Effective Date: ________, 2026
We place paramount importance on protecting your personal data. Please read carefully and fully understand this Privacy Policy (hereinafter referred to as the “Policy”) before using this Website. This Policy sets out how we collect, use, store, share and protect your personal data, and the data rights you are entitled to. Should you have any questions regarding this Policy, please reach us through the contact details stated at the end.
I. Scope of Application
- 1.1 This Policy applies to all activities you perform on this Website, including but not limited to account registration, page browsing, order placement, AI functionality access, online consultation and form submission.
- 1.2 This Policy complies with the following applicable laws and regulations: European Union’s General Data Protection Regulation (GDPR), ePrivacy Directive, Singapore’s Personal Data Protection Act (PDPA), California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), as well as Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
- 1.3 Third-party services embedded in this Website shall abide by their own privacy policies. By using any third-party service, you are deemed to have read, understood, and agreed to that service’s privacy policy.
II. Types of Collected Personal Data
- 2.1 Account and Identity Information (User-submitted Data)
We collect the following information you actively provide during service use:
- Account registration information: name, company name, email address, phone number, login password and cookies;
- Contact information: phone number, shipping address and billing address (for paying users);
- Transaction information: order records, commodities and service details, payment status and invoice information;
- Communication data: online consultation content, AI chat prompts and inquiry descriptions;
- User-generated content: texts, images, videos and commodity descriptions uploaded to this Website.
- 2.2 Automated Data Collection
We collect data automatically using website automation tools, server logs and AI activity logs:
- Device data: browser type, operating system version, device model, screen resolution, language settings;
- Network identifiers: anonymized IP address, access timestamp, page browsing history;
- User interactions: feature click journeys, page dwell time, bounce rate, referral sources;
- AI invocation logs: AI chat prompts, AI-generated content summaries, feature invocation frequency, session duration;
- Cookie data: See Section 7 Cookie Policy of this Policy
- 2.3 Data from Third Parties
We may obtain your personal data from third-party providers in the following circumstances:
- Third-party payment processor (Stripe): transaction confirmation, payment status and billing details;
- Instant messaging service provider (Sendbird): online consultation records and message content;
- AI service providers: returned chat content, technical logs and invocation status;
- Data analytics tool (Google Analytics): aggregated usage statistics.
- 2.4 Sensitive Personal Data Statement: We do not voluntarily collect sensitive personal data including ethnicity, religious beliefs, health status, financial account details, identification numbers and precise geolocation, unless necessary for service provision and permitted by your explicit consent. Do not include such sensitive data in AI chat inputs. AI service providers may process submitted content under their own privacy policies.
III. Purposes of Data Processing
- 3.1 We adhere strictly to the “data minimization” principle, and process your personal data only to the extent necessary for the purposes below:
- Service delivery: provision of contracted services including core website functions, AI-generated content, online consultation and order processing;
- Account administration: account registration, identity authentication, security protection and anomaly detection (legal basis: performance of contract);
- Customer support: inquiry response, complaint handling and technical assistance;
- Security protection: risk control, fraud prevention, abnormal access detection, DDoS mitigation and cyber intrusion defense;
- AI functionality improvement: enhancement of AI response quality and scenario adaptability via de-identified data;
- Compliance obligations: fulfilment of statutory retention requirements, cooperation with law enforcement requests and tax compliance;
- Marketing communications: delivery of promotional notifications (conducted solely upon your explicit consent, which may be withdrawn at any time).
- 3.2 Your personal data shall not be processed for new purposes without reasonable connection to the aforesaid intentions. We will notify you in advance and obtain requisite consent prior to any new data processing activities.
IV. Specific Rules Governing AI Data Processing
- 4.1 Processing Specifications for AI Integration Services
We deliver AI functionalities via the below service providers, with relevant data processing specifications specified as follows:
- Google Gemini/OpenAI/Anthropic Claude: AI-generated content with large language models; data hosted in the United States; user data not utilized for model training by default;
- Microsoft Azure AI Model: enterprise-grade AI inference service; Zero Data Retention enabled by default; prompts and responses not stored by Microsoft;
- LangChain (edge layer, site protection, AI Copilot): edge acceleration, security defense and conversational AI services; LangChain commits not to sell user personal data to third parties;
- Tavily AI URL Search: real-time web search service; search results not retained long-term and not utilized for advertising purposes.
- 4.2 Consent Rules for Model Training
- Your chat prompts and AI-generated content shall not be used for fundamental model training or fine-tuning by default;
- Should we intend to leverage de-identified data for optimization of the platform’s AI functionalities, separate explicit consent via dedicated consent tickbox will be acquired. You may submit an opt-out request via our designated email address at any time. We will cease relevant data usage and erase original data within 30 days, excluding data irreversibly integrated into model parameters;
- Anonymized aggregated statistical data may be applied for AI service quality assessment without additional user consent.
