!

Download|TopOn GLOBAL MOBILE NON-GAMING APP ADVERTISING MONETIZATION REPORT

Read>>

TopOn Advertising services privacy policy

Updated July 10, 2026


1. Introduction

The TopOn entities (for the purposes of applicable data protection laws, the TopOn entities that provide the TopOn Service and bear the applicable disclosure obligations are TOPON PTE. LTD. and Ascent Pro Technology Limited, referred to as “TopOn”, “we”, “us” or “our”) provide this Privacy Policy to explain how we collect, use and share personal data. This Policy applies to the following two categories of data subjects:

a) if you are a U.S. citizen or an entity duly organized under the laws of the United States, the TopOn entity that processes your personal data is Ascent Pro Technology Limited; and

b) if you do not fall within the circumstances described in (a) above, the TopOn entity that processes your personal data is TOPON PTE. LTD.

In this Policy, unless otherwise specified, Ascent Pro Technology Limited and TOPON PTE. LTD. are collectively referred to as “TopOn”.

 

This Policy covers TopOn’s processing of the following two categories of personal data:

(1) Personal data we receive when we provide our service, including (i) device personal data about end users we collect through our software development kit (“SDK”), application programming interface (“API”), our platforms, services or technologies from traffic supply partners such as mobile app developer, ad exchange platform, supply-side platform, mediation platform; (ii) personal data about end users’ interaction with ads collect through our SDK, API or other technologies, or collected and transferred to us by our Business Partners (e.g. mobile app developers, advertisers, hereinafter referred to as “Business Partners”) or any third party designated by them; (iii) device personal data generated during end users’ use of our Business Partners’ mobile apps, websites, platforms or services and personal data collected and transferred to us by our Business Partners or any third party designated by them; (iv) personal data provided by Business Partners when they use TopOn’s platforms, technologies, services. In the Privacy Policy of the TopOn Services, the end users mentioned in this section are collectively referred to as “User”, “you” or “your”; the SDK, API, any technology, platform or service provided by TopOn mentioned in this section are referred to as “TopOn Service”.

(2) Personal data we receive through the following websites from website visitors (hereinafter referred to as “Visitors”, “you” or “your”) in the Privacy Policy of TopOn Website: (i) our website at: www.toponad.net or any other website on which this Policy is posted, as well as (ii) any website we provide to Business Partners or potential clients in order to provide our services.

This Policy is subject to any service agreement between TopOn and you. By using the TopOn Service or TopOn Site, you acknowledge that you have read, understood and agreed to this Policy. Please review this Policy before using the TopOn Service or the TopOn Site.

We evaluate this Policy and procedures to implement improvements and refinements from time to time. If this Privacy Policy is significantly modified, we will publish an announcement on the TopOn website before the new Privacy Policy takes effect.

Data protection and maintaining the trust of our Business Partners and you is at the core of TopOn’s business principles. Accordingly, compliance with applicable data protection laws is our top priority, and this Policy has been updated to comply with the requirements of applicable laws and regulations relating to the protection of personal data, including the EU General Data Protection Regulation (“GDPR”), the U.S. Children’s Online Privacy Protection Act (“COPPA”), the California Consumer Privacy Act (“CCPA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Utah Consumer Privacy Act (“UCPA”), the Connecticut Data Privacy Act (“CDPA”), and the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais) (“LGPD”). Where our cooperation with you is subject to European data protection laws, TopOn is the controller of your personal data under such laws.

For the purposes of this Policy, “Processor” means a “processor” under the GDPR, VCDPA, CPA, CDPA and UCPA, and a “service provider” under the CCPA; and “Controller” means a “controller” under the GDPR, VCDPA, CPA, CDPA and UCPA, and a “business” under the CCPA.

 

2. How and why we collect user personal data

This Privacy Policy describes TopOn’s personal data collection and personal data use behavior in the following scenarios:

Based on the nature of the user's use of TopOn services or services provided by any of TopOn's business partners, we may directly or through our business partners (such as: mobile application developers, programmatic advertising exchanges, advertising aggregation platforms, advertising demand parties Platform, traffic provider platform) collects personal data. For example:

(1) When we provide traffic monetization services and mobile advertising aggregation tools for mobile application developers, the mobile application developers will embed our SDK in their mobile applications, and we will obtain user personal data through the SDK;

(2) When we cooperate with a programmatic advertising exchange platform or a traffic supplier platform, and the programmatic advertising exchange platform or traffic supplier platform sends advertising needs to our demand-side platform, it may share user personal data with us;

(3) Our advertisers, advertising demand-side platforms, programmatic advertising exchange platforms or the third-party attribution platforms they use will share user personal data with us;

In the process of providing TopOn services, we do not establish direct contact with users. We will obtain the relevant consent for the collection and use of users’ personal data through TopOn’s business partners (such as mobile application developers using TopOn’s SDK, programmatic advertising exchange platforms, advertising aggregation platforms, advertising demand-side platforms, traffic supply-side platforms, etc.). In our cooperation agreement with TopOn's business partners, we have required them to promise and guarantee the legality of the data sources, and they will inform users of the specific circumstances of our processing of personal data in accordance with the requirements of applicable laws, and obtain valid consent from users where required by applicable law and ensure that users can revoke such consent at any time.

TopOn services may link to third-party websites, applications or other third-party content. Please note that we have no control over the processing of user personal data by third parties, and third parties may have privacy protection regulations that are different from those described in this privacy policy.

When we collect personal data such as name and email address of partners’ business representatives, our purpose is to conduct business communications with them, including necessary communications to perform the contract between us and the partner.

 

3. Personal data we may collect

When you browse advertisements using TopOn services or use services provided by TopOn's business partners, we and/or our business partners may collect your personal data. App developers may choose to share the personal data they collect with us through our SDK. To learn more about how the application developer collects, uses, and shares your personal data and whether you agree to the developer's use of your relevant personal data, please check the privacy policy of the relevant application developer. Please note that through our cooperation agreements with our partners, we will require them to obtain your consent in advance regarding the personal data that may be collected and shared about you during the service process before using our services.

(1) The data we collect through our SDK may include the following types

Data type

Field

Location information

[Required information] IP address

Device/Advertising ID

[Required information]

Android: GAID

iOS only: IDFV

[Optional information]

IOS: IDFA

Note: If you restrict your device or application from obtaining your device/advertising ID in accordance with Article 7 of this policy, we will not collect the corresponding information;

Device information

[Required information] Device manufacturer, device model, device operating system information (version name, version number), device type, device language, device screen information (orientation, resolution), device network type, hardware serial number, device sensor information (accelerometer, gyroscope sensor, etc.), Limit Ad Tracking (LAT) status, phone boot time, phone user name summary, device storage capacity information, SIM card information (mcc & mnc)

[Optional information]

CPU type, device battery power information, device volume and font size, whether it is an emulator, whether it is USB connection, whether it is developer mode, system build type, system build label, system build user, radio firmware version, system boot program version number, hardware name, host address, system development code, system source control version number, device display version number, device substrate name

Application information

[Required information] TopOn partner application package name, application version number and features, SDK version

[Optional information]

Whether it is downloaded from the app store, list of installed applications;

Usage Data

[Required Information] When you interact with an advertisement promoted by us, we will collect information about your interaction with the advertisement, such as browsing and clicking on the advertisement.

Other information

[Required Information] Device event information (such as system crashes, system activity), timestamp, date and time of your request and source URL, user agent and TCF string.

Note: The TCF string is a machine-readable string defined by IAB Europe that encodes your consent choices regarding our processing of personal information. For more information about the TCF string, please visit the IAB Europe website. To avoid any doubt, we collect your TCF string information only when you are located in the European Economic Area (EEA).

TopOn participates in the IAB Europe Transparency and Consent Framework and complies with its specifications and policies. Within this framework, TopOn’s vendor ID is 1305.

 

Access Request

Special note: If you use a developer application that integrates TopOn SDK, TopOn SDK will apply for the corresponding permissions through the developer application. The developer should inform you of the TopOn SDK, subject name, type and purpose of processing personal information, privacy policy, etc., and obtain your consent before using the TopOn SDK to carry out relevant business functions. Since there may be some differences in the information fields collected by different SDK versions and whether they are optional, the specific collection situation is subject to the SDK version connected to the developer application you are actually using. Developers must ensure that users agree to the Privacy Policy before initializing the TopOn SDK. TopOn SDK users will only collect information and apply for permissions after agreeing to the "Privacy Policy".

 

For Android system

Items

Function

Purpose

Timing

INTERNET 

[Optional] Mobile network

For online advertising service requests

Developers apply for this permission when they call SDK functions that require it. For example, developers apply for this permission when they need to adjust advertising monetization strategies and data analysis services based on mobile network conditions.

