IAdea Firmware & Connected Services Privacy Notice
This Privacy Notice describes how IAdea Corporation and IAdea America Corp. ("IAdea," "we," "us," or "our") process information in connection with supported IAdea Devices, Firmware, and Connected Services. It supplements the IAdea Device & Firmware EULA and IAdea Connected Services Terms. For convenience and clarity, key privacy-related terms are defined below. Capitalized terms not defined in this Privacy Notice have the meanings given in the applicable IAdea Device & Firmware EULA, IAdea Connected Services Terms, or IAdea Data Processing Addendum ("DPA"), as applicable.
Key Terms
"Customer" means the organization that purchases, deploys, administers, activates, or uses an IAdea Device or Connected Service.
"Device" means an IAdea-manufactured or IAdea-authorized hardware product covered by this Privacy Notice.
"Firmware" means IAdea software supplied with or for a Device, including the operating-system image, IAdea applications, security components, device-specific software, and Updates.
"Connected Services" means IAdea-hosted or IAdea-operated services associated with a Device, including Zero-Touch Enrollment, device management, provisioning, diagnostics, update services, and related cloud services.
"Customer Data" means information, configuration, applications, content, certificates, enrollment profiles, credentials, URLs, or other materials that a Customer submits, assigns, uploads, or otherwise makes available through Connected Services.
"Technical Data" means device, software, diagnostic, operational, security, update, provisioning, usage, and service information generated or processed in connection with Devices, Firmware, and Connected Services.
"Authorized Administrator" means a person designated or permitted by a Customer to administer the Customer's account, Devices, profiles, applications, or Connected Services.
"Personal Data" means information relating to an identified or identifiable individual, or equivalent information protected as personal information or personal data under applicable privacy law.
"Zero-Touch Enrollment or ZTE" means IAdea's service for validating an eligible Device and automatically applying configuration assigned by an Authorized Administrator.
"Update" means a firmware, operating-system, security, certificate, trust-store, IAdea application, configuration, compatibility, bug-fix, feature, or similar package made available for a Device.
"Standard Firmware Telemetry" means Technical Data generated or transmitted through standard Firmware operation for device, software, security, update, diagnostic, or operational purposes; it is not designed to collect end-user content or directly identifying end-user information as described in Section 2.5.
"MDEP" means the Microsoft Device Ecosystem Platform and related Microsoft-provided components incorporated into or used with supported IAdea Firmware.
These definitions are provided for this Privacy Notice. If a term has a more specific meaning under applicable privacy law, that legal meaning controls for purposes of that law.
1. Scope and Roles
This Notice applies to information processed by IAdea through supported Firmware, device-management connectivity, Zero-Touch Enrollment, provisioning, update services, diagnostics, customer portals, and related support activities.
Depending on the context and applicable law, IAdea may act as a controller/business for account, security, service-administration, billing, product-improvement, and legal-compliance information, and as a processor/service provider when processing personal data contained in Customer Data on behalf of an enterprise Customer. The applicable DPA governs processor activities where required.
Customer organizations remain responsible for their own notices, lawful bases, employee or end-user communications, access controls, and decisions about Customer Data submitted through the services.
2. Information We Process
2.1 Device and technical information
Device model and product family; hardware and board revision; serial number or Device identifier; Device hash or attestation identifier; Firmware and application versions; security-patch level; boot-integrity, Secure Boot, or attestation status; update channel and deployment group; update status and errors; uptime and operating status; resource usage and performance information; system events, crash data, diagnostic logs, and error codes; network type, connection status, and limited network metadata; timestamps and time-zone configuration; language and region; enabled services and configuration state; remote-management status; and provisioning or enrollment status.
2.2 Customer and administrator account information
Organization name, business contact information for administrators, account identifiers, subscription or entitlement information, authentication and authorization records, Device assignment records, audit records, and support interactions.
2.3 Provisioning and configuration information
Provisioning profiles; network and proxy settings; certificate and enrollment configuration; application, web application, URL, and content assignments; kiosk and device-management configuration; deployment status; and other settings Customer chooses to deliver through Connected Services.
2.4 Support information
Logs, screenshots, diagnostic packages, Device information, configuration information, communications, and other materials submitted in connection with support or security investigations.
2.5 Information standard telemetry is not designed to collect
Standard Firmware telemetry is not designed to collect an individual's name, personal email address, personal telephone number, account password, private communications, audio or video content, or files/content displayed by the Device. However, logs or configuration supplied by a Customer may incidentally contain personal or confidential information, and Customer should minimize such information where practicable.
