BOYA Notra - Data Security and Privacy Policy

Version: v2.0
Effective Date: April 29, 2025

Introduction

Shenzhen Perfect Acoustic Technology Co., Ltd. ("We") takes the protection of user privacy and personal information very seriously. When you use our products and/or services, we may collect and use your relevant information. This "BOYA Notra Data Security and Privacy Policy" (the "Privacy Policy") aims to explain how we collect, use, store, share, and transfer this information, as well as how we provide you with access, updates, deletion, and protection of this information. We hope you will carefully read and confirm your full understanding of this policy before using our products and/or services. If you have any questions while reading, please contact our customer service for consultation. If you disagree with any terms in this agreement, please stop submitting information.

Before using our products and services, please be sure to carefully read and understand this policy, ensuring you fully understand and agree before use. We will explain professional terms involved in this policy in simple language for your convenience.

If you have any questions or concerns regarding this Privacy Policy or related matters, please contact us promptly.

This policy will help you understand the following:

1. How We Collect and Use Your Personal Information

We are committed to protecting the personal information you provide when using BOYA Notra. We follow laws and regulations in collecting, using, storing, and transmitting personal information, adhering to privacy protection principles to safeguard your information. Personal information refers to various types of information recorded electronically or by other means related to identified or identifiable natural persons, excluding anonymized information.

The personal information covered by this Privacy Policy includes:

Sensitive personal information refers to personal information that, if leaked or used illegally, can easily lead to the infringement of a natural person's dignity or endanger their personal or property safety. This includes biometrics, religious beliefs, specific identity, healthcare, financial accounts, location tracks, and the personal information of minors under the age of 14.

The sensitive personal information covered by this Privacy Policy includes: Personal location information (positioning information), audio recording information.

We will only collect and use your personal information for the following purposes to complete the business functions of the APP:

(i) Situations where you must authorize us to collect and use your personal information

Our services include core functions necessary to enable online shopping, improve our services, and ensure transaction security. We may collect, store, and use the following information about you to perform these functions. If you do not provide such information, you will be unable to utilize the services we provide. These functions include:

1. Functions Necessary for After-Sales Service

2. Providing Personalized Services and Improving Service Quality

To enhance your service experience, improve service quality, or recommend better or more suitable services to you, we may collect your order information, browsing information, and interests for data analysis to form a user profile. This profile will be used to show you information about events or services you might be interested in. We may also obtain other information about you that we reasonably need to provide services and improve quality, including information you provide when contacting customer service, information you send us in response to surveys you participate in, and information we obtain when you interact with our affiliates and partners. For information collected from your various devices, we may associate it so we can provide you with consistent services across these devices. We may combine information from one service with information from other services to provide you with services, personalized content, and recommendations.

To enhance your experience with our services, we may collect and use your personal information for the following additional features. If you choose not to provide such personal information, you may still use the basic functions of this application. Please note that by enabling these permissions, you authorize us to collect and use your personal information for the purposes described below. By disabling these permissions, you revoke your authorization, and we will no longer collect or use your personal information, nor will we be able to provide the features that rely on these permissions. Your decision to disable permissions will not affect the processing of personal information previously conducted based on your authorization.

3. Ensuring Operational Security Necessary for Transactions

To improve system security, prevent phishing and fraud, and protect account security, we may use your browsing information, order information, frequently used software information, and device information to assess your account risk. We may also record some URLs considered risky. Device information may be collected to analyze system issues, measure traffic, and rank potential risks based on exception information you choose to send.

(ii) Situations Where Personal Information May Be Collected Without Explicit Consent

(iii) Rules for Using Your Personal Information

(iiii) Clipboard

To ensure the proper functioning of basic editing features such as copy and paste, this product needs access to your clipboard. This is used to process the text or links you actively copy, allowing you to edit content or quickly open web pages.

2. How We Share, Transfer, and Publicly Disclose Your Personal Information

(i) Sharing

We will not share your personal information with any company, organization, or individual outside Shenzhen Perfect Acoustic Technology Co., Ltd., except in the following cases:

  1. With your prior explicit consent or authorization
  2. Necessary to comply with applicable laws, regulations, legal procedures, or mandatory administrative or judicial requirements
  3. Necessary to protect BOYA Notra, affiliates or partners, you, other users, or public interest, property, or safety from harm
  4. Sharing information solely to realize core functions or provide the services you need
  5. Necessary to handle disputes or controversies between you and others at your request
  6. Necessary to comply with relevant agreements or other legal documents provided with consent
  7. Used for academic research purposes
  8. Used for public interests in accordance with laws and regulations

We may share your personal information with our affiliates (subsidiaries, holding companies, advertising companies, etc.), subject to this Privacy Policy's purposes. If affiliates wish to change processing purposes, they will seek your authorization again.

We may share order, account, device, and location information with partners or third parties to ensure smooth service delivery. Sharing is limited to lawful, necessary, and specific purposes, and partners cannot use information for other purposes. Partners include:

  1. Suppliers of goods or technical services: These third parties support our functions, providing infrastructure, logistics, payment, and data processing. Information is shared to enable core shopping functions, e.g., with logistics providers for delivery or payment providers to confirm transactions.
  2. Third-party merchants: Necessary order and transaction information is shared to allow purchase and completion of after-sales service.

3. Partners Hiring Us for Promotional Activities

Sometimes we may provide promotional services to our user base on behalf of other businesses. We may share your personal information and indirect user profiles formed by aggregating your non-personal information with partners who hire us for marketing activities ("Principals"). However, we will only provide these Principals with information about the scope and effectiveness of the marketing campaign, not your personally identifiable information, or we will aggregate this information so it cannot identify you personally. For example, we might tell the Principal how many people saw their marketing campaign or purchased the Principal's goods after seeing the information, or provide them with statistical information that does not personally identify individuals to help them understand their audience or customers.

For companies, organizations, and individuals with whom we share personal information, we will sign strict confidentiality agreements with them, requiring them to process personal information according to our instructions, this Privacy Policy, and any other relevant confidentiality and security measures.

(ii) Transfer

We will not transfer your personal information to any company, organization, or individual, except in the following cases:

  1. With your prior explicit consent or authorization;
  2. Necessary to comply with applicable laws and regulations, legal procedures, or mandatory administrative or judicial requirements;
  3. Necessary according to relevant agreements signed with you (including electronically signed agreements and corresponding platform rules) or other legal documents provided with consent;
  4. In the event of mergers, divisions, dissolution, bankruptcy, or other reasons requiring the transfer of your personal information, we will inform you of the recipient's name(s) and contact details. We will require the new company or organization to continue to be bound by this Privacy Policy, or they must seek your authorization and consent again.

(iii) Public Disclosure

We will only publicly disclose your personal information under the following circumstances and provided we take security measures that meet industry standards:

  1. Disclose the specific personal information you designate according to your needs and in the manner you explicitly agree to;
  2. When laws, regulations, mandatory administrative law enforcement, or judicial requirements necessitate providing your personal information, we may publicly disclose it based on the type of information requested and the method of disclosure. We will require presentation of legal documents such as subpoenas or inquiry letters. We review all requests carefully to ensure they have legal basis and are limited to data law enforcement is entitled to obtain.

3. How We Protect and Store Your Personal Information

(i) Technologies and Measures We Use to Protect Your Personal Information

We attach great importance to the security of personal information and take all reasonably feasible measures to protect it:

1. Data Security Technical Measures

2. Other Security Measures

3. Access Control

4. Minimizing Data Collection

We take all reasonable steps to avoid collecting irrelevant personal information and retain information only as long as necessary, unless required or permitted by law.

5. Internet Security Disclaimer

The internet is not 100% secure. We strive to ensure security of information, but if safeguards are compromised, leading to unauthorized access or damage, we will bear appropriate legal liability.

6. Security Incident Handling

If a personal information security incident occurs, we will promptly inform you, including:

We will notify via email, letter, phone, or push messages. If individual notification is difficult, announcements will be published. Regulatory authorities will also be informed as required.

(ii) Storing Your Personal Information

  1. All personal information is stored within the People's Republic of China. Cross-border transfer requires your separate consent, adherence to signed data protection agreements, this Privacy Policy, and relevant laws.
  2. Unless required by law, personal information will be retained for one month after account cancellation, after which it will be deleted or anonymized.
  3. Upon termination of service or operations, you will be notified at least 30 days in advance. Personal information will be deleted or anonymized after termination.

