Mysa Privacy Policy

Mysa – Privacy Policy

Date: 2020-September-21

We are Empowered Homes Inc., operating as Mysa (“Mysa”), and our mission is to help the world become more environmentally friendly and sustainable through energy efficiency and conservation, led by innovative technology that enriches lives. We care deeply about the privacy of our customers and users of our smart thermostat products (“Products”), Mysa mobile application (“App”) users, and visitors to our website, getmysa.com (the “Site”). The purpose of this Privacy Policy is to provide you with information about how we collect, use and disclose Personal Information. If you have any questions about this Policy, or about our Privacy Practices in general, please contact our Privacy Officer at privacy@getmysa.com.

 

By using our Site, purchasing a Product, downloading our App, or registering an account with Mysa, you indicate that you understand, accept, and consent to the practices described in this Privacy Policy. This Policy may change from time to time (see “Changes to our Privacy Policy”, below). Your continued use of the App, the Site or a Product after we make changes indicates that you accept and consent to those changes, so please check the Policy periodically for updates.

 

I. Collection and Use of Personal Information

“Personal Information” means information about an identifiable individual, or information that in combination with other, readily available information, might identify an individual. Examples include your name, email address, or IP address. Below is a description of the kinds of Personal Information we collect, the purpose for the collection, and how we use that information. We also collect information that is not Personal Information, as outlined below.

 

Any time we collect Personal Information, we limit the amount of information collected to what is necessary to achieve the purpose we collected it for, and retain it only as long as is needed for that purpose.

 

Note that our Site and App are not intended for children under the age of 13 years. No one under the age of 13 years may provide any Personal Information to or on the Site or App. We do not knowingly collect Personal Information from children under the age of 13 years. If you believe we may have collected any information about a child under the age of 13 years, please contact us at privacy@getmysa.com.

 

Site visits

When you visit or navigate through the Mysa Site, certain information is collected automatically from you, while other information is provided by you upon request.

 

Information collected automatically includes Site usage details, IP addresses, the OS system you may be running, and information collected through cookies, web beacons, and other tracking technologies. This information is used to allow Mysa to analyze visitation patterns to our Site, and to enhance a visitor’s experience when using our Site.

 

Information you may decide to provide Mysa upon request includes general information about your home and heating if you complete the “Mysa Compatibility Checker”, your email address or phone number if you ask us to contact you, or your name and email address if you choose to subscribe to our newsletter. If you subscribe to our newsletter, or otherwise ask to receive promotional emails or messages from us, you can unsubscribe at any time.

 

You can also choose to leave reviews and post pictures of your Mysa Product on the Site, which may include Personal Information (for example, your name or user name, and information about your use of and experience with the Mysa Product).

 

Cookies

Cookies are small pieces of data that are transferred to your computer’s hard drive through your Web browser from our Web server. A cookie cannot read data from your hard disk or read cookie files that may have been created from other sites. The Mysa Site utilizes cookies only as a means of providing personalization features to our visitors. In addition, we may use cookies to assist users in completing an incomplete purchase for items left in their shopping cart.

 

You can choose whether to accept cookies by changing the settings of your browser. Typically, by accessing the browser’s help feature you can obtain information on how to prevent your browser from accepting all cookies or to notify you when a cookie is being sent. If you choose not to accept these cookies, your experience at our website and other websites may be diminished and some features may not work as intended.

 

Our Site may contain links to other websites operated by third parties such as media sites and app stores and may include social media features such as Facebook and Twitter buttons (such as “Like,” “Tweet” or “Pin”). These third-party sites may collect information about you if you click on a link and the social media sites may automatically record information about your browsing behavior every time you visit a site that has a social media button. Your interactions with these features are governed by the privacy policy of the company providing the feature, not by our Privacy Policy. We do not control what information these third parties collect. Please review your privacy settings on your social media sites and think carefully before clicking on links which may take you to a third-party website.

 

In addition, we may permit third-party partners to use cookies and other technology to collect information about your browsing activities over time and across different websites when you use our Site. This cookie information may be used to generate custom and lookalike audiences and similar marketing outreaches.

 

You can opt-out of several third party ad servers' and networks' cookies simultaneously by using an opt-out tool created by the Digital Advertising Alliance of Canada or an opt-out tool created by the Network Advertising Initiative. You can also access these websites to learn more about online behavioural advertising and how to stop websites from placing cookies on your device. Opting out of a network does not mean you will no longer receive online advertising. It does mean that the network from which you opted out will no longer deliver ads tailored to your web preferences and usage patterns.

