Skip to content

Flex Privacy Policy

Effective Date: Aug 14, 2026

This Privacy Policy explains how Hyena Inc. collects, uses, discloses, and otherwise processes personal information through the Flex mobile application, Flex web pages, connected e-bike features, and related support services that link to this Privacy Policy. It also explains the privacy rights and choices available to users.

1. Scope and Identity of the Company

Hyena Inc. provides the Flex platform and is the entity responsible for the personal information described in this Privacy Policy. In this Privacy Policy, "Flex," "Hyena," "we," "us," and "our" refer to Hyena Inc. "Services" means the Flex mobile application, Flex web pages, connected e-bike features, software, support resources, and related services that link to this Privacy Policy.

This Privacy Policy does not apply to a Hyena product or service that displays a different privacy notice, including the Hyena corporate website, Hyena Rider Assistant, Kalkhoff Display, dealer tools, fleet or employer programs, and other business-to-business services, unless the applicable notice expressly states otherwise. Information processed by Apple, Google, Strava, Tree-Nation, a social network, or another independent third party under that party's own terms and privacy policy is outside the scope of this Privacy Policy after the third party receives it. Section 4 explains when Flex discloses information to those parties.

Our Terms of Service govern use of the Services. Section 12 of this Privacy Policy contains the Consumer Health Data notice for applicable U.S. consumer health data laws. This Privacy Policy supplements, but does not replace, contextual notices shown at account creation; when location, heart-rate, public-sharing, EcoGem, research, AI, or integration features are activated; and at other points where law requires notice or consent.

This Privacy Policy and contextual feature notices apply together. Where a feature-specific notice conflicts with this Privacy Policy, the feature-specific notice controls only for that feature and to the extent of the conflict. Region-specific notices appear in Section 11 and Section 12 for the United States, and in Section 13 for the EEA and UK.

Meaning of “GDPR” and EU/UK differences. In this Privacy Policy, references to the “GDPR” mean the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR (as defined in the UK Data Protection Act 2018) together, and Article references apply to both, save where a difference is indicated. Where the two regimes impose different requirements — in particular the digital age of consent under Article 8, the instruments used for transfers of personal data to third countries, and the competent representative and supervisory authority — the rules applicable to the relevant territory govern, as set out in the corresponding sections. For users in the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO); for users in the EEA, it is the competent national supervisory authority.

2. Personal Information We Collect

We collect personal information from users, automatically through the Services and connected devices, from service providers, and from third parties that a user chooses to connect. The information available to us depends on the features a user activates, device permissions, privacy settings, and interactions with the Services.

2.1 Information a User Provides

Account and authentication information. We collect a user's name, email address, authentication identifier or token, age range, and other information needed to create and secure an account. A user may create an account through Sign in with Apple or Google Sign-In. Flex does not receive the password used for the user's Apple or Google account. Apple users may choose to provide an Apple private relay email address.

Profile information. We collect information a user chooses to add to a profile, such as a username, avatar, background image, age range, e-bike model, and riding goals or preferences. Except where a field is identified as required, profile information is optional.

Content and communications. We collect routes, photos, posts, comments, reports, survey responses, feedback, support requests, and other information a user submits through the Services, including health, location, or other sensitive information a user chooses to include. We may also receive information about a user that another person submits in a report, comment, support request, or similar communication. We collect metadata needed to deliver, moderate, secure, and resolve that content.

Consent and preference records. We maintain records of privacy choices, device permissions, consent, withdrawal, account visibility, route-visibility settings, connected integrations, notification choices, parent or legal guardian assent where applicable, and requests to exercise privacy rights. A parent or legal guardian assent record may include the parent or legal guardian's name, contact information, relationship to the user, verification signal, Terms version, timestamp, revocation, and the minor account concerned.

2.2 Information Generated Through Use of the Services

Ride and activity information. When a user records or uploads a ride, we collect information such as date, time, duration, distance, elevation gain and loss, estimated calorie expenditure, estimated carbon-dioxide savings, speed, cadence, rider power, battery level, estimated remaining range, motor-assistance level, connection status, goals, quests, achievements, EcoGem activity, and related statistics. Some values are estimates. Ride information is treated as health data, and as a special category of personal data under Article 9 GDPR, only to the extent it identifies, reveals, or is used to infer a person’s physical or mental health status; the same information is treated as consumer health data under applicable U.S. state law.

Precise location and route information. Following the required disclosure, the device permission, and any consent required by law, Flex collects precise location when the user starts an active ride or another location-enabled feature. The device permission is a technical access control and is not, by itself, the legal basis for the processing; the applicable legal bases are set out in Section 13. Collection may continue while the app is not visible during the active feature. It does not begin merely because the app is open. Collection ends when the user ends the feature or disables location access, subject to limited buffering or later synchronization of points already recorded. Device and in-app indicators identify active collection where supported. A crash, forced app closure, phone restart, or permission change may interrupt recording. Disabling location prevents future route recording and other location-dependent functions.

Interaction and community information. We collect information about activities viewed, users followed or blocked, followers, likes, comments, reports, hidden content, campaign participation, feed interactions, weekly goals, and similar actions.

Device, telemetry, and log information. We collect device type, operating-system and app version, language, time zone, network and Internet Protocol address, device and application identifiers, Bluetooth and connection identifiers, authentication events, session and diagnostic logs, crash reports, performance data, security events, and similar technical information. When needed to pair, operate, support, or secure a connected e-bike, we may also collect the bike model and component or product identifiers associated with the connection. Flex does not use advertising identifiers for targeted advertising.

Cookies and similar technologies. The native Flex application uses software development kits and similar technologies rather than browser cookies. Flex web pages may use cookies, pixels, local storage, and similar technologies. Section 6 provides additional details.

2.3 Information From Connected Devices and Services

Connected e-bikes and sensors. A connected e-bike transmits ride, component, connection, and performance data needed to provide the Services. If a user separately chooses to connect a compatible heart-rate sensor and provides the required consent, Flex collects heart-rate readings for rides. Flex will not begin optional heart-rate collection merely because a sensor is discoverable; the user must first give explicit consent through the separate consent flow described in Section 12, which the user may decline or later withdraw without losing access to the core Services. For users in the EEA and UK, this constitutes explicit consent within the meaning of Article 9(2)(a) GDPR, as the legal basis described in Section 13.

