SIKEY AI Assistant Smart Assistant Privacy Policy
Effective Date: Date of User’s first use of the Application
This Privacy Policy applies to the SIKEY AI Assistant mobile application (hereinafter referred to as the "Application", "SIKEY AI Assistant", or "we"). It transparently explains how we collect, use, store, protect, share and dispose of Users’ personal data, and clarifies the data rights enjoyed by Users in global markets including Europe, the United States, India, and Southeast Asia. We fully comply with applicable laws and regulations such as GDPR, CCPA/CPRA, India’s DPDP Act, Singapore PDPA, Indonesia’s PDP Law, and Thailand PDPA.
Important Notice: By using the Application, you acknowledge that you have fully read, understood and agreed to all terms of this Privacy Policy. If you do not agree with this Policy, please stop using the Application and related services immediately. Minors may only use the Application with the consent and supervision of their parent or legal guardian.
1. Scope of Application and Definitions
1.1 Scope of Application
This Policy applies to all Users who access or use the SIKEY-AI Smart Assistant, covering the three core functions of AI Smart Q&A, Quick Subscription via QR Code, and Personal Center, as well as all scenarios including customer service, technical support and account management. Regardless of your location in Europe, the United States, India, Southeast Asia or other regions, the provisions of this Policy shall apply, together with the mandatory privacy laws and regulations of the corresponding region.
1.2 Core Definitions
Personal Data: Information that can directly or indirectly identify your identity, including but not limited to account information, device information, QR code subscription records, AI Q&A interaction content, and payment-related information (desensitized).
Sensitive Personal Data: Data requiring a higher level of protection, including biometric information, sensitive financial payment information, and religious/racial-related information (we do not actively collect such information).
Processing: Any operation performed on personal data, such as collection, storage, use, processing, transmission, sharing and deletion.
Data Controller: The operating entity of SIKEY-AI, which determines the purposes and means of personal data processing.
2. Personal Data We Collect and Collection Methods
We strictly adhere to the principles of data minimization and purpose limitation, and only collect data necessary to provide services, without collecting information irrelevant to core functions.
2.1 Data Collected Actively
Account and Personal Center Data: Nickname, contact information and account password (encrypted storage) provided during registration/login; preference settings actively filled in by you in the Personal Center.
Subscription Service Data: QR code scanning records, subscription package details, order status, and payment vouchers (desensitized, no full storage of bank card/payment account numbers) when activating the AI Assist service for HMD feature phones via QR code.
AI Interaction Data: Questions submitted and responses generated when using the AI Smart Q&A function (only used to provide services and optimize AI models in compliance with regulatory requirements).
2.2 Data Collected Automatically
Device Information: Device model, operating system, unique device identifier (desensitized), and IP address (for Users in Europe/India, IP addresses are only used for localized services and not for precise tracking).
Usage Information: Function usage frequency, subscription activation/cancellation records, page access paths, and crash logs (only used for fault repair).
2.3 Data We Do Not Collect
We do not actively collect non-essential data such as address book, photo album, SMS, call records, precise geographic location (unless authorized by you for specific services), and biometric information.
3. Purposes of Personal Data Use
We only use personal data for the following legitimate and specific purposes, and shall not process it beyond the stated scope:
Provide, operate and maintain the core functions of AI Smart Q&A, QR Code Subscription and Personal Center;
Process subscription orders, complete payment settlement, and manage subscription status and renewal reminders;
Optimize AI model performance and improve Q&A accuracy and service experience (using anonymized and aggregated data);
Verify account identity, protect account and data security, and prevent fraud, abuse and security risks;
Respond to customer service inquiries and complaints, and fulfill legal obligations;
Comply with applicable laws and regulatory requirements, and cooperate with legitimate judicial/administrative investigations.
4. Data Sharing and Third-Party Disclosure
We will not sell or rent Users’ personal data to unrelated third parties, and only share data in compliance with the following circumstances:
4.1 Authorized Third Parties for Sharing
Authorized Partners: Payment service providers (only for subscription fee settlement), HMD device manufacturers (only for subscription function linkage), and cloud service providers (data storage and computing support);
Legally Required Disclosure: Comply with laws, court orders, regulatory directives, or protect the legitimate rights and interests of us and Users;
Merger/Reorganization: In the event of a merger or asset transfer, data will be transferred as assets, and the successor entity shall abide by this Privacy Policy.
4.2 Third-Party Restrictions
All third-party partners are required to sign data processing agreements, commit to complying with regional privacy laws (GDPR, DPDP Act, PDPA, etc.), and only process data within the authorized scope for no other purposes.
