Effective Date: [May 30, 2025]
Published Date: [May 30, 2025]
KiwiCloud PTE. LTD. ("KiwiCloud" , "we" , "us" or "our") is committed to protecting the privacy and security of the data generated and managed by the KiwiCloud UEM platform (the "Services"). This Privacy Policy explains (1) what data we collect, (2) how we use, store, and share it, and (3) the rights and choices available to you. This policy applies only to device-generated data processed through the Services and does not cover any personal data collected outside the Services or by third-party sites.
Note: We do not collect personal user data (e.g., names, email addresses, personal documents, GPS location).
We process device data for the following legitimate business purposes:
EU GDPR
Lawful Basis: Art. 6(1)(f) – processing is necessary for our legitimate interests in providing and improving device-management services, balanced against your rights.
Data Subject Rights: Access, rectification, erasure, and restriction of processing. Contact us (see Section 13) to exercise your rights.
California CCPA/CPRA
Our processing of device data typically falls outside the definition of "personal information" under CCPA, but if you believe any data we hold is subject to CCPA, please contact us.
Storage Locations: Secure cloud servers in multiple global regions. All in-transit and at-rest data are encrypted.
Retention Period: By default, we retain device data for 24 months. Customers may request extensions for compliance or audit purposes.
Deletion: After the retention period, data are permanently deleted. You may also request immediate deletion via your admin console or by contacting us.
Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest.
Access Controls: Role-based access (RBAC) and strong password policies.
Account Protection: Support for multi-factor authentication (2FA) and single sign-on (SSO).
Monitoring & Audit: Real-time security event detection and comprehensive logging.
We may engage trusted subprocessors (e.g., cloud hosting, security audit firms) to perform services on our behalf. They are contractually bound to use device data only to provide those services and to maintain equivalent privacy and security standards.
We may disclose device data if required by law, regulation, or valid legal process (e.g., court order, government request).
Access & Correction: Administrators can view and correct device data via the UEM console.
Deletion Requests: Submit deletion or export requests through your admin console or by emailing us.
Policy Withdrawal: If you object to our processing, you may stop using the Services; upon request, we will delete all device data (unless retention is legally required).
Our Services are not directed to children under 13. We do not knowingly collect personal data from minors. If you believe we have collected such data, please contact us for removal.
Our web console may use cookies or local storage for session management, security, and performance. These technologies are not used to track you across third-party sites. You may disable them via your browser settings, but some functionality may be impacted.
Where device data is transferred outside Singapore (e.g., to EU or US data centers), we rely on appropriate safeguards such as Standard Contractual Clauses under GDPR to ensure lawful cross-border transfers.
We may update this Privacy Policy periodically. We will post the revised version at https://kiwi.cloud/privacy with a new "Effective Date". For material changes, we will also provide notice via the platform or email.
If you have questions, concerns, or requests regarding this Privacy Policy or your device data, please contact: contact@kiwi.cloud
生效日期: [2025年5月30日]
发布日期: [2025年5月30日]
KiwiCloud PTE. LTD.(以下简称“KiwiCloud”或“我们”)非常重视您的隐私和设备数据的安全。我们依据中华人民共和国《个人信息保护法》《网络安全法》《数据安全法》等相关法律法规,制定本隐私政策,明确说明我们如何收集、使用、存储和共享您通过 KiwiCloud UEM 平台(以下简称“本服务”)所生成的设备数据,并说明您享有的权利。 请您在使用我们的产品或服务前,务必仔细阅读并充分理解本政策,特别是以加粗形式标识的条款。
1. 中国法律框架下的数据处理原则
我们依照《个人信息保护法》第十三条规定的合法处理情形收集并处理数据,主要包括:2. 针对跨境数据传输
如设备数据需传输至境外服务器(如新加坡、欧洲或美国),我们将严格遵守中国数据出境相关规定,如安全评估、标准合同备案或其他合规程序,并确保数据在跨境传输过程中加密及受保护。o到期后系统将自动永久删除数据;
o管理员亦可随时通过控制台或联系客服发起即时删除或导出请求。