富途员工股权激励计划(ESOP)产品服务个人用户隐私政策


更新时间:2023年6月20日

生效时间:2023年6月20日


为充分保障您的权利,我们对《富途员工股权激励计划(ESOP)产品服务个人用户隐私政策》(下称“本政策”)进行了更新,此版本的更新主要集中于:

1. 为帮助您更清晰地了解您在使用我们的产品及服务时,我们如何收集和使用您的个人信息和敏感个人信息,我们更新了《个人信息收集清单》,且涉及敏感个人信息的内容已加粗、加下划线突显,供您阅读了解。

2. 为避免造成您的困惑或误解,我们更新了第九章“您的个人信息如何在全球范围转移”的内容,向您介绍您所适用的数据跨境传输情况。







正文


您的信任对我们非常重要,我们深知个人信息对您的重要性,我们将按法律法规要求,采取相应安全保护措施,尽力保护您的个人信息安全可控。我们致力于维持您对我们的信任,恪守以下原则,保护您的个人信息:权责一致原则、目的明确原则、选择同意原则、最少够用原则、确保安全原则、主体参与原则、公开透明原则等。有鉴于此,富途网络科技(深圳)有限公司及其关联公司作为富途集团旗下ESOP平台产品及服务的提供者(或简称“富途”或“我们”)制定本《隐私政策》(下称“本政策”)并提醒您:本政策适用于您通过任何方式使用ESOP平台产品及服务。在使用ESOP平台产品及服务前,请您务必仔细阅读并透彻理解本政策,在确认充分理解并同意后使用相关产品或服务。一旦您开始使用ESOP平台产品及服务,即表示您已充分理解并同意本政策。

如您对本政策内容有任何疑问、意见或建议,可以通过邮箱privacy@futunn.com以电子邮件方式与我们联系,我们邮寄的联系方式如下:


联系人:富途数据与个人信息保护中心

地址:深圳市南山区科兴科学园D1栋25F

邮编:518000


本政策将帮助您了解以下内容:

一、我们如何收集您的个人信息

二、我们如何处理收集的信息

三、我们如何使用Cookie和同类技术

四、我们如何共享、转让、公开披露您的个人信息

五、我们如何保护您的个人信息

六、我们如何存储信息

七、您管理自己信息的权利

八、我们如何保护未成年人的信息

九、您的个人信息如何在全球范围转移

十、我们处理您的敏感个人信息可能对您权益的影响

十一、我们可能向您发送的信息

十二、本政策如何更新

十三、本政策适用范围

十四、如何联系我们



一、我们如何收集您的个人信息

为了向您提供服务,维护ESOP平台产品及服务的正常运行,改进及优化我们的服务体验并保障您的账号安全,我们会出于本政策下述目的及方式收集您的个人信息,以及基于您使用ESOP平台产品及服务时产生的信息:

1、ESOP平台账号登录

只有您所在公司已与ESOP业务达成合作且您为所在公司激励计划的对象授权使用ESOP平台,您才可以登录、使用ESOP平台的产品及服务。

为了保证您的账号安全,当您首次登录使用富途ESOP平台产品或服务时,您需提供您的手机号码和短信验证码完成账号初步验证;

验证通过后,如您已创建了富途牛牛账号并与该手机号码绑定,则需要提供您的密码需完成密码验证方可成功登录;如您的手机号码未与任何富途牛牛账号绑定,则系统会为您生成富途牛牛账号,并需要您为其设置密码。

最后,您需要进一步通过身份证件号码后六位完成身份校验,校验通过后即成功登录。我们收集您的身份证号信息等信息完成多重验证,充分保障您的账号安全,提供ESOP平台账号登录、创建服务所必需,如您拒绝提供,您将无法使用我们的服务。

2、ESOP股权激励用户服务

(1)当您所在的公司与富途ESOP业务达成合作后,公司ESOP管理员(通常为公司的被授权人员)会向富途提供您的个人信息,用以启用ESOP平台、完成后续的股权激励服务,相关个人信息包括:姓名、手机号码、身份证件号码、联系邮箱、工号、税款信息

您确认您已授权您所在公司及授权人员基于提供ESOP平台产品或服务目的,将上述个人信息提供给富途。

(2)同时在某些激励计划的特殊安排模式下,我们可能接受公司委托,通过ESOP平台代为向您收集您的姓名、出生日期、用户ID、身份证件号码、国籍、银行账户信息、联系地址、富途牛牛账号、持仓股票、持仓数量、交易记录、资金记录、税款信息

我们经以上渠道收集到的个人信息将用于支持您员工期权及长期激励计划的开立及后续操作以保证ESOP业务可向您提供或继续提供行权、交易、结汇等相关服务,并满足境外法定审查的要求。如您拒绝提供,我们将无法为您及公司提供相应的行权、交易、结汇等相关服务。

3、ESOP产品及服务的安全运营

为保障用户正常使用ESOP产品及服务、用户的账号安全、识别账号异常状态,我们会收集您的如下个人信息:

(1)日志信息:当您使用我们的网站或客户端提供的产品或服务时,我们会自动收集您对我们服务的详细使用情况,作为有关网络日志保存。例如您的登录账号、搜索查询内容、IP地址、浏览器的类型版本、使用的语言、访问日期和时间及您访问的网页浏览记录、停留时长、刷新记录、操作记录。

(2)设备信息:当您使用我们的网站或客户端提供的产品或服务时,我们会接收并记录您所使用的设备相关信息(如操作系统及版本)。

4、其他情形

另外,根据相关法律法规及国家标准,以下情形中,我们可能会收集、使用您的相关个人信息无需征求您的授权同意

(1)与国家安全、国防安全等国家利益直接相关的;

(2)与公共安全、公共卫生、公众知情等重大公共利益直接相关的;

(3)与犯罪侦查、起诉、审判和判决执行等直接相关的;

(4)出于维护您或其他个人的生命、财产、声誉等重大合法权益但又很难得到本人同意的;

(5)所收集的个人信息是您自行向社会公众公开的;

(6)从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开等渠道;

(7)根据您要求签订和履行合同所必需的;

(8)用于维护所提供的产品或服务的安全稳定运行所必需的,例如发现、处置产品或服务的故障;

(9)为开展合法的新闻报道所必需的;

(10)出于公共利益开展统计或学术研究所必要,且其对外提供学术研究或描述的结果时,对结果中所包含的个人信息进行去标识化处理的;

(11)法律法规规定的其他情形。

5、 请您理解,我们向您提供的功能和服务是不断更新和发展的,如果某一功能或服务未在前述说明中且收集了您的信息,我们会通过页面提示、交互流程、网站公告等方式另行向您说明信息收集的内容、范围和目的。

6、 我们可能从关联方、第三方合作伙伴获取您授权共享的相关信息。我们将在符合相关法律规定,并依据与关联方或者第三方合作伙伴的约定、确信其提供的信息来源合法的前提下,收集并使用您的这些信息。

7、 以上由您提供的信息中,可能包含您的敏感个人信息,例如银行账号、交易记录、虚拟财产信息、系统账号、邮箱地址及其有关的密码、电话号码、网页浏览记录、位置信息。请您谨慎并留意个人敏感信息,您同意您的敏感个人信息我们可以按本政策所述的目的和方式来处理。

