Privacy Policy
Version: V2.0 Last Updated: September 4, 2026
Shenzhen Ultra Easy Technology Co., Ltd. (深圳市优创亿科技有限公司, hereinafter referred to as “Ultra Easy,” “we,” “us,” “our,” or the “Company”) values your privacy and the security of your personal information. This Privacy Policy explains how we collect, use, store, share, transfer, and protect your personal information when providing companion apps for smart wearable devices, cloud services, device connectivity, health and fitness features, data synchronization, data export, and related technical services, as well as how you may exercise your applicable rights.
1. Scope of This Policy
1.1 Multi-Tier OEM / ODM Business Model
Ultra Easy primarily operates as a provider of smart wearable technology solutions, apps, and cloud services. Our technical solutions may pass through one or more OEMs, ODMs, brand owners, distributors, importers, or other commercial partners before ultimately being offered to users under different brands, models, or product combinations.
Accordingly, unless otherwise expressly stated for a specific product or project:
- This Policy is not tied to any particular end-consumer brand;
- This Policy is not tied to any specific hardware model;
- Ultra Easy is not necessarily the brand owner, seller, importer, or manufacturer of the final hardware product;
- The brand, manufacturer, seller, importer, and after-sales service provider of a specific hardware product shall be determined by the product packaging, sales page, in-app notice, or publicly available information of the relevant brand owner.
Ultra Easy may assume different legal roles in different projects depending on the actual data-processing relationship. For example, we may independently determine the purposes and means of certain processing activities, while for other activities we may only provide technical processing services in accordance with lawful instructions from an OEM or brand customer. The specific legal role shall be determined based on the actual project, contractual arrangements, and applicable law.
1.2 General Policy and Product/Regional Supplemental Notices
Because data-processing practices may differ by device, brand, feature, country, and region, we may provide a Product Privacy Notice, Third-Party SDK List, Connected Product and Related Service Data Notice, or other supplemental documents for a specific app, device, feature, or region.
If a supplemental document conflicts with this Policy with respect to a specific product or processing activity, the more specific supplemental document shall prevail for that matter. All non-conflicting provisions of this Policy will continue to apply.
2. Definitions
For purposes of this Policy:
- “Personal Information” means information recorded electronically or by other means that relates to an identified or identifiable natural person. Applicable laws in different regions may use terms such as “personal data,” “Personal Data,” or “Personal Information.”
- “Sensitive Personal Information” means information that, if leaked or unlawfully used, may create a higher risk to an individual’s rights and interests, including medical and health information, precise location or movement trajectories, biometric information, children’s information, and other information within the scope defined by applicable law.
- “Health Data” includes information relating to physical condition, health, exercise, or physiological status that is entered by the user, measured by a smart wearable device, calculated by the app, or read from a third-party health platform with the user’s authorization.
- “Connected Product Data” and “Related Service Data” have the meanings assigned to those terms under Regulation (EU) 2023/2854 (EU Data Act) where that Regulation applies in the European Union / European Economic Area.
3. Information We Collect and Process
The specific data processed depends on the device model, sensor capabilities, firmware version, app version, features actively enabled by the user, account status, and scope of authorization. Not all products process all of the categories listed below.
3.1 Account and Basic Profile Information
When you register, sign in, or manage an account, we may process:
- Mobile phone number;
- Email address;
- Nickname;
- Profile photo;
- Country/region;
- Language;
- Time zone;
- Date of birth or age;
- Gender;
- Height and weight;
- Exercise preferences, goals, and other information you choose to provide.
If you use a third-party sign-in service, we may obtain, within the scope you authorize, the necessary account identifier, nickname, profile photo, email address, or other information required for sign-in that is returned by the third-party platform.
3.2 Health and Body Data
Depending on device and feature support, we may process:
- Heart rate;
- Blood oxygen saturation (SpO₂);
- Blood pressure;
- Body temperature;
- Weight;
- BMI;
- Body fat and body composition;
- ECG / electrocardiogram measurement results;
- Respiratory rate;
- Sleep duration, sleep stages, and sleep results;
- Stress and mood-related results;
- Women’s health data, such as menstrual records, cycle information, related symptoms, and predictions;
- Other health data generated by compatible smart wearable devices that you choose to synchronize.
In Mainland China, the above medical and health information and movement trajectories associated with health features may constitute sensitive personal information. In the European Union / European Economic Area, health data generally constitutes special categories of personal data under Article 9 of the GDPR. In the United States, relevant information may constitute consumer health data or sensitive personal information under applicable state law.
