eeKey Privacy Policy
Last Updated: July 06, 2026
Effective Date: July 06, 2026
Preamble
Guangdong HUNE Intelligent Technology Co., Ltd. (hereinafter collectively referred to as “Us”, “We” or “Our”) fully recognizes the critical value of your Personal Information and shall implement comprehensive measures to guarantee its security and integrity. We commit to safeguarding your trust by abiding by the core principles governing personal data protection, namely consistency of rights and obligations, clear purpose limitation, informed consent, data minimization, security assurance, data subject participation, openness and transparency, and other applicable statutory principles. Meanwhile, We undertake to deploy industry-standard technical and organizational safeguards to protect your Personal Information in compliance with prevailing cybersecurity and data protection regulations.
This Privacy Policy (the “Policy”) governs all Products and Services supplied by Us. Please read and fully comprehend all provisions herein prior to accessing or utilizing Our Products and Services. Should you have any inquiries regarding this Policy, please contact Us via the channels specified in Section X below.
This Policy sets forth the following key matters for your reference:
- Modes and Purposes of Our Collection and Processing of Your Personal Information
- Permissible Scenarios for the Utilization of Collected Personal Information
- Rules Governing the Sharing of Your Personal Information
- Technical and Organizational Safeguards for Your Personal Information
- Statutory Rights Held by You in Respect of Your Personal Information
- Retention Periods of Personal Information
- Handling Rules for Minors’ Personal Information
- Cross-Border Transmission Mechanisms for Personal Information
- Amendment Rules for This Policy
- Contact Information for Inquiries
I. Collection and Processing of Your Personal Information
“Personal Information” means all information recorded by electronic or other means that identifies or is capable of identifying a specific natural person. We collect Personal Information solely to deliver contracted Products and Services and to comply with applicable laws, administrative regulations and normative documents. You reserve the right to choose whether to provide such data; however, failure to furnish required Personal Information may render Us unable to provide corresponding functional support or resolve your service requests. The categories of data collected are specified as follows:
1. Account and Profile Data
Upon your account registration, We may collect your account identifier and contact details, including email address, mobile phone number, username and login credentials. During your ongoing interaction with Our Products, We may further collect your account nickname, avatar, country/region code, language preference and time zone settings.
2. User Feedback Data
When you submit feedback, complaints or service suggestions to Us, We shall collect the email address, mobile number you submitted together with attached texts, images and video content, for the sole purpose of troubleshooting equipment faults and responding to your requests in a timely manner.
3. Smart Device Connection Data
We may collect Wi-Fi parameters including SSID, BSSID, Wi-Fi MAC address and Wi-Fi password, as well as Bluetooth MAC addresses and unique device IDs of connected smart locks.
4. Mobile Device Metadata
To ensure stable service operation, optimize user experience and secure your account against unauthorized access, We automatically collect device metadata during product interaction, including public IP address, mobile operating system version, device model, wireless connection parameters, push notification identifiers, system language, regional settings, application version, screen dimension and resolution.
5. Third-Party Individuals’ Information
Certain product functionalities require you to submit Personal Information of other natural persons, such as nicknames, email addresses and mobile numbers. Refusal to provide such data will only disable relevant dedicated functions without impairing your access to other core services. By voluntarily submitting third-party Personal Information, you warrant that you have obtained valid consent from the relevant data subjects for Us to process their data in accordance with the purposes and methods stipulated in this Policy.
Appendix: Required System Permissions & Functional Grounds
- Location Permission: Enables Bluetooth device discovery and Wi-Fi network provisioning for smart hardware
- Bluetooth Permission: Establishes communication channels between mobile terminals and Bluetooth smart locks
- Wi-Fi Access & Activation Permission: Facilitates network configuration for connected smart devices
- Phone State Reading Permission: Generates unique local device identifiers on client terminals
- Contacts Access Permission: Allows one-click selection of contact information when adding authorized users
- Camera Permission: Supports QR code scanning for device activation, account sharing and avatar uploading
- Album Storage Permission: Enables avatar upload and local image storage
- General Storage Permission: Permits reading and writing of images, local files and application crash logs
II. Permissible Purposes for Processing Personal Information
All collection and processing activities of Personal Information shall be conducted in compliance with applicable laws to deliver contracted Products and Services. You hereby irrevocably consent to Our processing of your Personal Information for the purposes defined herein, and to disclosure of such data to Our affiliated enterprises (covering communication, social media, technology and cloud service sectors) and authorized third-party service providers as hereinafter specified. We may utilize your Personal Information for the following legitimate purposes: a. Supply, maintain, upgrade and iterate Our hardware Products and mobile Application Services; b. Conduct official communications with you regarding equipment firmware upgrades, software updates, technical support inquiries and service notifications; c. Carry out authorized marketing and promotional activities, and distribute corresponding promotional materials (see the “Direct Marketing” clause for supplementary details); d. Compile anonymized statistical data on product usage to optimize service architecture and user experience; e. Archive and retain relevant data to fulfill business operation obligations and statutory compliance requirements; f. Deliver offline local functional services without real-time server synchronization.
