SKG Health Privacy Policy

Overview

SKG Health Technology Co., Ltd. and its affiliates (hereinafter referred to as “SKG”, “we”, “us” or “our”) attach great importance to your privacy. The SKG health App is a platform through which SKG provides device connection, health and wellness management, software technologies and related services. Product features may vary by country or region and by device model.
This Privacy Policy (hereinafter referred to as the “Policy”) applies to SKG Health App and explains how and why we collect, use, store, share, transfer and protect your personal data. If a different SKG affiliate acts as the controller, business, service provider or operating entity for your country or region, we will provide the relevant information in the App, on our website or through other appropriate means.
“Personal data” or “personal information” means any information relating to an identified or identifiable natural person. Depending on applicable law, personal data may include sensitive personal data, sensitive personal information, special category data or consumer health data. Health-related data generated by, measured by, or entered into SKG health may receive enhanced protection under applicable data protection laws.
We process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability. Where applicable laws require us to identify a legal basis, we rely on one or more of the following legal bases: performance of a contract or steps prior to entering into a contract; your consent or explicit consent; our legitimate interests, provided that such interests are not overridden by your rights and interests; compliance with legal obligations; protection of vital interests; and other legal bases permitted by applicable law.
This Policy will help you understand the following:
I. How We Collect and Use Your Information
II. How We Share and Disclose Your Information
III. International Data Transfers and Storage
IV. How We Protect Your Information
V. Children's Privacy
VI. Your Rights
VII. Updates to Privacy Policy
VIII. How to Contact Us
Please carefully read and understand this Policy before using our products or services. If you have any objections, comments or suggestions regarding this Policy, you may contact us through the contact information we provide.

I. How We Collect and Use Your Information

Personal Data Collected During Your Use of Products and Services

1. Personal Data Required for Core Functions

Certain functions are necessary for the basic operation of our products and services. If you do not provide the relevant personal data, we may be unable to provide the corresponding products or services to you. Where applicable law requires a legal basis, we generally process personal data for core functions to perform our contract with you and to maintain the security and proper operation of our services.
1.1 Account Registration, Login, Verification and Device Management
1.1.1 When you register an account for this App, you need to provide at least the password you intend to use, your mobile phone number or email address, and the country or region you select. We will verify whether your identity information is valid by sending you a verification code. We collect this data to help you complete registration. If you refuse to provide the above data, you will be unable to create an account in this App.
1.1.2 To manage the SKG smart devices bound by you, when you bind our devices, we need to collect your device identifiers, including MAC address; device hardware information; device usage information, including device name, device model, operating system and application version, language settings, unique device identifier, carrier network type and similar information; basic system information; location information; and network information. We collect such information for the purposes of better establishing Bluetooth connections, managing device configurations, completing software upgrades, displaying data sources and collecting statistics on device activation. Such data will also be used to improve your network connection experience and the compatibility between devices and system versions. If you refuse to provide the above information, we will be unable to complete device binding or provide device-related services.
1.2 Improvement of User Experience
When you use our functions or services, we will automatically collect details of your use of our services and store them as network logs. Such information includes the type of content you browse, the date and time of access, page access records and duration of stay. This type of data constitutes basic log information necessary for optimizing product system compatibility, maintaining network security and improving user experience. Where applicable law requires a legal basis, we process such logs based on our legitimate interests in maintaining security, troubleshooting, improving compatibility and improving our services, or where necessary to provide the App functions you request.

