PRIVACY POLICY
We, Retail Technology Asia Limited and its affiliates (collectively, "RTA" or "we"), are strongly committed to respecting the Users’ (including both Enterprise Users and Employee Users, collectively, “Users” or “you”) privacy and protecting your information.
This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use the RTA OS system, which is operated by us, including forms such as "OS Phone," "OS Pad," and "OS PC," as well as functions including but not limited to order placement, article query, inventory management, and goods receive and returns (collectively, the "Services"). Please note that this Privacy Policy does not apply to the processing of your information by third parties through your use of any third-party integrations available via our Services. Please always review the relevant third-party provider's legal documents including but not limited to terms of service and privacy policy.
If you have any questions, comments, or suggestions, please contact us through the feedback channels specified in the “Contact Us” section of this Privacy Policy.
This Privacy Policy aims to inform you about the following:
I. What Personal Data Do We Collect and When Do We Collect
II. Why and How We Use Your Personal Data
III. How We Share Your Personal Data
IV. How Do We Use Cookies and Similar Technologies
V. How We Protect Your Personal Data
VI. How to Exercise Your Personal Data Subject Rights
VII. How Long We Store Your Personal Data
VIII. Whether Your Data Will be Transmitted to a Third Country
IX. How We Handle Minors’ Personal Data
X. Changes to Our Privacy Policy
XI. Contact Us
XII. Definitions and Interpretation
XIII. Additional Country and Regional Specific Provisions
I. What Personal Data Do We Collect and When Do We Collect
We collect your personal data strictly based on the requirements of the applicable laws, regulations, regulatory requirements, and mature industry security standards, and the consensus reached with Enterprise Users in the data processing agreement or similar agreements that we made with such Enterprise Users. We collect your personal data to fulfill our service obligations and to optimize the Services. We will not collect your personal data without specified, explicit and legitimate basis.
The following list outlines the personal data that we may collect under different scenarios
1. Data you provide to us
We receive and store necessary personal data you provide in relation to use certain functions of the Services. Specific personal data categories are as shown below. You are fully capable of choosing not to provide certain types of personal data, but absence of certain personal data may result in limitations or inability to use certain features of the Services.
Contact Data: name, phone number, email address, profile picture.
Account Data: account number, account password, third-party platform account data, pictures.
2. Personal data collected by automated means
We automatically collect and store certain data about your use of the Services. Specific categories of automatically collected personal data are listed below. Such data are necessary for logging in your account and using our basic services. If you refuse to provide such personal data, please discontinue using the Services and contact the Enterprise User Administrator who activated your account for further deletion of such personal data.
Device Information: device ID, device name, device model, device type, hardware serial number, device MAC address, software list, device advertising identifier, operating system name, operating system version, system language, resolution, device identification code (IMEI/IDFA/OpenUDID/GUID, or SIM card IMSI information, Android ID), network card address.
Service Usage Data: When you use our Services, we automatically collect detailed information about your usage of our Services, saved as service logs, including browsing, clicking, search queries, transactions, information published, as well as IP address, browser type, telecommunications operator, language used, access date and time. We also automatically collect your UID.
3. Data from other sources
We may receive data about you from Enterprise User (data controller):
Personal data related to the business relationship with RTA: employee number, affiliated group, affiliated Enterprise User, store number, store name
Such information is provided by the Enterprise User Administrator. Before the Enterprise User provides such personal data of yours to us, the processing of such information shall have been lawfully authorized by you and is managed by the Enterprise User you work for. Based on the Enterprise User's commitment to the legality of the source of such personal data, we make such data collection for matching purpose with the Enterprise Users in order to provide you with corresponding product functions and protect your rights and interests.
4. Data of Employee User generated from additional functions
If you are an Employee User, during your use of the Services, beyond the information necessary for the basic services we provide, we will also collect information required based on other functions activated by your affiliated Enterprise User. In such cases, we will collect and process information based on the instructions of that Enterprise User to achieve the functional purpose.
Such Additional Function Data belonging to Employee Users include: work information and records generated from using the Services, communication and call records, geolocation and movement trajectory information.
