CODE27 PRIVACY POLICY

Last Updated: October 27, 2025

Effective Date: October 27, 2025

Introduction

SyBran Technology Limited ("Company," "we," "us," or "our"), a company organized under the laws of the People's Republic of China, values the privacy of individuals who use our products and services. This Privacy Policy ("Policy") explains how we collect, use, disclose, store, and protect personal information about users of our Services.
Who We Are: We are SyBran Technology Limited, the company behind CODE27, an AI companion device and platform.

What This Policy Covers: This Policy applies to personal information collected through:
- The CODE27 hardware device ("Device")
- The CODE27 mobile application ("App")
- Our website at code27.co and all subdomains ("Website")
- All AI companion services, including 3D character animation, voice interaction, image processing, and audio processing
- Contests, sweepstakes, competitions, and promotional activities ("Promotions")
- Public galleries, voting features, and community interactions
- Customer support and communications
(collectively, the "Services")

Your Consent: By using our Services, you acknowledge that you have read, understood, and agree to the data practices described in this Policy. If you do not agree with this Policy, please do not use the Services.
Contact Information: For privacy questions or to exercise your privacy rights, contact us at privacy@code27.co.

Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Data Processing Architecture
  4. Event Logs and Safety Monitoring
  5. Visual Data and Biometric Information
  6. How We Share Your Information
  7. Promotions and Public Galleries
  8. Minors (Ages 13-17)
  9. Data Retention
  10. Cookies and Tracking Technologies
  11. AI-Specific Disclosures
  12. Your Privacy Rights
  13. California Privacy Rights (CCPA/CPRA)
  14. International Data Transfers
  15. Security
  16. Changes to This Policy
  17. Contact Us
  18. EU/UK Territorial Scope and Representative Assessment


1. Information We Collect

We collect information you provide to us, information automatically collected from your use of the Services, and information from third parties.

1.1 Information You Provide

Account Information: When you create an account, we collect:
- Name or display name/pen name
- Email address
- Password (stored as a cryptographic hash)
- Date of birth (for age verification)
- Country/region
- Account preferences and settings

Payment Information: We use third-party payment processors to handle transactions. We do not directly store complete credit card numbers or banking credentials on our servers. Our payment processors include:
- Airwallex (for Device and accessory purchases): Collects payment details including name, billing address, and payment method information. Privacy policy: https://www.airwallex.com/privacy-policy
- Stripe (for subscription services): Processes recurring subscription payments when subscription services launch. Privacy policy: https://stripe.com/privacy
- Kickstarter (for campaign backers): If you purchased through our Kickstarter campaign, payment was processed by Kickstarter according to their privacy policy. Privacy policy: https://www.kickstarter.com/privacy

Verification Information: To adjust Content Safety Filter settings or access age-restricted features, we may collect age verification data through approved methods such as:
- Date of birth confirmation
- Photo ID verification
- Credit card verification
- Facial age estimation technology
- Mobile network operator authentication
We store only the verification result (pass/fail status) and verification date, not copies of identity documents.

Promotion Entries: When you participate in Promotions, we collect:
- Entry submissions (artwork, images, descriptions, titles)
- Portfolio links and social media handles
- Metadata tags (art style, rendering method, mood/theme, character form)
- Public teasers and character spotlights
- Confidential notes for judges (shown only to judging panel)
- Voting activity and preferences

Winner Verification Data: If you are selected as a finalist or winner in a Promotion, we collect:
- Full legal name
- Postal address and phone number
- Government-issued identification (for verification)
- Tax forms (W-9, W-8BEN, or local equivalent)
- For minors: Parent/guardian name, contact details, and documentary proof of consent

User Content: We process the following content when you interact with your AI companion:
- Text inputs and messages
- Voice recordings
- Images and video
- Custom scripts and Spellbooks configurations
- Uploaded 3D models and custom assets
Important: User Content is processed in real-time for AI response generation and is immediately deleted after processing. We do not permanently store conversations, voice recordings, images, or video data in our cloud systems (see Section 3 for details).

