$ cat /legal/privacy.md

// privacy_policy

Last Updated: 2024-12-25 | Version: 2.0

privacy.md

/**
* Shenzhen Xingwen Artificial Intelligence Co., Ltd. (hereinafter referred to as "we" or "AskAIs")
* understands the importance of personal information to you. We will take appropriate
* security measures in accordance with legal requirements to protect your personal information.
*/

This Privacy Policy applies to all products and services provided by AskAIs. Please carefully read and fully understand this policy, especially the provisions marked in bold/underlined, before using our services.

00. Legal Basis and Scope of Application

This policy is formulated in accordance with the following laws and regulations:

- Cybersecurity Law of the People's Republic of China

- Data Security Law of the People's Republic of China

- Personal Information Protection Law of the People's Republic of China

- Interim Measures for the Management of Generative Artificial Intelligence Services

- Provisions on the Management of Algorithmic Recommendations for Internet Information Services

- Hong Kong Personal Data (Privacy) Ordinance (applicable to Hong Kong users)

- Other applicable laws and regulations

Applicable Entity:Shenzhen Xingwen Artificial Intelligence Co., Ltd.
Unified Social Credit Code:[Company Credit Code]
Registered Address:Shenzhen, Guangdong Province, China

01. Collection of Personal Information

We only collect your personal information within lawful, legitimate, and necessary scope:

1.1 Account Registration Information

- Phone number/email address (for account registration and identity verification)

- Username/nickname (for account identification)

- Password (encrypted storage for account security)

- Third-party login information (such as WeChat OpenID, only authorized information obtained)

1.2 Real-Name Verification Information (if applicable)

- Real name (enterprise users need to provide company name)

- ID number/Unified Social Credit Code

- Contact address (for invoice and contract delivery)

1.3 Service Usage Information

- Conversation records (your interactions with AI)

- Uploaded files and documents

- Generated content and output results

- Usage preferences and settings

1.5 Device and Network Information

- Device model, operating system, unique device identifiers

- IP address, network carrier information

- Browser type, language settings

- Access date, time, and duration

⚠️ Sensitive Information Notice:
We do not actively collect sensitive personal information such as race, ethnicity, religious beliefs, biometric data, medical health, or financial account information. If collection is necessary for services, we will obtain your explicit consent separately.

02. Data Storage and Cross-Border Transfer

To ensure data security and compliance, we adopt a regional storage strategy:
Mainland China users: Data stored on servers within Mainland China
Hong Kong and international users: Data stored on Hong Kong servers

Storage Location: We automatically assign data storage locations based on your registration region to ensure compliance with local regulations.

Retention Period: We only retain your personal information for the period necessary to provide services. After account cancellation, we will delete or anonymize your personal information within 30 business days, unless otherwise required by law.

Cross-Border Transfer: If cross-border data transfer is required for business purposes, we will ensure your personal information security through standard contracts and security assessments in accordance with the Personal Information Protection Law.

03. Use of Personal Information

We strictly follow the principles of lawfulness, legitimacy, and necessity, using your personal information within the following scope:

- Service Provision: Providing core functions such as AI chat, document generation, and task management

- Identity Verification: Verifying your identity and ensuring account security

- Customer Service: Responding to your inquiries, complaints, and suggestions

- Service Improvement: Analyzing usage data to optimize product experience (de-identified)

- Security Protection: Preventing, detecting, and investigating fraud and illegal activities

- Notifications: Sending service notices and security alerts (can be disabled)

- Legal Compliance: Complying with laws, regulations, and regulatory requirements

AI Model Training Notice:
In accordance with the 'Interim Measures for the Management of Generative AI Services', if your data may be used for AI model training optimization, we will obtain your separate consent and only use de-identified data. You have the right to refuse, which will not affect your use of basic services.

04. Personal Information Security Protection

We adopt industry-leading technical measures and management methods to protect your personal information:

Technical Measures

TLS 1.3 encrypted transmission

AES-256 encrypted data storage

Tiered access permission management

Sensitive data desensitization

Intrusion detection and prevention systems

Management Measures

Information security management system

Employee confidentiality agreements

Regular security training

Third-party security audits

Emergency response plans

Security Incident Response:
In the event of a personal information security incident, we will promptly inform you of the basic situation, potential impact, measures taken, and preventive measures you can take, in accordance with legal requirements. If individual notification is difficult, we will issue a public announcement through reasonable and effective means.

05. Sharing, Transfer, and Disclosure of Personal Information

We will not sell your personal information. We only share or disclose your information in the following circumstances:

5.1 Sharing with Your Consent

With your explicit consent, we may share information with third parties you designate.

5.2 Sharing with Affiliates

We may share necessary personal information with affiliates to provide better services.

5.3 Sharing with Authorized Partners

Including but not limited to cloud service providers, payment service providers, SMS/email service providers. We sign strict confidentiality agreements with them.

5.4 Legally Required Disclosure

In accordance with laws, regulations, litigation dispute resolution needs, or lawful requests from administrative or judicial authorities.

5.5 Business Changes

In the event of merger, acquisition, or asset transfer, we will ensure the successor continues to fulfill this policy's obligations.

06. Your Rights

In accordance with the Personal Information Protection Law and related regulations, you have the following rights regarding your personal information:

Right to Know

Understand how we process your personal information

Right to Decide

Independently decide whether to consent to personal information processing

Right to Access

Access and obtain copies of your personal information

Right to Correct

Correct inaccurate or incomplete personal information

Right to Delete

Request deletion of your personal information

Right to Withdraw Consent

Withdraw previously given consent

Right to Portability

Transfer your personal information to other processors

Right to Account Cancellation

Cancel your account and delete related information

To exercise the above rights, please contact: privacy@askais.com
We will respond within 15 business days of receiving your request.

07. Cookies and Similar Technologies

To ensure proper website operation and provide a better user experience, we use the following technologies:

Essential Cookies

Used for identity verification and session management, cannot be disabled

Functional Cookies

Remember your preference settings such as language and theme

Analytics Cookies

Help us understand website usage and improve services

// You can manage cookies through browser settings. For details, see our Cookie Policy

08. Protection of Minors

Important Notice:
This service is intended for users 18 years of age and older. If you are a minor under 18, please read this policy with the guidance of a guardian and use our services only with guardian consent.

We will protect minors' personal information in accordance with relevant national laws and regulations. If we discover that personal information was collected from a minor without guardian consent, we will promptly delete the relevant data.

09. Automated Decision-Making

Our AI services may make automated decisions through algorithms. Under the Personal Information Protection Law, you have the right to request explanations and to refuse decisions made solely through automated decision-making that significantly affect your rights. If you have objections to automated decision results, please contact us for manual review.

10. Privacy Policy Updates

We may update this Privacy Policy from time to time. For significant changes, we will notify you in advance through site notifications, email, or pop-ups. If you continue to use our services after the policy update, you agree to accept the updated policy. We recommend checking this page regularly for the latest privacy protection information.

11. Complaints and Reports

If you believe our personal information processing has infringed your legitimate rights, you may seek recourse through the following channels:

- Contact our privacy protection officer

- File complaints with cyberspace administration, market regulation departments, or other competent authorities

- File a lawsuit with a competent court

12. Contact Us

Company Name: Shenzhen Xingwen Artificial Intelligence Co., Ltd.

Registered Address: Shenzhen, Guangdong Province, China

Privacy Email: privacy@askais.com

Customer Support: support@askais.com

// We will verify and process your feedback as soon as possible, generally within 15 business days

13. Supplementary Terms for Hong Kong and International Users

For Hong Kong Users:
This policy complies with the requirements of the Hong Kong Personal Data (Privacy) Ordinance (PDPO). You may file complaints with the Office of the Privacy Commissioner for Personal Data, Hong Kong.

For Users in Other Regions:
If you are located in the EU/European Economic Area, we will comply with the General Data Protection Regulation (GDPR), including but not limited to data subject rights, lawful bases, and cross-border transfer mechanisms.

// By using AskAIs services, you acknowledge that you have read, understood, and agreed to this Privacy Policy | Terms of Service

<AI Document />

> ready_