SIMDA SIMDA

Personal Information Protection Policy

How we collect, use, store, and protect your personal information and your data rights.

Last updated: 7/1/2026

Nanjing Xingyue Yuda Information Technology Co., Ltd. (hereinafter referred to as “SIMDA”, “we”, “us”, or “the Company”) is a service provider specializing in electronic product research, development, and manufacturing solutions, and operates the official website www.simdatech.com (hereinafter referred to as “this Website”). We fully recognize the importance of your personal information and are committed to protecting it, together with your right to privacy, with the utmost good faith and care. This Personal Information Protection Policy (hereinafter “this Policy”) constitutes a legally binding instrument between you and us regarding the processing of your personal information. Before using this Website or accepting any of our services, please read and fully understand the entire content of this Policy.

I. General Provisions

1.1 Statutory Basis

This Policy is formulated in accordance with the Personal Information Protection Law of the People’s Republic of China (hereinafter “PIPL”), the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Civil Code of the People’s Republic of China, and the normative documents issued by the competent authorities of cyberspace administration, public security, and market supervision, and shall be updated in step with the revision of the aforementioned laws and regulations.

1.2 Scope of Application

This Policy applies to the processing of your personal information that takes place when you interact with SIMDA through this Website, email, telephone, instant-messaging tools, in-person visits, and any other channels. This Policy does not extend to third-party websites or services that you may access via hyperlinks on this Website; such third parties maintain their own independent privacy policies, which we recommend that you review before visiting.

1.3 Information About the Controller

The personal information controller responsible for this Website and the related business is identified as follows. Company name: Nanjing Xingyue Yuda Information Technology Co., Ltd. Registered address: Nanjing, Jiangsu Province, People’s Republic of China. Official website: www.simdatech.com. Contact email: samliu_simda@foxmail.com. The personal information protection officer is the Company’s data compliance specialist and may be reached through the email address above; we will respond to your requests in a timely manner as required by law.

1.4 Definitions

“Personal information” refers to any information relating to identified or identifiable natural persons recorded by electronic or other means, but does not include information that has been anonymized. “Sensitive personal information” refers to personal information that, once leaked or used unlawfully, may easily lead to harm to the dignity of a natural person or to his or her personal or property safety, including biometric identification, religious belief, specific identity, medical and health information, financial account information, whereabouts and trajectories, as well as the personal information of minors under the age of fourteen. “Processing” includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information. “De-identification” refers to the process by which personal information is processed such that it cannot be used to identify a specific natural person without the use of additional information. “Anonymization” refers to the process by which personal information is processed such that it cannot be used to identify a specific natural person and cannot be restored.

II. Categories of Personal Information We Collect

2.1 Information You Actively Provide

When you communicate with us through the contact form on this Website, email, telephone, or in person, we collect information that you actively submit, which primarily includes: your name or preferred form of address; the name of the company or organization you represent; your title; your email address; your telephone number; your region; a description of your project requirements (such as the type of electronic product, target functionality, technical specifications, expected volume, and delivery timeline); business and technical documents you voluntarily provide during the communication; and, after a non-disclosure agreement (NDA) has been signed, the R&D drawings, specification documents, and sample information that you provide to us.

2.2 Information Collected Automatically

When you visit this Website, our servers and related technical components automatically record certain information, including: your Internet Protocol (IP) address (stored after de-identification); browser type and version; operating system; device identifiers; access time and session duration; referring and exit pages; click paths and browsing records; and access status codes and other log information, as well as preference settings captured through cookies and similar technologies. For the specific rules governing our use of cookies, please refer to the separate Cookie Policy published on this Website.

2.3 Special Note on Sensitive Personal Information

As a matter of principle, we do not actively collect your sensitive personal information. If, for business purposes, you voluntarily provide sensitive personal information such as identity-document numbers, bank-account details, or biometric data, we will obtain your separate consent in accordance with PIPL and apply the strictest protective measures. Except where necessary to achieve the specific purpose for which you have given explicit authorization, we will not process such sensitive information.