III. Sharing Rules for Your Personal Information
We shall not disclose your Personal Information to any external enterprises, organizations or individuals, save for the following legally permitted circumstances:
- Sharing with your explicit, informed written consent;
- Mandatory disclosure required by applicable laws, administrative regulations or compulsory orders issued by competent government authorities;
- Sharing with authorized service partners: Certain functional modules are delivered by Our designated partners. We shall only share the minimum volume of Personal Information necessary to fulfill the agreed service objectives, and all data processing activities by such partners shall be restricted strictly to the purposes outlined in this Policy. All authorized partners shall enter into binding data protection agreements with Us to enforce equivalent security standards.
The complete list of authorized push service third parties, together with official website links and privacy policy hyperlinks, are set forth below:
1. Alibaba EMAS Mobile Push
2. Xiaomi Push
- Categories of collected data: Device identifiers (IMEI, Android ID, MEID, OAID, Serial Number, UUID), WLAN hotspot information
- Processing purpose: Push message delivery to Xiaomi devices
- Service scenario: Official notification push for Our mobile application on Xiaomi mobile terminals
- Responsible entity: Beijing Xiaomi Mobile Software Co., Ltd.
- Data collection method: Embedded SDK automatic collection
- Official portal:
https://dev.mi.com/console/appservice/push.html
- Third-party privacy policy:
https://dev.mi.com/console/doc/detail?pId=1822
3. Huawei Push
4. OPPO Push
- Categories of collected data: Device identifiers (IMEI, SIM serial number, IMSI), application metadata (package name, version, running status), network parameters (IP address, domain resolution results, network type)
- Processing purpose: Push message delivery to OPPO devices
- Service scenario: Official notification push for Our mobile application on OPPO mobile terminals
- Responsible entity: Guangdong Heyta Technology Co., Ltd.
- Data collection method: Embedded SDK automatic collection
- Official portal:
https://open.oppomobile.com/wiki/doc#id=10194
- Third-party privacy policy:
https://open.oppomobile.com/wiki/doc#id=10288
5. Google Push
- Categories of collected data: Device identifiers (IMEI, SIM serial number, IMSI), application metadata (package name, version, running status), network parameters (IP address, domain resolution results, network type)
- Processing purpose: Push message delivery for overseas Android terminals
- Service scenario: Official notification push for Our mobile application on non-Chinese Android devices
- Responsible entity: Google LLC
- Data collection method: Embedded SDK automatic collection
- Official portal:
https://www.google.com
- Third-party privacy policy:
https://policies.google.com/u/1/privacy?hl=en-SG&fg=1
IV. Data Security Safeguards
- We deploy internationally recognized technical and organizational safeguards to prevent unauthorized access, public disclosure, improper utilization, tampering, damage or loss of your Personal Information, including end-to-end encryption, authenticated access control systems, anti-intrusion protection mechanisms and periodic internal data protection training for all staff with data access privileges.
- We adhere to the data minimization principle and refrain from collecting irrelevant or excessive Personal Information. Your data shall only be retained for the shortest period necessary to fulfill the processing purposes herein, unless extended retention is mandated or permitted by applicable laws.
- The public internet cannot be deemed a fully secure transmission medium; emails and instant messaging channels operate without mandatory end-to-end encryption. We strongly advise against transmitting sensitive Personal Information via such channels and recommend complex login passwords to reinforce account security.
- Notwithstanding all reasonable security measures implemented by Us, absolute data security cannot be guaranteed under existing internet technical conditions. You acknowledge and accept the inherent risks of unauthorized access, theft or alteration of Personal Information arising from network vulnerabilities, and agree to bear corresponding liabilities accordingly.
- In the event of any Personal Information security incident, We shall notify you promptly via email, formal letter, telephone or in-app push notifications in compliance with regulatory requirements, disclosing incident details, potential adverse impacts, remedial measures implemented or to be adopted, risk mitigation guidance and available remedies. Where individual separate notification is impracticable, We shall issue a public announcement through reasonable and effective channels. Meanwhile, We shall actively report incident handling progress to competent regulatory authorities as required by law.