Apple Health and Strava. These integrations are under development and are not currently available. If Flex offers an export and a user activates it, Flex will send the selected Flex ride information to the chosen account at the user's direction. Unless separately disclosed and authorized, Flex will not import Apple Health records or Strava activity data. Flex may receive integration metadata needed to connect and operate the export, such as authorization results, account or athlete identifiers, access tokens, scopes, connection status, errors, and transaction responses. A user will be able to disconnect an integration to stop future exports and revoke Flex-held tokens where applicable. Disconnection will not delete information previously received by the third party; the user must use that party's tools to manage it.

Third-party sign-in. When a user signs in through Apple or Google, we receive information authorized by the user and the provider, which may include a name, email address, private relay address, profile information, and authentication token. The provider's controls determine what information is made available.

Service providers, campaign providers, connected-device partners, and other users. We may receive information from support and survey providers, fraud and security providers, campaign fulfillment providers, e-bike manufacturers, brands, dealers, repair providers, sensor providers, and other Flex users. If a user requests warranty, maintenance, firmware, dealer, or manufacturer support through Flex, we may receive or disclose the minimum account, component, diagnostic, connection, or support information needed to fulfill that request. The relevant party may act as a processor under Hyena's instructions or as an independent controller under its own notice, depending on the service.

3. How We Use Personal Information

We use personal information for the purposes described below and do not use it for materially incompatible purposes without providing any notice or consent required by law.

3.1 Provide and Personalize the Services

We use information to create, authenticate, secure, and maintain accounts; connect an e-bike or sensor; record rides; display routes, performance summaries, and statistics; calculate estimates; enable goals, quests, campaigns, and EcoGem functions; provide feeds and user suggestions; enable follows, likes, comments, reports, blocks, and other community features; provide data exports and user-directed integrations; and remember settings and choices.

We may use a general riding area, derived from route information as a city, district, or similar place name rather than a precise route, to rank a feed or suggest activities relevant to the user. We do not use precise routes or consumer health data for third-party advertising.

3.2 Communicate With Users

We use contact and account information to send service messages, security alerts, support responses, rights-request communications, policy and terms notices, and invitations to optional research or surveys. We send in-app and push notifications about account activity, goals, community interactions, campaigns, and weekly recaps according to a user's settings and device permissions.

Flex does not currently send promotional email or SMS messages. We may invite users to optional research or surveys, and recipients may decline future invitations. Before introducing promotional messages or location-based advertising, we will provide any notice, consent, and opt-out method required by law.

3.3 Operate Eco Campaigns and Rewards

We use ride, goal, account, e-bike, and EcoGem information to determine eligibility, record earning and redemption activity, prevent manipulation, administer campaigns, and fulfill a redemption selected by the user. When a user chooses a Tree-Nation or similar redemption, we disclose the information identified in the confirmation screen to the fulfillment provider. Where feasible, we use a campaign identifier rather than a full name or email address.

3.4 Support, Safety, Security, and Enforcement

We use information to answer requests; troubleshoot the Services; authenticate users; detect fraud, fake rides, manipulation, spam, malicious activity, security incidents, and violations of the Terms of Service or Community Standards; investigate reports; restrict or remove content; block interactions; suspend community features; terminate accounts; protect users and the public; and preserve evidence.

Reports are not identified to the reported user except when required by law or necessary to protect rights or safety. Authorized personnel and service providers may review reported content and related account information. We may use automated tools to identify potentially harmful or prohibited content. Flex provides any content-moderation notice, complaint-handling process, statement of reasons, or internal review required by applicable law and may offer a voluntary process where available.

If and to the extent the EU Digital Services Act applies to Flex, Flex will provide the statement of reasons, complaint-handling, and other process required by that law. The applicable process will be described in the then-current Community Standards or another designated legal notice.

3.5 Analytics, Product Improvement, and Research

We use device, telemetry, interaction, and appropriately minimized ride information to understand reliability and feature use, diagnose crashes, improve security, measure performance, develop and test features, and conduct internal research. Where reasonably possible, we use aggregated or deidentified information.

We do not use consumer health data, precise route information, or Strava-derived data to train a general-purpose artificial-intelligence model. We do not permit a service provider to use Flex personal information to train its own general-purpose model.

3.6 Artificial Intelligence Features

Flex does not offer a consumer-facing artificial-intelligence or machine-learning feature in version 1.0. Progress summaries are calculated algorithmically. Hyena may use internal staff tools to assist moderation, but that internal use is not a consumer AI feature. Before a future consumer AI feature uses personal information in a materially different way, we will update the relevant notice and obtain any consent required by law.

If Flex later offers a consumer AI feature, its output may be inaccurate and is not medical, fitness, safety, or professional advice. Hyena will use data minimization, access controls, testing, and human review appropriate to the feature. Flex will not use consumer AI to make decisions that produce legal or similarly significant effects concerning a user without the notice and safeguards required by law.

We use and preserve information to comply with law; respond to valid legal process; protect legal rights; prevent death, serious bodily harm, fraud, or abuse; establish, exercise, or defend legal claims; conduct audits; complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets; and fulfill other lawful corporate obligations.

4. How We Disclose Personal Information

We disclose personal information only as described below, according to user settings and directions, and as permitted or required by law.

4.1 Other Users and the Public

Each activity has a visibility setting. For users 18 and over, "Anyone" (public — viewable by Flex users and the public, including search engine results) is pre-selected. For users 16 and 17, "Only me" (private) is pre-selected. The setting is shown on the Save Activity screen before the activity is published. The user can change it there, change it on a saved activity at any time, or change the pre-selected value in settings. An activity marked "Only me" is not displayed to other users, although Hyena and its providers may access it for operation, support, safety, security, and legal purposes.

An activity marked "Anyone" may be viewed by registered users, people without a Flex account, search engines, and anyone who receives the link. Public content may be copied, cached, indexed, exported, or reshared by others. Viewers may see the username, profile image, e-bike model, the activity title, date, time, and place name, the description, photos and videos, the route, ride statistics such as distance, moving and elapsed time, elevation gain, calories, average and maximum speed, rider power, and cadence, estimated carbon-dioxide savings, and badges earned. Within Flex, viewers may also see likes and comments, and the people who left them.

Profile information is visible to other Flex users and is not controlled by the activity visibility setting. A profile shows the username, profile and background images, e-bike model, follower and following counts and lists, XP, level, EcoGem balance, current streak, total activities, estimated carbon-dioxide savings, trees planted through Eco Campaigns, badges, and aggregate riding statistics. Other users can reach a profile from the Feed, an activity, a comment, or a follower or following list. Setting every activity to "Only me" does not hide profile information. Blocking another user limits interaction within Flex but does not prevent that person from opening a shared activity link or viewing an intentionally public page while logged out.