ACCESS_NETWORK_STATE

[Required] Check network connectivity status

Determine the type of network connection (Wi-Fi / mobile network)

This permission is requested when the developer calls SDK functions that require it. For example, if the developer needs to adjust ad delivery strategies and data analytics services based on the mobile network status, this permission will be required.

ACCESS_WIFI_STATE

[Required] Check Wi-Fi connection status

Determine the network environment

This permission is requested when the developer calls SDK functions that require it. For example, if the developer needs to adjust ad delivery strategies and data analytics services based on the mobile network status, this permission will be required.

com.google.android.gms.permission.AD_ID

[Required] Obtain the Google Advertising ID (GAID)

Used for ad targeting and attribution

This permission is requested when the developer calls SDK functions that require it. For example, if the developer needs to adjust ad delivery strategies and data analytics services based on the mobile network status, this permission will be required.

 

 For IOS system

Item

Function

Purpose

Timing

NSUserTrackingUsageDescription

[Optional] Obtain the device ID to identify device information

Advertising and anti-fraud

Developers call this permission when they call SDK functions that require this permission. Developers apply for this permission when they need to adjust advertising monetization strategies and data analysis services based on device information.

 

(2) When you browse and click on the advertisements we promote, and then download and use the products (such as applications) promoted by the advertisements, we will collect the information from the advertisers, demand side platform, programmatic advertising exchange platforms or other The following information is collected from the third-party attribution platform used:

Data type

Field

Location information

[Required information] IP address

[Optional information] Country, city;

Device/Advertising ID

[Required Information] IMEI, OAID, IDFV, mobile advertising identifier (such as Apple IDFA, Google Advertising ID and Amazon ID), MAC address;

Device information

[Required information] Device manufacturer, device model, device operating system information, device language, device type, device network information, device operator;

Application information

[Optional information] TopOn partner’s application package name and application version;

Usage data

[Required information] The timestamp of the installation event or other events;

Other information

[Optional information] User agent;

 

(3) When TopOn serves as an advertising demand-side platform ("DSP"), programmatic advertising trading platforms and traffic supply-side platforms may transmit personal information to us through API and other technologies, which may include:

Data type

Field

Location information

[Required information] IP address

[Optional information] Country, time zone and regional settings (country and preferred language);

Device/Advertising ID

[Required Information] International Mobile Equipment Identity (IMEI), Android ID, OAID, IDFV, mobile advertising identifier (such as Apple IDFA, Google Advertising ID and Amazon ID), MAC address;

Device information

[Required information] Device screen information, device manufacturer, device model, device operating system information, device type, device network information, limited advertising tracking (LAT) status;

Application information

[Required information] TopOn partner’s application package name, application version and features;

Usage Data

[Required Information] When you interact with the advertisements we promote, we will collect information about your interaction with the advertisements we promote, such as information about browsing and clicking on the advertisements;

Other information

[Optional information] Information transmitted by other advertising information exchange platforms or media platforms, user agents.

 

(4) As we provide TopOn Service for our Business Partners, we may collect name, job title, email address, contact address and the account name and password used to access TopOn websites, IP address of the individuals using TopOn services on behalf of such Business Partners.

We will cooperate with programmatic advertising exchange platforms, advertising demand-side platforms, traffic supply-side platforms and other partners with good reputations. After the advertising data exchange platform or the media platform receives an advertising request with your personal data, and where permitted by law, the personal data will be transferred to TopOn, and advertising is then served to you on the Internet.

Legal exemption from consent to process personal data

In accordance with the requirements of applicable laws, we have contractually agreed that our business partners (such as mobile application developers and advertisers who use TopOn's SDK, etc.) will obtain consent from users or their employees on our behalf regarding the processing described in this Privacy Policy. Users or their employees may revoke consent at any time. At the same time, please understand that in the following situations, in accordance with laws and regulations, we do not need to obtain your consent to process your personal data:

(1) Necessary to enter into or perform a contract at your request;

(2) Necessary to perform statutory duties or obligations, such as those directly related to national security, national defense security, criminal investigation, prosecution, trial and judgment execution, etc.;

(3) In order to respond to public health emergencies, or necessary to protect the life, health and property safety of natural persons in emergency situations;

(4) Implement news reporting, public opinion supervision and other activities for the public interest, and process personal data within a reasonable scope;

(5) Process the personal data you disclose on your own within a reasonable scope, or other personal data that has been legally disclosed (such as personal data legally disclosed through legal news reports, government data disclosure and other channels);

(6) Other situations stipulated by laws and regulations.

Special note: According to legal provisions, if the data cannot identify a specific individual alone or in combination with other data, it does not belong to personal data. When your data can identify you alone or in combination with other data, or when we combine data that is not associated with any specific individual with your personal data, we will treat it as your personal data in accordance with this Privacy Policy Process and protect.

If you are located in the European Economic Area, where necessary, we will use your personal data based on "legitimate interests" specified in the GDPR. Our legitimate interests include the following: monitoring and preventing fraud, eliminating technical obstacles to system operation, and ensuring the correct and safe operation of systems and processes.

 

ABOUT SENSITIVE PERSONAL DATA

Sensitive personal data means personal data that, if leaked or unlawfully used, could easily infringe upon the dignity of a natural person or endanger personal or property safety. The scope of sensitive personal data may vary depending on the applicable data protection laws.

We do not collect your sensitive personal data. Our Business Partners will transfer to us, or authorize us to process, your sensitive personal data only after notifying you of the necessity of processing such sensitive personal data and the impact on your rights and interests, and obtaining your explicit consent where required by applicable law.

 

4. How we use users’ personal data

We use your personal data in the following manner:

Type of personal data

Usage

Including all types of personal data described in paragraphs (1) to (3) of Article 3 of this Policy

Basic business functions: Your device might be distinguished from other devices based on information it automatically send. We use your personal data to display ads on your device through automatic decision making process. Ads may be shown to you based on information we legally collected such as the content you’re viewing, the app you’re using, your approximate location, your device type and your device status.  Where required by applicable law, we will obtain your explicit consent before conducting automated decision-making or profiling that produces legal or similarly significant effects concerning you.

Extended Business Functions: Your device information will be used to collect information about the cause of application crashes for later crash problem solving.

Including all types of personal data described in paragraphs(4)of Article 3 of this Policy

We may collect and use personal data of Users who are representing our Business Partners to use TopOn Service (e.g. employees of publishers or advertisers) for purpose of business contact and direct marking (e.g. sending marketing emails).

Sensitive personal data

We will not collect your sensitive personal data without your explicit consent. Our Business Partners will transmit or authorize us to process your sensitive personal data after notifying you the necessity of processing your sensitive personal data and the impact of your rights and interests with your explicit consent. 

 

5. How we share and disclose users’ personal data

Subject to applicable legal requirements, we may share personal data with third parties based on the following purposes and scenarios:

(1) Share

When we purchase advertising traffic from mobile application developers to provide them with monetization services, or when we act as a programmatic advertising trading platform or traffic supplier platform, we may, in order to fulfill our contractual obligations to business partners, provide services to such business partners, including reporting to them on the performance and effectiveness of the ads that users interact with, including statistics on traffic quality, and sharing users' personal data with our business partners for anti-fraud purposes. The personal data we share is limited to personal data related to advertising performance and effectiveness, such as device information, clicks, impressions, installations or activations. These business partners may use such users’ personal data to count users’ interactions with advertisements/websites, evaluate the performance and effectiveness of advertisements that users watch or interact with, identify areas of interest to users, and better understand the traffic usage or user behavior of websites and applications to improve their services. Our business partners’ use of the information disclosed by us is governed by their own privacy policies.

We may also use third-party technical service providers (such as cloud service providers) to process personal data in order to ensure the correct and appropriate operation of systems and processes and to store data.

In accordance with applicable personal data protection laws, we will not share users' personal data with third parties other than TopOn affiliated companies unless authorized by the user or otherwise permitted or required by applicable law. This restriction does not apply to information that has been anonymized in a manner that prevents the identification of any specific individual and cannot be restored. Users can request information about the names, contact information, and other information of our business partners and third-party technical service providers at privacy@toponad.net.

We may also share aggregated or anonymized information with other third parties in accordance with the terms of this Privacy Policy.

Type of Third Parties

Type of Information

Processing Purpose and Processing Method

Advertisers, advertising agencies, advertising attribution service providers, advertising demand-side platforms, TopOn affiliates

①Location Information: IP, Country, Time Zone and Locale Setting (include country information and preferred language).

②Device ID/ Avertising ID: Android ID, OAID, IDFV, IDFAGAIDAmazon ID. We will not collect such information if you restrict your device or the app from acquiring device ID or advertising ID according to Article 7 of this Policy.

