1. Scope & data controller
This Privacy Policy applies to:
- Our corporate website at dasitktech.com and any sub-domain (collectively, the "Website").
- Our mobile applications published on Google Play and the Apple App Store (the "Apps").
- Our consumer electronics, wholesale, retail, import/export, R&D and technical consulting services (the "Services").
- Our business communications, including email, contact forms, customer support channels and events.
The data controller for personal data collected under this policy is:
Hong Kong Dasitaike Electronics Technology Co., Limited
Registered office: Rm 903A 9/F CAMERON COML CTR 458-468 HENNESSY RD, Causeway Bay, Hong Kong
Email: support@dasitktech.com
Key accounts: xionghao@dasitktech.com
Where Dasitaike processes personal data on behalf of a business customer (for example, providing analytics or a hosted feature inside a customer's account), Dasitaike acts as a data processor and the customer is the controller. In those cases the customer's own privacy notice will govern, and Dasitaike processes the data under the customer's instructions and a Data Processing Agreement (DPA).
2. Definitions
- Personal data means any information that identifies, or can reasonably be used to identify, a natural person.
- Processing means any operation performed on personal data, including collection, storage, use, disclosure or erasure.
- Processors / service providers are third parties that process personal data on our behalf under written instructions.
- Ad partners are companies that deliver, measure or facilitate advertising in our Apps or on our Website.
- Child means a person under the age of 13, unless a higher age of digital consent applies in the user's jurisdiction (e.g. 14 in certain EU member states, 14 under UK GDPR, 13 under CCPA, 13 under COPPA).
- Sensitive personal data means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation, or precise geolocation.
3. Data we collect
We collect the following categories of personal data, depending on the product, feature and jurisdiction:
3.1 Data you provide directly
- Account & contact data: name, email address, company name, role, postal address, phone number, country, language.
- Identity verification data: where required by law or by our payment / anti-fraud partners, government ID, tax ID or business registration number.
- Communications data: messages and attachments you send us via contact forms, email, in-app chat, support tickets or social media.
- Survey, research & feedback data: responses to voluntary surveys, beta programs, user research sessions or feedback requests.
- Marketing preferences: subscription choices, language and region preferences, consent records.
3.2 Data collected automatically
- Device data: device model, operating system version, browser type and version, language, screen size, mobile carrier.
- Usage data: features used, screens viewed, buttons tapped, in-app events, time spent, session length, referrer and exit page.
- Log data: IP address (truncated or full depending on region), timestamps, error logs, performance metrics.
- Approximate location: country, region, city-level location derived from IP address. We do not collect precise GPS coordinates unless an explicit feature requires it and you have granted permission.
- Advertising identifiers: the Google Advertising ID (GAID), Apple Identifier for Advertisers (IDFA), and (where supported) the Apple Identifier for Vendors (IDFV). These are reset by the user via the device's "Limit Ad Tracking" / "Ask App Not To Track" settings.
- Cookies & similar: first-party cookies, local storage, IndexedDB entries and similar identifiers on our Website. See Cookies & similar technologies.
3.3 Data from third parties
- Public profile data: when you follow or interact with our brand pages on Facebook, Instagram, X / Twitter, LinkedIn, YouTube, WeChat or other platforms, in accordance with those platforms' policies.
- App store data: aggregated download, crash and rating data made available to us by Google Play and the Apple App Store.
- Trade, freight & anti-fraud data: shipment tracking, customs status and sanctions screening results from logistics and compliance partners.
- Payment data: limited transaction data from our payment processors (we do not see or store full card numbers; card data is handled by the PCI-DSS compliant processor).
4. Sources of data
We collect personal data from the following sources:
- Directly from you, when you create an account, contact us, request a quote, place an order, subscribe to a newsletter, register for a beta or use our Services.
- Automatically from your device, through your use of our Website or Apps.
- From third-party processors and partners as described above.
- From public sources, including public corporate registries, business networks and trade publications, when you have made the information public.
5. Purposes of processing
We process personal data for the following purposes:
- To provide, operate, maintain, secure and improve the Website, the Apps and the Services.
- To create and manage your account, to authenticate you and to remember your preferences.
- To process and fulfil orders, quotes, shipments, returns, refunds, RMA requests and warranty claims.