Map Visibility hides the displayed start and end portions of a route. It is enabled by default with a 200-metre hidden range. A user can change the range or turn it off under Settings → Map Visibility. A change applies to activities recorded afterwards and does not change how a previously published route is displayed. Masking applies to the map shown to others and does not change or delete the route data Hyena holds. Elevation, place names, photos, timing, other metadata, exports, prior links, and cached copies may still reveal a location.

4.2 Service Providers

Hyena uses service providers that process personal information on Hyena's behalf and subject to the contractual and legal restrictions applicable to their roles. Certain connected-device partners, campaign providers, integrations, or other recipients may instead process information independently under their own terms and privacy notices. Section 4.3 and Section 4.4 describe user-directed and independent recipients. A service provider acting as a processor within the meaning of Article 28 GDPR processes personal data only on Hyena’s documented instructions and not for its own purposes, and is bound by a data processing agreement covering confidentiality, security, sub-processing, assistance, and deletion or return of the data. A recipient that determines its own purposes and means (such as an independent integration or connected-device partner) acts as a separate controller under its own privacy notice. Engaging a processor does not itself provide a legal basis for the processing: the underlying collection and use continue to require, and rely on, the legal bases set out in Section 13, including explicit consent under Article 9(2)(a) GDPR for health data. The data processing agreement and any transfer safeguards supplement, but do not replace, those legal bases.

Flex uses the following providers and provider categories:

  • Amazon Web Services and applicable Google Firebase infrastructureFunction: Hosting, database, storage, transmission, and application-infrastructure services used to operate Flex. These providers process information for Hyena subject to the contractual and legal restrictions applicable to the deployed services. Information potentially processed: Account, content, ride, route, activated health, device, security, preference, and other service information needed for the relevant data flow.
  • Google Firebase AuthenticationFunction: Authentication and account-security services used to create and protect Flex accounts. Its processing is governed by the deployed configuration, applicable contract, this Privacy Policy, and the provider terms that apply to the service. Information potentially processed: Account identifier, email or relay address, authentication token, and security events; not heart-rate readings or health records.
  • MapboxFunction: Maps, geocoding, elevation, and route-rendering functions. Depending on the requested function, Mapbox may receive coordinates, route points, map requests, device information, and network information. Its processing is governed by the applicable service configuration, contractual terms, this Privacy Policy, and the Section 12 of this Privacy Policy. Information potentially processed: Coordinates, route information, map requests, device and network information, including health-related location information where a route could reasonably indicate a health-service visit.
  • OneSignalFunction: Push-notification delivery and related message operations used by Flex, subject to the applicable configuration and contractual restrictions. Information potentially processed: Device or push token, notification identifier, notification content, and account or event identifier needed for the message.
  • Amplitude, Firebase Analytics, and SegmentFunction: Product analytics and event routing used to understand feature use, reliability, and performance, subject to the configured event schema and applicable contractual restrictions. Information potentially processed: Device, app, event, interaction, and pseudonymous account information defined by the configured event schema.
  • Firebase Crashlytics and Firebase Performance MonitoringFunction: Crash diagnosis and technical-performance monitoring used to maintain and improve Flex, subject to the deployed configuration and applicable contractual restrictions. Information potentially processed: Device, app, crash, log, and performance information generated by the configured diagnostic tools.
  • AI feature providers, if introducedFunction: Role and feature-specific processing disclosed before launch. Information potentially processed: Only information described in an updated notice and, where required, a consent flow.
  • Support, survey, security, and content-moderation providersFunction: Support, research, safety, moderation, and security as service providers when acting under Hyena's instructions. Information potentially processed: Only the account, content, communication, device, or event information needed for the applicable task.

Hyena reviews the provider list as the Services change and updates this Privacy Policy when a new provider materially changes the information processed or the purposes described here.

Section 12 of this Privacy Policy governs consumer health data. In version 1.0, analytics, crash-reporting, performance-monitoring, and notification payloads do not receive raw heart-rate readings or raw GPS paths. Notification payloads contain only a username and activity title. Mapbox receives coordinates and related map requests, not heart-rate readings. Content moderation reviews reported content only. Support tools, cloud logs and observability, and security tools receive access only as necessary for the authorized purpose and are subject to the restrictions and verification described in Section 12.

4.3 User-Directed Services and Sharing

We disclose information when a user connects or directs a service, such as exporting a ride to Apple Health or Strava, sharing a link through email or social media, or redeeming a campaign reward. The receiving party's terms and privacy policy govern information after receipt.

4.4 Campaign, Fulfillment, and Connected-Device Partners

For a Tree-Nation redemption, Flex may disclose the user's name and email address, campaign identifier, redemption details, and confirmation information when those details are needed to issue a certificate in the user's name or fulfill the selected benefit. The confirmation screen identifies the data and recipient before disclosure. Where the provider supports a campaign identifier or user-selected display name instead, Flex may offer that less-identifying option. Depending on the arrangement, Tree-Nation or another provider may act for Hyena, independently under its own notice, or in a mixed role.

If a user requests manufacturer, dealer, repair, warranty, maintenance, firmware, or connected-device support through Flex, the relevant partner may receive the minimum account, component, diagnostic, connection, or support information needed for that request. The partner's role and independent information practices are disclosed where applicable.

We may preserve or disclose information if we reasonably believe disclosure is required by law or valid legal process; necessary to prevent death, serious bodily harm, fraud, abuse, or a security incident; needed to investigate or enforce an agreement; or necessary to protect rights, property, users, or the public. We may also transfer information in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable notice and purpose limitations.

4.6 Deidentified and Aggregated Information

We may disclose information that has been aggregated or deidentified so that it cannot reasonably be linked to an individual or device. We maintain deidentified information in deidentified form and do not attempt to reidentify it except as permitted by law to test deidentification methods. We apply contractual restrictions to recipients where required. Removing a name alone does not make a precise route, unique bike identifier, or small-cohort dataset deidentified.

4.7 No Sale of Personal Information and No Advertising Use

Flex does not sell personal information as "sale" is defined under applicable U.S. state privacy laws and does not share personal information for cross-context behavioral or targeted advertising. Flex does not use consumer health data or precise routes for advertising.

If these practices change, we will update this Privacy Policy before the change, provide required notices and controls, and obtain affirmative consent where required.