③ Device Information: device make, device model, information of operating system, device type, information of screen, information of battery, device volume and font size, whether the it is an emulator, information of network, information of hardware, information of device sensor, Limited Ad Tracking (LAT) status, system boot time, device user name, information of storage capacity;

④Application Information: package name of the app of TopOn’s Business Partners, whether it is downloaded from App Store, version and characteristic of the app used by you when you interact with TopOn’s Service, SDK version, list of installed apps;

⑤Interactive Information: when you view ads served by us or have other interaction with ads served by us, we may collect information about your interaction with such ads, for example, information that you have viewed or clicked an ad.

⑥Others: user-agent.

①for conducting advertising attribution and settlement with advertisers/advertising agencies. In relation to such processing activities of personal data, TopOn acts as a Processor under the GDPR on behalf of the advertisers/advertising agencies to process Users' personal data;

②for monitoring the quality of advertising delivery;

③ Place advertisements.

 

In particular, if a mobile application developer only chooses to use our mediation tool service but does not choose our programmatic advertising exchange service or does not sell its in-app advertising space to us, other advertising SDKs integrated in our SDK need to Obtain the consent of the mobile application developer and have the third-party advertising SDK collect relevant information. The list, name and personal information processing rules of the third-party advertising SDK are as follows:

Advertising platform abbreviation

Name of processing subject

subject Types and fields of personal information

Purpose and scenarios of use

Privacy policy link

Meta

Meta Platforms Inc. Meta Platforms Ireland Limited

The type of information we (here we refer to as Meta) collect and process depends on how you use our products. For example, the information we collect is different for a user who sells furniture on Marketplace and a user who posts a Reels short video on Instagram. Even if you don't have an account, we will collect some information about you whenever you use our products. The information we collect is as follows:

Your updates and the information you provide

Friends, fans and other contacts

App, browser and device information

Information from partners, suppliers and other third parties

Subject to the policy in Meta Privacy Policy

https://www.facebook.com/privacy/policy

Pangle

Bytedance Pte. Ltd.,

The types of personal data processed by us (here we refer to Pangle) depend on the circumstances of collection and the nature of the services requested or transactions entered into for our partners.

2 When you interact with partner sites, we process certain information about you and your device. This information may be automatically collected from your device using our software code (called a "Software Development Kit" or "SDK") or shared with us by other advertising exchanges (such as Google DoubleClick). We also use cookies (text files inserted into your browser when you visit our partners or clients’ mobile apps and websites) and other tracking technologies that are available on your device.

.3 The information we process about you may include some or all of the following categories:

 

A. Information automatically obtained from your device

 

I. Identifiers: We may process device-specific identifiers, such as your IP address, a mobile advertising identifier (such as the "Google Advertising ID" on Android phones or the "Advertiser ID" on iOS devices) or our Pangle specific identifier. The SDK is assigned to your device. The Mobile Advertising Identifier is an identifier provided by your device's operating system that allows companies like Pangle to identify your device across applications for advertising purposes. In addition to the mobile advertising identifier and other similar technologies, Pangle may obtain your device model, operating system (such as iOS or Android), your device's language setting, general geographic area, time zone, network type (such as 5G or WiFi) , your ROM version, screen resolution (to learn which ads work best for your device), mobile country code and mobile network code, and when your device was last updated and launched.

 

2. Geolocation data: We may infer your approximate geographical location based on the IP address of your device. With your consent or permission under applicable data protection laws, we may also use GPS data from your phone to process your precise latitude and longitude.

 

3. Internet activity: We may process information about your application and website usage, including the name and version of the application or website that integrates Pangle. We may also process information about your interaction with any advertising we serve (for example, information about the ad served, viewed or clicked on, such as the type of ad, where and when the ad was served, whether you clicked on it and whether you visited the advertiser's website or download of the advertiser's application, as well as any preferences you may express regarding that advertising).

 

b. Information obtained from other sources

 

I. From time to time we may receive information about you from other sources. For example, we may receive information about you from third parties (such as advertising exchanges that share data with us to serve ads) if the law permits the third party to disclose this information to us.

 

2. The information we receive from these sources may include identifiers (such as your IP address or mobile advertising identifiers), information about your Internet activities (such as information about your interactions with third-party websites, applications and advertisements) ) and inferences related to your preferences and information. Characteristics (such as your approximate age and gender).

Subject to the policy in Pangle Privacy Policy

https://www.pangleglobal.com/zh/privacy/enduser-en

Admob & Ad manager

 Google LLC and its affiliates

We (herein we refer to Google) collect information about the apps, browsers and devices you use to access Google services to provide useful features such as automatic product updates, dimming the screen when the battery is low, and more.

The information we collect includes unique identifiers, browser type and settings, device type and settings, operating system, mobile network information (including carrier name and phone number), and application version numbers. We also collect information about how your apps, browsers, and devices interact with Google services, including IP addresses, crash reports, system activity, and the date, time, and referrer of the corresponding request.

We collect this information when Google services on your device communicate with our servers (for example, when you install an app from the Play Store or when the service checks for automatic updates). If you are using an Android device with Google apps installed, your device periodically communicates with Google servers to provide information about your device and its connection to Google services. This information includes your device type and carrier name, crash reports, your installed apps, and other information about how you use your Android device (depending on your device settings).

Subject to the policy in Admob Privacy Policy

https://policies.google.com/privacy

Appnext

Appnext PTE. Ltd,

Device and app information – this category includes your device’s type and model, system language, the device’s operating system (such as Android or iOS), SDK version, mobile carrier name, mobile browsers installed on the device (such as Chrome or Safari), app history and usage information (such as information about running and installed apps on the device), information regarding downloads and installations of mobile applications and any information regarding in-app events (such as in-app purchases), your device’s IP address, and identifiers assigned to your device, such as its iOS Identifier for Advertising (IDFA), Android Advertising ID, or other types of unique device identifiers (a number uniquely allocated to your device by your device manufacturer).

Ad information – this category includes information about the online ads and personalized content we have served (or attempted to serve) to you. It includes things like how many times an ad has been served to you, what page the ad appeared on, whether you viewed, clicked on or otherwise interacted with the ad, ad engagement history and whether you visited the Advertiser’s website, downloaded an app or purchased the product or service advertised.

Location information – Appnext collects information about your general location (such as city and country). For example, we may use the IP address to identify your general location. This information does not tell us where your device is precisely located. This information is sent as a normal part of internet traffic. In addition, we also collect implicit location information, which allows us to infer that you are either interested in a place or that you might be at the place – this information does not actually tell us where your device is precisely located.

In addition, Appnext may collect the precise location of your device (using GPS signals, device sensors, Wi-Fi access points, Bluetooth signals, Beacons signals and cell tower ids that can be used to derive or estimate precise location, or other geo-location data), when location services have been enabled by the end user for the mobile app or website that uses our SDK (you typically have to choose to turn on device-based location services).

Log information – this category includes the app or website visited, session start/stop time, time zone, and network connection type (e.g., WiFi, cellular), and cookie information.

Information from advertising partners (“Advertisers”) and other third parties – this category includes information we receive from our Publishers, Advertisers and other Partners that we work with to help us deliver ads and personalized content to you and recognize you across browsers and devices. This may include pseudonymous advertiser identifiers that some Advertisers or other third party ad platforms choose to share with us. This information is also used to enhance data points about a particular unique browser or device.

Subject to the policy in Google’s Privacy Policy

https://www.appnext.com/privacy-policy-oem-operators/

Inmobi

InMobi Pte. Ltd.

