This privacy policy is designed to inform users of The Sync Project website, mobile application and services (collectively, the "Service") about how Bose Corporation (“Bose”, “we” and “us”) gathers and uses personal information collected by us in connection with use of the Service. You may have been invited to use, download or install the Service from a third party or directly by The Sync Project or Bose as part of a new or an ongoing study or research project (such third party, the "Institutional Client"), or you may have subscribed or downloaded and installed the Service for your personal use. We will take reasonable steps to protect user privacy consistent with the guidelines set forth in this policy and with applicable U.S. and European Union laws. In this policy, "user" or "you" means any individual using the Service, whether by downloading or browsing the Service, registering with us by creating an account, or participating in any other activities available through the Service. Our Privacy Policy is incorporated as part of the Sync End User Terms and Conditions. Please read this Policy and our End User Terms and Conditions carefully before using our Services and read them again when we notify you of changes to the Privacy Policy that may be made from time to time. BY ACCESSING OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTAND, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY AND OUR END USER TERMS AND CONDITIONS. IF YOU DO NOT AGREE TO THESE TERMS, DO NOT USE THE SERVICE.

What Information Do We Collect?

Personal Information: We collect the following personal information in connection with the Service: (a) when you register to use the Service, whether in your individual capacity or on behalf of an organization, we may collect the personal information that is disclosed on our online on in-application registration form, such as your name, email address, Username, unique device identifier or other device identifier ("UDID"), and other information detailed therein; (b) if you communicate with us by email, we will collect your email address; and All of this information is referred to in this Policy as "Personal Information".

Non-personal information:

"Non-personally identifiable data" or "non-personal data" as used in this Agreement means information that does not directly identify you, including, but not limited to, data that has been "aggregated" and/or "de-identified", such that any personally identifiable data has been removed.

1.    Mobile Tracking Information: We may collect non-personally identifiable data from you, from the mobile device in which the Software is installed, and from your use of the Software, which may include, but is not limited to: (i) device properties of the mobile device on which the Software is installed; (ii) information about the device software platform and firmware; (iii) information about the mobile phone carrier; (iv) Information about the availability, type and strength of the wireless connection (v) Information about other installed applications and services (vi) other non-personal data as reasonably required by us to enhance the Software and to demonstrate or test any health impact on users due to their use of the Software. We may also use Mobile Tracking technologies such as cookies, web beacons, pixel tags and clear GIFs, as well as embedded code in the Services itself, in order to operate the Service efficiently and to collect data related to your usage of and interaction with the Service, the web and general use and interaction with your mobile device. and your location and speed of movement while you use your mobile device (all such use, "Mobile Use"). We do not access or collect the content of your Mobile Use, such as conversations or messages.

2.    We may collect:

1.    certain demographic information, such as age and gender, which are disclosed by you to us.

2.    user interaction data which includes, but is not limited to, location samples, accelerometer and other phone sensor samples, smartphone actions, and smartphone screen-time related to, or resulting from, your use of the Services.

3.    Data on your use of music services, including but not limited to time and duration of music listening and the names, identifiers, associated metadata and sequence of the specific music tracks listened to. We may also collect start, pause, play, stop and volume information.

4.    Information on your physiology and health through any devices and sensors you choose to connect with the Services. This includes, but is not limited to your heart rate and heart rate variability data, sleep quality and duration, brainwave patterns, skin conductance, respiration rate, etc.

5.    User survey data: if you use the Services to respond to surveys and questions from us or an Institutional Client, we may collect the information you provide in your responses, such as health and medical information (if any), your answers or submissions to study surveys and health and clinical questionnaires, inferred mental, emotional or physical health status for specific conditions, and survey alerts.

6.    Information on contextual and environmental parameters – weather, type of activity engaged in, etc.

All the above information will be collected and stored in a de-identified manner.

Log Data: Our servers automatically record information ("Log Data") created by your use of the Services. Log Data may include information such as your IP address, browser type, operating system, location, device, and cookie information. We receive Log Data when you interact with our Services, for example, when you visit our Websites, sign into our Services, or interact with our email notifications. We use Log Data to provide our Services and to measure, customize, and improve them collect and use in the aggregate.

