CoFrame 隐私政策
提示条款
您的信任对我们非常重要,我们深知个人信息对您的重要性,并会尽全力保护您的个人信息安全可靠。我们致力于维持您对我们的信任,恪守以下原则,保护您的个人信息:权责一致原则、目的明确原则、选择统一原则、最小必要原则、确保安全原则、主体参与原则、公开透明原则等。同时,我们将按业界成熟的安全标准,采取相应的安全保护措施来保护您的个人信息。鉴于此,“CoFrame”服务提供者(或简称“我们”)制定本《隐私权政策》(下称“本政策/本隐私权政策”)并提醒您:
本政策适用于“CoFrame”提供的所有产品和服务,包括但不限于电脑端、移动智能终端、车载端的应用程序、网页、供第三方网站和应用程序使用的软件开发工具包(SDK)和应用程序编程接口(API)以及不断创新研发的产品及服务。如您使用“CoFrame”提供的某项或某几项服务有其单独的隐私权政策的,该服务对应的隐私权政策将与本隐私权政策一起构成一套完整的隐私权政策。
需要特别说明的是,本政策不适用于其他第三方向您提供的服务,为确保流畅的产品体验,您可能会收到来自第三方提供的内容或网络链接。请您谨慎选择是否访问第三方提供的链接、内容、产品和服务。在向第三方提交个人信息之前,请认真阅读这些第三方的隐私政策。
在使用我们各项产品或服务前,请您务必仔细阅读并透彻理解本政策。特别是以粗体/粗体下划线标识的条款,请您重点阅读,在确认充分理解并同意后再开始使用。如对本政策内容有任何疑问、意见或建议,您可通过“CoFrame”提供的各种联系方式与我们联系。
第一部分 定义
“CoFrame”:指“CoFrame”手机APP端。
“CoFrame”服务提供者:指研发并提供“CoFrame”APP法人主体,即深圳市同洲电子股份有限公司。
儿童:指不满十四周岁的未成年人。
个人信息:指以电子或者其他方式记录的能够单独或者与其他信息结合识别特定自然人身份或者反映特定自然人活动情况的各种信息。
个人敏感信息:指包括人脸信息、身份证件号码、个人生物识别信息、银行账号、财产信息、行踪轨迹、交易信息、儿童信息的个人私密信息(我们将在本隐私权政策中对具体个人敏感信息以粗体进行显著标识)。 个人信息删除:指在实现日常业务功能所涉及的系统中去除个人信息的行为,使其保持不可被检索、访问的状态。
第二部分 隐私权政策
本隐私权政策部分将帮助您了解以下内容:
- 我们如何收集和使用您的个人信息
- 我们如何使用 Cookie 和同类技术
- 我们如何委托处理、共享、转让、公开披露您的个人信息
- 我们如何保护您的个人信息
- 您如何管理您的个人信息
- 对第三方的责任声明
- 我们如何处理儿童的个人信息
- 您的个人信息如何在全球范围转移
- 本隐私权政策如何更新
一、我们如何收集和使用您的信息
您理解并同意:
- 我们致力于打造多样的产品和服务以满足您的需求。因我们向您提供的产品和服务种类众多,且不同用户选择使用的具体产品/服务范围存在差异,相应地,各类功能及收集使用的个人信息类型、范围会有所区别,请以具体的产品/服务功能为准;
- 为给您带来更好的产品和服务体验,我们在持续努力改进我们的技术,随之我们可能会不时推出新的或优化后的功能,可能需要收集、使用新的个人信息或变更个人信息使用目的或方式。对此, 我们将通过更新本政策、弹窗、页面提示方式另行向您说明对应信息的收集目的、范围及使用方式,并为您提供自主选择同意的方式,且在征得您明示同意后收集、使用。
(一)帮助您成为我们的用户
1、注册、登录
为帮助您成为我们的用户,以便我们为您提供用户服务。您需要提供手机号码创建帐号设置密码(或验证码)和昵称以成为我们的注册用户。当您注册、登录我们的服务时,我们会收集您的唯一设备标识符信息(ANDROID ID),用于标识您为我们的用户。
2、信息完善
您可以选择进一步完善本产品帐号信息,如填写生日、性别信息,但如果您不提供这些信息,也不会影响您使用本产品提供的基础服务。
(二)为您提供浏览服务
1. 查询和搜索功能。在您使用我们本地新闻资讯、生活服务、爆料服务过程中,为识别帐号异常状态、了解产品适配性、向您提供更契合您需求的内容展示和搜索结果,同时基于文件缓存、下载,日志存储基础运营需求, 我们需要获得您的公共区域读写权限,访问网络连接,并可能会自动收集您的使用情况并存储为网络日志信息,包括:
设备信息:我们会根据您在软件安装及/或使用中的具体操作,接收并记录您所使用的设备相关信息(包括设备型号、设备序列号、操作系统版本、设备设置、唯一设备标识符(ANDROID ID)、设备环境软硬件特征信息、MAC地址)、 设备所在位置相关信息(包括您授权的 GPS 位置以及 WLAN 接入点、蓝牙和基站传感器信息)、 设备状态信息(获取 wifi 状态、获取/修改 WiFi 状态),以及当前 Wi-Fi 网络标识信息(SSID、BSSID、MAC地址)。
服务日志信息:当您使用我们提供的产品或服务时,我们会自动收集您对我们服务的详细使用情况,作为服务日志保存,包括 浏览、点击查看、搜索查询、收藏、关注分享信息、发布信息, 以及浏览器类型、电信运营商、使用语言、访问日期和时间。
智能相框配网功能。当您使用“CoFrame”APP 添加智能相框设备时,为实现相框配网连接,我们需要申请您的 Wi-Fi 权限及位置权限,通过系统 API 获取当前连接的 Wi-Fi 信息(包括 SSID、BSSID、MAC地址),同时获取您的唯一设备标识符信息(ANDROID ID)用于标识配网设备。若您拒绝提供上述信息,将无法使用智能相框配网功能,但不会影响您正常使用其它功能。
关于收集 BSSID、MAC地址、SSID 的专项说明: 为实现智能相框 Wi-Fi 配网、局域网设备发现、连接校验及配网安全保障,我们会在您授权后收集以下设备网络标识信息:
- SSID:即您当前连接或选择的 Wi-Fi 网络名称。收集目的为将智能相框接入您指定的无线网络;收集方式为在您使用配网功能时通过系统 API(如 WifiManager)读取当前 Wi-Fi 信息。
- BSSID:即您当前连接的 Wi-Fi 接入点标识。收集目的为识别并匹配目标无线网络,避免连错网络;收集方式同上,仅在配网及设备连接校验场景使用。
- MAC地址:包括手机设备的 Wi-Fi MAC地址、蓝牙 MAC地址,以及相框设备/路由器相关的 MAC地址。收集目的为设备识别、局域网发现、配网校验及连接状态确认;收集方式为在您使用配网或设备管理功能时通过系统 API 获取。我们不会将 MAC地址用于精准定位,也不会出售给第三方。
上述 BSSID、MAC地址、SSID 仅用于智能相框配网、设备绑定与连接状态展示,不会用于与您身份无关的画像或广告投放。您可拒绝提供;拒绝后将无法完成配网及局域网发现,但不影响浏览等其他功能。您也可在系统设置中关闭位置/Wi-Fi 相关权限,或通过本政策第五部分申请删除相关信息。
请注意,单独的设备信息、服务日志信息是无法识别特定自然人身份的信息。如果我们将这类非个人信息与其他信息结合用于识别特定自然人身份,或者将其与个人信息结合使用,则在结合使用期间,这类非个人信息将被视为个人信息,除取得您授权或法律法规另有规定外,我们会将这类信息做匿名化、去标识化处理。
2. 调用第三方应用功能。我们将获取您 手机的摄像头权限 用以帮助您使用已登录的移动设备扫描网页二维码的形式登录网页端产品。
3. 当 APP 进入到后台时,我们将获取 正在运行中的进程及应用列表 ,以给出离开 APP 的安全提示。
此外,我们也会为了不断改进和优化上述的功能来使用您的上述信息。
我们收集、使用的上述信息均进行了去标识化处理,数据分析仅对应特定的、无法直接关联您身份的编码,不会与您的真实身份相关联。
(三)为您提供信息发布和互动服务
1、内容上传与发布
- 当您使用内容评论、回复功能时,我们将收集您选择发布的信息内容,并展示您的昵称、头像、发布内容(图文、视音频)。
- 当您使用上传图片、视音频功能时,我们会申请您的摄像头、麦克风、相册权限,只有在您明确同意后我们才会在您同意的范围内允许录音或者允许拍照。当您的手机使用 SD 卡时,为了读取相册,我们还会申请读取 SD 卡上的数据、修改/删除 SD 卡上的数据。若您拒绝提供,将无法使用此功能,但不会影响您正常使用其它功能。
- 您发布信息并选择显示位置时,我们会申请您的位置权限,获取地理位置,并收集与本服务相关的位置信息。若您拒绝提供精确地理位置信息,将无法使用此功能,但不会影响您正常使用其它功能。
- 请注意,您公开发布的信息中可能会涉及您或他人的个人信息甚至个人敏感信息,如您发布时选择上传包含个人信息的图片。请您更加谨慎地考虑,是否在使用我们的服务时共享甚至公开分享相关信息。您公开发布的信息中涉及儿童个人信息的,需在发布前取得所涉及儿童的监护人授权。
- 智能相框设备管理。当您在“CoFrame”APP 中管理智能相框设备时,我们会申请您的位置权限,获取地理位置信息,用于智能相框的定位与设备匹配。若您拒绝提供精确地理位置信息,将无法使用智能相框设备定位功能,但不会影响您正常使用其它功能。
2、互动
您对感兴趣的内容、专题产生互动(进行收藏、点赞、评论或分享内容时)我们会收集您收藏的帐号,并向您展示您关注帐号发布内容。当您使用向微博、微信第三方平台分享信息的功能时,我们会收集您的软件列表,用于判断微信、微博第三方社交软件是否已安装。您参与答题时,我们会收集您的答题数据并进行展示。
3、消息通知
为向您提供应急广播、消息通知服务,我们会申请您的系统通知权限,用于系统及用户消息告知。若您拒绝提供,将无法收到我们的消息通知,但不会影响您正常使用其它功能。
为提升消息的送达率,及时地为您进行消息提醒,我们会默认为您开启关联启动功能,以保持应用的活跃度。如您不想开通此功能,我们建议您手动进行关闭,一般关闭路径:设置 - 应用 - 应用启动管理 - 选择应用“CoFrame” - 关闭关联启动功能。
(四)为您提供安全保障
为预防、发现、调查欺诈、危害帐户安全或其他违反与我们协议的行为,或实现您访问的目的,我们将收集您的网络信息、设备信息、手机型号、硬件信息和系统信息。为更好地预防网络漏洞、计算机病毒、网络攻击、网络侵入安全风险,更准确地识别违反法律法规或我们相关协议规则的情况,我们可能使用或整合您的会员信息、设备信息、服务日志信息以及我们合作伙伴取得您授权或依据法律共享的信息,来综合判断您帐户及交易风险、进行身份验证、检测及防范安全事件,并依法采取必要的记录、审计、分析、处置措施。为实现智能相框配网及设备管理的安全验证,预防欺诈、保障您的设备与帐户安全,我们会收集您的 Wi-Fi 信息(SSID、BSSID、MAC地址)、设备标识信息(ANDROID ID)、设备型号及系统信息,用于配网身份验证、异常检测及安全风险防范。
为了使您能够接收信息推送、在第三方平台分享信息、使用语音播报服务必要功能用途,我们的应用中会嵌入授权合作伙伴的 SDK 或其他类似的应用程序。我们接入的第三方提供的软件开发包(SDK)目录如下:
微信开放平台
使用目的:分享内容到微信消息或朋友圈
收集个人信息类型:设备标识信息、网络信息
官网链接:https://open.weixin.qq.com/
我们会对授权合作伙伴获取有关信息的应用程序接口(API)、软件工具开发包(SDK)进行严格的安全检测,并与授权合作伙伴约定严格的数据保护措施,令其按照我们的委托目的、服务说明、本隐私权政策以及其他任何相关的保密和安全措施来处理个人信息。
(五)其他
- 若您提供的信息中含有其他用户的个人信息,在向我们提供这些个人信息之前,您需确保您已经取得合法的授权。
- 若我们将信息用于本政策未载明的其他用途,或者将基于特定目的收集而来的信息用于其他目的,或者我们主动从第三方处获取您的个人信息,均会事先获得您的同意。