When you view an advertisement distributed through InMobi on a site, app or other digital media, we may collect information on your device and your interaction with the advertisement. This information enables us to serve advertisements to you, improve our Services including to recognize your device when you use other sites and applications that have partnered with us. InMobi may also collect information about you when you elect to interact with our surveys or opinion-based applications. Information we may collect includes:

(a) Device identifiers. Device identifiers are alphanumeric strings that are unique to your device. These include:

iOS devices’ Identifier for Advertising (IDFA) and iOS Identifier for Vendors (IDFV)

Google Advertising ID (GAID), or Android ID for Android devices

Identifier for Advertising on OTT and CTV platforms

International mobile equipment identity (IMEI), in certain jurisdiction as permitted by applicable law

Cookie IDs

(b) Location information, including:

Geo-location or precise location of your device if you have given the app or site permission to collect your location information

Location information we infer based on data collected through a WiFi identifier that your device is connected to, in accordance with applicable law and provided location access is permitted

Location information we infer from your device’s IP address, provided that we will not infer location from an IP address to a more precise than city-level of accuracy unless you have given the app or site permission to collect your location information

(c) Network information, including:

Mobile carrier

Network provider or ISP

Network type (e.g., WiFi or cellular)

IP address

IDs of WiFi access points to which your device is connected

Date and time of connection

(d) Information about apps or sites and our Software Development Kit (SDK), including:

App or site name or version

App identifier

SDK version

API key identifier

Other information about/on your device, including:

Device type (e.g., make and model)

Device startup time and update time

Device name

Screen size

Memory and hard drive capacity

Operating system and version (e.g., iOS 14, Android, Windows, Blackberry)

Mobile browser used (e.g., Chrome, Safari, Firefox)

Language settings (including country code) and time zone

App usage

Device sensor signals (Accelerometer, Gyroscope, Proximity sensor, Orientation/Rotation Vector, Audio Controls Integration)

Advertisement information. We collect information about the ad presented on your device, including:

The content type of the ad (the advertiser and category, e.g. games, finance, entertainment, news)

The ad type (e.g. whether the ad is a text, image, video or other format based)

Where the ad is being served (e.g. the site, digital media or app on which the ad appears)

Whether you viewed, clicked or otherwise interacted with the ad

Survey information. We may ask users to voluntarily participate in online surveys. These surveys help brands improve their products and services offered to you. If you fill out a survey, we may collect your device information described above and information you provide, including your:

Age

Name

Email address

Phone number

Gender

Occupation and income range

Family size and other demographic information

Preference for brands, modes of travel, and other consumer choices.

Inmobi's privacy policy shall prevail.

https://inmobi.cn/privacy-policy

Start.io

Start.io Inc.

Online identifiers: advertising identifiers (the IDFA and/or IDFV on iOS devices, and the ADID on Android devices (the “ADID”)).

Internet Protocol (IP) address.

Please note that, although the ADID and IP address are treated as personally identifiable information in many jurisdictions (such as the European Economic Area, the EEA), in certain jurisdictions such data is not treated as personal data.

Location information.

If the SDK is installed, the name of the application and its category; if the SDK is not installed, the name of the application through which you interact with the Start.io network.

Gender and age (whether inferred by us or strictly provided to us by other data sources).

Query data, i.e. whether certain applications are installed on your mobile device (expressed in one-way hashed form).

Other general data: device attributes (operating system, OS version and device type), Bluetooth-paired devices, device sensors (such as the accelerometer), your carrier, internet service provider (ISP), network connection details and Wi-Fi data, roaming, local time zone and language settings.

The privacy policy of Start.io shall prevail.

https://www.start.io/policy/privacy-policy-site/

Except as expressly stated in this Policy, we will not disclose User’s personal data to any third party without User’s consent.

We have agreed with the partners who have direct access to the user that the partner will inform the user of the above-mentioned third party information and obtain the user's consent.

We may also share aggregate or anonymous information with other third parties in accordance with the terms of this Policy.

 

(2) Assignment

Where it becomes necessary to transfer a User’s personal data as a result of a merger, division, dissolution, declaration of bankruptcy, or transfer of assets or business, we will inform the User of the name and contact details of the recipient in accordance with the law, and will contractually require the recipient to continue to perform the obligations of a personal data controller or processor. Where the recipient changes the original purpose or method of processing, we will require the recipient to obtain the User’s consent again in accordance with the law, or to satisfy another lawful basis required under applicable law.

 

(3) Disclosure

We may disclose your data to third parties for legal, regulatory, judicial or administrative purposes. We will disclose your data only where we consider it necessary or appropriate to do so, for the following reasons:

(i) to comply with applicable privacy laws and regulations;

(ii) to respond to subpoenas, search warrants or other legal process;

(iii) in response to a request from a public authority or governmental body;

(iv) to enforce our terms and conditions;

(v) where we believe in good faith that such disclosure is necessary to protect the rights of us or our affiliates and subsidiaries; and

(vi) to establish or exercise our legal rights, or to defend against legal claims.

 

6. International Transfers

The primary locations at which we process your personal data are Singapore and the United States; however, we may also transfer data to all other countries in which TopOn and its affiliates, service providers and partners conduct business. All data transfers are carried out in accordance with applicable laws and regulations — for example, by entering into data transfer agreements — in order to safeguard the security of your data.

If you are located in the European Economic Area (“EEA”), the personal data we collect about you will be transferred to, or may be remotely accessed from, countries located outside the EEA, including the United States, Singapore or other countries that have not been recognized by the European Commission as providing an adequate level of protection for personal data. We will, however, provide appropriate safeguards for such personal data as required by applicable law. Where required by law, our Business Partners will obtain your consent to transfer your personal data outside the EEA, including to TopOn or other recipients as described in this Policy. You may withdraw your consent at any time.

If you are a U.S. person, we comply with applicable U.S. laws and regulations, including the U.S. Department of Justice Data Security Program (DSP), and will not unlawfully transfer, share or otherwise make available your personal data.

 

7. Your data rights

(1)If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another country or region whose applicable data protection laws grant you comparable rights, you may, to the extent permitted by applicable law, have one or more of the following data subject rights:

a. Right of access. You have the right to request access to the personal data we process relating to you and to obtain information about how we process such personal data.

b. Right to rectification. You have the right to request that we correct inaccurate or incomplete personal data.

c. Right to erasure. You have the right to request that we delete your personal data in the circumstances provided by applicable law.

d. Right to restriction of processing. You have the right to request that we restrict the processing of your personal data in the circumstances provided by applicable law.

e. Right to object. You have the right to object to our processing of your personal data in the circumstances provided by applicable law, including objecting to processing based on legitimate interests or processing for direct-marketing purposes.

f. Right to data portability. You have the right, in the circumstances provided by applicable law, to request that we provide you, or a third party of your choosing, with a copy of your personal data in a structured, commonly used and machine-readable format.

g. Right to withdraw consent. Where we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

h. Rights relating to automated decision-making. In the circumstances provided by applicable law, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, or to request that we provide human intervention, allow you to express your point of view, or contest the decision.

i. Right to lodge a complaint. You have the right to lodge a complaint regarding our processing of your personal data with the data protection supervisory authority in your location or having jurisdiction.

 

Priority of local law. Although we endeavour to provide users with a relatively complete set of data rights on a global basis, the specific rights available may vary depending on your jurisdiction. Where the rights described in this Policy are inconsistent with the mandatory provisions of the data protection laws applicable in your location, the mandatory provisions of the applicable law in your location shall prevail.

 

(2)Privacy Rights of U.S. Residents

If you are a U.S. resident, you may have one or more of the following privacy rights under applicable U.S. federal or state privacy laws, including but not limited to the rights provided under the privacy laws of California, Virginia, Colorado, Connecticut, Utah and other applicable states:

a. To confirm whether we are processing your personal information and to access that personal information.

b. To correct inaccuracies in your personal information.

c. To delete your personal information.

d. To obtain a copy of the personal information you have provided to us.

e. To opt out of our processing of your personal information for the purposes of: (i) targeted advertising or personalized advertising; (ii) the sale of your personal information; (iii) the sharing of your personal information; or (iv) profiling or analysis in furtherance of decisions that produce legal or similarly significant effects concerning you.

f. Right to opt out of sale or sharing. You have the right to opt out of the sale or sharing of your personal information.

g. Right to limit the use and disclosure of sensitive personal information. You have the right, to the extent provided by applicable law, to request that we limit the use and disclosure of your sensitive personal information, except for uses permitted by applicable law.

h. Right to non-discrimination. You have the right to exercise the rights granted to you under applicable privacy laws free from discrimination.

i. Right to appeal. If we decline your privacy rights request and the applicable state privacy law grants you a right to appeal, you may appeal in the manner provided in our response, or by sending an email to privacy@toponad.net.

 

If you are a resident of the State of California, you may also request that we disclose how we have collected, used, sold, shared or disclosed your personal information during the period prescribed by applicable law, which generally covers the preceding 12 months. Where permitted by applicable law, you may also request that we disclose such information for a period exceeding 12 months, provided that this right applies only to personal information collected by us on or after January 1, 2022 and still retained by us, and is subject to the exceptions provided by applicable law. The foregoing does not require us to retain personal information for longer in order to respond to such a request.

 

The information that California residents may request includes:

a. the categories of personal information we have collected;

b. the categories of sources from which the personal information was collected;

c. the business or commercial purpose for collecting or sharing personal information;

d. the categories of third parties to whom we disclose personal information;

e. the categories of personal information that we have sold, shared or disclosed for a business purpose;

f. the categories of third parties to whom the personal information was sold or shared, or disclosed for a business purpose; and

g. a copy of the personal information we have collected about you during the period prescribed by applicable law.

The rights described above are not exhaustive and do not limit any other privacy rights you may have under applicable U.S. federal or state law. If the laws of your state of residence grant you additional privacy rights not expressly set out in this section, this Policy does not limit or prevent you from exercising those rights in accordance with the law. We will comply with applicable U.S. state data privacy laws to protect your personal information.

 

(3)How to Exercise Your Rights

Regardless of which country or region you are located in, you may submit a data subject rights request to us by sending an email to privacy@toponad.net. This mailbox is also available for users in the EEA, the UK, the United States and other applicable regions to submit requests to access, correct, delete, restrict the processing of, object to the processing of, withdraw consent to, port or opt out of the processing of their personal information, or to exercise other privacy rights granted by applicable law.

If you wish to opt out of the sale or sharing of your personal information, you may also do so by sending “Do Not Sell or Share My Data” to our privacy mailbox, or by submitting the relevant online form on the TopOn official website.

If you wish to limit our use and disclosure of your sensitive personal information, or to opt out of our processing of your personal information for the purposes of targeted or personalized advertising, the sale or sharing of personal information, or profiling or analysis in furtherance of decisions that produce legal or similarly significant effects concerning you, you may submit a request to us by sending an email to privacy@toponad.net.

To the extent required by applicable law, we will also recognize and honour opt-out preferences expressed by users through browsers, device settings, platform permission settings or other applicable preference signals.

When you submit a request, we will verify your request in accordance with our internal procedures and on the basis of the information you provide (such as a device ID, company email or other necessary information). If you fail to provide the information necessary to verify your identity or to locate the relevant personal information, we may be unable to process your request, or may decline your request as permitted by law.

You may designate an authorized agent to submit an applicable privacy rights request on your behalf by providing the authorized agent with written permission to do so and by verifying your own identity with us directly as we may require. We will deny any request from an agent that does not submit valid proof of authorization.

 

(4)Our Timeframes for Responding to Requests

We will process your request without undue delay and respond to you within the period required by applicable law. Specifically:

a. If you are located in the EEA or the UK, we will generally respond within one month of receiving your request. For complex or multiple requests, where permitted by applicable law, we may extend the response period by up to a further two months, and will inform you of the extension and the reasons for it within one month of receiving the request.

b. If you are a U.S. resident, we will generally respond within 45 days of receiving a verifiable consumer request. For complex or multiple requests, where permitted by applicable law, we may extend the response period by a further 45 days, and will inform you of the extension and the reasons for it within the initial 45-day period.

c. If you are located in another country or region, we will respond to your request within the period prescribed by the applicable data protection laws of your location; where local law does not prescribe a specific period, we will generally respond within 30 days of receiving a verifiable request.

d. If we decline to act on your request as permitted by law, we will explain the reasons for the refusal within the period required by applicable law and, where required by applicable law, inform you of the appeal, complaint or other remedies available to you.

Unless otherwise provided by applicable law, we will generally respond by electronic means to requests submitted electronically; where you request a response by other means, and where permitted by applicable law and technically feasible, we will give reasonable consideration to your request.

 

(5) Personalized Advertising Settings

No matter you are in which country or region, you can opt out personalized ads in the following way:

Guidance of Opt out

You can opt-out from receiving interest-based advertising or behavioural advertising from TopOn on supported devices following the guideline below.

On an iOS device, if you are using iOS 14.5 or above, you can click on "Ask the App Not to Track" in the app's asking pop-up window or manage your "Tracking" settings in [Settings] - [Privacy] . If you ask the App not to track, TopOn will not access your advertising identifiers and will not use advertising identifiers to infer your interests or serve advertisements to target devices based on your inferred interests.

On Android devices, your settings may allow you to “Opt out of Interest-Based Ads.” When you opt out using this setting on a device, TopOn will not use information collected from that device to infer your interests or serve ads to that device that are targeted based on your inferred interests.

You can also manage your personalized advertising settings by clicking on the [Settings] section of the mobile app you have downloaded to find privacy-related settings. If you choose not to allow personalized advertising, TopOn will not use information collected from your device to infer your interests or serve ads to target devices based on inferred interests.

Your mobile web browser may also provide a “Do Not Track” browser setting. When you have enabled this setting in your browser, TopOn will not use mobile web browsing information from that browser to infer your interests or serve ads to that device that are targeting based on your inferred interests.

 

8. Security of users’ personal data

The security of User’s information is our utmost priority, and we take strict measures in order to protect our data from unauthorized access, use, disclosure or destruction of data. We have implemented physical, technical and administrative security measures for the Services that comply with applicable laws and industry standards. For example, we use firewalls, encryption technology and other automated software designed to protect against fraud and identity theft; our data is only stored in centers that provide high-level security for User’s information. Physical access is strictly controlled both at the perimeter and at building ingress points by our staff utilizing video surveillance and other electronic means. We will establish a dedicated security team, security management system, and data security process to safeguard the security of your personal data. We adopt a strict data use and access system to ensure that only authorized personnel have access to your personal data, and conduct security audits of data and technology when appropriate. We will develop emergency handling plans and activate them immediately in the event of a user information security incident, in an effort to prevent the expansion of the impact and consequences of such security incidents. Once a user information security incident (leakage, loss, etc.) has occurred, we will promptly inform you in accordance with the requirements of laws and regulations.

We also protect User’s privacy by seeking to minimize the amount of sensitive data that we store on our servers in the first place. We also seek appropriate contractual protection from our partners regarding their treatment of user data.

We will retain your data for as long as necessary to achieve the collection purposes described in this Policy. Generally, your data will be retained in our systems for no more than two (2) years from the date of collection. The criteria we use to determine the retention period include:

(i) how long the personal data is needed to provide the services and operate the business;

(ii) the categories and sensitivity of the personal data collected; and

(iii) whether we are subject to a legal, contractual or similar obligation to retain the data (for example, mandatory data retention laws, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation or dispute resolution).

 

9. Protection for minors

TopOn services are mainly for adults. We do not actively or deliberately collect personal information from minors, nor do we conduct user profiling or personalized recommendations for minors. In the personal information collection scenarios we disclose, we distinguish specific information subjects through device information rather than age. In scenarios where partners transfer and share data with us, we clearly require our partners to formulate special minors' information protection policies in accordance with the law and adopt stricter data desensitization and encryption technology based on the actual conditions of their own products and services. minor.

If the end user is a minor in accordance with applicable laws, please be sure to work carefully under the supervision and guidance of your parents or other guardians before using the developer's application that has integrated TopOn's products and services or the application of the advertiser that cooperates with TopOn for advertising. Read the privacy policy of the developer or advertiser application and this privacy policy, and use the application or provide personal information with the consent of your guardian.

We protect the personal information of minors in accordance with applicable relevant laws and regulations, and will only collect, use, store, share, transfer or otherwise as permitted by law, with consent from parents or other guardians, or as necessary to protect minors. If we discover that we have collected personal information from a minor without first obtaining verifiable parental consent, we will take steps to delete the information as quickly as possible.

If you are a parent or other guardian of a minor, if you have any questions about the personal information of the minor under your custody, please contact us through the contact information disclosed in this privacy policy.

If parents or guardians discover that their children have provided us with their personal information without consent, parents or guardians should contact us promptly. We will take reasonable steps to ensure that such information is removed from our files.

 

10. Marketing

If you are our Business Partners, we or our affiliates may contact you periodically by e-mail to provide information regarding our products, services and content that may be of interest to you. If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent.

If you decide at any time that you no longer wish to receive such communications from us, you may follow the unsubscribe instructions provided in any of the communications or request to be opted-out of receiving such communications via email to privacy@toponad.net

 

11. Contact us

You can contact our DPO by sending a written request to privacy@toponad.net.

 

EU Privacy Representative

We value your privacy and your rights as a data subject. We have therefore appointed Prighter Group, together with its local partners, as our representative in the European Union pursuant to Article 27 of the GDPR and as an additional point of contact for privacy-related matters.

If you are located in the European Union, you may contact us through Prighter or exercise your data protection rights, such as requesting access to, rectification of, or erasure of your personal data, through Prighter’s privacy portal: https://app.prighter.com/portal/19448304506.

1. INTRODUCTION

This Privacy Policy of TopOn Website applies to information collection and use including while you are visiting and using the TopOn Site. According to the General Data Protection Regulation (GDPR), TopOn is the data controller of your personal data.

 

2. WHAT INFORMATION WE COLLECT

As you navigate through this TopOn Site, we may collect information include:

(1) Personal data you voluntarily provide (for example, names, birth dates, numbers or copies of your personal ID card/passport/social security card/driver's license/other license, addresses, telephone numbers, E-mail addresses, occupations, education, work experience, account log-in information, debit or credit card or other payment account information and related information). Among them, numbers or copies of your personal ID card/passport/social security card/driver's license/other license may constitute sensitive personal data under the definition of CCPA; debit or credit card or other collection account information may constitute sensitive personal data under the definition of CCPA.

