Privacy Policy for App
Effective date: 18-07-2022
Updated: 18-07-2022
Aquaporin A/S (“we”, “us”, “our”, “Aquaporin”) is committed to protecting your privacy. This Privacy Policy (“Policy”) describes our practices in connection with Personal Data we collect, handle and process through your individual use of the following services, products, and related mobile applications (collectively, the “Services”): Aquaporin application.
Before you use our Services, please carefully read through this Policy and understand our purposes and practices of collection, processing of your Personal Data, including how we use, store, share and transfer Personal Data. In the Policy you will also find ways to execute your rights of access, update, delete or protect your Personal Data.
When you accept this Policy, register with your Personal Data, or if you start to use our Services and do not expressly object to the contents of this Policy, we will consider that you fully understand and agree with this Policy.
Definitions
For the purpose of this Policy the following terms shall have the meanings attributed to them herein below:
“Personal Data” means any information generated, collected, recorded and/or stored, electronically or otherwise, that can be used alone or together with other data, to uniquely identify any living human being. Personal Data includes name, emails, addresses, phone numbers, location data, IP-addresses, unique IDs, search and browser history, etc. related to you personally.
“Aquaporin Products” refers to an electronic device that connects to other devices or networks using a wireless connection, including Aquaporin drinking water products.
“App” or “Software” refer to that mobile application developed by Aquaporin that provides end users remote control to Aquaporin Products and with the ability to connect to the supplier IoT Platform.
What Personal Data do we collect?
When you use our Services, we will ask you to submit necessary Personal Data that is required to provide those Services. If you do not submit your Personal Data, we may not be able to provide you with our Services.
1. Information you voluntarily provide us:
• Registered account data: When you register an account with us, we may collect your name and contact details, such as your email address, phone number, user name, and login credentials. During your interaction with our Services, we may further collect your nickname, profile picture, country code, language preference or time zone information into your account.
• Feedback: When using feedback and suggestion features in Services, we will collect your email address, mobile phone number and your feedback content to address your problems and solve device failures on a timely basis.
Information based on additional functions
In order to offer you more convenient and higher-quality Services with optimized user experiences, we may collect and use certain information if you consent to use additional functions in the App. Please note, if you do not provide such information, you may continue to use basic Services of the App and connected Aquaporin Products, but certain features based on these additional functions may not be available. These additional functions may include:
1. Additional functions based on the location information:
When you enable the location-based functions through permission settings on your mobile device, we will collect and process your location information to enable such function as pairing with your Aquaporin Products. Also, we may collect information about your: a) real-time and precise location, for instance when you choose to use the automation scenarios for controlling your Aquaporin Products, or b) non-precise geo-location that shows where the App is located when you use certain Aquaporin Products or the Services.
Based on your consent, when you enable the geo-fence feature, your location information will be generated and shared with Google Maps services. Please note that Google has corresponding data protection measures, which you may refer to Google’s Data Processing and Security Terms for more details.
You may disable the collection and use of your location information by changing your mobile device settings, upon which we will cease to collect and use your location information. Please learn how to disable the collection and use of your location information for iOS and Android on the Internet.
2. Additional functions based on camera:
You may use the camera to scan the code by turning on the camera permission to pair with an Aquaporin Product, take video, etc. Please be aware that even if you have agreed to enable the camera permission, we will only obtain information when you actively use the camera for scanning codes, video recording, etc.
You may opt-out the using of camera permission. Please learn how to do it for iOS and Android on the Internet.
3. Additional functions for accessing and uploading pictures/videos based on photo albums (picture library/video library):
You can use this function to upload your photos/pictures/videos, after turning on the photo album permission, in order to change the avatar, report device usage problems by providing photo proofs, etc. When you use the photos and other functions, we will not recognize this information; but when you report a device usage problem, we may use the photos/pictures you upload to locate your problem.
You may opt-out the using of photo album permission. Please learn how to do it for iOS and Android on the Internet.
4. Additional functions related to microphone permission:
You can use the microphone to send voice information after turning on the microphone permission, such as shooting videos, waking up the voice assistant, etc. For these functions, we will collect your voice information to recognize your command. Please be aware that even if you have agreed to enable the microphone permission, we will only obtain voice information through the microphone when you voluntarily activate the microphone in the App.
You may opt-out the using of microphone permission. Please learn how to do it for iOS and Android on the Internet.
5. Additional functions based on storage permission (Android):
The purpose is to ensure the stable operation of the App by utilizing the storage permission. After you give or indicate the permission to read/write your mobile device’s storage, we will access pictures, files, crash log information and other necessary information from your mobile device’s storage to provide you with functions, such as information publications, or record the crash log information locally.
