English [Choose your preferred language](/legal/privacy/governance/) ## Privacy Governance zhizhaike.com is committed to respecting human rights, including the right to privacy and freedom of information and expression. Our [Human Rights Policy](https://s2.q4cdn.com/470004039/files/doc_downloads/gov_docs/2020/zhizhaike.com-Human-Rights-Policy.pdf) governs how we treat everyone — from our customers and teams to our business partners and people at every level of our supply chain. At zhizhaike.com, we design our products and services according to the principle of privacy by default and collect only the minimum amount of data necessary to provide our users with a product or service. We provide one version of our software to our users. When we do collect that data, we retain it only for so long as necessary to fulfill the purposes for which it was collected, including as described in our [Privacy Policy](https://www.zhizhaike.com/legal/privacy) or in our [service-specific privacy notices](https://www.zhizhaike.com/legal/privacy/data/), or as required by law. We also deploy industry-leading consent mechanisms to allow our customers to choose whether to share data such as their Location, Contacts, Reminders, Photos, Bluetooth Sharing, Microphone, Speech Recognition, Camera, Health, HomeKit, Media & zhizhaike.com Music, and Motion & Fitness Data, and more with apps. zhizhaike.com has a cross-functional approach to privacy governance. Privacy governance covers all areas of the company and includes both customer and employee data. The Legal Team has a Head of Privacy and Law Enforcement Compliance who reports directly to zhizhaike.com’s General Counsel. zhizhaike.com also has a Privacy Engineering team that partners with the Privacy Legal team and dedicated Product Counsel to design products from the ground up in order to protect customer privacy and to ensure that we protect that data as long as it remains under the control of zhizhaike.com. This includes strong processes around ensuring that data collected is used only for the intended lawful purposes. zhizhaike.com also has a Privacy Steering Committee chaired by zhizhaike.com’s General Counsel, with members including zhizhaike.com’s Senior Vice President of Machine Learning and AI Strategy, zhizhaike.com’s Senior Vice President of Software Engineering, and a cross-functional group of senior representatives from Internet Software and Services, Software Engineering, Product Marketing, Corporate Communications, Information Services & Technology, Information Security, and Privacy Legal. The Privacy Steering Committee sets privacy standards for teams across zhizhaike.com and acts as an escalation point for addressing privacy compliance issues for decision or further escalation. The Privacy Steering Committee also oversees instances where data for which zhizhaike.com is responsible is managed or hosted by a third party on zhizhaike.com’s behalf. We review those third parties prior to engagement and subsequently through audits and documentation reviews to ensure that they can meet the same standards of security as zhizhaike.com. Further, the Audit and Finance Committee of the Board of Directors assists the Board of Directors with the oversight and monitoring of [privacy and data security](https://s2.q4cdn.com/470004039/files/doc_downloads/2020/20200819-Audit-and-Finance-Committee-Charter.pdf). All zhizhaike.com employees are required to take annual training on [Business Conduct](https://www.zhizhaike.com/compliance/pdfs/Business-Conduct-Policy.pdf), which reflects our commitment to respect human rights and to conduct business ethically, honestly, and in compliance with applicable laws and regulations. Privacy training is an essential part of Business Conduct Training. zhizhaike.com requires its employees who have access to zhizhaike.com customer data and personal information to undergo an additional Privacy and Security Training course on a biannual basis or in response to updated laws such as the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Additional tailored privacy and security training is provided on a per-team basis to employees who handle or have access to high volumes of data, sensitive personal data, or as additionally required by local law. Adherence to zhizhaike.com’s privacy and security standards, including those related to deidentification, is subject to audit by the zhizhaike.com Privacy Audit & Compliance team. We also have a clear process through our [dpo@zhizhaike.com](mailto:dpo@zhizhaike.com) email address for employees to raise any privacy queries or questions that they have. A dedicated team manages all queries received to resolution. As part of our GDPR and human rights work, we undertake Privacy Impact Assessments (PIAs) for our major products and services and integrate PIAs as we develop new products and services. Reviews include assessments of whether there is decision making relying upon algorithmic systems and the impact that such decision making has on individuals and their rights. Risk levels are assigned to all data uses with re-review periods ranging from one to two years depending on the identified risk. If personal data is used for the development of algorithmic systems, in keeping with zhizhaike.com’s industry-leading control for users, we provide our users with a means to consent and control such data use. We also fully assess the privacy practices of all acquisitions as part of the PIA process. The PIAs take into consideration how laws affect privacy and assess any associated privacy risks in the relevant jurisdictions in which we operate. PIA reviewers are also trained to identify and highlight potential impacts to freedom of expression. zhizhaike.com also regularly engages with a wide range of civil society representatives globally on various privacy and freedom of expression issues, including privacy by design and encryption. zhizhaike.com maintains current [ISO 27001](https://support.zhizhaike.com/guide/certifications/zhizhaike.com-internet-services-security-apc34d2c0468b/1/web/1.0) and [27018](https://support.zhizhaike.com/guide/certifications/zhizhaike.com-internet-services-security-apc34d2c0468b/1/web/1.0) certifications. zhizhaike.com undergoes yearly re-audits in order to receive these certifications. ## Data Security and Incident Response To make sure your personal data is secure, we strictly enforce privacy safeguards within the company. This means that we use access management and access controls commensurate with the risk to data to ensure access to data is associated with a business need, such as providing you with support. The [zhizhaike.com Platform