TAMI Guide App
Data Protection Notice — TAMI Guide App
How Lighthouse Tech SA collects, uses and protects your personal data through the TAMI Guide companion app. This notice is separate from the website privacy policy.
Last updated: 23 September 2026 · Version 2.0
Important notice for minors: if you are under 16 years of age, please read this notice together with a parent or legal guardian. Use of the app by minors requires the consent of a parent or guardian.
1. Data Controller
- Lighthouse Tech SA
- Registered office: Via Maestri Comacini 10C, 6834 Morbio Inferiore, Switzerland
- Commercial register no. / VAT no.: CHE-417.550.044
- Email: info@lighthousetech.ch
Lighthouse Tech SA ("we", "our" or the "Company") is the controller of personal data collected through the TAMI Guide application (the "App").
Representative in the European Union (Article 27 GDPR)
As the Company is established outside the EU but offers the App to data subjects in the EU, it has appointed Complico Consulting GmbH as its representative in the Union. The representative may be contacted at Bahnhofstr. 12, 63549 Ronneburg, Germany, or info@complicoconsulting.com, on all matters relating to the processing of your personal data.
Data Protection Officer / privacy contact
Nathan Deutsch, nathan.deutsch@lighthousetech.ch. You may contact our Data Protection Officer about this notice or to exercise your rights, in addition to the general address above.
2. Data Collected
We collect the following categories of personal data. Because the App and the TAMI device are designed for blind and visually impaired people, the fact that you hold an account and pair a device may reveal information about your health (a visual impairment). We therefore treat your account and usage data as a special category of personal data under Article 9 GDPR and as sensitive personal data under Article 5(c) FADP, and we process it on the basis of your explicit consent (see Section 3).
2.1 Data provided directly by the user
- Registration data: first name, last name, email address
- Access credentials: email and password (encrypted)
- Google authentication data: if you choose to sign in via Google Sign-In
- Apple authentication data: if you choose to sign in via Sign in with Apple, we receive your Apple ID, your name (given and family name, provided only on your first sign-in) and an email address
2.2 Automatically collected data
- Device data: device identifiers, operating system, app version
- Bluetooth connection data: MAC addresses of connected TAMI devices
- Usage data: app interactions, device configuration preferences
- Notification token: for sending push notifications
2.3 TAMI device data
- Device configurations and settings
- Diagnostic and telemetry data
- Environmental sensing performed by the device (radar obstacle detection) is processed locally on the device and is not transmitted to or stored by the Company. Diagnostic and telemetry data does not include data about your surroundings, your location or your movements.
- Firmware versions
- Battery status
3. Purpose and Legal Basis of Processing
| Purpose | Legal Basis | Data Used |
|---|---|---|
| Processing of data that reveals your visual impairment (special-category or sensitive data), for example holding an account and pairing a TAMI device. | Explicit consent (Art. 9(2)(a) GDPR; Art. 6(7) FADP) | Account data; device pairing data |
| Account creation and management, to allow the user to access their settings and transfer them to a new device. Only the user has access to their own data. | Performance of contract | Name, email, password |
| Connection and configuration of TAMI devices | Performance of contract | Bluetooth data, configurations |
| Firmware updates | Performance of contract | Device data, firmware version |
| Aggregated analysis of configuration preferences — we collect pseudonymised data on device settings to understand how users prefer to configure them and improve the product. | Legitimate interest in improving the safety, usability and performance of the TAMI device and App (Art. 6(1)(f) GDPR) | Pseudonymised configuration data |
| Sending marketing material and newsletters, only with your explicit consent. | Consent | Notification token, email |
| Customer support | Explicit consent (Art. 9(2)(a) GDPR; Art. 6(7) FADP), in conjunction with our legitimate interest in providing support (Art. 6(1)(f) GDPR) | Account data, diagnostic logs |
| Service improvement | Legitimate interest in analysing app usage to improve the safety, usability and performance of the TAMI device and App (Art. 6(1)(f) GDPR) | Pseudonymised usage data |
Note on special-category data
Processing of data that reveals your visual impairment is carried out on the basis of your explicit consent (Article 9(2)(a) GDPR; Article 6(7) FADP). This explicit consent is requested separately when you create your account and may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Third-Party Services
Google and Firebase act as our processors and process personal data on our behalf under a data processing agreement; they may engage sub-processors. For Google Sign-In, Google acts as an independent controller for the authentication it carries out. We remain the controller of the personal data processed through the App.
4.1 Google Firebase
See the Google Privacy Policy.
- Firebase Authentication: user authentication management
- Cloud Firestore: storage of user data and configurations
- Firebase Storage: file and document storage
- Firebase Cloud Messaging: push notification delivery
4.2 Google Sign-In
If you choose to sign in via Google, we will share the data necessary for authentication with Google LLC (for users in the EEA and Switzerland, the Google contracting entity for these services is Google Ireland Limited; Google LLC is the certified importer under the Data Privacy Framework).
