Privacy Policy
1. Personal data
Personal data refers to information that, when used alone or in combination with other information, can identify an individual. Such data is submitted to us by you when you use our website, products, or services, and when you interact with us, or we obtain it by recording how you interact with our website, products, or services, for example, through technologies such as cookies. The data we collect depends on the website you visit or the products and services you use, and may include personal data such as name, address, email, phone number, etc. We collect personal data in order to contact you, provide corresponding services, send important notifications, etc.
2. Privacy Policy
Shanghai Chaifu Robot Co., Ltd. and its global subsidiaries (hereinafter referred to as "Chaifu", "we")"Or 'our'") is well aware of the importance of personal data to customers and users. To this end, Chai Fu places great emphasis on the protection of customers' and users' personal data, and has taken a series of measures to ensure that relevant businesses comply with applicable personal data protection requirements (such as GDPR).
2.1 To ensure the effective implementation of personal data protection requirements, Chai Fu has appointed a Data Protection Officer (DPO).
2.2 ChaiFu adopts industry-recognized methods and practices for personal data protection. In business scenarios where GDPR applies, ChaiFu utilizes the Data Protection Impact Assessment (DPIA) method to assess and mitigate personal data security risks in its products and services.
2.2.1 ChaiFu requires a thorough assessment of personal data involved in products and services, and projects involving personal data must undergo DPIA;
2.2.2 Projects involving personal data must establish data inventories and data flow diagrams;
2.2.3 Projects involving personal data must identify potential risks in the data processing process (including collection, use, storage, sharing, deletion, etc.), and take corresponding measures (including management, physical, and technical measures) based on the risk level)
2.2.4 After completing the DPIA, a corresponding report must be output and approved by the DPO.
2.3. ChaiFu implemented technical measures including intrusion detection, access control, encryption, data leakage prevention, anti-spam, terminal security protection, vulnerability scanning, and conducted penetration testing to verify the effectiveness of personal data protection measures.
2.4. ChaiFu has established an emergency response mechanism for personal data leakage. In the event of a personal data leakage, Chai Fu will immediately initiate the emergency response process, striving to minimize the potential losses caused by the leakage and ensure that affected individuals are properly notified.
2.5. ChaiFu has established a continuous employee privacy policy training mechanism to ensure that every employee involved in GDPR can accurately understand the legal principles of data protection based on their specific job responsibilities, and strictly implement the applicable systems and processes of the company.
2.6. To ensure compliance, ChaiFu implemented necessary technical and process audits for personal data protection.
Personal data protection is not only a legal requirement but also a corporate social responsibility. Chaifu will continuously optimize its products and services to ensure security and privacy, and reduce the risk of personal data protection for customers and users.
3. Policy Updates
ChaiFu reserves the right to update or modify this policy from time to time. If there are any changes to this policy, we will post the latest version here. If we make significant changes to our privacy policy, we may also notify you through different channels, such as posting a notice on our website or sending you a separate notification.