Privacy Policy

Privacy at Jiason.

This is the full Privacy Policy for jiasontech.com and the Jiason mobile applications published on Google Play and the Apple App Store. We use plain English, we list every advertising SDK we integrate, and we tell you exactly how to reach a human.

Operator: Jiason Technology Co., Limited, Hong Kong.
Effective date: · Last updated: .

A.0 Document identity

This document is the Privacy Policy of Jiason Technology Co., Limited, a company incorporated in the Hong Kong Special Administrative Region ("Hong Kong") with its registered office at Rm 5B 12/F TUNG LEE INDL BLDG 9 LAI YIP ST, Kwun Tong, Hong Kong.

The Privacy Policy applies to:

  • Our public website at https://jiasontech.com and every subdomain we operate;
  • The Jiason mobile applications published under our developer account on the Apple App Store and on Google Play, including the "Jiason" companion app for smart-home device management.

By using the website or the mobile applications, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please stop using the service and contact us at support@jiasontech.com so we can answer your questions.

Throughout this document, "we", "us", "our" and "Jiason" refer to Jiason Technology Co., Limited. "You" and "your" refer to any natural person using the website or the mobile applications.

A.1 App Store & Google Play compliance

A.1.1 Apple App Store Review Guidelines

Our iOS applications comply with the Apple App Store Review Guidelines, in particular §5.1.1 (Privacy) and §5.1.2 (Data Use and Sharing). The privacy nutrition labels shown in the App Store product page reflect the categories of data described in this Privacy Policy. We do not use data for purposes that are inconsistent with the labels we publish, and we do not "track" users as that term is defined under Apple's App Tracking Transparency framework without first presenting a prompt and obtaining consent in jurisdictions where consent is required.

A.1.2 Google Play Developer Program Policy

Our Android applications comply with the Google Play Developer Program Policy, the Google Play Developer Distribution Agreement, and any associated addenda (including the Play Console App Content requirements). We keep the Data Safety form for each app aligned with the categories of data we actually collect and share.

A.1.3 Google Play User Data Policy

We declare our use of the following permitted purposes under the Google Play User Data Policy:

  • Account functionality — sign in, preferences, language, paired devices.
  • Device functionality — provisioning, telemetry, OTA update delivery.
  • Analytics — aggregated usage statistics, only with consent where consent is required by applicable law.
  • Advertising — display of advertising through the SDKs listed in §A.7.
  • Developer communications and support — in-app messages, ticket handling, customer-success follow-up.

We do not sell user data, and we do not transfer user data to data brokers.

A.1.4 Google Play Families Policy

Our mobile applications are not designed for children. We do not knowingly target audiences under the age of 13, and we do not include content that is presented as primarily for children. We do not use advertising IDs to build profiles of users we know or suspect to be under 13. If we add a parent-facing or teacher-app toggle in the future we will update this section and obtain any required age-assurance signals.

A.2 Data controller and contact

A.2.1 Controller identity

The data controller responsible for your personal data is:

Jiason Technology Co., Limited
Rm 5B 12/F TUNG LEE INDL BLDG 9 LAI YIP ST
Kwun Tong, Hong Kong SAR
Email: support@jiasontech.com

A.2.2 Data Protection Officer / privacy contact

For all privacy enquiries — including requests to access, correct, delete, port, restrict, or object to the processing of your personal data — please contact our privacy team at support@jiasontech.com with the subject line "Privacy request". Postal enquiries may be sent to the address above, marked for the attention of the Privacy Officer.

We aim to acknowledge every request within five (5) business days and to substantively respond within thirty (30) calendar days. Where a request is complex, we may extend the response window by a further sixty (60) days and we will notify you of the extension within the initial thirty-day window.

