Privacy Policy

How FLH Co., Ltd. collects, uses, discloses, and protects your personal data across Ferqo devices, software, website, and customer support.

Versionv1.1Effective2026-07-01

Welcome to the Ferqo App, owned and operated by FLH Co., Ltd. We respect and are committed to protecting your personal privacy in compliance with applicable laws and regulations. This Policy explains how we collect, use, disclose, and protect your personal data.

By using this service, or by your parent or guardian consenting to the provision of your personal data to the Company, you (or your guardian) are deemed to have read and agreed to this Policy.

01

Scope of Privacy Policy

This Policy applies to the Company’s collection, processing, and use of personal data when you use the Company’s smart home products and services, including devices, software, the official website, and customer support services. You are not required to provide personal data, but failure to do so may result in certain services being unavailable or the Company being unable to respond to your requests.

02

Collection, Processing, and Use of Personal Data

When you visit our website or use service features, we may ask you to provide necessary personal data depending on the nature of the service. Such data will only be processed and used within the scope of specific purposes; without your written consent, it will not be used for other purposes.

2.1 Directly Collected Personal Data

  • Account registration information. When you register an account on the App, we collect your name, email address, password, or other authentication information you provide.
  • Contact information. When you contact us via service email, online customer support, surveys, or phone, we retain your name, email, contact details, and the time of interaction.
  • Service usage information. When you use specific features of the App, such as smart home device control or scene settings, we may collect data you actively input or generate.

2.2 Automatically Collected Information

  • Device information. We automatically collect device-related information, including but not limited to device model, operating system version, unique device identifier (UDID), IP address, carrier information, language settings, and screen resolution.
  • Usage behaviour data. When you browse or use the App, our servers record your IP address, usage time, browser type, browsing and click history, frequency of in-App feature use, and App crash logs. This information is used solely for internal service optimization, feature improvement, troubleshooting, and market trend analysis, and is not disclosed externally.
  • Cookies and tracking technologies. To provide the best service experience, the App may write and read Cookies or use similar tracking technologies on your device. Functional Cookies (login status, language preferences) are enabled by default. Tracking technologies used for marketing purposes are disabled by default and will only be activated upon your explicit consent. You may raise your privacy settings in your browser or device settings to reject all Cookies, but this may cause some App features to not function properly.

2.3 Purposes of Data Processing and Use

  • To provide, maintain, and improve the App and related services.
  • To process your inquiries, orders, and requests.
  • To provide customer support and technical assistance.
  • To analyze user behaviour and preferences in order to optimize service content and user experience.
  • For internal statistical analysis, market research, and product development.
  • For marketing and promotional purposes, with your consent.
  • To comply with legal regulations or government agency requirements.
  • To provide accurate services, we conduct statistical analysis of survey responses and may publish statistical data or descriptive text that does not involve specific individuals’ data.

2.4 De-Identified Data

The App de-identifies the collected device information and usage behaviour data — for example, by removing personal identifiers and aggregating data — so that it cannot be traced back to a specific individual. De-identified data will primarily be used for statistical analysis, trend research, and service optimization, and may be shared with third parties.

2.5 Statutory Purpose Codes and Legal Basis for Collection

The App collects, processes, and uses personal data based on the following legal grounds and statutory specific purposes as defined in the Enforcement Rules of the Personal Data Protection Act.

  • Code 069 — Contractual and similar legal relationship matters. Processing necessary for the provision of core services such as device control, account management, and OTA firmware updates.
  • Code 090 — Consumer and customer management and services. Customer inquiries, technical support, and after-sales services.
  • Code 040 — Marketing. Sending product updates and promotional information with your explicit consent. Consent is obtained via an opt-in checkbox, unchecked by default, during App onboarding or account registration. You may withdraw consent at any time by emailing [email protected] or adjusting settings in the App.
  • Code 063 — Collection, processing, and use of personal data by non-public entities pursuant to statutory obligations. Compliance with the Personal Data Protection Act and other applicable laws.

2.6 IoT Device Telemetry Data

The smart home hub automatically collects and uploads the following telemetry data during operation.

  • Data collected. Device connection status, firmware version number, feature usage records (scene trigger counts, automation execution records), device error codes, and crash reports.
  • Collection frequency. Device status is reported every 30 seconds; error codes or status change events are uploaded in real time; diagnostic logs are uploaded once upon device restart or failure.
  • Purpose of collection. Used for providing remote control functionality, firmware update notifications, fault diagnosis, and overall service quality monitoring.
  • Data processor. Telemetry data is processed by FLH Co., Ltd. and stored on Google Cloud Platform (Google LLC, USA). Crash reports are additionally processed via Google Firebase. See Section 5 for details.
  • The smart home hub does not have environmental sensing capabilities — no temperature, humidity, image, audio, or other sensors — and does not collect any environmental data.