Google Analytics: The Service uses Google Analytics, a web analytics service provided by Google, Inc. ("Google"). That tool uses cookies to help us analyze how users use the Service. The information generated by the cookies about your use of the Service (including your IP address) will be transmitted to and stored by Google under its privacy policy: 

You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of the Service. By using the Service, you consent to the processing of your information by Google in the manner and for the purposes set out above.

How Do We Use the Information We Collect?

Personal Information and Non-personal information: We will use and store Personal Information and Non-personal Information for the purpose of delivering the Service to you and where applicable, to our Institutional Clients, and to analyze and enhance the operation of the Service. We store Personal Information, Mobile Tracking Information (including Mobile Use) and other non-personal information, and where applicable, any information obtained from our Institutional Clients for proprietary analysis and development of a personalized behavioral index for each user or where applicable, the Institutional Client. Personal Information and Mobile Tracking Information may also be used for the internal operational and administrative purposes of the Service.

We will not use Mobile Tracking Information (including Mobile Use) or Personal Information to direct marketing or advertising to target users, through their use of the Service. We may employ third party ad serving technologies that use certain methods to collect information as a result of ad serving through the Software, including using demographic and location information as well as information logged from your hardware or device to ensure that appropriate advertising is presented within the Software. These advertising companies collect and use information under their own privacy policies. These ad serving technologies may be integrated into the Software; if you do not want to be subject to this technology, do not use or access the Software.

We will also use non-aggregate, non-personal information for research purposes to understand personalized effects of music on health and to improve the software and services for individual users.

User-Generated Content: If you use our user-generated content services, like posting a playlist, question, answer or blog, you should be aware that any personally identifiable information you submit there can be read, collected, or used by other users and could be used to send you unsolicited messages. We are not responsible for the personally identifiable information you choose to submit in these forums.

Aggregate Information: We will create statistical, aggregated data relating to our users and the Service for analytical purposes. Aggregated data includes data derived from Personal Information and obtained by us from other sources; in its aggregated form and does not relate to or identify any individual (such data "Aggregate Information"). We use Aggregate Information to understand our customer base and to develop, improve and market our Services, and for research and development of the Software and future products and services (including but not limited to research with respect to the health effects of music and the impact of use of the Software on health and wellbeing).

Legal Exception: Under certain circumstances Personal Information may be subject to disclosure pursuant to judicial or other government subpoenas, warrants, or orders. As such, notwithstanding the above, we may in any event use Personal Information, Mobile Tracking Information, Aggregate Information and any other information collected and created through the Service to the extent required by law or legal process, to resolve disputes, to enforce our agreements (including this Privacy Policy and the Sync End User Terms and Conditions) with you, or if in our reasonable discretion use is necessary to protect our legal rights or to protect third parties.

Email Communications: If you register and provide your email address, we may send you administrative emails. If you wish to opt out of these emails, you may do so by following the "unsubscribe" instructions in the email.

Account Closure: If any of your account information appears to be incorrect, please contact us and let us know. If you close your account, we will delete your account information and any Personal Information associated with your account, but other information you submitted that is not associated with you personally may not be deleted.

What Information Do We Disclose to Third Parties?

Personal Information: We will not disclose your Personal Information to any third party except as follows:

1.    We may disclose your Personal Information to an Institutional Client on whose behalf the information was collected.

2.    We will not sell your personal data to third parties or disclose your personal data other than as specified in this Section. Personal data may be disclosed by us to our affiliates, agents and contractors to collect and process such data on our behalf. We may disclose your personal data to third parties as required by law enforcement or other government officials. We may also disclose your personal data to third parties when we have a reason to believe that a disclosure is necessary to protect our or our affiliates’ rights, property, operations, users or others who may be harmed or may suffer loss or damage, or to combat fraud and/or comply with a judicial proceeding, court order, or legal process served on us or our affiliates.

