Zonergy Century Co., Ltd. "Zonergy Cloud" Platform Privacy Agreement

I. Preamble to the Agreement

(I) Purpose of the Agreement

Zonergy Century Co., Ltd. (hereinafter referred to as "we", "the Company") fully recognizes the importance of privacy protection to users. This Privacy Agreement aims to clarify the rules for the collection, storage, use, processing, transmission, provision, disclosure, and deletion of user information by the "Zonergy Cloud" platform (hereinafter referred to as "the Platform") and the related rights and obligations, ensuring the lawful rights and interests of users.

(II) Scope of Application

This Privacy Agreement applies to users' use of all services provided by the "Zonergy Cloud" Platform through any means, including but not limited to platform registration, login, energy storage device data upload, data analysis, remote monitoring, operation and maintenance management, and related derivative services.

Services provided by the Platform's third-party partners (such as third-party payment, map services, etc.) have their privacy protection rules independently formulated and enforced by such third parties. We are not responsible for these rules. Users are advised to carefully read the third parties' privacy agreements.

(III) User Consent

By registering, logging in, or using the services of the "Zonergy Cloud" Platform, the user indicates that they have fully read, understood, and agree to all contents of this Privacy Agreement, including any subsequent modifications we make to this Agreement. If the user does not agree to this Agreement, they should immediately cease using the Platform's services.

II. Definitions

1. User: Refers to any natural person aged 18 or above, legal person, or other organization that registers, logs in, and uses the services of the "Zonergy Cloud" Platform, including energy storage device owners, operation and maintenance personnel, partners, etc.

2. User Information: Refers to all types of information related to the user collected by us during the user's use of the Platform services, including Personal Information, Device Information, Energy Storage Data, etc.

3. Personal Information: Refers to any information recorded electronically or by other means that can identify a specific natural person's identity or reflect a specific natural person's activities, either alone or in combination with other information, such as name, contact information, ID number, etc.

4. Device Information: Refers to information related to the user's energy storage devices connected to the Platform, including device model, serial number, hardware configuration, installation location, operating status, etc.

5. Energy Storage Data: Refers to various data generated during the operation of energy storage devices, including charge/discharge data, power data, voltage/current data, temperature data, fault alarm data, etc.

6. Data Node: Refers to the dedicated server clusters used by the Platform to store User Information, including the Domestic Node (located within China), the Singapore Node (located within Singapore), and the planned Frankfurt Node (to be located within Germany). Each node is an independent deployment architecture.

III. Information Collection and Use

(I) Types of Information Collected

1. Registration Information: When registering for a Platform account, users need to provide information such as username, password, mobile phone number, email address, etc. Legal persons or other organization users also need to provide organization name, unified social credit code, contact person information, etc.

2. Personal Information: To provide personalized services and meet compliance requirements, we may collect users' names, ID numbers, occupations, industries, etc. Users can choose whether to provide this information voluntarily.

3. Device Information: When users connect energy storage devices to the Platform, the Platform will automatically collect information such as device model, serial number, hardware configuration, installation location, network status, firmware version, etc., to facilitate device connection, monitoring, and management.

4. Energy Storage Data: The Platform will continuously collect Energy Storage Data generated during the operation of energy storage devices, including charge/discharge data, power data, voltage/current data, temperature data, fault alarm data, etc., for data analysis, device operation and maintenance, performance optimization, security assurance, etc.

5. Usage Behavior Information: We will collect information related to users' use of the Platform, including login time, login location, operation records, browsing history, service usage duration, etc., to improve Platform service quality and optimize user experience.

6. Other Information: With user consent or as required by laws and regulations, we may collect other information related to Platform services.

(II) Purpose of Information Use

1. To provide users with core services such as Platform registration, login, device connection, data monitoring, operation and maintenance management, etc.

2. To analyze the operating status of energy storage devices, providing value-added services such as fault warnings, maintenance reminders, performance optimization suggestions, etc.

3. To optimize Platform functions and service processes, improve user experience, and develop new features and services that meet user needs.

4. To ensure the security of the Platform and user information, prevent risks such as fraud and malicious attacks, and maintain the normal operation order of the Platform.

5. To comply with laws, regulations, and regulatory requirements, and fulfill relevant compliance obligations.

6. Other lawful purposes with user consent.

(III) Methods of Information Collection

1. Voluntary Provision by Users: Including information filled in during registration, information uploaded during use, feedback voluntarily submitted, etc.

2. Automatic Collection by the Platform: Through Platform systems, server logs, device sensors, and other technical means, automatically collecting Usage Behavior Information, Device Information, and Energy Storage Data.

3. Third-Party Provision: Obtaining relevant information from legitimate and compliant third-party partners with user consent or as permitted by laws and regulations.

