Privacy Policy

Starailab respects your privacy

StarAI Inc ("Starailab" or "We") respects our user’s (“User” or “You”) privacy and are committed to protecting it through our compliance with this policy (the “Policy”). This Policy describes the types of information we may collect from you or that you may provide when you visit the website www.starailab.com (our "Website"), or software applications including SYBLE, and our other services (collectively our “Services”), and our practices for collecting, using, maintaining, protecting, and disclosing that information.

When processing your personal data, we attach great importance to protecting your private data and ensuring that your data is secure. This data protection Policy tells you about the data we process, why we need it, and how you can lodge an objection to the processing of your data.

Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Services. By accessing or using the Services, you agree to this Policy. This Policy may change from time to time (see Amending this Data Protection Policy). Your continued use of the Services after we make changes is deemed to be acceptance of those changes, so please check the Policy periodically for updates.

What personal data do we collect?
The personal data we collect is limited to information regarding our relationship with you. This includes contact information, such as your name, telephone number, address and email address. Information that cannot be linked to your identity (e.g. statistical information, such as the number of users of our online services) is not considered to be personal data. We also collect information about you in order to provide our services, including your date of birth, the time of day you were born, and the location in which you were born. We also upload your contact list information, but will seek your permission before doing so.

How do we collect personal data?
We collect personal information from you directly when you provide it to us through our Services, and automatically as you navigate and use our Services. Information we collect automatically may include usage details, IP addresses, or information collected through cookies. When we collect your personal information for a specific purpose, we will make that purpose known to you. Also note that
personal data will be uploaded to our servers and we will obtain your consent before the data is uploaded.

Do we pass your data on to third parties?
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.

We may disclose personal information that we collect or you provide as described in this Policy: (i) to our subsidiaries and affiliates; (ii) to contractors, service providers, and other third parties we use to support our business and who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them; (iii) to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Starailab's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Starailab about our Services users is among the assets transferred; (iv) to fulfill the purpose for which you provide it; (v) for any other purpose disclosed by us when you provide the information; or (vi) with your consent.

We may also disclose your personal information: (i) to comply with any court order, law, or legal process, including to respond to any government or regulatory request; (ii) to enforce or apply our terms of use (refer to legal section for terms of use) and other agreements, including for billing and collection purposes; and (iii) if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Starailab, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

How long do we retain your personal data?
We retain your data as long as necessary for our business. However, if you choose to opt out after having provided personal data, we will delete any data that has identification to you with you and continue storing the other underlying data.

What data are processed when you use our Services?
In general, you may visit our Services without providing personal information. When you visit the site, our servers make a temporary record of each access in a log file. The following technical data are collected and stored until they are automatically deleted after no more than seven months:

  1. The IP address of the computer used to access the site
  2. The date and time of access
  3. The website from which access was obtained, if applicable, as well as the search term used, as applicable
  4. The name and URL of the accessed file
  5. The search queries used
  6. Your computer’s operating system (shown by the user agent)
  7. The browser you are using (shown by the user agent)
  8. The type of device, if access is obtained through a mobile telephone
  9. The transmission protocol used

By collecting and processing these data, we promote system security and stability, allow for error and performance analysis, and serve internal statistical needs. This also enables us to optimize our online services. In addition, IP addresses are used to preset the Services language. Finally, we insert cookies and use cookie-based applications and tools when users access our Services. More detailed information can be found in the next section. 

What are cookies, and when are they used?
Cookies are small text files that are placed on your computer when you visit some of our Services. When you return to the applicable Services, your browser transmits the information contained in the cookies back to us, and this allows the system to recognize your terminal device. With the help of cookies, we are able to optimize our website and facilitate its use.

When you visit our website, a popup message informs you of our use of cookies and of the fact that visiting the site implies your consent.

If you opt not to permit the use of cookies, you may deactivate and delete all cookies at any time. For more information, consult your browser’s help function. If you choose to deactivate cookies, however, certain functions on our Services may no longer be available to you. The deactivation or deletion process must be repeated if you use a different browser or terminal device.

How do we use tracking tools?
We need statistical information about the use of our online services to make them more user-friendly, measure their range and conduct market research. We use web analytics tools for this purpose, specifically Google Analytics and/or social media pixels. The user profiles we create using these tools and cookies are not linked to personal data. The tools do not use visitors’ IP addresses, or they abbreviate them immediately after the information is collected.

In addition to the data listed above, we gather the following information on some of our Services:

  1. The user’s navigation path on the Services
  2. The length of time the user spends on the Services, Website or subpage
  3. The subpage from which the user leaves the Services
  4. The country, region or city from which the Services are accessed
  5. The terminal device (type, version, color depth, resolution, width and height of the browser window)
  6. Repeat or new visitor

This information is used to analyze Services use. 

 Social media
Our Services may contain plugins and links to several social networks (Facebook, Twitter, LinkedIn, Google+, Xing etc.). The links are marked with the logos of the providers. Clicking on a link takes you to the relevant social media platform, where this Policy does not apply. The provisions that apply there can be found in the data protection policy posted on the respective provider’s website.

Personal information is not transmitted to the social media provider until you click on a link or plugin. By accessing the linked site, you are allowing the provider to process your data. We have no influence over such data processing, nor do we have information about the extent of data collection, the purposes for which the data are processed, or the retention period. We have no information about the deletion of data by the plugin provider.

What rights do you have concerning your personal data?
You have the following rights:

  1. You are entitled to request information about your stored data.
  2. You may request that your personal data be corrected, supplemented, blocked or deleted.
  3. If you have consented to the processing of your data, you may revoke that consent at any time, effective going forward.

You may do so via email. See Contact section.

 Data security
We use appropriate technical and organizational security measures to protect stored personal data against manipulation, partial or total loss, and unauthorized access by third parties. Our security measures are continually upgraded as technology advances.

 Amending this Data Protection Policy
We reserve the right to amend or supplement this Policy at any time, as we see fit and in accordance with applicable data protection laws. If we make material changes to how we treat our users' personal information, we will notify you through a notice on our Services’ home page. Please consult this Policy on a regular basis.

Children Under the Age of 15

Our Services is not intended for children under 15 years of age. Children between the ages of 15 and 18 may utilize the services with verifiable parental consent. No one under age 15 may provide any information to or on the Services. We do not knowingly collect personal information from children under 15. If you are under 15, do not use or provide any information on this Services or through any of its features, register on the Services, use any of the interactive or public comment features of the Services, or provide any information about yourself to us, including your name, address, telephone number, birthdate, email address, or any screen name or user name you may use. If we learn we have collected or received personal information from a child under the age of 18 without verification of parental consent, or information from a child under the age of 15, we will delete that information. If you believe we might have any information from or about a child under 15, please contact us at privacy@starailab.com.

Contact
If you have questions about your rights concerning your personal data or related issues, please contact: privacy@starailab.com

Privacy For California Residents

This section supplements the information above and applies solely to all visitors, users, and others who reside in the State of California. We have adopted this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this Policy.

Information We Collect

We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device ("personal information"). Personal information does not include:

  1. Publicly available information from government records.
  2. Deidentified or aggregated consumer information.

In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:

a)        Identifiers

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.

Collected : YES

b)        Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.

Some personal information included in this category may overlap with other categories.

Collected : YES

c)        Protected classification characteristics under California or federal law

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

Collected : YES

d)        Commercial information.

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Collected : YES

e)        Biometric information

Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data

Collected : NO

f)        Internet or other similar network activity

Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.

Collected : YES

g)         Geolocation Data

Physical location or movements.

Collected : YES

h)        Sensory Data

Audio, electronic, visual, thermal, olfactory, or similar information.

Collected : NO

i)        Professional or employment-related information

Current or past job history or performance evaluations.

Collected : NO

j)        Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34

C.F.R. Part 99))

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records

Collected : NO

k)        Inferences drawn from other personal information

Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes

Collected : YES

We obtain the categories of personal information listed above from the following categories of sources:

  1. Directly from you. For example, from forms you complete or products and services you purchase.
  2. Indirectly from you. For example, from observing your actions on our Website.

