Prior to the use of DingTalk products or services, please carefully read and thoroughly understand this Policy. If you have any questions, comments or suggestions on the content of this Policy, you may contact us via [DataProtection.DingT@service.dingtalk.com].
Part 1 Definitions
- DingTalk Service Providers: means DingTalk (Singapore) Private Limited, who research, develop and provide DingTalk products and services; as well as other relevant local affiliates (including Alibaba Cloud (Malaysia) Sdn. Bhd. for Malaysia) collectively named as "DingTalk”, “DingTalk Company” or “we”.
- Affiliate: mean any affiliate of DingTalk Service Providers as disclosed by Alibaba Group Holding Limited in its latest annual report. For details, please visit http://www.alibabagroup.com/en/ir/secfilings.
- Personal Information: means any information relating to an identified or identifiable natural person (an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person), whether on its own or in combination with other information.
- Sensitive Personal Information: includes, without limitation, personal information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
- Personal Information Deletion: means the removal of Personal Information from the systems as involved in daily business operations so as to keep such information irretrievable and inaccessible.
Part 2 Legal Statement
I. Ownership of Rights
DingTalk logo, “钉钉”, “钉三多”，“DingTalk”, “Ding” and other texts, graphics and combinations thereof, other marks and symbols of DingTalk and DingTalk service names are the registered trademarks of DingTalk and its Affiliates in China and other countries. Without the written authorization of DingTalk, no one may display, use or otherwise process (including without limitation reproduce, disseminate, show, mirror, upload and download) any of the said trademarks in any way or represent to others that he/she/it has the right to display, use or otherwise process any of the said trademarks.
The intellectual property rights in all of DingTalk’s products, services, technologies and all applications or their components/features/name (“Technical Services”) shall vest in DingTalk Company or their right owners.
Unless otherwise stated by DingTalk, all rights (including but not limited to copyright, trademark right, patent right, trade secret and any other related rights) in, of and to all documents and other information (including but not limited to texts, graphs, pictures, photos, audios, videos, icons, colors, layout and electronic documents) published by DingTalk on websites are vested in DingTalk. Without the permission of DingTalk, no one may use the said information (including but not limited to monitor, reproduce, rebroadcast, display, mirror, upload and download any contents in Aliyun.com via programs or devices). Where any one is authorized to browse, reproduce, print or disseminate the information relating to DingTalk products and services, such information shall not be used for commercial purposes and this statement of rights must be included in use of all information or any portion thereof.
II. Limitation of Liability
Where DingTalk users upload, provide or publish relevant information on or in DingTalk App, DingTalk official website, forums, communities and open platforms, including but not limited to user name, company name, contact person and contact details, relevant pictures and information, such information shall be provided by DingTalk users on their own and DingTalk users must legally assume all liabilities for any information they provide.
DingTalk reposts works (including contents on forums) for the purpose of distributing information and better service DingTalk individual users and enterprise/organization users, which does not mean that DingTalk agrees with the viewpoints in the works or confirms the authenticity of the contents of the works.
DingTalk hereby reminds you that you shall abide by laws of the Republic of Singapore and all other applicable domestic laws in the countries in using DingTalk’s products and services, and you shall not endanger cyber security or utilize DingTalk products and services to engage in activities that infringe upon others’ reputation right, privacy, intellectual property rights or other legitimate interests. Notwithstanding such reminders, DingTalk will assume no liability for your purposes of using DingTalk products and services.
III. Protection of Intellectual Property
We respect intellectual property rights and oppose and combat any infringement upon intellectual property rights. If any organization or individual deems that each and any product, service, content delivered by DingTalk Service and/or Third Party Service may infringe upon its/his/her legitimate interests, such organization or individual may issue a written notice of claims with preliminary supporting documents and in either of the following ways and DingTalk will deal with the same as soon as possible in accordance with laws after receipt of applicable notice from the intellectual property right owner by mailing the notice and original supporting documents to:
Attention: DingTalk User Operation Center
Address: Building No.5, DingTalk Park, 959 Gaojiao Road, Wuchang Street, Yuhang District, Hangzhou, P.R. China，311100
This part will help you understand the followings:
- How we collect your Personal Information
- How do we use your Personal Information
- How we share, transfer and disclose your Personal Information
- How we protect your Personal Information
- How we process Personal Information of minors
- How we store and transfer Personal Information outside your country
- Information for EEA Residents only
- How we update this Policy
- How to contact us
I. How we collect and use your Personal Information
(I) How we collect your information
In order to provide DingTalk Service to You and DingTalk Enterprise/organization Users, to maintain the normal operation of DingTalk Service, improve and optimize our service experience and ensure your account security, we will collect information that you actively provide, authorize or provide based on the requirements of your company/organization, together with information generated when You use DingTalk Service and based on the following purposes and methods of this Policy:
- Help you become a DingTalk user
To become a DingTalk user, you are required to provide your cellphone number, name, ID，type of industry, job title, gender, date of birth, company email address and/or other basic information so as to create a DingTalk account and password. We collect this information so that we are able to provide you with membership services, including instant messaging, video conference, VOIP, DING, creation of corporate address books and groups and other functions for communication. If you wish to make a multi-party DingTalk conference call, you are required to authorize us to have access to your mobile contacts.
