Legal · Privacy

Privacy Policy

This Policy explains how DIKUROOMS Trading Co., Limited ("DIKUROOMS", "we", "us") collects, uses, shares and protects personal data when you visit dikurooms.com or use the mobile applications we publish on the Google Play Store and Apple App Store. We have written it to be complete, plain and specific — including the full inventory of advertising SDKs integrated in our apps and the rights granted to you under the major regional privacy laws.

Effective date: 23 September 2026 Last updated: 23 September 2026 Controller: DIKUROOMS Trading Co., Limited

Table of contents

  1. Scope and controller
  2. Definitions
  3. Data we collect
  4. How we collect data
  5. Legal basis (GDPR / UK GDPR Art. 6)
  6. How we use data
  7. Sharing and disclosure
  8. Ad partners — SDK inventory
  9. A.8.1 Google AdMob
  10. A.8.2 Google Ad Manager
  11. A.8.3 Meta Audience Network
  12. A.8.4 Unity Ads
  13. A.8.5 AppLovin (MAX)
  14. A.8.6 ironSource / LevelPlay
  15. A.8.7 Pangle
  16. A.8.8 Vungle
  17. A.8.9 Chartboost
  18. A.8.10 InMobi
  19. A.8.11 Tapjoy
  20. A.8.12 Mintegral
  21. A.8.13 Digital Turbine
  22. A.8.14 Liftoff
  23. A.8.15 Moloco
  24. A.8.16 Yahoo (Verizon Media)
  25. A.8.17 Smaato
  26. A.8.18 Start.io
  27. A.8.19 Appodeal
  1. Ad formats used in our apps
  2. App-store compliance
  3. Regional laws
  4. Children's data
  5. Cookies and tracking
  6. International transfers
  7. Retention
  8. Your rights
  9. Security
  10. Changes to this policy
  11. Contact

1. Scope and controller

This Privacy Policy applies to:

  • the corporate website dikurooms.com (including all sub-pages such as /services.html, /culture.html, /news.html, /contact.html); and
  • the mobile applications published by DIKUROOMS Trading Co., Limited on the Google Play Store and the Apple App Store.

The data controller responsible for the processing of your personal data under this Policy is:

DIKUROOMS Trading Co., Limited
Rm F(B22) 2/F FREDER CTR 3 MOK CHEONG ST
To Kwa Wan, Kowloon, Hong Kong SAR
Email: support@dikurooms.com

If you are in the European Economic Area (EEA), the United Kingdom (UK) or Switzerland, this entity is also your controller under the General Data Protection Regulation (GDPR) and the UK GDPR. Where local law requires, we additionally rely on locally appointed representatives — please contact us for details.

2. Definitions

For the purposes of this Policy:

  • Personal data means any information relating to an identified or identifiable natural person.
  • Processing means any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
  • Controller means the entity that determines the purposes and means of the processing (DIKUROOMS).
  • Processor means an entity that processes personal data on the controller's behalf (e.g. a hosting or email provider).
  • User means any individual accessing the website or installing/using our apps.
  • Child means a person under the age defined by the law of their place of residence (see § 12).
  • SDK means a software development kit integrated into our apps (most often an advertising SDK listed in § 8).
  • Advertising identifier means a device-level identifier used by ad partners for ad selection and measurement — the Google Advertising ID (GAID) on Android and Apple's Identifier for Advertisers (IDFA) on iOS.
  • EEA means the European Economic Area.
  • UK means the United Kingdom of Great Britain and Northern Ireland.
  • California means the State of California, USA.

3. Data we collect

We collect the following categories of data, depending on how you use our Services:

Identifiers

  • Name, email address, company, job title (when you submit a contact or inquiry form).
  • IP address, browser user agent, referrer, device and operating-system identifiers.
  • Mobile-app identifiers: GAID (Android), IDFA (iOS), app instance ID, push-notification token.

Commercial information

  • The inquiry topic and message body you choose to send us.
  • Order, quote or service-request metadata you provide.

Internet / network activity

  • Pages visited, time on page, scroll depth, referrer URL, timestamps.
  • Search terms you used to reach our site.