IV. Information Storage and Protection

(I) Storage Deployment and Data Isolation

1. Node Deployment Description: The Platform adopts a multi-node distributed storage architecture. User Information will be stored in the corresponding Data Node based on the service region selected during user registration, device installation location, or business requirements:(1) Domestic Node: Stores information related to users within China and energy storage devices deployed within China;(2) Singapore Node: Stores information related to users in the Asia-Pacific, Southeast Asia, Central Asia, and surrounding regions, as well as energy storage devices deployed in those regions;(3) Frankfurt Node (Future Deployment): Stores information related to users in Europe and energy storage devices deployed in that region.

2. Data Isolation Guarantee: Each Data Node is an independently deployed server cluster, equipped with dedicated network environments, storage resources, and security protection systems. Strict technical isolation mechanisms are established between nodes. User Information is stored and processed only within its affiliated node and will not be transmitted or synchronized in any form between the Domestic Node, Singapore Node, and Frankfurt Node.

3. Storage Media and Compliance Requirements: Servers in all nodes comply with local data storage security standards. Specifically:(1) Storage in the Domestic Node complies with the requirements of the "Cybersecurity Law of the People's Republic of China," the "Data Security Law," and the "Personal Information Protection Law";(2) Storage in the Singapore Node complies with the requirements of Singapore's "Personal Data Protection Act" (PDPA);(3) Storage in the Frankfurt Node complies with the requirements of the EU's "General Data Protection Regulation" (GDPR) and relevant German local data protection laws and regulations.

(II) Storage Period

1. We will determine the storage period of User Information based on the purpose of use and the regional legal requirements corresponding to the affiliated node:(1) Registration Information, Personal Information, etc.: Continuously stored during the existence of the user account. Upon account cancellation, deletion or anonymization will be completed according to local legal requirements;(2) Energy Storage Data, Usage Behavior Information, etc.: Stored for a reasonable period necessary to achieve the collection purpose. After the period expires, deletion or anonymization will be performed according to the legal requirements of the corresponding node;(3) Where laws and regulations have special requirements regarding storage periods, those requirements shall prevail.

2. After a user cancels their account, we will cease using the related User Information and will complete the deletion or anonymization of that User Information within its affiliated node within 30 days (or within the period required by the local laws and regulations of the corresponding node), unless otherwise stipulated by laws and regulations.

(III) Security Protection Measures

1. Technical Safeguards:(1) All nodes employ transmission encryption (SSL/TLS 1.3) and storage encryption (SM3, AES-256) technologies to prevent information from being intercepted, tampered with, or leaked;(2) Access control, permission level management, operation log auditing, and other technologies are used to restrict internal personnel's access to User Information. Only authorized personnel can access relevant information within the scope of their duties;(3) Each node independently conducts regular security vulnerability scans, penetration tests, and emergency drills to continuously improve node security protection capabilities.

2. Management Safeguards:(1) Establish a cross-regional information security management system. Each node is equipped with a dedicated security operations team, with clear delineation of security responsibilities;(2) Provide targeted security training and confidentiality education to employees who handle User Information, and require them to sign confidentiality agreements;(3) Formulate node-specific data security incident emergency response plans. In the event of a security incident, handling will occur only within the affiliated node, without affecting the data security of other nodes.

3. Third-Party Safeguards: If a node utilizes storage resources from a third-party cloud service provider, we will strictly review the third party's security qualifications (e.g., the Domestic Node provider must pass the Class III National Security Protection Level certification, the Frankfurt Node provider must pass GDPR compliance certification), sign confidentiality agreements and data processing agreements, and clarify data isolation obligations and security responsibilities.

(IV) Security Risk Notice

Despite the above security protection measures we have adopted, due to the complexity of the network environment and the limitations of technological development, it is impossible to completely eliminate the risk of User Information being illegally accessed, stolen, or leaked. Users should properly safeguard their own identity credentials such as account passwords and verification codes, and avoid information leakage caused by their own improper operations. If users discover any account anomalies or information leaks, they should notify us immediately.

V. Information Sharing, Transfer, and Public Disclosure

(I) Information Sharing

1. We will not share users' Personal Information and Energy Storage Data with third parties, unless we obtain the user's explicit consent.

2. To provide Platform services and achieve cooperation objectives, we may share necessary User Information with the following third parties (the shared information is limited to the minimum scope necessary to achieve the purpose and sharing only occurs within the Data Node where the User Information resides):(1) Third-party service providers: Such as cloud service providers, local operation and maintenance service providers, etc., for the corresponding node. We will sign agreements with such third parties, requiring them to comply with confidentiality obligations and data isolation requirements, and not to use the shared information for other purposes;(2) Partners: Such as energy storage device upstream/downstream enterprises, regional operation and maintenance partners, etc. Subject to user consent, only share relevant Device Information and Energy Storage Data within the user's affiliated node to provide joint services;(3) Legal and Regulatory Requirements: According to the mandatory requirements of laws and regulations, judicial authorities, or administrative regulatory departments in the jurisdiction of the node where the User Information resides, we may share User Information with relevant departments.

(II) Information Transfer

1. Without user consent, we will not transfer User Information to any third party, and will not transfer User Information from one node to another node or transfer it cross-nodes to a third party.