Communications: If you contact customer support, provide feedback, or communicate with us, we collect:
- Contents of your messages and attachments
- Contact information
- Support ticket history

1.2 Information Collected Automatically

Device Information: We collect information about your CODE27 Device, including:
- Device serial number and hardware model
- Firmware version and operating system version
- Device identifiers (MAC address, unique device ID)
- Hardware configuration and capabilities

Usage Information: We collect anonymized information about how you use the Services, including:
- Features accessed and interaction timestamps
- Session duration and frequency
- Error logs and crash reports
- Performance metrics and diagnostic information
- App version and update history
This information is collected as anonymized event logs (see Section 4 for details).

Mobile App Information: From the CODE27 mobile app, we collect:
- App version
- Mobile device type and model
- Operating system version
- Device identifiers (IDFA on iOS, Advertising ID on Android, where permitted)
- Crash reports and error logs

Location Information: We may infer your general location (country/region) based on IP address to:
- Comply with regional legal requirements
- Provide location-appropriate services
- Apply regional content restrictions
- Determine applicable privacy laws
We do not collect precise geolocation data unless you explicitly enable location services for specific features.

Camera and Microphone Data: When you use camera or microphone features with your AI companion:
- Visual and audio data is transmitted to our cloud services for real-time AI processing
- This data is immediately deleted after processing and response generation
- No persistent recordings are stored in cloud systems
- See Section 5 for details on biometric processing

1.3 Information from Third Parties

Third-Party Authentication: If you choose to sign in using third-party authentication services, we receive personal information from those providers:
- Google Sign-In: We receive your name, email address, profile picture, and Google account identifier. Google's privacy policy: https://policies.google.com/privacy
- Apple Sign-In: We receive your name, email address (or Apple private relay email), and Apple ID identifier. Apple's privacy policy: https://www.apple.com/legal/privacy/
- Discord Sign-In: We receive your username, email address, avatar, Discord user identifier, and discriminator. Discord's privacy policy: https://discord.com/privacy
- X (Twitter) Sign-In: We receive your name, username, email address, profile picture, and X account identifier. X's privacy policy: https://x.com/en/privacy

By using third-party authentication, you authorize us to collect this information according to your permissions with those services.
Third-Party Integrations: When you use Spellbooks to connect to third-party services, those services may provide data to the Device according to your integration configuration. We do not store third-party API responses on our servers.
Service Providers: We may receive information from service providers who assist in operating the Services, including payment processors, fraud prevention services, and analytics providers.


2. How We Use Your Information

We use the information we collect for the following purposes, based on the legal grounds specified in the table below.

Legal Bases Explained:
- Contract performance: Processing is necessary to provide the Services you've requested
- Consent: You have given explicit permission for the processing
- Legal obligation: Processing is required to comply with applicable laws
- Legitimate interest: Processing is necessary for our legitimate business interests, balanced against your privacy rights
You may withdraw consent at any time by contacting privacy@code27.co or adjusting settings in your Account. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.


3. Data Processing Architecture

CODE27 uses a privacy-preserving stateless architecture that minimizes data retention in cloud systems.

3.1 Cloud Processing (No Storage)
When you interact with your AI companion using our cloud services:
1. Your voice, text, and visual inputs are transmitted to our cloud services for real-time AI processing
2. Emotion detection analyzes current emotional state to inform companion responses
3. AI-generated responses are returned to your Device
4. Raw audio, images, and video are immediately deleted after processing
5. No conversation content, voice recordings, or visual data is stored in our cloud
This stateless approach means:
- Conversations are not available for our review or analysis
- Your interactions remain private and ephemeral
- We cannot retrieve or reconstruct past conversations from our servers
- Privacy is protected by design

3.2 Device Storage (User Controlled)
Data stored locally on your CODE27 Device includes:
- Conversation history with your AI companion
- Emotion context and conversation summaries (as part of companion memory)
- AI companion customizations and preferences
- Uploaded 3D models and custom assets
- Spellbook integration configurations
- Face unlock biometric templates (if enabled - stored in secure on-device storage only)
You retain full control over Device-stored data through:
- Settings > Data Management
- Device > Factory Reset
- App > Export Data (where available)
We have no access to data stored locally on your Device unless you choose to sync it or contact support for troubleshooting.

