Privacy Policy

Update!

Our Privacy Policy was updated on January 22nd, 2024 and took effect on January 22nd, 2024. This Privacy Policy can provide details on how we manage your personal information forour products and services, unless a separate privacy policy is provided for the specific products or serviceprovided by Lumi United Technology Co., Ltd.and its affiliates (Include but not limited to Shenzhen Aqara Software Service Co. , Ltd.,)(hereinafter referred to as "Lumi Company","we","us" or "our").

Please take a moment to familiarize yourself with our privacy practices and let us know if you have any questions.

OUR COMMITMENT TO YOU

This Privacy Policy sets out how Lumi United Technology Co., Ltd. ("Lumi Company", "we", "our" or "us") collects, uses, discloses, processes and protects any personal information that you give us when you use our products and services. Should we ask you to provide certain information by which you can be identified when usingLumi Company's products and services, it will only be used in accordance with this Privacy Policy and/or our terms and conditions for users.

The Privacy Policy is designed with you in mind, and it is important that you have a comprehensive understanding of our personal information collection and usage practices, as well as full confidence that ultimately, you have control of any personal information provided to Lumi Company.

In this Privacy Policy, "personal information" means information that can be used to identify an individual, either from that information alone or from that information combined with other information Lumi Company has access to about that individual. Such personal information may include but not limit to the information you provide to us or upload, device-related information, etc.

By using our products and services, you are deemed to have read, acknowledged and accepted all the provisions stated here in the Privacy Policy, including any changes we may make from time to time. In order to comply with applicable laws, including local data protection legislation (e.g. General Data Protection Regulation in Europe Union), we will specifically seek prior explicit consent to the particular processing (e.g. automated individual decision-making) of special categories of personal data (if any). We are committed to protecting the privacy, confidentiality and security of your personal information by complying with applicable laws, including your local data protection legislation. We are equally committed to ensuring that all our employees and agents uphold these obligations.

Ultimately, what we want is the best for all our users. Should you have any concerns with our data handling practice as summarized in this Privacy Policy, please contact our Data Protection Officer at privacy@lumiunited.com to address your specific concerns. We will be happy to address them directly.

WHAT INFORMATION IS COLLECTED AND HOW WE CAN USE IT

TYPES OF INFORMATION COLLECTED

In order to provide our services to you, we will ask you to provide personal information that is necessary to provide those services to you. If you do not provide your personal information, we may not be able to provide you with our products or services.

We will only collect the information that is necessary for its specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. We may collect the following types of information (which may or may not be personal information):

INFORMATION COLLECTED BY THE THIRD PARTIES

Please be aware that in order to realize the relevant functions and ensure the safety and stability of the service, we have accessed the software tool development kit (SDK) provided by a third party, and we will conduct strict security monitoring on the SDK obtained by the partner to protect the data security.

In the following table, we list the types of third-party SDKs accessed in the Aqara Home app, as well as the types of personal information you collect and the purpose of use:

Name of the third party SDK Information collection types Information collection/purpose of use Operating systems
Shangyun(CS2 Network) Camera device ID, network information (IP, current network type and name) It is used to set up the p2p connection of the camera after the camera device is added Andriod and iOS
Facebook open-source framework Device information (including device model, device identifier (AndroidID/ IDFA/ OPENUDID/ GUID/ OAID) It is used to log in Facebook Andriod and iOS
Sensors Data IP address, sensor list, acceleration sensor, device information (device version, device manufacturer, device model information), device identification information (hardware serial number, IMEI, MAC address, IMSI information, IDFA, AndroidID), device status information, Install application package name information, network information (WIFI parameter ssid), operator information, location information, IDFV, OAID, VAID, UUID, IMSI It is used to initialize the SDK for data collection after the user agrees to the Privacy Andriod and iOS
Application performance monitoring full-link version App monitoring SDK (1) Device information: device ID, device model, operating system, system time zone, screen resolution, disk usage, memory usage, number of running threads, CPU information (frequency, model, architecture), mobile device country code (MCC) ), Mobile Device Network Coding (MNC), device dpi; Android ID, device brand, operating system api version, user agent, battery power, network traffic, device abi, ROM; (2) Application information: application version, application package Name, process startup time, crash time, crashed thread name, active page name, all thread stacks of the current process, application service log information, application file name, application file size, disk size; fd list; (3) system and network Identification information: user ID, IP address, operator information, network access mode. Use automation programs and algorithms to identify devices, obtain device status (online, offline, and network environment), perform device count statistics, and debug single device problems. Andriod and iOS
International translation platform SDK (1) Device information: device brand, device model, operating system; (2) Application information: application package name; (3) System or network identification information: network access mode (WIFI status); (4) Personal location information: System country/region information. Obtain the i18n copy configured by the customer on the translation platform. This parameter will be used by the server to configure the grayscale dimension selection for grayscale delivery. Andriod and iOS
AndroidX Webkit(chromium) SSID, BSSID, MAC address, WIFI information, AndroidX Webkit (chromium) needs to monitor the WIFI switch and signal status, and will obtain WIFI information, MAC address, SSID, installed APP information, and sensor information multiple times. AndroidX auxiliary development tools provided by Google, based on the WebKit browser engine, provide web browsing services Andriod
GeTui Device ID, device model, app version number, system version number, device platform, device manufacturer, network information and position-related information, application list information It is used to provide the message pushing service for models of the iOS system iOS
Ali Mobile PUSH (EMAS) Device identification information ( operating system, device model, IP, operator information) It is used to recognize the pushing device and push messages to the single device Andriod
Xiaomi PUSH Device identification information (IMEI) [targeting at the following versions of Android Q], OAID, Android ID and MAC address), setting information of the notification bar, network status information (IP, current network type and name) It is used to provide the message pushing service for the mobile terminal of Mi brand Andriod
OPPO PUSH Device-related information (such as IMEI [targeting at the following versions of Android Q], Android ID), application list It is used to provide the message pushing service for the mobile terminal of OPPO brand Andriod
vivo PUSH Device-related information (such as IMEI [targeting at the following versions of Android Q], Android ID), application list It is used to provide the message pushing service for the mobile terminal of vivo brand Andriod
FCM PUSH List of applications in operation It is used to receive the message pushing service when the overseas device is used in the overseas region, including APNS push Andriod

HOW THE PERSONAL INFORMATION IS USED

We may use your personal information for the following purposes:

WITH WHOM WE SHARE YOUR INFORMATION

We do not sell any personal information to third parties.

We may disclose your personal information on occasion to third parties (as described below) in order to provide the products or services that you have requested. If you no longer wish to allow us sharing this information, please contact us at privacy@lumiunited.com.

To help us provide you with services described in this Privacy Policy, we may, where necessary, share your personal information with our third party service providers listed in this section below. These third party service providers may process your personal information on Lumi Company's behalf or for one or more of the purposes of this Privacy Policy. You should know that when Lumi Company shares your personal information with a Third Party Service Provider under any circumstance described in this section, Lumi Company will contractually specify that the third party is subject to practices and obligations to comply with applicable local data protection laws. Lumi Company will contractually ensure compliance by any Third Party Service Providers with the privacy standards that apply to them in your home jurisdiction.

SHARING WITH THIRD PARTY SERVICE PROVIDERS

To provide better customer support service to you, we entrust a third party service provider to process some of your personal information, here are the details:

Name of the third party: Freshworks

Nature of the sharing: Entrusted processing of personal information

Purposes to process the information: To provide customer support service; Communicating with you about your device, service or any general queries, such as updates, customer inquiry support, information about our events, notices.

Category of information processed: Feedback information.

Recipient's location: 2950 South Delaware St. 2nd Floor, San Mateo, CA 94403 U.S.A.

Retention period of the recipient: During the period of providing technical services to us, which will not exceed the period that is necessary to fulfill the purpose for which the information was collected, or as required or permitted by applicable laws.

INFORMATION NOT REQUIRING CONSENT

Lumi Company may disclose your personal information to others without further consent when it is required by law.

For the avoidance of doubt, Lumi Company may collect, use or disclose your personal information without your consent if it is and only to the extent it is allowed explicitly under local data protection laws. Such disclosure may be brought about by the necessity to protect our rights, ensure the safety of you and other people, and comply with the requirements of the local government to facilitate the investigations of illegal activities.

SECURITY SAFEGUARDS

LUMI COMPANY'S SECURITY MEASURES

We are committed to ensuring that your personal information is secure. In order to prevent unauthorized access, disclosure or other similar risks, we have put in place reasonable physical, electronic and managerial procedures to safeguard and secure the information we collect from your using of Lumi Company products and services and on Lumi Company's websites. We will use all reasonable efforts to safeguard your personal information.