Approximate location

  • City- and country-level location inferred server-side from your IP address. We do not collect precise GPS coordinates from the website; the mobile apps do not request precise location unless explicitly required by a feature you opt into.

Mobile-app telemetry

  • App version, build number, OS version, device model, locale, crash logs and diagnostic traces.
  • Ad events: impression, click, completion, reward-grant, mediation waterfall outcomes.

We do not knowingly collect government-issued identifiers (passport, national ID), precise geolocation, biometric data, health data, sexual orientation, racial or ethnic origin, religious beliefs, or financial account credentials.

4. How we collect data

Directly from you

  • When you submit the contact form on /contact.html or send us an email.
  • When you create an account or invitation in one of our mobile apps.

Automatically from your device

  • Cookies and similar storage on the website (see § 13).
  • Server logs captured by our hosting provider.
  • Mobile-app SDKs that initialize at app launch to deliver and measure ads (see § 8).

From partners

  • App-store partners (Apple, Google) provide basic install, crash and aggregate usage statistics.
  • Ad networks return auction results, ad-rendering events and aggregated performance metrics (see § 8).

5. Legal basis (GDPR / UK GDPR Art. 6)

For users in the EEA and the UK we rely on the following lawful bases under Article 6 of the GDPR / UK GDPR:

  • Consent (Art. 6(1)(a)) — for non-essential cookies, ad personalization, and marketing emails. You may withdraw consent at any time without affecting prior lawful processing.
  • Performance of contract (Art. 6(1)(b)) — to respond to an inquiry, deliver a quote, or fulfil an order you have placed.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, customs, accounting, record-keeping and law-enforcement obligations.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Services secure, prevent abuse, and produce internal aggregate reports. We conduct and re-test a balancing on a case-by-case basis and offer an objection mechanism (see § 16).

Where we rely on consent, the cookie banner on our website or the in-app consent prompt collects it. You can change your choice at any time.

6. How we use data

  • To respond to your inquiries and provide customer support.
  • To operate, maintain, secure and improve the website and the mobile apps.
  • To select, render and measure advertising (see § 8 and § 9).
  • To produce aggregated, de-identified analytics.
  • To comply with applicable law and enforce our Terms.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you, and we do not build user profiles for advertising beyond what the ad partners listed in § 8 do on their own behalf.

7. Sharing and disclosure

Service providers (processors)

We share personal data with vetted service providers acting as processors on our behalf, including:

  • Hosting and content delivery.
  • Email and customer-support tools.
  • Privacy-respecting analytics.
  • Advertising SDKs listed in § 8 (each acts as an independent controller for the data they receive).

Legal

We may disclose personal data when required by law, valid legal process, or to protect the rights, property or safety of DIKUROOMS, our users or others.

Business transfers

If DIKUROOMS undergoes a merger, acquisition, reorganisation or sale of assets, personal data may be transferred under continued protection of this Policy (or a successor policy notified to you).

No sale of personal data. We do not sell personal data for money. Some sharing with advertising partners described in § 8 may qualify as "sharing" under the CCPA/CPRA; California residents may opt out using the mechanisms described in § 11.

8. Ad partners — SDK inventory

Our mobile applications integrate the following advertising SDKs. Each sub-section below documents (a) what the SDK does, (b) the data it collects, (c) our lawful basis for the integration (and the vendor's own role as controller for the data they receive), (d) how to opt out on iOS and Android, and (e) a link to the vendor's privacy page. The list reflects our production configuration as of the Last updated date above; minor additions or removals are reflected in our App Store privacy labels and Data safety forms.

8.1 Google AdMob (Google)

Behaviors
Initializes at app launch, requests ads from Google's ad network, renders banner / interstitial / native / rewarded formats, handles clicks and conversion tracking, and reports aggregated performance to our developer dashboard.
Data collected
Advertising ID (GAID/IDFA), IP address, coarse location (city/country), device model, OS version, app bundle ID, session timestamp, ad-impression and interaction events.
Lawful basis
Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads and basic measurement. Google is an independent controller for the data it processes.
Opt-out
iOS: Settings → Privacy & Security → Tracking → toggle off for our app; Apple's App Tracking Transparency prompt. Android: Settings → Privacy → Ads → Opt out of Ads Personalization; reset advertising ID. Vendor page: policies.google.com/technologies/partner-sites.