5. Multi-Market Data Compliance Rules (Core Provisions)
We have formulated differentiated compliance measures to protect Users’ territorial rights in accordance with regional regulatory requirements:
5.1 Europe (Applicable to GDPR)
Legal Bases for Data Processing: User’s explicit consent, performance of a contract, compliance with legal obligations, and legitimate interests;
User Rights: Access, rectification, erasure, data portability, restriction of processing, objection to processing, and withdrawal of consent;
Data Transborder Transfer: Data transfer outside Europe shall adopt Standard Contractual Clauses (SCC) or equivalent protection mechanisms;
Data Breach: Notify the competent authority within 72 hours, and inform affected Users of high-risk breaches;
Data Protection Officer (DPO): A dedicated person has been appointed to handle data compliance for European Users, with contact information at the end of this Policy.
5.2 United States (Applicable to CCPA/CPRA)
User Rights: Access to data, deletion of data, opt-out of data sharing, and non-discriminatory treatment;
Transparency: Clearly disclose the categories of collected data, purposes of use, and third parties for sharing;
Minors’ Data: We do not knowingly collect data from minors under the age of 13 unless with parental consent.
5.3 India (Applicable to DPDP Act)
Data Localization: Personal data of Indian Users is preferentially stored on servers located in India, and sensitive data shall not be transferred abroad in violation of regulations;
Consent Requirements: Obtain verifiable and freely withdrawable explicit consent from Users, with no pre-checked consent boxes;
User Rights: Right to be informed, access, rectification, erasure, data portability, and appeal;
Data Breach: Notify the Data Protection Board of India within 72 hours, and inform affected Users simultaneously.
5.4 Southeast Asia (Applicable to Singapore PDPA, Indonesia PDP Law, Thailand PDPA, etc.)
Singapore PDPA: Obtain explicit consent, limit usage purposes, set reasonable data retention periods, and ensure equivalent protection for cross-border transfers;
Indonesia PDP Law: Cross-border data transfer shall meet equivalent protection standards, and additional consent is required for sensitive data processing;
Thailand PDPA: Separate authorization for sensitive data, prohibition of use for undisclosed purposes, and protection of the right to rectification and erasure.
6. Data Storage and Security Protection
6.1 Storage Period
We only store data for the shortest period necessary to achieve the purpose of collection, and shall completely delete or anonymize data upon expiration:
Account Data: Duration of account existence + 180 days after account cancellation (for compliance traceability);
Subscription Data: Subscription period + 90 days after expiration (for order verification and after-sales support);
AI Interaction Data: 30 days after service use (excluding anonymized data used for model optimization).
6.2 Security Measures
We adopt international-standard security technologies and management measures to prevent data leakage, loss and tampering:
Data Encryption: Transport layer encryption (TLS/SSL), storage encryption, and sensitive data desensitization;
Access Control: Strict authority management, with only authorized personnel able to access personal data;
Security Audit: Regular data security testing, vulnerability repair and compliance audits;
Emergency Mechanism: Establish a data breach emergency plan for rapid response to security incidents.
7. User Data Rights and Exercise Methods
Regardless of your market location, you may exercise your data rights through the following channels, and we will respond within the statutory time limit:
7.1 General Rights
Access/Inquiry: View the personal data we collect about you and its processing status;
Rectification/Supplementation: Correct inaccurate or incomplete personal data;
Deletion/Account Cancellation: Apply for deletion of personal data or account cancellation (except for data required to be retained by law);
Withdrawal of Consent: Withdraw previously granted consent for data processing (without affecting legitimate processing prior to withdrawal);
Complaint & Feedback: Raise objections or complaints regarding data processing activities.
7.2 Channels for Exercising Rights
Submit an application through Personal Center - Settings - Privacy & Data in the Application, or send an email to our customer service mailbox. We will respond within the following timeframes:
Europe/GDPR: Respond within 1 month, extendable by 2 months for complex cases;
United States/CCPA: Respond within 45 days;
India/DPDP Act: Respond within 30 days;
Southeast Asia/PDPA: Respond within 30 days.
8. Special Notes on Subscription Services
When subscribing to the AI Assist service for HMD feature phones via QR code, the scanning action is only used to verify subscription eligibility and redirect to the payment page, with no additional sensitive data collected;
Subscription-related data is only used for order management, service activation and renewal reminders; data processing will cease upon subscription cancellation;
Users may check subscription status, manage auto-renewal and apply for subscription cancellation at any time in the Personal Center.
9. Policy Updates and Notifications
We reserve the right to revise this Privacy Policy in light of regulatory updates and function adjustments. Material changes will be notified to Users via in-app pop-ups, emails or announcements. The revised Policy shall take effect on the date of publication, and continued use of the Application by Users shall constitute acceptance of the revised content.
10. Disclaimer
In the event of data leakage caused by force majeure, hacking attacks or third-party violations, we will do our utmost to stop losses but shall not be liable for undue responsibilities;
Users shall bear sole responsibility for losses caused by improper custody or disclosure of account passwords;
This Policy only applies to the SIKEY AI Assistant, and the privacy practices of third-party links/services are the sole responsibility of such third parties.