Version:v20260820

Xiaomi's General Privacy Policy

Our General Privacy Policy was updated on 31 July 2026.

Please take a moment to familiarise yourself with our privacy practices and let us know if you have any questions.

Overview

1. Introduction

2. What does personal detail mean?

3. What personal detail do we collect and use for what purposes?

4. How do we share your personal detail?

5. What is the legal basis for processing your personal detail?

6. What are our security safeguards to protect your personal detail?

7. How long will your personal detail be stored?

8. How can you manage your privacy preferences?

9. What are your data protection rights?

10. How to exercise your data protection rights and contact us?

11. How is your personal detail transferred globally?

12. How do we protect minors’ personal detail?

13. Do you have to agree to any third-party terms and conditions?

14. How do we update this Privacy Policy?

1. Introduction

Xiaomi Communications Co., Ltd., along with our global affiliates (collectively, “Xiaomi”, ”we”, “us”, or “our”) regard Privacy as a core value and protecting your privacy is our top priority. Although each Xiaomi product or service may have its own privacy policy, we have summarised some key aspects in this Privacy Policy. This way, you can quickly access the detail in two layers: a simpler version here and a more detailed and specific one by referring to the privacy policy of the product and/or service of your interest.

Please note that the processing of personal detail carried out by Xiaomi may differ depending on the said products and/or services, as well as the features used and the configuration chosen by each user. Please review the privacy statement or supplementary notice applicable to the relevant product or service (the “Product Privacy Notice”). It explains how that product or service processes your personal detail, how to exercise your rights, the identity of the relevant data controller(s), and how to contact them. If there is any conflict, the Product Privacy Notice will prevail for that product or service; otherwise, this Policy will apply.

Ultimately, what we want is what is best for all our users. Should you have any questions about our data processing practices as summarised in this Privacy Policy, please contact us via https://privacy.mi.com/support to address your specific queries. We will be happy to hear from you.

2. What does personal detail mean?

Under this Privacy Policy, "personal detail" means detail that can be used to directly or indirectly identify an individual, either from that detail alone or from that detail combined with other detail about that individual available to Xiaomi, except as otherwise specifically provided by applicable law in your region. It includes detail such as name, contact details, identification numbers, location data or online identifiers (e.g., Xiaomi Account ID). We will use your personal detail in accordance with this Privacy Policy, the applicable Product Privacy Notice, and applicable law.

3. What personal detail do we collect and use for what purposes?

3.1 Collection of personal detail from you

The processing of personal detail carried out by Xiaomi may differ depending on the products and/or services as well as on the features used and the configuration chosen by each user. Therefore, when using our products or services, your personal detail will be processed to provide you with the products and/or services you request.

Though you can find further detail in the applicable Product Privacy Notice of the products and/or services you are using, the main reason why we collect personal detail is to provide you with the products and services of your choosing. The types of personal detail we collect may vary depending on the product or service, the device, the features enabled, and the country or region. Accordingly, not all of the detail listed below is collected in every case.

Depending on the service you choose, we may collect the following types of detail:

3.1.1 Information you provide to us

We may collect any personal detail you provide to us that is necessary to provide the service you choose. Depending on the service, this may include:

  • **Identity & Account Data: **When you create an account or profile with us, we may ask for detail such as your name, nickname, Xiaomi Account ID, date of birth, gender, nationality, profile photo, job, and security-related detail you provide when applicable. In certain jurisdictions, we may ask for your identity proofs issued by local authorities or other detail that can authenticate your identity based on real-name account registration, credit or internet payment, or other applicable requirements.
  • **Contact Data: **If you order a product or paid service from us, we also ask for your email address, mobile phone number, delivery or mailing address, and social media ID. Certain services allow you to communicate and share detail with others. To enable those services, we may process detail such as the phone numbers of senders and recipients.
  • **Financial & Transaction Data: **If you order a product or paid service from us, we also ask for detail such as order detail, invoicing details, bank account number, account holder name, and credit card number.
  • **Communication with Us: **Information you provide when you engage with us, our content, or our marketing or promotional activities (such as voice recordings, message content, call records, email/chat history, materials such as videos and photos submitted by you, user feedback for services or surveys).

