隐私政策(GDPR合规版)
生效日期:2026年8月11日
隐私政策官方URL:https://www.nelpo.com/pages/privacy-policy-gdpr-compliant-version(请替换为您的有效静态HTML页面URL,需符合:标准http/https格式、无需登录/跳转、可自动化读取、非博客/云笔记/文件格式,与APP/网站内展示内容完全一致)
本隐私政策(以下简称“本政策”)由【深圳声动健康科技有限公司】(以下简称“我们”)制定,旨在明确我们收集、使用、存储、传输、披露您的个人数据的规则,保障您的个人数据权益,严格遵守欧盟《通用数据保护条例》(General Data Protection Regulation,简称“GDPR”)及相关法律法规要求。无论您是否位于欧盟境内,只要您是欧盟居民,或我们处理的是欧盟居民的个人数据,均适用本政策。
请您在使用我们的产品/服务前,仔细阅读并理解本政策全部内容。您使用我们的产品/服务,即表示您同意我们按照本政策处理您的个人数据。
一、数据控制者信息
数据控制者:深圳声动健康科技有限公司
注册地址/主要经营地址:深圳市宝安区西乡街道固兴社区航城大道敦发工业园C栋403
联系邮箱(数据保护相关):emily.wang@snmtek.com
数据保护官(DPO,如适用):王消静,联系邮箱:emily.wang@snmtek.com
二、个人数据的收集范围与方式
2.1 收集的个人数据类型
我们仅收集实现产品/服务功能所必需的个人数据,遵循“数据最小化”原则,不收集与服务无关的信息,具体包括:
• 身份识别数据:姓名、电子邮箱地址、电话号码、身份证/护照号码(如涉及跨境服务或身份验证);
• 使用数据:您使用我们产品/服务的行为记录,包括浏览记录、点击记录、使用时长、操作偏好、设备信息(设备型号、操作系统、IP地址、浏览器类型);
• 交易数据:若您使用付费服务,包括支付金额、支付方式、交易记录、收货地址(如适用);
• 同意数据:您对个人数据处理的同意记录、同意日期及撤回同意的记录;
• 特殊类别个人数据:如无明确、单独的书面同意,我们绝不收集种族或民族 origin、政治观点、宗教或哲学信仰、工会成员身份、基因数据、生物识别数据、健康数据、性生活或性取向相关数据(GDPR第9条规定的特殊类别数据)。
2.2 收集方式
• 主动提供:您在注册账号、填写表单、提交咨询、进行交易时,主动向我们提供的个人数据;
• 自动收集:通过我们的网站、APP、服务器日志等技术手段,自动收集您使用产品/服务时产生的使用数据和设备数据(如IP地址、浏览器类型等),此类数据不单独识别个人身份,仅用于服务优化和安全保障;
• 第三方来源:仅在您明确同意或法律允许的情况下,从合法合规的第三方(如支付服务商、身份验证服务商)获取您的必要个人数据,且会对第三方提供的数据进行合规性验证。
三、个人数据的使用目的与法律依据
3.1 使用目的
我们使用您的个人数据仅用于以下合法目的,且不超出实现服务所需的范围:
• 为您提供产品/服务,完成账号注册、登录、交易、咨询响应等核心功能;
• 优化产品/服务体验,分析用户使用行为,改进功能设计、提升服务稳定性和安全性;
• 向您发送产品更新、服务通知、重要提醒(非营销类);
• 处理您的投诉、反馈,解决服务过程中出现的问题;
• 遵守法律法规要求,履行法定义务(如税务申报、合规审计);
• 防止欺诈、盗用等违法违规行为,保障您的账号安全和我们的合法权益;
• 在您明确同意的情况下,向您发送营销信息(您可随时撤回同意)。
3.2 法律依据(GDPR第6条)
我们处理您个人数据的法律依据包括:
• 您的明确同意(如同意接收营销信息、同意收集设备数据);
• 履行与您之间的合同,为提供您请求的产品/服务所必需;
• 遵守我们的法定义务(如税务、审计、数据留存相关法律要求);
• 追求合法利益(如优化服务、防止欺诈),且该合法利益不损害您的个人数据权益。
四、个人数据的存储规则
4.1 存储地点
我们将您的个人数据存储在欧盟境内的服务器上;若因业务需要,需将数据传输至欧盟境外,将严格遵守GDPR第48-50条关于跨境数据传输的要求:
• 仅传输至欧盟委员会认定的“数据保护水平充分”的国家/地区;
• 若传输至未被认定的国家/地区,将签订欧盟标准合同条款(SCCs),或采取加密、匿名化等适当保障措施,确保数据保护水平不低于GDPR要求;
• 跨境数据传输前,将向您告知传输目的、接收方、保障措施等信息(如涉及您的核心权益)。
4.2 存储期限
我们遵循“存储限制”原则,仅在实现收集目的所需的最短期限内存储您的个人数据:
• 核心服务相关数据(如账号信息、交易记录):存储至您注销账号后1年,或满足法律规定的留存期限(如税务留存要求);
• 使用数据(如浏览记录、操作日志):存储至服务优化目的实现后6个月,或法律另有规定;
• 同意记录:存储至您撤回同意后6个月,或法律要求的更长期限;
• 若数据存储期限届满,我们将采取删除、匿名化(使其无法识别个人身份)等措施,彻底销毁相关数据,不得用于任何其他目的。
4.3 存储安全
我们采取符合GDPR要求的技术和管理措施,保障您的个人数据安全,防止数据泄露、损毁、丢失、篡改、非法访问:
• 技术措施:采用SSL/TLS加密传输、数据加密存储、访问控制、入侵检测与防御系统、定期安全审计;
