← Back to TUYA filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
4.A.History and Development of the Company
We commenced our operations in June 2014 through Hangzhou Tuya Technology Co., Ltd., or Hangzhou Tuya Technology.
In August 2014, Tuya, Inc., our current ultimate holding company, was incorporated under the laws of the Cayman Islands.
In September 2014, Tuya (HK) Limited, currently a wholly owned subsidiary of Tuya Inc., was incorporated under the laws of Hong Kong.
In December 2014, Hangzhou Tuya Information Technology Co., Ltd. (formerly known as Hangzhou Aixiangji Technology Co., Ltd.) (“Tuya Information”) was incorporated in the PRC. Tuya Information is currently a wholly owned subsidiary of Tuya (HK) Limited.
In June 2018, we effected a 10-for-1 share subdivision, following which each of our issued and unissued ordinary shares and preferred shares was subdivided into 10 ordinary shares and preferred shares, respectively.
In March 2021, our ADSs commenced trading on the NYSE under the symbol “TUYA.” We raised, from our initial public offering and from the underwriters’ exercise of option to purchase additional ADSs, approximately US$904.7 million in net proceeds after deducting underwriting commissions and the offering expenses paid by us.
On July 5, 2022, Hong Kong time, our Class A ordinary shares commenced trading on the Main Board of the Hong Kong Stock Exchange under the stock code “2391.” We raised from our global offering in connection with the listing in Hong Kong approximately HK$70.0 million in net proceeds after deducting underwriting commissions, fees and the offering expenses.
We are subject to the periodic reporting and other informational requirements of the Exchange Act as applicable to foreign private issuers. Under the Exchange Act, we are required to file reports and other information with the SEC. Specifically, we are required to file annually a Form 20-F within four months after the end of each fiscal year. The SEC also maintains a website at www.sec.gov that contains reports, proxy and information statements, and other information regarding registrants that make electronic filings with the SEC using its EDGAR system. Such information can also be found on the Company’s investor relations website at https://ir.tuya.com.
70
Table of Contents
4.B.Business Overview
A REVIEW OF 2025
In 2025, we continued to improve our operating performance and advance the execution of our AI-related initiatives, while also returning capital to shareholders through cash dividends. During the year, we achieved revenue growth and further improved profitability and operating efficiency. Our non-GAAP operating income reached a record level, and we remained profitable on a GAAP basis, primarily due to increased operating leverage, continued expense discipline and a decrease in share-based compensation.
In 2025, we continued to integrate our Spatial LLM and On-Device AI capabilities into our platform and expanded into additional product categories, including AI-powered toys. We believe these efforts enhanced the functionality of our offerings and supported broader engagement across our ecosystem, including our registered AI developer community. We also continued to declare and pay cash dividends during the year, reflecting our capital allocation approach and confidence in our business and financial position.
Business review
In 2025, our total revenue reached about US$321.8 million, a 7.8% year-over-year growth. Our overall gross margin remained stable at around 48.2%, while annual operating expenses declined by approximately 24.1% year-over-year due to continued cost discipline of the company. For the year, our non-GAAP profit from operations reached US$33.7 million, with a non-GAAP operating margin of 10.5%, validating the effectiveness and scalability of Tuya’s unique software-and-hardware integrated business model. Our non-GAAP net profit in 2025 reached US$80.1 million, with a year-over-year growth of around 6.4%. Additionally, we achieved net profit of US$57.9 million on GAAP basis, with a year-over-year growth of over ten times. This achievement enhances our flexibility at the statutory shareholders’ equity level and enables us to pursue further strategic initiatives for long-term growth.
On the cash flow side, we generated around US$81.0 million in positive operating cash flow in 2025. Following the dividend declared in February and in August, both of which have been fully paid, we ended the year with a net cash balance exceeding US$1,017.3 million, maintaining a strong liquidity position.
For PaaS business, we witnessed a more diversified and dynamic developer base, contributing to solid year-over-year growth across all categories. Our product category structure has become increasingly balanced and diversified, aligning with the trend of customers expanding their product lines. In a highly fragmented and dispersed global consumer electronics market, the widespread adoption of technology continues to drive innovations across diverse product categories. The increasing variety of smart devices is fostering a more comprehensive approach to Spatial Intelligence, enhancing user convenience and comfort, ultimately progressing toward the vision of an interconnected and interactable intelligent ecosystem.
Our Smart Solution business continued to gain traction, particularly among top-tier customers, achieving approximately 8.9% year-over-year growth in 2025. For instance, in response to the French government’s energy subsidy initiative, we supported our French customers in becoming among the first to meet the national energy efficiency subsidy standards, helping households lower energy consumption. At this stage of smart technology development, whether in consumer electronics or industry-specific applications, a rich ecosystem of smart devices is essential for top-tier customers. In this regard, Tuya possesses a significant advantage over the market with its expansive developer ecosystem, and Smart Solution further enhances our ability to support customers, strengthen engagement, and boost their market competitiveness.
We remain committed to building a robust developer ecosystem. As of the end of 2025, the number of registered developers on our platform reached around 1.8 million, with over 1.2 million SKUs of smart devices developed on Tuya’s platform, spanning more than 3,200 product categories. We continue to foster an extensive ecosystem by, for example, integrating with Google Home APIs to create a seamless smart home experience and collaborating with Chery to establish a new “vehicle-home interconnectivity” ecosystem. At the same time, we are dedicated to expanding Tuya’s global influence, positioning ourselves as a reliable partner for customers and developers worldwide. Our HEMS solution was recognized in the United Nations Global Compact (UNGC) report, “20 Best Corporate Sustainability Practices in 20 Years,” highlighting Tuya’s commitment to sustainability. Additionally, we achieved a Wind ESG rating of “A,” and we were included in the S&P Sustainability Yearbook China Edition.
71
Table of Contents
Development of device and edge AI
AI Agent Development Platform
We launched our Tuya AI Agent development platform in 2024 and continuously invested and upgraded such platform, further enhancing the capabilities in AI hardware development. Adopting an LLM-agnostic architecture, the platform currently supports seamless integration with various leading large language models (LLMs), including ChatGPT, Qwen, DeepSeek, Doubao, Mistral’s Le Chat, Gemini, Amazon Nova, and Claude, among others.
By building a middleware layer that connects foundational model capabilities with device functionalities, the platform significantly lowers the technical barriers for developers to build AI devices and applications. Developers are empowered to flexibly select the most appropriate models based on their business requirements and accelerate product development using the templates, capability components, and scalable frameworks provided by the platform.
At the platform capability level, we further introduced a workflow orchestration mechanism and a skills framework. Developers can visually orchestrate the task workflows of AI Agents, combining perception, reasoning, device control, and service capabilities. Simultaneously, frequently used capabilities can be encapsulated into reusable skillsets, thereby enabling the construction of more flexible and scalable AI applications. Furthermore, we introduced an AI autonomous workflow planning capability, allowing AI Agents to automatically plan multi-step task workflows based on user objectives. This further elevates the autonomous decision-making capabilities of smart devices in complex scenarios.
● Multimodal AI Interaction. To elevate the interactive experience between AI and devices, we introduced multimodal AI interaction capabilities to the platform. This enables devices to understand and process various input formats, such as voice, images, video, and text, and generate corresponding multimodal outputs. This capability allows smart devices to understand user needs and environmental states more naturally. For instance, in scenarios like family companionship, pet interaction, and home management, devices can conduct comprehensive analyses using multimodal information to provide smarter and more personalized service experiences.
● Long-Term Memory and Emotional Intelligence. Tailored for long-term interaction and companion device scenarios, we built a genuine long-term memory capability within the platform that simulates human memory mechanisms. Our system simulates the human process of memory formation and updating through memory extraction, user persona knowledge graphs, dynamic confidence evaluation, and forgetting mechanisms. This enables AI Agents to gradually develop a more stable and personalized understanding of users over long-term interactions.
Concurrently, we integrated emotional recognition capabilities into the platform, allowing AI to identify emotional changes in user speech or behavior. This facilitates a more natural and emotionally resonant interactive experience in companionship, education, and other interactive scenarios.
AI Hardware Developer Components
To lower the barriers to AI hardware development, we launched a comprehensive suite of AI hardware panel components for developers. Developers can directly invoke various AI capabilities in a modular fashion, eliminating the need for complex development from the ground up.
These components encompass functional modules such as voice cloning, character customization, dialogue record organization, memory management, voiceprint recognition, and emotional recognition. They empower developers to rapidly build AI-capable hardware products and interactive interfaces.
Through these modular components, developers can complete the functional design and user experience construction of AI hardware products in a significantly shorter timeframe, drastically reducing the complexity of AI product development.
72
Table of Contents
AI Coding for Hardware Development
To further reduce the threshold for AI hardware development, we introduced the AI Coding development panel. Developers can describe their requirements using natural language, and the AI will automatically generate the relevant functional code and device logic.
This capability currently supports multiple categories, including AI hardware devices, electrical, and lighting equipment. It enables developers to complete device functional development and product prototyping much faster, thereby significantly boosting development efficiency and shortening the product development cycle.
OVERVIEW
We are a global leading AI cloud platform service provider with a mission to build an AIoT developer ecosystem and enable everything to be smart. We have pioneered a purpose-built AI cloud developer platform that delivers a full suite of offerings, including Platform-as-a-Service (“PaaS”), Software-as-a-Service (“SaaS”) and Smart Solutions to developers of smart device, commercial applications, and industries. Through our AI cloud developer platform, we have activated a vibrant global developer community of brands, OEMs, AI agents, system integrators and independent software vendors to collectively strive for smart solutions ecosystem embodying the principles of green and low-carbon, security, high efficiency, agility, and openness. We are the largest third-party AI cloud platform offering PaaS in the global market of PaaS in terms of the volume of smart devices powered in 2025, according to CIC.
73
Table of Contents
We deliver a variety of offerings. Our PaaS offering enables businesses, including original equipment manufacturers (“OEMs”) and brands, and developers to develop, launch, manage and monetize software-enabled smart devices and services. Our SaaS offering for those who use smart devices includes industry SaaS that enables businesses to deploy, connect, and manage large numbers and different types of smart devices in different vertical scenarios for spatial intelligence, cloud-based software value-added services that provide end users with additional smart scenario features such as cloud storage, AI audio and video interaction, and Cube Smart Private Cloud Solution that enables large-scale conglomerates to build their own autonomous and controllable smart business platforms. We also offer businesses, developers and end users a diverse range of other cloud-based value-added services to improve their ability to develop and manage IoT experiences. Additionally, we offer smart solutions for smart devices in which we provide customers with smart devices that integrated AI and intelligent software capabilities beyond IoT.
Our business model is both unique and innovative. First, we offer technology, products, and services to enterprises, positioning us as a typical enterprise service business. Second, we focus on the smart device sector, and the products we provide are essential components of our customers’ own businesses and products. Our goal is to empower customers—helping them build their own smart products and achieve success in their respective downstream end market. As a result, majority of our revenue reflects the cyclical nature of smart devices and follows the dynamics of the hardware supply chain. Lastly, like a brain for smart devices, our platform provides an “one-platform-all-smart” unified user experience, enabling end users to fully benefit from smart scenarios through a connected device ecosystem with an agnostic system—regardless of the underlying cloud service, IaaS provider, communication protocol, chip, or LLM, etc. These features collectively contribute to the network effects typical of internet-based business models, and together, they form our core competitive advantages and barriers to entry.
74
Table of Contents
Our platform benefits from network effects driven by our ecosystem of developers, businesses, partners and end users. End users of smart devices demand a unified user experience to interact with various types of devices from different brands through one portal, such as a single interface—only achievable when all devices have the same “brain.” This is akin to using different apps on one smartphone. Our platform provides an open architecture to connect any device from any brand, while enabling users to manage all devices across brands through a single portal. As a result, we believe that as our platform continues to grow, more brands and OEMs want to join our platform to integrate their devices onto the single user interface using the same “brain”, through which devices from other brands are connected. These self-reinforcing network effects further increase our brand awareness and generate word-of-mouth referrals, helping us build an extensive, vibrant and increasingly interconnected AIoT ecosystem.
Our offerings enable customers across a broad range of industry verticals, such as smart home, smart business, renewable energy, education, agriculture, outdoors and sport, and entertainment. We have cultivated a large and diversified customer base, primarily including brands, OEMs, industry operators and system integrators. Starting from the end of 2021, we have been strategically optimizing our customer base to focus more on key account enterprises. In 2025, we served approximately 5,900 customers and our AI cloud platform empowered approximately 3,800 brands to develop their smart devices, including leading brands and enterprises such as Calex, Philips, Schneider Electric, Sharp, ABB, SCG, Panasonic, Changhong, TCL, Midea, etc. Our PaaS currently enables businesses and developers across over 200 countries and regions globally to develop smart devices in approximately 3,200 categories. We have established a large and active community of over 1.8 million registered AIoT device and software developers as of December 31, 2025.
In the past, our business has scaled rapidly by leveraging our strong software and robust platform-based delivery capabilities. However, prior to the second half of 2023, the global consumer electronics industry went through a headwind cycle, primarily due to global high inflation and supply-chain-wide destocking. Thanks to industry-wide efforts and moderately declining inflation, the downstream inventory level gradually returned to normal in the second half of 2023.
75
Table of Contents
Throughout 2025, despite a complex and evolving operating environment, the industry sustained its growth trajectory, supported by normalized inventory levels and a strategic focus on high-value intelligent solutions. We believe the accelerated adoption of generative AI and LLMs in 2025 has moved beyond conceptual stages into deep, scenario-based integration, significantly increasing the penetration of smart devices and applications across both consumer and industrial sectors. With the effective execution of our customer and product strategies, coupled with the utilization and innovation of emerging technologies, our revenue increased by 7.8% to US$321.8 million in 2025 from US$298.6 million in 2024. Our net profit increased from US$5.0 million in 2024 to US$57.9 million in 2025. See “Item 5. Operating and Financial Review and Prospects—5.A. Operating Results—Discussion of Results of Operations.”
Challenges in the AIoT Era
By transforming the way people interact with the physical world, IoT and AI is also changing how brands and OEMs develop products and operate their business. With favorable technology drivers, consumers are increasingly demanding a software-like experience—in addition to the traditional physical interfaces—when interacting with devices, and are showing growing interest and high expectations for AI. As a result, brands and OEMs are seeking to build software capabilities in order to offer AIoT-enabled smart devices.
However, for brands and OEMs, building software and AI capabilities from scratch is both costly and time-consuming, causing many of their AIoT ventures to be unsuccessful. While a limited number of leading brands have built their own AIoT solutions, these solutions often are restricted to their own products, or products of their selected business partners, and the vast majority of brands and OEMs globally simply do not have the capital and technology expertise necessary to develop and deploy software across millions of devices, according to CIC. Brands, OEMs and developers face a number of challenges in delivering software-enabled AIoT offerings, such as (i) lack of development talent and capabilities, (ii) high cost and complexity to develop platforms, tools and applications, (iii) long development cycles, (iv) lack of standardized, easy-to-use software infrastructure and tools for developers and (v) inconsistent user experience caused by the fragmented market due to the variety of smart device categories and products across the brands and regions, which hinders the long-term potential of AIoT applications. These significant challenges can affect the end user experience and create the need for a third-party AI cloud platform that takes care of the complexities of developing, launching, supporting and growing AIoT software and unifying the IoT standards among fragmentation, so businesses and developers can leverage full-stack infrastructure and tools to develop devices and software applications with ease and cost-efficiency.
76
Table of Contents
Tuya Solution—an AI Cloud Platform for Global Developers
We offer what we call an “AI cloud platform”—a platform that is open to all types of brands, OEMs and developers from across the world where they can access a common infrastructure and all the ready-to-use software, development tools and services needed to develop and manage smart devices with AI capabilities. According to CIC, we offered the world’s first IoT cloud development platform, giving us significant first-mover advantages in attracting and building long-term relationships with brands and OEMs globally.
Our platform is a one-stop AI cloud platform with an agnostic system across diverse cloud services, IaaS, device categories, edge capabilities and hardware architectures. It allows our brands and OEMs to digitalize their businesses and transform the experience of their end users across a diverse range of use cases.
We use “AI cloud platform” as a collective term to refer to a combination of the various IoT capabilities, AI capabilities, products and services that we offer to brands, OEMs, developers, partners and end users. As illustrated in the diagram below, our AI cloud platform encompasses the various AI and IoT developer kits and cloud infrastructure capabilities, and our products and services are built upon such capabilities. For more information, see “—Our Technologies.” Through our platform we have established an ecosystem of brands, OEMs, developers, partners and end users.