3.3 Activity and Fitness Data
This may include:
- Step count;
- Distance;
- Calories;
- Activity duration;
- Exercise type;
- Exercise start/end time;
- Exercise duration;
- Pace;
- Altitude;
- Swimming laps, stroke count, stroke type, etc.;
- GPS latitude and longitude, exercise routes, and movement trajectories;
- Training effect, training load, recovery time, and other exercise-related results.
3.4 Device, App, and Network Technical Data
To connect devices, ensure compatibility, maintain stability, and protect security, we may process:
- Mobile phone brand, model, operating system, and OS version;
- App version, language, region, and time zone;
- Smart wearable device name, model, and necessary device identifiers;
- Firmware version;
- Bluetooth connection status;
- Battery level;
- Network type and network status;
- Device operating status;
- Synchronization status;
- IP address;
- Necessary crash, error, fault, and diagnostic information.
We follow the principle of data minimization and do not collect information merely because it is technically accessible.
3.5 Location Data
When you actively use outdoor exercise, route tracking, maps, weather, or other location-dependent features, we may, after obtaining system permission or other applicable authorization, process:
- Approximate location;
- Precise GPS location;
- Latitude and longitude;
- Exercise routes or movement trajectories;
- Location information necessary for the relevant feature.
We request location permission only when required for the relevant feature. Background location is used only where genuinely necessary for a feature and after the user has granted authorization.
3.6 Calls, SMS, and Contacts Information
When you actively enable incoming-call alerts, SMS alerts, caller/contact display, or similar features, the App may, after obtaining system permission, read:
- Incoming call number or call status;
- Contact name and phone number;
- SMS sender and message content;
- Other information necessary for the notification feature.
This data is primarily used to synchronize information to a paired watch, band, or other wearable device for display. Unless otherwise expressly stated for a specific product, we do not retain your complete contact list, SMS message body, or call content as long-term cloud-stored data.
3.7 Music Control Information
When you use music-control features, we may read information about the currently playing media, including:
- Song title;
- Album title;
- Artist;
- Playback status;
- Other information necessary for music control.
This information is primarily used to synchronize display and controls to a wearable device and, unless otherwise expressly stated, is not retained as long-term cloud-stored data.
3.8 Women’s Health and Information You Actively Submit
If you actively enable women’s health features, we may process information you enter, including:
- Menstrual duration;
- Cycle interval;
- Date of the most recent menstrual period;
- Menstrual start/end dates;
- Menstrual symptoms and mood;
- Information related to cycle calculations and reminders.
If you set exercise goals, weight goals, heart-rate alerts, watch-face backgrounds, or other personalized features, we process the information you actively provide to enable those features.
3.9 Friends and Family Features
If a specific App provides friends, family-member, or data-sharing features:
- Relevant health, activity, or device data will only be displayed or shared after the users concerned actively establish the relationship and complete the required authorization;
- Each party may revoke authorization through the methods provided by the product;
- A data subject’s health data may not be accessed through this feature without that data subject’s authorization.
3.10 User Feedback and Customer Support Information
When you submit feedback, a fault report, or a customer-support request, we may process:
- The issue description you provide;
- Contact information;
- Screenshots;
- Device model;
- App/firmware version;
- Logs you actively upload;
- Diagnostic information necessary to troubleshoot the issue.
3.11 Android App Availability / Installation Status
On certain Android versions, in order to determine whether a login, sharing, push-notification, or third-party service is available, the App may, within the scope permitted by the operating system, query whether specific third-party apps are installed.
We seek to use the minimum necessary method of querying whether specific apps are present rather than indiscriminately obtaining a complete list of installed apps. Unless otherwise expressly stated for a specific feature, we do not upload a complete software installation list to our servers or retain such a list long term.
3.12 Third-Party Health and Fitness Platform Data
After you actively authorize access, we may exchange data within the authorized scope with:
- Apple Health / HealthKit;
- Google Health Connect;
- Strava.
The specific data categories read from or written to these services are determined by the scope of authorization shown to you by the operating system or third-party platform.