You may opt-out the using of storage permission. Please learn how to do it for Android on the Internet.
6. Additional functions based on notification permission:
The reason why we ask you for the permission is to send you notifications about using the Aquaporin Products or Services, and you require an alert or message so that you can capture the real-time status.
You may opt-out the using of notification permission. Please learn how to do it for iOS and Android on the Internet.
7. Additional functions based on alert window permission:
You may choose to bind a camera in the App and require the App to display the real-time image of the camera in a separate window.
You may opt-out the using of alert window information. Please learn how to do it for iOS and Android on the Internet.
8. Additional functions based on Bluetooth permission:
You can enable Bluetooth functions after turning on the permission, including controlling the Aquaporin Products, acquiring status of, discovering and configuring Aquaporin Products. In these functions, we will communicate with Aquaporin Products via Bluetooth. Please be aware that even if you have agreed to enable the Bluetooth permission, we will only use Bluetooth for communication in these scenarios: display device status on the home page and Aquaporin Product panel; perform device control on the home page and Aquaporin Product panel; discovering Aquaporin Products on the home page and the add device page, Aquaporin Product distribution network.
You may opt-out the using of Bluetooth. Please learn how to do it for iOS and Android on the Internet.
9. Additional functions based on HomeKit permission (iOS):
You can enable related functions after enabling HomeKit permissions, including discovering Aquaporin Products, enabling Aquaporin Product network configuration, controlling Aquaporin Products, and checking Aquaporin Product status. Among these functions, we will process data with the "Home“ app that comes with the iOS system through HomeKit. Please be aware that even if you have agreed to enable the HomeKit permission, we will only use it in these scenarios: on the home page, to discover HomeKit devices, HomeKit device network configuration; in "Settings - HomeKit" for discovering HomeKit devices, HomeKit device network configuration.
You may opt-out the using of HomeKit permission. Please learn how to do it for iOS on the Internet.
Please note that if you turn on any permissions described above, you authorize us to collect and use relevant Personal Data to provide you with corresponding Services. Once you turn off any permissions, we will take it as canceling the authorization, and we will no longer continue to collect Personal Data based on the corresponding permissions, and the related functions may be terminated. However, your decision to turn off the permission will not affect the previous collection and use of information based on your authorization.
2. Information we collect automatically:
• Mobile device information: When you interact with our Services, in order to provide and maintain the normal operation of our Services, to improve and optimize our Services, and to protect your account security, we automatically collect mobile device information, such as mobile device model number, IP address, wireless connection information, the type and version of the operating system, application version number, push notification identifier, log files, and mobile network information. Meanwhile, we will collect your software version number. In order to ensure the security of the operating environment or to provide Services, we will collect information about the installed mobile applications and other software you use.
• Usage data: During your interaction with our websites and Services, we automatically collect usage data relating to visits, clicks, downloads, messages sent/received, and other usage of our websites and Services.
• Log information: When you use the App, in order to improve your user experience, the system and exception log may be uploaded, including your IP address, language preference setting, operating system version, date or time of access, so that we can facilitate and accurately identify problems and help you solve them in timely manner.
Please note that we cannot identify a specific individual by using device information or log information alone. However, if these types of non-personal information, combined with other information, may be used to identify a specific individual, such information will be treated as Personal Data. Unless we have obtained your consent or unless otherwise provided by data protection laws and regulations, we will aggregate or desensitize such information.
3. Aquaporin Products related information:
• Basic information of Aquaporin Products: When you connect your Aquaporin Products with the Services, we may collect basic information about your Aquaporin Products such as device name, device ID, online status, activation time, firmware version, and upgrade information.
• Information collected during the process of connecting to an Aquaporin Product: Based on the type of Aquaporin Product you need to connect, the basic information collected includes Wi-Fi information, device MAC address, etc.
• Information reported by Aquaporin Products: Depending on the different Aquaporin Products you elect to connect with our Services, we may collect different information reported by your Aquaporin Products. For example, water usage, TDS levels of in and outlet, temperature, filter lifetime.
• Information collected during the process of using camera: smart cameras may collect images, videos and/or QR codes taken by them.
Purpose and legal basis for processing Personal Data
The purposes for which we may process information about you are as follows:
• Provide you with our Services: We process your account data, mobile device information, usage data, location information, and Aquaporin Product related information to provide you with the Services that you have requested. The legal basis for this processing is to perform our contract with you according to End-user and Service Agreement.