3.    We may use and disclose to our partners and contractors the collected non-personal data, including, but not limited to, for purposes of enabling and restricting the operation of the Software, analyzing usage of the Software, research and development of the Software and future products and services (including but not limited to research with respect to the health effects of music and the impact of use of the Software on health and wellbeing), and advertisement serving.

4.    We may disclose your Personal Information to third party contractors engaged to provide services on our behalf ("Contractors"), such as performing marketing, analyzing data and usage of the Service, operating the Service or providing support and maintenance services for the Service, or providing customer service. We enter into agreements with all Contractors that require Contractors to use the Personal Information they receive only to perform services for us.

5.    We may disclose your Personal Information when we have your consent to share the information.

Non-personal Information: We will not disclose your Mobile Tracking Information to any third parties except as follows:

1.    We may disclose your Mobile Tracking Information to Contractors, in order to analyze the performance of the Service and the behavior of users, and to operate and improve the Service.

2.    We may disclose your Mobile Tracking Information when we have your consent to share the information.

Aggregate Information: We may disclose Aggregate Information to third parties, such as potential customers, business partners, advertisers, and funding sources, in order to describe our business and operations. We may also license and sell Aggregate Information.

Additional Disclosures: We reserve the right to disclose any information we collect in connection with the Service, including Personal Information and Mobile Tracking Information, (a) to any successor to our business as a result of any merger, acquisition, asset sale or similar transaction; and (b) to any law enforcement, judicial authority, or governmental or regulatory authority, to the extent required by law or if in our reasonable discretion disclosure is necessary to enforce or protect our legal rights or to protect third parties.

Privacy Settings

We are happy to allow you to review or amend your email address or account information held in our database, at any time. Please contact us by sending an email to: . If you would like your account permanently removed from our database, please contact us at . We will promptly delete your account and you will no longer receive marketing emails from us.

Termination of your account will not delete all Personal Information or Non-personal Information that we hold relating to you, and we will retain this information and may use and disclose it in accordance with this Privacy Policy. We may still contact users who have deleted their information for administrative purposes in connection with the Services.

General

Security: We use reasonable security precautions to protect the security and integrity of your Personal Information in accordance with this policy and applicable law. We will take commercially reasonable measures to ensure that any personal information is stored securely and separate from the non-personal information such that no direct connections can be made between an individual’s identity and any associated de-identify non-personal information. However, no Internet transmission is completely secure, and we cannot guarantee that security breaches will not occur. Without limitation of the foregoing, we are not responsible for the actions of hackers and other unauthorized third parties that breach our reasonable security procedures. Nor are we responsible for other breaches to your Personal Information outside our control, such as resulting from loss, theft or unauthorized use of your mobile device.

Links: The Services may contain links to other websites. We are not responsible for the privacy practices or the content of those websites. Users should be aware of this when they leave our Service and are encouraged to review the privacy statements of each third party website. This Privacy Policy applies solely to information collected by the Service.

Amendments: We may modify or amend this policy from time to time. If we make any material changes, as determined by us, in the way in which Personal Information or Non-personal Information is collected, used or transferred, we will notify you of these changes by modification of this Privacy Policy, which will be available for review by you at the Service. Notwithstanding any modifications we may make, any Personal Information and Non-personal Information collected by us from you will be treated in accordance with the privacy policy in effect at the time information was collected, unless we obtain your consent otherwise.

Children: We do not knowingly collect or maintain personally identifiable information from persons under 18 years of age, and no part of the Service is directed at persons under 18. If you are under 18 years of age, then please do not use the Service. If we learn that personally identifiable information of persons less than 18 years of age has been collected without verifiable parental consent, then we will take the appropriate steps to delete this information. To make such a request, please contact us at .

Service Visitors from outside the United States: Bose and its servers are located in the United States and are subject to the applicable state and federal laws of the United States. If you choose to access or use the Service, you consent to the use and disclosure of information in accordance with this privacy policy and subject to such laws.

Policy last updated on: February 20, 2018