Privacy Policy

Last updated:

Scope of the Ari Privacy Policy

This Privacy Policy explains how RealWear, Inc., (hereinafter "Company" "we", "us", "our"), processes Personal Data in connection with your access to and use of our websites, online stores, marketplaces, cloud services, software applications, device software, artificial intelligence functionality, integrations, and other products, services, features, and functionality that we make available from time to time, (collectively, the "Services").


Privacy Commitment

We take the protection of your privacy and Personal Data very seriously and are committed to protecting your personal, confidential, and otherwise sensitive information. We aspire to conduct business and process your Personal Data in accordance with all applicable data protection legislation, in all markets within which we operate.


Definitions

"Controller" means the person or organization that determines the purposes and means of processing Personal Data.

"Cookies" means a small data file that is stored on your device and contains data such as your personal site settings and log-in information.

"Customer" means any person or entity that purchases, subscribes to, accesses, or otherwise uses the Services.

"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual.

"User," "You" or "Your" means any individual who accesses or uses the Services.


1. What Is Our Role in Collecting and Processing Your Personal Data?

Depending on how you access the Services, different parties may act as the Controller:

1.1 Customer Managed Deployments

If you use the Services, as an employee, contractor, or authorized user of an organization (for example, your employer or enterprise business customer) that has subscribed to the Services, that organization is typically the Controller for your use of the Services.

1.2 Direct / Self-Service Users

If you sign up and use any Services, directly with us (without a business enterprise customer in between), we are the Controller for your use of the Services.

We engage third-party service providers and data processors to support the operation of the Services and our business activities, including cloud hosting, payment processing, authentication, analytics, communications, marketing, customer support, security, monitoring, and artificial intelligence functionality.

1.3 When We Act as Controller

We act as the Controller when we determine the purposes and means of processing Personal Data, including for account registration, account administration, subscriptions, billing, payment processing, authentication, fraud prevention, security monitoring, service usage analytics, legal compliance, and other business and operational purposes related to providing, maintaining, securing, and improving the Services.

1.4 When We Act as Processor

For certain Customers, we process Personal Data on behalf of those Customers where they determine how the Services are configured and used. In such cases, we act as a data processor and process Personal Data only in accordance with the Customer's instructions and applicable contractual commitments.


2. What Information Do We Collect?

2.1 We may collect and process Personal Data when you use the Services as follows:
2.1.1 Identification and Account Information

To create, administer, secure, and manage your account, provide access to the Services, authenticate users, communicate with you regarding the Services, and otherwise operate the Services, we may collect the following information:

  • Name, username, display name, or other account identifiers;

  • Contact details (for example, mailing address, billing address, telephone number, or email address);

  • Company, organization, department, job title, role, or other affiliation information;

  • Account registration, subscription, licensing, billing, purchase, transaction, and account preference information;

  • Authentication, authorization, and account security information (for example, single sign-on credentials, identity tokens, roles, permissions, multifactor authentication settings, and account identifiers); and

  • Any other information requested by us or voluntarily provided by you.

2.1.2 When You Use Our Websites, Online Stores, or Marketplaces

When you visit our websites, create an account, purchase products or services, subscribe to the Services, download applications, use marketplace functionality, or otherwise interact with our websites, we may collect your name, email address, shipping and billing address, telephone number, company or organization information, transaction and subscription information, account information, and other information necessary to provide the requested products, services, and functionality.

Payments and subscription transactions may be processed by third-party payment and ecommerce providers, such as Stripe or Shopify, and we may receive information related to those transactions from such providers.

2.1.3 Usage and Device Data
  • Information about the devices, applications, and systems you use to access the Services, including AR devices, mobile devices, computers, browsers, operating systems, device identifiers, application versions, and related technical information;

  • Log, telemetry, and usage data, including timestamps, feature usage, operational metrics, performance information, diagnostics, error logs, and other information relating to use of the Services;

  • Security, authentication, and access-related information, including login events, account activity, authentication status, and related security information;

  • Approximate location information derived from IP address, browser settings, referral sources, and links followed when leaving the Services (generally at the country or regional level and where necessary for security, routing, analytics, and compliance purposes); and

  • Diagnostic, crash-reporting, troubleshooting, and performance information used to operate, maintain, secure, and improve the Services.