3.3 Cloud Data Storage (Minimal)
We store the following data on our servers:
- Account credentials (email, password hash)
- Subscription status and payment history (transaction records only)
- Device registration information (Device serial number, activation date, firmware version)
- Anonymized event logs (described in Section 4)
- Promotion entries and public gallery content
- Winner verification documents (retained as required by law)


4. Event Logs and Safety Monitoring

4.1 Anonymous Event Logs
To operate the Services securely and demonstrate legal compliance, we create anonymous event logs containing:
- Timestamp of event
- Event type (e.g., auth.login.success, feature.camera.activated, integration.api.called)
- Device identifier (for debugging purposes)
- Success/failure status and error codes
- General feature usage statistics
What is NOT logged: Message content, user inputs/outputs, voice recordings, images, videos, or any reconstructable personal information.
Retention: Operational event logs are retained for 90 days. Safety intervention logs are retained for 3 years in anonymized form for California SB243 reporting compliance.

4.2 Safety Monitoring and Crisis Intervention
We employ real-time automated systems to detect expressions of suicidal ideation, self-harm, or crisis situations in compliance with California Business and Professions Code Section 22601 et seq. (Assembly Bill 2939 - SB243).
When our systems detect concerning expressions:
1. You receive immediate notification with crisis resource information:
- National Suicide Prevention Lifeline: 988
- Crisis Text Line: Text HOME to 741741
- Emergency Services: 911
2. An anonymous event log records:
- Timestamp
- Intervention type (e.g., safety.crisis_detected, safety.resources_displayed)
- Device identifier
- No conversation content is stored
3. The AI companion may adjust responses to prioritize safety
Safety Metrics Reporting: Beginning July 1, 2027, we will report aggregated safety metrics to California's Office of Suicide Prevention as required by law. These reports contain only anonymized statistical data, not individual user information.
Details: Our complete safety protocols are published at code27.co/safety.

4.3 Automated Data Protection Measures
CODE27 implements real-time content filtering to detect and block transmission of highly sensitive information categories, including:
- Government identification numbers (Social Security numbers, driver's licenses, passport numbers)
- Financial account credentials (credit/debit card numbers with security codes, bank account and routing numbers)
- Authentication credentials (passwords, security codes, API keys when not used for authorized Spellbook integrations)
When our systems detect these data types:
1. The information is blocked from being processed by AI services
2. Not stored in logs or records
3. Replaced with a privacy protection notice to the user
Data You Control: CODE27's filtering is designed to prevent accidental disclosure of highly sensitive credentials. The following data types may be processed when voluntarily shared as part of normal companion interaction:
- Phone numbers and email addresses (particularly for Spellbook integrations with contacts, calendars, and email)
- General health or personal information shared in conversation
- Public information retrieved through Spellbook API integrations
Limitations: Automated filtering cannot guarantee detection of all sensitive information in all contexts. Users should avoid sharing highly sensitive credentials with AI systems and review Spellbook integration permissions carefully.
Filtering Event Logs: When sensitive data filtering is triggered, we create an anonymous event log containing:
- Timestamp
- Filter type activated
- Device identifier
- No content of filtered data or user identifiers is stored
These logs are retained for 90 days for security monitoring and compliance.



5. Visual Data and Biometric Information

5.1 Camera Processing
The CODE27 Device camera enables visual interactions with your AI companion. Camera features require your explicit permission on first use and can be disabled in Settings > Privacy > Camera.
Visual Data Processing:
- Camera feed processed in real-time to enable visual AI responses
- Optional emotion recognition feature analyzes facial expressions to understand emotional context and inform companion responses
- Visual data may be processed on-device or via cloud AI services depending on feature complexity
- All visual data is immediately deleted after processing
Data Retention:
- Visual data is processed in real-time and immediately deleted after processing
- Emotion context summaries are stored on your Device as part of companion memory
- No persistent facial recognition profiles are stored in cloud systems
- No images or video recordings are retained on our servers
Physical Indicator: A physical indicator light activates when the camera is in use, providing visual confirmation of camera activity.
User Control: All camera features can be disabled in Device Settings > Privacy > Camera. Disabling the camera will prevent visual interactions but will not affect other Device functionality.
Legal Basis: Processing of camera data, including emotion recognition, is based on your explicit consent. Emotion detection processes visual data to understand emotional context for AI responses, not for identification purposes. You may withdraw consent and disable these features at any time in Settings > Privacy > Camera.

