1. Scope and controller
This Privacy Policy applies to:
- the corporate website dikurooms.com (including all sub-pages such as
/services.html, /culture.html, /news.html, /contact.html); and
- the mobile applications published by DIKUROOMS Trading Co., Limited on the Google Play Store and the Apple App Store.
The data controller responsible for the processing of your personal data under this Policy is:
DIKUROOMS Trading Co., Limited
Rm F(B22) 2/F FREDER CTR 3 MOK CHEONG ST
To Kwa Wan, Kowloon, Hong Kong SAR
Email: support@dikurooms.com
If you are in the European Economic Area (EEA), the United Kingdom (UK) or Switzerland, this entity is also your controller under the General Data Protection Regulation (GDPR) and the UK GDPR. Where local law requires, we additionally rely on locally appointed representatives — please contact us for details.
2. Definitions
For the purposes of this Policy:
- Personal data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
- Controller means the entity that determines the purposes and means of the processing (DIKUROOMS).
- Processor means an entity that processes personal data on the controller's behalf (e.g. a hosting or email provider).
- User means any individual accessing the website or installing/using our apps.
- Child means a person under the age defined by the law of their place of residence (see § 12).
- SDK means a software development kit integrated into our apps (most often an advertising SDK listed in § 8).
- Advertising identifier means a device-level identifier used by ad partners for ad selection and measurement — the Google Advertising ID (GAID) on Android and Apple's Identifier for Advertisers (IDFA) on iOS.
- EEA means the European Economic Area.
- UK means the United Kingdom of Great Britain and Northern Ireland.
- California means the State of California, USA.
3. Data we collect
We collect the following categories of data, depending on how you use our Services:
Identifiers
- Name, email address, company, job title (when you submit a contact or inquiry form).
- IP address, browser user agent, referrer, device and operating-system identifiers.
- Mobile-app identifiers: GAID (Android), IDFA (iOS), app instance ID, push-notification token.
Commercial information
- The inquiry topic and message body you choose to send us.
- Order, quote or service-request metadata you provide.
Internet / network activity
- Pages visited, time on page, scroll depth, referrer URL, timestamps.
- Search terms you used to reach our site.
Approximate location
- City- and country-level location inferred server-side from your IP address. We do not collect precise GPS coordinates from the website; the mobile apps do not request precise location unless explicitly required by a feature you opt into.
Mobile-app telemetry
- App version, build number, OS version, device model, locale, crash logs and diagnostic traces.
- Ad events: impression, click, completion, reward-grant, mediation waterfall outcomes.
We do not knowingly collect government-issued identifiers (passport, national ID), precise geolocation, biometric data, health data, sexual orientation, racial or ethnic origin, religious beliefs, or financial account credentials.
4. How we collect data
Directly from you
- When you submit the contact form on
/contact.html or send us an email.
- When you create an account or invitation in one of our mobile apps.
Automatically from your device
- Cookies and similar storage on the website (see § 13).
- Server logs captured by our hosting provider.
- Mobile-app SDKs that initialize at app launch to deliver and measure ads (see § 8).
From partners
- App-store partners (Apple, Google) provide basic install, crash and aggregate usage statistics.
- Ad networks return auction results, ad-rendering events and aggregated performance metrics (see § 8).
5. Legal basis (GDPR / UK GDPR Art. 6)
For users in the EEA and the UK we rely on the following lawful bases under Article 6 of the GDPR / UK GDPR:
- Consent (Art. 6(1)(a)) — for non-essential cookies, ad personalization, and marketing emails. You may withdraw consent at any time without affecting prior lawful processing.
- Performance of contract (Art. 6(1)(b)) — to respond to an inquiry, deliver a quote, or fulfil an order you have placed.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, customs, accounting, record-keeping and law-enforcement obligations.
- Legitimate interests (Art. 6(1)(f)) — to keep the Services secure, prevent abuse, and produce internal aggregate reports. We conduct and re-test a balancing on a case-by-case basis and offer an objection mechanism (see § 16).
Where we rely on consent, the cookie banner on our website or the in-app consent prompt collects it. You can change your choice at any time.
