PRIVACY POLICY

Last updated: [04/25/2026]

Foshan Aike Medical Equipment Co., Ltd. (Brand: AI DENTAL) (hereinafter referred to as “we”, “us”, “our” or the “Company”) has established this Privacy Policy (hereinafter referred to as “this Policy”) to strictly protect the security of personal data and fulfill privacy protection obligations in jurisdictions around the world in compliance with applicable laws. This Policy applies to our full range of products, services, official website, events and all related business scenarios, and takes effect for users globally.

1. Company Name, Address and Contact Information

Company Name: Foshan Aike Medical Equipment Co., Ltd. (Brand: AI DENTAL)

Registered Address: 2nd Floor, Building 4, Area D, Guangdong New Light Source Industrial Base, Langsha, Luocun, Shishan Town, Nanhai District, Foshan City

Official Website: www.ai-dental.cn/

2. Management and Security Measures for Personal Data

We have established a complete personal data security management system and organizational system, formulated standardized data processing procedures, and carried out regular privacy compliance training and assessment for all employees with access to personal data.

To ensure the accuracy, completeness and currency of personal data, and prevent risks such as unauthorized access, loss, damage, falsification and leakage of personal data, we will implement comprehensive and necessary security control measures, including organizational and technical measures, to exercise strict full-lifecycle management of personal data. At the same time, we will conduct continuous supervision and compliance audits on outsourced service providers and affiliated group companies entrusted with personal data processing, to ensure that their data processing activities comply with this Policy and applicable legal requirements.

3. Categories of Personal Data We Collect

We only collect personal data necessary to achieve our business purposes, covering six categories of subjects: customers (including business partners and distributors), healthcare professionals (including physicians, dentists, dental hygienists, etc.), patients, shareholders, job applicants, and current employees. The specific categories are as follows:

(1) Personal Data Related to Customers

A. Full name, email address, phone number, contact address

B. Company/organization name, job title and position information

C. Business communication information (including content related to business negotiations and cooperation docking)

D. Inquiries sent to us and subsequent interactive communication records

E. Records related to customers’ purchase, use, and intended purchase of our products/services

F. Opinions, reviews, and survey feedback on our products/services

G. Interaction information with our official website, including browsing history, IP address, and device identification information

H. Photos and video materials containing your portrait taken when visiting our office premises or participating in our events

I. Necessary information for visiting our premises or participating in our events, such as dietary preferences, age, accessibility needs, etc.

J. Necessary information related to itinerary arrangements such as visas and passports required for visits by overseas personnel

(2) Personal Data Related to Healthcare Professionals (excluding Paragraph (1) above)

A. Information contained in the resume, including work history, educational background, and professional qualifications

B. Information related to practicing licenses, including relevant practicing qualification certificates of physicians, dental hygienists, etc.

C. Information related to the use of our products to provide medical and dental services

D. Information related to clinical studies and trials of our products

(3) Personal Data Related to Patients

A. Information related to clinical studies and trials of our products

B. Necessary information for fulfilling reporting obligations to regulatory authorities in relevant countries/regions after the occurrence of adverse events related to our products, including full name, age, date of birth, gender, body weight, ethnic origin, race, and disease treatment-related information

(4) Personal Data Related to Shareholders

A. Full name, contact address

B. Shareholder number

C. Number of shares held and voting rights information

D. Information related to the exercise of shareholder rights including voting rights

E. Communication records with us

(5) Personal Data Related to Job Applicants

A. Full name, email address, phone number, contact address

B. Information contained in the resume, including work history, educational background, and professional qualifications

C. Necessary information for employment, including nationality and visa information

D. Background check information (in compliance with applicable legal requirements)

(6) Personal Data Related to Current Employees (excluding Paragraph (5) above)

A. Family information and emergency contact information

B. Information related to human resource management such as attendance and personnel evaluation

C. Necessary information for payroll, social security and welfare benefits, including bank account information

D. Health-related information

4. Purposes for Use of Personal Data

We only process personal data of the corresponding subjects to the extent necessary to achieve the following purposes, and all processing activities are strictly in compliance with applicable legal requirements:

(1) Conduct business communication, including sharing personal data with our affiliated group companies and product distributors to advance business cooperation

(2) Conduct sales, maintenance, repair of our products/services and related information notification services

(3) Conduct planning, research, development and optimization of our products/services, including providing personal data to notified bodies assessing whether medical devices comply with laws and regulations in relevant countries and regions