若我们从第三方处间接获取您的信息的,我们会在收集前明确以书面形式要求该第三方在已依法取得您同意后收集个人信息,并向您告知共享的信息内容,且涉及敏感信息的在提供给我们使用前需经过您的明确确认,要求第三方对个人信息来源的合法性和合规性作出承诺,如第三方有违反行为的,我们会明确要求对方承担相应法律责任;同时,我们的专业安全团队对个人信息会进行安全加固(包括敏感信息报备、敏感信息加密存储、访问权限控制)。我们会使用不低于我们对自身用户个人信息同的保护手段与措施对间接获取的个人信息进行保护。
3、征得授权同意的例外
您充分理解并同意,我们在以下情况下收集、使用您的个人信息无需您的授权同意,且我们可能不会响应您提出的更正/修改、删除、注销、撤回同意、索取信息的请求:
- 与国家安全、国防安全有关的;
- 与公共安全、公共卫生、重大公共利益有关的;
- 与犯罪侦查、起诉、审判和判决执行司法或行政执法有关的;
- 出于维护您或其他个人的生命、财产重大合法权益但又很难得到本人同意的;
- 您自行向社会公众公开的个人信息;
- 从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开渠道;
- 根据与您签订和履行相关协议或其他书面文件所必需的;
- 用于维护所提供的产品及/或服务的安全稳定运行所必需的,发现、处置产品及/或服务的故障;
- 为合法的新闻报道所必需的;
- 学术研究机构基于公共利益开展统计或学术研究所必要,且对外提供学术研究或描述的结果时,对结果中所包含的个人信息进行去标识化处理的;
- 法律法规规定的其他情形;
- 为实现智能设备配网所必需,且已通过隐私政策明确告知并取得您同意的。
请知悉,根据适用的法律,若我们对个人信息采取技术措施和其他必要措施进行处理,使得数据接收方无法重新识别特定个人且不能复原,或我们可能会对收集的信息进行去标识化地研究、统计分析和预测,用于改善我们的内容和布局,为商业决策提供产品或服务支撑,以及改进我们的产品和服务(包括使用匿名数据进行机器学习或模型算法训练),则此类处理后数据的使用无需另行向您通知并征得您的同意。
4、如我们停止运营我们的产品或服务,我们将及时停止继续收集您个人信息的活动,将停止运营的通知以逐一送达或公告的形式通知您,并对我们所持有的与已关停业务相关的个人信息进行删除或匿名化处理。
(六)人脸数据处理
1. 我们收集的人脸数据
当您使用“CoFrame”APP 中基于人工智能技术的人脸相关功能(包括但不限于人脸检测、人脸分析、人脸识别、人像处理、AI 效果生成等)时,我们需要收集您主动上传的人脸图像、照片或视频中的人脸信息。具体收集的人脸数据包括:
- 人脸图像/照片:您通过相机拍摄或从相册上传的包含人脸的图片;
- 面部特征信息:通过人工智能算法从人脸图像中提取的面部特征点、面部轮廓等数学表征信息;
- 人脸识别结果:经算法处理后生成的人脸检测、人脸分析、人脸验证等相关结果数据。
请您特别注意:人脸信息属于个人敏感信息。根据《中华人民共和国个人信息保护法》及《人脸识别技术应用安全管理办法》的相关规定,人脸信息属于敏感个人信息,我们将在处理前取得您的单独同意。
2. 人脸数据的使用目的
我们收集和使用您的人脸数据仅用于以下明确目的:
- AI 功能服务:为您提供人脸检测、人脸分析、人脸识别、AI 滤镜、AI 效果生成等功能,实现您所请求的图像处理、风格转换、美颜美化等具体服务;
- 身份验证:在需要进行实名认证或身份核验的场景下,通过人脸比对验证操作人身份;
- 服务优化:在确保不识别到您个人身份的前提下,对人脸数据进行匿名化、去标识化处理后,用于改进和优化我们的人工智能算法和模型,提升功能准确性和用户体验。
我们承诺,不会将您的人脸数据用于本政策未载明的其他用途。如确需用于其他目的,我们将另行向您告知并再次征得您的明确同意。
3. 人脸数据的共享与存储
(1)共享
我们承诺,不会将您的人脸数据与“CoFrame”服务提供者以外的任何第三方共享,但以下情况除外:
- 第三方 AI 服务提供商:如您使用的人脸相关功能需要通过第三方人工智能服务商(例如 AI 模型服务提供商)进行处理,我们将在您使用该功能前通过明确的弹窗告知您数据传输的对象、数据类型和用途,并在获得您的单独同意后,将您的人脸图像/照片以加密方式传输至该第三方服务商进行处理。该第三方服务商仅能在完成您所请求的具体功能所必需的范围内接触和处理数据,不得将数据用于其他任何目的。
- 法律法规要求:根据法律法规、诉讼、争议解决需要,或按行政、司法机关依法提出的要求,我们可能需要对外共享您的相关信息。
(2)存储
- 存储地点:您的人脸数据将存储在中华人民共和国境内。如因使用第三方 AI 服务而涉及数据出境,我们将按照国家有关规定进行出境安全评估,并确保符合相关法律法规要求。
- 存储方式:我们采用业界领先的加密技术对您的人脸数据进行加密存储,并通过严格的访问控制机制,确保只有经授权的人员在必要情况下才能访问。
4. 人脸数据的保留期限
我们仅在为实现本政策所述目的所必要的最短期限内保留您的人脸数据,具体标准如下:
- 实时处理场景:对于仅用于一次性 AI 效果生成的人脸图像,我们在完成处理后立即删除,不在服务器端留存;
- 需留存场景:如因身份验证、账户安全等需要留存人脸特征信息,我们将在您使用相关服务期间保留,并在您注销账户或撤回同意后及时删除;
- 法律法规另有要求的,从其规定。
在超出上述保留期限后,我们将根据适用法律的要求删除您的人脸数据或对其进行匿名化处理。
5. 您的权利
您对人脸数据享有以下权利:
- 知情权:您有权了解我们收集、使用、共享您人脸数据的详细情况;
- 同意权:您有权随时撤回您对人脸数据处理的同意,撤回后我们将停止处理相关数据;
- 删除权:您有权要求我们删除您的人脸数据。您可以通过“第五部分 您如何管理您的个人信息”中列明的方式提出删除请求;
- 拒绝权:您有权拒绝提供人脸数据,拒绝后仅影响相关 AI 功能的正常使用,不影响您使用本产品的其他基础服务。
6. 征得授权同意的例外
您充分理解并同意,我们在以下情况下处理人脸数据无需事先征得您的授权同意:
- 与国家安全、国防安全直接相关的;
- 与公共安全、公共卫生、重大公共利益直接相关的;
- 与犯罪侦查、起诉、审判和判决执行等直接相关的;
- 出于维护您或其他个人的生命、财产等重大合法权益但又很难得到本人同意的;
- 您自行向社会公众公开的人脸信息;
- 从合法公开披露的信息中收集人脸信息的。
7. 未成年人人脸数据保护
如您为儿童(不满十四周岁的未成年人),在使用人脸相关功能前,必须取得您的监护人的明确同意。我们不会在未获得监护人同意的情况下收集儿童的人脸数据。如发现未经监护人同意收集了儿童人脸数据,我们将尽快删除相关数据。
二、我们如何使用 Cookie 和同类技术
(一)Cookie
为确保“CoFrame”平台正常运转、为您获得更轻松的访问体验,我们会在您的计算机或移动设备上存储 Cookie、Flash Cookie,或浏览器(或关联应用程序)提供的其他通常包含标识符、站点名称以及一些号码和字符的本地存储(统称“Cookie”)。借助于 Cookie,本平台能够存储您的偏好数据。
如果您的附加服务允许,您可修改对 Cookie 的接受程度或拒绝我们的 Cookie。有关详情,请参见 AboutCookies.org。但如果您这么做,您将可能无法享受更佳的服务体验,甚至在某些情况下可能会影响您安全访问我们的网站,且可能需要在每一次访问我们的平台时更改用户设置;因您的个人修改导致个人数据泄漏或相关其他用户数据泄漏的,由您承担全部法律责任。
(二)Cookie 同类技术
除 Cookie 外,我们还会使用网站信标、像素标签、ETag 其他同类技术。
我们向您发送的电子邮件可能含有链接至我们网站内容的地址链接,如果您点击该链接,我们则会跟踪此次点击,帮助我们了解您的产品或服务偏好,以便于我们主动改善客户服务体验。网站信标通常是一种嵌入到网站或电子邮件中的透明图像。借助于电子邮件中的像素标签,我们能够获知电子邮件是否被打开。如果您不希望自己的活动以这种方式被追踪,则可以随时从我们的寄信名单中退订。
ETag(实体标签)是在互联网浏览器与互联网服务器之间背后传送的 HTTP 协议标头,可代替 Cookie。ETag 可以帮助我们避免不必要的服务器负载,提高服务效率,节省资源、能源,同时,我们可能通过 ETag 来记录您的身份,以便我们可以更深入地了解和改善我们的产品或服务。大多数浏览器均为用户提供了清除浏览器缓存数据的功能,您可以在浏览器设置功能中进行相应的数据清除操作。但请注意,如果停用 ETag,您可能无法享受相对更佳的产品或服务体验;由此造成的个人数据丢失,由个人承担不利后果。
三、我们如何委托处理、共享、转让、公开披露您的个人信息
(一)委托处理
本业务功能中某些具体的模块或功能由外部供应商提供。例如我们会聘请服务提供商来协助我们提供客户支持。
对我们委托处理个人信息的公司、组织和个人,我们会与其签署严格的保密协定,要求他们按照我们的要求、本个人信息保护政策以及其他任何相关的保密和安全措施来处理个人信息。
(一)共享
我们不会与“CoFrame”服务提供者以外的公司、组织和个人共享您的个人信息,但以下情况除外:
- 在法定情形下的共享:我们可能会根据法律法规规定、诉讼、争议解决需要,或按行政、司法机关依法提出的要求,对外共享您的个人信息。
- 在获取明确同意的情况下共享:获得您的明确同意后,我们会与其他方共享您的个人信息。
- 与授权合作伙伴共享:智能设备服务提供商。我们可能委托智能设备服务提供商为您提供智能相框的配网、管理等服务,我们仅会出于本隐私权政策声明的合法、正当、必要、特定、明确的目的共享您的 Wi-Fi 信息(SSID、BSSID、MAC地址)及设备标识信息(ANDROID ID),授权合作伙伴只能接触到其履行职责所需信息,且不得将此信息用于其他任何目的。
目前,我们的授权合作伙伴包括以下类型:
- 内容分析服务类的授权合作伙伴。“CoFrame”中的内容可能由我们的合作方,或者我们与软件服务提供商、智能设备提供商、系统服务提供商(以下或称“服务提供方”)联合向您提供。除非得到您的许可,否则我们不会将您的个人身份信息与提供内容、分析服务的合作伙伴共享。我们会委托这些合作伙伴处理与内容覆盖面和有效性相关的信息,但不会提供您的个人身份信息,我们会将去标识化后的个人信息与这些服务提供方进行共享,基于综合统计并通过算法作特征与偏好分析,形成间接人群画像,而不会识别到您个人。这类合作伙伴可能将上述信息与他们合法获取的其他数据相结合,以执行我们委托的内容服务或决策建议。
- 供应商、服务提供商和其他合作伙伴。我们将信息发送给支持我们业务的供应商、服务提供商和其他合作伙伴,这些支持包括受我们委托提供的技术基础设施服务、分析我们服务的使用方式、衡量广告和服务的有效性、提供客户服务、支付便利。
- AI 服务提供商。如您使用人脸检测、人脸分析、AI 效果生成等人工智能相关功能,我们可能在获得您单独同意后,将您的人脸图像/照片以加密方式传输给第三方 AI 服务提供商进行处理。我们仅会出于实现您所请求的具体功能之目的共享必要的人脸数据,并要求合作伙伴严格按照我们的委托目的、服务说明、本隐私权政策以及相关保密和安全措施来处理数据,不得将数据用于其他任何目的或留存数据。
我们会对授权合作伙伴获取有关信息的应用程序接口(API)、软件工具开发包(SDK)进行严格的安全检测,并与授权合作伙伴约定严格的数据保护措施,令其按照我们的委托目的、服务说明、本隐私权政策以及其他任何相关的保密和安全措施来处理个人信息。
(二)转让
我们不会将您的个人信息转让给任何公司、组织和个人,但以下情况除外:
- 在获取明确同意的情况下转让:获得您的明确同意后,我们会向其他方转让您的个人信息;
- 在本产品服务提供者发生合并、收购或破产清算情形,或其他涉及合并、收购或破产清算情形时,如涉及到个人信息转让,我们会要求新的持有您个人信息的公司、组织继续受本政策的约束,否则我们将要求该公司、组织和个人重新向您征求授权同意。
(三)公开披露
我们仅会在以下情况下,公开披露您的个人信息:
- 获得您明确同意或基于您的主动选择,我们可能会公开披露您的个人信息;
- 如果我们确定您出现违反法律法规或严重违反本产品相关协议规则的情况,或为保护本产品及其关联公司用户或公众的人身财产安全免遭侵害,我们可能依据法律法规或本产品相关协议规则披露关于您的个人信息,包括相关违规行为以及本产品已对您采取的措施。
(四)共享、转让、公开披露个人信息时事先征得授权同意的例外
以下情形中,共享、转让、公开披露您的个人信息无需事先征得您的授权同意:
- 与国家安全、国防安全有关的;
- 与公共安全、公共卫生、重大公共利益有关的;
- 与犯罪侦查、起诉、审判和判决执行有关的;
- 出于维护您或其他个人的生命、财产重大合法权益但又很难得到本人同意的;
- 您自行向社会公众公开的个人信息;
- 从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开渠道。
根据法律规定,共享、转让经去标识化处理的个人信息,且确保数据接收方无法复原并重新识别个人信息主体的,不属于个人信息的对外共享、转让及公开披露行为,对此类数据的保存及处理将无需另行向您通知并征得您的同意。
四、我们如何保护您的个人信息安全
- 我们已采取符合业界标准、合理可行的安全防护措施保护您的信息,防止个人信息遭到未经授权访问、公开披露、使用、修改、损坏或丢失。在您的客户端与服务器之间交换数据时受 SSL 协议加密保护;我们会使用加密技术提高个人信息的安全性;我们会使用受信赖的保护机制防止个人信息遭到恶意攻击;我们会部署访问控制机制,尽力确保只有授权人员才可访问个人信息;以及我们会举办安全和隐私保护培训课程,加强员工对于保护个人信息重要性的认识。
- 我们有行业先进的以数据为核心、围绕数据生命周期进行的数据安全管理体系,从组织建设、制度设计、人员管理、产品技术方面多维度提升整个系统的安全性。
-
我们会采取合理可行的措施,尽力避免收集无关的个人信息。我们只会在达成本政策所述目的所需的期限内保留您的个人信息,除非法律有强制的存留要求。而我们判断前述期限的标准包括:
- 保证我们为您提供服务的安全和质量;
- 您是否同意更长的留存期间;
- 是否存在保留期限的其他特别约定。
-
互联网并非绝对安全的环境,在使用“CoFrame”的服务时,我们强烈建议您不要使用非“CoFrame”推荐的通信方式发送您的信息。您可以通过我们的服务建立联系和相互分享。当您通过我们的服务创建交流、交易或分享时,您可以自主选择沟通或分享的对象,作为能够看到您的联络方式、交流信息或分享内容相关信息的第三方。
请注意,您在使用我们服务时自愿共享甚至公开分享的信息,可能会涉及您或他人的个人信息甚至个人敏感信息。请您更加谨慎地考虑,是否在使用我们的服务时共享甚至公开分享相关信息。
请使用复杂密码,协助我们保证您的帐号安全。我们将尽力保障您发送给我们的任何信息的安全性。如果由于我们的原因,导致“CoFrame”物理、技术或管理防护设施遭到破坏,导致信息被非授权访问、公开披露、篡改或毁坏,导致您的合法权益受损,我们将依法承担相应责任;非因我方原因造成您个人数据的泄漏、篡改或毁坏,导致您的合法权益受损,由相关责任方承担法律责任。 - 我们将不定期更新并公开安全风险、个人信息安全影响评估报告有关内容,您可通过我们的公告方式获得。
- 在不幸发生个人信息安全事件后,我们将按照法律法规的要求向您告知:安全事件的基本情况和可能的影响、我们已采取或将要采取的处置措施、您可自主防范和降低风险的建议、对您的补救措施。事件相关情况我们将以邮件、信函、电话、推送通知方式告知您,难以逐一告知个人信息主体时,我们会采取合理、有效的方式发布公告。
-
我们会在符合法律法规要求,以及实现信息收集目的的必要期限内,保存上述收集的您的个人信息。超过上述期限后,我们将不会再保留个人信息或对个人信息进行匿名化。
数据存储地点:我们在本产品和服务中所收集和产生的个人信息,将存储在中华人民共和国境内。
数据存储期限:我们仅为实现上述目的所需要的时间来保留您的个人信息,并在超出保留时间后删除或匿名化处理您的个人信息,但法律法规另有要求的除外。您的个人数据的存储期限至少 6 个月。
同时,我们还将按照监管部门要求,上报个人信息安全事件的处置情况。
五、您如何管理您的个人信息
您可以通过以下方式访问及管理您的个人信息:
(一)访问您的个人信息
-
您有权访问您的个人信息,法律法规规定的例外情况除外。您可以通过以下方式自行访问您的个人信息:
帐户信息——如果您希望访问或编辑您的帐户中的个人基本资料信息,您可以通过登录您的帐号执行此类操作。
清除缓存——您可以通过设置清除缓存记录。 - 如果您无法通过上述路径访问您的个人信息,您可以随时通过“CoFrame”提供的意见反馈与我们取得联系。我们将在 15 天内回复您的访问请求。
- 对于您在使用我们的产品或服务过程中产生的其他个人信息,我们将根据“(八)响应您的上述请求”向您提供相关安排。
(二)更正您的个人信息
当您发现我们处理的关于您的个人信息有错误时,您有权要求我们做出更正或补充。您可以通过“(一)访问您的个人信息”中列明的方式提出更正或补充申请。
如果您无法通过上述链接更正这些个人信息,您可以随时使用我们的意见反馈表单联系,或者发送电子邮件给我们。我们将在 30 天内回复您的更正请求。
(三)删除您的个人信息
- 您可以通过“(一)访问您的个人信息”中列明的方式删除您的部分个人信息。
-
在以下情形中,您可以向我们提出删除个人信息的请求:
- 如果我们处理个人信息的行为违反法律法规;
- 如果我们收集、使用您的个人信息,却未征得您的明确同意;
- 如果我们处理个人信息的行为严重违反了与您的约定;
- 如果您不再使用我们的产品或服务,或您主动注销了帐号;
- 如果我们永久不再为您提供产品或服务;
- 如果您注销了智能相框设备或不再使用智能相框配网功能,您可以向我们提出删除相关 Wi-Fi 信息(SSID、BSSID、MAC地址)及设备标识信息(ANDROID ID)的请求。
- 若我们决定响应您的删除请求,我们还将同时尽可能通知从我们处获得您的个人信息的主体,要求其及时删除,除非法律法规另有规定,或这些主体获得您的独立授权。
- 当您从我们的服务中删除信息后,我们可能不会立即从备份系统中删除相应的信息,但会在备份更新时删除这些信息。
(四)获取个人信息副本
您有权获取您的个人信息副本,您可以通过第十条列出的联系方式向我们提出获取个人信息副本的需求。在技术可行的前提下,如数据接口已匹配,我们还可按您的要求,直接将您的个人信息副本传输给您指定的第三方。
(五)改变您授权同意的范围
每个业务功能需要一些基本的个人信息才能得以完成(见本隐私权政策“第二部分”)。除此之外,您可以通过解除绑定、修改个人设置、删除相关信息方式撤回部分授权,也可以通过关闭功能的方式撤销部分授权。
当您收回同意后,我们将不再处理相应的个人信息。但您收回同意的决定,不会影响此前基于您的授权而开展的个人信息处理。
(六)个人信息主体注销账户
- 您可以自行在“个人信息”页面提交账户注销申请。
- 在您主动注销账户之后,我们将停止为您提供产品或服务,根据适用法律的要求删除您的个人信息,或使其匿名化处理。
(七)约束信息系统自动决策
在某些业务功能中,我们可能仅依据信息系统、算法在内的非人工自动决策机制做出决定。如果这些决定显著影响您的合法权益,您有权要求我们做出解释,我们也将在不侵害本产品商业秘密或其他用户权益、社会公共利益的前提下提供申诉方法。
(八)响应您的上述请求
- 为保障安全,您可能需要提供书面请求,或以其他方式证明您的身份。我们可能会先要求您验证自己的身份,然后再处理您的请求。
- 一般来说,我们将在 15 天内做出答复,特殊情形下最长将在不超过三十天或法律法规规定期限内作出答复。
- 对于您合理的请求,我们原则上不收取费用,但对多次重复、超出合理限度的请求,我们将视情收取一定成本费用。对于那些无端重复、需要过多技术手段(需要开发新系统或从根本上改变现行惯例)、给他人合法权益带来风险或者非常不切实际的请求,我们可能会予以拒绝。
-
在以下情形中,按照法律法规要求,我们将无法响应您的请求:
- 与国家安全、国防安全有关的;
- 与公共安全、公共卫生、重大公共利益有关的;
- 与犯罪侦查、起诉、审判和执行判决有关的;
- 有充分证据表明个人信息主体存在主观恶意或滥用权利的;
- 响应您的请求将导致您或其他个人、组织的合法权益受到严重损害的;
- 涉及商业秘密的。
六、对第三方责任声明
如您访问通过“CoFrame”接入的第三方服务或程序时,第三方可能会有自己的隐私权保护政策。当您查看第三方开发的应用程序时,这些第三方程序可能会放置他们自己的 Cookie 或网络 Beacon,这些 Cookie 或网络 Beacon 不受我们控制,且它们的使用不受本隐私政策的约束。我们会努力要求这些主体对您个人信息采取保护措施,建议您与他们联系以获得关于他们隐私政策的详细情况。如您发现第三方开发的应用程序存在风险,建议您终止相关操作。
七、我们如何处理儿童的个人信息
我们的产品、网站和服务主要面向成年人。如果没有父母或监护人的同意,儿童不得创建自己的用户帐户。如您为儿童,我们要求您请您的监护人仔细阅读本隐私权政策,并在征得您的监护人同意的前提下使用我们的服务或向我们提供信息。
对于经监护人同意使用我们的产品或服务而收集儿童个人信息的情况,我们只会在法律法规允许、监护人明确同意或者保护儿童所必要的情况下使用、共享、转让或披露此信息。
如果我们发现自己在未事先获得可证实的父母同意的情况下收集了儿童的个人信息,则会设法尽快删除相关数据。
八、您的个人信息如何在全球范围转移
我们在中华人民共和国境内运营中收集和产生的个人信息,存储在中国境内,以下情形除外:
- 法律法规有明确规定;
- 获得您的明确授权。
针对以上情形,我们会确保依据本隐私权政策对您的个人信息提供足够的保护。存在出境情况的,将按照国家有关规定进行出境安全评估。
九、本隐私权政策如何更新
我们的隐私权政策可能变更,除法律法规或监管规定另有强制性规定外,经调整或变更的内容一经通知或公布后的 7 日后生效。如您在隐私权政策调整或变更后继续使用“CoFrame”提供的任一服务或访问相关网站或相关应用程序的,我们相信这代表您已充分阅读、理解并接受修改后的隐私权政策并受其约束。
- 未经您明确同意,我们不会限制您按照本隐私权政策所应享有的权利。我们会在专门页面上发布对隐私权政策所做的任何变更。
- 对于重大变更,我们还会提供更为显著的通知(向您提供弹窗提示)。
本政策所指的重大变更包括但不限于:
- 我们的服务模式发生重大变化。如处理个人信息的目的、处理的个人信息类型、个人信息的使用方式;
- 我们在控制权方面发生重大变化。如并购重组引起的所有者变更;
- 个人信息共享、转让或公开披露的主要对象发生变化;
- 您参与个人信息处理方面的权利及其行使方式发生重大变化;
- 我们负责处理个人信息安全的责任部门、联络方式及投诉渠道发生变化;
- 个人信息安全影响评估报告表明存在高风险。
深圳市同洲电子股份有限公司
CoFrame Privacy Policy
Important Notice
