We use essential cookies for the website to function, as well as analytics cookies for analyzing and creating statistics of the website performance. To agree to the use of analytics cookies, click "Accept All". You can manage your preferences at any time by clicking "Cookie Settings" on the footer. More Information.

Only Essential Cookies
Accept All
MaterialsConsole

HUAWEI AppGallery Connect Service Agreement

Click to download HUAWEI AppGallery Connect Service Agreement.

The following terms and conditions (hereinafter referred to as this "Agreement" or the "AppGallery Connect Service Agreement") constitute a legally binding agreement between you and Huawei. This Agreement is a supplementary agreement to the HUAWEI Developers Service Agreement concluded by and between you and Huawei, and together with the latter govern your use of the Huawei Services of the HUAWEI AppGallery Connect ("AppGallery Connect") as a Huawei Developer. By clicking the "I Agree" button below this Agreement or using any service under this Agreement, you shall be deemed to have fully understood and accepted this Agreement as of the date of such acceptance or use ("Effective Date").

Any matters not addressed herein shall be subject to the HUAWEI Developers Service Agreement. In the event of any conflict between this Agreement and the HUAWEI Developers Service Agreement, this Agreement shall prevail with respect to any matters within the scope of the Huawei Services provided via HUAWEI AppGallery Connect.

1. Definitions

Capitalized terms not defined herein shall have the meanings ascribed to them in the HUAWEI Developers Service Agreement. The following terms shall have the following meanings when used in this Agreement:

1.1 "Application" means software programs that Developers provide via HUAWEI AppGallery Connect which can be installed and/or run on mobile internet devices, including but not limited to application software programs and Quick Apps. Applications fall into the scope of "Products" defined in the HUAWEI Developers Service Agreement.

1.2 "AppTouch Provider" means the entity that operates HUAWEI AppTouch.

1.3 "EEA" means the European Economic Area, consisting of the Member States of the European Union and Iceland, Liechtenstein, and Norway.

1.4 "EU SCC" mean the standard contractual clauses issued by the European Commission by implementing decision 2021/914 of 4 June, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

1.5 "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

1.6 "Huawei", "we", "our" or "us" means the signing entity determined in accordance with Clause 7 herein, which provides services for you under this Agreement.

1.7 "HUAWEI AppGallery" or "AppGallery" means the Huawei Platform developed and/or operated by Huawei and/or its Affiliates, which displays and makes available your Products for viewing, download, and purchase by End Users, including but not limited to HUAWEI AppGallery software, HUAWEI GameCenter software, HUAWEI EducationCenter software, and HUAWEI AppTouch.

1.8 "HUAWEI AppGallery Connect" means the platform that hosts HUAWEI AppGallery and provides one-stop services for Products to be displayed and/or distributed through HUAWEI AppGallery. HUAWEI AppGallery Connect provides Developers with various Huawei Services, including but not limited to distribution services (Application and content distribution, preordering, internal testing, and initial release), operations services (product operations, content operations, activity operations, and user operations), analysis services (distribution analysis, operations analysis, quality analysis, and advanced analysis), development services (business development and growth services), and link distribution services.

1.9 "Huawei AppTouch" or "AppTouch" means the distribution platforms (a) for which Huawei cooperates with third parties ("AppTouch Provider (s)"), including but not limited to telecom carriers, in operations and branding, (b) developed and/or for which technical support is provided by Huawei, and (c) that allow Developers to showcase and distribute Products, such as apps and games, to End Users, in order to increase exposure, traffic, monetization opportunities, and users for the Products. The HUAWEI AppTouch list is set forth here. Huawei may update the list from time to time upon prior notice to you. If you have any comments or questions about the distribution of your Products on HUAWEI AppTouch, you may contact Huawei through your account manager at Huawei or via apptouch@huawei.com. Huawei will respect your choice.

1.10 "HUAWEI Developer Console" or "Console" means the management center and other online tools or services (which may be updated from time to time) provided by Huawei to Developers at https://developer.huawei.com/consumer/en/console#/. The Console is interconnected with other Huawei Platforms (including but not limited to HUAWEI AppGallery Connect, HUAWEI AppGallery, HUAWEI Themes, HUAWEI Assistant, and Huawei AppTouch).

1.11 "Paid Products" means Products requiring End Users to pay a fee to access and/or download, including but not limited to pay-per-download Products, in-app-purchase Products, and other paid digital content Products.

1.12 "Parties" means you and Huawei (see definition above).

1.13 "Personal Data" means any information relating to an identified or identifiable natural person in so far as it is processed under this Agreement.

1.14 "Third Country" means a country that is neither part of the EEA nor has been declared adequate by a decision of the European Commission according to the mechanism lined out in Article 45 GDPR.

1.15 “UK Addendum” means the addendum to the EU SCC issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022, as amended, available here: https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf).

2. This Service

Development Services

Huawei provides you with various development services for the Application development, testing, monetization, etc., to help you develop and build Applications more conveniently and quickly.

Distribution Services

Huawei provides you with distribution services, such as the Application release (e.g. initial release) and preordering services, to help you release your Applications on HUAWEI AppGallery.

Operations Services

Huawei provides you with services, such as product operations, content operations, activity operations, user operations, and community management, to support you with multi-dimensional operations management.

Billing Services

Huawei provides you with billing services, which facilitate accurate payment calculation, transactions consummation, and service performance.

