Vita link — User Agreement and Privacy Policy (Full Version)

Version: v1.0 | Updated: 2025-09-05 | Effective: 2025-09-05

This policy is formulated and published by Sysmo Technologies Co., Ltd (hereinafter referred to as "Sysmo" or "we"), and applies to your use of the "Vita link" mobile application, official mini-programs/webpages, and associated smart hardware (collectively referred to as "the Product"). We understand the importance of personal information and privacy to you and will process your personal information in accordance with the principles of minimum necessity, transparency, and security.

Important Notice: Vita link is used for health behavior management and reference purposes and is not classified as a medical device. It should not be used for disease diagnosis or treatment. If you have medical concerns, please consult a professional physician.


1. Definitions and Scope of Application


2. How We Collect and Use Your Personal Information

We follow the principles of legality, legitimacy, and necessity to collect and use your personal information according to functional modules and scenarios. You can manage and withdraw permissions in system settings. The information required for different functions, purposes, collection methods, necessity, and retention periods are as follows:

Function/Scenario Information Type and Details Collection Method Purpose/Legal Basis Necessity Retention Period
Registration/Login and Account Management Name, gender, date of birth, phone number/email, contact address, avatar, nickname; verification code, login logs You actively fill in; system automatically generates logs Create and maintain account, identity verification, notification communication; Legal basis: contract performance, explicit consent Core necessary Account duration; deleted or anonymized within 30 days after cancellation (unless otherwise required by law)
Device Binding and Management Device Identifiers: ICCID, IMSI, SN, Android ID, IMEI, OAID, MAC; device model, system version, app version, carrier, network status, Bluetooth/Wi-Fi information (BSSID/SSID/IP) Automatic collection; calling system/Bluetooth/network interfaces Device unique identification, binding and pairing; prevent malicious registration and fraud; stability and compatibility adaptation; Legal basis: contract performance, legitimate interests (security), explicit consent Core necessary Account duration; security audit and tracing information retained for up to 24 months
Health Data Collection and Analysis Sensitive Personal Information: heart rate, respiratory rate, heart rate variability (HRV), sleep duration/stages/quality, device sensor data and generated health/sleep reports, risk assessment results; Optional: medical history, medication (not required) Through paired hardware, Bluetooth sync, your active input/import Provide health trends, personalized advice and reminders; Legal basis: explicit consent (can be withdrawn at any time) Core necessary (required for report generation) Account duration; deleted or anonymized within 30 days after deletion or cancellation; aggregated statistical data may be retained long-term and irreversibly de-identified
Health Reminders/Notifications (including SOS) Push identifier (Push Token), device identifier, latest monitoring results, reminder rules; optional emergency contact name and phone (added by you) Automatically generated/you actively fill in; push service SDK Send threshold/abnormal reminders to you or emergency contacts; Legal basis: contract performance, explicit consent Core necessary (when reminders enabled) 12 months from reminder generation; emergency contact information can be deleted at any time
Customer Service and Feedback Contact information, problem description, ticket records, necessary device/log information You actively submit; client generates logs Identify problems, provide support and after-sales service; Legal basis: contract performance, explicit consent Necessary 24 months after ticket closure
Operation Security and Fault Diagnosis Crash logs, performance metrics, exception stacks, network request records (desensitized), timestamps and IP Automatic collection Ensure service security and stability, anti-attack and anti-cheat; Legal basis: legitimate interests (security) Necessary Not exceeding 24 months
Optional Location-Related Functions Location information (GPS, Wi-Fi, base station) — collected only when you authorize Automatically collected after system authorization Bluetooth scanning/pairing assistance, geo-localized reminders; Legal basis: explicit consent Non-core, can be disabled Not exceeding 12 months or stopped and deleted upon withdrawal of authorization
Profile Completion/Questionnaire Lifestyle habits, exercise preferences, etc. (optional) You actively fill in Optimize analysis models and personalized suggestions; Legal basis: explicit consent Non-core, optional Account duration or when you delete

Special Notice (Device Identifiers): To comply with app store requirements and ensure device binding and account security, we explicitly disclose that we collect and use identifiers such as ICCID, IMSI, SN, Android ID, IMEI, MAC for device unique identification, binding management, anti-cheat and security. You can withdraw authorization in system permissions or "Settings - Privacy Management", but this may result in binding and reminder functions being unavailable.

Exceptions to Obtaining Consent

According to laws and regulations, we may process personal information without obtaining your consent in the following circumstances: related to national security, public safety, or major public interests; related to criminal investigation, prosecution, trial, and judgment execution; necessary for fulfilling legal obligations; necessary for concluding or performing a contract to which you are a party; necessary to protect the life, health, and property safety of you or others within a reasonable scope; processing personal information that you have made public or that has been legally disclosed; processing within a reasonable scope in accordance with laws.


3. How We Use Cookies, SDKs, and Similar Technologies

1) Cookies/Local Storage

Used to save login status, preference settings, and page performance. You can clear them in system settings, but this may affect your experience.

