EU Data Act Notice
EU Data Act Notice
EU Data Act Notice
Version: v1.0
Effective Date: 2026.01.20
This Notice is provided in accordance with the EU Data Act (Regulation (EU) 2023/2854) (the "EU Data Act").
1. Data Holder Information
Data Holder: Shenzhen Firstnum E-commerce Co., Ltd
Registered Address: UNIT A ON 20TH FLOOR WANG CHEONG BUILDING NO.251 RECLAMATION STREET KOWLOON H
We act as the data holder under the EU Data Act for the connected products described below.
2. Connected Products Overview
Connected Product means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user.
The functions of these connected products, as well as details regarding the data they generate and how it is handled, are described in the following sections of this notice.
3. Data Generated/Collected by Connected Products
| Data Name | Data Type | Data Processing Purposes | Data Format | Estimated Volume | Whether generating data continuously and in real time | Intended Retention Period | Storage Location | Data Nature | Data Erasure | Security Measures | Trade secret | Data Sharing Interface |
| Device identification information (serial number/model/hardware version/wireless MAC) | Connected Product Data - Device Identification | Equipment identification, registration binding, after-sales and compliance traceability; Network interface management | JSON/Key Value Pair | Several tens of bytes - several KB/device | No | Equipment lifecycle; Unbind/Restore Factory and Clear Binding Copy | Local NVRAM/Flash of the device; Synchronize to cloud bound library if necessary | Personal data | Factory reset: Clear configuration and identification associations; After unbinding from the cloud, delete according to the policy (such as 30 days) | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Firmware/Software Version and Component List(Firmware/Driver) | Product Data - Software Status | Equipment operation and security maintenance (compatibility, vulnerability repair, upgrade decision) | JSON/Text version | Few KB/device | YES | Local permanent | Device local Flash; Cloud log/asset repository (if enabled) | Non personal data | Restore factory and delete local records; Cloud based deletion or anonymization based on support period/legal deadline | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| System operational status (startup time/runtime duration/remaining battery) | Product Data - Operational Telemetry | Fault diagnosis, stability improvement, and after-sales analysis | JSON/Log Text | Several tens of bytes per event; 0.1-1MB per day | YES | Local rolling for 7-30 days | Local log area of the device; Optional upload to cloud diagnostic database | Non personal data | Local log scrolling coverage; User triggers log clearing/factory reset; Cloud based automatic deletion based on retention period | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| LAN parameters (LAN IP/subnet) | Product Data - Network Configuration (User Input) | Provide local network connectivity, address planning, and management | JSON/Key Value Pair | Few KB/device | NO | Device lifecycle or user settings | Local NVRAM/Flash of the device; Optional cloud configuration backup | Non personal data | Reset to factory settings and clear; Cloud backup deleted after unbinding/logging out (e.g. 30 days) | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| DHCP lease and connected terminal list (MAC/hostname/IP) | Product Data - Terminal Connection Data | Network management, troubleshooting, parental control/visitor network management | JSON/SQLite | As the number of terminals increases: 0.5-2KB per terminal; daily variation of 0.1-5MB | YES | Local rolling for 7-30 days (configurable) | Device local running memory+local database; Optional cloud | Personal data | Clear history/restore factory immediately delete; Cloud based automatic deletion based on retention period | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Wireless network configuration (SSID/encryption mode/channel) | Product Data - Wireless Configuration (User Input) | Provide Wi-Fi access and performance optimization; Compliance and Interference Management | JSON | Few KB/device | NO | Device lifecycle or user settings | Local NVRAM/Flash of the device | Non personal data | Restore factory deletion; Users can manually clear/reset | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Wireless key/credential (Wi Fi PSK) | Product Data - Security Credentials (User Input) | Identity verification and access control ensure device and network security | Encrypt storage/hash (not saved in plaintext) | Several tens of bytes - several KB | NO | Device lifecycle or user settings | Device local secure storage area (Flash/NVRAM) | Personal data | Restore factory deleted key materials; Support users to modify/reset; Cloud does not save plaintext |
Sensitive data is stored only in hashed/encrypted form; implement key isolation; strict identity auth for admin interfaces; brute-force attack resistance enabled; TLS transmission adopted. | NO | YES |
| Device Health Indicators (CPU) |
