Privacy Policy
Last updated: 2026-05-23
This Privacy Policy explains how POSHEAR ("POSHEAR", "we", "us", "our"), a company established in the European Union, collects, uses, discloses, and protects personal information when you visit our website, join our waitlist, or interact with our communications (the "Service"). It applies to visitors in the European Economic Area (EEA), the United Kingdom, the United States (including California and Texas), and elsewhere.
This is a startup-ready template for informational purposes only and is not legal advice. Have qualified counsel in your jurisdiction review before publication.
1. Controller and Contact
For the purposes of the EU/UK General Data Protection Regulation (GDPR), POSHEAR is the data controller of personal data processed through the Service. You can reach us at info@poshear.com for any privacy question, request, or complaint.
2. Personal Data We Collect
- Contact data — email address you provide to join the waitlist or to contact support.
- Consent and preference data — your cookie and communications choices, the timestamp and version of the policy in force when consent was given.
- Technical data — a one-way hash of your IP address, user-agent string, approximate country derived from your IP, Global Privacy Control (GPC) signal where sent by your browser, and timestamps. Raw IP addresses are not stored.
- Analytics data — aggregate, cookieless usage statistics via Plausible, and only where required, with your consent.
- Communications — content of messages you send us and email delivery metadata (e.g., bounces, unsubscribes).
We do not knowingly collect data from anyone under 18. We do not process health or hearing data through the Service at this stage. If the POSHEAR product later offers features that process such information, we will provide a separate notice, obtain explicit consent where required, and update this Policy accordingly.
3. Purposes and Legal Bases (GDPR Art. 6)
- Operate the Service and waitlist — performance of a contract or pre-contractual steps you request (Art. 6(1)(b)).
- Send transactional communications (e.g., double opt-in verification, unsubscribe confirmations) — performance of a pre-contractual measure (Art. 6(1)(b)) and your consent for non-essential updates (Art. 6(1)(a)).
- Security, abuse prevention, rate limiting, and audit logging — our legitimate interest in protecting the Service and our users (Art. 6(1)(f)).
- Analytics — your consent (Art. 6(1)(a)) where required.
- Compliance with legal obligations — including responding to data subject requests and lawful authority requests (Art. 6(1)(c)).
4. How We Share Personal Data
We do not sell personal information and we do not engage in "sharing" of personal information for cross-context behavioral advertising (as defined under California law). We disclose data only to:
- Service providers (processors) acting under written instructions and a Data Processing Agreement: Lovable Cloud (managed backend and database hosting), Cloudflare (edge delivery and DDoS protection), Plausible (privacy-preserving analytics when consented), and our transactional email provider.
- Professional advisers (lawyers, accountants, auditors) under duties of confidentiality.
- Authorities where required by law, regulation, court order, or to protect our legal rights, users, or third parties.
- Successors in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections and notice where required by law.
5. International Data Transfers
Where personal data is transferred outside the EEA or the United Kingdom to a country not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021/914) and, where applicable, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures (e.g., encryption in transit and at rest, IP hashing, access controls). Copies are available on request.
6. Retention
- Waitlist email (verified): until you unsubscribe or until product launch + 12 months.
- Unverified waitlist entries: deleted automatically after 30 days.
- Consent records: 5 years from collection, to evidence lawful processing.
- Security audit logs and IP hashes: 12 months.
- Email suppression list: retained indefinitely to honor unsubscribe requests.
- Support correspondence: 24 months after resolution.
We delete or anonymize personal data when the applicable retention period ends.
7. Security
We implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit (TLS) and at rest, hashed IP addresses, hashed and salted authentication tokens, role-based access controls, audit logging, isolated environments for production data, vendor due diligence, and incident response procedures. No system is perfectly secure; in the event of a personal data breach affecting EU/UK data subjects we will notify the competent supervisory authority within 72 hours where required by Art. 33 GDPR, and affected individuals where Art. 34 applies.
8. Your Rights — EEA, UK, and Switzerland (GDPR)
You have the right to:
- access your personal data and obtain a copy (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erase data ("right to be forgotten") (Art. 17);
- restrict processing (Art. 18);
- data portability in a structured, machine-readable format (Art. 20);
- object to processing based on legitimate interests or direct marketing (Art. 21);
- withdraw consent at any time, without affecting prior lawful processing (Art. 7(3));
- lodge a complaint with your local supervisory authority (Art. 77) — without prejudice to any other administrative or judicial remedy.
We do not engage in solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
9. Your Rights — United States
Depending on your state of residence, you may have additional rights, including under the California Consumer Privacy Act as amended by the CPRA, the Texas Data Privacy and Security Act (TDPSA), and other state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Oregon OCPA, and others). These rights generally include:
- the right to know what personal information we collect and how we use and disclose it;
- the right to access and to obtain a copy of your personal information;
- the right to correct inaccurate personal information;
- the right to delete personal information, subject to legal exceptions;
- the right to opt out of the "sale" or "sharing" of personal information and of targeted advertising — we do not sell or share personal information and do not engage in targeted advertising;
- the right to limit the use of sensitive personal information (we do not process sensitive personal information through the waitlist Service);
- the right to non-discrimination for exercising your rights;
- under Texas TDPSA, the right to appeal a refusal to act on a request, and to contact the Texas Attorney General if your appeal is denied.
We honor Global Privacy Control (GPC) signals as a valid opt-out request where applicable. Authorized agents may submit requests on your behalf with verification. For details, see our CCPA/CPRA notice and Texas TDPSA notice.
10. How to Exercise Your Rights
Email us at info@poshear.com or use our Privacy Center. We will respond within the time required by applicable law (generally within one month under GDPR and 45 days under U.S. state laws, extendable where permitted). We may need to verify your identity before acting. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive requests, as permitted by law.
11. Cookies and Similar Technologies
See our Cookie Policy. EEA/UK visitors are asked for prior, freely given, specific, informed, and unambiguous consent for non-essential cookies. U.S. visitors are presented with a notice and an opt-out mechanism consistent with applicable state law.
12. Children
The Service is not directed to children under 18 and we do not knowingly collect data from them. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be highlighted on this page with a new "Last updated" date and, where appropriate, communicated by email or in-product notice. We retain prior versions for reference.
14. Contact
Contact us at info@poshear.com for privacy questions, rights requests, or to designate an authorized agent. EEA/UK residents may also lodge a complaint with their local supervisory authority.