8.2 Google Ad Manager (Google)

Behaviors
Loads and traffics direct-sold and programmatic ad lines through Google Ad Manager, mediates to other networks, and renders banner, native and interstitial formats. Records impressions, clicks and viewability events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad-unit ID, ad request and response timestamps.
Lawful basis
Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads and ad serving.
Opt-out
Same platform-level opt-outs as AdMob. Vendor page: policies.google.com/technologies/ads.

8.3 Meta Audience Network (Meta Platforms)

Behaviors
Requests banner, interstitial, native and rewarded-video ads from Meta's auction; reports impressions, clicks and conversions; supports Advanced Analytics for advertisers running Meta campaigns.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, event timestamps, conversion events.
Lawful basis
Consent in the EEA/UK; legitimate interest for limited measurement. Meta is an independent controller for the data it processes.
Opt-out
iOS: App Tracking Transparency prompt; toggle "Allow Meta to use your ad ID" in Facebook settings. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: facebook.com/privacy/policies/cookies.

8.4 Unity Ads (Unity Technologies)

Behaviors
Initializes the Unity Ads framework, requests ads from Unity's network, renders rewarded video, interstitial and banner formats, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session ID, ad-request and impression timestamps.
Lawful basis
Consent for personalized ads in the EEA/UK; legitimate interest for non-personalized ads. Unity is an independent controller.
Opt-out
iOS: App Tracking Transparency; "Limit Ad Tracking" toggle. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: unity.com/legal/privacy-policy.

8.5 AppLovin (MAX) (AppLovin)

Behaviors
Runs an in-app bidding mediation layer (MAX), requests ads across configured networks, renders banner, interstitial, rewarded and native formats, and supports AppLovin's own exchange.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, MAX mediation waterfall outputs.
Lawful basis
Consent for personalized ads in the EEA/UK; legitimate interest for ad serving and basic measurement. AppLovin is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: applovin.com/privacy.

8.6 ironSource / Unity LevelPlay (Unity / ironSource)

Behaviors
Mediation and bidding via Unity LevelPlay (the rebrand of ironSource); renders banner, interstitial, rewarded video and native ads; routes ad requests to multiple networks.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, mediation waterfall decisions.
Lawful basis
Consent for personalized ads in the EEA/UK; legitimate interest otherwise. Unity / ironSource is an independent controller for the data it processes.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: is.com/privacy-policy.

8.7 Pangle (ByteDance)

Behaviors
Initializes Pangle's ad SDK, requests banner, interstitial, rewarded video and feed ads from ByteDance's network, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad-request timestamps.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. ByteDance is an independent controller for the data it processes.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: pangleglobal.com/privacy.

8.8 Vungle (Liftoff)

Behaviors
Initializes Vungle's SDK, requests rewarded video, interstitial and banner ads, and reports impressions, clicks and reward grants.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Liftoff (Vungle) is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: liftoff.io/privacy.

8.9 Chartboost (Inmar)

Behaviors
Initializes the Chartboost SDK, requests banner, interstitial and rewarded-video ads, and reports ad events to its dashboards.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Inmar (Chartboost) is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: chartboost.com/legal/privacy-policy.

8.10 InMobi (InMobi)

Behaviors
Initializes InMobi's SDK, requests banner, interstitial, rewarded video and native ads, performs viewability checks, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, interaction events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. InMobi is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: inmobi.com/privacy-policy.

8.11 Tapjoy (Tapjoy)

Behaviors
Initializes Tapjoy's SDK, surfaces offerwall and rewarded ad units, mediates ad requests, and reports reward events to our server.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, offerwall events, reward IDs and timestamps.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Tapjoy is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: tapjoy.com/legal/advertisers/privacy-policy.

8.12 Mintegral (Mintegral)

Behaviors
Initializes Mintegral's SDK, requests banner, interstitial, rewarded video and splash ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad-request timestamps.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Mintegral is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: mintegral.com/en/privacy.

8.13 Digital Turbine (Digital Turbine)

Behaviors
Initializes Digital Turbine's SDK (formerly AdColony / Fyber), renders full-screen and rewarded video ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad event timestamps.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Digital Turbine is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: digitalturbine.com/privacy-policy.

