Personal Information Protection and Privacy Policy
This Statement only applies to ZKBio CVSecurity series products or services of ZKBio CVSecurity, including ZKBio CVSecurity,ZKBio CVAccess,ZKBio CVConnect and ZKBio Zexus Mobile App.(hereinafter referred to as "this Product" or "this Service")
Lastly updated on: July 2026
If you have any question, comment or suggestion, please contact us via the following means:
Email: Service-AF-XM@zkteco.com
Tel: 4006-900-999
This Statement will help you understand the following:
n Personal information collection rules
n How we protect your personal information
n Your rights
n How we handle personal information of minors
n How this Statement is updated
n How to contact us
Xiamen ZKTeco Information Technology Co., Ltd. and its affiliates (hereinafter referred to as "ZKTeco", or "Company" or "We") understands the importance of personal information and will do everything possible to protect your personal information. We are committed to preserving your trust in us by protecting your personal information based on the following principles: responsibility in accordance with authority, purpose specification, informed consent, minimal necessary, security safeguard, subject participation, openness and transparency, etc. ZKTeco also commits to protect your personal information by implementing appropriate security measures in accordance with industry accepted security standards.
Notice:
Our company is merely the supplier of this software. The following content only serve to remind you of the information collection functions that this software can achieve, the information processing methods that this software can support, and the security management methods and technologies adopted. As a software product supplier, we only provide this software and assist in deploying it on the local area network devices of the software application party who bought this software for its own purposes. We do not transfer the personal information collected by this software to our company, so we are unable to obtain your personal information. Therefore, please understand and agree that, if you have any requests regarding the deletion or rectification of your personal information, please contact the application party or other entities who can actually determine the means and purposes of processing your personal information.
Before using any products (or services), please read this Statement carefully and make sure you have fully understood and agreed to this Statement. If you do not agree with the Statement or any of its terms, you should stop using this product and service and contact the application party who provided you with this software to express your requests (if your employer requires you to use this software to enter information, the application party of this software is your employer; if you participate in a meeting and you are required to use this software, the application party of this software is the organizer or the venue’s property owner) (hereinafter referred to as “application party”). If you are a company that purchases and applies this software, please note that you are the application party of this software and should assume the corresponding responsibilities as a data processor and/or controller under the applicable law, and effectively manage user data and privacy. Please understand and agree that unless otherwise provided by law, our company will not be able to assume any legal responsibility for any legal claims made by users against application party.
I Personal information collection rules
(1) Which of your personal information will be collected by us
1. When you use ZKBio CVSecurity product, including the integrated management platform and ZKBio Zexus APP.we will collect the following information of yours:
The service features we offer must operate based on specific data. If you choose to use such service features, you must provide or allow us to collect necessary information, including: name/personnel number/company, department/position, email or mobile phone number, facial photos, license plate number, visitor information (name, mobile phone number).
Additionally, if you are an enterprise/organization administrator for this product (or service), when you authorize the activation of cloud services, we will collect personal information submitted by individual users within your enterprise/organization when they use this product (or service).
2. You may choose to provide or allow us to collect the following information: employee gender, visitor facial photos,device information and application information.
Device Information: To provide better services and features, our APP integrates with Umeng, FCM, and Linphone SDKs. When you use the APP and related services, to ensure the normal operation of the APP and services, we will collect information such as your hardware model, hardware serial number, device location information, operating system version number, MAC address, software list, unique device identifier [for Android such as Android ID, OAID, GAID, for iOS such as IDFV, IDFA: different identifiers may vary in terms of validity, whether they can be reset by users, and the method of acquisition, OPENUDID, GUID, SIM card IMSI information, etc.], software version number, network access method and type, operation log information, carrier unified anonymous identifier, IP address, WLAN access point (such as SSID, BSSID), Bluetooth, base station, software version number, network access method/type/status, network quality data, operation/use/service log, and other data.
Application Information: Crash reports of applications, status of notification toggles, list of installed applications on the device, and other related information.
To ensure the stable operation of the software, the implementation of features, and the introduction of third-party SDKs used in business scenarios:
|
Third-Party SDK Name |
Third-Party Link |
Type of Personal Information Collected |
Purpose of Use |
Privacy Policy Link |
|
Umeng SDK |
com.umeng.umsdk |
Obtaining carrier name, obtaining BSSID, network type, device screen density, IMEI, SIM card serial number, SIM card carrier, IMSI, current running process, SSID, accessing external storage (attempting to write data to SD Card), current Wi-Fi connection information, radio firmware version |
With user authorization, to provide message pushing and statistics functions |
https://www.umeng.com/page/policy |
|
FCM SDK |
com.google.firebase |
Obtaining information about paired Bluetooth devices, device account information, Wi-Fi DHCP information, Wi-Fi list, BSSID, device screen density, IMEI, SIM card serial number, listening for account updates, SIM card carrier, IMSI, current running process, phone type, SSID, accessing external storage (attempting to write data to SD Card), current Wi-Fi connection information |
With user authorization, to provide real-time message pushing functions |
https://policies.google.com/privacy |
|
Linphone SDK |
org.linphone:linphone-sdk-android |
Device screen width, device screen height, data network type, current running process, MEID, network type, current Wi-Fi connection information, device screen density, SIM card status, IMEI, SIM card carrier |
With user authorization, to provide third-party video intercom related functions |
https://www.linphone.org/privacy-policy |
Although such information is not necessarily required for running our service features, but it is very important for us as it may help us to improve our service quality and develop new products or services. We will not force you to provide such information and your denial will not affect your use of the service features.