A.2.3 UK / EU representative

Jiason Technology Co., Limited is a small Hong Kong company and does not currently have an establishment in the European Union or the United Kingdom within the meaning of GDPR Article 27 or the UK GDPR. We rely on the controller-based exemption — that is, we apply GDPR-equivalent standards to the data of users we identify as in the EU/UK, but we are not required to appoint an Article 27 representative at this scale. If we onboard EU or UK customers at scale, or if our processing of EU/UK personal data materially changes, we will appoint a representative and update this section.

A.3 Information we collect

A.3.1 Account data

If you create a Jiason account we collect: your name, email address, login credentials (stored as a salted hash), the language and region you choose, and (optionally) a profile photo you upload. If you sign in with Apple, Google, or another federated provider, we receive a verified identifier and a display name from that provider.

A.3.2 Device data

The mobile applications collect: device model, operating system and version, app version, language and time zone, IP-derived country, push-notification token. The website collects: user agent, IP-derived country, referrer, and the URL you requested.

A.3.3 Smart-home telemetry

If you pair a Jiason device or a third-party Matter, Zigbee, or Wi-Fi device through the app, we collect: paired-device identifier, firmware version, room and scene names you create, automation rules you define, and energy readings where the device supports them. Telemetry is opt-in and can be turned off at any time from the app settings.

A.3.4 Location

We collect coarse IP-derived country for fraud prevention, currency selection, and regional feature gating. We collect precise location only if you grant the in-app permission and only for the specific feature that needs it (for example, "find a paired device" or "sunset-aware automations"). You may revoke this permission at any time in your device settings.

A.3.5 Usage data

We collect event-level usage data (screens visited, buttons tapped, toggles changed, errors observed) and crash reports with stack traces and device state at the time of the crash. Crash reports are retained for up to ninety (90) days unless required longer for active debugging.

A.3.6 Cookies and similar technologies

Our website uses a small set of cookies and local-storage items. The table below lists each one. We do not use any non-essential cookies until you opt in.

NamePurposeExpiryTypeCategory
jiason_sessionAnonymous session identifier for forms.SessionFirst-partyStrictly necessary
jiason_consentRecords cookie consent state.180 daysFirst-partyStrictly necessary
jiason_prefStores UI preferences (motion, theme).365 daysFirst-partyFunctional
jiason_localeStores chosen language.365 daysFirst-partyFunctional

We do not currently load any analytics or advertising cookies on the public website. If we add them in future we will update this section and present an opt-in banner in jurisdictions where opt-in is required.

A.3.7 SDK / ad-platform data

Our mobile applications integrate the third-party SDKs listed in §A.7. Each SDK collects its own set of data, which we describe for every platform. We do not allow our advertising partners to combine the data they collect from our apps with personally identifiable information you give us directly, except where you have given separate consent.

A.4 Legal bases for processing (GDPR Article 6)

For users in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the UK GDPR / EU GDPR:

A.4.1 Contract

Where processing is necessary to perform the contract you have entered into with us — for example, creating your account, pairing your devices, providing customer support, and delivering the features you have paid for.

A.4.2 Legitimate interests

Where processing is necessary for our legitimate interests — for example, securing the service, preventing fraud, debugging issues, and improving product quality — provided that your interests and fundamental rights do not override those interests. You may object to such processing as described in §A.11.

A.4.3 Consent

Where required by applicable law — for example, for non-essential cookies, advertising personalisation, precise location, and optional analytics — we obtain your consent before processing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

A.4.4 Legal obligation

Where processing is necessary to comply with a legal obligation — for example, tax and accounting record-keeping, anti-money-laundering checks, and lawful law-enforcement requests.

A.5 How we use information

A.5.1 Service provision

To create and maintain your account, to pair your Jiason and third-party smart-home devices, to deliver app features (scenes, energy monitoring, automations), and to send you transactional notifications (firmware updates, security alerts).

A.5.2 Analytics

To understand, in aggregate, which features are used and which fail. We do not use analytics to identify individual users. Where consent is required we obtain it before enabling analytics.