(2) some information that are not voluntarily provided such as your browser type, domain name, IP address, pages visited, and the length of your user session using various technologies and means, such as Internet Protocol Address, cookies, Internet Tags and navigational data collection.

TopOn is entitled to take measures to validate the authenticity of personal data you provide.

If you give us personal data of somebody else, you should warrant that you have gained their permission to do so.

 

3. HOW WE USE YOUR INFORMATION

Based on your consent or based on our legitimate interests, we may use your personal data for the following purposes: (i) to provide you with TopOn’s products or services or information; (ii) to sign you up for an event or training; (iii) to contact you and respond to your requests and enquiries; (iv) for business administration, including statistical analysis; (v) to personalize your visit to the TopOn Site and to assist you while you use the Site; (vi) to improve the TopOn Site by helping us understand who uses the Site; or (vii) to periodically provide you with information about our products and services and content that may be of interest to you by email.

If you decide at any time that you no longer wish to receive such communications from us, you may follow the unsubscribe instructions provided in any of the emails or request to be opted-out of receiving such communications via email to privacy@toponad.net

 

4. DISCLOSURE OF YOUR PERSONAL DATA

Subject to compliance with applicable laws and regulations, we may disclose User’s personal data to TopOn’s Affiliates and other third parties.

We may use Third-party Technology Service Providers to provide us with services who may have access to your personal data, including companies that assist with programming and technical aspects of hosting and operating the TopOn Site, technical service provider (e.g. Google Analysis) that assists with analyzing the usage of our website, or email service provider.

We may also share aggregate or anonymous information with other third parties in accordance with the terms of this Policy.

We may disclose users' personal data to our affiliates for the purposes set out in this Policy or to promote the products or services of our affiliates to users.

The servers used in the operation of the TopOn Site automatically identify a computer by its IP address. Although, we will not be able to identify the computer using its IP address once you have left the TopOn Site. If we, in good faith, determine that you have or are attempting to misuse or harm the Site, we may investigate and cooperate with appropriate law enforcement agencies to protect our rights or property.

Similarly, we may share your personal data as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property, or the rights, property or safety of others, including to advisers, law enforcement agencies, judicial and regulatory authorities. We may also transfer your personal data to a third party that acquires all or part of our assets or shares, or that succeeds us in carrying on all or a part of our business, whether by merger, acquisition, reorganization or otherwise.

Similarly, we may share your personal data as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property, or the rights, property or safety of others, including to advisers, law enforcement agencies, judicial and regulatory authorities. We may also transfer your personal data to a third party that acquires all or part of our assets or shares, or that succeeds us in carrying on all or a part of our business, whether by merger, acquisition, reorganization or otherwise.

 

5. INTERNATIONAL TRANSFERS

The primary locations at which we process your personal data are Singapore and the United States; however, we may also transfer data to all other countries in which TopOn and its affiliates, service providers and partners conduct business. All data transfers are carried out in accordance with applicable laws and regulations — for example, by entering into data transfer agreements — in order to safeguard the security of your data.

If you are located in the European Economic Area (“EEA”), the personal data we collect about you will be transferred to, or may be remotely accessed from, countries located outside the EEA, including the United States, Singapore or other countries that have not been recognized by the European Commission as providing an adequate level of protection for personal data. We will, however, provide appropriate safeguards for such personal data as required by applicable law. Where required by law, our Business Partners will obtain your consent to transfer your personal data outside the EEA, including to TopOn or other recipients as described in this Policy. You may withdraw your consent at any time.

If you are a U.S. person, we comply with applicable U.S. laws and regulations, including the U.S. Department of Justice Data Security Program (DSP), and will not unlawfully transfer, share or otherwise make available your personal data.

 

6. YOUR DATA RIGHTS

(1)If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another country or region whose applicable data protection laws grant you comparable rights, you may, to the extent permitted by applicable law, have one or more of the following data subject rights:

a. Right of access. You have the right to request access to the personal data we process relating to you and to obtain information about how we process such personal data.

b. Right to rectification. You have the right to request that we correct inaccurate or incomplete personal data.

c. Right to erasure. You have the right to request that we delete your personal data in the circumstances provided by applicable law.

d. Right to restriction of processing. You have the right to request that we restrict the processing of your personal data in the circumstances provided by applicable law.

e. Right to object. You have the right to object to our processing of your personal data in the circumstances provided by applicable law, including objecting to processing based on legitimate interests or processing for direct-marketing purposes.

f. Right to data portability. You have the right, in the circumstances provided by applicable law, to request that we provide you, or a third party of your choosing, with a copy of your personal data in a structured, commonly used and machine-readable format.

g. Right to withdraw consent. Where we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

h. Rights relating to automated decision-making. In the circumstances provided by applicable law, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, or to request that we provide human intervention, allow you to express your point of view, or contest the decision.

i. Right to lodge a complaint. You have the right to lodge a complaint regarding our processing of your personal data with the data protection supervisory authority in your location or having jurisdiction.

 

Priority of local law. Although we endeavour to provide users with a relatively complete set of data rights on a global basis, the specific rights available may vary depending on your jurisdiction. Where the rights described in this Policy are inconsistent with the mandatory provisions of the data protection laws applicable in your location, the mandatory provisions of the applicable law in your location shall prevail.

 

(2)Privacy Rights of U.S. Residents

If you are a U.S. resident, you may have one or more of the following privacy rights under applicable U.S. federal or state privacy laws, including but not limited to the rights provided under the privacy laws of California, Virginia, Colorado, Connecticut, Utah and other applicable states:

a. To confirm whether we are processing your personal information and to access that personal information.

b. To correct inaccuracies in your personal information.

c. To delete your personal information.

d. To obtain a copy of the personal information you have provided to us.

e. To opt out of our processing of your personal information for the purposes of: (i) targeted advertising or personalized advertising; (ii) the sale of your personal information; (iii) the sharing of your personal information; or (iv) profiling or analysis in furtherance of decisions that produce legal or similarly significant effects concerning you.

f. Right to opt out of sale or sharing. You have the right to opt out of the sale or sharing of your personal information.

g. Right to limit the use and disclosure of sensitive personal information. You have the right, to the extent provided by applicable law, to request that we limit the use and disclosure of your sensitive personal information, except for uses permitted by applicable law.

h. Right to non-discrimination. You have the right to exercise the rights granted to you under applicable privacy laws free from discrimination.

i. Right to appeal. If we decline your privacy rights request and the applicable state privacy law grants you a right to appeal, you may appeal in the manner provided in our response, or by sending an email to privacy@toponad.net.

 

If you are a resident of the State of California, you may also request that we disclose how we have collected, used, sold, shared or disclosed your personal information during the period prescribed by applicable law, which generally covers the preceding 12 months. Where permitted by applicable law, you may also request that we disclose such information for a period exceeding 12 months, provided that this right applies only to personal information collected by us on or after January 1, 2022 and still retained by us, and is subject to the exceptions provided by applicable law. The foregoing does not require us to retain personal information for longer in order to respond to such a request.

 

The information that California residents may request includes:

h. the categories of personal information we have collected;

i. the categories of sources from which the personal information was collected;

j. the business or commercial purpose for collecting or sharing personal information;

k. the categories of third parties to whom we disclose personal information;

l. the categories of personal information that we have sold, shared or disclosed for a business purpose;

m. the categories of third parties to whom the personal information was sold or shared, or disclosed for a business purpose; and

n. a copy of the personal information we have collected about you during the period prescribed by applicable law.

 

The rights described above are not exhaustive and do not limit any other privacy rights you may have under applicable U.S. federal or state law. If the laws of your state of residence grant you additional privacy rights not expressly set out in this section, this Policy does not limit or prevent you from exercising those rights in accordance with the law. We will comply with applicable U.S. state data privacy laws to protect your personal information.

 

(3)How to Exercise Your Rights

Regardless of which country or region you are located in, you may submit a data subject rights request to us by sending an email to privacy@toponad.net. This mailbox is also available for users in the EEA, the UK, the United States and other applicable regions to submit requests to access, correct, delete, restrict the processing of, object to the processing of, withdraw consent to, port or opt out of the processing of their personal information, or to exercise other privacy rights granted by applicable law.

If you wish to opt out of the sale or sharing of your personal information, you may also do so by sending “Do Not Sell or Share My Data” to our privacy mailbox, or by submitting the relevant online form on the TopOn official website.

If you wish to limit our use and disclosure of your sensitive personal information, or to opt out of our processing of your personal information for the purposes of targeted or personalized advertising, the sale or sharing of personal information, or profiling or analysis in furtherance of decisions that produce legal or similarly significant effects concerning you, you may submit a request to us by sending an email to privacy@toponad.net.