2.7 Personal Data Retention Periods

  • Account information. For the duration of the account; fully deleted within 30 days of account deletion.
  • Device telemetry and usage logs. Retained for 90 days after collection, then automatically deleted.
  • Customer service records. Retained for 2 years after case closure.
  • Data required by law. Retained for the period required by applicable laws — for example, e-commerce transaction records retained for 5 years.

Data exceeding the retention period will be irreversibly deleted or de-identified in accordance with security standards.

03

Data Protection

The App employs information security measures and equipment such as firewalls, antivirus systems, intrusion detection systems, and TLS encrypted transmission, with strict access controls to ensure that only authorized personnel can access personal data. All relevant personnel have signed confidentiality obligations; violations will be handled in accordance with the law.

If business needs require the entrustment of personal data processing to a third party, we will require and supervise them to comply with confidentiality and information security obligations.

Cross-border data transfer

Some personal data may be stored or processed on overseas cloud servers. The cloud infrastructure currently used is located in the United States, provided by Google Cloud Platform (Google LLC). The Company has entered into Data Processing Agreements (DPA) and Standard Contractual Clauses (SCC) with the relevant service providers, requiring them to comply with equivalent or higher data protection standards to ensure adequate protection of personal data.

Data security incident notification

In the event of a personal data breach, alteration, or loss, the Company will notify the competent authority after investigation, where required by law, and, as appropriate, inform affected users of the incident details and countermeasures taken via App notification or email within a reasonable timeframe.

04

External Website Links

This website may provide links to other websites. Such third-party websites are not governed by this Policy; please refer to their respective privacy policies.

05

Sharing Personal Data with Third Parties

Except as required by law or contract, we will not provide, exchange, rent, or sell your personal data to third parties without your written consent. However, in the following circumstances, processing or disclosure may occur within the necessary scope.

  • With your written consent.
  • As expressly required by law.
  • To eliminate dangers to your life, body, freedom, or property.
  • For statistical or academic research in cooperation with government agencies or academic institutions for the public interest, where the data cannot identify specific individuals.
  • When your actions violate the Terms of Service or may damage the rights of the App or other users, or for the purpose of protecting your rights.
  • Where outsourced contractors must process personal data to provide services to you, such as payment services, data analysis services, or cloud storage services. In such cases, we will enter into confidentiality agreements with the outsourced contractors and require them to process your personal data only within the scope instructed by the Company.
  • Key outsourced service providers. The App’s primary outsourced service providers include, but are not limited to, Google Cloud Platform / Google LLC (cloud computing and storage, USA) and Google Firebase (push notifications and app crash analytics, USA). These providers process personal data solely on the Company’s instructions, may not use it for other purposes, and have signed data processing and confidentiality agreements.
06

Amendments to the Privacy Policy

This Policy may be revised as needed. Revisions will be published within the App or on the official website and will take effect immediately. We recommend that you review it regularly for the latest content. If you continue to use the App services after revisions to this Policy, you are deemed to have read and agreed to the revised Policy.

07

Your Rights

Pursuant to the Personal Data Protection Act, you may exercise the following rights with respect to your personal data.

  • To inquire or request access.
  • To request a copy.
  • To request supplementation or correction.
  • To request cessation of collection, processing, or use.
  • To request deletion.

To exercise the above rights, please contact us through the contact information provided in the App. To ensure data security, we may require you to provide identity verification. The Company will respond to your request within 30 days of receipt; in complex cases, this may be extended to 60 days, but you will be notified of the reason for extension within the initial 30 days.

  • Right to object to use for marketing purposes (Article 20). If the Company uses your personal data for marketing purposes, you may object at any time, and the Company will immediately cease such use. Please apply through the App settings or by emailing [email protected].
  • Right to file a complaint with the competent authority. If you believe the Company’s processing of your personal data violates the Personal Data Protection Act, you have the right to file a complaint with the competent personal data protection authority, currently the National Development Council.
08

Protection of Minors

If you are under twenty years of age, you may use this Service only after your parent or guardian has read and agreed to all the contents of this Policy. By continuing to use this Service, you represent that your parent or guardian has consented.

The Company does not knowingly collect personal data from children under the age of 13. If the Company discovers that personal data has been collected from a child under 13 without verified parental consent, it will promptly delete such data and suspend the provision of services to that child.

09

Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us through the following means.

Data Protection Officer

For privacy-related inquiries or to exercise your data rights, contact our designated DPO at [email protected].

Customer Service

[email protected]

Company Address

FLH Co., Ltd.
9F, No. 35, Lane 11, Guangfu North Road, Songshan District, Taipei City 105, Taiwan

Thank you for your trust and support of the Ferqo App.