Privacy Policy

Last Updated: Apr 18, 2024
Effective on: Apr 18, 2024


Introduction

HELIOS, a business travel management and expense reimbursement product developed by Shanghai Zhenhui Information Technology Co., Ltd. (hereinafter referred to as "we" or "us"), understands that you are concerned about how your personal data we collect is used and shared.We will collect and use your personal information in accordance with the laws and regulations of the People's Republic of China, including the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Information Security Technology-Personal Information Security Specification (GB/T 35273-2020), and other relevant laws, regulations, and technical specifications, to help us provide you with better products and services. This Privacy Policy describes the privacy practices of HELIOS in connection with personal information that we collect through various channels including the extended features of the software applications provided and the websites operated (collectively, the "domain names"), through our social media pages (collectively, our "social media pages"), and through other online and offline services and email messages sent to you (collectively, including the domains, the apps and our social media pages, the "sites"). "You" or "User" means any individual who accesses or otherwise uses the website.

This Privacy Policy does not apply to the practices of third parties that are not owned or controlled by HELIOS, nor to individuals who are not employed or managed by HELIOS. This Privacy Policy also does not apply to information we receive or process as a software provider on behalf of our tenants, such as information we receive through HELIOS's expense claim software service or other HELIOS services, including any apps we provide for tenants (collectively referred to as "subscription services"). Such information is subject to the terms of the applicable subscription service agreement, not this Privacy Policy.

You can contact us at privacy@huilianyi.com for a copy of this Privacy Policy.


What types of information does HELIOS collect?

  1. Personal data: "Personal data" is information that directly or indirectly identifies you or other individuals, which may include name, title, company name, job function, expertise, postal address, mobile number, email address, browser and device information (including IP address), and information collected through cookies and other similar technologies. If you submit any personal data relating to other people to us or to any service providers in connection with this website, please ensure you are legally authorized to do so and permit us to collect and process such information in accordance with this Privacy Policy.
  2. Device information: "Device information" refers to device identifiers (such as the IMEI/android ID/ICCID information of your device model), device MAC address, mobile application list and other information. Without your authorization, we will not obtain the above information in advance. Most mobile phone terminal manufacturers currently support changes to device identifiers to ensure your independent control of personal information.
  3. Other information: "Other information" is any information that will not and cannot be used to disclose your identity or other individual's identity, such as information that has been completely and permanently anonymous and aggregated. We use this information to promote the operation of our website and for other purposes described below.
  4. Generally, we will collect and use your personal data in the following scenarios:
    • At the time of activating your account, we will collect your mainland China/international mobile number or email address; at the time of logging in to your account through One Click Login, we will collect your mobile number or email address; at the time of logging in to our system using Single Sign On (SSO), we will collect your email address or mobile number (or enterprise account and name); and, at the time of recovering or resetting the forgotten password, we will collect the verification code sent to you.
    • Under normal circumstances, your enterprise administrator will provide your personal data, including necessary information (such as email address) and other non-necessary information (such as name, mobile number, gender, company, department, job position, designation, rank, employee id, direct manager, hire date and work site address) to us after obtaining your authorization, to help you register as a Helios user and enjoy our services. At the same time, we will also be responsible for updating your personal data saved in our system. If you refuse to provide the necessary information, your enterprise administrator will not be able to complete the user registration.
    • If you want to request for reimbursement for your business expenses, we may need to collect your bank account holder name, card number, bank address, bank branch name, Alipay account, account holder name, Alipay UID and other information.
    • If you want to use the services provided by third-party TMCs through Helios, we will collect relevant information about you, which may include your name, id information, email address, mobile number, gender, location, authorizer, department and rank, and provide it to the third-party TMC after obtaining your explicit consent and authorization. We collect and provide such information for the purpose of providing you with hotel or flight booking, notification and subsequent cancellation and change services. For details, see the TMC Authorization Agreement.
    • If you want to use our Private Vehicle function, we will collect your location information.
    • The information you provide through our customer service or when you participate in our activities, such as your name, mobile number, address and other information that may be included in the questionnaire you fill in when you participate in our online activities.
    • We will collect some information from your device, such as the device model, operating system, unique device identifier, mode of access to the network, type and state, browser type, IP address, referral site, date and time of each visitor request, service logs and operation logs, for the purpose of better understanding how our visitors use our website. We may release this information from time to time in a summary manner, for example by publishing reports on trends in the use of our website.
    • Required application permissions:
      1. Scan, OCR and Upload Attachments features: Permissions to access and change device’s internal storage, access camera, and access gallery;
      2. Image Reading feature: Permissions to access and change device’s internal storage;
      3. Contact Us feature: Permissions to directly make phone calls;
      4. Mileage Allowance Positioning feature: Permissions to get location info, WLAN connectivity and device status info;
      5. Auxiliary Positioning feature: Permissions to get WLAN connectivity info;
      6. Voice Input feature: Permissions to access microphone;
      7. Positioning feature: Permissions to get device status info and permissions to access and change WLAN connectivity info.