5. Public Content and Location Safety

A public route can reveal sensitive patterns, including where a person lives, works, attends school, receives health or other services, worships, or regularly travels. Users should review the route, audience, and Map Visibility setting before publishing it. Users should avoid posting their own sensitive health or location information and must not disclose another person's information without authority. Additional protections for a known minor depend on applicable law and the product configuration described at the time of use.

A user who makes content public directs Flex to display that content according to the selected setting. A later change to private visibility stops Flex from displaying the activity publicly, but copied content, third-party shares, search-engine caches, and prior exports may remain outside Flex's control.

Additional restrictions on health-related location information, including requirements that apply where California law applies, are described in Section 12 of this Privacy Policy contains additional consumer-health restrictions and details.

6. Cookies, SDKs, and Similar Technologies

The native Flex application uses SDKs and similar technologies for authentication, maps, push notifications, analytics, crash reporting, performance monitoring, security, and requested integrations. Flex web pages may use cookies, pixels, local storage, scripts, and similar technologies for essential functions, preferences, security, and analytics.

A cookie or SDK may collect device, browser, network, event, interaction, and pseudonymous identifier information. We do not authorize analytics providers to use Flex data for their own advertising, cross-client profiling, or combination with unrelated-service data for cross-context behavioral advertising. No third party is authorized to collect personal information through Flex over time and across unrelated websites or online services for advertising or an independent profiling purpose.

Where required, nonessential technologies will not operate until the user provides consent. A user can manage cookies through Flex cookie settings where available and through browser controls. Where legally required and technically applicable, we recognize a qualifying universal opt-out preference signal, such as Global Privacy Control, as a request to opt out of sale or targeted-advertising sharing. Flex currently does not engage in either activity, so the signal confirms rather than changes current practice. If Flex later implements a consent-management platform or materially expands website tracking, Hyena may publish a separate Cookie Policy in addition to this section. Independently of data protection law, the storing of information on, and the gaining of access to information already stored in, a user’s terminal equipment — including through cookies, SDKs, local storage, and device identifiers — is governed in the EEA by the national laws implementing Article 5(3) of the ePrivacy Directive (2002/58/EC), for example Section 25 of the German TDDDG, and in the United Kingdom by the Privacy and Electronic Communications Regulations. Under those rules Flex accesses or stores such information only with the user’s consent, except where this is strictly necessary to provide a service explicitly requested by the user (for example authentication, security, or delivering a notification the user has enabled). Any resulting processing of personal data additionally requires a legal basis under the GDPR, as described in Section 13.

The Hyena corporate website uses a separate cookie and privacy notice. Its technologies and practices are not Flex practices unless this Privacy Policy expressly says otherwise.

7. Privacy Rights and Choices

Depending on location and applicable law, a user may have the rights described below. Hyena may provide some rights voluntarily even when not legally required.

Access and portability. A user may request confirmation of processing, access to personal information, and a portable copy. The in-app export under Settings > Export Data provides a structured file that may include profile, rides, routes, GPS data, e-bike pairings, goals, rewards, content, comments, likes, photos, and heart-rate data if collected.

Correction. A user may correct editable profile and account information in settings or request correction of an inaccurate profile field, bike association, route record, or inference. Measured sensor and ride records may be preserved as originally captured for integrity, fraud prevention, or legal purposes. Where alteration would compromise integrity, Flex may correct the associated field, annotate the record, or delete it where appropriate and legally permitted.

Deletion. A user may delete individual activities or content and may initiate account deletion under Settings > Delete Account. Account deletion removes or deidentifies personal information subject to legal, security, fraud-prevention, backup, and other permitted exceptions. Public comments, likes, and thread interactions may be deleted, anonymized, or retained under a generic label where needed to preserve another user’s conversation, moderation evidence, or legal rights. Completion may take up to 45 days for active systems. For requests under the GDPR or UK GDPR, erasure is completed without undue delay and in any event within one month of receipt, extendable by up to two further months where necessary given the complexity and number of requests (Article 12(3)); where a shorter statutory period applies, that shorter period governs. Covered consumer health data in archives or backups is deleted within the period required by applicable law.

Consent withdrawal. A user may withdraw consent prospectively, including by disconnecting a heart-rate sensor or integration and changing device permissions. Withdrawal takes effect for the future only: from the point of withdrawal Flex stops collecting the affected data, while processing carried out before withdrawal remains lawful. Personal data already collected on the basis of the withdrawn consent, including health data, are deleted or anonymised after withdrawal unless another legal basis (such as a statutory retention obligation or the establishment, exercise, or defence of legal claims) requires their continued retention. Withdrawal does not affect information already received by a third party.

Opt out of sale, targeted advertising, or qualifying profiling. Flex currently does not sell personal information, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. If this changes, Flex will provide required opt-out methods before the practice begins.

Limit use of sensitive personal information. Flex uses precise geolocation, account authentication information, and consumer health data only to provide requested Services and for other purposes permitted by applicable law. Flex does not use sensitive personal information to infer characteristics for advertising.

Appeal. If Hyena denies a request and applicable law provides an appeal right, the response explains how to appeal. An appeal may be submitted using the denial instructions or by emailing flex@hyenatek.com with the subject line "Privacy Appeal." Hyena responds within the period required by applicable law and identifies the relevant regulator or complaint method if the appeal is denied. A user in the EEA, the UK, or Switzerland may at any time lodge a complaint with their local data protection supervisory authority, whether or not an appeal has been submitted.

No discrimination. Hyena will not unlawfully discriminate against a user for exercising a privacy right.

7.1 How to Submit a Request

A user may use the in-app privacy controls or contact flex@hyenatek.com with the subject line "Privacy Request." If a user cannot access the app, the email method remains available.

We may verify a request through the existing account, control of the associated or relay email address, or other information reasonably necessary to match the request. If the user has lost Apple or Google access, we use a proportionate alternative that is available in the approved request process. We do not request sensitive information that is unnecessary for verification.

An authorized agent may submit a request by emailing flex@hyenatek.com with the subject line "Authorized Agent Privacy Request" and providing written permission or other legally sufficient proof of authority. We may also verify the consumer directly. A parent, guardian, or other legally authorized person may exercise a minor's rights where applicable, subject to verification of authority.

We generally respond within 45 days, subject to a permitted extension. For requests under the GDPR, Hyena responds without undue delay and in any event within one month of receipt; that period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, and Hyena informs the user of any such extension within one month. Requests are free, although a reasonable fee may be charged or a request may be denied if permitted by law and the request is manifestly unfounded, excessive, or repetitive.