(4) Invitation, organization and operation of events and exhibitions, as well as reception of visitors to our office premises, including providing personal data to sponsor companies/organizations of the events

(5) Conduct public relations and marketing activities, including providing product review information to social network companies and publishing on social platforms

(6) Respond to inquiries and appeals from customers and relevant subjects

(7) Manage shareholder relationships and protect shareholder rights and interests

(8) Daily communication with employees and internal management

(9) Human resource management including attendance, payroll payment and personnel evaluation

(10) Employee education, training and capacity improvement

(11) Employee occupational health and work safety management

(12) Recruitment screening, communication and employment process handling for job applicants

(13) Management and security protection of system accounts

(14) Optimization of official website service quality, including providing browsing history to web analytics providers

(15) Prevent unauthorized use of the official website, and handle cybersecurity incidents and related disputes

(16) Establish, exercise or defend our legitimate legal rights

(17) Fulfill obligations stipulated by laws and regulations, including providing personal data to competent regulatory authorities

5. Provision of Personal Data to Third Parties

We will only provide your personal data to third parties to the extent necessary to achieve the purposes set out in Section 4 above, or as required by mandatory provisions of applicable laws. When providing personal data to third parties, we will strictly comply with applicable legal requirements and take all necessary compliance safeguards, including obtaining your consent.

The recipients to whom we may provide personal data include, but are not limited to, the following subjects, and the processing activities of all recipients are strictly limited to the agreed business purposes and applicable legal requirements:

 

Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. (excluding companies that are deemed joint controllers of personal data under applicable laws)

Authorized distributors of our products

Notified bodies and compliance certification bodies assessing whether medical devices comply with laws and regulations in relevant countries and regions

Sponsor companies and co-organizers of our events

Service providers, including web analytics providers, IT infrastructure service providers, logistics service providers, payment processors, legal consulting agencies, etc.

Social network operators

Competent regulatory authorities, law enforcement agencies, judicial authorities, etc.

6. Children’s Privacy

We only collect personal data of children when permitted by applicable laws. If we collect personal data of children, we will strictly comply with applicable legal requirements and take necessary compliance measures including obtaining the consent of the child or their legal guardian.

For users in the European Economic Area (EEA) and the United Kingdom (UK), a child means a person under the age of 16; for users in the United States, a child means a person under the age of 13.

7. Sensitive Personal Data

If the personal data we collect is classified as sensitive personal data (including special categories of personal data) under applicable laws, we will process it only after obtaining your consent or taking statutory compliance safeguards in strict accordance with applicable legal requirements.

Only under statutory circumstances such as fulfilling legal obligations, protecting public health, conducting clinical research, and fulfilling medical device regulatory obligations, we may process relevant sensitive personal data without obtaining your consent, and all processing activities are strictly limited to the scope permitted by applicable laws.

8. Outsourcing of Personal Data Processing

We may outsource all or part of the personal data processing business to third-party service providers only to the extent necessary to achieve the purposes set out in Section 4 above.

In outsourcing cooperation, we only select third-party service providers with sufficient data security protection capabilities and compliance qualifications. We will sign a legally binding outsourcing processing agreement with the service provider, clarifying the purpose, time limit, scope of data processing, rights and obligations of both parties, and security obligations. We will implement necessary and appropriate control over the service provider’s personal data processing activities through regular audits and continuous supervision to ensure the security of personal data.

We will not be liable for any damage caused by the service provider’s illegal processing of personal data, unless such damage is directly caused by our intentional misconduct or gross negligence.

9. Joint Use of Personal Data

We may jointly use your personal data with affiliated group companies in accordance with the following agreement, which is fully in compliance with the relevant provisions on joint controllers under applicable laws:

Categories of Jointly Used Personal Data

All categories of personal data listed in Section 3 of this Policy

Scope of Joint Users

All affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

Purposes of Joint Use

All purposes of use listed in Section 4 of this Policy

Responsible Entity for Joint Use

Foshan Aike Medical Equipment Co., Ltd. (Brand: AI DENTAL). For information about the contact address of the Company, please refer to the official website link listed in Section 1 of this Policy

10. Your Rights

You have the right to exercise relevant statutory rights regarding your personal data in accordance with applicable laws, including but not limited to: withdrawal of consent given, access, rectification/supplementation, restriction of processing, erasure, prohibition of provision to third parties, objection to processing, and data portability.

If you submit a request to exercise the above rights, we will strictly review the request in accordance with applicable legal requirements and respond within the statutory time limit.