8、 除了上述已列举场景,我们还会基于客服、账号管理等为您提供服务的目的收集、处理您的个人信息,您可通过点击《ESOP个人信息收集清单》详细了解我们收集及使用您的个人信息的具体情况。如果你不同意提供特定功能下的个人信息,你将无法使用该等功能或可能影响您使用本服务的全部功能和服务。


二、我们将如何处理收集的信息

基于国家相关法律法规的规定,以及为向您提供服务及提升服务质量、向您提供安全、顺畅、高效和个性化的体验的目的,我们将在严格遵守法律法规的规定、本政策及其他与您的约定的前提下,将收集的信息用于以下用途。

1、向您提供各项相关服务;

2、使我们了解您如何接入和使用相关服务,以满足您的个性化需求;

3、开发和服务优化。例如,当我们的系统发生故障时,我们会记录和分析系统故障时产生的信息,优化我们的服务;

4、向您发送营销信息推广富途服务或第三方商品和服务,推荐您感兴趣的信息和资讯以及发出与富途服务有关的通知;

5、评估、改善我们的推广效果等;

6、管理软件。例如,进行软件认证、软件升级等;

7、邀请您参与有关我们服务的调查;

8、预防、发现、调查欺诈、侵权、危害安全、非法或违反与我们或与我们关联公司的协议、政策或规则的行为,保护您、其他用户或公众以及我们或我们关联公司的合法权益,我们会使用或整合您的个人信息、服务使用信息、设备信息、日志信息以及我们关联公司、合作伙伴取得您授权或依据法律共享的信息,来综合判断您账户及交易风险、进行身份验证、检测及防范安全事件,并依法采取必要的记录、审计、分析、处置措施;

9、为了确保服务的安全,帮助我们更好地了解我们应用程序的运行情况,我们可能记录相关信息,例如,您使用应用程序的频率、崩溃数据、总体使用情况、性能数据以及应用程序的来源,但我们不会将我们存储在分析软件中的信息与您在应用程序中提供的个人身份信息相结合;

10、经您授权的其他用途。

如我们处理您的个人信息超出了与收集时所声称的目的及具有直接或合理关联的范围,我们将在处理您的个人信息前,再次向您告知并征得您的明示同意。


三、我们如何使用Cookie和同类技术

1、Cookie

为使您获得更轻松的访问体验,您使用ESOP产品或服务时,我们可能会通过采用各种技术收集和存储您访问ESOP产品或服务的相关数据,在您访问或再次访问ESOP产品或服务时,我们能识别您的身份,并通过分析数据为您提供更好更多的服务,包括使用小型数据文件识别您的身份,这么做是为了解您的使用习惯,帮您省去重复输入账户信息的步骤,或者帮助判断您的账户安全。这些数据文件可能是Cookie、Flash Cookie,或您的浏览器或关联应用程序提供的其他本地存储(统称“Cookie”)。我们不会将 Cookie 用于本政策所述目的之外的任何用途。您可根据自己的偏好管理或删除 Cookie。有关详情,请参见 AboutCookies.org。您可以清除计算机上保存的所有 Cookie,大部分网络浏览器都设有阻止Cookie 的功能。但如果您这么做,在某些情况下您可能无法使用依赖于cookies的ESOP产品或服务的部分功能,则需要在每一次访问我们的网站时亲自更改用户设置。

2、网站信标和像素标签

除 Cookie 外,我们还可能在网站上使用网站信标和像素标签等其他同类技术。例如,我们向您发送的电子邮件可能含有链接至我们网站内容的点击 URL。如果您点击该链接,我们则会跟踪此次点击,帮助我们了解您的产品或服务偏好并改善用户服务。网站信标通常是一种嵌入到网站或电子邮件中的透明图像。借助于电子邮件中的像素标签,我们能够获知电子邮件是否被打开。

3、Do Not Track(请勿追踪)

很多网络浏览器均设有 Do Not Track 功能,该功能可向网站发布 Do Not Track 请求。目前,主要互联网标准组织尚未设立相关政策来规定网站应如何应对此类请求。但如果您的浏览器启用了 Do Not Track,那么我们会尊重您的选择。


四、我们如何共享、转让、公开披露您的个人信息

1、共享

我们不会与ESOP产品或服务相关服务提供者以外的公司、组织和个人共享您的个人信息,但以下情况除外:

(1)在获取您同意的情况下共享:获得您的明确同意后,我们会与其他方共享您的个人信息。

(2)在法定情形下的共享:我们可能会根据法律法规规定、诉讼争议解决需要,或按行政、司法机关依法提出的要求,对外共享您的个人信息。

(3)在您选择使用ESOP在线签署功能时,由于只有透露您的资料(如您的姓名等身份信息)才能提供您所要求的第三方产品和服务,或者用于ESOP业务进行数据分析或研究、改善我们的产品和服务。目前我们接入的第三方服务主要包括:第三方平台“上上签电子签约平台”、“腾讯云”服务,提供在线签署相关功能或服务。该等接入第三方服务由相关方负责运营,须受第三方自己的服务条款及信息保护声明(而非本政策)约束。

(4)如您被他人投诉或您投诉他人,我们会将您的身份信息等投诉相关信息提供给相关监管机构,用于解决投诉纠纷,但法律法规明确禁止提供的除外。

(5)为了遵守法律、执行或适用我们服务的使用条件和其他协议,或者为防止欺诈等违法活动和减少信用风险,而与其他公司和组织交换信息。

(6)与我们的附属公司共享:您的个人信息可能会与富途集团的附属公司共享。我们只会共享必要的个人信息,且受本政策中所声明目的的约束。附属公司如要改变个人信息的处理目的,将再次征求您的授权同意。

(7)与授权合作伙伴共享:仅为实现本政策中声明的目的,我们的某些服务将由授权合作伙伴提供。我们可能会与合作伙伴共享您的某些个人信息,以提供更好的用户服务和用户体验。例如,在您参与我们提供的奖励活动时,我们必须与合作伙伴共享您的个人信息才能安排发放奖励,或者安排合作伙伴提供服务。我们仅会出于合法、正当、必要、特定、明确的目的共享您的个人信息,并且只会共享提供服务所必要的个人信息。我们的合作伙伴无权将共享的个人信息用于任何其他用途。

(8)依据ESOP平台《富途安逸用户服务协议》与您的相关约定向第三方共享。如果您希望进一步了解我们向第三方共享信息的情况,请您阅读《第三方共享信息情况说明》

(9)您与我们关于信息共享的其他约定。

对我们与之共享个人信息的公司、组织和个人,我们会与其签署严格的保密协定,要求他们按照我们的说明、本政策以及其他任何相关的保密和安全措施来处理个人信息。

2、转让

除以下情形外,我们不会主动转让您的个人信息至:

(1)相关操作在事前已征得您的明示同意的;

(2)在涉及合并、收购或破产清算时,如涉及到个人信息转让,我们会要求新的持有您个人信息的公司、组织继续受本政策的约束,否则我们将要求该公司、组织重新向您征求授权同意;

