with services suited to your needs, we need to collect and use your device information, including the operating system type and other basic information that identifies your device. This is necessary for us to provide our products and/or services. If you refuse to authorize us to collect and use it, you will not be able to use our products and/or services.
We would like to specially remind you that: Due to the different nature of our products and services, the content provided to you also differs. Therefore, the basic and additional functions of specific products and/or services (including the types and scope of your personal information they collect) will also vary depending on the content of the product/service, with specific details subject to the actual provision of the product/service. In addition, you understand and agree that we hope to provide you with complete products and services, so we will continuously improve our products and services, including technology. This means we may frequently introduce new business functions that may require collecting new personal information or changing the purpose or method of using personal information. If a function or product/service that requires collecting your personal information is not described in this Privacy Policy, we will separately explain to you the purpose, content, method of use, and scope of such information collection through updates to this Privacy Policy, page prompts, pop-up windows, etc., and provide you with a method to independently choose to consent, and collect only after obtaining your explicit consent. In this process, if you have any questions about the relevant matters, you may contact us through the methods described in this Privacy Policy, and we will respond to you as soon as possible.
We also do not permit any third party to collect, edit, sell, or freely disseminate your personal information by any means. If any user of our products engages in the above activities, once discovered, we have the right to immediately terminate cooperation with that user.
IMPORTANT NOTICE: Our smart bed product is not a medical device. The services we provide are not medical services. Our data is not medical data. Our services cannot replace the medical services of hospitals and doctors. Our data shall not be used as medical reference data and shall not be used to diagnose, treat, or prevent any disease or symptom. The reminders and suggestions we push to you are for reference only. You have the right to decide whether to take any action and shall bear all consequences arising from taking such action.
3. How We Transfer, Transmit, and Disclose Your Personal Data
We undertake that unless we obtain your prior consent or as required by laws and regulations, we will not provide, sell, rent, share, trade, or otherwise transfer or provide any personal data to any third party. Any third party is prohibited from accessing all of your personal data. We will also prevent any third party from collecting, editing, selling, or freely disseminating your personal data in any manner.
3.1 Cross-Border Data Processing
We may sometimes transfer your personal data across borders to the regions described below to provide or improve our products or services. If you do not wish us to continue sharing the data provided below, please contact us.
If you are located in the EEA or the UK, additional storage and cross-border transfer disclosures and the applicable transfer safeguards are described in Section 9 of this Privacy Policy.
A. Keeson Technology Corporation Limited
(1) Country: China
(2) Personal Information Transferred: The team within China will access your device diagnostic information (device ID, device model, firmware version, motor connection status, sensor readings, error codes, operation logs) and aggregated sleep data (statistical indicators such as sleep duration, heart rate, respiratory rate, number of snoring events, etc.).
(3) Purpose of Transfer: To provide remote device diagnostics, troubleshooting, and sleep algorithm model optimization services.
(4) Retention Period by Recipient: The team within China only accesses remotely and does not store data.
(5) If you refuse to transfer your personal information to Keeson Technology Corporation Limited, we will be unable to provide you with after-sales services including fault diagnosis and equipment maintenance.
B. Samsung Electronics Co., Ltd.
(1) Country: South Korea
(2) Personal Information Transferred: Sleep data (deep sleep duration, light sleep duration, awake time, REM sleep duration), heart rate.
(3) Purpose of Transfer: To provide health management services by synchronizing your health data to Samsung Health so that you can centrally view it on that platform.
(4) Retention Period by Recipient: Retained during your use of Samsung Health services; for details, please refer to Samsung's Privacy Policy.
(5) If you refuse to provide information to Samsung Electronics Co., Ltd., you will not be able to view the information collected by this App in Samsung Health, but this will not affect your normal use of other functions.
3.2 Data Migration
We will not transfer your information to any entity except in the following circumstances:
(1) You voluntarily apply for transfer;
(2) We have obtained your explicit consent;
(3) If we are involved in a merger, acquisition, or sale of all or part of our assets, we will notify you of any changes to your personal information via email.
3.3 Disclosure
We may disclose and share your personal information with relevant parties as described below.
3.3.1 Sharing
Your personal information is an important basis and component for us to provide you with products and/or services. We will only process your personal information within the purposes and scope described in this Privacy Policy or in accordance with the requirements of laws and regulations, and will keep it strictly confidential. We will not share your personal information with third-party companies, organizations, and individuals unless one or more of the following circumstances exist:
(1) You make the request yourself;
(2) We have obtained your explicit authorization and consent in advance;
(3) Other circumstances provided by laws and regulations.
3.3.2 Entrusted Processing
You understand and acknowledge that we may entrust authorized partners to process your personal information so that they can provide certain services or perform functions on our behalf. We will only entrust them to process your information for the legitimate, proper, necessary, specific, and explicit purposes stated in this Privacy Policy. Authorized partners can only access the information necessary to perform their duties, and we will require them through agreements not to use this information for any other purposes beyond the scope of the entrustment. If an authorized partner uses your information for purposes we have not entrusted, they will separately obtain your consent.
To ensure the stable operation and functional implementation of our APP, so that you can use and enjoy more services and functions, our APP embeds SDKs or other similar applications from third parties we cooperate with. The third-party SDKs we use are as follows:
1) SDK Name: Google Firebase SDK (iOS/Android)
Developer: Google LLC
Scope of Information Collected: Device identifiers (such as Firebase Installation ID, Instance ID, FCM Token), application information, device information, network status, IP address, push delivery and click information, application usage events, crash and diagnostic information; when using Auth/Firestore, account authentication information and business data may also be processed.
Purpose: Used for message push, application statistical analysis, crash diagnostics, account authentication, cloud data services, and in-app messaging capabilities.
SDK Privacy Policy Link: https://firebase.google.com/support/privacy
2) SDK Name: Google Sign-In SDK (Google Sign-In / Google Play Services Auth, iOS/Android)
Developer: Google LLC
Scope of Information Collected: Your authorized Google account information (such as user identifier, email, nickname, avatar), login token, and device information, application information, and network information required to complete login.
Purpose: Used to support users logging in or restoring login status through their Google account.
SDK Privacy Policy Link: https://policies.google.com/privacy
3) SDK Name: Apple HealthKit (iOS System Capability)
Developer: Apple Inc.
Scope of Information Collected: After your authorization, writes health data such as sleep analysis, sleep stages, and heart rate.
Purpose: Used to synchronize sleep and heart rate data generated by this application to Apple Health.
SDK Privacy Policy Link: https://www.apple.com/legal/privacy/consumer-health-personal-data/en-ww/
4) SDK Name: Google Health Connect SDK (Android)
Developer: Google LLC
Scope of Information Collected: After your authorization, writes health and fitness data such as sleep and heart rate.
Purpose: Used to synchronize sleep, heart rate, and other data to Health Connect and support users in uniformly managing health data authorizations.
SDK Privacy Policy Link: https://support.google.com/android/answer/12201227
5) SDK Name: Samsung Health Data SDK (Android)
Developer: Samsung Electronics Co., Ltd.
Scope of Information Collected: After your authorization, writes health data such as sleep, sleep stages, and heart rate in Samsung Health.
Purpose: Used to synchronize this application's sleep and heart rate data to Samsung Health.
SDK Privacy Policy Link: https://health.apps.samsung.com/privacy
6) SDK Name: Nordic DFU SDK / iOSDFULibrary (iOS/Android)
Developer: Nordic Semiconductor ASA
Scope of Information Collected: Bluetooth device name, Bluetooth device identifier, connection status, firmware package information, upgrade progress, and upgrade logs.
Purpose: Used to perform OTA/DFU upgrades of smart bed-related firmware via Bluetooth.
SDK Privacy Policy Link: https://www.nordicsemi.com/Privacy/Privacy-Policy
7) SDK Name: FastBle SDK (Android)
Developer: Jasonchenlijian (Open Source Project Maintainer)
Scope of Information Collected: Bluetooth device name, MAC address or Bluetooth identifier, broadcast data, connection status, signal strength, and other Bluetooth scanning and connection information.
