Legals

VONDER PRIVACY POLICY

This Privacy Policy (the “Policy”) explains how we collect, use, store, disclose, and share (collectively “process”) your personal data when you use VONDER smart glasses (the “Device”), the companion VONDER application (the “App”), and the related services we provide (collectively the “Services”).

Depending on how you purchased your Device, the data controller responsible for your personal data differs:
• Vonderful Inc., registered at 254 Chapman Rd, Ste 208 #23943, Newark, Delaware 19702, USA, is the data controller for personal data collected from users who purchase through our official website (https://www.vonder.ai/).
• Vonderful HK Inc., registered at UNIT 1003,10/F TOWER 2, SILVERCORD, 30 CANTON RD, TSIM SHA TSUI, HONG KONG, is the data controller for personal data collected from users who purchase through other authorized sale channels.

If you are located in the EU/EEA, you may also contact our EU representative, Eden Future NL B.V., at Airborne Avenue 79, Office C05, 2133LV Hoofddorp, Netherlands. For any privacy questions or complaints, please contact us at legal@vonder.ai

For users in the United Kingdom, this Policy applies in the same way as it does to users in the EEA. References to the GDPR are to the UK GDPR and the Data Protection Act 2018; references to the EEA include the UK, and the relevant supervisory authority is the UK Information Commissioner’s Office (ICO).

This Policy may be updated from time to time. Where changes are material, we will notify you in advance through in-App notice, push notification, email, or other appropriate means.

1. What data do we collect

For the purpose of this Policy, “personal data” means any information relating to an identified or identifiable individual.

1.1 Categories of personal data we collect

We collect the following categories of personal data:

Account Information — the email address and authentication information associated with your Google, Apple, and email sign-in, your account status, and profile data you choose to provide. We do not require you to provide your personal identification information to create an account.

Device & Technical Information — device identifiers, device model, operating system and version, app version, Bluetooth and connection data, IP address, network information, device settings, and device operation logs.

Location Information — where you enable location access, the location data used to provide location-based features such as weather and location-tagged memories.

Firmware Information — during firmware updates, information about the firmware version and update packages.

Order & Purchase Information — when you purchase a Device or subscription plan, the information necessary to fulfil your order, such as your name, postal address, phone number, email address, and subscription billing record.

Audio & Transcription Data — when you use a recording mode (described below) or voice chat, audio captured by the Device and the text transcribed from it. The original audio is deleted from our systems immediately after transcription. Where a service provider processes audio to perform the transcription, it is retained only for as long as necessary for that purpose and is then deleted.

AI Summary, Input and Output — the input content of the AI assistant on the App or the web Service, the summaries we generate from transcriptions, and the responses of the AI assistant generated in reply to your inputs.

Prescription Information (health data) — if you order prescription lenses, the optical prescription you provide. This is health data and constitutes a special category of personal data under Article 9 GDPR; we process it only as described in Sections 2, 4 and 5.

Usage & Diagnostic Information — feature usage, settings, logs, and crash data used to maintain, secure, and improve the Services.

Memory (subscription feature). Memory is part of paid subscription feature that stores content from your interactions with the AI assistant, together with behavioural data from your use of the in-app News feature, to give you a more personalised experience over time. This content is organised by topic into “memory tags.” You can delete your Memory data both locally and in the cloud; please note that deleting a memory tag deletes all underlying data associated with that tag.

Personalisation and profiling. Where you use the Memory and News features, we analyse your memory content and keywords, and your in-app News browsing and interests, to build a profile of your preferences in order to personalise and recommend content to you, including news topics. This profiling is not used to make decisions that produce legal or similarly significant effects for you, and we do not use it to infer sensitive characteristics about you or for advertising.

You can opt out of Memory-based profiling at any time by deleting your Memory data. Personalised recommendation is an inherent part of the News feature and cannot be separately switched off; if you do not wish to receive it, you can stop using or discontinue your subscription to the News feature.

1.2 How VONDER processes audio

How the recording modes work. VONDER offers two recording modes. Both are off by default and must be actively enabled by you. In both modes, audio is transcribed into text, and the original audio is deleted from our systems immediately after transcription.

All-day auto-pilot notetaking mode. When enabled, the Device acts as your always-available note-taking assistant and captures only the wearer’s voice. We apply technical measures to minimise the capture of other surrounding voices. This mode is off by default and is enabled only with your consent. The original audio is handled as described in Section 1.1.

Meeting mode. When enabled, the Device indicates its recording status through an indicator light. The Device captures meeting audio for the provision of transcription and summary. It distinguishes the wearer’s voice from other sound sources by the physical means described below; it does not separate or identify individual participants’ voiceprint data or other biometric data.