For example, when you access your Aqara Account, you can choose to use authorization code verification process for better security. When you send or receive data from your Lumi Company's device to our servers, we make sure they are encrypted using Secure Sockets Layer ("SSL") and other algorithms.

All your personal information is stored on secure servers that are protected in controlled facilities. We classify your data based on importance and sensitivity, and ensure that your personal information has the highest security level.

We ensure that the personal data, which we store on the local server, will not be directly transmitted back to mainland China without data desensitization to protect the security of the user's personal data.

We make sure that our employees and Third Party Service Providers who access the information to help provide you with our products and services are subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet such obligations. We have special access controls for cloud based data storage as well. All in all, we regularly review our information collection, storage and processing practices, including physical security measures, to guard against any unauthorized access and use.

By using our products and services or providing personal information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use. If we learn of a security system's breach, we may attempt to notify you electronically by posting a notice on the site or through the product or service and/or by sending an e-mail to you. You may have a legal right to receive this notice in writing.

WHAT YOU CAN DO

RETENTION POLICY

Personal information will be held for as long as it is necessary to fulfill the purpose for which it was collected, or as required or permitted by applicable laws. We will cease to retain and delete or anonymize personal information, or remove the means by which the personal information can be associated with particular individuals, as soon as it is reasonable to assume that the purpose for which that personal information was collected is no longer being served by retention of the personal information.If further processing is for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes according to the applicable laws, the data can be further retained by Lumi Company even if the further processing is incompatible with original purposes.

All the personal information on the device will be erased when you reset your device to factory default settings. To implement this, for hub, you can press the button on the hub 10 times to delete all local user data; for light bulb, you can fast turn on/off bulb 5 times to delete all local user data, and for other sub-devices, you can press and hold the reset button for 10 seconds to delete all local user data. Beware that factory settings can't be undone, so you have to make sure that you don't need the information any more.

ACCESSING OTHER FEATURES ON YOUR DEVICE

Our applications may need access to certain features on your device such as Wi-Fi network status. This information is used to allow the applications to run on your device and allow you to interact with the applications. At any time, you may revoke your permissions by turning these off at the device level or contacting us at privacy@lumiunited.com

YOUR RIGHTS

CONTROLLING SETTINGS

Lumi Company recognizes that privacy concerns differ from person to person. Therefore, we provide examples of ways Lumi Company makes available for you to choose to restrict the collection, use, disclosure or processing of your personal information and control your privacy settings:

YOUR RIGHTS TO YOUR INFORMAION: ACCESS, UPDATING, CORRECTING OR ERASURE

WITHDRAWAL OF CONSENT

You can change the scope of your consent or withdraw your authorization in the Aqara Home App by deleting, correcting information, or disabling related device permission functions on your device, or you can click "Profile"-"Settings"- "Terms of Use and Privacy Policy"-"Revocation of Terms of Use and Privacy Policy Authorization" to revoke your authorization.

You may withdraw your consent for the collection, use and/or disclosure of your personal information in our possession or control by submitting a request. This may be done bysending e-mail to privacy@lumiunited.com. We will process your request within a reasonable time from when the request was made, and thereafter not collect, use and/or disclose your personal information as per your request. The withdrawal of your consent or authorization will not affect the validity of our processing carried out on the basis of the consent up until the point of withdrawal.

Please recognize that your withdrawal of consent could result in certain consequences. Depending on the extent of your withdrawal of consent for us to process your personal information, it may mean that you will not be able to enjoy Aqara Hub and its sub-device products and services.

CANCELLING A SERVICE OR ACCOUNT

If you wish to cancel a specific product or service, you can send an email to privacy@lumiunited.com for logout service. If you wish to cancel the Aqara Home Account, please note that the cancellation will prevent you from using the full range of our products and services. Cancellation may be prevented or delayed in certain circumstances.

TRANSFER OF PERSONAL INFORMATION OUTSIDE OF YOUR JURISDICTION

To the extent that we may need to transfer personal information outside of your jurisdiction to the third part service provider, we shall do so in accordance with the applicable laws. In particular, we will ensure that all transfers will be in accordance with requirements under your applicable local data protection laws by putting in place appropriate safeguards.

