MOVAhome Privacy Policy

Introduction

“MOVAhome” is a platform (or service) operated by Dreame Innovation Technology (Suzhou) Co., Ltd. and its affiliates (hereinafter referred to as “we”, “us”, “our”, or “Dreame”) to provide you with smart hardware device control and management services.

We understand and are fully aware of the importance of personal data to you, and we will do our best to protect the security of your personal data. We are committed to maintaining your trust in us and protecting your personal data by abiding by the principles of lawfulness, legitimacy, necessity and good faith, consistency of rights and responsibilities, clear purpose, selective consent, minimum sufficiency, security assurance, subject participation, and openness and transparency. We promise to adopt security protection measures to protect your personal data in accordance with industry-recognized security standards. This Privacy Policy sets out how we process the information you provide to us when you use our app.

Please read and understand this policy carefully before using our products (or services). If you have any questions, please contact us via any of the contact methods described in “Contact us” of this Privacy Policy. Our dedicated privacy department and personnel will reply to you within the time frame required by each country's policies and laws.

This Privacy Policy will help you understand:

I.How We Collect and Use Your Personal Data

II. How We Use Cookies and Similar Technologies

III. How We Share Your Personal Data

IV. How We Retain and Secure Your Personal Data

V. Your Rights

VI. Protection of Minors

VII Transfer of Personal Data Between Countries

VIII. Contact Us

IX. Update of This Privacy Policy

I. How We Collect and Use Your Personal Data

Personal data refers to all kinds of information recorded electronically or in other ways that are related to an identified or identifiable natural person, excluding anonymized information.

(i) Collection and Processing of Your Personal Data for Basic Services of MOVAhome

Personal data is collected for the purpose of providing you with products and/or services. We promise to comply with the relevant applicable laws, regulations and other regulatory documents. In the following cases, you need to give consent to provide the following categories of information, such that we can safely and effectively implement the basic functions. Otherwise, you may not be able to enjoy the corresponding products and services.

1. Signup and Login on MOVAhome

When you want to sign up or log in to MOVAhome, you are required to provide us with your phone number/email/third-party account that is availiable to register MOVAhome.

2. Maintenance of MOVAhome Account Information

In order to help you update your account information, you can provide us information related to your account, such as your avatar, nickname and other necessary information.

3. Connection and Management of Smart Hardware Devices

Your login information, as well as information related to your phone, smart hardware device, Wi-Fi and Bluetooth information may be collected to provide you with MOVAhome services and enable you to securely connect and manage your smart hardware device. This information will be used to provide you with quick smart hardware device connection, as well as device connection and management functions. In the process of connecting devices, we need to enable your mobile phone's Bluetooth permission and WLAN permission for device communication and your mobile phone location permission to scan nearby devices and obtain the WiFi information currently connected to your mobile phone.

4. Updates to MOVAhome App and Smart Hardware Device

We may use the version information of your MOVAhome app and phone model to provide you with updates to the MOVAhome app, so that you can continue to enjoy the latest MOVAhome services. We may also collect the list and version information of the connected smart hardware device to provide you with updates to your smart hardware device, to ensure that you can use the service provided in the latest version (including the firmware version). MOVAhome only provides the update path for the smart hardware device. The firmware version is provided by the manufacturer of the smart hardware device, and the manufacturer shall be responsible for the version quality and update results. If you fail to provide this information, you will not be able to update to the new versions of the MOVAhome app and smart hardware device firmware.

(ii) Collection and Processing of Your Personal Data for Additional Functions of MOVAhome

In addition to the basic services of MOVAhome, we may also collect and use your personal data in the following additional functions. If you fail to provide such information, you may still use the basic services of MOVAhome, but it may be impossible for you to use the additional functions that could be convenient for you. The additional functions include:

1. Device Sharing

When you use the device sharing feature to share your device with a friend, we may collect your friend's MOVAhome account information and information about the device you are sharing. Please note that when you use the device sharing feature, the shared user may also view your device information in their app interface at any time. To protect the security of your personal data, some personal data involved in certain devices may not be shared, depending on the device you are sharing.

2. Online Feedback

We provide you with an online feedback channel to help you effectively solve any potential problems you might have with your MOVAhome app and smart hardware device. To this end, we need to collect the following information from you: Log information of MOVAhome app and device, your contact information, problem description, and pictures and videos about the problem. The purpose of collecting such information is to analyze and locate the cause of the problem. The purpose of collecting your contact information is to follow up and check if the problem is fully resolved or to contact you to supplement additional information as necessary.