If you wish to realize intelligent check-in, review & approval procedures, sign-in, log, announcement, Ding Mail, Ding Drive and other co-working functions by using DingTalk, you are required to provide additional data for supplementing the account information so that we are able to provide more customized products or services (including but not limited to your job position; main business focus; email; fingerprint; facial photo and geographical location). If you do not provide this information, your use of customized products or services will be affected, but your use of the basic functions of DingTalk and browsing of DingTalk websites will not be affected.
After activating DingTalk and becoming a DingTalk user, you may modify your Personal Information such as nickname, phone number, date of birth and region via [DingTalk APP-Me-click name or profile picture]. When your company deregisters its DingTalk Enterprise account, we will anonymize or delete your Personal Information relating to the Enterprise. Your Personal Information as a separate individual DingTalk User will be maintained in case you are still using DingTalk. Should you deregister your individual DingTalk account, we will anonymize or delete your Personal Information pursuant to applicable laws and regulations (see the 'Data Retention' section, below).
You may refer to the latest version of DingTalk APP for deregistration of DingTalk account within DingTalk clients via [DingTalk APP-Me-Settings-Account and Security-Delete DingTalk Account] and its further process therewith.
You are not required to register to be our member or provide the above information if you only use such basic services as browsing and searching the official website of DingTalk and open.dingtalk.com for services and the introduction thereof.
- Provide you with products or services
1) Information provided by you to us
We will collect any feedback of experience in using DingTalk products and services to help us better understand your experience, user requirements and improve our products or services.
You may purchase products or services in DingTalk for others, provided that you have being duly authorized to provide the Personal Information of such actual purchaser with its/his/her authorization. We shall not be liable to each and any infringement if you provide us this information without due authorization from the individual.
Some of our products and services require payment. For more information, please see the section entitled 'Information provided by third parties to us', below.
2) Information collected by us when you use non-customized services
In order to provide you with intelligent DingTalk hardware and/or DingTalk Apps, webpage presentations and search results that better meet your needs, understand product fitness and identify abnormalities of accounts, we will collect and connect the information relating to the product and/or services used by you and the way you use them, including:
Device information: On the basis of the specific authorizations granted by you in installation and use of the software, we will receive and record information relating to the device used by you (e.g. device model, operating system version, device settings, unique device identifier and other information of software and hardware features) and the location of such device (e.g., IP address, GPS/Beidou location information, and any Wi-Fi access point, Bluetooth, base station and other sensor information).
Log information: When you use products or services provided by our website, we will automatically collect detailed information relating to your use of our services and save them as network logs (such as your searches, IP addresses, types of browsers, telecommunication service providers, languages, visit dates and times, web pages visited by you, and status of the call by reviewing information provided through DingTalk conference call and/or voice messages).
Please note that the device information or log information alone is not sufficient to identify a certain natural person. If we combine such non-Personal Information with other information to identify certain natural person, or use the same in combination with Personal Information, then such non-Personal Information will be deemed as Personal Information during such combination, and we will anonymize and de-identify such Personal Information (unless we have your authorization or it is otherwise provided by laws and regulations).
We will collect the information on purchase orders placed by you in using our services to present such information to you and facilitate your management of purchase orders.
When you contact us, we might keep the history and content of your communication/call or contact information given by you so as to contact you or help you solve problems, and might record solutions and results of relevant problems.
3) Information collected by us when you use customized services
In order to provide you with customized services that:
a) provide consistent experiences in different service terminals or devices;
b) provide you with input recommendations and customer service reception;
c) provide you with information push that best meet your needs;
d) understand product fitness; and
e) identifies abnormalities of accounts),
we will collect information relating to your use of services, including device information, log, service use information.
