LEGAL

Privacy Policy

Last updated: 2026/06/24

This policy applies to the websites, platforms, software, and service features associated with SEER SONUS / SONUS AI (collectively, the "Services") operated by SEER SONUS Co., Ltd. (Unified Business No. 60539465; hereinafter the "Company," "we," or "us").

Contents

The Company recognizes the importance of personal data protection and has established this Privacy Policy (the "Policy") to explain how we collect, process, use, store, protect, and disclose personal data, as well as the rights data subjects may exercise under the law. Users should read this Policy in full before using the Services.

1. Scope of Application

This Policy applies to all personal data processing involved when users access the following services:

  • The Company's official website
  • The SONUS AI / SEER SONUS platform operated by the Company, including the customer portal, professional back office, and appointment and contact features
  • Online forms, surveys, appointment systems, customer support, email, event registration, and other interactive processes related to the Services

This Policy does not apply to third-party websites, services, or platforms. If users follow links within the Services to other websites or use third-party tools, the privacy policies and terms of service of those third parties shall apply, and the Company assumes no responsibility therefor.

2. Categories of Personal Data Collected

Depending on how users interact with the Company, their account role, the nature of the business relationship, and actual usage, the Company may collect the following categories of personal data:

  1. Basic Identification and Contact Data
    Including but not limited to name, company name, job title, phone number, email address, mailing address, contact preferences, and account identifiers.
  2. Account and Authentication Data
    Including but not limited to login credentials, password hashes, permission roles, multi-factor authentication data, login timestamps, source IP addresses, device information, and access logs.
  3. Business and Service Management Data
    Including but not limited to inquiries, statements of business needs, contract information, payment and billing data, customer service records, notification settings, and subscription preferences.
  4. Usage and Technical Data
    Including but not limited to browser type and version, operating system information, device identifiers, data collected via cookies and similar technologies, browsing records, click-event logs, error logs, activity trails, system events, and audit records.
  5. Survey, Preference, and Interaction Data
    Including but not limited to needs questionnaires, budget intentions, usage preferences, feature preferences, lifestyle information, communication-context records, feedback, and customer support conversations.
  6. Hearing and Health-Related Data
    Where users or their affiliated organizations use certain features of the Services, the Company may process the following data:
    • Pure-tone audiogram image files or digitized assessment results
    • Hearing threshold data
    • Medical history, ear-related conditions, hearing aid usage history, and device needs
    • Health or care information related to product recommendations, follow-up, and after-sales service

    The foregoing data may constitute special-category personal data as defined in Article 6 of the Personal Data Protection Act (PDPA). The Company will process such data in accordance with applicable laws and relevant contractual arrangements.

  7. Data Provided by Partner Organizations
    Where users access the Services through partner clinics, retail stores, medical institutions, or enterprise customers, the Company may receive service-related personal data from such partner organizations.

3. Methods of Collection

The Company may collect users' personal data through the following methods:

  • Provided directly by the user: including filling out forms, registering an account, contacting the Company, uploading files, submitting survey data, or making an appointment.
  • Collected automatically by the system: log records, cookie data, and device and usage-behavior information generated automatically while users access the Services.
  • Provided by third parties: supplied by the organization, company, clinic, or store to which the user belongs, or by their authorized personnel.
  • Lawfully obtained: acquired from third-party service providers, system integrators, or partners pursuant to law or within the scope of lawful authorization.