How does HELIOS collect information?

We and our service providers may collect personal data and other information in various ways, including:

  1. Through the website: We may collect information through the website. For example, when you apply for a free trial or demo, register for a webinar, contact us, subscribe to our email newsletter, download product content (such as product white papers) or register to try out our software services.
  2. Through our offline services: We may collect your information offline. For example, when you participate in one of our activities, call a sales representative, or contact a HELIOS representative.
  3. Through you: When you voluntarily provide information, HELIOS will collect information such as your location or your preferred method of communication. Unless used in conjunction with personal data, this information will not identify you or any other user of this website.
  4. From other sources: In order to enhance our ability to provide you with relevant marketing, offers and services, we obtain information about you from other sources, such as public databases, joint marketing partners, social media platforms and other third parties.
  5. Through your browser or device: Certain information is collected by most browsers or automatically through your device, such as your media access control (MAC) address, computer type (Windows or Macintosh), screen resolution, name and version of operating system, device manufacturer and model, language, type and version of web browser, and the name and version of the site (such as an application) you are using. Your "IP address" is a number that is automatically assigned to the computer that you are using by your Internet service provider (ISP). An IP address may be identified and logged automatically in our server log files whenever a user accesses the site, along with the time of the visit and the pages that were visited. Collecting IP addresses is standard practice and is done automatically by many websites, applications and other services. We use the IP address for several purposes, such as calculating usage levels, diagnosing server problems, and administering sites. We may also derive your approximate location from your IP address.
  6. Through your use of the apps: When you download and use an app, we and our service providers may track and collect app usage data, such as the date and time the app on your device accesses our servers as well as the information and files downloaded to the app, based on your device number.
  7. Using cookies and other similar technologies: "Cookies" include general information in the form of small files, which are placed on personal devices, making it easier for individuals to communicate and interact with websites. When you access our website, we may send one or more cookies to your device, which allow us to store information about your device, helping us provide you a good experience when accessing our website and improve the services and functions provided for you. We recognize the automatic browser signal about the tracking mechanism, which may include the "Do-Not-Track" signals.
  8. By aggregating information: Aggregated personal data does not personally identify you or any other user of the site (for example, we may aggregate personal data to calculate the percentage of our users who have a particular telephone area code).
  9. Through your enterprise: This information may include your name, mobile number, email address, gender, company, department, position, designation, rank, employee id, hire date, and work site address. Before uploading your personal data to Helios, enterprise users should ensure that they have obtained your explicit consent in advance and have fully informed you of the purpose, scope and usage of relevant data.

How does HELIOS use personal data?

We may use personal data for the following purposes:

  1. To respond to your inquiries and meet your requirements; for example, to send you the materials and newsletters you request, as well as information and materials about our products and services.
  2. To send you administrative information, for example, information about the site and changes to our terms, conditions and policies.
  3. For our business purposes, such as data analysis, audits, security and fraud monitoring and prevention, developing new products, enhancing, improving or modifying our site and services, identifying usage trends, determining the effectiveness of our promotional campaigns and operating and expanding our business activities.
  4. We will:
    1. obey applicable laws, including laws outside your country of residence;
    2. comply with legal procedures;
    3. respond to requests from public and government authorities, including those outside your country of residence;
    4. enforce our terms and conditions;
    5. protect our business or the business of any of our affiliates;
    6. protect our rights, privacy, security or property, or the rights of our affiliates, you or others;
    7. seek available remedies or limit possible damages.
    The legal basis for our collection and use of the above personal data will depend on the relevant personal data and the actual condition of our collection. We may collect and use your personal data for the purpose of our legitimate business interests. For example, we may directly promote HELIOS expense claim platform and applications to potential business-to-business (B2B) customers. In some cases, the legal basis for processing personal data will also be based on your consent or a contract with you. In some cases, we may also have a legal obligation to collect personal data from you.
    If we ask you to provide personal data to comply with legal requirements or to enter into a contract, we will make it clear at the relevant time whether you must provide your personal data (and the possible consequences if you do not provide your personal data).