5.2 Face Unlock Authentication (Optional)
CODE27 offers an optional face unlock feature for Device authentication.
How Face Unlock Works:
1. When enabled, facial biometric data is captured and converted into an encrypted mathematical template
2. This template is stored exclusively on your CODE27 Device in secure on-device storage
3. Face authentication occurs entirely on-device through local comparison
4. Facial biometric data is NEVER transmitted to cloud servers or stored remotely
Legal Basis: Face unlock processing relies on your explicit consent. You may disable face unlock at any time in Settings > Security.
Data Retention: Face unlock templates are stored on-device until you disable the feature or perform a factory reset. We have no access to these biometric templates.
Biometric Data Notice (Illinois BIPA & Similar Laws): If you are a resident of Illinois or another jurisdiction with biometric privacy laws, you acknowledge that:
- Face unlock uses biometric identifiers (facial geometry)
- Biometric data is stored on your Device and retained until you disable the feature
- Biometric data is used solely for authentication purposes
- We do not sell, lease, or trade biometric data
- Biometric data is protected using industry-standard security measures


6. How We Share Your Information

We share personal information only in the limited circumstances described below. We do not sell personal information for monetary consideration.

6.1 Service Providers
We share personal data with third-party service providers who assist in operating our Services under contractual obligations to protect your data:
AI and Voice Services:
- ElevenLabs, Inc. provides text-to-speech voice synthesis and conversational AI services. When you interact with your AI companion, text inputs are transmitted to ElevenLabs for voice generation and AI processing. ElevenLabs processes this data according to their privacy policy: https://elevenlabs.io/privacy-policy
- Data Retention by ElevenLabs: Voice data may be retained by ElevenLabs for up to 3 years after last interaction and may be used for AI model improvement. You can opt out of ElevenLabs AI training by contacting us at privacy@code27.co to request opt-out on your behalf.
Payment Processing:
- Airwallex processes hardware purchases for CODE27 Device and accessories. Privacy policy: https://www.airwallex.com/privacy-policy
- Stripe, Inc. will process subscription payments when subscription services launch. Privacy policy: https://stripe.com/privacy
Website Analytics (Website Only):
- Google Analytics collects website usage information including page views, referring pages, and anonymized IP addresses. The CODE27 Device and mobile app do not use Google Analytics. Opt-out: https://tools.google.com/dlpage/gaoptout
- Meta Pixel enables advertising measurement and delivery on our website. Privacy policy: https://www.facebook.com/privacy/policy. The CODE27 Device and mobile app do not use Meta Pixel.
Cloud Infrastructure:
- We operate our own compute infrastructure located in North America (United States and Canada). User data is processed on our controlled servers.
A complete list of service providers, including their privacy policies and data processing details, is available at code27.co/legal/service-providers.

6.2 Spellbooks Third-Party Integrations
Spellbooks allows you to create custom integrations connecting your AI companion to third-party APIs and services. Spellbooks is currently rolling out to beta users.
When you enable a Spellbook integration:
- Data is transmitted to third-party services based on your configuration
- You control which third-party services to connect
- You are responsible for reviewing third-party services' privacy policies
- We do not control and are not responsible for third-party data practices
- Integration configurations are stored on your Device
Data Processing: We create anonymous event logs when integrations are triggered (timestamp, integration type, success/failure status) without storing API response content or personal data retrieved from third-party services.

6.3 Promotion Partners
For Winners and Finalists (With Your Consent): If you are selected as a finalist or winner in a Promotion and provide opt-in consent, we may share your contact information with approved partners so they can contact you about potential licensing, collaboration, or commission opportunities related to your entry.
For minors, we require guardian consent before sharing contact information with partners.
For Non-Winners: We do not share non-winners' contact details with partners unless you opt in. We may forward partner inquiries to you without sharing your contact details.