4. How to Manage Your Personal Information

Shenzhen Perfect Acoustic Technology Co., Ltd. takes your concerns about personal information seriously and makes every effort to protect your rights to access, correct, delete, supplement, access, and withdraw consent to your personal information, so you have full capacity to protect your privacy and security. Your rights include:

  1. Access, correct, and supplement your personal information;
  2. Delete your personal information;
  3. Change the scope of your authorization consent or withdraw your authorization;
  4. Cancel your account.

We provide a function within our product for you to request account cancellation. To protect your legitimate rights and interests, we need to verify your identity before cancelling your account and determine whether to support your cancellation application based on your usage of BOYA Notra products. After you cancel your account, we will stop providing you with products and/or services and, subject to your request and except as otherwise provided by laws or regulations, delete your personal information.

Responding to Your Requests

If you are unable to access, correct, or delete your personal information in the ways described above, or if you need to access, correct, or delete other personal information generated by your use of our products and/or services, or if you believe BOYA Notra has violated any laws, regulations, or agreements with you in collecting or using personal information, you can contact us through the methods provided at the bottom of this agreement. For security reasons, we may need you to provide a written request or otherwise prove your identity. We will respond to your request within 30 days of receiving your feedback and verifying your identity. For your reasonable requests, we generally do not charge fees. However, for repeated requests exceeding reasonable limits, we may charge a cost fee at our discretion. We may refuse requests that are unnecessarily repetitive, require excessive technical means, pose a risk to the legitimate rights of others, or are highly impractical.

We May Be Unable to Respond to Requests If:

  1. Information is necessary to protect public interests, whether for health, safety, or other reasons;
  2. Information is needed for historical research, statistics, or scientific research;
  3. Information is necessary to comply with laws or regulations;
  4. Related to national security or defense security;
  5. Related to public safety, public health, or significant public interests;
  6. Related to crime investigation, prosecution, trial, etc.;
  7. There is sufficient evidence to indicate subjective malice or abuse of rights by the requester;
  8. Responding would seriously harm the legitimate rights and interests of you or others;
  9. Involves trade secrets.

Obtaining a Copy of Personal Information

You have the right to obtain a copy of your personal information. If you need a copy of the personal information we have collected about you, you can contact us using the contact methods agreed upon in Section 9. How to Contact Us. Relevant personnel will verify your identity and provide a copy of your personal information. Subject to laws, regulations, and technical feasibility, we will provide the information according to your requirements.

5. How We Handle Children's Personal Information

Shenzhen Perfect Acoustic Technology Co., Ltd. places great importance on the protection of children's personal information. Our products, websites, and services are primarily aimed at adults. Children may not create their own user accounts without parental or guardian consent.

We will only use or publicly disclose this information if permitted by law, with explicit parental or guardian consent, or when necessary to protect the child. Anyone under the age of 14 is considered a child. If we discover we have collected a child's personal information without prior verifiable parental consent, we will seek to delete the relevant data as soon as possible.

6. How Your Personal Information is Transferred Globally

In principle, personal information we collect will be stored within China. As we provide products and services through resources and servers worldwide, your information may be transferred to or accessed from other jurisdictions, which may have different data protection laws. We will ensure your personal information is fully protected within China, sign contracts with foreign recipients agreeing on rights and obligations, inform you of recipient details, and implement security measures such as data de-identification before cross-border transfer.

7. Notices and Revisions

This Privacy Policy will be updated as our business develops to provide better service. We will not reduce your rights without your explicit consent. Updates will be posted on our website before they take effect, or through other appropriate means. For major changes, we will provide prominent notices via email, SMS, or special notices on pages. Major changes include:

  1. Significant changes in service model, processing purpose, types of information, or usage methods;
  2. Major changes in equity or organizational structure;
  3. Changes in main recipients of personal information;
  4. Significant changes in your rights and how to exercise them;
  5. Changes in responsible contact methods and complaint channels.

8. How We Use Cookies and Similar Technologies

When you visit the APP, we use "Cookies"—small text files stored on your device's hard drive by the web server. We may use Cookies and similar technologies, such as web beacons, to store user preferences and settings, monitor website performance, prevent suspicious activities, fraudulent traffic, and other violations.

9. How to Contact Us

If you have any questions, comments, or suggestions regarding this Privacy Policy or your personal information, you can contact us as follows. We will respond within 15 working days:

Appendix: Links to Third-Party Service Provider Privacy Policies