A.5.3 Advertising

To display advertising through the SDKs described in §A.7 in the formats described in §A.8. Advertising personalisation only takes place where you have consented (or where applicable law allows it without consent, for example under legitimate interest in certain US states). You can opt out at any time using the controls described in §A.8.5.

A.5.4 Customer support

To respond to your support requests, to diagnose issues, and to improve our support quality. We may attach diagnostic data to your ticket when you request it from inside the app.

A.5.5 Security and fraud prevention

To detect and prevent abuse, unauthorised access, and fraudulent transactions. We may suspend accounts or block IPs that exhibit abusive patterns, and we may share indicators with payment and identity providers to validate transactions.

A.6 Disclosure to third parties

A.6.1 Service providers

We share data with carefully selected service providers that process data on our behalf under written instructions. Categories of provider include:

  • Cloud hosting and storage — operating the application backend and database.
  • Email and notification delivery — sending transactional and support emails and push notifications.
  • Error monitoring and crash reporting — receiving aggregated, de-identified stack traces.
  • Customer support tooling — routing and tracking tickets.
  • Payment processors — handling subscription billing through Apple and Google.

Each provider is bound by a data-processing agreement consistent with applicable law. We do not allow our providers to use your data for their own marketing or to train their general-purpose models on it.

A.6.2 Advertising networks

As described in §A.7, the mobile applications integrate a number of advertising SDKs. Each SDK receives the data described in its own subsection, governed by the privacy notice and opt-out tools of that platform.

A.6.3 Legal disclosures

We may disclose personal data where compelled by a court of competent jurisdiction, by a binding legal process, or by an applicable law-enforcement or regulatory request. Where we are permitted to do so we will notify the affected user before responding, unless the request itself prohibits notification.

A.6.4 Business transfers

If Jiason Technology Co., Limited is acquired, merges with another entity, or sells substantially all of its assets, your personal data may be transferred to the acquiring entity. We will provide affected users with a notice (by email and in-app) at least thirty (30) days before the transfer takes effect, and the acquiring entity will be required to honour this Privacy Policy.

A.7 Disclosure to advertising networks — per platform

The mobile applications integrate the third-party advertising SDKs listed below. Each subsection describes the SDK behaviours, the data collected by that SDK, our lawful basis, the opt-out mechanism available to you, and a link to that platform's own privacy documentation. SDKs are loaded only when a relevant ad format is requested and only after we have obtained any required consent.

A.7.1 Google AdMob

Role in the app: display of open-screen, banner, interstitial, and rewarded-video ads; mediation layer for other SDKs in this list.

Data collected: Advertising ID (GAID on Android, IDFA on iOS), IP address, coarse location derived from IP, app-identifier, device information, ad impressions and clicks, and the consent state of the user.

Lawful basis: consent (for personalisation) and legitimate interest (for fraud prevention and frequency capping).

Opt-out: Reset your advertising ID in your device settings; enable "Limit Ad Tracking" on iOS or "Opt out of Ads Personalisation" on Android; visit adssettings.google.com.

Platform privacy page: policies.google.com/privacy.

A.7.2 Google Ad Manager

Role in the app: programmatic ad serving for direct-sold and open-auction inventory.

Data collected: advertising ID, IP address, coarse location, device and app identifiers, ad requests and responses.

Lawful basis: consent (personalisation) and legitimate interest (fraud prevention).

Opt-out: same as AdMob above; the controls are shared.

Platform privacy page: policies.google.com/privacy.

A.7.3 Meta Audience Network

Role in the app: display of banner, interstitial, and rewarded-video ads through Meta's mediation.

Data collected: advertising ID, IP address, device information, app events, coarse location, and (if you have a Facebook account and consented) hashed identifiers used to match against Meta's graph.

Lawful basis: consent.

Opt-out: "Ad Preferences" inside Facebook; the iOS App Tracking Transparency prompt; the Android "Opt out of Ads Personalisation" toggle.

Platform privacy page: facebook.com/policy.php.

A.7.4 Unity Ads

Role in the app: display of video and playable ads in our apps.