To the extent required by applicable law, we will also recognize and honour opt-out preferences expressed by users through browsers, device settings, platform permission settings or other applicable preference signals.

When you submit a request, we will verify your request in accordance with our internal procedures and on the basis of the information you provide (such as a device ID, company email or other necessary information). If you fail to provide the information necessary to verify your identity or to locate the relevant personal information, we may be unable to process your request, or may decline your request as permitted by law.

You may designate an authorized agent to submit an applicable privacy rights request on your behalf by providing the authorized agent with written permission to do so and by verifying your own identity with us directly as we may require. We will deny any request from an agent that does not submit valid proof of authorization.

 

(4)Our Timeframes for Responding to Requests

We will process your request without undue delay and respond to you within the period required by applicable law. Specifically:

e. If you are located in the EEA or the UK, we will generally respond within one month of receiving your request. For complex or multiple requests, where permitted by applicable law, we may extend the response period by up to a further two months, and will inform you of the extension and the reasons for it within one month of receiving the request.

f. If you are a U.S. resident, we will generally respond within 45 days of receiving a verifiable consumer request. For complex or multiple requests, where permitted by applicable law, we may extend the response period by a further 45 days, and will inform you of the extension and the reasons for it within the initial 45-day period.

g. If you are located in another country or region, we will respond to your request within the period prescribed by the applicable data protection laws of your location; where local law does not prescribe a specific period, we will generally respond within 30 days of receiving a verifiable request.

h. If we decline to act on your request as permitted by law, we will explain the reasons for the refusal within the period required by applicable law and, where required by applicable law, inform you of the appeal, complaint or other remedies available to you.

Unless otherwise provided by applicable law, we will generally respond by electronic means to requests submitted electronically; where you request a response by other means, and where permitted by applicable law and technically feasible, we will give reasonable consideration to your request.

 

7. SECURITY OF YOUR PERSONAL DATA

The security of User’s information is our utmost priority, and we take strict measures in order to protect our data from unauthorized access, use, disclosure or destruction of data. We have implemented physical, technical and administrative security measures for the Services that comply with applicable laws and industry standards. For example, we use firewalls, encryption technology and other automated software designed to protect against fraud and identity theft; our data is only stored in centers that provide high-level security for User’s information. Physical access is strictly controlled both at the perimeter and at building ingress points by our staff utilizing video surveillance and other electronic means.

We also protect User’s privacy by seeking to minimize the amount of sensitive data that we store on our servers in the first place. We also seek appropriate contractual protection from our partners regarding their treatment of user data.

We will retain your data for as long as necessary to achieve the collection purposes described in this Policy. Generally, your data will be retained in our systems for no more than two (2) years from the date of collection. The criteria we use to determine the retention period include: (i) how long the personal data is needed to provide the services and operate the business; (ii) the categories and sensitivity of the personal data collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the data (for example, mandatory data retention laws, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation or dispute resolution).

 

8. PROTECTION OF MINORS

The Site does not knowingly collect any personal data from minors. The personal data of any minor you provide shall be agreed by the minor’s parent or guardian in advance. Minor is defined in accordance with the laws applicable to this Policy of TopOn Website.

We process minor’s personal data according to requirements of related laws and regulations. Except as otherwise provided by law, we will only collect, use, store, disclose, or make available to the public the personal data where permitted by law, with consent of parents or other guardians, or for the necessity of protection of the minors. If we notice the collection of personal data of minors without verifiable consent of parents, we will take measures to delete related information as soon as possible.

If you are parents or other guardian of minors, please contact us via the email we provide in this Policy when you have any question regarding to the protection of minors.

If you are Users in the U.S., we ensure that we comply with COPPA. If our business partners (such as Publishers) operate apps directed to children under the age of thirteen (13) or knowingly collect, use or disclose personal data of children under the age of thirteen (13) during our cooperation, they will obtain verifiable parental consent for TopOn to collect, use or disclose such personal data according to this Policy. Further, such business partners must enable the COPPA settings when using the TopOn Services. This allows TopOn to ensure that any persistent identifiers collected about Users of apps that are flagged as “child-directed” will be processed according to the requirements of COPPA, including not being used to serve behaviorally-targeted ads or track users for such purposes in violation of COPPA. In addition, we will not knowingly collect any other personal data (such as the precise geo-location of Users’ devices) from Users of Apps that we know to be directed to children under the age of thirteen (13).

If you are Users in California U.S.,we ensure that we comply with CCPA. We will not sell or conduct targeted advertising with the data of consumers under the age of 16, unless there is explicit opt-in consent. If the request for consent is declined, we will not ask again for 12 months. Minors under the age of 13 must get permission from a parent or guardian to opt-in.

If a parent or guardian becomes aware that his or her child has provided us with information without their consent, he or she should promptly contact us and we take reasonable steps to ensure that such information is deleted from our files.

 

9. USE OF COOKIES AND OTHER TRACKING TECHNOLOGIES

TopOn may use cookies or other technology (collectively “Cookies”) to collect certain information about you when you are visiting the Site. Please read our Cookies Policy for more details.

 

10. OUTSIDE SITES AND LINKING

The Site may contain links and pointers to other sites on the Internet that are owned or operated by third party vendors and other third parties (the “ Outside Sites “). TopOn is not responsible for the availability of, or the content located on or through, any Outside Site, including any webcasting or other form of transmission received from any Outside Sites. You should contact the site administrator or Webmaster for those Outside Sites if you have any concerns regarding such links or the content located on such Outside Sites. TopOn permits certain third party links to the home page of its Site, provided that TopOn is provided with notice of such links and does not thereafter object to such linking. TopOn a reserves the right to revoke unilaterally any consent that it may at any time give to any linkage, including linkages to the home page. The Outside Sites are being provided to you only as a convenience and any link or pointer contained on this Site does not imply endorsement of the Outside Sites.

 

11. COPYRIGHT

All Site content, design, text, graphics, images, logos, buttons, icons, interfaces, audio and video clips, and the selection and arrangements thereof are the exclusive property of TopOn, or its respective content providers, and are protected by Singapore and international copyright laws. All software used on the Site is the property of TopOn or its respective software suppliers, and such software is protected by Hong Kong SAR and international copyright laws and other applicable laws and treaties. Users of this Site shall not transmit/post any information to this Site that infringes the copyright or other intellectual property rights of others.

 

12. TRADEMARKS

All trademarks, service marks and trade names used on the Site (collectively the “Marks“) are solely owned by TopOn. The Marks may not be used in connection with any product or service that is not a product or service of TopOn or that is likely to cause confusion among customers, or that in any manner disparages or discredits TopOn.

 

13. ONLINE CONDUCT

Any conduct by a person that in TopOn ‘s sole discretion restricts or inhibits any other person from using or enjoying the Site, is prohibited. You agree to use the Site only for lawful purposes and in accordance with that prohibition. You agree that you will not post on the Site or transmit any unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, sexually explicit, profane, hateful, racially, ethnically, or otherwise objectionable material of any kind, including, but not limited to, any material that encourages conduct that would constitute a criminal offense, give rise to civil liability or otherwise violate any applicable local, state, national, or international law.

 

14. TERMINATION OF USAGE

TopOn may, without incurring any liability to you, terminate access by you or suspend any access to all or part of the Site, without notice, for any conduct that TopOn, in its sole discretion, believes is in violation of any applicable law or this Agreement, or is harmful to the interests of another user, a third-party, a merchant, a sponsor, a licensor, a service provider, or the Site.

Due to the rapidly evolving technologies on the Internet, we may occasionally update this Policy. All revisions will be posted to this website www.topon.com

 

15. CONTACT US

You can contact our DPO by sending a written request to privacy@toponad.net.

EU Privacy Representative

We value your privacy and your rights as a data subject. We have therefore appointed Prighter Group, together with its local partners, as our representative in the European Union pursuant to Article 27 of the GDPR and as an additional point of contact for privacy-related matters.

If you are located in the European Union, you may contact us through Prighter or exercise your data protection rights, such as requesting access to, rectification of, or erasure of your personal data, through Prighter’s privacy portal: https://app.prighter.com/portal/19448304506.

This Applicant and Candidate Privacy Privacy (“Privacy”) applies when you submit a job application, resume, CV or other candidate information to TopOn through the TopOn website, recruitment email, job boards, employee referrals, recruitment agencies or other recruitment channels.

TopOn respects and values the privacy of applicants and candidates. This Privacy explains how TopOn collects, uses, stores, shares and protects your personal information in connection with recruitment, candidate evaluation, interview arrangements, hiring communications and related human resources processes. It also explains the rights you may have in relation to your personal information.