Purpose: Used to scan, connect to, and control smart bed Bluetooth devices. This SDK primarily provides Bluetooth connectivity capabilities locally and does not separately transmit personal information to the SDK developer's servers.
SDK Privacy Policy Link: https://github.com/Jasonchenlijian/FastBle
3.3.3 Transfer
If we need to transfer personal information due to merger, division, dissolution, declaration of bankruptcy, or other reasons, we will inform you of the name and contact information of the recipient. The recipient will continue to fulfill this Privacy Policy and other legal obligations. If the recipient changes the original processing purpose or method, they will obtain your consent again.
3.3.4 Public Disclosure
Public disclosure refers to the act of publishing information to society or an unspecified group of people. We will only publicly disclose your personal information under the following circumstances:
(1) Based on your active choice or other separate consent;
(2) We determine that you have violated laws and regulations or seriously violated agreements or rules with us;
(3) Circumstances where laws and regulations permit disclosure.
Please be aware that even with your authorized consent, we will only publicly disclose your personal information for legitimate, proper, necessary, specific, and explicit purposes, and will endeavor to de-identify personal information in the publicly disclosed content. You understand and acknowledge that anonymized information cannot point to or identify you, no longer constitutes your personal information, and its public disclosure does not require your authorized consent.
4. Your Rights Regarding Personal Information
4.1 Control Settings
We provide you with the following methods to limit the collection, use, disclosure, or processing of personal data and to control privacy settings:
(1) Log in or log out of your account;
(2) Data toggles;
(3) Cancel your subscription account. Special note: If you cancel your subscription account, all data stored in the account will be permanently and irrecoverably deleted.
You may also contact us at any time through the contact information at the beginning of this Privacy Policy to express your views to us.
4.2 Your Rights Over Personal Data
In accordance with the laws and regulations of your jurisdiction, you have the right to control the personal data we process, including accessing, correcting, and deleting your personal data, withdrawing your previous consent to personal data, and deleting your account in our application. You may independently exercise any of these rights. If you have any questions or difficulties in exercising your rights, please contact us. This Privacy Policy requires that your request comply with applicable laws and regulations and the following conditions:
(1) Your request should be made in writing or by email (unless local law explicitly recognizes oral requests);
(2) Provide sufficient information for us to verify your identity and ensure that the applicant is the data subject or a legally authorized person.
(3) Once we have sufficient information to confirm that your request can be processed, we will respond to your request within any period prescribed by the data protection laws applicable to you.
A. Right of Access
You have the right to ask whether we process your personal data and to request a copy of your personal data. We do not charge a fee for reasonable requests. If your request is manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee.
B. Right to Rectification
You have the right to correct your personal information or request us to make corrections. To help you exercise this right, we provide you with two methods, namely online independent correction and request for correction:
(1) You can directly correct some personal information in our application.
(2) If you encounter difficulties in exercising this right, or if online independent correction is not authorized or available, you may request us to make the correction.
C. Right to Deletion
In accordance with applicable law, you have the right to request the deletion of your personal data. We will consider the reasons for your deletion request and take reasonable measures, including technical measures.
D. Right to Object
In accordance with applicable law, in certain circumstances, you have the right to object to our processing of your personal data.
E. Right to Data Portability
If data processing is carried out by automated means and we obtained such data from you based on your consent or for contractual purposes, you have the right to request that we provide your personal data to you in a structured, commonly used, and machine-readable format, or transfer it to another controller.
F. Right to Withdraw Consent
If you have explicitly consented to the processing of your personal data, you may withdraw such consent at any time. If you intend to change the scope of permissions related to certain functions, you may modify your personal settings through our application or the relevant settings interface included in our products and services. Alternatively, you may also revoke all authorization for us to continue collecting your personal data by canceling your subscription. If you encounter difficulties in the process, please contact us.
We will no longer collect your personal data, and you will also not receive the corresponding services we provide when you revoke the authorization related to the collection of personal data. However, you acknowledge and agree that, unless you exercise the "Right to Deletion" above, the withdrawal of your consent or authorization will not affect the validity of the processing and storage that has been conducted based on your consent.
