Privacy Policy for SUNBOOSTER GmbH

Update Date:
2024/06/27

Effective Date:2024/06/27

You are welcome to use our products and services!

The Privacy Policy (hereinafter referred to as the "Policy") applies to the services of SUNBOOSTER mobile application (hereinafter referred to as "service") provided by SUNBOOSTER GmbH (hereinafter referred to as "Sunbooster" or "we"). It aims to provide you with a comprehensive understanding of what data we collected, the purpose of the collection, how we utilize such data, and how we protect such data when you use our products and services.

Your trust is of the utmost importance to us, and we understand the significance of your personal data to you. Therefore, we will collect your personal data only to the extent necessary and required by law. We will make every effort to safeguard your data from leakage, destruction or loss using reasonable and effective information security technology and management processes, as well as appropriate security measures.

Please read this Policy carefully and thoroughly understand it before using our products and services, especially the bold and underlined terms. By agreeing to this Privacy Policy, you acknowledge that you are familiar with the features provided by the application and the necessary personal data required for its operation. Moreover, you authorize the collection and use of your personal data. If you have any questions about this Policy, please contact us as specified in Article 8. We do not provide products or services to minors. If you are under the legal age of majority of your country or region, please stop using the service or providing your personal data.

The Policy covers the following topics related to your personal data:

1. How we collect and use your personal data

2. How we share and disclose your personal data

3. How we store your personal data

4. How we protect your personal data

5. Your rights regarding your personal data

6. Cross-border transfer of personal data

7. How we protect personal data of minors

8. How to contact us

1. How We Collect and Use Your Personal Data

The legal basis for collecting and using your personal data will vary depending on the specific data and the context in which it is collected. Generally, we will only collect data with your consent, when necessary to fulfill our contractual obligations towards you, or where the processing is in our legitimate interests.

We rely on our legitimate interests to analyze, improve and optimize our application, products and services, and to maintain the security of our networks and systems; We base the processing of your data on our legitimate interests in operating and administering our application and to provide you with the content you access and request; we process your personal data by monitoring the use of our application/services, verifying accounts and activity, and analyzing suspicious activity for fraud prevention, to the extent this is necessary for our legitimate interest in promoting the safety and security of the technology systems use for our services, and in protecting our rights and the rights of others.

1.1 Personal data you need to provide

We will ask you to provide certain personal data necessary for the delivery of our services. Please note that if you choose not to provide the required personal data, we may be prevented from delivering our products or services.

1.1.1. When you register an account and log in to SUNBOOSTER, you need to provide us with your email address and corresponding login credentials for the purpose of verifying your identity in accordance.

1.2 Personal data you may choose to provide

To enhance your experience in controlling and managing smart devices provided by the platform, we may request your consent to collect and use your personal data for the following additional features. While basic services will remain accessible without your personal data, granting consent will enable you to access additional features, offering added convenience. The additional features include user feedback, device sharing, application and firmware upgrades.

1.2.1 When you provide feedback, we may collect the issues you reported to better understand the problems you encountered. In order to accurately identify and promptly help you resolve issues, you may use the "Upload Logs" feature to submit information including your access date and time, operation time, usage frequency, and overall usage. We will store the log you uploaded for 7 days. Please note that device information or logs alone cannot identify specific individuals. However, if such non-personal data is combined with other information that can be used to identify specific individuals, such information will be treated as personal data. Unless we obtain your consent or as otherwise required by data protection laws and regulations, we will aggregate or anonymize such information.

1.2.2 In order to provide you with more convenient services and better products, you need to complete your personal data, including your nickname and photo.

1.2.3 We support the linkage feature among smart devices by setting specific rules. We may collect the home location information and precise location information set in the geofence, rules set for smart scenes, sleep schedule settings, and specified device statuses to provide you with the linkage feature so that the App can execute the functions of the device according to the rules you set. Please rest assured that the linkage rule is effective only after you set rules and enable it voluntarily, and you may delete data at any time by removing the family or disabling the family mode.

1.3 Information collected automatically

To provide our products and services, we automatically collect certain data to ensure their proper functioning and performance.

