Access Control App Privacy Policy
Last Updated: [2026]年[04]⽉[24]⽇ Effective Date: [2026]年[04]⽉[24]⽇ Company Name: [Zhuhai Taichuan Cloud Technology Co., Ltd.] Contact: [joy@cn.taichuan.com] Thank you for using [E-Key] (hereinafter referred to as "this App"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information. We strictly comply with applicable data protection laws, including but not limited to: The EU General Data Protection Regulation (GDPR) The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) The Illinois Biometric Information Privacy Act (BIPA) and other similar state laws in the US The Saudi Arabian Personal Data Protection Law (PDPL) The UAE Federal Data Protection Law (No. 45/2021) Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) Other applicable local privacy laws Please read this Privacy Policy carefully and fully understand it before using this App. If you do not agree with any part of this policy, please discontinue use of this App immediately.
- Information We Collect To provide core functionalities such as access control, visitor management, and security logging, we may collect the following categories of personal information: 1.1 Information You Actively Provide Account Information: Name, email address, phone number, login password (stored in encrypted form). Authentication Information: If you opt for advanced verification methods (e.g., facial recognition), we will collect related biometric templates only upon your explicit and separate consent, strictly for unlocking doors and stored in encrypted form. Access Authorization Information: The IDs of the access control devices you are associated with, permission groups, permanent address, office number, etc. Visitor Information: When you add or invite a visitor, you may need to provide the visitor's name, phone number, expected visit time, and visitor photo (for temporary identification). 1.2 Information Collected Automatically Device Information: Device model, operating system version, unique device identifiers (e.g., IDFA, Google Advertising ID), IP address, language settings. Log Information: Time of your App usage, door opening records, unauthorized attempts, administrative operation logs (for security auditing). Camera/Photo Album Information: Accessed only when you actively scan an access QR code, upload a profile picture, or visitor photo. We do not collect this information automatically. 1.3 Information from Third-Party Sources If you register through your employer or property management for a unified account, they may provide us with your name, assigned floor/area, and access permission groups.
- How We Use Your Information We process your personal information only under the following lawful bases: Necessary for the performance of a contract (GDPR Art. 6(1)(b)): To provide you with core services like door unlocking, permission management, visitor invitations, and viewing access records. Based on your consent (GDPR Art. 6(1)(a)): For activities requiring separate authorization, such as processing biometric information or sending push notifications. Compliance with a legal obligation (GDPR Art. 6(1)(c)): Retaining necessary access logs to respond to lawful requests from law enforcement or regulatory authorities. Legitimate interests (GDPR Art. 6(1)(f)): Improving App security, preventing fraud, analyzing service performance, and conducting internal statistical analysis. Specific purposes include: Purpose Explanation Providing Door Access & Authentication Verifies your door unlocking requests using your account, device identifiers, and biometric features (if applicable). Visitor Management Generates temporary passwords/QR codes and records visitor entry/exit times. Security Safeguards Detects abnormal door opening behavior and device misuse attempts (e.g., temporary lockout after consecutive failures). Such simple rules do not constitute automated decision- making in the sense of GDPR Article 22. Customer Support Responds to your inquiries and resolves technical issues. Compliance Auditing Provides necessary data to property management or internal corporate audits. Push Notifications Sends door unlocking results, visitor arrival alerts, and access anomaly warnings (can be turned off).
- Information Storage & Retention Storage Location: Your personal information is primarily stored on servers of [e.g., AWS/GCP/Azure located in Germany/Ireland/US/Saudi Arabia]. The specific region depends on your location: Users in the European Economic Area: Stored in data centers within the EU. Users in California and other US states: Stored in data centers within the United States. Users in Saudi Arabia: Your sensitive data (biometric, precise location) will be stored in data centers within Saudi Arabia; non-sensitive data may be stored in the EU or US, but we will obtain regulatory authorization or sign Standard Contractual Clauses (SCCs) under Saudi PDPL. Users in the UAE: Your data is stored in [within the UAE or the EU], ensuring an equivalent level of protection for cross-border transfers. For other cross-border transfers, we ensure data security through Standard Contractual Clauses (SCCs) or equivalent protection mechanisms. Retention Period: Account Information: Deleted 30 days after you close your account, unless otherwise required by law. Access Logs: Retained for a maximum of 12 months (for security auditing). Visitor Information: Automatically deleted 7 days after the visitor's scheduled visit ends. Biometric Templates: Deleted immediately upon you deactivating the feature or closing your account.