(3)其他因根据法律法规的规定、有权机关的要求需要转让您的个人信息的。

3、公开披露

我们仅会在以下情况下,公开披露您的个人信息:

(1)获得您明确同意后;

(2)基于法律的公开披露:在法律、法律程序、诉讼或政府主管部门强制性要求的情况下,我们可能会公开披露您的个人信息;

(3)如果我们确定您出现违反法律法规或严重违反ESOP产品或服务相关协议规则的情况,或为保护ESOP产品或服务及其关联公司用户或公众的人身财产安全免遭侵害,我们可能依据法律法规或ESOP产品或服务相关协议规则征得您同意的情况下披露关于您的个人信息,包括相关违规行为以及ESOP产品或服务已对您采取的措施。

4、共享、转让、公开披露个人信息时事先征得授权同意的例外

(1)与国家安全、国防安全有关的;

(2)与公共安全、公共卫生、重大公共利益有关的;

(3)与犯罪侦查、起诉、审判和判决执行等有关的;

(4)出于维护您或其他个人的生命、财产等重大合法权益但又很难得到本人同意的;

(5)您自行向社会公众公开的个人信息;

(6)从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开等渠道。

(7)请您注意,根据法律规定,共享、转让经匿名化处理的个人信息,且确保数据接收方无法复原并重新识别个人信息主体的,不属于个人信息的对外共享、转让及公开披露行为,对此类数据的保存及处理将无需另行向您通知并征得您的同意。


五、我们如何保护您的个人信息

1、我们会采取各种预防措施来保护您的个人信息,以保障您的个人信息免遭丢失、盗用和误用,以及被擅自取阅、披露、更改或销毁。为确保您个人信息的安全,我们有严格的信息安全规定和流程,并有专门的信息安全团队在公司内部严格执行上述措施。

2、我们通过采取系统加密措施,访问管理控制和限制、及时删除或脱敏相关数据等安全保障技术与程序,使用户的个人数据免于未经授权的访问、使用或披露,保障数据与个人信息安全。我们的数据安全与个人信息保护能力已经取得包括但不限于以下认证:ISO29151个人身份信息保护实践指南证书、ISO27701隐私信息管理体系证书、ISO27001信息安全管理认证、SOC1审计认证与公安部信息系统安全保护等级三级认证。

3、我们会采取一切合理可行的措施,确保未收集无关的个人信息。我们只会在达成本政策所述目的所需的期限内保留您的个人信息,除非需要延长保留期或受到法律的允许。

4、我们会建立应急处理预案,若发生个人信息泄露等安全事件,我们会启动应急预案,阻止安全事件扩大。我们将及时将事件相关情况以邮件、信函、电话、推送通知等方式告知您,难以逐一告知个人信息主体时,我们会采取合理、有效的方式发布公告。

5、互联网环境并非百分之百安全,尽管我们有这些安全措施,但请注意在互联网上不存在“完善的安全措施”,我们将尽力确保您的信息的安全性。您可以通过不向任何人(除非此人经您正式授权)披露您的登录密码或账号信息,以防止密码泄漏以至危害您的账号安全。我们建议您不在设备供应商许可或保修的范围以外所修改的任何设备或操作系统(例如:已经“越狱”的移动设备)上使用本服务。在前述设备或操作系统使用本服务,可能会具有个人信息泄漏的风险。我们不对因您未能保持个人信息的私密性而导致第三方访问您的个人信息进而造成的安全疏漏承担责任。尽管有上述规定,如果发生其他任何互联网用户未经授权使用您账号的情况或其他任何安全漏洞,您应当立即通知我们。您的协助将有助于我们保护您个人信息的私密性。同时,我们还将按照监管部门要求,主动上报个人信息安全事件的处置情况。


六、我们如何存储信息

1、我们会按照相关法律法规规定,将在中华人民共和国境内收集的您的个人信息存储于中华人民共和国境内,并依法对这些信息进行严格保密。如部分情形下需要向境外机构传输境内收集的相关用户个人信息的,我们会按照法律、行政法规和相关监管部门的规定执行,并通过签订协议、现场核查等有效措施,要求境外机构为所获得的您的个人信息保密。

2、一般而言,我们仅为实现目的所必需的最短时间保留您的个人信息。但在下列情况下,我们有可能因需符合法律要求,更改个人信息的存储时间:

(1)为遵守适用的法律法规等有关规定;

(2)为遵守法院判决、裁定或其他法律程序的规定;

(3)为遵守相关政府机关或法定授权组织的要求;

(4)为执行相关服务协议或本政策、维护社会公共利益,为保护我们的用户、我们或我们的关联公司、其他用户或雇员的人身财产安全或其他合法权益所合理必需的用途。


七、您管理自己信息的权利

1、在您使用ESOP产品或服务的服务期间,为了您可以更加便捷地访问、更正、删除您的个人信息,同时保障您撤回对个人信息使用的同意及注销账户的权利,您可以通过以下途径管理您的个人信息:

(1)访问您的个人信息,如果您希望访问您的账户中的个人信息,您可以在登录ESOP系统后到个人资料信息页面进行查看;

(2)更正您的个人信息,如果您希望更正您的邮箱地址,您可以在登录ESOP系统后到个人资料信息页面进行更正,如果您希望更正您的其他个人信息,您可以联系您公司的ESOP管理员对您的个人信息进行更正,或由公司ESOP管理员联系富途进行操作;

(3)删除您的个人信息,您可以联系您公司ESOP管理员,由公司ESOP管理员联系富途删除你的个人信息;

(4)注销账户,您可以联系您公司的ESOP管理员,由公司ESOP管理员联系富途进行注销账户的操作;

(5)撤回个人信息处理同意,您可以联系您公司的ESOP管理员,由公司ESOP管理员联系富途撤回你授予富途处理您个人信息的同意;

(6)获取你的个人信息,您可以联系您公司的ESOP管理员,由公司ESOP管理员联系富途获取你在富途储存的个人信息。

(7)解除账号绑定,您可以联系您公司ESOP的管理员,要求管理员解除您的富途牛牛账号与ESOP产品或服务的绑定关系,届时您不可以再登录ESOP系统。

2、如您发现我们采集、使用您个人信息的行为,违反了法律、行政法规规定或违反了与您的约定,您可通过privacy@futunn.com联系我们,要求删除该违反行为下采集的您的个人信息。

3、如您发现我们采集、储存的您的个人信息有错误的,您可以通过privacy@futunn.com联系并要求我们及时更正。


八、我们如何保护未成年人的信息

我们非常重视对未成年人个人信息的保护,但我们ESOP产品、服务和网站和服务主要面向成年人,我们不会在明知的情况下收集未成年人个人信息。如果您发现我们无意收集了未成年人的个人信息,请您立即通知我们,我们会尽快设法删除相关数据。


九、您的个人信息如何在全球范围转移*

原则上,我们在中华人民共和国境内收集和产生的个人信息,将存储在中华人民共和国境内。

由于我们通过遍布全球的资源和服务器提供产品或服务,这意味着,在获得您的单独授权同意后,您的个人信息可能会被转移到您使用产品或服务所在国家/地区的境外管辖区,或者受到来自这些管辖区的访问。此类管辖区可能设有不同的数据保护法,甚至未设立相关法律。在此类情况下,我们会确保您的个人信息得到在中华人民共和国境内足够同等的保护。例如,我们会请求您对跨境转移个人信息的单独同意,与境外接收方签署跨境传输协议并在跨境数据转移之前实施数据去标识化等安全举措,充分保障您的个人信息权益与安全。