2.1.4 Support and Communication
  • Information you provide when you contact us for support, customer service, account assistance, billing inquiries, technical troubleshooting, or other communications (including through email, chat, support tickets, web forms, telephone communications, or other support channels);

  • Information relating to support requests, service incidents, troubleshooting activities, diagnostic information, and communications with our support personnel; and

  • Feedback, feature requests, bug reports, product reviews, survey responses, and other information you voluntarily provide regarding the Services.

2.2 We may collect and process the following Personal Data and related content when you use AI-powered features of the Services:
2.2.1 Voice, Text, and AI-Generated Content
  • Voice inputs, audio streams, voice recordings (where retained), and transcription data generated when you use voice-enabled features of the Services;

  • Text prompts, questions, commands, and other content submitted through AI-powered features of the Services; and

  • Outputs generated by the Services, including text responses, summaries, recommendations, and other content generated based on information submitted through the Services.

  • Voice-enabled functionality may process audio inputs to perform speech recognition, transcription, command execution, and response generation. Audio streams may be processed in real time by Company or its service providers to provide requested functionality. Depending on the Services configuration, applicable Customer settings, and applicable law, audio recordings and transcription data may be stored, retained, or deleted following processing.

2.2.2 Memories and Conversation History
  • Conversation history, including the timing, content, and context of interactions with AI-powered features of the Services; and

  • Optional memories, preferences, settings, personalization information, and other context you choose to provide or save through the Services to improve continuity across interactions.

Depending on the Services configuration, users, administrators, and applicable Customers may be able to review, modify, export, disable, or delete stored memories and conversation history through the Services.

2.2.3 Information from Integrations

If you or a Customer connect the Services to third-party systems, we may process Personal Data and other information made available through those systems.

Examples include:

  • Microsoft 365 / Microsoft Entra ID: emails, calendar entries, tasks, files, Teams channels and messages, contacts, and related information to the extent access has been granted by you or the applicable Customer; and

  • Other Connected Services: Documents, files, communications, tickets, asset data, CRM data, knowledge-base content, productivity-platform information, and similar information as configured by the Customer.

The categories of information accessible through integrations depend on the specific integration and permissions granted by you or the applicable Customer. Access to integrated systems may be modified, restricted, or revoked through the applicable third-party system or Services settings.


3. Use of AI Systems

The Services may use artificial intelligence technologies, including speech recognition, natural language processing, large language models, retrieval systems, text-to-speech technologies, and related AI technologies to provide features and functionality. When you use AI-powered features of the Services, we may process prompts, voice inputs, transcriptions, conversation content, uploaded files, information obtained through authorized integrations, memories, preferences, and related context necessary to provide requested functionality, generate responses, and operate the Services.

Except where expressly authorized by the applicable Customer, we do not use identifiable conversation content, uploaded content, memories, prompts, or other Personal Data submitted through the Services to train, retrain, fine-tune, or otherwise develop generalized artificial intelligence or machine learning models for use by other customers or third parties.

AI-generated responses may be inaccurate, incomplete, outdated, or otherwise unsuitable for a particular purpose. Users should independently evaluate and verify AI-generated outputs before relying upon them.

Depending on the features used, the Services may utilize search, retrieval, memory, observability, analytics, and other supporting technologies to improve response quality, maintain context across interactions, monitor service performance, and provide requested functionality.


4. What Is Our Purpose and Legal Basis for Processing Personal Data?

4.1 Providing and Operating the Services
  • To register, authenticate, administer, and provide access to the Services;

  • To administer accounts, subscriptions, licensing, and related customer relationships;

  • To process purchases, subscriptions, billing transactions, and payments relating to products, services, applications, and marketplace offerings;

  • To process voice inputs, text inputs, uploaded content, and other information necessary to provide AI-powered functionality and generate responses;

  • To enable features such as conversation history, memories, personalization, and context retrieval;

  • To connect to and facilitate integrations with third-party systems and services authorized by you or the applicable Customer (for example, Microsoft 365, Shopify, Stripe, or other connected services);

  • To prevent fraud, abuse, unauthorized access, and other misuse of the Services; and

  • To monitor, analyze, operate, maintain, secure, support, troubleshoot, and improve the Services.

Legal basis:

  • Performance of a contract where we provide the Services directly to you; and/or

  • Legitimate business interests in providing, operating, maintaining, securing, supporting, and improving the Services.

4.2 Personalization (History and Memories)
  • To remember relevant context across sessions (for example, your role, preferences, ongoing tasks);

  • To show previous conversations or references you have chosen to keep; and

  • To adjust the behavior of the Services based on user, team, or Customer preferences and configurations (for example, domain-specific knowledge).

Certain Services may include conversation history, memory, personalization, or context retention features. These features may store information such as prior conversations, preferences, user-provided instructions, job roles, recurring tasks, or other information that helps improve continuity of interactions across sessions. Depending on the Services configuration, users, administrators, and applicable Customers may be able to review, modify, export, disable, or delete stored memories and conversation history through the Services. The availability of these controls may vary based on the specific Services and the settings configured by the applicable Customer.

Legal basis:

  • Your consent; or

  • Legitimate business interests in providing more effective, personalized, and user-friendly Services, subject to your right to object and/or disable such features.

You may be able to turn off, review, export, modify, or clear conversation history and memories through the Services settings or through controls made available by your administrator or the applicable Customer.

4.3 Security, Abuse Prevention and Service Quality
  • To protect the Services against misuse, fraud, unauthorized access, abuse, and security incidents;

  • To authenticate users and maintain the security, integrity, and availability of the Services;

  • To monitor, detect, investigate, prevent, and remediate technical issues, service disruptions, security events, and other operational issues;

  • To generate and maintain technical logs, telemetry, diagnostics, audit trails, and operational records (including, where enabled, interactions with third-party AI infrastructure);

  • To collect diagnostic, crash-reporting, troubleshooting, performance, and usage information necessary to operate, maintain, secure, support, and improve the Services; and

  • To monitor and analyze service performance, reliability, functionality, and user experience.

Legal Basis:

  • Legitimate interests in operating, maintaining, securing, supporting, monitoring, and improving the Services; and

  • Compliance with legal obligations, including obligations to maintain certain records, logs, and security-related information.

Where optional advanced logging, analytics, monitoring, or diagnostic functionality is enabled, we may rely on your consent, the applicable Customer's instructions, or another lawful basis permitted under applicable law.

4.4 Product Improvement and Research
  • To communicate information about the Services, our products, events, updates, and other offerings that may be of interest to you;

  • To analyze aggregated, de-identified, and/or pseudonymized usage information, understand how the Services perform, identify trends, troubleshoot issues, and improve the functionality, reliability, security, and user experience of the Services;

  • To develop, test, maintain, and enhance existing and future products, services, features, and functionality; and

  • To conduct business analysis, research, statistical reporting, and operational planning relating to the Services and our business.

Except where expressly authorized by the applicable Customer, we do not use identifiable conversation content, uploaded content, memories, prompts, or other Personal Data submitted through the Services to train, retrain, fine-tune, or otherwise develop generalized artificial intelligence or machine learning models for use by other customers or third parties.

Legal Basis:

  • Legitimate business interests in operating, maintaining, securing, supporting, analyzing, developing, and improving the Services, while implementing measures designed to reduce privacy risks (for example, aggregation, de-identification, or pseudonymization); and/or

  • Your consent where required by law or where directed by the applicable Customer.

4.5 Compliance and Legal Claims
  • To comply with legal, regulatory, compliance, tax, accounting, audit, reporting, law enforcement, court order, and other legal obligations; and

  • To establish, exercise, enforce, or defend legal rights, claims, investigations, disputes, or legal proceedings.

Legal Basis:

  • Compliance with legal obligations; and

  • Legitimate business interests in protecting our rights, interests, users, Customers, Services, and business operations, including managing and defending legal claims.


5. Cookies and Similar Technologies

If you use our websites we may use cookies or similar technologies:

  • Strictly necessary cookies to operate, secure, and administer our websites and Services;

  • Optional cookies and similar technologies (where used) for analytics, performance monitoring, functionality, personalization, and feature enhancements.

We use cookies and similar technologies to help operate, secure, and improve our websites and Services, understand how visitors use them, and enhance the user experience. Some cookies remain on your device until they expire or are deleted. These cookies may allow us to recognize your browser or device when you return to our websites. You can configure your browser settings to notify you when cookies are being used and, in some cases, refuse or delete cookies. Please note that disabling certain cookies may limit the functionality of our websites or Services. Where required by applicable law, we will obtain your consent before placing non-essential cookies or similar technologies on your device.

HubSpot: We may use HubSpot to support marketing, customer relationship management, website forms, analytics, and related business activities. HubSpot may use cookies or similar technologies to collect information about how visitors interact with our websites. For more information regarding HubSpot's privacy practices, please visit: https://legal.hubspot.com/privacy-policy.

Google Analytics: We may use Google Analytics to understand how visitors interact with our websites, measure website traffic, identify areas for improvement, and enhance the user experience. Google Analytics may collect information about your use of our websites through cookies and similar technologies. For additional information regarding Google's privacy practices, please visit: https://policies.google.com/privacy.

We and our service providers may also use similar technologies necessary to support authentication, security, shopping cart functionality, subscriptions, purchases, fraud prevention, and operation of marketplace features.


6. How Do We Share Your Personal Data?

We may share Personal Data with the following categories of recipients where necessary to provide, operate, secure, support, and improve the Services, comply with legal obligations, or otherwise as described in this Privacy Policy.

6.1 Customers and Authorized Administrators

If you access or use the Services through a Customer that administers or controls your access to the Services, the Customer and its authorized administrators may access information relating to your use of the Services, including account information, usage information, logs, reports, configuration settings, conversation history, memories, integrated content, and other information made available through the Services, subject to the Customer's policies and configuration choices.

6.2 Technology Service Providers

We may share Personal Data with third-party service providers that support the operation of the Services, including providers of cloud hosting, infrastructure, databases, artificial intelligence technologies, authentication, communications, security, monitoring, diagnostics, analytics, search, retrieval, memory, personalization, and customer support services. These providers process Personal Data solely as necessary to provide services to Company and are subject to contractual obligations regarding privacy, confidentiality, and data protection.

6.3 Integration Partners

If you or the applicable Customer connect the Services to third-party systems (for example, Microsoft 365), we may share and receive Personal Data and other information with and from those systems in accordance with the permissions granted through the applicable third-party service. The categories of information shared depend on the integrations enabled and the permissions authorized by you or the applicable Customer.

6.4 Payment, Commerce, and Fulfillment Providers

When you purchase products, subscriptions, applications, marketplace offerings, or other Services, we may share Personal Data with payment processors, ecommerce providers, subscription management providers, shipping carriers, logistics providers, and transaction partners to process payments, administer subscriptions, fulfill orders, prevent fraud, and provide related services.

Additional information regarding certain providers is available in their privacy policies:

  • Stripe: https://stripe.com/privacy

  • Shopify: https://www.shopify.com/legal/privacy

6.5 Professional Advisors and Authorities

We may share Personal Data with auditors, accountants, legal advisers, insurers, regulators, courts, law enforcement agencies, governmental authorities, or other third parties where required or permitted by law, including to comply with legal obligations or establish, exercise, or defend legal claims.

6.6 We Do Not Sell Your Personal Data.


7. Where Is Personal Data Processed or Controlled?

We are a United States company. We process Personal Data in accordance with applicable data protection laws and implement safeguards designed to protect Personal Data when it is transferred internationally. We process Personal Data in the United States and other countries where we, our affiliates, or our service providers operate. As a result, Personal Data may be transferred to, stored in, or accessed from countries outside your jurisdiction, including countries that may not provide the same level of data protection as your home country.

Where we transfer personal data to such countries, we ensure that appropriate safeguards are in place, such as:

  • An adequacy decision by the European Commission or relevant authority; and/or

  • Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional technical and organizational measures; and/or

  • The EU–US Data Privacy Framework or UK–US Data Bridge, where applicable.

You may contact us for more information regarding international transfers and applicable safeguards, subject to appropriate confidentiality restrictions.


8. Data Retention

We retain Personal Data only for as long as necessary for the purposes described in this Privacy Policy, to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, and protect our legal rights. Retention periods may vary depending on the nature of the information, the Services used, applicable legal requirements, and settings established by you, your administrator, or the applicable Customer.

By default, we apply the following retention principles:

  • Account, subscription, billing, transaction, and business records: retained for the duration of the applicable account, contract, or business relationship, plus any additional period reasonably necessary to comply with legal obligations, maintain business records, or resolve disputes.

  • Conversation history, memories, personalization data, and other user-generated content: retained until deleted by you or the applicable Customer, until the applicable account is closed, or as otherwise configured through the Services, subject to backup and retention processes.

  • Technical logs, telemetry, diagnostics, security records, and operational data: retained for periods reasonably necessary to support security, troubleshooting, system reliability, compliance, and operation of the Services.

