Privacy Policy

Updated June 5,2022

This US (California) Addendum (“Addendum”) to the Nothing Technology Limited (also “Nothing,” “we,” “us,” “our”) Privacy Policy (https://us.nothing.tech/pages/privacy-policy) applies to all visitors, users, and others who access or use our website, https://us.nothing.tech/ (“Website”), products or apps, create a Nothing account, contact our customer service, request information from us, direct third parties to share data with us or communicate with us via social media or otherwise and reside in the State of California. The terms set out in this Addendum are in addition to the other terms set out in our Privacy Policy and form an integral part of the Privacy Policy as to residents of California. In the event of any conflict or inconsistency between the body of the Privacy Policy and the terms of this Addendum, the terms of this Addendum shall govern and prevail solely as to residents of California. 

 

“Personal Data” in this Addendum has the same meaning as “personal information” in the California Consumer Privacy Act (Cal. Civ. Code Ann. § 1798.140(v)).  

 

1. Collection and Use of Personal Data 

 

During the preceding 12 months, we have collected and used the Personal Data described in the “What Personal Data we collect” section of the Privacy Policy, in the categories set forth below, and for the purpose described in the section, “How do we use your Personal Data,” of the Privacy Policy.

In particular, we may have collected the following categories of Personal Data from consumers within the last twelve (12) months: 

 

Category

Examples

Collected

A. Identifiers.

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.

YES

B. Personal information categories.

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.

Some personal information included in this category may overlap with other categories.

YES

C. Protected classification characteristics under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

YES

D. Commercial information.

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

YES

E. Biometric information.

Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

NO

F. Internet or other similar network activity.

Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.

YES

G. Geolocation data.

Physical location or movements.

YES

H. Sensory data

Audio, electronic, visual, thermal, olfactory, or similar information.

NO

I. Professional or employment-related information.

Current or past job history or performance evaluations.

YES

J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

NO

K. Inferences drawn from other personal information

A profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

YES

 

We obtain the categories of Personal Data listed above from the following categories of sources:

  1. Directly from you. For example, from forms you complete or purchases you make.
  2. Indirectly from you. For example, from collecting data, such as device and browser information, and usage data, based on your actions on our Website. 
  3. From third party or public or commercially available sources or from companies that partner with us.  This may include information we receive from our advertising and market research partners, who may provide us with information about your interest in and engagement with our online advertisements. 

 

2. Disclosure or Sale of Personal Data 

 

As described in the Privacy Policy, we may disclose your Personal Data to third part(y/ies) for business purposes. We only make these disclosures for business purposes under written agreements with such third part(y/ies) that require the recipient to (i) keep the Personal Data confidential, and (ii) not use it for any purpose(s) other than those necessary for the performance of the agreement. In the preceding twelve (12) months, Company has disclosed Personal Data for business purposes to the categories of third parties indicated below:

 

  1. Processors or other service providers
  2. Data aggregators
  3. Affiliates
  4. Partners
  5. Cookie data recipients (See Cookies Policy)

 

We may also disclose your Personal Data to third parties when you explicitly ask or authorize us to do so, in order to provide you with certain services. For example, if you choose to participate in the hearing test within the Nothing X app, we make certain Personal Data available to our third-party partner, Mimi Hearing Technologies GmbH, to provide you with personalized sound function.

 

In addition, we may share your Personal Data for the purposes of direct marketing or targeted advertising, as described in the “How do we disclose your Personal Data” section of the Privacy Policy, subject to your right to opt-out of such sharing (see “Opt-Out of Disclosure or Sale” in Section 3 below), and also with third parties who use automated technologies such as cookies or similar technologies to make statistical analyses for us, as described in the “How and when we collect Personal Data about you – data generated during your use of Nothing Services” section of the Privacy Policy. 

 

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.

 

We do not sell, and in the preceding twelve (12) months we have not sold, any Personal Data. 

 

3. Your Rights

 

In addition to the data subject rights mentioned in the Privacy Policy, you also have the following rights under the California Consumer Privacy Act:

 

  1. Opt-Out of Disclosure, Sharing or Sale: If you are age 16 or older, you have the right to opt out of the sale of your Personal Data or the sharing of your Personal Data by making your request through privacy@nothing.tech or visit https://us.nothing.tech/pages/contact-support. In accordance with CCPA, we do not knowingly sell or share the Personal Data of individuals between the ages of 13-15, without the individual’s express consent, or under the age of 13, without the express consent of the individual’s parent or guardian.
    You do not need to create an account with us to exercise your opt-out rights. We will only use Personal Data provided in an opt-out request to review and comply with the request.
  2. Right to Limit Use or Disclosure of Sensitive Personal Data: You have the right to limit the use or disclosure of your sensitive Personal Data to uses which are:
    a. necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services, b. to help ensure the security and integrity of the Personal Data,
    c. for short-term, transient use, provided that the Personal Data is not disclosed to another party and is not used to build a profile about you or otherwise alter your experience,
    d. performing services on our behalf, or
    e. undertaking activities to verify or maintain the quality or safety of a service or device that is owned by us, or improve, upgrade, or enhance the said service or device.