3.1.2 Information that we collect during your use of the services

  • Device and Usage Information. Your device information, including connected devices (such as the manufacturer and the model) and software information (such as the operating system and software versions), IMEI/OAID and other unique device ID (such as the serial number(SN), MAC address, IP address, advertising ID (e.g., for mobile devices, GAID and Android ID)), SIM-related information(e.g., IMSI number, SIM card operator and its location area), Space ID, screen display information, device keypad information, device activation time, basic hardware information, sales channel, performance metrics(such as CPU, network, storage, battery usage, screen resolution and device temperature, camera lens model, number of times the screen was woken or unlocked), and settings of the devices you use to access the services.
  • **Mobile Network Information, **such as network operator, connection type, and location detail, including mobile country code, mobile network code, location area code, and cell identity.
  • detail related to Your App Usage, including unique identifiers for an app (e.g., VAID, OAID, AAID, Instance ID) and basic app detail installed on your device, such as the app list, app ID detail, SDK version, system update settings, system and/or app settings (country and region, language, time zone, font), sign-in detail, the time the app enters/exits the foreground, app status records (e.g., downloading, installing, updating, deleting), IP, network status, and detail about how you use and interact with apps, content and services, such as browsing and playback history, search queries, content provider or source detail, content views and exposure, viewing mode and duration, frequency of content or feature interactions, subscriptions, and actions such as likes, ratings, badges, comments, favourites, shares or clicks.
  • Location Information (only for specific services/features): various types of detail on your precise or approximate location if you use location-related services (navigation, weather, Find device, etc.). This detail might include region, country code, city code, mobile network code, mobile country code, cell identity, longitude and latitude data, time zone settings, and language settings. You can restrict individual apps' access to location detail at any time in Settings > Apps > Permissions > Permissions > Location.
  • Log detail: Diagnostic, technical, error and usage detail related to your use of certain features, apps and websites. This might include cookies and other identifier technologies, IP addresses, network request detail, temporary message history, standard system logs, crash detail, and log detail generated through your use of a service (such as registration time, access time, activity time, etc.).
  • **detail Sync with the Cloud: **Materials or data might be synced when you use cloud services for access and sharing, such as photos, videos, notes, contacts, calendars and other user-generated content associated with your Xiaomi Account. We will prohibit our employees and any third parties from directly accessing your personal detail without your consent.
  • Other detail: environmental characteristics value (ECV) (i.e. value generated from Xiaomi Account ID, device ID, connected Wi-Fi ID, and location detail).

You are not required to provide the personal detail we have requested. However, if you choose not to do so, we may not be able to provide you with our products or services or respond to your requests in certain cases.

3.1.3 Detail from third-party sources

When permitted by law, we will collect detail about you from public or legitimate commercial sources. For example:

  • Verification Data for Security and Fraud Prevention: detail (such as your phone number) that we validate through legitimate third-party sources with your authorisation.
  • Advertising Optimization Data: unique identifiers (such as IMEI, OAID, or GAID) obtained from advertisers, and, under certain circumstances, partial conversion performance data (such as clicks) corresponding to your use of advertising services.
  • Third-Party Social Network Account Information: account ID, nickname, profile photo, and email address, when you use a social network account to sign in to a Xiaomi service.
  • Information about You Provided by Other Users: for example, your delivery address that another user may provide to us when they buy products for you via mi.com services.

3.1.4 Non-Personally Identifiable Information

We may also collect other types of detail that are not directly or indirectly linked to an individual and that may not be defined as personal detail under applicable local laws. Such detail is referred to as non-personally identifiable detail. We may collect, use, transfer and disclose non-personally identifiable detail. Here are some examples of the detail we collect and how we may use it in an aggregated, non-personally identifiable format:

  • This detail may include statistical data generated when you use a specific service (e.g. non-identifiable device-related detail, daily usage, page visits, page access duration and session events);
  • Network monitoring data (e.g. request time, number of requests or error requests, etc.);
  • App crash events (e.g. the logs automatically generated after an app crashes).

The purpose of such collection is to improve the services we provide to you. The type and amount of detail collected depend on how you use our products and/or services.