Interactive and Notification

To keep you informed promptly of Application development, distribution, and operations, we provide the notification service and interactive messaging service.

3. Use of HUAWEI AppGallery Connect by You

3.1 You authorize Huawei to present your Products to End Users on your behalf through HUAWEI AppGallery Connect and the HUAWEI AppGallery, which provides access for End Users to view, download, and/or purchase your Products.

3.2 You are responsible for uploading your Products to HUAWEI AppGallery Connect, providing required Production Information and support to End Users, and accurately disclosing the permissions necessary for the Products to function on End Users' devices. End Users are instructed to contact you regarding any defects or performance issues of your Products.

3.3 Any and all the Products that you submit on HUAWEI AppGallery Connect must be subject to and pass Huawei's review before they are released on Huawei Platforms. Huawei may decide whether or not to release such a Product and on which Huawei Platform said Product will be released. If you wish to make any change to a Product after submission to Huawei, you shall first resubmit the changed Product to Huawei for review. Similarly, unless otherwise agreed by Huawei, all bug fixes, updates, upgrades, modifications, enhancements, supplements to, revisions, and new versions (collectively "Updates") of your Applications you release on the Huawei Platforms shall first be submitted to Huawei for review. Notwithstanding the foregoing, you agree that the release of a Product on Huawei Platforms (or any Updates to any parts thereof) does not exempt you from any and all liabilities for said Product, including but not limited to liability for breach of applicable laws, infringement of any third party rights (including but not limited to intellectual property rights) and defects in the Product.

3.4 You shall provide an End User Agreement or End User License Agreement (EULA) (collectively "End User Agreement"), service policies, and other necessary information in each of your Products, and ensure that these are prominent and transparent to End Users. The End User Agreement shall comply with local laws, regulations, customs, and conventions. You shall submit a copy of the End User Agreement when you apply to Huawei for releasing your Products. Huawei shall not be under any obligation to review and approve your End User Agreement. Your submission of the End User Agreement to Huawei shall not be deemed as an acceptance of it by Huawei or relieve you from your obligations in this Clause 3.4.

3.5 You agree to supply and maintain valid and accurate contact information that will be displayed in each of your Products' detail page and made available to End Users for customer support and legal purposes.

3.6 You shall be responsible for the conception, development, processing, modification, testing, maintenance, and management of your Products at your own cost. You shall be solely responsible for the operation of your Products and handling of any complaints or disputes arising out of or in relation to the Products, and you shall be solely liable for any and all issues and liabilities incurred by End Users using your Products. If you fail to solve an End User's problem in a timely manner, as a result of which that End User makes a claim of compensation against Huawei, Huawei may propose and facilitate a solution and decide whether to compensate said End User upon reasonable judgment at its own discretion, but without any obligation to do so or any admission of liability on Huawei's part. You shall bear any and all expenses incurred therefrom.

3.7 If you provide links for Application downloads, you warrant and undertake that: (a) the Application link is valid and points to the latest version of the Application; (b) you will not tamper with the Application link or landing page; (c) the landing page and the content to be directed from the landing page do not contain any illegal content or infringe any third party's rights (including but not limited to intellectual property rights).

3.8 If you want to use the sandbox testing function in the development services, you warrant that: (a) The test account and related information (including but not limited to the HUAWEI IDs and nicknames of test members) provided by you have been authorized by the right holder(s), and do not infringe upon the interests of any third parties or violate any applicable laws and regulations; (b) the test account is used only for the sandbox testing of your Application. You will not use the test account in any other scenarios or disclose it to any third parties; (c) you are the owner of the test account and shall be responsible for any and all actions of your test account. If you entrust a test member to use your test account, you will be jointly and severally liable for the behavior of said test member.

3.9 Application Rating. You shall ensure the authenticity, accuracy, and legitimacy of the age rating information submitted by you, and assume corresponding responsibilities. Huawei may review the rating result decided by yourself and related materials, and adjust said Application rating result based on the review results. If Huawei finds or receives a complaint from an End User that your Product does not comply with applicable laws and regulations or related Huawei rules or policies, Huawei may, at its sole discretion, take appropriate measures, such as removing said Product from Huawei Platforms, blocking the Product, and disconnecting the link to the Product. Huawei's review, rating, and adjustment of your Products shall not be deemed as an express or implied guarantee or warranty for the legitimacy and compliance of your Products with this Agreement or applicable laws. You shall assume full liability for the content of your Products. Huawei has the right to adjust its own Application rating system and its age rating criteria.

3.10 You acknowledge and agree that the age rating function in some areas of HUAWEI AppGallery Connect is provided by third-party rating agencies selected by Huawei. To implement the Application rating function in said areas, you agree that the minimum following information will be provided to said third-party rating agencies: your company name (or your name if you are an individual developer), questionnaire details, Application details, Application installation package, email address, Application copyrights, publication approval number, and your operating qualifications such as a business license or certificate of incorporation.

3.11 In order to help your Products quickly pass Huawei's review, please read and abide by the HUAWEI AppGallery Review Guidelines (which may be updated from time to time). Your Products shall meet said guidelines.

3.12 This Agreement applies to both Products that End Users can access for free of charge and Paid Products. Your Paid Products are displayed to End Users at prices and currency you establish in your sole discretion. To avoid unexpected fees for End Users, you agree that Products that were initially offered free of charge to End Users will remain free of charge. Any additional charges will correlate with an alternative or supplemental version of the Product.