When you use the service features, our software will request you to grant the following system privileges related to personal information: enable audio & camera, obtain location.
If you deny the request, we will not be able to provide the service features. In addition to the above, you may choose to grant our software other system privileges.
When you contact us, we may keep a record of the contents of our communication or your contact information, which allows us to contact you or assist you with problems, as well as the solution of related issues and their outcomes.
(2) How we use your personal information
1. For necessary personal information, we will use the following information to maintain and improve existing service features and develop new ones.
|
Information Type |
Purpose of Use |
Retention Period |
|||
|
Employee |
|
Name/Personnel Number/Company |
To provide employee identity identification |
We will only retain your personal information for the period necessary to achieve the purposes stated in this Policy, unless a longer retention period is permitted or required by law. (a) User-Defined Retention: We provide you with the ability to manage the retention period of your data. You may independently select the retention duration for your personal data through the [specific function path: "System" -> "Data Cleaning" within the Product]. Upon the expiration of the retention period you set, we will delete the corresponding data or process it in an anonymized manner. (b) Statutory Retention: If we are unable to delete the data in accordance with the period you set due to compliance with legal obligations, resolution of disputes, enforcement of agreements, or other such reasons, we will retain your relevant information for the period necessary to complete the handling of such matters in accordance with law. During this period, the processing of such data will be subject to strict restrictions.
|
|
|
Department/Position |
Personal Information Collection Required by Your Enterprise/Organization |
||||
|
Email or Mobile Number |
Providing Account Login Services |
||||
|
Collecting and Providing Facial Recognition Services for Access Control and Time Attendance within the Scope of Business Used by Your Enterprise/Organization |
||||
|
Visual Intercom Business |
Employee Name/Personnel Number |
Providing Employee Identity Identification |
|||
|
Access Control Business |
Employee Name/Personnel Number and Access Records |
Collecting and Providing Remote Access to Access Control Records within the Scope of Business Used by Your Enterprise/Organization |
|||
|
Visitor |
Visitor Name/Mobile Number |
Visitor Identity Verification |
|||
2. For unnecessary personal information, we will use that for the following purposes:
|
Information Type |
Purpose of Use |
Retention Period |
|
|
Employee |
Gender |
Personal information collection required by your organization |
We will only retain your personal information for the period necessary to achieve the purposes stated in this Policy, unless a longer retention period is permitted or required by law. (a) User-Defined Retention: We provide you with the ability to manage the retention period of your data. You may independently select the retention duration for your personal data through the [specific function path: "System" -> "Data Cleaning" within the Product]. Upon the expiration of the retention period you set, we will delete the corresponding data or process it in an anonymized manner. (b) Statutory Retention: If we are unable to delete the data in accordance with the period you set due to compliance with legal obligations, resolution of disputes, enforcement of agreements, or other such reasons, we will retain your relevant information for the period necessary to complete the handling of such matters in accordance with law. During this period, the processing of such data will be subject to strict restrictions. |
|
Visitor |
Facial Photo |
|
|
|
License Plate Number |
Personal information collection required for your visit to the organization, to provide vehicle access control services |
||
(3) How we use Cookies and similar technologies
1. Cookies
Cookies and similar technologies are widely used in the Internet. To ensure the smooth operation of the website, the application party may store a small data file named Cookie in your computer or mobile device. A Cookie typically contains identifiers, site names, and some numbers and characters. With the Cookie, such a website can store your preference and other data. In such case, the application party shall not not use Cookies for any other purpose than that specified in this Statement. You may manage the Cookie according to your own preference or delete it. You may choose to delete all Cookies saved in your computer, and most of the web browsers have a feature to block the Cookies. But if you do this, you will need to change the user settings each time you visit the website.
2. Other similar technologies
In addition to Cookies, the application party may also use other similar technologies such as website beacons and pixel tags on its website to help it understands your preference for products or services and improve its customer service.
