EU Data Act Notice

EU Data Act Notice

EU Data Act Notice

Version: v1.0

Effective Date: 2026.01.20

This Notice is provided in accordance with the EU Data Act (Regulation (EU) 2023/2854) (the "EU Data Act").

1. Data Holder Information

Data Holder: Shenzhen Firstnum E-commerce Co., Ltd

Registered Address: UNIT A ON 20TH FLOOR WANG CHEONG BUILDING NO.251 RECLAMATION STREET KOWLOON H

We act as the data holder under the EU Data Act for the connected products described below.

2. Connected Products Overview

Connected Product means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user.

The functions of these connected products, as well as details regarding the data they generate and how it is handled, are described in the following sections of this notice.

3. Data Generated/Collected by Connected Products

Data Name Data Type Data Processing Purposes Data Format Estimated Volume Whether generating data continuously and in real time Intended Retention Period Storage Location Data Nature Data Erasure Security Measures Trade secret Data Sharing Interface
Device identification information (serial number/model/hardware version/wireless MAC) Connected Product Data - Device Identification Equipment identification, registration binding, after-sales and compliance traceability; Network interface management JSON/Key Value Pair Several tens of bytes - several KB/device No Equipment lifecycle; Unbind/Restore Factory and Clear Binding Copy Local NVRAM/Flash of the device; Synchronize to cloud bound library if necessary Personal data Factory reset: Clear configuration and identification associations; After unbinding from the cloud, delete according to the policy (such as 30 days) Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Firmware/Software Version and Component List(Firmware/Driver) Product Data - Software Status Equipment operation and security maintenance (compatibility, vulnerability repair, upgrade decision) JSON/Text version Few KB/device YES Local permanent Device local Flash; Cloud log/asset repository (if enabled) Non personal data Restore factory and delete local records; Cloud based deletion or anonymization based on support period/legal deadline Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
System operational status (startup time/runtime duration/remaining battery) Product Data - Operational Telemetry Fault diagnosis, stability improvement, and after-sales analysis JSON/Log Text Several tens of bytes per event; 0.1-1MB per day YES Local rolling for 7-30 days Local log area of the device; Optional upload to cloud diagnostic database Non personal data Local log scrolling coverage; User triggers log clearing/factory reset; Cloud based automatic deletion based on retention period Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
LAN parameters (LAN IP/subnet) Product Data - Network Configuration (User Input) Provide local network connectivity, address planning, and management JSON/Key Value Pair Few KB/device NO Device lifecycle or user settings Local NVRAM/Flash of the device; Optional cloud configuration backup Non personal data Reset to factory settings and clear; Cloud backup deleted after unbinding/logging out (e.g. 30 days) Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
DHCP lease and connected terminal list (MAC/hostname/IP) Product Data - Terminal Connection Data Network management, troubleshooting, parental control/visitor network management JSON/SQLite As the number of terminals increases: 0.5-2KB per terminal; daily variation of 0.1-5MB YES Local rolling for 7-30 days (configurable) Device local running memory+local database; Optional cloud Personal data Clear history/restore factory immediately delete; Cloud based automatic deletion based on retention period Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Wireless network configuration (SSID/encryption mode/channel) Product Data - Wireless Configuration (User Input) Provide Wi-Fi access and performance optimization; Compliance and Interference Management JSON Few KB/device NO Device lifecycle or user settings Local NVRAM/Flash of the device Non personal data Restore factory deletion; Users can manually clear/reset Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Wireless key/credential (Wi Fi PSK) Product Data - Security Credentials (User Input) Identity verification and access control ensure device and network security Encrypt storage/hash (not saved in plaintext) Several tens of bytes - several KB NO Device lifecycle or user settings Device local secure storage area (Flash/NVRAM) Personal data Restore factory deleted key materials; Support users to modify/reset; Cloud does not save plaintext
Sensitive data is stored only in hashed/encrypted form; implement key isolation; strict identity auth for admin interfaces; brute-force attack resistance enabled; TLS transmission adopted. NO YES
Device Health Indicators (CPU)
Product Data - Device Health Telemetry Stability monitoring JSON 0.1-2MB/day YES Local 7-30 days Local device; Optional cloud Non personal data Restore the factory and clear the local environment; Cloud based deletion by retention period Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Time and Time Zone/Synchronization Status (NTP Server) Product Data - System Configuration/Status Ensure that the logs are consistent with the security protocol time JSON Several tens of KB/device YES Local rolling for 30 days Local device Non personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Cellular Network Identity Identification (IMSI/IMEI/ICCID/eSIM Profile ID) Product Data - Core Network Identification Register, authenticate, and connect in cellular networks; Equipment Management and Compliance JSON Several tens of KB/device NO Local permanent Local device Non personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Cellular network connection status and telemetry (signal quality/network type/operator name) Product Data - Network Telemetry Network selection and optimization, signal display JSON Several tens of KB/device NO Local rolling for 7-30 days Local device Non personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
SMS function data (inbox/outbox, SMS content, sender number, timestamp) Product Data - Communication Data Receive operator SMS (balance, verification code) and service messages JSON Several tens of KB/device NO Local permanent Local device Personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Contact information (name, phone number) User Data - Address Book Used for contact recognition and management in SMS or communication functions JSON Several tens of KB/device NO Local permanent Local device Personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
Reference Knowledge 33/1000 Translation Machine · General Field APN configuration (access point name, username, password, authentication type, protocol, roaming protocol)