Use of Personal Information

We may use or disclose the personal information we collect for one or more of the following purposes:

  1. To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to ask a question about our Services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a Service, we will use that information to process your payment and facilitate delivery.
  2. To provide, support, personalize, and develop our Services.
  3. To create, maintain, customize, and secure your account with us.
  4. To process your requests, purchases, transactions, and payments and prevent transactional fraud.
  5. To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
  6. To help maintain the safety, security, and integrity of our Services, products and services, databases and other technology assets, and business.
  7. For testing, research, analysis, and product development, including to develop and improve our services.
  8. To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  9. As described to you when collecting your personal information or as otherwise set forth in the CCPA.
  10. To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our consumers is among the assets transferred.

We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

Sharing Personal Information

We may share your personal information by disclosing it to a third party for a business purpose. We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, and prohibit using the disclosed information for any purpose except performing the contract. In the preceding twelve (12) months, Starailabs has not disclosed personal information for a business purpose.

We do not sell personal information. In the preceding twelve (12) months, Starailabs has not sold personal information.

Your Rights and Choices

The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

Right to Know and Data Portability

You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months (the "right to know"). Once we receive your request and confirm your identity, we will disclose to you:

  1. The categories of personal information we collected about you.
  2. The categories of sources for the personal information we collected about you.
  3. Our business or commercial purpose for collecting or selling that personal information.
  4. The categories of third parties with whom we share that personal information.
  5. If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
  1. sales, identifying the personal information categories that each category of recipient purchased; and
  2. disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.
  1. The specific pieces of personal information we collected about you (also called a data portability request).

Right to Delete

You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions (the "right to delete"). Once we receive your request and confirm your identity, we will review your request to see if an exception allowing us to retain the information applies. We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:

  1. Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
  3. Debug products to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent.
  7. Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
  8. Comply with a legal obligation.
  9. Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
  10. We will delete or deidentify personal information not subject to one of these exceptions from our records and will direct our service providers to take similar action.

Exercising Your Rights to Know or Delete

To exercise your rights to know or delete described above, please submit a request by either:

  1. Emailing us at privacy@starailab.com

Only you, or someone legally authorized to act on your behalf, may make a request to know or delete related to your personal information.

You may only submit a request to know twice within a 12-month period. Your request to know or delete must:

  1. Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
  2. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.

You do not need to create an account with us to submit a request to know or delete. However, we do consider requests made through your password protected account sufficiently verified when the request relates to personal information associated with that specific account.

We will only use personal information provided in the request to verify the requestor's identity or authority to make it.

Response Timing and Format

We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please email us at privacy@starailab.com.

We endeavor to substantively respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing.

If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.

Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Personal Information Sales Opt-Out and Opt-In Rights

If you are age 16 or older, you have the right to direct us to not sell your personal information at any time (the "right to opt-out"). We do not sell the personal information of consumers we actually know are less than 16 years old. Consumers who opt-in to personal information sales may opt-out of future sales at any time.

You do not need to create an account with us to exercise your opt-out rights. We will only use personal information provided in an opt-out request to review and comply with the request.

Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  1. Deny you goods or services.
  2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  3. Provide you a different level or quality of goods or services.
  4. Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Privacy Notice for EU Residents

This section governs personal data, information relating to an identified or identifiable natural person, gathered from data subjects located in the EU only.

General Data Protection Regulation (“GDPR”) Information

The following information describes our commitments to you under EU General Data Protection Regulation (“GDPR”).

The GDPR makes a distinction between organizations that process personal data for their own purposes (known as "Data Controllers") and organizations that process personal data on behalf of other organizations (known as "Data Processors"). Starailab only acts as a Data Controller for very limited types of data, such as the information you enter when you register an account with us or the information you submit when using our software.

When We Act as a Data Controller

When we process your data as a Data Controller, the following applies.

We collect, use, and share your personal data where we are satisfied that we have an appropriate legal basis to do this. This may be because:

  1. Consent:  Our use of your personal data is in accordance with your consent. If we process your personal data based on consent, you will be asked for said consent at or before the time of data collection. You may withdraw your consent at any time, and will not suffer any detriment for withdrawing your consent.

  1. Contract: Our use of your personal data is to fulfill a contract between you and us.

  1. Legal Obligation: Our use of your personal data is necessary to comply with a relevant legal or regulatory obligation that we have (for example, where we are required to disclose personal data to a court, or store information due to federal financial regulations); or

  1. Legitimate Interest: Our use of your personal data is for a legitimate interest of ours, such as fraud prevention and ensuring our network’s security.

Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, EU residents have certain rights in relation to their personal data:

  1. Right to Access. You have the right to access to your personal data that is being processed; specifically you may request to view your personal data and obtain copies of your personal data.

  1. Right to Rectification. You have the right to request modifications to your personal data if it is out of date or inaccurate. In some circumstances, you may be able to exercise this right, in whole or in part, through your existing account with us.

  1. Right of Erasure. You have the right to ask that we delete your personal data.  However, we are not required to comply with your request to erase personal data if the processing of your personal data is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims.

  1. Right to Restriction of Processing. Under certain circumstances, you have the right to request we restrict processing your personal data You have the right to restrict the use of your personal data.  However, we can continue to use your personal data following a request for restriction (a) where we have your consent; (b) to establish, exercise or defend legal claims; or (c) to protect the rights of another natural or legal person.

  1. Right to Data Portability: To the extent that we process your information (i) based on your consent or under a contract; and (ii) through automated means, you have the right to receive such personal data in a structured, commonly used, machine-readable format, or you can ask to have it transferred directly to another data controller.

  1. Right to Object: You have the right to object to the processing of your personal data. However, we may still process your personal data if we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.

  1. Right to Object to Automated Processing.  You have the right to object to decisions based on automated processing, such as where a computer assesses factors in the data we collect about you and makes a determination. However, we do not currently make any decisions based on automated processing.

We retain your personal data for as long as necessary to provide you with our services, or for other important purposes such as complying with legal obligations, resolving disputes, and enforcing our agreements.

We ask that you attempt to resolve any issues regarding your data protection or requests with us first before contacting the relevant supervisory authority.  If you would like to exercise any of the rights described above, please send a request to privacy@Starailab.com. In your message, please indicate the right you would like to exercise and the information that you would like to access, review, correct, or delete.

We may ask you for additional information to confirm your identity and for security purposes, before disclosing the requested personal data.

We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.

When Starailab Acts as a Data Processor

Where we process your data in our capacity as a Data Processor, the processing of your data will not be governed by the foregoing provisions (“When We Act As Data Controller”), but you can contact the Data Controller directly to learn about their processing of your information and to exercise your rights, or we will forward your request directly to them at your request.

Starailab’s “privacy by design” approach requires that our default user data protection levels be at the highest setting by default. In the unlikely event of breach, Starailab will notify data subjects and Supervisory Authorities (SAs) in the EU according to procedures provided in GDPR Articles 33 and 34.

Lawful Requests

Starailab may be required to disclose personal information pursuant to lawful requests made by public authorities, including to meet national security or law enforcement requirements.

Inquiries and Complaints

We take safeguarding your privacy very seriously. If you wish to verify, correct or delete any personal information we have collected, or if you have any questions or concerns, or if you have any complaints, please contact: privacy@Starailab.com

Notice

When Starailab collects personal information from individuals, it will inform the individual of the purpose for which it collects and uses the personal information and the types of non-agent third parties to which Starailab discloses or may disclose that information. Starailab shall provide the individual with the choice and means for limiting the use and disclosure of their personal information. Notice will be provided in clear and conspicuous language when individuals are first asked to provide personal information to Starailab, or as soon as practicable thereafter, and in any event before Starailab uses or discloses personal information for a purpose other than for which it was originally collected.

In instances in which Starailab is not the controller or collector of the personal information, but only a processor, it has no means of providing individuals with the choice and means for limiting the use and disclosure of their personal information or providing notices when individuals are first asked to provide personal information to Starailab. In such instances, Starailab will comply with the instructions of the controller of such information; provide appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, and to the extent appropriate, assist the controller in responding to individuals exercising their rights under the Principles.

Choice

In those instances in which Starailab collects personal information from individuals, it will offer individuals the opportunity to choose (opt out) whether their personal information is (1) to be disclosed to a third party or (2) to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.

Disclosures to Third Parties

In those instances in which Starailab collects personal information from individuals, prior to disclosing personal information to a third party, Starailab shall notify the individual of such disclosure and allow the individual the choice to opt out of such disclosure. Starailab shall ensure that any agent third party for which personal information may be disclosed subscribes to these principles or are subject to law providing the same level of privacy protection as is required by these principles and agree in writing to provide an adequate level of privacy protection.

#5125545 v1 / 74507-001