How we separate speakers/voice data

VONDER distinguishes the wearer’s voice from other sound sources in the surrounding environment, which is not based on identifying or distinguishing individuals. In this process, VONDER does not collect, extract, store, or compare voiceprints or any other biometric identifiers, does not create any voiceprint template or database, and is not capable of recognising the same individual across different recordings or sessions. VONDER does not process voice data for the purpose of identifying a natural person.

Your responsibility in multi-person settings

Where a meeting mode may capture the voices of other people, you are responsible for ensuring that you have obtained any consent required under the laws applicable to you before recording.

Access permissions

Your use of Services requires the following access to your device. You may manage the access permission under Settings.

Categories

Purpose

User Management

Wireless Data Permission (WLAN & Cellular)

Login and all functions except caching

No, required for app usage

Bluetooth Permission

Connecting glasses

No, required for connecting glasses

Microphone Permission

For a smoother AI conversation experience

Yes (can be disabled in system settings)

Location Permission

Weather queries, recording location-related memories

Yes (can be disabled in system settings)

Media & Apple Music

Wake music playback via AI, iOS only

Yes (can be disabled in system settings)

Notification

Sending you service-related notifications

Yes (can be disabled in system settings)

2. How we use your data

We only use your personal data where applicable law permits.

Our legal bases depend on the data and the context in which we process it:
• performance of a contract;
• your consent;
• our legitimate interests (providing, maintaining and securing the Services, preventing misuse and fraud, and protecting our and others’ legal rights); and
• compliance with legal obligations.

The purposes for which we process personal data and the legal bases are set out below:

Type of Personal Data

Purpose

Legal Basis

Account Information, Device & Technical Information

Account creation and account management

Performance of contract

Location Information

To provide weather and location-tagged memories

Consent

Audio & Transcription Data, AI Summary, Input and Output

To provide recording transcription and audio summaries

Consent

AI Summary, Input and Output

To provide the AI assistant in response to the input content

Performance of contract

AI Summary, Input and Output; Usage & Diagnostic Information

To provide the Memory feature and personalised content recommendations (including profiling)

Performance of contract

Prescription Information (health data)

To fulfil orders for prescription lenses

Performance of contract and consent

Order & Subscription Information

To fulfil and manage your orders and subscription

Performance of contract

Firmware Information, Device & Technical Information

To provide firmware updates and maintain your Device

Performance of contract

Device & Technical Information, Usage & Diagnostic Information

To maintain, improve, secure and troubleshoot the Services

Legitimate interests

3. How do we retain and protect your data?

You can choose to sync up your data to the cloud or stay with your Device.

Retention. Original audio recordings are deleted from our systems immediately after transcription and are not retained by us thereafter. Where a service provider processes audio to perform the transcription, it is retained only for as long as necessary for that purpose. Transcripts, AI summaries, chat content, and Memory data are retained until you delete them or delete your account. Other categories of personal data are retained for the period required to fulfil the purpose for which they were collected; where legal obligations require longer retention, we retain that data for the period prescribed by applicable law. Once the purpose for which it was collected no longer applies, personal data will be deleted or anonymised in accordance with applicable law.

Security. We implement appropriate technical and organisational measures, including encryption in transit, access controls, and security obligations imposed on our processors, to protect your data against loss, misuse, and unauthorised access. Please note no method of internet transmission is completely secure, so while we take reasonable steps to protect your data, we cannot guarantee absolute security.

4. How will we disclose your data?

We may disclose your information in the following ways:

Affiliated entities We may disclose information among our affiliated companies to deliver and support the Services and operate our business.

Service providers We use selected third-party vendors to help provide the Services, including cloud hosting and data storage, speech-to-text transcription, AI model providers, logistic service providers, etc. These providers may access your information only to perform services for us or to comply with legal requirements.

Lens manufacturer Where you order prescription lenses, we disclose your prescription to our lens manufacturer for the sole purpose of producing your lenses. The manufacturer processes this data on our behalf under a data processing agreement incorporating the EU Standard Contractual Clauses. As prescription data constitutes health data, this disclosure is subject to enhanced contractual safeguards. Cross-border transfer of this data is addressed in Section 5.

Marketplace platforms If you purchase through other authorized sale channels, your order and fulfilment information is handled through those platforms under their terms and our agreements with them.

Connected third-party services Some features let you connect VONDER to third-party services that you choose to use (for example, music or streaming services). When you initiate such a connection, we disclose the information necessary to enable that service (for example, your login credentials or a request you direct to that service). These connections are optional and initiated by you; your use of the connected service is governed by that third party’s own terms and privacy policy. We encourage you to review their policies before connecting.

Third-party SDKs and similar technologies The VONDER Products, including the App and the web Service, incorporate third-party software development kits, and similar technologies that process certain device, usage, and online identifier information to provide functions such as log-in, analytics, crash reporting, payment, push notifications, etc. Depending on the specific technology, these providers act as our processors or as independent controllers under their own privacy policies. For details of the third-party technologies we use and the information they process, see our List of Third-Party SDK and Cookie Policy.