3.13 In the event that you violate any of the preceding terms, Huawei has the right to, upon its reasonable judgment at its sole discretion, delete the relevant information, Application, or Product, remove it from HUAWEI AppGallery, terminate the promotion and operation of related Products on Huawei Platforms, terminate this Agreement, or add the said Products to the app blocklist and take necessary security control measures on the blocklisted apps. 

3.14 If you want to use the Distribution Services for Paid Products through HUAWEI AppGallery Connect, you shall apply for the Merchant Services at the Console, and separately sign the HUAWEI Developers Merchant Service Agreement and HUAWEI AppGallery Connect Distribution Service Agreement for Paid Apps with Huawei.

3.15 You acknowledge that during your use of this Service, Huawei will process your Personal Data in accordance with the HUAWEI AppGallery Connect Privacy Notice (hereinafter, the "Privacy Notice").

4. Product Removal

4.1 You may remove your Products from HUAWEI AppGallery at any time. Nevertheless, you agree that before removing any Product from Huawei Platforms, you shall (a) notify Huawei and related End Users in advance; (b) release an announcement to End Users on the Product pages within a reasonable period of time (at least sixty (60) days if it is a Paid Product), and close the payment portal upon the expiry of said announcement period; (c) comply with this Agreement and terms and conditions of any other relevant agreements, including but not limited to refund requirements. Such announcement shall be kept posted until such Product is formally removed.

4.2 Huawei does not undertake any obligation to monitor your Products or their content. If Huawei becomes aware and determines in its sole discretion that a Product or any portion thereof (a) violates any applicable laws; (b) violates this Agreement, applicable policies, or other relevant Huawei Agreements; (c) creates liability for or has an adverse impact on Huawei; then Huawei may reject, remove, suspend, or reclassify the Product from HUAWEI AppGallery. Huawei reserves the right, at its sole discretion, to suspend and/or bar any Product from HUAWEI AppGallery.

4.3 If your Product is removed from Huawei Platforms, you undertake (a) not to affect the rights of End Users who have previously purchased or downloaded said Product; and (b) not to remove said Product from End Users' devices where previously purchased or downloaded Products are stored.

4.4 You shall be responsible for resolving any and all disputes arising out of or in relation to removal of your Products, or suspension or termination of distribution. You must handle the rights and interests of End Users in your Products in accordance with applicable laws and regulations, including but not limited to refund (if applicable) or compensation. You shall ensure that such refund or other handling methods comply with relevant laws and regulations. Otherwise, you shall be solely liable for any and all losses incurred therefrom upon End Users.

5. Privacy Protection

5.1 You are the controller of Personal Data relating to End Users and their comments that you obtain from Huawei and/or AppTouch. The aforesaid Personal Data may include without being limited to End Users' nickname, comments, ratings, rating time, country, and region. You shall use such Personal Data only for purposes of this Agreement, and ensure the lawfulness of the processing of such data in accordance with applicable laws.

5.2 If your Application or service needs to collect any Personal Data, you must ensure a legal basis for such data processing in accordance with applicable laws and only collect such data as necessary as for the running of your Application and the implementation of its functions. In addition, you must inform End Users of the purposes, scope, and usage of such data collection to protect their right to know.

5.3 After you collect Personal Data and/or receive the Personal Data shared by Huawei or AppTouch provider, you shall take necessary technical and management measures to ensure the security of such data and to protect the Personal Data against accidental or unlawful destruction or accidental loss, alteration, and unauthorized disclosure or access, which shall provide a level of security appropriate to the risks represented by the data processing and the nature of the data received from Huawei regarding End Users to be protected.

5.4 You shall provide End Users with a method for correcting and deleting their Personal Data, subject to their data privacy rights and applicable laws.

5.5 Data Breach. If you suspect or become aware of any unauthorized access to any Personal Data by any unauthorized individuals or third parties, or become aware of any other security breaches relating to Personal Data held or stored by you under this Agreement or in connection with the performance of the services under this Agreement, you shall immediately notify Huawei in writing and shall fully cooperate with Huawei to prevent or stop such a Data Breach. In the event of such a Data Breach, you shall fully and immediately comply with applicable laws, and shall take appropriate steps to remedy such a Data Breach. You shall defend, indemnify, and hold Huawei, its Affiliates, and their respective officers, directors, employees, and agents, harmless from and against any and all claims, suits, causes of action, liabilities, losses, costs, and damages, including reasonable attorney's fees, arising out of or in relation to any third-party claim arising from breach by you of your obligations contained in this Section, except to the extent resulting from the acts or omissions of Huawei.

5.6 In accordance with Clause 7 herein:

(i) if (1) you are contracting this Agreement with Aspiegel SE, and you are located in a country or region outside the EU which the European Commission finds to be unable to provide adequate protection for Personal Data, or (2) Personal Data transferred between relevant AppTouch Provider established in EU/EEA and you (as applicable) when you are located in a country or region outside the EU which the European Commission finds to be unable to provide adequate protection for Personal Data, then Huawei and you, or relevant AppTouch Provider and you (as applicable), shall comply with the GDPR Data Transfer Agreement as provided in Exhibit A for export and import of such Personal Data. The Parties shall be deemed to have executed the EU SCC, according to the process described in the preamble of this Agreement, such that:

  • The relevant module of the EU SCC is "MODULE ONE: Transfer controller to controller";
  • Huawei (or relevant AppTouch Provider, as applicable) is the "data exporter" and you are the "data importer" referred to in the EU SCC;
  • In clause 7 of the EU SCC, the Parties choose to include the "docking clause";
  • In clause 11 of the EU SCC, the Parties do not choose the optional complaint mechanism;
  • In clause 17 of the EU SCC, the Parties choose Option 1 and the governing law shall be Irish law;
  • In clause 18 of the EU SCC, the Parties choose the courts of Ireland;
  • The competent supervisory authority referred to in clause 13 of the EU SCC shall be the supervisory authority of Ireland; and
  • In case of discrepancy with any provision in the AppGallery Connect Service Agreement, the EU SCC shall prevail.
  • The scope and nature of the transfer is set out in the Section B of Annex I from Exhibit A later in this document.
  • The competent supervisory authority is the Irish Data Protection Commission.