2. Personal Data You May Choose to Provide for Optional Functions

To make our products or services more convenient for you and improve your user experience, the following extended functions may collect and use your personal data. If you do not provide such personal data, you may still use the core functions of the products or services, but you may be unable to use the extended functions we provide to you. Where these optional functions involve health-related data, we generally rely on your consent or explicit consent where required by applicable law. These extended functions include:
2.1 Health Monitoring
For general health management and reference, when you use our watch products, we may collect your health related information, including blood pressure, blood oxygen, heart rate, resting heart rate, heart rate variability (HRV), stress, weight, sleep and fatigue level. We collect such data for the purposes of measuring, recording, displaying and calculating health-related data, so as to provide you with general wellness information and reference insights. If you refuse to provide the above data, you may be unable to use the health monitoring functions, but this will not affect your use of other functions of SKG health.
2.2 Health Profile
When you use the health profile function, we need to collect basic information voluntarily provided by you, such as gender, age, occupation, height, weight and sleep information. We collect such data to provide you with general wellness profiles, records, reference-based wellness plans and lifestyle suggestions. If you do not provide such data, you may be unable to conduct the relevant services, but this will not affect your use of other functions of SKG health.
2.3 Health Insights
When you bind an SKG smart device and choose to use the wellness insights, based on your explicit authorization and consent, we will collect your health data, including blood pressure, blood oxygen, ECG-related data, heart rate, resting heart rate, heart rate variability (HRV), stress, sleep and fatigue level. We will use intelligent algorithms to analyze possible patterns, changes or trends in your general wellness indicators. However, you should fully understand and agree that this function and the results of intelligent algorithm analysis are intended to provide health insight services and help you better understand your health status. They do not constitute medical diagnosis, clinical assessment, treatment advice, emergency monitoring or professional medical advice, and cannot replace the advice from qualified healthcare professionals. If you feel unwell, please consult a qualified healthcare professional. If you do not agree to provide the above information, you will be unable to use the health insights function, but this will not affect your use of other functions of SKG health. This function does not involve automated decision-making that produces legal effects concerning you or similarly significantly affects you.
2.4 Family Care Function
When you choose to use the family care function, you may independently add other accounts as your family members or friends. After you have agreed to our collection of relevant health information, and based on your explicit authorization and consent, we will, within the scope authorized by you, share the health information you choose to share with the family member or friend accounts designated by you. Such information may include blood pressure, blood oxygen, ECG related data, heart rate, resting heart rate, heart rate variability (HRV), stress, sleep and fatigue level. At the same time, you may also view the relevant health information shared by your family members or friends after obtaining their independent and explicit authorization within the App. While the family care function is enabled, if this App identifies any wellness notification relating to you or your family members or friends, the relevant notification will be pushed to the authorized family member or friend accounts. You and your family members or friends may independently decide whether to contact each other, provide care or take further action. You and your family members or friends should understand and agree that this App does not assume any form of legal liability for whether a family member or friend takes actual contact, care or medical assistance measures after receiving a notification. You may adjust, limit or cancel the scope of health information sharing, or unbind the family member or friend relationship, at any time. If you do not agree to provide the above information, you will be unable to use the family care function, but this will not affect your use of other functions of SKG health.
2.5 Q&A Function
When you use our Q&A module, we will collect the images, contact information, text, comments, likes and other data that you upload. The data and contact information you upload will only be used for communication and problem identification. If you do not provide such data, our developers may be unable to resolve the issues you encounter, but this will not affect your use of other functions of SKG health. Where applicable law requires a legal basis, we process such information to provide customer support requested by you and based on our legitimate interests in resolving issues and improving service quality.
2.6 Feedback Function
To improve the quality of our services and make it easier for you to provide feedback on problems or faults encountered when using our products and services, based on your consent, we will request access to your camera or photo album on the feedback page and collect the images you upload, so that we can better understand the issues you encounter during use. If you do not provide such data, you may be unable to provide feedback, but this will not affect your use of other functions of SKG health. Where applicable law requires a legal basis, we process such information based on your consent where device permissions are involved, and otherwise based on our legitimate interests in understanding feedback and improving our products and services.