4. Purposes of Collection and Use

The Company collects, processes, and uses users' personal data for the following specific purposes:

  • Providing, operating, managing, and continuously improving the Services
  • Creating and managing user accounts, authentication, permission control, and access management
  • Appointment handling, survey collection, customer support, notifications, follow-up, and after-sales service
  • Generating recommendations, reports, dashboards, system prompts, analytical results, and workflow support
  • Information security monitoring, auditing, anomaly detection, troubleshooting, system backup, and disaster recovery
  • Performing contractual obligations, billing, reconciliation, collection and payment of funds, invoicing, and internal administration
  • Responding to inquiries, providing product information, and sending service notices and important updates
  • Service quality analysis, product research and development, statistical analysis, and feature optimization
  • Subject to applicable laws and contractual terms, conducting training, model optimization, anonymization or de-identification, and related analysis
  • Legal compliance, cooperation with regulatory authorities, responding to judicial or administrative proceedings, and the exercise, assertion, or defense of the Company's lawful rights and interests

Pursuant to Article 8 of the Personal Data Protection Act (PDPA), when collecting personal data the Company shall, in principle, inform the data subject of the collecting entity, the purpose of collection, the categories of data, the period, territory, recipients, and methods of use, the rights the data subject may exercise under the law, and the impact on their interests of declining to provide such data.

5. Handling of Special-Category and Health Data

Given that the Services involve processing hearing assessment results, medical history, health conditions, or medical-related information, the Company processes such special-category personal data only where one of the following statutory conditions is met:

  • Where necessary to provide a service requested by the user or their affiliated organization
  • Where processed pursuant to applicable law, contractual terms, or a lawful delegation relationship
  • Where valid written consent meeting statutory requirements has been obtained from the data subject
  • Other circumstances permitted under applicable law

Where a user accesses the Services on behalf of an organization, that user shall ensure and warrant that:

  • They have lawful authority to upload, enter, or submit the relevant data
  • They have fulfilled the statutory notification obligation for data collection and obtained the necessary authorization or consent
  • The submitted data is true, accurate, and complete and does not infringe the rights of any third party

6. Period, Territory, Recipients, and Methods of Use

1. Period of Use

For the duration of the specific purpose, the term of the contract, and the statutory retention period, or for such reasonable period as is necessary for dispute resolution, the assertion of rights, legal defense, security auditing, and operational management.

2. Territory of Use

The country or region in which the user is located, the Republic of China (Taiwan), and the jurisdictions in which the Company or its appointed service providers actually deliver services, or store or process data.

3. Recipients of Use

Users' personal data may be provided, to the extent necessary, to the following recipients:

  • The Company and its duly authorized internal personnel
  • The enterprise customer, partner organization, clinic, retail store, or system administrator to which the user belongs
  • Cloud service providers, hosting providers, information security providers, customer service and notification providers, data analytics providers, and other parties commissioned by the Company to process personal data
  • Judicial, administrative, or regulatory authorities with investigative powers under the law
  • Other parties to whom disclosure is permitted with the data subject's consent or under the law
4. Methods of Use

Collection, recording, storage, editing, organization, analysis, retrieval, transmission, output, deletion, and other legally permitted processing of personal data, whether by automated or non-automated means.

7. Provision and Disclosure of Personal Data

Except as otherwise provided in this Policy, with the data subject's consent, or as expressly required by law, the Company shall not sell, exchange, or rent users' personal data to third parties.

The Company may provide or disclose personal data to third parties in the following circumstances:

  • For outsourced processing necessary to provide the Services
  • To perform contractual obligations or carry out functions requested by the user or their affiliated organization
  • To comply with legal obligations, court rulings or orders, or lawful requests from government authorities
  • To protect the rights, property, and safety of the Company, users, partners, or the public
  • In a merger, acquisition, business transfer, asset transfer, reorganization, or investment transaction, providing data to the counterparty for due diligence subject to confidentiality obligations
  • For analysis, research, or service optimization on a statistical, de-identified, or anonymized basis, where the processed data can no longer directly or indirectly identify a specific individual

8. International Transfer of Personal Data

Because the Services may rely on international cloud infrastructure or third-party technology services, users' personal data may be transferred to, stored in, or processed in jurisdictions other than the user's location.

When transferring personal data internationally, the Company will adopt appropriate safeguards in accordance with applicable law and reasonable commercial practice to preserve the confidentiality, integrity, and availability of the data.

