隐私政策

北京巴拉多多科技有限公司(以下称「我们」)非常重视你的个人信息。本政策说明我们在你使用本应用制作证件照时,会处理哪些信息、为什么处理、与谁共享,以及你可以怎样管理它们。请你在使用前完整阅读,特别是加粗部分。

一、我们处理哪些信息

1. 你主动选择的照片。制作证件照需要把你选中的这张照片交由我们的服务完成处理,再把成片回传给你。这一步是完成制作所必需的,照片会离开你的设备。 我们只处理你当次选中的照片。

2. 与照片相关的技术校验信息。为避免同一张照片被重复传输,我们会处理一项由照片内容生成的校验值。它不包含你的身份信息,也无法据以还原照片。

3. 制作参数。你选择的规格(如一寸、美国签证)、底色,以及你自定义的尺寸与文件大小范围。

4. 产品来源标识。用于区分请求来自本应用还是我们的其他产品,不含任何设备唯一标识

5. 你主动提交的反馈。只有你在「意见反馈」里点提交时才会收集:反馈正文、你选填的回访邮箱、你附上的截图(最多 3 张),以及你的系统版本与应用版本号。邮箱只用于就这条反馈回复你;版本信息只用于复现你遇到的问题。这里同样不含任何设备唯一标识,邮箱和截图都可以不填。

6. 留在你设备上的信息。成片会在应用的私有存储中留一份,供你在「我的照片」里查看;你在首页搜索过的规格关键词也会留在本地。这两项都不会上传,你可以在应用内自行删除,卸载应用时也会一并清除。

我们不收集:位置、通讯录、短信、通话记录、剪贴板、已安装应用列表,也不收集 IMEI/OAID/MAC 等设备唯一标识用于广告追踪。本应用未接入任何广告或数据分析 SDK。

二、我们如何使用这些信息

仅用于向你提供证件照制作服务:处理你的照片,并按你选择的规格回传成片。

你提交的反馈只用于处理你反映的问题、并在你留了邮箱时回复你,不作他用。

我们不会将上述信息用于用户画像、精准营销或自动化决策。

三、我们处理这些信息的法律依据

制作证件照 —— 基于你的同意。 你在首次启动的指引里点「同意并继续」,并在每次主动选择照片时,即表示同意我们为你处理这一张照片。你可以随时撤回同意,撤回不影响撤回前已经进行的处理。

交付你请求的成片 —— 基于履行我们与你之间的协议。 为做出你要的那张图,我们需要处理你选择的规格、底色与尺寸参数。

处理你提交的反馈 —— 基于我们回应用户问题、改进产品的正当利益;你留下的回访邮箱则基于你的同意。

遵守法律义务。 在法律法规要求或有权机关依法调查时,我们可能需要保留或提供相关信息。

以上四项依次对应欧盟《通用数据保护条例》第 6 条第 1 款的 (a)、(b)、(f)、(c) 项。如你所在国家/地区的法律有更严格的要求,以当地法律为准。

四、关于人脸的说明

证件照必须按发证机关的要求确定头部在画面中的位置与比例,因此在制作过程中,我们会检测你所上传照片中人脸的位置,用于裁切与构图。

我们不做人脸识别。 我们不会提取、生成或存储任何可用于识别你身份的人脸特征模板,不会将你的照片与任何人脸数据库比对,也不会用它来辨认你是谁,或推断你的年龄、性别、情绪、健康、种族等任何属性。

我们不会将你的照片用于训练任何模型,也不会将其用于本政策所述之外的任何目的。

五、我们与谁共享

1. 云服务提供商。为完成文件的传输与存放,你的照片、以及你在意见反馈里附的截图,会经由我们委托的云服务提供商处理。受托方只能按我们的指令处理这些文件,不得用于自身目的,我们与其订有相应的数据处理约定。