- 4.3 Ownership and Review Accountability of AI-generated Content
- Intellectual property ownership: The compiled and organized AI-generated content shall vest in our company. Relevant provisions are stipulated in Clause 7 of the Terms of Service;
- AI output risk notice: AI-generated content may contain misinterpretation, irrelevant replies, logical flaws and factual errors. Users shall not represent AI-generated content as fully manually authored;
- Review accountability: we conduct reasonable review over AI-generated content, and assume no indemnification liability beyond stipulations of this Policy for inaccuracy or incompleteness arising from inherent technical limitations of AI technology.
- 4.4 Status of Third-party AI Service Providers as Data Processors Under the GDPR regulatory framework, Google Gemini, OpenAI, Anthropic, Azure AI, LangChain and Tavily act as our data processors. Data Processing Agreements (DPAs) incorporating Standard Contractual Clauses (SCCs) have been executed with us to define processing scope and data security obligations.
V. Data Storage and Cross-border Transfer
- 5.1 Data Storage Infrastructure
- All your data is stored in AWS data centers located in the United States;
- Your data will not be transmitted to WebHub headquarters in Singapore, and shall only be processed and stored within North America;
- All data transfer is encrypted via TLS 1.3 protocol.
- 5.2 Compliance Mechanisms for Cross-border Transfer
We adopt the following mechanisms to ensure lawful cross-border data transfer:
- Both the United States and Singapore have obtained adequacy decisions from the European Union under GDPR;
- We have entered into DPAs incorporating SCCs with all third-party AI and cloud service providers;
- We have signed a DPA with WebHub, stipulating that WebHub acts as our data processor and only processes data within the necessary scope of services, without using data for other purposes;
- 5.3 Data Retention Period
Your data will be retained in accordance with the terms below, excluding data subject to statutory retention obligations:
- Account registration data: retained during account validity, and erased within 30 days upon account deactivation;
- AI-generated site content and configurations: retained during account validity, and erased within 12 months upon account deactivation;
- AI conversation records (general chat logs): retained for no more than 90 days, permanently deleted automatically upon expiry;
- AI conversation records (LangChain AI Copilot): retained for no more than 90 days; recording can be disabled after opt-out;
- LangChain edge logs (traffic metadata): retained for no more than 30 days;
- Tavily search query logs: retained for no more than 90 days, then anonymized upon expiry;
- Security logs: retained for no more than 12 months;
- Statutorily required data: retained as mandated by tax laws, e-commerce laws and other applicable laws, and deleted once retention obligation expires;
- Anonymized statistical data: retained indefinitely without the possibility of re-identifying individual users;
- Azure AI invocation logs (Zero Data Retention mode): zero data retention by default; logs kept for 30 days if enabled.
- 5.4 Post-deletion Data Handling: Deleted data will be irreversibly destroyed to preclude any restoration. Anonymized statistical data may be utilized for AI model improvement without additional user consent.
VI. Data Sharing and Third-party Disclosure
- 6.1 We undertake not to sell, rent or transfer your personal data. Data may only be shared with third parties under the following circumstances: The platform may integrate third-party service providers such as Amazon Web Services (AWS), Cloudflare, Microsoft Azure OpenAI, Google Gemini, OpenAI, Sendbird, Google Analytics, Google Search Console, Elastic Email, Tavily, Cohere, LangGraph/LangSmith, Semrush, and others, for the provision of cloud infrastructure, network security and acceleration, artificial intelligence generation, real-time communication, email delivery, internet search, search analytics, SEO capabilities, and related enhanced features. The specific scope of integration is subject to the actual activation on the platform.
Your personal data may also be shared with payment processor (Stripe) during transaction settlement, limited to transaction-essential information and governed by the processor’s privacy policy. Your personal data may also be shared in the following circumstances:
- with regulatory authorities and law enforcement agencies as required by law to respond to law enforcement requests;
- in connection with a corporate reorganization, merger, or acquisition, for business continuity purposes.
- 6.2 Data Processor Oversight: We conduct regular audits of all data processors to verify their data protection practices comply with provisions herein.
VII. Cookie Policy
- 7.1 Cookie Overview
This Website uses cookies and similar tracking technologies to sustain basic website functions, analyze user behavior and optimize user experience. A cookie is a small piece of text data stored on your device, placed by us or third-party service providers when you access the Website.
- 7.2 Classification and Description of Cookies
- Strictly Necessary Cookies: These cookies are essential for the proper functioning of the Website to operate properly. They may be set without your consent and cannot be disabled.
- Non-essential Cookies: These cookies are not required for the operation of the Website and are used solely to optimize services, analyze usage data, or provide personalized marketing. They will only be set after you have explicitly clicked “Accept”, and you may withdraw your consent at any time. The cookies include performance/analytics cookies, advertising/marketing cookies, social media cookies, functionality cookies, etc.