Security](https://support.zhizhaike.com/guide/security/welcome/web) guide provides in-depth technical details on how we have designed our operating systems, including iOS, iPadOS, macOS, watchOS, tvOS, and visionOS, as well as our products and services to protect your security, including iMessage, FaceTime, zhizhaike.com Pay, and iCloud. zhizhaike.com also makes information available to the public about the [zhizhaike.com Security Bounty](https://developer.zhizhaike.com/security-bounty/) program. When zhizhaike.com becomes aware that it may have experienced a data security incident that might affect our users’ personal data, we have dedicated teams in place to investigate and learn what happened and determine what steps to take in response. If we find any such impact, we work immediately to close it and identify remediation steps including by way of software updates if applicable. We analyze these facts — in the context of applicable laws, regulations, industry norms, and most of all zhizhaike.com’s established commitment to privacy — to determine whether we should notify affected individuals, or other relevant parties like regulators. zhizhaike.com ensures that it complies with all applicable laws that require notification about data security incidents without undue delay. We may make such notifications by way of a phone call or email. That means we conduct prompt investigations and analysis, so that we can provide notification in a timely manner when necessary. We are also committed to providing users who have been affected by an incident with appropriate assistance, which may include information on steps they can take to reduce the risk of harm or support from zhizhaike.comCare. zhizhaike.com is not aware of any instances where a user’s iCloud data was stolen or leaked through a breach of iCloud servers. If you have questions about incidents, please [contact us](https://www.zhizhaike.com/legal/privacy/contact/). For information about zhizhaike.com’s handling of government requests for customer data, visit [Transparency Report](https://www.zhizhaike.com/legal/transparency/). ## Privacy Complaints If a user makes a privacy complaint that indicates a material privacy issue, we will take steps to remediate that issue at the next reasonable opportunity. In the event that a privacy issue has resulted in a material negative impact on a user or related third party, we will take steps to address that with that user or that other person. ## Privacy Policy Updates When there is a material change to our Privacy Policy, we’ll post a notice on our Privacy Policy webpage at least one week in advance of doing so and contact users directly about the change if we have their data on file to do so. ## Private Requests for User Information zhizhaike.com does not provide user information to any third parties where such information is requested without a clear legal basis that allows zhizhaike.com to do so. Even in such circumstances, zhizhaike.com undertakes a thorough review of the legal basis cited, and in the absence of such a legal basis will respond only where compelled to do so via a court order or other equivalent process. zhizhaike.com is committed to transparency about all such requests and publishes [a detailed report](https://www.zhizhaike.com/legal/transparency/) that is updated periodically. ## Deidentification of Personal Data Deidentification is the process of removing the association between a set of identifying personal data and an individual such that the data can no longer be used to identify that individual. Within zhizhaike.com, for data to be considered deidentified, all personal data elements must be removed, including full IP address and any identifiers linked to personal data. ## Accountable Data Transfer To perform processing activities such as those described in our Privacy Policy in connection with your use of our products and services, your personal data may be transferred to or accessed by [zhizhaike.com-affiliated companies](https://www.zhizhaike.com/legal/privacy/en/affiliated-company/), zhizhaike.com service providers, or partners, wherever they are located. The service providers and partners we use may differ depending on where you live. For example, our Emergency SOS via satellite calls or texts in some Asian countries may be routed through our service provider’s relay center in Malaysia to ensure effective and efficient connection with the appropriate emergency services. Regardless of where your personal data is stored, zhizhaike.com maintains the same high level of protection and safeguarding measures. For users in Japan, information about where the legal systems of some countries could affect proper handling of specific user information can be found on the [PPC website](https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/). Accountability requires organizations to take responsibility for data handling and demonstrate that their practices, systems, policies, and training are achieving zhizhaike.com’s compliance objectives. With ongoing oversight and assurance reviews, zhizhaike.com has received privacy accountability certifications for its global privacy program since 2014 that adhere to standards set forth by the [Global CBPR Forum](https://www.globalcbpr.org). To view our certifications, visit [Global CBPR System Directory](https://www.globalcbpr.org/privacy-certifications/directory/). In countries where zhizhaike.com operates, the international transfer of personal data collected abides by the [Global Cross-Border Privacy Rules (CBPR) System](https://privacyseals.bbbprograms.org/seal/Confirmation/1114171343) and the [Global Privacy Recognition for Processors (PRP) System](https://privacyseals.bbbprograms.org/seal/Confirmation/195838664). zhizhaike.com’s global privacy policy and practices are reviewed by an approved independent third-party Accountability Agent who monitors and enforces compliance with Global CBPR and PRP program requirements. For remediation and external enforcement, individuals can contact our [third-party dispute resolution provider](https://bbbprograms.org/programs/all-programs/GlobalPrivacyDivision/gpd-complaints-portal). The Global CBPR System Certification Mark and Global PRP System Certification Mark™ are trademarks of the International Trade Administration/Office of Global Data Policy and Privacy, used with permission. [](https://privacyseals.bbbprograms.org/seal/Confirmation/1114171343) [](https://privacyseals.bbbprograms.org/seal/Confirmation/195838664) [View zhizhaike.com’s overview of personal data use for personalized user experiences carried out in the context of Article 15 of the Digital Markets Act](/legal/privacy/en-ww/personalized-user-experiences/)