G. Right to Account Cancellation
You have the right to cancel your account. You can cancel your account on the APP's "Settings - Account & Security - Delete Your Account" page, or you may contact us through the contact information provided at the beginning of this Privacy Policy to cancel your account on your behalf. Please proceed with caution. After you cancel, we will no longer provide you with all products and services. Unless otherwise provided by applicable laws and regulations, all information, data, and records associated with your use of that account will be deleted or anonymized.
H. Right to Non-Discrimination
You will not be discriminated against by us for exercising any of the above rights, including not being denied services or having the quality of services reduced as a result.
5. How We Store and Protect Your Personal Data
5.1 Storage of Personal Information
A. Storage Location: If you are located in the United States, we store your personal information on cloud servers located within the United States; if you are located in the EEA or the UK, we store your personal information on cloud servers located within the European Union. In each case, we store your personal information in accordance with the provisions of laws and regulations. (For specific types, please refer to Section 2 "How We Collect and Use Your Personal Information" of this Privacy Policy.)
B. Storage Period: We will retain your personal information for the minimum period necessary to achieve the purposes of providing our products and services. The maximum storage period for personal information stored in the Bluetooth box installed on the product is ten (10) days. The maximum storage period for unprocessed raw personal information on cloud servers is seven (7) days. The maximum storage period for processed sleep report information on cloud servers is one (1) year. The maximum storage period for processed personal information other than sleep reports on cloud servers is until you cancel your account. After exceeding the above storage periods, we will anonymize your personal information, unless otherwise provided by laws and regulations.
C. Destruction Procedures and Methods: When the retention period for personal information expires or when the purpose of processing has been achieved such that the retention of personal information becomes unnecessary, we will immediately destroy the relevant personal information. If, after the expiration of the personal information retention period you agreed to or after the processing purpose has been achieved, it is necessary to continue retaining personal information under other laws and regulations, we will transfer the personal information to a separate database or store it in another location. The procedures and methods for destroying personal information are as follows:
(1) Destruction Procedure: We will select personal information with grounds for destruction and destroy it after approval by our personal information protection officer.
(2) Destruction Method: We will destroy personal information recorded and stored in electronic file form so that the records cannot be regenerated, and shred or destroy personal information recorded and stored in paper documents using a shredder.
5.2 Personal Information Protection Measures
We have always attached great importance to protecting the security of user personal information. To this end, we have adopted multi-layered protection measures including industry-standard security technical measures and supporting organizational structure and management systems to minimize the risk of your information being leaked, damaged, misused, accessed without authorization, disclosed without authorization, or altered. These include:
A. Data Security Technical Measures
(1) In terms of data security transmission, we use cryptographic technologies such as Transport Layer Security (TLS) protocols, and prevent transmission link sniffing and eavesdropping risks through HTTPS and other methods, establishing a secure privacy data transmission environment to ensure the confidentiality and integrity of data transmission;
(2) In terms of data security storage, we classify data and adopt additional security protection measures such as encrypted storage;
(3) In terms of security control for data access and use, we implement strict data access permission control mechanisms to prevent unauthorized reading, copying, modification, deletion, or removal of data;
(4) We have established a comprehensive audit mechanism to monitor and audit the full lifecycle of data, preventing your personal information from being subject to unauthorized access, public disclosure, use, modification, human or accidental damage or loss;
(5) Other measures to achieve data security protection.
B. Data Security Organizational and Management Measures
(1) We regularly organize employees to participate in training related to security, privacy, and personal information protection and require completion of prescribed assessments, strengthening employees' awareness of the importance of protecting personal information;
(2) We have established a good coordination and linkage mechanism with regulatory agencies and third-party assessment institutions to promptly defend against and handle various information security threats, providing comprehensive protection for your information security;
(3) Other feasible security organizational and management measures.