To prevent risks such as fraud, identity impersonation and abuse of rights, and protect the security of your personal information, we have the right to require you to provide valid identity documents to complete identity verification before responding to your request. For repetitive, excessive, unfounded requests that may infringe on the legitimate rights and interests of third parties, we have the right to reject them in accordance with applicable legal requirements, or charge a reasonable administrative fee for requests beyond the reasonable scope.

If you need to exercise the above rights, or have any questions about your rights, please contact us through the contact window listed in Section 12 of this Policy.

11. Compliance with Laws and Regulations and Policy Revision

We will strictly comply with all applicable laws and regulations, regulatory requirements and industry norms related to personal data protection, and will make necessary revisions to this Policy in accordance with changes in laws and regulations, business adjustments, regulatory requirements and other circumstances.

After the revision of this Policy, the updated version will be published on our official website (www.ai-dental.cn/), and the updated version will clearly indicate the latest revision date and effective date. We will notify you in advance by email, official website announcement or other reasonable means in accordance with applicable legal requirements. Your continued use of our products, services, official website or participation in our events after the effective date of the revised version shall be deemed that you have fully read, understood and accepted the revised Policy.

12. Contact Window

For inquiries, requests to exercise rights, complaints and suggestions related to personal data processing, you can contact us through the following methods: Contact Address: 2nd Floor, Building 4, Area D, Guangdong New Light Source Industrial Base, Langsha, Luocun, Shishan Town, Nanhai District, Foshan City Contact Number: 15915235523 / +86 0757-82820562 

Email Address:

13. Additional Information for Residents of the European Economic Area (EEA) and the United Kingdom (UK)

For residents of the EEA and the UK, we provide the following additional information in accordance with the EU General Data Protection Regulation (GDPR), UK GDPR and relevant supporting regulations (hereinafter collectively referred to as "EU/UK Privacy Laws"). In the event of any inconsistency or conflict between the foregoing general terms of this Policy and this Additional Information, this Additional Information shall prevail for residents of the EEA and the UK to the extent of such inconsistency or conflict.

(1) Data Controller

We are the controller of personal data processing as defined in the EU/UK Privacy Laws.

(2) Means of Collection of Personal Data

We collect your personal data through the following channels, with corresponding specific scenarios as follows:

Collection Scenario

Sources of Data

When conducting business negotiations and communication with us

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. Authorized distributors of our products

When purchasing or intending to purchase our products, or applying for product maintenance and repair services

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. Authorized distributors of our products

When sending inquiries or appeal feedback to us

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. Authorized distributors of our products

When participating in our events and exhibitions, or applying for a visit to our office premises

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. Authorized distributors of our products

When providing reviews, feedback and survey questionnaires on our products/services

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd. Authorized distributors of our products

When using our official website

Yourself

When participating in clinical studies and trials related to our products

Yourself Affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

When acquiring our shares and being registered in the shareholder register

Yourself (Shareholder)

When submitting a job application and participating in our recruitment process

Yourself (Job Applicant)

When establishing an employment relationship with us and joining the Company

Yourself (Employee) Affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

(3) Lawful Grounds for Processing

We process personal data for the purposes set out in Section 4 of this Policy based on the following lawful grounds stipulated in the EU/UK Privacy Laws, with the corresponding relationship as follows:

Purpose of Personal Data Processing

Lawful Grounds

Business communication and cooperation docking

Legitimate interests pursued by us and third parties including our business partners: To ensure smooth business communication and cooperation between us and our business partners

Sales, maintenance, repair of our products/services and related information notification

Legitimate interests pursued by us and third parties including our business partners: To provide our products and related services to you in a standardized and proper manner; Performance of a contract: To fulfill contractual obligations related to products/services entered into with you

Planning, research, development and optimization of our products/services

Legitimate interests pursued by us: To continuously optimize and upgrade our products and services, and ensure product compliance and use safety

Public relations and marketing activities

Your explicit consent; Legitimate interests pursued by us: To send you information about our products, services and events relevant to you, and you have the right to object to such processing at any time

Invitation, organization of events and exhibitions, and visitor reception

Legitimate interests pursued by us: To organize relevant events and receive visitors in a standardized and proper manner, and ensure the normal operation of events

Response to inquiries and appeal feedback

Legitimate interests pursued by us and third parties including our business partners: To respond to your inquiries and appeals in a standardized and proper manner, and protect your legitimate rights and interests

Shareholder relationship management and rights protection

Legitimate interests pursued by us: To comply with applicable laws and regulations such as the Company Law of the People's Republic of China, establish a smooth communication mechanism with shareholders, and protect the legitimate rights and interests of shareholders