4. Why We Process This Information
We may process information for the following purposes:
- Creating and managing accounts;
- Connecting, binding, and managing smart wearable devices;
- Synchronizing and displaying activity, exercise, sleep, and health data;
- Calculating or displaying BMI, sleep results, exercise results, and other user-requested features;
- Providing heart rate, blood oxygen, ECG, women’s health, and other features actively enabled by the user;
- Providing GPS exercise routes, maps, and weather services;
- Synchronizing incoming calls, SMS messages, contacts, or music status to paired devices;
- Providing firmware upgrades, device compatibility, and settings management;
- Interoperating with HealthKit, Health Connect, Strava, and other third-party services selected by the user;
- Providing data export, account management, and user-rights request functions;
- Conducting fault analysis, security protection, and service-stability maintenance;
- Improving products, optimizing algorithms, analyzing feature usage, and developing new features;
- Conducting anonymized or aggregated statistics;
- Complying with legal obligations, handling disputes, and protecting the lawful rights, interests, safety, and property of users, us, or third parties.
4.1 Restrictions on the Use of Health Data
We do not use users’ health data for personalized advertising or advertising profiles.
We do not use users’ health data to train AI models.
Product improvement, algorithm optimization, and research and development should preferentially use anonymized, aggregated, or de-identified data. If identifiable health data must be used, we will determine an appropriate lawful basis under applicable law and, where required, obtain separate consent, explicit consent, or other valid authorization.
5. Legal Bases in Different Regions
5.1 Users in Mainland China
Where the Personal Information Protection Law of the People’s Republic of China and other applicable laws apply, we may process personal information based on:
- Your consent given on a fully informed basis;
- Necessity for entering into or performing a contract to which you are a party;
- Necessity for fulfilling statutory duties or legal obligations;
- Emergency circumstances necessary to protect the life, health, or property of a natural person;
- Other legal bases permitted by applicable law.
For medical and health information, precise location/movement trajectories, and other sensitive personal information, we process such information only for a specific purpose and where strictly necessary, and we adopt enhanced protective measures. Where separate consent is required by law, we will obtain it separately.
5.2 Users in the European Union / European Economic Area
Where the GDPR applies, depending on the specific processing activity we rely on:
- GDPR Art. 6(1)(b): performance of a contract or taking steps at the user’s request prior to entering into a contract;
- GDPR Art. 6(1)(a): the user’s consent;
- GDPR Art. 6(1)(c): compliance with a legal obligation;
- GDPR Art. 6(1)(f): our or a third party’s legitimate interests, such as security, fraud prevention, fault diagnosis, and proportionate product improvement, provided those interests are not overridden by the user’s fundamental rights and freedoms;
- Other lawful bases applicable under law.
For health data that constitutes special categories of personal data, where required we also rely on a valid basis under GDPR Art. 9, typically including explicit consent under Art. 9(2)(a), or another basis permitted by applicable law.
5.3 Users in the United States
Privacy laws in the United States vary by state and data category. Depending on applicable law and the specific processing activity, we may process personal information and consumer health data for:
- Providing products or services actively requested by the user;
- The user’s consent;
- Compliance with legal obligations;
- Preventing fraud and security incidents;
- Other purposes permitted by law.
If a state requires separate consent for consumer health data, sensitive personal information, or certain sale or sharing activities, or requires an opt-out mechanism, we will comply with the applicable state law.
6. Device Permissions
The App requests permissions only when required for the relevant feature. Common permissions may include:
| Permission | Typical Purpose |
|---|---|
| Bluetooth / Nearby Devices | Search for, connect to, and synchronize smart wearable devices |
| Location | Outdoor exercise routes, maps, weather; Bluetooth scanning on certain Android versions |
| Background Location | Used only for genuinely necessary features such as continuous outdoor exercise tracking |
| Notifications | Incoming calls, SMS messages, App messages, or device reminders |
| Phone State / Call-Related Permissions | On supported Android versions, enables user-activated functions such as incoming-call alerts and call rejection |
| Contacts | Display contact names on the wearable device |
| SMS | Synchronize necessary content to the device when the user actively enables SMS alerts |
| Camera | Scan QR codes, take profile photos, create watch faces, etc. |
| Photos / Media / Files | Set a profile photo or watch face, save or select necessary files, perform firmware upgrades, etc. |
| Health Data Permissions | Exchange user-authorized data with HealthKit, Health Connect, and other health platforms |
| Network | Sign-in, cloud synchronization, firmware upgrades, maps, third-party services, and necessary network functions |
You may manage or revoke permissions at any time through your mobile operating system settings. Revoking a permission may cause the associated feature to stop functioning properly, but it will not affect features unrelated to that permission.