8. Retention

We retain personal information only for as long as reasonably necessary and proportionate to the disclosed purposes, taking into account account status, user controls, sensitivity, security, fraud prevention, legal obligations, disputes, and technical requirements.

  • Account and profile information — For the life of the account and a limited period after deletion as needed to complete the request, protect security, prevent fraud, resolve disputes, and meet legal duties.
  • Ride, route, precise location, photos, posts, comments, and health data — Until the user deletes the item or account, unless a legal hold, security need, or other permitted exception applies; public copies and third-party exports may remain outside Flex.
  • Consent, parent or legal guardian assent, and privacy-choice records — For as long as needed to demonstrate and honor the choice, manage age transitions or revocation, and meet applicable legal recordkeeping requirements.
  • EcoGem, redemption, and missing-credit records — For as long as needed to administer the program, validate claims, resolve disputes, prevent fraud, document fulfillment, and meet tax, accounting, or legal duties.
  • Support, report, moderation, privacy-rights appeal, and complaint records — For as long as needed to resolve the matter, document reviewer notes and outcomes, protect users, enforce standards, and establish or defend legal claims.
  • Security, authentication, diagnostic logs — Retained for no longer than necessary for security, reliability, and diagnostic purposes, save where continued storage is required in an individual case to establish, exercise, or defend legal claims.
  • Analytics and telemetry records — Retained for no longer than necessary to establish reliability and performance baselines, and to understand feature use, and are then deleted or aggregated; the retention period is determined by reference to the analysis window needed for that purpose, subject to any shorter period set by the applicable vendor configuration.
  • Backups and Hyena-controlled caches — According to the approved disaster-recovery and cache-expiration schedule; deleted data is not returned to ordinary active use, and covered consumer health data is removed within the period required by applicable law.
  • Deidentified and aggregated information — May be retained without a fixed period if maintained in deidentified form and not reidentified.

Beyond the periods and criteria stated above, Hyena retains personal data only for as long as necessary for the purposes described and thereafter deletes it, unless a statutory retention obligation (for example under tax or commercial law) requires longer storage, in which case the data are restricted from other processing until the obligation expires.

9. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risks to individuals, Hyena implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures include, as appropriate, the encryption and pseudonymisation of personal data; measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems; the ability to restore availability and access to personal data after an incident; and a process for regularly testing and evaluating the effectiveness of the measures. Controls are applied in particular to the sensitivity of precise location and health data. No method of storage or transmission is completely secure. Users should protect their device, Apple or Google account, and authentication methods and should promptly report suspected unauthorized access.

Access to consumer health data and raw precise location is limited to personnel and providers that need it for authorized purposes. A provider acting for Hyena is subject to confidentiality, security, incident-notification, use, assistance, and deletion duties required for its legal role.

10. Users Age 16 and Older

The Services are not intended for anyone under 16, and we do not knowingly collect personal information from a person under 16. Hyena applies 16 as a uniform minimum age across the EEA and the UK; this is the highest age of consent permitted under Article 8 GDPR, so no lower national threshold requires a separate, lower age for Flex. A person under 16 must not create an account. If we learn that an account belongs to a person under 16, we will take reasonable steps to remove the account and associated information.

Users age 16 or 17 receive Only Me activity defaults and additional protections required by applicable law and the approved product design. These users may change the default visibility in settings or set visibility for each activity when saving it. Where the UK Age-Appropriate Design Code applies, we provide an age-appropriate experience consistent with that code and with other applicable children's privacy standards. We do not sell or use known minors' personal information for targeted advertising. We do not knowingly retain a minor's precise location longer than reasonably necessary for the requested feature.

Flex may limit, alter, or restrict a minor's account or feature when consent, parental authorization, age assurance, or another protection is required by applicable law and cannot be obtained. A parent or legal guardian who believes a person under 16 has used the Services, or who wishes to exercise a minor's applicable privacy rights, may contact flex@hyenatek.com.

11. Notice for Residents of Certain U.S. States

This section supplements the rest of this Privacy Policy when a U.S. state privacy law applies to Hyena or the processing. Rights and obligations vary by state and may be subject to effective dates, thresholds, exemptions, and exceptions. Because state-law coverage changes over time and depends on the circumstances, this section is organized by data category and right rather than an exhaustive static list of states. Section 11.2 provides California-specific disclosures. Section 12 and the standalone Consumer Health Data section of this Privacy Policy address Washington, Nevada, Connecticut, and similar consumer-health laws. Hyena may provide some rights to users even when a particular state law does not apply to Hyena.

11.1 Categories of Personal Information

Depending on the features used, Flex collects and may disclose the categories below. To the extent required by applicable law, these disclosures also describe practices during the preceding 12 months. Flex does not sell these categories or share them for cross-context behavioral advertising.

Identifiers

Examples: Name, email, username, authentication token, IP address, device or app identifier, and parent or legal guardian contact and assent records where applicable. Sources: The user; a parent or legal guardian; Apple or Google; the device; and service providers. Purposes: Account creation and maintenance, authentication, age eligibility, parent or legal guardian assent, support, security, and notifications. Recipients: Hosting, authentication, push-notification, support, analytics, and security providers.

Customer Records and Profile Information

Examples: Profile image, age range, e-bike information, preferences, and parent or legal guardian relationship where applicable. Sources: The user; a parent or legal guardian; and the connected e-bike. Purposes: Profile functions, personalization, age-appropriate experience, assent, and service operation. Recipients: Hosting and support providers; other users only according to the user's settings.

Internet, Application, and Network Activity

Examples: App events, viewed content, likes, follows, session and log data, and cookie or SDK events. Sources: The device, application, web pages, and SDKs. Purposes: Service operation, analytics, security, and improvement. Recipients: Analytics, crash-reporting, performance, hosting, and security providers.

Precise Geolocation and Route Information

Examples: GPS coordinates, routes, elevation, and place names. Sources: The device, connected e-bike, and map provider. Purposes: Ride recording, maps, statistics, and user-directed public display. Recipients: Hosting and map providers; other users or the public according to the user's settings.

Sensory and Content Information

Examples: Photos, posts, comments, reports, support communications, and health or location information included in user content. Sources: The user and other users. Purposes: Community features, moderation, support, and safety. Recipients: Hosting, support, moderation, and security providers; other users or the public according to the user's settings.

Commercial and Reward Information

Examples: EcoGem earning, campaign participation, redemption, and e-bike association. Sources: User activity, Flex, and fulfillment providers. Purposes: Rewards administration, fulfillment, and fraud prevention. Recipients: Hosting, campaign, and fulfillment providers.