• 管理措施:明确数据访问权限、对员工进行数据保护培训、签订保密协议、建立数据安全管理制度;
• 数据泄露应对:若发生个人数据泄露,将在72小时内通知欧盟数据保护机构(DPA)和受影响的您(如泄露可能对您的权益造成高风险),并采取补救措施,降低风险。
五、个人数据的披露与共享
我们承诺不向任何无关第三方出售、出租、共享您的个人数据,仅在以下情况下,在符合GDPR要求的前提下披露或共享:
• 获得您的明确书面同意;
• 为履行与您的合同,向必要的第三方服务提供商(如支付服务商、物流服务商)共享,且仅共享实现服务所需的最小范围数据,同时与第三方签订数据处理协议(DPA),要求其遵守GDPR及相关规定,对数据进行严格保护;
• 遵守法律法规要求,响应司法机关、行政机关的合法请求(如法院传票、行政调查);
• 为保护您的合法权益、我们的合法权益或公共利益,在紧急情况下(如防止欺诈、保护人身安全)的必要披露;
• 公司合并、分立、收购、清算等情形下,个人数据作为资产的一部分进行转移,且受让方需继续遵守本政策及GDPR要求。
六、您的个人数据权利(GDPR赋予)
作为欧盟居民,您依法享有以下个人数据权利,我们将免费为您提供相关服务,无不合理拖延:
• 访问权:您有权要求我们确认是否在处理您的个人数据,并获取您的个人数据副本、处理目的、存储期限、共享对象等相关信息;
• 更正权:若您的个人数据存在不准确、不完整的情况,有权要求我们及时更正;
• 删除权(被遗忘权):在以下情况下,您有权要求我们删除您的个人数据:数据已无使用必要、您撤回同意、我们的处理行为违法、法律要求删除;
• 限制处理权:您有权要求我们暂停处理您的个人数据(如对数据准确性有异议、处理行为违法),直至相关问题解决;
• 数据可携权:您有权要求我们以结构化、常用、机器可读的格式,提供您的个人数据副本,并可要求我们将数据传输至另一数据控制者(在技术可行的情况下);
• 反对权:您有权反对我们基于“合法利益”或“营销目的”处理您的个人数据,我们将停止相关处理(除非有合法理由或法律要求继续处理);
• 撤回同意权:您可随时撤回对个人数据处理的同意(如撤回营销信息接收同意),撤回同意不影响撤回前我们基于您的同意所进行的合法数据处理。
若您希望行使上述权利,请通过本政策第一条提供的联系邮箱与我们联系,我们将在30个工作日内响应您的请求(复杂情况可延长至60个工作日,并及时告知您)。
七、Cookie及类似技术的使用
我们使用Cookie及类似技术(如像素标签),用于优化网站/APP体验、分析使用行为、保障服务安全,具体规则如下:
• 必要Cookie:用于实现核心服务功能(如账号登录、交易安全),无法禁用,否则将影响服务使用;
• 非必要Cookie:用于分析使用行为、个性化推荐、营销推广,您可在浏览器/APP设置中禁用,禁用后不影响核心服务使用;
• 我们将在您首次访问时,明确告知您Cookie的使用类型、目的,获得您的同意后再使用非必要Cookie,您可随时更改同意设置。
八、政策的更新与通知
我们将根据GDPR及相关法律法规的更新、产品/服务的变化,不定期更新本隐私政策。更新后的政策将通过我们的官方网站(即本政策开头提供的URL)、APP弹窗等方式通知您,更新后的政策自发布之日起生效。
若更新内容涉及您的核心权益(如数据收集范围、使用目的、您的权利),我们将在更新前7个工作日通知您,您继续使用我们的产品/服务,即表示同意更新后的政策。
九、投诉与争议解决
若您认为我们的个人数据处理行为违反GDPR或本政策,可首先通过本政策第一条提供的联系邮箱与我们联系,我们将及时调查并处理。
若您对我们的处理结果不满意,有权向您所在国家/地区的欧盟数据保护机构(DPA)提起投诉,我们将积极配合DPA的调查工作。
十、其他
本政策的最终解释权归深圳声动健康科技有限公司所有。若本政策与GDPR及相关法律法规相冲突,以GDPR及相关法律法规为准。
Privacy Policy (GDPR Compliant Version)
Effective Date: March 12, 2026
Official URL of Privacy Policy: https://www.nelpo.com/pages/privacy-policy-gdpr-compliant-version (Please replace with your valid static HTML page URL, which must comply with: standard http/https format, no login/jump required, automatable reading, not a blog/cloud note/file format, and consistent with the content displayed in your APP/website)
