Privacy Policy

This Privacy Policy is a global unified official privacy standard for the FomioPlay video playback application (hereinafter referred to simply as “This Application”), strictly conforming to the European Union‘s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Global General Digital Data Protection Code, which applies to users in all regions of the world, without any regional territorial restrictions. This Policy clearly describes all the rules of this Application for the collection, use, storage, sharing, protection, and legal rights of users‘ personal data. By downloading, installing, registering, logging in, and using all services of this App, the user indicates that they have fully read, understood, and unconditionally agreed to all terms and conditions of this Privacy Policy. Official Privacy Advisory and Question Feedback Email: kxhealthpro@outlook.com

1. General Rules and Policy Effectiveness Description

1.1 Policy scope

1.1.1 This Privacy Policy applies to all end users using the FomioPlay app and its accompanying features worldwide, including all official versions of mobile, desktop, and tablet devices and subsequent iterative updates.

1.1.2 This Policy also restricts the data processing behavior of this Application Operating Entities, Technology Providers, and compliant third parties. All data operations related to the Services must comply with this Policy and international general privacy compliance standards.

1.1.3 This Policy applies only to user data collected and processed independently by this Application, and does not apply to data behavior resulting from third-party websites, third-party applications, or external jump links.

1.2 Policy Enforcement and Recognition Rules

1.2.1 The first time a user installs, opens an application, registers an account, or uses any of the core features, this is considered a voluntary acceptance of this Privacy Policy, and this Policy immediately becomes legally binding on users.

1.2.2 If users do not agree to any terms of this Policy, they should immediately uninstall this App and terminate all usage of the Services.

1.3 Policy Updates and Disclosure Mechanisms

1.3.1 Operators reserve the right to amend this Policy according to reasonable circumstances such as service upgrades, functional iterations, international compliance standards updates, and business adjustments.

1.3.2 The policy update will be made globally public through application client pop-ups, in-site announcements, and official announcement pages, and will take effect immediately upon completion. Your continued use of the Service is considered to be the full terms upon acceptance of the update.

1.3.3 Users are obligated to periodically review the latest privacy policy, and are self-responsible for any privacy practices resulting from continuing to use the Services after the policy is updated.

2. Scope of Collection of User Personal Data and Legitimate Base

2.1 Users Proactively Submit Data

2.1.1 Account Base Data: Identity information such as user registration, user name voluntarily submitted when logging into an account, linked mailbox, login authentication information, and account base data are used only for account verification and permissions management.

2.1.2 Interactive Feedback Data: Content such as the contact details that users proactively fill out when submitting inquiries, complaints, suggestions, problem descriptions, and supporting testimonial information through official email or in-app feedback features.

2.2 Application Automated Data Collection

2.2.1 Device Environment Data: Device information such as device model, OS version, device unique identifier, hardware parameters, network access type, etc., is used to adapt application execution, troubleshoot compatibility issues, and ensure service stability.

2.2.2 Service behavior data: User video playback history, playback progress, favorite content, browsing preferences, feature click tracks, usage duration, and other behavior data are used to optimize the product experience and service logic.

2.2.3 Security Log Data: Access IP address, access time, operation logs, anomalous behavior records, and other data for risk identification, security protection, and defense against malicious attack behavior.

2.3 Data Collection Compliance Principles

2.3.1 Minimum Required Principle: This Application collects only the data necessary to provide the core video playback service, does not overcollect, and does not force requests for sensitive privacy information that is not related to the service.

2.3.2 Voluntary Authorization Principle: Non-essential data collection requires explicit user authorization. Users can voluntarily turn off matching permissions. Denial of authorization only affects matching functionality, not the underlying playback service.

2.3.3 Legal Justification Principles: All data collection activities are based on the three major international common legal grounds of user authorization, service fulfillment, and legal compliance requirements, without any illegal collection activities.

3. Purpose of User Data Use and Rules for Processing

3.1 Basic Service Operational Usage

3.1.1 Basic account services such as user account registration, login verification, permissions management, and account status maintenance are used to ensure normal and stable use of user accounts.