1.3.1. Information collected when you use our services.

When you use the service, to ensure that you properly use our service and maintain the proper operation of our service, we may read the information related to your mobile device, including the device model, IP address, operating system version, and language used.

1.3.2. In order to provide you with the latest services, we may use your application version information and device model to offer you upgrade services. Additionally, we may collect the list of connected smart devices and their version information to provide you with device upgrade features, ensuring that you can use the latest version of services, including firmware versions. You can enable or disable upgrades at any time in the app's [Settings] – [Device Upgrade] section.

1.3.3 Information collected during the connection to a smart device. Based on the types of smart devices you need to connect to, we may collect:

1.3.3.1 We collect information about smart devices, including the name, model, ID, online status, activation time, IP address, device SN, device MAC address, SIM card information of the device, firmware version and upgrade information.

1.3.3.2 For the smart devices connected via Wi-Fi: In addition to the data as described in Article 1.3.3.1, we also collect Wi-Fi information (SSID, Wi-Fi password and MAC address of the Wi-Fi device).

1.3.3.3 For the smart devices connected via Wi-Fi after a local connection is established via Bluetooth: In addition to the data as described in Article 1.3.3.1, we also collect Wi-Fi information (SSID and Wi-Fi password) and device Bluetooth MAC address.

1.3.4. To provide you with notification push service, including sending notifications about software updates or fault alerts, and system notifications, we will collect Firebase Installation ID.

1.4. Request device permission

Please note that by granting any permission, you authorize us to collect and use relevant personal data to deliver corresponding services to you. If you choose to disable any permission and cancel your authorization, we will cease to collect and use the personal data based on the permission, and we will not be able to deliver the corresponding services to you. However, please note that disabling your permissions will not affect the data collection and use based on your previous authorization.

To help you effectively manage your information, we will inform you of the purpose of the permission when requesting permissions during the product usage process. Additionally, you can change the authorization settings at any time through the permissions settings page on your device or the "Settings" page in the SUNBOOSTER app.

The following are details of the relevant functions and permissions for reference.

1.4.1 Read and write external storage (Android): Used to read and write photos and files on the device in features such as scanning.

1.4.2 Read and write album storage (Android and iOS): Used to identify photos and save photos.

1.4.3 Location permission (Android and iOS): Used to identify the region, find nearby smart devices and the nearby WLAN list.

1.4.4 Camera permission (Android and iOS): Used to scan QR codes for device binding and other features.

1.4.5 Bluetooth permission (Android and iOS): Used to connect the Bluetooth signal emitted by the device for device communication.

1.4.6 WLAN permission (Android and iOS): Used to configure device Wi-Fi for device communication.

1.4.7 Microphone (Android, iOS versions): Used for music rhythm operations on smart devices.

1.4.8 Notification permission (Android, iOS versions): Used for system notifications, device alarms, etc.

1.5. We may send you service-related announcements when we consider it necessary (e.g., during temporary service suspension for maintenance, or security, privacy or administrative-related communications). Please note that these service-related announcements are not promotional and you may not opt out of receiving them.

1.6. If the information you provide contains personal data of other users, you must ensure that you have obtained their legal consent before providing such data to us. In case of personal data about a minor, you must obtain the consent of the minor's guardian prior to dissemination, in which case the guardian has the right to contact us, as specified in Article 8 of this Policy, to request correction or deletion of such data.

We will obtain your prior consent if we intend to use the data for purposes other than those specified in this Policy, or if we intend to use the collected data for purposes beyond its original intention, or if we actively obtain your data from third parties.

2. How We Share and Disclose Your Personal Data

2.1. We do not sell any personal data to third parties. However, to provide you with the products and services described in this Privacy Policy, we may need to share your personal data with our third-party service providers and business partners. Rest assured that Sunbooster conducts due diligence and enters into contracts to ensure that these third-party service providers comply with the applicable privacy protection laws in your jurisdiction.