Based upon our Tuya AI cloud platform, we offer the following major cloud-based products and services:
● PaaS. PaaS provides brands and OEMs with a common software infrastructure and ready-to-use software and development tools that they need to develop, manage and upgrade smart devices. PaaS combines cloud-based connectivity and basic IoT services, edge capabilities, app development and device optimization solutions, which we believe are the most fundamental elements of enabling a product with IoT. Our platform allows customers to simultaneously work with multiple public cloud solutions, such as Amazon Web Services, Microsoft Azure, Alibaba Cloud and Tencent Cloud, as well as their private cloud infrastructures, with the flexibility to switch among them if needed. Our PaaS transforms traditional products into IoT-enabled products with computing, storage and networking capabilities on the “edge,” laying the foundation for a low code or no code development environment. We also provide a suite of developer tools and cloud-based services for customers to personalize or develop IoT applications that connect to our AI cloud platform and manage their smart devices for a variety of use cases. In addition, we are integrating more AI capabilities into our platform and offering them to developers in the form of PaaS, enabling more intelligent and versatile application development.
77
Table of Contents
● SaaS. We offer industry SaaS, vertical-focused software solutions for spatial intelligence in different industry verticals. Businesses, such as hotel operators or property managers, leverage our SaaS solutions to intelligently manage their operations based on connected smart devices, thereby creating more smart scenes, improving user experiences and operating efficiency or optimizing costs by conducting better energy management. We also offer cloud-based software value-added services to business customers or end users that provide additional smart scenario features such as cloud storage, AI audio and video interaction. Our SaaS offerings are fully integrated with our IoT cloud infrastructure, device management apps and user apps, for customers to use in a plug-and-play manner. In addition, we will be continuously enriching our SaaS portfolio with more AI-powered services—such as energy management strategies, AI-driven interactive content—to further enhance the value and user experience for end users.
OUR PRODUCTS AND SERVICES
We offer our products and services to all key AIoT stakeholders. We set out to offer PaaS to customers developing smart devices, including brands and their contracted OEMs. Over time, we have extended our offerings to those who use smart devices. We offer SaaS including industry SaaS that enables businesses to deploy, connect, and manage large numbers and different types of smart devices in different vertical scenarios for spatial intelligence, cloud-based software value-added services that provide end users with additional smart scenario features, such as cloud storage, AI audio and video interaction, and Cube Smart Private Cloud Solution that enables large-scale enterprise customers to build their own autonomous and controllable smart business platforms. We also offer businesses, developers and end users a diverse range of other cloud-based value-added services to improve their ability to develop and manage IoT experiences. Additionally, we offer Smart Solution for smart devices in which we provide customers with smart devices that integrated AI and intelligent software capabilities beyond IoT.
For Business Customers Developing Smart Devices
PaaS
Our PaaS is an integrated, all-in-one product for brands and OEMs to build and manage smart devices.
Our PaaS combines cloud-based connectivity and basic IoT services, edge capabilities, app development, and device optimization solutions which we believe are the most fundamental elements of IoT capabilities. Customers can also leverage our developer toolkits, including SDKs and open APIs, to customize for desired use cases and functionalities.
● Cloud-based connectivity and basic IoT services. Our AI cloud platform assigns a unique virtual ID to each device powered by Tuya and pairs it with a “digital twin.” A digital twin enables real-time, closed-loop interactions between the cloud and the physical smart device throughout its life cycle. As the status of the device changes, the digital twin synchronizes with it and “closes the loop” by interacting with the device to enable different functions and use cases.
78
Table of Contents
Digital twin and the cloud-based connectivity it enables offer many features hard to imagine in the pre-IoT era, such as using a smartphone to control multiple devices remotely and predicting failure based on patterns learned from vast amounts of IoT data. It also brings convenience and safety to end users. For example, when smoke is detected while nobody is at home, it automatically turns off the gas and sends alerts. End users also benefit from basic IoT services such as automatic device scene switches based on real-time weather data obtained by the cloud through the internet. Digital twin also makes troubleshooting easier and less costly by providing developers with a virtual test environment to troubleshoot problems without making any changes to the physical device.
Our PaaS offers developers, many of whom work for brands and OEMs, a portal through which they can access a variety of software and development tools, as illustrated in the screenshots below.
● IoT edge capabilities. To become “smart,” a device must have key capabilities such as connectivity, storage and data processing, which we call “edge” capabilities, embedded in modules installed on the device. Our PaaS offers a library of edge capabilities for customers to choose from, as well as visualized, simple tools and dashboards for them to quickly find what they need. Our PaaS currently supports all mainstream wireless technologies, including Wi-Fi, Bluetooth, ZigBee, Thread, Matter and other IoT edge capabilities.
The below screenshot illustrates the interface through which developers can leverage PaaS to embed edge capabilities.
79
Table of Contents
The edge capabilities we offer are all pre-coded and ready-to-use, giving customers shorter time-to-market than writing the codes from scratch.
● App development. An easy-to-use app is key to a superior AIoT experience. We offer “white label” apps with minimal modification required to give customers the shortest time-to-market. This “one-app-for-all” approach enables end users to manage multiple devices, even those from different brands and categories, using one app only. Our customers may choose to engage us to design tailor-made apps or, in many more cases, customize the apps themselves or through third-party developers with development tools that we offer.
The below screenshot showcases our “one-app-for-all” approach that enables end users to manage various functions and different categories of devices using a single app, as well as our “Smart Scene” functions, which allow users to configure and manage present scenes and recommend smart scenes according to connected devices and user behaviors.
80
Table of Contents
● AI Capabilities: AI agents are at the core of AI device, as they define the AI capabilities such device can deliver—such as interacting with devices through natural conversation, performing multimodal data analysis and processing, and executing AI control strategies. We are integrating these AI capabilities into our platform and offering them to developers in the form of PaaS, in order to support their needs in developing AI device and promote penetration of smart devices and scenarios, enabling more intelligent and versatile application development.
● Device optimization solutions. Even equipped with the edge capabilities, sometimes a device may not function well if the hardware is incompatible with the software. We bridge this gap for customers by helping them optimize the design, manufacturing and configuration of Tuya-powered devices to ensure that the hardware and software integrate to deliver the desired use cases and functionality. We also provide developers with a suite of analytics and debugging tools to help them independently identify root causes and troubleshoot problems.
Our PaaS also includes the following ancillary business related or technical related value-added services:
● Tuya Mall. It refers to the services that we offer to customers to help them build their own online marketplace to sell and distribute smart devices.
● Ecosystem partnership with virtual assistant providers. We enable our customers to add voice control powered by Amazon’s Alexa, Google Assistant and Samsung SmartThings and other voice-based capabilities to their devices.
● Others. In addition, we provide approximately dozens of ancillary value-added services, such as app function expansion service, device testing, “Work with Alexa” certification, “ZigBee Alliance” certification, and joint research and development of innovative smart applications, among other things. We also enable our customers to process and leverage device-level and app-level information to generate business insights to help improve their businesses.
Our PaaS offers an all-agnostic development environment across diverse cloud services, IaaS, device categories, edge capabilities and hardware architectures, allowing customers to simultaneously work with multiple public or private cloud infrastructure and with the flexibility to switch among them if needed, develop their product portfolios with different communication protocols and IoT chips, and leverage the differentiated capabilities and advantages of various LLMs to better suite their smart devices. This flexibility is valued by customers because it enables them to scale up their product portfolios as well as to cater to the broadest user bases across global markets, as different brands may have different preferences over cloud infrastructures, chips, and LLMs, etc., from commercial or compliance perspectives. In addition, according to CIC, we are the world’s first IoT cloud development platform at scale that is cloud-agnostic.
The following flow chart illustrates how we connect and empower key stakeholders surrounding our PaaS, i.e., chip vendors, brands (including retailers offering private-label smart devices) and their contracted OEMs, distribution channels, as well as end users. For more information about the value-added services we provide directly to end users, see “—For Business Customers and End Users Using Smart Devices.”
81
Table of Contents
Smart Solution
In 2023, we upgraded our product strategy to further enhance our software-and-hardware integrated business model by expanding beyond PaaS into a more comprehensive hardware solution model. This strategic shift aims to provide developers and customers not only with advanced software capabilities, but also with competitive, ready-to-deploy smart hardware solutions. Under this strategy, we offer smart solutions for smart devices, which target selected sophisticated and high-value potential smart device categories, to our customers such as brands and telecom operators in the form of delivering finished smart devices that integrated AI and intelligent software capabilities beyond IoT. As this business has grown to represent a larger share of our overall smart device business, we officially renamed the business line from Smart Device Distribution to Smart Solution starting in 2024. Our Smart Solutions cover both our core smart home offerings and a broader range of commercial verticals—including hospitality, real estate, mobility, and renewable energy. In 2025, we continued to scale this business by targeting high-value product categories such as AI-powered emotional companionship products and residential energy management.
Our Smart Solution enables these customers to benefit from smart devices with more self-developed, integrated AI and smart software capabilities beyond IoT. These include advanced algorithms for multimodal interaction, mapping, streaming media, and software protocols for gateways, among others. Leveraging refined software and hardware integration, we empower our customers to expand their market share while continuing to optimize our revenue streams and overall business scale for Smart Solutions.
We also believe that the efficient distribution of Tuya-powered smart devices to target audiences benefits our long-term competitive edge and sustainability. To this end, we strategically offer some of our customers, mainly brands and system integrators, who prefer not to deal with a multiple OEMs option to purchase directly from us finished smart devices deployed with PaaS sourced from qualified OEMs. These customers typically place purchase orders directly with us by specifying the type of smart devices. We then source devices for these customers from qualified OEMs selected based on the type of products, hardware specifications and other metrics. We earn the difference between the prices at which the products are sourced and sold.
In addition, we provide customers with the access to Tuya Expo, a dedicated business-to-business (B2B) platform connecting brands globally with an extensive network of OEMs. Currently, only a de minimis portion of our revenue is derived from Tuya Expo.
For Business Customers and End Users Using Smart Devices
SaaS
Industry SaaS
We offer industry SaaS, vertical-focused software solutions that enable businesses to deploy, connect, and manage large numbers and different types of smart devices for spatial intelligence in different industry verticals. Just like how billions of people use apps to enjoy mobile technology, we design industry SaaS as plug-and-play everyday tools for people to interact with and harness the power of IoT. Industry SaaS makes life easier, healthier and more enjoyable, and drives efficiency, cost saving and productivity for businesses of all sizes across industries.
Our industry SaaS is built to be brand-agnostic and is compatible with Tuya-powered devices across brands and categories. We believe this is the key reason our customers choose us over other industry SaaS providers, especially those that only support certain brands exclusively, because our brand-agnostic industry SaaS enables customers to manage their diverse business needs and smart device products across different brands and categories. Industry SaaS customers have the flexibility in sourcing smart devices by themselves, from OEMs recommended by us or via other channels based on their own preferences.
We offer industry SaaS to select verticals with the potential of monetizing our IoT capabilities. We are also able to deliver the infrastructure and core capabilities of industry SaaS as a vertical-agnostic solution that they can use to create industry-specific applications and use cases.
82
Table of Contents
Set out below are a few examples of our industry SaaS and the use cases they enable:
● AI home energy management system (“AI HEMS”) SaaS solution is a software-based home energy management solution featuring multiple AI capability innovations, including AI load identification, AI energy insights, AI energy scheduling, and AI energy returns. It is designed not only to help households and property managers gain deeper visibility and control over home electricity usage, but also to maximize energy efficiency through intelligent forecasting, automatic adjustment, and coordinated energy control. It enables smarter energy decisions, reduces unnecessary consumption, and supports the transition toward low-carbon, intelligent living environments.
o For example, in power generation forecasting, AI HEMS SaaS solution can analyze future weather conditions to predict power generation with AI capabilities. Meanwhile, users can also leverage AI to analyze electricity market and core energy service provider pricing data for a dynamic pricing prediction. Powered by AI algorithms such as NILM (Non-Intrusive Load Monitoring), it can identify energy usage by individual appliances and estimate their respective shares of electricity usage. Combined with household electricity consumption profiles, it predicts future electricity demand with AI. By comprehensively considering parameters such as battery capacity and charge/discharge power, it ultimately formulates an AI HEMS operation strategy for optimal returns across solar energy generation, storage, charging, and consumption.
o We also launched our plug-and-start micro solar-storage integrated solution. Driven by energy supply-demand tensions and favorable policies, plug-and-start micro solar-storage systems are experiencing rapid growth. The prominent advantage of this solution lies in its convenient plug-and-start installation by integrating the capabilities to convert, store, and maintain solar energy. Combined with our dynamic price analysis and AI energy scheduling capabilities, it enables smart charging and discharging, reducing electricity bills while decreasing reliance on traditional energy sources.
o Furthermore, leveraging our unique open platform and rich partner ecosystem, we have achieved efficient interconnection among energy storage devices, metering devices, home appliance brands, and energy service platforms. This novel integration model of smart home and energy ecosystems endows the energy solution with unique value. It not only effectively alleviates grid loads and achieves peak shaving and valley filling, but also provides users with a more convenient and intelligent one-stop energy management experience, making green living truly accessible.
● Smart hotel/apartment SaaS solution offers a management solution for hotels and resorts, designed to not only provide convenience for hotel guests, but also drive automation, efficiency and responsiveness for the hospitality industry. For apartments, we also offer a toolkit for landlords and rental apartment operators to connect smart door locks, sockets and other smart devices to increase the value of their properties and make them easier to manage. It is compatible with all mainstream property management systems (“PMS”), as well as customers’ own systems purpose-built for a wide range of use cases, including campuses, offices and other commercial facilities.
o Our Smart Hotel/Apartment SaaS solution allows the management to monitor different aspects of hotel services, such as housekeeping, guest traffic control, property surveillance and maintenance, from a single control point. In our Smart Hotel/Apartment SaaS solution, we have integrated both wired protocols (KNX, DALI, etc.) and wireless protocols (ZigBee, Bluetooth Mesh, WiFi, etc.), enabling more Tuya ecosystem products and third-party standard products to be incorporated into our system. This integration facilitates owners and integrators in transitioning from small-scale scenarios to medium-scale projects and even building system integration. Additionally, this SaaS capability acts as the foundational intelligence for Tuya spatial AI, achieving deep integration with various Tuya AI Solutions, including Tuya Energy Management System and Whole House SaaS Solutions
o The hotel experience – guests staying at a hotel utilizing our smart hotel app can personalize their surroundings without having to adjust every individual device. Hotels are also able to save on utilities bills by taking advantage of human activity detection-based lighting and air conditioning in public areas and guest rooms.
83
Table of Contents
o The resident experience – residents can monitor energy and utilities usage, create simple one-click actions to streamline routines or create access credentials for all guests. Apartment managers can monitor apartment maintenance more efficiently through our smart apartment software.
We primarily market our industry SaaS to system integrators. We also sell directly to individual industry operators, such as hotel or property managers. We mainly target large, established organizations with leading positions in their respective verticals and geographies, so that we can leverage their industry expertise and existing customer bases to quickly gain market shares and build brand awareness.
Cloud-based software value-added services
Since inception, we have allowed end users to connect to our platform to access a variety of basic cloud-based services, such as receiving app updates, for free. We also provide cloud-based value-added service technologies to our business customers, enabling them to serve end users while sharing revenue with us, or we offer end users the option to pay a fee to access a curated suite of cloud-based software value-added services with the resulting revenue shared with the business customers responsible for serving those end users:
● Cloud Storage – A cloud-based service that allows end users to revisit and replay content captured by their smart devices, such as pictures for memorable moments throughout the day or heartwarming interactions with pets.
● AI audio and video – AI-powered interactive experiences that support customized natural and emotional engagement. For example, an AI voice assistant for emotional companionship products (such as AI-powered interactive devices) can dynamically adjust its personality traits, voice, or accent to deliver emotional value or meet specific user interaction needs in various scenarios via LLM integration.
● Push messaging – sends users SMS text messages when a specific event (e.g., fire alarm going off) happens;
● Content – a library of digital content that enhances users’ AIoT experience, such as music, podcasts and even a bedtime story that users can ask their Tuya-powered virtual assistant to tell for their kids; and
● Others – various other cloud-based value-added services, such as stream media, among others.
As we gain more insights about customer demands through their feedback, we will continue to roll out additional value-added services for business customers ultimately serving end users, aiming to provide an engaging and continuously improved customer experience.
Cube – The Smart Private Cloud Solution
We officially released Cube Smart Private Cloud (“Cube”) in early 2022, which complements our existing public platform and enables us to address the need for large-scale conglomerates, such as our Fortune 500 customers, for building their autonomous and controllable smart business platforms. Cube also allows customers to access the full range of capabilities of our platform to build out their own smart businesses faster with improved sustainability and value creation.
As one of our core long-term strategies, we will continue our innovation of Cube. For example, in 2023, we expanded and refined our product matrix, improved delivery efficiency, reduced operational costs for our clients and expanded AI capabilities while fostering deeper collaborations with global conglomerates. The introduction of the Cube, Cube Lite and Cube Edge product matrices in 2023 further diversified the applicability of Cube across different scenarios. These launches provided our customers with a wider range of choices, tailored to the specific requirements of vertical industries and enterprises of different sizes. In 2025, we further optimized Cube’s modular architecture and product matrices, including Cube, Cube Lite, and Cube Edge, allowing enterprises to deploy SaaS-like vertical solutions with the security of a private cloud. By enhancing our AI capabilities within Cube, we provided
84
Table of Contents
our clients with more intelligent and efficient vertical solutions to address complex business challenges. Cube remains our strategic engine for securing long-term collaboration opportunities with global key accounts.