II. Why and How We Use Your Personal Data
In accordance with the relevant requirements of the applicable laws, we process personal data on behalf of the Enterprise User when providing services for you. As we only act as a Personal Data Processor in this process, we may only process your various personal data based on the instructions of the Enterprise User as the Personal Data Controller under the premise of complying with the applicable laws. Any information you provide is retained and controlled by Enterprise User as the Personal Data Controller. An Enterprise User Administrator is generally a personnel authorized or designated by an Enterprise User with administrative rights under the Enterprise User’s account. We will work with you to the fullest extent possible to realize your legitimate personal data rights in accordance with our agreements with data controllers, instructions from Enterprise User Administrator, applicable laws and regulations.
RTA only uses the personal data that has been collected for the sole purpose of implementing some of the product features for your use. The details of why and how your personal data is used are as follow。
| Purpose | Type of Personal Data | Legal Bases |
| To provide you with functions related to user account management, such as account registration, account deletion, account login, and modification of account information | *Contact Data *Account Data *Service Usage Data *Personal data related to the business relationship with RTA | Performance of contract |
| To provide and facilitate the Services for you, so that you could interact with the Services | *Service Usage Data *Additional Function Data | Performance of contract |
| To communicate with you for non-marketing purposes including by sending you Services-related notices, push notifications, and other messages. | *Contact Data *Service Usage Data | Performance of contract |
| To identify the abnormal status, ensure the stability and security of our Services as well as to improve our Services | *Device Information *Service Usage Data | Legitimate interests & Performance of contract & Consent, where required by applicable laws |
| To investigate and resolve security issues | *Device Information *Service Usage Data | |
| To comply with legal obligations, and defending against legal claims and disputes | *Contact Data * Account Data *Device Information *Service Usage Data *Service Usage Data *Personal data related to the business relationship with RTA *Additional Function Data | Legal obligations & Legitimate interests & Consent, where required by applicable laws |
III. How We Share Your Personal Data
We may share your personal data with the recipients or in the scenarios listed below, for the above purposes.
(1) Service Providers and Business Partners. Certain specific modules or functions within our products/services are provided by external suppliers. For example, we may use third-party software for functions like account verification or audio extraction. For companies, organizations, and individuals entrusted by us to process personal data, we enter into strict confidentiality agreements requiring them to process personal data according to our requirements, this Privacy Policy, and any other relevant confidentiality and security measures.
(2) Our Corporate Group. To facilitate our provision of Services to you, identify abnormal member accounts, and protect the personal or property safety of our affiliates, other users, or the public from infringement, your personal data may be shared with our affiliates. We only share necessary personal data, constrained by the purposes stated in this Privacy Policy. If we share your sensitive personal data or if our affiliates change the purpose of use and processing of personal data, we will seek your authorization and consent again.
(3) Enterprise User and its Designated Third Parties. To enable the affiliated Enterprise User to manage, verify, and supervise the work status of its Employee Users, we will share information provided by the Employee User under relevant functions with the Enterprise User or any third parties designated by it, based on the product/service content selected and activated by that Enterprise User.
(4) Legal Obligations. We may share your personal data as required by laws and regulations, litigation, dispute resolution needs, or requests from administrative or judicial authorities according to law.
(5) Third-party software tool development kit (SDK). In order to provide better services, we use third-party SDKs. These third-party SDKs may collect your personal data while providing you with more comprehensive services. We adopt necessary technical measures to evaluate and control the collection and use of your personal data by these third-party SDKs to ensure that your personal data is effectively protected. We conduct strict security checks on SDKs and require our partners to take strict measures to protect your personal data.
(6) Sale or Merger. In the event of a merger, acquisition, bankruptcy liquidation, or other similar transaction involving us, if personal data transfer is involved, we will require the new holder of your personal data to continue to be bound by this Privacy Policy. Otherwise, we will require that company, organization, or individual to seek your authorization and consent again.
(7) With Your Consent. We may share your personal data for other purposes pursuant to your consent or at your direction.
IV. How Do We Use Cookies and Similar Technologies
To provide you with a more convenient access experience, when you use the Services, we may collect and store data related to your access using various technologies. When you access or revisit the Services, we can recognize your identity and analyze the data to provide you with better and more services. This includes using small data files to identify you, done to understand your usage habits, save you the trouble of repeatedly entering account information, or help determine your account security. These datafiles may be Cookies, Flash Cookies, or other local storage provided by your browser or associated applications (collectively referred to as "Cookies"). Please review our Cookies Policy [m1] published on our official website for more information about how you can control our use of cookies and similar technologies.