Data collected: advertising ID, IP address, device model and OS version, app version, ad interaction events, and (if you grant it) location.

Lawful basis: consent.

Opt-out: reset your advertising ID; enable Limit Ad Tracking / Opt out of Ads Personalisation; visit unity.com/privacy for the privacy portal.

Platform privacy page: unity.com/legal/privacy-policy.

A.7.5 AppLovin

Role in the app: display of banner, interstitial, native, and rewarded-video ads.

Data collected: advertising ID, IP address, device identifiers, app events, coarse location, and information about the ads shown.

Lawful basis: consent.

Opt-out: device-level controls as above; AppLovin's "Opt out of interest-based advertising" at applovin.com/optout.

Platform privacy page: applovin.com/privacy.

A.7.6 ironSource (Unity LevelPlay)

Role in the app: mediation platform that auctions ad requests to multiple demand sources.

Data collected: advertising ID, IP address, device information, app events.

Lawful basis: consent.

Opt-out: device-level controls; ironSource's privacy portal at is.com/privacy-policy.

Platform privacy page: is.com/privacy-policy.

A.7.7 Pangle (ByteDance)

Role in the app: display of banner, interstitial, native, and rewarded-video ads, with a strong footprint in Asia-Pacific.

Data collected: advertising ID, IP address, device and OS information, coarse location, app events, and interaction events.

Lawful basis: consent.

Opt-out: device-level controls; Pangle's interest-based advertising controls at pangleglobal.com/privacy.

Platform privacy page: pangleglobal.com/privacy.

A.7.8 Vungle

Role in the app: display of video and playable ads, especially rewarded-video formats.

Data collected: advertising ID, IP address, device information, app events.

Lawful basis: consent.

Opt-out: device-level controls; Vungle's opt-out page at vungle.com/privacy.

Platform privacy page: vungle.com/privacy.

A.7.9 Chartboost

Role in the app: display of in-app video and interactive ads, with mediation.

Data collected: advertising ID, IP address, device information, app events, coarse location.

Lawful basis: consent.

Opt-out: device-level controls; Chartboost's privacy portal at chartboost.com/privacy.

Platform privacy page: chartboost.com/privacy.

A.7.10 InMobi

Role in the app: display of display, video, and rewarded-video ads.

Data collected: advertising ID, IP address, device and OS information, app events, coarse location.

Lawful basis: consent.

Opt-out: device-level controls; InMobi's opt-out at inmobi.com/opt-out.

Platform privacy page: inmobi.com/privacy-policy.

A.7.11 Tapjoy

Role in the app: rewarded video ads and offerwall.

Data collected: advertising ID, IP address, device information, app events, opt-in identifiers for offerwall rewards.

Lawful basis: consent.

Opt-out: device-level controls; Tapjoy's privacy portal at tapjoy.com/legal/privacy-policy.

Platform privacy page: tapjoy.com/legal/privacy-policy.

A.7.12 Mintegral

Role in the app: display of video and interactive ads, especially in Asia-Pacific.

Data collected: advertising ID, IP address, device and OS information, coarse location, app events.

Lawful basis: consent.

Opt-out: device-level controls; Mintegral's privacy portal at mintegral.com/en/privacy.

Platform privacy page: mintegral.com/en/privacy.

A.7.13 Digital Turbine

Role in the app: display of in-app ads and certain device-level delivery services.

Data collected: advertising ID, IP address, device information, app events.

Lawful basis: consent.

Opt-out: device-level controls; Digital Turbine's opt-out at digitalturbine.com/privacy-policy.

Platform privacy page: digitalturbine.com/privacy-policy.

A.7.14 Liftoff

Role in the app: display of in-app ads, including rewarded video and playable formats.

Data collected: advertising ID, IP address, device information, app events.

Lawful basis: consent.

Opt-out: device-level controls; Liftoff's privacy portal at liftoff.io/privacy-policy.

Platform privacy page: liftoff.io/privacy-policy.

