The company's explanation, the adviser's view and the page in the filing: see MattersAs advised by our PRC Legal Adviser and U.S. Legal Adviser and based on the due diligence conducted by our U.S. Legal Adviser in connection with the [REDACTED], such collection and use of personal data comply with material applicable laws and regulations concerning data privacy and security in China and the United States during the Track Record Period and up to the Latest Practicable Date.
Business · p. 189
Data, cybersecurity & privacy
Hong Kong IPO disclosure precedents · 52 companies, 55 items
personal information and data protection, cross-border data transfer, cybersecurity review, CIIO, data incidents, MLPS
Compliance matters are read from filings since 24 August 2026.
As to cross-border data transfer, we mainly transfer summary clinical trial data which does not contain personal information of enrolled patients for regulatory communications and filings and we have not conducted any cross-border transfer of personal data.
Business · p. 220
The company's explanation, the adviser's view and the page in the filing: see MattersDuring the Track Record Period and up to the Latest Practicable Date, we had complied with all relevant laws and regulations concerning data privacy and security in the PRC and the United States in all material aspects and had not been subject to any material administrative penalty concerning data privacy and security.
Business · p. 220
In respect of our cross-border data transfer activities, as confirmed by our data compliance legal counsel, we are exempt from applying for the outbound data transfer security assessment, concluding a standard contract for the outbound transfer of personal information or obtaining personal information protection certification, for the reason set out as below.
Business · p. 203
Based on the foregoing, as of the Latest Practicable Date, our Directors and our data compliance legal counsel are of the view that we are not subject to a mandatory cybersecurity review pursuant to the Cybersecurity Review Measures.
Business · p. 203
The company's explanation, the adviser's view and the page in the filing: see MattersAs such, as of the Latest Practicable Date, our cross-border data transfers are in compliance with the requirements of the Personal Information Protection Law, the Regulation on Network Data Security Management, the Provisions on Promoting and Regulating Cross-Border Data Flows, and other relevant laws and regulations.
Business · p. 205
During the Track Record Period and up to the Latest Practicable Date, we had not transmitted any personal information collected or generated in the course of our operations in Chinese Mainland to any overseas entity, organization or individual.
Business · p. 208
The company's explanation, the adviser's view and the page in the filing: see MattersAs confirmed by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had not incurred any related administrative penalties.
Business · p. 208
None of such information constitutes sensitive personal information or involves any data identified, publicly announced or informed as important data by competent authorities.
Business · p. 136
The company's explanation, the adviser's view and the page in the filing: see MattersBased on the foregoing, our PRC Legal Advisor is of the view that we have complied with applicable PRC laws and regulations relating to data privacy, cybersecurity and data security in all material respects.
Business · p. 136
As advised by our PRC Data Compliance Counsel, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with applicable PRC laws and regulations relating to data privacy, cybersecurity, cross-border data transfer and data security in all material respects, and had not been subject to any administrative penalties or legal proceedings in relation thereto.
Business · p. 197
The company's explanation, the adviser's view and the page in the filing: see MattersWe were not required to undergo a security assessment, enter into the standard contract for the cross-border transfer of personal information, or obtain personal information protection certification.
Business · p. 197
Given the above, our PRC Data Compliance Legal Advisers are of the view that we have completed the self-assessment for outbound data transfer in the course of our business as required under the applicable PRC laws and regulations relating to outbound data transfer and that such outbound data transfer activities are compliant with the applicable PRC laws and regulations relating to outbound data transfer.
Business · p. 174
The company's explanation, the adviser's view and the page in the filing: see MattersIn addition, during the Track Record Period and up to the Latest Practicable Date, as advised by our PRC Data Compliance Legal Advisers and the Directors confirm that we have complied with the applicable PRC laws and regulations relating to data security, personal information protection and cyber security in all material respects.