V. How We Protect Your Personal Data
We have implemented reasonable and feasible security protection measures aligned with industry standards to protect your information against unauthorized access, public disclosure, use, modification, damage, or loss. For example: Data exchanged between your system terminal and our servers is protected by SSL protocol encryption; We provide HTTPS protocol secure browsing for the website; We use encryption technologies to enhance the security of personal data; We employ trusted protection mechanisms to prevent personal data from malicious attacks; We deploy access control mechanisms to endeavor to ensure only authorized personnel can access personal data; and we conduct security and privacy protection training to strengthen employees' awareness of the importance of protecting personal data.
We maintain an industry-leading data-centric security management system centered around the data lifecycle, enhancing overall system security through organizational structure, system design, personnel management, and product technology. Currently, our critical information systems have obtained multiple internationally recognized certifications related to personal data protection and information security management, including ISO 27701 (Privacy Information Management System) and ISO 27001 (Information Security Management System).
We retain your personal data only for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our criteria for determining this period include:
a) Completing work records related to you, addressing your potential queries, or handling disputes;
b) Ensuring the security and quality of the Services we provide to you;
c) Whether you have consented to a longer retention period; and
d) The existence of any other special agreements regarding retention periods.
Beyond the above period, we will delete or anonymize your personal data as required by applicable laws or regulations.
Notwithstanding the aforementioned reasonable security measures, please be aware and understand that due to the limitations of technology, the internet is not an absolutely secure environment. Therefore, we strongly recommend that you take proactive measures to protect the security of your personal data, including but not limited to using complex passwords and strengthening permission controls, to assist us in ensuring your account security. We will endeavor to ensure the security of any information you send to us. If our physical, technical, or administrative safeguards are breached, leading to unauthorized access, public disclosure, alteration, or destruction of your personal data, thereby damaging your legitimate rights and interests, we will bear corresponding legal liabilities.
In the unfortunate event of a personal data security incident, we will notify you in accordance with legal requirements, providing information on the basic situation of the security incident and its potential impact; measures we have taken or will take; recommendations for you to prevent and mitigate risks; and remedial measures available to you. We will inform you of the incident-related circumstances via email, letter, phone, push notification, etc. If it is difficult to notify each data subject individually, we will adopt reasonable and effective methods to issue an announcement. Simultaneously, we will report the handling of the personal data security incident to the relevant supervisory authorities as required.
VI. How to Exercise Your Personal Data Subject Rights
To the extent provided by applicable data protection laws, you have the following personal data rights:
1.The right to be informed
You have the right to clearly understand and be informed of how we process your personal data, the types of personal data we process, the purposes for processing such personal data, and the information about the third parties to which your personal data is shared with. In this Privacy Policy, we have a detailed explanation of the processing of your personal data. If you have any questions, please contact the Enterprise User Administrator who activated your account to further assist you.
2.The right to access your personal data and obtain a copy
You have the right to access your account to view your personal data at any time through the websites or Apps. You may contact the Enterprise User Administrator who activated your account if you wish to access your other personal data, obtain a copy of your personal data, or encounter difficulties while exercising the aforementioned rights.
3.The right to rectification
You have the right to ask us to rectify any incomplete or inaccurate personal data we hold about you. However, in any case, you need to ensure the authenticity and accuracy of the data you provide. If any loss is incurred due to the incorrect, inaccurate, or incomplete data provided, you need to assume responsibility for this.
If you wish to rectify your other personal data, or encounter difficulties while exercising the aforementioned rights, you can contact the Enterprise User Administrator who activated your account. The Enterprise User Administrator will respond to your request in time after confirmation of your identity.
4.The right to erasure
You have the right to delete your account and erase your personal data. Additionally, you may also request deletion of the personal data you provide by contacting the Enterprise User Administrator who activated your account. If some of your personal data cannot be deleted, we will inform you of the reasons for not taking action. If you request us to delete your personal data, you may not be able to continue to use any Service that requires our use of your personal data.