8.14 Liftoff (Liftoff)

Behaviors
Runs Liftoff's monetization stack (formerly Vungle + GameRefinery + analytics), requests banner, interstitial, rewarded and native ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, session length, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Liftoff is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: liftoff.io/privacy.

8.15 Moloco (Moloco)

Behaviors
Initializes Moloco's SDK, requests programmatic banner, interstitial, rewarded and native ads from its DSP, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Moloco is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: moloco.com/privacy-policy.

8.16 Yahoo (Verizon Media)

Behaviors
Initializes Yahoo's ad SDK (formerly Verizon Media / Oath), requests banner, interstitial, native and rewarded ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Yahoo is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: legal.yahoo.com/us/en/yahoo/privacy/index.html.

8.17 Smaato (Smaato)

Behaviors
Initializes Smaato's SDK, runs a real-time ad exchange, requests banner, interstitial, rewarded and native ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Smaato is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: smaato.com/privacy-policy.

8.18 Start.io (Start.io)

Behaviors
Initializes Start.io's SDK, requests banner, interstitial, rewarded and native ads, and reports ad events.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Start.io is an independent controller.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: start.io/privacy-policy.

8.19 Appodeal (Appodeal)

Behaviors
Acts as a mediation layer that orchestrates multiple ad networks (including AdMob, Meta Audience Network, Unity Ads, Vungle, AppLovin, Pangle, InMobi, Tapjoy, Chartboost, Mintegral, Digital Turbine, Smaato, Start.io, Liftoff, Moloco, Yahoo and others) inside a single SDK, requests and renders banner, interstitial, rewarded video and native ads.
Data collected
Advertising ID, IP address, coarse location, device/OS metadata, app bundle ID, ad events, mediation waterfall outcomes.
Lawful basis
Consent in the EEA/UK; legitimate interest otherwise. Appodeal and the underlying networks each act as an independent controller for the data they receive.
Opt-out
iOS: App Tracking Transparency. Android: Settings → Privacy → Ads → Opt out of Ads Personalization. Vendor page: appodeal.com/privacy-policy.

9. Ad formats used in our apps

Our apps use the following ad formats. The data flowing to the ad partners named in § 8 for each format is described below; the user controls described here apply in addition to the platform-level controls listed in § 8.

Splash / open-screen ads

Full-screen ad shown immediately at app launch or when returning to the app after a long background period.

When it appears: at cold start and on foreground after the configured timeout.

Data flowing to ad partners: advertising ID (GAID/IDFA), app bundle ID, session timestamp, coarse location, device/OS metadata.

User control: the splash ad has a "close" or "skip" affordance after the mandatory minimum display time required by the network. On Android, opting out of Ads Personalization disables personalized targeting; on iOS, denying App Tracking Transparency limits the data sent.

Rewarded video ads

User-initiated ad that the user opts in to view in exchange for an in-app reward (e.g. an extra life, currency, or feature unlock).

When it appears: only when the user taps an explicit "watch ad" button or chooses a rewarded offer inside the app.

Data flowing to ad partners: advertising ID (GAID/IDFA), app bundle ID, placement / reward ID, completion event timestamp, coarse location, device/OS metadata.

User control: the reward is granted only after the user has watched the ad to completion (or to the network's check-point). No reward is granted for skipping before completion. The user can always decline to start the ad.

Interstitial ads

Full-screen ad shown at natural transition points in the app flow (e.g. between scenes, on completion of a level, before showing results).

When it appears: at predefined transition points only, and never more often than the network's frequency cap (and never two interstitials back-to-back where the network prohibits it).

Data flowing to ad partners: advertising ID (GAID/IDFA), ad-unit ID, app bundle ID, frequency-cap metadata, coarse location, device/OS metadata.

User control: a "close" or "continue" affordance is shown after the network's required minimum display time. On Android, opting out of Ads Personalization applies; on iOS, denying App Tracking Transparency limits the data sent.

Banner ads

A persistent rectangular strip at the top or bottom of a screen that remains visible while the user interacts with the underlying content.