To the extent that the data protection laws of the UK apply to the transfer of personal data under this Agreement, the Parties execute the UK Addendum which is incorporated into this Agreement and applies to transfers of personal data outside the UK (except for cases where such data is transferred to a country within the EU/EEA or to another country recognized as adequate in terms of level of data protection by the UK). Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the “Exporter” is Huawei and you are the “Importer”, their details are set forth in this Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCC referred to in Section 5.6 (i) above; (iii) in Table 3, the information is as provided in Annex I (A and B) and Annex II to the “Approved EU SCCs” (as set out in Exhibit A of this Agreement); and (iv) in Table 4, the “Exporter” can terminate the UK Addendum.

(ii) if you are contracting this Agreement with Huawei Services (Hong Kong) Co., Limited, and your Business Area is not Russia, and your servers to receive such data are located outside of Singapore, then Huawei and you, or relevant AppTouch Provider and you (as applicable), shall comply with the Data Transfer Agreement as provided in Exhibit B for export and import of such Personal Data.

(iii) if you are contracting this Agreement withShenzhen Huawei Siray Technologies Co., Ltd, your Business Area is Russia, and your servers to receive such data are located outside of Russia, Huawei and you, or relevant AppTouch Provider and you (as applicable), shall comply with the Data Transfer Agreement in Compliance with Russian Legislation as provided in Exhibit C for export and import of such Personal Data.

`

6. Termination

6.1 Upon termination of the HUAWEI Developers Service Agreement by either Party, this Agreement will terminate automatically. However, the termination of this Agreement by either Party will not result in the termination of the HUAWEI Developers Service Agreement.

6.2 If you want to terminate this Agreement, you shall remove all of your Products from HUAWEI AppGallery Connect and cease your use of the HUAWEI AppGallery Connect and its services in accordance with this Agreement.

6.3 After termination of this Agreement, Huawei will no longer distribute your Products, but may retain and use copies of such Products strictly and solely for the purpose of dealing with potential disputes and lawsuits in connection with said Products.

7. Distribution Area and Signing Entity

Please refer to the Clause in the HUAWEI Developers Service Agreement which is headed "Distribution Area and Signing Huawei Entities".

8. Governing Law and Dispute Resolution

Please refer to the Clause in the HUAWEI Developers Service Agreement which is headed "Governing Law and Dispute Resolution".

Exhibit A: GDPR Data Transfer Agreement

Standard Contractual Clauses

(Controller to Controller)

This Exhibit A shall incorporate the EU SCC (Module one, transfer: controller to controller), as further specified above in section 5.6 (i), and as set out here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX%3A32021D0914&locale=en

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

Name: shall be the contracting Huawei entity, determined according to clause 7 of the AppGallery Connect Service Agreement, or the AppTouch providers listed [here] (as applicable)

Address: shall be the address of the entity determined under clause 7 of the AppGallery Connect Service Agreement, or with respect to AppTouch providers, as listed [here]

Contact person's name, position and contact details: Joerg Thomas, Director, DPO office, DPO@huawei.com

Activities relevant to the data transferred under these Clauses:

Allowing the data subjects of data exporter to review and raise issues to the app developers (importer) to allow issue fixing and improvement of user experience.

Signature and date:

Role: Controller

Data importer(s): 

Name: your name or, as the case may be, the name of the company you represent. You being the Developer who signed the HUAWEI AppGallery Connect Service Agreement with data exporter and part of the Agreement

Address: your place of business or, as the case may be, the place of business of the company you represent

Contact person's name, position and contact details: your contact details and information as you have provided them in context of the AppGallery Connect services and your Developer account.

Activities relevant to the data transferred under these Clauses:

Ensure that data subject's issues and feedback is assessed and product improved

Signature and date:

Role: Controller

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred

Data subjects of the data exporter who have signed the AppGallery and/or the AppTouch agreements and make reviews about the importer's applications/services;

Categories of personal data transferred

The personal data transferred concern the following categories of data:

  • HUAWEI ID account information: user's nickname
  • Usage information: application comments, ratings, rating time, and application distributed country/region

Sensitive data transferred (if applicable) and applied restrictions or safeguards:

N/A

The frequency of the transfer:

The data transfers are triggered by the application store platforms, more specifically when the data subjects make comments or review 3rd party apps distributed on the application store.

Nature of the processing

The personal data transferred is accessed via the AppGallery Connect console utilized by the importers to access data subject's reviews and comments.

Purpose(s) of the data transfer and further processing

The transfer is made for the following purposes:

  • Provide replies and feedback to data subjects' reviews/comments on applications platforms such as AppGallery.
  • Assist in improving services and products by these apps developers.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: In accordance with the privacy policies and data retention practices of the data importer, subject to the applicable data protection laws.