  • Website inquiries, marketing communications, support requests, and related communications: retained for a reasonable period necessary to respond to requests, provide support, maintain records, comply with legal obligations, and resolve disputes.

  • Backup data: retained in accordance with our backup and disaster recovery processes and deleted or overwritten pursuant to applicable retention schedules.

If you request deletion of your Personal Data, we will delete or de-identify the information from active systems as required by applicable law. Deleted information may remain in backup systems until those backups are overwritten or expire, unless retention is required by law or our contractual obligations to the applicable Customer.


9. Security

We implement reasonable technical, administrative, and organizational measures designed to protect Personal Data from unauthorized access, disclosure, alteration, loss, misuse, or destruction. These measures include, where appropriate:

  • Encryption in transit and at rest;

  • Access controls designed to limit access to authorized personnel;

  • Security monitoring, incident detection, and response procedures;

  • Regular backups and recovery processes;

  • Employee training and confidentiality obligations; and

  • Vendor due diligence and contractual safeguards for service providers that process Personal Data on our behalf.

No method of transmission over the Internet or method of electronic storage is completely secure. However, we continuously work to protect the Services and improve our security practices. If we become aware of a Personal Data breach that may pose a risk to individuals, we will provide any required notifications to affected individuals, the applicable Controller, regulators, or other authorities as required by applicable law.


10. Your Rights

Depending on your location and applicable law (for example, GDPR, UK GDPR, Swiss FADP, or other privacy laws), you may have the following rights in relation to your Personal Data:

  • Right of access – to request access to and copies of your Personal Data, subject to applicable law. Where permitted by law, we may charge a reasonable fee for additional copies or repetitive requests.

  • Right to rectification – to request correction of Personal Data that you believe is inaccurate or incomplete;

  • Right to erasure – to request deletion of your Personal Data in certain circumstances, to the extent permitted by law;

  • Right to restriction – to request that we restrict processing of your Personal Data in certain circumstances;

  • Right to data portability – to receive your Personal Data in a structured, commonly used, and machine-readable format and, where applicable, transmit it to another Controller;

  • Right to object – to object to processing of your Personal Data based on our legitimate interests and to opt out of certain uses of your Personal Data; and

  • Right to withdraw consent – where processing is based on your consent, to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

Where a Customer acts as the Controller for Personal Data processed through the Services, we may direct your request to the applicable Customer or work with that Customer to respond to your request. To exercise your rights, please contact us using the details in Section 14 below. We may request additional information to verify your identity before responding to your request. We will respond to your request within the time period required by applicable law. You also have the right to lodge a complaint with a supervisory authority, including in the EU/EEA, the United Kingdom, or Switzerland, where applicable.


11. Children

The Services are not intended for individuals under 18 years of age, and we do not knowingly collect Personal Data from individuals under 18. If we become aware that we have collected Personal Data from an individual under 18, we will take reasonable steps to delete such information. Where access to the Services is provided through a Customer, the applicable Customer is responsible for ensuring that only authorized users are permitted to access and use the Services.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Services, applicable law, our data processing practices, or other operational requirements. When we make changes, we will post the updated Privacy Policy and revise the "Last Updated" date at the top of this Privacy Policy. If we make material changes, we may take additional steps to notify you, which may include notices within the Services, email communications, website notices, account notifications, or other reasonable means of communication, where appropriate.


13. Company and Contact Information

If you have questions or concerns about this Privacy Policy or our data practices, you can contact us at:

  • RealWear, Inc., a Washington corporation located at 4400 NE 77th Avenue, Suite 275, Vancouver, WA 98662, United States.

  • Email: legal@realwear.com


For California Residents:

Under California Civil Code Section 1798.83 (also known as S.B. 27), if you are a California resident and your relationship with Company is primarily for personal, family, or household purposes, you may request certain information regarding Company's disclosure, if any, of Personal Data to third parties for their direct marketing purposes. To make such a request, please contact legal@realwear.com. You may make such a request once per calendar year. If applicable, we will provide, by email, a list of the categories of Personal Data disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year, together with the names and addresses of those third parties. Please note that not all disclosures of Personal Data are subject to S.B. 27.

© 2024 RealWear Inc. All rights reserved.
© 2024 RealWear Inc. All rights reserved.
© 2024 RealWear Inc. All rights reserved.