OUR TECHNOLOGIES
Tuya IoT cloud infrastructure
Our AI cloud platform and product offerings are supported by Tuya IoT cloud infrastructure, our unified underlying infrastructure, as illustrated below.
Our IoT technologies consist mainly of a Things Technology Platform (“TTP”) and an Application Enabling Platform (“AEP”). TTP and AEP together serve as the bedrock of our AI cloud platform and product offerings. We also have Business Technology Platform (“BTP”), which is the competency center that provides the technology foundation to the upper layer of our Tuya IoT cloud infrastructure. With these technologies, developers can develop, manage, and upgrade smart devices and customize IoT capabilities for their specific user cases. We believe that these technological features are the foundation to our mission of enabling everything to be smart and integration of AI capabilities and services, empowering us to build a growing and dynamic network of developers and partners, and driving our long-term revenue growth.
● Things Technology Platform (“TTP”) is the technology that enables real-time, closed-loop data exchanges between the cloud and the physical smart devices throughout their life cycle, thus improving the efficiency of IoT deployment. By integrating all types of data points and functions from hundreds of thousands of consumer smart devices, TTP generates a consistent and standardized “Things Model,” which allows developers to further customize it based on specific use cases. Our platform provides customers with a suite of solutions so they can have all the necessary features in their product development without switching to a different platform. Furthermore, TTP connects, authorizes, authenticates and manages IoT devices, enabling stable and precise connections and interactions across various devices with different functions, attributes, models and manufacturers.
Our TTP consists of the following components:
o IoT Edge features edge computing capabilities that bring computation to the edge. IoT devices can spend less time communicating with the cloud, react more quickly to local changes and operate more securely and reliably;
o IoT Core is the core ability to connect, authorize, authenticate and manage digital twins devices;
85
Table of Contents
o Things Model creates virtual representations of physical smart devices that enable analysis of data and monitoring of systems to prevent downtime, test new devices by using simulations and troubleshoot problems even before they occur;
o Event Hubs provides a unified streaming platform with time retention buffer, decoupling event producers from event consumers;
o Over-the-air Engine, or OTA Engine, provides unified OTA strategy and data analysis, predicts when devices need upgrades, reduces device OTA risks, and optimizes device usage activities; and
o Virtualized Device Computing enhances a smart device’s hardware capabilities from the cloud platform by managing device access and scenes control through the edge of the network.
● Application Enabling Platform (“AEP”) provides brands, OEMs and developers with a one-stop shop of AI and IoT cloud capabilities that they can use to add, customize or integrate functionality in a development environment that is “low-code” or even “no-code,” meaning that those IoT cloud capabilities are ready-to-use by developers so that they do not have to write the codes from scratch. More specifically, AEP enables us to modularize the underlying functionalities and capabilities of its TTP, and visualize such functionalities and capabilities as icons and buttons on the development platform’s operating interface. This allows customers to easily understand, select, drag and drop the desired functionalities for their smart devices in the development process even with little or no programming expertise. Leveraging our AEP, customers may reduce the time for developing devices or functionalities from months to days. In addition, our AEP is also equipped with device testing tools for manufacturing purposes, allowing customers to shorten the production-to-delivery cycle and achieve mass production for the smart devices within weeks. Our AEP delivers significant development efficiency.
AEP includes Tuya Platform Applications and Developer Kits that allow us to deliver PaaS, SaaS and other value-added services.
o Developer Kits allow developers to integrate tailored-made AI and IoT capabilities through a variety of APIs, SDKs and low-code development accelerators that allow developers to add, customize, or integrate systems and functionality based on specific requirements and needs.
o Tuya Platform Applications combine a no-code development platform, an IoT data analysis platform and an IoT industry solution studio to provide full platform-based business service capabilities.
● Business Technology Platform (BTP) is the competency center that provides the technology foundation to the upper layer of our Tuya IoT cloud infrastructure in the form of modular micro-services. It brings together a suite of service modules, such as big data computing, AI algorithm service and IoT device management, that work together to optimize customer experience.
We have deployed seven data centers hosted worldwide, including in China, the United States, Europe, India and Singapore.
Tuya AI Agent Development Platform
Our AI Agent development platform is a key pillar of our AI technology stack. It provides the foundational architecture for developing, deploying, and managing AI agents on smart hardware, enabling real-time interaction, multimodal understanding, and continuous intelligence at the device level.
● The platform is agnostic across cloud, LLMs, and edge environments, ensuring seamless compatibility with mainstream cloud infrastructures, a variety of large language models, and diverse connectivity and chip-level protocols. This flexibility enables AI capabilities to be deployed across a broad range of hardware and network configurations.
86
Table of Contents
● Built on the Adaptive Expert System (AES) architecture, the platform allows for modular construction and orchestration of AI agents. These agents possess abilities such as intent recognition, contextual reasoning, memory persistence, and scenario-specific response generation—driving intelligent decision-making within devices.
● The system also includes a Multi-Agent Runtime (MAR) that enables multiple agents to work concurrently on a single device, coordinating tasks such as perception, inference, and control. This distributed runtime framework supports complex, multi-layered task flows while maintaining low-latency responsiveness.
● To ensure interoperability and openness, we developed the MCP protocol, which acts as a standardized interface layer between AI agents and external services. MCP allows agents to securely call third-party tools, data sources, or services in a structured, modular fashion—similar to a universal adapter for AI services.
● The AI Agent Development Suite provides a complete set of tools to support agent design and deployment, including prompt engineering, knowledge base configuration, scene orchestration, memory and dialogue management, debugging, and simulation tools. Developers can choose from template-based creation or fully customized agent pipelines to suit their application needs.
● Our platform also supports edge-cloud collaborative AI, optimizing model execution efficiency across a range of hardware capabilities, while enabling over-the-air (OTA) updates to continuously evolve device intelligence over time.
● Developers can choose from two modes of creation:
o Template-based development, offering quick-start agent structures that are configurable and easy to extend;
o Fully customized development, allowing precise control over memory loops, model selection, and toolchain design for advanced use cases.
RESEARCH & DEVELOPMENT
Our leadership is built by our teams who are passionate about IoT. As of December 31, 2025, we had 1,026 research and development employees, representing approximately 70% of total employees. Our research and development team primarily consists of technology and platform development engineers responsible for (i) developing and iterating proprietary IoT technologies (e.g., TTP and AEP) and implementing enhancements and upgrades to our AI cloud platform; (ii) building AI engineering capabilities by developing AI agents and integrating key AI functions into our platform; (iii) developing and upgrading our products, including PaaS, Cube and SaaS; and (iv) optimizing our internal operational systems and technologies. Our research and development team members have on average over ten years of experience across a significant number of different subject areas such as IoT, industry design, cloud computing, AI and machine learning.
In 2025, our research and development initiatives on AI yielded advancements in following technological innovation and product development:
● AI Agent Development Platform: we launched the Tuya AI Agent development platform, a significant enhancement to our AI capabilities. This platform is designed to be LLM-agnostic and currently supports integration with a broad range of mainstream LLMs, including ChatGPT, Qwen, DeepSeek, Doubao, Le Chat by Mistral, Gemini, Amazon Nova, and Claude, among others. By abstracting the complexities involved in building AI devices and applications from scratch, the platform serves as a critical middleware layer that connects LLM capabilities with practical, real-world use cases. Developers are empowered to select the most appropriate LLMs for their specific business and market requirements, and can accelerate product development through Tuya’s pre-built templates and customizable solutions.
87
Table of Contents
● Spatial LLM: we introduced Spatial LLM, a generative AI solution that integrates large language models with real-time spatial data and smart device context within the Tuya ecosystem. Spatial LLM bridges the gap between applying general-purpose LLMs and specific AIoT business scenarios by enabling intelligent scene analysis, adaptive automation, and optimized decision-making. In energy management scenarios, Spatial LLM analyzes real-time consumption data across devices and environments to generate tailored energy-saving and emission-reduction strategies. The solution has been deployed across industrial, commercial, and residential settings, improving operational efficiency, reducing energy costs, and enhancing user experience through AI-driven scenario awareness and control.
Our AI cloud platform and proprietary cutting-edge IoT technologies have been developed in-house. We have invested substantially in research and development and we expect to continue to devote significant resources to research and development activities and incur a substantial amount of research and development expenses to enhance our competitive edge. In 2023, 2024 and 2025, we incurred research and development expenses of US$102.3 million, US$95.0 million and US$89.7 million, representing 44.5%, 31.8% and 27.9% of our total revenue for the same years, respectively. These investments have continued to result in the launch of innovative products that have helped us attract new customers and increase sales to our existing customers.
BRANDS WE SERVE
Our growth strategies are tailored around the brands we serve and their contracted OEMs. For leading brands and their OEMs in target categories and those with large demands in our products, we are focused on providing bespoke support and services by, for example, offering free trials of product enhancements and new features and functionality. In 2025, our PaaS empowered a total of over 3,800 brands to develop smart devices.
Substantially all of the brands we serve relate to our PaaS business. We typically do not enter into agreements in relation to PaaS business directly with the brands and instead enter into agreements with their contracted OEMs. In these circumstances, we consider such OEMs to be our customers. In limited circumstances, we also enter into agreements directly with brands in relation to certain value-added services, in which case we also consider such brands to be our customers.
OUR CUSTOMERS
We define our customers as entities from whom we generate revenues for the products and services we provide. We had approximately 5,900 customers in 2025, primarily including brands, OEMs, industry operators and system integrators. Starting from the end of 2021, we have been strategically optimizing our customer base, to focus on key account enterprises. In 2025, our PaaS empowered over 3,800 brands to develop their smart devices, including leading brands and enterprises such as Calex, Philips, Schneider Electric, Sharp, ABB, SCG, Panasonic, Changhong, TCL, Midea, etc. As we have cultivated a large and diversified customer base across different industry verticals, we believe that none of our customers is material to our total revenue. We provide online customer support services and tools for our customers to submit customer complaints and service requests anytime and anywhere.
We use the dollar-based net expansion rate for PaaS as a useful indicator of our customers’ loyalty and tendency to expand their usage of our platform over time. The dollar-based expansion rate for PaaS experienced a decline prior to early 2023 due to significant events that had adversely affected the global economy, including (i) shipping disruptions in late 2021 that delayed product deliveries and affected holiday sales; (ii) persistent inflation that dampened consumer sentiment; and (iii) supply-demand mismatch that led to an excess of inventory for downstream enterprises. As a result, our dollar-based net expansion rate of PaaS declined in early 2023. In the second half of 2023, with the easing of the downstream inventory backlog and the gradual recovery of the global economy, coupled with the effective customer-focus and product enhancement strategies we adopted to navigate through the macroeconomic headwinds, the dollar-based net expansion rate for PaaS rebounded and improved. Driven by increasing demand amid the global economic recovery and supply chain normalization in 2024, and our strategic focus on customer needs and product enhancements, the dollar-based net expansion rate for PaaS improved to 116% as of March 31, 2024, 127% as of June 30, 2024, 124% as of September 30, 2024, and 122% as of December 31, 2024, compared to the same period in 2023. The dollar-based net expansion rate for PaaS moderately declined to 102% as of December 31, 2025, reflecting the normalization of growth patterns among some of our customers with large revenue contribution following a period of rapid expansion in 2024, and our shifted strategic focus prioritizing new customers acquisition, who are currently in the initial ramp-up phase and expected to drive long-term expansion.
88
Table of Contents
For more information about the mismatch between supply and demand in the global consumer electronics sector and the risks that it poses to us and our customers, see “Item 3. Key Information—3.D.Risk Factors—Risks Related to Our Business and Industry—We operate in an emerging and evolving market, which may develop differently from or more slowly than we expect. If our market does not grow as we expect, or if we cannot expand our products and services to meet the demands of this market, our revenue may decline, or fail to grow, and we may continue to incur operating losses.” For a detailed discussion of the dollar-based net expansion rate for PaaS and certain other key operating metrics, see “Item 5. Operating and Financial Review and Prospects—5.A. Operating Results—Key Operating Metrics.”
QUALITY CONTROL
We are committed to providing customers with our products and services of consistently high quality. We emphasize quality control in all aspects of our business, including, for example, design, research, production, sales and after-sales services. We strictly control the quality of our business and operations. In order to monitor the quality and ensure that our products and services meet all our internal benchmarks and specifications, we have implemented various quality-control checks into our business process. In addition, we provide after-sales services and support to our customers.
We have devoted significant resources to the quality control of our products and services. Our quality control is a cross-departmental responsibility shared by multiple teams across business functions, including supply chain management, quality assurance, safety and compliance, and after-sales and customer service. In particular, these teams are responsible for establishing quality control standards, procedures for inspection of our raw materials and products and review standards of our suppliers. They are also responsible for handling customer complaints and compliance with applicable laws and international and national standards.
SALES, MARKETING AND BRANDING
We generate sales primarily through our direct marketing efforts targeting brands and OEMs, with a focus on attracting new customers as well as expanding usage within our existing customer base. We also generate customer leads indirectly through offline retail channels and e-commerce platforms. We currently operate dedicated regional sales forces covering a number of our key overseas markets, such as the United States, Europe, India, Latin America and Asia Pacific. We also market our products and services through media, word of mouth, advertising and promotion to further enhance awareness of our brand as well as to increase our brand exposure across various customer bases.
As we expand our footprint globally, we have invested substantially in developing localized marketing strategies and employing sales and support staff. In particular, we focus on educating customers about the “Powered by Tuya” smart ecosystem.
We utilize a multitude of sales and marketing channels, including:
● online marketing channels such as search engine optimization, private domain operations and the online developer platform on our website;
● offline channels such as word-of-mouth referrals from brands owners, OEMs, retailers and other industry participants;
● brand marketing through industry conferences and events, including Mobile World Congress, International Consumer Electronics Show and Hong Kong Electronics Fair, where we demonstrate how we empower developers to push the boundary of IoT; and
● developer outreach via code sharing platforms and Q&A websites such as GitHub and Zhihu.
We are committed to nurturing our developer community and have taken initiatives to boost developer engagement. By the fourth quarter of 2025, our registered developer base had grown to over 1.8 million. Our TuyaOS low-code development framework currently supports over 2,300 types, covering all protocols and categories within the Tuya platform. Additionally, we have created over 1,200 development documents, and our developer forum has amassed more than 14,000 technical support posts. Our development tools have also evolved to support more self-service operations, further solidifying the foundation for expanding the developer community.
89
Table of Contents
INTELLECTUAL PROPERTY
We rely on a combination of patent, copyright, trade secret and trademark laws as well as contractual restrictions such as confidentiality agreements, licenses and intellectual property assignment agreements. We also maintain a policy requiring our employees, contractors, consultants and other third parties to enter into confidentiality and proprietary rights agreements to control access to our proprietary information. As of March 31, 2026, we had registered 742 patents, 1,611 trademarks, 203 copyrights and 134 domain names in China and overseas. We have registered “Tuya” and “Powered by Tuya” as trademarks.
Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy or otherwise obtain and use our technology. Monitoring unauthorized use of our technology is difficult and costly, and we cannot be certain that the steps we have taken will prevent misappropriation of our technology. From time to time, we may have to resort to litigation to enforce our intellectual property rights, which could result in substantial costs and diversion of our resources. In addition, third parties may initiate lawsuits against us alleging infringement of their proprietary rights or declaring their non-infringement of our intellectual property rights. In the event of a successful claim of infringement and our failure or inability to develop non-infringing technology or license the infringed or similar technology on a timely basis, our business could be harmed. Even if we are able to license the infringed or similar technology, license fees could be substantial and may adversely affect our results of operations.
DATA SECURITY AND PRIVACY
When providing our products and services, we may have access to certain data of our customers and the end users, primarily certain machine-generated data produced by the smart devices powered by us. Such data consist primarily of the following types of device- and app-level information:
● data collected when a user registers in the mobile app that connects and controls smart devices powered by Tuya, or the App, such as basic account information (e.g., email address used to create an account);
● data collected through the App, such as App usage data and log information, mobile phone information (i.e., types and models of the mobile phones on which the App is installed), and feedback that users submit via the App; and
● data collected from smart devices, such as basic device data (e.g., on or off status and color) and data reported by the devices (e.g., humidity).
Collection of such data is based on users’ proactive consent to the in-App privacy policy prior to their use of the App. Such data will be collected, based on the type of data, either by the user’s active submission or our automatic collection, both of which are accomplished through the execution of predefined program logics embedded in the code of the App or the device’s firmware. The data are then transmitted to our cloud platform from the App or the device for processing. The data collected will be stored on specific data services as part of our cloud platform. Based on the user’s request, our cloud platform, also through the execution of predefined codes, will process the data and send feedback back to the App or the device. The primary purpose of the processing of the data is to facilitate the provision of our products and services to the users so that the devices may function properly.