9. Retention and Deletion of Personal Data

The Company retains users' personal data only as long as necessary for the purposes of collection. Upon expiry of the retention period, when the purpose of collection no longer exists, or when the data subject lawfully exercises the right to deletion or the right to request cessation of use and meets the statutory requirements, the Company will delete, de-identify, or cease using the personal data in accordance with its internal procedures and the law.

The preceding paragraph does not apply in the following circumstances:

  • Where retention is required or permitted by express provision of law
  • Where necessary for dispute resolution, evidence preservation, the assertion of rights, or legal defense
  • Where data temporarily remains in backup systems and will be overwritten or purged within a reasonable operational cycle
  • Where data that has been de-identified or anonymized may lawfully continue to be retained and used

10. Information Security Measures

The Company adopts reasonable and appropriate technical and organizational security measures to prevent unauthorized access, alteration, destruction, loss, or disclosure of personal data. Such measures include but are not limited to:

  • Encryption of data in transit
  • Encryption of data at rest and special protection for sensitive fields
  • Tiered access controls and enforcement of the principle of least privilege
  • Multi-factor authentication and login protection
  • System log management, access record retention, and audit trails
  • Data backup and disaster recovery plans
  • Personnel access management and information security training
  • Security management of outsourced vendors and contractual confidentiality obligations

However, no method of data transmission over the internet or electronic storage can guarantee absolute security. The Company will continuously review and strengthen its safeguards according to the nature of the data and the level of risk.

11. Handling of Data Breach Incidents

Upon becoming aware that personal data in its custody has been stolen, altered, damaged, lost, or disclosed, the Company will take necessary responsive measures in accordance with applicable law, including incident investigation, damage control, system remediation, incident logging, and notifying affected data subjects as required by law. Pursuant to Article 12 of the Personal Data Protection Act (PDPA), a non-government agency shall notify the data subjects by appropriate means after becoming aware of a breach of personal data.

12. Exercise of Data Subject Rights

Pursuant to Article 3 of the Personal Data Protection Act (PDPA), data subjects may exercise the following rights with respect to their personal data:

  • Inquire about or request to review the data
  • Request a copy of the data
  • Request supplementation or correction
  • Request cessation of collection, processing, or use
  • Request deletion

Under Article 3 of the Personal Data Protection Act (PDPA), the foregoing rights may not be waived in advance or restricted by special agreement.

To exercise these rights, data subjects should submit a request to the Company using the contact method provided in this Policy. To verify the applicant's identity, the Company may require the submission of necessary supporting documents and will respond in writing on the outcome within the statutory period.

14. Protection of Minors' Personal Data

The Services are intended primarily for use by enterprises, organizations, and their authorized personnel. Where a minor's personal data is involved in a particular context, the user responsible for uploading or processing such data shall ensure that the consent of the legal guardian or other necessary authorization has been lawfully obtained, and shall process the data only to the extent lawful and necessary.

15. Third-Party Service Integrations and External Links

The Services may integrate third-party login services, analytics tools, push notification services, cloud storage, map services, payment gateways, or other technical services. Such third-party providers may process certain personal data of users as necessary to deliver their functions. Users understand and agree that use of such third-party services is governed by their respective terms of service and privacy policies.

16. Amendments to This Policy

The Company may amend this Policy at any time due to changes in law, business adjustments, feature updates, or changes in internal processes. The amended version will be posted on this website or within the Services interface and takes effect from the date of posting. For material changes, the Company will notify users by appropriate means.

17. Contact

Data Controller: SEER SONUS Co., Ltd. (Unified Business No. 60539465).

If you have any questions or complaints regarding this Policy or our handling of personal data, or wish to exercise your rights, please contact us by email:

Email: contact@seersonus.com

To request a Data Processing Agreement (DPA), or our data-protection and security documentation, please reach out via the email above or Contact us.

See also: Terms of Service

Still have questions? Contact us