We aggregate this detail to provide you with more useful detail and understand which parts of our websites, products and services you are most interested in. For example, we may need to know the number of users who are active on a given day, but do not need to know who is active on that day, and therefore aggregated data is sufficient for statistical analysis. We will endeavour to isolate your personal detail from non-personally identifiable detail and ensure that the two types of data are used separately. However, if we combine non-personally identifiable detail with personal detail, the combined detail will be treated as personal detail under applicable data protection laws and this Privacy Policy for as long as it remains combined.

3.2 How we use the personal detail that we collect

Depending on the products or services you use, we may process personal detail for one or more of the following purposes:

  • Activating and registering the Xiaomi products or services you purchase for you.

  • Creating and maintaining your Xiaomi Account to provide you with the services you request.

  • Providing, processing, maintaining, improving, and developing our products and/or services to you, such as delivery, activation, verification, notification of system/app updates and installations, after-sales support, customer support.

  • Implementing and maintaining security safeguards to prevent loss and fraud, such as identifying users and verifying user identity.

  • Handling your questions or requests about devices and services, such as answering customer inquiries, sending system and app notifications, and managing your involvement in events and promotions (e.g., sweepstakes).

  • Conducting relevant promotional activities, such as providing marketing and promotional materials and updates. We will conduct such activities based on your consent unless otherwise specified under applicable laws. If you no longer wish to receive certain types of promotional materials, you may withdraw your consent using the method provided in the message (such as the unsubscribe link at the bottom of the message). Please also see section 9 “What are your data protection rights” below.

  • Internal purposes, such as data analysis, research, and development of statistical detail related to the use of our products or services to improve our products or services. For example, machine learning or model algorithm training is performed after de-identification processing.

  • Improving user experience through data, hardware, and software analysis, such as analysing the memory usage or the CPU utilization of your apps. Some opt-in features, such as the User Experience Program, allow Xiaomi to analyse data about how users use their mobile phones, Xiaomi system services and other services provided by Xiaomi to improve the user experience, such as by sending crash reports.

  • Storing and maintaining detail related to you for our business operations (such as business statistics) or for fulfilling our legal obligations.

  • Providing personalised services and content, including advertisements. To protect your privacy, we use a unique identifier rather than your name, email address or other detail that can directly identify you to provide you with personalised products, services and activities, including advertising.

    We may combine this detail with other detail (including detail across different services or devices such as computers, mobile phones, smart TVs and other connected devices) to provide and improve our products, services, content and advertising.

    For example, we may use your Xiaomi Account details across all services you use that require a Xiaomi Account. Furthermore, in order to improve your experience and our services, while complying with relevant laws and regulations and (where required) with your consent, we may sort out detail from different products, services, or equipment from you or related to you to form a label, which will be used to provide suggestions, customised content, and personalised features.

    Personalised ads would, for example, be provided based on your activities, usage and preferences related to our apps and services. We create profiles by analysing the aforementioned detail, building segments (groups with specific shared characteristics) and placing your personal detail in one or more segments. Targeted advertising is carried out only with your consent, where required under applicable laws.

    Based on the reasons for the aforementioned combination and the requirements of applicable laws, we will provide you with specific control mechanisms for such segmentation and personalisation. You have the right to control whether you receive direct marketing from us. In order to exercise these rights, you can turn these features on or off at any time in Settings > Passwords & security > Privacy > Ad services or Settings > Passwords & security > System security > Ad services, or you can contact us via https://privacy.mi.com/support, or refer to the control mechanisms described in the applicable Product Privacy Policy for each product. Please also see section 9 "What are your data protection rights" below.

  • Providing services locally on terminal devices that do not require communication with our servers, such as using Notes on your device when cloud synchronisation is not enabled.

Further detail about how specific products or services process personal detail is available on the relevant settings page or in the applicable Product Privacy Notice. The availability of certain features may vary by country or region. In addition, the features and the way we process personal detail in connection with the same product or service may differ depending on the country or region.

4. How do we share your personal detail?

To provide you with our products and services, we may share your personal detail with the following entities for the purposes described above.

  • **Affiliates: **Other Xiaomi-affiliated companies. We may share personal detail with them only for specific, definite and legitimate purposes, such as advertising measurement, research and development, logistics and order fulfilment, after-sales services, data security, cloud hosting and IT maintenance services.