• Improve our Services: We process your mobile device information, usage data, location information and Aquaporin Product related information to ensure the functions and safety of the Services, to develop and improve the Services, to analyze the efficiency of our operations and to prevent and trace fraudulent or inappropriate usage. The legal basis for this processing is to perform our contract with you according to our End-user and Service Agreement.
• Non-marketing communication: We process your Personal Data to send you important information regarding the Services, changes to our terms, conditions, and policies and/or other administrative information. At the same time, we will also send you notifications related to the Services you have purchased, such as alert Services. You can check the “App Notification” in the App ("Me &rt; Message Center &rt; Setting &rt; Notification Settings”) to manage these communications. When you decide not to enable the notification function, we will no longer process your information for such purpose. The legal basis for this processing is to perform our contract with you according to our End-user and Service Agreement.
• Data analysis: In order to analyze the usage of our Services we provide and improve your user experience, we will analyze the data you provide us, a) we need to check your problems when you encounter any malfunctions during the usage of the Services, under such circumstance, you may not able to opt-out because it is highly relate to your functionalities and quality of using our Services, and b) analyze data about how you interface with the Services or under particular scenarios so that you can better enjoy the convenience brought by our Services, under such circumstance, if you do not agree to data analysis of your data, you can enter the privacy settings of App (“My &rt; Settings &rt; Privacy Permission Settings &rt; Data Analysis”) to opt-out your selection. The legal basis for such processing is based on your consent.
• Marketing communication personalization: We may process your account data, usage data, device information to personalize Services design and to provide you with Services tailored for you, such as recommending and displaying information and advertisements regarding Services suited to you, and to invite you to participate in surveys relating to your use of the Services. If you do not allow us to process your Personal Data for personalization, you may opt out when you enter the App, or by changing your preferences in “Privacy Settings” (“Me&rt; Settings &rt; Privacy Permission Settings &rt; Personalization”) in the App. The legal basis for this processing is your consent.
• Legal compliance: We disclose information if we are legally required to do so, or if we have a good faith belief that such use is reasonably necessary to:
o comply with a legal obligation, process or request;
•
o enforce our End-User and Service Agreement and other agreements, policies, and standards, including investigation of any potential violation thereof;
•
o protect the rights, property or safety of us, our users, a third party or the public as required or permitted by law; or
•
o detect, prevent or otherwise address security, fraud or technical issues.
If there is any change in the purposes for processing your Personal Data, we will inform you about such change via email and/or a prominent notice on our website of such changes of purposes, and choices you may have regarding your Personal Data.
Who do we share the Personal Data with?
At Aquaporin, we only share Personal Data in ways that we tell you about. We may share your Personal Data with the following recipients:
• Our third-party service providers who perform certain business-related functions for us, such as website hosting, data analysis, payment and credit card processing, infrastructure provision, IT services, customer support service, e-mail delivery services, and other similar services to enable them to provide services to us.
• Our customers and other business partners who provide you, directly or indirectly, with your Aquaporin Products, and/or networks and systems through which you access and use our websites and Services.
• Subsidiaries or affiliates within our corporate family for purpose of regular business activities based on our instructions and in compliance with applicable law, this Policy and other appropriate confidentiality and security measures.
• An affiliate or other third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including without limitation in connection with any bankruptcy or similar proceedings). In such an event, you will be notified via email and/or a prominent notice on our website of any change in ownership, and choices you may have regarding your Personal Data.
• As we believe in good faith that access to, or use, preservation, or disclosure of the information is reasonably necessary or appropriate to:
o
a. comply with applicable law, regulation, legal process, or lawful governmental request;
b. enforce our End-User and Service Agreement and other agreements, policies, and standards, including investigation of any potential violation thereof;
c. protect our operation and business systems;
d. protect the rights, property or safety of us, our users, a third party or the public as required or permitted by law; or
e. perform risk management, screening and checks for unlawful, fraudulent, deceptive or malicious activities.
Except for the third parties mentioned above, we only disclose your Personal Data to other third parties with your consent.
International transfer of information collected
Aquaporin will comply with applicable data localization requirements in corresponding jurisdictions with respect to storage of data. To facilitate our operation, we may transfer, store and process your Personal Data in jurisdictions other than where you live. Laws in these countries may differ from the laws applicable to your country of residence. When we do so, we will ensure that an adequate level of protection is provided for the information by using the following approach:
• contractual arrangements with the recipient of the personal data on the basis of approved EU standard contractual clauses per GDPR Art. 46. For more information, see https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
If you would like further detail on the safeguards we have in place, you can contact us directly as described in this Policy.