2. 其余处理均由我们自行完成,不涉及其他接收方。

除法律法规要求或配合有权机关调查外,我们不会向任何第三方出售、出租或交换你的照片

照片留存:上传的原图与成片在服务端保留 7 天,到期自动删除。

六、本应用申请的权限

网络访问:完成照片的上传与成片的回传。这是应用运行的必要权限。

读取相册:只在你主动点击「从相册选择」时触发,用于让你挑选要制作的照片。我们只读取你选中的那一张,不会扫描你的相册。

写入相册:只在你主动点击「保存到相册」时触发,用于把成片存到你的设备。在较早版本的系统上,这一步需要存储权限。

你可以随时在系统设置里关闭这些权限。关闭后相应功能不可用,但不影响你使用应用的其他部分。

七、第三方 SDK

本应用未集成任何广告、统计分析、推送或第三方登录 SDK,不存在向此类第三方回传你的个人信息的情形。

为实现选图、保存到相册、网络传输等基础功能,本应用使用了少量通用开源组件。它们全部在你的设备本地运行,不向其开发方发送任何信息。

八、数据存储地点与跨境传输

我们用于提供本应用服务的服务器位于法国境内(欧盟)。 你的照片、以及你在意见反馈里提交的内容,都在法国境内完成处理与存放,不会存放于中华人民共和国境内

如果你身处欧洲经济区(EEA)或英国:你的数据始终留在欧洲经济区内,不存在向第三国的跨境传输。

如果你身处欧洲经济区与英国之外:使用本应用意味着你的数据会被传输至法国境内处理。我们与受托的云服务提供商订有数据处理约定,约束其只能按我们的指令处理这些数据;在法律要求采用特定传输机制的情形下,我们采用欧盟标准合同条款(SCC)等法律允许的机制。

无论在何处处理,照片都按前述留存期限到期删除。

如你对数据的处理地点有疑问,或希望我们就此作出进一步说明,可以随时通过下方联系方式与我们联系。

九、我们如何保护你的信息

传输过程全程使用 HTTPS 加密。 存放期间,文件保存在有访问控制的存储中,仅授权人员在履行职责所必需的范围内可以访问。

上传的原图与成片在服务端保留 7 天,到期自动删除,删除后我们不再保留副本。

任何安全措施都不能保证绝对安全。万一发生可能危及你个人信息安全的事件,我们会按照法律要求的时限通知你以及相关监管机构。

十、未成年人保护

本应用面向成年人。如果你未满 13 周岁(在部分国家/地区为 16 周岁),请在监护人陪同下阅读本政策,并在取得监护人同意后再使用本应用。

我们不会在明知的情况下收集儿童的个人信息。如果我们发现在未事先获得监护人同意的情况下收集了儿童的个人信息,会尽快删除。监护人如发现此类情形,可通过下方联系方式要求我们删除。

十一、你的权利

你对自己的个人信息享有下列权利,行使这些权利我们不收取任何费用,也不会因此给予你差别待遇:

查阅与获取副本 —— 了解我们处理了你的哪些信息,并向我们索取一份副本。

更正 —— 要求我们更正不准确或不完整的信息。

删除 —— 要求我们在留存期届满前提前删除已上传到服务端的照片。留在你设备上的成片与搜索记录,你可以在应用内自行删除,卸载应用时也会一并清除。

限制处理与反对处理 —— 在法律规定的情形下,要求我们暂停处理,或者反对我们基于正当利益进行的处理。

数据可携带 —— 要求我们以通用的、机器可读的格式,向你或你指定的第三方提供你所提供的那部分信息。

撤回同意 —— 你可以随时撤回:在系统设置里关闭相册权限,或卸载本应用。撤回不影响撤回前已经进行的处理。

行使方式 —— 发邮件到 service@baladuoduo.com。我们会在收到请求后 15 个工作日内答复;法律规定了更短期限的,从其规定。为保护你的信息,我们可能需要先核实提出请求的确实是你本人。