6. How we use data
- To respond to your inquiries and provide customer support.
- To operate, maintain, secure and improve the website and the mobile apps.
- To select, render and measure advertising (see § 8 and § 9).
- To produce aggregated, de-identified analytics.
- To comply with applicable law and enforce our Terms.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you, and we do not build user profiles for advertising beyond what the ad partners listed in § 8 do on their own behalf.
7. Sharing and disclosure
Service providers (processors)
We share personal data with vetted service providers acting as processors on our behalf, including:
- Hosting and content delivery.
- Email and customer-support tools.
- Privacy-respecting analytics.
- Advertising SDKs listed in § 8 (each acts as an independent controller for the data they receive).
Legal
We may disclose personal data when required by law, valid legal process, or to protect the rights, property or safety of DIKUROOMS, our users or others.
Business transfers
If DIKUROOMS undergoes a merger, acquisition, reorganisation or sale of assets, personal data may be transferred under continued protection of this Policy (or a successor policy notified to you).
No sale of personal data. We do not sell personal data for money. Some sharing with advertising partners described in § 8 may qualify as "sharing" under the CCPA/CPRA; California residents may opt out using the mechanisms described in § 11.
8. Ad partners — SDK inventory
Our mobile applications integrate the following advertising SDKs. Each sub-section below documents (a) what the SDK does, (b) the data it collects, (c) our lawful basis for the integration (and the vendor's own role as controller for the data they receive), (d) how to opt out on iOS and Android, and (e) a link to the vendor's privacy page. The list reflects our production configuration as of the Last updated date above; minor additions or removals are reflected in our App Store privacy labels and Data safety forms.
8.1 Google AdMob (Google)
- Behaviors
- Initializes at app launch, requests ads from Google's ad network, renders banner / interstitial / native / rewarded formats, handles clicks and conversion tracking, and reports aggregated performance to our developer dashboard.
- Data collected
- Advertising ID (GAID/IDFA), IP address, coarse location (city/country), device model, OS version, app bundle ID, session timestamp, ad-impression and interaction events.
- Lawful basis
- Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads and basic measurement. Google is an independent controller for the data it processes.
- Opt-out
- iOS: Settings → Privacy & Security → Tracking → toggle off for our app; Apple's App Tracking Transparency prompt. Android: Settings → Privacy → Ads → Opt out of Ads Personalization; reset advertising ID. Vendor page: policies.google.com/technologies/partner-sites.
8.2 Google Ad Manager (Google)
- Behaviors
- Loads and traffics direct-sold and programmatic ad lines through Google Ad Manager, mediates to other networks, and renders banner, native and interstitial formats. Records impressions, clicks and viewability events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad-unit ID, ad request and response timestamps.
- Lawful basis
- Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads and ad serving.
- Opt-out
- Same platform-level opt-outs as AdMob. Vendor page: policies.google.com/technologies/ads.
- Behaviors
- Requests banner, interstitial, native and rewarded-video ads from Meta's auction; reports impressions, clicks and conversions; supports Advanced Analytics for advertisers running Meta campaigns.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, event timestamps, conversion events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest for limited measurement. Meta is an independent controller for the data it processes.
- Opt-out
- iOS: App Tracking Transparency prompt; toggle "Allow Meta to use your ad ID" in Facebook settings. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: facebook.com/privacy/policies/cookies.
8.4 Unity Ads (Unity Technologies)
- Behaviors
- Initializes the Unity Ads framework, requests ads from Unity's network, renders rewarded video, interstitial and banner formats, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session ID, ad-request and impression timestamps.
- Lawful basis
- Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads. Unity is an independent controller.
- Opt-out
- iOS: App Tracking Transparency; "Limit Ad Tracking" toggle. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: unity.com/legal/privacy-policy.
8.5 AppLovin (MAX) (AppLovin)
- Behaviors
- Runs an in-app bidding mediation layer (MAX), requests ads across configured networks, renders banner, interstitial, rewarded and native formats, and supports AppLovin's own exchange.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, MAX mediation waterfall outputs.
- Lawful basis
- Consent for personalized ads in the EEA/UK; legitimate interest for ad serving and basic measurement. AppLovin is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: applovin.com/privacy.
8.6 ironSource / Unity LevelPlay (Unity / ironSource)
- Behaviors
- Mediation and bidding via Unity LevelPlay (the rebrand of ironSource); renders banner, interstitial, rewarded video and native ads; routes ad requests to multiple networks.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, mediation waterfall decisions.
- Lawful basis
- Consent for personalized ads in the EEA/UK; legitimate interest otherwise. Unity / ironSource is an independent controller for the data it processes.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: is.com/privacy-policy.
8.7 Pangle (ByteDance)
- Behaviors
- Initializes Pangle's ad SDK, requests banner, interstitial, rewarded video and feed ads from ByteDance's network, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad-request timestamps.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. ByteDance is an independent controller for the data it processes.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: pangleglobal.com/privacy.
8.8 Vungle (Liftoff)
- Behaviors
- Initializes Vungle's SDK, requests rewarded video, interstitial and banner ads, and reports impressions, clicks and reward grants.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Liftoff (Vungle) is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: liftoff.io/privacy.
8.9 Chartboost (Inmar)
- Behaviors
- Initializes the Chartboost SDK, requests banner, interstitial and rewarded-video ads, and reports ad events to its dashboards.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Inmar (Chartboost) is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: chartboost.com/legal/privacy-policy.
8.10 InMobi (InMobi)
- Behaviors
- Initializes InMobi's SDK, requests banner, interstitial, rewarded video and native ads, performs viewability checks, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, interaction events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. InMobi is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: inmobi.com/privacy-policy.
8.11 Tapjoy (Tapjoy)
- Behaviors
- Initializes Tapjoy's SDK, surfaces offerwall and rewarded ad units, mediates ad requests, and reports reward events to our server.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, offerwall events, reward IDs and timestamps.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Tapjoy is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: tapjoy.com/legal/advertisers/privacy-policy.
8.12 Mintegral (Mintegral)
- Behaviors
- Initializes Mintegral's SDK, requests banner, interstitial, rewarded video and splash ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad-request timestamps.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Mintegral is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: mintegral.com/en/privacy.
8.13 Digital Turbine (Digital Turbine)
- Behaviors
- Initializes Digital Turbine's SDK (formerly AdColony / Fyber), renders full-screen and rewarded video ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad event timestamps.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Digital Turbine is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: digitalturbine.com/privacy-policy.
8.14 Liftoff (Liftoff)
- Behaviors
- Runs Liftoff's monetization stack (formerly Vungle + GameRefinery + analytics), requests banner, interstitial, rewarded and native ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Liftoff is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: liftoff.io/privacy.
8.15 Moloco (Moloco)
- Behaviors
- Initializes Moloco's SDK, requests programmatic banner, interstitial, rewarded and native ads from its DSP, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Moloco is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: moloco.com/privacy-policy.
8.16 Yahoo (Verizon Media)
- Behaviors
- Initializes Yahoo's ad SDK (formerly Verizon Media / Oath), requests banner, interstitial, native and rewarded ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Yahoo is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: legal.yahoo.com/us/en/yahoo/privacy/index.html.
8.17 Smaato (Smaato)
- Behaviors
- Initializes Smaato's SDK, runs a real-time ad exchange, requests banner, interstitial, rewarded and native ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Smaato is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: smaato.com/privacy-policy.
8.18 Start.io (Start.io)
- Behaviors
- Initializes Start.io's SDK, requests banner, interstitial, rewarded and native ads, and reports ad events.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Start.io is an independent controller.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: start.io/privacy-policy.
8.19 Appodeal (Appodeal)
- Behaviors
- Acts as a mediation layer that orchestrates multiple ad networks (including AdMob, Meta Audience Network, Unity Ads, Vungle, AppLovin, Pangle, InMobi, Tapjoy, Chartboost, Mintegral, Digital Turbine, Smaato, Start.io, Liftoff, Moloco, Yahoo and others) inside a single SDK, requests and renders banner, interstitial, rewarded video and native ads.