Product Data - Device Health Telemetry | Stability monitoring | JSON | 0.1-2MB/day | YES | Local 7-30 days | Local device; Optional cloud | Non personal data | Restore the factory and clear the local environment; Cloud based deletion by retention period | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Time and Time Zone/Synchronization Status (NTP Server) | Product Data - System Configuration/Status | Ensure that the logs are consistent with the security protocol time | JSON | Several tens of KB/device | YES | Local rolling for 30 days | Local device | Non personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Cellular Network Identity Identification (IMSI/IMEI/ICCID/eSIM Profile ID) | Product Data - Core Network Identification | Register, authenticate, and connect in cellular networks; Equipment Management and Compliance | JSON | Several tens of KB/device | NO | Local permanent | Local device | Non personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Cellular network connection status and telemetry (signal quality/network type/operator name) | Product Data - Network Telemetry | Network selection and optimization, signal display | JSON | Several tens of KB/device | NO | Local rolling for 7-30 days | Local device | Non personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| SMS function data (inbox/outbox, SMS content, sender number, timestamp) | Product Data - Communication Data | Receive operator SMS (balance, verification code) and service messages | JSON | Several tens of KB/device | NO | Local permanent | Local device | Personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Contact information (name, phone number) | User Data - Address Book | Used for contact recognition and management in SMS or communication functions | JSON | Several tens of KB/device | NO | Local permanent | Local device | Personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| Reference Knowledge 33/1000 Translation Machine · General Field APN configuration (access point name, username, password, authentication type, protocol, roaming protocol) |
Product Data - Cellular Network Configuration | Configure the device to correctly access the mobile data network of the operator and realize Internet access | JSON | Several tens of KB/device | No | Local rolling for 7-30 days | Local device | Non personal data | Restore factory clearance; Rolling overlay | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
| ESIM card PIN code (PIN, PUK) | Security credentials - card lock | Verify user identity, unlock eSIM/SIM card to enable cellular network and prevent unauthorized use | JSON | Several tens of KB/device | No | Local permanent | SIM card | Personal data | Restore factory clearance; Do not clear | Device side access control (administrator/user roles), minimum permissions; Sensitive configuration encryption/ciphertext storage; Local management and interface use HTTPS/TLS; Key operation audit logs. | NO | YES |
Data means any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audio-visual recording.
4. User Data Access, Erasure and Portability
Individuals or legal entities using our Connected Products hereinafter referred to as ("Users") have the right, in accordance with the EU Data Act, to request access to, erasure of, or portability of data generated/collected by Connected Products.
These requests can be submitted via [9. Contact and Data Request Channel]
5. Data Sharing and Compliance with Requests for Data
Data generated by our Connected Products may be shared with third parties under Articles 4 to 7 of the EU Data Act, applicable to the following requesters:
5.1 Business-to-Business (B2B) Access Requests
Exclusively based on the User’s explicit consent;
Contracts shall specify: Purpose limitation, Confidentiality obligations, Data security measures, and Prohibition of misuse.
5.2 Business-to-Government (B2G) Access Requests
Based on Article 14-18 of the EU Data Act, data may be shared with public authorities:
Permitted under Article 15 for emergencies or legitimate public tasks (e.g., natural disasters, public safety, pandemics);
Data transmitted via encrypted secure channels with strict purpose binding;
Government entities must submit formal written requests with access logging;
The data minimisation principle applies to all shared datasets.
5.3 Third Parties Requests Submission
Third parties may submit formal requests through [9.Contact and Data Request Channel].
6. Data Security and Protection Mechanism
To ensure the security of data generated by Connected Products manufactured by Shenzhen Firstnum E-commerce Co., Ltd, we implement the following technical and organizational safeguards throughout the processes of data transmission, storage, and access:
l Implement full security encryption during storage and transmission to prevent data from unauthorised access, use or disclosure (such as by using SSL to encrypt many Services).
l Regularly review practices regarding data collection, storage and processing (including physical security measures) to prevent unauthorised access to or tampering with our various systems and data.
l Establish access rights management mechanism to authorize only necessary personnel to access data.
l Conduct security and privacy protection training, testing and other activities to enhance employee awareness of and proficiency in data protection.
l Use international and industry-recognised standards to protect your data and actively pursue relevant security and privacy protection accreditation.
7. Interoperability Notes
We ensure that the recipient can process the data in a structured, commonly used and machine-readable format in order to comply with the interoperability requirements of Articles 33 of the EU Data Act.
8. Data Use Restrictions and Prohibited Purposes
Without Shenzhen Firstnum E-commerce Co., Ltd’s express written authorization or, unless legally required, data shall not be used for the following purposes:
-Development of competing products;
-Reverse engineering of algorithms;
-Targeted advertising or profiling of users.
Any breach of these restrictions may result in legal consequences and revocation of access.
9. Contact and Data Request Channel
Responsible Person: Rock
Email Address:12745310@qq.com
10. Policy Updates
This policy will be updated regularly based on legal requirements and business needs. All updates will be announced through our official website and related channels.