A.7.15 Moloco

Role in the app: programmatic bidding and ad serving, particularly in CTV and mobile in-app.

Data collected: advertising ID, IP address, device and OS information, app events, coarse location.

Lawful basis: consent.

Opt-out: device-level controls; Moloco's opt-out at moloco.com/privacy-policy.

Platform privacy page: moloco.com/privacy-policy.

A.7.16 Yahoo (Verizon Media)

Role in the app: display of native and video ads through Yahoo's demand-side stack.

Data collected: advertising ID, IP address, device and OS information, coarse location, app events.

Lawful basis: consent.

Opt-out: device-level controls; Yahoo's Ad Interest Manager at legal.yahoo.com/us/en/yahoo/privacy/index.html.

Platform privacy page: legal.yahoo.com/us/en/yahoo/privacy/index.html.

A.7.17 Smaato

Role in the app: real-time bidding and ad serving for in-app inventory.

Data collected: advertising ID, IP address, device and OS information, coarse location.

Lawful basis: consent.

Opt-out: device-level controls; Smaato's privacy portal at smaato.com/privacy-policy.

Platform privacy page: smaato.com/privacy-policy.

A.7.18 Start.io

Role in the app: display of in-app ads with a focus on app-install formats.

Data collected: advertising ID, IP address, device and OS information, app events.

Lawful basis: consent.

Opt-out: device-level controls; Start.io's opt-out at start.io/policy/privacy.

Platform privacy page: start.io/policy/privacy.

A.7.19 Appodeal

Role in the app: mediation platform that aggregates demand from multiple networks, including many of those listed above.

Data collected: advertising ID, IP address, device and OS information, app events.

Lawful basis: consent.

Opt-out: device-level controls; Appodeal's privacy portal at appodeal.com/privacy-policy.

Platform privacy page: appodeal.com/privacy-policy.

A.8 Ad formats in the app

The mobile applications may display the four ad formats described below. Each format has its own user-facing label and its own user controls.

A.8.1 Open-screen / splash ads

Open-screen (or "splash") ads are full-screen ads shown when the app launches and at certain transitions between sessions. They cannot be dismissed by the user — they are shown for a fixed duration before the user proceeds to the app. Open-screen ads collect the same data as the underlying SDK that serves them (see §A.7) and use the device advertising ID for frequency capping. If you do not wish to see open-screen ads, you may stop using the app.

A.8.2 Rewarded video ads

Rewarded video ads are user-initiated — for example, by tapping "watch an ad to unlock a feature" or "watch an ad to skip a wait". They never auto-play. You are always told what reward is on offer, you always watch the ad in full, and you are never required to watch more than one at a time. The data collected by rewarded-video ads is the same as for the SDK serving them (see §A.7).

A.8.3 Interstitial ads

Interstitial ads are full-screen ads shown between content screens — for example, after a user completes a pairing flow or before they return to the dashboard. They are clearly labelled "Ad" and include a visible close control. We apply frequency capping to limit how often an interstitial can appear in a single session. The data collected is the same as for the underlying SDK.

A.8.4 Banner ads

Banner ads are small, rectangular ads shown at the bottom or inline on long pages of the app. They remain visible until they refresh on a timed cycle. They respect operating-system-level ad-tracking toggles. The data collected is the same as for the underlying SDK.

A.8.5 Opting out of personalised ads

You can opt out of personalised advertising through any combination of the following controls:

  • iOS — Settings > Privacy & Security > Tracking > toggle off "Allow tracking of apps for our apps".
  • Android — Settings > Google > Ads > toggle on "Opt out of Ads Personalisation".
  • Google "My Ad Center"adssettings.google.com.
  • Meta Ad Preferences — accessible from any Facebook or Instagram account.
  • In-app — the "Reset advertising ID" button in our app's privacy settings clears the cached identifier and forces the next ad request to start fresh.

Opting out does not stop ads from being shown; it stops them from being personalised to your interests.