C. COMPETENT SUPERVISORY AUTHORITY

As set out in Section 5.6 above

ANNEX II

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

The following measures are the minimum required to be implemented by the data importer on the transferred Personal Data:

  • Implement Information Security and Privacy Protection policies and procedures for critical assets and business processes in accordance with relevant laws, regulations and aligned to industry standards like ISO27001 or NIST Cyber Security Framework.
  • Regularly assess security controls and risks in your information system(s) to determine if the controls are effective in their application, particularly following major changes, security incidents or data breaches.
  • Ability to ensure the ongoing confidentiality, integrity, availability and resilience of Personal Data and systems and services that process the Personal Data.
  • Manage supplier relationships including security requirements, SLAs, outsourcing agreements for contracts being used as part of the service provision including data processing agreements in place with the sub-processors you use to deliver the services or products in accordance with the GDPR.
  • Perform appropriate background checks on personnel (employees, contractors and third party users) before hiring, when needed and legally permitted.
  • All relevant personnel should be adequately and regularly trained on security and privacy protection.
  • Manage access to protect personal data and systems or services that process and store personal data from unauthorized access following separation of duties and least privilege principles. Access controls should include identity management, authentication of users incorporating a strong password policy, authorization, accountability, network segregation, regular access reviews (i.e. rights and privileges) and access revocation where access is no longer necessary.
  • Implement a strong password policy by enforcing the use of sufficiently complex combinations of characters and numbers, length, enforcing periodic password renewal, restrictions on password reuse, ensure passwords are encrypted and incorporate multi-factor where possible.
  • Establish, protect, and maintain the integrity of your network, platforms and services by taking steps to detect and prevent successful security incidents like DDoS, viruses, code injections or other malware that can alter the functionality of the systems, or confidentiality, integrity or availability of information and systems, through industry best practice security controls like malware protection, DDoS protection, IDS/IPS, firewalls, vulnerability scanning, patch management.
  • Ensure network and information systems and services are subject to regular security testing (e.g. penetration testing, vulnerability scanning, static and dynamic application security testing), including for major upgrades, to identify vulnerabilities that could expose your service to increased risk of malicious intrusion, modification, and unauthorized access to sensitive data.
  • Implement a patch management process to ensure updates are performed on systems with critical and high risk vulnerabilities addressed immediately, with all other system flaws, weaknesses or deficiencies identified, reported and remediated in a timely manner.
  • Antivirus software must be loaded and operational on all systems processing personal data. Other malware detection techniques should be used where possible (e.g., email scanning, file system scanning, internet traffic scanning, etc.).
  • Assets are inventoried, classified and updated when changes occur (i.e. new systems/software introduced, systems decommissioned).
  • Establish change and configuration management procedures for key network and information systems to manage configuration securely.
  • Implement network and information systems security event logging and monitoring for the offered service using Security Operations Center (SOC), Security Information and Event Management (SIEM), agents to report anomalous behavior at both network and host level.
  • Protect logs against modification or tampering.
  • Protect the service infrastructure from unauthorized software being installed.
  • Ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident (i.e. security incidents and/or data breaches) through effective detection, response and reporting capabilities.
  • Provide continuity for the services offered, ability to recover from data loss, protection against compromise, provision of appropriate failover, necessary data retention and an effective data backup policy.
  • Use pseudonymisation and encryption to protect the confidentiality of personal data and other sensitive data while in transit or at rest. Encryption should meet industry standard requirements like NIST FIPS 140.
  • Ensure personal data removal, deletion and sanitization measures meet appropriate levels of security.
  • Service software is developed in a secure way through secure coding practices, following industry best practices (i.e. OWASP Top 10, Secure Coding Standards) including vulnerability analysis.
  • Ensure perimeter and internal network protection, maintain physical or logical separation between the perimeter network and internal networks containing personal data. Development and test environments are secured and separated from live production environments.
  • Ensure physical security of locations at which personal data is processed including reasonable steps to protect against unauthorized access.
  • Devices used for handling Personal Data should not permit data to be written to removable media or to have data read from same nor should they allow printing of Personal data to an unauthorized printer. Such devices should have password protected screensavers implemented and be locked as a matter of course when the user leaves the workstation.
  • All important and confidential documentation is removed from the desk and locked away when items are not in use or an employee leaves his/her workstation
  • Remote access to network and information systems is secured through VPN connection while using devices that have been adequately secured against compromise (e.g. through the use of antivirus software and patching devices with available security fixes).

Exhibit B: Data Transfer Agreement

Standard contractual clauses for the transfer of personal data from the Community to third countries (controller to controller transfers)

Data Transfer Agreement

Between

Name of the data exporting organization: Huawei Services (Hong Kong) Co., Limited

Address: 9th Floor, Tower 6, The Gateway, No. 9 Canton Road, Tsim Sha Tsui, Kowloon, Hong Kong

and Huawei Services (Hong Kong) Co., Limited on behalf of other Data Controllers (please refer to our website for the controller list)

hereinafter "data exporter"

And

Developer who signed the HUAWEI AppGallery Connect Service Agreement with data exporter and part of the Agreement

hereinafter "data importer"

each a "party"; together "the parties".