Lumi Company may use overseas facilities to process or back up your personal information. Currently, Lumi Company has data centers in mainland China, Germany, South Korea, Singapore, Russia and United States. These overseas jurisdictions may or may not have in place data protection laws which are substantially similar to that in your home jurisdiction. We may transfer to and store your personal information at our overseas facilities. However, this does not change any of our commitments to safeguard your personal information in accordance with this Privacy Policy.Your personal information may be accessible to law enforcement or other authorities pursuant to a lawful request. By providing information to Lumi Company, you consent to the storage of your pe6655rsonal information in these locations. **If you use our services in the area of the European Economic Area (EEA), The privacy policy for EEA shall apply. **If we share personal data originating by you in the EEA to a third party service provider outside the EEA, we will do so on the basis of EU standard contractual clauses or any other safeguards provided for in the GDPR.

MISCELLANEOUS

MINORS /CHILDREN'S PRIVACY

Our services are restricted to individuals who are 18 years of age or older. We do not permit individuals under the age of 18 on our platform.We consider it the responsibility of parents to monitor their children's use of our products and services. Lumi Companydoes not knowingly collect personally identifiable information from children.

7666666It is our policy not to require personal information from minors or offer to send any promotional materials to persons in that category. Lumi Companydoes not seek or intend to seek to receive any personal information from minors. Should a parent or guardian have reasons to believe that a minor has provided Lumi Companywith personal information without their prior consent, please contact us to ensure that the personal information is removed and the minor unsubscribes from any of the applicable Lumi Company's services.

UPDATES TO THE PRIVACY POLICY

We keep our Privacy Policy under regular review and may update this privacy policy to reflect changes to our information practices. If we make material changes to our Privacy Policy, we will notify you by email (sent to the e-mail address specified in your account) or post the changes on all the Lumi Company websites or through software, so that you may be aware of the information we collect and how we use it. Such changes to our Privacy Policy shall apply from the effective date as set out in the notice or on the website. We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of products and services on the websites, mobile phones and/or any other device will be taken as acceptance of the updated Privacy Policy. We will seek consent from you again before we collect more personal information from you or when we wish to use or disclose your personal information for new purposes.

CONTACT US

If you have any comments or questions about this Privacy Policy or any questions relating to Lumi Company's collection, use or disclosure of your personal information, please contact us at the address below referencing "Privacy Policy":

Lumi United Technology Co., Ltd

Room 801-804, Building 1, Chongwen Park, Nanshan iPark, No. 3370, Liuxian Avenue, Fuguang Community, Taoyuan Residential District, Nanshan District, Shenzhen, China

Email: privacy@lumiunited.com

Thank you for taking the time to understand our Privacy Policy!

Addendum for California Residents

The terms of this Addendum apply to residents of California under the California Consumer Privacy Act ("CCPA") and other applicable laws. The CCPA provides California residents with certain legal rights such as "do not sell." These rights are not absolute and are subject to certain exceptions.

We collect, use, disclose and retain your personal information in the same way as described in the main body of this Privacy Policy.

In the past 12 months, we have not sold personal information of California residents within the meaning of "sold" in the CCPA.

SPECIAL RIGHTS UNDER THE CCPA

If you are a California resident and the CCPA does not recognize an exemption that applies to you or your personal information, besides the rights described in main body of this Privacy Policy, you also have the right to be free from unlawful discrimination for exercising your rights including providing a different level or quality of services or deny goods or services to you when you exercise your rights under the CCPA.

We aim to fulfill all verified requests within 45 days pursuant to the CCPA. If necessary, extensions for an additional 45 days will be accompanied by an explanation for the delay.

How to Exercise Your Rights

You may log into your Aqara Home account and manage your data from there.If you are a California resident to whom the CCPA applies, you may exercise your rights, if any, to other data by contacting us at privacy@lumiunited.com.

Additionally, if you are a California resident under age 18 and are a registered user of Lumi Company, then you may request that we remove any submission you publicly posted on or in the site of Lumi Company. To request removal of a submission, please send an email with a detailed description of the specific submission to privacy@lumiunited.com. You also may be able to log in to your account and delete your own submission. LGEUS reserves the right to request that you provide information that will enable us to confirm that the Submission that you want removed was created and posted by you.