- To send you transactional communications, including order confirmations, shipping updates, security alerts and administrative messages.
- To send you marketing communications you have consented to, with the ability to opt out at any time.
- To personalize content, recommendations and advertising inside the Apps and on the Website, subject to your consent and applicable law.
- To measure ad performance, run frequency capping, prevent fraud, attribute installs and attribute in-app events, in compliance with the relevant store policies.
- To respond to your inquiries, support requests and complaints, and to manage our relationship with you.
- To conduct research, analytics and product development, including aggregated and de-identified analytics.
- To detect, prevent and address fraud, security incidents, abuse, illegal activity and violations of our Terms of Service.
- To comply with our legal obligations, including tax, accounting, trade compliance, sanctions screening and law enforcement requests.
- To establish, exercise or defend legal claims.
6. Legal bases (GDPR / UK GDPR)
For users in the European Economic Area, the United Kingdom and other jurisdictions that recognize a similar legal basis framework, we rely on the following legal bases under Article 6 GDPR:
- Performance of a contract — to provide the Services you have requested, to fulfil orders and to manage your account.
- Legitimate interests — to operate, secure and improve the Services, to prevent fraud, to perform aggregated analytics and (where applicable) for direct marketing by electronic means to existing customers, balanced against your rights and freedoms.
- Consent — for non-essential cookies, for storing or accessing information on your device, for personalized advertising, for sharing data with certain ad partners and for sending marketing communications to new contacts. You can withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Legal obligation — to comply with tax, accounting, trade, customs, sanctions and law enforcement obligations.
- Vital interests & public interest — in rare cases to protect your vital interests or to respond to public interest tasks.
Where we process special categories of personal data, we rely on Article 9(2) GDPR (typically explicit consent) or another lawful basis under applicable law.
7. Sharing & processors
We do not sell personal data. We share personal data with the following categories of recipients, only as necessary for the purposes described in this policy and under appropriate safeguards:
- Processors that host our infrastructure, deliver our emails, process payments, provide customer support tools, run our analytics, or provide us with IT and security services — each under a written data processing agreement.
- Logistics & trade partners — freight forwarders, customs brokers, couriers, trade compliance and screening services.
- Ad partners as described in detail in the next section.
- App stores — Google Play and the Apple App Store, which receive aggregated download, crash and rating information when you install or use our Apps.
- Business transfers — if Dasitaike is acquired, merged or sells substantially all of its assets, personal data may be transferred to the acquirer under the same level of protection.
- Legal & regulatory — courts, regulators, law enforcement, tax authorities and other public bodies where we are required to disclose.
- With your consent — any other recipient you have specifically authorized.
A current list of our material sub-processors is available on request at support@dasitktech.com.
8. Ad networks & mediation
Our Apps and our Website display advertising through a curated set of monetization partners and a mediation stack. The list below reflects the partners we may integrate. The list of active partners for each individual App is published in that App's store listing (Data Safety / App Privacy details) and in the app-ads.txt file hosted at dasitktech.com/app-ads.txt, which is updated whenever we onboard or offboard a partner.
Each partner processes data under its own privacy policy and in compliance with applicable laws and the policies of the relevant app store. Where required (e.g. EEA, UK, California), we surface a consent dialog before any personalized advertising or before any non-essential storage is set on the user's device.
Common categories of data shared with or processed by these ad partners include: advertising identifiers (GAID, IDFA, IDFV), IP address (often truncated), coarse location (country/region), device model and OS version, app version, language, session information, ad impression and click events, and (where the user has given consent) a profile ID for ad personalization. We do not share government identifiers, financial account numbers, or health data with ad partners.
For users in the EEA, the UK, Switzerland, California and other regions with applicable laws, we use a consent management platform that surfaces a clear opt-in / opt-out for personalized advertising, and we honor the Global Privacy Control (GPC) and Apple's App Tracking Transparency (ATT) signals where they are technically available to us.
9. Ad formats
Our Apps typically integrate the following ad formats, in compliance with Google Play, the Apple App Store and our regional obligations. Ad unit placement, frequency and disclosure are configured to respect each platform's rules and our age-gating and consent state.
- Splash / open ads — full-screen ads that appear on app launch or when returning to the app after a long background. Splash ads are served through SDKs that honor the consent state and the platform's "Limit Ad Tracking" / "Ask App Not To Track" settings. They are not shown to users we have determined to be children.