十、我们处理您的敏感个人信息可能对您权益的影响

依据《信息安全技术个人信息安全影响评估指南》(“指南”),以定性方式为例,可从“限制个人自主决定权”、“引发差别性待遇”、“个人名誉受损和遭受精神压力”和“人身财产受损”四个维度对个人信息的权益进行影响程度判定。在我们依据本政策处理您敏感个人信息的场景下,我们对您的个人权益影响程度判定如下表所示:

影响类别 影响描述 影响程度
限定个人自主决定权 例如被占用额外的时间
引发差别性待遇 例如耗费额外的时间获取公平的服务或取得相应的资格等
个人名誉受损和遭受精神压力 例如被频繁打扰、产生厌烦和恼怒情绪等
人身财产受损 例如因个人信息更正而需执行额外的流程(或提供额外的证明性材料)等

请注意:该判定结果仅是我们参照指南作出的对您个人权益影响造成的相对不利的评估说明,并不代表您将因我们处理您的敏感个人信息而承受此等不利影响。


十一、我们可能向您发送的信息

1、您在使用我们的服务时,我们可能向您发送电子邮件、短信、资讯或推送通知。您可以按照我们的相关提示,在设备上选择取消订阅。

2、我们可能在必要时(例如,因系统维护而暂停某一项服务时)向您发出与服务有关的公告。您可能无法取消这些与服务有关、性质不属于广告的公告。


十二、本政策如何更新

我们将根据相关法律法规的要求、业务发生变化或其他必要情形下,及时更新本政策,未经您明确同意,我们不会削减您按照本政策所应享有的权利,我们会在本页面上发布对本政策所做的变更,并通过官网发布或其他您可能合适接收通知的方式告知修改后的政策。在该种情况下,若您继续使用我们的服务,即表示同意受经修订更新后的政策约束。


十三、本政策适用范围

1、除我们明确说明需适用我们其他特别制定的单独隐私政策或条款的服务外,本政策适用于您使用的所有富途集团下公司提供的ESOP产品及服务。但某些服务已根据需要设定其特定的隐私指引/声明,如本政策与特定服务的隐私指引/声明有不一致之处,请以该特定隐私指引/声明为准。

2、本政策所有条款的标题仅为阅读方便,本身并无实际涵义,不能作为本政策涵义解释的依据。


十四、如何联系我们

如果您对本政策或数据处理有任何疑问、意见或建议,可以通过邮箱privacy@futunn.com与我们联系,我们邮寄的联系方式如下:

联系人:富途数据与个人信息保护中心

地址:深圳市南山区科兴科学园D1栋25F

邮编:518000

电子邮箱:privacy@futunn.com


一般情况下,我们将尽快审核所涉问题,并在收到您的投诉反馈后的十五天内予以回复。






ESOP个人信息收集清单

核心场景/业务功能

信息种类

收集/使用目的

保存期限

注册登录

姓名、手机号码、验证码、密码、身份证件号码(身份证号码、护照或其他证件)、电子邮箱、工号、税务信息

用于账号验证和登录

ESOP平台账户存续期间

设备信息(设备机型、操作系统及版本、客户端版本、设备分辨率、软硬件特征信息)

用于识别设备的数据(如设备序列号)或关于设备的数据 (如浏览器类型);用于故障排除、系统更新、软件适配,提升用户体验

ESOP平台账户存续期间

账号管理

姓名、手机号码、身份证件号码(身份证号码或护照)、验证码、电子邮箱、人脸识别信息(若开通此功能)

用于重置ESOP账号绑定的手机号码或电子邮箱,身份验证

ESOP平台账户存续期间

头像、昵称

用于完善网络身份标识、提供个性化展示

设备信息(设备机型、操作系统及版本、客户端版本等;历史登录设备信息)

用于识别设备的数据(如设备序列号)或关于设备的数据 (如浏览器类型); 用于故障排除、系统更新、软件适配,提升用户体验; 用于管理登录设备,防止他人盗用

ESOP平台账户信息,如账号名称、用户名、密码

用于找回与修改密码、解锁、注销账号

用户行权与交易

姓名、身份证件号码(身份证号码或护照)、富途牛牛账号、用户ID、工号、流水记录(结汇信息,包括打款批次、发起结汇日期、结汇净收)、流水记录(税款信息,包括激励税款、已汇税款、本次结汇税款)

用于提供结汇服务

适用法律法规规定的保存期限

姓名、身份证件号码(身份证号码或护照)、富途牛牛账号、国籍、银行账户信息(银行卡、开户名、银行国际代码(SWIFT CODE)、国际银行账户号码(IBAN))

用于满足富途的法定审查义务

适用法律法规规定的保存期限

客户服务

用户与客服的联系记录、ESOP平台账户信息、身份核验信息等为解决用户咨询事项所必须的信息

用于回应用户投诉建议、问题咨询及争议处理

ESOP平台账户存续期间

安全运行

日志信息,如登录帐号、搜索查询内容、IP地址、浏览器的类型、电信运营商、网络环境、使用的语言、注册年限、访问日期和时间、您访问的网页浏览记录、停留时长、刷新记录、操作记录

设备信息(设备机型、操作系统及版本、客户端版本等;历史登录设备信息)

用于保障用户正常使用产品及服务、用户的账号安全、识别账号异常状态

ESOP平台账户存续期间

员工管理

姓名、工号、富途牛牛账号、电子邮箱、手机号码、身份证件号码(身份证或护照号码)、税务居民身份

用户基础信息管理

ESOP平台账户存续期间

授予管理

姓名、工号、富途牛牛账号、电子邮箱、手机号码、身份证件号码(身份证或护照号码)、税务居民身份

用于激励数据的管理、记录

ESOP平台账户存续期间

在线签署

姓名、工号、富途牛牛账号、手机号码、电子邮箱、人脸识别信息(若开通此功能)身份证件号码(身份证或护照号码)

用于协议签署通知及签署人身份验证

ESOP平台账户存续期间

报表管理

姓名、工号、富途牛牛账号、电子邮箱、手机号码、身份证件号码(身份证或护照号码)

用于激励数据统计、持有情况统计

ESOP平台账户存续期间

第三方共享信息情况说明

基于实现在用户身份认证、手机设备安全、接收信息推送、账户认证和登录以及保障信息安全的目的,在向您提供服务过程中,ESOP平台会与第三方共享信息,我们将这些第三方服务商的名称、使用目的、官网链接、隐私政策分别列明如下。

1、SDK类

2、非SDK类

序号

名称

共享信息种类

目的

数据接收方

链接

适用平台

1

上上签

用户身份信息,包括姓名、证件号码;合同信息

使用上上签在线签署,为客户生成专属的数字证书,用作在线协议签署;为客户生成电子协议

杭州尚尚签网络科技有限公司

官网链接:https://www.bestsign.cn/

隐私政策链接:https://ent.bestsign.cn/account-center/legal-agreement/privacy-policy

web

2

腾讯云

用户身份信息,包括姓名、证件号码

使用腾讯云二要素认证、人脸核身服务,验证国内客户身份真实性,确保协议签署有效性

深圳市腾讯计算机系统有限公司

官网链接:https://cloud.tencent.com/

隐私政策链接:https://cloud.tencent.com/document/product/301/11470

web


Futu Employee Equity Incentive Plan (ESOP) Product Services

Personal User Privacy Policy


Last update time: June 20th 2023

Effective time: June 20th 2023


In order to fully protect your rights, we have updated the "Futu Employee Equity Incentive Plan (ESOP) Product Services Personal User Privacy Policy" ("Privacy Policy"), which is as set out below.