Definitions

For the purposes of the clauses:

(a) "individual", "personal data", and "processing" shall have the same meaning as in the Personal Data Protection Act (No. 26 of 2012) of Singapore;

(b) "Data Exporter" shall mean the organization who transfers the personal data;

(c) "Data Importer" shall mean the organization who agrees to receive in a country or territory outside Singapore the personal data transferred to it by or on behalf of the Data Exporter for processing in accordance with the terms of theses clauses;

(d) "Data Subject" shall mean the Data Subject that is particularly described in Annex B herein below;

(e) "clauses" shall mean these contractual clauses, which are a free-standing document that does not incorporate commercial business terms established by the parties under separate commercial arrangements.

(f) "PDPA" shall mean the Personal Data Protection Act (No. 26 of 2012) of Singapore.

The details of the transfer (as well as the personal data covered) are specified in Annex B, which forms an integral part of the clauses.

I. Obligations of the Data Exporter

The Data Exporter warrants and undertakes that:

(a) The personal data has been collected, processed and transferred in accordance with the relevant provisions of the applicable data protection law (and, where applicable, has been notified to the relevant authorities of the country where the Data Exporter is established).

(b) It has used reasonable efforts to determine that the Data Importer is able to satisfy its legal obligations under these clauses.

(c) It will provide the Data Importer, when so requested, with copies of relevant data protection laws or references or any requirements set out in any advisory or other guidelines issued from time to time by Personal Data Protection Commission of Singapore ("PDPC") to them (where relevant, and not including legal advice).

(d) It will respond to enquiries from Data Subjects and the authority concerning processing of the personal data by the Data Importer, unless the parties have agreed that the Data Importer will so respond, in which case the Data Exporter will still respond to the extent reasonably possible and with the information reasonably available to it if the Data Importer is unwilling or unable to respond. Responses will be made within a reasonable time.

(e) It will make available, upon request, a copy of the clauses to Data Subjects who are third-party beneficiaries under clause III, unless the clauses contain confidential information, in which case it may remove such information. Where information is removed, the Data Exporter shall inform Data Subjects in writing of the reason for removal and of their right to draw the removal to the attention of the authority. However, the Data Exporter shall abide by a decision of the authority regarding access to the full text of the clauses by Data Subjects, as long as Data Subjects have agreed to respect the confidentiality of the confidential information removed. The Data Exporter shall also provide a copy of the clauses to the authority where required.

II. Obligations of the Data Importer

The Data Importer warrants and undertakes that:

(a) It will have in place appropriate technical and organizational measures to provide a standard of protection, that is comparable to the protection required by the PDPA and any requirements set out in any advisory or other guidelines issued from time to time by the PDPC, to the personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, and which provide a level of security appropriate to the risk represented by the processing and the nature of the data to be protected.

(b) It will have in place procedures so that any third party it authorizes to have access to the personal data, including processors, will respect and maintain the confidentiality and security of the personal data. Any person acting under the authority of the Data Importer, including a data processor shall be obligated to process the personal data only on instructions from the Data Importer. This provision does not apply to persons authorized or required by law or regulation to have access to the personal data.

(c) It has no reason to believe, at the time of entering into these clauses, in the existence of any local laws that would have a substantial adverse effect on the guarantees provided for under these clauses, and it will inform the Data Exporter if it becomes aware of any such laws.

(d) It will process the personal data for purposes described in Annex B, and has the legal authority to give the warranties and fulfill the undertakings set out in these clauses.

(e) It will identify to the Data Exporter a contact point within its organization authorized to respond to enquiries concerning of the personal data, and will cooperate in good faith with the Data Exporter, the Data Subject and the authority concerning all such enquiries within a reasonable time. In case of legal dissolution of the Data Exporter, or if the parties have so agreed, the Data Importer will assume responsibility for compliance with the provisions of clause I (e).

(f) At the request of the Data Exporter, it will provide the Data Exporter with evidence of financial resources sufficient to fulfill its responsibilities under clause III (which may include insurance coverage).

(g) Upon reasonable request of the Data Exporter, it will submit its data processing facilities, data files and documentation needed for processing to reviewing, auditing and/or certifying by the Data Exporter (or any independent or impartial inspection agents or auditors, selected by the Data Exporter and not reasonably objected to by the Data Importer) to ascertain compliance with the warranties and undertakings in these clauses, with reasonable notice and during regular business hours. The request will be subject to any necessary consent or approval from a regulatory or supervisory authority within the country of the Data Importer, which consent or approval the Data Importer will attempt to obtain in a timely fashion.

(h) It will process the personal data, in accordance with:

(i) The data protection laws of Singapore, and the relevant regulations, provisions or other requirements issued by PDPC; and

(ii) The data processing principles set forth in Annex A.

(i) It will not disclose or transfer the personal data to a third-party organization located outside Singapore unless with prior consent of the Data Exporter on the transfer and

(1) The third-party organization processes the personal data in accordance with requirements prescribed under PDPA finding that the third-party organization provides a standard of protection to personal data so transferred that is comparable to the protection under PDPA;

(2) Data subjects have been given the opportunity to object, after having been informed of the purposes of the transfer, the categories of recipients and the fact that the countries to which data is exported may have different data protection standards.

III. Liability and third party rights

(a) The Data Importer shall be liable to the Data Exporter for damages it causes by any breach of these clauses. Liability as between the parties is including but not limited to actual damage suffered and penalties imposed by government or local authority. The Data Importer shall be liable to Data Subjects for damages it causes by any breach of third party rights under these clauses. This does not affect the liability of the Data Exporter under its data protection law.

(b) The parties agree that a Data Subject shall have the right to enforce as a third-party beneficiary this clause and clauses I(b), I(d), I(e), II(a), II(d), II(e), II(h), II(i), III(a), V, VI(d) and VII against the Data Importer or the Data Exporter, for their respective breach of their contractual obligations, with regard to his personal data, and accept jurisdiction for this purpose in the Data Exporter's country of establishment. In cases involving allegations of breach by the Data Importer, the Data Subject must first request the Data Exporter to take appropriate action to enforce his rights against the Data Importer, if the Data Exporter does not take such action within a reasonable period (which under normal circumstances would be one month), the Data Subject may then enforce his rights against the Data Importer directly. A Data Subject is entitled to proceed directly against a Data Exporter that has failed to use reasonable efforts to determine that the Data Importer is able to satisfy its legal obligations under these clauses (the Data Exporter shall have the burden to prove that it took reasonable efforts).

IV. Law applicable to the clauses

These clauses shall be governed by the laws of Singapore.

V. Resolution of disputes with Data Subjects or the authority

(a) In the event of a dispute or claim brought by a Data Subject or the authority concerning the processing of the personal data against either or both of the parties, the parties will inform each other about any such disputes or claims, and will cooperate with a view to settling them amicably in a timely fashion.

(b) The parties agree to respond to any generally available non-binding mediation procedure initiated by a Data Subject or by the authority. If they do participate in the proceedings, the parties may elect to do so remotely (such as by telephone or other electronic means). The parties also agree to consider participating in any other arbitration, mediation or other dispute resolution proceedings developed for data protection disputes.

(c) Each party shall abide by a decision of a competent court of Singapore or of the authority which is final and against which no further appeal is possible.

VI. Termination

(a) In the event that the Data Importer is in breach of its obligations under these clauses, then the Data Exporter may temporarily suspend the transfer of personal data to the Data Importer until the breach is repaired or the contract is terminated.

(b) In the event that:

(i) The transfer of personal data to the Data Importer has been temporarily suspended by the Data Exporter for longer than one month pursuant to paragraph (a);

(ii) Compliance by the Data Importer with theses clauses would put it in breach of its legal or regulatory obligations in the country of import;

(iii) The Data Importer is in substantial or persistent breach of any warranties or undertakings given by it under these clauses;

(iv) A final decision against which no further appeal is possible of a competent court of Singapore or of the authority rules that there has been a breach of the clauses by the Data Importer or the Data Exporter; or

(v) A petition is presented for the administration or winding up of the Data Importer, whether in its personal or business capacity, which petition is not dismissed within the applicable period for such dismissal under applicable law; a winding up order is made; a receiver is appointed over any of its assets; a trustee in bankruptcy is appointed, if the Data Importer is an individual; a company voluntary arrangement is commenced by it; or any equivalent event in any jurisdiction occurs then the Data Exporter, without prejudice to any other rights which it may have against the Data Importer, shall be entitled to terminate these clauses, in which case the authority shall be informed where required. In cases covered by (i), (ii), or (iv) above the Data Importer may also terminate these clauses.

(c) Either party may terminate these clauses if (i) any Commission positive adequacy decision under Singapore PDPA 2012 (or any superseding text) is issued in relation to the country (or a sector thereof) to which the data is transferred and processed by the Data Importer, or any superseding text becomes directly applicable in such country.

(d) The parties agree that the termination of these clauses at any time, in any circumstances and for whatever reason (except for termination under clause VI(c)) does not exempt them from the obligations and/or conditions under the clauses as regards the processing of the personal data transferred.

VII. Variation of these clauses

The parties may not modify these clauses except to update any information in Annex B, in which case they will inform the authority where required. This does not preclude the parties from adding additional commercial clauses where required.

VIII. Description of the Transfer

The details of the transfer and of the personal data are specified in Annex B. The parties agree that Annex B may contain confidential business information which they will not disclose to third parties, except as required by law or in response to a competent regulatory or government agency, or as required under clause I(e). The parties may execute additional annexes to cover additional transfers, which will be submitted to the authority where required. Annex B may, in the alternative, be drafted to cover multiple transfers.

ANNEX A to the Data Transfer Agreement

DATA PROCESSING PRINCIPLES

1. Purpose limitation: Personal data may be processed and subsequently used or further communicated only for purposes described in Annex B or subsequently authorized by the Data Subject.

2. Data quality and proportionality: Personal data must be accurate and, where necessary, kept up to date. The personal data must be adequate, relevant and not excessive in relation to the purposes for which they are transferred and further processed.

3. Transparency: Data subjects must be provided with information necessary to ensure fair processing (such as information about the purposes of processing and about the transfer), unless such information has already been given by the Data Exporter.

4. Security and confidentiality: Technical and organizational security measures must be taken by the organization that are appropriate to the risks, such as against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, presented by the processing. Any person acting under the authority of the organization, including a processor, must not process the data except on instructions from the Data Exporter.