Your trust is very important to us. We understand the importance of personal information and will do our utmost to protect the security and reliability of your personal information. We are committed to maintaining your trust and adhere to the following principles when protecting your personal information: consistency of rights and responsibilities, clear purpose, choice and consent, minimization and necessity, security assurance, subject participation, and openness and transparency. We will also adopt appropriate security measures consistent with industry standards to protect your personal information. Accordingly, the “CoFrame” service provider (or “we,” “us,” or “our”) has formulated this Privacy Policy (the “Policy” or “Privacy Policy”) and reminds you that:
This Policy applies to all products and services provided by “CoFrame,” including but not limited to applications on computers, mobile smart terminals, and in-vehicle devices, webpages, software development kits (SDKs) and application programming interfaces (APIs) for third-party websites and applications, as well as products and services developed through continuous innovation. If a particular service provided by “CoFrame” has its own separate privacy policy, that policy together with this Privacy Policy constitutes a complete privacy policy for that service.
Please note that this Policy does not apply to services provided to you by other third parties. To ensure a smooth product experience, you may receive content or links from third parties. Please carefully consider whether to visit third-party links, content, products, or services. Before submitting personal information to a third party, please carefully read that third party’s privacy policy.
Before using any of our products or services, please carefully read and fully understand this Policy—especially terms marked in bold or bold underline. Please confirm that you fully understand and agree before you begin using our services. If you have any questions, comments, or suggestions regarding this Policy, you may contact us through the contact methods provided by “CoFrame.”
Part I — Definitions
“CoFrame”: means the “CoFrame” mobile application.
“CoFrame” service provider: means the legal entity that develops and provides the “CoFrame” app, namely Coship Electronics Co.,Ltd.
Child: means a minor under the age of fourteen (14).
Personal information: means various information recorded electronically or by other means that, alone or in combination with other information, can identify a specific natural person or reflect the activities of a specific natural person.
Sensitive personal information: means personal private information including facial information, identity document numbers, biometric information, bank account numbers, property information, location tracking information, transaction information, and children’s information (we will prominently mark specific sensitive personal information in bold in this Privacy Policy). Deletion of personal information: means removing personal information from systems involved in day-to-day business functions so that it can no longer be retrieved or accessed.
Part II — Privacy Policy
This Privacy Policy will help you understand the following:
- How We Collect and Use Your Personal Information
- How We Use Cookies and Similar Technologies
- How We Entrust Processing of, Share, Transfer, and Publicly Disclose Your Personal Information
- How We Protect Your Personal Information
- How You Can Manage Your Personal Information
- Disclaimer Regarding Third Parties
- How We Handle Children’s Personal Information
- How Your Personal Information Is Transferred Globally
- How This Privacy Policy Is Updated
I. How We Collect and Use Your Information
You understand and agree that:
- We strive to create diverse products and services to meet your needs. Because we offer many types of products and services, and different users choose different product/service scopes, the types and scope of personal information collected and used for various features may differ. Please refer to the specific product/service features.
- To provide a better product and service experience, we continuously improve our technology and may from time to time launch new or optimized features, which may require collecting or using new personal information or changing the purpose or manner of use. We will separately explain the purpose, scope, and manner of such collection through updates to this Policy, pop-ups, or on-page notices, provide you with a way to choose whether to consent, and collect and use such information only after obtaining your express consent.
(1) Helping You Become Our User
1. Registration and Login
To help you become our user and to provide user services, you need to provide a mobile phone number, create an account password (or verification code), and a nickname to become a registered user. When you register for or log in to our services, we collect your unique device identifier (ANDROID ID) to identify you as our user.
2. Profile Completion