- 7.3 Cookie Management: You may adjust cookie preferences via browser settings such as clearing cookies and blocking third-party cookies, the “Cookie Settings” panel at the Website footer, or our privacy preference center. The processing of cookies carried out prior to the withdrawal of your consent shall remain unaffected; after withdrawal, relevant cookie functionalities will be restricted.
- 7.4 Do Not Track: We respect your privacy preferences. Please note that “Do Not Track” browser setting may be incompatible with certain website features, for which we assume no liability.
VIII. Data Security Safeguards
- 8.1 Technical Protection Measures
We implement the following technical safeguards to secure your personal data:
- Transfer encryption: All data transfer is protected by TLS 1.3 encryption against interception;
- Access control: Role-based access control combined with multi-factor authentication, adhering to the principle of least privilege;
- Edge security: DDoS protection and Web Application Firewall (WAF) filtering provided by the LangChain edge layer safeguard platform and user website security;;
- AI-generated content security: Azure AI Content Safety automatically filters harmful input and output content;
- Data isolation: Data of individual users and different functionalities is stored and processed separately to prevent unauthorized cross-data access.
- 8.2 Data Breach Response
In the event of a data security incident, we shall report the case to relevant regulatory authorities within 72 hours. Affected users will be promptly notified of breached data categories, potential impacts and remedial measures adopted, with reasonable remedies provided accordingly.
IX. User Data Rights
- 9.1 Your Data Rights
- Right of Access: You may inquire with us at any time to understand what personal data about you is collected through cookies;
- Right to Rectification: If you discover that the collected data is inaccurate, you may request that we correct it;
- Right to Erasure: You may request that we delete the personal data collected about you through cookies;
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data;
- Right to Data Portability: You have the right to request that we provide your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to you or another data controller;
- Right to Object: You may object to data processing based on legitimate interests under specific circumstances;
- Right to Lodge a Complaint: You may lodge a complaint with a local data protection supervisory authority.
- Right against automated decision-making: You may decline substantial decisions solely produced by automated processing activities including user profiling.
- 9.2 Exercise of Rights
You may exercise the foregoing rights through the following means:
- Self-service portal: View and export your account data independently via the “Account Settings—Privacy Management” page on our Website;
- Email application: Submit your request to our official contact email. We will respond to your inquiry within 30 days;
- Third-party AI data processing: We will assist you in submitting data deletion requests to relevant service providers for personal data handled by Azure AI, LangChain and Tavily;
- 9.3 CCPA Specific Provisions (For California Residents)
- Non-sale Commitment: We will not sell your personal data within the definition set forth by the CCPA;
- Right to Know: You have the right to access details regarding categories, sources, processing purposes and sharing parties of your collected personal data;
- Right to Erasure: You may request removal of your personal data, save for specific exceptions;
- Right to Nondiscrimination: No discriminatory service standards or pricing will be applied when you exercise your right to privacy.
- 9.4 Identity Authentication: To secure your account, we will verify your identity before processing any rights-related requests. You shall provide valid identification information for authentication purposes.
X. Minor Protection
- 10.1 Our Website services are not directed at persons under 18 years of age or below the legal age of majority in applicable countries/regions. We refrain from intentional collection of personal data belonging to minors.
- 10.2 Any personal data mistakenly collected from underage users will be deleted immediately upon discovery.
- 10.3 Minors are eligible to use our services only after their guardians have fully acknowledged and agreed to this Policy, and usage shall be confined within the scope authorized by guardians. Minors must stop using the services immediately if guardians decline consent.
- 10.4 Guardians may apply for account cancellation and deletion of relevant data via our contact email address upon discovering that minors under their guardianship have registered accounts.
XI. Policy Amendment and Notification
- 11.1 We reserve the right to amend this Policy at any time as required by changes in laws and regulations, regulatory requirements, and business adjustments.
- 11.2 Material revisions cover, without limitation, major changes to processing purposes, addition of new data processors, fundamental adjustments to cross-border data transfer rules and substantial limitations imposed on user rights.
- 11.3 Users will be notified of material amendments 30 days in advance through Website pop-ups, registered emails or Website announcements. Revised terms shall come into force once the public notice period ends.
- 11.4 Minor revisions such as textual polishing and layout modification take effect instantly after online update, with no separate individual notice required.
- 11.5 Your continued use of the services of this Website shall be deemed as acceptance of the updated Policy. If you do not agree to the updated Policy, you have the right to cease using the services and cancel your account within the notice period.
- 11.6 Historical versions of this Policy will be archived on the Website for public inspection.
XII. Contact Information
- 12.1 Contact Information of the Data Controller:
Contact Email: [____@____.com]
Contact Address: [ ]
- 12.2 WebHub Technical Platform Contact Channels:
Customer Service Email: