Hesai Privacy Policy

Updated by March 15, 2022
Effective Date: March 15, 2022

Hesai Technology Co., Ltd., its subsidiaries and affiliates (hereinafter referred to as “Hesai” or “we”) greatly respect your personal information and privacy (hereinafter referred to as You”). When you use our online products or services, we may collect, store, use and disclose your personal information in accordance with Hesai Privacy Policy (hereinafter referred to as “Privacy Policy”). Through this Privacy Policy, we will explain that during the use of our online products and services, the personal information we may collect and how we store, use and protect your personal information, etc. We will also explain how you can access, update, remove and protect your information. We are committed to protect any personal and/or privacy information by implementing well-established security protocols of relevant industries and applying appropriate security measures in compliance with any applicable laws and regulations.

This Private Policy applies to the online products or services we provide, including Hesai App, WeChat Mini Program, WeChat Official Account, official website, etc., except the products or services provided by any third parties through the above-identified online services and products.  Neither does this Privacy Policy apply to certain online products or services which we have set up separate privacy policies.

Before using our online products and/or services, we request that you carefully read and fully understand all terms of this Privacy Policy, especially those in bold print, to confirm that you fully understand our processing rules of your personal information and make the choices you deem appropriate. If you choose to use our products and/or services, you will be deemed to have fully understood and agreed to the entire contents of this Privacy Policy and to be bound by it. If you have voluntarily provided information, you consented to the collection, disclosure, transfer, storage and other uses of provided information as described in this Privacy Policy. You may revoke consent by providing a written notice to Hesai by using information provided in Section No. 11 “Contact Us” and we will cease using and processing your personal information after due confirmation and investigation.

WeChat Mini Program, WeChat Official Account, official website, etc. are platforms where we provide online products and/or services. This Privacy Policy explains how Hesai collects, uses and store your personal information and what rights you have, , which includes the following important aspects:

1)  Personal information refers to information that is recorded electronically or otherwise that identifies a specific natural person, either alone or in combination with other information to reflect the activities of a specific natural person, such as name, date of birth, identification number, personal biologicalidentifying information, address, contact details, communication records and contents, account number and password, property information, digital trails, health information, transaction information. You represent that the personal information you provide are true, legitimate, complete and valid.

2)  We will individuallyspecify on the types of personal information we collect and their purposes, so that you can understand the categories, reasons for use and collection methods of how specific personal information we collect for a particular feature.

3)  When you use certain functions, such as authorized login, login registration, consultation scheduling and event registration, we will collect sensitive information with your consent. Unless required by applicable laws and regulations to collect this information, refusal to provide this information will only prevent you from using specific features, but will not affect your normal use of other features of the platform.

4)  At present, Hesai does not proactively share or transfer your personal information to third parties outside its affiliates. If there are cases of sharing or transferring your personal information,or you needing us to share or transfer your personal information to third parties outside of our affiliates, we will directly confirm with you or via a third party that your consent has been given to the above actions. In addition, we will conduct risk assessments on providing information externally.

5)  At present, Hesai does not proactively obtain your personal information from third party sources other than Hesai’s affiliates and subsidiaries. If Hesai's business requires the use and processing of your information beyond the scope of your initial consent given to Hesai or a third party, we will obtain your updated consent. In addition, we will strictly abide by all relevant laws and regulations, especially not to obtain your personal information indirectly throughillegal channels.

6)  You can access and correct your personal information through the channels listed in this policy, or you can withdraw your consent, cancel your account and complain.

For more detailed information, please read the relevant sections in the following index:

1. Information we collect

2. Storage of information

3. Information security

4. How do we use the information

5. How do we use cookies and similar technologies

6. Information sharing, transferand disclosure

7. Your rights

8. Changes

9. Protection of minors

10. How personal information is transferred globally

11. Contact us

1. Information We Collect

During the use of Hesai’s services, Hesai may collect information that you provide, on your own initiative, or as a result of using the service, in order to provide and optimize our service, keeping your information secure:

1.1 When you register, we may collectyour name, phone number, password, and verification code. This information is collected to complete the registration of our platform. If you do not provide or consent to the collection of such information, you may not be able to use our personal information registration, SMS notification, etc.