You may choose to further complete your account information, such as birthday and gender. If you do not provide this information, it will not affect your use of the basic services of this product.
(2) Providing Browsing Services
1. Query and Search Features. When you use our local news, lifestyle services, and tip-off services, in order to detect abnormal account status, understand product compatibility, provide content displays and search results that better match your needs, and support basic operations such as file caching, downloads, and log storage, we need read/write access to public storage areas and network access, and may automatically collect your usage information and store it as network log information, including:
Device information: Based on your specific actions during installation and/or use of the software, we receive and record device-related information (including device model, device serial number, operating system version, device settings, unique device identifier (ANDROID ID), software/hardware characteristic information of the device environment, and MAC address), location-related information of the device (including GPS location authorized by you, as well as WLAN access points, Bluetooth, and base-station sensor information), device status information (obtaining Wi-Fi status; obtaining/modifying Wi-Fi status), and current Wi-Fi network identifiers (SSID, BSSID, MAC address).
Service log information: When you use our products or services, we automatically collect detailed usage information as service logs, including browsing, click-to-view, search queries, favorites, following and sharing information, and published information, as well as browser type, telecom carrier, language used, and access date and time.
Smart photo frame network provisioning. When you use the “CoFrame” app to add a smart photo frame device, in order to complete network provisioning, we need to request Wi-Fi and location permissions and obtain current Wi-Fi information (including SSID, BSSID, and MAC address) through system APIs, as well as your unique device identifier (ANDROID ID) to identify the provisioning device. If you refuse to provide the above information, you will be unable to use smart photo frame network provisioning, but this will not affect your normal use of other features.
Specific disclosure regarding collection of BSSID, MAC address, and SSID: To complete smart photo frame Wi-Fi provisioning, local-network device discovery, connection verification, and provisioning security, we collect the following device network identifiers after you authorize us:
- SSID: the name of the Wi-Fi network you are connected to or select. Purpose: to connect the smart photo frame to the wireless network you specify. Method: read current Wi-Fi information through system APIs (such as WifiManager) when you use the provisioning feature.
- BSSID: the identifier of the Wi-Fi access point you are currently connected to. Purpose: to identify and match the target wireless network and avoid connecting to the wrong network. Method: same as above; used only for provisioning and connection verification.
- MAC address: including the Wi-Fi MAC address and Bluetooth MAC address of your phone, as well as MAC addresses related to the photo frame device/router. Purpose: device identification, local-network discovery, provisioning verification, and connection status confirmation. Method: obtained through system APIs when you use provisioning or device management. We will not use MAC addresses for precise location tracking, nor sell them to third parties.
The above BSSID, MAC address, and SSID are used only for smart photo frame provisioning, device binding, and connection status display, and will not be used for unrelated profiling or advertising. You may refuse to provide them; refusal will prevent provisioning and local-network discovery, but will not affect other features such as browsing. You may also turn off related location/Wi-Fi permissions in system settings, or request deletion under Section V of this Policy.
Please note that device information or service log information alone cannot identify a specific natural person. If we combine such non-personal information with other information to identify a specific natural person, or use it together with personal information, then during such combined use it will be treated as personal information. Except where we have obtained your authorization or where laws and regulations provide otherwise, we will anonymize and de-identify such information.
2. Calling third-party application features. We will obtain camera permission on your phone to help you log in to the web product by scanning a webpage QR code with your logged-in mobile device.
3. When the app enters the background, we will obtain the list of running processes and applications to provide a security reminder when you leave the app.
In addition, we may use the above information to continuously improve and optimize the above features.