(4) How the software share, transfer and disclose your personal information
We only serves as a software product supplier, and the software is deployed on the local area network of the software application party. We cannot actually obtain your personal information, and therefore cannot make decisions to share, transfer, or publicly disclose your personal information. This chapter about how software can share, transfer, and publicly disclose personal information is only a principle explanation of the methods that this software can support or recommend. The actual sharing, transfer, and public disclosure of your personal information should depend on the software application party.
1. Share
Without your explicit consent, this software generally requires the software application party will not share your personal information with any other company, organization and individual.
The application party may share your personal information with an external institution if required by laws and regulations or government authorities.
2. Transfer
This software generally requires the software application party will not transfer your personal information to any other company, organization or individual, except under the following circumstances:
a) Transfer with your explicit consent: with your explicit consent, the application party will transfer your personal information to other parties;
b) If any merger, acquisition or bankruptcy process involves transfer of your personal information, the application party will request the new company or organization in possession of your personal information to continue to be bound by this Statement, or the application party will request the new company or organization to seek your permission again.
3. Public disclosure
The software application party shall only disclose your personal information in the following circumstances:
a) With your explicit consent;
b) Law-based disclosure: the application party may disclose your personal information in cases where such disclosure is required by the applicable laws, legal proceedings, litigation or government authorities, such as in the following cases where applicable:
² Related to personal information controller’s performance of obligations prescribed by laws and regulations;
² Directly related to national security or national defense security;
² Directly related to public safety, public health or vital public interests;
² Directly related to crime investigation, prosecution, trial and judgment execution;
² Where such disclosure is necessary for protecting the vital legitimate interests such as life and property of the subject of personal information or any other individual while it is difficult to obtain the consent therefrom;
² Where the personal information involved is disclosed to the public by the subject itself;
² Where such disclosure is necessary for signing and performing the contract concerned according to the requirements of the subject of personal information;
² Where the personal information is collected from legally and publicly disclosed information, such as legal news reports and publicized government information;
² Where such disclosure is necessary for maintaining safe and stable operation of the products/services provided, such as identification or disposal of failures of products/services;
² Where the personal information controller is a news agency and such disclosure is necessary for legal news reporting;
² Where the personal information controller is an academic research institute, and such disclosure is necessary for statistics or academic research in the public interest, and the personal information contained in the results of academic research or description provided externally is de-identified.
Please note that according to law, sharing, transferring or disclosing personal information does not include the scenario in which personal information is de-identified in such a way that the recipient of such information cannot restore the information or re-identify the subject of personal information before it is shared, transferred, or disclosed. As a result, we may store or process such information without notifying you or obtaining your consent.
I How we protect your personal information
We only serves as a software product supplier and cannot actually obtain your personal information. This software supports and has taken appropriate physical and technical measures to protect data. This chapter only provides a principle-level explanation of the technical means that this software can support or adopt. Except for the information protection achieved by our company through software design such as technical measures and security capabilities, we does not actually manage your personal information. The protection and management of your personal information in other aspects depend on the software application party.
(1) We are very concerned about the security of personal information. We will adopt appropriate physical, management and technical measures to protect your personal information from unauthorized access, disclosure, use, modification, damage, or loss. For example, we will protect data confidentiality using encryption technology, protect data from malicious attacks using protection mechanisms, limit the access to personal information to authorized personnel by deploying the access control mechanism, and enhance the awareness of personnel of the importance of personal information protection by providing security and privacy protection training. We will try our best to protect your personal information, but you should be aware that no security measure is impeccable.
(2) The software application party shall store your personal information for as long as is necessary to achieve the goals outlined in this Statement, unless extension of such period is required or permitted by law. The data storage period may vary due to different scenarios and different products and services. The software application party shall determine the storage period based on the following considerations: time needed to complete our services, which includes providing products and services, maintaining corresponding transaction and business records, controlling and improving the performance and quality of products and services, ensuring safety of systems, products and services and dealing with possible inquiries or complaints from users and problem identification; whether the user concerned agrees with a longer storage period; and special requirements of laws or contracts. The software application party shall keep your account registration information for as long as we need it to provide you with services. You may also choose to cancel your account. After your cancellation, the software application party shall stop providing products and services to you based on your account, and delete your personal information, unless otherwise required by law.
(3) In case of unfortunate occurrence of any personal information security incident, the software application party shall notify you in accordance with laws and regulations (within no later than 30 natural days) of the particulars and possible impact of the incident, measures it has taken or will take, suggestions on how you should prevent and minimize risks and remedies available to you, etc, via email, letter, phone call or notification. If it is difficult to inform all subjects one by one, the software application party shall post an announcement in a reasonable and effective manner. Meanwhile, the software application party shall also make a report on how we have handled the incident to the higher authority in accordance with the requirements of the regulatory body.
(4) Despite of the above-mentioned security measures, the Internet environment is not 100% safe. Please be aware that there is no "perfect security measure" on the Internet, but the application party will try its best to ensure safety of your information.