- Data collected
- Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, mediation waterfall outcomes.
- Lawful basis
- Consent in the EEA/UK; legitimate interest otherwise. Appodeal and the underlying networks each act as an independent controller for the data they receive.
- Opt-out
- iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: appodeal.com/privacy-policy.
10. App-store compliance
Apple App Store Review Guidelines
Our mobile apps comply with all current Apple App Store Review Guidelines, including the following families that govern privacy:
- Guideline 1 (Objectionable Content) — content standards and user safety.
- Guideline 2 (Functionality) — apps must work as advertised and must not crash.
- Guideline 3 (Accuracy) — metadata, screenshots and descriptions must reflect actual functionality.
- Guideline 4 (Design) — UI and UX must follow Apple's design conventions.
- Guideline 5 (Legal), including:
- 5.1.1 (App Privacy) — accurate responses to the App Privacy questions on App Store Connect for every app version.
- 5.1.2 (Data Use) — data is used only as the user reasonably expects and only for the purposes disclosed in the privacy label and in this Policy.
- Privacy Manifest — apps submit a current Privacy Manifest declaring all Required Reason APIs accessed, in line with the requirement that became effective on 1 May 2024.
Google Play Developer Program Policy
Our apps comply with the Google Play Developer Program Policy, including:
- User Data policies — Prominent Disclosure & Consent, and the requirement that all data collection, use and sharing match the disclosures in the Data safety form.
- Permissions policy — apps request only the runtime permissions strictly necessary for the functionality described.
- Families policy — where applicable, apps designed for or attractive to children comply with the Families requirements.
We keep the App Store privacy nutrition labels and the Play Console Data safety forms current for every app we publish on every store.
11. Regional laws
The rights below apply depending on where you live. We honour them regardless of which store you used to install our apps. To exercise any of these rights, see § 16 or contact us at support@dikurooms.com.
GDPR (EU) Regulation (EU) 2016/679
- Rights: access, rectification, erasure, restriction of processing, data portability, objection to processing, and rights related to automated decision-making and profiling.
- Contact: support@dikurooms.com.
- Supervisory authority: you may lodge a complaint with your national data-protection authority. The European Data Protection Board's directory of authorities is at edpb.europa.eu.
UK GDPR + Data Protection Act 2018 United Kingdom
- Rights: the same rights as under the EU GDPR, applied under UK law.
- Contact: support@dikurooms.com.
- Supervisory authority: the Information Commissioner's Office (ICO) at ico.org.uk.
CCPA / CPRA (California) Cal. Civ. Code §1798.100 et seq.
- Rights: right to know what personal information we have collected and shared; right to delete; right to correct inaccurate information; right to opt out of the sale or sharing of personal information; right to limit the use of sensitive personal information; right to non-discrimination for exercising these rights.
- "Do Not Sell or Share My Personal Information": a footer link is provided wherever the law applies. You may also email support@dikurooms.com.
- Authorised agent: you may designate an authorised agent to submit a request on your behalf.
LGPD (Brazil) Lei nº 13.709/2018
- Rights: confirmation of the existence of processing; access; correction; anonymization, blocking or elimination of unnecessary or excessive data; portability; deletion of personal data processed with consent; information about public and private entities with which data has been shared; information about the possibility of not providing consent and the consequences of doing so; withdrawal of consent.
- Contact: support@dikurooms.com.
- Supervisory authority: the Autoridade Nacional de Proteção de Dados (ANPD).
PIPEDA (Canada) Personal Information Protection and Electronic Documents Act
- Rights: access to your personal information; challenge its accuracy; withdraw consent; file a complaint.
- Contact: support@dikurooms.com.
- Supervisory authority: the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
Australia Privacy Act 1988 Australian Privacy Principles (APPs)
- Rights: access, correction, and the right to make a complaint about breaches of the APPs.
- Contact: support@dikurooms.com.
- Supervisory authority: the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Singapore PDPA Personal Data Protection Act 2012
- Rights: access, correction, and withdrawal of consent for the continued use or disclosure of your personal data.