Use of App Permissions

When you use SKG health, the following device permissions may be triggered. To help you better manage your data, we will inform you of the purpose of each permission when requesting it during your use of the product, as well as the possible impact on your use of the relevant services if you do not enable such permission. Before using a specific function, you may choose whether to authorize the following permissions. You may also change the authorization status at any time through the permission settings page of your device.
1. Bluetooth Permission: When you use SKG health to control hardware products and wish to connect the hardware products to SKG health for use, we will, after obtaining your consent, access the Bluetooth permission on your mobile phone for the purpose of enabling device control. If you refuse to grant this permission, you will be unable to use the above function, but this will not affect your normal use of other functions.
2. Location Permission: When you use location-related services, we may access your location permission in order to provide you with relevant services. If you do not provide location permission, you may be unable to search for nearby devices or use location-related services, but this will not affect your normal use of other functions.
3. Camera Permission: When you submit problem feedback in SKG health and take photos or videos to send us your relevant questions, you need to enable camera permission. If you refuse to enable camera permission, you will be unable to use the foregoing function, but this will not affect your normal use of other functions.
4. Calendar Permission (Android): You may enable the “Use Reminder” function and customize the time for using the product. When the customized time arrives, we will access your calendar permission and remind you through the calendar. If you refuse to enable this function, you will be unable to use the above function, but this will not affect your normal use of other functions.
5. Call Permission: When you connect an SKG smart watch through the App, you need to enable permissions for contacts and call logs so that the caller’s name can be displayed on the watch for incoming call reminders and so that you can call back from the watch. We will not collect your contacts or call log information. This permission is used only for the incoming call reminder function for Bluetooth calling. If you refuse to provide this information or refuse to enable contacts and call log permissions, you will only be unable to use the business function described above, and this will not affect your use of other functions of SKG health.
  1. 6. SMS Permission: When you connect an SKG smart watch through the App, you need to enable SMS permission so that you can receive SMS reminders on the watch. We will not collect the content of your SMS messages. This permission is used only for the SMS reminder function on the watch. If you refuse to provide this information or refuse to enable SMS permission, you will only be unable to use the business function described above, and this will not affect your use of other functions of SKG health.

Access to Third-Party Applications

When you connect a third-party application to our products or services, we may obtain necessary personal data from the developer or technical service provider of such third-party application for purposes such as providing integration support, service connection or technical support. If you refuse our collection of the relevant personal data, all or part of the third-party application functions may not be available, but this will not affect your use of other functions of our products or services.
The developers and technical service providers of such third-party applications may directly collect and use your personal data in accordance with their own privacy policies. We recommend that you read and understand those privacy policies before accepting the relevant services and providing your personal data. We will provide a third-party list or equivalent notice in the App or on our website where required by applicable law, including information such as the name of the third party, processing purpose, type of personal data involved, processing method and privacy policy link.

Use of Cookies or Similar Technologies

We may use cookies or similar technologies through web links to obtain and use your information and store such information as log information. Such technologies may help us improve login experience, analyze website or App performance, maintain security, prevent fraud and improve services.
We will not improperly associate log information collected through cookies or similar technologies with other personally identifiable information collected by us. If you wish to disable cookies or similar technologies, you may manage them through your device or browser settings. Please note that disabling them may affect certain personalized services, but will not affect the normal use of basic functions. Where required by applicable law, we will provide a cookie notice, consent management tool or opt-out mechanism for non-essential cookies, analytics technologies or advertising-related technologies.

Non-Personal Data

We may also collect other information that cannot directly or indirectly identify a specific individual and is not considered personal data under applicable law. Such information is referred to as non-personal information. We may collect, use, transfer and disclose non-personal information to optimize user experience, analyze business operations and improve service quality.
We will use reasonable efforts to separate your personal data from non-personal information and ensure that the two types of information are used separately. For purposes of this Policy, if we combine non-personal information with personal data, the combined information will be treated as personal data for as long as it remains combined.

Circumstances Where We May Process Personal Data Without Additional Consent

You understand that, where permitted by applicable law, we may collect, use or otherwise process your personal data without obtaining your additional consent in certain circumstances, including where:
  1. The processing is necessary to comply with applicable laws, regulations, legal procedures, or requests from competent governmental, regulatory, judicial or law enforcement authorities.
  2. The processing is necessary for us to perform statutory duties, regulatory obligations, product safety obligations, tax, accounting, consumer protection or other legal obligations.
  3. The processing is necessary to enter into or perform a contract or other agreement with you, or to provide the products or services you request.
  4. The processing is necessary to respond to emergencies, public health incidents, or to protect the life, health, safety, property or other vital interests of you or another individual.
  5. The processing is necessary to protect the security, integrity and normal operation of our products, services, systems and users, including detecting, preventing and addressing fraud, abuse, security incidents or technical issues.
  6. The personal data has been made publicly available by you, or is processed within a reasonable scope from information that has been lawfully and publicly disclosed, such as lawful news reports, government information disclosure or other lawful public sources.
  7. The processing is otherwise permitted or required by applicable laws and regulations.
Please understand that our functions and services may be updated and developed from time to time. If a function or service not described above collects or processes your personal data, we will inform you of the categories of personal data involved, the purposes of processing, and other information required by applicable law through page prompts, interactive processes, website or App announcements, separate agreements or other appropriate means, and will obtain your consent where required by applicable law.

II. How We Share and Disclose Your Information

We promise that we are not in the business of selling your personal information to others, which means that we will not exchange your personal information for monetary consideration. We share customers' personal information with SKG's affiliates, service providers or partners, in order to conduct business operations smoothly in providing you with the full capabilities of our products and services.
The parties with whom we may share or disclose your personal information include:
SKG Affiliated Entities. We may disclose personal information within our affiliated entities under common ownership and control within the SKG family of companies who are essential to maintaining our worldwide brand and service, enabling our global management, and enhancing our Services and your customer experience.
Third-Party Service Providers. We engage third-party companies and individuals to perform functions on our behalf. We may disclose your personal information to these providers so they can perform their services. These service providers have access only to the personal information needed to perform their functions and are contractually obligated to maintain its confidentiality and security. The types of service providers we use include:
  • Device Connection and Technical Service Providers. We may use service providers to support device binding, Bluetooth connection, device configuration, software updates, device activation statistics, troubleshooting and compatibility improvement.
  • Push Notification and Communication Service Providers. We may use service providers to send App notifications, device-related reminders, service messages, verification codes and other communications related to your use of SKG health.
  • Analytics, Crash Reporting and Security Service Providers. We may use analytics, crash reporting, log analysis and security service providers to identify and resolve errors, maintain service security, prevent fraud and abuse, improve App stability and optimize product performance.
  • Customer Support and Feedback Service Providers. We may use customer support, feedback management or communication tools to respond to your inquiries, handle problem reports, process feedback, locate issues and improve service quality.
  • Location, Weather or Map Service Providers. Where you use location-related services, we may use third-party service providers to support nearby device search, location records, weather information or other location-related functions, subject to your device permission settings and applicable law.
  • In-App Webpage and Functionality Providers. We may use third-party webview services or other technical tools to display H5 pages, support App functions, improve user experience or ensure compatibility.
We may provide a Third-Party List or equivalent disclosure in the App, on our website or through other appropriate channels to inform you about the third parties involved, the purposes of processing, the types of personal information processed, and links to relevant third-party privacy policies where applicable.
Third-Party Type of information collected Purpose and Scenario Privacy policy and contact information
AURORA SDK (Shenzhen Hexun Huagu Information Technology Co., Ltd.) a. Device parameters and system information (device type, device model, system version, SIM card status, screen resolution, device hardware manufacturer, device product name, device storage space, system name, and system language);
b. Device identifiers (IMEI, IDFA, Android ID, GAID, MAC address, OAID, AAID, IMSI, and UAID);
c. Network information (IP address, WiFi information, base station information, DNS address, DHCP address, SSID, and BSSID).
a. Used to identify device specifications, including device type, device model, and system version, to ensure accurate delivery of push notifications;
b. Used to identify unique users, ensuring the precise delivery of push notifications and the accurate statistics of push data;
c. Used to optimize network connection requests between the SDK and server, ensuring service stability and continuity, while enabling regional push notification features.
《Privacy Policy》:https://www.jiguang.cn/license/privacy
Tencent bugly SDK (Shenzhen Tencent IT System Co., Ltd.) iOS Version:
Device model, operating system version, OS build number, Wi-Fi status, CPU attributes, available memory space, disk space, runtime device status (memory occupied by the process), IDFV, and region code.
Android Version:
Device model, device brand, Android OS version, Android API level, manufacturer OS version, CPU architecture type, device root status, disk space usage, SD card space usage, memory space usage, network type, and the process name and PID currently running in the application.
Used to provide professional exception reporting and operational statistics, helping us to promptly identify and resolve system anomalies, track product operational dynamics, and respond to your feedback in a timely manner. 《Bugly SDK Rule of information protection》:https://bugly.qq.com/docs/user-guide/instruction-manual-privacy/
Google Map(Google Inc.) Device information, network information and location information Providing location records and obtain weather information https://policies.google.com/privacy?hl=zh-CN
Tencent Browsing SDK Device information (device model, operating system, CPU type, screen width and height, screen orientation, screen pixels);Application information (host application package name, version number) Used to display H5 pages within the App 'Tencent Browsing Service SDK Personal Information Protection Rules': https://rule.tencent.com/rule/1c4e2b4b-d0f6-4a75-a5c6-1cfce00a390df
AndroidUtilCode(BlankjUtilCode) AndroidID Used for trajectory analysis of App device control to improve and optimize products and enhance user experience. 《GitHub General Privacy Statement》:https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Government, Courts and Law Enforcement. We may disclose information about you to these parties to comply with legal obligations as described above.
With Your Consent. We may disclose your personal information to any other third party where you have provided your consent.