  • **Business Partners: **Third parties with whom we partner to provide services For example, we may share your detail with the following types of business partners:

    • Content or feature providers (e.g. map service providers for navigation, weather data providers for weather services)
    • Providers of product or technical services (e.g. payment service providers, delivery and logistics providers for order fulfilment)
    • Advertising partners, such as advertising networks, advertising platforms and measurement providers, that help us deliver, measure and improve advertising and related services
    • Third-party developers offering services via our platforms
  • **Service Providers: **Carefully selected companies that provide services for or on our behalf, such as customer care and contact centres, cloud infrastructure and hosting providers, analytics and market research service providers, as well as marketing and communication delivery providers. They are required to process personal detail in accordance with this Privacy Policy and our instructions. They cannot use the personal detail we share with them for their own purposes.

In addition, and to the extent necessary, Xiaomi will disclose the relevant personal detail to competent public authorities, regulators, courts, tribunals or law enforcement agencies where required by applicable law or pursuant to a valid legal process. Where permitted by law, we will assess the validity and scope of the request and disclose only the personal detail reasonably necessary for the relevant lawful purpose.

When necessary and permitted by applicable law, Xiaomi will disclose your personal detail to establish, exercise or defend legal claims, protect our rights, property, assets or services, or prevent fraud and security threats.

We may share your personal detail with our accountants, auditors, lawyers or other external professional advisors where necessary for them to provide professional advice or services. Such advisors are subject to professional or contractual confidentiality obligations.

We may share your personal detail with investors and other relevant third parties in the event of an actual or potential sale of, or other corporate transaction involving, an entity in the Xiaomi Group, subject to appropriate confidentiality and data protection safeguards.

For further detail, as each product or service has its own characteristics, please refer to the applicable Product Privacy Notice for the products and/or services you use.

5. What is the legal basis for processing your personal detail?

We process your personal detail only where we have a valid legal basis under applicable law. Where applicable under the laws of your jurisdiction, the legal bases for processing your personal detail under this Privacy Policy are:

  • To comply with contractual obligations. When you create a profile, register for or access Xiaomi products and services, the purposes of processing your personal detail are primarily determined by the relevant service, and we will process your personal detail to provide that service to you.

    Please note that providing some of your personal detail is mandatory (e.g. when marked as such or with an asterisk). If you do not provide such personal detail, we may not be able to provide you with our products or services.

  • As a result of your consent. With your consent, we may process personal detail that you voluntarily provide when you participate in optional activities, such as promotions.

  • On the basis of Xiaomi's legal obligations. In certain circumstances, we may be required by law to retain or otherwise process your personal detail. In some cases (e.g. storing your personal detail as a result of a dispute or at the request or inquiry of a data protection supervisory authority), processing your personal detail will be necessary for us to fulfil these obligations.

  • Within the scope of a legitimate interest. In certain circumstances, where the processing has a minimal impact on your privacy, we may process your personal detail for the following legitimate interests:

    • Information system security, network security and cybersecurity within Xiaomi.
    • To enhance system security, prevent phishing website fraud, and protect account security.
    • Corporate operations, due diligence and internal audit (in particular, relating to detail security and/or privacy).
    • Product development and enhancement (including the analysis and optimisation of Xiaomi Account settings or features).

    For example, to ensure the security of our services and help us further understand the performance of our apps, we may record relevant detail, such as the frequency of your usage, crash log detail, overall usage, performance data and app source. To prevent unauthorised vendors from unlocking devices, we may collect your Xiaomi Account ID, the serial number and IP address of the computer used for the operation, and the serial number and device detail of your mobile device.

6. What are our security safeguards to protect your personal detail?

6.1 Xiaomi's security safeguards

We are committed to keeping your personal detail secure. To prevent unauthorised access, disclosure or other similar risks, we have put in place all legally required physical, electronic and managerial measures to safeguard and secure the detail we collect from you. We will ensure that we safeguard your personal detail in accordance with applicable law.

For example, when you access your Xiaomi Account, you will use our two-step verification process for enhanced security if your account is at risk. When you send or receive data from your Xiaomi device to or from our servers, we ensure that the data is encrypted using Transport Layer Security ("TLS") and other algorithms.