7. Cookies and Similar Technologies
Our websites, help center, or web services may use cookies, pixels, SDKs, or similar technologies to:
- Maintain sign-in status;
- Save language and preferences;
- Provide basic functionality;
- Protect security;
- Analyze usage of pages or services.
Where required by applicable law, we provide cookie settings, consent-management tools, or opt-out mechanisms.
For users in the United States, where applicable law requires recognition of and response to statutory preference signals such as Global Privacy Control (GPC), we will process such signals as required by law.
We do not make commitments beyond what applicable law requires solely because a browser sends a traditional “Do Not Track” signal.
8. How We Share, Entrust Processing of, or Disclose Information
We do not sell your health data.
We do not provide your health data to advertisers for advertising profiling.
We may share, entrust the processing of, or disclose necessary information in the following circumstances:
8.1 User-Initiated Authorization or Request
For example, when you actively connect to:
- Apple Health / HealthKit;
- Google Health Connect;
- Strava;
- Friends/family data sharing;
- Other third-party services you expressly select.
8.2 Service Providers
To provide cloud storage, infrastructure, maps, analytics, push notifications, sign-in, customer support, security, or other necessary services, we may engage service providers to process necessary data under contractual restrictions.
We reasonably manage service providers in accordance with applicable law and require them to process data only for agreed purposes, implement security measures, and comply with confidentiality and data-protection obligations.
8.3 OEM / ODM / Brand Partners
In multi-tier OEM / ODM projects, if a brand owner or partner lawfully assumes responsibility for data control, after-sales service, user requests, or compliance obligations for a specific product or service, we may provide relevant information to that entity to the extent necessary.
The specific data roles, scope, and responsibilities for a project are determined by the applicable product privacy notice, contracts, and applicable law.
8.4 Legal Requirements and Protection of Rights and Interests
We may provide necessary information where required by applicable laws and regulations, courts, regulators, or law-enforcement authorities, or make necessary disclosures as permitted by law to protect the lawful rights, interests, safety, and property of users, the Company, or third parties.
8.5 Corporate Transactions
In the event of a merger, acquisition, restructuring, asset transfer, or similar transaction, we may transfer relevant information to the extent permitted by law and take necessary measures to ensure that personal information continues to be protected. Where the law requires notice or renewed consent, we will comply accordingly.
9. Third-Party SDKs / Third-Party Services / App Permissions
Different OEM / ODM App versions may use different third-party components. We recommend that each officially released version also provide an in-app accessible Third-Party SDK / Service List identifying the actual integrated entity, data categories, purposes of use, and the third party’s privacy policy.
The current general technical solution may include:
| Third-Party Service | Main Purpose |
|---|---|
| Apple Health / HealthKit | Read/write health data authorized by the user |
| Google Health Connect | Interoperate with user-authorized health and fitness data |
| Strava | Interoperate with user-authorized fitness data |
| Amap / Amap Location | Maps, location, and exercise routes in Mainland China or applicable regions |
| Google Maps | Maps and exercise routes in applicable regions |
| User-selected sign-in, sharing, or related services | |
| User-selected sign-in or sharing (if enabled in the specific version) | |
| X (formerly Twitter) | User-selected sign-in or sharing (if enabled in the specific version) |
| Umeng+ | Analytics, stability, push-notification, or other modules enabled in the specific version |
Do I have to agree to any third-party terms and conditions?
Our Privacy Policy does not apply to products and services provided by third parties. Depending on the products and services you use, these may include third-party products and services involving analytics, map services, sign-in services, and other categories. Some may be provided through links to third-party websites, while others may be integrated through SDKs, APIs, or similar methods. When you use these products or services, those third parties may also collect your information. We strongly recommend that you take time to read the privacy policies of those third parties just as you read ours. We are not responsible for, and cannot control, how third parties use personal information they collect from you. Our Privacy Policy does not apply to other websites linked through our services.
By using Google Fit, you agree to Google Fit’s terms of service and privacy policy: http://www.google.com/policies/privacy
By using Apple Health, you agree to Apple’s terms of service and privacy policy: https://www.apple.com/legal/privacy/szh/
In addition, we integrate the SDKs listed below. When you use the relevant products, the information collected by the SDK, the purpose of collection, and the applicable third-party privacy policy are as follows:
Amap Maps / Amap Location: requires access to your location permission and may collect device information, network status, location information, and Wi-Fi information to provide maps and location services during outdoor exercise; privacy policy: https://lbs.amap.com/pages/privacy
Google Maps: requires access to your location permission and may collect device information, network status, and location information to record your location during outdoor exercise; privacy policy: https://support.google.com/contributionpolicy/answer/7401426?hl=zh-Hant
Alipay: requires access to your camera permission and storage permission and may collect network status, basic personal information submitted when registering an Alipay account, transaction information, and device information in order to provide Alipay payment services at your request; privacy policy: https://intl.alipay.com/ihome/help/agreements/detail.htm?agreement=AlipayPrivacyPolicy
WeChat Login: requires network permission and external-storage write permission and may collect network status in order to provide account login and information-sharing services at your direction; privacy policy: http://weixin.qq.com/agreement
Facebook Login: requires network permission and may collect network status in order to provide login and information-sharing services at your direction; privacy policy: https://opensource.facebook.com/legal/privacy/
QQ Login: requires network permission and external-storage write permission and may collect network status in order to provide information-sharing services at your direction; privacy policy: http://www.qq.com/privacy.htm
Twitter Login: requires network permission and external-storage write permission and may collect network status in order to provide information-sharing services at your direction; privacy policy: https://developer.twitter.com/zh-cn/more/developer-terms/agreement-and-policy
By using Weibo, you agree to Weibo’s terms of service and privacy policy: http://weibo.com/signup/v5/protocol
Our products integrate the Umeng+ SDK. The Umeng+ SDK needs to collect device MAC address, unique device identifiers (IMEI / Android ID / IDFA / OPENUDID / GUID, SIM-card IMSI information) to provide statistical analytics services, and uses geographic location to calibrate report accuracy and provide basic anti-fraud capabilities. By using Umeng, you agree to Umeng’s terms of service and privacy policy: https://www.umeng.com/page/policy
9.1 App Permissions
Storage Permission: When you use sharing, set a profile picture from your photo library, set a watch-face background, perform firmware upgrades, or use similar features, this permission is required to read image information or write app-related information. If you do not need these services, you may disable the permission at any time; doing so will not affect other services.
Camera Permission: When you connect a device by scanning a QR code, add friends/family, use shake-to-take-photo, or take a photo to set a profile picture or watch-face background, we request this permission to complete image capture. If you do not need these services, you may disable the permission at any time; doing so will not affect other services.
Location Permission: When you use map positioning to generate exercise routes, Bluetooth pairing, weather push, or other location-related search functions, you may choose to enable this permission so that your current location can be determined. If your phone runs Android 10 or later, background-location permission may also be requested to ensure normal recording of exercise data and routes. If you do not need these services, you may disable the permission at any time; doing so will not affect other services.
Phone Permission: When you use a wearable device to reject incoming calls or receive incoming-call information on the wearable, you may choose to enable this permission so that phone status can be obtained. If you do not grant this permission, normal operation of these features may be affected.
Call Permission: When you use a wearable device to reject incoming calls or receive incoming-call information on the wearable, you may choose to enable this permission so that the wearable can properly reject calls and receive incoming-call information. If you do not grant this permission, normal operation of these features may be affected.
Call Log Permission: When you use the wearable device to receive incoming-call number notifications, you may choose to enable this permission so that the caller’s number can be displayed on the paired device. If you do not need this service, you may disable the permission at any time; doing so will not affect other services.
Contacts Permission: When you use features that push caller contact information or SMS contact information to the device, you may choose to enable this permission so that contact information can be displayed on the wearable device. If you do not need this service, you may disable the permission at any time; doing so will not affect other services.
SMS Permission: When you use the feature that pushes SMS messages to the device, you may choose to enable this permission so that message content can be displayed on the wearable device. If you do not need this service, you may disable the permission at any time; doing so will not affect other services.
Auto-Start Permission: Used so the App can push message notifications to the Bluetooth device while running in the background, allowing users to notice and not miss important messages and calls. The App does not proactively prompt users to enable this permission; users must enable it themselves. It may be disabled at any time without affecting other services.
You may manage your system permissions at any time in the system “Settings.”
10. Data Storage and International Transfers
10.1 Users in the European Union / European Economic Area
For users in the European Union / European Economic Area:
The primary cloud storage region for account data and related health and fitness data is Frankfurt, Germany.
EU data uses a cross-Region disaster-recovery architecture, and both the primary storage Region and the disaster-recovery Region are located in Frankfurt, Germany.
For the EU account health and fitness databases covered by this Policy:
- No database or disaster-recovery copy is stored in Hong Kong, China;
- No database or disaster-recovery copy is stored in Singapore;
- No database or disaster-recovery copy is stored in the United States;
- Relevant service logs in the EU environment are not synchronized across borders.