When it appears: on screens where the app has been configured to show a banner ad unit.

Data flowing to ad partners: advertising ID (GAID/IDFA), ad-unit ID, viewability / impression events, coarse location, device/OS metadata.

User control: some screens offer a "hide ads" toggle that, when available, removes the banner for that session or until the next purchase. On Android, opting out of Ads Personalization applies; on iOS, denying App Tracking Transparency limits the data sent.

10. App-store compliance

Apple App Store Review Guidelines

Our mobile apps comply with all current Apple App Store Review Guidelines, including the following families that govern privacy:

  • Guideline 1 (Objectionable Content) — content standards and user safety.
  • Guideline 2 (Functionality) — apps must work as advertised and must not crash.
  • Guideline 3 (Accuracy) — metadata, screenshots and descriptions must reflect actual functionality.
  • Guideline 4 (Design) — UI and UX must follow Apple's design conventions.
  • Guideline 5 (Legal), including:
    • 5.1.1 (App Privacy) — accurate responses to the App Privacy questions on App Store Connect for every app version.
    • 5.1.2 (Data Use) — data is used only as the user reasonably expects and only for the purposes disclosed in the privacy label and in this Policy.
    • Privacy Manifest — apps submit a current Privacy Manifest declaring all Required Reason APIs accessed, in line with the requirement that became effective on 1 May 2024.

Google Play Developer Program Policy

Our apps comply with the Google Play Developer Program Policy, including:

  • User Data policies — Prominent Disclosure & Consent, and the requirement that all data collection, use and sharing match the disclosures in the Data safety form.
  • Permissions policy — apps request only the runtime permissions strictly necessary for the functionality described.
  • Families policy — where applicable, apps designed for or attractive to children comply with the Families requirements.

We keep the App Store privacy nutrition labels and the Play Console Data safety forms current for every app we publish on every store.

11. Regional laws

The rights below apply depending on where you live. We honour them regardless of which store you used to install our apps. To exercise any of these rights, see § 16 or contact us at support@dikurooms.com.

GDPR (EU) Regulation (EU) 2016/679

  • Rights: access, rectification, erasure, restriction of processing, data portability, objection to processing, and rights related to automated decision-making and profiling.
  • Contact: support@dikurooms.com.
  • Supervisory authority: you may lodge a complaint with your national data-protection authority. The European Data Protection Board's directory of authorities is at edpb.europa.eu.

UK GDPR + Data Protection Act 2018 United Kingdom

  • Rights: the same rights as under the EU GDPR, applied under UK law.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Information Commissioner's Office (ICO) at ico.org.uk.

CCPA / CPRA (California) Cal. Civ. Code §1798.100 et seq.

  • Rights: right to know what personal information we have collected and shared; right to delete; right to correct inaccurate information; right to opt out of the sale or sharing of personal information; right to limit the use of sensitive personal information; right to non-discrimination for exercising these rights.
  • "Do Not Sell or Share My Personal Information": a footer link is provided wherever the law applies. You may also email support@dikurooms.com.
  • Authorised agent: you may designate an authorised agent to submit a request on your behalf.

LGPD (Brazil) Lei nº 13.709/2018

  • Rights: confirmation of the existence of processing; access; correction; anonymization, blocking or elimination of unnecessary or excessive data; portability; deletion of personal data processed with consent; information about public and private entities with which data has been shared; information about the possibility of not providing consent and the consequences of doing so; withdrawal of consent.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Autoridade Nacional de Proteção de Dados (ANPD).

PIPEDA (Canada) Personal Information Protection and Electronic Documents Act

  • Rights: access to your personal information; challenge its accuracy; withdraw consent; file a complaint.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

Australia Privacy Act 1988 Australian Privacy Principles (APPs)

  • Rights: access, correction, and the right to make a complaint about breaches of the APPs.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Singapore PDPA Personal Data Protection Act 2012

  • Rights: access, correction, and withdrawal of consent for the continued use or disclosure of your personal data.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

Japan APPI Act on the Protection of Personal Information

  • Rights: disclosure, correction, addition, deletion, cessation of use or disclosure of your personal information, and the right to opt out of third-party sharing for marketing purposes.
  • Contact: support@dikurooms.com.
  • Supervisory authority: the Personal Information Protection Commission (PPC) of Japan.