- Information Sharing & Disclosure We do not sell your personal information (as defined by CCPA). Sharing occurs only in the following necessary circumstances: 4.1 Service Providers We may share necessary information with third-party service providers for: cloud storage, push notifications, map/location services, crash analytics, and email delivery. These vendors must sign data processing agreements and can only process data per our instructions. 4.2 Property/Corporate Administrators If your access control system is provided by a property management company or employer, we may share with them: Your name, employee ID, access permission groups, and entry/exit records (for verifying access compliance). Visitor invitation records and visitor photos (for security verification). 4.3 Legal Compliance & Security Responding to court subpoenas, search warrants, or other lawful government requests. Protecting the rights, property, or safety of the App, our users, or the public. 4.4 Business Transactions In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the assets. We will notify you in advance and provide an opportunity to opt-out.
- Your Privacy Rights Depending on your region, you have the following rights. We will respond within the legally required timeframe (GDPR/Saudi PDPL: 30 days; CCPA: 45 days). Right Explanation Right of Access Confirm whether we process your personal information and obtain a copy of the data. Right to Rectification Request correction of inaccurate or incomplete data. Right to Erasure ("Right to be Request deletion of your data under Forgotten") specific circumstances (e.g., withdrawing consent, data no longer necessary). Right to Restriction of Processing Request a temporary restriction on how we process your data. Right to Data Portability Receive the data you provided in a structured, commonly used, and machine-readable format (without adversely affecting the rights of others). Right to Object Object to data processing based on "legitimate interests" or for direct marketing. Withdraw Consent Withdraw previously given consent at any time (does not affect the legality of processing before withdrawal). Rights regarding Automated We do not use purely automated Decision-Making decision-making that produces legal or similarly significant effects concerning you. Right to Lodge a Complaint Complain to your regulatory authority (e.g., France's CNIL, UK's ICO, California Attorney General's Office, Saudi SDAIA, UAE Data Office). How to Exercise Your Rights Please submit your request via email to [Privacy Email Address]. Identity verification may require you to provide necessary information. CCPA Specific Declaration: We do not "sell" your personal information (including the information of minors). We also do not engage in "sharing" for cross-context behavioral advertising. California residents have the right to request disclosure of the categories of personal information collected, used, and disclosed in the past 12 months, and to request deletion. BIPA declaration for Illinois users is provided in Section 12.
- Special Processing of Sensitive Personal Information The only sensitive information this App may process is biometric data (facial/fingerprint). Processing is based on: Your explicit, separate, written consent (with an additional electronic signature required for Illinois users). Such processing is absolutely necessary to enable the secure door unlocking functionality, and you have multiple alternative verification methods available, including face recognition, QR code scanning, or App control unlocking. Biometric Data Processing Measures: Feature templates are extracted and then encrypted for storage either in the device's Trusted Execution Environment (TEE) or in cloud-based Hardware Security Modules (HSM). Not used for any other purpose (e.g., identity tracking, analytics). Real-time comparison occurs only upon each unlock request, without retaining raw biometric features in comparison logs. Retention Period: See Section 3. Deletion Method: You can delete registered biometric features via App settings or contact [Contact Email] to request deletion without needing to close your account.
- Children's Privacy This App is not directed at minors. Age limits apply based on your location: EU & Most Countries: Under 16 years old California, USA: Under 13 years old Saudi Arabia & UAE: Under 18 years old Other Regions: As defined by local laws We do not knowingly collect personal information from anyone below the aforementioned age. If we discover registration without parental consent, we will promptly delete the relevant account and data. If a parent or guardian believes we have collected a child's information, please contact us at [Contact Email].