 

Online purchases

When you purchase a Mysa Product through our Site, we collect from you information required in order to complete the purchase transaction. In order to make a purchase through our Site, you must provide the following information:

  • Your Name
  • Billing Address (for Credit Card Orders)
  • Shipping Address
  • E-Mail Address
  • Phone Number
  • Credit Card Number (for Credit Card Orders)
  • Expiration Date (for Credit Card Orders)
  • CCV2 Code (for Credit Card Orders)

This information will be shared with our online shopping cart provider and payment processor, Shopify. We use shopping cart features that safeguard this information by using industry standard SSL (Secure Sockets Layer) encrypted servers. SSL encodes the information transferred between you and the server, rendering it unreadable to anyone trying to intercept the information. Your credit card data is not collected or stored by Mysa. For more information about Shopify’s privacy practices, please see their privacy policy, available here

 

Use of a Mysa Product

Once installed in your home, your Mysa Product will collect device and environmental or field data  at frequent intervals throughout the day, including room temperature and humidity, set point history, schedule history, voltage and current measurement and devise settings such as brightness and device mode (“Product Data”).

 

Product Data is processed both within the Product and remotely in order to allow the Product to optimize energy efficiency and minimize energy usage depending on the particular data. The Product Data is also used to prepare reports on your energy usage, which may be emailed to you. You can access your own energy usage reports at any time, through your account. Your usage reports are not available to anyone else.

 

All Product Data is stored using Amazon Web Services, and other cloud processing tools to analyze data and tailor features to the specific device environment or assist customers with technical issues. A Mysa Product has 30 minutes of storage for Product Data.  Every 30 minutes, this data is uploaded and cleared from Product memory. Some device settings are stored on the Product such as WiFi credentials, however they are protected using encryption, and can be deleted via a factory reset on the device. To delete any Product Information stored in the cloud, you must make a request to Mysa, as outlined below.

 

Creating an Account and using the App

When you download the Mysa App onto your mobile device, you will be asked to create a user account in order to start using the App. In order to create an account, you will be prompted to provide a username, your country and Province (or State) of residence, zip or postal code, your email address, and a password (“Account Data”). You will then be prompted to pair your mobile device app with your Mysa Product. You will also be asked for information about the location in which your Product is installed – for example, where in your home the Product is located, how many floors your home has, etc.

 

You can share your Mysa Product with additional accounts, so that more than one user can control a device. In order to do this, you must add in the additional users' name(s) and email addresses. Each additional user will have to create their own Mysa account to access the Mysa Product.

 

Once you have an account and it is paired with your Product, you will be able to remotely view and control your Product from anywhere on the internet via the App. You can also input additional information, such as a time schedule, to allow your thermostat settings to change at pre-selected times.

 

In order to enable location-based features relating to your Product, such as geo-fencing (allowing your Product to detect that you are away from your home and then automatically adjusting accordingly), you will be asked if you would like to provide geolocation data from your mobile device. Note that Mysa does not record the actual, physical location of you or your mobile device.  When a user sets geofence parameters, Mysa is able to detect whether the user’s mobile device is within those parameters. The actual locations of the geofence and the mobile device are unknown to Mysa. If you do not want Mysa to collect or use geofencing information, you can decline to provide this information, or at any time opt-out of providing location information through your device settings. Note, however, that opting out of the App's collection of location information will cause its location-based features to be disabled.

 

It is also possible to use a Product without creating an account, but there will be limited functionality.

 

If you have opted in to receiving communications from Mysa, we will provide personalized recommendations to you on how to get the most out of your Product.

 

Automatic Information Collection and Tracking Technologies through use of the App

Certain information is collected automatically when you download or use the App, such as usage details (for example, traffic data and data logs), and information about your device and internet connection, such as your device’s unique device identifier, IP address, OS system and browser type. Information is also collected through cookies and other tracking technologies (for more information, refer to the “Cookies” section, above).

 

The information we collect automatically is statistical information and may include Personal Information. This usage information helps us to improve our App to tailor our customer's experience and to deliver a more personalized service, including by helping us to:

  • Estimate our audience size and usage patterns.
  • Store information about your preferences and customize our App according to your individual interests.
  • Recognize you when you use the App.

If you do not want us to collect this information, do not download the App or delete it from your device.

 

II. Sharing of Personal Information

Mysa does not sell your Personal Information. We will only disclose your Personal Information that we collect or you provide as follows:

  • To our subsidiaries and affiliates to provide us or you with services related to your use of the Product or the App;
  • With your explicit consent;
  • To comply with the law;
  • To contractors, service providers, and other third parties we use to support our business, such as analytics and search engine providers that help us optimize and improve our services. We contractually require these third parties to keep Personal Information confidential, use it only for the purposes for which we disclose it to them, and to process Personal Information following the same standards set out in this Policy;
  • To protect and defend the rights or property of Mysa or Mysa customers/users, including to enforce our rights arising from any contracts between you and us, including the Mysa Terms of Use and for billing and collection;
  • To cooperate with the investigations of purported unlawful activities as required by law;
  • As part of business transitions, such as upon the sale of Mysa. In the event of a sale and a transfer of Personal Information in connection with a business transaction, Mysa will request that the purchaser treat all data in accordance with our Privacy Policy in place at that time.