A.9 Cookies, Do Not Track, Global Privacy Control

A.9.1 Cookies used

The complete list of cookies used on jiasontech.com is set out in §A.3.6. We do not currently use analytics or advertising cookies on the website. If we add analytics cookies, we will load them only after obtaining the consent required in your jurisdiction.

A.9.2 Cookie banner

EU and UK users see an opt-in cookie banner — non-essential cookies are blocked until consent is given. California, Virginia, Colorado, Connecticut, Utah, and other US-state users covered by applicable comprehensive privacy laws see an opt-out banner with a "Do Not Sell or Share My Personal Information" link. Users in jurisdictions with no specific cookie or sale-opt-out law see no banner; only the strictly-necessary cookies described above are set.

A.9.3 Do Not Track / Global Privacy Control

We honour the Global Privacy Control (GPC) signal as an opt-out of "sale" or "sharing" of personal information under the California Consumer Privacy Act / California Privacy Rights Act and equivalent state laws. Where we receive a GPC signal we treat it as binding for the browser or device that sent it. We also honour the legacy Do Not Track signal in the same way where it is technically feasible to do so.

A.10 Children's data

A.10.1 Age gate

Our mobile applications are not designed for children. We do not knowingly target users aged below the age of digital consent in their jurisdiction:

  • 13 in the United States under the Children's Online Privacy Protection Act (COPPA);
  • 16 in the European Union under the GDPR (default age for digital consent, modifiable by member state);
  • 13 in the United Kingdom under the Age-Appropriate Design Code (default);
  • 13 in Australia and Singapore;
  • 18 in jurisdictions where that is the age of majority for digital consent.

Where a user is below the applicable age we expect a parent or guardian to provide the consent required by law before the user creates an account. The app does not include a child-directed age gate in v1; if we add age assurance we will update this section.

A.10.2 No knowingly collected children's data

We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without verifiable parental consent, we delete it as soon as possible. Please contact support@jiasontech.com if you believe we have done so.

A.10.3 COPPA compliance

We do not serve behavioural advertising to users we know or suspect to be under 13 in the United States. We do not knowingly collect persistent identifiers for the purpose of behavioural advertising to such users.

A.10.4 GDPR-K / UK Age-Appropriate Design Code

Where we discover that a user is under 18 (for example, by an in-app confirmation or by a verified request from a parent), we apply high-privacy defaults: telemetry is opt-out rather than opt-in, precise location is off, advertising personalisation is off, and connected social features are limited.

A.11 Regional rights

Depending on where you live, you may have some or all of the rights set out below. We extend the substantive rights to all users regardless of jurisdiction where it is feasible to do so.

A.11.1 GDPR (European Economic Area) and UK GDPR

If you are in the EEA or the UK you have the right to:

  • Access the personal data we hold about you;
  • Rectification of inaccurate or incomplete personal data;
  • Erasure ("right to be forgotten") of your personal data;
  • Restriction of processing in specific circumstances;
  • Data portability in a structured, commonly used, machine-readable format;
  • Object to processing based on legitimate interests, including profiling;
  • Withdraw consent at any time, without affecting prior processing;
  • Lodge a complaint with a supervisory authority — for example, the Information Commissioner's Office (UK) or your local EU data-protection authority.

A.11.2 CCPA / CPRA (California)

If you are a California resident you have the right to:

  • Know what categories of personal information we collect and how we use them;
  • Delete personal information we have collected from you;
  • Correct inaccurate personal information;
  • Opt out of sale or sharing of your personal information — we do not sell personal information;
  • Limit use of sensitive personal information — we do not collect sensitive personal information;
  • Non-discrimination for exercising any of these rights.

A.11.3 LGPD (Brazil)

If you are in Brazil you have rights analogous to the GDPR: confirmation of the existence of processing, access, correction, anonymisation, portability, erasure, consent withdrawal, and the right to complain to the Autoridade Nacional de Proteção de Dados (ANPD).