To provide technical support, system operations and maintenance, troubleshooting, security management, and service-stability support, authorized Ultra Easy technical personnel located in Mainland China may, where necessary, remotely access relevant data located in Frankfurt, Germany.
We apply least-privilege access, identity authentication, role-based authorization, access controls, operation auditing, data minimization, necessity restrictions, and confidentiality requirements to such access.
Such remote access does not mean that the EU user database is copied to and stored long term in Mainland China.
If a specific access arrangement constitutes an international data transfer within the meaning of Chapter V of the GDPR, we will adopt an applicable lawful transfer mechanism and safeguards based on the actual recipient relationship, such as the EU Standard Contractual Clauses (SCCs), an appropriate data-transfer risk assessment, and supplementary security measures.
10.2 Users in Mainland China
For personal information collected and generated in Mainland China, we determine data-storage and cross-border arrangements in accordance with applicable Chinese law.
Where it is necessary to provide personal information outside the People’s Republic of China, we will, as applicable:
- Complete the applicable cross-border data compliance mechanism;
- Inform you of the overseas recipient, purposes and methods of processing, categories of personal information, methods for exercising your rights, and other required matters;
- Obtain your separate consent where required by law;
- Take necessary measures to ensure that overseas processing meets applicable data-protection standards.
If a specific product involves the export of personal information from Mainland China, we will provide further disclosure through a product privacy notice, separate notice, or other lawful means.
10.3 Users in the United States and Other Regions
For users in the United States and other regions, the location of data storage and processing depends on the specific OEM project, the user’s region, and the cloud-service architecture used.
If data is transferred to a country or region outside the user’s location, we will adopt reasonable contractual, organizational, and technical safeguards in accordance with applicable law.
11. Data Retention and Account Deletion
11.1 General Retention Principle
We retain personal information only for as long as necessary to achieve the purposes described in this Policy or as required by law.
Actual retention periods may vary depending on product functionality, account status, legal obligations, and security needs.
11.2 Health, Fitness, and Account-History Data
For users who sign in to an account and use cloud synchronization, health, fitness, and account-history data is generally retained until:
- You actively delete it;
- You delete your account;
- The relevant service terminates and the data is no longer needed;
- Or another retention period required by law expires.
11.3 Account Deletion
You may request account deletion in the App through:
“Me” → “Personal Information” → “Delete Account”
(the specific path may change with App versions).
After account deletion is completed, account-related personal data, health data, and fitness data in normal production systems will generally be deleted or irreversibly anonymized within 1–3 days, except for limited data that must be retained under applicable laws and regulations.
Data in disaster-recovery environments will be overwritten, expire, or be deleted according to the established disaster-recovery lifecycle. After normal production data is deleted, the corresponding disaster-recovery data will be isolated and will no longer be used for ordinary business processing.
12. Data Access, Export, and Portability
Users may export applicable data through:
“Me” → “Third-Party Services” → “Data Export”
The current export format is:
ZIP archive + CSV files.
To the extent required by applicable law, we will provide data in a structured, commonly used, machine-readable format, together with relevant explanations or metadata necessary to understand the data.
If the in-App function cannot satisfy your statutory rights request, you may contact us at:
support@ute-tech.com.cn
13. How You Can Manage Personal Information and Exercise Your Rights
Depending on your location and applicable law, you may have rights including:
- The right to know / be informed;
- The right of access and to obtain a copy;
- The right to correction or supplementation;
- The right to deletion;
- The right to withdraw consent;
- The right to restrict processing;
- The right to object to processing;
- The right to data portability;
- The right to request an explanation of automated decision-making;
- The right to opt out of certain sale, sharing, targeted advertising, or profiling activities;
- The right to limit the use and disclosure of sensitive personal information;
- The right to lodge a complaint with a supervisory authority;
- Other rights provided by applicable law.
To protect account and health-data security, we may reasonably verify your identity. We will not discriminate against you or treat you unfairly in any manner prohibited by law because you exercise your privacy rights in accordance with law.
14. Special Provisions for Mainland China
If you are located in Mainland China, this Section applies together with the other provisions of this Policy.
14.1 Sensitive Personal Information
Medical and health information, precise location / movement trajectories, and personal information of minors under the age of 14 may constitute sensitive personal information.
We process such information only for specific purposes, where strictly necessary, and subject to enhanced safeguards. Where separate consent is required by law, we will obtain separate consent through an independent pop-up, feature authorization page, system permission, or other clear means.