How does HELIOS share personal data?

HELIOS may disclose the processed personal data in the following cases (specific individuals cannot be identified and the data cannot be recovered):

  1. Subsidiaries and affiliates: We may disclose personal data to our subsidiaries and affiliates for the purposes described in this Privacy Policy. HELIOS is the party responsible for managing the jointly used personal data.
  2. Third-party business partners: We cooperates with various businesses and works closely with them to promote or sell products or services. In some cases, these businesses operate on the website. We may disclose personal data to our partners for the above purposes. Some of our third-party business partners may co-sponsor activities and other products with us. When you register for an activity or product, we may share your personal data with these co-sponsors to allow them to send you marketing messages that may be of interest to you as permitted by applicable laws.
  3. Agents and service providers: We may sign contracts with other companies and people to perform tasks on our behalf, and share your personal data with some of them to provide you with products or services, or to communicate with you in other ways, such as providing promotions on our behalf. Examples include removing duplicate information from customer list, analyzing data, providing marketing assistance, billing, processing credit card payments, providing technical support for our services, providing customer service, and performing analysis related to our products or services. We may also provide your personal data to agents and service providers to verify or aggregate the aggregated usage data we provide to our partners. When we share this information in this way, we will require our agents or service providers to maintain the privacy, confidentiality and security of personal data.
  4. HELIOS blog and social media pages: You may also disclose personal data through websites, message boards, chats, profile pages and blogs, and other services where you can post information and materials. This information can be displayed in a public manner, such as through a search engine or other publicly available platform, and can be "captured" or searched by third parties. Please do not post any information that you do not want to disclose to the public.
  5. Analysis and automatic decision making: We combine the data obtained through the methods described in Section 2 to help determine the products and services that may be of interest to you, and when you will purchase based on your repeated interactions with our website, email and content. Our marketing and sales personnel will participate in this process and will not make automatic decisions that would lead to legal effects or similar ones that could significantly affect individuals.
  6. To protect HELIOS and others: We may disclose personal data as we believe to be necessary or appropriate to law enforcement, taxation, fraud prevention, credit risk agencies, and other companies and organizations. See the last point in Section 3 above for the reason.

How does HELIOS use and disclose other information?

We may use and disclose other non-personal information unless we provide otherwise in accordance with applicable legal requirements. If we are required to treat other information as personal data in accordance with applicable laws, we will use or disclose it in the same way as we use and disclose personal data. In some cases, we may combine other information with personal data (such as combining your name with the name of your organization). If the combination allows you to be identified, we will treat the combined information as personal data as long as it is combined.

How does HELIOS protect my personal data?

We have implemented appropriate organizational, technical, and management measures to protect personal data within the organization, including security control to prevent unauthorized access to our system. Although we have taken reasonable measures to protect your personal data from loss, misuse, interference, and unauthorized access, modification, and disclosure, you should be aware that no security procedures or protocols can guarantee 100% protection from intrusion or hacking. Therefore, you always take some risks by sharing personal data online. If you have reason to believe that your interaction with us is no longer safe (for example, if you believe that the security of your account has been compromised), please notify us immediately following the "Questions, concerns, or complaints" section below.

How do I access, correct, modify, delete information about me or permanently remove my account?

If you want to access, correct, modify, delete or restrict the use or disclosure of any personal data collected and stored by HELIOS or to transfer it to other organizations or to permanently remove your account, please notify us at privacy@huilianyi.com so that we can consider and respond to your request in accordance with applicable laws. If you want to object to the processing of your personal data for direct marketing purposes, please use the mechanism outlined in Section 9 ("What choice do I have?"). To protect your interests, we only implement requests for personal data related to the specific email address that you send us the request to, and we need to verify your identity before implementing your request. We will respond to your request within fifteen (15) days. Please note that we need to retain certain information for record purposes and/or to complete any transaction that you started before requesting access, change, or deletion.

