Privacy Policy

Effective Date: ________, 2026
We place paramount importance on protecting your personal data. Please read carefully and fully understand this Privacy Policy (hereinafter referred to as the “Policy”) before using this Website. This Policy sets out how we collect, use, store, share and protect your personal data, and the data rights you are entitled to. Should you have any questions regarding this Policy, please reach us through the contact details stated at the end.

I. Scope of Application

  1. 1.1 This Policy applies to all activities you perform on this Website, including but not limited to account registration, page browsing, order placement, AI functionality access, online consultation and form submission.
  2. 1.2 This Policy complies with the following applicable laws and regulations: European Union’s General Data Protection Regulation (GDPR), ePrivacy Directive, Singapore’s Personal Data Protection Act (PDPA), California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), as well as Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
  3. 1.3 Third-party services embedded in this Website shall abide by their own privacy policies. By using any third-party service, you are deemed to have read, understood, and agreed to that service’s privacy policy.

II. Types of Collected Personal Data

  1. 2.1 Account and Identity Information (User-submitted Data)

We collect the following information you actively provide during service use:

  1. 2.2 Automated Data Collection

We collect data automatically using website automation tools, server logs and AI activity logs:

  1. 2.3 Data from Third Parties

We may obtain your personal data from third-party providers in the following circumstances:

  1. 2.4 Sensitive Personal Data Statement: We do not voluntarily collect sensitive personal data including ethnicity, religious beliefs, health status, financial account details, identification numbers and precise geolocation, unless necessary for service provision and permitted by your explicit consent. Do not include such sensitive data in AI chat inputs. AI service providers may process submitted content under their own privacy policies.

III. Purposes of Data Processing

  1. 3.1 We adhere strictly to the “data minimization” principle, and process your personal data only to the extent necessary for the purposes below:
  1. 3.2 Your personal data shall not be processed for new purposes without reasonable connection to the aforesaid intentions. We will notify you in advance and obtain requisite consent prior to any new data processing activities.

IV. Specific Rules Governing AI Data Processing

  1. 4.1 Processing Specifications for AI Integration Services

We deliver AI functionalities via the below service providers, with relevant data processing specifications specified as follows:

  1. 4.2 Consent Rules for Model Training
  1. 4.3 Ownership and Review Accountability of AI-generated Content
  1. 4.4 Status of Third-party AI Service Providers as Data Processors Under the GDPR regulatory framework, Google Gemini, OpenAI, Anthropic, Azure AI, LangChain and Tavily act as our data processors. Data Processing Agreements (DPAs) incorporating Standard Contractual Clauses (SCCs) have been executed with us to define processing scope and data security obligations.

V. Data Storage and Cross-border Transfer

  1. 5.1 Data Storage Infrastructure
  1. 5.2 Compliance Mechanisms for Cross-border Transfer

We adopt the following mechanisms to ensure lawful cross-border data transfer:

  1. 5.3 Data Retention Period

Your data will be retained in accordance with the terms below, excluding data subject to statutory retention obligations:

  1. 5.4 Post-deletion Data Handling: Deleted data will be irreversibly destroyed to preclude any restoration. Anonymized statistical data may be utilized for AI model improvement without additional user consent.

VI. Data Sharing and Third-party Disclosure

  1. 6.1 We undertake not to sell, rent or transfer your personal data. Data may only be shared with third parties under the following circumstances: The platform may integrate third-party service providers such as Amazon Web Services (AWS), Cloudflare, Microsoft Azure OpenAI, Google Gemini, OpenAI, Sendbird, Google Analytics, Google Search Console, Elastic Email, Tavily, Cohere, LangGraph/LangSmith, Semrush, and others, for the provision of cloud infrastructure, network security and acceleration, artificial intelligence generation, real-time communication, email delivery, internet search, search analytics, SEO capabilities, and related enhanced features. The specific scope of integration is subject to the actual activation on the platform.

Your personal data may also be shared with payment processor (Stripe) during transaction settlement, limited to transaction-essential information and governed by the processor’s privacy policy. Your personal data may also be shared in the following circumstances:

  1. 6.2 Data Processor Oversight: We conduct regular audits of all data processors to verify their data protection practices comply with provisions herein.

VII. Cookie Policy

  1. 7.1 Cookie Overview

This Website uses cookies and similar tracking technologies to sustain basic website functions, analyze user behavior and optimize user experience. A cookie is a small piece of text data stored on your device, placed by us or third-party service providers when you access the Website.

  1. 7.2 Classification and Description of Cookies
  1. 7.3 Cookie Management: You may adjust cookie preferences via browser settings such as clearing cookies and blocking third-party cookies, the “Cookie Settings” panel at the Website footer, or our privacy preference center. The processing of cookies carried out prior to the withdrawal of your consent shall remain unaffected; after withdrawal, relevant cookie functionalities will be restricted.
  2. 7.4 Do Not Track: We respect your privacy preferences. Please note that “Do Not Track” browser setting may be incompatible with certain website features, for which we assume no liability.

VIII. Data Security Safeguards

  1. 8.1 Technical Protection Measures

We implement the following technical safeguards to secure your personal data:

  1. 8.2 Data Breach Response

In the event of a data security incident, we shall report the case to relevant regulatory authorities within 72 hours. Affected users will be promptly notified of breached data categories, potential impacts and remedial measures adopted, with reasonable remedies provided accordingly.

IX. User Data Rights

  1. 9.1 Your Data Rights
  1. 9.2 Exercise of Rights

You may exercise the foregoing rights through the following means:

  1. 9.3 CCPA Specific Provisions (For California Residents)
  1. 9.4 Identity Authentication: To secure your account, we will verify your identity before processing any rights-related requests. You shall provide valid identification information for authentication purposes.

X. Minor Protection

  1. 10.1 Our Website services are not directed at persons under 18 years of age or below the legal age of majority in applicable countries/regions. We refrain from intentional collection of personal data belonging to minors.
  2. 10.2 Any personal data mistakenly collected from underage users will be deleted immediately upon discovery.
  3. 10.3 Minors are eligible to use our services only after their guardians have fully acknowledged and agreed to this Policy, and usage shall be confined within the scope authorized by guardians. Minors must stop using the services immediately if guardians decline consent.
  4. 10.4 Guardians may apply for account cancellation and deletion of relevant data via our contact email address upon discovering that minors under their guardianship have registered accounts.

XI. Policy Amendment and Notification

  1. 11.1 We reserve the right to amend this Policy at any time as required by changes in laws and regulations, regulatory requirements, and business adjustments.
  2. 11.2 Material revisions cover, without limitation, major changes to processing purposes, addition of new data processors, fundamental adjustments to cross-border data transfer rules and substantial limitations imposed on user rights.
  3. 11.3 Users will be notified of material amendments 30 days in advance through Website pop-ups, registered emails or Website announcements. Revised terms shall come into force once the public notice period ends.
  4. 11.4 Minor revisions such as textual polishing and layout modification take effect instantly after online update, with no separate individual notice required.
  5. 11.5 Your continued use of the services of this Website shall be deemed as acceptance of the updated Policy. If you do not agree to the updated Policy, you have the right to cease using the services and cancel your account within the notice period.
  6. 11.6 Historical versions of this Policy will be archived on the Website for public inspection.

XII. Contact Information

  1. 12.1 Contact Information of the Data Controller:

Contact Email: [____@____.com]
Contact Address: [ ]

  1. 12.2 WebHub Technical Platform Contact Channels:

Customer Service Email: