Update Date: July 9, 2026
Dear users, Zhejiang POCTech Co.,Ltd., (hereinafter referred to as "Zhejiang POCTech" or "we") as data controller, attach great importance to the protection of your personal data, and when you access and use the Yuwell Anytime application (hereinafter referred to as the "App" or "Anytime") developed and operated by us, we will protect your personal data in accordance with this Privacy Policy (hereinafter referred to as the "Policy").
This Policy is designed to help you understand what personal data we collect, why we collect it, and how we protect it. We will collect and process your personal data in accordance with the Thailand Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), and other relevant laws and regulations of Thailand and provide services to you.
Before you use Anytime, please be sure to read and understand this Policy carefully and completely, especially the bold and/or underlined parts. If you wish to use the services provided by the App, please express your explicit consent to this Policy by clicking "Read and Agree", otherwise, please do not use the App or provide us with your personal data.
Data Controller and Data Protection Officer (DPO)
In accordance with the Thailand Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), Section 23(5), we hereby inform you of the following data controller information:
Data Controller: Zhejiang POCTech Co.,Ltd.
Address: No.1633 Hongfeng Road, Building 11 & 12, Huzhou City, Zhejiang, 313000, China
Email (Customer Service): helpdesk@yuyue.com.cn
Email (Data Protection Officer): zhangxiaoyu@yuyue.com.cn
Data Protection Officer (DPO): The person appointed by us to oversee our personal data protection practices, ensure compliance with the PDPA, and serve as the point of contact for data subjects and the Personal Data Protection Committee (PDPC).
If you have any questions, comments, or suggestions about this Policy, or wish to exercise your rights as a data subject, please contact us through the above channels.
Related Definitions
1. Personal Data: Any data relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic,
cultural or social identity of that natural person. The personal data in this Policy refers to your personal data that we collect, store, transmit and use in order to provide services to you.
2. Sensitive Personal Data: Under the Thailand PDPA, personal data relating to a person's health, disability, genetics, biometric data, or any data which may affect the data subject in the same way as prescribed by the Personal Data Protection Committee (PDPC) is classified as sensitive personal data. Your blood glucose data and health-related information collected through this App constitute sensitive personal data under Thai law.
3. Continuous Glucose Monitoring ("CGM") System ("product"): A monitoring technology that monitors glucose concentrations in subcutaneous tissue fluid through a glucose sensor to reflect glucose ("blood glucose") level. With Yuwell Anytime app, transmitter, and sensor as the main components.
4. Anytime: The Yuwell Anytime app, a blood glucose data collection and analysis platform developed and operated by Zhejiang POCTech Co.,Ltd..
5. Sensor: Medical detector for monitoring blood glucose concentration by subcutaneous tissue fluid of users.
6. Transmitter: The device collect the biological signal generated by the sensor, convert it into blood glucose data and send it to Anytime via Bluetooth.
7. User: The natural person who meets the qualification requirements of Anytime users and registers and logs in to the Anytime account through the designated method.
8. Company Group: The company group composed of the parent company of Zhejiang POCTech Co.,Ltd. and its subsidiaries and branches.
9. Distributor: The organization that sells our products to you.
10. Data Protection Officer (DPO): The person appointed by us to oversee our personal data protection practices, ensure compliance with the PDPA, and serve as the point of contact for data subjects and the PDPC.
1. Scope of Application
1.1 As an integral part of the CGM system manufactured by Zhejiang POCTech Co.,Ltd., this App can be used to continuously record, analyze and share your blood glucose levels. This Policy only applies to you when you use the product or service of this App, including collecting blood glucose data with sensor and transmitter, viewing blood glucose data and charts, etc.
1.2 This Policy does not apply to services provided to you by third-party. For example, if our third-party service provider provides services to you through our the App, the data you provide to the service provider does not apply to this Policy.
1.3 The App may contain links to third-party website. Any access to and use of such linked website is not governed by this Policy, but rather by the privacy policy of such third-party website. We are not responsible for the data practice of such third-party website.
2. How to Collect and Use Personal Data
Based on your explicit consent, in order to provide you with the product and service, we collect and use the following personal data after taking appropriate security measures. You should provide us with accurate personal data, otherwise you will not be able to use the corresponding products or services accurately.
2.1 We collect and use the following personal data:
2.1.1 Data you provide directly to us
(a) Account Information
We will collect your email address and registration password and send a verification link to your email address to complete the authentication of your account identity, create, activate and manage your account, including verifying your identity and ensuring account security. If you cannot complete the verification by yourself, you can contact us to help activate your account.
(b) Third-Party Account Information
If you invite a third party to bind your account to view your blood glucose data and related reports, we will collect the third-party account in order to identify the bound object.
(c) Personal Profile
If you fill in your personal profile, we may collect your gender, birthday, height, weight, type of diabetes to better analyze your blood glucose level. In addition, you can customize your profile photo, and we may collect your uploaded photo for profile setting.
(d) Blood Glucose Information
While you are wearing this product, we will collect your blood glucose data continuously for the purpose of recording and analyzing your blood glucose level.
(e) Event Record
We may collect the event (including basic insulin, prandial insulin, GLP-1RA, oral medicine, diet, exercise) recorded by you in the App to better analyze your blood glucose change levels.
2.1.2 Data Collected Automatically
In order to ensure the consistency of this App and provide you with services that better meet your needs, we may collect:
(a) Log Information
We need to keep the necessary logs in order to comply with the applicable PDPA and related laws of Thailand.
(b) Device and Network Information
We will collect data of the device you use according to the specific permissions you explicitly agree to open when installing and using the App, to provide corresponding services:
| Device Permissions have been Obtained |
Information Collected | Purpose of Collection |
|---|---|---|
| Camera, Flashlight | Available or not | Upload photo |
| Front-desk Location Background Location ACCESS COARSE LOCATION ACCESS FINE LOCATION ACCESS BACKGROUND LOCATION |
We don't use the collected location information. The location permission of users of Android 13 and previous versions would be turned on by default at the same time when turning on Bluetooth, the users of after Android 13 and IOS do not turn on location permission and no location data collection. | |
| Bluetooth | Available or not | Check whether data can be transmitted |
| Storage | Storage Information | Read the information of the storage space or store information in storage space |
| Network | Available or not | Check whether the network environment meets the use conditions of products or services |
| Vibrate | Available or not | To alert users of events |
| Notification | Available or not | Check whether notification can be sent to the user |
| Modify configuration (such as language, keyguard) |
Configuration setting information | Determine under what configuration to provide products or services |
2.1.3 Consequences of Not Providing Personal Data
In accordance with the PDPA Section 23(2), we hereby inform you that if you choose not to provide certain personal data, the following consequences may occur:
(a) If you do not provide account information (email address, password), you will not be able to create, activate, or manage your Anytime account, and thus will not be able to use the core functions of the App.
(b) If you do not provide blood glucose data (by not wearing the CGM sensor or not connecting the transmitter), we will not be able to record, analyze, or generate reports of your blood glucose levels, and you will not be able to use the core monitoring and analysis functions of the App.
(c) If you do not provide personal profile information (gender, birthday, height, weight, type of diabetes), we may not be able to provide you with personalized blood glucose analysis and health insights, though the basic monitoring functions will still be available.
(d) If you do not provide event records, the analysis of your blood glucose change levels may be less accurate or comprehensive.
Please note that providing personal data is voluntary, and you may choose not to provide non-essential data. However, the absence of certain data may affect the quality, accuracy, or availability of the services provided.
2.2 How we use your personal data
We will use your data in accordance with the purposes and methods disclosed in this Policy, and if we need to change the above purposes and types of data, or if we use the data for other purposes not specified in this Policy, or use the data collected for specific purposes for other purposes, we will obtain your explicit consent in advance as required by the PDPA and related personal data protection laws of Thailand.
3. Legal Basis for Processing Personal Data
Under the Thailand PDPA, we process your personal data based on the following legal bases:
(a) Consent: Your explicit consent is the primary legal basis for our collection, use, and disclosure of your personal data, including sensitive personal data (such as your blood glucose data and health information). You have the right to refuse consent or withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
(b) Performance of Contract: The processing of your personal data is necessary for the performance of the contract between you and us for the provision of CGM products and services.
(c) Compliance with Legal Obligations: In certain circumstances, we may process your personal data to comply with applicable laws and regulations of Thailand.
(d) Vital Interests: In emergency situations where your life or health is at risk, we may process your personal data without prior consent to protect your vital interests.
3.1 Sensitive Personal Data Processing
Your blood glucose data and health-related information constitute sensitive personal data under the Thailand PDPA. We will only collect, use, or disclose such sensitive personal data with your explicit consent, unless an exception under the PDPA applies. We will inform you of the specific purposes for processing sensitive personal data before obtaining your consent.
3.2 Consent Mechanism
We obtain your consent through a clear affirmative action (such as clicking the "Read and Agree" button or checkbox) before collecting your personal data. The consent request is clearly separated from other messages and delivered in a format which is easily accessible and understandable.
You have the right to withdraw your consent at any time by contacting us as specified in Section 9 of this Policy.
4. How to Share and Transfer Personal Data
4.1 We will not share your personal data with other organizations and individuals except in the following circumstances:
(a) Sharing by companies within the company group: After obtaining your explicit consent, we may share your personal data with companies within company group as data processors when it is necessary for the relevant entities according to their functions, and ensure the security of personal data through secure transmission and division of authority. We will enter into data processing agreements with such entities in accordance with the requirements of the Thailand PDPA.
(b) Sharing with distributors: If you feedback the possible problems of the product to distributors for support, we will reply to you through the original channel after troubleshooting the problems. This process may involve us sharing your personal data with distributors, and we will take access control and other means to ensure the safety of personal data.
(c) Sharing in the Event of a Merger or Division of a Company: In the event of a merger, acquisition or bankruptcy liquidation between us and another legal entity, or other circumstances involving a merger, acquisition or bankruptcy liquidation, if the transfer of personal data involved, we will require the new organization holding your personal data to continue to be bound by this Policy and obtain your explicit consent again.
4.2 We provide you with the option to transfer your personal data:
(a) Transferring to Bound Users through "Follow": If you use the "Follow" function of the App, after you provide the recipient account, we will transmit your blood glucose data to the third-party user bound to you through secure transmission based on your request, and you should confirm the identity of the third party and whether the account is accurate before initiating the sharing.
(b) Transferring to glooko: In order to provide you the blood glucose analysis report that meets glooko's standards, we will share your information with glooko in a secure manner based on your request after you visit glooko website through the App. For the subsequent processing of your personal data, please refer to glooko website.
4.3 Data Localization and Cross-border Transfer
Your personal data is stored and processed within Thailand. We do not transfer your personal data outside of Thailand. All data processing activities, including storage, are conducted on servers located in Thailand to ensure compliance with the Thailand PDPA and to protect your personal data.
In the event that we need to transfer your personal data to recipients located outside of Thailand in the future, we will implement appropriate safeguards to ensure an adequate level of data protection under the PDPA. This may include selecting partners located in countries that are recognized as providing an adequate level of data protection and, where applicable, implementing safeguards in accordance with standard data protection clauses or other mechanisms approved by
the PDPC. We will obtain your explicit consent before any cross-border transfer of your personal data, where required by law.
4.4 We will sign strict Confidentiality Agreement and Data Protection Agreement with the receivers, and require them to process your personal data in accordance with laws, this Policy and take any necessary security measures.
5. Retention Period of Personal Data
We will retain your personal data for the period necessary to provide you with services, however, if laws and regulations provide otherwise for the retention period, you agree to retain it for a longer period, ensure the safety and quality of services, achieve the purpose of dispute resolution, and it is technically difficult to achieve it, we will extend the retention period after the expiration of the aforesaid retention period, in accordance with the law, in accordance with the agreement or within a reasonable range. After the retention period has expired, we will delete or anonymize your personal data in accordance with the statutory provisions.
5.1 We will inform you of the retention period of your personal data at or before the time of collection. If we are unable to specify an exact retention period, we will explain the criteria or process used to determine the retention period.
5.2 Upon your request, we will delete or anonymize your personal data in accordance with the criteria prescribed by the PDPC, unless retention is required by law or for the establishment, exercise, or defense of legal claims.
6. How to Protect the Security of Personal Data
6.1 We take the security of your personal data very seriously. In order to ensure the security of your personal data, we have taken appropriate data security protection measures to protect your personal data from unauthorized access, use, modification, public disclosure, damage or loss. For example:
(a) Ensure the security of personal information from many aspects such as security management organization and policy.
(b) Implement security management measures such as database EBS snapshot strategy and status alarm strategy to effectively protect the integrity and security of personal data.
(c) Implement data authority management for employees, and gradually establish a data classification and grading system to ensure that only authorized personnel can access personal data;
(d) Implement strict Confidentiality Management for personnel involved in data use and security management, and regularly carry out training related to data security protection.
6.2 In the unfortunate event of a personal data security incident (such as unauthorized access, use, modification, public disclosure, damage or loss), we will promptly inform you of the basic
situation and possible impact of the security incident, the measures we have taken or will take to deal with it, the suggestions you can take to prevent and reduce the risk independently, and the remedial measures for you in accordance with the requirements of the PDPA and related regulations of Thailand. When it is difficult to notify the personal data subject one by one, we will make an announcement in a reasonable and effective manner.
6.3 We will report the handling situation of personal data security incidents to the Personal Data Protection Committee (PDPC) without undue delay, and in any event, if feasible, within 72 hours of becoming aware of such breach, in accordance with the requirements of the PDPA.
6.4 If our products and services cease to operate, we will take reasonable steps to protect the security of your personal data, including promptly stopping activities that collect data. Notification of cessation of operation will be notified in the form of a notice or announcement on a case-by-case basis, and the stored personal data will be deleted or anonymized.
7. Protection of Minors' Personal Data
We take the protection of minor's information very seriously. Please be aware that our products and services are only intended for adults over the age of 18, minors under 18 should not use this product. If you accidentally use this product on a minor under 18, please immediately notify us to take reasonable steps to delete the relevant personal data. If we become aware that we have collected personal data from a minor under 18 without the authorization of parent or guardian, we will take reasonable steps to delete it as soon as possible.
8. Your Privacy Rights
8.1 We will strive to safeguard your rights in our personal data processing activities, including but not limited to:
(a) Right of Access
Request access to the personal data we hold about you. Your request should include a detailed and accurate description of the personal data you wish to access.
(b) Right to Rectification
Request to correct data that you believe is inaccurate, incomplete, or misleading. Under the PDPA, we are obligated to ensure that your personal data remains accurate, up-to-date, complete, and not misleading.
(c) Right to Restriction of Processing
Ask us to limit or restrict our use of your personal data according to your legal requirements and specific circumstances.
(d) Right to Data Portability
Ask us to offer the personal data you have provided to us in a structured, commonly used, machine-readable and reasonable format and, where technically feasible, to transfer the data to
other entity. This right only applies to providing us with your personal data with your consent or as a party to the contract.
(e) Withdrawal of Consent
Withdraw your consent to the use of your personal data that you have previously provided to us. If you do so, this will not affect the lawfulness of the personal data we processed before you withdraw your consent.
(f) Right to Erasure
Request us to delete your personal data. Please note that we may not be able to delete all your personal data. In this case, we will clearly tell you the reason and take appropriate measures to protect your personal data and ensure that it will not be used again.
(g) Right to Object
Object to the processing of your personal data for direct marketing purposes or where processing is based on our legitimate interests.
(h) Right to Complaint
If you have any suggestions on our protection of your privacy rights, you can contact us directly to feedback, and you also have the right to complain to the Personal Data Protection Committee (PDPC) or other competent supervisory authorities in Thailand.
8.2 If you wish to exercise your rights, please contact us as specified in the "How to Contact Us" section below. We may ask you to confirm your identity before we process your request.
8.3 Respond to your request
We will respond to your request within a reasonable period, and in any event, within the timeframe prescribed by the PDPA and related regulations of Thailand. If you are not satisfied with our response, you can continue to contact us through the contact information described in this Policy, or lodge a complaint with the PDPC.
9. How to Contact Us
9.1 If you have any questions or suggestions about the content of this Policy, or wish to exercise your rights or have other matters, you can contact Customer Service Center in helpdesk@yuyue.com.cn or contact Data Protection Officer in zhangxiaoyu@yuyue.com.cn by email. You can also write to the following address:
Data Protection Officer
Zhejiang POCTech Co.,Ltd.
No.1633 Hongfeng Road
Building 11 & 12
Huzhou City
Zhejiang
313000
China
9.2 We have appointed a Data Protection Officer (DPO) in accordance with the Thailand PDPA to oversee our personal data protection practices and serve as the point of contact for data subjects and the PDPC.
10. Update the Privacy Policy
Our Privacy Policy may be updated periodically to reflect changes in the way we process personal data, and the updated time will be marked at the beginning of the Privacy Policy. We will not limit your rights under this Policy without your explicit consent. We will use reasonable efforts to prompt you to read the updated Privacy Policy.
If we make material changes to this Policy that affect your rights, we will notify you in advance through the App or by other reasonable means, and obtain your consent where required by the PDPA.