Device, Telemetry, and Component Information

Examples: App version, device type, crash data, battery, speed, cadence, power, motor assistance, connection status, and bike or component identifiers. Sources: The device, connected e-bike, SDKs, and connected-device partners. Purposes: Service operation, diagnostics, analytics, ride summaries, and user-requested warranty or maintenance support. Recipients: Hosting, analytics, crash-reporting, performance, map, manufacturer, dealer, repair, or sensor providers, as applicable.

Health or Wellness Information

Examples: Heart rate, calorie estimates, fitness goals, health-related inferences, health information submitted in content, and covered health-related location. Sources: The user; other users; a sensor; the connected e-bike; device location; and Flex calculations. Purposes: User-requested summaries, maps, statistics, support, safety, and security. Recipients: Restricted infrastructure, map, support, security, and user-directed integration recipients described in Section 12.

Inferences

Examples: Feed ranking, ride trends, goal progress, and fraud or safety signals. Sources: The information described in this Privacy Policy. Purposes: Personalization, security, moderation, and service improvement. Recipients: Hosting, analytics, security, and moderation providers.

Sensitive Personal Information

Examples: Account credentials or tokens, precise geolocation, consumer health data, and personal information of known minors. Sources: The user; a parent or legal guardian; the device; a sensor; the sign-in provider; and other users. Purposes: Requested services, age-appropriate experience, security, and legal compliance. Recipients: Restricted providers and user-directed recipients.

11.2 California-Specific Disclosures

Flex does not sell personal information and does not share it for cross-context behavioral advertising. Flex does not use or disclose sensitive personal information for purposes that would require a right-to-limit notice under the CCPA. Flex has not sold or shared the personal information of consumers under 16.

California residents may request to know categories and specific pieces of personal information, delete personal information, correct inaccuracies, receive portable information, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service. Contract terms cannot waive rights provided by the CCPA.

11.3 EcoGem Rewards Privacy Notice

EcoGems are a voluntary loyalty and rewards program. Participation is not required to use the core Services. The applicable program or campaign screen states whether enrollment is required or earning occurs automatically, which private or public rides qualify, the activity data needed for validation, earning rates, limits, partners, benefits, expiration rules, and material restrictions.

Flex uses the minimum ride-validation signals described in the program screen, together with account, reward, claim, and redemption records, to administer EcoGems, prevent fraud, fulfill benefits, and resolve disputes. Optional heart-rate data is not required. Flex states before enrollment whether precise routes are needed or whether distance and other validation signals are sufficient. Program-performance measurement uses aggregated or deidentified information where reasonably possible.

A user may disable participation or withdraw prospectively through the method identified in the applicable program or by contacting flex@hyenatek.com. Withdrawal stops future earning and program processing that is not otherwise required, does not reverse a completed redemption, and may leave records needed for fulfillment, fraud prevention, disputes, accounting, or law. Account deletion ends participation and is subject to the disclosures presented before confirmation.

Tree-Nation and any other fulfillment partner, together with the benefit each provides, and the information needed for fulfillment, are identified at registration or before redemption. If Hyena later determines that EcoGems constitute a financial incentive, price or service difference, or bona fide loyalty program requiring additional notice under applicable law, Flex will provide the required state-specific notice, valuation or necessity explanation, and opt-in before enrollment.

11.4 Other State Rights

Depending on the state, a user may also have a right to obtain a list of specific third parties, opt out of targeted advertising or certain profiling, revoke consent to sensitive-data processing, designate an authorized agent, or appeal a denial. Hyena will honor applicable rights through the process in Section 7.

12. Consumer Health Data for Users in United States

This Section explains how Hyena collects, uses, processes, and shares consumer health data through Flex. It is intended to provide the notice required by applicable U.S. consumer health data laws, including Washington's My Health My Data Act, Nevada consumer health data law, applicable Connecticut provisions, and similar laws. Coverage depends on the law, effective date, jurisdiction, product design, and processing involved.

"Consumer health data" means personal information that identifies or is reasonably linkable to a consumer and identifies, reveals, or may be used to infer the consumer's past, present, or future physical or mental health status, to the extent covered by applicable law. Flex does not sell consumer health data or use it for advertising, data brokerage, eligibility or insurance decisions, or general-purpose artificial-intelligence model training.

The remainder of this Section describes the relevant consumer health data, sources, uses, consent and sharing choices, recipients, rights, security practices, and contact methods. It supplements the rest of this Privacy Policy for consumer health data.

12.1 Consumer Health Data We Collect

Flex may collect consumer health data when a user activates or uses the relevant feature. This may include heart-rate readings from a compatible sensor; fitness and activity information when it identifies, reveals, or is used to infer health status; derived or inferred health information; health information included in content or communications; and precise location that could reasonably indicate an attempt to acquire or receive health services or supplies.

Flex ordinarily processes location to record a ride, not to infer health status or identify health-care seeking. A route may incidentally pass a health-related site. Applicable law may nevertheless treat precise location as consumer health data. If Flex intentionally uses location to infer health status or identify health-care seeking, it will provide a purpose-specific notice and obtain any consent required by law.

12.2 Sources and Uses

Flex may collect consumer health data from the user; other users who submit information about the user; a connected heart-rate sensor; a connected e-bike; ride and location functions; calculations or inferences performed by Flex; and providers that return information needed to operate a requested feature.

Flex may transmit consumer health data from the user's device or connected equipment, store it in restricted infrastructure, calculate or derive requested ride summaries and estimates, display it to the user, secure it, export selected information at the user's direction, and delete or deidentify it according to user controls and applicable law. Flex uses consumer health data only to provide a requested feature, provide user-requested support, secure the Services, prevent fraud or abuse, comply with law, or establish, exercise, or defend legal claims.

Before collecting optional heart-rate or other consumer health data for a purpose requiring consent, Flex presents a separate request identifying the categories collected, specific purposes and uses, categories of entities that will receive the data, and withdrawal method. Consent is not obtained through acceptance of general Terms of Service, inactivity, or a deceptive design. Flex can be used without enabling optional heart-rate collection.

An operating-system permission is separate from consent required by consumer health or privacy law. Where active-ride location is treated as consumer health data, Flex applies the notice, consent, sharing, minimization, publication, and retention rule adopted for that jurisdiction and product flow. Flex does not disclose consumer health data for an optional purpose without separate affirmative sharing consent where required. A user may withdraw consent prospectively through the applicable in-app control, by disconnecting a sensor or integration, by changing device permissions, or by submitting a Consumer Health Data Request.