2. If the Company undergoes changes such as mergers, divisions, acquisitions, restructuring, liquidation, etc., the User Information of a particular node may be transferred as part of that node's assets to the entity resulting from the change. We will notify users of that node in advance and require the transferee to continue fulfilling the node isolation obligations and security protection responsibilities stipulated in this Privacy Agreement to ensure the security of User Information.

(III) Public Disclosure of Information

1. We will not publicly disclose users' Personal Information and Energy Storage Data, unless we obtain the user's explicit consent.

2. Due to legal and regulatory requirements or public interest needs (such as responding to public emergencies, protecting others' lawful rights and interests, etc.), we may publicly disclose User Information within a reasonable scope, but will take measures such as de-identification, and disclosure will be limited to the geographic region corresponding to the node where the User Information resides, to protect user privacy.

VI. User Rights

(I) Right to Access and Inquire

Users have the right to log into their Platform account to access and inquire about their own Registration Information, Personal Information, Device Information, Energy Storage Data, and the location of the Data Node where their information resides, among other relevant information.

(II) Right to Rectification

If users find that their information is incorrect or incomplete, they have the right to request us to make corrections. We will promptly make corrections after verification.

(III) Right to Deletion

Under circumstances compliant with laws and regulations and the provisions of this Agreement, users have the right to request us to delete part or all of their information (including all information within the affiliated node), such as canceling an account or deleting specific Energy Storage Data. We will promptly handle such requests after verification.

(IV) Right to Withdraw Consent

Users have the right to withdraw their consent to the collection, use, sharing, and other matters of information outlined in this Agreement. However, after withdrawal of consent, we may not be able to continue providing related services, and users shall bear the consequences arising therefrom.

(V) Right to Data Portability (Applicable to Cross-Border Users)

Users who meet the requirements of local laws and regulations corresponding to the affiliated node have the right to request us to migrate their Personal Information and Energy Storage Data stored in a specific node to a compliant storage location they designate. We will assist in processing this request subject to technical feasibility and legal requirements, and the migration process will not involve data transmission from other nodes.

(VI) Right to Complain

If users have objections to our information processing activities, they have the right to file a complaint with us. We will conduct a review within a stipulated time and provide feedback on the processing result.

(VII) Methods for Exercising Rights

Users can exercise the above rights through the Platform's customer service channels (e.g., customer service phone, online customer service, email, etc.). We will respond to and process user requests within a reasonable period.

VII. Third-Party Services

The Platform may contain links or entry points to third-party services (such as third-party payment, map services, regional data analysis tools, etc.). The privacy protection rules for third-party services are independently formulated and enforced by the third parties and are unrelated to us.

When using third-party services, users should carefully read the third party's privacy agreement and service terms. The collection and use of user information by third parties is their sole responsibility, and we assume no liability. Third-party services can only obtain information related to the user from within the user's affiliated node and cannot access user data from other nodes.

VIII. Agreement Modification and Notice

(I) Agreement Modification

We reserve the right to modify this Privacy Agreement based on changes in laws and regulations, adjustments to Platform services (including node deployment adjustments), and other circumstances. The modified agreement will be published in a prominent position on the Platform for a period of no less than 30 days.

(II) Notification Method

After the agreement is modified, we will notify users via Platform announcements, in-site messages, SMS, email, and other methods. If a user continues to use the Platform services after the publication period ends, it indicates their acceptance of the modified Privacy Agreement; if the user does not agree, they should immediately cease using the Platform services.

IX. Governing Law and Dispute Resolution

(I) Governing Law

The conclusion, performance, interpretation, and dispute resolution of this Privacy Agreement shall be governed by the laws of the People's Republic of China. However, for User Information stored in the Singapore Node or the Frankfurt Node, matters related to the storage and processing of such information shall also be governed by the laws and regulations of the jurisdiction where that node is located (excluding conflict of law rules).

(II) Dispute Resolution

Any dispute arising between the user and us out of or in connection with this Privacy Agreement shall first be resolved through friendly negotiation. If negotiation fails, either party shall have the right to bring a lawsuit in the competent people's court at the location of the Company, or, in accordance with the provisions of the local laws and regulations of the jurisdiction where the User Information's affiliated node is located, apply to the competent dispute resolution institution for resolution.

X. Contact Information

If users have any questions, comments, or suggestions regarding this Privacy Agreement, or need to exercise relevant rights or report information security issues, they may contact us via the following methods:

· Company Name: Zonergy Century Co., Ltd.

· Contact Address: 25th Floor, Building 2, Dongguang AI Valley, 6 Chengye Road, Chenghua District, Chengdu, China

· Customer Service Tel: 028-83550719

· Email: global@zonergy.com

We will promptly verify and process user feedback upon receipt and reply within a reasonable period.

XI. Miscellaneous Provisions

This Privacy Agreement shall take effect from the date the user registers or first uses the Platform services. Matters not covered by this Agreement shall be handled in accordance with relevant laws and regulations and the Platform's Service Terms.