Last updated: 6 November 2020

At Samsung Electronics Co., Ltd., we know how important privacy is to our customers. Samsung is the data controller for Knox. We created this Samsung Knox Privacy Policy to make sure you understand how we collect and use your personal information.

Our Privacy Policy at https://account.samsung.com/membership/terms/privacypolicy also applies to your use of Knox. Our Privacy Policy contains more information about how we use your data. It also includes information about your rights and how to contact us. Please read our Privacy Policy in addition to this Samsung Knox Privacy Policy. However, this Samsung Knox Privacy Policy shall always prevail over the Privacy Policy in relation to how we use your information for Knox.

WHAT INFORMATION DO WE COLLECT?

Through Knox, Samsung obtains and maintains information about you in various ways.

Information About Your Use of Knox

We will collect information about your use of our Knox through software on your devices and by other means. We will collect:

• Device and app information, such as device identifiers and other unique identifiers, device software version, OS version, device models, application package name, application package version and hash data of the application.

• Information about your usage of Knox, including how, when and how often you use your devices and Knox. Samsung’s servers will receive information when you interact with Knox, such as information about your use of Knox and your interactions with Knox.

• With your separate consent, application logs to identify and diagnose errors with Knox. We will explain more in detail on the types of data collected and used in the separate consent.

We also may collect other information about you, your devices and apps and your use of Knox in ways that we describe to you at the time of collection or otherwise with your consent.

We may use third-party analytics services, such as Google Analytics. The information we obtain may be disclosed to or collected directly by these providers and other relevant third parties who use the information, for example, to evaluate your use of Knox and to help administer Knox. To learn more about Google Analytics, please visit https://www.google.com/policies/privacy/partners/.

HOW DO WE USE YOUR INFORMATION?

We use the information collected for the following purposes:

• register and authenticate you or your device for Knox activation and manage Knox licences;

• provide Knox framework and its features and services;

• respond to your requests, enquiries and instructions made through or about Knox;

• operate, evaluate and improve our business (including developing new products, enhancing and improving our products and the services; managing our communications; analysing our products, customer base and services; conducting market research; performing data analytics; and performing accounting, auditing and other internal functions);

• analyse our products and services to help us better understand our customers in order to offer the most relevant communications, services and experiences to you;

• provide software updates, maintenance services and support for Knox;

• comply with and enforce applicable legal requirements, relevant industry standards and our policies, including this Samsung Knox Privacy Policy and the Privacy Policy;

• protect the rights, property or safety of Samsung Electronics, or any of our affiliates, business partners or customers.

Samsung processes personal information for the purposes described above. Samsung’s legal basis to process personal information is outlined below:

Keeping our promise to you (performance of contract); GDPR Article 6(1)(b)

• Registering and authenticating you or your device for Knox activation; and

• Providing you with Knox, including managing Knox licences.

To promote our business interests (legitimate interests); GDPR Article 6(1)(f)

• Responding to your requests, enquiries and instructions;

• Operating, evaluating, analysing and improving Knox and our business;

• Maintaining adequate security measures; and

• Protecting against liability, including complying with industry standards and enforcing our policies.

To comply with the law, regulatory obligations and legal processes; GDPR Article 6(1)(c)

• Complying with applicable statutes and regulations and court orders.

With your Consent; GDPR Article 6(1)(a)

• Collecting and processing application logs to identify and diagnose errors.

WHO DO WE SHARE YOUR INFORMATION WITH?

We will disclose your information internally within our business and to the following entities, but only for the purposes described above.

• Affiliates: other Samsung Electronics Group companies which we control or own;

• Service providers: carefully selected companies that provide services for or on behalf of us, such as cloud platform providers who maintain data on our behalf. These providers are also committed to protecting your information;

• Other parties when required by law or as necessary to protect Knox: for example, it may be necessary by law, legal process or court order from governmental authorities to disclose your information. They may also seek your information from us for the purposes of law enforcement, national security, anti-terrorism or other issues that are related to public security;

• Other parties in connection with corporate transactions: we may disclose your information to a third party as part of a merger or transfer, acquisition or sale or in the event of bankruptcy; and

• Other parties with your consent or at your direction: in addition to the disclosures described in this Samsung Knox Privacy Policy, we may share information about you with third parties when you separately consent to or request such sharing.

HOW LONG DO WE RETAIN YOUR INFORMATION AND WHERE DOES IT GO?

How long your data will be retained depends on the legal basis relied upon to process your data. For example, data we process to perform our contract with you requires us to keep the data throughout the time you use Knox. As long as you are an active user of Knox, we will retain and process this data. Data such as your account information and device information and identifiers fall into this category.

Data we process to promote our business interests, such as your usage of Knox, is only kept for as long as is needed for the purposes for which it was collected. For example, this data may be collected to perform analytics so we can develop improvements to Knox, or we may process data to keep a record of enquiries you have made through or about Knox to improve your customer service experience.

In addition, we may also process your data based on your consent. If you withdraw your consent, we will stop processing the data that relies on your consent, but it will not impact the processing of the data collected prior to your withdrawal until the purposes for which such data was collected have been achieved.

Please note, although we aim to retain your data for the time period described above, your data may be processed longer pursuant to applicable law. For example, if a specific statute mandates the requirement of a certain piece of data, we comply and retain that data until the required retention period expires.

As long as your data is retained by us your data will always be subject to appropriate safeguards.

Your use of Knox will involve the transfer, storage and processing of your personal information to other countries; such countries include, but are not limited to, countries in the European Economic Area, the Philippines, Brazil, the United States, Canada and the Republic of Korea. All international data transfers are subject to legal requirements to ensure that your personal information is processed safely and as you would expect.

UPDATES TO THIS SAMSUNG KNOX PRIVACY POLICY

This Samsung Knox Privacy Policy may be updated to let you know about changes in how we collect and process your information in Knox or changes in related laws. The date when the document was last updated is shown at the top of this Samsung Knox Privacy Policy.