POCKETBOOK E-READER'S PRIVACY NOTICE

The revised privacy policy will be effective starting on July 21, 2026

INTRODUCTION

Welcome to the PocketBook e-reader's privacy notice.

PocketBook e-reader's respects your privacy and is committed to protecting your personal data. This privacy notice will inform you as to how we look after your personal data when you use your PocketBook e-reader when it is connected to Wi-Fi and tell you about your privacy rights and how the law protects you.

This privacy notice is provided in a layered format so you can click through to the specific areas set out below. Please also use the Glossary to understand the meaning of some of the terms used in this privacy notice.

1. IMPORTANT INFORMATION AND WHO WE ARE

PURPOSE OF THIS PRIVACY NOTICE

This privacy notice aims to give you information on how PocketBook International SA collects and processes your personal data through your use of your e-reader under the brand PocketBook ("the Reader"), including any data you may provide through the Reader or by using other services of PocketBook International SA or our partners. We also own, operate and offer related services, like Send-to-PocketBook, Cloud and Support for e-readers. Support means the provision of end-customer support via telephone or email to customers before, during and after a purchase of products and services under the brand PocketBook. We refer to Readers, together with our other services as ("Services") in this policy. Services are part of the PocketBook Group Services and Products, which belong to PocketBook International SA, based in Lugano, Switzerland. More information about PocketBook International SA is available at https://www.pocketbook.ch.

The Services are not intended for children under 16 and PocketBook International SA does not knowingly collect data relating to children. Users must be at least 16 years old or older to register for a Services Account to use the PocketBook Services. If a parent or guardian believes that PocketBook International SA has in its database the personal information of a child under the age of 16, please contact us at privacy@pocketbook-int.com and we will use our best efforts to remove the information from our records.

It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements the other notices and is not intended to override them.

If you do not agree with this policy, do not access or use our Services or interact with any other aspect of our business.

CONTROLLER

PocketBook International SA is the company which produces e-readers under the brand PocketBook ("Products").

PocketBook International SA is the controller and responsible for your personal data (collectively referred to as "PocketBook", "we", "us" or "our" in this privacy notice).

Other companies in the PocketBook Group may also act as joint controllers or processors. These entities, located both within and outside the EEA, provide IT and system administration services and contribute to internal reporting and service operations.

If you have any questions about this privacy notice, including any requests to exercise your legal rights under the GDPR, please contact us by email privacy@pocketbook-int.com.

CHANGES TO THE PRIVACY NOTICE

We may revise the provisions of this Privacy Notice as necessary. The latest version of the Privacy Notice will govern the terms of use of your personal data by us and it will always be published at https://legal.pocketbook-int.com/e-ink/privacynotice.

THIRD-PARTY LINKS

Readers may have links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites, plug-ins and applications and are not responsible for their privacy statements.

2. THE DATA WE COLLECT ABOUT YOU

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

PLEASE NOTE THAT THE READER ITSELF DOES NOT COLLECT ANY KIND OF PERSONAL IDENTITY, CONTRACT, FINANCIAL, OR TRANSACTION DATA ABOUT YOU.

When you connect to Wi-Fi from your Reader we can collect such information concerning the Reader and its use:

  1. Technical Data: your login data, device serial number, firmware version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Services.
  2. Usage Data: includes information about how you use the Reader and its features. We collect this information to better understand usage preferences and to develop more reliable, user-friendly, and efficient Readers.

However, if you choose to activate the PIN code feature on your Reader and provide a recovery email address, certain technical and usage data that was previously non-identified (pseudonymous) may become linked to you. In particular, we may process the following:

  1. Email address that you provide us for PIN code recovery.
  2. PIN code status and user action history, including the status of the PIN (enabled/disabled), date of status change, and type of user action (e.g. set/reset).
    We do not collect or store your PIN code. It is securely stored on the device in hashed form.
  1. Device and Service Metadata means information that our infrastructure automatically collects in addition to Technical and Usage Data, which is necessary for the functioning of the device and related services.

    This metadata does not concern the content of your e-books or files but rather technical information generated by the Reader or by services you use. Examples of such metadata are device identifiers (serial number, device model, firmware version it runs on), the connection data (date/time, IP address of connections, browser user agent), as well as technical details about how services work on your Reader.

