EmoEx Privacy Policy
Effective Date: September 8, 2026
1. Data Controller and Contact Information
EmoEx Technology Limited is the data controller responsible for the personal data collected through the EmoEx website, mobile applications, bot interactions, and related services.
-
Company Name: EmoEx Technology Limited
-
Registered Address: 14 Manawa Road, Remuera, Auckland 1050, New Zealand
-
General Inquiries: info@emoexai.com
Data Protection Officer (DPO) We have appointed an internal Data Protection Officer to oversee our privacy and data protection practices:
-
Contact: Gemini Wen, CTO
-
Email: privacy@emoexai.com
European Union (EU) Representative (GDPR Article 27) Pursuant to Article 27 of the General Data Protection Regulation (GDPR), EmoEx Technology Limited has appointed Instant EU GDPR Representative Ltd as its representative in the European Union:
-
Representative: INSTANT EU GDPR REPRESENTATIVE LIMITED
-
Contact Person: Adam Brogden
-
Email: contact@gdprlocal.com
-
Website: www.gdprlocal.com
-
Address: Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland
-
EU Privacy Request Submission Page: https://emoextechnologylimited.gdprlocal.com/eu
United Kingdom (UK) Representative (UK GDPR Article 27) For individuals located in the United Kingdom:
-
Representative: Jenny Hamilton, Chief of R&D
-
Email: privacy@emoexai.com
2. Age Requirement and Minimum Age Policy
EmoEx services and mobile applications are strictly intended for individuals who are at least 18 years of age. We do not provide our services to minors, nor do we knowingly collect or solicit personal data from anyone under the age of 18. If we learn or have reason to believe that a user is under 18 years of age, we will immediately deactivate the account and delete all associated personal information from our systems.
3. Information We Collect
We collect information to provide, maintain, and enhance our services:
-
Personal Account Data: When you register, we may collect your email address and account credentials used exclusively for account creation, authentication, password recovery, and service communications.
-
Demographic Details: Non-specific demographic data such as gender or age bracket (18+), collected strictly to personalise and refine user experience.
-
Situational and Emotional Keywords: Contextual keywords relating to emotional and situational topics extracted from interactions with EmoEx Bot to enhance conversation quality and responsiveness.
-
Technical and Usage Data: IP addresses, operating system, browser type, device identifiers, session metadata, and system interaction logs.
-
App Permissions & Media Access: With your explicit permission, the app may request camera or photo access for profile customisation and FeelLog entries. Biometric authentication features (such as Face ID or Touch ID) are processed locally on your device hardware; EmoEx does not collect, access, or store biometric identifiers.
-
Excluded Data Categories: EmoEx does not collect or process sensitive personal data, including government-issued identification numbers, precise physical street addresses, medical records, or financial banking credentials.
4. Legal Bases for Processing Personal Data
Under the GDPR and UK GDPR, we process your personal data under the following lawful bases:
-
Performance of a Contract: Processing your contact credentials, authentication data, and account details as necessary to create your account, manage user access, and deliver the conversational features of the EmoEx platform.
-
Legitimate Interests: Processing technical usage logs, session identifiers, and aggregated conversational keywords to maintain system security, detect and prevent fraud or abuse, ensure high service availability, and refine our conversational AI models.
-
Consent: Where required by applicable law, obtaining your explicit consent before deploying non-essential tracking cookies or optional analytics technologies.
-
Legal Obligations: Retaining transaction and basic account records where necessary to satisfy legal, tax, or regulatory compliance requirements.
5. Cookies and Tracking Technologies
We use cookies, web beacons, and similar tracking technologies to ensure our website functions correctly, remember user preferences, maintain session security, and analyse aggregate traffic trends. You can manage your cookie preferences through your web browser settings at any time.
6. Third-Party Service Providers and Data Sharing
We do not sell, rent, or trade your personal information. To provide and operate the EmoEx platform, we share necessary data with vetted third-party service providers who process data strictly on our behalf under written contractual agreements:
-
Cloud Infrastructure and Hosting: Enterprise cloud server infrastructure, database hosting, and automated backup services (such as Google Cloud Platform).
-
AI Processing and Inference: Advanced machine learning model providers that assist in generating real-time conversational responses under strict confidentiality obligations.
-
Authentication and Security: Identity management, DDoS mitigation, and continuous security monitoring services.
All service providers are bound by strict contractual terms to maintain appropriate confidentiality, technical security, and data protection safeguards in compliance with applicable privacy laws.
7. Compelled Legal Disclosures
We may disclose personal data if required to do so by law, court order, search warrant, subpoena, or valid regulatory demand. Upon receipt of any such legal request, we verify the validity and scope of the demand and disclose only the specific information strictly required by law.
8. International Data Transfers
EmoEx is headquartered in New Zealand, and our cloud infrastructure and third-party service providers operate in the United States, Australia, and other global regions.
When personal data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred internationally to countries that have not received an adequacy decision from the European Commission, we implement appropriate safeguards, including:
-
Standard Contractual Clauses (EU SCCs) approved by the European Commission.
-
The UK International Data Transfer Addendum to the EU SCCs.
-
Recognised adequacy decisions, including the European Commission’s adequacy decision for New Zealand.
9. Data Retention and Security
-
Account Information: Retained for the active duration of your account. If you request account deletion, your personal details are permanently deleted or anonymised within 60 days.
-
Session Processing: Real-time conversational exchanges processed on backend systems are cleared following the conclusion of your active session and remain available to you via your secure user access.
-
Security and System Logs: Infrastructure, diagnostic, and access logs are retained for up to 1 year for security monitoring and audit integrity.
-
Technical Safeguards: All customer data in transit is encrypted using TLS 1.2 or higher, and stored data is encrypted at rest using industry-standard AES-256 encryption.
10. Your Data Protection Rights
Under GDPR, UK GDPR, and applicable data privacy regulations, you have the following rights regarding your personal data:
-
Right of Access: You may request confirmation of processing and a copy of your personal data.
-
Right to Rectification: You may request the correction of inaccurate or incomplete personal information.
-
Right to Erasure (“Right to be Forgotten”): You may request the deletion of your personal data when it is no longer needed for the purposes for which it was collected.
-
Right to Restriction: You may request that we temporarily suspend the processing of your personal data under certain statutory conditions.
-
Right to Data Portability: You may request to receive your personal data in a structured, commonly used, and machine-readable format.
-
Right to Object: You have the right to object at any time to data processing based on our legitimate interests or direct marketing.
How to Exercise Your Rights
-
General and UK Inquiries: Email our privacy team directly at privacy@emoexai.com
-
EU Inquiries: Submit your request directly to our EU Representative via their online privacy form at https://emoextechnologylimited.gdprlocal.com/eu or by email at contact@gdprlocal.com
We will verify your identity and respond to your request within one calendar month.
Right to Lodge a Complaint
If you believe our processing of your personal data infringes applicable data protection laws, you have the right to lodge a formal complaint with a supervisory authority:
-
EU/EEA Residents: You may lodge a complaint with the Data Protection Commission (DPC) in Ireland (where our EU representative is established) or your local national Data Protection Authority.
-
UK Residents: You may lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our legal obligations, product features, or data practices. When updates are published, we will revise the “Effective Date” at the top of this document. Continued use of our platform after revisions become effective indicates your acknowledgment of the updated policy.