Your personal data will be used only for locating and solving the problem, and will not be displayed or used for pushing commercial advertisements. If you fail to provide such information, it will be impossible for us to effectively locate and solve your problem.

3. Marketing Information Displaying and Pushing

We may provide or promote marketing information for our products and service on the app launch page, homepage, or pop-up ads (which you can close with one click), send or display relevant messages to your app. After obtaining your authorization, we may send marketing messages to you via SMS, phone, and/or email using the contact information provided by you, such as phone number and email. You may choose to refuse such marketing messages at any time.

4. User Experience Program

In order to enhance the operational experience, operational performance, and functional design of our products, and provide better products and services to users, we invite you to participate in our User Experience Program. You agree that when you join the User Experience Program, you have carefully read and fully agreed to this program.

When you participate in our User Experience Program, we may collect your device information; relevant log information after the device turns abnormal; relevant data of negative events such as device collision. We collect such information to help us improve our products and services and provide you with a better user experience. If you do not provide the above information, it will not affect your use of the product, but it may affect your user experience.

You understand and agree that when you join this program, your above information will be transmitted to our R&D center in China for processing. We will store your personal data in accordance with applicable laws or regulations and keep it for as long as it is necessary to meet the purpose of personal data collection.

We promise to use the data provided by you in strict accordance with the requirements of laws and regulations, and take strict protective measures to ensure the security of your data. You can join or withdraw from the User Experience Program at any time through "Me" - "Settings" - "About" - "User Experience Program".

(iii) Obtaining Your Personal Data from Third Parties

We may obtain your personal data from third parties in some cases where permitted by law. For example:

1. In the management of third party smart hardware devices, we will cooperate with third party service providers subject to your authorization, which involves us obtaining your personal data from the third party service providers. In the management of third party devices, we will obtain the following personal data about you under the condition that you have linked to a third party account:

Information of the third party account, including the account ID, nickname and avatar, depending on the scope of your authorization.

Device and network information, including device identifier, MAC address, and device serial number, used to identify the device currently in operation and security control of the device.

If our processing of your personal data required in the course of our business is beyond the scope of the consent you originally authorized when you provided your personal data to a third party service provider, we will obtain your express consent before processing such personal data. In addition, we will strictly comply with relevant laws and regulations and require third party service providers to guarantee the legality of the information they provide.

(iv) Non-personal Data

We may also collect other information that could not identify a specific individual (i.e., non-personal data), for example, statistical data generated when you use a specific service, such as user actions (including clicks, page redirection, browsing time). The purpose of collecting such information is to improve the service we provide to you. The type and amount of information collected depends on how you use our products and/or services. Such information will be aggregated to help us provide more useful information to our customers and learn about which parts of our website, products and services are of most interest to them, so that our service interface can be optimized. Aggregated data is considered non-personal data for the purposes of this Privacy Policy. If non-personal data is used in combination with personal data, such information will be treated as personal data during the period of combined use.

(v) System Permissions Description

For the purpose of product function implementation and safe and stable operation, we may request or use relevant system permissions, such as camera, album and location permissions. Please be assured that these permissions will not be enabled by default, and we will only request the relevant permissions from you and obtain the corresponding information (if involved) when you trigger the relevant business function. The permissions we request are only necessary to implement specific features, and you may revoke authorization of system permissions at any time. If you refuse or revoke your authorization of system permissions, you will not be able to use the corresponding features, but this will not affect your normal use of other features.

II. How We Use Cookies and Similar Technologies

We may store small data files called cookies on your device to ensure the proper functioning of MOVAhome. Cookies usually contain identifiers, site names, and some numbers and characters. MOVAhome can use cookies to store your login account, preferences and other data to simplify steps for your repetitive operations (such as signup and login) and provide you with services that are more suitable for your personal needs.

We will not use cookies for any purpose other than those specified in this declaration. You may manage or delete cookies according to your preferences. If you do so, however, in some cases this may affect your safe access to MOVAhome and you may have to change the user settings each time you access MOVAhome.

III. How We Share Your Personal Data

Dreame may share personal data with Dreame-affiliated companies, service providers who act on our behalf, our partners, developers, and publishers, or others at your direction. Further, Dreame does not share personal data with third parties for their own marketing purposes.