14.2 Personal Information Protection Impact Assessments
Where required by law, we conduct personal information protection impact assessments for the processing of sensitive personal information, entrusted processing, provision of information to other processors, cross-border provision, or other processing activities that may have a significant impact on individuals’ rights and interests, and we retain the relevant records.
14.3 Minors
If we process personal information of minors under the age of 14, we will obtain the consent of a parent or other guardian in accordance with law and adopt special protective measures as required by applicable law.
14.4 Cross-Border Transfers
If personal information of users in Mainland China is lawfully provided outside China, we will comply with applicable requirements relating to cross-border data-transfer mechanisms, notice, and separate consent.
15. Special Provisions for the European Union / European Economic Area
If you are located in the European Union / European Economic Area, this Section applies together with the other provisions of this Policy.
15.1 GDPR Rights
Subject to the conditions set out in the GDPR, you may have:
- The right of access;
- The right to rectification;
- The right to erasure;
- The right to restriction of processing;
- The right to object;
- The right to data portability;
- The right to withdraw consent;
- Where applicable, the right to object to certain automated decisions or obtain human intervention;
- The right to lodge a complaint with a competent data protection supervisory authority.
15.2 Health Data
Health data such as heart rate, blood oxygen, ECG, sleep, and women’s health data may constitute special categories of personal data under GDPR Art. 9. Where applicable, we will obtain explicit consent or rely on another lawful basis permitted by law.
15.3 EU Data Act
For connected product data and related service data subject to Regulation (EU) 2023/2854, users may access applicable data through the App’s data-export function.
Current path:
“Me” → “Third-Party Services” → “Data Export”
Current export format:
ZIP + CSV
For readily available data that is actually obtained by Ultra Easy and falls within the applicable scope, we will, to the extent required by law, make such data available to users free of charge, securely, without undue delay, and in a structured, commonly used, machine-readable format, together with necessary metadata.
Users may also, in accordance with law, request that applicable data be made available to an eligible third party of their choice. Requests may be submitted to support@ute-tech.com.cn. If the relevant data is controlled by another brand owner, manufacturer, or Data Holder, we may direct the request to the appropriate entity.
A user’s right of access to data does not automatically entitle the user to obtain software source code, algorithm source code, algorithm weights, calibration parameters, proprietary BLE protocols, internal firmware parameters, or other technical information protected as trade secrets or intellectual property under applicable law.
15.4 EU Representative / DPO
If GDPR Article 27 requires us to appoint an EU representative, we will publish the representative’s identity and contact information through the App, our website, or the relevant product privacy notice.
If GDPR Article 37 requires us to appoint a Data Protection Officer (DPO), we will publish the relevant contact information in accordance with law.
16. Special Provisions for the United States
If you are located in the United States, this Section applies together with the other provisions of this Policy.
16.1 General State Privacy Rights
Certain U.S. state laws may provide rights to access, confirm processing, obtain a copy, correct, delete, port data, opt out of sale / sharing / targeted advertising / certain profiling, limit the processing of sensitive information, and appeal decisions concerning privacy requests.
Where such laws apply to us or to a specific OEM project, we will respond in accordance with law.
16.2 California / CCPA-CPRA (Where Applicable)
If the California Consumer Privacy Act, as amended by the CPRA (collectively, “CCPA”), applies to the relevant processing activities, California consumers may have:
- The right to know what personal information we collect, use, and disclose;
- The right to obtain a copy of personal information;
- The right to delete;
- The right to correct;
- The right to opt out of “sale” or “sharing”;
- Where applicable, the right to limit the use and disclosure of sensitive personal information;
- The right not to receive treatment prohibited by law because they exercise CCPA rights.
We do not sell users’ health data.
We do not use users’ health data for cross-context behavioral advertising.
If a specific OEM version introduces processing of non-health data that legally constitutes a CCPA “sale” or “sharing,” we will provide an applicable Notice at Collection, opt-out mechanism, and, where required by law, recognize and respond to GPC signals.
16.3 Consumer Health Data
Certain U.S. states provide special protections for consumer health data outside HIPAA-covered contexts.