5.The right to restriction of processing
In the following cases, you have the right to ask us to limit (stop any active) processing of your personal data in certain circumstances. If you have encountered any of the following situations, you can contact the Enterprise User Administrator who activated your account. The Enterprise User Administrator will respond to your request in time after confirmation of your identity.
(1) The personal data we collect about you is inaccurate, and you provide us permission and a certain period to verify its accuracy;
(2) You believe the processing of your personal data is unlawful, but you request to restrict the use of your personal data instead of requesting its erasure;
(3) We no longer need the personal data for the purposes of the processing, but you need the personal data in order to exercise or defend your legal rights;
(4) You have objected to the processing of your personal data based on legitimate interests and are evaluating the legal basis you proposed.
6.The right to object to processing
You have the right to object to the processing of your personal data based on your legitimate interests. Unless we can prove that there are legitimate reasons, we will no longer process your personal data.
7.The right to information portability
You may contact the Enterprise User Administrator who activated your account to request the personal data you have provided to us in a structured, commonly used and machine-readable format and have it transferred to another controller, to the extent applicable.
8.The right to withdraw consent
Where we process your personal data on the basis of your consent, you may withdraw your consent by contacting the Enterprise User Administrator who activated your account. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
9.Not to be subject to a decision based solely on automated means
The Services will not involve the scenario of automated decision making as of now.
10.Lodge a complaint with your local data protection authority
Subject to applicable data protection laws, you may have the right to submit your complaint to the local data protection authority where you reside if you consider that the processing of your personal data infringes any applicable data protection laws.
11.Responding to Your Request
Depending on your jurisdiction, you may be entitled to additional rights in relation to your personal data. If you would like to contact us to exercise one or more of these rights, to ask a question about these rights or any other provision of this Policy or about our processing of your personal data, or to file a complaint about how we process your personal data, you may contact your Enterprise User Administrator or send email to info@dmall.com to contact us. You may be asked to submit relevant proof to verify your identity for safety reasons before your request is processed. Once the legitimacy and identity of your request is verified, we will complete the necessary processing within a reasonable time period after receiving the confirmation from the Enterprise User Administrator.
VII. How Long We Store Your Personal Data
We adhere to retention policies for the personal data we collect to ensure that it is not retained longer than necessary for the intended purpose. Different retention periods are applied to the various types of personal data collected by us in accordance with the service needs and regulatory requirements. We may retain your personal data for additional periods if necessary for compliance with legal obligations to process your personal data or if the personal data is needed by us to assert or defend itself against legal claims.
We will retain your personal data until the end of the relevant retention period or until the claims in question have been settled. To the extent allowed by applicable laws, we store your personal data only for as long as it is required:
to provide our Services to you;
to develop Services until this is no longer necessary or we are informed that your relationship with the Enterprise User has changed;
to fulfill our legitimate business purposes as further described in this Privacy Policy, unless you object to our use of your personal data for these purposes;
for us to comply with statutory obligations to retain personal data, resulting inter alia e.g., from applicable export, finance, tax or commercial laws;
until you revoke a consent you previously granted to us to process your personal data.
Upon expiration of the retention period, we will either delete or anonymize your personal data. Measures will be taken to render the information irrecoverable or irreproducible.
VIII. Whether Your Data Will be Transmitted to a Third Country
Personal data collected and generated during your use of our Services is stored in Singapore. Due to the international nature of our business, we may remotely access your personal data from Mainland China and your personal data may also be accessed by our affiliates or be transferred to third-party service providers and business partners, in connection with the purposes set out in this Privacy Policy. For this reason, we transfer personal data to other jurisdictions that may have different laws and data protection compliance requirements to those that apply in the jurisdiction in which you are located. Additionally, in accordance with applicable laws and regulations, your personal data may be accessed by law enforcement authorities in the recipient country.
In the event of an international transfer of personal data, when required by applicable laws, we will provide an adequate level of protection for your personal data using various means, including where appropriate, implementing data transfer agreements that comply with applicable laws between our affiliates and third parties (where applicable) or any other lawful approach that permits the lawful transfer of personal data from those countries.
If you have any questions regarding the cross-border transfer of your information or wish to obtain further information, please contact us using the details provided in Section XI below.