The above information we collect and use has been de-identified. Data analysis corresponds only to specific codes that cannot be directly linked to your identity and will not be associated with your real identity.
(3) Providing Information Publishing and Interaction Services
1. Content Upload and Publishing
- When you use content commenting or reply features, we will collect the information content you choose to publish and display your nickname, avatar, and published content (text/images, audio/video).
- When you upload images or audio/video, we will request camera, microphone, and photo album permissions. Only after you expressly agree will we allow recording or photo-taking within the scope of your consent. If your phone uses an SD card, to read the album we may also request permission to read data on the SD card and to modify/delete data on the SD card. If you refuse, you will be unable to use this feature, but this will not affect your normal use of other features.
- When you publish information and choose to display your location, we will request location permission, obtain geographic location, and collect location information related to this service. If you refuse to provide precise location information, you will be unable to use this feature, but this will not affect your normal use of other features.
- Please note that information you publicly post may involve your or others’ personal information or even sensitive personal information, such as images containing personal information. Please carefully consider whether to share or publicly disclose such information when using our services. If publicly posted information involves a child’s personal information, you must obtain authorization from the child’s guardian before posting.
- Smart photo frame device management. When you manage smart photo frame devices in the “CoFrame” app, we will request location permission and obtain geographic location information for smart photo frame positioning and device matching. If you refuse to provide precise location information, you will be unable to use smart photo frame device positioning, but this will not affect your normal use of other features.
2. Interaction
When you interact with content or topics of interest (favorites, likes, comments, or shares), we collect the accounts you favorite and show you content published by accounts you follow. When you share information to third-party platforms such as Weibo or WeChat, we collect your software list to determine whether WeChat, Weibo, or other social apps are installed. When you participate in quizzes, we collect and display your answer data.
3. Message Notifications
To provide emergency broadcasts and message notification services, we request system notification permission for system and user message alerts. If you refuse, you will not receive our message notifications, but this will not affect your normal use of other features.
To improve message delivery rates and provide timely reminders, we enable associated/startup-related features by default to keep the app active. If you do not want this feature, we recommend turning it off manually. Typical path: Settings → Apps → App launch management → select “CoFrame” → turn off associated startup.
(4) Providing Security Assurance
To prevent, detect, and investigate fraud, threats to account security, or other violations of agreements with us, or to fulfill the purpose of your access, we will collect your network information, device information, phone model, hardware information, and system information. To better prevent network vulnerabilities, computer viruses, network attacks, and intrusion risks, and to more accurately identify violations of laws, regulations, or our related agreement rules, we may use or combine your membership information, device information, service log information, and information that our partners have obtained with your authorization or shared according to law, to comprehensively assess account and transaction risks, perform identity verification, detect and prevent security incidents, and take necessary recording, auditing, analysis, and handling measures as required by law. To implement security verification for smart photo frame network provisioning and device management, prevent fraud, and protect your device and account security, we collect your Wi-Fi information (SSID, BSSID, MAC address), device identifier (ANDROID ID), device model, and system information for provisioning identity verification, anomaly detection, and security risk prevention.
To enable necessary features such as receiving push notifications, sharing information on third-party platforms, and using voice broadcast services, our application embeds SDKs or similar applications from authorized partners. The third-party software development kits (SDKs) we integrate are as follows:
WeChat Open Platform
Purpose: Share content to WeChat messages or Moments
Types of personal information collected: Device identifiers, network information
Official website: https://open.weixin.qq.com/
We conduct strict security assessments of the APIs and SDKs through which authorized partners obtain information, and agree with them on strict data protection measures so that they process personal information in accordance with our entrusted purposes, service descriptions, this Privacy Policy, and any other relevant confidentiality and security measures.
(5) Other
- If the information you provide contains another user’s personal information, you must ensure that you have obtained lawful authorization before providing such personal information to us.
- If we use information for purposes not stated in this Policy, use information collected for a specific purpose for other purposes, or actively obtain your personal information from third parties, we will obtain your consent in advance.
If we obtain your information indirectly from a third party, we will, before collection, clearly require in writing that the third party has collected the personal information after lawfully obtaining your consent, and inform you of the shared information content. Where sensitive information is involved, your explicit confirmation is required before it is provided to us. We require the third party to commit to the legality and compliance of the personal information source; if the third party violates this, we will clearly require it to bear corresponding legal liability. At the same time, our professional security team will strengthen the security of personal information (including reporting of sensitive information, encrypted storage of sensitive information, and access control). We will protect indirectly obtained personal information with means and measures no less protective than those we apply to our own users’ personal information.
3. Exceptions to Obtaining Authorization and Consent
You fully understand and agree that in the following circumstances we may collect and use your personal information without your authorization and consent, and we may not respond to your requests for correction/modification, deletion, account cancellation, withdrawal of consent, or access to information:
- Related to national security or national defense security;
- Related to public security, public health, or major public interests;
- Related to criminal investigation, prosecution, trial, and enforcement of judgments, or administrative law enforcement;
- Necessary to protect your or another individual’s major lawful rights and interests in life or property, where it is difficult to obtain the individual’s consent;
- Personal information that you have disclosed to the public yourself;
- Personal information collected from lawfully publicly disclosed information, such as lawful news reports or government information disclosure channels;
- Necessary for entering into and performing relevant agreements or other written documents with you;
- Necessary to maintain the secure and stable operation of the products and/or services provided, including detecting and handling faults in products and/or services;
- Necessary for lawful news reporting;
- Necessary for academic research institutions to conduct statistics or academic research in the public interest, where personal information contained in results provided externally is de-identified;
- Other circumstances provided by laws and regulations;
- Necessary to achieve smart device network provisioning, where this has been clearly stated in the privacy policy and your consent has been obtained.
Please note that under applicable law, if we process personal information with technical and other necessary measures so that the data recipient cannot re-identify a specific individual and cannot restore the data, or if we may conduct de-identified research, statistical analysis, and prediction on collected information to improve our content and layout, support commercial decisions regarding products or services, and improve our products and services (including using anonymous data for machine learning or model algorithm training), then use of such processed data does not require separate notice to or consent from you.
4. If we cease operating our products or services, we will promptly stop further collection of your personal information, notify you of the cessation by individual delivery or announcement, and delete or anonymize personal information we hold that is related to the discontinued business.
(6) Facial Data Processing
1. Facial Data We Collect
When you use AI-based facial features in the “CoFrame” app (including but not limited to face detection, face analysis, face recognition, portrait processing, and AI effect generation), we need to collect facial information in facial images, photos, or videos that you actively upload. Specifically, facial data collected includes:
- Facial images/photos: Images containing faces that you capture with the camera or upload from your album;
- Facial feature information: Mathematical representations such as facial feature points and facial contours extracted from facial images via AI algorithms;
- Face recognition results: Related result data generated after algorithmic processing, such as face detection, face analysis, and face verification.
Please note in particular: facial information is sensitive personal information. Under the Personal Information Protection Law of the People’s Republic of China and relevant rules on the security of facial recognition technology applications, facial information is sensitive personal information, and we will obtain your separate consent before processing it.
2. Purposes of Using Facial Data
We collect and use your facial data only for the following clear purposes:
- AI feature services: To provide face detection, face analysis, face recognition, AI filters, AI effect generation, and other features, and to deliver the specific image processing, style transfer, beautification, and similar services you request;
- Identity verification: In scenarios requiring real-name authentication or identity verification, to verify the operator’s identity through face comparison;
- Service optimization: On the premise that your personal identity is not identified, after anonymizing and de-identifying facial data, to improve and optimize our AI algorithms and models and enhance feature accuracy and user experience.
We undertake not to use your facial data for purposes not stated in this Policy. If use for other purposes is truly necessary, we will separately inform you and obtain your explicit consent again.
3. Sharing and Storage of Facial Data
(1) Sharing
We undertake not to share your facial data with any third party other than the “CoFrame” service provider, except in the following cases:
- Third-party AI service providers: If a facial feature you use requires processing by a third-party AI service provider (such as an AI model service provider), we will clearly notify you via a pop-up before you use the feature of the data recipient, data types, and purposes, and only after obtaining your separate consent will we transmit your facial images/photos in encrypted form to that third-party provider for processing. The third-party provider may access and process the data only to the extent necessary to complete the specific feature you requested, and may not use the data for any other purpose.
- Legal requirements: As required by laws and regulations, litigation, or dispute resolution, or pursuant to lawful requests by administrative or judicial authorities, we may need to share your relevant information externally.
(2) Storage
- Storage location: Your facial data will be stored within the People’s Republic of China. If use of third-party AI services involves cross-border data transfer, we will conduct outbound security assessments in accordance with relevant national regulations and ensure compliance with applicable laws and regulations.
- Storage method: We use industry-leading encryption technologies to store your facial data and apply strict access control mechanisms so that only authorized personnel may access it when necessary.