This Privacy Policy (hereinafter referred to as "this Policy") is formulated by [Shenzhen SNM Tech Co.,Ltd.] (hereinafter referred to as "we") to clarify the rules for us to collect, use, store, transmit, and disclose your personal data, protect your personal data rights and interests, and strictly comply with the requirements of the European Union's General Data Protection Regulation (GDPR) and relevant laws and regulations. Whether you are located within the European Union or not, this Policy shall apply if you are an EU resident or if the personal data we process belongs to an EU resident.
Please carefully read and understand the entire content of this Policy before using our products/services. Your use of our products/services indicates that you agree to our processing of your personal data in accordance with this Policy.
1. Information of the Data Controller
Data Controller: Shenzhen SNM Tech Co.,Ltd.
Registered Address/Principal Place of Business: Room 403, Building C, Dunfa Industrial Park, Hangcheng Avenue, Guxing Community, Xixiang Subdistrict, Bao'an District, Shenzhen, Guangdong, China
Contact Email (for Data Protection): emily.wang@snmtek.com
Data Protection Officer (DPO, if applicable): Emily, Contact Email: emily.wang@snmtek.com
2. Scope and Methods of Collecting Personal Data
2.1 Types of Personal Data Collected
We only collect personal data necessary for the functions of our products/services, adhering to the principle of "data minimization" and not collecting information irrelevant to the services. Specifically, it includes:
• Identity Data: Name, email address, phone number, ID/passport number (if involving cross-border services or identity verification);
• Usage Data: Records of your behavior when using our products/services, including browsing history, click records, usage duration, operation preferences, and device information (device model, operating system, IP address, browser type);
• Transaction Data: If you use paid services, including payment amount, payment method, transaction records, and shipping address (if applicable);
• Consent Data: Records of your consent to personal data processing, date of consent, and records of withdrawal of consent;
• Special Category Personal Data: Without your explicit and separate written consent, we will never collect data related to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or sexual life or sexual orientation (special category data specified in Article 9 of GDPR).