2) Third-Party SDK List (please maintain according to actual usage)

SDK/Service Provider Function and Purpose Information That May Be Collected Usage Scenario Official Website/Privacy Policy
Manufacturer Push Channels (Samsung, Xiaomi, etc.) Message/reminder push Device identifiers (Push Token, device model, system version), network information, app information Health reminders, message notifications Please fill in respective privacy policy links
Statistical Analysis Crash and performance analysis, activity statistics Device identifiers, app version, crash logs, usage events Stability and experience optimization Please fill in corresponding links
Cloud Storage/Object Storage Data and resource storage Account ID, file metadata, encrypted content summary Report and record storage Please fill in corresponding links

Note: We sign strict data processing agreements with third parties entrusted with processing, requiring them to process information only within the entrusted scope and adopt security measures no less than ours.


4. Sharing, Transfer, and Public Disclosure of Personal Information


5. How We Store and Protect Your Personal Information


6. Your Rights and How to Exercise Them

Subject to compliance with laws and regulations, you have the following rights, which can be exercised through "My - Privacy Management", in-app online customer service, or email/phone:


7. Protection of Minors and Children's Information

If you are a minor (under 18 years old), you should use this product with the consent and guidance of your guardian; if you are a child under 14 years old, we will obtain the guardian's explicit consent according to legal requirements and adopt stricter protective measures. If we discover that children's personal information has been collected without consent, we will delete it promptly.


8. Cross-Border Information Transfer

Currently, we do not transfer personal information abroad. If cross-border transfer is necessary in the future, we will conduct security assessments or sign standard contracts for cross-border transfer of personal information in accordance with regulatory requirements, clarify the obligations of the recipient, and separately obtain your explicit consent.


9. Permission Usage and Disabling Guide (Android)

Permission Name (Example) Purpose Trigger Scenario Required How to Disable and Impact
Bluetooth (BLUETOOTH/BLUETOOTH_SCAN/CONNECT/ADVERTISE) Pairing with hardware, data synchronization Device binding, real-time monitoring Required for binding/collection System Settings → App Permissions → Bluetooth; disabling will prevent binding/sync
Location (ACCESS_FINE_LOCATION/COARSE_LOCATION) Required by Android for BLE scanning; location-related functions Search/pair devices, location services (if enabled) Non-core (but BLE scanning requires it on some systems) Disabling may affect pairing stability and location functions
Phone/Device Info (READ_PHONE_STATE, etc.) Read ICCID/IMSI/IMEI, network status for device unique identification and security Registration/login, device binding, security risk control Required for binding/risk control Disabling will affect binding, anti-cheat, and exception diagnosis
Storage (READ/WRITE_EXTERNAL_STORAGE or scoped storage) Cache reports, export data, select avatar/images View/export reports, upload avatar/feedback attachments Non-core Disabling will prevent export or image attachment upload
Camera (CAMERA) Scan QR code to bind device, upload feedback images/avatar QR code pairing, upload materials Non-core Can switch to manual input or not upload images after disabling
Notifications (POST_NOTIFICATIONS) Health reminders and SOS pop-ups/push Messages/reminders Non-core (required when reminders enabled) Disabling will prevent receiving notification reminders

Note: Permission names and displays may vary across different devices and system versions; please refer to the system interface.


10. Background Running Notice

To ensure timely receipt of SOS notifications and device Bluetooth status change reminders, this application may run in the background or be awakened by the system.

We will not frequently auto-start or associated-start without your consent. You can choose whether to allow background running in the app's "Settings - Background Permission Management".


11. App Store Disclosure Consistency Notice (AppGallery, etc.)

We have disclosed "the purpose, method, and scope of personal information collection" in both the in-app Privacy Policy page and the Privacy Policy link submitted to the app store, particularly providing clear explanations for the collection and use of device identifiers such as ICCID, IMSI, SN, Android ID, IMEI, MAC, consistent with actual permission requests.


12. Policy Updates and Changes

When the following significant changes occur, we will re-obtain your consent through prominent means such as in-app messages, pop-ups, or page announcements:


13. Contact Us (Personal Information Protection Officer)

If you have any questions, comments, or suggestions regarding this policy or personal information protection, you can contact us through:

We will respond within 15 working days after receiving your request; for complex matters, no longer than 30 working days.


14. Key Points of User Agreement (Applied in Parallel with Privacy Policy)


15. Third-Party AI Services and Data Sharing

This app uses third-party AI services for text analysis, Q&A, health advice generation, and device data explanation.

With your explicit consent, the app may send only the minimum necessary data, including respiratory, activity, and sleep data, to the Qwen AI service provider.

We share data only as needed to provide these features and require the third party to protect it in accordance with applicable privacy and security requirements.

If you do not agree, the related AI features will not be available, but other non-AI features will remain usable.


16. Appendix A: Types of Personal Information Not Collected/Not Enabled by Default

Unless you actively enable in specific functions or we separately obtain your explicit consent, we do not collect: your contacts, call records, SMS content, calendar, browsing history, financial accounts and payment passwords, biometric information (face/fingerprint).


17. Appendix B: Terms and Explanations


18. Version and Effectiveness


© Sysmo Technologies Co., Ltd. All Rights Reserved