向监管机构投诉 —— 如果你认为我们对你个人信息的处理违反了法律,你有权向你惯常居住地、工作地或涉嫌违法行为发生地的数据保护监管机构投诉。我们的服务器位于法国,对应的监管机构是法国国家信息与自由委员会(CNIL);如果你在英国,对应的是英国信息专员办公室(ICO)。在此之前也欢迎你先联系我们,我们希望能先把问题解决掉。

如果你是美国加州等州的居民 —— 我们不出售你的个人信息,也不为跨语境行为广告而「共享」你的个人信息,过去没有做过,将来也不会。上述查阅、更正、删除的权利同样适用于你,行使方式相同。

十二、本政策的更新

本政策发生重大变更时,我们会在应用内以显著方式提示你,并再次征求你的同意。非重大的文字调整,我们会更新页首的更新日期。你可以随时在「我的 — 关于我们」中查看最新版本。

Privacy Policy

Beijing Baladuoduo Technology Co., Ltd. ("we") takes your personal information seriously. This policy explains what we process when you make an ID photo with this app, why, who we share it with, and how you can control it.

1. What we process

The photo you choose. Making an ID photo requires that photo to be handed to our service for processing, after which the finished photo is returned to you. This step is necessary to produce the result, and it means the photo leaves your device. We only ever process the one photo you select.

A technical checksum derived from the photo, processed so that the same photo need not be transferred twice. It carries no identity information and the photo cannot be reconstructed from it.

The parameters you choose: the spec, the backdrop colour, and any custom size or file-size range.

A product identifier used only to tell this app apart from our other products. It contains no device identifier.

What you submit through Feedback, collected only when you tap submit: the message itself, the reply-to email address if you choose to give one, any screenshots you attach (up to three), and your OS and app version. The email is used only to answer that piece of feedback; the version information only to reproduce the problem. This carries no device identifier either, and both the email and the screenshots are optional.

Information kept on your device. A copy of each finished photo is held in the app's private storage so you can find it under My Photos, and the spec keywords you have searched for stay on the device too. Neither is uploaded; you can delete them in the app, and uninstalling removes them as well.

We do not collect location, contacts, messages, call logs, clipboard contents or the list of installed apps, and we do not collect advertising identifiers. No advertising or analytics SDK is integrated in this app.

2. How we use it

Only to provide the ID-photo service: processing your photo and returning the result at the spec you chose.

Feedback you send is used only to work on the problem you reported and to reply to you if you left an email address. Nothing else.

We do not use it for profiling, targeted marketing or automated decision-making.

3. Our legal bases for processing

Making the ID photo — your consent. You give it when you tap "Agree and continue" on first launch, and again each time you actively choose a photo to process. You can withdraw consent at any time; withdrawal does not affect processing already carried out.

Delivering the photo you asked for — performance of our agreement with you. We need the spec, backdrop and size you chose in order to produce the result.

Handling your feedback — our legitimate interest in answering users and improving the product; the reply-to email address you may leave rests on your consent.

Complying with legal obligations, where the law or a lawful request from an authority requires us to keep or hand over information.

These correspond, in order, to Article 6(1)(a), (b), (f) and (c) of the EU General Data Protection Regulation. Where the law of your own country or region is stricter, that law prevails.

4. About faces

An ID photo has to place the head at the position and proportion the issuing authority requires, so while making it we detect where the face is in the photo you upload, in order to crop and compose the frame.

We do not do facial recognition. We do not extract, generate or store any facial template capable of identifying you, we do not compare your photo against any face database, and we do not use it to work out who you are or to infer your age, gender, emotion, health, race or any other attribute.

We do not use your photos to train any model, and we do not use them for any purpose beyond those described in this policy.

5. Who we share it with

Cloud service providers. To carry and hold the files, your photo and any screenshot you attach to feedback are handled by providers we engage. They may act only on our instructions and may not use the files for their own purposes, and we have data-processing terms in place with them.

Everything else is done by us; there are no other recipients.