Product Data - Cellular Network Configuration Configure the device to correctly access the mobile data network of the operator and realize Internet access JSON Several tens of KB/device No Local rolling for 7-30 days Local device Non personal data Restore factory clearance; Rolling overlay Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES
ESIM card PIN code (PIN, PUK) Security credentials - card lock Verify user identity, unlock eSIM/SIM card to enable cellular network and prevent unauthorized use JSON Several tens of KB/device No Local permanent SIM card Personal data Restore factory clearance; Do not clear Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. NO YES


 

Data means any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audio-visual recording.

4. User Data Access, Erasure and Portability

Individuals or legal entities using our Connected Products hereinafter referred to as ("Users") have the right, in accordance with the EU Data Act, to request access to, erasure of, or portability of data generated/collected by Connected Products.

These requests can be submitted via [9. Contact and Data Request Channel]

5. Data Sharing and Compliance with Requests for Data

Data generated by our Connected Products may be shared with third parties under Articles 4 to 7 of the EU Data Act, applicable to the following requesters:

5.1 Business-to-Business (B2B) Access Requests

Exclusively based on the Users explicit consent;

Contracts shall specify: Purpose limitation, Confidentiality obligations, Data security measures, and Prohibition of misuse.

5.2 Business-to-Government (B2G) Access Requests

Based on Article 14-18 of the EU Data Act, data may be shared with public authorities:

Permitted under Article 15 for emergencies or legitimate public tasks (e.g., natural disasters, public safety, pandemics);

Data transmitted via encrypted secure channels with strict purpose binding;

Government entities must submit formal written requests with access logging;

The data minimisation principle applies to all shared datasets.

5.3 Third Parties Requests Submission

Third parties may submit formal requests through [9.Contact and Data Request Channel].

6. Data Security and Protection Mechanism

To ensure the security of data generated by Connected Products manufactured by Shenzhen Firstnum E-commerce Co., Ltd, we implement the following technical and organizational safeguards throughout the processes of data transmission, storage, and access:

l  Implement full security encryption during storage and transmission to prevent data from unauthorised access, use or disclosure (such as by using SSL to encrypt many Services).

l  Regularly review practices regarding data collection, storage and processing (including physical security measures) to prevent unauthorised access to or tampering with our various systems and data.

l  Establish access rights management mechanism to authorize only necessary personnel to access data.

l  Conduct security and privacy protection training, testing and other activities to enhance employee awareness of and proficiency in data protection.

l  Use international and industry-recognised standards to protect your data and actively pursue relevant security and privacy protection accreditation.

7. Interoperability Notes

We ensure that the recipient can process the data in a structured, commonly used and machine-readable format in order to comply with the interoperability requirements of Articles 33 of the EU Data Act.

8. Data Use Restrictions and Prohibited Purposes

Without Shenzhen Firstnum E-commerce Co., Ltd’s express written authorization or, unless legally required, data shall not be used for the following purposes:

-Development of competing products;

-Reverse engineering of algorithms;

-Targeted advertising or profiling of users.

Any breach of these restrictions may result in legal consequences and revocation of access.

9. Contact and Data Request Channel

Responsible Person: Rock

Email Address:12745310@qq.com

10. Policy Updates

This policy will be updated regularly based on legal requirements and business needs. All updates will be announced through our official website and related channels.