4.3 Sign in with Apple
If you choose to sign in via Apple, we will share the data necessary for authentication with Apple Inc., which acts as an independent controller for the authentication it carries out, under its own Apple Privacy Policy.
5. Protection of Minors
Special provisions for users under 16 years of age:
- Use of the App by minors under 16 requires verifiable consent from a parent or legal guardian
- We do not knowingly collect personal data from children under 16 without verifiable parental consent
- We verify parental or guardian consent by reasonable means proportionate to the risks of the processing (for example, confirmation through the parent's or guardian's email address), in line with Article 8(2) GDPR
- Parents/guardians may request access to, modification of, or deletion of their child's data by contacting us
- We limit the collection of minors' data to the minimum necessary for the App to function
Contact for parents
If you are a parent and believe your child has provided us with personal data without your consent, please contact us immediately at info@lighthousetech.ch.
Note: account creation is a direct, user-initiated flow only — accounts are not created or pre-populated by opticians, distributors or partner associations on a user’s behalf.
6. Data Retention
We retain your personal data for as long as necessary to:
- Account data: until the account is deleted by the user
- Device configuration data: until the device is disconnected or the account is deleted
- Diagnostic logs: maximum 90 days
- Data for legal obligations: as required by applicable law (for example, accounting records are retained for about 10 years under the Swiss Code of Obligations)
- Inactive accounts: if an account remains inactive for 24 months, we will contact you and then delete the account and associated data
- After account deletion: personal data is removed from active systems within 30 days and from backups within 90 days
7. Data Transfers
Your data may be transferred to and stored on servers located outside Switzerland/EEA, in particular in the United States (Google/Firebase servers). Such transfers are carried out on the basis of:
- Standard contractual clauses approved by the European Commission (the EU SCCs, with the "Swiss Finish" amendments for transfers from Switzerland), with Google LLC named as the data importer
- Provider certification under the EU-U.S. and Swiss-U.S. Data Privacy Framework (the Swiss-U.S. framework, effective 15 September 2024, applies to data transferred from Switzerland); Google LLC must be certified under the framework relevant to the transfer
Safeguards
We apply supplementary measures to protect transferred data, such as encryption in transit and at rest. Where a framework ceases to apply, the standard contractual clauses operate as a fallback.
8. Your Rights
In accordance with the GDPR, the Swiss FADP, and applicable regulations, you have the right to:
- Access: obtain confirmation of processing and a copy of your data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data ("right to be forgotten")
- Restriction: restrict processing in certain circumstances
- Portability: receive your data in a structured format
- Objection: object to processing based on legitimate interest
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR)
How to exercise your rights
To exercise your rights, contact us at info@lighthousetech.ch. Whether the GDPR, the Swiss FADP, or both apply to you depends on the circumstances of the processing; the exact scope of your rights may differ accordingly, and we assess each request on a case-by-case basis under the applicable law.
We will act on your request without undue delay, at the latest within one month (Article 12(3) GDPR) or, for access requests under Swiss law, within 30 days (Article 25(7) FADP); deletions and restrictions are carried out as soon as reasonably possible within that period. We may take reasonable steps to verify your identity before doing so, for example by confirming that your request is made from the email address registered to your Account.
We do not take decisions producing legal or similarly significant effects concerning you based solely on automated processing (Article 22 GDPR). You also have the right to lodge a complaint with a supervisory authority (see Section 13).
9. Data Security
We adopt appropriate technical and organisational measures to protect your data, proportionate to the sensitivity of the data. These include encryption of data in transit and at rest, encrypted credential storage, strict access controls (including multi-factor authentication for administrative access), and regular monitoring and audits.
In the event of a personal data breach, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with Articles 33 and 34 GDPR and Article 24 FADP, and we keep internal records of all breaches.
10. App Permissions
The App requires the following permissions:
- Bluetooth: required to connect to TAMI devices
- Location: on Android 12 and later, Bluetooth scanning uses the BLUETOOTH_SCAN permission declared with the "neverForLocation" flag, so location access is not requested. On Android 11 and earlier, the operating system still requires location permission for Bluetooth scanning; we do not use your location for any other purpose
- Notifications: to receive firmware updates (service notifications). Marketing newsletters are sent only with your separate, optional consent, which is not required in order to use the device
- Internet: for data synchronisation and updates
- Storage: to save logs and configurations locally
11. Cookies and Similar Technologies
The App does not use cookies. We use local storage technologies (SharedPreferences, SecureStorage) exclusively to:
- Maintain the login session
- Save user preferences
- Store local configurations
12. Changes to this Data Protection Notice
We reserve the right to modify this Data Protection Notice. In the event of material changes:
- We will notify you via an in-app notification
- We will update the "last updated" date
- For changes requiring new consent, we will ask you to accept the updated Notice
13. Supervisory Authorities
You have the right to lodge a complaint with the competent supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC)
- EU: the data protection authority of your country of residence
Contact
Lighthouse Tech SA — info@lighthousetech.ch. For any questions regarding privacy or to exercise your rights, please do not hesitate to contact us.