As described above, the collection, processing and storage of the data that we may have access to are predominantly accomplished through the execution of predefined codes at the App or device level or embedded in our cloud platform. While we have the right to access and process such data to the extent proactively consented to by our customers or users, we do not have control over such data, except in very limited circumstances where we are by contract explicitly authorized by the users to do so. In any event, it is the users who retain the ownership of the personal information contained in the data.
90
Table of Contents
We have designed strict data protection policies to ensure that the collection, use, storage, transmission and dissemination of such data are in compliance with applicable laws and with prevalent industry practice. Specifically, our policies cover three main areas: data security, cloud service security and access control management.
● Data Security Policies: we have published the Information Security Management Manual based on an industry-recognized information security management framework. Our Policy of Handling Individual Privacy Rights aims to address privacy-related requirements outlined by multiple data privacy laws and regulations about individual privacy requests, the internal process and responsible departments for responding to different types of data requests. Our Information Classification & Handling Policy has been developed to classify all information created, collected, processed and/or disseminated within the organization into different levels of sensitivity and criticality. Our Data Backup Policy requires mandatory electronic backup, so that data and application programs can be restored when an incident impacting the integrity of such data occurs. In addition, we have adopted the Tuya Incident and Data Breach Response Plan, which provides a well-defined, organized approach for handling any potential threat to servers and data, as well as taking appropriate action when the data breach concerns personal information.
● Cloud Service Security Policies: we have published the Management Process of Access to Information Systems and Surveillance of Use with the goal of strengthening the surveillance and control of access to our cloud information systems and to manage the security monitoring and log reviews within the infrastructure. Our Change Management Security Policy sets forth necessary processes to internally review and approve of potential changes before execution. Our Data Retention Policy aims to provide clear understandings of our roles and responsibilities for data retention and processing, and to regulate such retention, use and deletion of data collected and processed by us.
● Access Control Management Policies: we have designed Access Control Policies, which outline the categories of access to system platforms, application, machines and the alignment of personnel functionality accordingly, in an effort to achieve effective access control and to ensure information security integrity and confidentiality. We have also developed Management Process of Secure Areas to help us maintain the security of physical access to our facilities and offices by establishing effective perimeters and safeguard measures, which is an integral part of ensuring the integrity, security and confidentiality of data.
We have established an all-round information system in reference to data security requirements and best practices and intend to continually invest heavily in data security and privacy protection. Our information system applies multiple layers of safeguards, including internal and external firewalls, enterprise-standard web application firewalls, risk management platform, and runtime application self-protection, or RASP, a security technology that detects and blocks computer attacks using information from inside the running software. We encrypt data throughout its life cycle to safeguard privacy and enhance data security. We implement a robust internal authentication and authorization system to ensure confidential and important data can only be accessed through computers for authorized use and only authorized staff can access those computers. We have clear and strict authorization and authentication procedures and policies in place. Our employees only have access to data which is directly relevant and necessary for their responsibilities and for limited purposes and are required to verify authorization upon every access attempt. We have also implemented robust internal rules and procedures, including security assessment in the design and implementation of R&D projects and code auditing, to ensure that the designed security requirements are met in our R&D activities and code quality and security. Furthermore, we have established an incident response team that consists of a Chief Information Security Officer (CISO), a Data Protection Officer (DPO) and a Chief Privacy Officer (CPO) to provide a quick, effective and orderly response to servers and personal information related to potential or actual incidents such as virus infections, hacker attempts and break-ins, improper disclosure of confidential information, system service interruptions, breach of personal information, and other events with serious information security implications.
We have completed information security, privacy and compliance certifications/validations with the consultation of various global agencies, and now serve as a reliable AIoT platform with comprehensive certificates. We have obtained the ISO 27001 Information Security Management System Certificate, ISO 27017 Certificate for Information Security of Cloud Services and ISO 27701 Certificate for Protection of Personally Identifiable Information, and the recently established ISO/IEC 42001 Artificial Intelligence Management System Certificate, demonstrating our proactive commitment to responsible and ethical AI governance. Furthermore, we are fully committed to complying with the GDPR and CCPA. We have also worked with top privacy compliance and cybersecurity firms, such as TrustArc, ioXt Alliance and Palo Alto Networks, for privacy management and penetration testing.
91
Table of Contents
As of the date of this annual report, we have not received any material claim from any third party against us on the ground of infringement of such party’s right to data protection as provided by the Civil Code of the PRC or any applicable laws and regulations in other jurisdictions, and we have not experienced any material data loss or breach incidents.
ENVIRONMENTAL, SOCIAL AND GOVERNANCE
We are committed to promoting corporate social responsibility and sustainable development and integrating these principles into all major aspects of our business operations. Corporate social responsibility is regarded as a core component of our growth philosophy and is pivotal to our ability to create sustainable value for our shareholders, partners, customers and employees, while embracing diversity and serving the broader public interest. In 2025, we received an A rating from Wind, and were also included in the S&P Global Sustainability Yearbook (China Edition) 2025, recognizing our continued efforts and achievements in ESG.
Our board of directors has adopted a comprehensive policy on environmental, social and corporate governance responsibilities, or the ESG Policy, which sets forth our corporate social responsibility objectives and provides guidance on practicing corporate social responsibility in our daily operations. Under our ESG Policy, one of our main ESG objectives is to reduce any negative impacts on the environment through our commitment to energy savings and sustainable development. In addition, we endeavor to support and have a lasting positive impact on the local community through various initiatives, including corporate philanthropy, establishing community partnerships and mobilizing our employees to participate in volunteer work. Under our ESG Policy, we will also focus on embracing diversity within our organization and equal and respectful treatment of all of our employees in their hiring, training, wellness and professional and personal development.
Our board of directors has the collective and overall responsibility for establishing, adopting and reviewing the ESG vision, policy and target, and evaluating, determining and addressing our ESG-related risks. We have continued to improve the oversight by our board of directors of ESG matters through a series of measures, including taking into account ESG matters in board room discussions and strategic planning, conducting and regularly refreshing a materiality assessment to identify and assess all material ESG issues, developing and regularly reviewing ESG policies, and regularly monitoring ESG performance against our goals.
Commitment to Sustainable Development through Products and Services
As a global company deeply committed to environment and social responsibility, we always strive to make society a better place with our IoT technologies and products. We target to achieve sustainability which constitutes a fundamental strategy for us as we expand and diversify our offerings. In particular, we endeavor to incorporate environmental and ESG-related considerations into our product development process and have been actively exploring ways to achieve environmental protection and realize carbon neutrality. Many of our offerings of key products and services, such as our energy-efficient algorithms that aim to decrease energy usage of smart devices as much as possible, help customers optimize their business processes, reduce costs and improve operational efficiency.
92
Table of Contents
In the mid-term, we will continue to monitor our carbon emissions, which we expect to mainly come from office premises, and continue to implement sustainable and environmentally friendly practices to reduce our carbon emissions. We also intend to leverage our IoT technologies and products to help customers further achieve energy savings while optimizing device functionalities, and explore new, innovative designs for smart device energy storage and usage. In the long term, we intend to use our technological capabilities to enable greater sustainability across different industry verticals, enhance energy usage efficiency and optimize environmental and waste management through the implementation of various carbon neutral practices.
Embracing Diversity and Building a Healthy Workplace
We will continue to prioritize achieving diversity within our organization and equal and respectful treatment of all of our employees in their hiring, training, wellness and professional and personal development. In particular, we recognize and embrace the benefits of having a gender-diverse board as an essential element in maintaining our company’s competitive advantage and enhancing our ability to attract, retain and motivate employees from the widest possible pool of available talent. We are committed to taking a proactive approach in recruiting female directors and aligning directors’ diverse competencies and perspectives with the company’s strategy. While maximizing equal career opportunity for everyone, we will also continue to promote work-life balance and create a happy culture in our workplace for all of our employees.
As we do not operate any production facilities, we are not subject to material health, work safety, social or environmental risks. To ensure compliance with applicable laws and regulations, our human resources department will, if necessary and after consultation with our legal advisors, adjust our human resources policies to accommodate material changes to relevant labor and safety laws and regulations. In 2025 and up to the date of this annual report, we have not been subject to any fines or other penalties due to non-compliance in relation to health, workplace safety or environmental regulations, and have not had any accident or claim for personal or property damage made by our employees which had materially and adversely affected our financial condition or business operations.
Supporting the Community
As a company with a strong sense of and commitment to social responsibility, we have in recent years launched a series of non-profit events and campaigns as part of our corporate social responsibility efforts.
● In September 2023, we donated smart devices with a total value of RMB0.4 million to Dashu Town, Chun’an District, Hangzhou, to promote rural revitalization and poverty alleviation.
● In November 2023, we donated smart devices with a total value of RMB0.5 million to Seda County in Sichuan, aiming to drive the infrastructure development in disadvantaged regions.
● In December 2024, we donated supplies with a total value of around RMB0.4 million to Derong County in Ganzi, Sichuan, to support underprivileged areas and contribute to regional development.
● In December 2024, we donated supplies with a total value of around RMB35.2 thousand to Luniu Town in Hangzhou, through the Zhejiang Association for Science Popularization to support rural revitalization.
● In December 2024, we donated products with a total value of around RMB0.1 million to Zhejiang International Studies University to support the enhancement of its smart infrastructure.
● In December 2024, we donated smart devices with a total value of around RMB25.9 thousand to the migrant workers’ school in Hongtang Street, Ningbo, to help create a better learning environment for the children.
● In December 2025, we donated smart devices with a total value of around RMB74.3 thousand to Zhejiang International Studies University, to support the enhancement of its smart infrastructure.
● In December 2025, we donated smart devices with a total value of around RMB107.8 thousand to The Hong Kong University of Science and Technology (Guangzhou), to support the enhancement of its smart infrastructure.
93
Table of Contents
Integrating Sustainable and Environmentally Friendly Practices into Our Business Operations
Although our business operations do not directly produce pollutants that directly affect the environment, we endeavor to implement sustainable and economically friendly practices in our own operations to reduce our carbon footprint such as reducing the energy consumption through, for example:
● Installing energy-efficient lighting and ensuring lights are switched off when out of use either manually or through automatic sensors;
● Requiring double-sided printing of documents throughout our offices;
● Actively driving reductions in the use of paper, water and electricity throughout our offices;
● Switching off certain IT equipment or automatic power shutdown for certain systems and devices; and
● Air conditioning controls, with measures including requirements on lowest temperature, regular maintenance of air cooling technologies and optimal timing controls.
We believe that our policies can help us meet our environmental sustainability goals by reducing energy consumption in our operations.
Managing ESG Risks
We are committed to a thorough analysis and assessment process that will enable us to identify any material ESG risks and take actions to address these risks timely and effectively. We identify, assess, manage and mitigate environmental, social and climate-related risks by having dedicated teams to take care of the life-cycle management of the corresponding project. For example, personnel from our human resources and government-related affairs departments are responsible for overseeing the management and monitoring of our waste management system and our energy savings and consumption control program to ensure that we achieve the goals of energy savings and consumption reduction. Our management also actively oversees the identification and monitoring of the actual and potential environmental, social and climate-related risks on our business, strategy and financial performance, and take these issues into account during the course of our business, strategic and financial planning. Our management will assess the likelihood of such risks occurring and the estimated magnitude of any potential impact. We may also engage independent third parties to evaluate the ESG risks and review our existing strategy, target and internal controls. Necessary improvement will then be implemented to mitigate any major ESG risks identified.
As a technology company, we do not currently have any material liabilities relating to health, work safety and environment, and do not expect that we will incur any material liabilities in this regard which could have any material adverse impact on our business and operating results. However, potential risks associated with climate change or other climate-related issues may have financial implications for us. For instance, extreme weather conditions may cause suspension or disruption to our business operations and have an impact on our financial condition. Extreme weather may also cause disruptions for our suppliers, which may in turn adversely impact our ability to serve our customers and end users. In 2025 and up to the date of this annual report, our business, results of operations and financial condition have not been materially and adversely impacted by any climate-related incidents.
94
Table of Contents
SEASONALITY
We have in the past experienced, and expect in the future to continue to experience, seasonal fluctuations in our revenue and sales from time to time, as a result of the holiday season, customers’ buying patterns, and changes in the business and economic environment that are outside our and our customers’ control. We typically experience lower growth in revenues in the first quarter as a result the reduced production capacities of OEMs located in China due to the annual Lunar New Year holidays. We expect the historical seasonality trends to continue to have a material impact on our results of operations and financial condition. However, certain unique events may cause the historical seasonal trends and patterns to temporarily no longer apply, such as high global inflation weakening consumption sentiment and dampening enterprises’ confidence in doing business, downstream inventory backlog disrupting enterprises’ business and operating plans, supply chain disruption interfering with delivery of goods, and the imposition of new tariffs or adjustments in existing tariffs or trade barriers. See “Item 3. Key Information—3.D.Risk Factors—Risks Related to Our Business and Industry—Seasonality may cause fluctuations in our sales and operating results.”
COMPETITION
The global AIoT platform market is rapidly evolving. We compete in the ordinary course of business with technology companies providing AIoT services and solutions, internet-related services and products for AIoT, and AIoT-enabling platforms, and e-commerce companies offering AIoT-related cloud products and services.
We may, from time to time, face competition from both large, well-established IoT service providers, and less-established IoT companies or companies that offer capabilities that compete with some of our offerings. However, the global IoT and AIoT platform market has also been facing headwind in 2023, with certain players in the IoT field who are engaged in business similar to our PaaS business announcing the termination of their IoT platform services. The global AIoT platform market is rapidly evolving. Following significant industry consolidation, the 2025 landscape now prioritizes fully integrated architecture and spatial intelligence. According to CIC, we are the world’s largest independent and cloud-agnostic AIoT platform by device volume in 2025, supported by our comprehensive full-stack capabilities across cloud, edge, and device.
We believe that none of our competitors currently competes directly with us across all of our offerings, and we compete favorably on the basis of the factors below:
● ability to support multiple use cases on a single platform;
● ease of deployment, implementation and use;
● platform performance, interoperability, scalability and reliability;
● ability to help customers achieve global IoT deployment;
● ability to build a supply chain ecosystem;
● customer support and platform maintenance;
● brand awareness and reputation;
● sales and marketing efforts; and
● ability to ensure data security and privacy.
95
Table of Contents
INSURANCE
We maintain the statutory social insurance as required by the relevant local laws and regulations. In addition, we maintain a supplemental employee commercial healthcare insurance program aiming to promote the work safety, health and well-being of our employees. We maintain liability insurance policies to cover potential product liability claims, cybersecurity insurance policies to cover the costs associated with a breach of third-party data in the event that the data is lost or stolen, and technical errors and omissions policies for liabilities in connection with failures of a service or software. Consistent with customary industry practice in the PRC and the other markets in which we operate, we do not maintain key-man life insurance.
LICENSES, PERMISSIONS AND APPROVALS
As of the date of this annual report, all requisite licenses, permissions and approvals have been obtained from relevant regulatory authorities that are material to our operations. None of such licenses, permissions or approvals have been denied or rescinded.
The following table sets forth details of licenses, permissions and approvals held by our PRC subsidiaries that are material to current business operations in China, and the former VIE did not hold any such material licenses, permissions or approvals.
License Holder Issuing Authority Grant Dates Expiration Date
Registration and Filing of Foreign Trade Operator Tuya Information Hangzhou City Xihu District Commission of Commerce February 15, 2022 N/A
Registration of Consignee or Consignor of Imported or Exported Goods Tuya Information Hangzhou Customs May 11, 2018 Long-term
Registration and Filing of Foreign Trade Operator Zhejiang Tuya Hangzhou City Xihu District Commission of Commerce November 12, 2021 N/A
Registration of Consignee or Consignor of Imported or Exported Goods Zhejiang Tuya Qianjiang Customs May 27, 2020 Long-term
In the view of Jia Yuan Law Offices, our PRC legal counsel, we had complied with the relevant applicable PRC laws relating to the required licenses, permissions and approvals to business operations in China in all material respects in 2025 and up to the date of this annual report. Based on its understanding of the relevant PRC laws and regulations, our PRC legal counsel has also advised us that, to the best of their knowledge, there should be no material legal impediment for us to renew these licenses, permissions and approvals as long as we comply with the relevant legal requirements and we take all necessary steps and submit the relevant applications in accordance with the requirements and schedules prescribed by the applicable PRC laws and regulations.
96
Table of Contents
For the consequences to us and investors if we do not receive or maintain requisite licenses, permissions and approvals necessary to conduct operations in China, or if applicable laws, regulations or interpretations change and we are required to obtain additional permissions or approvals in the future, see Item 3. Key Information—3.D. Risk Factors—Risk Related to Our Business and Industry—Any failure to maintain necessary permits and licenses to operate our business operations under applicable laws and regulations could materially and adversely affect our business and results of operations.”