2.2. Please note that certain features in SUNBOOSTER are provided by third-party partners (hereinafter referred to as "SDK Providers") in the form of SDK plug-ins. The SDK Providers will obtain corresponding permissions and information to deliver these features or services to you. Information collected by such SDK plug-ins shall not constitute personal data. If information collected by such SDK plug-ins constitutes personal data, any personal data collected by SDK plug-ins provided by any SDK technical service providers is subject to their respective personal data processing policies. You may access https://policies.google.com/privacy and https://developers.google.com/maps/documentation/android-sdk/play-data-disclosure to know more about the personal data processing policies of the SDKs we used.

2.3. Sharing with our affiliates: To enhance our services and ensure the safety of Sunbooster affiliates, other users, or the public, we may share your personal data with Sunbooster affiliates for specific, explicit and lawful purposes stated in this Policy. Only the data necessary for service delivery will be shared. We require the affiliates to implement at least as stringent protective measures as those in this policy, as well as their strict compliance with applicable laws and regulations. If our affiliates intend to change the purpose of personal data processing, they must obtain your prior consent.

2.4. Disclosure to law enforcement agencies, public or judicial authorities and organizations. We will disclose the data if required by law or if we believe in good faith that such disclosure is reasonable and necessary to:

l Comply with a statutory obligation, process, or requirement;

l Enforce the terms of service and other agreements, policies, and standards, as well as to investigate any potential violations of these documents;

l Identify, prevent, or resolve security, fraud, or technological issues;

l Protect the rights, property, or safety of Sunbooster, our users, third parties, or the public (which may include exchanging information with other enterprises and institutions for the purpose of preventing fraud and reducing credit risk), as required or permitted by law.

2.5. Sharing with third parties in business transactions. If we are acquired, merged or cooperate with other companies, or sell assets, we may disclose information to third parties. This may involve disclosing your data to potential buyers or including user information in the transferred assets.

3. How We Store Your Personal Data

We retain personal data for as long as it is necessary for the purposes described in this Privacy Policy or as required by applicable laws. We will stop retaining your personal data, and delete or anonymize your personal data once the purpose of personal data collection is fulfilled, upon your request for information deletion and account cancellation, or termination of a product or service. However, we may retain the data collected for public interest, scientific, historical research or statistical purposes, in accordance with the applicable law, even if further processing is not related to the original purpose of collection.

4. How We Protect Your Personal Data

4.1. We employ industry-standard security measures to protect your personal data from unauthorized access, disclosure, use, modification, damage or loss. These measures include SSL encryption technology for data exchange between your mobile devices and servers, secure browsing over HTTPS, encryption technology for personal data, trusted protection mechanisms against malicious attacks, access control for authorized personnel, and regular security and privacy training for our employees.

4.2. The Internet is not absolutely secure, so we strongly advise against using the communication methods other than those recommended by Sunbooster while using our products or services. Through our products or services, you can connect and share data with others. When you create communications, conduct transactions or share data through our products or services, you have the option to choose who you communicate, trade, or share the data with as a third party, and they may have access to data such as contact details, exchanged information, or shared content.

4.3. We will promptly notify you of a user information security incident, in accordance with applicable laws and regulations, and provide essential details about the incident, its potential impact, the measures taken or planned, advice on risk prevention and mitigation, and available remedies, etc. We will use various communication methods, such as emails, letters, phone calls, push notifications or other means. In the event it is challenging to notify each individual data subject, we will utilize reasonable and effective means to make public announcements. Additionally, we will report the handling of user information security incidents in accordance with the requirements of the relevant data protection or regulatory authorities.

5. Your Rights Regarding Your Personal Data

In accordance with applicable national or regional laws and regulations, you are entitled to request access, correction and deletion of your personal data held by us (hereinafter referred to as the "Request"). Further information is provided below.

5.1. Right of access

5.1.1 Account information: If you want to access or edit your profile information, update your password and more, after logging in to your account, you can access or edit such information by clicking [My] – [My Account].

5.1.2 Personal data: To access the personal data generated during your use of our products or services, please contact us as specified in Article 8.

5.2. Right to rectification

You are entitled to request us to correct inaccurate or incomplete personal data. Simply visit the Personal Data Settings page or contact us directly, and we will promptly address your request to ensure the accuracy of your data.