    This may include information about downloading or updating voice packages and dictionaries, synchronization events, file delivery status in Send-to-PocketBook, login and authentication events, or confirming consent to legal documents. It can also cover account-related data like your PocketBook ID (user ID), email, access tokens, and login events, user-generated usage information such as bookmarks, notes or your current reading position, history of borrowed books in integrated library apps and configuration data including Wi-Fi and Bluetooth settings, browser history and cookies, device and application settings and the status of your device PIN.

PLEASE NOTE!

In case you are using any of our additional Services, which collect Personal data, please read their Privacy notices:

  1. PocketBook Reader application iOS/Android
  2. Send-to-PocketBook
  3. Cloud
  4. PocketBook online bookstore (available in your region)
  5. PocketBook × Libby Application.

    Due to our PocketBook × Libby Application, our PocketBook Readers became "library friendly devices". The PocketBook × Libby Application is a gateway to the OverDrive platform, enabling you to search for and to borrow e-books and audiobooks from your library for free, using your library card, and to read the borrowed books on a compatible PocketBook Reader (or to listen to audiobooks online if applicable).

    PocketBook x Libby Application interacts with the Overdrive Platform, which is under the control of OverDrive, Inc. (a US company with the registered address at 1 Overdrive Way Cleveland, OH 44125, USA). OverDrive Inc. adopted the required principles for the EU-U.S. Data Privacy Framework (DPF), UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, as set forth by the U.S. Department of Commerce. Please read OverDrive Inc.'s privacy documents following the links: https://www.overdrive.com/policies/privacy-policy https://user-privacy.overdrive.com.

    To identify you as a person eligible to access the borrowed e-books and audiobooks, a secret token will be sent to and stored on your PocketBook Reader after your signing into the library's OverDrive website with your library card.

3. HOW IS YOUR DATA COLLECTED?

We use Automated technologies and interactions as the method to collect data from and about you. When your Reader is connected to Wi-Fi, we may automatically collect Technical and Usage Data, as well as Device and Service Metadata. This metadata may include pseudonymous identifiers and technical information about your device and how you interact with the Reader. This data is generated by the Reader or our servers and is necessary to provide updates, deliver files, enable authentication and ensure the proper functioning of the device. If your Reader is offline, the relevant Technical and Usage Data may be stored locally on the device and sent automatically once an internet connection becomes available.

If you choose to activate the PIN code feature and provide a recovery email address, this information may become linked to you and thus qualify as personal data under applicable data protection laws.

4. HOW WE USE YOUR PERSONAL DATA

The Reader itself does not collect any personal data. Only in case you activate the PIN code feature on your Reader and provide a recovery email address, or if you log in through the Reader to our other Services listed in Section 2 The data we collect about you, we and those Services will collect and process your Personal Data.

PURPOSES FOR WHICH WE WILL USE YOUR DATA

We have set out below, in a table format, a description of all the ways we plan to use data we collect from your Reader, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

NOTE that we do not collect any personal data if you use only Reader without activating the PIN code feature or using of any from our Services.

Purpose/Activity Type of data Lawful basis for processing including basis of legitimate interest
To use data analytics to improve our Reader and make your reading experiences better (a) Technical
(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Readers updated and relevant, to develop our business)
To display contextual recommendations and catalog lists on the Reader, where available when you are signed in to the PocketBook Store on the device, based on device language/region settings and aggregated popularity trends. (a) Technical
(b) Usage
Necessary for our legitimate interests to provide and improve content discovery features and optimise the Store/catalog experience. You may object to this processing.
To provide PIN code functionality, allow recovery and ensure device security (a) Email address;
(b) Technical (device serial number);
(c) PIN status and action logs
Necessary for the performance of a contract with you; Necessary for our legitimate interests (to provide secure device usage, recovery options and support)
To operate and support device functionality, deliver files, enable synchronization, and provide technical support Device and Service Metadata (as described in Section 2) Necessary for the performance of a contract with you; Necessary for our legitimate interests (to provide reliable operation of Readers and related services, debugging, compliance with legal obligations under the EU Data Act)

5. DISCLOSURES OF YOUR PERSONAL DATA

We do not share the content of your books, notes, or other content stored on your Reader with third parties for analytics or advertising/marketing services.

If you activate the PIN code feature and provide a recovery email address, certain data we collect about you may become linked to you and may be considered personal data under applicable data protection laws. In such cases, we may share the relevant data with PocketBook internal teams and trusted service providers strictly to provide the PIN recovery and related support functions.