How will HELIOS store my personal data?

  1. Storage Location: In adherence to legal and regulatory provisions, the personal information collected and generated within the People's Republic of China during our operation will be stored within the territory of the People's Republic of China. Currently, we do not transfer your personal information abroad. If there is a need to transfer it overseas to satisfy corporate office management requirements, we will ensure through agreements and other means that your personal information is protected with no less rigor than is mandated by this policy and applicable national regulations.
  2. Storage Period: We will retain your personal data for the period necessary to fulfill the original collection purposes, including pursuing our legitimate business interests, complying with our legal obligations, resolving disputes, and enforcing applicable agreements.

What choice do I have?

You can always choose not to disclose information. However, if you choose to do so, you may be restricted from being responded to inquiries or enjoying our services. You can cancel the subscription through the "Unsubscribe" or unsubscribe link in the email, or send an email to privacy@huilianyi.com and choose not to receive marketing messages from HELIOS or our affiliates. We will comply with your request as soon as reasonably practicable. Please note that we may still send you important administrative email messages after you choose not to receive marketing-related emails.

Can children use HELIOS's website?

Our website is not directed to individuals under the age of eighteen (18). HELIOS will not intentionally or specifically collect information about individuals under the age of 18, and believes that children of any age should obtain the consent of their parents or legal guardians before providing any personal data. If you believe that we have collected such information by mistake or inadvertently, please notify us at privacy@huilianyi.com so that we can delete this information from our server.

Third-party websites

Our website has direct links or "Share" or "Like" buttons that can be used to link to other websites on the Internet; other websites may also contain links to our website. The information privacy practices or content of such other websites are subject to the privacy policies of those websites, not this Privacy Policy. We recommend that you check the privacy policies found on such other websites, services, and applications to understand how your information is collected and used. Also, please note that we are not responsible for the collection, use, and disclosure policies and practices (including data security practices) of other organizations, such as application providers, social media platform providers, operating system providers, wireless service providers, or device manufacturers, including any personal data that you disclose to other organizations through apps or social media pages.

Third-party SDKs

Some of the services of Helios APP need to be jointly provided by our partners (for example, notifications in notification bar). For this reason, the partners' software development kits (hereinafter referred to as "SDKs") or other similar applications will be embedded in Helios APP. If you use such services provided by third parties on our platform, you agree that your information will be directly collected and processed by them (such as in the form of embedded code or plug-ins). For example, when you use a mobile phone, the PUSH SDK provided by the mobile phone manufacturer needs to read your equipment identification number and information related to networking for pushing/issuing notifications. Helios APP will carry out strict security detection on the SDKs or other similar applications, and require our partners to take strict data protection measures to effectively protect your legitimate rights and interests.
For more details, please refer to the Directory of Helios APP Third-party SDKs.

Sensitive personal information

We request that you not send or disclose any non-necessary personal data to us, for example, social security number (SSN), information relating to race or ethnicity, sexual orientation, political opinions, religious or other beliefs, health, biometric or genetic characteristics, criminal background or community membership. We collect necessary sensitive personal information for the purpose of providing services to you. If you refuse to provide such information, you may not be able to get relevant services from us.

Updates to this Privacy Policy

We may change this Privacy Policy. The "Last Updated" legend at the top of this page indicates when this Privacy Policy was last revised. Any updates to this Privacy Policy will take effect when we post a revised Privacy Policy on our website.

Questions, concerns, or complaints

We take your privacy seriously. If you have any questions, concerns, or complaints about how we as a data controller collect and process your information, please contact our data protection officer (DPO). You can send an email to dataprotection@huilianyi.com or send a mail to the address of Room 202, No. 16, Jinhuan Business Garden, Lane 1977, Jinshajiang Road, Putuo District, Shanghai, 200333.

Since email communication is not always secure, please do not include credit card information or other sensitive information in the email.

HELIOS will take every privacy complaint seriously. Your complaints will be evaluated by appropriate personnel in order to resolve issues in a timely and effective manner. We request you work with us during this process and provide relevant information that we may need.

You may have the right to complain to the data protection agency about our collection and use of your personal data. Please contact your local data protection agency for more information.