All your personal detail is stored on secure servers and protected in controlled facilities. We classify your detail based on its importance and sensitivity and ensure that your personal detail receives the required level of security. We have special access controls for cloud-based data storage and regularly review our detail collection, storage and processing practices, including physical security measures, to guard against any unauthorised access or use.

However, you should be aware that using the Internet is not entirely secure, and for this reason, we cannot guarantee the security or integrity of any personal detail transferred to or from you via the Internet.

We conduct due diligence on business partners and third-party service providers to ensure that they are able to protect your personal detail. We also check that these third parties maintain appropriate security standards by putting in place appropriate contractual restrictions and, where necessary, carrying out audits and assessments. In addition, our employees and those of our business partners and third-party service providers who access your personal detail are subject to enforceable contractual confidentiality obligations. We conduct security and privacy protection training courses and assessments to enhance our employees' awareness of the importance of protecting personal detail. We will take all practicable and legally required steps to safeguard your personal detail.

If a personal detail breach occurs, we will comply with the legal requirements under applicable data protection laws, including notifying the relevant data protection supervisory authority and data subjects of the breach where required.

6.2 What you can do

You can set a unique password for Xiaomi services by not disclosing your sign-in password or account detail to anybody (unless such person is duly authorised by you) to avoid password leaks to other websites which may harm your account security at Xiaomi. Whenever possible, please do not disclose the verification code you receive to anyone (including those who claim to be Xiaomi customer service). Whenever you sign in as a Xiaomi Account user on this Platform, particularly on someone else's computer or public Internet terminals, you should always sign out at the end of your session. Xiaomi cannot be held responsible for security lapses caused by third parties accessing your personal detail as a result of your failure to keep your personal detail private. Notwithstanding the foregoing, you should notify us immediately if there is any unauthorised access to or use of your account by any other Internet user or any other security breach. Your assistance will help us protect the privacy of your personal detail.

6.3 Accessing other features on your device

Our applications may access certain features on your device. This detail is used to allow the applications to run on your device and enable you to interact with the applications. At any time you can revoke your permissions by turning them off at the device level or by contacting us at https://privacy.mi.com/support.

7. How long will your personal detail be stored?

As a general rule, we retain personal detail for the period necessary for the purposes described in our privacy policies or as required by applicable law. We will cease to retain and delete or anonymise personal detail once the purpose of collection is fulfilled, after we confirm your request for erasure, or after we terminate the operation of the corresponding services, except when required or permitted by applicable law, in which case your personal detail will be isolated and will not be further processed except for the fulfilment of legal responsibilities and other purposes permitted by applicable law. In such circumstances, your personal detail may be made available exclusively to the parties permitted by applicable law. Once the corresponding retention periods have elapsed, such personal detail will be deleted or anonymised.

8. How can you manage your privacy preferences?

We recognise that privacy concerns differ from person to person. Therefore, we provide examples of ways for you to restrict the collection, use, disclosure or other processing of your personal detail and to control your privacy settings:

  • View and update your account security detail, personal detail, permissions, and device management on your device in Settings > Xiaomi Account, or by signing in to https://account.xiaomi.com;
  • View and update your detail in the account on this Platform in My Account > Edit detail;
  • Update your notification preferences in the account on this Platform in My Account > Notification Preferences;
  • Cancel a service or account. If you wish to cancel your Xiaomi Account, you may do so by following the steps in Settings > Xiaomi Account > Help > Delete Account, or by visiting https://account.xiaomi.com;
  • If you have previously agreed to us using your personal detail for the purposes stated in the relevant privacy policy, including this Privacy Policy and the applicable Product Privacy Notice, you may change your mind at any time by contacting us on https://privacy.mi.com/support.

Please note that cancellation of your Xiaomi Account or profile will prevent you from using the full range of Xiaomi products and related services. To protect your or others' legitimate rights and interests, we will evaluate whether to support your request for cancellation based on your use of various Xiaomi products and services.

9. What are your data protection rights?

You have certain rights in relation to personal detail that we hold about you (referred here as the "request"). Please note that, depending on where you are based, these rights will be subject to specific exclusions and exceptions under applicable local law:

  • Right to access/obtain a report detailing the personal detail we hold about you. A copy of your personal detail processed by us will be provided to you upon your request, free of charge. For any additional requests for relevant detail, we may charge a reasonable fee based on actual administrative costs in accordance with applicable law. In any event, please note that you can log in to Xiaomi Account and/or this Platform to check some of your personal detail we hold about you.
  • Right to correct your personal detail. If any detail we hold about you is incorrect or incomplete, you are entitled to have your personal detail corrected or completed based on the purpose of use. Note that you can also log in to Xiaomi Account and/or this Platform to correct some of your data.
  • Right to erase your personal detail. Based on the requirements of applicable law, you have the right to request the deletion or removal of your personal detail where there is no compelling reason for us to keep using it. We shall consider the grounds for your erasure request and take reasonable steps, including technical measures, to proceed with the erasure of your personal detail. Please note that we may not be able to immediately remove the detail from the backup system due to applicable law (for instance, when necessary to preserve your personal detail for potential claims which may arise out of or in relation to the processing of such personal detail) and/or technology limitations. If this is the case, we will securely store your personal detail and isolate it from any further processing until the detail can be deleted or be made anonymous.
  • Right to object to the processing of your personal detail. You have the right to object, on grounds relating to your situation, to the processing of your personal detail which is based on Xiaomi's legitimate interest or other legal grounds permitted by applicable law. If you object to such processing, we will no longer process your data on these grounds and for these purposes unless we are permitted by applicable law. You also have the right to object to processing for direct marketing at any time under applicable laws, and we will stop such processing.
  • Right to restrict the processing of your personal detail. You have the right to restrict the processing of your personal detail by us, for instance, when the processing is unlawful according to your understanding, but you oppose the erasure of your personal detail. In such cases, your personal detail will only be processed with your consent, for the exercise or defence of legal claims, or for other legal purposes or on other legal grounds permitted by applicable law.
  • Right to data portability. Under some circumstances provided by law, you have the right to receive the personal detail concerning you in a structured, commonly used and machine-readable format and/or transmit that personal detail to another data controller.
  • Right to withdraw consent. In those cases where your consent is required for the processing of your personal detail, you may withdraw such consent at any time. However, please note that if you withdraw your consent, you may not be able to continue to use this Platform and its related services, and/or access certain detail or features. The withdrawal of your consent or authorisation will not affect the validity of our collection and processing carried out on the basis of the consent up until the point of withdrawal.
  • Other rights under applicable law.

Please remember that you may also access, update, and delete some details relating to certain personal detail in your account of this Platform, in your Xiaomi Account at https://account.xiaomi.com or by signing into your Xiaomi Account on your device. For additional detail, please write to us or contact us via https://privacy.mi.com/support.

10. How to exercise your data protection rights and contact us?

If you have any comments or questions about this Privacy Policy or any questions relating to Xiaomi's collection, use or disclosure of your personal detail, or you want to exercise your data protection rights according to the above Section, feel free to contact us by visiting https://privacy.mi.com/support or at the below addresses (your request should be made in writing). When we receive questions about personal detail or requests to download or access items, we have a professional team that addresses such concerns, including Data Protection Officers (DPOs), who can be contacted through https://privacy.mi.com/support, or in the below postal addresses. If your question itself involves a significant issue, we may ask you for more detail. If you consult us, we will provide detail on the relevant complaint channels that may be applicable based on your actual situation.

  • For users located in the European Economic Area (EEA), the UK and Switzerland(CH):

Xiaomi Technology Netherlands B.V., Prinses Margrietplantsoen 39, 2595 AM, The Hague, The Netherlands

  • For users located in India:

Xiaomi Technology India Private Limited, Building Orchid, Block E, Embassy Tech Village, Outer Ring Road, Devarabisanahalli, Bengaluru, Karnataka - 560103, India

Any discrepancies and grievances with respect to processing of sensitive personal detail or detail shall be informed to the designated Grievance Officer as mentioned below:

Name: Vishwanath C

Telephone: 080 6885 6286, Mon-Sat 9 AM to 6 PM

Email: grievance.officer@xiaomi.com

  • For users located in other countries/territories:

Xiaomi Technologies Singapore Pte. Ltd. 1 Fusionopolis Link #04-02/03 Nexus@one-north, Singapore 138542

Please, make sure that you provide sufficient detail to enable Xiaomi to verify your identity and ensure that you are the data subject or legally authorised to act on the data subject's behalf. Once we obtain sufficient detail to confirm that your request can be processed, we shall proceed to respond to your request within any timeframe set out under your applicable data protection law.

