BOYA Notra - Data Security and Privacy Policy
Version: v2.0
Effective Date: April 29, 2025
Introduction
Shenzhen Perfect Acoustic Technology Co., Ltd. ("We") takes the protection of user privacy and personal information very seriously. When you use our products and/or services, we may collect and use your relevant information. This "BOYA Notra Data Security and Privacy Policy" (the "Privacy Policy") aims to explain how we collect, use, store, share, and transfer this information, as well as how we provide you with access, updates, deletion, and protection of this information. We hope you will carefully read and confirm your full understanding of this policy before using our products and/or services. If you have any questions while reading, please contact our customer service for consultation. If you disagree with any terms in this agreement, please stop submitting information.
Before using our products and services, please be sure to carefully read and understand this policy, ensuring you fully understand and agree before use. We will explain professional terms involved in this policy in simple language for your convenience.
If you have any questions or concerns regarding this Privacy Policy or related matters, please contact us promptly.
This policy will help you understand the following:
- How We Collect and Use Your Personal Information
- How We Share, Transfer, and Publicly Disclose Your Personal Information
- How We Protect and Store Your Personal Information
- How to Manage Your Personal Information
- How We Handle Children's Personal Information
- How Your Personal Information is Transferred Globally
- Notices and Revisions
- How We Use Cookies and Similar Technologies
- How to Contact Us
1. How We Collect and Use Your Personal Information
We are committed to protecting the personal information you provide when using BOYA Notra. We follow laws and regulations in collecting, using, storing, and transmitting personal information, adhering to privacy protection principles to safeguard your information. Personal information refers to various types of information recorded electronically or by other means related to identified or identifiable natural persons, excluding anonymized information.
The personal information covered by this Privacy Policy includes:
- Basic Information (including nickname, region, email address, device number)
- Network Identification Information (including system account)
- Personal Internet Records (including login records, page interaction events, page dwell time)
Sensitive personal information refers to personal information that, if leaked or used illegally, can easily lead to the infringement of a natural person's dignity or endanger their personal or property safety. This includes biometrics, religious beliefs, specific identity, healthcare, financial accounts, location tracks, and the personal information of minors under the age of 14.
The sensitive personal information covered by this Privacy Policy includes: Personal location information (positioning information), audio recording information.
We will only collect and use your personal information for the following purposes to complete the business functions of the APP:
(i) Situations where you must authorize us to collect and use your personal information
Our services include core functions necessary to enable online shopping, improve our services, and ensure transaction security. We may collect, store, and use the following information about you to perform these functions. If you do not provide such information, you will be unable to utilize the services we provide. These functions include:
1. Functions Necessary for After-Sales Service
- User Registration: When you register, you need to provide us at least with the mobile phone number (or email address) you intend to use. We will verify your identity by sending a verification code to confirm its validity. You can also choose to register and log in using a third-party account, such as WeChat login, Apple ID login, or Google login. "BOYA USER" will be your default nickname, but you can change and add your nickname, gender, date of birth, and real-name verification information. Your additional account information helps us provide personalized services and a better event experience. Password rules: 8-20 characters, containing at least two types of letters, numbers, and special symbols.
-
Device Management: Collects hardware and software information such as device model, device serial number, operating system version, device settings, unique device identifiers including IMEI, MEID, MAC address, Android ID, OAID, ICCID, network status, and the list of installed software, as well as device location-related information including GPS location and WLAN access point information (such as SSID, BSSID, Bluetooth, and other sensor data) to optimize services.
- Purchase Service: When purchasing a service, the system generates an order containing service details, amount, and payment method. This "Order Information" is used to verify identity, process payment, check orders, provide customer service, and detect transaction anomalies to protect security.
- Payment Function: Payment services (Apple Pay, Stripe, credit cards, Alipay, WeChat Pay, etc.) may require sharing order number and transaction amount with payment institutions for processing.
- Delivery Service Function: BOYA Notra affiliates handle delivery and may use your order information to ensure proper fulfillment of ordered services.
2. Providing Personalized Services and Improving Service Quality
To enhance your service experience, improve service quality, or recommend better or more suitable services to you, we may collect your order information, browsing information, and interests for data analysis to form a user profile. This profile will be used to show you information about events or services you might be interested in. We may also obtain other information about you that we reasonably need to provide services and improve quality, including information you provide when contacting customer service, information you send us in response to surveys you participate in, and information we obtain when you interact with our affiliates and partners. For information collected from your various devices, we may associate it so we can provide you with consistent services across these devices. We may combine information from one service with information from other services to provide you with services, personalized content, and recommendations.
To enhance your experience with our services, we may collect and use your personal information for the following additional features. If you choose not to provide such personal information, you may still use the basic functions of this application. Please note that by enabling these permissions, you authorize us to collect and use your personal information for the purposes described below. By disabling these permissions, you revoke your authorization, and we will no longer collect or use your personal information, nor will we be able to provide the features that rely on these permissions. Your decision to disable permissions will not affect the processing of personal information previously conducted based on your authorization.
- Camera-Based Features: We request your authorization to access the camera function on your device so that you may use the camera to capture and upload custom avatars or other image files.
- Photo Upload Features: We require your authorization for BOYA Notra to access your photo gallery. This supports features such as capturing photos, uploading images, and updating your avatar. You may also provide images through the consultation window to help us better address device-related inquiries and suggestions.
- Microphone-Based Features: We require your authorization to access the microphone for functions such as recording, audio transcription, and translation services. This permission may also be used to generate time-stamped text segments for easier content review.
- Storage-Based Features: We require access to file read/write permissions on your device to enable file synchronization across devices, version management, and storage monitoring. The system automatically records file operation logs to ensure security and traceability.
- Notification-Based Features: To ensure proper implementation of membership benefits, we require access to your subscription information to verify service entitlements. This data is used to display current membership validity and provide renewal reminders.
3. Ensuring Operational Security Necessary for Transactions
To improve system security, prevent phishing and fraud, and protect account security, we may use your browsing information, order information, frequently used software information, and device information to assess your account risk. We may also record some URLs considered risky. Device information may be collected to analyze system issues, measure traffic, and rank potential risks based on exception information you choose to send.
(ii) Situations Where Personal Information May Be Collected Without Explicit Consent
- Related to national security and defense security
- Related to public safety, public health, and significant public interests
- Related to crime investigation, prosecution, trial, and execution of judgments
- Necessary to protect significant legal rights of the personal information subject or others, but obtaining consent is difficult
- Necessary to fulfill a contract or business arrangement previously agreed upon
- Information disclosed publicly by the personal information subject
- Information obtained from legally disclosed sources, e.g., legal news reports or government disclosures
- Necessary to realize the functions and services of the product according to your requirements
- Necessary to maintain security and stable operation of the products and/or services
- Other circumstances stipulated by laws and regulations
(iii) Rules for Using Your Personal Information
- Collected personal information will be used in accordance with this Privacy Policy to realize the functions of our products and/or services.
- After collection, data will be de-identified through technical means. The processed information will be unable to identify the subject and may be used for analysis or commercial purposes without disclosing personal information.
- All personal information provided during usage is continuously authorized unless you delete it. When you cancel your account, we will stop using and delete your personal information within a reasonable period.
- We may compile statistics on product usage and share with the public or third parties, without containing identifying information.
- Any use of personal information for purposes other than those stated in this policy will require prior consent initiated by you.
(iiii) Clipboard
To ensure the proper functioning of basic editing features such as copy and paste, this product needs access to your clipboard. This is used to process the text or links you actively copy, allowing you to edit content or quickly open web pages.
2. How We Share, Transfer, and Publicly Disclose Your Personal Information
(i) Sharing
We will not share your personal information with any company, organization, or individual outside Shenzhen Perfect Acoustic Technology Co., Ltd., except in the following cases:
- With your prior explicit consent or authorization
- Necessary to comply with applicable laws, regulations, legal procedures, or mandatory administrative or judicial requirements
- Necessary to protect BOYA Notra, affiliates or partners, you, other users, or public interest, property, or safety from harm
- Sharing information solely to realize core functions or provide the services you need
- Necessary to handle disputes or controversies between you and others at your request
- Necessary to comply with relevant agreements or other legal documents provided with consent
- Used for academic research purposes
- Used for public interests in accordance with laws and regulations
We may share your personal information with our affiliates (subsidiaries, holding companies, advertising companies, etc.), subject to this Privacy Policy's purposes. If affiliates wish to change processing purposes, they will seek your authorization again.
We may share order, account, device, and location information with partners or third parties to ensure smooth service delivery. Sharing is limited to lawful, necessary, and specific purposes, and partners cannot use information for other purposes. Partners include:
- Suppliers of goods or technical services: These third parties support our functions, providing infrastructure, logistics, payment, and data processing. Information is shared to enable core shopping functions, e.g., with logistics providers for delivery or payment providers to confirm transactions.
- Third-party merchants: Necessary order and transaction information is shared to allow purchase and completion of after-sales service.
3. Partners Hiring Us for Promotional Activities
Sometimes we may provide promotional services to our user base on behalf of other businesses. We may share your personal information and indirect user profiles formed by aggregating your non-personal information with partners who hire us for marketing activities ("Principals"). However, we will only provide these Principals with information about the scope and effectiveness of the marketing campaign, not your personally identifiable information, or we will aggregate this information so it cannot identify you personally. For example, we might tell the Principal how many people saw their marketing campaign or purchased the Principal's goods after seeing the information, or provide them with statistical information that does not personally identify individuals to help them understand their audience or customers.
For companies, organizations, and individuals with whom we share personal information, we will sign strict confidentiality agreements with them, requiring them to process personal information according to our instructions, this Privacy Policy, and any other relevant confidentiality and security measures.
(ii) Transfer
We will not transfer your personal information to any company, organization, or individual, except in the following cases:
- With your prior explicit consent or authorization;
- Necessary to comply with applicable laws and regulations, legal procedures, or mandatory administrative or judicial requirements;
- Necessary according to relevant agreements signed with you (including electronically signed agreements and corresponding platform rules) or other legal documents provided with consent;
- In the event of mergers, divisions, dissolution, bankruptcy, or other reasons requiring the transfer of your personal information, we will inform you of the recipient's name(s) and contact details. We will require the new company or organization to continue to be bound by this Privacy Policy, or they must seek your authorization and consent again.
(iii) Public Disclosure
We will only publicly disclose your personal information under the following circumstances and provided we take security measures that meet industry standards:
- Disclose the specific personal information you designate according to your needs and in the manner you explicitly agree to;
- When laws, regulations, mandatory administrative law enforcement, or judicial requirements necessitate providing your personal information, we may publicly disclose it based on the type of information requested and the method of disclosure. We will require presentation of legal documents such as subpoenas or inquiry letters. We review all requests carefully to ensure they have legal basis and are limited to data law enforcement is entitled to obtain.
3. How We Protect and Store Your Personal Information
(i) Technologies and Measures We Use to Protect Your Personal Information
We attach great importance to the security of personal information and take all reasonably feasible measures to protect it:
1. Data Security Technical Measures
- Adopting industry-standard security measures, including system specifications and security technologies, to prevent unauthorized access, use, modification, or loss of personal information.
- BOYA Notra uses encryption technologies such as TLS to ensure security during transmission.
- BOYA Notra encrypts stored personal information and employs isolation technology. Data masking techniques like content replacement and SHA256 are used in personal information display or correlation calculations.
- Strict data access controls and multi-factor authentication technologies protect personal information and prevent misuse.
- Automatic code security checks and data access log analysis are used for security auditing.
- Google Cloud provides infrastructure support for data security and integrity.
- OpenAI platform is used anonymously to obtain results, protecting privacy.
2. Other Security Measures
- Data classification and grading systems, data security management specifications, and data security development specifications are implemented.
- Comprehensive security controls through confidentiality agreements, monitoring, and auditing mechanisms.
- Security awareness is strengthened through training courses for employees.
3. Access Control
- Only employees and partners who need access may view personal information, with strict permission and monitoring mechanisms.
- All personnel accessing personal information must abide by confidentiality obligations. Noncompliance may lead to legal liability or termination of the relationship.
4. Minimizing Data Collection
We take all reasonable steps to avoid collecting irrelevant personal information and retain information only as long as necessary, unless required or permitted by law.
5. Internet Security Disclaimer
The internet is not 100% secure. We strive to ensure security of information, but if safeguards are compromised, leading to unauthorized access or damage, we will bear appropriate legal liability.
6. Security Incident Handling
If a personal information security incident occurs, we will promptly inform you, including:
- The basic situation and potential impact
- Measures taken or planned
- Suggestions to mitigate risks
- Available remedies
We will notify via email, letter, phone, or push messages. If individual notification is difficult, announcements will be published. Regulatory authorities will also be informed as required.
(ii) Storing Your Personal Information
- All personal information is stored within the People's Republic of China. Cross-border transfer requires your separate consent, adherence to signed data protection agreements, this Privacy Policy, and relevant laws.
- Unless required by law, personal information will be retained for one month after account cancellation, after which it will be deleted or anonymized.
- Upon termination of service or operations, you will be notified at least 30 days in advance. Personal information will be deleted or anonymized after termination.
