Privacy Policy
Learn more about Nelpo Privacy Policy
Privacy Policy (GDPR Compliant Version)
Effective Date: March 12, 2026
Official URL of Privacy Policy: https://nelpo-hearing.com/privacy-policy/
(Please replace with your valid static HTML page URL, which must comply with: standard http/https format, no login/jump required, automatable reading, not a blog/cloud note/file format, and consistent with the content displayed in your APP/website)
This Privacy Policy (hereinafter referred to as “this Policy”) is formulated by [Shenzhen SNM Tech Co.,Ltd.] (hereinafter referred to as “we”) to clarify the rules for us to collect, use, store, transmit, and disclose your personal data, protect your personal data rights and interests, and strictly comply with the requirements of the European Union’s General Data Protection Regulation (GDPR) and relevant laws and regulations. Whether you are located within the European Union or not, this Policy shall apply if you are an EU resident or if the personal data we process belongs to an EU resident.
Please carefully read and understand the entire content of this Policy before using our products/services. Your use of our products/services indicates that you agree to our processing of your personal data in accordance with this Policy.
1. Information of the Data Controller
Data Controller: Shenzhen SNM Tech Co.,Ltd.
Registered Address/Principal Place of Business: Room 403, Building C, Dunfa Industrial Park, Hangcheng Avenue, Guxing Community, Xixiang Subdistrict, Bao’an District, Shenzhen, Guangdong, China
Contact Email (for Data Protection): emily.wang@snmtek.com
Data Protection Officer (DPO, if applicable): Emily, Contact Email: emily.wang@snmtek.com
2. Scope and Methods of Collecting Personal Data
2.1 Types of Personal Data Collected
We only collect personal data necessary for the functions of our products/services, adhering to the principle of “data minimization” and not collecting information irrelevant to the services. Specifically, it includes:
-
- Identity Data: Name, email address, phone number, ID/passport number (if involving cross-border services or identity verification);
-
- Usage Data: Records of your behavior when using our products/services, including browsing history, click records, usage duration, operation preferences, and device information (device model, operating system, IP address, browser type);
-
- Transaction Data: If you use paid services, including payment amount, payment method, transaction records, and shipping address (if applicable);
-
- Consent Data: Records of your consent to personal data processing, date of consent, and records of withdrawal of consent;
-
- Special Category Personal Data: Without your explicit and separate written consent, we will never collect data related to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or sexual life or sexual orientation (special category data specified in Article 9 of GDPR).
2.2 Methods of Collection
-
- Active Provision: Personal data you actively provide to us when registering an account, filling out forms, submitting inquiries, or conducting transactions;
-
- Automatic Collection: Through our websites, APPs, server logs and other technical means, automatically collect usage data and device data generated when you use our products/services (such as IP address, browser type, etc.). Such data does not identify individuals alone and is only used for service optimization and security protection;
-
- Third-Party Sources: Only with your explicit consent or as permitted by law, we will obtain your necessary personal data from legally compliant third parties (such as payment service providers, identity verification service providers), and we will conduct compliance verification on the data provided by third parties.
3. Purposes and Legal Bases for Using Personal Data
3.1 Purposes of Use
We use your personal data only for the following legitimate purposes and within the scope necessary to provide services:
-
- To provide you with products/services and complete core functions such as account registration, login, transactions, and inquiry responses;
-
- To optimize the product/service experience, analyze user behavior, and improve function design, service stability and security;
-
- To send you product updates, service notifications, and important reminders (non-marketing);
-
- To handle your complaints and feedback and resolve problems arising in the service process;
-
- To comply with legal and regulatory requirements and fulfill legal obligations (such as tax declaration, compliance audit);
-
- To prevent fraudulent, theft and other illegal activities and protect the security of your account and our legitimate rights and interests;
-
- To send you marketing information with your explicit consent (you can withdraw your consent at any time).
3.2 Legal Bases (Article 6 of GDPR)
The legal bases for us to process your personal data include:
-
- Your explicit consent (such as consent to receive marketing information, consent to collect device data);
-
- Performance of the contract with you, which is necessary to provide the products/services you request;
-
- Compliance with our legal obligations (such as legal requirements related to tax and data retention);
-
- Pursuit of legitimate interests (such as optimizing services, preventing fraud), and such legitimate interests do not harm your personal data rights and interests.
4. Rules for Storing Personal Data
4.1 Storage Location
We store your personal data on servers located within the European Union; if it is necessary to transmit data outside the European Union due to business needs, we will strictly comply with the requirements of Articles 48-50 of GDPR on cross-border data transmission:
-
- Transmit only to countries/regions recognized by the European Commission as having “adequate level of data protection”;
-
- If transmitting to a country/region not recognized, we will sign EU Standard Contractual Clauses (SCCs) or take appropriate safeguards such as encryption and anonymization to ensure that the level of data protection is not lower than the requirements of GDPR;
-
- Before cross-border data transmission, we will inform you of the purpose of transmission, the recipient, safeguards and other information (if it involves your core rights and interests).
4.2 Storage Period
We follow the principle of “storage limitation” and only store your personal data for the shortest period necessary to achieve the purpose of collection:
-
- Core service-related data (such as account information, transaction records): stored for 1 year after you cancel your account, or for the retention period required by law (such as tax retention requirements);
-
- Usage data (such as browsing history, operation logs): stored for 6 months after the purpose of service optimization is achieved, or as otherwise required by law;
-
- Consent records: stored for 6 months after you withdraw your consent, or for a longer period required by law;
-
- If the data storage period expires, we will take measures such as deletion and anonymization (making it impossible to identify individuals) to completely destroy the relevant data, which shall not be used for any other purposes.