6.4 Public Display
Promotion Entries: If you submit an entry to a Promotion, certain information will be publicly displayed in galleries:
- Your display name/pen name
- Entry artwork and images
- Entry title and public description
- Portfolio links you provide
- Metadata tags
This information may be indexed by search engines and shared by other users. We cannot control third-party reposts or caches.
Winner Announcements: If you are selected as a winner, we will publicly announce:
- Your name or display name
- Hometown (city/state/country)
- Entry title and images
- Portfolio link

6.5 Legal Requirements
We may disclose personal information when required by law or to protect our rights:
- In response to lawful requests from law enforcement, courts, or government authorities
- To comply with legal obligations, court orders, subpoenas, or legal processes
- To protect the rights, property, or safety of SyBran Technology Limited, our users, or the public
- To prevent, detect, or investigate fraud, security threats, or illegal activities
- In connection with legal proceedings or investigations

6.6 Business Transfers
If SyBran Technology Limited is involved in a merger, acquisition, asset sale, financing, bankruptcy, or other corporate transaction, your personal data may be disclosed to or transferred to potential or actual acquirers, investors, advisors, and other parties involved in the transaction.
In such events:
- Acquirers must agree to protect your data consistent with this Privacy Policy
- We will provide notice via email and prominent notice on our website before transfer
- Your data rights under applicable law continue with the new entity
- You may exercise deletion rights before the transfer completes where legally permitted
Data stored locally on your CODE27 Device remains under your direct control and is not transferred as part of corporate transactions.

6.7 With Your Consent
We may share personal information with third parties when you direct us to do so or provide explicit consent.


7. Promotions and Public Galleries

7.1 Information Collected for Promotions
When you participate in Promotions (contests, sweepstakes, competitions), we collect:
- Entry Submissions: Artwork, images, descriptions, titles, portfolio links, metadata
- Account Information: Display name, email, country/region
- Voting Activity: Your votes and voting patterns
- Winner Verification: Full name, address, phone number, date of birth, tax forms, government ID (for finalists/winners only)
- Guardian Data (for minors): Guardian name, contact details, documentary proof of consent

7.2 Public Gallery Display
Entries in the public gallery may include:
- Your display name/pen name
- Artwork and images
- Entry title and description
- Portfolio links
- Metadata tags (art style, rendering method, mood/theme)
Public Visibility: Public gallery content may be indexed by search engines and shared by others. You may request removal of non-winning entries after the Promotion, subject to feasibility and residual copies beyond our control.

7.3 How Promotion Data Is Used
We use Promotion data for:
- Receiving and validating entries
- Public gallery display
- Voting and judging
- Finalist and winner selection
- Announcements and publicity
- Prize delivery and tax compliance
- Fraud prevention and vote integrity
- Analytics to improve future Promotions

7.4 Retention of Promotion Data
- Non-winner data: Retained for up to 12 months after Promotion conclusion, then deleted or anonymized
- Winner lists and winning entries: Retained for archival and transparency purposes while Promotion results remain published or otherwise promoted, subject to periodic review and your rights
- Prize-related and tax records: Retained as required by law (typically 7 years)


8. Minors (Ages 13-17)

8.1 Eligibility
Participants aged 13–17 may use the Services only with the consent of a parent or legal guardian. Persons under 13 are not eligible to use the Services, and we will delete any data inadvertently collected from them.

8.2 Parental Consent
At Account creation or Promotion entry, minors must affirm that parental consent has been obtained. Documentary proof will be requested only if the minor becomes a finalist or winner in a Promotion, or if otherwise required by law.
Required Documentation (for finalists/winners):
- Guardian name and contact information
- Documentary proof of consent (signed consent form, notarized statement, or video verification)
- Minor's date of birth and government-issued ID (for age verification)
Failure to provide proof within the stated timeframe will result in disqualification from Promotions or Account suspension.

8.3 EEA/UK Digital Age of Consent
For EEA/UK participants, where required by local law, consent must be provided or authorized by the holder of parental responsibility for users under the applicable digital age of consent (13–16 depending on country).