Daily communication with employees and internal management

Legitimate interests pursued by us: To ensure the normal operation and management order of the enterprise

Human resource management related work

Legitimate interests pursued by us: To conduct enterprise human resource management in a standardized manner; Performance of a contract: To fulfill obligations under the employment contract entered into with employees

Employee education and training

Legitimate interests pursued by us: To improve the professional competence of employees and ensure the quality of products and services

Employee occupational health and work safety management

Legitimate interests pursued by us: To ensure the occupational health of employees and workplace safety; Protection of the vital interests of employees

Recruitment screening and employment process handling

Steps prior to entering into an employment contract: To carry out recruitment related work based on your job application

System account management and security protection

Legitimate interests pursued by us: To ensure the security of information systems and accounts, and prevent cybersecurity risks

Official website service quality optimization

Legitimate interests pursued by us: To continuously optimize the user experience of the official website and improve service quality

Prevention of unauthorized use of the official website and handling of related disputes

Legitimate interests pursued by us: To ensure the normal operation and functional stability of the official website, and prevent cybersecurity and fraud risks

Establishment, exercise or defense of legitimate legal rights

Legitimate interests pursued by us: To safeguard our legitimate rights and interests through legal channels, and respond to relevant litigation, arbitration and disputes

Fulfillment of obligations stipulated by laws and regulations

Compliance with legal obligations: To comply with applicable laws and regulations, regulatory requirements, and fulfill statutory obligations such as medical device supervision and adverse event reporting

(4) Retention Period

We will only retain your personal data for the shortest period necessary to achieve the purposes of processing, or for the retention period mandatory required by applicable laws. When the retention period expires, or the purposes of processing have been achieved and your personal data is no longer needed to be retained, we will immediately delete or anonymize your personal data in strict accordance with the EU/UK Privacy Laws.

(5) Cross-Border Transfer of Personal Data

Our disclosure of your personal data to our contractors (processors within the meaning of the GDPR/UK GDPR), affiliated group companies, or other third parties may constitute a cross-border transfer of personal data to a country or territory outside the EEA member states or the UK, including the People's Republic of China, which has not received an adequacy decision from the European Commission or the UK government.

In such cases, we will implement all necessary safeguards to ensure the protection of your personal data in full compliance with GDPR, UK GDPR and applicable data protection laws. The primary safeguard we rely on is the Standard Contractual Clauses (SCCs) adopted by the European Commission, the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the European Commission's SCCs approved by the UK Parliament, as applicable.

We ensure that all such transfers are covered by a valid signed agreement incorporating the applicable SCCs/IDTA, which imposes binding data protection obligations on the data recipient, equivalent to those under GDPR/UK GDPR. You may request a copy of the relevant signed data transfer agreement at any time by contacting our data protection contact point set out in this Policy.

For transfers related to medical device regulatory compliance, including adverse event reporting, post-market surveillance, and conformity assessment with EU MDR/UK MDR, we will ensure such transfers are conducted in full compliance with both medical device regulations and data protection laws, with all necessary safeguards in place.

(6) Your Rights

You have the following rights under the EU/UK Privacy Laws with respect to your personal data processed by us:

Right to withdraw consent: You have the right to withdraw your consent previously given to our processing of your personal data at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Right of access: You have the right to inquire about, access and request copies of your personal data held by us.

Right to rectification: You have the right to request us to correct inaccurate personal data about you, and to complete incomplete personal data held by us.

Right to erasure: You have the right to request that we erase your personal data, under certain conditions in accordance with applicable laws.

Right to restriction of processing: You have the right to request that we restrict the processing of your personal data, under certain conditions in accordance with applicable laws.

Right to data portability: You have the right to request us to provide your personal data in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller, under certain conditions in accordance with applicable laws.

Right to object: You have the right to object to our processing of your personal data based on our legitimate interests, under certain conditions in accordance with applicable laws.

If you need to exercise the above rights, or have any questions about your rights, please contact us through the contact window listed in Section 12 of this Policy.

(7) Right to Lodge a Complaint with a Data Protection Authority

You have the right to lodge a complaint about our personal data processing activities with the data protection supervisory authority in the jurisdiction of your residence. Contact information for supervisory authorities can be found via the official links below:

For EEA residents: https://edpb.europa.eu/about-edpb/about-edpb/members_en

For UK residents: https://ico.org.uk/

14. Additional Information for Residents of the United States

For residents of the United States, we provide the following additional information in accordance with applicable U.S. federal and state privacy laws and regulations, including the California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Texas Data Privacy and Security Act (TDPSA) (hereinafter collectively referred to as "U.S. Privacy Laws"). In the event of any inconsistency or conflict between the foregoing general terms of this Policy and this Additional Information, this Additional Information shall prevail for residents of the United States to the extent of such inconsistency or conflict.