1.2 When you use WeChat Mini Programto authorize login, we will collect phone number, nickname, profile picture, region, gender. This information is collected to quickly complete the authorized login of our platform. Without providing or agreeing to collect this information, you may not be able to use our authorized login service properly.

1.3 When you use the feature of event registration, we will collect yourlocation, name and phone number This information is collected for the purpose of completing the event registration quickly. Without providing or agreeing to collect this information, you may not be able to use our event registration service properly.

1.4 When you use theplatform of Hesai, to ensure your normal use of our services and maintain the normal operation of our services, and to improve and optimize our service experience and keep your information safe, we will collect information on how you access the network, access time and log information, which are the basic information that need to be collected to provide the services.

1.5 When you submit complaintsand suggestions or technical support needs, we will collect your name, phone number, company, job title, emailand detailed information. This information is collected for follow-up and verification of complaints or suggestions, conducting any subsequent service and satisfaction surveys. If you do not provide or agree to collect this information, you may not be able to properly use our feature of complaints and suggestions and to receive high-quality customer service.

In addition, in accordance with applicable laws and regulations and national standards, we may, WITHOUT your consent, collect and use the relevant personal information you provide for the following circumstances:

1)  Directly related to national and defense security, and other national interests;

2) Directly related to vital public interests such as public safety, public health, public information;

3) Directly related to criminalinvestigation, prosecution, trial and enforcement of judgments;

4) When the life, property and reputation of you and others need to be protected and it is extremely to obtain your consent;

5) Personal information disclosed to the public by you;

6) Collecting personal information from legally and publicly disclosed information, such as news reports, disclosure by government and other legal channels;

7) Necessary use and processing to perform contracts with you or to act upon your request;

8) Necessary use and processing to maintain safe and robust operation of the products or services provided, such as the detection and treatment of bugs in the products or services;

9) Necessary use and processing to carry out legitimate press reporting;

10) Necessary use and processing to carry out statistical or academic research in the public interest. When the results of such statistical and academic research are provided to an external source, any personal information included in the results has been subject to de-identification treatment;

11) All other circumstances provided for in laws and regulations.

Please understand that the features and services we provide to you are constantly updated and evolving. When your updated consent is needed, we are allowed to obtain your consent by providing information about the content, scope and purpose of the information collection through emails, page prompts, interactive processes and website announcements.

2. Storage of Information

2.1 Where information is stored

In compliance with laws and regulations, the personal information of users collected within China will be stored within Chinese territory.

2.2 Duration of information storage

In general, we will only keep your personal information to achieve our purposes for a necessary period of time, such as name, mobile phone number. When our products or services cease operation, we will notify you through push notifications, announcements, etc., and remove or anonymize your personal information within a reasonable period.

3. Information Security

3.1 We strive to secure the information of our users against loss, improper use, unauthorized access or disclosure. And we will use various security measures to secure information within a proper level of security. For example, we use methods such as encryption and anonymization, to protect your personal information. While doing our best to prevent the leakage of your personal information, we have been enhancing the software security capabilities installed on your device side. For example, we will encrypt certain parts of your information locally on your device for secure transmission. We will conduct malicious code detection, vulnerability detection, and repair prior to the release of the installed software. We have also established specialized management systems, processes and organizations to ensure information security. For example, we strictly restrict the range of people who have access to information, requiring compliance with confidentiality obligations, and conduct audits. In the events of security incidents such as personal information leakage, we will initiate contingency plans to prevent further expansion of such incidents and inform you through push notifications, announcements, etc.

