2nu Support Privacy Notice

Effective date: 2 September 2026

This notice explains how 2NU (H.K.) LIMITED (referred to as 2nu, we, us or our) handles personal data when people use the 2nu website support chat, when support conversations are connected to a verified Shopify customer account, and when our authorized operator uses the private 2nu Support app.

This notice supplements the main 2nu website Privacy Policy. If the notices conflict, please contact us so we can explain which entity and notice applies to your transaction or market. Privacy contact: care@2nu.vision.

1. Data we handle

  • Support messages and the language, market and time of the conversation.
  • AI-generated replies, model and knowledge-base version, confidence, citations and correction or review history.
  • An anonymous browser or customer identifier used to reconnect a conversation.
  • Your name, email address and verified Shopify customer identifier after you choose to sign in.
  • Read-only order context such as order number, date, status, amount, currency and product line items.
  • An exact proposed shipping address or cancellation or replacement instruction when an authorized operator reviews a customer-requested order proposal.
  • Pages or Sport Match results recorded only when analytics processing is allowed through Shopify Customer Privacy.
  • Separate analytics and marketing consent records.
  • Requests for a human teammate, operator replies, internal support notes and follow-up tasks.
  • Bounded technical and security records such as hashed device credentials, idempotency references, audit events and request-status codes.

We do not ask the private operator app for Contacts, Photos, precise location, advertising identifiers, Health or Fitness data, or biometric templates.

2. Voice transcription

If you choose to record a voice message in the website chat:

  • The recording is sent through the conversation-bound support service to a local Whisper transcription worker.
  • Raw audio is processed in memory and is not retained as a file or CRM field.
  • The detected transcript and language are returned to you for review.
  • The transcript becomes part of the conversation only after you confirm and send it.
  • Once sent, the transcript follows the same retention rules as typed chat.

Do not include unnecessary sensitive information in a voice or text message.

3. How we use the data

  • Answer product, fit, lens, prescription, order and customer-care questions.
  • Maintain conversation continuity for anonymous and signed-in customers.
  • Show verified order context to an authorized support operator.
  • Generate and review AI replies grounded in the current 2nu knowledge base.
  • Identify replies that need human input and allow human takeover.
  • Maintain internal notes, follow-up tasks, corrections, security controls and audit history.
  • Present an exact encrypted order proposal for authorized operator approval or decline.
  • Process access, correction, consent-withdrawal and deletion requests.
  • Meet legal, fraud-prevention, dispute and recordkeeping obligations.

Account sign-in does not by itself grant marketing consent. Analytics consent does not grant marketing consent. We keep these choices separate.

4. AI use and human review

The support service may send the information needed to answer a message to an AI service selected inside the protected Zo runtime. The current design uses an OpenAI model for response generation and records the model, knowledge-base version and citations used for operator review.

AI can make mistakes. A customer can request human input, and our operator can take over a case. Approved operator corrections are review records and are not automatically published into the knowledge base.

AI cannot independently change an order. The current production deployment keeps all Shopify execution capabilities disabled. If a separate release later enables an action, it must still receive Ivan’s approval and final confirmation and pass fresh eligibility, idempotency, readback and audit controls.

5. Service providers and transfers

We use service providers only as needed to operate support, including:

  • Shopify for storefront, customer-account and verified order services.
  • Zo Computer for protected application and CRM infrastructure.
  • OpenAI for approved AI response generation.
  • Brevo only if marketing sync is later enabled and the customer has separate current marketing consent.

These providers may process data in other jurisdictions. We require processors to protect personal data through contractual or other appropriate measures and to use it only for the instructed service, subject to applicable law.

The native operator app contains no advertising, tracking, analytics, social login or third-party SDK dependency.

6. Retention

  • Complete customer and AI conversation records are retained for 36 months by default so we can provide continuity, review AI quality and handle disputes.
  • After that period, closed conversations are anonymized unless the case is active or a legal or documented business retention need applies.
  • Conversation-linked message text, internal note text, task titles, corrected answers, proposal ciphertext and raw order or customer binding are removed or redacted by anonymization; only bounded hash-based audit evidence remains.
  • When no retained active conversation remains, linked profile identity, consent, journey, marketing-outbox and verified order snapshots are removed or anonymized according to the data type.
  • Mobile operator device credentials expire after no more than 90 days; only a hash is stored by the gateway.
  • Raw voice audio is not retained.
  • Bounded audit metadata may be retained where needed to demonstrate security, consent, deletion, legal compliance or action integrity.

We may retain specific records for longer where required by law, to establish or defend legal claims, to prevent fraud, or under a documented legal hold.

7. Security

We use measures designed to limit unauthorized access and accidental loss, including HTTPS transport, least-privilege private services, hashed device credentials, this-device-only Keychain storage, Face ID, Touch ID or passcode access for the operator app, bounded tokens, idempotent actions and audit records.

No system can guarantee absolute security. If you believe your information or a support conversation has been accessed improperly, contact us promptly.

8. Your choices and rights

Subject to applicable law, you may ask us to:

  • Provide access to personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Explain how your data is used or shared.
  • Withdraw analytics or marketing consent for future processing.
  • Delete or anonymize data that is no longer required.
  • Review a response through a human support teammate.

Send a request to care@2nu.vision. We may need to verify your identity before disclosing, correcting or deleting account or order-linked information. A deletion request enters a separate auditable workflow and does not delete data on receipt. An authorized operator reviews it and confirms fulfilment separately. Active support cases and legal, fraud, dispute or other documented permitted retention may delay or limit fulfilment. We will explain any refusal or limitation where required.

9. Children

The support service is not designed to collect personal data from children without appropriate authorization. If you believe a child has submitted personal data improperly, contact us so we can review and take appropriate action.

10. Changes to this notice

We may update this notice when the support service, law or service providers change. The published notice will show its effective date. Material changes will be communicated where required.

11. Contact

2NU (H.K.) LIMITED

Email: care@2nu.vision

Website: https://2nu.vision

Registered address: 702 Kowloon Building, Mongkok, Kowloon, Hong Kong