In recent years, the PRC government has increasingly tightened the regulation of cybersecurity, and indicated an intent to exert more oversight and control over securities offerings and other capital markets activities that are conducted overseas and foreign investment in China-based companies like us. See “Item 3. Key Information—Recent PRC Regulatory Developments.” As of the date of this annual report, we have not been required to go through a cybersecurity review by the CAC, or required to obtain any permission from, or complete any filing with, the CSRC in connection with our prior public offerings or maintaining the listing status on applicable stock exchanges. Nor have we received any formal inquiry, notice, warning, sanction, or any regulatory objection in relation to cybersecurity review from the CSRC, the CAC or any other PRC regulatory agencies that have jurisdiction over our operations. There remains substantial uncertainty as to how PRC legislative, administrative and regulatory authorities will interpret, implement and enforce existing laws and regulations in this area, and whether existing requirements will be further refined or new laws, regulations, rules, implementing measures or interpretations will be promulgated. As a result, the potential impact of such laws, regulations and regulatory developments on our business operations, our ability to accept foreign investments and conduct follow-on offerings, and our listing status on, or ability to remain listed on, applicable stock exchanges remains uncertain. For details of related risks, see “Item 3. Key Information—3.D. Risk Factors—Risks Related to Doing Business in China—The filing, approval or other administration requirements of the CSRC, the CAC or other PRC government authorities may be required to maintain our listing status or conduct future offshore securities offerings.”
REGULATIONS
Regulation Relating to Foreign Investment
Investments activities in China by foreign investors are principally governed by the Encouraged Industries Catalog for Foreign Investment (2025 version) (the “Catalog”), which was promulgated by the Ministry of Commerce (“MOFCOM”) and the National Development and Reform Commission (the “NDRC”) on December 15, 2025 and became effective on February 1, 2026 and the Special Administrative Measures for Foreign Investment Access (Negative List 2024) (the “Negative List (2024)”), which was promulgated by the MOFCOM and the NDRC on September 6, 2024 and became effective on November 1, 2024. The Catalog and the Negative List (2024) set forth the industries in which foreign investments are encouraged, restricted and prohibited. Industries that are not listed in any of these three categories are generally open to foreign investment unless otherwise specifically restricted by other PRC rules and regulations. Article 6 of the Interpretation Note of the Negative List (2024), which is consistent with Article 6 of the Interpretation Note of the Negative List 2021, provides that, where a domestic enterprise engaged in the business in the prohibited areas of the Negative List (2024) seeks to issue and list its shares overseas, it shall complete the examination process and obtain approval of the relevant competent authorities of the State, the foreign investor shall not participate in the operation and management of the enterprise, and its shareholding percentage shall be subject to the relevant provisions on the administration of domestic securities investment by foreign investors. On January 18, 2022, the NDRC held a press conference to further clarify the position of Article 6 above, during which the spokesman made it clear that Article 6 shall only be applicable to the situations where domestic enterprises were seeking a direct overseas issuance and listing (i.e., H-shares listing).
According to the Negative List (2024), the foreign equity interest ownership of entities that engage in value-added telecommunications business (except for e-commerce, domestic multiparty communication, storage and forwarding and call center) must not exceed 50%.
97
Table of Contents
On March 15, 2019, the National People’s Congress approved the Foreign Investment Law of the PRC (the “Foreign Investment Law”), which took effect on January 1, 2020 and replaced the Sino-Foreign Equity Joint Venture Enterprise Law of the PRC, the Sino-Foreign Cooperative Joint Venture Enterprise Law of the PRC and the Wholly Foreign-Invested Enterprise Law of the PRC and became the legal foundation for foreign investment in the PRC. On December 26, 2019, the State Council issued the Regulations on Implementing the Foreign Investment Law of the PRC, or the Implementation Rules, which took effect on January 1, 2020 and replaced the Regulations on Implementing the Sino-Foreign Equity Joint Venture Enterprise Law of the PRC, Provisional Regulations on the Duration of Sino-Foreign Equity Joint Venture Enterprise Law, the Regulations on Implementing the Wholly Foreign-Invested Enterprise Law of the PRC and the Regulations on Implementing the Sino-Foreign Cooperative Joint Venture Enterprise Law of the PRC. Pursuant to the Foreign Investment Law and the Implementation Rules, the existing foreign-invested enterprises established prior to the effective date of the Foreign Investment Law are allowed to keep their corporate organization forms for five years from the effectiveness of the Foreign Investment Law before such existing foreign-invested enterprises change their organization forms and organization structures in accordance with the Company Law of the PRC, which was last amended in December 2023 and came into effect on July 1, 2024, the Partnership Enterprise Law of the PRC and other applicable laws. Pursuant to the Company Law, shareholders of a limited liability company must pay in their subscribed registered capital in full within five years from the date of establishment of the company or the date of its capital increase, and companies established before July 1, 2024 should gradually adjust their capital contributions to meet this new requirement. The Company Law also involves aspects of the company’s organizational structure, corporate governance, and the rights and obligations of shareholders, which also apply to foreign investment enterprises in the PRC.
Pursuant to the Foreign Investment Law, foreign investment means the investment activities within the PRC directly or indirectly conducted by foreign natural persons, enterprises and other organizations (the “foreign investor”), including the following circumstances: (i) a foreign investor, individually or collectively with other investors, establishes a foreign-invested enterprise within the PRC; (ii) a foreign investor acquires any shares, equities, portion of property or other similar interest in an enterprise within the PRC; (iii) a foreign investor, individually or collectively with other investors, invests in a new project within the PRC; and (iv) foreign investors invest in the PRC through any other methods under laws, administrative regulations or provisions prescribed by the State Council of the PRC. The PRC applies the administrative system of pre-establishment national treatment plus negative list to foreign investment.
On December 30, 2019, MOFCOM and the State Administration for Market Regulation (the “SAMR”) issued the Measures for the Reporting of Foreign Investment Information, which took effect on January 1, 2020 and replaced the Interim Measures for the Recordation Administration of the Formation and Modification of Foreign-Funded Enterprises, and thus foreign investors carrying out investment activities directly or indirectly in China, instead of filing formalities, must report their foreign investment information to the commerce authorities.
Regulation Relating to Value-Added Telecommunication Services
The Telecommunications Regulations of the People’s Republic of China (the “Telecommunications Regulations”) promulgated by the State Council on September 25, 2000 and last amended on February 6, 2016, provide a regulatory framework for telecommunication services providers in mainland China. The Telecommunications Regulations require telecommunication services providers to obtain an operating license prior to the commencement of their operations. The Telecommunications Regulations categorize telecommunications businesses into basic telecommunications businesses and value-added telecommunications businesses, according to the Catalog of Telecommunications Business, attached to the Telecommunications Regulations and last amended by the Ministry of Industry and Information Technology (the “MIIT”) on June 6, 2019.
98
Table of Contents
Regulation Relating to Cybersecurity, Data Security and Privacy Protection
PRC
Cybersecurity
On December 28, 2000, the SCNPC enacted the Decision on the Protection of Internet Security, as amended on August 27, 2009, which provides that the following activities conducted through the internet are subject to criminal liabilities: (i) gaining improper entry into any of the computer information networks relating to state affairs, national defensive affairs, or cutting-edge science and technology; (ii) violation of relevant provisions of the state in the form of unauthorized interruption of any computer network or communication service, as a result of which the computer network or communication system cannot function normally; (iii) spreading rumor, slander or other harmful information via the internet for the purpose of inciting subversion of the state political power; (iv) stealing or divulging state secrets, intelligence or military secrets via internet; (v) spreading false or inappropriate commercial information; or (vi) infringing on the intellectual property.
On December 13, 2005, the Ministry of Public Security issued the Provisions on the Technical Measures for Internet Security Protection, which took effect on March 1, 2006. These regulations require internet service providers to take proper measures including anti-virus, data backup, keeping records of certain information such as the log-in and exit time of users, and other related measures, and to keep records of certain information about their users for at least 60 days. On June 22, 2007, the Ministry of Public Security, the State Secrecy Bureau, the State Cryptography Administration and the Information Office of the State Council jointly promulgated the Administrative Measures for the Multi-level Protection of Information Security, under which the security protection grade of an information system may be classified into five grades. Companies operating and using information systems shall protect the information systems and any system equal to or above Level II as determined in accordance with these measures, a record-filing with the competent authority is required.
The Cybersecurity Law of the PRC, or the Cybersecurity Law, was initially adopted by the SCNPC on November 7, 2016, and most recently amended on Octorber 28, 2025, with such amendments taking effect on January 1, 2026. Regarded as the fundamental law in the area of cybersecurity in China, the amended Cybersecurity Law regulates network operators and others from the following perspectives: the principle of cyberspace sovereignty, security obligations of network operators and providers of network products and services, protection of personal information, protection of critical information infrastructure, data use and cross-border transfer, network interoperability and standardization. Notably, the recent amendments substantially increase the maximum financial penalties for cybersecurity violations (up to RMB 10 million), expand extraterritorial jurisdiction over overseas entities endangering China’s cybersecurity, and introduce new statutory requirements for artificial intelligence ethics, risk monitoring, and safety oversight. Network operators shall, according to the requirements of the rules for graded protection of cybersecurity, fulfill security protection obligations, so as to ensure that the network is free from interference, damage or unauthorized access, and prevent network data from being divulged, stolen or falsified. In addition, network operators that collect personal information shall follow the principles of legitimacy, rationality and necessity and shall not collect or use any personal information without due authorization of the person whose personal information is collected. Each individual is entitled to require a network operator to delete his or her personal information if he or she finds that collection and use of such information by such operator violate the laws, administrative regulations or the agreement by and between such network operator and such individual, and is entitled to require any network operator to make corrections if he or she finds errors in such information collected and stored by such network operator. Such network operator shall take measures to delete the information or correct the error.
99
Table of Contents
On December 28, 2021, the CAC and certain other PRC regulatory authorities promulgated the Measures for Cybersecurity Review (the “Cybersecurity Review Measures”), which provide that (i) network platform operators holding over one million users’ personal information shall apply with the Cybersecurity Review Office for a cybersecurity review when listing in a foreign country, and (ii) operators of “critical information infrastructure” that intend to purchase network products and services that will or may affect national security shall apply for a cybersecurity review and (iii) network platform operators carrying out data processing that will affect or may affect national security shall apply for a cybersecurity review. The Cybersecurity Review Measures took effect on February 15, 2022 and replaced the Measures for Cybersecurity Review promulgated in April 2020. For a detailed discussion of the risks and uncertainties related to our compliance with regulations on cyber security, please see “Item 3. Key Information—3.D.Risk Factors—Risks Related to our Business and Industry—Compliance with the rapidly evolving landscape of global data privacy and data security laws may be challenging, and any failure or perceived failure to comply with such laws, or other concerns about our practices or policies with respect to the processing of personal information, could damage our reputation and deter current and potential customers and end users from using our platform and products and services or subject us to significant compliance costs or penalties, which could materially and adversely affect our business, financial condition and results of operations.”
Data Security
On June 10, 2021, the SCNPC promulgated the Data Security Law of the PRC, or the Data Security Law, which took effect on September 1, 2021. According to the Data Security Law, the enterprises conducting data processing activities shall establish and improve their data security management systems, organize data security trainings and adopt corresponding technical measures and other necessary measures, with a view to guaranteeing the data security. Chapter 4 of the Data Security Law provides for the obligations of general data processing and data security protection, including (i) establishing and improving the whole-process data security management system; (ii) strengthening risk monitoring and properly handling data security incidents; and (iii) legally and properly collecting and using data. Our company has established a relatively complete data security management system, organized and carried out data security education and training, adopted corresponding technical measures and organizations to protect data security, formulated a data security incident management system, carried out risk monitoring and assessment, handled information security level protection filing and assessment for call center service platforms, and performed corresponding network security level protection obligations. In addition, pursuant to the Data Security Law, a data security system should be established to administer data at different levels and by different categories, and impose specific compliance obligations on processors of important data, including (i) specifying the person and institution responsible for data security and implementing data security protection responsibilities; (ii) conducting regular risk assessment of its data processing activities; and (iii) fulfilling the regulatory requirements for transmitting important data overseas. Further, remedial measures shall be taken immediately upon discovery of any data security defects or bugs, and users shall be timely notified and competent authorities shall be informed in accordance with relevant provisions if any data security incident occurs. If an enterprise conducting data processing activities fails to meet such requirements, it would be subject to regulatory penalties, including fine, suspension of the relevant business, close of business for rectification and revocation of the relevant business permit or business license.
On July 7, 2022, the CAC published Measures on Security Assessments for the Cross-border Transfer of Data which took effect on September 1, 2022. It is applicable to cross-border transfers of personal information and important data collected and generated in China under certain circumstances. Apart from that, the measures provides detailed requirements for contracts concluded between data processors and overseas recipients, including but not limited to the purpose of cross-border data transfer, the overseas storage site, the restrictions concerning the transfer of cross-border data from overseas recipients to other organizations and individuals, the security measures to be taken by the overseas recipients when there is a material change in the actual control or scope of business, liability for breach of data security obligations and binding and enforceable dispute resolution provisions and the proper emergency disposal to be taken in the event of risks such as data breaches.
100
Table of Contents
On March 22, 2024, the CAC promulgated the Provisions on Promoting and Regulating Cross-Border Data Flows, effective on the date of promulgation. The provisions provide several exemptions to processors of data which exempt them from undergoing data security assessment, obtaining personal information protection certification, or entering into standard contracts for outbound transfer of personal information for businesses. These exemptions include, among others, scenarios where a data processor, other than a CIIO, has cumulatively transferred personal information (excluding sensitive personal information) of fewer than 100,000 individuals to overseas recipients since January 1 of the current year. In addition, a data processor, other than a CIIO, shall enter into a standard contract with overseas recipients for the cross-border transfer of personal information, or obtain certification for personal information protection if, since January 1 of the current year, the data processor has cumulatively transferred to overseas recipients personal information (excluding sensitive personal information) of more than 100,000 but fewer than 1,000,000 individuals, or sensitive personal information of fewer than 10,000 individuals. The provisions also explicitly state that data processors are not required to apply for security assessment on cross-border transfer of important data, provided that the relevant data has not been notified or published as important data by relevant departments or regions.
In order to guide and assist data processors in submitting data export security assessments in a standardized and orderly manner, the CAC prepared the Guidelines for Data Export Security Assessment Application (Version 3.0) in June 2025, which provide specific requirements for the method, process, and materials required for submitting a data export security assessment application and simplify the materials required to be submitted by the data processors.
On November 14, 2021, the CAC released the Regulations on the Administration of Cyber Data Security (Draft for Comments) (the “Draft Cyber Data Security Regulation”). On September 24, 2024, the CAC promulgated the Regulations on the Administration of Cyber Data Security (the “Regulation on Cyber Data Security”), which became effective on January 1, 2025. The Regulation on Cyber Data Security reiterate the general regulations for cyber data processing activities, rules of personal information protection, important data security protection, network data cross-border transfer management, and the responsibilities of internet platform service providers. In addition, unlike the Draft Cyber Data Security Regulation, the officially promulgated Regulation on Cyber Data Security does not specifically include the requirement that cyber data processing entities seeking a Hong Kong listing that affects or may affect national security, or data processors that handle personal information of more than one million people contemplating to list its securities on a “foreign” stock exchange, or the merger, reorganization or division of internet platform operators that have acquired a large number of data resources related to national security, economic development or public interests, which affect or may affect national security should apply for a cybersecurity review. Instead, the Regulation on Cyber Data Security generally provides that cyber data processors whose cyber data processing activities affect or may affect national security shall be subject to national security review in accordance with the relevant regulations. According to the PRC National Security Law, “national security” refers to a status in which the regime, sovereignty, unity, territorial integrity, welfare of the people, sustainable economic and social development, and other vital interests of the state are relatively not in danger and not threatened internally or externally and the ability to maintain a sustained security status. However, the criteria for determining the circumstances that “affect or may affect national security” for the purpose of the Regulation on Cyber Data Security remain unclear and are subject to further clarification by the CAC.
Privacy Protection
The PRC Constitution states that PRC law protects the freedom and privacy of communications of citizens and prohibits infringement of such rights. In recent years, PRC government authorities have enacted legislation on internet use to protect personal information from any unauthorized disclosure. On May 28, 2020, the National People’s Congress of the PRC approved the Civil Code of the PRC, which took effect on January 1, 2021. Pursuant to the Civil Code of the PRC, the personal information of a natural person shall be protected by the laws. Any organization or individual shall legally obtain such personal information of others when necessary and ensure the safety of such information, and shall not illegally collect, use, process or transmit personal information of others, or illegally purchase or sell, provide or make public personal information of others. The Administrative Measures on Internet Information Services, issued by the State Council on September 25, 2000 and last amended on December 6, 2024, prohibit ICP service operators from insulting or slandering a third party or infringing the lawful rights and interests of a third-party.