5. Rights of access, correction and objection: As provided under the PDPA, Data Subjects must, whether directly or via a third party, be provided with the Personal Information about them that an organization holds, except for requests which are manifestly abusive, based on unreasonable intervals or their number or repetitive or systematic nature, or for which access need not be granted under the law of the country of the Data Exporter. Provided that the authority has given its prior approval, access need also not be granted when doing so would be likely to seriously harm the interests of the Data Importer or other organizations dealing with the Data Importer and such interests are not overridden by the interests for fundamental rights and freedoms of the Data Subject. The sources of the personal data need not be identified when this is not possible by reasonable efforts, or where the rights of persons other than the individual would be violated. Data subjects must be able to have the Personal Information about them rectified, amended where it is inaccurate or processed against these principles. If there are compelling grounds to doubt the legitimacy of the request, the organization may require further justifications before proceeding to rectification, amendment. Notification of any rectification, amendment to third parties to whom the data has been disclosed need not be made when this involves a disproportionate effort. A Data Subject must also be able to object to the processing of the personal data relating to him if there are compelling legitimate grounds relating to his particular situation.

6. Data used for marketing purposes: Where data is processed for the purposes of direct marketing, effective procedures should exist allowing the Data Subject at any time to "opt-out" from having his data used for such purposes.

7. Automated decisions: For purposes hereof "automated decision" shall mean a decision by the Data Exporter or the Data Importer which produces legal effects concerning a Data Subject or significantly affects a Data Subject and which is based solely on automated processing of personal data intended to evaluate certain personal aspects relating to him, such as his performance at work, creditworthiness, reliability, conduct, etc. The Data Importer shall not make any automated decisions concerning Data Subjects, except when:

(a) (i) such decisions are made by the Data Importer in entering into or performing a contract with the Data Subject, and

(ii) the Data Subject is given an opportunity to discuss the results of a relevant automated decision with a representative of the parties making such decision or otherwise to make representations to that parties.

Or

(b) Where otherwise provided by the law of the Data Exporter.

ANNEX B to the Data Transfer Agreement

DESCRIPTION OF THE TRANSFER

Data subjects

The personal data transferred concern the following categories of data subjects:

Data subjects of the data exporter who have signed both the AppGallery and AppTouch agreements and write comments.

Purposes of the transfer(s)

The transfer is made for the following purposes:

• Provide replies and feedback to data subjects' reviews/comments on applications platforms such as AppGallery.

• Assist in improving services and products by these apps developers.

Categories of data

The personal data transferred concern the following categories of data:

• Users' name, comments, ratings, rating time, country, region, etc.

Recipients

The personal data transferred may be disclosed only to the following recipients or categories of recipients:

•Data importer

Sensitive data (if appropriate)

The personal data transferred concern the following categories of sensitive data:

N/A

Data protection registration information of data exporter (where applicable)

N/A

Additional useful information (storage limits and other relevant information)

Contact points for data protection enquiries

Data importer Data exporter Place Data Protection Contact here

Huawei: datamanagement.hshk@huawei.com

AppTouch Provider: AppTouch Provider DPO

Exhibit C: Data Transfer Agreement in Compliance with Russian Legislation

Between

Name of the data exporting organization: Shenzhen Huawei Siray Technologies Co., Ltd

Address: Room 501, Building A1 No. 1 Jingyue Road, Jiulongshan Community Fucheng Subdistrict, Longhua District Shenzhen, Guangdong China

and Shenzhen Huawei Siray Technologies Co., Ltd on behalf of other Data Controllers (please refer to our website for the controller list)

hereinafter "data exporter"

And

Developer who signed the HUAWEI AppGallery Connect Service Agreement with data exporter and part of the Agreement

hereinafter "data importer"

each a "party"; together "the parties".

Each of the Parties is a personal data operator, including personal data processed as part of the fulfillment of obligations provided within the Agreement.

For the purposes of the Agreement, personal data refers to information that is in accordance with the legislation of the Russian Federation, to be transferred by data exporter to data importer and includes the following data:

• Users' name, comments, ratings, rating time, country, region, etc.

The personal data transferred concern the following categories of data subjects:

• Data subjects of the data exporter who have signed both the AppGallery and AppTouch agreements and write comments.

The transfer is made for the following purposes:

• Provide replies and feedback to data subjects' reviews/comments on applications platforms such as AppGallery.

• Assist in improving services and products by these apps developers.

The transfer of personal data is not considered by the Parties as an instruction to process personal data.

Each of the Parties shall ensure the confidentiality of personal data received within the framework of the Agreement, compliance with the requirements for personal data processing established by Federal Law No. 152-FZ of July 27, 2006 "On Personal Data" and regulatory acts adopted in its execution, and shall be responsible for taking all necessary legal, organizational and technical measures to protect personal data from unauthorized or accidental access to them, destruction, modification, blocking, copying, dissemination of personal data as well as other illegal actions such data.

The Party that provides personal data shall be responsible for the legality and accuracy of provided data to other Party for the purpose of executing the Agreement, as well as for obtaining the consent of the data subjects to transfer their personal data to the other Party in the manner prescribed by the legislation of the Russian Federation personal data.

The Party that received personal data from the other Party does not assume the obligation to inform the subjects whose personal data has been transferred about the beginning of their processing, since the Party that transfers personal data must bear the obligation to inform the data subjects accordingly.

The Party receiving personal data has the right to engage in processing the received personal data of third parties for the purpose of executing the Agreement in the necessary volume only if the other Party provides confirmation of receipt of the relevant consent from the personal data subject. In any case, a Party is obliged, upon the request of the other Party, to provide information about third parties who were provided with personal data or who had access to them: their full and abbreviated name, address of the location (place of registration and residence), information about which particular personal data what particular subjects and for what purposes were transferred to third parties.

Search
Enter a keyword.