Device information: On the basis of the specific authorizations granted by you in installation and use of the customized services, we will receive and record information relating to the device used by you (e.g. device model, operating system version, device settings, unique device identifier and other information of software and hardware features) and the location of such device (e.g., IP address, GPS/Beidou location information, and any Wi-Fi access point, Bluetooth, base station and other sensor information).
Log Information: When you use our website, we will automatically collect detailed information relating to your use of our services and save them as network logs, such as your IP addresses, types of browsers, telecommunication service providers, languages, visit dates and times, length of visits, information of software and hardware features, web pages visited by you and DingTalk Cookies (see 'Cookies and other similar tracking technologies' section, below)
Service use information: We will record information submitted or generated in your use of DingTalk products and services, information stored in Ding Drive, documents transmitted through other Affiliates to DingTalk, list of friends created, settings (e.g., password, automatic login, general settings, privacy settings, message alert).
When you undertake certain operations (e.g. adding friends to your groups) by using DingTalk services, we will send notices to you or others (such as the added friends).
4) Information provided by third parties to us
DingTalk will collect your Personal Information when any other user makes any operation related to you, and from DingTalk’s Affiliates, partners or other lawful channels. We will only collect this Personal Information where we have checked that these third parties either have your consent or are otherwise legally permitted or required to disclose your personal information to us.
For example, some of our products and services require payment. If you wish to use any of these paid products or services, you are required to provide your bank card information and/or, where applicable, bind your account to Alipay for us to check your payment status.
If you are using iPhone or iPad, when you enable DingTalk Sport, you agree that we will request and receive your step information from Apple's HealthKit via DingTalk, otherwise you will not be able to use DingTalk Sport. Without your consent, we will not share your step information DingTalk received from Apple's HealthKit with any third party, including any advertisers and any other agents, and will not use HealthKit information for marketing, advertising and similar companies.
- Other purposes
In general, we will use the Personal Information we collect from you only for the purposes described in this Policy or for purposes that we explain to you at the time we collect your Personal Information. However, we may also use your Personal Information for other purposes that are not incompatible with the purposes we have disclosed to you (such as archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes) if and where this is permitted by applicable laws. When we collect your information for any other specific purpose not specified in this Policy, we will obtain your consent in advance.
The purpose for DingTalk to collect and use the Personal Information is to better operate the DingTalk products and services (including but not limited to provide customized services to you), and we will notify you of all new functions and new services with a notice on website, via email, by phone call or short message. We may also send you business information that you may be interested in (including but not limited to the products, services or business investment opportunities of DingTalk’s Affiliates or any other third party), provided however that DingTalk will not view or use your business data while you are applying the Dingtalk cloud storage, Dingtalk email and/or IM function.
II How we use your information
We collect your information for the purpose of providing you with services and improving the service quality. Therefore, we will use your information for the following purposes:
Provide you with DingTalk products or services you intend to use, and maintain, improve and optimize these services and experience with these services.
We may use or integrate your user information, service use information, device information, log information and information shared by our Affiliates or partners (either with your authorization or as required by laws), in order to:
a) prevent, identify and investigate in any fraud, infringement, dangerous act, illegal act or act in violation of our (or our Affiliates’) agreements, policies or rules;
b) to protect yours, ours, our Affiliates’or the public’s lawful interests; and
c) comprehensively assess the risks faced by your account and in your transaction,
d) carry out authentication of your identity,
e) prevent a security event (such as a data breach); and
f) undertake any necessary recording, audit, analysis and handling measures according to laws.
- We may process your information or combine your information with information from other services in order to provide customized services to you such as to recommend to you any contents which you may be interested in (including but not limited to a) sending product and service information to you, b) displaying personalized third-party promotional information to you through the system, or c) subject to your consent, share information with the partners of Ding Talk Service Providers so that they may send information about their products and services to you.
- Any other purpose as permitted by you.
To provide you with better user experience, when you use DingTalk products or services, we may collect and store data relevant with your visit to DingTalk service by employing various technologies. In this way, when you visit or revisit DingTalk service, we will be able to identify you and provide customized services to you by analyzing your Personal Information. This will include verifying your identity through small data files, so that we will be able to understand your habits or assist you with using the services (for example to help you avoid repeated input of account information or help assess the security of your account). These data files may be Cookie, Flash Cookie or other local storage provided by your browser or relevant applications (collectively, “Cookie”).