III. International Data Transfers and Storage

We process your personal data through global operations and control facilities. Currently, we have data centers or lease high-standard data centers in multiple countries and regions around the world. Based on the purposes described in this Privacy Policy, we will reasonably plan and select appropriate data centers to store the personal data collected and generated, depending on your country or region and our business operation needs. The jurisdictions where these global facilities are located may not protect personal data according to the same standards as your jurisdiction, and different data protection laws may involve different legal risks and differences in security compliance. However, this does not change our commitment to complying with this Privacy Policy and protecting your personal data. Regardless of where your personal data is processed, we will ensure that your personal data receives adequate and equivalent protection by implementing unified security safeguards, including but not limited to transmission encryption, access controls, de-identification/anonymization and other technical and organizational measures, and by entering into strict data processing and protection agreements with overseas recipients.
If we need to transfer personal data outside your jurisdiction, whether to our affiliates or third-party service providers, we will comply with applicable laws. We will implement unified security safeguards to ensure that all such transfers meet the requirements of applicable data protection laws in your country or region and that your personal data is adequately protected:
Users in China
Personal information collected and generated during our operations within the territory of the People’s Republic of China will be strictly stored in data centers located within China. Except in special circumstances permitted by laws, administrative regulations or relevant regulatory authorities, we will not, in principle, transfer your personal information outside China. Where it is truly necessary to provide personal information overseas, we will strictly comply with the requirements of the Personal Information Protection Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China and other relevant laws and regulations, perform a security assessment for the outbound transfer of personal information, enter into the standard contract for outbound transfer of personal information formulated by the national cyberspace administration (CAC SCCs) or pass personal information protection certification by a professional institution, and lawfully inform you of the specific information of the overseas recipient and obtain your separate consent.
Users in EU Member States, the United Kingdom and Switzerland
We will store personal data from users in the EU, the United Kingdom and Switzerland in data centers located in Germany. As Germany is an EU Member State, and the United Kingdom and Switzerland officially recognize the EU/Germany as providing an adequate level of data protection, such storage falls within the free flow of data under the adequacy standard. If, due to business needs, it is necessary to further transfer data from Germany to other jurisdictions outside the EU, the United Kingdom or Switzerland, we will implement lawful cross-border transfer mechanisms and security assessments that comply with local legal requirements in accordance with the different requirements of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act (UK GDPR/Data Protection Act 2018), and the Swiss Federal Act on Data Protection (FADP).
Users in the United States
We will store your personal data in data centers located in California, United States. If interstate processing or cross-border transfer of data is involved, we will strictly comply with applicable U.S. federal laws and comprehensive state privacy and data protection laws and regulations. We ensure that any sharing, transfer or disclosure of data complies with the restrictions on “service providers/processors” under the above laws, and we prohibit recipients from using the data beyond the purposes authorized in this Policy.
Users in Singapore
We will store your personal data in data centers located in Singapore. If cross-border transfer of data is required, we will, in accordance with the requirements of Singapore’s Personal Data Protection Act (PDPA), ensure that contractual clauses, binding corporate rules or other protective measures that comply with the PDPA are adopted in the course of cross-border data transfers, so as to ensure that overseas recipients provide a level of protection equivalent to that required under the PDPA.
Users in Other Countries
We will comply with the data protection laws and regulations of your country or region regarding local storage or cross-border transfers of data. If local law imposes mandatory requirements for cross-border transfers, such as local storage, separate user consent, security assessment or execution of designated standard contracts, we will implement the cross-border transfer of data only after fully satisfying such legal requirements and adopting an equivalent level of security protection.