For consumer health data such as heart rate, blood oxygen, sleep, ECG, women’s health, body measurements, and health-related precise location:
- We clearly disclose the categories of data collected and the purposes for which they are used;
- Except where necessary to provide a product or service actively requested by the user or otherwise permitted by law, we obtain applicable consent where required by law;
- If the law requires separate consent for “sharing” and “collection,” we obtain them separately;
- Users may request access, deletion, or withdrawal of consent for future processing / sharing as provided by law;
- We do not sell consumer health data. If a future specific project involves a legally defined “sale,” the applicable separate authorization requirements must first be satisfied and the relevant notices updated.
16.4 Health Data Security Incidents
If the U.S. federal FTC Health Breach Notification Rule or other applicable state breach-notification laws apply and a health-data security incident occurs that legally requires notification, we will provide notice to affected users, regulators, or other required parties in accordance with applicable law.
16.5 HIPAA
This App is a consumer-facing smart wearable and health-management technology service and does not automatically become subject to HIPAA merely because it processes health data.
If a specific OEM project, healthcare-provider collaboration, or other project causes certain data to be subject to HIPAA or another specialized U.S. healthcare law, the applicable project-specific privacy notice and legal requirements will prevail.
17. Children and Minors
Our general services are not primarily directed at children.
- Mainland China: If we process personal information of minors under the age of 14, we will obtain the consent of a parent or other guardian and adopt special protective measures in accordance with law.
- European Union / European Economic Area: Where processing is based on a child’s consent to an information society service, the applicable age is determined by the GDPR and the law of the relevant Member State and may range from 13 to 16 years old.
- United States: If COPPA or another children’s privacy law applies and we knowingly collect personal information from a protected child, we will obtain verifiable parental consent or take other measures required by law.
If you are a parent or guardian and believe that a child has provided us with personal information without appropriate authorization, please contact us at support@ute-tech.com.cn.
18. Information Security and Data Breaches
We use reasonable technical and organizational measures to protect personal information, including:
- Encryption in transit, such as TLS;
- Appropriate storage protection;
- Identity authentication;
- Least-privilege and access controls;
- Operation auditing;
- Environment segregation;
- Vulnerability remediation and security updates;
- Data backup and disaster recovery;
- Employee confidentiality obligations and privacy/security training;
- Contractual and security requirements for third-party service providers.
No internet-based system can guarantee absolute security.
If a personal-information or health-data security incident occurs, we will take remedial measures in accordance with applicable law and, where legally required, provide notice to users, regulators, or other relevant parties.
19. Automated Decision-Making, Profiling, and Marketing
Our health data is not used for advertising profiles.
If a future version uses automated decision-making or profiling that produces legally significant effects on users, we will provide transparent notice in accordance with applicable law and offer applicable opt-out, explanation, human-intervention, or other rights mechanisms.
Marketing communications are sent only where permitted by law or after obtaining any required consent. You may opt out of non-essential marketing through the unsubscribe method in the communication, App settings, or by contacting us.
20. Trade Secrets and Anonymous Data
De-identified, anonymized, or aggregated data may no longer constitute personal information if, under applicable law, it can no longer reasonably identify an individual. We may lawfully use such data for statistics, product improvement, algorithm optimization, security analysis, and research and development.
Algorithm source code, calibration parameters, proprietary BLE protocols, internal firmware parameters, internal model parameters, and similar technical information may constitute our trade secrets or intellectual property. Nothing in this Policy concerning user data rights constitutes a transfer of ownership of such technical intellectual property.
21. Updates to This Policy
We may update this Policy for reasons including:
- Changes in product features;
- Changes in SDKs or third-party services;
- Changes in data-processing practices;
- Changes in cloud architecture;
- Changes in laws, regulations, or regulatory requirements.
For changes that materially affect users’ rights and interests, we will provide notice through the App, website, email, or another reasonable and prominent method.
If applicable law requires renewed consent for a new processing purpose, we will obtain such consent in accordance with law before the relevant processing begins.
22. Contact Us and Complaints
If you have any questions about this Policy, our data-processing activities, or your rights, you may contact:
Shenzhen Ultra Easy Technology Co., Ltd. (深圳市优创亿科技有限公司) Address: 22/F, Tower A, Huizhi R&D Center, Longteng Community, Xixiang Subdistrict, Bao’an District, Shenzhen, China Email: support@ute-tech.com.cn
Before processing access, deletion, export, or other rights requests, we may take reasonable steps to verify your identity.
You may also lodge a complaint with a competent personal information protection, data protection, consumer protection, or other regulatory authority under the laws applicable in your location.
For data or features independently controlled by the final OEM / ODM brand owner, you may also submit requests directly to that brand owner using the privacy contact information it provides.