2.2 Methods of Collection
• Active Provision: Personal data you actively provide to us when registering an account, filling out forms, submitting inquiries, or conducting transactions;
• Automatic Collection: Through our websites, APPs, server logs and other technical means, automatically collect usage data and device data generated when you use our products/services (such as IP address, browser type, etc.). Such data does not identify individuals alone and is only used for service optimization and security protection;
• Third-Party Sources: Only with your explicit consent or as permitted by law, we will obtain your necessary personal data from legally compliant third parties (such as payment service providers, identity verification service providers), and we will conduct compliance verification on the data provided by third parties.
3. Purposes and Legal Bases for Using Personal Data
3.1 Purposes of Use
We use your personal data only for the following legitimate purposes and within the scope necessary to provide services:
• To provide you with products/services and complete core functions such as account registration, login, transactions, and inquiry responses;
• To optimize the product/service experience, analyze user behavior, and improve function design, service stability and security;
• To send you product updates, service notifications, and important reminders (non-marketing);
• To handle your complaints and feedback and resolve problems arising in the service process;
• To comply with legal and regulatory requirements and fulfill legal obligations (such as tax declaration, compliance audit);
• To prevent fraudulent, theft and other illegal activities and protect the security of your account and our legitimate rights and interests;
• To send you marketing information with your explicit consent (you can withdraw your consent at any time).
3.2 Legal Bases (Article 6 of GDPR)
The legal bases for us to process your personal data include:
• Your explicit consent (such as consent to receive marketing information, consent to collect device data);
• Performance of the contract with you, which is necessary to provide the products/services you request;
• Compliance with our legal obligations (such as legal requirements related to tax and data retention);
• Pursuit of legitimate interests (such as optimizing services, preventing fraud), and such legitimate interests do not harm your personal data rights and interests.
4. Rules for Storing Personal Data
4.1 Storage Location
We store your personal data on servers located within the European Union; if it is necessary to transmit data outside the European Union due to business needs, we will strictly comply with the requirements of Articles 48-50 of GDPR on cross-border data transmission:
• Transmit only to countries/regions recognized by the European Commission as having "adequate level of data protection";
• If transmitting to a country/region not recognized, we will sign EU Standard Contractual Clauses (SCCs) or take appropriate safeguards such as encryption and anonymization to ensure that the level of data protection is not lower than the requirements of GDPR;
• Before cross-border data transmission, we will inform you of the purpose of transmission, the recipient, safeguards and other information (if it involves your core rights and interests).
4.2 Storage Period
We follow the principle of "storage limitation" and only store your personal data for the shortest period necessary to achieve the purpose of collection:
• Core service-related data (such as account information, transaction records): stored for 1 year after you cancel your account, or for the retention period required by law (such as tax retention requirements);
• Usage data (such as browsing history, operation logs): stored for 6 months after the purpose of service optimization is achieved, or as otherwise required by law;
• Consent records: stored for 6 months after you withdraw your consent, or for a longer period required by law;
• If the data storage period expires, we will take measures such as deletion and anonymization (making it impossible to identify individuals) to completely destroy the relevant data, which shall not be used for any other purposes.
4.3 Storage Security
We take technical and management measures that meet the requirements of GDPR to ensure the security of your personal data and prevent data leakage, damage, loss, tampering, and illegal access:
• Technical Measures: Adopt SSL/TLS encrypted transmission, encrypted data storage, access control, intrusion detection and prevention systems, and regular security audits;
• Management Measures: Clarify data access rights, provide data protection training for employees, sign confidentiality agreements, and establish data security management systems;
• Data Breach Response: In the event of a personal data breach, we will notify the EU Data Protection Authority (DPA) and the affected you within 72 hours (if the breach may pose a high risk to your rights and interests), and take remedial measures to reduce risks.