IV. How We Protect Your Personal Data

We are committed to protecting the security of your personal data. To prevent unauthorized access, disclosure or other similar risks, we implement all legally required physical, electronic and administrative systems and operating procedures to safeguard the security of the information collected from your products or devices. We will protect your personal data in accordance with laws and regulations.
We will conduct due diligence on third-party service providers and business partners to ensure that they have the capability to protect your personal data. We will also use appropriate contractual restrictions and, where necessary, audits and assessments to check whether third parties have adopted appropriate security standards. In addition, employees, third-party service providers and business partners who access your personal data are subject to strict contractual confidentiality obligations.
We adopt industry-standard security technologies, organizational and management measures, including but not limited to network firewalls, encrypted storage, de-identification, masked display, access control measures, host and network isolation, information classification management, and the formulation and implementation of personal data security incident response plans, to minimize the risk of leakage, damage, misuse, unauthorized access, unauthorized disclosure or alteration of your information.
We will conduct security and privacy protection training courses and assessments to strengthen employees’ awareness of the importance of protecting personal data. We will take all practicable and legally required measures to protect your personal data.
Please understand that although we will do our best to ensure the security of any information you send to us, the internet environment is not 100% secure, and we do not assume liability for any risks or losses arising therefrom or in connection therewith. If a personal data security incident unfortunately occurs, we will, in accordance with the requirements of laws and regulations, promptly inform you of the types of information involved in the security incident or possible leakage, tampering or loss of personal data, the causes and possible harm, the remedial measures we will take, and the measures you can take to mitigate harm. We will promptly notify you of incident-related procedures by email, letter, telephone, push notification or other means. Where it is difficult to notify personal data subjects one by one, we will issue an announcement in a reasonable and effective manner. At the same time, we will report the handling of the personal data security incident to regulatory authorities as required.

V. Minors' Privacy

With respect to the protection of minors’ personal data, SKG health is intended for adult users and, in principle, does not provide services to minors. According to relevant laws and regulations, if you are a minor, you should obtain the prior consent of your parent or legal guardian before using our services or products. As a minor, considering that the definition of a minor may vary by country or region and will be adjusted according to the provisions of each country or region, before using our products or services, you should obtain the prior consent of your parent or guardian in accordance with the registration and use process, and your parent or guardian should assist you in completing the product or service registration process so that you can use the products or services we provide.
For minors, we will not knowingly collect minors’ personal data without the consent of the minor’s parent or guardian. For minors’ personal data collected with the consent of a parent or guardian, we will collect and use such data only in compliance with local legal requirements and with the explicit consent of the parent or guardian. If you are a parent or guardian and discover that your child has obtained a service account, you may contact us through the contact information set out in this Policy and request that we delete the personal data from our systems. We will delete such data as soon as possible.