  1. Service Providers. Dreame may engage third parties to act as our service providers and perform certain tasks on our behalf, such as processing or storing data, including personal data, in connection with your use of our services and delivering products to customers. Dreame service providers are obligated to handle personal data consistent with this Privacy Policy and according to our instructions. They cannot use the personal data we share for their own purposes and must delete or return the personal data once they’ve fulfilled our request.
  2. Partners. At times, Dreame may partner with third parties to provide services or other offerings. For example, some websites are offered by Dreame and our partners. Dreame requires its partners to protect your personal data.
  3. Dreame’s Subsidiaries or Affiliates. Dreame is an international company, to carry out business activities on a regular basis or to provide you better service and products, we may have to share personal data with our subsidiaries or affiliates.
  4. Others. Dreame may share personal data with others at your direction or with your consent, such as when we share information with your carrier to activate your account. We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate. We may also disclose information about you where there is a lawful basis for doing so, if we determine that disclosure is reasonably necessary to enforce our terms and conditions or to protect our operations or users, or in the event of a reorganization, merger, or sale.

Dreame does not sell your personal data including as “sale” is defined in Nevada and California. Dreame also does not “share” your personal data as that term is defined in California.

IV. How We Retain and Secure Your Personal Data

(i) Where We Retain Your Personal Data

Currently, Dreame runs data centers worldwide. Your personal data is stored in the server according to the region you live. If you are Europe Union user under General Data Protection Regulation (hereinafter referred to as “GDPR”), your personal data will be stored in the German server.

(ii) Storage Period

We retain personal data for a period for the sake of information collection described in this Policy, or we do so in compliance with locally applicable relevant legal requirements. After fulfilling the purpose of personal data collection, or after we confirm your application of deletion or cancellation, or after we terminate the operation of corresponding products or services, we will stop retaining personal data and delete or anonymize it. If it is for the purpose of public interest, scientific, historical research or statistics, we will continue to retain relevant data based on applicable laws, even if further data processing is irrelevant to the original purpose.

(iii) Our Protection Measures

We are committed to guaranteeing the security of your personal data. To prevent unauthorized access, disclosure or other similar risks, we have implemented reasonable processes of physical, electronic and supervisory measures to protect the information we collect from your products and the Dreame website. We will take all reasonable measures to protect your personal data.

Your data will be classified according to importance and sensitivity, and your personal data will be protected with the highest level of security. We guarantee that employees and third party service providers who access this information to help provide products and services to you have strict contractual confidentiality obligations; otherwise, they will be subject to disciplinary action or termination of cooperation. In summary, we will regularly review information collection, retention and processing practices, including physical security measures, to prevent any unauthorized access and use.

We will take all feasible measures to protect your personal data. However, you should be aware that the use of information via the Internet is not always secure. Therefore, we cannot guarantee the security or integrity of any personal data transmitted bidirectionally over the Internet.

V. Your Rights

You have the right to exercise rights in relation to any personal data that we hold about you (hereinafter referred to as requests) in accordance with the applicable national or regional laws and regulations. Most laws require that requests made by subjects of personal data be subject to specific requirements. In this Privacy Policy, your requests should comply with the following requirements:

1. For the purpose of protecting the security of your information, your requests should be in writing (unless oral requests are expressly recognized by local laws) and made through our dedicated request channel.

2. You need to provide sufficient information to enable us to verify your identity and ensure that the person making the requests is the subject of the requested information or is their legally authorized person.

We reserve the right to refuse to process meaningless/entangled repetitive requests, or requests for inappropriate technical tasks, or requests that compromise the privacy of others, or requests that are extremely impractical, or requests that are not required to be granted under local law. We may also reject some aspects of your requests if we believe that they may prevent us from using the data lawfully for the aforementioned anti-fraud and security purposes.

Once we have sufficient information to confirm that your requests can be processed, we will respond to your requests within the time period specified by applicable data protection laws.

You may exercise your right to know, access, correct, transfer, restrict the processing of, and delete your personal data by contacting us at privacy@dreame.tech or via the app.

There may be situations where we cannot grant your request — for example, if you ask us to delete your transaction data and Dreame is legally obligated to keep a record of that transaction to comply with law. We may also decline to grant a request where doing so would undermine our legitimate use of data for anti-fraud and security purposes, such as when you request deletion of an account that is being investigated for security concerns. Other reasons your privacy request may be denied are if it jeopardizes the privacy of others, is frivolous or vexatious, or would be extremely impractical or unreasonable.

(i) Rights under GDPR

If you are Europe Union user under GDPR, you can exercise the following rights:

1. The right to obtain from us the erasure of your personal data. We shall consider the grounds regarding your erasure request and take reasonable steps, including technical measures, if the grounds apply to GDPR.

2. The right to obtain from us the restriction of processing your personal data. We shall consider the grounds regarding your restriction request. If the grounds apply to GDPR, we shall only process your personal data under applicable circumstances in GDPR and inform you before the restriction of processing is lifted.