5. Disclosure and Sharing of Personal Data
We commit not to sell, rent, or share your personal data to any irrelevant third parties. We will only disclose or share it in accordance with the requirements of GDPR in the following circumstances:
• Obtain your explicit written consent;
• To perform the contract with you, share with necessary third-party service providers (such as payment service providers, logistics service providers), and only share the minimum scope of data necessary to provide services. At the same time, sign a Data Processing Agreement (DPA) with third parties, requiring them to comply with GDPR and relevant regulations and strictly protect the data;
• Comply with legal and regulatory requirements and respond to legitimate requests from judicial and administrative authorities (such as court subpoenas, administrative investigations);
• Necessary disclosure in emergency situations (such as preventing fraud, protecting personal safety) to protect your legitimate rights and interests, our legitimate rights and interests, or public interests;
• In the event of company merger, division, acquisition, liquidation, etc., personal data is transferred as part of the assets, and the transferee shall continue to comply with this Policy and GDPR requirements.
6. Your Personal Data Rights (Granted by GDPR)
As an EU resident, you have the following personal data rights in accordance with the law, and we will provide you with relevant services free of charge without unreasonable delay:
• Right of Access: You have the right to require us to confirm whether we are processing your personal data, and to obtain a copy of your personal data, processing purposes, storage period, sharing objects and other relevant information;
• Right to Rectification: If your personal data is inaccurate or incomplete, you have the right to require us to correct it in a timely manner;
• Right to Erasure (Right to be Forgotten): In the following circumstances, you have the right to require us to delete your personal data: the data is no longer necessary for the purpose of use, you withdraw your consent, our processing behavior is illegal, or the law requires deletion;
• Right to Restriction of Processing: You have the right to require us to suspend the processing of your personal data (such as objection to the accuracy of data, illegal processing behavior) until the relevant issues are resolved;
• Right to Data Portability: You have the right to require us to provide a copy of your personal data in a structured, commonly used, machine-readable format, and may require us to transmit the data to another data controller (if technically feasible);
• Right to Object: You have the right to object to our processing of your personal data based on "legitimate interests" or "marketing purposes", and we will stop the relevant processing (unless there are legitimate reasons or legal requirements to continue processing);
• Right to Withdraw Consent: You can withdraw your consent to personal data processing at any time (such as withdrawing consent to receive marketing information). The withdrawal of consent does not affect the legal data processing we conducted based on your consent before the withdrawal.
If you wish to exercise the above rights, please contact us through the contact email provided in Section 1 of this Policy. We will respond to your request within 30 working days (complex cases can be extended to 60 working days, and we will inform you in a timely manner).
7. Use of Cookies and Similar Technologies
We use Cookies and similar technologies (such as pixel tags) to optimize the website/APP experience, analyze usage behavior, and ensure service security. The specific rules are as follows:
• Necessary Cookies: Used to implement core service functions (such as account login, transaction security), which cannot be disabled, otherwise it will affect the use of services;
• Non-necessary Cookies: Used for analyzing usage behavior, personalized recommendations, and marketing promotions. You can disable them in browser/APP settings, and disabling them will not affect the use of core services;
• When you visit for the first time, we will clearly inform you of the type and purpose of Cookies, and use non-necessary Cookies only after obtaining your consent. You can change your consent settings at any time.
8. Update and Notification of the Policy
We will update this Privacy Policy from time to time in accordance with the updates of GDPR and relevant laws and regulations, and changes in products/services. The updated policy will be notified to you through our official website (i.e., the URL provided at the beginning of this Policy), APP pop-up windows, etc., and the updated policy will take effect on the date of publication.
If the updated content involves your core rights and interests (such as the scope of data collection, purpose of use, your rights), we will notify you 7 working days before the update. Your continued use of our products/services indicates that you agree to the updated policy.
9. Complaints and Dispute Resolution
If you believe that our personal data processing behavior violates GDPR or this Policy, you can first contact us through the contact email provided in Section 1 of this Policy, and we will investigate and handle it in a timely manner.
If you are not satisfied with our handling result, you have the right to file a complaint with the EU Data Protection Authority (DPA) in your country/region, and we will actively cooperate with the DPA's investigation.
10. Others
The final interpretation right of this Policy belongs to Shenzhen SNM Tech Co.,Ltd. If this Policy conflicts with GDPR and relevant laws and regulations, GDPR and relevant laws and regulations shall prevail.