8.4 Enhanced Protections for Minors
For users under 18:
- Content Safety Filters are enabled by default and cannot be adjusted
- Sexually explicit visual material is blocked
- Enhanced safety monitoring is applied
- Crisis intervention resources are prominently displayed
- Reminder notifications appear every 3 hours to take breaks and remember you are interacting with AI
- Parental oversight features are available through Account settings


9. Data Retention

We retain personal information only as long as necessary for the purposes set out in this Policy, subject to periodic review and applicable legal requirements.

ElevenLabs Data Retention: Voice data transmitted to ElevenLabs for speech synthesis is subject to their retention policies (up to 3 years). See ElevenLabs Privacy Policy: https://elevenlabs.io/privacy-policy
Legal Hold Exceptions: We may retain data longer when required by law, to resolve disputes, enforce agreements, or defend legal claims. You will be notified if your data is subject to legal hold.


10. Cookies and Tracking Technologies

10.1 Website Cookies
Our website uses cookies and similar technologies for analytics and marketing purposes. The CODE27 Device and mobile app do not use advertising cookies or cross-app tracking technologies.
Cookie Types:
Strictly Necessary Cookies: Essential for website functionality, including authentication, security features (CSRF protection), and session management. These cannot be disabled.
Analytics Cookies: Google Analytics collects website usage information including page views, navigation patterns, and anonymized IP addresses to understand how users interact with our website. Google's privacy practices: https://policies.google.com/privacy
Marketing Cookies: Meta Pixel enables measurement of advertising effectiveness and delivery of relevant ads to users who have visited our website. Meta's privacy practices: https://www.facebook.com/privacy/policy

10.2 Your Cookie Choices
Browser Settings: Adjust cookie preferences through your browser settings. Note that disabling strictly necessary cookies may impact website functionality.
Opt-Out Tools:
- Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
- Meta advertising preferences: https://www.facebook.com/ads/preferences
Global Privacy Control (GPC): We honor Global Privacy Control signals for marketing cookies. GPC browser extension: https://globalprivacycontrol.org/
Do Not Track: Our website honors Global Privacy Control signals but does not respond to older Do Not Track (DNT) browser signals, as there is no accepted standard for DNT implementation.

10.3 Mobile App and Device
The CODE27 mobile app and Device do not use:
- Advertising cookies
- Cross-app tracking
- Advertising identifiers (except for app store analytics)
- Third-party analytics SDKs (beyond crash reporting)


11. AI-Specific Disclosures

11.1 AI Limitations
The Services utilize artificial intelligence to generate responses. You should understand:
- AI responses may contain inaccuracies, errors, or offensive material
- AI-generated content does not represent our views or opinions
- You should not rely on AI responses for medical, legal, financial, or professional advice
- You must evaluate AI-generated content for accuracy before relying on or sharing it
- AI responses are generated dynamically; similar inputs may produce different outputs based on conversation context
- The AI is not a substitute for human relationships or professional services

11.2 AI Training and Model Improvement
Our AI Models: We do not use your conversations to train our own AI models.
Third-Party AI Providers: ElevenLabs may use voice data for AI model improvement according to their privacy policy. You can opt out by contacting us at privacy@code27.co to request opt-out on your behalf. See ElevenLabs Privacy Policy: https://elevenlabs.io/privacy-policy

11.3 Automated Decision-Making
We use automated systems for:
- Content filtering and safety monitoring
- Age verification (facial age estimation, where applicable)
- Fraud detection and abuse prevention
- Crisis intervention detection
These automated systems may have significant effects on your access to the Services. You may:
- Request human review of automated decisions
- Challenge inaccurate determinations
- Contact privacy@code27.co to exercise these rights


12. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information.

12.1 Universal Rights
Access: Request a copy of the personal information we hold about you.
Correction: Request correction of inaccurate or incomplete personal information.
Deletion: Request deletion of your personal information, subject to legal obligations and legitimate interests.
Data Portability: Request a copy of your personal information in a structured, machine-readable format (JSON or CSV).
Objection: Object to processing of your personal information based on legitimate interests.
Restriction: Request restriction of processing in certain circumstances.
Withdraw Consent: Where processing is based on consent, withdraw consent at any time (does not affect lawfulness of prior processing).
Lodge a Complaint: Lodge a complaint with your supervisory authority if you believe we have violated your privacy rights.

