Phomemo Data Cross-Border Transfer Commitment

Version: 1.0

Date: 2024.12.1

Phomemo is committed to ensuring the protection and privacy of personal data in accordance with the General Data Protection Regulations (GDPR). In the process of providing excellent service and support by APP Phomemo, our team in China may access certain categories of personal data, as follows:

Data categories that support team access:

Account information and user credentials: This includes email address and authorization information of third-party social media. The processing purposes of these data include account creation, application availability, customer support and service status and availability update.

Device data: this category includes device ID and print log, including photos, IMEI, IP and UID. The data is processed to provide relevant features, understand the sales status of equipment and assist technical support. The purpose of the photo needs to be clarified.

After determining these data categories, Phomemo ensures that all cross-border data transmissions comply with the following GDPR compliance measures:

1. The Legal Basis of Data Transmission: Appropriate Protection Measures

2. Phomemo ensures that all cross-border data transmission is based on appropriate protection measures that meet GDPR standards.

3. Regular audit of safety infrastructure

4. In order to ensure the integrity and security of our data processing infrastructure, Phomemo conducts annual audit technical measures/certificates according to the following standards. These audits are designed to strictly assess and verify our compliance with the principles of security and privacy. Technical measures reflect the need to ensure that our infrastructure remains resilient to threats and conforms to the best practices of data protection.

5. Enable data subjects to exercise their rights.

6. As a data controller, Phomemo fully supports our customers as data subjects, enabling data subjects to exercise their rights under GDPR. The data subject can contact us through our designated Data Protection Officer (DPO) at DPO, privacy@quin.com. Our DPO is committed to solving and responding to inquiries and requests within one week to promote the effective implementation of the rights of data subjects.

7. Annual risk assessment

8. Phomemo conducts a comprehensive risk assessment of data protection regulations and practices every year, including those applicable to China. This assessment is essential to identify and mitigate any risks associated with cross-border data transmission. Review and update the results of risk assessment every year to reflect the latest development and ensure continuous compliance with GDPR requirements.

 

Phomemo hereby declares its commitment to GDPR compliance and responsible and secure cross-border data transmission management. We are committed to transparency, accountability and continuous improvement in data protection.