1. To help you understand how we collect and use your personal information and sensitive personal information when you use our products and the service, we have updated the ESOP Personal Information Collection Checklist. We also have bolded and underlined the contents of sensitive personal information for your information.

2. To help you understand the cross-border transfer of personal information, we have updated Section 9, "How your Personal Data is transferred globally", to provide you with more detailed information.







Content


Your trust is very important to us. We are well aware of the importance of Personal Data to you. We will take corresponding security protection measures in accordance with the requirements of laws and regulations, and endeavour to keep your Personal Data safe and controllable. We are committed to maintaining your trust in us and protecting your Personal Information by adhering to the following principles: balancing rights with responsibilities, clear purpose, consent, minimum necessary, security, participation of PI Subjects, transparency. In view of this, Futu Network Technology (Shenzhen) Co., Ltd. And its affiliates, as the providers of services of Futu Employee Equity Incentive Plan (ESOP) Product and Services (referred to as "we" or "Futu") have formulated this "Privacy Policy" (hereinafter referred to as "this Policy") and would like to remind you that: This Policy applies to any use of the ESOP platform products and services. Before using the ESOP platform products and services, please be sure to read and thoroughly understand this Policy, and use related products or services only after confirming your full understanding and agreement to this Policy. Once you start using the ESOP platform products and services, you are deemed to have fully understood and agreed to this Policy.

If you have any questions, comments or suggestions about the content of this Policy, you can contact us by email at privacy@futunn.com. Our contact information is as follows:


Contact: Futu Data and Personal Information Protection Centre

Address: 25F, Building D1, Kexing Science Park, Nanshan District, Shenzhen

Postcode: 518000


This Policy will help you understand the following:

1. How we collect your Personal Data

2. How we use the Personal Data we collect

3. How we use cookies and similar technologies

4. How do we share, transfer and publicly disclose your Personal Data

5. How we protect your Personal Data

6. How we store your Personal Data

7. Your right to manage your Personal Data

8. How do we protect the Personal Data of minors

9. How your Personal Data is transferred globally

10. How our processing of your sensitive personal information may affect your rights

11. Information we may send you

12. Updates to this Policy

13. Scope of application of this Policy

14. How to contact us



1. How we collect your Personal Data

In order to provide services to you, maintain the proper functioning of the ESOP platform products and services, improve and optimize our service experience, and protect your account security, we may collect your personal information and information based on your use of ESOP products and services for the following purposes and in the manners described in this policy:

1.1 ESOP platform account login

Only when your company has entered into a partnership with the ESOP services and you are authorized to use the ESOP platform for the purpose of your company's incentive plan, can you log in and use the ESOP platform products and services.

To ensure the security of your account, you will be required to provide your mobile phone number and SMS verification code to complete initial account verification when you first log in to use the products or services on the ESOP platform;

After the verification, if you have already created a Futubull account and linked it to your mobile number, then you need to provide your password to complete the password verification to log in; if your mobile number is not linked to any Futubull account, the system will generate a Futubull account for you, and you can set a password for it.

To complete the final verification, you need to provide the last six digits of your ID number. Then you can login successfully. We collect your ID number and other information to complete multiple verifications to fully secure your account and provide the necessary information for ESOP platform account login and service creation. If you refuse to provide it, you will not be able to use our services.

1.2 ESOP equity incentive user services

1) Once your company has entered into a partnership with Futu ESOP services, the company ESOP administrator (usually an authorized person in the company) will provide Futu with your personal information to enable the ESOP platform and to complete the subsequent equity incentive service. Your personal information includes: name, mobile number, ID number, email, employee ID and tax information.

You confirm that you have authorized your company and authorized personnel to provide the above personal information to Futu for the purpose of providing ESOP platform products or services.

2) We may also be instructed by the company to collect your name, date of birth, user ID, ID number, nationality, bank account information, address, Futubull ID, stock positions, positions quantity, transaction history, funds records and tax information through the ESOP platform under the special arrangement model of certain incentive plans.

The personal information we collect through the above channels will be used to support the opening and subsequent operation of your employee option and long-term incentive plans to ensure that the ESOP service is available to you or continues to be available to you for exercise, trading, settlement, and other related services, and to meet the requirements of overseas statutory reviews. If you refuse to provide it, we will not be able to provide you and the Company with the appropriate exercise, trading, settlement, and other related services.

1.3 Secure operation of ESOP products and services

In order to protect the regular use of ESOP products and services, the safety of users' accounts, and to identify abnormal account status, we may collect the following personal information from you:

a) Log information: When you use the products or services provided by our website or client, we will automatically collect your detailed usage of our services and save them as relevant network logs. For example, your login account, search query content, IP address, browser type and version, language used, date and time of access, and web browsing records you visit, length of stay, refresh records, and operation records.

b) Device information: When you use the products or services provided by our website or client, we will receive and record the device-related information (such as operating system and version) you are using.

1.4 Other circumstances

In addition, we may collect and use your relevant Personal Data without asking for your authorization when we are required to do so in order to comply with applicable law or court order:

a) Directly related to national interests such as national security, national defense security, etc.;

b) Directly related to significant public interests such as public safety, public health and public right to know;

c) Directly related to crime investigation, prosecution, trial and execution of judgments;

d) For the purpose of protecting your life, property, reputation, and other significant legitimate rights and interests or those of other individuals but where it is difficult to obtain your consent;

e) Where the personal information collected is disclosed to the public by you;

f) Where personal information is collected from information that is lawfully and publicly disclosed, such as legitimate news reports, government information disclosure, and other channels;

g) Necessary for the signing and performance of a contract at your request;

h) Necessary for maintaining the safe and stable operation of the product or services, such as detecting and solving malfunctions of the product or services;

i) Necessary for the conduct of legitimate news reporting;

j) Necessary for statistical or academic research in the public interest and where it provides the results of academic research or descriptions to the public by de-identifying the personal information contained in the results;

k) Other circumstances as provided by law and regulations.

1.5 Please understand that the functions and services we provide to you are constantly being updated and developed. If a function or service is not in the above description and your information is collected, we will notify you through page prompts, interactive processes, and website announcements. The content, scope and purpose of information collection will be explained to you separately by other means.

1.6 We may obtain relevant information that you authorize to share with our affiliates and third-party partners. We will collect and use your information under the premise of complying with relevant laws and regulations, in accordance with the agreement with affiliates or third-party partners, and on the premise that the sources of information provided by them are legal.

