This policy explains how WINGSTART HONG KONG LIMITED collects, uses, stores, shares, and protects personal information when you use the Nafnti App, website, smart bird feeders, cameras, AI bird recognition, cloud storage, and related services.
We adhere to the principles of data minimization, purpose limitation, transparency, fairness, security, and storage limitation. Please read this policy carefully before using our services.
Under the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the Company acts as the "data user" controlling the collection, holding, processing, or use of personal data. Under the GDPR, UK GDPR, or other applicable laws, the Company generally acts as the data controller.
The Company commits to embedding data protection measures at the design stage of products and services in accordance with Privacy by Design principles, and performing Data Protection Impact Assessments (DPIAs) for high-risk processing activities where required by applicable laws.
This Policy applies to the Nafnti App, official website, account system, smart bird feeders and camera devices, cloud storage, AI bird recognition, device sharing, customer support, and related data processing activities.
Third-party platforms or services that process information independently for their own purposes are governed by their respective privacy policies, such as the Apple App Store, Google Play, and third-party websites visited via user redirection.
This Policy applies to users in the following jurisdictions: the United States (including state privacy laws), Canada (including PIPEDA and Quebec Law 25), the United Kingdom (UK GDPR), the European Union and European Economic Area (GDPR), Hong Kong SAR (PDPO), and other markets with applicable privacy regulations.
During device setup, the App may process the Wi-Fi network name (SSID) and password to connect the device to your chosen network. We use this information solely to complete the connection and troubleshoot necessary pairing issues; it is never used for advertising or unrelated purposes. Such information may be processed on the device side or via encrypted channels by technical service providers; actual storage mechanisms are subject to real-time setup page instructions and technical implementations.
Apple and Google handle the processing of payment credentials directly. We do not obtain or store complete credit card numbers, CVVs, or app store account passwords.
Depending on applicable regional privacy laws, the following categories may constitute "sensitive personal information" or "special category data":
Granting operating system permissions does not mean all associated data is automatically uploaded to our servers. We process only the minimum necessary information required for specific functions and technical implementations. Users may revoke permissions at any time via system settings.
Terminology for legal bases varies across jurisdictions. We rely on valid legal bases under applicable laws. For users in the EU, UK, and Canada, processing is grounded in GDPR Article 6, UK GDPR Article 6, and PIPEDA Principle 4.3 requirements.
Compatible devices analyze bird visits locally on the edge device and may transmit species labels, confidence scores, and event data to the App or servers. When cloud storage is enabled, event-triggered video snippets or snapshot images may be stored in the cloud.
AI bird recognition is intended for nature observation and media curation; it is not used to make automated decisions that produce legal or similarly significant effects on individuals. AI results may contain inaccuracies, and users may submit feedback where available.
Under GDPR Article 22 and Quebec Law 25 Section 12, you have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects. Our AI bird recognition features do not constitute such decisions.
If user-generated media is used to train or substantially enhance foundational AI models in the future, we will provide separate notice and obtain necessary consent or offer an opt-out mechanism as required by applicable laws.
Prior to launching significant new AI capabilities, we evaluate the need for and execute Data Protection Impact Assessments (DPIAs) in compliance with applicable legal frameworks.
Camera devices may inadvertently capture visitors, neighbors, passersby, or other individuals. The account holder assumes primary responsibility for device placement, field of view adjustments, and compliance with local notice requirements.
Users should avoid directing cameras toward private spaces of third parties, post physical notices, obtain necessary consents, or adjust camera angles where required by local laws. Upon receiving legitimate third-party privacy requests, we may request the device owner's cooperation to remediate concerns.
Under GDPR Article 10 principles, if identifiable third-party personal data is incidentally recorded, we will delete or de-identify such content within a reasonable timeframe upon becoming aware, unless retention is mandated by law.
To enforce the rule of "one 7-day free trial per eligible user account," we retain minimal anti-abuse logs, such as irreversible hashes of account identifiers, redemption timestamps, entitlement status, and relevant device/transaction tokens.
Even if an account is deleted, these minimal records may be retained for the duration of the free trial program and a reasonable closing period to prevent repeated claims, fraud, and disputes. These logs are never used for advertising or restoring deleted account content.
In-app purchases processed via the Apple App Store or Google Play are handled directly by the respective platforms regarding payment credential processing, charges, auto-renewals, and refunds. We receive transaction tokens and subscription state data solely to validate entitlements.
Deleting a Nafnti account or uninstalling the App does not automatically cancel platform subscriptions. Users must cancel auto-renewals through their Apple Account or Google Account settings.
We share information only as necessary to deliver services, fulfill legal duties, or upon obtaining authorization. Recipients may include:
We require service providers (processors) acting on our behalf to process data strictly according to our instructions, execute Data Processing Agreements (DPAs), and maintain reasonable security measures.
We do not sell your personal information for monetary consideration nor share it for cross-context behavioral advertising without explicit consent or statutory authorization. Data transfers to binding contract vendors do not constitute a "sale" or "sharing" under these terms. Definitions under California CCPA/CPRA are further detailed in Section 20.
Our services integrate technical SDKs from Apple, Google, Amazon Web Services, device connection vendors, push gateways, email tools, customer service platforms, and crash reporting utilities. We maintain an up-to-date SDK inventory detailing provider names, purposes, collected data types, and privacy policy links within the App or official website.
Before integrating new third-party SDKs that materially alter data processing practices, we will update relevant disclosures and obtain consent where required by applicable laws.
For third-party integration services involving cross-border data transfers, we mandate compliance mechanisms aligned with Section 13.
The Company is incorporated in Hong Kong SAR. Primary cloud servers may be located in the United States, while device technical operations and customer support may be supplied by service providers operating across various global regions. Consequently, your personal information may be transferred across borders.
We implement one or more of the following transfer mechanisms pursuant to applicable laws:
You may request a copy or summary of applicable transfer mechanism safeguards by contacting our privacy email.
As of the last update date, the Company has not received binding government orders or prohibitions restricting international data flows. Should GDPR/UK GDPR Article 27 apply, designated representatives will be appointed and updated herein prior to initiating covered processing operations.
We retain personal information only for the minimum period necessary to fulfill processing purposes, comply with statutory obligations, or protect legitimate business interests.
Upon expiration of retention limits or fulfillment of processing purposes, data is securely erased or irrevocably anonymized.
In the event of a security incident posing a high risk to the rights and freedoms of individuals, we will promptly execute the following remedial actions:
We deploy technical and organizational measures to safeguard personal information, including:
Despite these safeguards, internet transmissions cannot be guaranteed to be 100% secure. While absolute security cannot be guaranteed, we commit to executing immediate remediation upon discovering security threats.
Depending on your jurisdiction, you may hold the following privacy rights:
You may exercise these rights through App settings, by emailing nafntiapp@gmail.com, or using the contact options in Section 26. We respond to verified requests within 30 days (GDPR/UK GDPR) or 45 days (CCPA). Identity verification may be required to protect user security.
As the "data user" under the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the Company accords Hong Kong users the following statutory rights:
If you have inquiries regarding our data handling, contact our Data Protection Officer; Hong Kong users may also file complaints with the Privacy Commissioner for Personal Data (PCPD).
For users located in the European Economic Area (EEA) and the UK, processing operations are governed by the EU GDPR and UK GDPR. Legal bases relied upon are outlined in Section 6.
We deploy automated tools such as AI bird recognition. Under GDPR Article 22 and UK GDPR, you maintain rights to:
Safeguards applied to data transfers outside the EEA and UK are detailed in Section 13.
EEA residents may lodge complaints with their local Data Protection Authority (DPA). UK residents may contact the Information Commissioner's Office (ICO).
California consumers hold the following specific rights:
Submit California privacy requests via nafntiapp@gmail.com with the subject line "California Privacy Rights Request." We will not discriminate against you for exercising your rights.
Under the CPRA, we acknowledge and fulfill verified requests within 45 days. If an extension up to an additional 45 days is required (totaling 90 days), we will notify you of the delay and cause within the initial 45-day window.
Comprehensive privacy statutes exist in multiple US states. Residents of covered states may exercise rights comparable to CCPA/CPRA provisions:
Residents of these states may submit requests to nafntiapp@gmail.com specifying their state of residence and request type. Responses will be delivered within statutory windows (typically 45 days).
State privacy laws strictly forbid discrimination based on right enforcement. If your state is not explicitly listed, you may contact us to verify applicable rights.
Pursuant to regulations in Colorado, Connecticut, California, and other applicable states, we honor recognized Universal Opt-Out Signals. When your browser or device broadcasts a recognized opt-out signal (such as Global Privacy Control, GPC), we process it as a valid request to opt out of data sales, sharing, and targeted advertising.
To exercise your right to opt out of personal data sales or targeted sharing, you may:
For California minors under 16 years of age, affirmative double opt-in authorization is required before collecting, selling, or sharing personal data.
For users located in Canada, data handling complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), and Quebec residents are additionally protected under Quebec Law 25.