We never sell, rent or trade your photos. We disclose them only where required by law or by a lawful request from an authority.

Retention: the original you upload and the finished photo are kept on the server for 7 days, then deleted automatically.

6. Permissions this app requests

Network access — required to send the photo and receive the result.

Photo library read — triggered only when you tap "Choose from album". We read only the photo you select; we never scan your library.

Photo library write — triggered only when you tap "Save to album". On older systems this needs the storage permission.

You can revoke any of these in system settings at any time. The corresponding feature then stops working; the rest of the app is unaffected.

7. Third-party SDKs

No advertising, analytics, push-notification or third-party sign-in SDK is integrated in this app, so no personal information of yours is sent to any such third party.

A few general-purpose open-source components are used for basics such as picking a photo, saving to the album and network transfer. They run entirely on your device and send nothing to their authors.

8. Where your data is processed

The servers we use to provide this app are located in France, in the European Union. Your photo, and anything you submit through the feedback form, is processed and held in France. It is not held in mainland China.

If you are in the European Economic Area (EEA) or the United Kingdom, your data stays within the EEA and no transfer to a third country takes place.

If you are outside the EEA and the United Kingdom, using this app means your data is transferred to France to be processed. We have data processing agreements with the cloud providers we entrust, binding them to act only on our instructions; where the law requires a specific transfer mechanism, we rely on the EU Standard Contractual Clauses or another mechanism permitted by law.

Wherever it is processed, your photo is deleted at the end of the retention period stated above.

Contact us using the details below if you have any question about where your photo is processed, or would like more detail on this.

9. How we protect your information

Everything is encrypted in transit with HTTPS. While held, files sit in access-controlled storage that only authorised staff can reach, and only as far as their job requires.

On the server, the original you upload and the finished photo are kept on the server for 7 days, then deleted automatically; we keep no copy after that.

No security measure can guarantee absolute safety. Should an incident occur that may put your personal information at risk, we will notify you and the relevant supervisory authority within the time the law allows.

10. Children

This app is intended for adults. If you are under 13 (16 in some jurisdictions), please read this policy with your guardian and use the app only with their consent.

We do not knowingly collect personal information from children. If we find that we have done so without a guardian's prior consent, we delete it as soon as we can. Guardians who become aware of such a case can ask us to delete it using the contact details below.

11. Your rights

You have the following rights over your personal information. Exercising them is free, and we will not treat you differently for doing so:

Access and a copy — find out what we process about you and ask us for a copy.

Rectification — ask us to correct information that is inaccurate or incomplete.

Erasure — ask us to delete a photo from the server before the retention period is up. The finished photos and search history held on your device can be deleted in the app, and uninstalling removes them as well.

Restriction and objection — in the cases the law provides, ask us to pause processing, or object to processing we base on legitimate interests.

Portability — ask us to provide the information you gave us, to you or to a third party you name, in a common machine-readable format.

Withdraw consent — at any time, by revoking the photo permission in system settings or uninstalling the app. Withdrawal does not affect processing already carried out.

How to exercise them — email service@baladuoduo.com. We answer within 15 working days, or sooner where the law sets a shorter deadline. To protect your information we may first need to verify that the request really comes from you.

Complain to a supervisory authority — if you believe our handling of your personal information breaks the law, you may complain to the data protection authority where you live, where you work, or where the alleged breach took place. Our servers are in France, so the authority concerned is the Commission Nationale de l'Informatique et des Libertés (CNIL); in the United Kingdom it is the Information Commissioner's Office (ICO). We would rather you came to us first and let us put it right.

If you live in California or another US state with similar law — we do not sell your personal information and do not "share" it for cross-context behavioural advertising. We never have and we will not. The rights to access, correct and delete set out above apply to you as well, by the same route.

12. Changes

If this policy changes materially we will tell you in the app and ask for your consent again. For minor wording changes we update the date at the top. The current version is always available under Profile — About.