1.7 Information provided by you may include your personal sensitive information, such as bank account numbers, transaction records, virtual property information, system account numbers, email addresses and their related passwords, phone numbers, web browsing records, and location information. Please be careful and pay attention to sensitive Personal Data, and you agree that we can process your sensitive Personal Data in accordance with the purposes and methods described in this Policy.

1.8 In addition to the scenarios already listed above, we may also collect and process your personal information for the purposes of providing services to you, such as customer service, account management, etc. You can learn more about how we collect and use your personal information by clicking on the "ESOP Personal Information Collection Checklist". If you do not agree to provide personal information under certain features, you will not be able to use those features, or it may affect your access to the full range of features and the services.


2. How we use the Personal Data we collect

Based on the provisions of relevant laws and regulations, and for the purpose of providing you with services and improving service quality, and providing you with a safe, smooth, efficient and personalized experience, we will strictly abide by the provisions of laws and regulations regulating Personal Data and this Policy.

1) To provide you with various services;

2) To understand how you access and use the services and to meet your customized needs;

3) Development and service optimization: To optimize and develop our services. For example, when our system fails, we will record and analyze the information generated;

4) To send you marketing information to promote Futu services or third-party goods and services, recommend information and information you are interested in, and issue notifications related to Futu services;

5) To evaluate and improve our promotion campaigns and assess their effectiveness;

6) To improve our management software. For example, software certification, software upgrade, etc.;

7) To invite you to participate in surveys about our services;

8) To prevent, detect, investigate acts that are fraudulent, or which infringes the rights of any person, or which jeopardizes security, or is illegal, or violates any agreements, policies or rules with us or any of our affiliates; or to protect the legitimate rights and interests of any user, or the public, as well as us and/or our affiliates. We will use and/or integrate your Personal Data, service usage information, device information, log information, and information that our affiliates and partners have obtained from you with your authorization or shared in accordance with the law to comprehensively analyze your account and transaction risks, and identity verification; to detect and prevent security incidents; and to take necessary recording, auditing, analysis, and disposal measures in accordance with the law;

9) To ensure the security of the service and help us better understand the operation of our application. We may record relevant information, such as the frequency of your use of the application, crash data, overall usage, performance data and the source of the application, but we do not combine the information we store in the analytics software with the personally identifiable information you provide in the app;

10) Any other purpose authorized by you.

If we use your Personal Data beyond the scope of the purposes listed above that is directly or reasonably related to the any of the above purposes at the time of collection, we will inform you again and obtain your express consent before using your Personal Data for such purposes.


3. How we use cookies and similar technologies

3.1 Cookies

In order to provide you with an easier access experience, when you use ESOP platform products or services, we may use various technologies to collect and store data related to your access to ESOP platform products or services. When visiting ESOP platform products or services, we can identify your identity, and provide you with better and more services by analyzing data, including identifying your identity using small data files, in order to understand your usage habits, to save you the step of repeatedly entering account information, or to help determine the security of your account. These data files may be cookies, Flash cookies, or other local storage provided by your browser or associated application (collectively, "Cookies"). We will not use Cookies for any purpose other than those described in this policy. You can manage or delete Cookies according to your preferences. See AboutCookies.org for details. You can clear all Cookies saved on your computer, and most web browsers have a Cookie-blocking feature. However, if you do this, in some cases you may not be able to use some functions of the ESOP platform products or services that rely on cookies, and you need to personally change the user settings every time you visit our website.

3.2 Web Beacons and Pixel Tags

In addition to Cookies, we may also use other similar technologies such as web beacons and pixel tags on our website. For example, an email we send you may contain a click URL linking to the content of our website. If you click on the link, we will track the click to help us understand your product or service preferences and improve customer service. A web beacon is usually a transparent image embedded in a website or email. With the help of pixel tags in emails, we can tell if an email has been opened.

3.3 Do Not Track

Many web browsers have a Do Not Track feature that issues a Do Not Track request to a website. Currently, no major Internet standards organization has established policies governing how websites should respond to such requests. But if your browser has Do Not Track enabled, then we will respect your choice.


4. How do we share, transfer and publicly disclose your Personal Data

1) Share

We will not share your Personal Data with companies, organizations and individuals other than service providers related to ESOP products or services, except in the following cases:

a) Sharing with your consent: After obtaining your explicit consent, we may share your Personal Data with other parties.

b) Sharing under statutory circumstances: We may share your Personal Data externally in accordance with laws and regulations, the need for litigation and dispute resolution, or as required by administrative and judicial authorities in accordance with the law.

c) When you choose to use the online signing function of the ESOP, only by revealing your Personal Data (such as your name and other identity information) can you receive the third-party products and services you require, or use such products and services together with the equity management platform. At present, the third-party services we access mainly include: third-party platform "Docusign" and "Tencent Cloud" services, which provide online signing related functions or services. Such access to third-party services is operated by the relevant parties and is subject to the third-party's own terms of service and information protection statement (not this "Privacy Policy"). You agree to us sharing your Personal Data with such third parties.

d) If a complaint regarding you has been received, or where you lodge a compliant against others, we will provide your Personal Data and other complaint-related information to the relevant regulatory agencies for the purpose of resolving complaints and disputes, unless the provision of such Personal Data is expressly prohibited by laws and regulations.

e) We may exchange information (including your Personal Data) with other companies and organizations in order to comply with laws, to enforce or apply the conditions of use of our services and other agreements, or to prevent fraud and other illegal activities, or to reduce credit risks.

f) Sharing with our affiliates: Your Personal Data may be shared with Futu's affiliates. We will only share necessary Personal Data and subject to the purposes stated in this Policy. If the affiliated company wants to change the purpose of processing Personal Data, it will ask for your authorization again.

g) Sharing with authorized partners: Some of our services will be provided by authorized partners only for the purposes stated in this Policy. We may share some of your Personal Data with our partners to provide better customer service and user experience. For example, when you participate in a reward activity we offer, we must share your Personal Data with our partners in order to arrange for rewards to be issued, or to arrange for partners to provide services. We will only share your Personal Data for legal, legitimate, necessary, specific and explicit purposes, and only share Personal Data necessary to provide services. Our partners are not authorized to use the shared Personal Data for any other purpose.

h) Share with third parties in accordance with the relevant agreements between the ESOP platform "Futu I&E User Service Agreement" and you. We may share your Personal Data with such third parties. If you wish to learn more about our sharing of information with third parties, please read the Third-Party Information Sharing Instructions.

i) Other agreements between you and us about information sharing.

For companies, organizations and individuals with whom we share Personal Data, we will sign strict confidentiality agreements with them, requiring them to process Personal Data in accordance with our instructions, this Policy and other relevant confidentiality and security measures, and in accordance with all applicable laws.

2) Transfer

We will not actively transfer your Personal Data to third parties except in the following circumstances:

a) Where your express consent has been obtained in advance;

b) If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include user information among our assets transferred to or acquired by a third party. You acknowledge and agree that such transfers may occur, and that any parties who acquire us may continue to use your Personal Data according to this Policy, or we will require the company, organization to obtain authorized consent from you again;

c) Where it is necessary to transfer your Personal Data in accordance with the provisions of laws and regulations, and/or the requirements of competent authorities.