12.2 How to Exercise Your Rights
To exercise these rights, contact us at:
- Email: privacy@code27.co
- App: Settings > Account > Privacy Rights
- Web Form: code27.co/privacy-request
Verification: We will verify your identity before acting on a request (for example, by confirming control of your email address or requesting limited additional information).
Authorized Agents: You may authorize an agent to submit a request on your behalf. We may require proof of authorization and verification of your identity.
Response Time: We will respond within 30 days (45 days for complex requests). We will notify you if we need additional time.
No Fee: We do not charge a fee to exercise your rights unless the request is manifestly unfounded, excessive, or repetitive.

12.3 GDPR Rights (EEA/UK Residents)
If you are located in the European Economic Area or United Kingdom, you have additional rights under the GDPR/UK GDPR:
- Right to lodge a complaint with your supervisory authority
- Right to data portability in machine-readable format
- Right to object to direct marketing (including profiling)
- Right to object to automated decision-making
- Right to erasure ("right to be forgotten") subject to legal exceptions
Supervisory Authorities: A list of EEA data protection authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. UK Information Commissioner's Office: https://ico.org.uk


13. California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

13.1 Categories of Information Collected
See Section 1 for detailed descriptions. In the 12 months preceding the Last Updated date of this Policy, we have collected the following categories of personal information:
- Identifiers: Name, email, account username, Device identifiers, IP address
- Personal information categories (Cal. Civ. Code § 1798.80(e)): Name, address, telephone number
- Protected classification characteristics: Age, date of birth
- Commercial information: Purchase history, payment transactions
- Biometric information: Facial geometry (for optional Face Unlock only, stored on-device)
- Internet or network activity: Browsing history on our website, app usage, Device interaction logs
- Geolocation data: General location (country/region) inferred from IP address
- Audio, electronic, visual information: Voice recordings, images, video (processed in real-time, not stored)
- Inferences: Preferences, characteristics, behavior patterns drawn from usage

13.2 Sources of Information
- Directly from you (Account creation, Promotion entries, communications)
- Automatically from your Device, app, or website usage
- From third-party authentication providers (Google, Apple)
- From service providers (payment processors, analytics)

13.3 Purposes for Collection
See Section 2 for detailed purposes. We use personal information to:
- Provide and improve the Services
- Process payments and fulfill transactions
- Communicate with you
- Administer Promotions
- Ensure safety and security
- Comply with legal obligations

13.4 Sharing of Personal Information
In the 12 months preceding the Last Updated date of this Policy, we have disclosed the following categories of personal information for business purposes:

We do not sell personal information as defined by California law.
"Sharing" for Cross-Context Behavioral Advertising: Our use of Meta Pixel and Google Analytics on our website (not on the Device or App) may constitute "sharing" for cross-context behavioral advertising purposes under California law. California residents can opt out at code27.co/your-privacy-choices or by enabling Global Privacy Control.

13.5 California Privacy Rights
Right to Know/Access: Request disclosure of:
- Categories and specific pieces of personal information collected
- Categories of sources from which information was collected
- Business or commercial purposes for collection
- Categories of third parties with whom we share information
Right to Delete: Request deletion of personal information we have collected (subject to exceptions).
Right to Correct: Request correction of inaccurate personal information.
Right to Opt-Out of Sale/Sharing: We do not sell personal information for monetary consideration. You may opt out of "sharing" for cross-context behavioral advertising (Meta Pixel, Google Analytics on website) at code27.co/your-privacy-choices.
Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond service provision (as defined by CPRA).
Right to Non-Discrimination: We will not discriminate against you for exercising your rights.
Shine the Light Law: California residents may request information about disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

13.6 How to Exercise California Rights
Submit requests via:
- Email: privacy@code27.co (subject line: "California Privacy Request")
- Phone: 1-844-726-3327 (Toll-Free)
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We may request verification of authorization.
Response Time: We will respond within 45 days (may extend to 90 days for complex requests with notice).
Appeals: If we deny your request in whole or in part, you may appeal by replying to our decision email with "Appeal" in the subject line. We will explain our final decision in writing within the period required by law.