101
Table of Contents
On December 29, 2011, the MIIT promulgated the Several Provisions on Regulating the Market Order of Internet Information Services, which became effective on March 15, 2012. On December 28, 2012, the SCNPC promulgated the Decision on Strengthening Network Information Protection to enhance the legal protection of information security and privacy on the internet. The Provisions on Protection of Personal Information of Telecommunications and Internet Users promulgated by the MIIT on July 16, 2013 contains detailed requirements on the use and collection of personal information as well as the security measures to be taken by internet service providers. Specifically, (i) the users’ personal information shall not be collected without prior consent; (ii) the personal information shall not be collected other than those necessary for internet service providers to provide services; (iii) the personal information shall be kept strictly confidential; and (iv) a series of detailed measures shall be taken to prevent any divulgence, damage, tampering or loss of personal information of users.
The Administrative Provisions on Security Vulnerability of Network Products, or Provisions, were jointly promulgated by the MIIT, the CAC and the MPS on July 12, 2021 and took effect on September 1, 2021. Network product providers, network operators as well as organizations or individuals engaging in the discovery, collection, release and other activities of network product security vulnerability are subject to the Provisions and shall establish channels to receive information of security vulnerability of their respective network products and shall examine and fix such security vulnerability in a timely manner. Network product providers are required to report relevant information of security vulnerability of network products with the MIIT within two days and to provide technical support for network product users. Network operators shall take measures to examine and fix security vulnerability after discovering or acknowledging that their networks, information systems or equipment have security loopholes. According to the Provisions, the breaching parties may be subject to administrative penalty as regulated in accordance with the Cybersecurity Law. Since the Provisions are relatively new, uncertainties still exist in relation to its interpretation and implementation.
Pursuant to the Interpretation of the Supreme People’s Court and the Supreme People’s Procuratorate on Several Issues regarding Legal Application in Criminal Cases Infringing upon the Personal Information of Citizens, which was issued on May 8, 2017 and took effect on June 1, 2017, the following activities may constitute the crime of infringing upon a citizen’s personal information: (i) providing a citizen’s personal information to specified persons or releasing a citizen’s personal information online or through other methods in violation of relevant national provisions; (ii) providing legitimately collected information relating to a citizen to others without such citizen’s consent (unless the information is processed, not traceable to a specific person and not recoverable); (iii) collecting a citizen’s personal information in violation of applicable rules and regulations when performing a duty or providing services; or (iv) collecting a citizen’s personal information by purchasing, accepting or exchanging such information in violation of applicable rules and regulations. Pursuant to the Civil Code of the PRC, the collection, storage, use, process, transmission, provision and disclosure of personal information shall follow the principles of legitimacy, properness and necessity.
The Cybersecurity Law provides that network operators shall obtain the individual’s prior consent before collecting the personal information of such individual and take necessary technical measures or other appropriate measures to protect the personal information, and shall not provide the personal information to any third party without the individual’s prior consent unless such personal information has been processed in a proper way that a specific person will not be identified. For the operators of crucial information infrastructure, the personal information and crucial data must be stored within the territory of the People’s Republic of China. Where such data need to be provided to overseas parties due to business requirements, a security assessment shall be conducted before the transmission of the data.
On August 20, 2021, the SCNPC promulgated the Personal Information Protection Law of the PRC (the “Personal Information Protection Law”), which took effect on November 1, 2021. The law aims to protect the rights and interests of personal information and regulate the processing of personal information. The Personal Information Protection Law stipulates certain important concepts with respect to personal information processing: (i) “personal information” refers to all kinds of information related to identified or identifiable natural persons recorded by electronic or other means, excluding the information processed anonymously; (ii) “processing of personal information” includes the collection, storage, use, processing, transmission, provision, disclosure and deletion of personal information, among others; and (iii) “personal information processor” refers to an organization or individual that independently determines the purpose and method of the processing in the processing of personal information.
The Personal Information Protection Law also stipulates the obligations in the circumstance of entrusted processing. Where a personal information processor entrusts others with the processing of personal information, (i) the personal information processor shall agree with the agent on substantial matters like purpose, term, method of entrusted processing, type of information and protection measures, as well as supervise the processing activities of the agent; and (ii) the agent shall process personal information strictly within the scope as agreed, and ensure the security of the personal information processed and assist the personal information processor to perform his legal obligations.
102
Table of Contents
On August 22, 2019, the CAC issued the Regulation on Cyber Protection of Children’s Personal Information, effective on October 1, 2019. Network operators are required to establish special policies and user agreements to protect children’s personal information, and to appoint special personnel in charge of protecting children’s personal information. Network operators who collect, use, transfer or disclose personal information of children are required to, in a prominent and clear way, notify and obtain consent from children’s guardians.
On November 28, 2019, the Secretary Bureau of the CAC, the General Office of the MIIT, the General Office of the Ministry of Public Security and the General Office of the SAMR promulgated the Method for Identifying the Illegal Collection and Use of Personal Information by Apps, which took effect on November 28, 2019 (the “Method”). The Method provides guidance for the regulatory authorities to identify the illegal collection and use of personal information through mobile apps, and for the app operators to conduct self-examination and self-correction and for other participants to voluntarily monitor compliance. The Method lists six types of illegal collection and usage of personal information, including “failure to publish rules on the collection and usage of personal information,” “failure to expressly state the purpose, manner and scope of the collection and usage of personal information,” “collecting and using personal information without obtaining consents from users,” “collecting personal information irrelevant to the services provided,” “providing personal information to other parties without obtaining consent” and “failure to provide the function of deleting or correcting personal information as required by law or failure to publish the methods for complaints and reports or other information”. For a detailed discussion of the risks and uncertainties related to our compliance with regulations on privacy protection, please see “Item 3. Key Information—3.D.Risk Factors—Risks Related to our Business and Industry—Compliance with the rapidly evolving landscape of global data privacy and data security laws may be challenging, and any failure or perceived failure to comply with such laws, or other concerns about our practices or policies with respect to the processing of personal information, could damage our reputation and deter current and potential customers and end users from using our platform and products and services or subject us to significant compliance costs or penalties, which could materially and adversely affect our business, financial condition and results of operations.”
EU, U.K.
The following is a summary of selected data security and privacy laws of the EU and the U.S. We believe that these laws and regulations are relevant to our business operations because certain of our data centers, as well as many of the brands we serve, are located in the EU or the U.S. We believe many of these laws and regulations, such as the General Data Protection Regulation (EU) 2016/679 (the “GDPR”), represent leading standards of data security and privacy in the world, and we have adopted internal controls, policies and procedures that we believe are consistent with the applicable standards under such laws and regulations. We have also completed information security, privacy and compliance certifications and validations from top privacy compliance and cybersecurity firms, such as TrustArc. For more information, see “Item 4. Information on the Company—4.B. Business Overview—Data Security and Privacy.”
103
Table of Contents
The GDPR, which applies to the collection, use, storage, retention, transfer, disclosure and other processing of personal data obtained from individuals located in the EU or by businesses operating within the EU, became effective on May 25, 2018 and has resulted, and will continue to result, in significantly greater compliance burdens and costs for companies with customers, end users, or operations in the EU. The GDPR places stringent obligations and operational requirements on us as both a processor and controller of personal data and could make it more difficult or more costly for us to use and share personal data. For example, requirements placed on data controllers include, among other things, transparent and expanded disclosure to data subjects about how their personal data is to be used, limitations on retention of information, mandatory data breach notification requirements, record keeping and documentation requirements, and higher standards for data controllers to demonstrate that they have obtained valid consent for certain data processing activities. Under the GDPR, data protection supervisory authorities are given various enforcement powers, including levying fines of up to 20 million Euros or up to 4% of an organization’s annual worldwide turnover, whichever is greater, for the preceding financial year, for non-compliance. Data subjects also have the right to be compensated for damages suffered as a result of a controller or processor’s non-compliance with the GDPR. While the GDPR provides a more harmonized approach to data protection regulation across the EU member states, it also gives EU member states certain areas of discretion; and therefore, laws and regulations in relation to certain data processing activities may differ on a member state by member state basis, which could further limit our ability to use and share personal data and could require localized changes to our operating model. In addition to the GDPR, the EU also has released a proposed Regulation on Privacy and Electronic Communications, or the ePrivacy Regulation, to replace the EU’s current Privacy and Electronic Communications Directive, or the ePrivacy Directive, to, among other things, better align EU member states and the rules governing online tracking technologies and electronic communications, such as unsolicited marketing and cookies, with the requirements of the GDPR. While the ePrivacy Regulation was originally intended to be adopted on May 25, 2018 (alongside the GDPR), on February 11, 2025, the European Commission announced the end of the legislative procedure for the ePrivacy Regulation. As the legislative proposal has been formally withdrawn without being reintroduced, we will continue to be subject to the existing ePrivacy Directive and its implementation into national laws across EU member states, mitigating the immediate risk of a sweeping, GDPR-level fining regime specific to electronic communications.
Under the GDPR, restrictions are placed on transfers of personal data outside of the European Economic Area to countries which have not been deemed “adequate” by the European Commission (including the PRC). The Court of Justice of the European Union (the “CJEU”) issued a decision on July 16, 2020, invaliding the EU-US Privacy Shield Framework, which provided one mechanism for lawful cross-border transfers of personal data between the EU and the United States. While the decision did not invalidate the use of the European Commission’s approved standard contractual clauses, another mechanism for making lawful cross-border transfers, the decision has called the validity of standard contractual clauses into question under certain circumstances, and has made the legality of transferring personal data from the EU to the U.S. or various other jurisdictions outside of the EU more uncertain. Specifically, the CJEU stated that companies must now assess the validity of standard contractual clauses on a case-by-case basis, taking into consideration whether the standard contractual clauses provide sufficient protection in light of any access by the public authorities of the third country to where the personal data is transferred, and the relevant aspects of the legal system of such third country. Additionally, in October 2022, President Biden signed an executive order to implement the EU-U.S. Data privacy Framework, which serves as a replacement to the EU-US Privacy Shield. Moreover, on July 10, 2023 the European Commission adopted an adequacy decision concluding that the United States ensures an adequate level of protection for personal data transferred from the EEA to the United States under the EU-U.S. Data Privacy Framework (followed on October 12, 2023 with the adoption of an adequacy decision in the U.K. for the U.K.-US Data Bridge). In September 2025, the EU General Court dismissed an initial legal challenge against the EU-U.S. Data Privacy Framework. However, the adequacy decision remains subject to potential future appeals to the CJEU or challenges by privacy activists, and any resulting legal uncertainty could increase our costs and affect our ability to efficiently process personal data from the EEA. While the European Commission published revised standard contractual clauses for transferring personal data from the EU to third countries, and the European Data Protection Board issued certain recommendations relating to measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, the CJEU’s decision has increased uncertainty surrounding data transfers from the EU to third countries that may not offer the same level of protection for data subjects’ rights as the EU. Due to these recent regulatory changes and guidance, we may need to invest in additional technical, legal and organization safeguards in the future to avoid disruptions to data flows within our business and to and from our customers and service providers. Furthermore, this uncertainty, and its eventual resolution, may increase our costs of compliance, impede our ability to transfer data and conduct our business, and harm our business or results of operations.
104
Table of Contents
Additionally, the withdrawal of the United Kingdom (“U.K.”) from the EU (commonly known as “Brexit”) has created uncertainty with regard to the regulation of privacy and data protection in the U.K. Since January 1, 2021, when the transitional period following Brexit expired, the so-called U.K. GDPR (combining the GDPR and the U.K.’s Data Protection Act of 2018) has been in effect in the U.K. Although the U.K. GDPR currently imposes substantially the same obligations as the GDPR, and currently authorizes similar fines, the U.K. GDPR will not automatically incorporate changes to the GDPR going forward (which would need to be specifically incorporated by the U.K. government). Recently, the U.K. enacted the Data (Use and Access) Act 2025 (the “DUA Act”), which introduces sweeping reforms to the U.K.’s data laws and deviates in certain respects from the EU GDPR. The European Commission has renewed its “adequacy” decision to the U.K., which facilitates the sharing of personal data between the EU and the U.K. until December 2031. However, if not extended after sunset, it may be revoked in the future by the European Commission if the U.K. data protection regime is reformed in ways that deviate substantially from the level of protection currently in place. Adding further complexity for international data flows, in March 2022, the U.K. adopted its own International Data Transfer Agreement for transfers of personal data out of the U.K. to so-called third countries, as well as an international data transfer addendum that can be used with GDPR’s standard contractual clauses for the same purpose. All of this creates a risk of divergent parallel regimes and related uncertainty, along with the potential for increased compliance costs and risks for affected businesses based on differing interpretation and enforcement by regulators and authorities.
United States
In the United States, various federal regulators, including governmental agencies like the Federal Trade Commission, and states and state regulators have adopted, or are considering adopting, laws and regulations concerning personal data and data security, such as the California Consumer Privacy Act, of 2018 (as modified by the California Privacy Rights Act, collectively “CCPA”). This patchwork of legislation and regulation may give rise to conflicts or differing views of personal privacy rights. For example, certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal data than federal, international or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. One such comprehensive privacy law in the United States is the CCPA, which came into effect on January 1, 2020 and was significantly amended as of January 1, 2023. Among other things, the CCPA requires companies that process personal information of California residents to make detailed disclosures to consumers about such companies’ data collection, use and sharing practices, gives California residents expanded rights to access and delete their personal information and to opt out of certain personal information sharing with (and sales of personal information to) third parties. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of personal data that may increase the likelihood of, and risks associated with, data breach litigation. Additionally, the CCPA expands consumers’ rights with respect to certain sensitive personal information, further restricts the use of cross-context behavioral advertising and creates a state agency, the California Privacy Protection Agency, to oversee implementation and enforcement efforts. Amendments have been made to the CCPA, and the California Privacy Protection Agency continues to promulgate complex new regulations, including stringent rules effective in 2026 governing cybersecurity audits, privacy risk assessments, and consumers’ rights regarding Automated Decision-Making Technology (ADMT). As we integrate AI capabilities into our platform, it remains unclear how these evolving provisions will be interpreted and enforced, potentially resulting in further uncertainty and requiring us to continually adapt our data processing practices and incur additional compliance costs. In addition, all 50 states have laws that require the provision of notification for security breaches of personal information to affected individuals, state officers or others. Possible consequences for non-compliance with these various state laws include enforcement actions in response to rules and regulations promulgated under the authority of federal agencies and state attorneys general and legislatures and consumer protection agencies. State laws are changing rapidly and there have been ongoing discussions and proposals in the U.S. Congress with respect to new federal data privacy and security laws to which we would become subject if enacted. All of these evolving compliance and operational requirements impose significant costs that are likely to increase over time, may require us to modify our data processing practices and policies, divert resources from other initiatives and projects, and could restrict the way products and services involving data are offered, all of which may have a material and adverse impact on our business, financial condition and results of operations.
Registration for Import and Export Goods
Pursuant to the Customs Law of the People’s Republic of China promulgated by the SCNPC on January 22, 1987 and last amended on April 29, 2021, unless otherwise stipulated, the declaration of import and export goods may be made by consignees and consignors themselves, and such formalities may also be completed by their entrusted customs brokers that have filed with the Customs. The consignees and consignors for import or export of goods and the customs brokers engaged in customs declaration shall file with the Customs in accordance with the laws.
105
Table of Contents
Pursuant to the Administrative Provisions of the Customs of the People’s Republic of China on the Record Filings of Customs Declaration Entities promulgated by the General Administration of Customs on November 19, 2021, where the consignee or consignor of imported or exported goods or a customs declaration enterprise applies for recordation, it shall obtain the qualification of market entities; particularly where the consignee or consignor of imported or exported goods applies for recordation, it shall be filed as a foreign trade business. Where the consignee or consignor of imported or exported goods or a customs declaration enterprise has undergone the formalities of recordation for customs declaration entities, branches that meet the requirements of the preceding paragraph may also apply for recordation for customs declaration entities.
In addition, the Measures for the Record Filing and Registration of Foreign Trade Business Operators, which was promulgated by MOFCOM on June 25, 2004 and last amended on May 10, 2021, require any foreign trade business operator that is engaged in the import and export of goods or technology shall be registered for archival purposes with the administrative department of foreign trade of the State Council or the institution entrusted thereby, unless it is otherwise provided for by any law, administrative regulation or the foreign trade department of the State Council. The specific measures for archival registration shall be formulated by the foreign trade department of the State Council. Where any foreign trade business operator that fails to file for record and registration according to relevant provisions, the customs may not handle the procedures of customs declarations and release of the import or export goods. On December 30, 2022, the SCNPC promulgated the Decision on Amending the Foreign Trade Law of the PRC, and accordingly foreign trade operators engaged in the import and export of goods or technologies are not required to go through the filing and registration procedures from December 30, 2022.
Regulations Relating to Product Quality
Products made in mainland China are subject to the Product Quality Law of the People’s Republic of China, which was promulgated on February 22, 1993, last amended on December 29, 2018. According to the Product Quality Law, a manufacturer of a product is responsible to compensate for the damages to any person or property caused by the defect of such a product, unless the manufacturer is able to prove that (i) it has not circulated the product; (ii) the defect did not exist at the time when the product was circulated; or (iii) scientific or technological knowledge at the time when the product was circulated was not such that it allowed the defect to be discovered.