(5) To ensure good browsing experience, a third party other than us or our partners (hereinafter referred to as the "third party") may send contents or website links to you. We have no control over the third party. You may choose whether to access the links, contents, products, and services provided by the third party. We have no control over the third-party privacy or data protection policies as the third party is not bound by this Statement. Before you submit personal information to the third party, please read its privacy protection policies.
II Your rights
In accordance with Chinese laws, regulations, standards, and established practices of other countries and jurisdictions, we reminds you that you can exercise the following rights over your personal information to the software application party:
(1) Access your personal information
You have the right to access your personal information, unless otherwise provided by laws and regulations. If you want to do so, please contact the software application party.
(2) Correct your personal information
Upon noticing any of your personal information the application party processed is wrong, you have the right to request the application party to make corrections.
(3) Delete your personal information
In the following cases, you may request the application party in writing to delete your personal information:
1. The application party processing your personal information in violation of laws and regulations;
2. The application party collecting or using your personal information without your consent;
3. The application party processing personal information in violation of the agreement with you;
4. You can no longer use this product or service, or you have canceled your account; or
5. The application party no longer provides you with this products or services.
In circumstances prescribed by applicable laws, you have the right to revoke your consent to the application party’s processing of your personal information at any time. However, the cancellation will have no bearing on the legality and effectiveness of your personal information that the application party previously processed with your consent, or other appropriate legitimacy.
(4) Respond to your request
To safeguard security, you may need to provide a request in writing or otherwise prove your identity. The application party may ask you to provide proof of your identity before processing your request.
If you directly request us or through software application party to change our technical means (such as developing new systems or fundamentally changing current practices), pose risks to the legitimate rights and interests of others, or are very impractical (such as involving information stored on backup tapes), we and the software application party may refuse.
We and the software application party may not respond to your request in the following circumstances:
1. The request is related to personal information controller’s performance of obligations prescribed by laws and regulations;
2. The request is directly related to national security or national defense security;
3. The request is directly related to public safety, public health or vital public interests;
4. The request is directly related to crime investigation, prosecution, trial and judgment execution;
5. The personal information controller has sufficient evidence that the subject of personal information is subjectively malicious or abusing his/her rights;
6. Not responding to the request is for protecting the vital legitimate interests such as life and property of the subject of personal information or any other individual, while it is difficult to obtain the consent therefrom;
7. Responding to request of the subject of personal information will bring serious damage to the legitimate rights and interests of the subject or any other individual or organization; or
8. The request involves trade secrets.
III How the software application party handle personal information of minors
Our products, website and services are mainly designed for adults. Without consent of parents or guardians, minors shall not create their own account. If you are a minor, it is recommended that you ask your parents or guardian to read this Statement carefully, and only use our services or information provided by the software with consent of your parents or guardian.
The software application party shall only use or disclose personal information of minors collected with their parents' or guardians' consent if and to the extent that such use or disclosure is permitted by law or we have obtained their parents' or guardians' explicit consent, and such use or disclosure is for the purpose of protecting minors.
Upon noticing that we have collected personal information of minors without the prior consent from verifiable parents, the software application party shall delete such information as soon as possible.
IV How this Statement is updated
This Statement is subject to change from time to time.
Without your explicit consent, we will not cut your rights you are entitled to under this Statement. We will post any change to this Statement on our website.
For major changes, we will also provide a more prominent notification (for some services, we will send notice via email, stating the particulars of changes to this Statement).
Major changes referred to in this Statement include, but are not limited to:
1. Major changes of our service model, such as change of purpose, type or way of use of personal information;
2. Major changes in ownership structure or organizational structure, such as changes caused by business adjustment, bankruptcy, merger and acquisition;
3. Change of the party with which we share personal information or to which we transfer or disclose personal information;
4. Major changes in your rights of participating in the handling of personal information or the way you exercise such rights;
5. Changes of the department responsible for personal information security, or of the contact information or of the channel for filing a complaint;
We will also archive the previous versions of this Statement for your reference.
V How to contact us
If you have any question, comment or suggestion about this Statement, please contact us at: 4006-900-999, or send an email to Service-AF-XM@zkteco.com, or a letter to: Building D09, Software Park Phase III, Jimei District, Xiamen City, Fujian Province, Zip code: 361000. Normally, we will reply within seven working days. More contact information is available on our website (http://www.zkteco.com). Please note that this software is provided and deployed on the local area network device of the software application party, and our company does not actually obtain your personal information. If you want to access, correct, delete, or learn about the processing of your personal information, please contact the software application party according to the prompts at Notice section. Please understand that your personal information is stored in the local area network of the software application party. As we does not have access to any of your personal information, we will not be able to respond to your requests for your personal information.