3.2 While we have taken the necessary steps to protect your personal information, given the limitations, relativity and unpredictability of cyber security technology, such as computer viruses, network intrusions and attack disruptions, you acknowledge and agree that: Hesai, under no circumstances, shall be responsible for any damage or loss caused by the above-identified actions or any actions which Hesai could not reasonably predict or control (for example,  equipment maintenance of the information network, connection failures of the information network, failure of computers, communications or other systems, power failure, strikes, labor disputes, riots, uprisings, shortages of materials and production capacity, fires, floods, storms, explosions, wars, government actions, orders from judicial administrative organs, third-party causes, etc.).  Regardless, we will try our best to reduce the damages and impacts you may experience.

4. How We Use the Information

We may use the information gathered through certain features for our other services. For example, we might use the information we gather when using one of our features or services to provide you with specific content, including but not limited to display ads (which you can learn more in the ad page), information security tips for what you've read, indirect user profile based on feature tags for providing more precise and personalized services and content.

To ensure the security of our services and help us better understand the operation of our applications, we may record relevant information. For example, the frequency of your application, crash data, overall usage, performance data, and the source of your applications. We will not combine the information we store in the analysis software with any personal identity information you provide in your application. If you notice a combination of such information, please notify us immediately.

At present, Hesai may provide information to third parties authorized by relevant regulators for information authenticity verification or service delivery. You acknowledge and agree with above actions. When you use certain features to trigger the messaging of Hesai, to successfully receive relevant text messages, we will share your mobile phone number with a third-party SMS operator. We will conduct a risk assessment of providing information externally and ensure that services provided by the above third-party institutions are legally compliant.

Your personal information may be inadvertently collected or used by us without your consent, you acknowledge and agree that Hesai is allowed to inform you and obtain your consent within a reasonable period after the inadvertent collection and use are discovered by us.

5. How to Use Cookies and Similar Technologies

We or our third-party partners may collect your information by placing secured cookies and related technologies to provide you with a more personalized user experience and services. We will strictly require third-party partners to comply with the relevant provisions of this policy.

You can also set up and manage cookies through browser. But please note that if you deactivate cookies, you may not have the best service experience and some services may not work properly.

6. Sharing, Transfer and Public Disclosure of Information

At present, other than our affiliates and subsidiaries, we do not proactively share or transfer the personal information you provide to third parties. If there are situations where you or your personal information is shared or transferred, or if you need us to share or transfer your personal information to third parties, we will confirm that a third party has your consent to the above-mentioned actions.

We will not publicly disclose the personal information we collect. If public disclosure is necessary, we will inform you of the purpose, the type of information disclosed and the sensitive information that may be involved. With your consent, we will also conduct a risk assessment of providing information externally.

As our business continues to grow, we might go for mergers, acquisitions, asset transfers, bankruptcy, liquidation, etc. We will require new controllers to continue to protect your or your personal information in accordance with laws and regulations and not less than the standards required by this policy.

In addition, according to relevant laws and regulations and national standards, we may share, transfer or disclose personal information publicly without your prior authorization in the following cases:

1)  Directly related to national and defense security, and other national interests;

2) Directly related to vital public interests such as public safety, public health, public information;

3) Directly related to criminal investigation, prosecution, trial and enforcement of judgments;

4) When the life, property and reputation of you and others need to be protected and it is extremely to obtain your consent;

5) Personal information disclosed to the public by you;

6) Collecting personal information from legally and publicly disclosed information, such as news reports, disclosure by government and other legal channels;

Other circumstances provided for in laws and regulations.

7. Your Rights

In accordance with the relevant Chinese laws, regulations, standards and prevailing practices of other countries and regions, you have the following rights to your personal information:

7.1 Access to Your Personal Information

You may obtain access to your personal information via a registered account with Hesai’s online products or services, except for exceptions under laws and regulations.

If you are unable to access this personal information in the above way, please contact us through the contact information given in section 11.

7.2 Correct Your Personal Information

You have the right to make corrections when you find out that there is an error in your personal information.

If you are unable to correct your personal information in the above way, please contact us through the contact information in section 11.