IX.How We Handle Minors’ Personal Data
In general, our Services are not directed to individuals below the age of 16 years, or equivalent minimum age in the relevant jurisdiction (“minors”). We do not collect personal data from minors (Enterprise Users are responsible for verifying the identity of minors). We attach great importance to the protection of minors’ personal data, and if we become aware that certain personal data of a minor has been collected incorrectly, we will take instantaneous and reasonable steps to delete such data to the greatest operable extent. As a data subject, legal guardian of the minor or other eligible person, you can also request to delete the data of such minors by contacting the Enterprise User Administrator or by sending an email to info@dmall.com.
X. Changes to Our Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our personal data practices. As such we encourage you to revisit this Privacy Policy regularly. The date at the top of this Privacy Policy lets you know when it was last updated. If there are any substantial changes to this Privacy Policy, depending on the nature of such changes, we will notify you in advance through pop-ups, push notifications, emails, and other appropriate means. We will handle your personal data in a manner consistent with the Privacy Policy under which it was collected unless we are allowed to handle it differently.
XI. Contact Us
We welcome questions, opinions and concerns about our Privacy Policy and privacy practices. If you wish to provide feedback, have questions or concerns, or wish to exercise your rights with respect to your personal data, please contact us by using the following information:
Retail Technology Asia Limited
Address: [Unit717-718, Level7, CoreF, Cyberport3, 100 Cyberport Road, Hong Kong]
Representative: [Michael Lo]
Contact details:
• send an email to info@dmall.com, and we will complete the review and processing within one month after receiving your comments and suggestions. If we are unable to respond to your request, we will send you a notice and explain the reason.
• "Contact Us" section of our website or App.
XII. Definitions and Interpretation
User: All users of the Services, including Enterprise Users and Employee Users.
Enterprise User: Non-natural person users of the Services, including but not limited to companies, government agencies, partnerships, individual businesses, and other organizations.
Enterprise User Administrator: Personnel authorized or designated by an Enterprise User with administrative rights under the Enterprise User’s account. Any actions taken by the Enterprise User Administrator under the Enterprise User’s account shall be deemed as actions of such Enterprise User, for which the Enterprise User shall bear full responsibility.
Employee User: Natural persons using the Services at the direction of the Enterprise User, including but not limited to formal employees, dispatched personnel, and temporary service personnel of the Enterprise User. Employee Users include Enterprise User Administrators and other employee users. Enterprise Users shall manage Employee Users effectively through the Services.
Enterprise Account: A system account for the Services obtained by an Enterprise User through registration or execution of a service agreement.
Employee Account: A sub-account under an Enterprise Account created by the Enterprise User Administrator for an Employee User, with permissions and functions configured by the Enterprise User Administrator in accordance with the Enterprise User’s authorization and requirements.
Personal Data: any data relating to an identified or identifiable individual. In certain jurisdictions, this may be referred to as “personal information”.
Personal Data Controller: an individual or an organization that determines the purposes and means of data processing.
Personal Data Processor: an individual or an organization that processes personal data on behalf of and per the instruction of the Personal Data Controller. When we process data controlled by an Enterprise Account under the entrustment of the Enterprise User, the Enterprise User is the Personal Data Controller, and we are the Personal Data Processor.
XIII. Additional Country and Regional Specific Provisions
1. Where RTA is subject to the requirements of Singapore’s Personal Data Protection Act (“PDPA”)
Where RTA is subject to the requirements of Singapore’s Personal Data Protection Act (“PDPA”), the following applies:
RTA has appointed a Data Protection Officer for Singapore. Written inquiries, requests or complaints to our Data Protection Officer may be addressed to:
Subject: Data Protection Officer
Email: [dposingapore.list@hankunlaw.com ]
Contact: [65-6013 2999 ]
2. Where RTA is subject to privacy requirements in the Philippines
Where RTA is subject to privacy requirements in the Philippines, the following also applies:
Within the Philippines you have the right to:
· Claim compensation as finally awarded by the National Privacy Commission or the courts if you suffered damages due to inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal data, considering any violation of your rights and freedoms.
· File a complaint with the National Privacy Commission if you are the subject of a privacy violation or personal data breach or are otherwise personally affected by a violation of the Data Privacy Act.
· Your Transmissibility Rights. Your lawful heirs and assigns may invoke your rights at any time after your death or when you are incapacitated or incapable of exercising your rights.
Updated and Effective: August 31, 2025