2.4 Information Relating to Minors

This Website serves enterprise clients and adult professionals and is not directed at persons under the age of fourteen. If you are a minor, please read this Policy and use this Website under the supervision of a guardian, and provide any personal information to us only after obtaining the guardian’s consent. Upon becoming aware that we have collected personal information from a minor, we will delete the relevant information without delay in accordance with the law.

III. Lawful Bases for Processing Personal Information

Before collecting and using your personal information, we will obtain your explicit consent after fully informing you of the purpose, method, and categories of information involved, the retention period, and your rights. You have the right to withdraw that consent at any time; such withdrawal does not affect the validity of the processing activities carried out before the withdrawal.

3.2 Necessary for the Conclusion or Performance of a Contract

When you establish a business relationship with us, sign a service contract, or enter into a non-disclosure agreement, we process your personal information to the extent necessary for the conclusion or performance of that contract, including but not limited to identity verification, contract execution, project delivery, payment settlement, and after-sales service.

3.3 Necessary for the Performance of Statutory Duties or Obligations

To fulfill obligations imposed on us by laws and regulations, or to respond to lawful and reasonable requests made by the competent authorities for cyberspace administration, public security, and market supervision, we will process the relevant information within the scope permitted by law.

3.4 Other Lawful Bases

In emergency situations necessary to protect your life, health, or property or that of others; where processing is necessary for the public interest such as news reporting or public-opinion supervision; or under other circumstances stipulated by laws and regulations, we may process your personal information without obtaining consent, while strictly observing the principles of necessity, minimization, and reasonableness.

IV. Purposes and Scope of Processing

4.1 Business Inquiry and Quotation

We use the information to respond to inquiries submitted through this Website, to provide product solutions, technical recommendations, and quotations, and to arrange business coordination and on-site visits. The information processed primarily includes your name, company, contact details, and project-requirement description.

4.2 Contract Performance and Project Delivery

Following the execution of a contract and non-disclosure agreement, we use the information to carry out electronic product research, design, prototyping, testing, production, and delivery. The information processed includes your identity and contact information, project materials, and business data generated over the course of cooperation.

4.3 Service Improvement and Statistical Analysis

We use access logs and operational data that have been de-identified or anonymized for statistical analysis, in order to understand Website usage patterns, user preferences, and service shortcomings, and thereby optimize Website structure, content layout, and service workflows. Once processed, such data cannot be linked to any specific natural person and no longer constitutes personal information.

4.4 Security and Compliance

We use the information for identity verification, access control, security auditing, risk monitoring, and incident tracing, in order to safeguard this Website and your personal information; and to support regulatory inspection, internal audit, and compliance record-keeping.

4.5 Purpose-Limitation Commitment

We process your personal information only to the extent necessary to achieve the purposes set out in this Policy. Where the information is to be used for any purpose not described herein, we will obtain your consent anew.

V. Storage and Protection of Personal Information

5.1 Storage Location

Personal information collected and generated within the territory of the People’s Republic of China is stored on servers and in data centers located within mainland China that comply with the requirements of the national cybersecurity classified-protection system. Unless otherwise provided by laws and regulations or with your separate consent, we will not transfer your personal information outside the People’s Republic of China.

5.2 Retention Period

We retain your personal information only for the shortest period necessary to achieve the purpose of collection, with specific periods determined by business scenario: business inquiry records are retained for three years after the most recent communication; contracts and project-related materials are retained for ten years after contract termination, in order to satisfy quality traceability and statutory record-keeping requirements; and access logs are retained for no longer than six months, unless otherwise required by laws and regulations. Upon expiry of the foregoing periods, we will delete or anonymize the information by technical means.

5.3 Security Safeguards

We have established an information security management system with reference to the national cybersecurity classified-protection system. The technical and organizational measures we adopt include: TLS/SSL encryption for data in transit; high-strength cryptographic encryption or masking of sensitive fields; independent deployment of databases with tiered authorization and least-privilege access; firewalls, intrusion-detection systems, and security-audit mechanisms; confidentiality agreements signed with all employees combined with regular compliance training for staff in sensitive positions; and project materials archived independently by client to prevent cross-contamination. Over the past twelve years we have maintained a zero-leak record with respect to client information.