14. International Data Transfers

We operate compute infrastructure located in North America (United States and Canada). When you use our Services, your personal data is transferred to and processed on our servers in these locations.

14.1 Cross-Border Transfers
Standard Contractual Clauses (SCCs): We use appropriate safeguards for international data transfers, including Standard Contractual Clauses with service providers who process data outside your jurisdiction, including ElevenLabs and Stripe.
Your Consent: By using our Services, you acknowledge and consent to the transfer of your personal data to the United States and Canada for processing as described in this Policy.
You may request a copy of the safeguards we use for international transfers by contacting privacy@code27.co.

14.2 Cross-Border Data Transfers Table

15. Security

We implement technical and organizational security measures to protect personal information, including:
Technical Measures:
- Encryption of data in transit (TLS/SSL) and at rest (AES-256)
- Secure authentication and password hashing (bcrypt)
- Access controls and role-based permissions
- Regular security audits and vulnerability assessments
- Intrusion detection and prevention systems
- Secure development practices and code reviews
Organizational Measures:
- Employee training and confidentiality obligations
- Background checks for employees with data access
- Incident response procedures and breach notification protocols
- Vendor security assessments and data processing agreements
- Data minimization and privacy-by-design principles
Limitations: However, no system is completely secure. We cannot guarantee absolute security of your information. You use the Services at your own risk.
Data Breach Notification: In the event of a data breach affecting your personal information, we will notify you as required by applicable law. Notifications will be sent via email to your account address within the timeframe required by law (typically 72 hours for GDPR, without unreasonable delay for CCPA).


16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, legal requirements, or business operations.
Notification of Changes: We will provide notice of material changes by:
- Posting the updated Policy on this page with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice within the App or Device interface
- Other reasonable means of notification
Effective Date: Changes will become effective:
- For material changes affecting your rights: 30 days after notice is provided
- For non-material changes (e.g., clarifications, formatting): Immediately upon posting
Your Acceptance: By continuing to use the Services after the effective date of the updated Policy, you agree to be bound by the modified Policy. If you do not agree to the changes, you must stop using the Services and may delete your Account.
Version History: We maintain a version history of this Policy. You may request previous versions by contacting privacy@code27.co.


17. Contact Us

For privacy questions, to exercise your privacy rights, or to report privacy concerns, please contact us:
SyBran Technology Limited
Phone: 1-844-726-3327 (Toll-Free)
Email:
- Privacy matters: privacy@code27.co
- General inquiries: service@code27.co
- Data subject requests: privacy@code27.co
Mailing Address:
SyBran Technology Limited
440 N BARRANCA AVE #9805
COVINA, CA 91723
UNITED STATES
Attention: Privacy Officer
Website: code27.co
Response Time: We will respond to your inquiry within the timeframe required by applicable law (typically 30 days, 45 days for complex requests).


18. EU/UK Territorial Scope and Representative Assessment

We accept users from the EEA and the UK. For individuals located in the EEA/UK, our processing may fall within the territorial scope of the GDPR/UK GDPR (Article 3). We are not established in the EEA/UK.
Representative Assessment (Article 27 GDPR):
The processing of personal data in connection with Promotions is an occasional activity that is not part of our regular core business operations of designing, manufacturing, and selling hardware products. Based on our assessment in accordance with Article 27(2)(a) GDPR (and the equivalent UK GDPR provision), this processing is occasional, does not involve large-scale processing of special-category or criminal-offense data, and is unlikely to result in a risk to individuals' rights and freedoms. Accordingly, appointment of an EU/UK representative is not required at this time.
Commitment to Compliance: Should the nature of our processing change, or should we receive a valid inquiry from an EEA/UK data subject or supervisory authority indicating a need for a designated representative, we will promptly appoint one to ensure effective communication and compliance.
EEA/UK participants may send data requests to privacy@code27.co; we will respond within the timeframes required by applicable law. Nothing here limits any right EEA/UK data subjects have to lodge a complaint with a supervisory authority.
All EEA/UK inquiries related to this assessment may be directed to privacy@code27.co; we will respond within the timeframes required by applicable law.


END OF PRIVACY POLICY


Acknowledgment: By using the Services, you acknowledge that you have read, understood, and agree to this Privacy Policy.