- Rewarded video ads — user-initiated full-screen video ads in exchange for an in-app reward. Rewarded ads always require an explicit user tap to opt in. The reward and the watch length are disclosed before the ad starts.
- Interstitial ads — full-screen ads shown at natural transition points (e.g. between screens, after completing a task). We apply frequency caps and respect cooldown periods, and we do not show interstitial ads in ways that would interrupt an unfinished user task.
- Banner ads — inline rectangular ads placed in designated zones of the app interface. Banner ads are clearly delineated from the surrounding content. In contexts that may be accessed by children, banner ads are configured to only show contextual (non-personalized) creative.
Where required, we tag our ad requests with signals indicating that the user is in the EEA, the UK, California, Brazil or another region with consent requirements, that the user is (or is not) a child, and that consent has been (or has not been) granted for personalized advertising.
10. App store disclosures
10.1 Google Play
Our Apps are published under the Google Play Developer Distribution Agreement and are required to comply with the Google Play Developer Program Policies, including (where applicable):
- User Data Policy — we collect and use only the data necessary to provide the App, we disclose data practices in the Play Console Data Safety form, and we do not sell personal data.
- Families Policy — Apps that are designed for, or may be of interest to, children comply with the Families Policy, including the requirement to disable personalized advertising and certain SDKs when a child is using the App.
- Ads Policy — all advertising shown in our Apps complies with the Google Play Ads Policy, including rules around interstitial ad placement, rewarded ad disclosure and ad attribution.
- Permissions Policy — we request only the runtime permissions that are necessary for a feature, and we provide in-context explanations before the user is prompted.
- SDK Policy — every third-party SDK that accesses personal data is declared in the Play Console and complies with the SDK requirements.
10.2 Apple App Store
Our Apps are published under the Apple Developer Program License Agreement and are reviewed against the App Store Review Guidelines. Specifically, we comply with:
- Guideline 1.4.1 — Apps that access user data disclose the access prominently and obtain consent before collecting or using the data.
- Guideline 1.5 — Apps must not transmit data off the device in a manner that exposes users to privacy risks without their knowledge and consent.
- Guideline 2.1 — App Completeness — privacy practices and ad disclosures are accurate.
- Guideline 5.1.1(ix) — Apps in the Kids category or that are designed for children must not transmit personally identifiable information or device identifiers to third parties, must not include behavioral advertising, and must not include third-party analytics or third-party advertising networks whose ToS are inconsistent with Kids category rules.
- App Privacy Details — each App's "App Privacy" section is filled out accurately and updated whenever the data practices change.
- App Tracking Transparency — we request tracking permission via the AppTrackingTransparency framework only after we have displayed a clear explanation; we honor the user's choice and do not use tracking for users who have denied it.
- Nutrition Labels (Data Safety) — the data we collect, link to identity, use to track, and the categories of third parties we share with are all declared.
11. Children & age gating
Protecting children is a core part of our design process.
- We do not knowingly collect personal data from children. If we learn that we have inadvertently collected personal data from a child, we will delete it as soon as possible.
- Where our Apps may be of interest to children (for example, an app that a school might deploy), we either (a) restrict the App to audiences over the local age of digital consent, or (b) implement the Google Play Families Policy and the Apple App Store Kids category rules — disabling personalized advertising, disabling third-party analytics, and not transmitting device identifiers to ad networks.
- We do not show splash ads, rewarded ads, or any personalized ad to a user we have determined to be a child. We do not use third-party remarketing on users we have determined to be a child.
- We do not condition participation in any feature, content, or game on the child providing more personal data than is reasonably necessary.
- Age gating is implemented at the App level. Where the age cannot be determined, the App defaults to the most protective settings.
- COPPA (Children's Online Privacy Protection Act) — for users we believe to be under 13 and located in the United States, we do not collect personal data except as permitted under COPPA (e.g. for the support of the internal operations of the App).
- GDPR-K / UK Age-Appropriate Design Code (Children's Code) — for users we believe to be under the age of digital consent in the EEA or the UK, we apply the highest privacy settings by default and do not engage in profiling or behaviorally-targeted advertising.
- If you believe a child has provided us with personal data, contact support@dasitktech.com and we will delete the data.