3) Public disclosure

We will only publicly disclose your Personal Data in the following circumstances:

a) After obtaining your explicit consent;

b) Public disclosure based on law: We may publicly disclose your Personal Data if required by law, or any governmental authority or pursuant to any court order;

c) If we determine that you have violated laws and regulations or seriously violated the relevant agreement rules of ESOP products or services, or in order to protect the safety of any person or the safety of any property or the ESOP products or services, or the safety of us or any of our affiliates, or the safety of any other users, or to protect the public from your infringement, we may disclose your Personal Data with your consent in accordance with laws, regulations, and rules of the ESOP product or service-related agreements, including without limitation information regarding your violations and the measures that the ESOP products or services have taken against you

4) Exceptions to prior authorized consent for personal information sharing, transfer, and public disclosure

a) Directly related to national interests such as national security, national defense security, etc.;

b) Directly related to significant public interests such as public safety, public health, and public right to know;

c) Directly related to crime investigation, prosecution, trial, and execution of judgments;

d) For the purpose of protecting your life, property, reputation, and other significant legitimate rights and interests or those of other individuals but where it is difficult to obtain your consent;

e) Where the personal information collected is disclosed to the public by you;

f) Where personal information is collected from information that is lawfully and publicly disclosed, such as legitimate news reports, government information disclosure, and other channels;

g) Please note that, according to the law, sharing or transferring personal information that has been anonymized and ensuring that the recipient can't recover and re-identify the subject of the personal information is not considered an act of sharing, transferring, or publicly disclosing personal information to the public. The storage and processing of such data will not require separate notification to you and your consent.


5. How we protect your Personal Data

1) We will take various preventive measures to protect your Personal Data to protect your Personal Data from loss, misappropriation and misuse, as well as unauthorized access, disclosure, alteration or destruction. To ensure the security of your Personal Data, we have strict information security regulations and procedures, and a dedicated information security team strictly implements the above measures within the company.

2) We take security protection technologies and procedures such as system encryption measures, access management control and restriction, timely deletion or desensitization of relevant data, etc., to protect users' personal data from unauthorized access, use or disclosure, and to protect data and personal data. information security. Our data security and personal information protection capabilities have achieved certifications including but not limited to the following: ISO29151: certificate of practice for personally identifiable information protection, ISO27701: certificate of privacy information management, ISO27001: certificate of information management, SOC1 Report, and Certification of Information security technology cybersecurity protection 3.0.

3) We will take all reasonable and feasible measures to ensure that irrelevant personal data is not collected. We will only retain your Personal Data for as long as is necessary to achieve the purposes described in this Policy, unless an extension of the retention period is required or permitted by law.

4) We will establish an emergency response plan. If a security incident such as Personal Data leakage occurs, we will activate an emergency plan to prevent the expansion of the security incident. We will promptly notify you of the relevant information of the event by email, letter, telephone, push notification, etc. When it is difficult to inform the subject of Personal Data one by one, we will take a reasonable and effective way to publish an announcement.

5) The Internet environment is not 100% secure. Although we have these security measures, please note that there are no "perfect security measures" on the Internet, and we will try our best to ensure the security of your information. You can prevent your password from leaking and endanger your account security by not disclosing your login password or account information to anyone (unless the person is officially authorized by you). We recommend that you do not use the service on any device or operating system that has been modified outside the scope of the device vendor's license or warranty (eg, a "jailbroken" mobile device). The use of this service on the aforementioned devices or operating systems may lead to the risk of Personal Data leakage. We are not responsible for security omissions caused by third parties accessing your Personal Data due to your failure to keep it private. Notwithstanding the foregoing, you should notify us immediately of any unauthorized use of your account by any other Internet user or of any other security breach. Your assistance will help us protect the privacy of your Personal Data. At the same time, we will also proactively report the handling of Personal Data security incidents in accordance with the requirements of regulatory authorities.


6. How we store your Personal Data

1) We will store your Personal Data collected in China in accordance with relevant laws and regulations, and keep such information strictly confidential in accordance with the law. In some cases, we may transmit the relevant user Personal Data to our affiliates and other third parties in other jurisdictions. We will implement any such transmission in accordance with all applicable laws, and through effective measures such as signing agreements and on-site inspections.

2) Generally speaking, we only keep your Personal Data for the shortest time necessary to achieve the purpose. However, in the following cases, we may change the storage time of Personal Data to meet legal requirements:

a) In order to comply with applicable laws and regulations and other relevant regulations;

b) To comply with court judgments, rulings or other legal procedures;

c) To comply with the requirements of relevant government agencies or legally authorized organizations;

d) Where it is reasonable and necessary to do so for the purposes for the implementation of relevant service agreements or this Policy, the protection of the persons and property, the protection of other users, our employees, us and/or our affiliates, and/or to protect any other legitimate rights and interests.


7. Your right to manage your Personal Data

1) During your use of ESOP products or services, in order for you to access, correct and delete your Personal Data more conveniently, and to protect your right to withdraw your consent to the use of Personal Data and cancel your account, you can manage your Personal Data by:

a) Access your Personal Data: if you wish to access the Personal Data in your account, you can view it on the personal information page after logging in to the ESOP system;

b) To correct your Personal Data: if you want to correct your email address, you can go to the personal information page to correct after logging in to the ESOP system. If you want to correct any other Personal Data, you can contact the ESOP administrator, and that administrator will contact Futu for assistance to correct your Personal Data;

c) To delete your Personal Data: you can contact the ESOP administrator, and that administrator will contact Futu for assistance to delete your Personal Data;

d) To cancel the account: you can contact the ESOP administrator, and that administrator will contact Futu for assistance to delete your account;

e) To withdraw your consent to the processing of Personal Data: you can contact the ESOP administrator, and that administrator will contact Futu to withdraw your consent granted to Futu to process your Personal Data;

f) To obtain your Personal Data: you can contact the ESOP administrator, and that administrator will contact Futu to obtain your Personal Data stored with Futu;

g) To release the account binding: you can contact the ESOP administrator and ask the administrator to release the binding relationship between your Futubull account and the products or services of the ESOP products and services. After such unbinding, you can no longer log in to ESOP system.

2) If you find that our collection and use of your Personal Data violates the provisions of any applicable laws or any agreement between us, you can contact us at privacy@futunn.com and request to delete your data that has been collected under such violations.

3) If you find that your Personal Data collected and stored by us is wrong, you can contact us at privacy@futunn.com and ask us to correct it in time.


8. How do we protect the Personal Data of minors

We attach great importance to the protection of minors' Personal Data, but ESOP products, services and websites and services are mainly for adults, and we will not collect minors' Personal Data knowingly. If you find that we have unintentionally collected Personal Data of minors, please notify us immediately, and we will try to delete the relevant data as soon as possible.


9. How your Personal Data is transferred globally*

In general, the Personal Data we collect and generate in China will be stored in China.