5.4 Incident Response

Should a personal information security incident unfortunately occur, we will immediately activate our contingency plan, take remedial action to contain the harm, and notify you within the statutory time limit of the circumstances, cause, likely impact, and the measures taken or to be taken, while reporting the incident to the competent authorities in accordance with the law.

VI. Sharing, Transfer, and Public Disclosure of Personal Information

6.1 Sharing

We do not sell your personal information to any third party. We share necessary personal information with affiliated companies or business partners only in the following circumstances: first, where we have obtained your explicit consent; second, where it is necessary for the performance of a project contract, we may share information with partners commissioned to provide logistics, testing, surface-mount manufacturing, or structural-component processing services, and we will clearly set out in the commissioning contract the respective information-security obligations and confidentiality duties of both parties; third, where required by laws and regulations or compulsorily demanded by government authorities in accordance with the law. All commissioned processors must sign confidentiality agreements and may process the information only within the agreed scope.

6.2 Transfer

We will not transfer your personal information to any third party for that party’s independent commercial purposes. Where a transfer of personal information is required as a result of a merger, division, acquisition, or asset transfer, we will require the recipient to remain bound by this Policy; if the recipient changes the purpose or method of processing, it will obtain your consent anew in accordance with the law.

6.3 Public Disclosure

We will publicly disclose your personal information only where we have obtained your separate consent, where it is necessary to respond to a public-health emergency or to protect life, health, and property under emergency conditions, or where it is expressly required by laws and regulations.

6.4 Prior Notification for Sharing, Transfer, and Disclosure

Before sharing, transferring, or publicly disclosing your personal information, we will notify you in a conspicuous manner of the identity and contact information of the recipient, the purpose and method of processing, the categories of information involved, and your rights, and will obtain your consent or fulfill other statutory procedures as required by law.

VII. Cross-Border Transfer of Personal Information

As a matter of principle, personal information collected and generated within the People’s Republic of China is stored and processed only within the mainland. Where it is genuinely necessary, for business purposes, to provide personal information to an overseas recipient, we will, in strict accordance with Articles 38 through 40 of PIPL, inform you in advance of the name and contact information of the overseas recipient, the purpose and method of processing, the categories of information involved, and the means by which you may exercise your rights, and obtain your separate consent; at the same time, we will pass a security assessment organized by the national cyberspace administration, obtain certification from a specialized body, or conclude a standard contract formulated by the national cyberspace administration, and take the necessary measures to ensure that the overseas recipient’s processing activities meet the standard of protection required by PIPL.

VIII. Rights of the Data Subject

8.1 Right to Know and to Decide

You have the right to know and to determine the purpose, method, and scope of our processing of your personal information, and the right to restrict or refuse our processing activities, except where otherwise provided by laws and regulations.

8.2 Right of Access and of Copy

You have the right to request from us information about your personal information and to obtain a copy of that information within reasonable limits. After verifying your identity, we will respond within fifteen business days.

8.3 Right to Correction and to Completion

If you find that the personal information we process is inaccurate or incomplete, you have the right to request correction or supplementation. After verification, we will promptly make the correction or supplementation and notify the relevant recipients of the information.

8.4 Right to Deletion

You have the right to request that we delete your personal information in the following circumstances: the purpose of processing has been achieved, cannot be achieved, or is no longer necessary for achieving it; we have ceased to provide the service or the retention period has expired; you have withdrawn your consent; we have processed the information in violation of the law or of our agreement; or other circumstances stipulated by laws and regulations require deletion.

You have the right to withdraw your consent at any time through the contact channels set out in this Policy. Withdrawal of consent does not affect the validity of the processing activities, based on that consent, that were carried out before the withdrawal. Following the withdrawal, we will cease to process the relevant information, except where otherwise provided by laws and regulations or agreed in the contract.

8.6 Right to Data Portability

Where the conditions prescribed by the national cyberspace administration are met, you have the right to request that we transfer your personal information to another personal information controller that you designate; upon verification of the conditions, we will provide a copy of the information in a generally usable format.

8.7 Right to an Explanation

You have the right to inquire about our rules for processing personal information and to require an explanation of specific processing activities.