3.1.2 is used to adapt to user devices and network environments, optimize video playback quality, load speed, compatibility, and fix functional failures such as jams, flashbacks, and playback anomalies.

3.2 Product Optimization and Personalized Services

3.2.1 Based on user compliance behavior data, analyze usage preferences, optimize content distribution and feature layout, and provide users with more tailored personalized playback services and feature recommendations.

3.2.2 Statistics of product usage data, iterative optimization of application functionality, remediation of program vulnerabilities, and continuous improvement of the overall user experience globally.

3.3 Security Wind Control and Equity Guarantee

3.3.1 is used to identify risky behaviors such as unusual account logins, malicious operations, batch swipes, cyber attacks, and prevent security issues such as account theft, data leakage, and service abuse.

3.3.2 is used to check for irregular usage behavior, maintain the order of platform services, and ensure the security and legitimate interests of all users.

3.4 Compliance Communication and Legal Compliance

3.4.1 Used to respond to inquiries, complaints, and post-sales feedback submitted by users through official email, to complete problem verification, communication responses, and troubleshooting.

3.4.2 is used to meet international law and regulations, judicial audits, and compliance regulatory requirements, in conjunction with lawful and compliant data retrieval and auditing work.

4. Data Storage, Retention Cycles, and Security Protection

4.1 Data Storage Standards

4.1.1 All user compliant data is stored on international compliant cloud servers with cross-border compliant storage architecture, strictly complies with global data storage security standards, and does not violate cross-border transfers of non-compliant data.

4.1.2 Applications use industry-advanced encryption technologies to encrypt user confidential data in transit and at rest, prevent plaintext retention of data, and prevent data theft, tampering, and disclosure risks.

4.2 Data retention cycle

4.2.1 Regular Service Data: Preserved for service continuity during the lifetime of the user‘s account and normal service use; anonymized or completely deleted within the compliance cycle after the user signs out of the account.

4.2.2 Security Log Data: Only retained for a limited compliance cycle, automatically cleared upon expiration, and not permanently retained for user activity logs and network records.

4.2.3 Compliance Retention Data: Data that needs to be retained due to laws and regulations, dispute testimony, and security checks will be retained strictly according to the statutory period, and immediately cleared upon expiry.

4.3 Comprehensive Security Protection Mechanisms

4.3.1 Establish multi-layered firewalls, real-time risk monitoring systems, and data access hierarchical systems to strictly control internal and third-party data access permissions, preventing illegal retrieval and abuse of data.

4.3.2 Establish a contingency plan for data security, in case of security incidents such as data leakage, loss, and tampering, to immediately block the risk, address the source, control the loss, and inform users and regulatory agencies according to international compliance requirements.

5. Data Sharing, Disclosure, and Cross-Border Transfer Rules

5.1 Compliance Sharing Scope

5.1.1 This Application may only share** the minimum necessary data** with partner third parties providing technical operations, server support, compliance checks, and security protections, and only for the purposes of service operations.

5.1.2 All third parties in cooperation must sign strict data confidentiality agreements, comply with international data protection regulations, accept privacy compliance regulations from operators, and strictly prohibit the private use, disclosure, and resale of user data.

5.2 Prohibited Sharing Situations

5.2.1 You will not sell, rent, transfer, or disclose your personal data to any unrelated third party without your explicit written permission.

5.2.2 User privacy data will never be used for commercial marketing, precision harassment, cross-border promotion, profit monetization, etc. scenarios that are not related to core services.

5.3 Legal Disclosure and Cross-Border Transfer Rules

5.3.1 In the event of legal retrieval requirements from international laws and regulations, judicial authorities, and compliance regulators, relevant user data may be disclosed in accordance with law and regulations without requiring prior user authorization.

5.4.2 To avoid significant security risks, maintain public legitimate interests, and address infringement disputes, non-sensitive user data may be disclosed to the reasonable and necessary extent.

5.4.3 In the event of cross-border data transfers, cross-border data compliance mechanisms will be strictly followed, ensuring that the data recipients have the same level of privacy protection capabilities and fully protect the rights and interests of user data.