3. The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

4. The right to receive your personal data in a structured, commonly used format and transmit the information to another data controller.

If you are Europe Union user under GDPR, Dreame will provide systematic approach to manage personal data deeply engages our people, management processes and information systems by applying a risk management methodology. According to the GDPR, for instance, (1) Dreame set up a Data Protection Officer (DPO) in charge the data protection, and the contact of DPO is dpo.sg@dreame.tech; (2) Dreame Information designate a representative in Europe, and the contact of representative is representative.dreame@herrero.es; (3)procedure like data protection impact assessment (DPIA).

(ii) Rights under CCPA/CPRA

If you are a California resident and the California Consumer Privacy Act of 2018 (hereinafter referred to as “CCPA”) and The California Privacy Rights Act (hereinafter referred to as “CPRA”) do not recognize an exemption that applies to you or your personal data, you have the right to:

1. Request we disclose to you free of charge the following information covering the 12 months preceding your request:

(1) the categories of personal data about you that we collected;

(2) the categories of sources from which the personal data was collected;

(3) the purpose for collecting personal data about you;

(4) the categories of third parties to whom we disclosed personal data about you and the categories of personal data that was disclosed (if applicable) and the purpose for disclosing the personal data about you; and

(5) the specific pieces of personal data we collected about you.

2. Request we delete personal data we collected from you, unless CCPA/CPRA recognizes an exemption.

3. Be free from unlawful discrimination for exercising your rights including providing a different level or quality of services or deny goods or services to you when you exercise your rights under the CCPA/CPRA.

4. Have the right to opt out of certain uses and disclosures of your personal data. Where you have consented to Dreame’s processing of your personal data, you may withdraw that consent at any time and opt-out to further processing by contacting Dreame. In order to provide our services to you, we will ask you to provide personal data that is necessary to provide those services to you. If you do not provide your personal data, we may not be able to provide you with our products or services. Even if you opt-out, we may still collect and use non-personal data regarding your use of our products.

5. Do Not Track. Dreame does not track its customers over time and across third-party websites to provide targeted advertising and therefore does not respond to Do Not Track (DNT) signals. Third parties that have content embedded on Dreame’s websites such as a social feature or a stock ticker may set cookies on a user’s browser and/or obtain information about the fact that a web browser visited a specific Dreame website from a certain IP address. Third parties cannot collect any other personal information from Dreame’s websites unless you provide it to them directly.

We aim to fulfill all verified requests within 45 days pursuant to the CCPA/CPRA. If necessary, extensions for an additional 45 days will be accompanied by an explanation for the delay.

VI. Protection of Minors

We believe that it is the responsibility of parents to monitor their children's use of our products and services. However, our policy does not require the collection of personal data of minors or sending any promotional materials to them.

Dreame will not seek or attempt to seek to receive any personal data from minors. If a parent or guardian has reason to believe that a minor has submitted personal data to Dreame without their prior consent, please contact us to ensure that such personal data is deleted and that the minor unsubscribes from any applicable Dreame services.

VII. Transfer of Personal Data Between Countries

Dreame products and offerings connect you to the world. To make that possible, your personal data may be transferred to or accessed by entities around the world, including Dreame-affiliated companies, to perform processing activities such as those described in this Privacy Policy in connection with your use of our products and services. To the extent that we may need to transfer personal data outside of your jurisdiction, we shall do so in accordance with the applicable laws. In particular, we will ensure that all transfers will be in accordance with requirements under your applicable local data protection laws by putting in place appropriate safeguards. You will have the right to be informed of the appropriate safeguards taken by Dreame for this transfer of your personal data.

VIII. Contact Us

If you have any comments or questions about this Privacy Policy, or about our collection, use or disclosure of your personal data, please contact us via the contact information below. We will respond to you within 30 days after verifying your user status. Our professional team will resolve your requests, questions and problems related to your personal data. If your question involves significant matters, we may ask you to provide more information. If you are not satisfied with our response, you can make a complaint to the relevant regulatory authority in your jurisdiction. If you consult us about complaint channels, we will provide you with applicable information based on your actual situation.

Email address: privacy@dreame.tech

Tel.: +86-400-875-9511

Website: https://global.dreametech.com

IX. Updates of This Privacy Policy

Dreame reserves the right to update this Privacy Policy from time to time. In case of any changes, we will inform you via a pop-up message or other prominent means. We will only collect, use and retain your personal data in accordance with the updated policy with your consent.

This policy takes effect from the update date.

Last update date: 2024/6/1