The Consumer Rights and Interests Protection Law of the People’s Republic of China (the “Consumers Protection Law”) was promulgated on October 31, 1993 and became effective on January 1, 1994. The Consumers Protection Law has been further revised on August 27, 2009 and October 25, 2013. According to the Consumers Protection Law, unless otherwise provided by this law, an operator that provides products or services may bear civil liability in accordance with the Product Quality Law and other relevant laws and regulations.
According to the Administrative Regulations for Compulsory Product Certification, which was promulgated by the General Administration of Quality Supervision, Inspection and Quarantine P.R.C. (the “AQSIQ”) (which has merged into the State Administration for Market Regulation) on July 3, 2009 and last amended on September 29, 2022, products specified by the state shall not be delivered, sold, imported or used in other business activities until they are certified, or the Compulsory Product Certification, and labeled with China Compulsory Certification mark. For products that are subject to Compulsory Product Certification, the state implements unified product catalogs, or the 3C Catalog, unified compulsory requirements, standards and compliance assessment procedures in technical specification, unified certification marks and unified charging standards.
Regulation Relating to Intellectual Property Rights
Regulation on Patents
The SCNPC adopted the Patent Law of the PRC in 1984 and amended it in 1992, 2000, 2008 and 2020, respectively. A patentable invention or utility model must meet three conditions: novelty, inventiveness and practical applicability. Patents cannot be granted for scientific discoveries, rules and methods for intellectual activities, methods used to diagnose or treat diseases, animal and plant breeding methods of nuclear transformation or substances obtained by means of nuclear transformation. The Patent Office under the State Intellectual Property Office is responsible for receiving, examining and approving patent applications. A patent is valid for a 20-year term for an invention and a 10-year term for a utility model and a 15-year term for a design, starting from the application date. Except under certain specific circumstances provided by law, any third-party user must obtain consent or a proper license from the patent owner to use the patent, or else the use will constitute an infringement of the rights of the patent holder.
106
Table of Contents
Regulation on Copyright
In accordance with the Copyright Law of the PRC which was promulgated by the SCNPC on September 7, 1990 and last amended on November 11, 2020, and took effect on June 1, 2021. Chinese citizens, legal persons or other entities own the copyright in their works whether published or not, including written works; oral works; music, comedy arts of talking and singing, dance and acrobatics; work of art and architecture work; photographic works; cinematographic work and work created by the method similar to the film production method; engineering design drawing, product design drawing, map, sketch and other graphic works and model works; computer software and other works specified by laws and administrative regulations. The rights a copyright owner has include but are not limited to the following rights of the person and property rights: the right of publication, right of authorship, right of modification, right of integrity, right of reproduction, distribution right, rental right, right of network communication, translation right and right of compilation.
In accordance with the Regulations on the Protection of Computer Software promulgated by the State Council on June 4, 1991 and last amended on January 30, 2013, Chinese citizens, legal persons or other entities own the copyright, including the right of publication, right of authorship, right of modification, right of reproduction, distribution right, rental right, right of network communication, translation right and other right software copyright owners shall have in software developed by them, regard less of whether it has been published. In accordance with the Measures for the Registration of Computer Software Copyright promulgated by the National Copyright Administration on February 20, 2002, software copyrights, exclusive licensing contracts for software copyrights and software copyright transfer contracts shall be registered, and the National Copyright Administration shall be the competent authority for the administration of software copyright registration and designates the Copyright Protection Center of China as a software registration authority. The Copyright Protection Center of China shall grant a registration certificate to a computer software copyright applicant who complies with regulations.
Regulation on Trademark
Trademarks are protected by the Trademark Law of the PRC (Revised in 2019), or the Trademark Law, which was promulgated on August 23, 1982 and last amended on April 23, 2019 and come into effect on November 1, 2019, respectively, as well as the Implementation Regulation of Trademark Law of the PRC adopted by the State Council on August 3, 2002 (Revised in 2014). In China, registered trademarks include commodity trademarks, service trademarks, collective marks and certification marks.
The Trademark Office of China National Intellectual Property Administration handles trademark registrations and grants a term of 10 years to registered trademarks. Trademarks are renewable every ten years where a registered trademark needs to be used after the expiration of its validity term. A registration renewal application shall be filed within six months prior to the expiration of the term. A trademark registrant may license its registered trademark to another party by entering into a trademark license contract. Trademark license agreements must be filed with the Trademark Office to be recorded. The licensor shall supervise the quality of the commodities on which the trademark is used, and the licensee shall guarantee the quality of such commodities. The Trademark Law has adopted a “first come, first file” principle with respect to trademark registration. Where a trademark for which a registration application has been made is identical or similar to another trademark which has already been registered or been subject to a preliminary examination and approval for use on the same kind of or similar commodities or services, the application for registration of such trademark may be rejected. Any person applying for the registration of a trademark may not prejudice the existing right first obtained by others, nor may any person register in advance a trademark that has already been used by another party and has already gained a “sufficient degree of reputation” through such party’s use. Trademarks are granted for a term of 10 years. Twelve months prior to the expiration of the ten-year term, the trademark registrant shall apply for the renewal of registration; if the trademark registrant does not make the renewal during the foregoing period, another six-month extension can be granted.
Regulation on Domain Name
In accordance with the Measures for the Administration of Internet Domain Names, which was promulgated by the MIIT on August 24, 2017 and took effect on November 1, 2017, whoever engages in internet domain name services and its operation and maintenance, supervision and administration and other related activities within the territory of the People’s Republic of China shall abide by these Measures.
107
Table of Contents
In accordance with the Notice of the MIIT on Regulating the Use of Domain Names in Internet Information Services, which was promulgated by the MIIT of the PRC on November 27, 2017 and took effect on January 1, 2018, internet access service providers shall verify the identity of each internet information service provider, and shall not provide services to any internet information service provider who fails to provide real identity information.
Regulation Relating to Employment and Social Welfare
Regulation on Labor
Pursuant to the Labor Contract Law of the PRC, which was issued on June 29, 2007, amended on December 28, 2012 and became effective on July 1, 2013, labor contracts shall be concluded in writing if labor relationships are to be or have been established between enterprises or institutions and the laborers. Enterprises and institutions are forbidden to force laborers to work beyond the time limit and employers shall pay laborers for overtime work in accordance with national regulations. In addition, labor wages shall not be lower than local standards on minimum wages and shall be paid to laborers in a timely manner.
According to the Labor Law of the PRC, which was promulgated on July 5, 1994, last amended and became effective on December 29, 2018, enterprises and institutions shall establish and improve their system of work place safety and sanitation, strictly abide by state rules and standards on workplace safety, educate laborers in labor safety and sanitation in the PRC. Labor safety and sanitation facilities shall comply with state-fixed standards.
Enterprises and institutions shall provide laborers with a safe workplace and sanitary conditions that comply with state stipulations and the relevant articles of labor protection.
Regulation on Social Insurance and Housing Fund
In accordance with the Regulation of Insurance for Labor Injury, implemented on January 1, 2004, amended on December 20, 2010 and effective on January 1, 2011, the Provisional Measures for Maternity Insurance of Employees of Corporation, implemented on January 1, 1995, the Decisions on the Establishment of a Unified Program for Basic Old-Aged Pension Insurance of the State Council, issued on July 16, 1997, the Decisions on the Establishment of the Medical Insurance Program for Urban Workers of the State Council promulgated on December 14, 1998, the Unemployment Insurance Measures, promulgated on January 22, 1999, the Social Insurance Law of the PRC, implemented on July 1, 2011 and amended on December 29, 2018, and the Interim Regulations on the Collection and Payment of Social Insurance Premiums, promulgated on January 22, 1999 and amended on March 24, 2019, enterprises are obliged to provide their employees in the PRC with welfare schemes covering pension insurance, unemployment insurance, maternity insurance, labor injury insurance and medical insurance. These payments are made to local administrative authorities and any employer that fails to contribute may be fined and ordered to make up within a prescribed time limit.
In accordance with the Regulations on the Management of Housing Funds, which was promulgated by the State Council on April 3, 1999 and last amended on March 24, 2019, enterprises must register at the competent managing center for housing funds and upon the examination by such managing center of housing funds, these enterprises shall complete procedures for opening an account at the relevant bank for the deposit of employees’ housing funds. Enterprises are also required to pay and deposit housing funds on behalf of their employees in full and in a timely manner.
108
Table of Contents
Regulation Relating to Tax
Enterprise Income Tax
According to the Enterprise Income Tax Law of the PRC, or the EIT Law, and its relevant implementation regulations, taxpayers consist of resident enterprises and non-resident enterprises.
Resident enterprises are defined as enterprises that are established in China in accordance with PRC laws, or that are established in accordance with the laws of foreign countries but whose actual or de facto control is administered from within the PRC. Non-resident enterprises are defined as enterprises that are set up in accordance with the laws of foreign countries and whose actual administration is conducted outside the PRC, but have established institutions or premises in the PRC, or have no such established institutions or premises but have income generated from inside the PRC. Under the EIT Law and relevant implementing regulations, a uniform enterprise income tax rate of 25% is applicable. However, if non-resident enterprises have not formed permanent establishments or premises in the PRC, or if they have formed permanent establishment institutions or premises in the PRC but there is no actual relationship between the relevant income derived in the PRC and the established institutions or premises set up by them, the enterprise income tax is, in that case, set at a rate of 10% for their income sourced from inside the PRC.
According to the EIT Law and relevant implementation regulations, the EIT tax rate of a high and new technology enterprise is 15%. Pursuant to the Administrative Measures for the Recognition of High and New Technology Enterprises, which became effective on January 1, 2008 and amended on January 29, 2016, the certificate of a high and new technology enterprise is valid for three years. An enterprise shall, after being accredited as a high-tech enterprise, fill out and submit the statements on annual conditions concerning the intellectual property rights, scientific and technical personnel, expenses on research and development and operating income for the previous year on the “website for the administration of accreditation of high-tech enterprises.”
The Notice on Taxation Policies for Further Encouraging the Development of the Software and Integrated Circuit Industries, which was promulgated by the Ministry of Finance (the “MOF”) and the State Administration of Taxation (the “SAT”) on April 20, 2012 and became effective on January 1, 2011, and the Notice on Issues Relating to the Preferential Policies for Enterprise Income Tax in Software and Integrated Circuits Industry promulgated by MOF, the SAT, the NDRC and the MIIT on May 4, 2016, provide that, upon certification, newly established integrated circuit design enterprises and eligible software enterprises shall be exempt from the enterprise income tax for the first two years of the preferential period, and shall be levied thereon at half of the statutory rate of 25% for the next three years until the expiration of the preferential period.
Value-Added Tax
The Provisional Regulations of the PRC on Value-added Tax were promulgated by the State Council on December 13, 1993 and came into effect on January 1, 1994, which were subsequently amended on November 10, 2008, February 6, 2016 and November 19, 2017. The Detailed Rules for the Implementation of the Provisional Regulations of the PRC on Value-added Tax (Revised in 2011) was promulgated by the MOF on December 25, 1993 and subsequently amended on December 15, 2008 and October 28, 2011. These rules and regulations are collectively referred to as the VAT Law. On November 19, 2017, the State Council promulgated the Decisions on Abolishing the Provisional Regulations of the PRC on Business Tax and Amending the Provisional Regulations of the PRC on Value-added Tax, or the Order 691. On January 1, 2026, the Order 691 was repealed by the Value-added Tax Law of the PRC(the “VAT Law”), which was promulgated by the National People’s Congress Standing Committee(the “NPCSC”) on December 25, 2024. Under the VAT Law, the VAT rate, for selling goods, providing processing, repair and replacement services and tangible movables leasing services or importing goods will be 13%, for selling transport services, postal services, basic telecommunications, buildings, real property, or real property leasing services, transferring land use rights, or selling or importing certain goods specified in the VAT Law will be 9%, for selling services or intangible assets will be 6%, and for exporting goods will be 0%, and the levy rate of VAT to which the simple tax computation method applies is 3%.
109
Table of Contents
Dividend Withholding Tax
Furthermore, pursuant to the Notice of the SAT on the Issues Concerning the Application of the Dividend Clauses of Tax Agreements, which was promulgated and effective on February 20, 2009, all of the following requirements should be satisfied where a fiscal resident of the other party to the tax agreement needs to be entitled to such tax agreement treatment as being taxed at a tax rate specified in the tax agreement for the dividends paid to it by a PRC resident company: (i) such a fiscal resident who obtains dividends should be a company as provided in the tax agreement; (ii) owner’s equity interests and voting shares of the PRC resident company directly owned by such a fiscal resident reaches a specified percentage; and (iii) the equity interests of the PRC resident company directly owned by such a fiscal resident, at any time during the 12 months prior to the acquisition of the dividends, reaches a percentage specified in the tax agreement.
In addition, according to the Announcement of the State Taxation Administration on Issuing the Measures for Non-resident Taxpayers’ Enjoyment of Treaty Benefits, promulgated by the SAT on October 14, 2019 and became effective on January 1, 2020, where a non-resident enterprise that receives dividends from a PRC resident enterprise wishes to enjoy the favorable tax benefits under the convention treatment, it may be entitled to the convention treatment itself when filing a tax return or making a withholding declaration through a withholding agent, subject to the subsequent administration by the tax authorities.
Regulation Relating to Foreign Exchange
Pursuant to the Foreign Exchange Administration Regulations of the PRC, as amended in August 5, 2008, RMB is freely convertible for current account items, including the distribution of dividends, interest payments, trade and service-related foreign exchange transactions, but not for capital account items, such as direct investments, loans, repatriation of investments and investments in securities outside China, unless the prior approval of SAFE is obtained and prior registration with SAFE is made. On May 10, 2013, SAFE promulgated the Notice of the SAFE on Issuing the Provisions on the Foreign Exchange Administration of Domestic Direct Investment of Foreign Investors and the Supporting Documents, or the SAFE Circular No. 21, which was amended on October 10, 2018 and December 30, 2019. SAFE Circular No. 21 provided and simplified the operational steps and regulations on foreign exchange matters related to direct investment by foreign investors, including foreign exchange registration, account opening and use, receipt and payment of funds, and settlement and sales of foreign exchange.
Pursuant to the Notice of the SAFE on Further Improving and Adjusting Foreign Exchange Administration Policies for Direct Investment, or the SAFE Circular No. 59, which was promulgated by SAFE on November 19, 2012, became effective on December 17, 2012 and was further amended on May 4, 2015, October 10, 2018, December 30, 2019, and December 4, 2023, approval is not required for the opening of an account entry in foreign exchange accounts under direct investment. SAFE Notice No. 59 also simplified the capital verification and confirmation formalities for foreign invested entities, the foreign capital and foreign exchange registration formalities required for the foreign investors to acquire equities from a Chinese party, and further improved the administration on exchange settlement of foreign exchange capital of foreign invested entities.
Pursuant to the Notice of the SAFE on Issues concerning Foreign Exchange Administration of the Overseas Investment and Financing and the Round-tripping Investment Made by Domestic Residents through Special-Purpose Companies, or the SAFE Circular No. 37, which was promulgated by SAFE and became effective on July 4, 2014, (i) a PRC resident shall register with the local SAFE branch before he or she contributes assets or equity interests in an overseas SPV that is directly established or controlled by such PRC resident for the purpose of conducting investment or financing; and (ii) following the initial registration, such PRC resident is also required to register with the local SAFE branch for any major change, in respect of the overseas SPV, including, among other things, a change of the overseas SPV’s PRC resident shareholder(s), name of the overseas SPV, term of operation, or any increase or reduction of the overseas SPV’s registered capital, share transfer or swap, and merger or division. Pursuant to SAFE Circular No.37, failure to comply with these registration procedures may result in penalties.
Pursuant to the Notice of the SAFE on Further Simplifying and Improving Policies for the Foreign Exchange Administration of Direct Investment, or the SAFE Circular 13, which was promulgated on February 13, 2015, became effective on June 1, 2015 and was further amended on December 30, 2019, the foreign exchange registration under domestic direct investment and the foreign exchange registration under overseas direct investment is directly reviewed and handled by banks in accordance with the SAFE Circular 13, and the SAFE and its branches shall perform indirect regulation over the foreign exchange registration via banks.
110
Table of Contents
Regulation Relating to Dividend Distribution
The Company Law is the principal law that governs the dividends distribution by companies in the PRC and it applies to both PRC domestic companies and foreign-invested companies. Foreign-invested companies are also subject to the relevant requirements under the Foreign Investment Law and its implementing rules. Under these laws, regulations and rules, both domestic companies and foreign-invested companies in the PRC are required to set aside as general reserves at least 10% of their after-tax profit, until the cumulative amount of their reserves reaches 50% of their registered capital. PRC companies are not permitted to distribute any profits until any losses from prior fiscal years have been offset. Profits retained from prior fiscal years may be distributed together with distributable profits from the current fiscal year.