    Sensitive Personal Data includes account log-in information, credit card numbers in combination with security codes, passwords, or credentials to access said account or use said credit card, precise geolocation, racial origin, mail, email, or text message content, unless we are the intended recipient thereof, or genetic data. Personal Data that is collected or processed without the purpose of inferring characteristics about you is not subject to this section. You can make requests to limit use or disclosure of sensitive Personal Data through privacy@nothing.tech if you believe we are using your sensitive Personal Data beyond what is allowable under the law.
  3. Do Not Track: At this time, we are not aware of worldwide uniform or consistent industry standards or definitions for responding to, processing, or communicating “Do Not Track” signals. Accordingly, our services may be unable to respond to “Do Not Track” requests from browsers. 
  4. Right to Correct or Delete: You have the right to request that we delete any of your Personal Data that we collected from you and retained and to request that we correct any inaccurate Personal Data about you that we retain, subject to certain exceptions, by making your request through privacy@nothing.tech. Once we receive and confirm your verifiable deletion request, we will delete (and direct our service providers to delete) your Personal Data from our records, unless an exception applies. 

    1. We may deny your deletion request if retaining the Personal Data is necessary for us or our service provider(s) to: 
    1. Complete the transaction for which we collected the Personal Data, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you;
    2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
    3. Debug products to identify and repair errors that impair existing intended functionality;
    4. Exercise free speech rights, ensure the right of another to exercise their free speech rights, or exercise another right provided for by law;
    5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.) or similar state law(s);
    6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when deletion of the information may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent;
    7. Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us;
    8. Comply with a legal obligation; or
    9. Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
2. Once we receive and confirm your verifiable correction request, we will correct your Personal Data in our records (and direct our service providers to correct such information in their records), unless an exception applies.
    1. In determining the accuracy of the Personal Data that is the subject of a request to correct, we shall consider the totality of the circumstances relating to the contested Personal Data and may deny a request to correct if we determine that the contested Personal Data is more likely than not accurate, based on the totality of the circumstances.
    2. We may require a party making a request to correct to provide documentation supporting such request, if necessary to rebut our documentation that the Personal Data that is the subject of such request is accurate.
    3. We may delete contested Personal Data, as an alternative to correcting the information, if the deletion of the Personal Data does not negatively impact the party making such request to correct or if such party consents to the deletion.
    4. We may deny a party’s request to correct if we previously denied that party’s request to correct the same alleged inaccuracy within the past six (6) months of receiving the latter request.
    5. We may deny a request to correct based on our good-faith, reasonable, and documented belief that such request to correct is fraudulent or abusive.
    6. In responding to a request to correct, we will inform the party making such request whether we complied with the request and, if we do not, explain the basis for declining to do so.

5.  Non-Discrimination: We will not discriminate against you for exercising any of your rights described herein. Unless permitted by law, we will not:

    1. Deny you goods or services.
    2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
    3. Provide you a different level or quality of goods or services.
    4. Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

6. Right to Know: You have the right to request that we disclose certain information to you about our collection and use of your Personal Data over the past 12 months (the "right to know"). To exercise your rights, you or your authorized agent may contact us using the contact details provided under the section “Contact us” in the Privacy Policy. Once we receive your request, we may verify it by requesting information sufficient to confirm your identity, including by asking you to verify information about your use of the services. Once we receive your request and confirm your identity, we will disclose to you:

    1. The categories of Personal Data we collected about you.
    2. The categories of sources for the Personal Data we collected about you.
    3. Our business or commercial purpose for collecting or selling that Personal Data.
    4. The categories of third parties with whom we share that Personal Data.
    5. If we sold or disclosed your Personal Data for a business purpose, two separate lists disclosing:
      1. sales, identifying the Personal Data categories that each category of recipient purchased; and
      2. disclosures for a business purpose, identifying the Personal Data categories that each category of recipient obtained.
    6. The specific pieces of Personal Data we collected about you (also called a data portability request).

4. Exercising Access, Data Portability, and Deletion and Correction Rights

We will only respond to verifiable requests related to your Personal Data coming from you, or someone legally authorized to act on your behalf. You may also make a verifiable request on behalf of your minor child.

 

Such request must:

  1. Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Data or an authorized representative of that person.
  2. Communicate your request with sufficient detail to allow us to properly understand, evaluate, and respond to it.

 

We cannot respond to your request or provide you with Personal Data if we cannot verify your identity or authority to make the request and confirm that the relevant Personal Data relates to you. 

 

Making such a verifiable request does not require you to create an account with us. However, we do consider requests made through your password protected account sufficiently verified when the request relates to Personal Data associated with that specific account.

 

We will only use Personal Data provided in such a verifiable request to verify the requestor's identity or authority to make the request. 

 

5. Response Timing and Formats

 

We endeavor to respond to a verifiable request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing.

 

If you have an account with us, we may deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. 

 

Any disclosures we provide may only cover the 12-month period preceding our receipt of the verifiable request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Data that is commonly used and should allow you to transmit the information from one entity to another entity without undue hindrance.

 

6. California Shine the Light Law

 

California's "Shine the Light" law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request a list of all third parties to which we have disclosed certain of their Personal Data for direct marketing purposes. You may make one request per calendar year. In your request, please attest to the fact that you are a California resident and provide a current California address for your response. Please allow up to thirty (30) days for a response. To make such a request, please send an email to privacy@nothing.tech or write us at: Nothing Technology Limited, 4th Floor, 32-38 Saffron Hill, London, United Kingdom, EC1N 8FH

 

7. Contact Us

If you have any questions regarding this Privacy Policy, the US (California) Addendum or its implementation, here is how you can reach us: 

 

Email Address: privacy@nothing.tech.

Website: https://us.nothing.tech/pages/privacy-policy 

Postal Address: Nothing Technology Limited, 4th Floor, 32-38 Saffron Hill, London, United Kingdom, EC1N 8FH