(1) Data Controller

We are the personal information controller/business as defined in the U.S. Privacy Laws.

(2) Categories and Sources of Personal Information Collected

The categories and sources of personal information we have collected in the past 12 months are as follows, and all collection activities are strictly limited to the extent necessary to achieve the business purposes set out in Section 4 of this Policy:

Categories of Personal Information

Sources of Collection

Personal identifiers (full name, contact information, address, IP address, device identification information, etc.)

Yourself, affiliated companies of Foshan Aike Medical Equipment Co., Ltd., distributors of our products, service providers

Commercial records information (product purchase, use, intended purchase records, etc.)

Yourself, affiliated companies of Foshan Aike Medical Equipment Co., Ltd., distributors of our products

Internet activity information (official website browsing history, interaction information, etc.)

Yourself

Geolocation information

Yourself, the device you use

Professional or employment-related information (work history, qualifications, practicing license information, etc.)

Yourself, affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

Health-related information (treatment-related information, adverse event reporting-related information, etc.)

Yourself, medical institutions, affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

Audio, electronic, visual information (photos, videos related to events and visits, etc.)

Yourself, affiliated companies of Foshan Aike Medical Equipment Co., Ltd.

Other information related to you and necessary to achieve business purposes

Yourself, the aforementioned relevant sources

(3) Use, Disclosure and Sale/Sharing of Personal Information

We only use and disclose your personal information for the business purposes set out in Section 4 of this Policy, and the categories of recipients of specific disclosures are detailed in Section 5 of this Policy.

We do not sell your personal information to third parties, and only share your personal information for cross-context behavioral advertising to the extent permitted by applicable laws. For such sharing, we will strictly comply with the U.S. Privacy Laws and provide you with the right to opt out of such sharing at any time, and will not take any discriminatory measures against you if you choose to opt out.

(4) Retention Period

We will only retain your personal information for the shortest period necessary to achieve the purposes of processing, or for the retention period mandatory required by applicable laws. When the retention period expires, or the purposes of processing have been achieved and your personal data is no longer needed to be retained, we will immediately securely delete or anonymize your personal information.

(5) Cross-Border Transfer

When we transfer your personal information to countries/regions outside the United States, we will strictly comply with applicable U.S. state privacy laws and take sufficient security safeguards to ensure that your personal information rights and interests are effectively protected.

(6) Your Rights

You have the following statutory rights regarding your personal information in accordance with the U.S. Privacy Laws, and we will not take any discriminatory measures against you for exercising your rights:

Right to Know: You have the right to request us to disclose the relevant information about our collection, use, disclosure and sale of your personal information in the past 12 months.

Right to Access: You have the right to request access to your personal information held by us.

Right to Rectification: You have the right to request us to correct inaccurate personal information about you.

Right to Deletion: You have the right to request that we delete your personal information, under certain conditions in accordance with applicable laws.

Right to Opt Out: You have the right to opt out of our sharing of your personal information for cross-context behavioral advertising purposes at any time.

Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal information, under certain conditions in accordance with applicable laws.

To prevent risks such as fraud, identity impersonation and abuse of rights, we have the right to require you to provide valid identity documents to complete identity verification before responding to your request. You may exercise the above rights through the contact window listed in Section 12 of this Policy.

(7) Limitation of Liability

To the fullest extent permitted by applicable mandatory U.S. federal and state laws:

In no event shall we be liable for any indirect, incidental, special, punitive or consequential damages, including but not limited to loss of profits, loss of business, loss of revenue, or loss of goodwill, arising out of or related to our processing or disclosure of your personal information, even if we have been advised of the possibility of such damages.

Our total aggregate liability to you for any and all claims related to this Policy and the processing of your personal information shall not exceed the total amount you paid to us for the relevant products or services in the 12 months preceding the claim, or $1000, whichever is greater.

This limitation of liability does not apply to liability caused by our willful misconduct, gross negligence, or liability that cannot be limited by applicable mandatory law.

(8) Complaint Channel

If you have any questions, complaints or suggestions about our personal information processing activities, you can contact us through the contact window listed in Section 12 of this Policy, and we will respond within the statutory time limit.