4. How to Manage Your Personal Information
Shenzhen Perfect Acoustic Technology Co., Ltd. takes your concerns about personal information seriously and makes every effort to protect your rights to access, correct, delete, supplement, access, and withdraw consent to your personal information, so you have full capacity to protect your privacy and security. Your rights include:
- Access, correct, and supplement your personal information;
- Delete your personal information;
- Change the scope of your authorization consent or withdraw your authorization;
- Cancel your account.
We provide a function within our product for you to request account cancellation. To protect your legitimate rights and interests, we need to verify your identity before cancelling your account and determine whether to support your cancellation application based on your usage of BOYA Notra products. After you cancel your account, we will stop providing you with products and/or services and, subject to your request and except as otherwise provided by laws or regulations, delete your personal information.
Responding to Your Requests
If you are unable to access, correct, or delete your personal information in the ways described above, or if you need to access, correct, or delete other personal information generated by your use of our products and/or services, or if you believe BOYA Notra has violated any laws, regulations, or agreements with you in collecting or using personal information, you can contact us through the methods provided at the bottom of this agreement. For security reasons, we may need you to provide a written request or otherwise prove your identity. We will respond to your request within 30 days of receiving your feedback and verifying your identity. For your reasonable requests, we generally do not charge fees. However, for repeated requests exceeding reasonable limits, we may charge a cost fee at our discretion. We may refuse requests that are unnecessarily repetitive, require excessive technical means, pose a risk to the legitimate rights of others, or are highly impractical.
We May Be Unable to Respond to Requests If:
- Information is necessary to protect public interests, whether for health, safety, or other reasons;
- Information is needed for historical research, statistics, or scientific research;
- Information is necessary to comply with laws or regulations;
- Related to national security or defense security;
- Related to public safety, public health, or significant public interests;
- Related to crime investigation, prosecution, trial, etc.;
- There is sufficient evidence to indicate subjective malice or abuse of rights by the requester;
- Responding would seriously harm the legitimate rights and interests of you or others;
- Involves trade secrets.
Obtaining a Copy of Personal Information
You have the right to obtain a copy of your personal information. If you need a copy of the personal information we have collected about you, you can contact us using the contact methods agreed upon in Section 9. How to Contact Us. Relevant personnel will verify your identity and provide a copy of your personal information. Subject to laws, regulations, and technical feasibility, we will provide the information according to your requirements.
5. How We Handle Children's Personal Information
Shenzhen Perfect Acoustic Technology Co., Ltd. places great importance on the protection of children's personal information. Our products, websites, and services are primarily aimed at adults. Children may not create their own user accounts without parental or guardian consent.
We will only use or publicly disclose this information if permitted by law, with explicit parental or guardian consent, or when necessary to protect the child. Anyone under the age of 14 is considered a child. If we discover we have collected a child's personal information without prior verifiable parental consent, we will seek to delete the relevant data as soon as possible.
6. How Your Personal Information is Transferred Globally
In principle, personal information we collect will be stored within China. As we provide products and services through resources and servers worldwide, your information may be transferred to or accessed from other jurisdictions, which may have different data protection laws. We will ensure your personal information is fully protected within China, sign contracts with foreign recipients agreeing on rights and obligations, inform you of recipient details, and implement security measures such as data de-identification before cross-border transfer.
7. Notices and Revisions
This Privacy Policy will be updated as our business develops to provide better service. We will not reduce your rights without your explicit consent. Updates will be posted on our website before they take effect, or through other appropriate means. For major changes, we will provide prominent notices via email, SMS, or special notices on pages. Major changes include:
- Significant changes in service model, processing purpose, types of information, or usage methods;
- Major changes in equity or organizational structure;
- Changes in main recipients of personal information;
- Significant changes in your rights and how to exercise them;
- Changes in responsible contact methods and complaint channels.
8. How We Use Cookies and Similar Technologies
When you visit the APP, we use "Cookies"—small text files stored on your device's hard drive by the web server. We may use Cookies and similar technologies, such as web beacons, to store user preferences and settings, monitor website performance, prevent suspicious activities, fraudulent traffic, and other violations.
9. How to Contact Us
If you have any questions, comments, or suggestions regarding this Privacy Policy or your personal information, you can contact us as follows. We will respond within 15 working days:
- Email: se002@sz-cf.cn
- Phone: 400 613 1096 (Weekdays 09:00~12:00, 14:00~18:00)
Appendix: Links to Third-Party Service Provider Privacy Policies