IV. How we share, transfer and disclose your Personal Information
We will not share your Personal Information with companies, organizations or individuals other than DingTalk Service Providers, except in the following circumstances:
1. Sharing with explicit consent: We will share your Personal Information with other parties with your explicit consent;
2. Sharing as required by laws: We may share your Personal Information as required by laws, regulations, litigation, dispute resolution, or by administrative or judicial authority in accordance with laws where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
3. The products and services you request may only be provided with disclosure of your information. For example, for using Ding function and conference call service, your cellphone number confirmed with security code will be transmitted to basic telecommunication service operators for realization of communication, this information will then be displayed to other users as the number of incoming call;
4. When a complaint is made by others against you. If you infringe upon intellectual property rights or other lawful interests, we need to disclose your information as necessary to the complainer for settlement of complaint;
5. In order for you and your friends to find each other in your address book. After you enable “matching the address book” function, the system will match the corresponding attribute code after processing the cellphone numbers in your address book with strong encryption algorithm and display matching users to you. DingTalk will not retain any identifiable information in your address book. The data of cellphone numbers in your address book used in this process will be processed with strong encryption algorithm and the match will be conducted through processed attribute code.
6. Sharing with our Affiliates: In order to a) facilitate joint service from an account connected with different DingTalk services, b) recommend customized information that you may be interested in, or (c) protect personal information of the Affiliates of DingTalk, other users or the public, your Personal Information may be shared with our Affiliates. We will only share necessary Personal Information (for example, in order to facilitate your use of the products or services of our Affiliate with your DingTalk account, we will share your necessary account information with such Affiliate). If we intend to share your Sensitive Personal Information or the Affiliate changes the purpose of using and processing Personal Information, we will obtain your authorization and consent to this change.
7. Sharing with authorized partners: Certain services of ours will be jointly provided together with our authorized partners solely for the purposes stated in this Policy. We may share certain Personal Information of yours with our partners to provide better customer service and user experience. For example, when you purchase products on the website online, we have to share your Personal Information with logistics service providers to arrange delivery of such products, or we have to share your personal information to arrange with our partner to provide service. We will only share your Personal Information for lawful, proper, necessary, specific and explicit purposes to the extent required for providing the services. Our partners have no right to use the shared Personal Information for any other purpose irrelevant with products or services.
DingTalk services contain links to other websites. Except for otherwise stipulated by laws, DingTalk shall not be liable in any way for the privacy protection measures of those websites. We may add links to the websites of our business partners or shared brands when necessary, and the information provided shall be limited to general information and we will not disclose your identity.
We will only transfer your Personal Information to any company, organization or individual, in the following circumstances:
1. Transfer with explicit consent: We will transfer your Personal Information to other parties with your explicit consent;
2. In case of any acquisition, merger or insolvency liquidation, or other circumstances involving merger, acquisition or insolvency liquidation, of DingTalk Service Providers, if transfer of Personal Information is involved, we will require the new company, organization or individual in possession of your Personal Information to continue to be bound by this Policy, or we will require such company, organization and individual to obtain your authorization and consent again.
(III) Public disclosure
We will disclose your Personal Information to the public only under the following circumstances:
1. We may disclose your Personal Information to the public with your explicit consent;
2. If we determine that you have violated laws and regulations, or have a material breach of the agreements with or regulations of DingTalk, or we intend to protect DingTalk’s and its Affiliates’ users or the general public from damages to their personal security, we may disclose your Personal Information in accordance with laws and regulations, including the relevant violation and measures taken by DingTalk against you.
(IV) Exceptions to obtaining prior authorization and consent for sharing, transferring and disclosing Personal Information
Unless otherwise stated in a country specific addendum, your Personal Information may be shared, transferred or disclosed to the public without your authorization and consent under the following circumstances:
1. National safety and national defense security are involved;
2. Public security, public health, or major public interests are involved;
3. Criminal investigation, prosecution, judgment and enforcement are involved;
4. For the purpose of protecting your or other individual’s life, property and other major lawful rights and interests, where it is hard to obtain your or such individual’s prior consent;
5. The Personal Information is disclosed voluntarily by you to the public;
6. The Personal Information is collected from the information disclosed through lawful channels, such as lawful news reports or information disclosure by government, and is already publicly available
Pursuant to laws, sharing and transfer of de-identified Personal Information (which cannot be recovered by the recipient to re-identify the subjects of such Personal Information) does not constitute a transfer or disclosure of Personal Information, and therefore it may be stored and processed without notice to you.
V. How we protect your Personal Information
We will take various precautions to protect your Personal Information so as to safeguard your Personal Information from loss, misappropriation and misuse, and from being accessed, disclosed, modified or destroyed without permission. In order to protect the safety of your Personal Information, we have established strict information security provisions and procedures, and have a professional information security team to implement the above precautions within the company.