12.4 Consumer Health Data Recipients

Flex shares consumer health data only as necessary for the identified purpose. Amazon Web Services and Google Firebase database or storage services may process activated heart-rate, ride, route, account-linkage, and security information needed for a requested feature, subject to applicable contractual and legal restrictions. Google Firebase Authentication receives account or authentication identifiers and connection information, not heart-rate readings or health records.

Mapbox provides maps, route rendering, elevation, and place information. Depending on the requested function, it may receive precise coordinates, route points, map requests, and related device or network information; it does not receive heart-rate readings. Apple Health or Strava, if later offered, receives only information identified in the user-directed export flow. Support or security providers may receive the minimum health information needed for a user request or to investigate a security, fraud, abuse, or safety event. Legal or safety recipients may receive the minimum relevant data when permitted or required by law.

Analytics, advertising, general product-improvement, push-notification, content-moderation, crash-reporting, performance-monitoring, and general-purpose AI providers are not authorized to receive raw heart-rate readings, raw precise routes, or other consumer health data except where strictly necessary for a disclosed support, security, legal, or user-requested purpose and subject to applicable restrictions and consent requirements. No third party is authorized to collect consumer health data through Flex over time and across unrelated websites or online services for advertising, profiling, or another independent purpose.

12.5 Consumer Health Data Rights

Depending on applicable law, a covered consumer may request confirmation of whether Flex collects, shares, or sells consumer health data; access; a list of third parties and affiliates that received the data with an available contact method; correction; withdrawal of collection or sharing consent; and deletion.

Submit a request through the in-app privacy tools or email flex@hyenatek.com with the subject line "Consumer Health Data Request." To request a recipient list, state "Third-Party Recipient List" and the relevant date range. Flex uses reasonable methods to authenticate a request and does not require a new account. If a request is denied, Flex explains the reason and provides an appeal method where required by applicable law. A consumer may use the denial instructions or email flex@hyenatek.com with the subject line "Consumer Health Data Appeal."

A deletion request is sent to affiliates, processors, contractors, and other recipients as required by law. Flex deletes covered data from active systems without undue delay and within the applicable response period, subject to a permitted extension. Deletion from archives or backups may be delayed as applicable law permits. Measured sensor readings and completed ride records may be preserved as recorded for accuracy, fraud prevention, and integrity where legally permitted; where alteration would compromise integrity, Flex may correct an associated field, annotate the record, or delete it where appropriate.

12.6 Security, Processors, and Geofencing

Access to consumer health data is limited to personnel and providers who need it for an authorized purpose. Before a processor handles consumer health data, Hyena requires a binding written contract containing the instructions, purpose and use limits, confidentiality, security, incident-notification, deletion, rights-assistance, and remediation terms required by applicable law. A provider may not use the data for its own advertising, model training, cross-client profiling, or another independent purpose unless separately disclosed and lawfully authorized.

Where California law applies, Flex does not collect, use, disclose, sell, share, or retain personal information concerning a natural person who is physically located at, or within the legally defined precise geolocation of, a family-planning center, except as otherwise provided by law. Flex may collect or use that information only to the extent necessary to perform services or provide goods requested by the person. That requested-service exception does not, by itself, permit Flex to disclose, sell, share, or retain the information.

Flex does not authorize or use geofencing around an in-person health-care provider to identify or track a person seeking, receiving, or providing health-care services; collect personal information from that person; send a notification or advertisement related to the person's personal information or health-care services; or establish a health-related profile. Flex does not sell or share personal information to enable another person to conduct those activities. Flex does not use personal information obtained through geofencing, sale, or sharing that violates these restrictions. These restrictions are subject to the exceptions expressly provided by applicable law.

12.7 Changes and Contact

Flex will update this Section before collecting, using, or sharing a new category of consumer health data, adding a new recipient, or using consumer health data for a new purpose when notice or consent is required. If a change is material, Flex will notify affected users before the change takes effect and obtain renewed consent where required. To report a suspected security incident involving consumer health data, email flex@hyenatek.com with the subject line "Consumer Health Data Security Report."

13. International Processing and Notice for Users in the EEA and UK

Hyena Inc. is based in Taiwan. Personal information may be processed in the United States, Taiwan, and other countries where Hyena or an approved provider operates. Those countries may have different privacy laws.

Additional Information for Users in the EEA and UK

The following additional information applies in accordance with data protection laws in the European Economic Area (“EEA”), the United Kingdom (“UK”), and other relevant jurisdictions.

Data Controller: For a user in the EEA or UK, the data controller for the user's personal information is:

Hyena Inc. No.25, Jingke N. Rd., Nantun Dist., Taichung City 408, Taiwan (R.O.C.) flex@hyenatek.com

EU Representative (GDPR Article 27): Hyena has appointed a representative in the European Union who can be contacted on data protection matters at:

art-27-rep-hyenatec@rickert.law

UK Representative (UK GDPR Article 27): Hyena has appointed a representative in the United Kingdom who can be contacted on data protection matters at:

art-27-rep-hyenatec@rickert-services.uk

Data Subject Rights: In addition to the rights described in Section 7 (Privacy Rights and Choices), a user in the EEA, UK, or Switzerland has the right to object to, and seek restriction of, Hyena's processing of the user's personal information based on Hyena's legitimate interests or the performance of a task carried out in the public interest. In such cases, Hyena will cease processing the information unless it has compelling legitimate grounds to continue processing or where necessary for legal reasons. A user also has the right to object to processing for direct marketing at any time; Flex does not currently send marketing newsletters, and the only emails Flex sends relate to the user's account, support requests, or required updates to the Terms, this Privacy Policy, or the Community Standards. A user may also have the right to lodge a complaint with the user's local data protection supervisory authority. A user in the EEA, UK also has, under the GDPR, the rights of access, rectification, erasure, restriction of processing, and data portability, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. These rights are exercised through the mechanisms in Section 7.

A user in the EEA has the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of their habitual residence, place of work, or place of the alleged infringement. A complete list and contact details of national and regional EEA data protection authorities are available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en.