5.3. Right to erasure

You have the right to request deletion of your personal data. To erase your data please contact us as specified in Article 8.

5.4. Right to data portability

The right to data portability entitles you to receive a copy of your personal data in a structured, commonly used, and machine-readable format, and, where possible, we will forward it directly to the data controller. If you need assistance, contact us as specified in Article 8.

5.5. Right to cancel/delete your account

The account cancellation is a permanent action, so please proceed with caution. To cancel your account, follow the method below.

5.5.1 To cancel your account, navigate to: [Me] – [My Account] – [Account Cancellation]

5.5.2 If you need our assistance with account cancelation, contact us as provided in Article 8.

5.5.3 After your cancelling/deleting your account, we will stop providing products or services, and delete your personal data as per your request.

5.6. Right to withdraw consent

If our processing is based on your consent, you have the right to withdraw your consent at any time. Please note that withdrawing your consent will not affect the lawfulness of the processing that occurred before the withdrawal.

To withdraw your consent:

5.6.1 As mentioned above, you can withdraw your consent by navigating to [Me] – [System Settings] – [System Permission Management]. This includes permissions for location, camera, album (picture library/video library), microphone and Bluetooth.

5.6.2 Turn off push notifications, alerts and messages you have previously agreed to receive by navigating to [Me] – [Push Settings].

The display and turn-off methods of permissions may vary depending on the device. For details, see the instructions or guidelines of device and system developers.

5.6.3 You may contact us as specified in Article 8 to exercise this right.

5.7. Right to object to processing

You are entitled to object to the processing of your personal data or the processing for direct marketing purposes based on your personal reasons. To exercise this right please contact us as specified in Article 8.

5.8. Right to restriction of processing

You have the right to request that we temporarily or permanently stop processing all or some of your personal data. To exercise this right, please contact us as specified in Article 8.

6. Cross-border Transfer of Personal Data

Sunbooster is a global organization with legal entities, business processes and technical systems that operate across national borders. We currently store and process your information on cloud servers located in Germany.

To facilitate our operations, we may transfer, store and process your personal data in jurisdictions other than where you live. Laws in these countries may differ from the laws applicable to your country of residence. For instance, if you are a European Economic Area (EEA) data subject and your personal data is shared with our affiliates, partners, or third-party service providers acting on our behalf outside of the EEA, then it is done pursuant to necessary means to ensure an adequate level of protection. This includes an adequate decision of the European Commission confirming an adequate level of data protection in the respective non-EEA country per GDPR Article 45, or an agreement on the basis of approved EU standard contractual clauses per GDPR Article 46.

Upon request by contacting us as described in this Privacy Policy, we will provide you further information on the means of ensuring an adequate level of data protection.

7. How We Protect Personal Data of Minors

We do not provide services for minors. We treat minors under 14 or the legal age specified by local laws as children. When collecting children's personal data with parental consent, we will only use or disclose it if permitted by laws and regulations, or with the explicit consent of the parents/legal guardians, or if necessary for protecting the minors. If we unintentionally collect personal data from children without parental consent, legal authorization or the necessary protection of children, we will try to remove the content as soon as possible. As parents or legal guardians, you may also contact us as specified in Article 8 to delete related content.

8. How to Contact Us

8.1 If you have any questions, comments or suggestions about this Privacy Policy, or if you want to exercise your rights, or discuss any requests with us, please feel free to contact us at:

Email: service@sunbooster.com

8.2 To ensure security, you may need to provide a written request or prove your identity. We aim to respond within 15 days. However, depending on the complexity and volume of requests, this period may be extended for an additional 45 days, if necessary. If there is a delay in providing information, we will notify the data subject of the circumstances and the reason for the delay. If the time limit set in this paragraph conflicts with your local law, your local law prevails. If you disagree with how we handle your personal data, you can contact your local data protection authority.

We may update this Privacy Policy by updating our App. We recommend regularly checking our current Privacy Policy on the App.

Thank you for taking the time to read our Privacy Policy!