12. Cookies & similar technologies
Our Website uses cookies and similar technologies for the following purposes:
- Strictly necessary cookies — to provide the Website, remember your language and region, prevent fraud and balance load. These cookies do not require consent under the ePrivacy Directive.
- Functional cookies — to remember your preferences (e.g. theme, layout, dismissed banners).
- Analytics cookies — to count visits and understand how the Website is used, in aggregated form. Where required, these are only set after you have given consent.
- Advertising cookies & pixels — to measure the performance of our campaigns and (where you have consented) to personalize advertising. We honor "Do Not Track", "Global Privacy Control" and similar signals.
You can manage your cookie choices through our consent banner (where applicable), your browser's cookie settings, and your device's "Limit Ad Tracking" / "Ask App Not To Track" preferences.
13. International transfers
We are headquartered in Hong Kong, and we use processors in multiple regions. When personal data is transferred across borders, we rely on the following safeguards:
- For transfers out of the EEA, the UK or Switzerland: European Commission Standard Contractual Clauses (SCCs) and, where relevant, the UK International Data Transfer Addendum, supplemented by transfer impact assessments and (where required) additional technical and organizational measures.
- For transfers out of China: the CAC Standard Contract for Cross-Border Transfer of Personal Information, and (where required) a security assessment by the Cyberspace Administration of China.
- For transfers to or from the United States: the EU-U.S. Data Privacy Framework, where the recipient is certified, and SCCs otherwise.
- For transfers involving other regions: equivalent regional mechanisms, including contractual provisions and certifications.
Our default position is to keep personal data within the region of collection, where this is technically feasible. Where cross-border transfer is necessary, we apply the safeguards above and the principle of data minimization.
14. Retention
We retain personal data for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes and enforce our agreements. Specific retention windows include:
- Account data — for as long as your account is active, plus a reasonable wind-down period, and thereafter as required for tax, accounting and legal defense purposes (typically 7 years).
- Order and transaction data — typically 7 years from the date of the transaction, to comply with tax and accounting obligations.
- Server logs — typically 90 days, unless required to be retained longer for security incident investigation.
- Support correspondence — typically 3 years from the last contact.
- Marketing consent records — for as long as you are subscribed, plus a record of the withdrawal.
- Ad identifiers and ad attribution data — typically not longer than 13 months for most jurisdictions, in line with the relevant regulator guidance.
Where personal data is no longer needed, we securely delete or irreversibly anonymize it.
15. Security
We take the security of personal data seriously. Our technical and organizational measures include:
- Encryption of personal data in transit (TLS 1.2+) and at rest (industry-standard symmetric encryption).
- Access controls based on the principle of least privilege, with audit logging of sensitive access.
- Regular vulnerability scanning and periodic third-party penetration testing.
- Security awareness training for all employees who handle personal data.
- An incident response plan with defined roles, communication templates and notification timelines that meet GDPR (72 hours), CCPA (in the time required), PIPL (immediately where there is harm), LGPD (in a reasonable timeframe) and other applicable laws.
- Vendor due diligence and written agreements with all processors.
Despite our efforts, no system can be 100% secure. If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent authorities in accordance with applicable law.
16. Your rights & how to exercise them
Depending on where you live, you may have some or all of the following rights. We extend these rights to all users globally, regardless of jurisdiction, except where local law requires a different treatment.
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to correct inaccurate or incomplete personal data.
- Right to erasure / right to be forgotten — to request deletion of your personal data, subject to legal retention requirements.
- Right to restrict processing — to ask us to limit how we process your personal data while a complaint is being investigated.
- Right to data portability — to receive a machine-readable copy of personal data you have provided, where the processing is based on consent or contract and is carried out by automated means.
- Right to object — to object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent — at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right not to be subject to automated decision-making — including profiling, that produces legal or similarly significant effects, except where permitted by law.
- Right to lodge a complaint — with your local data protection authority.
To exercise any of these rights, email support@dasitktech.com with the subject line "Data Subject Request". We will respond within the statutory window (typically 30 days under GDPR, 45 days under CCPA, 15 days under PIPL). For security, we may need to verify your identity before acting on the request.