8.8 Right to Complain and to Report

If you believe that our processing of your personal information has infringed your lawful rights and interests, you have the right to lodge a complaint or report with the departments responsible for personal information protection, including the cyberspace administration and public security authorities, or to bring a lawsuit before a people’s court in accordance with the law.

8.9 Means of Exercising Your Rights

You may exercise the rights above through the contact channels listed in Section XIII of this Policy. To safeguard account security, we may, before processing a request, require you to provide information necessary for identity verification. We will not charge a fee for reasonable requests; for repeated requests that exceed reasonable limits, we may charge a necessary cost-based fee.

IX. Automated Decision-Making

We undertake not to use your personal information for automated decisions that would have a significant impact on your rights and interests, and not to carry out marketing by means of automated decision-making. Should future business developments require the use of automated decision-making, we will, in advance, conduct a personal information protection impact assessment, ensure the transparency of the decision-making process and the fairness and impartiality of the results, and provide you with a convenient means of refusing automated decisions and a channel for requesting an explanation of the outcome.

X. Protection of Minors’ Information

We attach great importance to the protection of minors’ information. If you are a minor under the age of fourteen, please read this Policy and use this Website under the supervision of a guardian, and provide any personal information to us only after obtaining the guardian’s consent. Upon becoming aware that we have collected personal information of a minor under the age of fourteen, we will treat that information as sensitive personal information in accordance with PIPL and apply the strictest protective measures. A guardian has the right to exercise data-subject rights at any time in accordance with Section VIII of this Policy and to request that we delete the relevant information.

XI. Retention Period for Personal Information

We retain your personal information only for the shortest period necessary to achieve the purpose of collection, as specified in Section 5.2 of this Policy. Upon expiry of the retention period, or following approval of your withdrawal of consent or deletion request, we will delete or anonymize the corresponding information by technical means so that it can no longer be used to identify you and no copies will be retained, except where otherwise provided by laws and regulations or otherwise agreed by you.

XII. Updates to and Notification of This Policy

We may revise this Policy from time to time when significant changes occur in laws and regulations, when our business scope is adjusted, or when the manner of processing personal information changes materially. For material changes (including but not limited to a change in the personal information controller, a material adjustment to the purpose or method of processing, an increase in the categories of information collected, or a change in the mechanism for exercising data-subject rights), we will alert you by means of a pop-up window, an announcement, or a notice sent to your registered email address, displayed prominently on this Website. If you do not agree with the revised content, you have the right to stop using the relevant services; if you continue to use them, you will be deemed to have accepted the revised Policy.

XIII. Contact and Complaint Channels

If you have any questions, suggestions, or complaints regarding this Policy, the exercise of your personal information rights, or our processing of your personal information, you may contact us in the following manner. Contact email: samliu_simda@foxmail.com. The telephone number and postal address are subject to the information published on the “Contact Us” page of this Website. The personal information protection officer is held by the data compliance specialist. After receiving your request, we will investigate and reply within fifteen business days; in complex cases, the response period may be appropriately extended in accordance with the law, with the reason communicated to you. If you are not satisfied with our response, or if you believe that our processing has infringed your lawful rights and interests, you may lodge a complaint or report with the departments responsible for personal information protection, including the cyberspace administration and public security authorities, or bring a lawsuit before a people’s court with jurisdiction in accordance with the law.

XIV. Supplementary Provisions

14.1 Right of Interpretation

The final right of interpretation of this Policy belongs to Nanjing Xingyue Yuda Information Technology Co., Ltd. The headings used in this Policy are for convenience of reading only and do not affect the interpretation of the substantive meaning of any provision.

14.2 Dispute Resolution

The conclusion, validity, interpretation, performance, revision, and termination of this Policy, and any disputes arising therefrom or in connection with the processing of your personal information by us, shall be governed by the laws of the People’s Republic of China. Disputes shall first be resolved through amicable consultation; if consultation fails, either party has the right to bring an action before a people’s court with jurisdiction at the place of domicile of Nanjing Xingyue Yuda Information Technology Co., Ltd.

14.3 Effectiveness

This Policy shall take effect on 1 July 2026 and shall supersede all previously published versions of the privacy policy. The Simplified Chinese version of this Policy shall prevail; any translated version is provided for reference only.