V. Your Statutory Rights Over Personal Information
In accordance with the Personal Information Protection Law of the People’s Republic of China, relevant supporting regulations and prevailing international data protection standards, We guarantee your exercise of the following rights to access, rectify, erase or restrict the processing of your Personal Information:
- Right to Access and Rectification: You may submit requests to inspect and correct any incomplete or inaccurate Personal Information stored by Us. We shall conduct identity verification prior to processing your request and respond within the statutory time limits stipulated by applicable data protection laws upon receipt of valid supporting materials.
- Right to Data Copy: We shall provide one free electronic copy of your processed Personal Information upon your initial request. Additional duplicate requests for identical data may incur reasonable administrative fees based on actual operational costs permitted by law.
- Right to Erasure: You may apply for permanent deletion of your account and associated Personal Information via the path: User Icon (Top Left of Homepage) → User Information → Delete Account (Bottom Right), following on-screen prompts. After account deletion is confirmed, legal and backup storage restrictions may prevent instant full data erasure; We shall securely isolate your Personal Information for a minimum of sixty (60) calendar days before irreversible anonymization or permanent deletion of backup records.
- Revocation of Consent: You reserve the right to withdraw prior consent for data processing at any time. Please note that consent revocation may restrict or terminate partial or all functional services dependent on such authorization, without invalidating lawful processing activities completed prior to revocation.
- Handling of User Requests: We impose no fees for reasonable, single requests. Repeated, excessive or unfounded duplicate requests may incur cost recovery charges. We reserve the right to reject requests that demand disproportionate technical transformation, create privacy risks to third parties, or are technically infeasible (e.g. retrieval of archived backup tape data). We may also deny repetitive, vexatious requests or demands that conflict with Our anti-fraud and security compliance obligations.
Statutory Exceptions for Request Refusal
We are legally authorized to decline your requests under the following circumstances:
- Matters directly connected to national security or national defense security;
- Matters directly connected to public safety, public health or major public interests;
- Matters directly connected to criminal investigation, public prosecution, judicial trial or judgment enforcement procedures;
- Sufficient evidence proves you submit requests with malicious intent or abuse statutory data subject rights;
- Fulfillment of your request would cause severe harm to the legitimate rights and interests of you or other natural persons/legal entities.
VI. Personal Information Retention Period
We shall process and store your Personal Information for the minimum duration required to fulfill the processing purposes set forth herein or to satisfy statutory retention obligations. Upon expiry of such periods, all corresponding data shall be securely destroyed or irreversibly anonymized. Retention termination triggers include:
- Full completion of all service and data processing objectives agreed between Us and you;
- Formal confirmation of your account cancellation and data erasure application;
- Permanent suspension or discontinuation of the relevant Products or Services.
If technical limitations prevent immediate full data deletion upon expiry, We shall implement strict isolation controls to block all further utilization of such Personal Information and conduct anonymization processing as soon as technically viable.
VII. Processing of Minors’ Personal Information
Our Products and Services are primarily intended for adult users. Minors under the age of eighteen (18) shall not register independent user accounts without prior explicit consent from their parents or legal guardians.
Where We lawfully collect minors’ Personal Information with verified guardian authorization, We shall only store and utilize such data to protect minors’ legitimate interests or as permitted by applicable laws; all unauthorized minor data shall be erased promptly upon discovery. Due to technical constraints, We cannot actively identify minor users. If you become aware that We have collected minor Personal Information without valid guardian consent, please contact Us immediately for permanent data deletion, except where mandatory legal retention obligations apply.
VIII. Cross-Border Transmission of Personal Information
In principle, all Personal Information collected and generated through Our Products and Services shall be stored within the territory of the People’s Republic of China.
As We operate global server and resource infrastructure, your Personal Information may be transmitted to or accessed by overseas jurisdictions with your explicit prior consent. Such regions may implement divergent or absent data protection legal frameworks. In such cases, We shall deploy equivalent protective mechanisms consistent with Chinese domestic data protection standards, including prior cross-border transmission consent collection and data de-identification anonymization safeguards before any offshore data transfer.
IX. Policy Amendment Statement
We reserve the right to revise or update this Policy periodically. All revised versions shall be published on Our official website with a clear updated date marker. Unless mandatory regulatory provisions specify otherwise, amended clauses shall take effect seven (7) calendar days following official publication. Your continued use of Our Products and Services after the effective date of revised terms shall constitute your full reading, understanding and unconditional acceptance of the updated Privacy Policy.
X. Contact Information
Should you have any questions, comments or suggestions regarding this Policy, please contact Us and reference “eeKey Privacy Policy” in all correspondence: Guangdong HUNE Intelligent Technology Co., Ltd. Address: HUNE High-tech Industrial Park, No.65 Xinxing Road, Jiangmen High-tech Zone, Guangdong Province, P.R.China National Toll-Free Service Hotline: 400-800-8688 Official Email: info@hune.cn