For users in the United Kingdom, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

Legal Bases: Certain data protection laws (such as those in the EEA, the UK, and Switzerland) require Hyena to identify a valid legal reason (called a "legal basis") before it collects, uses, shares, or otherwise processes a user's personal information. Common legal bases include:

  • Contract (Article 6(1)(b) GDPR): When processing personal information is necessary to perform Hyena's contract with the user (the Terms) or to take steps at the user's request before entering into a contract.
  • Consent (Article 6(1)(a); for special categories of data, Article 9(2)(a) GDPR): When the user has given Hyena permission to use the information for a specific reason. The user has the right to withdraw consent at any time.
  • Legitimate interests (Article 6(1)(f) GDPR): When Hyena uses the information in ways that are expected and that do not unfairly affect the user's rights.
  • Legal obligation (Article 6(1)(c) GDPR): When Hyena is required to process the information by law.
  • Vital interests (Article 6(1)(d) GDPR): When processing is needed to protect someone's life or safety.

Hyena relies on these legal bases for its main processing activities as follows:

  • Providing the Services — creating and managing the user's account, recording activities, enabling GPS-based features, personalizing the feed, facilitating interactions with other users, and sending service-related notifications: Contract (Article 6(1)(b) GDPR — performance of the contract).
  • Processing health data (such as heart rate from a connected sensor) and other special category data: the user's explicit consent (Article 9(2)(a) GDPR), which may be withdrawn at any time.
  • Processing precise geolocation for core, user-initiated ride-tracking features: Contract (Article 6(1)(b) GDPR). The device-level location permission the user grants is the technical means of access and operates alongside, but is distinct from, this legal basis.
  • Improving and securing the Services, analytics, troubleshooting, developing AI Features, and protecting users and the platform (the legitimate interests pursued being network and information security, the prevention of fraud and misuse, the diagnosis and correction of faults, and the improvement and further development of the Services): Legitimate interests (Article 6(1)(f) GDPR) (or Consent where required, such as for non-essential analytics technologies on Flex web pages). Where a purpose involves storing information on or accessing information from the user’s device (for example analytics, crash-reporting, or performance SDKs that are not strictly necessary), the device access itself is based on the user’s consent under the national laws implementing Article 5(3) of the ePrivacy Directive (in the United Kingdom, the Privacy and Electronic Communications Regulations), and this consent is separate from, and additional to, the GDPR legal basis for the subsequent processing.
  • Meeting legal and regulatory obligations and responding to lawful requests: Legal obligation (Article 6(1)(c) GDPR), and where necessary Vital interests (Article 6(1)(d) GDPR) to protect someone's safety.

Special categories of personal data (Article 9 GDPR). Some of the data Flex processes are special categories of personal data within the meaning of Article 9(1) GDPR — in particular health data, such as heart-rate readings, health-revealing activity or fitness data, and health-related location. Flex processes such data only where one of the conditions in Article 9(2) applies. As a rule, Flex relies on the user’s explicit consent under Article 9(2)(a), given through a separate, unbundled consent step (for example when the user connects a heart-rate sensor); this consent is distinct from, and additional to, the Article 6 legal basis for the same processing, and the user may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal and without losing access to the core Services. Where a user chooses to make an activity or route public and it reveals such data, Flex relies on Article 9(2)(e) (data manifestly made public by the user). Where necessary, Flex may also rely on Article 9(2)(f) for the establishment, exercise, or defence of legal claims. Flex does not use special category data for advertising, and applies the additional access and security controls described in Section 4, Section 9, and Section 12. On withdrawal of consent, special category data already collected are deleted or anonymised unless another condition in Article 9(2) or a statutory obligation requires their retention.

Cross-Border Data Transfers: Hyena is based in Taiwan and processes personal information on cloud infrastructure located in the United States. Its primary data stores are hosted on Google Firebase (multi-region nam7, with data centers in Iowa and Northern Virginia, United States) and Amazon Web Services (region us-east-1, Northern Virginia, United States). As the data controller, Hyena Inc. is established in Taiwan, and Hyena's staff in Taiwan access personal information to operate, maintain, support, and develop the Services. A user located outside the United States who chooses to use the Services or provide information acknowledges that the information will be transferred to, processed, and stored in the United States and Taiwan.

Transfers to providers in the United States are, where the relevant provider is certified under the EU-US Data Privacy Framework, covered by the European Commission’s adequacy decision of 10 July 2023 under Article 45 GDPR, and, for transfers subject to the UK GDPR, by the UK Extension to that Framework (the UK-US data bridge). For any United States transfer that is not covered by that Framework, and for all transfers to Taiwan — for which no adequacy decision exists — Hyena relies on appropriate safeguards within the meaning of Article 46 GDPR, in particular the European Commission’s Standard Contractual Clauses, supplemented for transfers subject to the UK GDPR by the UK International Data Transfer Addendum (or the UK International Data Transfer Agreement). Before relying on such safeguards, Hyena assesses the circumstances of the transfer and, where necessary, applies supplementary technical and organisational measures to ensure a level of protection essentially equivalent to that guaranteed within the EEA and the UK. Access to the data by Hyena’s own staff in Taiwan is treated as a transfer subject to the same safeguards. Hyena’s data processing agreements with Amazon Web Services (the AWS GDPR Data Processing Addendum, applicable under the AWS Service Terms) and with Google (the Google Cloud / Firebase Data Processing Terms, accepted for the Flex project) incorporate the Standard Contractual Clauses, which apply to any transfer not covered by the EU-US Data Privacy Framework and to transfers to Taiwan. Access to this information by Hyena’s own staff in Taiwan is carried out in its capacity as the data controller, and this processing remains subject to the GDPR, including through Hyena’s appointed EU and UK representatives. A user with further questions, or who would like copies of the applicable safeguards used to transfer information internationally, may contact Hyena using the information in Section 15.

14. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Services, law, or our practices. We will post the revised version with a new effective date. If a change is material, we will provide prominent advance notice through the app, email, or another appropriate method. We will obtain renewed affirmative consent before a change when required by law, including for a new category or purpose involving consumer health data.

We will maintain an accessible archive or change summary for material versions. Continued use will not be treated as consent where law requires a separate affirmative act.

15. Contact Us

Hyena Inc. No. 25, Jingke N. Rd. Nantun Dist., Taichung City 408 Taiwan (R.O.C.) Privacy and consumer-rights email: flex@hyenatek.com Suggested subject: "Privacy Request" or "Consumer Health Data Request" Telephone: +886 4 2359 8810

Preferred subject lines assist routing but are not required where applicable law recognizes an otherwise valid request.

For EU/EEA data protection inquiries, a user may also contact Hyena's EU Representative at art-27-rep-hyenatec@rickert.law. For UK data protection inquiries, a user may also contact Hyena's UK Representative at art-27-rep-hyenatec@rickert-services.uk.