C. Cooperation Agreement Terms Guarantee
(1) Before we indirectly collect your personal information from a third party, we will explicitly require in writing (such as cooperation agreements or commitment letters) that the third party has obtained your explicit consent before collecting and processing (such as sharing) personal information, and require the third party at the written agreement level to commit to the legality and compliance of the source of personal information. If the third party engages in any violation, we will explicitly require the other party to bear corresponding legal liability;
(2) Before we share your personal information with business partners, we will strictly require the partners' information protection obligations and responsibilities, and will write such requirements into our agreements with business partners. We will continuously supervise and audit, and once a business partner commits any violation, they will bear corresponding legal liability;
(3) Other content explicitly agreed upon in cooperation agreements.
5.3 Handling of Security Incidents
In the unfortunate event of a personal information security incident, we will, in accordance with the requirements of laws and regulations, promptly inform you of the basic situation of the security incident (including the items of personal information leaked, time, location, and circumstances, etc.) and possible damage, the measures we have taken or will take, suggestions for you to independently prevent and reduce risks, our response plan, and remedial procedures, etc. We will promptly inform you of the relevant situation of the incident via email, letter, phone call, push notification, or other means. If it is difficult to notify personal information subjects individually, we will take reasonable and effective measures to issue a public announcement. At the same time, where legally required, we will report to the relevant regulatory authorities.
Please be aware and understand that the internet is not an absolutely secure environment. If you discover that your personal information has been leaked, especially if your account or password has been compromised, please contact us immediately so that we can take corresponding measures to protect your information security.
6. Protection of Minors
We believe it is the responsibility of parents or guardians to supervise their children's use of our products or services. However, we do not directly provide services/products to minors, do not knowingly collect personal data of minors, and do not use personal data of minors. We take appropriate measures to ensure that the personal data of minors is not processed by us. If we discover that personal data has been collected from a minor, we will immediately delete such personal data. If a guardian discovers that a minor has provided personal information to us, please contact us immediately, and we will immediately delete the relevant data and cancel the corresponding account upon verification.
If you are a parent or guardian and believe a minor has provided personal data to us, please contact us to ensure that such personal information is immediately deleted and the minor is unsubscribed from any applicable services.
7. Updates to this Privacy Policy
We encourage you to review our Privacy Policy each time you use our products or services. To provide you with better services, we will update the terms of this Privacy Policy according to product updates and the relevant requirements of laws and regulations. Such updates constitute a part of this Privacy Policy. If such updates result in a substantial reduction or material change to your rights under this Privacy Policy, we will notify you by highlighting prompts in a prominent position before this Privacy Policy takes effect, or by sending you push messages, or through other means. If you continue to use our services, it means you have fully read, understood, and agree to be bound by the revised policy. To protect your legitimate rights and interests, we recommend that you periodically review this Privacy Policy on the APP's "Settings - Help Center" page.
The above-mentioned "material changes" include but are not limited to:
1. Material changes in our service model, such as changes in the purposes of processing personal information, types of personal information processed, methods, etc.;
2. Material changes in our ownership structure, organizational structure, etc., such as changes in ownership due to business adjustments, bankruptcy, mergers and acquisitions, etc.;
3. Changes in the primary recipients of personal information sharing, transfer, or public disclosure;
4. Material changes in your rights to participate in personal information processing and the methods of exercising such rights;
5. Changes in the contact information and complaint channels of the department responsible for personal information security;
6. Other important circumstances or circumstances that may seriously affect your personal rights and interests.
8. Miscellaneous
8.1 We solemnly remind you that there are provisions in this Privacy Policy that exempt our liability and limit your rights. Please read these provisions carefully and consider the risks yourself. Minors should be accompanied by their legal guardians when reading this Privacy Policy.
8.2 This Privacy Policy is protected by the mandatory laws of your country/region. If we are to handle any dispute arising from this agreement, we will prioritize resolution through friendly negotiation. If negotiation fails, you have the right to file a lawsuit with a court of competent jurisdiction in your place of residence or habitual residence, or to file a complaint with the local data protection regulatory authority.
8.3 If any provision of this Privacy Policy becomes invalid or unenforceable for any reason, the remaining provisions shall remain valid and binding on both parties.