Your rights relating to your Personal Data
We respect your rights and control over your Personal Data. If we process your Personal Data you may exercise any of the following rights:
• Request access to the Personal Data that we process about you: "My-Setting-Privacy Policy Management-Personal Data Export";
• Request that we correct inaccurate or incomplete Personal Data about you: 1) Modify your account number (email address or phone number): "Me &rt; Setting &rt; Account and Security &rt; Change your Account"; 2) Modify the nickname and/or time zone: "Me &rt; Personal Information";
• Request deletion of Personal Data about you: "Me &rt; Setting &rt; Account and Security &rt; Delete Account", when you confirm the deletion of your account, your Personal Data will be deleted accordingly;
• Request restrictions, temporarily or permanently, on our processing of some or all Personal Data about you: Please send over your request through "Me &rt; FAQ & Feedback", or send over the email request to iot@aquaporin.com;
• Request transfer of Personal Data to you or a third party where we process the data based on your consent or a contract with you, and where our processing is automated: Please send over your request through "Me &rt; FAQ & Feedback", or send over the email request to iot@aquaporin.com;
• Opt-out or object to our use of Personal Data about you where our use is based on your consent or our legitimate interests.
Withdrawal of consent: We will exercise your privacy right to withdraw consent through the following approaches:
1. For privacy permissions acquired through device system settings, your consent can be withdrawn by changing device permissions, including location, camera, photo album (picture library/video library), microphone, Bluetooth settings, notification settings and other related functions.
2. You may opt-out the non-marketing communication through “Me &rt; Message Center &rt; Settings” to manage your selection;
3. You may opt-out the data analysis features through “Me &rt; Settings &rt; Privacy Permission Settings”;
4. You may opt-out the personalization feature through “Me &rt; Settings &rt; Privacy Permission Settings &rt; Personalization”;
5. Unbind the Aquaporin Product through the App, and the information related to the Aquaporin Product will not be collected;
6. If you previously agreed to associate App account with a third-party service, such as a health platform, please unbind it on the third-party platform.
When you withdraw your consent or authorization, we may not be able to continue to provide you with certain Services correspondingly. However, your withdrawal of your consent or authorization will not affect the processing of Personal Data based on your consent before the withdrawal.
About Deletion of the account: You can find the delete function through “Me &rt; Settings &rt; Account and Security &rt; Delete Account (Deactivate Account)”.
Security measures
We use commercially reasonable physical, administrative, and technical safeguards to preserve the integrity and security of your Personal Data. Aquaporin provides various security strategies to effectively ensure data security of user and device. As for device access, Aquaporin proprietary algorithms are employed to ensure data isolation, access authentication, applying for authorization. As for data communication, communication using security algorithms and transmission encryption protocols and commercial level information encryption transmission based on dynamic keys are supported. As for data processing, strict data filtering and validation and complete data audit are applied. As for data storage, all confidential information of users will be safely encrypted for storage. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), you could immediately notify us of the problem by emailing to: iot@aquaporin.com.
Data retention
We process your Personal Data for the minimum period necessary for the purposes set out in this Policy, unless there is a specific legal requirement for us to keep the data for a longer retention period. We determine the appropriate retention period based on the amount, nature, and sensitivity of your Personal Data, and after the retention period ends, we will destruct your Personal Data.
• For as long as you require us to fulfill the Services you request from us as defined in the End-User and Service Agreement;
• Personal Data will no longer be retained when you request to remove your Personal Data, we will accordingly complete the task.
When we are unable to do so for technical reasons, we will ensure that appropriate measures are put in place to prevent any further such use of your Personal Data.
Children’s privacy
Protecting the privacy of young children is especially important to us. The Services are not directed to individuals under the age of thirteen (13) (or such other age provided by applicable law in your country/region of residence), and we request that these individuals do not provide any Personal Data to us. We do not knowingly collect Personal Data from any child unless we first obtain permission from that child’s parent or legal guardian. If we become aware that we have collected Personal Data from any child without permission from that child’s parent or legal guardian, we will take steps to remove that information.
Changes to this Policy
We may update this Policy to reflect changes to our information practices. If we make any material changes, we will notify you by email (send to the e-mail address specified in your account) or by means of a notice in the App prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
Contact Us
If you have any questions about our practices or this Policy, please contact us as follows:
Aquaporin A/S
Nymøllevej 78, DK-2800 Kongens Lyngby, Denmark
Email: iot@aquaporin.com