6. Legal Rights of Global User Data Subjects

6.1 Data Query and Access Rights

6.1.1 Users can log in to the Personal Center at any time to voluntarily query account basic information, service usage records, and the content of personal data stored by the platform.

6.1.2 Users can apply for bulk access to all their compliant stored data through the official contact email, and the operator will respond within the compliant time limit.

6.2 Data Correction and Deletion Rights

6.2.1 If there are errors or omissions in the user information retained by the platform, the user can voluntarily correct it in the account settings, or request manual corrections through the official email address.

6.2.2 Users have the right to voluntarily clear usage data such as playback records, collection records, etc. They can also request to log out of their account and completely clear personal privacy data.

6.3 Authorization Revocation and Processing Restrictions

6.3.1 Users can revoke authorization at any time in the device system or application privacy settings, and turn off services such as data collection, personalized recommendations, and more.

6.3.2 When users have objections to data processing behavior, they can apply to restrict the platform‘s subsequent processing of their data, and the platform will comply with the law.

6.4 Data Export and Claims Rights

6.4.1 Users can apply to export personal compliance data through official email addresses. The platform will provide data export services in standard formats to ensure the portability of user data.

6.4.2 If users believe that the platform‘s data processing behavior violates their privacy rights, they can submit a complaint through the official email address. The platform will review and feedback on the processing results within 3-7 working days.

7. Special Privacy Protection Terms for Minors

7.1 Principles of Protection of Minors

7.1.1 This Application strictly follows global standards for protecting minor data and implements the highest level of privacy protection for minor users under the age of 18.

7.1.2 The platform will not actively collect sensitive personal information from minors, and will not conduct commercial marketing, precision push, and other data utilization activities targeting minors.

7.2 Rules for Processing Underage Data

7.2.1 The use of this App by minors is subject to the consent and full supervision of the legal guardian, who is responsible for supervising the behavior of minors‘ use and data retention.

7.2.2 If a guardian discovers that a minor has registered an account without permission and has retained private data, they can apply for data deletion and account restriction through their official email address. The platform will take immediate action.

7.3 Adult Rights Control

The 7.3.1 platform defaults to privacy protection mode for underage users, reducing the range of data collection, shielding high-risk privacy risks, and maximizing privacy protection for underage users.

7.3.2 The Platforms will never use minor data for commercial operations and will not disclose any privacy information related to minors to third parties.

8. Disclaimer, contact channels, and dispute resolution

8.1 Privacy Disclaimer

8.1.1 The Platform assumes no responsibility for personal information that the User discloses, actively discloses, or shares of their own accord, as well as for privacy disclosures resulting from the User‘s own operational errors or the loss of their device.

8.1.2 Third-party jump links, third-party collaborative services, third-party applications, and data processing behaviors resulting from third-party applications are independently protected by third-party privacy protection, and the platform assumes no collateral responsibility.

8.1.3 Platforms are exempted from liability for privacy violations due to data disclosure due to irresistible forces, international network failures, and legal judicial checks.

8.2 Official Communications and Complaints Channels

8.2.1 If users have requests for advice, objections, complaints, or rights to this Privacy Policy, the only official communication address is: kxhealthpro@outlook.com

The 8.2.2 Platform will process each user‘s privacy claim in a standardized manner, complete reviews, respond to, and amendments within a compliant timeframe, and ensure users‘ legitimate privacy rights and interests.

8.3 Dispute Resolution Mechanisms

8.3.1 Controversies between users and platforms arising from this Privacy Policy are prioritized to be resolved by a global, universal, friendly negotiation method.

8.3.2 When negotiations fail to reach an agreement, the parties agree to adopt an international business arbitration mechanism to resolve the dispute, and the arbitration result is the final effective ruling.

8.4 Policy Independence and Effectiveness Notice

8.4.1 When any provision of this Policy is deemed invalid or unenforceable, it does not affect the full legal validity of all other provisions, and the remaining provisions remain in effect.

8.4.2 This “FomioPlay Privacy Policy” is officially effective globally from the date of publication and is effective for the long term.