Protection of VONDER and others We may disclose the information we collect about you if required to do so by law or in a good faith belief that such disclosure is reasonably necessary to: (a) comply with legal process (for example, a subpoena or court order); (b) enforce our terms of service or sale, this Privacy Policy, or other contracts with you, including investigation of potential violations; (c) respond to claims that any content violates the rights of third parties; or (d) protect the rights, property, or personal safety of Vonderful or others.

Business transfers If we are involved in a merger, acquisition, asset sale, or similar transaction, your information may be disclosed as part of, or in contemplation of, that transaction.

5. How we transfer your data internationally

Your personal data may be processed on servers, or accessed by our affiliates, service providers, and business partners, located outside the country where you live, including in jurisdictions that may not provide the same level of data protection as the one where you are located.

Where personal data is transferred outside the EEA or UK to a jurisdiction that has not been recognised as providing an adequate level of protection, we rely on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses, UK Addendum to the EU SCCs, or another lawful transfer mechanism, and we implement appropriate safeguards designed to ensure an equivalent level of protection for your personal data.

Our operations involve entities and service providers in several jurisdictions, including the United States, Hong Kong SAR, and Mainland China. Where audio is processed by our affliates or service providers outside your country for transcription purposes, such processing is subject to the safeguards described in this Section.

You may request more information about the safeguards we apply to international transfers using the contact details in Section 10.

6. Your data subject rights and choices

Subject to applicable law and depending on where you reside, you may request the following by contacting us as detailed in Section 10. We may need to verify your identity before responding.
• Access to, or a copy of, your personal data
• Confirmation of whether we process your personal data
• Correction of inaccurate or incomplete personal data
• Deletion of your personal data
• Transfer (portability) of certain personal data to you or another controller
• Restriction of, or objection to, certain processing
• Lodging a complaint with your local data protection authority

Where we rely on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

7. Children’s privacy

Our Services are intended for general audiences and are not directed at children. If we become aware that we have collected data without legally valid parental consent from children under an age where such consent is required, we will take reasonable steps to delete it as soon as possible.

8. Notice to California Residents

If you are a California resident, the CCPA requires us to provide the following additional information about the personal information we collect, use, and disclose.

Disclosure of personal information. In the past 12 months, we have collected and disclosed the following categories of personal information for business purposes:

We do not “sell” your personal information for money. We may “share” personal information for cross-context behavioral advertising as defined under the CCPA, through advertising technologies on our website. You can opt out at any time via Cookie Preference.

Automated profiling. We use automated profiling based on your Memory content and News preference, to personalise and recommend content. We do not use it to make decisions with legal or similarly significant effects, for advertising, or to infer sensitive characteristics, and you can opt out by deleting your Memory data or cancelling the subscription, or contact us for further assistance.

Sensitive personal information. Certain information described above constitutes “sensitive personal information” under the CCPA, namely your prescription (health) information and the contents of any recordings you elect to create. Such information is used solely to provide the features you request and for other permitted business purposes, and is not used to infer characteristics about you. We do not collect biometric information for the purpose of identifying you (see Section 1).

9. HIPAA Compliance [US Only]

We do not provide medical care or advice and are thus not a covered entity under HIPAA. The only health data we collect is your optical prescription, which we collect at checkout with your separate, explicit consent and use solely to produce your prescription lenses.

10. How to contact us

For questions about this Policy or to exercise your rights, contact us at legal@vonder.ai

EU/EEA representative: Eden Future NL B.V., Airborne Avenue 79, Office C05, 2133LV Hoofddorp, Netherlands.

11. Changes to this Policy

We may update this Policy from time to time. Where changes are material, we will notify you in advance through in-App notice, push notification, email, or other appropriate means. Please review it periodically for the latest version.

Appendix A: Web version of the AI assistant (EU/US)

This appendix applies when you use the web version of the VONDER AI assistant in a browser (app.vonder.ai). This appendix is incorporated into the main Privacy Policy.

You need a VONDER account to use the web Service. You can create a VONDER account by signing in with your Google account, Apple account, or email. The same account works across the web version and the VONDER Device. Your account data (including chat history) is shared across both as described in the main Policy.

On the web Service, you can interact with the assistant by typing or by voice instruction; the web Serivce does not support the recording modes available on the VONDER Device (Section 1.2).

We process the text and voice input you provide, together with the responses we generate, to provide the features you ask for. This input may include personal information you choose to provide, and sometimes sensitive information. We process it on the same terms set out elsewhere in this Policy — including how long we keep it (Section 3), who we share it with (Section 4), and how it may be transferred internationally (Section 5).

The web Service uses cookies and similar technologies. To learn more about our use of cookies and similar technologies, your choices, and how to manage them, please refer to our Cookie Policy.