12. Children's data

COPPA (US)

We do not direct our websites or mobile apps to children under 13 and we do not knowingly collect personal data from children under 13. Where we have done so inadvertently, we delete it on discovery. Parents or guardians who believe we hold data about their child may contact us at support@dikurooms.com to request access and deletion.

GDPR-K (EU)

The default age of digital consent under the GDPR is 16. Several EU member states have lowered this to 13 (including Germany, Ireland, the Netherlands, Sweden and Finland, for instance). Where our Services are accessible to under-16s in those jurisdictions, we rely on verifiable parental consent before any non-essential processing. Our apps are not specifically designed for or marketed to children.

UK Age-Appropriate Design Code (AADC)

Where our Services are likely to be accessed by children in the UK, we follow the AADC's standards of best interest of the child, data-minimization, default-high privacy settings, no behavioural advertising to children, and a Data Protection Impact Assessment before launch.

If we discover that we have collected personal data from a child in error, we delete it as soon as reasonably practicable.

13. Cookies and tracking

  • Strictly necessary cookies are always on and require no consent under EU/UK law.
  • Analytics cookies are opt-in in the EEA/UK; in the US the default can be opt-out.
  • Advertising cookies and SDKs are opt-in in the EEA/UK.
  • Our cookie banner offers Reject and Accept controls. Your choice is stored in a persistent cookie so that you are not re-prompted on every visit, and you can change your choice at any time from the link in the footer (where available).

14. International transfers

Personal data may be processed in Hong Kong, the EEA, the United Kingdom, the United States, Singapore or Japan depending on the service provider used for a given function. Where personal data is transferred outside the EEA, the UK or other jurisdictions that the European Commission or the UK ICO consider adequate, we rely on the following safeguards:

  • European Commission Standard Contractual Clauses (Commission Decision 2021/914), including the UK IDTA and the UK Addendum where applicable.
  • Equivalent safeguards under local law, including equivalent US state laws (CCQP) where applicable.
  • Vendor-level adequacy decisions or certifications where they exist.

15. Retention

  • Inquiry emails and contact-form submissions: 24 months from the last interaction.
  • Web server logs: 12 months.
  • Mobile-app analytics: 13 months maximum.
  • Ad-SDK identifiers and ad-event records: governed by the vendor's retention as published in the linked vendor privacy pages in § 8.

We may retain data for longer where required by tax, accounting or other legal obligations.

16. Your rights

Depending on where you live, you have some or all of the following rights with respect to your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data (the "right to be forgotten"), subject to legal exceptions.
  • Restriction — ask us to suspend processing of your data while a complaint is being investigated.
  • Portability — receive the data you provided to us in a structured, machine-readable format and transmit it to another controller.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdrawal of consent — at any time, without affecting prior lawful processing.
  • Complaint — to a supervisory authority (see § 11).

California-specific: right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination for exercising these rights.

How to exercise

Email support@dikurooms.com from the address associated with your account or installation. We respond within 30 days (or within 45 days where the CCPA/CPRA applies and an extension is permitted by law). For verification we may request information that reasonably demonstrates your identity.

17. Security

  • Personal data is encrypted in transit using TLS (HTTPS).
  • Personal data is encrypted at rest where commercially reasonable for the storage layer involved.
  • Access to personal data is restricted to staff who need it, under least-privilege controls.
  • In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the competent supervisory authority in accordance with applicable law.

No security measure is perfect; we continuously improve ours but cannot guarantee absolute security.

18. Changes to this policy

Material changes to this Policy will be posted with a new "Last updated" date at the top. Non-material changes (clarifications, corrections of typos, broken-link fixes) will be posted on this page without further notice. We encourage you to review this Policy periodically.

19. Contact

For any question about this Policy or to exercise your rights:

DIKUROOMS Trading Co., Limited
Rm F(B22) 2/F FREDER CTR 3 MOK CHEONG ST
To Kwa Wan, Kowloon, Hong Kong SAR
Email: support@dikurooms.com

© 2026 DIKUROOMS Trading Co., Limited. This Policy is also available on our Terms of Service page in the parent document.