Tuya Mobile Privacy Policy

Effective Date: 2019-12-25

Updated: 2019-11-25

Tuya Inc., its affiliates and subsidiaries (“we”, “us”, “our”, “Tuya”) are committed to protecting your privacy. This Mobile Privacy Policy (“Policy”) describes our practices in connection with information privacy on Personal Data we process through your individual use of the following services, products, and related mobile applications (collectively, the “Products”):

· Tuya Smart Mobile Application

· Smart Life Mobile Application

In this Privacy Policy, “Personal Data” means information that can be used to identify an individual, either from that information alone, or from that information and other information we have access to about that individual. “Smart Devices” refers to those nonstandard computing devices produced or manufactured by hardware manufacturers, with human-machine interface and the ability to transmit data that connect wirelessly to a network, including: smart home appliances, smart wearable devices, smart air cleaning devices, etc. “Apps” refers to those mobile applications developed by Tuya that provide end users remote control to Smart Devices and with the ability to connect to Tuya IoT Platform.

For other branded mobile applications powered by Tuya, our Clients control all the Personal Data collected through our Products. We collect the information under the direction of our Clients and the processing of such information shall be limited to the purpose of providing the service for which our Clients has engaged us. If you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the Client that you interact with directly.

What Personal Data do we collect

In order to provide our services to you, we will ask you to provide necessary Personal Data that is required to provide those services. If you do not provide your Personal Data, we may not be able to provide you with our products or services.

1. Information You Voluntarily Provide Us

· Account or Profile Data: When you register an account with us, we may collect your name and contact details, such as your email address, phone number, user name, and login credentials. During your interaction with our Products, we may further collect your nickname, profile picture, country code, language preference or time zone information into your account.

2. Information We Collect Automatically

· Device Information: When you interact with our Product, we automatically collect device information, such as the MAC address of your devices, IP address, wireless connection information, operating system type and version, application version number, push notification identifier, log files, and mobile network information.

· Usage Data: During your interaction with our Sites and Services, we automatically collect usage data relating to visits, clicks, downloads, messages sent/received, and other usage of our Sites and Services.

· Log Information: When you use our app, the system and exception log may be uploaded.

· Location Information: We may collect information about your real-time precise or non-precise geo-location when you use our specific Products or Services, such as robot cleaner and weather service.

3. Smart Devices Related Information

· Basic Information of Smart Devices: When you connect your Smart Devices with our Products or Services, we may collect basic information about your Smart Devices such as device name, device ID, online status, activation time, firmware version, and upgrade information.

· Information Reported by Smart Devices: Depending on the different Smart Devices you elect to connect with our Products or Services, we may collect different information reported by your Smart Devices. For example, smart weights or fitness trackers may report your height, weight, body fat mass (BFM), BMI and skeletal muscle mass (SMM); smart cameras may report images or videos captured by it.

Purposes and Legal Basis for Processing Personal Data

The purpose for which we may process information about you are as follows:

· Non-marketing Communication: We process your Personal Data to send you important information regarding the Services, changes to our terms, conditions, and policies and/or other administrative information. Because this information may be important, you may not opt-out of receiving such communications. The legal basis for this processing is to perform our contract with you according to our Terms of Use.

Who do We Share Personal Data with?

At Tuya, we only share Personal Data in ways that we tell you about. We may share your Personal Data with the following recipients:

Except for the third parties described above, to third parties only with your consent.

International Transfer of Information Collected

To facilitate our operation, we may transfer, store and process your Personal Data in jurisdictions other than where you live. Laws in these countries may differ from the laws applicable to your country of residence. When we do so, we will ensure that an adequate level of protection is provided for the information by using one or more of the following approaches:

If you would like further detail on the safeguards we have in place, you can contact us directly as described in this Privacy Policy.

Your Rights Relating to Your Personal Data

We respect your rights and control over your Personal Data. You may exercise any of the following rights:

· Via the “Profile – Personal Center” in our Products (for Product version 3.2 and later)

· By emailing us at privacy@tuya.com (for Product version before 3.2)

You do not have to pay a fee and we will aim to respond you within 30 days. If you decide to email us, in your request, please make clear what information you would like to have changed, whether you would like to have your Personal Data deleted from our database or otherwise let us know what limitations you would like to put on our use of your Personal Data. Please note that we may ask you to verify your identity before taking further action on your request, for security purposes.

You may:

· Request access to the Personal Data that we process about you;

· Request that we correct inaccurate or incomplete Personal Data about you;

· Request deletion of Personal Data about you;

· Request restrictions, temporarily or permanently, on our processing of some or all Personal Data about you;

· Request transfer of Personal Data to you or a third party where we process the data based on your consent or a contract with you, and where our processing is automated; and

· Opt-out or object to our use of Personal Data about you where our use is based on your consent or our legitimate interests.

Security

We use commercially reasonable physical, administrative, and technical safeguards to preserve the integrity and security of your Personal Data. Tuya provides various security strategies to effectively ensure data security of user and device. As for device access, Tuya proprietary algorithms are employed to ensure data isolation, access authentication, applying for authorization. As for data communication, communication using security algorithms and transmission encryption protocols and commercial level information encryption transmission based on dynamic keys are supported. As for data processing, strict data filtering and validation and complete data audit are applied. As for data storage, all confidential information of users will be safely encrypted for storage. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), you could immediately notify us of the problem by emailing privacy@tuya.com.

Data Retention

We process your Personal Data for the minimum period necessary for the purposes set out in this Privacy Policy, unless there is a specific legal requirement for us to keep the data for a longer retention period. We determine the appropriate retention period based on the amount, nature, and sensitivity of your Personal Data, and after the retention period ends, we will destruct your Personal Data. When we are unable to do so for technical reasons, we will ensure that appropriate measures are put in place to prevent any further such use of your Personal Data.

Dispute Resolution

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

Changes to this Policy Policy

We may update this Privacy Policy to reflect changes to our information practices, at least on an annual basis. If we make any material changes we will notify you by email (send to the e-mail address specified in your account) or by means of a notice in the mobile applications prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

Contact Us

If you have any questions about our practices or this Privacy Policy, please contact us as follows:

Tuya Inc.

Postal Mailing Address: 75 E Santa Clara St, 6th Floor, San Jose, CA 95113 or

5, 7, 8 and 7-12th Floor, Huace Business Builing A, Wuchanggang Road, Xihu District, Hangzhou, China

Email: privacy@tuya.com.

For European Union data subject, you have the right to lodge a complaint with a supervisory authority concerning Tuya’s data processing activities. For questions, or to exercise your rights as an EU data subject, please contact our EU Representative here:

Name: Data Protection Representative

Email: tuya@dpr.eu.com