4. Retention Period for Facial Data
We retain your facial data only for the shortest period necessary to achieve the purposes stated in this Policy, as follows:
- Real-time processing scenarios: For facial images used only for one-time AI effect generation, we delete them immediately after processing and do not retain them on the server;
- Scenarios requiring retention: If facial feature information must be retained for identity verification, account security, or similar needs, we will retain it during your use of the relevant services and delete it promptly after you cancel your account or withdraw consent;
- Where laws and regulations provide otherwise, those provisions shall prevail.
After the above retention periods expire, we will delete your facial data or anonymize it as required by applicable law.
5. Your Rights
You have the following rights regarding facial data:
- Right to be informed: You have the right to know the details of how we collect, use, and share your facial data;
- Right of consent: You may withdraw your consent to facial data processing at any time; after withdrawal, we will stop processing the relevant data;
- Right to deletion: You may request that we delete your facial data through the methods listed in “V. How You Can Manage Your Personal Information”;
- Right to refuse: You may refuse to provide facial data; refusal will affect only related AI features and will not affect your use of other basic services of this product.
6. Exceptions to Obtaining Authorization and Consent
You fully understand and agree that in the following circumstances we may process facial data without prior authorization and consent:
- Directly related to national security or national defense security;
- Directly related to public security, public health, or major public interests;
- Directly related to criminal investigation, prosecution, trial, and enforcement of judgments;
- Necessary to protect your or another individual’s major lawful rights and interests in life or property, where it is difficult to obtain the individual’s consent;
- Facial information that you have disclosed to the public yourself;
- Facial information collected from lawfully publicly disclosed information.
7. Protection of Minors’ Facial Data
If you are a child (a minor under fourteen), you must obtain clear consent from your guardian before using facial features. We will not collect a child’s facial data without guardian consent. If we discover that a child’s facial data has been collected without guardian consent, we will delete the relevant data as soon as possible.
II. How We Use Cookies and Similar Technologies
(1) Cookies
To ensure the normal operation of the “CoFrame” platform and to provide you with a smoother access experience, we store Cookies, Flash Cookies, or other local storage generally containing identifiers, site names, and some numbers and characters provided by the browser (or associated applications) on your computer or mobile device (collectively, “Cookies”). With Cookies, this platform can store your preference data.
If your additional services allow, you may modify the extent to which you accept Cookies or refuse our Cookies. For details, see AboutCookies.org. However, if you do so, you may be unable to enjoy a better service experience, and in some cases this may affect your secure access to our website, and you may need to change user settings each time you visit our platform. If your personal modifications cause leakage of personal data or related other users’ data, you shall bear full legal liability.
(2) Cookie-like Technologies
In addition to Cookies, we also use web beacons, pixel tags, ETags, and other similar technologies.
Emails we send you may contain links to content on our website. If you click such a link, we will track the click to help us understand your product or service preferences so that we can proactively improve customer service. A web beacon is usually a transparent image embedded in a website or email. With pixel tags in emails, we can learn whether an email has been opened. If you do not wish your activity to be tracked in this way, you may unsubscribe from our mailing list at any time.
An ETag (entity tag) is an HTTP protocol header transmitted behind the scenes between an Internet browser and an Internet server and can replace Cookies. ETags can help us avoid unnecessary server load, improve service efficiency, and save resources and energy. We may also use ETags to record your identity so that we can better understand and improve our products or services. Most browsers provide a function to clear browser cache data; you may perform corresponding data clearing operations in browser settings. Please note that if you disable ETags, you may be unable to enjoy a relatively better product or service experience; any resulting loss of personal data shall be borne by the individual.
III. How We Entrust Processing of, Share, Transfer, and Publicly Disclose Your Personal Information
(1) Entrusted Processing
Certain specific modules or features of this business function are provided by external suppliers. For example, we may engage service providers to assist us in providing customer support.
For companies, organizations, and individuals entrusted to process personal information, we will sign strict confidentiality agreements requiring them to process personal information in accordance with our requirements, this personal information protection policy, and any other relevant confidentiality and security measures.
(1) Sharing
We will not share your personal information with companies, organizations, or individuals other than the “CoFrame” service provider, except in the following cases:
- Sharing under statutory circumstances: We may share your personal information externally as required by laws and regulations, litigation, or dispute resolution, or pursuant to lawful requests by administrative or judicial authorities.
- Sharing with your explicit consent: After obtaining your explicit consent, we will share your personal information with other parties.
- Sharing with authorized partners: Smart device service providers. We may entrust smart device service providers to provide network provisioning, management, and other services for smart photo frames. We will share your Wi-Fi information (SSID, BSSID, MAC address) and device identifier (ANDROID ID) only for the lawful, legitimate, necessary, specific, and clear purposes stated in this Privacy Policy. Authorized partners may access only the information needed to perform their duties and may not use such information for any other purpose.
Currently, our authorized partners include the following types:
- Authorized partners for content analysis services. Content in “CoFrame” may be provided by our partners, or jointly by us and software service providers, smart device providers, or system service providers (collectively, “service providers”). Unless permitted by you, we will not share your personally identifiable information with partners that provide content or analysis services. We may entrust these partners to process information related to content coverage and effectiveness, but will not provide your personally identifiable information. We will share de-identified personal information with these service providers to form indirect audience profiles based on comprehensive statistics and algorithmic feature and preference analysis, without identifying you personally. Such partners may combine the above information with other data they lawfully obtain to perform the content services or decision recommendations we entrust.
- Suppliers, service providers, and other partners. We send information to suppliers, service providers, and other partners that support our business, including technical infrastructure services entrusted by us, analysis of how our services are used, measurement of advertising and service effectiveness, customer service, and payment facilitation.
- AI service providers. If you use AI-related features such as face detection, face analysis, or AI effect generation, we may, after obtaining your separate consent, transmit your facial images/photos in encrypted form to third-party AI service providers for processing. We will share only the necessary facial data for the specific feature you requested, and require partners to process the data strictly in accordance with our entrusted purposes, service descriptions, this Privacy Policy, and relevant confidentiality and security measures, and not to use the data for any other purpose or retain it.
We conduct strict security assessments of the APIs and SDKs through which authorized partners obtain information, and agree with them on strict data protection measures so that they process personal information in accordance with our entrusted purposes, service descriptions, this Privacy Policy, and any other relevant confidentiality and security measures.
(2) Transfer
We will not transfer your personal information to any company, organization, or individual, except in the following cases:
- Transfer with explicit consent: After obtaining your explicit consent, we will transfer your personal information to other parties;
- In the event of merger, acquisition, or bankruptcy liquidation of this product’s service provider, or other circumstances involving merger, acquisition, or bankruptcy liquidation, if personal information transfer is involved, we will require the new company or organization that holds your personal information to continue to be bound by this Policy; otherwise, we will require that company, organization, or individual to seek your authorization and consent again.
(3) Public Disclosure
We will publicly disclose your personal information only in the following circumstances:
- With your explicit consent or based on your active choice, we may publicly disclose your personal information;
- If we determine that you have violated laws and regulations or seriously violated the relevant agreement rules of this product, or to protect the personal and property safety of users of this product and its affiliates or the public from infringement, we may disclose personal information about you in accordance with laws and regulations or the relevant agreement rules of this product, including related violations and measures this product has taken against you.
(4) Exceptions to Prior Authorization and Consent for Sharing, Transfer, and Public Disclosure
In the following circumstances, sharing, transferring, or publicly disclosing your personal information does not require your prior authorization and consent:
- Related to national security or national defense security;
- Related to public security, public health, or major public interests;
- Related to criminal investigation, prosecution, trial, and enforcement of judgments;
- Necessary to protect your or another individual’s major lawful rights and interests in life or property, where it is difficult to obtain the individual’s consent;
- Personal information that you have disclosed to the public yourself;
- Personal information collected from lawfully publicly disclosed information, such as lawful news reports or government information disclosure channels.
According to law, sharing or transferring personal information that has been de-identified, where it is ensured that the data recipient cannot restore and re-identify the personal information subject, does not constitute external sharing, transfer, or public disclosure of personal information, and retention and processing of such data does not require separate notice to or consent from you.
IV. How We Protect the Security of Your Personal Information
- We have adopted industry-standard, reasonably practicable security measures to protect your information and prevent unauthorized access, public disclosure, use, modification, damage, or loss of personal information. Data exchanged between your client and the server is encrypted and protected by the SSL protocol; we use encryption technologies to improve the security of personal information; we use trusted protection mechanisms to prevent malicious attacks on personal information; we deploy access control mechanisms to try to ensure that only authorized personnel can access personal information; and we conduct security and privacy protection training to strengthen employees’ awareness of the importance of protecting personal information.
- We have an industry-advanced data security management system centered on data and covering the data lifecycle, improving overall system security from multiple dimensions including organizational structure, institutional design, personnel management, and product technology.
-
We will take reasonably practicable measures to avoid collecting irrelevant personal information. We will retain your personal information only for the period necessary to achieve the purposes stated in this Policy, unless the law mandates a retention period. Criteria we use to determine such period include:
- Ensuring the security and quality of services we provide to you;
- Whether you agree to a longer retention period;
- Whether there are other special agreements on the retention period.