Business · p. 175
Given that (i) CCRC has confirmed that listing in Hong Kong does not constitute a listing abroad; (ii) as of the Latest Practicable Date, we have not received any official notification from relevant regulatory authorities designating our network facilities and information systems as Critical Information Infrastructure (“CII”), and therefore we are not deemed as a CII operator; and (iii) as of the Latest Practicable Date, we had not received any notice that we are required to conduct a cybersecurity review or our data processing activity affects or may affect national security, therefore, our PRC Legal Advisor is of the view that as of the Latest Practicable Date, we were not required to file cybersecurity review under the Measures for Cybersecurity Review for our proposed listing.
Business · p. 190
As advised by our PRC Legal Advisor, we are not required to undergo a data export security assessment, on the basis that: (i) our business does not involve critical information infrastructure, we do not provide services to any critical information infrastructure operators, and we have not been designated as a critical information infrastructure operator by any relevant PRC authority; and (ii) the data involved in our sole cross-border data transmission scenario consists of hash values and device location information, which are not highly sensitive in nature, constitute general personal information only and do not fall within the definition of “important data” under the applicable PRC laws and regulations.
Business · p. 190
The company's explanation, the adviser's view and the page in the filing: see MattersIn line with our actual business operations, we have filed the Standard Contract for the Cross-Border Transfer of Personal Data (“個人信息出境標準合同”) and obtained the relevant certification.
Business · p. 190
In 2018, we became aware that certain personally identifiable information of our customers, including names, login credentials and credit card information, was stolen during a concerted criminal cyberattack on our computer network.
Risk Factors · p. 61
The company's explanation, the adviser's view and the page in the filing: see MattersIn October 2022, we reached a settlement agreement with the Office of the Attorney General, pursuant to which we paid US$1.9 million in settlement payment in the same month and have maintained a comprehensive information security programme that includes a series of cybersecurity measures to protect consumer information.
Business · p. 206
During the Track Record Period, we did not engage in cross-border data transactions and are not classified as a network platform operator processing personal information of over one million users or an operator of critical information infrastructure under the Cybersecurity Review Measures.
Risk Factors · p. 43
The company's explanation, the adviser's view and the page in the filing: see MattersBased on the due diligence conducted and documents reviewed by our PRC data compliance legal advisers on information security and privacy, during the Track Record Period and up to the Latest Practicable Date, we were in material compliance with the PRC laws and regulations relating to cybersecurity, data security and privacy protection, and had not been involved in any material violations, including the unlawful collection, use or provision of data.
Business · p. 178
Our PRC Legal Advisor and legal advisors in other relevant jurisdictions are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have been in compliance in all material respects with applicable laws and regulations relating to cybersecurity, data security and personal information protection in the PRC and other relevant jurisdictions.
Business · p. 201
The company's explanation, the adviser's view and the page in the filing: see MattersFurthermore, our domestic official website has successfully obtained the Level II Multi-Level Protection Scheme filing (網絡 安全等級保護二級備案) with the local public security authority.
Business · p. 201
Within the business scope of cellular IoT chips research, development and commercialization, our PRC Legal Advisor as to data compliance, is of the view that, we had complied, in all material respects, with the applicable laws and regulations with respect to data privacy, cybersecurity, and personal data protection during the Track Record Period and up to the Latest Practicable Date.
Business · p. 190
The company's explanation, the adviser's view and the page in the filing: see MattersAll data collected by us within Chinese Mainland is stored domestically.
Business · p. 189
The company's explanation, the adviser's view and the page in the filing: see MattersSubsequently, in September 2025, CNIL issued a fine of EUR 150 million against us in connection with our practices for obtaining user consent and cookie practices, though CNIL conceded that all alleged non-compliance had been remediated prior to the fine.
Business · p. 207
In April 2026, the Irish Data Protection Commission (the “DPC”) commenced a statutory inquiry into our transfers of certain EU personal data to China, following a complaint filed by a privacy advocacy group.
Business · p. 207
The company's explanation, the adviser's view and the page in the filing: see MattersWe are currently cooperating with this investigation and intend to vigorously defend our position that our transfers of EU personal data are compliant with the GDPR.
Business · p. 207
The company's explanation, the adviser's view and the page in the filing: see MattersWith respect to the matters disclosed in “Business — Legal Proceedings”, to the best of our knowledge, our practices are not materially non-compliant with applicable laws and regulations relating to data privacy and cybersecurity.
Business · p. 202