A.11.4 PIPEDA (Canada)

If you are in Canada you have the right of access to your personal data and the right to correct inaccuracies. Provincial additions apply in Québec (Law 25) and elsewhere — please contact us if you would like the provincial details.

A.11.5 Australia — Privacy Act 1988 (APP)

If you are in Australia you have the rights set out in the thirteen Australian Privacy Principles: access, correction, and the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).

A.11.6 Singapore — PDPA

If you are in Singapore you have the right of access, correction, and (where applicable) the right to opt out of marketing communications. The Do-Not-Call registry provisions apply to direct-marketing calls and messages.

A.11.7 Japan — APPI

If you are in Japan you have the rights set out in Articles 26 to 30 of the Act on the Protection of Personal Information (APPI), including the right to access, correct, suspend use, and stop third-party provision of your personal data. Cross-border transfers of personal data from Japan to a third country require consent under APPI Article 28 unless an exception applies; we obtain that consent where it is required.

To exercise any of these rights, email support@jiasontech.com with subject "Privacy request". We will respond within the time limits required by your jurisdiction.

A.12 Data retention

We retain personal data only for as long as we have a clear purpose to do so.

A.12.1 Account data

Kept while the account is active. When you request deletion, we delete or anonymise your account within thirty (30) days, except where retention is required by law (for example, tax records) or to resolve outstanding disputes.

A.12.2 Telemetry

Raw event-level telemetry is retained for up to ninety (90) days. Aggregated telemetry (counts, not events) is retained for up to thirteen (13) months so we can compare year-on-year trends.

A.12.3 Support tickets

Support tickets and their attachments are retained for up to twenty-four (24) months after closure, after which they are anonymised. Aggregated metrics about ticket volume and resolution time are retained indefinitely.

A.12.4 Ad-platform data

Data collected by the advertising SDKs in §A.7 is governed by the retention policy of that SDK. Please refer to each platform's privacy page for details.

A.13 International data transfers

A.13.1 Storage locations

Personal data is primarily stored in cloud regions selected for compliance and proximity: Hong Kong, Singapore, and an EU region (Frankfurt or Dublin) for EEA/UK users. Specific sub-processors and their regions are available on request.

A.13.2 Transfer mechanisms

Where personal data is transferred outside the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Agreement or the UK Addendum, and equivalent mechanisms recognised by applicable law. Our sub-processors are bound by data-processing agreements that incorporate these safeguards.

A.13.3 Hong Kong PDPO

Cross-border transfers of personal data from Hong Kong are subject to Section 33 of the Personal Data (Privacy) Ordinance. Where we transfer personal data out of Hong Kong we do so only to recipients that provide a level of protection comparable to the PDPO.

A.14 Security

A.14.1 Technical measures

We use TLS (HTTPS) for data in transit; encryption-at-rest encryption of personal-data stores; role-based access control with least-privilege defaults; and audit logging on access to production data.

A.14.2 Organisational measures

Personal data is accessible only to employees and contractors who need it to perform their role. We conduct vendor due diligence on every sub-processor that handles personal data on our behalf.

A.14.3 Incident response

We maintain an incident-response plan that includes breach detection, containment, and notification. Where a breach is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by GDPR Article 33.

A.15 Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top of this page and, where the change is material, we will notify you by:

  • posting a banner on the public website;
  • showing an in-app banner next time you open the app;
  • sending an email to the address on file (for material changes only).

Material changes give you at least thirty (30) days' notice before they take effect, except where a shorter period is required by law.

Version log

DateChange
First published version. Covers all 19 advertising SDKs listed in §A.7 and all four ad formats listed in §A.8.

A.16 Contact us

If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us:

Jiason Technology Co., Limited
Attn: Privacy Officer
Rm 5B 12/F TUNG LEE INDL BLDG 9 LAI YIP ST, Kwun Tong, Hong Kong
Email: support@jiasontech.com
Expected response window: ≤ 30 calendar days.