VI. Your Rights

We attach great importance to your management of personal data and make every effort to protect your rights to know, decide, access, copy, correct, delete, withdraw consent and other statutory rights, so that you have sufficient ability to protect your privacy and personal data security.
Right to Be Informed
You have the right to be informed about the processing of your personal data. You have the right to be informed, in a simple, transparent, understandable and easily accessible manner, of the data we hold and how we process your data. You may learn about the above information by reading this Privacy Policy. If you have any other questions, you may contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health.
Right of Access and Copy
You have the right to request access to and a copy of your personal data from us. You may view your avatar, nickname, mobile phone number and other personal account information by logging into SKG health > Me > clicking the symbol to the right of your nickname; and view your age, gender, date of birth, occupation, height, weight, blood type and other personal profile information by logging into SKG health > Me > Health Profile. You may also contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health, and we will respond to your request according to the methods and time limits specified in this Privacy Policy.
Right to Correction
If you find that your personal data is inaccurate or incomplete, you may change your avatar, nickname, mobile phone number and other personal account information by logging into SKG health > Me > clicking the symbol to the right of your nickname; and change your age, gender, date of birth, occupation, height, weight, blood type and other personal profile information by logging into SKG health > Me > Health Profile.
Right to Deletion
You may delete relevant information in SKG health by yourself. Please note that, due to applicable laws and security technology limitations, we may not be able to immediately delete the corresponding information from backup systems. In such cases, we will securely store your personal data and isolate it from any further processing until the backup can be cleared or anonymized.
You may also contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health to request deletion, and we will respond to your deletion request according to the methods and time limits specified in this Privacy Policy.
If we decide to respond to your deletion request, we will also notify the entities that obtained your personal data from us and require them to delete it in a timely manner, unless laws and regulations provide otherwise or such entities have obtained your independent authorization.
Right to Restrict Data Processing
Subject to applicable law, you have the right to restrict our processing of your personal data. You may contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health, and we will process your request within a reasonable time after it is submitted.
Please note that your request to restrict processing may result in your inability to continue receiving products and services provided by SKG.
Right to Data Portability
Where technically feasible, you may request that we transfer your personal data to a third party designated by you. You may contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health, and we will process your request within a reasonable time after it is submitted. If it is technically infeasible, we will also respond to you and explain the reason.
Rights Related to Automated Decision-Making
We currently do not process your personal data by means of automated decision-making. If we process your personal data by means of automated decision-making in the future, we will inform you and obtain your consent. You may also contact us through the contact information set out in this Policy or through “Contact Customer Service” in SKG health to refuse our processing of your personal data by means of automated decision-making.
Right to Withdraw Consent
Where we process your personal data based on your consent, you have the right to withdraw your consent at any time. You may withdraw the scope of authorization for our continued collection of your personal data or withdraw your authorization by logging into SKG health > Me > Settings > Authorization Management > Unbind Authorization. You may also withdraw all authorization for our continued collection of your personal data by logging into SKG health > Me > Settings > Account Cancellation.
Please understand that products or services may need to collect necessary personal data in order to function. When you withdraw consent, we will be unable to continue providing the service corresponding to the withdrawn consent, but this will not affect personal data processing services previously carried out based on your authorization.
Right to Account Cancellation
You may cancel your previously registered account at any time through online account cancellation or by contacting customer service. After your account is cancelled, the content, information, data and records under that account will be deleted or anonymized, except where laws and regulations provide otherwise or regulatory authorities have other requirements. Once account cancellation is completed, the account cannot be restored.
Right to Object
Subject to applicable law, you have the right to object to data processing activities conducted by us. You may contact us at skgapp@skg.com to submit an objection request, and we will respond to your request in a timely manner.
Exceptions to Responding to Your Rights Requests
  1. Where the request relates to our performance of obligations under laws and regulations.
  2. Where the request is directly related to national security or national defense security.
  3. Where the request is directly related to public security, public health or major public interests.
  4. Where the request is directly related to criminal investigation, prosecution, trial or enforcement of judgments.
  5. Where we have sufficient evidence that you or another personal data subject has subjective malice or is abusing rights.
  6. Where it is necessary to protect the life, property or other major lawful rights and interests of you or another personal data subject and it is difficult to obtain authorization from the individual.
  7. Where responding to your request or another personal data subject’s request would seriously harm the lawful rights and interests of you, another personal data subject, or an organization.
  8. Where the request involves trade secrets.
Please note that we generally do not charge fees for reasonable requests. However, for repeated requests or requests exceeding a reasonable limit, we may charge a certain cost-based fee as appropriate. For requests that are unreasonably repetitive, require excessive technical means, pose risks to the lawful rights and interests of others, or are highly impractical, we may refuse them.

VII. Updates to This Privacy Policy

This Privacy Policy was updated on [May 20, 2026] and became effective on [May 20, 2026].
Our Privacy Policy may change from time to time. We will publish any changes to this Policy on SKG health. For material changes, we will provide more prominent notice, such as by giving special prompts on the browsing page, explaining the specific changes to this Policy. Without your explicit consent, we will not reduce the rights you are entitled to under this Policy.
Material changes referred to in this Privacy Policy include, but are not limited to:
  1. Material changes to our service model.
  2. Material changes to the main recipients of personal data sharing, transfer or public disclosure.
  3. Material changes to your rights in relation to personal data processing and the methods for exercising them.
  4. Changes to our contact information or complaint channels.
  5. A personal data security impact assessment report indicating a high risk.
We will also archive previous versions of this Policy for your reference. If you do not accept the updated Privacy Policy, you may refuse to accept the updated Privacy Policy when it is updated and stop using the services or functions we provide.

VIII. How to Contact Us

We have established a dedicated personal data protection department. If you have any questions, comments or suggestions regarding this Policy, you may contact us through the following methods:
Telephone: 400-822-0888
 
In general, we will respond within fifteen working days. If you are not satisfied with our response, especially if our personal data processing activities have harmed your lawful rights and interests, you may also lodge a complaint or report with supervisory authority, or seek resolution by filing a lawsuit with a court of competent jurisdiction.