Regulations Relating to Employee Equity Incentive Plan
Pursuant to the SAFE Circular 37, PRC residents who participate in equity incentive plan in overseas non-publicly listed companies may submit applications to SAFE or its local branches for the foreign exchange registration with respect to offshore special purpose companies. In addition, pursuant to the Notice of Issues Related to the Foreign Exchange Administration for Domestic Individuals Participating in Stock Incentive Plan of Overseas Listed Company, or the SAFE Circular 7, which was issued by the SAFE on February 15, 2012, employees, directors, supervisors, and other senior management participating in any equity incentive plan of an overseas publicly listed company who are PRC citizens or who are non-PRC citizens residing in China for a continuous period of not less than one year, subject to a few exceptions, are required to register with SAFE through a domestic agency as regulated in SAFE Circular 7.
In addition, the SAT has issued certain circulars concerning employee stock options and restricted shares, including the Circular on Issues Concerning the Individual Income Tax on Share-option Incentives, or the SAT Circular 461, which was promulgated and took effect on August 24, 2009, and the Notice on Measures Enhancing the Reform in Taxation and Stimulating the Vitality of Market Players which was promulgated and took effect on October 12, 2021. Under the SAT Circular 461 and other relevant laws and regulations, employees working in the PRC who exercise stock options or are granted restricted shares will be subject to PRC individual income tax. The PRC subsidiaries of an overseas listed company are required to file documents related to employee stock options and restricted shares with relevant tax authorities and to withhold individual income taxes of employees who exercise their stock option or purchase restricted shares. If the employees fail to pay or the PRC subsidiaries fail to withhold income tax in accordance with relevant laws and regulations, the PRC subsidiary may face sanctions imposed by the tax authorities or other PRC government authorities.
Regulation Relating to M&A and Overseas Listing
The Regulations on Mergers and Acquisitions of Domestic Enterprises by Foreign Investors (the “M&A Rules”) was promulgated by six PRC ministries, including MOFCOM, the State-owned Assets Supervision and Administration Commission of the State Council, the SAT, the SAMR, the CSRC, and the SAFE, on August 8, 2006, and was amended and became effective on June 22, 2009. The M&A Rules stipulate that a foreign investor is required to obtain necessary approvals when it (i) acquires the equity of a domestic enterprise so as to convert the domestic enterprise into a foreign-invested enterprise; (ii) subscribes for the increased capital of a domestic enterprise so as to convert the domestic enterprise into a foreign-invested enterprise; (iii) establishes a foreign-invested enterprise through which it purchases the assets of any domestic enterprise and operates these assets; or (iv) purchases the assets of a domestic enterprise, and then invests such assets to establish a foreign-invested enterprise. The M&A Rules, among other things, further prescribed that a special purpose vehicle, formed for overseas listing purposes and controlled directly or indirectly by PRC companies or individuals, shall be approved by MOFCOM prior to its establishment and obtain the approval of the CSRC prior to the listing and trading of such special purpose vehicle’s securities on an overseas stock exchange.
Pursuant to the Notice of the Foreign Investment Administration of the MOFCOM on Distributing the Manual of Guidance on Administration for Foreign Investment Access, which was issued and became effective on December 18, 2008 by MOFCOM, notwithstanding the fact that (i) the domestic shareholder is connected with the foreign investor or not, or (ii) the foreign investor is the existing shareholder or the new investor, the M&A Rules shall not apply to the transfer of an equity interest in an incorporated foreign-invested enterprise from the domestic shareholder to the foreign investor.
111
Table of Contents
On February 17, 2023, the CSRC released the Trial Administrative Measures of Overseas Securities Offering and Listing by Domestic Companies, or the Trial Measures, and relevant supporting guidelines, collectively, the New Overseas Listing Rules, setting out new filing procedures for China-based companies seeking direct or indirect listings and offerings in overseas markets, which came into force since March 31, 2023. The New Overseas Listing Rules are applicable to PRC domestic companies that seek to offer and list securities in overseas markets, either through direct or indirect means. If an issuer meets both of the following criteria, the overseas securities offering and listing conducted by such issuer shall be deemed to be an indirect overseas offering subject to the filing procedures set forth under the New Overseas Listing Rules: (i) 50% or more of the issuer’s operating revenue, total profit, total assets or net assets as documented in its audited consolidated financial statements for the most recent fiscal year are derived from PRC domestic companies; and (ii) the issuer’s business activities are substantially conducted in mainland China, or its principal place(s) of business are located in mainland China, or the senior managers in charge of its business operations and management are mostly Chinese citizens or domiciled in mainland China. Pursuant to the New Overseas Listing Rules, an issuer listed in an overseas market that intends to effect any follow-on offering in the same overseas market where it has previously offered and listed securities should, through its major operating entity incorporated in the PRC, file relevant materials with the CSRC within three business days after the completion of any such follow-on offering.
Furthermore, according to New Overseas Listing Rules, after an issuer has completed its offering and listed its securities on an overseas stock exchange, the issuer shall submit a report to the CSRC within three business days after the occurrence and public disclosure of any material events, including: (i) a change of control; (ii) investigations of or sanctions imposed on the issuer by overseas securities regulatory agencies or other relevant competent authorities; (iii) changes of listing status or transfers of the listing segment; and (iv) a voluntary or mandatory delisting.
The New Overseas Listing Rules provide that in the event of any breach, including any failure to fulfill the filing procedure, or any offering and listing of securities in an overseas market in violation of the measures, the CSRC will order such domestic company to rectify, issue warnings to such domestic company, and impose a fine between RMB1 million and RMB10 million. Fines and warnings will be imposed on persons-in-charge and other persons who are directly liable. In addition, fines will also be imposed on controlling shareholders and actual controllers of the domestic company who initiate or cause the noncompliance activities described above.
In addition, the CSRC and other three relevant government authorities jointly promulgated the Provisions on Strengthening the Confidentiality and Archives Administration of Overseas Securities Offering and Listing by Domestic Companies (the “Provision on Confidentiality”) on February 24, 2023, which implemented on March 31, 2023. Pursuant to the Provision on Confidentiality, when a domestic company provides or publicly discloses the documents and materials involving state secrets and working secrets of state organs to the relevant securities companies, securities service institutions, overseas regulatory authorities and other entities and individuals, or provides or publicly discloses such the documents and materials through its overseas listing subjects, it shall report to the competent authority with the examination and approval authority for approval, and file with the same level secrecy administration department in accordance with the law. Domestic companies providing accounting archives or copies thereof to entities and individuals such as securities companies, securities service institutions and overseas regulatory authorities shall perform the corresponding procedures according to relevant national regulations. The working papers formed within the territory of the PRC by the securities companies and securities service institutions that provide related securities services for the overseas offering and listing of domestic enterprises shall be kept within the territory of the PRC. Cross-border transferring of such working papers shall go through the examination and approval formalities in accordance with the relevant national regulations.
112
Table of Contents
4.C.Organizational Structure
The following chart illustrates our corporate structure, including our significant subsidiaries as that term is defined under Section 1-02 of Regulation S-X under the Securities Act and certain other subsidiaries, as of the date of this annual report.
Historical Contractual Arrangements with the Former VIE and the Former VIE’s Registered Shareholders
Tuya Inc. is a Cayman Islands holding company and conducts its operations in China mainly through its PRC subsidiaries.
Investment in certain areas of the industries in which we currently operate and may operate are subject to restrictions under current PRC laws and regulations. After consultation with Jia Yuan Law Offices, our PRC legal counsel, we determined that it was not viable for us to hold Hangzhou Tuya Technology, the former VIE, directly through equity ownership. Instead, we decided that, in line with common practice in the PRC for industries subject to foreign investment restrictions, we would gain effective control over, and receive all the economic benefits generated by the businesses currently operated by the former VIE through the historical contractual arrangements between Tuya Information, on the one hand, and the former VIE and the registered shareholders, on the other hand. As a result of these historical contractual arrangements, we exerted effective control over the former VIE, and were considered the primary beneficiary of the former VIE for accounting purposes and consolidated its operating results in our financial statements under the U.S. GAAP.
113
Table of Contents
The former VIE did not contribute any revenue in 2023, 2024 or 2025. As of December 31, 2024 and its deregistration in November 2025 the assets of the former VIE, excluding amounts due from other companies in our group, represented less than 0.01% of our consolidated total assets on both dates. Additionally, the former VIE did not hold any licenses or permits that were material to our current business operations.
The historical contractual arrangements between Tuya Information, on the one hand, and the former VIE and its registered shareholders, on the other hand, were initially entered into in December 2014 and were amended and restated in January 2022. The following is a summary of these historical contractual arrangements. For the complete text of these historical contractual arrangements, please see the copies filed as exhibits to this annual report.
In the opinion of Jia Yuan Law Offices, our PRC legal counsel, the execution and performance of the historical contractual arrangements did not violate the provisions of the Civil Code of the PRC which might have led to their invalidity, and were binding on the parties thereto. The historical contractual arrangements could be enforced in accordance with PRC laws, except that the following arrangement might not have been enforceable under PRC laws: (i) the historical contractual arrangements provided that the arbitrator might impose restrictions on and/or dispose of the former VIE’s equity interests or land and other assets (such as for award of remedies), grant injunction (such as for the conduct of business or compelling the transfer of assets), or grant other interim relief, or order winding up of our consolidated affiliated entity through arbitration, and that the courts with jurisdiction (including the courts in Hong Kong, the place of incorporation of the Company, the place of incorporation of the former VIE, and the place where the principal assets of our company or the former VIE were located) had the right to grant interim relief in support of the arbitration, while under PRC laws, an arbitral body had no power to grant injunctive relief and might not directly issue a provisional or final liquidation order for the purpose of protecting assets of or equity interests in the former VIE in case of disputes. In addition, interim remedies or enforcement orders granted by overseas courts such as Hong Kong and the Cayman Islands may not be recognizable or enforceable in China, and (ii) the historical contractual arrangements provided that when the former VIE was liquidated or dissolved, persons recommended by Tuya Information were to be appointed as permitted by the PRC laws to establish a liquidation team to manage the assets of the former VIE.
In order to streamline our corporate structure and considering the changing regulatory environment, we had deregistered the former VIE in November 2025. Despite such deregistration, there are substantial uncertainties regarding the interpretation and application of current or future PRC laws and regulations. We have been further advised by our PRC legal counsel that if the PRC government were to find that the agreements that established the historical VIE structure did not comply with applicable PRC laws and regulations, we could be subject to penalties. For a detailed discussion of the risks and uncertainties related to these historical contractual arrangements and our corporate structure, please see “Item 3. Key Information – 3.D. Risk Factors—Risks Related to Our Corporate Structure.”
Exclusive Business Cooperation Agreement
Under this exclusive business cooperation agreement, Tuya Information agreed to provide the following services to Hangzhou Tuya Technology:
● the licensing of software legally owned by Tuya Information;
● the development, maintenance and update of software involved in Hangzhou Tuya Technology’s business;
● the design, installation, daily management, maintenance and updating of network system, hardware and database design;
● the technical support and training for employees of Hangzhou Tuya Technology;
● the assistance in consultancy, collection and research of technology and market information (excluding market research business that wholly foreign-owned enterprises are prohibited from conducting under PRC law);
● the provision of business management consultation;
● the provision of marketing and promotion services;
114
Table of Contents
● the leasing of equipment or properties; and
● other services requested by Hangzhou Tuya Technology from time to time to the extent permitted under PRC law.
Hangzhou Tuya Technology agreed to pay services fees to Tuya Information on a regular basis in discretion of Hangzhou Tuya Technology after considering certain factors as specified in the exclusive business cooperation agreement. The service fee were to be equivalent to the total income of Hangzhou Tuya Technology of each financial year, deducting the costs, expenses, taxes (excluding corporate income tax) and other statutory fees reserved or withdrawn. Hangzhou Tuya Technology were to pay the service fee to the bank account designated by Tuya Information within 10 days after receiving notice and bill from Tuya Information. This agreement was effective from December 23, 2014 and was to remain to be effective unless terminated by written notice of Tuya Information or according to the provisions in the agreement. Unless otherwise required by applicable laws, Hangzhou Tuya Technology did not have any right to terminate this exclusive business cooperation agreement in any event.
Equity Interest Pledge Agreement
Xueji (Jerry) Wang, one of the shareholders of Hangzhou Tuya Technology, entered into an equity pledge agreement with Tuya Information and Hangzhou Tuya Technology, originally dated December 23, 2014 and amended and restated on August 23, 2019 and January 19, 2022, respectively. Each of Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen, the shareholders of Hangzhou Tuya Technology, entered into an equity pledge agreement with Tuya Information and Hangzhou Tuya Technology, each originally dated December 23, 2014, amended on August 23, 2019 and amended and restated on January 19, 2022. Under such equity interest pledge agreements, each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen pledged his or her respective equity interest in Hangzhou Tuya Technology to Tuya Information to secure his or her obligations under the applicable exclusive business cooperation agreement, exclusive option agreement, and powers of attorney. Each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen further agreed to not transfer or pledge his or her respective equity interest in Hangzhou Tuya Technology without the prior written consent of Tuya Information. As the date of this annual report, the equity pledges under the equity interest pledge agreement had been terminated due to the deregistration of Hangzhou Tuya Technology in November 2025.
Exclusive Option Agreement
Under the exclusive option agreement entered into by Tuya Information, Hangzhou Tuya Technology and Xueji (Jerry) Wang, originally dated December 23, 2014 and amended and restated on August 23, 2019 and January 19, 2022, respectively, and the exclusive option agreements entered into by Tuya Information, Hangzhou Tuya Technology and each of Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen, each originally dated December 23, 2014 and amended and restated on January 19, 2022, each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen granted Tuya Information an option to purchase all or a portion of his or her respective equity interest in Hangzhou Tuya Technology at a price equal to the higher of RMB1.0 and the minimum amount of consideration permitted by PRC law. In addition, under each exclusive purchase option agreement, Hangzhou Tuya Technology has granted Tuya Information an option to purchase all or a portion of the assets held by Hangzhou Tuya Technology or its subsidiaries for the minimum amount of consideration permitted by PRC law. Each of Hangzhou Tuya Technology, Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen agrees that, in the event that Tuya Information exercises the equity interest purchase option or the asset purchase option, all the consideration received by them for this purpose will be fully returned to Tuya Information upon the request of Tuya Information, as long as in compliance with the PRC laws and regulations. Each of Hangzhou Tuya Technology, Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen agreed not to transfer, mortgage or permit any security interest to be created on any equity interest in or material assets of Hangzhou Tuya Technology without the prior written consent of Tuya Information. Each exclusive purchase option agreement shall remain in effect until all of the equity interests in Hangzhou Tuya Technology have been acquired by Tuya Information.
115
Table of Contents
Power of Attorney
Pursuant to a series of powers of attorney issued by each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen and accepted by Tuya Information on January 19, 2022, each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen irrevocably appointed Tuya Information or any designated person as their exclusive agent and attorney to act on their behalf on all shareholder matters of Hangzhou Tuya Technology and exercise all rights as shareholders of Hangzhou Tuya Technology. Each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen will provide full assistance to Tuya Information with respect to the exercise of such rights. Each of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen has undertaken that he or she will refrain from any action or omission that may cause any conflict of interest between himself and Tuya Information. These powers of attorney shall remain valid during the period that each of them is a shareholder of Hangzhou Tuya Technology.
Spousal Consent
Each spouse of Xueji (Jerry) Wang, Liaohan (Leo) Chen, Yaona Lin, Ruixin Zhou and Peihong Chen has signed a spousal consent. Under each spousal consent, the signing spouse agreed that the equity interests of Hangzhou Tuya Technology held and to be held by his/her spouse are his/her spouse’s personal property and do not constitute the communal estate marital assets of the signing spouse. The signing spouse unconditionally and irrevocably undertook to waive any rights or interests in such assets and not to make any assertions in connection with the equity interests in Hangzhou Tuya Technology held by his/her spouse. Moreover, each spouse agreed that the disposition of the equity interest in Hangzhou Tuya Technology which is held by and registered under the name of his/her spouse shall be made pursuant to the above-mentioned exclusive business cooperation agreement, exclusive option agreement and powers of attorney, as amended from time to time. In addition, in the event that any of them obtains any equity interest in Hangzhou Tuya Technology held by their respective spouses for any reason, such spouse agreed to be bound by similar obligations and agreed to enter into similar contractual arrangements. Each signing spouse undertook that in the event of death, bankruptcy, incapacity, divorce of his/her spouse, or any circumstance that may affect the exercise of his shareholder rights in Hangzhou Tuya Technology, the signing spouse will not, under any circumstances and in any way, take any action that may affect or hinder the obligations of her spouse under the above contractual arrangements.
4.D.Property, Plant and Equipment
Our principal executive office is located in Hangzhou, China under a lease that will expire in 2026. In addition, we operate internationally with local headquarters in Europe, Singapore, India, Japan and Colombia, among other locations. As of December 31, 2025, we leased seven properties with a gross floor area of approximately 19,700.1 square meters in China. These offices are leased, and we do not own any real property. We believe that our current facilities are adequate to meet our current needs.