7.3 Delete Your Personal Information

You can request to delete personal information in the following cases:

1) If our processing of personal information violates laws and regulations;

2) If we collect and use your personal information without your consent;

3) If our processing of personal information violates this Privacy Policy;

4) If you no longer use our products or services or have closed your account;

5) If we no longer provide you with products or services.

If we decide to respond to your deletion request, we will also notify the entities that have obtained your personal information from us to delete it in a timely manner, unless otherwise provided by the laws and regulations, or these entities receive your independent authorization.

Once your information has been removed from our services, we may not immediately delete the corresponding information from the backup system, but will delete the information when the backup is updated.

7.4 Change the Scope of Your Authorized Consent

Each business function requires some basic personal information to complete. For the collection and use of additional personal information, you can give or withdraw your authorization consent at any time.

You can change your authorization consent through contact information given in section 11.

When you retract your consent, we will cease any further processing of the appropriate personal information. But the retraction of your consent does not impact the legality of any previous processing of personal information based on your authorization.

7.5 Response to Your Above Request

For security purposes, you may need to provide a written request or otherwise to prove your identity. We may ask you to verify your identity before processing your request. If you are not satisfied, you can also make a complaint through the contact information given in section 11.

In principle, we will not charge fees for your reasonable requests, but we way charge fees as appropriate for repeated requests that exceed reasonable limits. We may reject the following requests: baseless and repeated requests, requests that require extraordinary technical effort (for example, the need to develop new systems or fundamentally change current practices), requests that pose risks to the legitimate interests of others, or highly impracticable requests (for example, involving information stored on backup tapes).

We will not be able to respond to your request in the following cases:

1) Related to the legal compliance of the controller of personal information;

2) Directly related to national and defense security, and other national interests;

3) Directly related to vital public interests such as public safety, public health, public information;

4) Directly related to criminal investigation, prosecution, trial and enforcement of judgments;

5) The controller of personal information has sufficient evidence to show that the subject of personal information is subjectively malicious or abusive;

6) When the life, property and reputation of you and others need to be protected and it is extremely to obtain your consent;

7) Responding to the request will cause serious harm to you or the legitimate rights and interests of other individuals or organizations;

8) Involving trade secrets.

8. Changes

 You acknowledge and agree that changes of the content of this policy can be made to you through any proper means, including email, push notifications, pop-ups, online publication, etc. If you do not agree to the new modifications, please contact us in time or stop using the services agreed upon in this policy immediately. If you choose to continue with the services, you are deemed to fully agree and accept the new modifications. If changes in objective circumstances and business guidelines cause us to interrupt or discontinue our services, we will promptly notify you.

9. Protection of Minors

We attach great importance to the protection of personal information of minors. According to the relevant laws and regulations, if you are a minor under the age of 18, you should review and agree to this Privacy Policy with your legal guardian, and you should obtain prior written consent from legal guardians before using the platform of Hesai. If you are the guardian of a minor, please find our contact details given in section 11 when you have questions about the personal information of the minor under your custody.

10. How Personal Information Is Transferred Globally

In principle, the personal information we collect and generate within the territory of the People’s Republic of China will be stored in the territory of the People’s Republic of China.

Since we provided our products or services through resources and servers around the world, this means that your personal information may be transferred to, or accessed from, the jurisdictions outside of the country/region in which you use the product or service, with your authorized consent.

Such jurisdictions may have different data protection laws, or even no such laws. In such cases, we will ensure that your personal information is adequately protected to the same extent as in the People's Republic of China. For example, we may request your consent for cross-border transfers of personal information or implement security measures such as data de-identification prior to cross-border data transfers.

11. Contact Us

If you have complaints and reports about network information security, or any questions, comments and suggestions regarding this policy or your information, contact us by:

Email: legal@hesaitech.com

We will review the issues as soon as we receive your feedback and respond within 15 days after successfully verifying your user identity.

Copyright © 2024 Hesai Group. All Rights Reserved.

crosschevron-right