3. Why We Process Information
- operate and maintain Firmware and Connected Services;
- authenticate and validate Devices and administrators;
- provide ZTE, provisioning, device-management, and remote-administration functions;
- deliver, stage, verify, and troubleshoot Updates;
- determine Device or Update eligibility;
- diagnose failures and respond to support requests;
- detect security threats, misuse, or unauthorized modification;
- assess Device integrity and attestation state;
- monitor service availability, reliability, and performance;
- improve compatibility, security, usability, and product quality;
- analyze recurring product issues and maintain audit/service records; and
- comply with legal, contractual, tax, accounting, security, and regulatory obligations.
4. Legal Bases and Regional Privacy Requirements
Where applicable law requires a legal basis for processing, IAdea relies on one or more bases appropriate to the context, which may include performance of a contract, legitimate interests in operating and securing enterprise products and services, compliance with legal obligations, consent where specifically required, and processing on Customer instructions under a DPA.
5. Optional Diagnostic Data and Customer Controls
Where the Firmware or Connected Services provide a control for optional diagnostic data, an Authorized Administrator may enable or disable that collection.
Disabling optional diagnostics does not prevent processing strictly necessary to validate a Device, provide a requested Update, complete requested provisioning, perform a requested support action, maintain security, operate the contracted service, or comply with law.
Administrators may also be able to disable certain management connectivity or Connected Service features. Doing so may limit remote management, provisioning, diagnostics, status reporting, automatic updates, or support.
6. How We Share Information
IAdea may share information with affiliates, infrastructure and hosting providers, support providers, security vendors, professional advisers, auditors, payment or billing providers where applicable, and other subprocessors or service providers that help operate the products and services, subject to appropriate contractual and security obligations.
IAdea may also disclose information when required by law, legal process, government request, or to protect rights, safety, systems, Customers, or Devices; in connection with a merger, acquisition, financing, reorganization, sale, or transfer of relevant assets; or at Customer direction.
7. International Data Transfers
Information may be processed in countries other than the country where a Device or Customer is located. Where applicable law requires transfer safeguards, IAdea will use an appropriate mechanism such as contractual clauses, adequacy mechanisms, or another legally recognized safeguard.
8. Retention
IAdea retains Technical Data, provisioning records, audit logs, account information, support records, and Customer Data only for as long as reasonably necessary for the purposes described in this Notice, subject to contractual commitments, security requirements, backup cycles, dispute resolution, and legal obligations.
9. Security
IAdea uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Safeguards may include access controls, encryption where appropriate, secure development and update processes, Device identity and attestation mechanisms, logging, vulnerability management, and incident-response procedures.
No system can be guaranteed completely secure. Customers are responsible for protecting administrator credentials, certificates, private keys, network configuration, and account access within their control.
10. Customer Data and Enterprise Processing
Customer is responsible for determining whether Customer Data contains personal, confidential, regulated, or sensitive information; providing required notices; obtaining required consents or authorizations; controlling administrator access; and configuring retention and access appropriately.
Where IAdea processes personal data on behalf of Customer, the applicable IAdea Data Processing Addendum governs that processing, including documented instructions, confidentiality, security, subprocessors, assistance obligations, deletion/return, and audit information.
11. Privacy Rights and Requests
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, objection, or information about certain processing. Some requests concerning data controlled by an enterprise Customer should be directed to that Customer because IAdea may process the data only on the Customer's instructions.
Requests may be submitted to legal@IAdea.com. IAdea may need to verify identity and may decline or limit requests where permitted by law.
12. Children
IAdea enterprise Devices and Connected Services are not directed to children for personal use. Customers deploying Devices in schools or environments involving minors are responsible for determining and satisfying applicable notice, consent, authorization, and configuration requirements.
13. Changes to this Notice
IAdea may update this Notice to reflect changes in products, services, processing, law, or security practices. Material changes will be communicated through reasonable channels such as an IAdea portal, Device notice, email to an administrator, product documentation, or IAdea's website. The "Last updated" date should be revised with each published version.
14. Contact and Applicable IAdea Entity
The applicable IAdea commercial contracting entity is determined under the IAdea Device & Firmware EULA, IAdea Connected Services Terms, or another applicable written agreement. IAdea does not rely on Device location, IP geolocation, installer location, or other automated geographic detection at Device onboarding to determine the contracting entity. Privacy-law roles may depend on the actual processing activity and applicable law rather than solely on the commercial contracting entity.
- IAdea Corporation – 3F, No. 21, Lane 168, Xingshan Road, Neihu, Taipei Taiwan, R.O.C.; Privacy contact: legal@IAdea.com.
- IAdea America Corp. – 20 Fairbanks Suite 170, Irvine, CA 92618, USA; Privacy contact: legal@IAdea.com.