For any other purpose we disclose when you provide the information.

 

Third party apps and integration

Mysa Products are capable of communicating and integrating with a growing number of third party devices, applications and services such as Alexa, Google Assistant, SmartThings, Apple HomeKit and IFTTT. If you enable integration with a third party service, you agree to share your Mysa Account Data and Product Data with that third party. Each of these third parties have their own privacy policies that may apply.

 

Transferring your Personal Information

We may transfer Personal Information that we collect or that you provide us to contractors, service providers, and other third parties we use to support the App and our Site (such as analytics providers that assist us with App and Site improvement and optimization) and who are contractually obligated to keep Personal Information confidential, use it only for the purposes for which we disclose it to them, and to process the Personal Information with the same standards set out in this Policy.

 

We may process, store, and transfer your Personal Information in and to other countries with different privacy laws that may or may not be as comprehensive as Canadian law. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that country may be able to obtain access to your Personal Information. Whenever we engage a service provider, we require that its privacy and security standards comply with this policy and applicable Canadian laws.

 

III. Accessing and Correcting your Personal Information

It is important that the Personal Information we hold about you is accurate and current. Please keep us informed if it changes. By law you have the right to request access to and to correct the Personal Information that we hold about you. You can review and change some of the Personal Information we hold by logging into the App and visiting your account profile. Certain Personal Information we store is not accessible by you through your account profile, but can be accessed by you upon request.

 

If you want to review, verify, correct, or withdraw consent to the use of your Personal Information you may send us an email at privacy@getmysa.com to make the request. In order to accommodate a request, we may ask you for additional information from you to prove your identity.

 

Applicable law may allow or require us to refuse to provide you with access to some or all of the Personal Information that we hold about you, or we may have destroyed, erased, or made your Personal Information anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.

 

If you are concerned about our response or would like to correct the information provided, you may contact our Privacy Officer at privacy@getmysa.com.

 

IV. Data Retention

Except as otherwise permitted or required by applicable law or regulation, we will only retain your Personal Information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Under some circumstances, we may anonymize or aggregate your Personal Information so that it can no longer be associated with you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose without further notice to you or your consent.

 

Any data stored on your Product can be deleted through a factory reset of the device. In order to request that any Personal Information stored in the cloud (or using any additional software tool) by Mysa be deleted, please make a request to Mysa, in writing, at privacy@getmysa.com.

 

V. Safeguarding of Personal Information

The security of your Personal Information is very important to us. We use physical, electronic, and administrative measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. We store all information you provide to us on secure servers.

 

The safety and security of your information also depends on you. Where we have given you (or you have chosen) a password for access to certain parts of our App (for example, to access your account), you are responsible for keeping it confidential. We ask you not to share your password with anyone. Unfortunately, the transmission of information via the Internet and mobile platforms is not completely secure. Although we do take commercially reasonable measures to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted through the App or our Site. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any App privacy settings or security measures.

 

VI. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes to this Privacy Policy will be posted on this page so that you are always aware of the information that we collect, how we use it, and under what circumstances we disclose it.

 

We include the date the Privacy Policy was last revised at the top of the page. You are responsible for ensuring you periodically visit this page to check for any changes.

 

I. California Privacy Rights

As of January 1, 2020, residents of California have additional rights related to their Personal Information under the California Consumer Privacy Act (CCPA), if applicable:

  • You have the right to request that Mysa discloses what Personal Information it collects, uses and discloses.
  • You have the right to request the deletion of your Personal Information stored by Mysa.
  • You have the right to opt-out of the sale your Personal Information by Mysa. Since we do not sell your Personal Information, you are deemed to have opted out.
  • You have a right to have an authorized agent make a request under the CCPA.
  • You have a right not to receive discriminatory treatment by Mysa for the exercise of the privacy rights conferred by the CCPA.

 

II. Contact Information and Challenging Compliance

We welcome your questions, comments, and requests regarding this Privacy Policy and our privacy practices. Please contact us at privacy@getmysa.com. We have procedures in place to receive and respond to complaints or inquiries about our handling of Personal Information, our compliance with this Policy, and with applicable privacy laws. To discuss our compliance with this policy please contact our Privacy Officer using the contact information listed above.