- Contact: support@dikurooms.com.
- Supervisory authority: the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.
Japan APPI Act on the Protection of Personal Information
- Rights: disclosure, correction, addition, deletion, cessation of use or disclosure of your personal information, and the right to opt out of third-party sharing for marketing purposes.
- Contact: support@dikurooms.com.
- Supervisory authority: the Personal Information Protection Commission (PPC) of Japan.
12. Children's data
COPPA (US)
We do not direct our websites or mobile apps to children under 13 and we do not knowingly collect personal data from children under 13. Where we have done so inadvertently, we delete it on discovery. Parents or guardians who believe we hold data about their child may contact us at support@dikurooms.com to request access and deletion.
GDPR-K (EU)
The default age of digital consent under the GDPR is 16. Several EU member states have lowered this to 13 (including Germany, Ireland, the Netherlands, Sweden and Finland, for instance). Where our Services are accessible to under-16s in those jurisdictions, we rely on verifiable parental consent before any non-essential processing. Our apps are not specifically designed for or marketed to children.
UK Age-Appropriate Design Code (AADC)
Where our Services are likely to be accessed by children in the UK, we follow the AADC's standards of best interest of the child, data-minimization, default-high privacy settings, no behavioural advertising to children, and a Data Protection Impact Assessment before launch.
If we discover that we have collected personal data from a child in error, we delete it as soon as reasonably practicable.
13. Cookies and tracking
- Strictly necessary cookies are always on and require no consent under EU/UK law.
- Analytics cookies are opt-in in the EEA/UK; in the US the default can be opt-out.
- Advertising cookies and SDKs are opt-in in the EEA/UK.
- Our cookie banner offers Reject and Accept controls. Your choice is stored in a persistent cookie so that you are not re-prompted on every visit, and you can change your choice at any time from the link in the footer (where available).
14. International transfers
Personal data may be processed in Hong Kong, the EEA, the United Kingdom, the United States, Singapore or Japan depending on the service provider used for a given function. Where personal data is transferred outside the EEA, the UK or other jurisdictions that the European Commission or the UK ICO consider adequate, we rely on the following safeguards:
- European Commission Standard Contractual Clauses (Commission Decision 2021/914), including the UK IDTA and the UK Addendum where applicable.
- Equivalent safeguards under local law, including equivalent US state laws (CCQP) where applicable.
- Vendor-level adequacy decisions or certifications where they exist.
15. Retention
- Inquiry emails and contact-form submissions: 24 months from the last interaction.
- Web server logs: 12 months.
- Mobile-app analytics: 13 months maximum.
- Ad-SDK identifiers and ad-event records: governed by the vendor's retention as published in the linked vendor privacy pages in § 8.
We may retain data for longer where required by tax, accounting or other legal obligations.
16. Your rights
Depending on where you live, you have some or all of the following rights with respect to your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (the "right to be forgotten"), subject to legal exceptions.
- Restriction — ask us to suspend processing of your data while a complaint is being investigated.
- Portability — receive the data you provided to us in a structured, machine-readable format and transmit it to another controller.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Withdrawal of consent — at any time, without affecting prior lawful processing.
- Complaint — to a supervisory authority (see § 11).
California-specific: right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination for exercising these rights.
How to exercise
Email support@dikurooms.com from the address associated with your account or installation. We respond within 30 days (or within 45 days where the CCPA/CPRA applies and an extension is permitted by law). For verification we may request information that reasonably demonstrates your identity.
17. Security
- Personal data is encrypted in transit using TLS (HTTPS).
- Personal data is encrypted at rest where commercially reasonable for the storage layer involved.
- Access to personal data is restricted to staff who need it, under least-privilege controls.
- In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the competent supervisory authority in accordance with applicable law.
No security measure is perfect; we continuously improve ours but cannot guarantee absolute security.
18. Changes to this policy
Material changes to this Policy will be posted with a new "Last updated" date at the top. Non-material changes (clarifications, corrections of typos, broken-link fixes) will be posted on this page without further notice. We encourage you to review this Policy periodically.