-
The Internet is not an absolutely secure environment. When using “CoFrame” services, we strongly recommend that you do not send your information using communication methods not recommended by “CoFrame.” You may establish contacts and share through our services. When you communicate, transact, or share through our services, you may independently choose the counterparties who can see your contact details, communication information, or shared content.
Please note that information you voluntarily share or even publicly disclose when using our services may involve your or others’ personal information or even sensitive personal information. Please carefully consider whether to share or publicly disclose such information when using our services.
Please use a complex password to help us keep your account secure. We will do our best to safeguard the security of any information you send to us. If, due to our reasons, the physical, technical, or managerial safeguards of “CoFrame” are compromised, resulting in unauthorized access, public disclosure, alteration, or destruction of information and damage to your lawful rights and interests, we will bear corresponding liability in accordance with the law. If leakage, alteration, or destruction of your personal data not caused by us results in damage to your lawful rights and interests, the relevant responsible party shall bear legal liability. - We will irregularly update and publicly disclose content related to security risks and personal information security impact assessment reports, which you may obtain through our announcements.
- In the unfortunate event of a personal information security incident, we will, as required by laws and regulations, inform you of: the basic situation of the security incident and its possible impact; the handling measures we have taken or will take; suggestions for you to independently prevent and reduce risks; and remedial measures for you. We will notify you of incident-related information by email, letter, phone, or push notification. Where it is difficult to notify personal information subjects individually, we will issue an announcement in a reasonable and effective manner.
-
We will retain the personal information collected above for the period necessary to achieve the purpose of collection and as required by laws and regulations. After that period, we will no longer retain the personal information or will anonymize it.
Data storage location: Personal information collected and generated in this product and service will be stored within the People’s Republic of China.
Data retention period: We retain your personal information only for the time needed to achieve the above purposes, and delete or anonymize it after the retention period, except where laws and regulations provide otherwise. Your personal data will be stored for at least 6 months.
We will also report the handling of personal information security incidents as required by regulatory authorities.
V. How You Can Manage Your Personal Information
You may access and manage your personal information in the following ways:
(1) Access Your Personal Information
-
You have the right to access your personal information, except where laws and regulations provide otherwise. You may access your personal information yourself as follows:
Account information — If you wish to access or edit basic personal profile information in your account, you may do so by logging into your account.
Clear cache — You may clear cache records through Settings. - If you cannot access your personal information through the above paths, you may contact us at any time through the feedback channels provided by “CoFrame.” We will respond to your access request within 15 days.
- For other personal information generated in the course of using our products or services, we will provide relevant arrangements according to “(8) Responding to Your Above Requests.”
(2) Correct Your Personal Information
When you find that personal information we process about you is incorrect, you have the right to request that we correct or supplement it. You may submit a correction or supplementation request through the methods listed in “(1) Access Your Personal Information.”
If you cannot correct such personal information through the above links, you may contact us at any time using our feedback form or by sending us an email. We will respond to your correction request within 30 days.
(3) Delete Your Personal Information
- You may delete some of your personal information through the methods listed in “(1) Access Your Personal Information.”
-
In the following circumstances, you may request that we delete personal information:
- If our processing of personal information violates laws and regulations;
- If we collect or use your personal information without obtaining your explicit consent;
- If our processing of personal information seriously violates our agreement with you;
- If you no longer use our products or services, or you actively cancel your account;
- If we permanently cease providing products or services to you;
- If you deregister a smart photo frame device or no longer use smart photo frame network provisioning, you may request that we delete related Wi-Fi information (SSID, BSSID, MAC address) and device identifier information (ANDROID ID).
- If we decide to respond to your deletion request, we will also, to the extent possible, notify entities that obtained your personal information from us and require them to delete it promptly, unless laws and regulations provide otherwise or those entities have obtained independent authorization from you.
- After you delete information from our services, we may not immediately delete the corresponding information from backup systems, but will delete such information when backups are updated.
(4) Obtain a Copy of Personal Information
You have the right to obtain a copy of your personal information. You may request a copy through the contact methods listed in Section X. Where technically feasible and if data interfaces are matched, we may also, at your request, directly transmit a copy of your personal information to a third party designated by you.
(5) Change the Scope of Your Authorized Consent
Each business feature requires some basic personal information to be completed (see “Part II” of this Privacy Policy). In addition, you may withdraw some authorizations by unbinding, modifying personal settings, or deleting relevant information, or revoke some authorizations by turning off features.
After you withdraw consent, we will no longer process the corresponding personal information. However, your decision to withdraw consent will not affect personal information processing previously conducted based on your authorization.
(6) Account Cancellation by the Personal Information Subject
- You may submit an account cancellation request yourself on the “Personal Information” page.
- After you actively cancel your account, we will stop providing products or services to you and, as required by applicable law, delete your personal information or anonymize it.
(7) Constraining Automated Decision-Making by Information Systems
In certain business features, we may make decisions solely based on non-human automated decision-making mechanisms including information systems and algorithms. If such decisions significantly affect your lawful rights and interests, you have the right to require us to explain, and we will also provide appeal methods on the premise that this product’s trade secrets or other users’ rights and interests or the public interest are not harmed.
(8) Responding to Your Above Requests
- To ensure security, you may need to provide a written request or otherwise prove your identity. We may first require you to verify your identity before processing your request.
- Generally, we will respond within 15 days; in special circumstances, we will respond within no more than thirty days or the period provided by laws and regulations.
- In principle, we do not charge fees for your reasonable requests, but for repeated requests beyond a reasonable extent, we may charge a certain cost fee as appropriate. We may refuse requests that are groundlessly repetitive, require excessive technical means (requiring development of new systems or fundamental changes to current practices), pose risks to others’ lawful rights and interests, or are highly impractical.
-
In the following circumstances, as required by laws and regulations, we will be unable to respond to your request:
- Related to national security or national defense security;
- Related to public security, public health, or major public interests;
- Related to criminal investigation, prosecution, trial, and enforcement of judgments;
- Where there is sufficient evidence that the personal information subject has subjective malice or is abusing rights;
- Where responding to your request would seriously harm the lawful rights and interests of you or other individuals or organizations;
- Involving trade secrets.
VI. Disclaimer Regarding Third Parties
When you access third-party services or programs integrated through “CoFrame,” those third parties may have their own privacy policies. When you view applications developed by third parties, those third-party programs may place their own Cookies or web beacons, which are not controlled by us and whose use is not governed by this Privacy Policy. We will endeavor to require these entities to take protective measures for your personal information, and we recommend that you contact them for details of their privacy policies. If you discover risks in applications developed by third parties, we recommend that you terminate the relevant operations.
VII. How We Handle Children’s Personal Information
Our products, websites, and services are primarily intended for adults. Without the consent of a parent or guardian, children may not create their own user accounts. If you are a child, we ask that you have your guardian carefully read this Privacy Policy and use our services or provide information to us only with your guardian’s consent.
For children’s personal information collected with a guardian’s consent for use of our products or services, we will use, share, transfer, or disclose such information only where permitted by laws and regulations, with the guardian’s explicit consent, or as necessary to protect the child.
If we discover that we have collected a child’s personal information without prior verifiable parental consent, we will seek to delete the relevant data as soon as possible.
VIII. How Your Personal Information Is Transferred Globally
Personal information collected and generated in our operations within the People’s Republic of China is stored in China, except in the following circumstances:
- Where laws and regulations expressly provide otherwise;
- Where we have obtained your explicit authorization.
In the above circumstances, we will ensure adequate protection of your personal information in accordance with this Privacy Policy. Where outbound transfer occurs, outbound security assessments will be conducted in accordance with relevant national regulations.
IX. How This Privacy Policy Is Updated
Our Privacy Policy may change. Except where laws, regulations, or regulatory requirements provide otherwise on a mandatory basis, adjusted or changed content takes effect 7 days after notice or publication. If you continue to use any service provided by “CoFrame” or visit related websites or applications after the Privacy Policy is adjusted or changed, we believe this represents that you have fully read, understood, and accepted the revised Privacy Policy and are bound by it.
- Without your explicit consent, we will not restrict the rights you should enjoy under this Privacy Policy. We will post any changes to the Privacy Policy on a dedicated page.
- For material changes, we will also provide more prominent notice (such as a pop-up prompt to you).
Material changes referred to in this Policy include but are not limited to:
- Significant changes in our service model, such as the purposes of processing personal information, types of personal information processed, or manners of using personal information;
- Significant changes in our control, such as owner changes due to mergers and reorganizations;
- Changes in the main recipients of personal information sharing, transfer, or public disclosure;
- Significant changes in your rights regarding personal information processing and how those rights are exercised;
- Changes in the department responsible for personal information security, contact methods, and complaint channels;
- A personal information security impact assessment report indicating high risk.
Coship Electronics Co.,Ltd