If you reside in a jurisdiction not explicitly named in this Policy, we nonetheless abide by applicable mandatory local data protection regulations. You may submit complaints to local supervisory bodies or direct rights requests to us via Section 26 channels, which we will address in harmony with cross-jurisdictional legal requirements.
The Nafnti App and smart bird feeder products are not marketed to or intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are a parent or legal guardian and discover that your child has provided us with personal information without consent, please contact us via our privacy email for prompt deletion.
Under the US Children's Online Privacy Protection Act (COPPA) and state laws, verifiable parental consent is mandatory prior to collecting data from children under 13 (or 16 depending on state jurisdiction).
Under GDPR Article 8, processing data of children under 16 (which member states may lower down to 13) requires parental consent. The age limit in the UK is 13.
Our official website and App services deployment may utilize cookies and similar tracking tools to support:
Non-essential cookies require explicit opt-in consent upon your initial visit. You may revoke consent or clear cookies at any time via your browser controls.
Under the ePrivacy Directive and UK PECR regulations, reading or writing non-essential device storage requires prior consent. Integrated third-party SDKs may deploy separate cookies or identifiers as detailed in Section 12.
We reserve the right to modify this Privacy Policy periodically. Material changes will be communicated in advance through in-app notices, registered email alerts, or web announcements.
Where updates materially diminish user rights or broaden data processing scopes, we will seek renewed explicit consent as mandated by law.
Continued use of our services following policy updates signifies acceptance of the revised terms, except where explicit consent renewal is legally required.
If you have questions, privacy rights requests, or complaints regarding this Privacy Policy, please contact us via:
Email: nafntiapp@gmail.com
If you remain unsatisfied with our response, you maintain the right to lodge formal complaints with appropriate supervisory authorities:
When engaging with us as an enterprise partner (such as distributors, agents, OEMs, or technology collaborators), we may process business contact information, contracts, order records, and tax details. These records constitute commercial data rather than consumer personal data, though business contact details contained therein are protected under applicable terms.
Personal information of business contacts (names, titles, email addresses, phone numbers) is safeguarded under this Privacy Policy. Contacts maintain applicable rights outlined in Section 17.
Enterprise clients may lodge privacy requests via designated account managers or our official privacy email address.
Commercial data is safeguarded under Section 16 security protocols, and breach notifications are managed pursuant to Section 15. In the event of an enterprise data compromise, contractual contact points will be notified promptly.
Upon termination of commercial partnerships, enterprise data is returned, purged, or anonymized in accordance with contract terms, save for statutory records retained pursuant to Section 14.
When acting as a data processor on behalf of enterprise clients, formal DPAs will be executed defining processing boundaries, data scope, security benchmarks, and termination clauses.
We respect partner intellectual property and trade secrets. Proprietary technical documentation, operational strategies, and business workflows shared during collaboration remain strictly confidential and will never be utilized for competitive purposes.
Except in cases of gross negligence or willful misconduct, our total liability for enterprise service claims is capped at the total fees paid by the client in the preceding 12 months or contract value, whichever is lower. Statutory indemnification for third-party claims arising from legal breaches will be handled per contract terms.
Enterprise point-of-contacts retain all individual rights under Section 17. Additionally, enterprise clients maintain rights to:
We disclose user data to government or law enforcement agencies only when required by valid legal process. We commit to:
Unless prohibited by law or valid court gag orders, we strive to notify affected users of government data demands promptly, enabling them to seek protective legal remedies.
When handling cross-border law enforcement access demands, we:
As of the last update, primary cloud databases are hosted in the United States. Auxiliary technical and customer support operations are conducted out of Hong Kong SAR, the United States, and other global vendor locations. Storage configurations are periodically evaluated to meet operational and regulatory demands.
Certain nations enforce mandatory data residency laws requiring local data storage. We monitor global localization mandates continuously; as operational footprints expand into covered regions, local storage architectures will be deployed accordingly.
This Policy is governed by the laws of Hong Kong SAR. Unless mandatory laws provide otherwise, disputes arising from this Policy or data processing shall first be addressed through good-faith negotiation. Unresolved disputes shall be submitted to the jurisdiction of courts in Hong Kong SAR.
Users in the EU, UK, US (California), and Canada retain supplementary rights under local mandatory statutes and may lodge complaints with local data protection regulators (see Section 26).
If any provision herein becomes invalid or unenforceable due to legal changes, such provision shall be deemed modified to the minimum extent necessary to achieve validity, while remaining provisions continue in full force. Policy terms will be updated periodically to maintain regulatory alignment.
This appendix serves internal legal review and version maintenance purposes. Statutory user rights are defined strictly by effective mandatory laws in your local jurisdiction.