We may also share certain Technical Data and Usage Data with trusted service providers who support the operation of the Reader and the provision of related services, for example providers of hosting and infrastructure, IT maintenance and security, and customer support services. Such service providers act as processors on our behalf and under our instructions.

Within PocketBook, access to personal data is limited to authorized employees and technical specialists who need such access to perform their duties, on a need-to-know basis and in accordance with the principle of least privilege.

Finally, to help us understand how the Reader is used and to improve it, we may share certain Technical Data and Usage Data with an analytics service provider acting as our processor.

6. INTERNATIONAL TRANSFERS

PocketBook is a worldwide company, which collects information globally and your personal data may be transferred to and stored in countries outside your country of residence, including Germany, for the purposes described in this Privacy Notice. Where applicable, we use appropriate safeguards for international transfers. The privacy protections and the rights of authorities to access your information in these countries may not be the same as in your home country.

We take additional measures when information is transferred from the European Economic Area (EEA). This includes having standard clauses approved by the European Commission in our contracts with parties that receive information outside the EEA. We also rely on European Commission adequacy decisions about certain countries, as applicable, for data transfers to countries outside the EEA.

7. DATA SECURITY

We have put in place appropriate security measures to prevent your data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8. DATA RETENTION

HOW LONG WILL YOU USE MY PERSONAL DATA FOR?

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your data, the purposes for which we process your data and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances you can ask us to delete your data: see request us for deletion of personal data below for further information.

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

9. YOUR LEGAL RIGHTS

Under certain circumstances, you have rights under data protection laws in relation to your personal data. As a user of our web-site you have such rights:

  1. Obtain confirmation from us as to whether personal data concerning you is being processed; if this is the case, you have the right to be informed of this personal data and the information specified in Art. 15 GDPR.
  2. Ask us for correction of incorrect personal data concerning you and, if necessary, for completion of incomplete personal data (Art. 16 GDPR).
  3. Request us for deletion of personal data relating to you immediately if one of the reasons listed in Art. 17 GDPR applies, for example, if the data is no longer needed for the purposes for which it was collected (right to deletion).
  4. Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  5. Object at any time to the processing of personal data concerning you for the purposes of direct marketing. You also have the right to object at any time to processing operations carried out pursuant to Art. 6 (1) clause 1 lit. e) or f) GDPR for reasons arising from your particular situation (Art. 21 GDPR). We will then no longer process the personal data for the purposes of direct advertising and otherwise only if we can prove compelling reasons for processing worthy of protection which outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.

    Object to the processing of Usage Data. Where we process Usage Data based on our legitimate interests, you may object to such processing. You can exercise this right by switching Usage Data to Off in the Reader settings (the default setting is On). When set to Off, the Reader stops collecting Usage Data. In addition, the collection of Usage Data may be enabled or disabled by configuration settings provided by our servers, which are checked periodically. If usage data collection is disabled, the Reader stops collecting Usage Data. Any Usage Data collected while your Reader was offline and not yet transmitted must be deleted and will not be transmitted. You may also request deletion of Usage Data associated with you, and we will take reasonable steps to delete it, including through tools provided by our analytics service provider.

  6. Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
  7. Data portability, meaning that you can request to receive from us the data concerning you which you have provided us with in a structured, common and machine-readable format. You may also transmit this data to other entities or have it transmitted by us (right to data transferability).
  8. Without prejudice to any other administrative or judicial remedy, you have the right to appeal to a supervisory authority if you consider that the processing of personal data relating to you is in breach of the GDPR (Art. 77 GDPR). You may file a complaint with a supervisory authority in your country of residence or PocketBook headquarters, if you believe the collection and use of your data infringe this Notice or applicable law. Since PocketBook International SA is registered in Switzerland, you may also file a complaint with Swiss data protection authority by following The Federal Data Protection and Information Commissioner (FDPIC).

If you would like to exercise any of your rights, or if you would like more information about these rights or the rights which may apply in your country, send a respective request to:

PocketBook International SA
Crocicchio Cortogna, 6, 6900 Lugano, Switzerland
Reg.No: CHE-416.098.857
Tel/fax: +41 91 922 07 05
pocketbook.ch
Email: help@pocketbook-int.com

Or use our dedicated channel for communication: privacy@pocketbook-int.com.

NO FEE USUALLY REQUIRED

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

WHAT WE MAY NEED FROM YOU

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

TIME LIMIT TO RESPOND

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.