4.3 Storage Security
We take technical and management measures that meet the requirements of GDPR to ensure the security of your personal data and prevent data leakage, damage, loss, tampering, and illegal access:
-
- Technical Measures: Adopt SSL/TLS encrypted transmission, encrypted data storage, access control, intrusion detection and prevention systems, and regular security audits;
-
- Management Measures: Clarify data access rights, provide data protection training for employees, sign confidentiality agreements, and establish data security management systems;
-
- Data Breach Response: In the event of a personal data breach, we will notify the EU Data Protection Authority (DPA) and the affected you within 72 hours (if the breach may pose a high risk to your rights and interests), and take remedial measures to reduce risks.
5. Disclosure and Sharing of Personal Data
We commit not to sell, rent, or share your personal data to any irrelevant third parties. We will only disclose or share it in accordance with the requirements of GDPR in the following circumstances:
-
- Obtain your explicit written consent;
-
- To perform the contract with you, share with necessary third-party service providers (such as payment service providers, logistics service providers), and only share the minimum scope of data necessary to provide services. At the same time, sign a Data Processing Agreement (DPA) with third parties, requiring them to comply with GDPR and relevant regulations and strictly protect the data;
-
- Comply with legal and regulatory requirements and respond to legitimate requests from judicial and administrative authorities (such as court subpoenas, administrative investigations);
-
- Necessary disclosure in emergency situations (such as preventing fraud, protecting personal safety) to protect your legitimate rights and interests, our legitimate rights and interests, or public interests;
-
- In the event of company merger, division, acquisition, liquidation, etc., personal data is transferred as part of the assets, and the transferee shall continue to comply with this Policy and GDPR requirements.
6. Your Personal Data Rights (Granted by GDPR)
As an EU resident, you have the following personal data rights in accordance with the law, and we will provide you with relevant services free of charge without unreasonable delay:
-
- Right of Access: You have the right to require us to confirm whether we are processing your personal data, and to obtain a copy of your personal data, processing purposes, storage period, sharing objects and other relevant information;
-
- Right to Rectification: If your personal data is inaccurate or incomplete, you have the right to require us to correct it in a timely manner;
-
- Right to Erasure (Right to be Forgotten): In the following circumstances, you have the right to require us to delete your personal data: the data is no longer necessary for the purpose of use, you withdraw your consent, our processing behavior is illegal, or the law requires deletion;
-
- Right to Restriction of Processing: You have the right to require us to suspend the processing of your personal data (such as objection to the accuracy of data, illegal processing behavior) until the relevant issues are resolved;
-
- Right to Data Portability: You have the right to require us to provide a copy of your personal data in a structured, commonly used, machine-readable format, and may require us to transmit the data to another data controller (if technically feasible);
-
- Right to Object: You have the right to object to our processing of your personal data based on “legitimate interests” or “marketing purposes”, and we will stop the relevant processing (unless there are legitimate reasons or legal requirements to continue processing);
-
- Right to Withdraw Consent: You can withdraw your consent to personal data processing at any time (such as withdrawing consent to receive marketing information). The withdrawal of consent does not affect the legal data processing we conducted based on your consent before the withdrawal.
If you wish to exercise the above rights, please contact us through the contact email provided in Section 1 of this Policy. We will respond to your request within 30 working days (complex cases can be extended to 60 working days, and we will inform you in a timely manner).
7. Use of Cookies and Similar Technologies
We use Cookies and similar technologies (such as pixel tags) to optimize the website/APP experience, analyze usage behavior, and ensure service security. The specific rules are as follows:
-
- Necessary Cookies: Used to implement core service functions (such as account login, transaction security), which cannot be disabled, otherwise it will affect the use of services;
-
- Non-necessary Cookies: Used for analyzing usage behavior, personalized recommendations, and marketing promotions. You can disable them in browser/APP settings, and disabling them will not affect the use of core services;
-
- When you visit for the first time, we will clearly inform you of the type and purpose of Cookies, and use non-necessary Cookies only after obtaining your consent. You can change your consent settings at any time.
8. Update and Notification of the Policy
We will update this Privacy Policy from time to time in accordance with the updates of GDPR and relevant laws and regulations, and changes in products/services. The updated policy will be notified to you through our official website (i.e., the URL provided at the beginning of this Policy), APP pop-up windows, etc., and the updated policy will take effect on the date of publication.
If the updated content involves your core rights and interests (such as the scope of data collection, purpose of use, your rights), we will notify you 7 working days before the update. Your continued use of our products/services indicates that you agree to the updated policy.
9. Complaints and Dispute Resolution
If you believe that our personal data processing behavior violates GDPR or this Policy, you can first contact us through the contact email provided in Section 1 of this Policy, and we will investigate and handle it in a timely manner.
If you are not satisfied with our handling result, you have the right to file a complaint with the EU Data Protection Authority (DPA) in your country/region, and we will actively cooperate with the DPA’s investigation.
10. Others
The final interpretation right of this Policy belongs to Shenzhen SNM Tech Co.,Ltd. If this Policy conflicts with GDPR and relevant laws and regulations, GDPR and relevant laws and regulations shall prevail.