DingTalk has established an industry-leading data security management system which centers on data and is implemented based on data life cycle, and has made efforts to improve the security of the entire system from multiple aspects, including organizational structure, system design, personnel management and product technology. Currently, our key information system has passed various certifications such as ISO27001 and classified security protection of information system (level III).
We will take reasonable and practical measures to avoid collecting irrelevant Personal Information to the maximum extent. We will retain your Personal Information only for the period necessary to achieve the purposes set forth in this Policy, unless it is necessary to prolong the retention period or permitted by law.
Given the fact that Internet environment is not completely secure, although we have those security measures in place, please bear in mind that there is no “perfect security measure” on the Internet, and we will use our best efforts to ensure the security of your information.
VI. Protection of minors
We attach great importance to the protection of information of minors. If you are a minor, we request that you:
1. ask your parents or guardian to read this Policy carefully,
2. use our DingTalk Services only with the consent of your parents or guardian;
3. provide us with a copy of your parent or guardian’s written consent to the collection of your personal information.
We will only use, share, transfer or disclose that Personal Information subject to laws and regulations and we will protect the Personal Information of minors in accordance with relevant national laws and regulations and this Policy.
VII. How we store and transfer Personal Information outside your country
Principally, your Personal Information collected by DingTalk shall be stored at DingTalk servers located in Singapore.
VIII. Information for EEA Residents Only
Legal Basis for Processing Personal Data
Our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.
However, we will normally collect Personal Information from you only (i) where we need the Personal Information to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so. In some cases, we may also have a legal obligation to collect Personal Information from you or may otherwise need the Personal Information to protect your vital interests or those of another person.
If we ask you to provide Personal Information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as of the possible consequences if you do not provide your Personal Information).
If we collect and use your Personal Information in reliance on our legitimate interests (or those of any third party), this interest will normally be to operate our platform and communicating with you as necessary to provide our services to you and for our legitimate commercial interest, for instance, when responding to your queries, improving our platform, undertaking marketing, or for the purposes of detecting or preventing illegal activities. We may have other legitimate interests and, if appropriate, we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided below.
Safeguards for Data Transfers
However, if you are a resident of the EEA, we have taken appropriate safeguards to require that your Personal Information will remain protected in accordance with this Policy. These include implementing the European Commission’s Standard Contractual Clauses for transfers of Personal Information between our group companies, which require all group companies to protect Personal Information they process from the EEA in accordance with European Union data protection law.
We retain Personal Information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
Data Protection Rights
If you are a resident of the European Economic Area, you have the following data protection rights:
1. If you wish to access, correct, update or request deletion of your Personal Information, you can do so at any time by contacting us using the contact details provided below.
2. In addition, you can object to processing of your Personal Information, ask us to restrict processing of your Personal Information or request portability of your Personal Information. Again, you can exercise these rights by contacting us using the contact details provided below.
3. You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided below.
4. Similarly, if we have collected and process your Personal Information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful processing grounds other than consent.
5. You have the right to complain to a data protection authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority.
The data controller of your Personal Information is [DingTalk (Singapore) Private Limited].
IX. How we update this Policy
Our Policy may change from time to time. Without your explicit consent, we will not reduce and/or restrict the rights you are entitled to under this Policy. We will publish any change to this Policy on DingTalk official website at www.dingtalk.com and, if changes are significant, we will also provide a more prominent notice (including using DingTalk to push a notification m4. essage to you, or by providing you a notice within a popup window on the DingTalk official website).
Significant changes to this Policy include but are not limited to the following:
1. our service pattern changes greatly, such as the purpose of dealing with DingTalk user’s Person5. al Information or our information processing method changes;
2. our control and organization structure changes greatly (for example there is a structural reorganisation, merger or acquisition);
3. our legal basis for processing DingTalk user’s Personal Information changes;
4. our internal departments change the security of its processing, its contact information or the complaints channel changes;
5. any DingTalk user information security impact assessment indicates that there is a high risk.
X. How to contact us
If you have any questions or concerns about this Policy and/or data processing of DingTalk, you may contact us via following email:
DingTalk (China) Information Technology Co., Ltd.
Addressee: DingTalk Data Protection Office
Address: Building No.5, DingTalk Park, 959 Gaojiao Road, Wuchang Street, Yuhang District, Hangzhou, P.R. China, 311100.
Generally, we will revert to you upon the receipt of your query within thirty (30) calendar days.
Last updated on: March 21, 2019