17. Region-specific rights
17.1 EEA / UK / Switzerland (GDPR, UK GDPR, FADP)
You have the rights set out in Section 16. The legal bases for our processing are described in Section 6. We honor the Global Privacy Control (GPC) signal. You can lodge a complaint with your local data protection authority (a list is available from the European Data Protection Board at edpb.europa.eu).
17.2 United States — California (CCPA / CPRA)
You have the right to know what categories of personal information we collect, the categories of sources, the business or commercial purpose, the categories of third parties with whom we share, and the specific pieces of personal information we have collected about you. You have the right to delete, the right to correct, the right to opt out of the sale or sharing of personal information (we do not sell), the right to limit the use of sensitive personal information (we do not use it for purposes that require an opt-out), and the right to non-discrimination for exercising these rights. We honor the Global Privacy Control signal as an opt-out. California residents may also designate an authorized agent to act on their behalf.
17.3 United States — other states
Residents of Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Delaware and other states with comprehensive privacy laws have similar rights. Where those laws apply, we extend the same controls.
17.4 United States — Children (COPPA)
For users we believe to be under 13 in the United States, see Section 11. Parents and guardians may review, request deletion of, or refuse further collection of their child's personal data by contacting us.
17.5 Brazil (LGPD)
You have the rights set out in Section 16, including confirmation of the existence of processing, access, correction, anonymization, portability, deletion, and information about sharing. The legal bases for our processing are described in Section 6. You can lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd.
17.6 China (PIPL)
You have the rights set out in Section 16. We rely on consent, contractual necessity, legal obligation and legitimate interests as the legal bases for our processing. Cross-border transfers are subject to the safeguards described in Section 13. You can lodge a complaint with the Cyberspace Administration of China.
17.7 Singapore (PDPA)
You have the right to access, correct and withdraw consent to the use of your personal data. You can lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.
17.8 Malaysia (PDPA 2010)
You have the right to access and correct your personal data, and to withdraw consent. You can lodge a complaint with the Department of Personal Data Protection (JPDP).
17.9 Thailand (PDPA)
You have the right to access, correct, delete and obtain a copy of your personal data, the right to object, the right to data portability and the right to withdraw consent. You can lodge a complaint with the Personal Data Protection Committee (PDPC) at pdpc.or.th.
17.10 Japan (APPI)
You have the right to access, correct, suspend use of and delete your personal data, and to opt out of the use of personal data for marketing. You can lodge a complaint with the Personal Information Protection Commission (PPC) at ppc.go.jp.
17.11 Australia (Privacy Act 1988 / APPs)
You have the rights set out in the Australian Privacy Principles, including access and correction. You can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
17.12 Canada (PIPEDA & Quebec Law 25)
You have the right to access, correct and (in Quebec) request deletion of your personal data, and to withdraw consent. You can lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or the Commission d'accès à l'information du Québec at cai.gouv.qc.ca.
17.13 India (DPDPA 2023)
You have the right to access, correct, erase, nominate and grievance redress. You can lodge a complaint with the Data Protection Board of India once operationalized.
17.14 South Korea (PIPA)
You have the rights set out in Section 16, with specific rules on cross-border transfer. You can lodge a complaint with the Personal Information Protection Commission at pipc.go.kr.
17.15 Other jurisdictions
If you are located in a jurisdiction that is not listed above, we will extend the highest standard of protection available to your data, including the standards described in this Privacy Policy, GDPR, CCPA/CPRA, COPPA and the relevant app store policies.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Post the updated policy on our Website and update the "Last updated" date at the top of this page.
- For changes that require renewed consent, request your consent again through our in-app consent dialog or the cookie banner.
- For changes that affect your rights, notify you by email (where you have provided one and consented to marketing) or by an in-app notice.
We keep prior versions of this policy in our records and can provide them on request.
19. Contact & Data Protection Officer
For any questions about this Privacy Policy, to exercise your rights, or to lodge a complaint, please contact us:
Hong Kong Dasitaike Electronics Technology Co., Limited
Attn: Data Protection Officer
Rm 903A 9/F CAMERON COML CTR 458-468 HENNESSY RD, Causeway Bay, Hong Kong
Email: support@dasitktech.com
Key accounts: xionghao@dasitktech.com
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (see Section 17 for the relevant authorities).
This Privacy Policy is provided in English. Translations may be made available in additional languages for convenience; in case of any conflict, the English version prevails.