We have the right to refuse to process requests that are not meaningful, manifestly unfounded or excessive, requests that damage others' right to privacy, extremely unrealistic requests, and requests that require disproportionate technical work, as well as requests not required under local law, regarding detail that has been made public, and regarding detail given under confidential conditions. If we believe that certain aspects of the request to delete or access the detail may result in our inability to legally use the detail for the aforementioned anti-fraud and security purposes, the request may also be rejected. We will inform you of any such decision not to process your request and the grounds of this decision if required by applicable law, in the event of which we will inform you within any timeframe set out under applicable law.

If you are not satisfied with the response you received, you can escalate the concern to the relevant regulatory authority in your jurisdiction.

11. How is your personal detail transferred globally?

Xiaomi processes and backs up personal detail through a global operating and control infrastructure. The Xiaomi entity that controls your personal detail may differ depending on your place of residence and specific product or service you use. Where relevant, more details will be provided in the applicable Product Privacy Notice.

Your use of our services may involve the transfer, storage, and processing of your personal detail within and outside of your country of residence where necessary to realize the purposes described in this Privacy Policy, the applicable Product Privacy Notice and applicable law. Xiaomi uses regional data hosting infrastructure located in India, the Netherlands, Russia, and Singapore, to support our products and services offered outside the Chinese Mainland.

The hosting location is determined by the region in which the relevant services are provided. In particular:

  • The personal detail we collect and generate in our operations in Russia is stored in data centres located in Russia.
  • The personal detail we collect and generate in operations in India is stored in data centres located in India.
  • The personal detail we collect and generate in operations in EEA/UK/CH is stored in data centres located in the Netherlands.
  • The personal detail we collect and generate in operations in areas other than the aforementioned regions is stored in data centres located in Singapore.
  • Xiaomi also transfers personal detail to affiliated companies, third-party service providers and business partners located outside the region in which the detail is hosted, for the purposes described in this Privacy Policy and the applicable Product Privacy Notice.
  • When Xiaomi transfers personal detail outside the region in which it is hosted, whether to affiliated companies or third-party service providers or business partners, we comply with the applicable data protection laws. We ensure that all such transfers are subject to the applicable legal transfer mechanism and appropriate technical and organisational measures, such as pseudonymisation, encryption, access controls and regular security assessments, to protect your detail during transmission and throughout its subsequent processing. You can obtain further detail about the safeguards applicable to your personal detail by contacting us at https://privacy.mi.com/support.

12. How do we protect minors’ personal detail?

We are committed to protecting the personal detail of minors. Parents and guardians are encouraged to guide and supervise their use of our products and services, and we will process minors’ personal detail and provide appropriate safeguards in accordance with applicable laws.

If you are a parent or guardian and you believe that a minor has provided Xiaomi with personal detail without appropriate authorisation, please contact us via https://privacy.mi.com/support. We will review the matter and take appropriate steps, including deleting the detail where required by applicable law.

13. Do you have to agree to any third-party terms and conditions?

Our Privacy Policy does not apply to products or services offered by a third party. Depending on the services you use, some of our products and services may incorporate third parties' products or services such as payment processing services. Some of these will be provided in the form of links to third parties' websites, and some will be accessed in the form of SDKs, APIs, etc. Your detail may also be collected by these third parties when you use these products or services. For this reason, we strongly suggest that you take the time to read the third party's privacy policy. This Privacy Policy does not apply to personal detail processed independently by those third parties. We are not responsible for and cannot control how third parties use personal detail which they collect from you.

14. How Do We Update This Privacy Policy?

We review this Privacy Policy periodically based on changes in our business, technology and applicable law and good practice, and we may update this Privacy Policy. If we make a material change to this Privacy Policy, we will notify you through a pop-up window, by email to the email address corresponding to your Xiaomi Account, or through other lawful and available means, so that you can learn about the detail we collect and how we use it. Such changes to this Privacy Policy will apply from the effective date specified in the above notice. We encourage you to check this page regularly for the latest detail on our privacy practices. Where required by applicable law, we will ask for your explicit consent when we collect additional personal detail from you or when we use or disclose your personal detail for new purposes.

Addendum for the European Economic Area, the United Kingdom and Switzerland (EEA/UK/CH)

This Addendum supplements Xiaomi General Privacy Policy (the “Privacy Policy”) and applies to you if you reside in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland (“CH”). It provides additional detail required under applicable data protection laws. This Addendum prevails over the Privacy Policy, which otherwise applies to matters not addressed herein.

Controllers

If you reside in the EEA, UK, or Switzerland, Xiaomi Technology Netherlands B.V. and Xiaomi Communications Co., Ltd. will act as joint data controllers for the processing activities for which they jointly determine the purposes and essential means. Your personal detail may also be remotely accessed from the Chinese Mainland through limited and secure access channels, and solely to the extent necessary for specific purposes, such as case-specific technical troubleshooting and after-sales service requests handling.

For you in the UK, our UK representative is:

Xiaomi Technology UK Limited, with registered address in Us & Co Stratford, Floor BR 40-11-12-13-14 11 Burford Road London, England E15 2ST

For you in Switzerland, our Swiss representative is:

Xiaomi Technology Switzerland GmbH, with registered address in Thurgauerstrasse 101, 8152 Glattpark (Opfikon).

Legal Bases for Processing

We process your personal detail only where we have a valid legal basis. The table below sets out the purposes for which we process your personal detail, the corresponding legal basis, and, where we rely on legitimate interests, the specific interests pursued.

International Data Transfers

To support our operations in EEA/UK/CH:

  • Certain companies within our corporate group may support our operations in the EEA, UK and Switzerland. Xiaomi Technologies Singapore Pte. Ltd. acts as an intragroup processor and processes personal detail on behalf of and under the instructions of the relevant controller. It provides various support services, such as server and infrastructure maintenance and technical support. Such transfers are only granted where necessary under strict internal authorisation and access control protocols.
  • We transfer your personal detail to third-party service providers and business partners located outside the EEA/UK/CH to enable the services described in this Privacy Policy or applicable Product Privacy Notice. Due to differences among our products and services, the specific details of these transfers (including recipients, countries, and legal mechanisms) vary.

When we transfer personal detail from the EEA/UK/CH to countries outside the EEA/UK/CH, we rely on the following legal mechanisms, as appropriate:

  • Adequacy Decisions: The European Commission, the UK Government, and the Swiss Federal Council have each recognised certain countries as providing an adequate level of data protection. For some products or services, we may transfer data to certain third-party service providers or business partners in such countries based on these decisions. Please refer to the applicable Product Privacy Notice for details.
  • Standard Contractual Clauses (SCCs): Where no adequacy decision exists, we generally rely on the European Commission’s approved standard contractual clauses as the primary safeguard. These (and their approved equivalent for the UK and CH) are used for transfers and limited remote access to our group entities outside the EEA/UK/CH, with which we have entered into SCCs. These entities are located in Singapore and the Chinese Mainland. Transfers to the Chinese Mainland involve limited, secure remote access only. SCCs are also used for transfers to certain third-party service providers or business partners; where this is the case, it will be noted in the applicable Product Privacy Notice. For all transfers based on contractual safeguards, we assess the laws and practices of the destination country and implement supplementary measures where required—including pseudonymisation, encryption, fine-grained access control, and continuous monitoring—to ensure an adequate level of protection.

You can obtain more detail about the relevant safeguards, including a copy of the SCCs, by contacting our Data Protection Officer at https://privacy.mi.com/support.

Complaints

You have the right to lodge a complaint with your local data protection supervisory authority. You can find a list of EEA authorities here. In the UK, you can complain to the Information Commissioner's Office (ICO); in Switzerland, to the Federal Data Protection and Information Commissioner (FDPIC). You can also raise your concerns directly with our data protection team at https://privacy.mi.com/support or reach out to our Data Protection Officer using the details provided below.

Contact Us

If you have questions about this Addendum or wish to exercise your rights, you can reach us and our DPO at:

  • Online: https://privacy.mi.com/support
  • Postal address: Prinses Margrietplantsoen 39, 2595 AM, The Hague, The Netherlands