Since we provide products or services through resources and servers all over the world, this means that, your Personal Data may be transferred to jurisdictions outside the country/region where you use the products or services, or subject to access from these jurisdictions. Such jurisdictions may have different data protection laws or even no relevant laws. In such cases, we shall ensure that any Personal Data transferred outside of China will be afforded a standard of protection that is comparable to the protection required under the PDPA. For example, we will request your individual consent for cross-border transfers of personal information, sign cross-border transfer agreements with foreign receivers, and implement security measures such as data de-identification before cross-border data transfers to fully protect the rights and security of your personal information.


10. How our processing of your sensitive personal information may affect your rights

Qualitative assessment, for example, can be conducted according to the “Information Security Technology – Security Impact Assessment Guide of Personal Information” (“The guide”), and be based on four dimensions: (1) influencing personal self-determination rights, (2) causing differential treatment, (3) causing personal reputational damages and mental stress, and (4) damaging personal property. In the scenarios where we process your sensitive personal information in accordance with this policy, we assess the degree of impact on your personal rights as set out in the table below:

Impact Dimension Impact Description Degree of Impact
Influencing personal self-determination rights E.g., extra time costs. Low
Causing differential treatment E.g., extra time costs to acquire fair services or qualifications, etc. Low
Causing personal reputational damages and mental stress E.g., frequent nuisance, weariness and annoyance, etc. Low
Damaging personal property Such as, extra procedures (or providing extra evidentiary documents) to correct personal information, etc. Low

Note: This assessment is only an indication of the relative adverse impact on your personal rights by referring to the guide. It does not mean that you will suffer such adverse impacts from our processing of your sensitive personal information.


11. Information we may send to you

1) When you use our services, we may send to you emails, text messages, information or push notifications. You can choose to unsubscribe from such notifications on your device by following our tips.

2) We may issue service-related announcements to you when necessary (for example, when a service is suspended due to system maintenance). You may not be able to cancel these service-related announcements that are not advertising in nature.


12. Updates to this Policy

We may from time to time update this Policy to take into account changes to the law, our business or any other relevant factors. Changes to this Policy will be posted on our website, and by the posting of any revised Policy on our website, you shall be deemed to have been notified of the changes made to the Policy and you shall agree to be bound by such updated Policy. If you are unsure whether you are reading the most current version, please contact us. Without limiting the foregoing, if you continue to use our services, you agree to be bound by the revised and updated Policy.


13. Scope of application of this policy

1) This policy applies to the products and services of the ESOP products and services of Futu that you use, except for services that we expressly state that our other specially formulated separate privacy policies or terms apply. However, some services have set their specific privacy guidelines/statements according to their needs. If there is any inconsistency between this policy and the privacy guidelines/statements of specific services, please refer to the specific privacy guidelines/statements.

2) The titles of all clauses of this Policy are for reading convenience only, have no actual meaning in themselves, and cannot be used as the basis for the interpretation of the meaning of this policy.


14. How to contact us

If you have any questions, comments or suggestions about this Policy or data processing, you can contact us by email at privacy@futunn.com, our contact details are as follows:

Contact: Futu Data and Personal Information Protection Centre

Address: 25F, Building D1, Kexing Science Park, Nanshan District, Shenzhen

Postcode: 518000

Email: privacy@futunn.com


Under normal circumstances, we will reply within fifteen days after receiving your relevant contact information and verifying your identity.






ESOP Personal Information Collection Checklist

Core Scenarios/Business Functions

Information Types

Collection/Use Purpose

Retention Period

Registration and login

Name, mobile number, verification code, password, (ID number, passport number or other identification), email, employee number, tax information

Account verification and login

During the existence of ESOP account

Device information (device model, operating system and version, client version, device resolution, hardware and software information)

Data to identify the device (e.g., device serial number) or data about the device (e.g., browser type); Troubleshooting, system updates, and software adaptations to enhance the user experience

During the existence of ESOP account

Account management

Name, mobile number, password, ID number (resident ID number or passport number),verification code, email, face recognition information (if enabled)

Reseting the mobile number or email linked to your ESOP account and identify verification

During the existence of ESOP account

Profile photo and name

Improving online identity and providing customized displays

Device information (device model, operating system and version, client version, device resolution, historical login device information)

Data to identify the device (e.g., device serial number) or data about the device (e.g., browser type); Troubleshooting, system updates, and software adaptations to enhance the user experience; Manage login devices to prevent others from stealing your account

ESOP platform account information, such as account name, username, password

Retrieving and changing the password, unlocking and canceling the account

Exercise and trading

Name, ID number (resident ID number or passport number), Futubull ID, user ID, employee ID, account statement (settlement information: payment batch, initiate date of settlement, settlement net income), account statement (tax information: incentive tax, remitted tax, current tax settlement)

Foreign exchange settlement services

Retention periods stipulated by applicable laws and regulations

Name, ID number (resident ID number or passport number), Futubull ID, nationality, bank account information (bank card, account name, bank international code (SWIFT CODE), international bank account number (IBAN))

Futu' statutory review

Retention periods stipulated by applicable laws and regulations

Customer services

Contact records with customer service, ESOP account information, identity verification information, and other information necessary to resolve user inquiries

Responding to user complaints and suggestions, inquiries and disputes

During the existence of ESOP account

Safe operation

Log information such as login account, search query content, IP address, browser type, telecom operator, network environment, language used, registration years, access date and time, web browsing history you visited, length of stay, refresh record, operation record, device information (historical login device information such as device model, operating system and version, client version, etc.)

To ensure the regular use of products and services, the security of users' accounts, and to identify abnormal account status

During the existence of ESOP account

Employees management

Name, employee number, Futubull account, email, mobile number, ID number (resident ID number or passport number), tax residence identity

User basic information management

During the existence of ESOP account

Grant management

Name, employee number, Futubull account, email, mobile number, ID number (resident ID number or passport number), tax residence identity

User basic information management

During the existence of ESOP account

E-signing

Name, employee number, Futubull account, mobile number, email, face recognition information (if enabled), ID number (resident ID number or passport number)

Used for protocol signing notification and signatory identity verification

During the existence of ESOP account

Report management

Name, employee number, Futubull account, email, mobile number, ID number (resident ID number or passport number)

Used for incentive data statistics and holdings statistics

During the existence of ESOP account

Description of Information Sharing with Third Parties

For the purposes of user verification, mobile device security, receiving information pushes, account verification and login, and information security, the ESOP platform may share information with third parties in the course of providing services to you. We have listed below the names of these third-party service providers, the purposes, links to their websites, and privacy policies.

1. SDK

None.

2. Non-SDK

No.

Name

Info Type

Purpose

Receiver

Link

Platform

1

Docusign

User identification information, including name and ID number; contract information

Using the online signatures of Docusign to generate a unique digital certificate for the client and to use it for online agreement signing; generating electronic agreements

Hangzhou BestSign Network Technology Co.,Ltd.

Website: https://www.bestsign.cn/

Privacy Policy: https://ent.bestsign.cn/account-center/legal-agreement/privacy-policy

web

2

Tencent Cloud

User identification information, including name and ID number

Use two-factor authentication and face ID service from Tencent Cloud to verify domestic clients' identities and ensure the validity of agreement signing

Shenzhen Tencent Computer Systems Company Limited

Website: https://cloud.tencent.com/

Privacy Policy: https://cloud.tencent.com/document/product/301/11470

web