In this Privacy, “TopOn”, “we”, “us” or “our” refers to the TopOn entity responsible for the role you apply for and the relevant affiliated entities involved in the recruitment process. To the extent required by applicable law, the TopOn entity responsible for the role you apply for will generally act as the personal information processor / data controller of your candidate personal information.

When you voluntarily submit your resume/CV to us by email or other means, or upload your resume/CV and submit a job application through the TopOn website, you will be deemed to have read, understood, and agreed to the personal information processing rules described in this Applicant and Candidate Privacy Policy.

Please note that submitting a job application, resume, CV or other candidate information to TopOn does not create or imply any offer of employment, employment relationship, engagement relationship or similar relationship.

 

1. Personal Information We May Collect

During the recruitment process, we may collect and process the following categories of personal information, depending on the specific role, recruitment process and applicable legal requirements, and only to the extent necessary:

  • Identification and contact information, such as your name, phone number, email address, place of residence, mailing address, photograph and, where necessary for the role or required by law, identification document information;
  • Education and work experience information, such as your education history, major, school, training experience, qualifications, certificates, employment history, previous employers, job titles, job responsibilities, project experience, portfolio, language skills and professional skills;
  • Application information, such as your resume/CV, cover letter, role applied for, preferred work location, salary expectations, available start date, recruitment channel and referral information;
  • Interview and assessment information, such as written test or assessment results, interview notes, interview feedback, communications with you, hiring team comments and candidate evaluation results;
  • Background verification information, such as verification of your education, employment history, professional qualifications, references or other role-related information, where permitted by applicable law and necessary for the role;
  • Offer and onboarding information, such as information required to issue an offer, complete onboarding and execute employment or engagement documents if you are successful;
  • Other information you voluntarily provide, such as information included in your resume, portfolio, email communications, interviews or other communications.

Please avoid providing sensitive personal information that is not relevant to the recruitment process, such as detailed health information, religious beliefs, political opinions, detailed family information, unnecessary copies of identification documents or bank account information, unless required by law, necessary for the role or specifically requested by us.

 

2. Sources of Personal Information

We may collect your personal information from the following sources:

  • Directly from you, such as through our recruitment email, email communications, offline recruitment events or interviews;
  • Job boards, recruitment agencies, headhunters or other third-party recruitment channels;
  • Employee referrals or business contact referrals;
  • Publicly available professional information, such as professional networking platforms, public portfolios or public technical community profiles;
  • Background check providers, previous employers, referees or educational institutions, where permitted by applicable law and necessary for the role.

 

3. How We Use Your Personal Information

We may process your personal information for the following purposes:

  • To receive, manage and evaluate your job application;
  • To assess your suitability for the relevant role;
  • To communicate with you about the recruitment process and arrange written tests, interviews, assessments or follow-up discussions;
  • To conduct candidate screening, evaluation, hiring decisions and salary or role matching analysis;
  • To conduct background checks where permitted by applicable law and necessary for the role;
  • To issue an offer and, if you are successful, complete onboarding, human resources administration and compliance procedures;
  • To include you in our talent pool and contact you about future opportunities, where you have consented or where permitted by applicable law;
  • To improve our recruitment processes, recruitment channels and candidate experience;
  • To comply with applicable laws, regulations, regulatory requirements, audits, compliance obligations, dispute resolution or legal proceedings;
  • To protect the legitimate rights, interests, safety and property of TopOn, candidates, employees or other relevant parties.

 

4. Legal Bases for Processing

Depending on applicable data protection laws, we may process your personal information based on one or more of the following legal bases:

  • To evaluate your application and take necessary steps before entering into an employment or engagement relationship with you;
  • Where necessary to enter into or perform an employment contract, engagement agreement or other relevant agreement;
  • To comply with applicable legal or regulatory obligations;
  • For our legitimate interests in recruitment management, business operations, compliance audits, security management and dispute resolution;
  • Based on your consent, such as where we retain your resume/CV in our talent pool, process certain sensitive personal information or contact you about future opportunities;
  • Other lawful bases permitted by applicable law.

 

5. Sensitive Personal Information

In general, we do not actively request sensitive personal information that is unrelated to recruitment. Where it is necessary to process sensitive personal information, such as identification document information, health information, disability accommodation information, background verification information or other special category information, we will do so only where permitted by applicable law, necessary for the role, based on your explicit consent, or otherwise required by law. We will apply reasonable protection measures to such information.

If you need reasonable accommodation for interviews or other recruitment steps due to health, disability or other circumstances, you may contact us. We will process such information only for the purpose of providing the accommodation and complying with applicable legal obligations.

 

6. How We Share Your Personal Information

We may share your personal information with the following recipients where necessary:

  • Authorized personnel within TopOn responsible for recruitment, human resources, legal, compliance, finance, information security and the relevant hiring teams;
  • TopOn affiliated entities, particularly for cross-region recruitment, role evaluation, group human resources management or internal opportunity assessment;
  • Service providers supporting the recruitment process, such as job boards, recruitment agencies, headhunters, background check providers, cloud service providers, IT system providers and email service providers;
  • Auditors, lawyers, consultants, regulators, law enforcement authorities, courts, arbitration bodies or other third parties legally entitled to receive the information, where required or permitted by applicable law;
  • Relevant transaction parties, advisers or successor entities in connection with a merger, division, restructuring, financing, asset transfer, business transfer or similar transaction, subject to appropriate safeguards;
  • Other recipients or circumstances permitted by applicable law.

We do not sell your candidate personal information. We also do not use your candidate personal information for commercial marketing purposes unrelated to recruitment, unless we have obtained your consent or are otherwise permitted by applicable law.

 

7. International Transfers

As TopOn operates globally, your personal information may be accessed, stored or processed in countries or regions outside your country or region of residence, including by TopOn affiliated entities, cross-border recruitment teams or service providers.

Where required by applicable law, we will complete necessary legal procedures before transferring your personal information across borders and adopt appropriate safeguards, such as data processing agreements, standard contractual clauses, cross-border transfer agreements or other mechanisms recognized by applicable law.

 

8. Retention Period

We retain your personal information only for as long as necessary to achieve the purposes described in this Privacy, unless a longer retention period is required or permitted by law.

For unsuccessful candidates, we generally retain your personal information for no longer than 6 months after the relevant recruitment process ends, for recruitment record management, compliance audits, dispute handling and future role matching. If you consent to join our talent pool, or where applicable law permits us to retain relevant information for future role matching, we may retain your information for the applicable period and contact you about future suitable roles.

For successful candidates, relevant personal information may be transferred to your employee file and will be processed and retained in accordance with the applicable employee privacy policy, employment contract and human resources policies.

When the retention period expires or the processing purpose no longer exists, we will delete, anonymize or otherwise handle your personal information in accordance with applicable laws and our internal policies.

 

9. Information Security

We adopt reasonable technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, loss, destruction or misuse. These measures may include access controls, access logs, encryption, internal confidentiality obligations, employee training, vendor management and security reviews.

Although we take reasonable steps to protect your personal information, no internet transmission or electronic storage method is completely secure. Please avoid submitting sensitive information that is unnecessary or unrelated to recruitment.

 

10. Your Rights

Depending on applicable data protection laws, you may have the right to:

  • Access or obtain a copy of your personal information;
  • Correct or supplement inaccurate or incomplete personal information;
  • Request deletion of your personal information;
  • Withdraw your consent;
  • Restrict or object to our processing of your personal information;
  • Request an explanation of our personal information processing rules;
  • Request portability of your personal information;
  • Lodge a complaint with a competent data protection authority.

These rights may be subject to conditions, limitations or exceptions under applicable law. We will verify and process your request in accordance with applicable legal requirements.

 

11. Third-Party Websites and Platforms

If you apply for a TopOn role through a third-party recruitment website, social media platform, recruitment agency or other third-party channel, that third party may collect and process your personal information in accordance with its own privacy policy. We encourage you to review the relevant third party’s privacy policy. This Privacy applies only to TopOn’s processing of candidate personal information.

 

12. Updates to This Privacy

We may update this Privacy from time to time due to changes in laws and regulations, recruitment processes, systems or business needs. The updated Privacy will be published on the TopOn website or through other appropriate channels and will take effect from the date of publication, unless otherwise stated.

 

13. Contact Us

If you have any questions, requests or complaints regarding this Privacy or our processing of candidate personal information, you may contact us at:

Recruitment contact email: zhaopin@toponad.com

Privacy contact email: privacy@toponad.com

Please read this Privacy carefully before submitting your job application or resume/CV to us. By submitting your job application, resume/CV or other candidate information to us, you acknowledge that you have been informed of the matters described in this Privacy.