- Data Security We implement industry-standard security measures, including: Transmission Security: TLS 1.3 encryption for all network communications. Storage Security: Passwords are hashed using bcrypt with salt; sensitive data (biometric features, visitor photos) is encrypted using AES-256. Access Control: Principle of least privilege enforced; only authorized personnel can access production databases. Regular Testing: Annual penetration testing and vulnerability scanning. Data Protection Impact Assessment (DPIA): Given the processing of biometric data and large-scale location information by this App, we have completed a DPIA. For a DPIA summary, please contact [Contact Email]. In the event of a data breach: We will notify the relevant supervisory authority within 72 hours (where applicable) and notify affected users via in-App messages or email if a high risk is determined.
- Cross-Border Data Transfers As we use globally distributed service providers, your information may be transferred to servers located outside your country/region. We ensure such transfers have a lawful basis: EU Users: EU Standard Contractual Clauses (SCCs). Saudi Users: Obtain authorization from the Saudi Data & AI Authority (SDAIA) or sign approved SCCs. UAE Users: Equivalent protection level mechanisms. You may contact [Contact Email] to obtain a copy of the relevant transfer agreements (commercially sensitive information may be redacted).
- Cookies & Similar Technologies This App does not use traditional browser cookies but may use local storage (within the App) or mobile identifiers to remember your login status and preferences. You can reset advertising identifiers through your device settings at any time.
- Changes to This Privacy Policy We may update this Privacy Policy from time to time. Material changes (e.g., affecting processing purposes or your rights) will be notified to you in advance via an in-App popup or email. We will also update the "Last Updated" date at the top of the policy. Your continued use of the App after changes become effective signifies your acceptance of the updated version.
- Region-Specific Supplements 12.1 For Users in Illinois, USA (BIPA Declaration) The following applies if you are a resident of Illinois: Written Consent: We will require your separate, electronic signature to consent to the collection, storage, and use of biometric information as detailed in this policy when you first enable biometric features (facial or fingerprint recognition). You can withdraw this consent at any time within the App; upon withdrawal, we will immediately delete your biometric information. Retention Schedule: Your biometric information will be permanently destroyed upon the earlier of: (a) 30 days after you disable biometric authentication; (b) 30 days after you close your account. In any case, retention will not exceed 3 years from your last interaction with the feature, unless otherwise required by law. No Conditioning of Service: You have the right to use the access service through other equivalent methods (e.g., PIN, SMS verification code) without using biometric features. Prohibition on Profiting: We will not sell, lease, trade, or otherwise profit from your biometric information. Data Breach Notification: In the event of a biometric data breach, we will notify you and the Illinois Attorney General as required by BIPA. 12.2 Special Notes for Middle East Users (Saudi Arabia & UAE) The following take precedence if you are located in the Kingdom of Saudi Arabia or the United Arab Emirates: Applicable Laws: We comply with the Saudi Personal Data Protection Law (PDPL) and the UAE Federal Data Protection Law (No. 45/2021). Sensitive Data Types: Biometric information (facial/fingerprint) and precise location information are treated as sensitive data. We will request your explicit, written consent separately for these. You can withdraw consent at any time in the App settings. Data Localization & Cross-Border Transfer: Saudi Users: Your sensitive data (biometric, precise location) will be stored in data centers within Saudi Arabia. Non-sensitive data may be transferred outside, but with authorization from SDAIA or by signing approved SCCs. UAE Users: Your data is stored in [within the UAE or the EU]; cross-border transfers follow equivalent protection standards. Local Representative: Saudi Arabia: Our Saudi data protection representative is [Representative Company Name, Address, Contact Details]. This representative handles your privacy inquiries, complaints, and communication with SDAIA. UAE: If needed, you can directly contact our DPO at [DPO Email]. Response Time: We will respond to your data subject requests within 30 days. Child Age Limit: We do not knowingly collect information from anyone under 18 years old. If you are a parent/guardian and believe we have collected a child's data, please contact [Email Address]. Language Version: An Arabic version of this Privacy Policy is available at [Link]. For UAE users, in case of conflict between the Arabic and English versions, the Arabic version prevails.
- Contact Us If you have any questions about this Privacy Policy or wish to exercise your rights, please contact: Email: [joy@cn.taichuan.com] Filing a Complaint: You may also lodge a complaint with the supervisory authority in your location. EU Residents: Find your relevant authority at https://edpb.europa.eu/about-edpb/about -edpb/members. Saudi Residents: Saudi Data & AI Authority (SDAIA) UAE Residents: UAE Data Office