9. Supplemental Provisions for Users in the EEA and the UK
This Section 9 applies to you only if you are located in the European Economic Area ("EEA") or the United Kingdom ("UK"). It supplements the other sections of this Privacy Policy. If there is any conflict between this Section 9 and the other sections of this Privacy Policy, this Section 9 shall prevail for users located in the EEA or the UK.
9.1 Data Controller and EU Representative
The data controller of your personal data is Keeson Technology Corporation Limited, whose contact details and Data Protection Officer are listed at the beginning of this Privacy Policy. For EU personal data protection matters, you may also contact our EU Representative, Ergomotion Unipessoal, Lda, whose contact details are listed at the beginning of this Privacy Policy.
9.2 Storage and International Data Transfers
If you are located in the EEA or the UK, we store your personal information on cloud servers located within the European Union (Amazon Web Services, Germany). We transfer your personal data outside the EEA only as described below:
A. Keeson Technology Corporation Limited (China): as described in Section 3.1, for remote device diagnostics, troubleshooting, and sleep algorithm model optimization. China has not been granted an adequacy decision by the European Commission. We therefore conduct such transfers based on your explicit consent in accordance with Article 49(1)(a) of the GDPR. You understand and acknowledge that transfers of data to China involve potential risks and that you may not enjoy the same legal remedies as those available within the EU.
B. Samsung Electronics Co., Ltd. (South Korea): as described in Section 3.1, only if you enable Samsung Health integration and grant the corresponding authorization.
C. OpenAI (servers located in Germany): if you use the AI Sleep Assistant described in Section 2.5, the text you input during interactions with the Sleep Assistant, your aggregated sleep data (such as sleep score, sleep duration, average HRV), the sleep tags you have selected, and basic device information (such as bed type, unit system, and time format preference) are processed to provide the intelligent Q&A service and personalized sleep health analysis. The maximum retention period by the recipient is thirty (30) days. If you do not use the AI functions, such data will not be transferred.
D. Ergomotion Unipessoal, Lda (Portugal): if you are located in the EEA or the UK, the manual customer service described in Section 2.8 is provided by our affiliate Ergomotion Unipessoal, Lda instead of Ergomotion, Inc., and the information described in Section 2.8 is shared with Ergomotion Unipessoal, Lda for the duration of your account's existence.
9.3 Your Rights and Complaints
In addition to the rights described in Section 4 of this Privacy Policy (including access, rectification, erasure, restriction of and objection to processing, and data portability under Articles 15-21 GDPR), you have the right to lodge a complaint with a data protection supervisory authority in the EEA member state or UK jurisdiction of your habitual residence, place of work, or place of the alleged infringement (Article 77 GDPR). We would, however, appreciate the chance to address your concerns first, and you may contact us, our Data Protection Officer, or our EU Representative at any time.
10. Supplemental Provisions for Users in the United States
This Section 10 applies to you only if you are located in the United States. It supplements the other sections of this Privacy Policy.
10.1 Consumer Health Data
For information on how we collect, use, share, and process consumer health data pursuant to the Washington State "My Health, My Data" Act and other similar state laws, please refer to the "Consumer Health Data Privacy Policy," which forms part of our privacy disclosures for United States users.
10.2 No Sale of Personal Information
As stated in Section 3 of this Privacy Policy, we do not sell your personal information to any third party unless we obtain your prior consent or as required by laws and regulations. We do not use your consumer health data, including data obtained from third-party health platforms, for any non-essential commercial purposes, such as advertising push, resale to unrelated third parties, or cross-context behavioral analysis.
10.3 State Privacy Rights
Depending on your state of residence, you may have rights to access, correct, delete, and obtain a copy of your personal information, and the right not to be discriminated against for exercising these rights, as described in Section 4 of this Privacy Policy. You or your authorized agent may exercise these rights through the contact information provided at the beginning of this Privacy Policy or through the in-App paths described in Sections 2 and 4. We will verify your identity before responding to your request and will respond within the period required by applicable state law.